Skip to content

Confidential Β· 20 Jul 2026

πŸ›‘οΈ Daily Cybersecurity Briefing β€” 2026-07-20 (Monday)

Window: last 24–48h (July 18–20). Severity: πŸ”΄ CRITICAL Β· 🟑 HIGH Β· 🟒 MEDIUM.

Threat level ELEVATEDVictims L30D 330Top actor QilinM&A L30D $100M

πŸ’Ό M&A ACTIVITY

No new named deals announced July 19–20.MediumWeekend cadence is typically quiet; Monday press releases expected through the day.
L30D summary (June 20 – July 20): 6 named July deals tracked in the database: LevelBlue β†’ Trustwave (Jul 1, MSSP consolidation), Qualcomm β†’ SAM Seamless Network (Jul 1, >$150M, IoT security), Zurich Insurance β†’ BOXX Insurance (Jul 3, SME cyber insurance), Viatel β†’ FullProxy (Jul 3, network security), Barracuda Networks β†’ Evo Security (Jul 7, MSP identity), Signicat β†’ Inverid (Jul 16, eID/NFC document verification). June contributed 13+ named deals per the database. Disclosed value in the 30-day window is dominated by Qualcommβ†’SAM (>$150M) with the remainder undisclosed. Themes: digital identity, managed security, and IoT/connected-device security continue to dominate July deal flow. SecurityWeek M&A tracker Β· Momentum Cyber mid-2026

⚠️ CRITICAL BREACHES & INCIDENTS

Ernst & Young (EY) β€” client tax records, investment data, and SSNs exposed via third-party IT support platform breach β€” disclosed July 15HighEY disclosed on July 15 that unauthorised access to a third-party IT support platform used for UK client engagements exposed client tax records, investment data, and Social Security Numbers. The breach window is estimated at March–April 2026. EY has notified affected clients directly; the attack vector is assessed as credential theft at the third-party vendor. No ransomware group has claimed the breach. Given EY's client base (FTSE 100, US Fortune 500), the exposure of tax and investment records is high-impact regardless of breach scale. 🟨 partial confirmation β€” scope not fully disclosed. BleepingComputer
Ecopetrol (Colombia) β€” national oil company, 3,300 accounts, extortion demands, encryption attempt blocked β€” July 17HighColombia's state-controlled oil company, Ecopetrol (annual revenue ~$25B, LATAM's second-largest energy company), disclosed on July 17 that an external actor gained unauthorised access to cloud-based file storage environments across approximately 15 subsidiaries, exfiltrating data from ~3,300 user accounts including financial records, customer data, and internal files. The attacker communicated extortion demands; a ransomware encryption attempt was made but blocked by existing controls. No data has been published on leak sites as of July 20. Ecopetrol filed a criminal complaint with the Colombian Attorney General; investigation ongoing with insurers and external forensics. No group has claimed the attack. 🟨 partial confirmation. PR Newswire/Ecopetrol statement Β· Colombia One
Abbott Laboratories / Exact Sciences β€” ShinyHunters β€” DLS deadline TOMORROW July 21 β€” 30M+ PII rows, 1M+ SSNs, 22M+ medical records β€” πŸŸ₯ unverifiedCriticalAttack vector now confirmed: vishing attack on an IT help-desk employee on July 4 led to Entra SSO credential compromise, giving ShinyHunters access to Microsoft Entra, ServiceNow, SharePoint, Databricks, and Coupa. Abbott confirmed it is investigating unauthorised access to its Cancer Diagnostics business (Exact Sciences subsidiary). No data published yet; DLS deadline is July 21 (tomorrow). Abbott has not confirmed the scope or data-theft component. BleepingComputer Β· Abbott statement
Fairlife LLC (Coca-Cola) β€” US dairy production suspended β€” still unattributed β€” July 16HighNo ransomware group has claimed Fairlife as of July 20. US production of Ultra-Filtered Milk, Core Power Protein Shakes, and Nutrition Plan products remains suspended; Canadian operations unaffected. Coca-Cola is working with external IR advisors and law enforcement. No data theft confirmed. Watch for DLS posting; the 4-day window without a claim is longer than typical for groups operating the exfil-then-extort model. TechCrunch Β· The Register

πŸ”“ CRITICAL VULNERABILITIES

FortiSandbox CVE-2026-25089 / CVE-2026-39808 β€” CVSS 9.1 each β€” FCEB deadline PASSED July 19CriticalTwo critical Fortinet FortiSandbox vulnerabilities were added to CISA KEV with a July 19 federal remediation deadline under BOD 26-04: CVE-2026-25089 (improper neutralisation of special elements enabling OS command injection via the management interface, CVSS 9.1) and CVE-2026-39808 (path traversal enabling arbitrary file read/write, CVSS 9.1). Both confirmed exploited in the wild. Chained together, these vulnerabilities allow unauthenticated attackers to achieve full compromise of FortiSandbox appliances β€” a class of device that processes suspicious files from the enterprise network, making a breach of the sandbox itself a high-value intelligence position. Federal agencies not patched as of close of business July 19 are in non-compliance with BOD 26-04. Enterprise teams should treat these as immediate-action items. CISA KEV Β· Fortinet PSIRT Β· BleepingComputer
CitrixBleed 2 β€” CVE-2026-8451 β€” Citrix NetScaler active exploitation in the wildCriticalActive exploitation confirmed for CVE-2026-8451, a memory disclosure vulnerability in Citrix NetScaler ADC and NetScaler Gateway enabling session token hijacking without authentication. Exploitation pattern mirrors CitrixBleed (CVE-2023-4966) from 2023 β€” attackers extract session tokens to bypass MFA and authenticate as legitimate users. Rapid7 MDR and Shadowserver have both logged exploitation attempts since mid-July. Patch to the latest NetScaler release; revoke all active sessions after patching (tokens extracted before patching remain valid). Rapid7 Β· Shadowserver Β· SecurityWeek
Oracle Critical Patch Update β€” July 21 release β€” CVE-2026-35278 PeopleSoft CVSS 9.8 β€” ShinyHunters attack vectorHighOracle's quarterly CPU drops tomorrow July 21. CVE-2026-35278, a critical authentication bypass in Oracle PeopleSoft Human Capital Management, CVSS 9.8, is confirmed exploited in the wild β€” ShinyHunters has used it as an initial-access vector in the ongoing Salesforce OAuth campaign. Organizations running PeopleSoft HCM should pre-stage patches for immediate application upon CPU release tomorrow. Oracle Security Alerts Β· The Hacker News
wp2shell CVE-2026-63030 β€” WordPress core pre-auth RCE β€” public exploits now availableHighSince the July 17 patch, multiple proof-of-concept exploits for CVE-2026-63030 have been published publicly. The no-authentication required primitive against all unpatched WordPress 6.9.0–7.0.1 installs is now a commodity attack. WordPress.org's forced auto-update covers managed hosting; self-hosted installs on older configurations may not have received it. Verify WordPress version is 6.9.5, 7.0.2, or later on all self-managed installations. Rapid7 ETR Β· The Hacker News

🚨 INTELLIGENCE AGENCY ALERTS & POLICY

AA26-194A β€” CISA / NSA / FBI + 19 partner agencies β€” Russian FSB Center 16 pre-positioning in global CNI via SNMPv1/2 and Cisco Smart Install β€” July 13CriticalA 20-agency joint advisory (AA26-194A) released July 13 by CISA, NSA, FBI, and 19 allied agencies details an active campaign by Russia's FSB Center 16 (Sandworm/Seashell Blizzard) targeting critical national infrastructure globally using SNMPv1/v2 community strings and Cisco Smart Install protocol abuse to achieve persistent access on network edge devices. The campaign systematically targets devices running default or weak SNMP community strings ("public"/"private") and Cisco switches with Smart Install enabled β€” both configurations are common in enterprise environments and network perimeters. FBI assessed this campaign represents pre-positioning for potential destructive operations against Western CNI, not just espionage. Immediate mitigations: disable SNMPv1/v2c (migrate to SNMPv3 with auth/priv), disable Cisco Smart Install where not required, rotate all SNMP community strings, audit internet-facing network device configurations. CISA AA26-194A Β· NCSC-UK Β· The Record
FortiSandbox FCEB deadline passed July 19HighCVE-2026-25089 and CVE-2026-39808 remediation was due yesterday. Non-compliant agencies should treat this as an active incident risk, not a patch backlog item. CISA BOD 26-04
Oracle CPU July 21 β€” pre-stage now.MediumThe quarterly CPU releases tomorrow; patch notes and affected version lists will be available at 8am US Eastern. Prioritise CVE-2026-35278 (PeopleSoft HCM CVSS 9.8) for immediate deployment. Oracle

🌐 THREAT ACTOR & CAMPAIGN ACTIVITY

Ransomware DLS movement (July 18–20):
QilinHighFour new DLS victims July 18–19: Salina Supply (US, home improvement/building supplies, Jul 18 πŸŸ₯), Eana (Argentina, satellite/connectivity, Jul 19 πŸŸ₯), Synergy Products (US, industrial manufacturing, Jul 19 πŸŸ₯), and a fourth unconfirmed posting under review. Qilin maintains rank 1 globally (335 last 3 months / 546 YTD). The Argentine telecoms targeting continues the group's Q3 2026 pattern of geographic and sector diversification beyond its North American/European base. [ransomware.live]
INC RansomHighTwo new DLS victims July 18: Reatile Group (South Africa, energy distribution, πŸŸ₯) and D.MAG New Material Technology (China, advanced materials manufacturing, πŸŸ₯). INC Ransom's South Africa energy targeting follows Qilin's July 17 hit on Acosol (Spain water utility), reinforcing Q3 2026 as the quarter where ransomware operators are visibly expanding into non-Western critical infrastructure. [ransomware.live]
NovaHighTwo new DLS victims July 19: MER-AL (Turkey, automotive components manufacturing, πŸŸ₯) and Dephub (Indonesia, government transportation/ports authority, πŸŸ₯). Nova (rank 9 on the leaderboard) claiming a government transportation entity in Indonesia signals the group's expansion beyond its previous commercial-sector focus. Government targeting raises the escalation risk profile. [ransomware.live]
D1R groupHighBig-game hunting targeting ARM Holdings, Synopsys, and Bosch (July 13) β€” D1R, a data-theft-first extortion group, has claimed simultaneous intrusions at three semiconductor/IP-intensive companies: ARM Holdings (UK, chip architecture IP), Synopsys (US, EDA software and semiconductor design tools), and Bosch (Germany, IoT/industrial technology). All three are foundational to the global semiconductor supply chain. The ARM + Synopsys combination in particular represents an extraordinary potential IP theft exposure β€” if confirmed, the combined design and toolchain access would give an adversary visibility into the architecture of billions of devices. All three claims are πŸŸ₯ unverified; no public statements from any of the companies as of July 20. [FalconFeeds] Β· [HookPhish]
The GentlemenMediumOvertook Qilin as most prolific group in June 2026 (115 vs 78 victims per month, 17% of all global attacks). The worm-capable spread mechanism continues to drive victim acquisition at a pace that no other group matches in the current environment. YTD 335 victims. Rank 2 globally. Check Point Research Β· Infosecurity Magazine

🌍 GEOPOLITICS

Analyst lens: how this week's cyber activity maps to state strategy. Defense Β· cyber Β· economics.
AA26-194A β€” the 20-agency FSB advisory is the clearest public articulation yet that Russia is pre-positioning for destructive operations against Western CNI, not merely conducting espionage.CriticalFBI's explicit assessment of "pre-positioning for potential destructive operations" in a joint advisory co-signed by 19 allies is a calibrated diplomatic signal as much as a technical warning: it places responsibility for network edge security failures on the operators of those networks while making attribution of any subsequent destructive event unambiguous. The technical vector β€” SNMPv1/v2 community strings and Cisco Smart Install, both decades-old protocols that remain endemic in enterprise and OT environments β€” is chosen precisely because remediation is operationally difficult at scale. The advisory lands during an already-elevated threat posture (FIFA World Cup final July 19, HSIN breach, Fairlife) and sets the structural expectation that the next major CNI disruption in a NATO country will be traceable to pre-planted access, not opportunistic exploitation. CISA AA26-194A Β· The Record
The Ecopetrol breach β€” Colombia's national oil company hit β€” is a direct data point in the broader pattern of state-adjacent energy sector targeting across non-NATO LATAM countries.HighEcopetrol is majority state-owned (~88% Colombian government), making this an attack on strategic state infrastructure, not a commercial ransomware target. The attacker blocked encryption with existing controls but still exfiltrated from 15 subsidiaries β€” suggesting a financially motivated rather than state-directed actor, but the intelligence value of financial and operational data from a state energy company remains high regardless of actor motivation. LATAM energy companies have historically operated outside the intensive CNI-hardening posture applied to US/EU counterparts; this breach and Ecopetrol's public disclosure are likely to accelerate regulatory attention from LATAM governments on energy sector cyber standards. Ecopetrol statement
The D1R claim against ARM Holdings + Synopsys + Bosch, if even partially confirmed, would represent the most significant semiconductor IP theft exposure in the public record since the 2021 NVIDIA breach.HighARM's chip architecture IP licenses are the foundation of essentially every mobile and embedded processor shipped globally; Synopsys EDA tools are how those chips are designed. A single intrusion that spans both companies would give an adversary the blueprint and the toolchain simultaneously. The coordinated targeting of three companies in a single campaign window signals a level of pre-planning inconsistent with opportunistic ransomware β€” D1R's model (exfil-only, no encryption) is consistent with IP theft as a primary objective, with extortion as the monetisation layer. The Bosch addition introduces industrial IoT and automotive component design data. All three claims remain unverified; treat as intelligence requiring direct vendor confirmation before acting. [FalconFeeds] Β· [HookPhish]
The Abbott DLS deadline (July 21 tomorrow) creates a 24-hour decision window that will determine whether 22M+ doctor-patient conversation records enter the criminal data marketplace.HighShinyHunters' vishing-to-Entra-SSO attack chain β€” confirmed at Abbott β€” is the same chain the group has used across the broader Salesforce OAuth campaign (700+ organisations). The structural implication: help-desk social engineering that bypasses MFA by resetting credentials at the identity provider level is now a documented, reproducible, scalable attack vector against enterprises relying on SSO. HIPAA notification obligations and class-action exposure are triggered by publication, not by negotiation outcome β€” Abbott's legal exposure clock starts tomorrow if ShinyHunters publishes. BleepingComputer Β· Abbott statement
FIFA World Cup final at MetLife Stadium (July 19) passed without a confirmed major cyber incident β€” a non-event that is still analytically significant.MediumOperation Riptide's six-week counter-infrastructure campaign, elevated NSSE threat posture, and FBI/CISA pre-event mitigations appear to have held. The Kali365 PhaaS platform and fraudulent FIFA domains generated the expected fan-targeting fraud activity but no confirmed disruption to event operations or broadcast infrastructure. The HSIN breach (detected weeks late) created the structural intelligence gap that concerned analysts most; the absence of exploitation timed to the final does not close that gap β€” the exfiltrated HSIN data remains in adversary hands. [FBI post-event statement] Β· CISA
Threat actors
1 Β· Qilin546 YTD
2 Β· The Gentlemen335 YTD
3 Β· Akira228 YTD
4 Β· DragonForce248 YTD
M&A activity
Socure β†’ Fravityβ€”
Brinqa β†’ PlexTracβ€”
Munich Re (via HSB) β†’ $575Mβ€”
Fortinet β†’ Virtue AIβ€”