// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRF-01DTG 0600Z
ColdRecon / Brief Archive / Week of July 20, 2026
Signal Brief · Archived

Week of July 20, 2026

2026-07-20 — 2026-07-26 · 5 PUBLIC EVENTS · GENERAL / NON-PERSONALIZED

In the week of July 20, 2026, ColdRecon logged 5 public endpoint-security events from open-source reporting — 3 research pocs, 1 vuln disclosure, 1 incident. Vendors in the record this week: Cursor, Apple.

The Week's Public Record

Events

2026-07-26
vuln disclosure
Cursor AI IDE Zero-Day Allows Malicious git.exe Execution on WindowsCursor git.exe hijack zero-day
A zero-day vulnerability in Cursor AI IDE allows a malicious git.exe placed in a repository to execute automatically when a Windows developer opens the project. The flaw was disclosed by Mindgard after seven months of unresponsiveness from Cursor. This enables arbitrary code execution with the user's privileges, bypassing security warnings.
2026-07-26
research poc
msaRAT Hides C2 Inside Legitimate Browser Processes to Evade EDRmsaRAT
The msaRAT malware, associated with Chaos ransomware, uses a technique to hide its command-and-control communication by injecting into Chrome or Edge browser processes. This allows it to blend into normal browser traffic, potentially evading endpoint detection that relies only on process name monitoring.
2026-07-26
research poc
OpenAI agent autonomously hacks company in security testOpenAI-Agent-Security-Test
In a controlled security test, an OpenAI agent autonomously compromised a company's systems over several days without detection. The incident demonstrates the potential for AI-driven attacks to operate stealthily and evade traditional security monitoring.
2026-07-26
incident
BlueNoroff Uses Fake Zoom and Teams Meetings to Steal CryptocurrencyBlueNoroff Fake Meeting Crypto Theft
North Korean threat group BlueNoroff is conducting a campaign using fake Zoom and Teams meeting invitations to deliver malware that scans for cryptocurrency wallets and hijacks Telegram sessions on Windows and macOS endpoints. The attack involves social engineering to trick victims into downloading malicious scripts, leading to theft of credentials and crypto assets.
2026-07-26
research poc
Apple Gatekeeper Bypass Replaces Trusted Mac Apps After FootholdApple Gatekeeper Bypass via App Replacement
Researchers demonstrated a technique to bypass Apple's Gatekeeper by replacing a trusted application after initial execution, allowing malicious code to run without triggering security warnings. This method undermines macOS code-signing and notarization checks, highlighting a gap in endpoint protection that relies solely on static reputation checks.
Every event in this brief is a record in ColdRecon's canonical set, drawn from public open-source reporting and linked to its source. This is the general, non-personalized signal — published 7 days after the fact. The live daily brief, written for your deals, is for cleared officers.

This is last week, public. Get this morning's, written for you.

The live ColdRecon brief lands at 0600 daily — the same signal, filtered to your competitors and framed for your deals. Request clearance and tomorrow's is yours.

Request Clearance →