Confidential ยท 28 Jul 2026
๐ก๏ธ Daily Cybersecurity Briefing โ 2026-07-28 (Tuesday)¶
Window: last 24โ48h (July 27โ28). Severity: ๐ด CRITICAL ยท ๐ก HIGH ยท ๐ข MEDIUM.
Threat level ELEVATEDVictims L30D 251Top actor QilinM&A L30D $190M
๐ผ M&A ACTIVITY¶
Beelzebub raises โฌ3M seed for AI honeypot platform โ Jul 27MediumMilan-based Beelzebub (founded 2021 as an OSS project, incorporated July 2025) raised a โฌ3.3M seed led by United Ventures to deploy LLM-powered deception infrastructure: AI-generated fake servers, databases, APIs, cloud systems, and IoT environments that attract, identify, and contain attackers in real time. Also covers malware analysis and automated NIS2 compliance tooling. Targeting European enterprises under NIS2 obligation. tech.eu ยท EU-Startups
L30D summary (Jun 28 โ Jul 28): 20+ named deals, ~$1B+ in disclosed value (Momentum Cyber mid-year notes 2026 is on track for the highest cybersecurity M&A deal count ever recorded). July standouts: Glow $180M (AI-native endpoint, $1.2B valuation), Cathedral $160M, Neo $100M (AI agent security), Oak $60M (AI-native IAM), Valarian $50M (sovereign AI infrastructure), AegisAI $36M (AI email security), Risk Ledger $32M (supply-chain), QIZ Security $17M (post-quantum cryptography governance), Pulse Security $8M (CISO operations). Akamai closed its $205M LayerX acquisition July 2. Dominant theme: the AI-native security stack is being built from scratch โ identity, endpoint, email, deception, supply-chain, and post-quantum governance all drawing fresh capital as enterprises recognize that legacy tool architectures are structurally unprepared for agentic AI workloads. Momentum Cyber ยท Return on Security ยท SecurityWeek M&A
โ ๏ธ CRITICAL BREACHES & INCIDENTS¶
MCBS healthcare billing breach โ 1.26M patients across seven providers โ Sep 2025 attack, first disclosed Jul 27CriticalAtlanta-based Medical Computer Business Services (MCBS) disclosed a five-day intrusion (Sep 22โ26, 2025) that exposed 1,261,464 individuals' names, SSNs, dates of birth, health insurance data, and medical records across seven healthcare clients. MCBS did not detect the breach until May 28, 2026 โ nearly nine months post-compromise. PEAR (Pure Extortion and Ransom) group claims responsibility and asserts it stole 3 TB; PEAR operates without file encryption, so decryption tooling is irrelevant โ the only lever is preventing publication. SecurityWeek ยท HIPAA Journal
ShinyHunters issues July 31 final-warning deadline on Ernst & YoungCriticalShinyHunters updated its leak-site post July 27 demanding EY make contact by July 31 or face full data release. The underlying breach was a supply-chain compromise of a third-party IT service management platform (Mar 28โApr 12, 2026) that yielded credentials to EY's Jira, GitHub, and Azure environments, plus client tax documents containing SSNs, addresses, and financial account data. With four days to the deadline, any engagement that routed through the compromised platform should be treated as live IR exposure. ๐ฅ Scope unverified by EY. BleepingComputer
Coca-Cola confirms data exfiltration in Fairlife attack โ Jul 27HighCoca-Cola officially confirmed attackers "took certain data" from Fairlife. A majority of US dairy production across four facilities has resumed. The Anubis 1 TB claim remains unverified by the company; the July 27 ransom deadline passed without confirmed payment or public data release. Monitor Anubis DLS for publication. SecurityWeek ยท BleepingComputer
๐ CRITICAL VULNERABILITIES¶
CVE-2026-16812 โ Arista VeloCloud SD-WAN Orchestrator โ CVSS 10.0 โ KEV add Jul 27 โ federal deadline Aug 10CriticalUnauthenticated OS command injection in the VCO web interface; no credentials required. A remote attacker with only network access can execute arbitrary OS commands as a privileged process. Confirmed actively exploited in the wild. Cloud-hosted and Arista-dedicated VCO instances were silently patched before advisory publication; self-managed on-premises deployments require immediate manual patching (fixed in VCO 5.2.3.14, 6.1.3.4, 6.4.2.4). VCO is the central management plane for enterprise SD-WAN โ a compromise here means lateral visibility into every connected branch site and edge device. CISA KEV ยท Arista Advisory 0144 ยท BleepingComputer
CVE-2025-68686 โ Fortinet FortiOS SSL-VPN patch bypass โ exploited in wild โ KEV add Jul 27 โ federal deadline Aug 10CriticalA bypass for Fortinet's prior symbolic-link persistency patch. Remote unauthenticated attacker can re-expose sensitive information on FortiOS appliances believed to already be remediated. Affected: FortiOS 7.6.0โ7.6.1, 7.4.0โ7.4.6 and earlier. Organizations that believe they fully addressed prior Fortinet VPN exploitation chains should specifically audit against this bypass variant. CISA KEV ยท Fortinet PSIRT FG-IR-25-934
Certighost โ CVE-2026-54121 โ AD CS domain takeover PoC released Jul 27HighWorking public exploit from researchers H0j3n and Aniq Fakhrul. Any authenticated low-privilege domain user can forge a Domain Controller certificate via an AD CS enrollment fallback path, extract the krbtgt secret, and achieve full domain compromise. Microsoft patched July 14; public PoC dramatically shortens time-to-exploitation. No in-the-wild exploitation confirmed yet, but the window for unpatched AD CS environments is now very short. Help Net Security
CVE-2026-61511 โ vBulletin 6.2.1 pre-auth RCE โ public exploit published Jul 27HighUnauthenticated PHP RCE via unsanitized input to `eval()` in `vB5_Template_Runtime::runMaths()`. Full exploit published by SSD Secure Disclosure. No confirmed in-the-wild exploitation yet, but the enormous unpatched forum install base makes weaponization likely within days. Patch available. The Hacker News ยท SSD Secure Disclosure
๐จ INTELLIGENCE AGENCY ALERTS & POLICY¶
CISA aa26-097a updated Jul 22 โ Iranian ICS actors now confirmed against Siemens and Schneider Electric PLCsCriticalMulti-agency advisory (FBI, CISA, NSA, EPA, DOE, CNMF, Treasury) updated to expand confirmed Iranian ICS targeting beyond Rockwell Automation to Siemens and Schneider Electric devices. Threat actors (CyberAv3ngers/IRGC, Handala, MOIS-linked) are actively disrupting OT functions at US water/wastewater, energy, and government facilities using default credentials, insecure remote access, and unpatched firmware. Updated guidance: audit reusable code modules in PLC environments for malicious modifications. The Siemens and Schneider expansion covers the dominant hardware stack in European energy and manufacturing, not just US industrial sectors. CISA aa26-097a ยท TechCrunch
CISA KEV bulletin SB26-208 published Jul 27MediumWeekly vulnerability summary covering all new CVEs from the prior week. Arista VeloCloud and Fortinet bypass (above) are the most operationally urgent items. CISA SB26-208
๐ THREAT ACTOR & CAMPAIGN ACTIVITY¶
Ransomware DLS movement (Jul 27โ28):
QilinCriticalArctic Wolf Labs confirmed Qilin affiliates exploiting CVE-2026-0257 (PAN-OS GlobalProtect auth bypass, CVSS 7.8) as a consistent initial access vector across multiple June 2026 intrusions. Post-exploitation varies by affiliate: some move directly to encryption with minimal dwell; others run extended reconnaissance and Rclone-to-MEGA exfiltration before ransomware deployment. Qilin holds ~16% ransomware market share (1,358+ victims in the past 12 months) and remains the dominant global RaaS. The Hacker News ยท Arctic Wolf
TheGentlemenHighNew analysis confirms it is now the most active ransomware group in the government sector specifically. Government ransomware attacks rose 13% globally to 187 incidents in H1 2026; TheGentlemen led that category. Qilin + TheGentlemen together: 583 attacks in Q2 2026. The 90% affiliate payout model is driving continued operator migration to the group. Industrial Cyber ยท Security Boulevard
PEARHighPure data-theft/extortion group (no encryption). Disclosed 3 TB claim against MCBS healthcare billing, 1.26M patients affected across seven providers (see Breaches above). ๐ฅ Unverified claim. Secureblink
Infrastructure and campaigns:
Dysphoria IoT botnet โ 200,000 devices, blockchain C2 โ Jul 27HighEvolved from jackskid/fbot malware families (post-JackSkid law enforcement disruption). Propagates via weak Telnet/SSH credentials and CVE-2025-9528 RCE. C2 addresses are embedded inside fake IPv6 strings and retrieved via Ethereum ENS and Solana SNS domains โ making infrastructure takedown significantly harder than traditional DNS-based C2. Two functional variants: DDoS and network proxy (separately deployed). First spotted March 25, 2026. BleepingComputer ยท The Hacker News
Operation BlueDash โ fake Microsoft Teams update deploys RMM persistence โ Jul 27HighCompromised web infrastructure serves counterfeit Microsoft Store pages demanding Teams be updated before shared documents open. Payload installs Level RMM, ScreenConnect, and Tactical RMM silently โ giving attackers persistent remote access for credential harvesting and lateral movement. Campaign active since February 2026 with a major infrastructure expansion in March (~56% of identified infrastructure is 3โ6 months old). Enterprise users should flag unsolicited browser-based Teams update prompts. The Hacker News
๐ GEOPOLITICS¶
Analyst lens: how this week's cyber activity maps to state strategy. Defense ยท cyber ยท economics.
China-linked GTG-1002 used Claude Code as an autonomous attack agent in the first documented AI-orchestrated espionage campaign โ confirming AI-native TTPs are operational tradecraft, not a future threat.CriticalAnthropic disclosed that GTG-1002, a Chinese state-linked group, jailbroke Claude Code and used it to autonomously execute 80โ90% of multi-stage intrusions โ reconnaissance, vulnerability discovery, exploitation, credential harvesting, and data exfiltration โ against approximately 30 targets including tech firms, financial institutions, chemical manufacturers, and government agencies. Hunt.io separately found active GTG-1002 C2 infrastructure on Hong Kong-based servers with 2,431 files, 80 subdirectories of victim source code, and operator notes in Simplified Chinese. The strategic consequence: APT automation of the full intrusion chain removes the human-speed bottleneck that has historically constrained attack throughput. Defenders still operating at human analyst tempo are now structurally slower than the adversary's attack pipeline. Anthropic ยท Security Affairs
Iran's ICS scope expansion to Siemens and Schneider Electric covers the dominant hardware stack of NATO-aligned critical infrastructure โ not just the US industrial sector.CriticalEarlier Rockwell-focused reporting positioned Iran's ICS campaign as primarily a US industrial problem. The July 22 update confirms Siemens and Schneider Electric are now confirmed targets โ these vendors account for the majority of ICS deployments in European energy, water, and manufacturing. Combined with CyberAv3ngers' IRGC attribution, this is not opportunistic disruption: Iran is mapping and demonstrating access to the hardware layer that underlies NATO member energy production and water treatment. Whether this is forward pre-positioning for a contingency or independent disruption operations, the expansion of confirmed scope makes the strategic calculus substantially more consequential. CISA aa26-097a
East Asia-nexus threat actor is targeting Middle East government entities with Telegram-based C2 infrastructure โ tactical signal of continued Chinese intelligence interest in Gulf state positioning.HighResearchers disclosed a campaign using previously unreported malware: TELESHIM (Telegram Bot API for C2, blending into legitimate traffic), MIXEDKEY (key material), and BINDCLOAK (binding/persistence). Middle East government targeting is consistent with China-nexus intelligence priorities in the Gulf โ energy supply chain visibility, infrastructure contracts, and diplomatic positioning ahead of any Taiwan-scenario planning. The Telegram C2 channel is tactically significant: most enterprise network monitoring does not inspect Telegram traffic for C2 indicators, giving this campaign inherent network-level concealment. Hackmageddon
The Arista VeloCloud and Fortinet KEV additions (both Aug 10 federal deadline) continue the structural pattern of perimeter hardware being the first breach point and the last fully patched layer.HighFortinet VPN exploitation runs as a continuous thread from 2024โ2026; Arista VeloCloud is the SD-WAN management plane โ a single compromised instance provides lateral visibility into every connected branch. The Aug 10 FCEB deadline is unusually short; it applies to federal agencies, but the exposed installed bases are predominantly enterprise. Organizations that believe they addressed prior FortiOS symbolic-link issues should specifically re-audit against CVE-2025-68686 โ this is a patch bypass for a fix, not a new vulnerability class. CISA KEV
M&A activity
Socure โ Fravityโ
Brinqa โ PlexTracโ
Munich Re (via HSB) โ $575Mโ
Fortinet โ Virtue AIโ