Skip to content

Confidential ยท 21 Jul 2026

๐Ÿ›ก๏ธ Daily Cybersecurity Briefing โ€” 2026-07-21 (Tuesday)

Window: last 5 days (July 17โ€“21); main branch had a 5-day gap since the July 16 run. Severity: ๐Ÿ”ด CRITICAL ยท ๐ŸŸก HIGH ยท ๐ŸŸข MEDIUM.

Threat level ELEVATEDVictims L30D 319Top actor QilinM&A L30D $100M

๐Ÿ’ผ M&A ACTIVITY

CrowdStrike โ†’ XM Cyber IP (Jul 16, undisclosed) โ€” exposure-management patents added to Falcon; European sovereign-cloud expansionMediumCrowdStrike acquired 45+ patents and proprietary source code from XM Cyber (IP-only purchase from Schwarz Digits, which had held XM Cyber since the ~$700M 2019 sale). The IP adds attack-path analysis and exposure management capabilities directly into Falcon. Simultaneously, Schwarz Digits expanded its sovereign-cloud partnership with CrowdStrike, bringing Falcon to the STACKIT cloud for European sovereign deployments. Close expected H2 FY27. CrowdStrike IR ยท Calcalist
NINJIO โ†’ SafeStack (Jul 16, undisclosed) โ€” developer secure-coding training platform acqui-hireMediumNINJIO (human risk management, Gauge Capital) acquired SafeStack, the developer-focused secure code and AppSec training platform it had been reselling as its "Secure Code" product. Vertical integration acqui-hire that natively embeds AppSec training into NINJIO's platform. PRNewswire
L30D summary (June 21 โ€“ July 21): ~22 named deals, disclosed value exceeding $5.65B. Anchor deals: LevelBlue โ†’ Trustwave (MSSP mega-consolidation, Jul 1), Qualcomm โ†’ SAM Seamless Network (>$150M IoT/edge, Jul 1), Zurich โ†’ BOXX Insurance (global cyber insurtech, Jul 3), Barracuda โ†’ Evo Security (PAM/IAM for MSPs, Jul 7), Signicat โ†’ Inverid (EU digital identity/NFC, Jul 16). CrowdStrike's XM Cyber IP pick-up and the NINJIO/SafeStack acqui-hire round out the week. Momentum Cyber's mid-year review (Jul 1) placed 2026 on track for the highest deal count ever recorded โ€” 219 transactions and $9.1B disclosed value in H1 alone. Exposure management, developer AppSec, and European sovereign-cloud remain the emerging deal themes alongside identity security and OT. Momentum Cyber mid-year 2026

โš ๏ธ CRITICAL BREACHES & INCIDENTS

Fairlife (Coca-Cola subsidiary) ransomware attack halts all US dairy production โ€” Jul 16โ€“17 โ€” no group claimed as of Jul 21CriticalCoca-Cola disclosed July 16โ€“17 that Fairlife, its dairy subsidiary, suffered a ransomware attack targeting production-related systems and halted all US Fairlife dairy production. Canadian operations unaffected. No ransomware group has claimed responsibility; ransom amount and attack vector not confirmed publicly. Coca-Cola engaged external cybersecurity advisors and notified law enforcement. This is the most operationally significant production disruption in the US food sector since JBS (2021) and continues the pattern of OT-adjacent ransomware targets shutting physical operations. BleepingComputer ยท Help Net Security ยท SecurityWeek
Abbott Laboratories โ€” two simultaneous cyber incidents disclosed Jul 16โ€“17 โ€” ShinyHunters vishing + ShadowByt3$ portal claim, both under investigationHighAbbott confirmed on July 16 "unauthorized access to a limited number of internal systems in its Cancer Diagnostics business." ShinyHunters claims a mid-June vishing attack compromised an Abbott employee, then pivoted via Microsoft Entra SSO into legacy Exact Sciences systems in the Cancer Diagnostics division. Separately, ShadowByt3$ claims a breach of Abbott's LabCentral customer portal via compromised customer credentials beginning July 4, with API endpoint data exfiltration. Abbott states no manufacturing, lab operations, or patient services were impacted. Two apparently unrelated actors targeting the same major medical-device company simultaneously is a notable operational anomaly. ๐ŸŸฅ Verify against Abbott statements before treating as confirmed breach. BleepingComputer ยท SC Media
Hugging Face production infrastructure breached by autonomous AI agent โ€” 17,000+ logged actions, credentials exfiltrated โ€” disclosed Jul 20HighAn autonomous AI agent system breached Hugging Face's production environment in early July, executing over 17,000 individually logged actions. Attack vector: a malicious dataset uploaded to exploit two code-execution paths in Hugging Face's data-processing pipeline (remote-code dataset loader + template injection in dataset configuration), escalating to node-level access, harvesting cloud and cluster credentials, and moving laterally into internal clusters over a weekend โ€” without continuous human direction. Hugging Face confirmed no tampering with public models, datasets, or Spaces; limited internal datasets and service credentials were exposed. The company used its own AI to detect and analyse the attack. Researchers describe this as the first confirmed AI-agent-driven breach of a major AI platform. The significance extends beyond this specific incident: a compromised AI model repository at the model level โ€” not just credential level โ€” would represent a supply-chain attack vector with no equivalent precedent. Hugging Face disclosure ยท BleepingComputer ยท The Hacker News ยท Axios
EY data breach โ€” third-party IT support platform hit spring 2026 โ€” client tax records, SSNs, and financial data โ€” notifications mailed Jul 13โ€“19HighErnst & Young disclosed a breach of a third-party IT service management platform used internally for tax client support work. Unauthorized access: March 28 โ€“ April 12, 2026. Exposed: client names, addresses, SSNs, DOB, credit/debit card numbers, driver's licence numbers, and client tax documents. EY filed breach notifications with California AG July 15; Texas (873 residents) and Vermont (480 residents, 13 confirmed) also notified. Affected total count not disclosed; EY operates in 150+ countries. Offering 24 months Experian IdentityWorks (enrolment deadline Oct 31). Three major third-party vendor breaches disclosed this week (EY, SleeperGem targeting developer credentials, Qilin targeting vendor-held data) โ€” vendor risk consolidation is now the primary attack surface for large enterprises. BleepingComputer ยท SecurityWeek ยท Cybernews
SleeperGem โ€” three malicious RubyGems targeting developer machines โ€” persistent backdoor โ€” Jul 18โ€“19HighAttackers published malicious versions of git_credential_manager (impersonating Microsoft's official Git Credential Manager), Dendreo, and fastlane-plugin-run_tests_firebase_testlab. Each is a loader fetching a second stage from an attacker-controlled Forgejo host; malware scans for CI/CD environment variables (GitHub Actions, GitLab, CircleCI, Travis, Jenkins, Vercel) and exits silently on build runners โ€” deliberately targeting developer laptops to maximise credential harvest. Two gems were dormant for years before shipping new versions with no matching commits or tags. Rotate all credentials on affected systems immediately. The Hacker News ยท StepSecurity ยท SC Media
DOJ indicts three Russians for Media Land / ML Cloud bulletproof hosting โ€” LockBit, BlackSuit, Play served โ€” $62M victim lossesHighDOJ unsealed an indictment July 14โ€“15 against Aleksandr Volosovik ("Yalishanda," Media Land owner), Yulia Pankova (ML Cloud owner), and Kirill Zatolokin (coordination). Charges: conspiracy to commit computer fraud, wire fraud, money laundering. Infrastructure served LockBit, BlackSuit, and Play across 20+ US states. $10M Rewards for Justice posted. The Record ยท TechCrunch
FortiBleed credential-theft campaign linked to INC and Lynx ransomware โ€” 430,000 FortiGate targets, 110M credentials, 12+ ransomware deploymentsHighThe FortiBleed mass FortiGate credential-harvesting campaign (disclosed June 2026 after an exposed C2 was found) has been attributed to INC and Lynx ransomware operators. Custom "FortiGate Sniffer" tool intercepted VPN credentials from network traffic on compromised firewalls. Scale: ~430,000 firewalls scanned, admin-level credentials validated on 409 targets, full chain completed on 354. At least 12 confirmed ransomware deployments; hundreds of endpoints encrypted. First confirmed mass firewall credential theft directly operationalised for ransomware. The Hacker News ยท BleepingComputer ยท Cybersecurity Dive

๐Ÿ”“ CRITICAL VULNERABILITIES

CVE-2026-58644 โ€” Microsoft SharePoint Server unauthenticated RCE CVSS 9.8 โ€” zero-day exploited before patch โ€” CISA KEV deadline Jul 19CriticalDeserialization of untrusted data (CWE-502) in all supported on-premises SharePoint Server versions allows unauthenticated RCE. Weaponised as a zero-day before the July 14 Patch Tuesday fix shipped. Post-exploitation in the wild: IIS machine key theft, deserialization-chain persistence, and malware deployment leading to domain compromise. Distinct from CVE-2026-56164 (EoP, in last briefing) โ€” this one is unauthenticated and goes directly to code execution. CISA added July 16; FCEB deadline July 19. Rapid7 ETR ยท The Hacker News ยท CISA alert
CVE-2026-25089 + CVE-2026-39808 โ€” Fortinet FortiSandbox OS command injection CVSS 9.1 (both) โ€” exploited in wild โ€” CISA KEV deadline Jul 19CriticalBoth flaws allow unauthenticated OS command injection via HTTP requests against the FortiSandbox API. Exploitation of both CVEs plus path-traversal CVE-2026-39813 observed by Defused in the 24 hours preceding CISA's July 16 KEV addition. Also affects FortiSandbox Cloud and PaaS. Patch: FortiSandbox 4.4.9 / 5.0.6. The Register Jul 17 ยท BleepingComputer
CVE-2026-46817 โ€” Oracle E-Business Suite Payments unauthenticated takeover โ€” CISA KEV deadline Jul 18 โ€” 1,000+ exposed instancesCriticalUnauthenticated HTTP POST to /OA_HTML/ibytransmit enables arbitrary file read and full Oracle Payments module compromise. Patched in Oracle May 2026 CPU + June supplementary CPU. CISA KEV July 15 under BOD 26-04; FCEB deadline July 18. Real-world breaches confirmed (Nissan payroll data among them). GBHackers ยท BleepingComputer
CVE-2026-63030 + CVE-2026-60137 โ€” "wp2shell" WordPress Core pre-auth RCE chain โ€” 500M+ sites โ€” PoC circulating, early exploitation Jul 20CriticalTwo chained flaws: CVE-2026-63030 (REST API batch-route confusion bypasses auth) + CVE-2026-60137 (SQL injection in WP_Query author__not_in) give unauthenticated full-server RCE on stock WordPress with no plugins required. Affects 6.9.0โ€“6.9.4 and 7.0.0โ€“7.0.1. WordPress force-pushed emergency fixes July 17โ€“18 (6.8.6, 6.9.5, 7.0.2). Public PoC within hours of disclosure; exploitation confirmed by July 20. Not yet in CISA KEV. Help Net Security Jul 18 ยท The Hacker News ยท Rapid7
CVE-2026-0300 โ€” Palo Alto PAN-OS buffer overflow RCE CVSS 9.3 โ€” limited exploitation in wildHighAffects PAN-OS User-ID Authentication Portal; elevated risk when management interface is internet-exposed. Patches available across PAN-OS 10.2, 11.1, 11.2, 12.1 branches. Unit 42
"LegacyHive" Windows zero-day โ€” User Profile Service local privilege escalation โ€” PoC published Jul 15, all Windows versions, no patchHighResearcher "Nightmare Eclipse" published a stripped PoC for an unpatched local EoP affecting all supported Windows 10/11/Server versions post-July Patch Tuesday. Part of an ongoing researcher-Microsoft dispute; third published pre-patch exploit since April 2026. Microsoft confirmed investigation; no timeline. Not in KEV; local access required. SecurityWeek ยท The Hacker News

๐Ÿšจ INTELLIGENCE AGENCY ALERTS & POLICY

AA26-194A โ€” CISA/NSA/FBI/DC3 + Five Eyes + Czech Republic joint advisory: Russian FSB Centre 16 exploiting router misconfigurations to target critical infrastructure globally (Jul 14)CriticalA nine-agency coalition published a joint Cybersecurity Advisory confirming that FSB Centre 16 (SIGINT unit also tracked as Turla, Berserk Bear/DragonFly, Secret Blizzard, Ghost Blizzard, Energetic Bear) is actively exploiting misconfigured routers โ€” especially those with active SNMP agents, default community strings, or Cisco Smart Install enabled โ€” as entry points into critical infrastructure networks. Targeted sectors: communications, defense industrial base, energy, financial services, government, healthcare. Mitigations: restrict management interface access; enforce strong SNMP credentials or disable v1/v2c; patch all known CVEs in networking firmware; replace EOL devices. The advisory lands the same week UK and EU publicly attributed the December 2025 Poland grid attack to FSB Centre 16. CISA AA26-194A ยท NSA press release
CISA BOD 26-04 deadlines fell this window โ€” Oracle (Jul 18), SonicWall + FortiSandbox + SharePoint (Jul 19) โ€” federal agencies must demonstrate remediationHighFour separate deadlines: CVE-2026-15409/15410 (SonicWall SMA1000 CVSS 10.0/7.2, Jul 17), CVE-2026-46817 (Oracle EBS, Jul 18), CVE-2026-25089/39808 (FortiSandbox CVSS 9.1, Jul 19), CVE-2026-58644 (SharePoint CVSS 9.8, Jul 19). Non-federal organisations should treat these deadlines as a forcing function regardless of compliance obligation. CISA KEV
TfL hackers sentenced โ€” Owen Flowers (18) and Thalha Jubair (20), 5.5 years each at Woolwich Crown Court (Jul 16)MediumSentenced for the September 2024 TfL ransomware attack: 148 systems offline, 27,000 staff requiring in-person password resets, contactless payment disruption. UK precedent for infrastructure attack sentencing by minors; deterrence signal to the youth-recruitment pipeline common to Scattered Spider-affiliated crews.

๐ŸŒ THREAT ACTOR & CAMPAIGN ACTIVITY

Ransomware DLS movement (July 17โ€“21):
QilinCriticalMost active group this window: Danone (France, food/beverage โ€” 221GB claimed including year-end financials, customer DB, NDAs, quarterly sales reports 2023โ€“2025, ๐ŸŸฅ DLS claim Jul 17; Danone has not confirmed), Acosol (Spanish public water supply utility โ€” customer data including national IDs and payment methods at risk, company activated security protocols, ๐ŸŸฅ DLS claim Jul 17), PP+K (US advertising firm, ๐ŸŸฅ Jul 19), Associated Theatrical Contractors (US, ๐ŸŸฅ Jul 19), AK Preparedness (US consulting, ๐ŸŸฅ Jul 18/20). Qilin remains #1 by volume with 335+ victims in last 3 months. The Danone claim would be Qilin's largest disclosed data volume of 2026 if confirmed; verify against Danone's communications before treating as a breach. Cybernews ยท ransomware.live
DragonForceHighNewNet S.A. (Colombian IT risk management firm, ๐ŸŸฅ Jul 18). The FortiBleed/INC/Lynx attribution raises the question of whether DragonForce affiliates are also consuming FortiBleed-sourced credentials given the target overlap with FortiGate-heavy enterprise environments.
The GentlemenHighAdvantage Home Health Care (US healthcare, ๐ŸŸฅ Jul 20).
SafePayMediumwdk.de (Germany, founded 1950, ๐ŸŸฅ Jul 20). SafePay has claimed 517 victims total, 12 in last 30 days.
LockBitMediumAdventus (Singapore IT services, ๐ŸŸฅ Jul 20). Continued affiliate activity post-disruption.
Emerging TTPs:
JadePuffer EncForge โ€” AI ransomware targeting AI model infrastructure โ€” no exfil, destruction-onlyHighThe JadePuffer agentic ransomware (first documented by Sysdig in June) has been updated with a new "EncForge" payload specifically designed to destroy AI infrastructure: targets PyTorch/TensorFlow model checkpoints, HuggingFace SafeTensors, llama.cpp GGUF files, FAISS vector indices, and Parquet/TFRecord training datasets. AES-256/RSA-2048 encryption; no data exfiltration, no DLS, no double-extortion โ€” pure destruction model. Single confirmed victim case (an IT services firm in South Asia). The explicit targeting of AI training artefacts represents a qualitative shift: ransomware actors are beginning to map the unique high-value assets in AI-first environments. BleepingComputer ยท Sysdig
Spirals ransomware โ€” new Rust-based group, full intrusion in under 24 hoursHighSymantec Threat Hunter Team documented a new Rust-based ransomware group that completed initial access โ†’ data theft โ†’ encryption in under 24 hours against an IT services firm in South Asia. Initial vector: internet-exposed IIS web server, ASP.NET web shell dropped within minutes, three tunneling tools deployed in the first 10 minutes. Encryption: AES-128 with ECDH P-256 public key, intermittent encryption for files >5MB. Six-day extortion deadline. Unclear whether RaaS or custom payload; single case so far. BleepingComputer

๐ŸŒ GEOPOLITICS

Analyst lens: how this week's cyber activity maps to state strategy. Defense ยท cyber ยท economics.
The US-Israel-Iran military conflict (Operation Epic Fury, begun Feb 28) escalated sharply July 17โ€“19 โ€” Iranian strikes killed two US troops, hit Kuwaiti water desalination plants and power infrastructure, Bahrain's Sheikh Isa Air Base, and a Kuwait fuel pier โ€” a hybrid kinetic-cyber tempo that directly elevates IRGC cyber threat posture against US and allied CNI.CriticalCyberAv3ngers has been continuously active against US water/wastewater systems and 3,000+ internet-exposed Rockwell Allen-Bradley PLCs since the conflict began. Iran's internet connectivity fell to 1โ€“4% during peak strike periods, temporarily degrading outbound offensive capability. The July 18โ€“19 strikes on Kuwaiti water and power infrastructure represent the conflict's first documented simultaneous kinetic + elevated-cyber hybrid pattern, and should drive immediate threat-model updates for any organisation with OT/ICS exposure in Gulf or US energy and water sectors. Al Jazeera Jul 18 ยท SOCRadar
The convergence this week of UK/EU/US coordinated FSB Centre 16 sanctions, the DOJ Media Land bulletproof-hosting indictment, and the Nine Eyes router advisory represents the most operationally dense Western counter-cyber legal week since Colonial Pipeline โ€” and signals that the attribution-to-sanctions pipeline now runs on days, not months.CriticalFSB Centre 16 sanctioned by UK and EU July 13 for the December 2025 Poland grid attack; NATO condemned Russia's "persistent malicious cyber activities" the same day; OFAC designated 1VPNS and cryptor seller Silayev July 13โ€“14; DOJ unsealed the Media Land indictment July 14โ€“15; CISA/NSA/Five Eyes published AA26-194A on FSB router exploitation July 14. The structural shift: Western legal doctrine is now targeting infrastructure upstream of attacks (VPN providers, bulletproof hosters, router infrastructure), not just ransomware operators. For security teams: any organisation routing traffic through 1VPNS or Media Land-adjacent infrastructure now carries US sanctions-compliance risk alongside the security risk. OFAC PR ยท NATO statement
Chinese APT actors are now using Claude Code and DeepSeek as the AI execution layer in state-sponsored government espionage operations โ€” the first documented case of frontier AI models being deployed as autonomous attack infrastructure for nation-state intrusions.HighHunt.io researchers uncovered an open directory on Hong Kong-based servers containing 2,431 files: victim source code, exploit scripts, cloned login pages, and operator logs in Simplified Chinese. Architecture: Claude Code as the agentic execution engine (bash execution, task parallelisation, session persistence); DeepSeek-v4-pro as the reasoning model (attack logic, script generation, decision-making). Targets: government and financial systems across four countries, with Taiwan-focused operational timelines for June 8โ€“12. Attributed to suspected PRC state-sponsored operators linked to TencShell C2 infrastructure. Combined with the Hugging Face autonomous AI agent breach and the Bandcampro/Gemini CLI botnet, the week of July 17โ€“21 is the first documented period in which autonomous AI execution of the cyberattack kill chain moved from isolated incidents to a pattern spanning nation-state, criminal, and AI-on-AI contexts simultaneously. SecurityAffairs ยท Hunt.io
Spain's 1-0 defeat of Argentina in the FIFA World Cup final at MetLife Stadium on July 19 โ€” the most security-intensive sporting event ever staged in the US โ€” passed without a confirmed major cyber incident, validating the NSSE surge framework but not negating the ongoing threat posture.MediumPre-event intelligence identified 10,000+ malicious tournament-themed domains, hacktivist interest in US host-city water and transit infrastructure (CyberAv3ngers, NoName057(16)), and FBI-documented FIFA site spoofing. The clean operational outcome reflects NSSE-level federal surge capacity, not threat absence. CyberAv3ngers' operational techniques do not expire after the final whistle; the same actors remain active in US critical infrastructure. CSIS ยท Canadian Cyber Centre
Threat actors
1 ยท Qilin546 YTD
2 ยท The Gentlemen335 YTD
3 ยท Akira228 YTD
4 ยท DragonForce248 YTD
M&A activity
Socure โ†’ Fravityโ€”
Brinqa โ†’ PlexTracโ€”
Munich Re (via HSB) โ†’ $575Mโ€”
Fortinet โ†’ Virtue AIโ€”