Cập nhật nhanh các tin an ninh mạng đáng chú ý trong ngày 31/07/2026, được biên tập tự động cho độc giả gocdulieu.com từ các nguồn bảo mật công khai. Bài viết tập trung vào rủi ro có thể ảnh hưởng tới quản trị viên hệ thống, đội vận hành bảo mật và doanh nghiệp.
Điểm nóng bảo mật
- Cisco warns of FMC static credential flaw exploited in zero-day attacks — Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices. […] Nguồn: BleepingComputer (30/07 04:35).
- Cisco FMC static credentials exploited by attackers (CVE-2026-20316) — A static credentials vulnerability (CVE-2026-20316) in Cisco Secure Firewall Management Center (FMC), a platform for centrally managing multiple Cisco Secure Firewall devices across a network, is being leveraged by attackers, CISA warned. T Nguồn: Help Net Security (30/07 17:44).
- Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities (KEV) catalog, follo Nguồn: The Hacker News (30/07 12:08).
- Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897) — Russia-affiliated cyber espionage group Laundry Bear (aka Void Blizzard, aka TA488) is exploiting CVE-2026-42897, a cross-site scripting vulnerability in Microsoft Exchange, to target US and European government entities and a variety of pri Nguồn: Help Net Security (30/07 21:23).
- Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation — The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access (OWA), to target U.S. and European governm Nguồn: The Hacker News (30/07 14:40).
- Microsoft Teams vishing attacks lead to Chaos ransomware attacks — Threat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks targeting North American organizations. […] Nguồn: BleepingComputer (30/07 22:56).
Ưu tiên xử lý trong 24–48 giờ
- Kiểm kê các dịch vụ public-facing: VPN, gateway, IAM/NAC, remote support, dashboard quản trị và hệ thống có quyền cao.
- Đối chiếu phiên bản với advisory chính thức; ưu tiên vá lỗ hổng đang bị khai thác, có PoC công khai hoặc ảnh hưởng thiết bị biên.
- Rà soát log đăng nhập, thay đổi cấu hình, session/token bất thường và dấu hiệu truy cập từ hạ tầng lạ.
- Với AI agent/plugin/extension, áp dụng quyền tối thiểu, bật logging cho tool-call/API call và tách dữ liệu nhạy cảm khỏi môi trường thử nghiệm.
CISA KEV / lỗ hổng cần theo dõi
- CISA KEV chưa truy cập được từ môi trường tự động (HTTPError: HTTP Error 403: Forbidden); cần đối chiếu thủ công nếu đang xử lý hệ thống trọng yếu.
Nguồn tham khảo
- BleepingComputer — Cisco warns of FMC static credential flaw exploited in zero-day attacks
- Help Net Security — Cisco FMC static credentials exploited by attackers (CVE-2026-20316)
- The Hacker News — Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
- Help Net Security — Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897)
- The Hacker News — Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
- BleepingComputer — Microsoft Teams vishing attacks lead to Chaos ransomware attacks
Lưu ý: Bản tin được biên tập theo hướng thực hành; trước khi áp dụng thay đổi trên hệ thống production, anh/chị nên đối chiếu với advisory chính thức của nhà cung cấp và quy trình change management nội bộ.
