Skip to content

Confidential Β· 19 Jul 2026

πŸ›‘οΈ Daily Cybersecurity Briefing β€” 2026-07-19 (Sunday)

Window: last 24h (July 18–19). Severity: πŸ”΄ CRITICAL Β· 🟑 HIGH Β· 🟒 MEDIUM.

Threat level ELEVATEDVictims L30D 331Top actor QilinM&A L30D $32M

πŸ’Ό M&A ACTIVITY

No new named deals announced July 18–19.MediumSignicat β†’ Inverid (Jul 16, digital identity / NFC document verification) remains the week's most recent transaction. The weekend cadence is typically quiet; Monday press releases are expected.
L30D summary (June 19 – July 19): 12+ named deals tracked in the database; undisclosed total vastly higher (June closed with 37 announced per SecurityWeek roundup). Named disclosed value within window: approximately $870M+ (Booz Allen Hamilton β†’ Ultra I&C Mission Solutions $720M Jun 22; Qualcomm β†’ SAM Seamless Network >$150M Jul 1; Aikido Security β†’ Root ~$70M Jun 30). Note: Accenture β†’ Dragos/runZero/NetRise (~$4.17B) and 1Password β†’ Apono ($250–300M) were announced June 18 and June 15 respectively β€” just outside this 30-day window. Other notable July closes: LevelBlue β†’ Trustwave (Jul 1, MDR/managed security scale), Zurich Insurance Group β†’ BOXX Insurance (Jul 3, SME cyber insurance), Barracuda Networks β†’ Evo Security (Jul 7, MSP identity security), Signicat β†’ Inverid (Jul 16, eID/NFC). Theme: digital identity, managed security, and IoT/connected-device security dominate July deal flow. SecurityWeek M&A tracker Β· Momentum Cyber mid-2026

⚠️ CRITICAL BREACHES & INCIDENTS

Abbott Laboratories / Exact Sciences β€” ShinyHunters claims 30M+ rows of PII, 1M+ SSNs, 22M+ medical records β€” July 18 β€” DLS deadline July 21 β€” πŸŸ₯ unverifiedCriticalAbbott Laboratories confirmed on July 18 that it is investigating unauthorised access to a limited number of internal systems in its Cancer Diagnostics business (Exact Sciences subsidiary). ShinyHunters added Abbott to its DLS and claims to have exfiltrated data from Microsoft Entra, ServiceNow, SharePoint, Databricks, and Coupa: reportedly 30M+ rows of customer PII (names, email, phone, address, DOB, 1M+ SSNs), 22M+ client notes containing doctor-patient conversations, 20M+ medical orders, and commercial agreements and NDAs. A second claim by ShadowByt3$ regarding Abbott's LabCentral portal is under parallel investigation. The DLS deadline was originally July 18 before being extended to July 21; no data has been published as of this briefing. Abbott has not confirmed the scope or data-theft component. This is the most significant healthcare breach claim since the ShinyHunters Salesforce OAuth campaign disclosed July 13. Do not treat DLS claim as confirmed breach β€” verify against Abbott IR communications before acting. BleepingComputer Β· Cybernews Β· Abbott statement
ViteVenom β€” 7 malicious npm packages deliver blockchain-C2 RAT to Vite frontend developers β€” Checkmarx July 17HighCheckmarx researchers disclosed a software supply chain campaign dubbed ViteVenom: seven malicious npm packages impersonating the `@vitejs/*` namespace, published June 29 – July 3, 2026. Part of the ChainVeil family, these packages use a four-tier blockchain C2 spanning Tron, Aptos, and Binance Smart Chain to deliver a remote access trojan capable of reverse shell, credential harvesting, file exfiltration, and persistent backdoor injection. Code does not execute at install time but at import time, evading many endpoint detections. Activity attributed to threat actor SuccessKey; first wallet activity traced to February 2026. Supply chain reach: all projects that installed the malicious packages between June 29 and July 3 should be considered compromised. The Hacker News Β· Unit 42 npm threat landscape
Panasonic Avionics β€” Coinbasecartel data-extortion claim β€” July 15 DLS β€” πŸŸ₯ unverifiedHighCoinbasecartel, a data-theft-first extortion group (emerged September 2025, 118+ claimed victims), listed Panasonic Avionics Corporation on its leak site on July 15. Panasonic Avionics supplies in-flight entertainment and connectivity systems to major commercial airlines; the claimed data scope includes employee records, user accounts, third-party credentials, and external attack surface items. No encryption confirmed; Coinbasecartel's model is exfil-and-extort without deploying ransomware. Aviation supply chain targeting with direct access to airline passenger-facing systems. [ransomware.live] Β· Breachsense Β· Bitdefender
Fairlife / Coca-Cola β€” no actor claimed, production status update pendingHighAs of this briefing, no ransomware group has posted Fairlife on a DLS. US dairy production reportedly remains suspended. Watch for DLS activity through July 21 (same window as Abbott deadline). [Coverage carried from July 18 briefing]

πŸ”“ CRITICAL VULNERABILITIES

CVE-2026-58644 β€” SharePoint unauthenticated RCE CVSS 9.8 β€” FCEB deadline TODAY July 19CriticalConfirmed exploited in the wild; deserialization of untrusted data vulnerability in all on-premises SharePoint Server versions enables unauthenticated RCE and IIS machine key theft for persistent access. Added CISA KEV July 16. Federal agencies without the July 14 cumulative update applied are in non-compliance as of today. SharePoint Online (M365 cloud) is unaffected. Enterprise teams: apply July 14 CU if not already done. CISA KEV Β· NVD Β· The Hacker News
CVE-2026-46817 β€” Oracle E-Business Suite (Payments module) unauthenticated account takeover CVSS 9.8 β€” FCEB deadline PASSED July 18CriticalCISA added CVE-2026-46817 to KEV on July 15 with an unusually aggressive 3-day federal remediation deadline (July 18, yesterday), under Binding Operational Directive 26-04. Improper privilege management in Oracle Payments enables unauthenticated remote compromise of the Oracle EBS Payments component; affects EBS versions 12.2.3–12.2.15. Honeypot telemetry showed isolated exploitation attempts since late June. Oracle patched in May 2026; organizations still on unpatched EBS are actively exploited. Beazley Security Β· BleepingComputer Β· SC Media

🚨 INTELLIGENCE AGENCY ALERTS & POLICY

SharePoint CVE-2026-58644 FCEB remediation deadline: TODAY.CriticalFederal agencies must have applied the July 14 cumulative update or implemented mitigations. Non-compliant agencies are now in violation of BOD 26-04. CISA
Oracle EBS CVE-2026-46817 FCEB deadline passed July 18.HighAgencies had three days from KEV addition (July 15) to remediate β€” an unusually compressed window that signals active, high-confidence exploitation data at the time of addition. Organizations still running unpatched EBS 12.2.3–12.2.15 should treat this as an active incident investigation, not a patch backlog item. CISA
FIFA World Cup final at MetLife Stadium, East Rutherford NJ β€” TODAY July 19 β€” peak NSSE threat window.HighFBI and CISA elevated threat posture remains in effect. Kali365 PhaaS platform and fraudulent FIFA domains remain active vectors targeting fans and event logistics. Operation Riptide's counter-infrastructure posture (launched June 9) is at maximum active tempo for the duration of the event.

🌐 THREAT ACTOR & CAMPAIGN ACTIVITY

Ransomware DLS movement (July 17–19):
QilinHighThree new DLS claims July 17–18: Acosol (public water utility, Spain, Jul 17 πŸŸ₯ β€” company activated security protocols, customers warned personal data including national ID and payment details may be compromised); Cafar (Buenos Aires, Argentina, Jul 17 πŸŸ₯ β€” sector unconfirmed, .org.ar domain); DroguerΓ­a Martorani (medical/pharmaceutical distributor, Buenos Aires, Argentina, Jul 18 πŸŸ₯ β€” imports and distributes hospital products nationally). The Acosol targeting is operationally significant: water utilities are designated critical infrastructure in Spain under NIS2, and a successful Qilin intrusion against a public water authority is the group's most direct critical infrastructure exposure to date. Qilin remains rank 1 globally by victim volume (335 last 3 months / 546 YTD). [ransomware.live] Β· Acosol cyberattack notice
The GentlemenHighOvertook Qilin as the most prolific ransomware operation in June 2026 per Check Point and Infosecurity Magazine: 115 victims in June vs Qilin's 78, accounting for 17% of all published global attacks. This is the first time Qilin has been displaced from the monthly top position in 2026. The Gentlemen has now posted 300 incidents in a recent trailing 3-month window. YTD 335 (per db). The group's worm-capable spread mechanism continues to accelerate victim acquisition pace. Infosecurity Magazine Β· Check Point Research
CoinbasecartelHighBeyond Panasonic Avionics (Jul 15), the group also claimed Axiom Global (Jul 14, US). Coinbasecartel's model β€” exfiltrate, build a negotiation portal, no encryption β€” is now a well-documented playbook. The Panasonic Avionics targeting continues the group's focus on high-value data-rich enterprises across transport and technology. 118+ total claimed victims since September 2025. HookPhish Β· Bitdefender
Chaos RaaS (BlackSuit successor)MediumChaos claimed Sleeman Breweries (Canadian craft brewer, Sapporo subsidiary) on its DLS. Sleeman was first disclosed as unattributed in the June 24 Sapporo Holdings incident (alongside Pokka Corporation Singapore). Chaos's claim now provides attribution context; the June 24 attack that forced system shutdowns at Pokka/Sleeman was likely conducted by or affiliated with the group. Chaos is assessed with moderate confidence as the BlackSuit successor by Cisco Talos. Undercode News Β· Security Boulevard

🌍 GEOPOLITICS

Analyst lens: how this week's cyber activity maps to state strategy. Defense Β· cyber Β· economics.
The Abbott Laboratories breach claim β€” if even partially confirmed β€” would be the most significant healthcare data exposure since Change Healthcare (2024), and it lands at a moment when ShinyHunters has already demonstrated a scalable SaaS OAuth attack chain against 700+ organisations.CriticalThe group's escalation from enterprise SaaS victims to a major medical device and diagnostics company β€” with alleged exfiltration of 22 million doctor-patient conversation records and over one million SSNs β€” represents a structural shift in their target selection toward high-sensitivity healthcare data. The DLS deadline extension to July 21 is a negotiation tactic, not a sign of weakness; historical ShinyHunters practice is to publish data if ransom is refused. Healthcare organisations running any of the affected platforms (Entra, ServiceNow, SharePoint, Databricks, Coupa) should treat this as a live threat indicator, not a news item. The structural risk: if ShinyHunters can exfiltrate patient conversation data at this scale, class-action exposure and HIPAA notification obligations will be triggered regardless of Abbott's negotiating outcome.
The FIFA World Cup final at MetLife Stadium today is the single highest-density multi-vector cyber threat event of 2026, and no confirmed disruption so far is not the same as no incident.CriticalThe FBI/CISA threat posture remains elevated; the Kali365 PhaaS platform and fraudulent FIFA domains remain live as of this briefing; Operation Riptide's active counter-infrastructure posture has been running for six weeks. The 90-minute broadcast window and the three-hour pre-/post-match high-attendance window at the stadium represent the maximum convergence of hacktivist, criminal, and nation-state attention on a single physical and digital event. Any incident timed to the broadcast will immediately become a geopolitical attribution question β€” the media amplification is the strategic objective, not the attack itself.
Qilin's successful targeting of Acosol, a Spanish public water utility, is the clearest signal yet that the group's affiliates are no longer self-limiting to commercial enterprises.HighWater utilities are explicitly designated critical infrastructure under Spain's NIS2 transposition and EU network security directives. A Qilin intrusion against Acosol β€” with claimed exfiltration of national ID numbers and payment data for the utility's subscriber base β€” sits on the direct escalation path from commercial ransomware toward critical infrastructure coercion. The significance is structural rather than individual: if Qilin affiliates are now successfully breaching NIS2-classified water infrastructure, regulators and national CERTs should expect the pattern to repeat in other utility sub-sectors (energy distribution, wastewater, rail signalling) where OT/IT boundary segmentation remains weak. Spain's INCIBE and CERT-ES are the relevant notification authorities.
ViteVenom's four-tier blockchain C2 (Tron, Aptos, Binance Smart Chain) is the most technically sophisticated evasion architecture disclosed in a supply chain attack to date, and it signals a maturation in adversarial anti-takedown design.HighTraditional C2 infrastructure can be seized or sinkholed; blockchain-based C2 is censorship-resistant by design. The SuccessKey actor's use of three separate blockchains as redundant C2 channels β€” activated in February 2026 but deployed at scale in late June/early July β€” demonstrates that supply chain attackers are now applying decentralised-infrastructure thinking from the cryptocurrency-theft ecosystem to developer tooling intrusions. The import-time-not-install-time execution is a direct counter to the layer of endpoint detection that triggers on `npm install` activity. Both techniques are likely to propagate to other supply chain campaigns within 6–12 months.
Threat actors
1 Β· Qilin546 YTD
2 Β· The Gentlemen335 YTD
3 Β· Akira228 YTD
4 Β· DragonForce248 YTD
M&A activity
Socure β†’ Fravityβ€”
Brinqa β†’ PlexTracβ€”
Munich Re (via HSB) β†’ $575Mβ€”
Fortinet β†’ Virtue AIβ€”