Confidential · 24 Jul 2026
🛡️ Daily Cybersecurity Briefing — 2026-07-24 (Friday)¶
Window: last 24h (July 23–24). Severity: 🔴 CRITICAL · 🟡 HIGH · 🟢 MEDIUM.
Threat level ELEVATEDVictims L30D 282Top actor QilinM&A L30D $36M
💼 M&A ACTIVITY¶
AegisAI — $36M Series A — AI-native email security countering AI spear-phishing surge (Jul 23)MediumBattery Ventures led with Accel and Foundation Capital co-investing; $49M total raised. San Francisco-based AegisAI deploys proprietary LLMs to detect AI-generated spear-phishing before it reaches corporate inboxes; the company reports a 5x surge in AI-crafted spear-phishing volume over the past year. Positions in the same demand wave that AI-enhanced email threats are creating. PRNewswire · TechCrunch
Abstract Security — $25M Series A extension — composable streaming-first SIEM (Jul 23)MediumCheyenne Ventures and AVP co-led; Olive Hill Ventures, Crosslink Capital, and Rally Ventures participated ($50M total). ARR grew 380% YoY, NRR 264% — positioned against monolithic SIEM incumbents as enterprises look to decouple data pipelines from analytics. The SIEM replacement cycle is a long-cycle but high-value motion; these metrics suggest product-market fit past early adopters. PRNewswire · SiliconANGLE
L30D summary (June 24 – July 24): 25 named deals, total disclosed value exceeding $6.1B. July volume: 12 named deals. June anchor: Accenture triple close — Dragos, NetRise, runZero (~$4.17B), the largest single-month cluster of 2026; Booz Allen/Ultra I&C ($720M), Dream Series D ($260M, $3B valuation), 1Password/Apono ($250-300M est.), SailPoint/Entro (~$200M est.). July anchors: CrowdStrike→XM Cyber (IP acquisition), LevelBlue→Trustwave (MSSP consolidation), Qualcomm→SAM Seamless Network (>$150M, secure home gateway AI), Palo Alto→Embrace (DEM/observability), AegisAI ($36M), Abstract Security ($25M), Glow ($180M endpoint AI security, Jul 22), Cathedral ($160M military cyber AI, Jul 22). Momentum Cyber mid-year: H1 2026 = 219 transactions, $9.1B disclosed value. Funding concentrated in AI-native detection, composable security operations, and OT/ICS. Momentum Cyber
⚠️ CRITICAL BREACHES & INCIDENTS¶
Origin Energy (Australia) — 4.8 million customers breached — names, addresses, DOBs, partial payment details — Jul 23CriticalAustralia's largest electricity retailer confirmed unauthorized access and data exfiltration July 23. Exposed fields: full names, residential addresses, dates of birth, phone numbers, account details, and partial payment card/bank account data (last four card digits or last three bank account digits). No confirmed attribution. Origin has engaged ACSC and Australian Federal Police; investigation ongoing. Scale makes this the largest confirmed energy-sector breach of 2026 to date. The Record · BleepingComputer
Abbott Laboratories — simultaneous dual extortion campaigns — ShinyHunters (Exact Sciences SSO) + ShadowByt3$ (LabCentral API) — Jul 21-23HighAbbott is simultaneously investigating two distinct extortion incidents. First: ShinyHunters compromised Abbott's Entra SSO connecting to Exact Sciences systems in mid-June via vishing; DLS deadline extended to July 21. Second: ShadowByt3$ claims API exfiltration from the LabCentral customer portal beginning July 4, alleging possession of CE certificates, manufacturing specs, and regulatory documents. Abbott stated no impact to manufacturing or patient care; scope of confirmed exfiltration unverified for either incident. 🟥 Both are DLS claims under investigation — verify before treating as confirmed breach. BleepingComputer · SecurityBoulevard
JadeProx APT (China-nexus) — TriBack loader campaign across Asia and Latin America — Group-IB report Jul 23HighGroup-IB published analysis of JadeProx, a China-nexus APT deploying a new malware family "TriBack" against Vietnamese public hospitals (medical imaging systems), the Malaysian Ministry of Foreign Affairs, Hong Kong educational infrastructure, and the National Congress of Honduras via spear-phishing. C2 hosted on Alibaba Cloud (Singapore region); actor OPSEC failure exposed the server. Campaign active since April 2026. 🟨 Attribution Group-IB only; no government-level corroboration yet. The Hacker News · GBHackers
Chaos ransomware — msaRAT technique routes C2 through Chrome/Edge WebRTC — significantly harder to detect — Talos Jul 23MediumCisco Talos published analysis of Chaos ransomware deploying msaRAT, a C2 implant that hides command-and-control traffic inside Chromium browser processes via WebRTC, making it indistinguishable from legitimate browser traffic at the network layer. Active in-the-wild double-extortion campaign; no specific named victims disclosed. The technique compounds the existing challenge of distinguishing malicious outbound traffic in environments with high browser usage. Help Net Security · Talos
🔓 CRITICAL VULNERABILITIES¶
CVE-2026-16232 — Check Point SmartConsole unauthenticated admin takeover (CVSS 9.1) — KEV Jul 22, FEDERAL DEADLINE JUL 25CriticalZero-day in Check Point SmartConsole (all supported releases: R81.10, R81.20, R82, R82.10). Unauthenticated remote attacker obtains an application login token and gains full administrative control of the management server, including complete firewall policy read/write access. Actively exploited against "a small number of customers" per Check Point; exploitation requires network access to the Management Server IP. CISA added to KEV July 22 with BOD 26-04 federal deadline July 25. Firewall policy modification by an attacker is a high-consequence pre-sabotage capability. CISA KEV · Rapid7 · The Hacker News
Oracle July CPU — 1,449 patches, 10 CVSS 10.0 flaws — PeopleSoft pre-auth RCE exploited at scale before patch releaseHighOracle's largest-ever quarterly patch release (1,434 CVEs across 334 products). Most operationally urgent: CVE-2026-35278 and CVE-2026-35273 (PeopleSoft PeopleTools pre-authentication RCE chain, CVSS 9.8) were exploited by ShinyHunters against 300+ servers across 100+ organizations before Oracle issued the July 21 patch. Additional CVSS 10.0 flaws affect Access Manager, Coherence, Data Integrator, HTTP Server, WebCenter Content. Organizations on-premises PeopleSoft should treat patching as emergency maintenance. SOCRadar · TechTimes
DEADLINE TODAY (Jul 24) — Three CISA KEV additions from July 21 — WordPress wp2shell RCE chain, Langflow, DD-WRTHighFour vulnerabilities added July 21 carry a federal remediation deadline of July 24. CVE-2026-63030 + CVE-2026-60137 form the "wp2shell" unauthenticated pre-auth RCE chain targeting WordPress 6.9.x/7.0.x via an interpretation conflict and SQL injection (SQL injection carries Aug 4 exception deadline). CVE-2026-0770 (Langflow, unauthenticated RCE via exec_globals parameter). CVE-2021-27137 (DD-WRT router firmware stack overflow — a 2021 flaw now confirmed actively exploited in 2026 at scale). Federal agencies: today is the deadline. CISA Jul 21 alert · Security Affairs
CVE-2026-50522 (SharePoint, CVSS 9.8) — deadline tomorrow Jul 25 — patch and rotate IIS machine keysHighFederal agencies face tomorrow's BOD 26-04 deadline for the fourth SharePoint flaw in this month's active-exploitation wave. Operational reminder: applying the patch alone is insufficient — attackers steal IIS machine keys in a single pre-auth HTTP request and that persistence survives patching. Key rotation is required post-patch. See Jul 23 briefing for full coverage. CISA KEV
🚨 INTELLIGENCE AGENCY ALERTS & POLICY¶
CISA AA26-204A — Laundry Bear (GRU) Zimbra zero-click zero-day — 90 days of email silently exfiltrated — 12-nation joint advisory (Jul 22-23)CriticalCISA, NSA, FBI, DoD, and 12+ allied national agencies published joint advisory AA26-204A attributing an active Zimbra Collaboration Suite exploitation campaign to Laundry Bear (also tracked as Void Blizzard, TA488; GRU attribution). Vulnerability: CVE-2025-66376, a stored XSS in Zimbra Classic UI. Zero-click: victim only needs to view the attacker's email in the webmail interface — no link click, no attachment open. On view, the exploit automatically exfiltrates the last 90 days of emails, all stored passwords, the Global Address List, and 2FA tokens. Exploited as a zero-day since at least July 2025; Synacor patched in November 2025 (ZCS 10.0.18 / 10.1.13). Unpatched servers remain actively targeted. Target scope: NATO member states and Ukraine-aligned government and commercial organizations. This is pre-conflict mass email collection on a scale made possible by automation. CISA AA26-204A · BleepingComputer · The Hacker News
US State Dept — visa restrictions on cyber scam operators and sextortion networks — announced Manila, Jul 23HighSecretary Rubio announced a new visa restriction policy from Manila targeting individuals complicit in cyberscams and sextortion, including immediate family members. Primary target: Chinese transnational criminal organizations operating industrial-scale scam centers in Southeast Asia (estimated $10B+ defrauded from Americans in 2024). The policy expands the consequences regime beyond APT actors to the criminal-state nexus operators running forced-labor scam factory infrastructure across Myanmar, Cambodia, and Laos. State Dept · The Record
🌐 THREAT ACTOR & CAMPAIGN ACTIVITY¶
Ransomware DLS movement (July 23-24):
QilinHighClaimed Recsa (South Africa, business services; recsasec.org) July 22-23, data leak threatened. 🟥 Unverified DLS claim. Volume context: 500+ victims in 2026, 1,496+ in last 12 months — Bitdefender ranks Qilin #1 by volume since June 2025. June volume dipped to ~80 (vs 100+ prior months) but remains dominant. DeXpose · Infosecurity Magazine
DeadlockHigh80+ total DLS victims; 57% Europe-Russia region (Spain 9, Italy 8, Poland 6, Germany 4). Concentrated on construction, engineering, business services. Blockchain C2 (Polygon) and kernel-mode EDR termination remain the operationally significant novel TTPs. Activity steady; no surge in the 24h window. ZeroFox
The GentlemenHigh483+ cumulative DLS victims across 66 countries; 117 claimed in June alone, the highest single-month count recorded for any group since mid-2025. RaaS scaling faster than any tracked group. Halcyon
Market context (Help Net Security Jul 24)Medium146 active ransomware groups currently operating; 61 new entrants between April 2025 and March 2026; 49.3% of victims are US-based; 32 new victims posted in the 24 hours around July 24. Help Net Security
APT / nation-state:
Laundry Bear (Russia, GRU)CriticalZimbra zero-click campaign against NATO governments (see Agency Alerts). Zero-click mass email collection at scale is ISR activity consistent with pre-escalation targeting list construction. This is the most operationally significant new Russian campaign disclosure this week.
UAT-9244 (China-nexus, assessed Salt Typhoon / FamousSparrow cluster overlap)HighActive espionage campaign against South American telecom providers using three custom implants: TernDoor (Windows backdoor), PeerTime (ELF backdoor, BitTorrent-protocol C2), and BruteEntry (ORB scanner brute-forcing SSH/Postgres/Tomcat on edge devices). Lateral pivot via Operational Relay Boxes built on compromised network devices. PRC reach into South American telecom infrastructure adds a region where US and China are actively competing for influence. Cisco Talos
JadeProx (China-nexus)Highsee Breaches. Multi-country espionage footprint with Alibaba Cloud C2; four confirmed target categories across three continents.
Kimsuky (DPRK)HighSouth Korean groupware vendor supply chain intrusion (follow-on to Jul 23 briefing); new Go-based implant variants BirdTroy (HTTP/3 C2) and DriveTroy (Google Drive exfil) expand C2 optionality and complicate detection. Three simultaneous DPRK campaigns active (Kimsuky, PolinRider, Mastra AI npm).
🌍 GEOPOLITICS¶
Analyst lens: how this week's cyber activity maps to state strategy. Defense · cyber · economics.
Laundry Bear's Zimbra campaign (CISA AA26-204A) is the clearest disclosed evidence yet that Russia is conducting automated mass email collection against NATO governments — the zero-click method and 90-day archive scope are designed for constructing targeting lists at pre-conflict intelligence preparation scale.CriticalZero-click exploitation of an authenticated webmail view means GRU is harvesting email archives, contact lists, passwords, and 2FA tokens from every unpatched Zimbra installation that receives a Laundry Bear message — no victim action required. The 12-nation advisory coordination and DoD co-signature signal that Western intelligence communities assess this as active collection against political and military targets, not general espionage. The structural implication: organizations running unpatched Zimbra in NATO or Ukraine-adjacent supply chains should treat patch/migration urgency as equivalent to the SharePoint wave this week. CISA AA26-204A · The Hacker News
Iran's resumed Strait of Hormuz crisis (Trump military strikes July 13, OFAC 50+ entity designations July 14) creates a structural cyber blowback window that has not yet materialized as confirmed attacks — but the historical pressure-response pattern is unambiguous.HighIranian threat actors (Cyber Av3ngers, Tortoiseshell, and affiliates) have responded to prior US military and economic escalation with wiper attacks on Western critical infrastructure, particularly water systems and energy OT. The July 22 AA26-097A update expanding Iranian PLC targets to Schneider and Siemens hardware (alongside the pre-existing Rockwell Allen-Bradley scope) suggests preparation, not just capability. No confirmed retaliatory cyber event as of today; monitor energy, water, and financial sector ICS/OT telemetry for Iranian-nexus indicators in the current window. CISA AA26-097A · Treasury
China's cyber operations are simultaneously expanding geographic scope (South American telecom via UAT-9244, Asian government espionage via JadeProx) and technical depth (AI coding tools in live intrusion chains) — two trends that compound each other as AI accelerates bespoke-tooling development.HighJadeProx's April-July campaign spans Vietnam, Malaysia, Hong Kong, and Honduras — covering both South China Sea-adjacent intelligence targets and a Latin American legislative body that suggests diplomatic intelligence priorities. UAT-9244 adds telecom provider access in a region where PRC is actively competing with the US on infrastructure investment. Chinese state actors incorporating Claude Code and DeepSeek into live intrusion chains (reported September 2025, updated July 2026) removes one of the last friction points in bespoke malware development. The Record · SecurityAffairs
The State Dept visa restriction announcement on cyber scam operators from Manila is the first US policy action specifically targeting the Chinese transnational criminal organizations running industrial-scale scam centers, and signals intent to close the accountability gap between APT-style attribution and the criminal-state nexus that funds and facilitates those same actors.HighScam center operators (Myanmar, Cambodia, Laos) use forced labor to run mass fraud operations estimated to have defrauded Americans of $10B+ in 2024; the criminal infrastructure overlaps with money-laundering channels that also serve state-affiliated cybercrime groups. Visa restrictions extending to family members mirror the Magnitsky-style sanctions pattern already applied to APT actors. The Manila announcement — during ASEAN meetings — frames this as a regional security partnership message, not just unilateral enforcement. State Dept · The Record
Oracle PeopleSoft mass exploitation (100+ organizations before patch release) is an intelligence gap problem: ShinyHunters operated against a pre-auth RCE zero-day in widely deployed ERP long enough to breach at scale — the seven-week window between exploit emergence and Oracle's public disclosure is the structural risk, not the vulnerability itself.MediumPeopleSoft runs HR, financial, and payroll systems for large enterprises; the exfiltrated data from 100+ organizations almost certainly includes workforce personally identifiable information and financial records. The pattern (ShinyHunters using Oracle vulnerabilities for large-scale data theft — see also Estee Lauder Oracle EBS breach Jul 22) is consistent across multiple Oracle product lines, suggesting the group has dedicated Oracle exploitation infrastructure. SOCRadar · TechTimes
M&A activity
Socure → Fravity—
Brinqa → PlexTrac—
Munich Re (via HSB) → $575M—
Fortinet → Virtue AI—