Confidential Β· 27 Jul 2026
π‘οΈ Daily Cybersecurity Briefing β 2026-07-27 (Monday)¶
Window: last 24β48h (July 25β27). Severity: π΄ CRITICAL Β· π‘ HIGH Β· π’ MEDIUM.
Threat level ELEVATEDVictims L30D 252Top actor QilinM&A L30D $36M
πΌ M&A ACTIVITY¶
Neo emerges from stealth with $100M to secure enterprise AI software β Jul 20MediumA16Z and Bessemer led combined seed + Series A funding for Neo, an agentic-software control platform built by ex-SentinelOne/Wiz/Palo Alto veterans (CEO Nick Warner, former SentinelOne COO). Neo inventories, assesses posture, attributes risk, and enforces policy across AI agents, AI-enabled apps, agentic browsers, and non-human identities β directly addressing the blind spot created when enterprises adopt agentic tools faster than security controls follow. SecurityWeek
Oak raises $60M seed to build AI-native Identity Operating System β Jul 15MediumAccel, Greylock, and CRV co-led the seed round for Oak, founded December 2025 by ex-SentinelOne CEO Shai Morag. The platform replaces fragmented IAM/IGA stacks with a single real-time control plane governing all human, machine, and AI agent identities β already GA and deployed at enterprise scale. Israeli-founded, addresses the identity governance gap that agentic AI workloads are widening. SecurityWeek Β· TechCrunch
L30D summary (Jun 27 β Jul 27): 17+ named deals, ~$800M+ in disclosed value. July alone: Neo $100M, Oak $60M, Cathedral $160M, Glow $180M, Risk Ledger $32M, Valarian $50M, AegisAI $36M, Abstract Security $25M, Cribl/CardinalOps (~$100M), plus Cisco/Zafran strategic, Palo Alto/Embrace, CrowdStrike/XM Cyber IP, Signicat/Inverid, NINJIO/SafeStack. Dominant consolidation theme: AI-native tooling for agentic environments β identity security, endpoint protection for AI workloads, and SOC automation are attracting the largest rounds at the highest valuations, driven by enterprise recognition that existing EDR and IAM controls are structurally unprepared for agentic architecture. Return on Security Β· SecurityWeek M&A
β οΈ CRITICAL BREACHES & INCIDENTS¶
Anubis ransomware / Fairlife (Coca-Cola subsidiary) β ransom deadline reached today, Jul 27CriticalAnubis struck Fairlife on approximately July 16, encrypting Nutanix production systems and claiming exfiltration of 1 TB of data. Fairlife halted US dairy production (Canada unaffected); Coca-Cola filed an SEC 8-K confirming the incident. Anubis set today (July 27) as the ransom resolution deadline. As of this briefing, no ransom payment or public data release has been confirmed. Anubis is a newer RaaS group (emerged late 2024, Sphinx-derived code), and this marks its first confirmed attack on a major US food-and-beverage manufacturer with supply-chain disruption. π₯ Unverified DLS claim β verify before treating data-release reports as confirmed. BleepingComputer Β· SecurityWeek
DHS confirms breach of Homeland Security Information Network (HSIN) β Jul 1 (confirmed), attack late Mayβearly JuneCriticalDHS confirmed attackers compromised HSIN, the classified inter-agency intelligence-sharing platform, gaining access between late May and early June 2026. The attackers stole credential files, ran malicious code, and deleted event logs to cover their tracks. Two automated security alerts were dismissed as false positives before the breach was confirmed β giving threat actors extended undetected dwell time. Classified systems were reportedly not accessed. The House Homeland Security Committee requested a formal classified briefing this week. Attribution not yet public. BleepingComputer Β· Nextgov
Cl0p launching Windchill extortion wave β industrial and defense supply chains targeted β ongoing from Jul 20CriticalCl0p affiliates have been exploiting CVE-2026-12569 (critical unauthenticated RCE in PTC Windchill and FlexPLM, patched June 17) as a zero-day since early June. From July 20, Cl0p began distributing extortion emails (subject: "Windchill PDMLink module serious data leak") to large internal distribution lists at victim organisations. Confirmed victim sectors: aerospace, defense, automotive, manufacturing, medical devices. The attack chains unauthenticated pre-auth disclosure with server-side RCE to deploy JSP webshells and exfiltrate engineering and product design data β then double-extort. Organizations running on-premises Windchill or FlexPLM who have not applied the June 17 patch are likely already compromised. BleepingComputer Β· Ransom-ISAC
π CRITICAL VULNERABILITIES¶
Chrome 150 β 7 memory-safety bugs patched (including 3 critical use-after-free) β Jul 23HighGoogle's latest Chrome stable update (150.0.7871.186/.187) closes seven memory-safety flaws: three critical-severity use-after-free in CameraCapture, GPU, and Network (all Google-discovered), three high-severity use-after-free in Cast, Ozone, and Aura, and one out-of-bounds read/write in V8 (found by OpenAI Codex Security). No in-the-wild exploitation confirmed. Organisations should verify endpoint Chrome versions are at 150.0.7871.186 or higher; auto-update lag can leave enterprise fleets exposed for 48β72h after a release. SecurityWeek
CVE-2026-12569 β PTC Windchill/FlexPLM critical RCE β CVSS 9.8 β actively exploited by Cl0p since JuneHighUnauthenticated deserialization flaw; patched June 17; weaponised as a zero-day before patch release. Now driving active extortion campaign (see Breaches above). Organizations in aerospace, defense, and manufacturing should treat unpatched instances as compromised and initiate forensic review of JSP webshell indicators. Rescana Β· Ransom-ISAC
For reference: CVE-2026-50522 (SharePoint, CVSS 9.8, KEV Jul 22) and CVE-2026-16232 (Check Point SmartConsole, CVSS 9.1, KEV Jul 22) FCEB remediation deadlines were Friday Jul 25 β verify federal and enterprise compliance posture.
π¨ INTELLIGENCE AGENCY ALERTS & POLICY¶
EU filed court cases against four member states for NIS2 non-compliance β Jul 25CriticalThe European Commission formally filed court proceedings against Ireland, Spain, France, and the Netherlands for failure to implement the NIS2 cybersecurity directive into national law by the October 2024 deadline. NIS2 requires mandatory cybersecurity hygiene, incident reporting, and supply-chain security controls across essential and important entities. Court proceedings signal the EU is moving from warning letters to enforcement; fines and compliance timelines will follow. Enterprises operating within EU markets and their supply chains should accelerate NIS2 gap assessments β France and Ireland in particular host significant portions of EU financial and tech sector operations. The Record
UK National Security State Threats Bill took effect β Jul 2026HighThe UK's new security legislation targeting hostile-state actors came into force, expanding the legal framework under which NCSC can compel disclosure and share intelligence with the private sector in the context of state-attributed cyber incidents. Directly complements the NCSC's public posture shift to a state-majority attribution framing for nationally significant incidents. Cybernews
π THREAT ACTOR & CAMPAIGN ACTIVITY¶
Ransomware DLS movement (Jul 26β27):
AnubisCriticalFairlife (Coca-Cola subsidiary, US food-beverage): extortion deadline today. π₯ Unverified DLS claim. BleepingComputer
INC RansomHighHealth Law Advocates (Boston non-profit, legal, Jul 26 posting). π₯ Unverified DLS claim. ransomware.live
Cl0pHighActive extortion campaign targeting PTC Windchill/FlexPLM users across aerospace, defense, and manufacturing (no named victims publicly disclosed by Cl0p yet; extortion direct to victim organisations). BleepingComputer
Broader landscape:
Qilin remains dominant in 2026 overallHigh1,358+ claimed victims YTD, 443% surge over 2025 pace; TheGentlemen displaced Qilin at the top of June's monthly leaderboard with 121 victims (Bitdefender July 2026 Debrief). The Qilin/TheGentlemen competitive dynamic is driving elevated aggregate victim counts, not replacing them. GBHackers
INC Ransom / UTA0533 exploiting SonicWall SMA 1000 CVSS 10.0 zero-daysHighConfirmed ransomware affiliate exploiting CVE-2026-15409 (SSRF) and CVE-2026-15410 (code injection) to achieve unauthenticated root RCE on SonicWall SMA 1000 appliances; active since June 22, three weeks before SonicWall's July 14 hotfix. Post-exploitation toolkit: ROOTRUN (priv-esc), KNUCKLEBALL (Python loader), Suo5 proxy, ORANGETAIL webshell. Any unpatched SMA 1000 appliance should be treated as a potential pre-compromised entry point. Rapid7 Β· Volexity
π GEOPOLITICS¶
Analyst lens: how this week's cyber activity maps to state strategy. Defense Β· cyber Β· economics.
North Korea arrested former military hackers for stealing from its own state banks β a DPRK internal discipline event that reveals the regime's crypto-finance apparatus is under strain.CriticalSouth Korean outlet Daily NK (citing Pyongyang sources, corroborated by CoinDesk and TRM Labs) reported that North Korean spy agencies raided a Pyongyang safe house on July 12, detaining state-trained hackers who had diverted funds from the Central Bank of the DPRK and Foreign Trade Bank into overseas crypto wallets, then converted them via Chinese brokers into USD and yuan. TRM Labs estimates DPRK stole $643M from just two DeFi attacks in H1 2026 β 76% of global crypto theft. That the regime is policing its own cyber corps is significant: it suggests either internal embezzlement is reaching a scale that threatens regime priorities, or the arrests are a public signal to the apparatus that state funds are off-limits. Either reading indicates the state-sponsored hacking infrastructure is not a monolithic tool of the regime β it has its own economic actors with divergent interests. Attribution caveat: Daily NK cites anonymous sources; no government corroboration yet. CoinDesk Β· Daily NK
The DHS/HSIN breach β a government intelligence-sharing network breached twice after false-positive alerts β tests whether the US federal government's own internal security posture can withstand the state-actor tempo it publicly warns about.CriticalHSIN is the network through which classified and sensitive-but-unclassified intelligence is shared between DHS and partner agencies. An attacker who exfiltrates credentials from it gains potential lateral access into participating agencies and their reporting pipelines. The pattern β automated alerts dismissed as false positives, extended dwell time, credential theft, log deletion β is consistent with state-sponsored APT TTPs rather than criminal ransomware. Attribution has not been published. The House briefing request will determine whether this is an isolated misconfiguration or evidence of a broader federal network posture problem. BleepingComputer
Cl0p's shift to PLM-system targeting (PTC Windchill) is a structural escalation in supply-chain leverage: it moves ransomware from operational IT into engineering data for aerospace, defense, and automotive customers β sectors where stolen CAD files, product specifications, and component sourcing data represent sovereign-level IP.HighUnlike generic ransomware hitting HR or financial systems, a Cl0p breach of a Windchill instance at an aerospace prime or defense subcontractor exposes the same product data that adversary states spend years in APT campaigns to steal. Whether or not Cl0p is state-directed is irrelevant to the strategic consequence: engineering IP from defence supply-chain companies is now being exfiltrated at scale by a criminal ransomware group, and that data will eventually reach secondary markets including state actors. BleepingComputer Β· Ransom-ISAC
The EU NIS2 court cases against Ireland, Spain, France, and the Netherlands mark the moment EU cyber policy transitions from a soft-compliance regime to an enforcement regime β and the timing coincides with peak state-actor pressure on European governments.HighFor companies operating in those four jurisdictions, NIS2 non-compliance is no longer a theoretical risk: court proceedings move the compliance clock from "implementation guidance" timelines to legally enforceable fines. Combined with the UK's new State Threats Bill, the European regulatory posture on cyber is hardening on both mandatory reporting and state-actor incident classification β two dimensions that will directly affect how multinationals report and escalate cyber incidents touching EU or UK operations. The Record
M&A activity
Socure β Fravityβ
Brinqa β PlexTracβ
Munich Re (via HSB) β $575Mβ
Fortinet β Virtue AIβ