Skip to content

Confidential Β· 02 Jul 2026

πŸ›‘οΈ Daily Cybersecurity Briefing β€” 2026-07-02 (Thursday)

Window: last 24–48h Β· Last updated: 19:04 UTC. Severity: πŸ”΄ CRITICAL Β· 🟑 HIGH Β· 🟒 MEDIUM.

Threat level ELEVATEDVictims L30D 340Top actor QilinM&A L30D $150M

πŸ’Ό M&A ACTIVITY

Aikido Security β†’ RootMedium(Jun 30, ~$70M) β€” Belgian open-source AppSec unicorn acquires Israeli startup Root.io; Root uses AI agents to generate backported patches for vulnerable open-source library versions in 15–40 minutes, without forcing version upgrades. Extends Aikido from scanning into autonomous remediation. Help Net Security Β· CTech
L30D summary (Jun 2–Jul 2):11 named deals closed or announced in June 2026, total disclosed value ~$5.6B+. The three biggest: (1) Accenture β†’ Dragos + runZero + NetRise (~$4.175B combined, Jun 18) β€” end-to-end OT/ICS platform; (2) Booz Allen Hamilton β†’ Ultra I&C Mission Solutions ($720M, Jun 22) β€” defense encryption / edge compute for classified programs; (3) Dream ($260M Series C, Jun 18) β€” national-level cyber AI. Also: 1Password/Apono ($250–300M, NHI/JIT), SailPoint/Entro (~$200M, NHI), Aikido/Root (~$70M, open-source autonomous remediation). Consolidation theme: NHI and JIT identity automation (boards acting on the ShinyHunters lesson), OT/ICS security, defense technology sovereignty, and AI-driven autonomous AppSec. Macro context: Momentum Cyber H1 2026 review (published Jul 1) counted 219 M&A transactions in H1 2026 ($9.1B disclosed value), tracking to the highest annual deal count Momentum Cyber has ever recorded; June was the strongest single month, driven by the Accenture/Dragos mega-deal. See M&A.md for the full tracker.

⚠️ CRITICAL BREACHES & INCIDENTS

"FortiBleed" β€” INC Ransom + Lynx joint operation: 86,644 FortiGate firewalls confirmed compromised, ~110M credentials exfiltrated (Jul 2 disclosure)CriticalA coordinated ~20-person criminal operation attributed jointly to INC Ransom and Lynx ransomware groups exploited CVE-2026-24858 (FortiCloud SSO SAML authentication bypass, CVSS 9.8) to target 430,000+ FortiGate firewall/VPN appliances across 194 countries; Fortinet forensic review confirmed 86,644 compromised. A bespoke "FortiGate Sniffer" credential-harvesting tool exfiltrated approximately 110 million credentials from compromised devices. Emergency patch and IOC guidance issued July 2; see Critical Vulnerabilities. Scale places this among the largest single-vendor network appliance compromises on record. Fortinet PSIRT Β· BleepingComputer
DHS Homeland Security Information Network (HSIN) breached β€” federal threat-sharing infrastructure confirmed hitCriticalServers hosting HSIN (the primary platform for sharing threat intelligence between federal agencies and state/local law enforcement fusion centers) plus an associated SharePoint collaboration system were compromised; attack window estimated late May–early June 2026, publicly disclosed July 1. DHS confirmed the breach, isolated affected systems, and launched a forensic investigation. No classified networks were affected, but HSIN carries sensitive law enforcement operational data including open investigations, facility-threat mappings, and inter-agency partner identities. Actor unattributed. BleepingComputer Β· Nextgov/FCW
ShinyHunters claims 21M Salesforce records from Fluke Corporation (Jul 2)HighShinyHunters posted Fluke Corporation (Fortive subsidiary; electronic test and measurement equipment; Everett, WA) on their DLS July 2, 2026, claiming over 21 million Salesforce records. Group stated failed negotiations before publishing. No Fluke or Fortive public statement; πŸŸ₯ unverified. Scale is consistent with ShinyHunters' Salesforce social-engineering campaign (now 32+ named victims in 2026). RedPacket Security Β· ransomware.live
Medtronic β€” ~300,000 healthcare customers notified of April breach (Jul 2)HighMedtronic began sending breach notification letters July 2, 2026 to approximately 300,000 healthcare customers affected by an April 13–19, 2026 unauthorized access incident. A third-party vendor credential compromise was the attack vector; data exposed includes names, contact information, and product/service history. Medical devices and patient safety systems confirmed unaffected. Class action investigation opened. ShinyHunters DLS attribution; 🟨 breach confirmed by Medtronic, group attribution via media reporting. HIPAA Journal Β· BleepingComputer
Japan multinational wave: Sapporo Holdings (Pokka/Sleeman), Aflac Japan, KDDI β€” three major companies disclose breachesHighSapporo Holdings Ltd. disclosed June 24, 2026 that two overseas subsidiaries (Pokka Corporation Singapore and Sleeman Breweries, Canada) sustained suspected unauthorized access; operations shut down, no confirmed data exfiltration yet. Completes a four-company cluster of Japanese multinational cyber incidents in June 2026: Sapporo (food+beverage), Aflac Japan (insurance), KDDI (telecoms, 14.22M accounts), and Nidec Chaun Choung Technology (electronics, Blackfield, $2M ransom). Common thread: overseas subsidiaries and third-party systems targeted, not Japanese domestic infrastructure. Actor for Sapporo unattributed. The Record
Aflac Japan β€” 4.38M customers exposed (disclosed Jun 30)HighUnauthorized access June 15–25, 2026 to Aflac's Japan subsidiary systems; names, addresses, and phone numbers for 4.38M customers exposed; banking details (account numbers, etc.) for approximately 230K customers affected. Japan FSA and police notified; US operations not affected. Attack vector undisclosed; attribution to Scattered Spider consistent with TTPs per industry analysis but πŸŸ₯ unverified. SecurityWeek Β· BleepingComputer
Nissan Americas β€” 53,000+ employees, Oracle PeopleSoft CVE-2026-35273 (carry-forward)HighSSNs, Social Insurance Numbers, banking/payroll/W-2/dependent data for current and former employees across US, Canada, Mexico, and Brazil; attack window May 27–June 9; ShinyHunters campaign. Multi-country regulatory exposure under US state laws, PIPEDA, LFPDPPP, and LGPD ongoing. The Register Β· SC Media
Kubota North America β€” employee HR data accessed for 35 days (disclosed Jun 30)HighUnauthorized access to Kubota North America Corporation's HR systems from March 16 to April 20, 2026; attackers accessed files containing employee and dependent personal data: names, SSNs, Social Insurance Numbers, dates of birth, and taxpayer IDs. Attack identified April 30; breach scope confirmed June 16; employee notifications sent June 30. At minimum 2,237 Texas residents confirmed affected; no ransomware group has claimed responsibility; actor unattributed. No operational disruption reported. BleepingComputer Β· ClaimDepot

πŸ”“ CRITICAL VULNERABILITIES

CVE-2026-24858 β€” FortiCloud SSO SAML authentication bypass CVSS 9.8 β€” actively exploited ("FortiBleed", Jul 2)CriticalCritical SAML authentication bypass in FortiGate / FortiCloud SSO allows unauthenticated remote takeover of firewall devices and credential harvesting at scale; no user interaction required. Exploited by INC Ransom + Lynx joint operation to compromise 86,644+ firewalls globally. Emergency patch issued July 2; update FortiOS to the latest release immediately and audit for FortiGate Sniffer IOCs in memory and logs. Fortinet PSIRT Β· BleepingComputer
CVE-2026-48558 β€” SimpleHelp RMM CVSS 10.0 β€” FEDERAL DEADLINE TODAY (Jul 2)CriticalAuthentication bypass via OIDC token signature non-verification; allows an unauthenticated attacker to forge technician sessions and circumvent MFA. Active exploitation confirmed in the wild: TaskWeaver + Djinn Stealer deployed by threat actors (BlackPoint Adversary Pursuit Group); discovered by Horizon3.ai. Approximately 14,000 exposed servers. Patch: SimpleHelp v5.5.16 / v6.0 RC2. KEV added June 29; BOD 22-01 federal deadline ends today. Horizon3.ai Β· SecurityAffairs
CVE-2026-46817 β€” Oracle E-Business Suite (Payments) CVSS 9.8 β€” active exploitation, ~950 exposed instancesCriticalUnauthenticated RCE / authentication bypass via the `ibytransmit` endpoint; exploitation first confirmed June 27. Exposed instance count updated: 450 (as of July 1) to approximately 950 per Shadowserver / Defused Cyber scanning as of July 2 morning β€” the jump reflects improved visibility into global EBS deployments, not new vulnerable instances. Linked to the Nissan Americas payroll breach; initial access brokers (DriveSurge) actively selling access. Patch: Oracle May 2026 Critical Security Patch Update. BleepingComputer Β· Shadowserver
CVE-2026-8037 β€” Progress Kemp LoadMaster CVSS 9.6 β€” active exploitation confirmed June 29CriticalPre-auth OS command injection via the `/accessv2` API endpoint; unauthenticated attacker can execute arbitrary commands as root on the load balancer appliance. Root cause: `escape_quotes()` fails to null-terminate sanitized strings, producing an OOB read into adjacent heap memory. Progress published advisory and patch on June 4; watchTowr Labs published full exploit chain writeup June 29, immediately triggering active exploitation attempts (confirmed eSentire). LoadMaster is a network-edge application delivery controller, making unauthenticated pre-auth RCE particularly severe. Restrict LoadMaster management access to trusted networks and apply firmware patch now. The Hacker News Β· SC Media
CVE-2026-50548 / CVE-2026-50549 "DuneSlide" β€” Cursor AI IDE CVSS 9.8 β€” prompt injection sandbox escape, patchedHighTwo chained flaws (Cato AI Labs, disclosed July 1): a crafted prompt in content fetched by Cursor's AI agent (via MCP server or web search result) causes a symlink traversal to bypass Cursor's terminal sandbox, then executes arbitrary commands on the developer's host as the logged-in user. No public exploitation confirmed. Patched in Cursor 3.0 (released April 2); all versions < 3.0 affected. Risk surface: developers who use Cursor against untrusted repositories, MCP servers, or web-search-augmented agents. Update Cursor immediately; audit MCP server trust boundaries. The Hacker News Β· SecurityWeek Β· Cato AI Labs / Straiker
CVE-2026-35273 β€” Oracle PeopleSoft CVSS 9.8 β€” ongoing ShinyHunters campaignHighPatched in Oracle June 2026 CSPU; zero-day exploited May 27–June 9 across 300+ instances / 100+ organizations. Mandiant actively notifying affected parties. Verify PeopleSoft patch status and restrict external access to `/psp/` endpoints. Google Cloud/Mandiant
StoneFly Storage Concentrator β€” CVSS v4 9.8 β€” unauthenticated RCE β†’ root (CISA ICSA-26-181-06, June 30)CriticalMultiple critical vulnerabilities disclosed in StoneFly Storage Concentrator SC and SCVM appliances: (1) command injection in debug.pl script reachable without authentication β€” remote attacker can execute arbitrary commands as root via crafted HTTP request; (2) command injection via ms_service.pl on TCP port 9000 (unauthenticated, root-level); (3) hardcoded credentials embedded in configuration files; (4) unauthenticated SQL injection via cookie values β€” leaks session tokens, password hashes, and stored secret keys; (5) reflected XSS in 404 error pages. CVEs: CVE-2026-56415, CVE-2026-55721, CVE-2026-50040, CVE-2026-50110, CVE-2026-56413. Affected: all SC/SCVM versions below 8.0.4.29. Patch: upgrade to Storage Concentrator 8.0.4.29 immediately. No CISA KEV entry yet; no confirmed exploitation reported. CISA ICSA-26-181-06 Β· Windows News
CVE-2026-33825 "BlueHammer" β€” Microsoft Defender CVSS 7.8 β€” now confirmed in ransomware campaigns per CISA (July 2)HighRace condition in Windows Defender's file remediation logic allows a local low-privileged attacker to overwrite arbitrary files and escalate to SYSTEM; successfully exploited, it exposes the SAM database and enables full local-host takeover. First disclosed April 2 by researcher "Nightmare Eclipse" (PoC published before Microsoft knew); patched April 14 Patch Tuesday; CISA KEV'd April 22 with May 6 federal deadline. CISA confirmed July 2 2026 that ransomware operators are now actively exploiting it as a privilege-escalation step in post-exploitation chains β€” making unpatched Windows 10/11 and Server endpoints live ransomware exposure. Patch if you haven't; this is a privilege-escalation force multiplier for any other initial access the attacker achieves. BleepingComputer Β· SecurityWeek Β· Picus Security
CVE-2026-45659 β€” Microsoft SharePoint Server RCE CVSS 8.8 β€” CISA KEV added July 1, FEDERAL DEADLINE JULY 4 (SATURDAY)HighDeserialization of untrusted data in SharePoint allows any authenticated user with Site Member permissions (the lowest contributor role) to execute arbitrary code over the network on affected servers; no admin access required, only a valid user account. Affects SharePoint Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016; patched in Microsoft's May 2026 Patch Tuesday. CISA added to the Known Exploited Vulnerabilities catalog July 1, 2026; BOD 26-04 federal remediation deadline is July 4, 2026 β€” a compressed 3-day window. Active exploitation confirmed in the wild. Prioritize patching SharePoint servers exposed to internal networks or internet β€” attacker surface is any authenticated user, meaning a single phished or compromised account is sufficient for initial code execution. The Hacker News Β· Help Net Security Β· SOCRadar Β· CISA KEV
Citrix NetScaler β€” 6 CVEs patched (CitrixBleed lineage, July 2, 2026)HighCitrix published a security bulletin July 2 addressing six vulnerabilities in NetScaler ADC and NetScaler Gateway. Key CVEs: CVE-2026-8451 (CVSS 8.8 β€” authenticated RCE via management interface), CVE-2026-8452 (CVSS 8.8 β€” privilege escalation), CVE-2026-8655 (CVSS 8.8 β€” authenticated memory corruption), CVE-2026-13474 (CVSS 8.7 β€” HTTP/2 Rapid Reset "Bomb" variant enabling DoS), CVE-2026-10816 (unauthenticated file read via management plane). Researcher community describes this batch as continuing the CitrixBleed architectural lineage β€” bugs in the same NetScaler SSL-VPN/ADC management stack that produced CVE-2023-4966. Fixed in NetScaler 14.1-72.61 and 13.1-63.18; older branches EOL. No exploitation confirmed at time of publication. Apply patches to all internet-exposed NetScaler ADC / Gateway appliances immediately β€” the CitrixBleed management-plane history means public exploitation tooling matures quickly for this product. Citrix Security Advisory Β· The Hacker News Β· watchTowr Labs Β· CERT-EU
Adobe ColdFusion + Campaign Classic β€” 7 CVSS 10.0 / 9.6 flaws, Priority 1 (July 1–2, 2026)HighAdobe released emergency patches for 11 vulnerabilities in ColdFusion (2025 Update 10 / 2023 Update 21) and 1 in Campaign Classic. Seven reach CVSS 10.0 or near-max: CVE-2026-48276, CVE-2026-48277, CVE-2026-48281, CVE-2026-48316, CVE-2026-48282, CVE-2026-48283 (ColdFusion β€” arbitrary code execution via unrestricted file upload, improper input validation, and path traversal) and CVE-2026-48286 (Campaign Classic CVSS 10.0 β€” incorrect authorization leading to unauthenticated arbitrary code execution). All exploit in low-complexity attacks requiring no user interaction. Adobe rates them Priority 1, indicating the company considers active exploitation likely, though no confirmed in-the-wild exploitation has been reported at time of publication. Patch ColdFusion and Campaign Classic immediately β€” Priority 1 patches attract rapid reverse-engineering and weaponization. The Hacker News Β· SecurityWeek Β· BleepingComputer
Browser-native ransomware via Chromium File System Access API β€” practical proof-of-concept (Check Point Research, Jul 1)HighCheck Point Research demonstrated that the Chromium File System Access API can be abused by a malicious web page to encrypt files in the browser's sandboxed virtual filesystem and demand payment β€” no native payload, download, or device exploit required. DeepSeek AI generated working attack code with notably lower refusal rates than competing models. On Android, Chromium-based browsers don't enforce the native-payload barrier, making mobile users the higher-risk target. No CVE assigned (API misuse, not a traditional vulnerability). No in-the-wild exploitation confirmed. Risk is primarily social engineering to a malicious site; users who don't store sensitive documents in browser-accessible directories on desktop are not materially exposed. Mobile Android Chromium users with downloaded documents in browser scope are higher risk. Check Point Research Β· The Hacker News Β· The Register

🚨 INTELLIGENCE AGENCY ALERTS & POLICY

Scattered Spider β€” Peter Stokes ("Bouquet"), 19, extradited to US (DOJ, Jul 1)CriticalDual US/Estonian citizen arrested in Finland April 2026 on an Interpol Red Notice; appeared before Chicago federal court June 30; DOJ announced extradition July 1. Charges: conspiracy, computer intrusion, wire fraud. Linked to 100+ Scattered Spider intrusions and $100M+ in cumulative ransom; first known intrusion committed at age 16; May 2025 luxury jeweler attack ($8M demand refused, $2M remediation). Stokes is the fifth Scattered Spider member to face US federal charges in 2025–2026. DOJ Β· Reuters
AA26-097A β€” Six-agency joint advisory: Iranian-affiliated actors exploiting PLCs in US critical infrastructureCritical(previously uncaptured across all prior briefings) β€” FBI / CISA / NSA / EPA / DOE / CNMF joint advisory published April 7, 2026 confirmed that Iranian-affiliated actors (CyberAv3ngers / IRGC-CEC linked) have exploited internet-exposed PLCs and HMIs in US water, energy, and government facilities since March 2026. Operational disruptions and financial losses were confirmed at victim organizations. Targeted equipment: Unitronics Vision series, AutomationDirect DirectLogic, Siemens SIMATIC, Schneider Electric Modicon. Attack vector: default credentials plus internet exposure β€” no sophisticated exploit required. CISA AA26-097A Β· FBI
CVE-2026-48558 federal remediation deadline (SimpleHelp) β€” TODAYHighBOD 22-01 / BOD 26-04 compliance deadline. Federal agencies not in compliance face CISA follow-up. See Critical Vulnerabilities section.

🌐 THREAT ACTOR & CAMPAIGN ACTIVITY

Ransomware DLS β€” July 1 activity:
The GentlemenHighJuly 1 victims: Boyne City (local government / US Michigan), FAC Logistique (logistics / France), Centre Ophtalmologique d'Ermont (healthcare ophthalmology / France), CTM India Limited motherson INDIA (automotive manufacturing / India; Motherson Group subsidiary; estimated attack June 22). Also active June 30: Mondottica (luxury eyewear / Italy), SDEZ (textile services / France), Melcor Developments Ltd (real estate+construction / Canada). June 24: Stadttheater Giessen (municipal theatre / Germany). June 22: Hooke Laboratories (biotech / US Lawrence MA), Royal Thai Navy Housing Cooperative (public sector / Thailand). All πŸŸ₯ unverified DLS claims. Group remains second-ranked actor by 2026 YTD count (~335 claimed); 483+ total DLS victims across 66 countries as of mid-June. Breachsense Β· RedPacket Security
SETTRAMedium(emerging actor, June 2026 debut): 7 new DLS claims since July 1 β€” Petra Diamonds (diamond mining / UK), City Lumber Company (building materials / US TN), Orion Registrar Inc. (certification / US), Amtivo (ISO certification / US), Joy Construction Corp (affordable housing construction / US), VCNY Home (home textiles / US; estimated attack June 2), and Cedrick Frank Associates (professional services / US). Now 22 known victims across 11+ countries. Infostealer-assisted initial access pattern consistent with established double-extortion operators. All πŸŸ₯ unverified. HookPhish Β· DeXpose Β· FalconFeeds Β· ransomware.live
QilinMediumJuly 1 DLS additions: Dennis Waters Rental Properties (real estate / US), Dynamic Laser Solutions Ltd. (industrial machinery / UK), Laughlin Nunnally Hood & Crum (legal services / US). All data scope and impact unconfirmed; πŸŸ₯ unverified DLS claims. DeXpose Β· ransomware.live
Brain CipherMediumJuly 1 victims: Golden State Orthopedic (healthcare / US) and Digital Dynamics Inc. (technology / US). Also claimed June 30: PAI Pharma (pharmaceuticals / US). All data scope unconfirmed; πŸŸ₯ unverified DLS claims. DeXpose Β· ransomware.live
KrybitMediumclaimed B'Laofood Joint Stock Company (food manufacturing / Vietnam) on July 1. Data scope unconfirmed; πŸŸ₯ unverified. DeXpose Β· ransomware.live
The GentlemenMediumalso claimed Pou Sheng International Holdings (footwear retail / China-HK, Yue Yuen Group subsidiary) and SDEZ (textile services / France; historic family-owned company est. 1816, 700+ employees, industrial laundry network across France and Belgium) on June 30. Both πŸŸ₯ unverified. ransomware.live
AkiraMediumAdvanced Business Systems (office solutions / US Quad Cities, 31 GB, June 30) and Refinery Hotel (hospitality / US New York City, July 1 β€” 15 GB claimed including employee PII β€” passports, driver's licenses, SSNs, W-9 forms β€” guest information, financials, contracts, and NDAs). Both πŸŸ₯ unverified. ransomware.live Β· HookPhish Β· RedPacket Security
MedusaLockerMediumJuly 1 victims: Dolrad (services / UAE; 69 emails claimed) and Penticton and District Society for Community Living (nonprofit / disability services / Canada BC). Both πŸŸ₯ unverified DLS claims. RedPacket Security Β· ransomware.live
AiLockMediumHokua Suites (luxury residential condo / US Honolulu HI, June 26). RaaS first observed March 2025; double-extortion with hybrid NTRUEncrypt+ChaCha20 encryption. πŸŸ₯ unverified. ransomware.live Β· DeXpose
Ransomware DLS β€” July 2 activity:
LockBitMediumclaimed A. Bianchini Ingeniero S.A. (industrial engineering / Spain). KRYBIT claimed AAI/aai.com.tw (electronics / Taiwan), DISS/diss.com (medical technology / US), and Azienda Ospedaliera Moscati (healthcare / Italy; claimed July 1). SafePay claimed AWO Kreisverband SΓΌdost e.V. (social welfare non-profit / Germany) and DIA179/dia179.com (architecture / Germany). INC Ransom claimed Colorado Rehabilitation & Occupational Medicine (healthcare / US). Qilin claimed Dixie Beverage West (beverage distribution / US). WorldLeaks claimed COMHAR/comhar.org (health and human services non-profit / Ireland). All πŸŸ₯ unverified DLS claims; data scope unconfirmed. ransomware.live
APT / Nation-state:
See INTELLIGENCE AGENCY ALERTS for Iranian ICS advisory AA26-097A (confirmed operational disruptions at US facilities since March 2026).
Iran post-ceasefire posture:HighDieNet continues DDoS operations against Gulf transport and financial infrastructure; Handala announced a pause on direct US attacks but has explicitly not stood down; IRGC-linked Seedworm/MOIS (Dindoor + Fakeset backdoors pre-planted in a US bank, US airport, NGOs, and a defense software company) retains active access that survives the ceasefire window.
AsyncRAT campaign via SEO-poisoned ScreenConnect installers (Kaspersky, Jul 2)HighOngoing campaign using 90+ lookalike domains across 10 languages impersonating legitimate ConnectWise ScreenConnect download pages; SEO poisoning surfaces fake pages high in search results. Victims download a trojanized installer that DLL-sideloads AsyncRAT, uses PowerShell for persistence, and achieves remote access via process hollowing β€” enabling follow-on data exfiltration or ransomware deployment. Attribution undisclosed. SC Media Β· The Hacker News
ChocoPoC RAT β€” fake PoC GitHub repos target vulnerability researchers via Python dependency hijacking (YesWeHack + Sekoia, Jul 1)HighAttackers embedded a data-stealing trojan in Python packages (frint, skytext on PyPI) listed as dependencies of convincing fake PoC exploit repos on GitHub; the PoC script itself appears clean β€” malware activates only when the lure script runs (environmental key gating). Capabilities: saved passwords, cookies, browser history from Chrome/Brave/Edge/Firefox; file exfiltration; remote shell; arbitrary Python execution. C2 uses Mapbox as a dead-drop read over DNS-over-HTTPS with domain fronting β€” traffic appears as ordinary Mapbox API calls, evading network monitoring. Seven fake repos identified, targeting CVEs for FortiWeb, React2Shell, PAN-OS, Ivanti Sentry, Check Point VPN, and Joomla. Servers still live as of July 1 disclosure. Security researchers and pentesters who run fresh PoC code are the primary target. The Hacker News Β· BleepingComputer
"Screening Serpens" β€” Iranian APT uses AppDomainManager hijacking against US, Israeli, and UAE targets (Unit 42, Jul 2)HighPalo Alto Unit 42 disclosed a new Iranian-nexus threat actor cluster ("Screening Serpens") exploiting .NET AppDomainManager injection to execute attacker-controlled code by hijacking trusted .NET application startup β€” no traditional payload drop required, bypassing application allowlisting controls. Targeted sectors: government, defense, and technology in the US, Israel, and UAE. Infrastructure overlaps with known IRGC-affiliated clusters. Attribution assessed with moderate confidence based on infrastructure and TTP analysis. Unit 42 Β· The Hacker News
JADEPUFFER β€” First documented fully autonomous AI-agent ransomware campaign (Sysdig TRT, Jul 2)HighSysdig documented the first ransomware attack run start-to-finish by an AI agent with no human operator at any stage. Entry via CVE-2025-3248 (Langflow unauthenticated Python code execution on an internet-facing instance); the agent autonomously swept for API keys (OpenAI/Anthropic/DeepSeek/Gemini) and cloud credentials (AWS/Azure/GCP/Alibaba/Tencent), raided MinIO storage using factory-default credentials (minioadmin:minioadmin), pivoted to a Nacos/MySQL server, encrypted all 1,342 Nacos service configurations, dropped source tables, and left a Bitcoin ransom note with a Proton Mail contact. No victim organization named. Attack payloads included plain-English commentary explaining each step β€” a model artifact distinguishing JADEPUFFER from human tradecraft; Sysdig classifies it as an "Agentic Threat Actor (ATA)." Signals that commodity AI tooling is lowering the bar for fully automated extortion against cloud-native DevOps stacks. Sysdig Β· The Hacker News Β· HackRead

🌍 GEOPOLITICS

Iran has confirmed sabotage capability inside US critical infrastructure, not just espionageCriticalThe six-agency AA26-097A advisory (April 7, 2026), previously uncaptured in these briefings, confirms Iranian-affiliated actors have already caused operational disruptions and financial losses at US water, energy, and government facilities. The attack surface is default-credential internet-exposed PLCs β€” a low-sophistication but high-consequence vector that mirrors the Oldsmar Water (2021) and Aliquippa Municipal Water (2023) playbooks. For any executive with OT assets, the CISA advisory is an actionable signal: audit PLC internet exposure this week, enforce credential rotation, and validate OT network segmentation before the post-ceasefire tempo accelerates.
DHS HSIN breach puts domestic law enforcement threat-sharing at riskCriticalHSIN is the operational backbone for state/local fusion centers and federal coordination on domestic threats. A breach of HSIN metadata β€” which investigations are active, which facilities are flagged, which inter-agency partners provided which tips β€” allows an adversary to map law enforcement priorities and potentially tip off monitored targets. Attribution remains unknown, but the breach joins a pattern of attacks targeting US intelligence-sharing architecture (including the 2025 DHS email compromise and the 2026 FBI field-office supply chain incident). For private-sector participants in HSIN, review what operational data you have shared through the platform in the last 90 days.
Scattered Spider extradition signals sustained Five Eyes law enforcement pressure is changing the risk calculus for Com-adjacent groupsHighPeter Stokes's extradition from Finland (Interpol + DOJ + Finnish NBI coordination) is the fifth Scattered Spider arrest to result in US charges this cycle. The group is reconstituting under new handles, but the cost of high-profile targeting is rising β€” 19-year-olds are being extradited internationally. For UK-headquartered companies (a primary Scattered Spider secondary focus), NCSC-UK tracks Com activity independently and has issued sector-specific guidance for retail and financial services.
Oracle EBS exposed instance doubling (450 to 950) is a systemic risk signal, not just a patch reminderHighThe near-doubling of externally visible Oracle EBS instances in five days of Shadowserver scanning reflects the scale of unpatched Oracle ERP deployments worldwide. With active exploitation confirmed and DriveSurge IABs monetizing access, any EBS instance on the public internet is a live intrusion risk today. The ShinyHunters/Nissan chain (PeopleSoft β†’ employee SSN/payroll exfiltration β†’ multi-country regulatory exposure) illustrates the downstream cost. Boards running Oracle-heavy ERP infrastructure should treat CVE-2026-46817 as a priority risk item alongside CVE-2026-35273.
Iran's post-ceasefire cyber posture: operational pause is theater, not stand-downMediumThe nominal ceasefire (June 17, 2026) has not produced a pause in Iranian cyber operations. DieNet DDoS activity continues against Gulf transport and finance; Handala's stated pause on US attacks explicitly excludes espionage and pre-positioning. Seedworm/MOIS access planted before the ceasefire remains active. The post-kinetic window is historically when Iranian groups shift from disruptive to intelligence-collection mode β€” translating battlefield leverage into long-term access before the next escalation cycle. Gulf-region and US critical infrastructure operators should expect elevated reconnaissance through Q3 2026.
Threat actors
1 Β· Qilin546 YTD
2 Β· The Gentlemen335 YTD
3 Β· Akira228 YTD
4 Β· DragonForce248 YTD
M&A activity
Socure β†’ Fravityβ€”
Brinqa β†’ PlexTracβ€”
Munich Re (via HSB) β†’ $575Mβ€”
Fortinet β†’ Virtue AIβ€”