Cập nhật nhanh các tin an ninh mạng đáng chú ý trong ngày 30/07/2026, được biên tập tự động cho độc giả gocdulieu.com từ các nguồn bảo mật công khai. Bài viết tập trung vào rủi ro có thể ảnh hưởng tới quản trị viên hệ thống, đội vận hành bảo mật và doanh nghiệp.
Điểm nóng bảo mật
- Cisco warns of FMC static credential flaw exploited in zero-day attacks — Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices. […] Nguồn: BleepingComputer (30/07 04:35).
- New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands — Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook and run shell commands as the Gite Nguồn: The Hacker News (29/07 14:47).
- Ghost Credentials Expose Cloud Systems to Hidden Identity Risks — Dormant nonhuman identities can create security blind spots, says security researcher Aleksandr Krasnov, who plans to release an open source tool next week at Black Hat USA 2026 that sniffs out trust paths. Nguồn: Dark Reading (29/07 04:33).
- Tame Dependabot: Group your updates, slow the cadence, keep security fast — Dependabot keeps your dependencies current, but its defaults can flood your repository with pull requests. Here's how grouping updates, slowing the cadence, and keeping security fixes fast cut the noise on a Microsoft open source project. T Nguồn: GitHub Security (29/07 23:00).
- Russian hackers exploit Exchange OWA zero-day for long-term mailbox access — The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email campaigns to deliver a sophisticated backdoor called OWAReaper. […] Nguồn: BleepingComputer (30/07 06:44).
- Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory — Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution. The vulnerability, t Nguồn: The Hacker News (29/07 22:39).
Ưu tiên xử lý trong 24–48 giờ
- Kiểm kê các dịch vụ public-facing: VPN, gateway, IAM/NAC, remote support, dashboard quản trị và hệ thống có quyền cao.
- Đối chiếu phiên bản với advisory chính thức; ưu tiên vá lỗ hổng đang bị khai thác, có PoC công khai hoặc ảnh hưởng thiết bị biên.
- Rà soát log đăng nhập, thay đổi cấu hình, session/token bất thường và dấu hiệu truy cập từ hạ tầng lạ.
- Với AI agent/plugin/extension, áp dụng quyền tối thiểu, bật logging cho tool-call/API call và tách dữ liệu nhạy cảm khỏi môi trường thử nghiệm.
CISA KEV / lỗ hổng cần theo dõi
- CISA KEV chưa truy cập được từ môi trường tự động (HTTPError: HTTP Error 403: Forbidden); cần đối chiếu thủ công nếu đang xử lý hệ thống trọng yếu.
Nguồn tham khảo
- BleepingComputer — Cisco warns of FMC static credential flaw exploited in zero-day attacks
- The Hacker News — New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands
- Dark Reading — Ghost Credentials Expose Cloud Systems to Hidden Identity Risks
- GitHub Security — Tame Dependabot: Group your updates, slow the cadence, keep security fast
- BleepingComputer — Russian hackers exploit Exchange OWA zero-day for long-term mailbox access
- The Hacker News — Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
Lưu ý: Bản tin được biên tập theo hướng thực hành; trước khi áp dụng thay đổi trên hệ thống production, anh/chị nên đối chiếu với advisory chính thức của nhà cung cấp và quy trình change management nội bộ.
