
Cybersecurity Threats and Vulnerabilities Reported by SANS Internet Storm Center on July 28, 2026
On July 28, 2026, the SANS Internet Storm Center reported multiple cybersecurity threats and vulnerabilities. Attackers exploited a variation of the Spring Boot heapdump endpoint, accessing unprotected or weakly secured (e.g., admin/admin credentials) actuator endpoints to extract memory snapshots containing sensitive data like API keys. A remote code execution (RCE) vulnerability in vBulletin was disclosed, stemming from improper sanitization of input passed to PHP’s exec function, enabling arbitrary command execution. Microsoft Defender for Linux received a flawed update that prevented the service from restarting after a system reboot, requiring manual remediation if the system was restarted before the fix was applied. MongoDB patched 26 vulnerabilities, including a critical memory corruption flaw in standalone instances with compute mode enabled, triggered via malformed BSON data in the aggregation pipeline, alongside multiple high-severity denial-of-service issues.