Confidential Β· 22 Jul 2026
π‘οΈ Daily Cybersecurity Briefing β 2026-07-22 (Wednesday)¶
Window: last 24h (July 21β22). Severity: π΄ CRITICAL Β· π‘ HIGH Β· π’ MEDIUM.
Threat level ELEVATEDVictims L30D 319Top actor QilinM&A L30D $160M
πΌ M&A ACTIVITY¶
Palo Alto Networks β Embrace (Jul 21, undisclosed) β DEM and Real User Monitoring added to Observability platform; Q1 FY27 closeMediumPalo Alto Networks announced intent to acquire Embrace, a user-focused observability company, to add high-fidelity Real User Monitoring (RUM) capabilities and extend its Observability platform into Digital Experience Monitoring (DEM). Observability ARR surpassed $300M in Q3 FY26. Also launching Synthetics for proactive pre-deployment application performance validation. Undisclosed value; Q1 FY27 close targeted. Palo Alto IR Β· GuruFocus
L30D summary (June 22 β July 22): ~23 named deals, disclosed value exceeding $5.65B. Anchor deals: LevelBlue β Trustwave (MSSP mega-consolidation, Jul 1), Qualcomm β SAM Seamless Network (>$150M IoT/edge, Jul 1), Zurich β BOXX Insurance (global cyber insurtech, Jul 3), Booz Allen β Ultra I&C Mission Solutions ($720M, Jun 22). Palo Alto/Embrace extends an observability + security convergence theme alongside CrowdStrike's XM Cyber IP pickup (Jul 16). Momentum Cyber mid-year review placed 2026 on track for the highest deal count ever recorded β 219 transactions and $9.1B disclosed value in H1 alone. Momentum Cyber mid-year 2026
β οΈ CRITICAL BREACHES & INCIDENTS¶
Romania ANCPI β entire national land registry database wiped after failed extortion β real estate market paralyzed β attributed to ByteToBreach (Zakaria Mahdjoub, Algeria)CriticalThreat actor ByteToBreach used valid credentials to access Romania's National Agency for Cadastre and Real Estate Advertising (ANCPI) around July 14, mapped internal systems, and wiped the entire national land registry database and backups after a failed extortion attempt. Property purchases stalled; notaries unable to authenticate documents; e-Terra and RENNS government applications went dark. Stolen data (citizen records, employee credentials, GitLab source code for ANCPI systems) put up for sale July 15. KELA identified the actor as Zakaria Mahdjoub of Oran, Algeria (handle ByteToBreach), who also breached Sweden's e-government portal in 2026. Offline backup confirmed to exist; recovery underway. Attack vector: valid credentials β no software exploit. Cybernews Β· Help Net Security Β· The Record Β· Risky Business
Anubis ransomware claims Fairlife (Coca-Cola) attack β group identified β ~1TB data, ransom deadline this week (UPDATE)HighAnubis RaaS (emerged December 2024) added Fairlife to its data leak site July 21, claiming approximately 1TB of corporate data and threatening publication unless Coca-Cola enters negotiations by end of the week. Coca-Cola had disclosed the attack July 16 (no group named at that time) and confirmed unauthorized third-party access to Fairlife's IT environment via SEC filing; all US dairy production suspended; Canadian operations unaffected. π₯ Data scope and exfiltration volume are Anubis claims only β verify before treating as confirmed. BleepingComputer Β· Cybernews Β· Coca-Cola IR
Craneware breach β healthcare financial software vendor, 2,000+ US hospitals affected β disclosed July 20HighEdinburgh-based Craneware (CRWR.L) disclosed unauthorized access to a subset of its data environment; a "significant volume of file names" was exfiltrated along with employee data and some customer/partner records. Company assesses much affected data is non-sensitive regulatory data. Services not disrupted; no remaining indicators of compromise; FBI and UK ICO notified. Craneware's financial performance platform is used by 2,000+ US hospitals, clinics, and pharmacies β supply-chain risk for patient billing and healthcare operations data. No group or actor has claimed responsibility. TechCrunch Β· SC Media
JADEPUFFER EncForge β AI-infrastructure ransomware returns to previously compromised server β July 21 updateMediumJADEPUFFER (agentic threat actor, first documented Sysdig July 1 via CVE-2025-3248/Langflow RCE) returned to the same previously compromised server and deployed a compiled EncForge binary targeting ~180 AI/ML file extensions (Hugging Face SafeTensors, PyTorch/TensorFlow checkpoints, llama.cpp GGUF weights, FAISS vector indices, LoRA adapters). The operator executed via the Langflow RCE channel, encoding scripts as base64 inside exec() calls to evade shell-level detection. Full operator-to-encryption run: 5 minutes 24 seconds. Potential losses: up to $500K per retrained model (single victim estimate). Pattern of return visits to known-compromised AI infrastructure now confirmed across two separate incidents. Sysdig blog Β· Help Net Security Β· The Hacker News
Emsisoft Q2 2026 ransomware report β 2,252 victims, 90 active groups, 99 countries β The Gentlemen overtakes QilinMediumQ2 2026 disclosed victims: 2,252 (down 15% QoQ from Q1's elevated pace, but up 51% YoY). The Gentlemen moved to #1 by named victim count; Qilin #2; Deadlock broke 11 months of silence with 75 June victims. US absorbed ~49% of victim activity; professional/scientific/technical services led for a fifth consecutive quarter. Deadlock's blockchain C2 and kernel-level EDR termination are flagged as the most significant new technique of the quarter. Emsisoft Β· ReliaQuest
π CRITICAL VULNERABILITIES¶
CVE-2026-50522 β SharePoint Server pre-auth RCE CVSS 9.8 β watchTowr PoC published July 20, exploitation confirmed in honeypots within hoursCriticalDeserialization flaw in SharePoint Enterprise Server 2016, 2019, and Subscription Edition; unauthenticated, no user interaction required. watchTowr published a public PoC approximately July 20; exploitation captured in honeypots within hours. Critical operational note: attackers steal IIS machine keys in a single HTTP request β persistence survives patching unless keys are also rotated. Distinct from CVE-2026-58644 (unauthenticated RCE, in CISA KEV since July 16). Organizations must patch AND rotate machine keys. Not yet in CISA KEV as of this briefing. The Hacker News Β· BleepingComputer Β· SecurityAffairs
CVE-2026-6875 β ServiceNow AI Platform pre-auth RCE β exploitation confirmed July 18-21, actively ongoingCriticalCode injection vulnerability allowing unauthenticated attacker to escape the ServiceNow script sandbox and achieve remote code execution on any targeted instance. Discovered April 2026 (Searchlight Cyber); hosted ServiceNow instances patched immediately; self-hosted patches available since June 2026. First wild exploitation confirmed July 18 by Defused; active as of July 21. ServiceNow states no evidence of impact to its hosted instances β risk is concentrated in self-hosted deployments. Help Net Security Β· The Hacker News
CISA KEV July 21 additions β WordPress wp2shell chain now formally KEV, plus Langflow and legacy DD-WRTHighCISA added four CVEs to its Known Exploited Vulnerabilities catalog on July 21, 2026: CVE-2026-63030 (WordPress Core REST API interpretation conflict, the wp2shell pre-auth RCE chain) + CVE-2026-60137 (WordPress Core SQL injection, same chain) β both already exploited in the wild as of July 20; CVE-2026-0770 (Langflow untrusted control sphere, exploited by JADEPUFFER and others); CVE-2021-27137 (DD-WRT stack-based buffer overflow β a 2021 CVE now formally in KEV indicating active exploitation of legacy router firmware). FCEB deadline: August 11, 2026. CISA
CVE-2026-0257 β Qilin affiliates now confirmed weaponising PAN-OS GlobalProtect authentication bypass for ransomware deploymentHighArctic Wolf Labs confirmed multiple intrusions since June 2026 starting with CVE-2026-0257 exploitation (CVSS 7.8, GlobalProtect portal/gateway auth bypass when override cookies are enabled) and progressing within hours to LSASS credential harvest, AD traversal, and domain-wide Qilin encryption. Patched by Palo Alto May 13; unpatched GlobalProtect deployments are at direct ransomware risk. Indicators include staging in C:\PerfLogs\, PsExec lateral movement, event log clearing. Arctic Wolf Β· The Hacker News Β· BleepingComputer
π¨ INTELLIGENCE AGENCY ALERTS & POLICY¶
CISA adds 4 KEVs July 21 β WordPress (wp2shell pre-auth RCE chain), Langflow, DD-WRTHighAs detailed in the Vulnerabilities section: CVE-2026-63030, CVE-2026-60137, CVE-2026-0770, CVE-2021-27137. FCEB deadline August 11, 2026. CISA alert
Spain fines 23andMe β¬3M β GDPR security failure ruling β genomics data governance precedentMediumSpain's data protection authority (AEPD) fined 23andMe β¬3M for failing to implement adequate security measures before its 2023 breach (6.9M+ individuals' health/ancestry data exposed). 23andMe filed for bankruptcy March 2025; data is now managed by a trustee. The ruling β arriving as regulators increasingly scrutinise genomics companies' breach-bankruptcy trajectories β is a precedent for GDPR enforcement on specialty biodata categories. The Record
π THREAT ACTOR & CAMPAIGN ACTIVITY¶
Ransomware DLS movement (July 21-22):
DeadlockCriticalMost active group on DLS as of July 22: 11 new victims posted in the last 24 hours, sectors concentrated in Construction & Engineering and Professional Services. 80+ victims total since emerging in June 2026 (75 June victims broke 11 months of silence). 57% of victims are in the Europe/Russia region. Technical differentiator: C2 proxy addresses stored in public Polygon blockchain smart contracts β traditional domain/IP-based takedowns are ineffective; operators update addresses via immutable blockchain transactions. Also deploys a kernel-mode driver exploit to terminate EDR processes entirely before encryption, removing telemetry defenders depend on. Combination of blockchain C2 and kernel EDR termination is the most operationally significant new technique documented in the Emsisoft Q2 report. Group-IB Β· Infosecurity Magazine Β· Emsisoft Q2
QilinHighCVE-2026-0257 campaign confirmed (see Vulnerabilities); PP+K (US advertising, π₯ Jul 19), Synergy Products (US tech, π₯ Jul 19) on DLS. Running total: 2,035+ named victims as of July 20; 1,358 over April 2025βMarch 2026 (Emsisoft). Still #1 by long-term volume despite The Gentlemen overtaking in Q2 count. The CVE-2026-0257 GlobalProtect campaign suggests Qilin affiliates have adopted a systematic VPN-credential harvesting pipeline as an initial access vector, complementing the FortiBleed-style campaigns attributed to INC/Lynx in prior briefings.
AnubisHighClaimed Fairlife / Coca-Cola (US food/beverage, ~1TB, π₯ Jul 21); also claimed Bath Fitter (US manufacturer, π₯ Jul 20). Anubis is a RaaS operation that emerged December 2024 and uses a double-extortion model; no encryption capability confirmed in some cases β verify ransom mechanism before responding to extortion claims.
SafePayHighCoordinated Germany spree July 20: 7 German victims in a single day β Stroebel Gruppe (industrial), WDK Deutsche Herstellerverband (manufacturers association), Jaecklin Industrial GmbH, LBB Treuhand GmbH (tax consulting), TimeTEX GmbH (educational supplies), Cenesco GmbH (IT solutions), Mende Grundbesitz GmbH (real estate). All π₯ DLS claims; data scope unconfirmed. SafePay's concentrated German industrial targeting pattern in July merits attention for organisations in the DACH manufacturing and industrial sector.
CoinbaseCartelMediumClaimed Caterpillar Inc. (US heavy equipment manufacturing, π₯ Jul 20). CoinbaseCartel is a data-theft/extortion operation (no encryption); initial access primarily via infostealer credential reuse; 160+ victims since September 2025. Verify before treating as a breach β the group has a history of misidentified targets and recycled data.
π GEOPOLITICS¶
Analyst lens: how this week's cyber activity maps to state strategy. Defense Β· cyber Β· economics.
Romania's national land registry destruction is a structural warning for EU public digital infrastructure: credential-based attacks on government data stores are existential, not just disruptive.CriticalByteToBreach used valid credentials β not a zero-day β to wipe a country's entire cadastral database. Romania's market halt (property sales, notary services, government applications) lasted days and required rebuilding from scratch. The structural lesson is narrow but important: government agencies holding irreplaceable registries often prioritize availability over least-privilege and offline-backup discipline, creating a category of attack where even a single compromised credential produces national-scale impact. Similar registries exist across the EU; the ANCPI incident is a forcing event for reviewing privileged access and offline backup posture on critical government data stores. Cybernews Β· Rescana analysis
The US-Israel-Iran conflict's transition to a sustained ambiguous phase has specific cyber implications: less predictable Iranian operations, active CyberAv3ngers persistence in US water/wastewater, Chinese dual-use technology supply routes into Iran remaining open.CriticalFollowing the brief June 14 ceasefire and its violation July 7 (Iranian Hormuz maritime strikes; US retaliation against 80+ targets), CSIS analysis describes the current phase as "sustained ambiguous confrontation" where cyber operations fill the space between overt kinetic action. Iranian cyber capability is preserved (operators distributed outside Iran via Starlink/diaspora networks); CyberAv3ngers remains active against US OT/ICS in water and power sectors; and Chinese companies continue supplying dual-use technology (missile components, geospatial intelligence) to Iran. For portfolio companies: the threat model from the conflict period does not expire on ceasefire β the actor capability and targeting intent persist. CSIS Β· Flare
Deadlock's blockchain C2 infrastructure represents a structural shift in ransomware resilience that law enforcement interdiction cannot solve with existing tools β a meaningful escalation in criminal infrastructure sophistication.HighTraditional ransomware C2 takedowns (domain seizures, IP blocking, hosting provider notifications) are the primary infrastructure-disruption lever available to law enforcement short of indictment. Deadlock's Polygon smart contract C2 β where proxy addresses are stored on a public decentralized blockchain β removes that lever entirely: there are no domains to seize, no IPs to block, no hosting provider to notify. Defenders must instead detect the behavioral signature of blockchain API calls from within the network (anomalous outbound HTTPS to Polygon/Alchemy RPC endpoints) or apply kernel-driver telemetry to catch the EDR termination step before encryption begins. Neither is a standard SOC playbook item. Group-IB Β· SC Media
Spain's β¬3M fine against 23andMe signals that EU data protection authorities are preparing to hold genomics companies' post-bankruptcy estates accountable β a pattern with implications for any portfolio company holding sensitive biodata.MediumThe AEPD ruling applies GDPR's security obligations (Art. 32) to breach failures that predated 23andMe's 2025 bankruptcy. The precedent matters because it establishes that a bankruptcy filing does not extinguish regulatory liability for prior data security failures β and that a trustee managing a bankrupt data estate can face enforcement. For portfolio companies in digital health, genomics, or any specialty biodata category: the EU enforcement queue will not wait for corporate restructuring to conclude. The Record
M&A activity
Socure β Fravityβ
Brinqa β PlexTracβ
Munich Re (via HSB) β $575Mβ
Fortinet β Virtue AIβ