Skip to content

Confidential ยท 15 Jul 2026

๐Ÿ›ก๏ธ Daily Cybersecurity Briefing โ€” 2026-07-15 (Wednesday)

Window: last 24โ€“48h (July 13โ€“15). Severity: ๐Ÿ”ด CRITICAL ยท ๐ŸŸก HIGH ยท ๐ŸŸข MEDIUM.

Threat level ELEVATEDVictims L30D 344Top actor QilinM&A L30D $60M

๐Ÿ’ผ M&A ACTIVITY

No new deals confirmed for July 15.MediumMid-week deal flow typically thin; trade press carrying no named July 14โ€“15 announcements as of this run. The pipeline: SecurityWeek's July 2026 monthly roundup is expected early August.
L30D summary (June 15 โ€“ July 15): ~17 named deals, disclosed value exceeding $5.5B. Headline: Accenture โ†’ Dragos + runZero + NetRise (~$4.17B, OT security platform play, largest single transaction of the year), Booz Allen Hamilton โ†’ Ultra I&C Mission Solutions ($720M, US/allied defence encryption), 1Password โ†’ Apono (~$250โ€“300M, JIT privileged access), SailPoint โ†’ Entro Security (~$200M, NHI/AI-agent identity), Cisco โ†’ WideField Security (undisclosed, Jun 18, Splunk Agentic SOC identity telemetry play). Consolidation theme: identity + AI-native detection + OT security dominating acquirer strategy. Momentum Cyber's H1 2026 Mid-Year Review (Jul 1) confirmed 219 transactions and $9.1B disclosed deal value in H1 โ€” strongest H1 on record. SecurityWeek M&A Tracker ยท Momentum Cyber/GlobeNewswire

โš ๏ธ CRITICAL BREACHES & INCIDENTS

ShinyHunters Salesforce OAuth campaign โ€” year-long, 700+ organisations potentially exposed โ€” Microsoft maps three attack vectors (July 13)CriticalMicrosoft published a detailed threat intelligence report on July 13 mapping a ShinyHunters-attributed campaign running from mid-2025 into mid-2026 that abused trusted Salesforce OAuth connections to bypass MFA and exfiltrate CRM data at scale. Three distinct vectors: (1) Vishing + fake Salesforce Data Loader app โ€” employees tricked into granting OAuth consent, letting attackers inherit the authenticated session and skip MFA entirely; (2) Supply chain โ€” compromised Salesloft Drift credentials (August 2025) exposed OAuth connection secrets used across multiple customer Salesforce tenants; a parallel November 2025 wave compromised Gainsight-published applications to maintain persistent API access across multiple customer instances; (3) Salesforce Aura guest access exploitation โ€” suspicious guest user activity allowed attackers to chain requests against the Aura framework and pull far more data than guest accounts should reach. Retail, education, and manufacturing verticals most affected. Google estimated Drift token theft alone potentially exposed 700+ organisations including Cloudflare, Zscaler, Palo Alto Networks, Proofpoint, PagerDuty, and Tanium. Microsoft has shipped OAuth risk scores to detect anomalous consent grants. Mitigation: audit third-party OAuth connections, restrict guest access to Salesforce Aura endpoints, and monitor for dormant OAuth token use. Microsoft Security Blog ยท The Hacker News
Nihon Kotsu (Japan's largest taxi operator) โ€” malware attack shuts dispatch and reservation systems (July 11)HighNihon Kotsu, Japan's largest taxi and chauffeur service, confirmed a malware infection via unauthorised external access detected on July 11. Affected systems included the taxi dispatch system (phone-based), hire car web order and reservation management, and several internal IT services; the "labour taxi" service for pregnant women across Tokyo, Yokohama, Saitama, and surrounding cities was also disrupted. The company immediately isolated affected networks, engaged external incident responders, and shut down impacted systems as a containment measure. As of July 14: no data exfiltration confirmed, no threat actor has claimed responsibility. Part of a broader pattern of transport sector malware attacks in Japan across 2026. BleepingComputer ยท SC Media ยท Cyber Express

๐Ÿ”“ CRITICAL VULNERABILITIES

Microsoft July 2026 Patch Tuesday โ€” record 622 flaws patched; two zero-days under active attack โ€” federal deadline July 17 for SharePoint (48 hours)CriticalToday's Patch Tuesday is the largest release in Microsoft's history: 622 vulnerabilities across Windows, Office, Azure, SQL Server, Exchange Server, SharePoint Server, Visual Studio, and Active Directory. 56 rated critical. Three zero-days, two exploited in the wild and now on CISA KEV:
CVE-2026-56164Elevation of Privilege in Microsoft SharePoint Server (2016/2019/Subscription Edition); missing authentication in a critical function; CVSS 5.3 (moderate) but confirmed exploited; CISA federal deadline: July 17 โ€” 48 hours from this briefing. On-premises SharePoint shops must treat this as emergency patching.
CVE-2026-56155Elevation of Privilege in Active Directory Federation Services; CVSS 7.8 (important); confirmed exploited in wild; allows attacker to gain administrator privileges; CISA federal deadline: July 28. ADFS is often deployed in hybrid identity environments โ€” compromise means persistent lateral access to federated cloud resources.
CVE-2026-50661Windows BitLocker security feature bypass; publicly disclosed but not yet confirmed exploited.
Previous record was 198 CVEs in a single June release; today's 622 suggests a sustained backlog of deferred patching work being cleared in bulk. Triage guidance: prioritise SharePoint (July 17 deadline), then ADFS, then all 56 criticals before month-end. BleepingComputer ยท Tenable ยท The Hacker News ยท CISA KEV

๐Ÿšจ INTELLIGENCE AGENCY ALERTS & POLICY

US Treasury OFAC sanctions first-ever VPN service (1VPNS) and Belarusian cryptor seller for ransomware support (July 14)CriticalThe US Treasury's OFAC designated 1VPNS (First VPN Service) and its administrator Dmytro Rashevskyi, plus Belarusian national Yegeniy Vladimirovich Silayev who sells cryptors (tools that disguise ransomware as benign files to evade antivirus detection). 1VPNS has advertised on criminal forums since 2014 as a no-logs, no-cooperation-with-law-enforcement service; European law enforcement seized its website in May 2026. This is the first time OFAC has sanctioned a VPN service specifically โ€” a doctrinal expansion beyond sanctioning operators, developers, and cryptocurrency exchanges to targeting the infrastructure enabler layer of the ransomware ecosystem. Rashevskyi used aliases "Maksim Sorin" and "Roman Chabanenko" to acquire hosting infrastructure from providers that would otherwise have refused service. Parallel State Department designation. Treasury/OFAC ยท The Hacker News ยท BleepingComputer ยท State Department

๐ŸŒ THREAT ACTOR & CAMPAIGN ACTIVITY

Ransomware DLS movement (July 14โ€“15):
DragonForceHigh2 new DLS victims July 14: Asimar (Asian Marine Service PCL) (maritime/Thailand โ€” leading Thai shipyard ๐ŸŸฅ), Momenta (AI/autonomous driving/China โ€” group claims access to all source code, financial documents, and configuration files ๐ŸŸฅ). Momenta is a commercially significant target: the Shenzhen-based startup has raised substantial VC funding and its source code and sensor-fusion IP represents high-value industrial espionage material in addition to a standard ransomware leverage play. DragonForce continues deploying Backdoor.Turn (Go-based, Microsoft Teams TURN relay C2 โ€” Symantec-confirmed). ransomware.live
QilinHigh1 new DLS victim July 14: Sedemi (sector/country unconfirmed ๐ŸŸฅ). Qilin maintains its #1 leaderboard position (335 L3M victims, 546 YTD). ransomware.live
Geopolitical / nation-state:
FIFA World Cup final โ€” July 19 (4 days) โ€” cyber threat window at peakHighThe July 19 MetLife Stadium final (designated National Special Security Event) is the highest-density soft-target window of 2026 for hacktivist and state-sponsored actors. CISA, the White House task force, and Canadian Centre for Cyber Security have all published warnings; 13,000+ malicious or suspicious World Cup-themed domains registered since January. Pro-Russia and pro-Iran hacktivist groups have explicitly signalled intent to target the tournament. All four US host cities operate municipal water and wastewater infrastructure inside the active threat advisory envelope (CyberAv3ngers/IRGC interest documented). Risk window closes July 20. Canadian Centre for Cyber Security ยท CSIS ยท Cybersecurity Dive

๐ŸŒ GEOPOLITICS

Analyst lens: how this week's cyber activity maps to state strategy. Defense ยท cyber ยท economics.
The record Microsoft Patch Tuesday (622 CVEs, 56 critical, 2 actively exploited zero-days) is less a security milestone than a transparency event: it reveals how much deferred patching work Microsoft has been carrying, and how much of that backlog sits in identity infrastructure (AD FS) and collaboration tools (SharePoint) that enterprises treat as perennial low-patching-priority.CriticalThe prior record was 198 CVEs in a single release; today's number is 3x that. The two exploited zero-days are both Elevation of Privilege flaws โ€” the class of vulnerability most useful to an actor who already has a foothold and needs to move laterally. The 48-hour CISA deadline on SharePoint indicates CISA has intelligence that exploitation is active and expanding. Organisations that have not yet automated Patch Tuesday deployment cycles for on-premises Microsoft infrastructure are running a structurally exposed posture that today's release highlights. The Hacker News ยท CISA KEV
OFAC sanctioning 1VPNS โ€” the first VPN service designated for ransomware support โ€” represents a doctrinal expansion of the US financial sanctions toolkit from targeting ransomware operators to targeting the anonymisation and obfuscation layer they depend on.CriticalPrior OFAC ransomware designations hit developers (Evil Corp, Conti affiliates), operators, and cryptocurrency exchanges. This action targets an infrastructure vendor that provided a service to many groups simultaneously, making the sanction's blast radius wider than a single operator takedown. The parallel State Department designation and European May 2026 seizure of 1VPNS infrastructure signal this is a coordinated Five Eyes-adjacent action. The policy implication: companies still using 1VPNS or similar no-log, criminal-forum-advertised VPN services for any purpose face OFAC secondary sanctions exposure. Treasury/OFAC ยท State Department
The DragonForce claim against Momenta โ€” a Chinese autonomous-driving AI startup โ€” is notable for the tension it reveals in the Chinese threat landscape: a non-state ransomware group targeting a Chinese national-priority technology company.HighChinese AV startups like Momenta operate with state-strategic importance (autonomous vehicles are a Made in China 2025/2035 priority sector). If the DragonForce claim is confirmed, it illustrates that ransomware groups operating from non-Chinese jurisdictions are willing to target Chinese IP without the political restraint that state-sponsored actors from Russia, North Korea, or China itself observe. Source code and sensor-fusion IP in a training-data-driven AV stack is not easily reconstructed after exfiltration; the extortion leverage is asymmetric. ransomware.live
The ShinyHunters Salesforce OAuth campaign โ€” a year-long, 700-org supply-chain attack through trusted SaaS OAuth tokens โ€” confirms that the enterprise identity perimeter has migrated from the directory (Active Directory, Entra ID) to the SaaS integration layer, where OAuth consent grants persist long after the original vendor relationship changes.HighThe attack required no credential compromise of the target organisation in its most effective variant: compromising a third-party integration vendor (Salesloft Drift) provided persistent API access to every Salesforce tenant that had authorised that vendor's application. The structural fix is not an MFA policy but an OAuth governance programme: periodic review and revocation of third-party consent grants, scope restriction, and anomaly detection on OAuth token usage patterns. Microsoft Security Blog
Threat actors
1 ยท Qilin546 YTD
2 ยท The Gentlemen335 YTD
3 ยท Akira228 YTD
4 ยท DragonForce248 YTD
M&A activity
Socure โ†’ Fravityโ€”
Brinqa โ†’ PlexTracโ€”
Munich Re (via HSB) โ†’ $575Mโ€”
Fortinet โ†’ Virtue AIโ€”