Skip to content

Confidential Β· 03 Jul 2026

πŸ›‘οΈ Daily Cybersecurity Briefing β€” 2026-07-03 (Friday)

Window: last 24–48h. Severity: πŸ”΄ CRITICAL Β· 🟑 HIGH Β· 🟒 MEDIUM.

Threat level ELEVATEDVictims L30D 348Top actor QilinM&A L30D $150M

πŸ’Ό M&A ACTIVITY

LevelBlue β†’ Trustwave (July 1, undisclosed)MediumLevelBlue acquires Trustwave to form the world's largest pure-play MSSP. Combined portfolio: MDR, offensive security (SpiderLabs), incident response, strategic advisory, and security software, plus existing AT&T Cybersecurity assets (Stroz Friedberg, Elysium Digital). Serves SMB through large enterprise and US public sector. LevelBlue PR Β· MSSP Alert
Zurich Insurance β†’ BOXX Insurance (July 3, undisclosed)MediumZurich acquires Toronto-based global cyber insurtech (retail + SME cyber insurance across 5 continents; prior Zurich partnership since 2021). BOXX continues as a standalone entity under Zurich Global Ventures, accelerating Zurich's cyber coverage for retail and SME customers. BOXX PR Β· Reinsurance News
Qualcomm β†’ SAM Seamless Network (July 1, >$150M)MediumQualcomm acquires Israeli IoT/connected-device security startup protecting 500M+ devices across 15M+ ISP/telco networks; customers include AT&T, Verizon, Bezeq, Telenet, and Virgin Media. SAM's on-device edge security layer blocks threats at network ingress without routing traffic through the cloud, reducing compute dependency and extending Qualcomm's Snapdragon platform into enterprise and consumer IoT security at scale. CTech Β· Globes
L30D summary (June 3 – July 3): 14 named deals, ~$5.85B+ in disclosed value. Dominant deal: Accenture's ~$4.17B OT/ICS security roll-up (Dragos + runZero + NetRise). Runner-up: Booz Allen / Ultra I&C ($720M, defence C2). Dream raised $260M Series C at $3B valuation for sovereign cyber-defence AI. Supporting theme: AI-native identity security (SailPoint/Entro ~$200M, 1Password/Apono ~$250–300M), SSPM/data governance, MSSP consolidation (LevelBlue/Trustwave today), and IoT security consolidation (Qualcomm/SAM). Market context: Momentum Cyber's Mid-Year 2026 Review (July 1) confirms H1 2026 set a record: 219 M&A transactions, $9.1B in disclosed deal value β€” on track for the highest annual deal count ever tracked. OT/ICS, defence, AI-native identity, and SME cyber insurance are the four consolidation vectors driving H2 2026. Momentum Cyber / GlobeNewswire

⚠️ CRITICAL BREACHES & INCIDENTS

"FortiBleed" β€” INC Ransom + Lynx joint operation confirmed; 12+ ransomware deployments, 73K credential server exposedCriticalFortinet/Unit 42 forensics now confirm 12 ransomware deployments across the 86,644 compromised FortiGate firewalls; a credential server holding ~73,000 harvested credential sets was found publicly exposed. Most significant finding: a single operator was observed simultaneously logged into both an INC Ransom negotiation panel and a Lynx negotiation panel during active negotiations β€” independently confirming what code analysis had only suggested: INC Ransom and Lynx are operated by the same actor. ~110M credential pairs exfiltrated via FortiGate Sniffer across the campaign. CVE-2026-24858 (CVSS 9.8). BleepingComputer Β· SOCRadar Β· TechTimes
Texas Parks & Wildlife β€” 3.09M hunting/fishing license holders exposed (previously uncaptured; disclosed June 22)High3,087,721 records exposed including driver's licence numbers, passport numbers, email, phone, and residential addresses via third-party licensing vendor compromise. Texas Cyber Command detected the intrusion. Same actor appears linked to Virginia DWR breach (shared SaaS platform). No SSNs, DOBs, or financial data confirmed stolen. CBS Texas Β· TechTimes Β· KXAN
Medtronic β€” ~300K healthcare customers notified July 2Highbreach April 13–19 via third-party vendor credential compromise; names, contact information, product/service history exposed. ShinyHunters DLS attribution. Medical devices and patient safety systems confirmed unaffected. Class action investigation underway. HIPAA Journal Β· BleepingComputer
DHS HSIN β€” federal threat-sharing network breached (disclosed July 1)Highattackers accessed Homeland Security Information Network servers and associated SharePoint systems used by state/local law enforcement fusion centres to share sensitive threat intelligence. Attack estimated late May–early June. Potential exposure: open investigations, facility threat mappings, inter-agency partner identities. DHS isolated affected systems; no classified networks hit; actor unattributed. BleepingComputer Β· Nextgov/FCW
Aflac Japan β€” 4.38 million customers exposed (disclosed June 30)Highunauthorized access June 15–25 exposed names, addresses, phone numbers, dates of birth, gender, policy details, and bank account details for ~4.38M policyholders and agents; ~230,000 records include bank account data. Reported to Japan's Financial Services Agency; no credit card or health diagnostic data confirmed stolen. No attribution. SecurityWeek Β· BleepingComputer
Klue/Icarus supply-chain attack β€” BeyondTrust and LastPass named; 195 customers affected; "hackers-get-hacked" (July 2–3)HighThe Icarus group's June 11–12 breach of Klue (CRM/competitive-intelligence SaaS) via legacy credentials harvested OAuth tokens granting access to customer Salesforce instances; BeyondTrust and LastPass disclosed impact on July 2, bringing the confirmed list to 15+ named organizations including HackerOne, Huntress, Jamf, OneTrust, Recorded Future, Snyk, Tanium, AlertMedia, and Blackbaud. Total affected: 195 Klue customers across industries. Critical twist: a second unnamed threat actor claims to have breached an Icarus member's server and stolen the already-stolen data β€” and is running an independent extortion campaign against the same victim set. Klue told customers Icarus is deleting data; the second group is uncontrolled. BeyondTrust and LastPass having their customer/partner data in a third-party CRM breach has direct phishing and social-engineering downstream risk. SecurityWeek Β· BleepingComputer

πŸ”“ CRITICAL VULNERABILITIES

CVE-2026-50751 β€” Check Point VPN authentication bypass CVSS 9.3 (Qilin-linked; KEV June 9; previously uncaptured across all prior runs)Highlogic flow weakness in deprecated IKEv1 key exchange allows unauthenticated remote attacker to bypass password authentication and establish a VPN session. Affects Check Point Remote Access VPN, Mobile Access, and Spark Firewall products with IKEv1 enabled. Qilin affiliates exploiting since May 7, 2026; activity surged in early June; confirmed impact across "a few dozen" organisations globally. CISA added to KEV June 9; federal deadline June 11 (already overdue by three weeks). Check Point issued a hotfix; patch or disable IKEv1 immediately. Help Net Security Β· BleepingComputer Β· Rapid7 Β· SecurityWeek
CVE-2026-45659 β€” Microsoft SharePoint Server RCE CVSS 8.8; federal deadline TOMORROW (Saturday July 4)Highdeserialization flaw; any authenticated Site Member can execute code remotely on SharePoint Subscription Edition/2019/2016. KEV added July 1; federal deadline July 4 per BOD 26-04. Today (Friday July 3) is the last working day for remediation. Patch available since May 2026. DHS HSIN breach involved SharePoint β€” a direct illustration of what an authenticated-RCE path enables. THN Β· CISA KEV Β· SOCRadar
CVE-2026-24858 β€” FortiCloud SSO SAML authentication bypass CVSS 9.8 ("FortiBleed" vector)Criticalunauthenticated SAML bypass enabling mass credential harvest from FortiGate appliances. 86,644 devices confirmed compromised; ~110M credential pairs exfiltrated. Fortinet patches available; firmware upgrade is critical for all FortiGate/FortiCloud environments. Fortinet PSIRT Β· BleepingComputer
Adobe ColdFusion + Campaign Classic β€” 7 critical flaws (July 1–2 disclosure)HighCVE-2026-48276/48277/48281/48316/48282/48283 (ColdFusion RCE chains, multiple CVSS 10.0) and CVE-2026-48286 (Campaign Classic unauthenticated RCE). Adobe Priority 1; no exploitation confirmed. Patch immediately β€” ColdFusion historically exploited within days of disclosures. THN Β· Adobe PSIRT
CVE-2026-43503 DirtyClone β€” Linux kernel LPE CVSS 8.8Highsilent root escalation via packet cloning; no trace in kernel logs; affects Debian, Fedora, Ubuntu; JFrog PoC published June 25. High risk in multi-tenant cloud and Kubernetes environments. JFrog Research Β· THN
CVE-2026-48558 β€” SimpleHelp RMM authentication bypass CVSS 10.0; CISA KEV deadline July 2Criticalunauthenticated OIDC token forgery in SimpleHelp 5.5.15 and earlier lets an attacker create a fully privileged technician account without credentials; Arctic Wolf confirmed active exploitation delivering Djinn Stealer to harvest credentials across all endpoints managed by the compromised server. ~14,000 SimpleHelp servers externally exposed; ~1,000 directly vulnerable. MSP attack vector makes blast radius extremely high: one compromised RMM server equals every downstream customer environment. Patch to 5.5.16 immediately. Arctic Wolf Β· Security Affairs
CVE-2026-46817 β€” Oracle E-Business Suite Payments CVSS 9.8; pre-PoC exploitation confirmed (July 2)Criticalunauthenticated RCE via Oracle Payments File Transmissions; affects EBS 12.2.3–12.2.15; patched in Oracle May 2026 CPU but exploitation confirmed from June 27 β€” before public exploit code was released. Over 950 EBS instances exposed publicly. Full takeover grants access to financial, supply chain, and HR transactional data. Separate from the ongoing Cl0p Oracle EBS campaign (CVE-2025-61882). The Register Β· Security Affairs Β· BleepingComputer
CVE-2026-8451 β€” Citrix NetScaler pre-auth memory overread CVSS 8.8; exploitation within 24h (July 1–2)Highpre-auth memory overread in NetScaler ADC/Gateway SAML IdP XML parser; causes appliance to return session IDs and sensitive data in the NSC_TASS cookie. Exploitation began within 24 hours of the July 1 patch. Separate CVEs in the same bulletin add HTTP/2 DoS, arbitrary file read, and memory overflow conditions. Fix: 14.1-72.61 / 13.1-63.18. watchTowr published detection artifacts. watchTowr Β· SecurityWeek Β· CyberScoop
CVE-2026-33825 (BlueHammer) β€” Microsoft Defender LPE; CISA confirms ransomware exploitation (July 1)HighCVSS-high privilege escalation in Microsoft Defender; disclosed April 2, patched April 14, KEV added April 22. CISA updated the KEV entry July 1 to flag active ransomware exploitation: attackers chain it to gain SYSTEM, disable AV/EDR, and install ransomware. Group not publicly attributed. BleepingComputer Β· Security Affairs
CVE-2026-8037 β€” Progress Kemp LoadMaster OS command injection CVSS 9.6–9.8; PoC + exploitation same dayHighpre-authentication OS command injection; watchTowr Labs published PoC June 29; eSentire TRU observed exploitation attempts within hours. Fix available: GA 7.2.63.2 / LTSF 7.2.54.18. LoadMaster is widely deployed as an ADC/load balancer in enterprise and healthcare environments. Not yet in KEV. watchTowr Β· eSentire TRU
CVE-2026-50548 + CVE-2026-50549 "DuneSlide" β€” Cursor AI IDE zero-click prompt injection to OS-level RCE (CVSS 9.8; Cato AI Labs, July 1)Hightwo critical sandbox-escape flaws in Cursor IDE < 3.0 enable zero-click prompt injection from attacker-controlled content (poisoned MCP server responses or web search results) to escalate to full OS-level code execution. CVE-2026-50548: an injected prompt steers the LLM to assign a non-default working_directory in run_terminal_cmd; Cursor blindly adds that path to its sandbox write-allow list, letting the attacker overwrite the cursorsandbox binary and strip sandbox restrictions from all future commands. CVE-2026-50549: a symlink canonicalization fallback β€” when Cursor fails to resolve a symlink's real destination, it trusts the in-project shortcut and writes straight through it to an outside location. Both paths reach full OS-level RCE as the logged-in developer, plus any connected cloud/SaaS workspaces. Cato AI Labs reported to Cursor in February 2026; patched in Cursor 3.0 (released April 2, 2026) β€” update immediately if any team member is running < 3.0. No exploitation in the wild confirmed. Cato AI Labs Β· THN Β· SecurityWeek
Argo CD repo-server unauthenticated RCE β€” no CVE, no patch, 18 months unaddressed (disclosure July 1, 2026)HighArgo CD's internal repo-server gRPC port carries no authentication; any attacker able to reach it (e.g., from a compromised pod in the same cluster) can execute arbitrary commands. Default Helm chart deployments ship without network policies, leaving the port reachable from any pod in the namespace. Attack chain: compromise one cluster pod β†’ reach repo-server via unprotected gRPC β†’ extract Redis password from environment variable β†’ poison Argo CD's Redis-cached deployment data β†’ malicious workload deploys on the next automatic GitOps sync. Vulnerability was reported to Argo CD maintainers in January 2025; still unpatched 18 months later, no CVE assigned. Mitigation: immediately enable Argo CD's built-in Kubernetes network policies (provided but opt-in) to isolate the repo-server and Redis ports to Argo CD components only. Critical risk in any multi-tenant or production Kubernetes environment using Argo CD without network-policy enforcement. THN Β· CSO Online Β· InfoWorld
CVE-2026-45447 β€” OpenSSL heap use-after-free; high severity; AI-discovered (patched June 9, previously uncaptured)Highheap use-after-free in PKCS7_verify() triggered when a PKCS#7 or S/MIME SignedData message presents digestAlgorithms as an empty ASN.1 SET; OpenSSL incorrectly frees a caller-owned BIO, causing heap corruption on next use β€” potential RCE in any application processing S/MIME or CMS signed messages. Discovered by Thai Duong (veteran cryptographer; co-discovered BEAST attack against TLS 1.0; previously at Google) in collaboration with Anthropic Research using Claude AI. Part of an 18-vulnerability batch patched June 9; CVE-2026-45447 is the highest-severity flaw. Affects all supported branches (1.0.2 through 4.0); patched in 4.0.1, 3.6.3, 3.5.7, 3.4.6, 3.0.21, and premium-support 1.1.1zh / 1.0.2zq. No exploitation confirmed. SecurityWeek Β· NVD
Chrome 151 β€” 382 vulnerabilities patched including 15 critical (released June 30, previously uncaptured)HighGoogle's stable-channel release patches 382 security vulnerabilities in a single update: 15 critical, 67 high, 169 medium, 131 low; 358 of 382 found internally by Google. All 15 critical flaws are use-after-free bugs concentrated in GPU, Extensions, Bluetooth, WebUSB, Chromoting, and core browser infrastructure β€” the exact components where memory corruption most directly enables arbitrary code execution. No in-the-wild exploitation confirmed; update Chrome immediately. Malwarebytes Β· SecurityWeek

🚨 INTELLIGENCE AGENCY ALERTS & POLICY

SharePoint BOD 26-04 β€” act today, Friday July 3HighCISA's BOD 26-04 compressed remediation window (3 days from KEV add July 1) for CVE-2026-45659 expires Saturday July 4. Friday is the effective last business day for federal agencies. Non-federal organisations running SharePoint on-prem should treat this as equivalent scope β€” the DHS HSIN breach demonstrates what authenticated collaboration-platform access yields. CISA BOD 26-04
Fake Interpol ransomware campaign β€” custom payload in Proton Drive archives (Bitdefender, July 2026)Highphishing emails impersonating Interpol investigators allege the recipient's organisation is under criminal investigation and direct victims to a Proton Drive link containing "evidence." The linked archive delivers custom ransomware embedded in a video file. Target sectors: legal, pharma, food/agriculture, media, technology, finance; geographic focus: Europe, Asia, Middle East, US; SMBs. Notable: decryption key is embedded inside the malware itself, meaning file recovery without payment is technically possible. C2 via Tox chat. Threat actor unattributed. Bitdefender Β· Dark Reading Β· Infosecurity Magazine Β· SC Media
AA26-097A β€” Iranian APT targeting internet-exposed PLCsHighCISA/FBI joint advisory remains current; campaign against US water, wastewater, and energy sector PLCs ongoing since March 2026. OT operators should audit internet-facing ICS assets immediately. CISA
US $10M Rewards for Justice bounty: Russian UNC5792 + UNC4221 (June 30)HighState Department offered $10M for information on two Russian FSB/military-linked units conducting device-code phishing against Signal and WhatsApp accounts of US and NATO government, military, intelligence officials, journalists, and NGOs covering Russia. FBI/CISA updated a joint advisory with new TTPs including theft of Signal Backup Recovery Keys. The Record Β· BleepingComputer
UK National Cyber Action Plan delayed (July 2)HighPublication due July 1 was postponed amid uncertainty over the Labour leadership contest opening July 9. The plan has already slipped once (promised end-2025, rebranded from "strategy" to "action plan"). FTSE 350 Cyber Resilience Pledge signed July 2 as planned; Β£90M SME commitment proceeds. No new delivery date given. The Record Β· Gov.UK
UK weakens Salt Typhoon telecoms response code after industry lobbying (effective mid-July)CriticalProposed UK telecoms security code developed in direct response to the Salt Typhoon campaign has been weakened: (1) dropped requirement to treat all incoming signalling as untrusted; (2) dropped mandatory monthly equipment restarts that would wipe memory-only malware; (3) deferred securing broad-access service accounts from end-2028 to end-2029. Lobbying coordinated by TechUK. Parliament has a 40-day scrutiny window. Directly undermines the defensive posture against an active, confirmed Chinese intrusion vector. The Record
Google + FBI disrupt NetNut residential proxy network β€” 2M compromised home devices (July 2)HighGoogle and FBI jointly disrupted NetNut (operated by NASDAQ-listed Israeli firm Alarum Technologies), a residential proxy network built from 2M+ compromised smart TVs and streaming devices. In a single June week, 316 distinct threat clusters β€” criminal and nation-state actors β€” used NetNut for anonymous attack routing. Google disabled NetNut accounts and C2 channels across Google services; FBI seized several NetNut domains. NetNut's reseller model means multiple "separate" proxy brands draw from the same compromised pool β€” infrastructure defenders should treat any provider in the Alarum ecosystem as potentially tainted. Google Cloud Blog Β· THN Β· SecurityWeek
Scattered Spider: Peter Stokes ("Bouquet") extradited from Finland β€” fifth US federal arrest (DOJ, July 1)HighDOJ announced the extradition of 19-year-old dual US/Estonian citizen Peter Stokes, arrested by Finnish NBI in April 2026 on an Interpol Red Notice and arraigned in Chicago federal court June 30. Charged with conspiracy to commit computer intrusion and wire fraud; linked to 100+ enterprise network breaches and $100M+ in collective ransom payments. Most specific charge: a May 2025 breach of a luxury jewellery retailer β€” $8M demand, $2M in victim losses without a ransom paid. Fifth Scattered Spider suspect charged in the US federal case. Interpol + DOJ + Finnish NBI coordination confirms the Five Eyes extradition channel is established, operational, and extending to under-20 suspects. DOJ Β· THN Β· Help Net Security

🌐 THREAT ACTOR & CAMPAIGN ACTIVITY

Ransomware DLS (July 1–3 window):
QilinHigh2 new DLS claims in this window: Pennant Hills Golf Club (hospitality/Australia, July 2, πŸŸ₯ unverified), Musashino University (education/Japan, seen June 29, previously uncaptured, πŸŸ₯ unverified). Qilin volume remains highest globally; no Q3 let-up visible. ransomware.live Β· RedPacket Security Β· hendryadrian.com
INC RansomHighRoundshield Partners LLP (UK private equity, July 1, 400 GB claimed, πŸŸ₯ unverified); Colorado Rehabilitation & Occupational Medicine (healthcare/US, July 2, πŸŸ₯ unverified); Oak Park, Michigan (local government/US, July 3, attack est. July 2, πŸŸ₯ unverified). ransomware.live Β· DeXpose
The GentlemenCriticalIndra Group (Spain; €5B revenue, 62,000 employees, 140 countries; one of Europe's largest defense/aerospace/IT conglomerates and the first Spanish company in NATO's cyberdefence coalition) posted to The Gentlemen DLS June 30, 2026; data publication deadline July 9; Indra confirmed the attack was limited to a non-critical subsidiary environment, CSIRT activated, operations unaffected; data type and scale unknown β€” treat as a live data-hostage situation until July 9. Also: CUI Agency (insurance/US Utah, July 3, πŸŸ₯ unverified) and MakoLab S.A. (IT consulting/Poland, July 3, πŸŸ₯ unverified); all three πŸŸ₯ unverified. Posting cadence remains 2–4 new victims per day. Kaspersky/Securelist June 30 deep-dive revealed ArmCorp as the group's predecessor Qilin affiliate identity (split July 22, 2025) and identified SharpADWS as a key reconnaissance tool β€” LDAP queries wrapped in SOAP messages evade standard AD event logging. Cybernews Β· Cybersecurity Insiders Β· DeXpose Β· Securelist
WorldLeaksMediumStarpool (Italian wellness/spa manufacturer, DLS July 1, πŸŸ₯ unverified); COMHAR (Irish mental health non-profit, DLS July 2, πŸŸ₯ unverified); Treet Group of Companies (Pakistani conglomerate spanning razor blades/textiles/power generation, DLS July 2, πŸŸ₯ unverified); Service IT (IT services/Brazil, DLS July 2, πŸŸ₯ unverified). ransomware.live Β· hendryadrian.com Β· hendryadrian.com
PayloadMediumTofutown (organic plant-based food manufacturing/Germany, est. 1981; Payload DLS July 2, 07:26 UTC, πŸŸ₯ unverified). ransomware.live Β· hendryadrian.com
MoneyMessageMediumX-Copper Professional Corporation (traffic-ticket defence law firm/Canada Ontario, DLS July 2, πŸŸ₯ unverified). hendryadrian.com
RansomHouseHighPrince George County, Virginia (government/US; DLS July 3, attack est. June 10; county confirmed cybersecurity incident June 11; phone/internet/online payments disrupted; PII possibly exposed β€” names, addresses, DOBs, driver's licence numbers, SSNs; FBI Cyber Crimes and CISA notified; credit monitoring offered; RansomHouse claims encryption and posted evidence pack; county has not confirmed ransomware attribution; πŸŸ₯ unverified). WRIC ABC 8News Β· GovTech Β· ransomware.live
KRYBITMedium3 new DLS claims July 1: AeroVision Avionics (aerospace electronics/Taiwan, πŸŸ₯ unverified), B'Laofood Joint Stock Company (food manufacturing/Vietnam, πŸŸ₯ unverified), DISS Corporation / DISS Analytics (analytics/US, πŸŸ₯ unverified). DeXpose Β· ransomware.live
AnubisMediumFerrum AG (manufacturing/Switzerland, July 3, πŸŸ₯ unverified); Quest Healthcare Solutions (healthcare/US, DLS July 2, employee data + internal files claimed, πŸŸ₯ unverified); Anubis now totals 92 claimed victims since December 2024, with 11 in June alone. ransomware.live Β· RansomLook Β· hendryadrian.com
ShinyHuntersMediumIngram Content Group (major US book distribution and publishing-services company, July 2, failed negotiations alleged, Salesforce data claimed, πŸŸ₯ unverified). BreachNews Β· hendryadrian.com
Campaigns:
Anubis ransomware mass-exploiting CitrixBleed 2 (CVE-2025-5777) β€” 91 victims, RMM tool abuse (Arctic Wolf, July 2)HighAnubis (formerly Sphinx until late 2024; 91 claimed victims as of July 3) is actively exploiting CVE-2025-5777 (CVSS 9.3, NetScaler ADC/Gateway pre-auth memory overread; MFA bypass via session-token exposure) for initial access, then deploying a fleet of RMM tools for persistence: ScreenConnect, Zoho Assist, MeshAgent, Remotely, UltraVNC, Total Software Deployment β€” multiple tools per victim to ensure redundant access. Double-threat model: encrypts and threatens wipe. Healthcare and financial services primary targets. Arctic Wolf Β· Techzine
VECT/TeamPCP supply chain attack β€” Trivy + LiteLLM CI/CD compromise, 1,000+ enterprise SaaS affected (THN, July 2)HighTeamPCP (UNC6780, also behind the GitHub breach) compromised the Trivy container-security scanner CI/CD pipeline March 19, 2026 and the LiteLLM AI gateway March 24, 2026; malicious code injected into both open-source tools harvested API keys, cloud credentials, and OAuth tokens from any enterprise CI/CD pipeline consuming the poisoned build artefacts. Estimated 1,000+ enterprise SaaS environments affected. The monetisation arm (Vect ransomware, from April 15, 2026) is actually a wiper: files >128KB are destroyed, not encrypted β€” there is no decryption key. THN Β· Sysdig
Screening Serpens (Iranian APT, Unit 42 July 2)HighAppDomainManager injection (.NET config hijacking) targeting US, Israeli, and UAE government and defence contractors. Sophisticated DLL hijacking; no CVE dependency. Unit 42 Β· THN
JADEPUFFER β€” first autonomous AI-agent ransomware (Sysdig TRT, July 2)HighCVE-2025-3248 (Langflow) initial access; autonomous credential sweeping across OpenAI/Anthropic/DeepSeek/Gemini API accounts and AWS/Azure/GCP/Alibaba/Tencent cloud platforms; MinIO factory-default credential exploitation; 1,342 configs encrypted. Sysdig classifies as "Agentic Threat Actor (ATA)." Sysdig TRT Β· THN Β· HackRead
ChocoPoC RAT β€” fake PoC repos on GitHub (YesWeHack/Sekoia July 1)Medium7 fake PoC repositories targeting researchers and pentesters; Python dependency hijacking injects data-stealing trojan via `frint`/`skytext` packages on PyPI; C2 via Mapbox dead-drop over DNS-over-HTTPS with domain fronting; harvests passwords/cookies/browser history and drops a remote shell. CVEs targeted: FortiWeb, React2Shell, PAN-OS, Ivanti Sentry, Check Point VPN, Joomla. YesWeHack Β· Sekoia

🌍 GEOPOLITICS

Check Point CVE-2026-50751 confirms Qilin's shift to patient, infrastructure-level exploitation.HighThe flaw was actively exploited for over a month before CISA added it to the KEV catalog, and federal remediation deadline (June 11) passed without a public incident wave β€” suggesting Qilin affiliates are using the access for dwell-and-deploy, not mass-spray. Any organisation that ran Check Point VPN with IKEv1 enabled between May 7 and the patch date should treat that period as a presumed-access window, not a near-miss.
"FortiBleed" operator confirmation that INC Ransom = Lynx is the most significant rebrand discovery of the year.HighDefenders attributing incidents only to one of the two brands have been tracking half the actor's footprint. The 73,000-device credential server sitting publicly exposed also means the collected access inventory β€” spanning Chevron, Samsung, AT&T, Comcast, and others β€” is now potentially available beyond INC/Lynx themselves. The downstream intrusion risk from credential reuse across this population is a multi-quarter exposure.
The fake Interpol campaign signals a tactical evolution in ransomware social engineering targeting SMBs.HighLaw-enforcement impersonation triggers a qualitatively different fear response than a standard ransom note β€” targets believe they face criminal liability, which raises compliance-driven payment pressure above technical sophistication. The embedded decryption key suggests the operator's priority is disruption-as-leverage, not technical control; organisations should brief legal and compliance staff now that Interpol-branded threats are in active circulation.
SharePoint's holiday-weekend deadline is a deliberate targeting window.HighNation-state and ransomware actors routinely time exploitation to holiday periods when SOC staffing is thin. CVE-2026-45659 (any authenticated Site Member β†’ RCE) on a SharePoint server is a lateral-movement accelerant in any environment with unfederated identity. The DHS HSIN SharePoint compromise β€” one of the most sensitive government collaboration platforms in US law enforcement β€” demonstrates the downstream intelligence yield of a single authentication breach.
JADEPUFFER foreshadows the commoditisation of AI-orchestrated intrusion at scale.MediumThe attack chain from Langflow initial access through autonomous API credential sweeping to MinIO encryption required no human operator involvement after deployment. The tradecraft is replicable by actors with limited technical expertise once the agent framework circulates in criminal forums. Strategic planning that assumes human-in-the-loop attack tempo will be structurally wrong within 12–18 months as agentic frameworks mature.
The UK's decision to weaken its Salt Typhoon telecoms response code is a strategic own goal.CriticalRolling back untrusted-signalling requirements and monthly memory-flush restarts β€” the precise controls that would catch persistent, memory-resident intrusion β€” at the direct request of telecom industry bodies reveals the structural tension between national security and commercial continuity. The NCSC separately disclosed that 75% of the 200+ CNI incidents it handled in the year to May 2026 were state-linked. A government that accepts this threat landscape while removing the countermeasures that target it is exposed to the gap politically and operationally.
Pegasus confirmed on PEGA Committee MEP investigating Pegasus (Citizen Lab, July 2–3).HighGreek MEP Stelios Kouloglou β€” a member of the European Parliament committee tasked with investigating Pegasus spyware abuses β€” was himself infected with Pegasus in October 2022 and March 2023. Citizen Lab (Report 194) identified two infection windows. The MEP plans to sue NSO Group. The operational implication: the committee's deliberations, source identities, and draft findings were likely accessible to whichever state operator deployed the spyware β€” a direct counter-intelligence penetration of the oversight body. Citizen Lab Report 194
The Gentlemen/Indra Group claim establishes a pattern of deliberate defense-industrial targeting by criminal ransomware.HighIndra is not a peripheral target: it is a NATO coalition member, Europe's dominant air traffic management integrator, and a supplier of C2, ISR, radar, and cyber systems to allied militaries. The June 28 TKMS/Atlas Elektronik DLS (German submarine sonar/torpedo guidance) and now June 30 Indra (Spanish-NATO defense/aerospace) in the same two-week window from the same actor is operationally significant. Whether The Gentlemen are state-enabled or simply opportunistic, the result is the same: NATO defense contractors' internal data is being staged for publication and sale. Defense primes and their supply chains should audit which subsidiaries may have had access to sensitive program data β€” Indra's own CSIRT assessed the breach as "non-critical," but victims consistently assess downward to minimize regulator and partner concern. Cybernews Β· Cybersecurity Insiders
Threat actors
1 Β· Qilin546 YTD
2 Β· The Gentlemen335 YTD
3 Β· Akira228 YTD
4 Β· DragonForce248 YTD
M&A activity
Socure β†’ Fravityβ€”
Brinqa β†’ PlexTracβ€”
Munich Re (via HSB) β†’ $575Mβ€”
Fortinet β†’ Virtue AIβ€”