Skip to content

Confidential ยท 13 Jul 2026

๐Ÿ›ก๏ธ Daily Cybersecurity Briefing โ€” 2026-07-13 (Monday)

Window: last 24โ€“48h (July 12โ€“13). Severity: ๐Ÿ”ด CRITICAL ยท ๐ŸŸก HIGH ยท ๐ŸŸข MEDIUM.

Threat level ELEVATEDVictims L30D 336Top actor QilinM&A L30D $50M

๐Ÿ’ผ M&A ACTIVITY

No new deals announced July 12โ€“13.MediumWeekend quiet; expect trade press to surface deals from last week's pipeline on Monday morning.
L30D summary (June 13 โ€“ July 13): ~17 named deals, disclosed value in excess of $6B. Headline transactions: Qualcomm โ†’ SAM Seamless Network (>$150M, IoT edge security), LevelBlue โ†’ Trustwave (undisclosed, world's largest pure-play MSSP), Barracuda Networks โ†’ Evo Security (Jul 7, PAM/IAM for MSPs), Akamai โ†’ LayerX (browser security, closed Jul 2). The consolidation theme is AI-native security and managed detection: every top-10 acquirer this cycle is buying expertise in automated detection, identity, or edge security. Momentum Cyber's H1 2026 Mid-Year Review (Jul 1) confirmed a record 219 M&A transactions and $9.1B disclosed deal value for the first half โ€” the strongest H1 in sector history.

โš ๏ธ CRITICAL BREACHES & INCIDENTS

Argentine Football Association (AFA) โ€” email account hijacked July 10, World Cup contextMediumHacktivist group operating under alias "Hossam Hassan" (Egyptian-linked connotations) seized an AFA institutional email account two days after Argentina's 3โ€“2 comeback victory over Egypt in the FIFA World Cup 2026 round of 16 (July 8). The attackers blasted messages to AFA contact lists with the subject line "SYSTEM HACKED: UNFAIR DECISION," accused match officials of corruption, and claim to have exfiltrated AFA's organisational database โ€” emails, hashed passwords, national IDs, phone numbers, IP addresses, and profile pictures. AFA confirmed the breach and launched an emergency internal investigation. Attribution is to a politically motivated hacktivist operation, not a financially motivated threat actor. Cybernews ยท CryptoBriefing ยท Daily Sabah

๐Ÿ”“ CRITICAL VULNERABILITIES

Ubiquiti UniFi OS โ€” 11 critical flaws patched July 8, CVEs 2026-47369/47370/54402 CVSS 9.9, active attacker interestCriticalUbiquiti shipped security updates July 8 addressing 11 critical vulnerabilities in UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS โ€” the common kernel across all UniFi hardware. The top three (CVE-2026-47369, CVE-2026-47370, CVE-2026-54402) are command injection flaws carrying CVSS 9.9; a low-privileged attacker with network access can execute arbitrary OS commands. Additional flaws in this batch include path traversal โ†’ auth bypass (CVE-2026-54403, CVSS 8.6) and SQL injection (CVE-2026-54404, CVSS 8.8). Separately, three earlier UniFi vulnerabilities (CVE-2026-34908, CVE-2026-34909, CVE-2026-34910) are already in CISA KEV and are now more than 12 days past their federal remediation deadline โ€” SecurityWeek reported confirmed attacker exploitation. Ubiquiti devices are pervasive in SMB, campus, and ISP environments; apply UniFi OS updates immediately and audit for evidence of prior compromise on overdue KEV CVEs. SecurityWeek ยท BleepingComputer ยท CISA KEV

๐Ÿšจ INTELLIGENCE AGENCY ALERTS & POLICY

No new CISA/FBI/NSA/NCSC advisories July 12โ€“13.MediumThe July 10 KEV batch (CVE-2026-48939 iCagenda + CVE-2026-56291 Balbooa Forms Joomla RCEs) and the Ubiquiti KEV deadline (overdue) remain the active compliance priorities. The overdue Ubiquiti KEV trio (CVE-2026-34908/909/910) is confirmed exploited โ€” federal teams should treat network segments running unpatched UniFi hardware as potentially compromised and audit logs.

๐ŸŒ THREAT ACTOR & CAMPAIGN ACTIVITY

Ransomware DLS movement (July 11โ€“13):
QilinHigh3 new DLS victims confirmed July 11โ€“12: Retelit SpA (IT services / telecommunications / Italy ๐ŸŸฅ unverified), Carolina Agri-Power (agricultural equipment / US ๐ŸŸฅ unverified), Century Equities (real estate / US ๐ŸŸฅ unverified). Total cumulative DLS claims: 1,510+. Qilin continues averaging 4โ€“5 new victims per day. All three ๐ŸŸฅ โ€” verify against secondary sources before treating as confirmed breaches. ransomware.live ยท PurpleOps
DragonForceHigh1 new DLS victim confirmed July 11: Access Group International (business services / US ๐ŸŸฅ unverified). DragonForce also disclosed this week by Symantec/Broadcom: a custom Go-based backdoor, Backdoor.Turn, that tunnels QUIC C2 traffic through legitimate Microsoft Teams TURN relay infrastructure โ€” the first known malware to exploit Teams TURN relays as a C2 proxy. The attack against a major US services firm gave DragonForce 1โ€“2 months of invisible dwell time; network defenders saw only outbound connections to Microsoft's own servers. Symantec also documented a novel BYOVD technique exploiting Huawei's HWAudioOs2Ec.sys driver, previously not known to be exploitable this way. SecurityWeek ยท The Hacker News ยท Symantec/Broadcom
New extortion actor / emerging campaigns:
Helix โ€” new data-extortion group, SharePoint-focused vishing + device-code phishingCriticalReliaQuest published July 9 a report on a previously undocumented group called Helix operating a multi-target data extortion campaign. Helix's kill chain: (1) voice-phishing call impersonating the target's manager โ€” caller ID spoofed โ€” convincing the target to initiate a Microsoft device-code authentication flow; (2) Helix captures the session token and immediately registers a new MFA authenticator for persistence; (3) scripted enumeration and bulk exfiltration of SharePoint content. ReliaQuest found one Helix exfiltration IP in the same autonomous system (AS 51852) as a confirmed BlackFile ("UNC6671") address โ€” suggesting shared infrastructure with the group that fragmented in April 2026 into Pink, Redact, and other successors. Separately, a potential link to the ShinyHunters ecosystem is assessed but not proven. Primary mitigation: disable device-code authentication in Entra ID Conditional Access policies. BleepingComputer ยท ReliaQuest ยท SC Media
Advanced / nation-state:
Silver Fox / MODBEACON โ€” China-linked Rust-based RAT, gRPC C2, targets APAC tech and educationHighQiAnXin and other researchers reported July 10 that the China-linked Silver Fox cybercrime group has deployed a new Rust-based remote-access trojan called MODBEACON in campaigns targeting technology, education, and state-owned enterprises. One campaign observed in mid-June 2026 used a distributor delivering MODBEACON via fake software installers; the RAT uses gRPC streaming over Amazon and Cloudflare CDN for encrypted C2 traffic, blending into corporate network baselines. Silver Fox's broader infrastructure relies on multiple independent distributors โ€” SEO poisoning, counterfeit installers, and Gh0st/WinOS (ValleyRAT) variants โ€” operated as a "cybercriminal arms dealer and traffic broker" model. SC Media ยท The Hacker News ยท QiAnXin

๐ŸŒ GEOPOLITICS

Analyst lens: how this week's cyber activity maps to state strategy. Defense ยท cyber ยท economics.
DragonForce's exploitation of Microsoft Teams TURN relay infrastructure as a C2 proxy โ€” routing attacker commands through servers indistinguishable from legitimate Teams call traffic โ€” represents the first publicly confirmed instance of legitimate collaboration infrastructure being weaponised at the network layer, not just the application layer, and eliminates the last reliable network-based detection signal.CriticalPrevious detection of C2 relied on identifying abnormal outbound destinations; Backdoor.Turn makes every connection to Microsoft's own infrastructure look identical to a Teams call. For defenders, this is the 2026 equivalent of the 2021 Log4Shell moment for enterprise collaboration tools: the perimeter assumption that "traffic to Microsoft = legitimate" is broken. Security operations teams should implement application-layer inspection of Teams traffic patterns, enforce strict Teams tenant isolation, and treat QUIC-over-TURN anomalies as a new detection hypothesis. SecurityWeek ยท Broadcom/Symantec
Helix's emergence from the BlackFile/ShinyHunters successor ecosystem is the third group this year to reconstitute from a disrupted or dissolved predecessor, confirming that the "fragmented successor" model is the dominant post-disruption pattern and that law-enforcement-imposed group shutdowns are now a recruitment and capability-distribution event, not an end-state.CriticalBlackFile dissolved April 2026 and has now produced at minimum three successor operations (Pink, Redact, and Helix); the shared infrastructure fingerprint linking Helix to BlackFile's AS suggests operational continuity, not just ideological inheritance. Intelligence-led defenders need actor-genealogy models, not point-in-time group blocklists, as the primary TTI anchor โ€” the name changes faster than the infrastructure and techniques. BleepingComputer ยท ReliaQuest
The Argentine Football Association breach during the FIFA World Cup 2026 confirms that major international sporting events create a systematic elevation of hacktivist and nuisance-actor tempo, and that sports federations and associated infrastructure carry concentrated brand and data risk for the duration.HighThe AFA attack (politically motivated, tied to a specific match result) sits alongside the prior HSIN inter-agency network compromise (state-linked, attributed to World Cup security coordination access), together illustrating that the World Cup threat surface spans from the hacktivist fringe to probable state-linked intelligence operations. With the tournament final at MetLife on July 19 six days away, the risk window is still live: stadium operations, law enforcement fusion centers, and the commercial ecosystem around ticket/hospitality data remain priority targets. Cybernews ยท BleepingComputer
Silver Fox's deployment of MODBEACON โ€” a Rust-based RAT using gRPC over CDN infrastructure for C2 โ€” continues the documented pattern of China-linked actors migrating from C/C++ or legacy frameworks to memory-safe languages that produce cleaner binaries, resist static analysis, and blend into cloud-native network profiles.HighThis is the third China-linked group in 2026 to field a Rust-based implant (after Volt Typhoon's 2025 WebShell upgrade and Salt Typhoon's TernDoor). The operational pattern โ€” multiple independent distributors acting as arms dealers, selling access to downstream APT operators โ€” mirrors the North Korean IT worker model applied to CNE, and represents a platform-as-a-service layer for Chinese intelligence collection that is structurally harder to disrupt than a single campaign. SC Media ยท QiAnXin
Ubiquiti's 11-flaw July 8 patch, arriving alongside three KEV-listed vulnerabilities still overdue in federal and critical infrastructure networks, illustrates the structural gap between patch availability and operational patching cycles for network infrastructure devices โ€” the exact gap that Salt Typhoon's 2025โ€“2026 campaigns exploited to access US telecoms.MediumUniFi hardware is pervasive in SMB and campus networks outside the large enterprise SOC envelope, which means that many affected devices are managed by MSPs or IT generalists without active vulnerability programs. The combination of CVSS 9.9 command injection, confirmed exploitation of the KEV trio, and an overdue federal deadline makes this a compounding risk for any organisation with unmanaged UniFi hardware on the perimeter. CISA KEV ยท SecurityWeek
Threat actors
1 ยท Qilin546 YTD
2 ยท The Gentlemen335 YTD
3 ยท Akira228 YTD
4 ยท DragonForce248 YTD
M&A activity
Socure โ†’ Fravityโ€”
Brinqa โ†’ PlexTracโ€”
Munich Re (via HSB) โ†’ $575Mโ€”
Fortinet โ†’ Virtue AIโ€”