Confidential Β· 30 Jul 2026
π‘οΈ Daily Cybersecurity Briefing β 2026-07-30 (Thursday)¶
Window: last 24β48h (July 29β30). Severity: π΄ CRITICAL Β· π‘ HIGH Β· π’ MEDIUM.
Threat level ELEVATEDVictims L30D 229Top actor QilinM&A L30D $190M
πΌ M&A ACTIVITY¶
No new cybersecurity deals were announced in the July 29β30 window.
L30D summary (Jun 30 β Jul 30): 23+ named deals, ~$2.1B+ in disclosed value. The dominant theme is AI agent security: Cyera/Oasis (~$1B NHI/data security), Glow ($180M AI-native endpoint), Cathedral ($160M DoD/IC deception), Neo ($100M agentic exposure management), Hush Security ($30M machine access governance), and Act Security ($60M agentic control plane) all closed in the last 30 days. Three of the top deals β Cyera/Oasis, Hush, and Act β were announced on a single day (July 28), partly catalysed by the same-day JFrog/OpenAI AI escape-from-containment disclosure. SecurityWeek M&A Β· Momentum Cyber
β οΈ CRITICAL BREACHES & INCIDENTS¶
AnMed Health System β ransomware closes 79 of 106 facilities across South Carolina and Georgia β detected Jul 25-26CriticalUpstate South Carolina regional health system AnMed shut down oncology, radiation, infusion, and imaging services across 79 of its 106 facilities after a cyberattack first detected around July 25-26. A 72-hour ransom demand was issued; deadline has likely passed without confirmed payment. The FBI and South Carolina Law Enforcement Division (SLED) are investigating. Class action investigations are underway. ERs remain open; inpatient capacity is reduced. π¨ Attribution unconfirmed; group not publicly named. HIPAA Journal Β· Healthcare IT News
Conduent breach confirmed at 62.2 million individuals β expanding disclosureCriticalConduent (business process outsourcing giant handling payroll, HR, and healthcare administration for hundreds of large enterprises and government agencies) breach count has grown to 62.2 million individuals per updated notifications as of the July 29 reporting cycle. A single outsourcing intermediary breach at this scale provides attacker access that would otherwise require dozens of separate intrusions β the same structural leverage as the 2023 MOVEit campaign. Kaseya Week in Breach Jul 29
Ernst & Young / ShinyHunters β July 31 deadline in under 24 hours, no resolution confirmedHighShinyHunters' July 31 extortion deadline expires tomorrow. No ransom payment confirmed; no early data release as of July 30. EY has not publicly contacted the group or confirmed the scope of Jira/GitHub/Azure access the group claims. EY is offering 24 months of Experian identity monitoring to affected clients. Any engagement routed through the March 28βApril 12 supply-chain compromise window (third-party ITSM platform) remains live IR exposure. π₯ Data scope unverified by EY. BleepingComputer Β· SecurityAffairs
JadePuffer β first fully autonomous end-to-end AI ransomware documented β Sysdig Jul 2026HighSysdig documented the first ransomware attack where an LLM agent autonomously executed the full kill chain: Langflow exploitation (CVE-2025-3248), lateral movement via Nacos auth bypass (CVE-2021-29441), encryption of 1,342 service configuration items, deletion of originals, and ransom note drop β with no human operator directing individual steps. This is qualitatively distinct from AI-assisted attacks; here the agent owned the entire chain. The economics of ransomware operations shift when operator overhead, coordination cost, and human exposure all decrease. Sysdig Blog Β· BleepingComputer
New ransomware DLS postings β Jul 29MediumSpace Bears posted StellarRAD Systems (US, Technology); Aurora posted Bretford Manufacturing (US, Manufacturing); an unattributed group posted Romania's National Prison Administration (Administratia Nationala a Penitenciarelor). π₯ All DLS claims unverified β verify before treating as confirmed breaches. ransomware.live
π CRITICAL VULNERABILITIES¶
CVE-2026-20316 β Cisco Secure Firewall Management Center β KEV added Jul 29 β hard-coded credential zero-dayCriticalA static low-privilege credential is baked into Cisco FMC software. Unauthenticated remote attackers can use it to log in and access sensitive data; chained with other FMC vulnerabilities, full privilege escalation is achievable. Exploited as a zero-day before Cisco patched or disclosed it β the 7th Cisco network management/SD-WAN zero-day of 2026. CISA added to KEV July 29; US federal agencies have a 21-day mandatory remediation window under BOD 26-04. BleepingComputer Β· CISA KEV
CVE-2026-6875 β ServiceNow AI Platform β CVSS 9.5 β second gadget chain discovered, still not on CISA KEVCriticalA second sandbox-escape gadget chain was confirmed, bypassing defenses specifically tuned to the original PoC. Organizations that blocked the known chain may remain vulnerable. Active exploitation confirmed for 11+ days with no KEV addition. Do not wait for KEV β patch immediately. Self-hosted instances: patch to the July 13 release. Help Net Security Β· TechTimes
CVE-2026-63077 β JetBrains TeamCity On-Premises β CVSS 9.8 β 3 days since disclosure, exploitation window activeHighUnauthenticated RCE via deserialization in the agent polling protocol. No confirmed exploitation yet, but TeamCity on-prem has a documented history of rapid post-disclosure weaponization: previous TeamCity flaws were exploited by APT29, Lazarus Group, and ransomware affiliates within days of disclosure. Patch to 2025.11.7 or 2026.1.3; TeamCity Cloud unaffected. Rapid7 ETR Β· JetBrains Advisory
CVE-2025-66376 β Zimbra Collaboration Suite β zero-click / half-click exploit, Laundry Bear zero-day (Jul 29: pivot to OWA)HighCISA/NSA/20+ partner agencies jointly warned July 23 of Russian Laundry Bear exploiting this Zimbra zero-day to steal emails without victim interaction. On July 29 β within 24 hours of the joint advisory going public β Proofpoint confirmed Laundry Bear pivoted to a new bug: CVE-2026-42897 in Microsoft Outlook Web Access (OWA). The 24-hour retooling cycle is a significant capability signal. Targets: US and European government, telecom, financial, aerospace sectors. The Record Β· Help Net Security
LegacyHive Windows zero-day β 15 days unpatched β 0patch micropatch availableHighThe Windows User Profile Service privilege escalation (no CVE, no Microsoft fix) remains unpatched 15 days after public disclosure. 0patch released a free unofficial micropatch July 20. Microsoft says it is "actively investigating." The flaw bypasses all July 2026 Patch Tuesday updates. Risk is moderate standalone (requires local access), HIGH when chained with a remote foothold. BleepingComputer 0patch Β· The Hacker News
π¨ INTELLIGENCE AGENCY ALERTS & POLICY¶
CISA publicly states adversaries are "already inside" US power grids β demands pre-built isolation plans β Jul 29CriticalA July 29 statement from CISA explicitly named China (Volt Typhoon) and Iran (CyberAv3ngers) as having pre-positioned access inside US electrical grids and critical infrastructure, and is now demanding that critical infrastructure operators have pre-built isolation plans ready to execute. This language goes beyond prior CISA advisories ("potential risk of pre-positioning") to a public admission that hostile actors are already embedded. Context: the CI Fortify 3-month isolation guidance (July 28) was the framework; this is the trigger-level statement that the threat is not hypothetical. TechTimes
Iran-attributed coordinated OT attack on 30+ Minnesota water and wastewater utilities β Jul 26-27CriticalA coordinated attack disrupted automated control functions across 30+ community water and wastewater systems in Minnesota including Plymouth, South St. Paul, Braham, and Maple Plain. Some systems were switched to manual operation; one plant temporarily went offline. No water quality or safety impact reported. MNIT activated statewide cybersecurity incident response; FBI is investigating. Attribution to Iranian-affiliated actors (CyberAv3ngers TTP match) is assessed π¨ partial pending FBI confirmation. CISA had updated its Iranian PLC advisory (AA26-097A) on July 22 to expand scope to Siemens and Schneider Electric PLCs β this attack followed within 4 days. BleepingComputer Β· SecurityWeek Β· Tenable
Laundry Bear multi-agency alert (Jul 23) β Russian state actor exploiting Zimbra zero-click zero-dayHighCISA, NSA, and 20+ partner agencies (Five Eyes) jointly warned July 23 of Laundry Bear (Russian state-sponsored) exploiting CVE-2025-66376 in Zimbra: a zero-click or half-click exploit that activates when a victim opens or previews an email in an unpatched ZCS instance. Targets: US and European government, telecom, financial, hospitality, and aerospace. Goal: email theft and credential/MFA code harvest. July 29 pivot to OWA CVE-2026-42897 noted in Vulnerabilities above. CISA Β· Computer Weekly Β· Dark Reading
DOJ Operation Riptide β 3 Russians + 2 bulletproof hosters indicted for serving LockBit, Cl0p, Play (unsealed Jul 14)HighAlexander Volosovik (43), Kirill Zatolokin (34), and Yulia Pankova (29) plus Medialand LLC and ML.Cloud LLC (St. Petersburg) were indicted for conspiracy to commit computer fraud, wire fraud, and money laundering; $62M+ in victim losses. Infrastructure served LockBit, Cl0p, and Play ransomware affiliates. Investigative partners: FBI, CISA, Dutch National Police, UK NCA, Australian Federal Police. DOJ Β· Tech Times
White House Gold Eagle Initiative β AI-powered vulnerability clearinghouse β launched Jul 15MediumAI-assisted federal vulnerability management clearinghouse under the Trump June 2 AI Executive Order, housed in Treasury and supported by DoD/DHS/CISA. Core platform: Carnegie Mellon VINCE. Frontier AI rapidly identifies, verifies, and prioritises vulnerabilities, then distributes actionable remediation to federal and private sector defenders. Participation largely voluntary. White House Β· The Record
π THREAT ACTOR & CAMPAIGN ACTIVITY¶
Ransomware DLS movement (Jul 29-30):
AnMed Health β Unknown group β 79 of 106 facilities closed, ransomware confirmedCriticalThe most operationally disruptive healthcare ransomware in the July window, covering cancer treatment, radiation, infusion, and imaging services across two US states. π¨ Attribution not yet confirmed. See Breaches above. HIPAA Journal
TheGentlemenHighConfirmed as most active ransomware group in Q2 2026 by The Insurer (July 24 report): 94 victims in June alone (highest monthly single-group total ever tracked), 483 total across 66 countries. 90% affiliate cut mirrors the RansomHub model that drove explosive growth; multi-OS codebase with worm-spreading propagation. Has definitively displaced Qilin as the highest-volume DLS operator. The Insurer Β· Halcyon
SafePayHighLeads July 2026 in raw DLS posting volume. Closed model (no affiliate network), primarily targeting SMBs and MSPs in US, Germany, and UK. 72 claims against German organisations β highest any group for that country. 537 cumulative victims as of July 27. ransomware.live Β· Flare
π₯ Space Bears β Posted StellarRAD Systems (US, Technology) Jul 29. π₯ Verify before treating as confirmed. ransomware.live
π₯ Aurora β Posted Bretford Manufacturing (US, Manufacturing) Jul 29. π₯ Verify before treating as confirmed. ransomware.live
AI-driven campaigns:
JadePuffer β first fully agentic AI ransomware observed in the wildCriticalSysdig documented an end-to-end attack executed entirely by an LLM agent (no human operator directing individual steps): Langflow RCE β Nacos auth bypass β 1,342 service configs encrypted β ransom note dropped. Extends the ai-agent-attacker-tradecraft signal to a new severity tier: autonomous ransomware is no longer theoretical. See also: GTG-1002 (Chinese autonomous espionage, July 20-22) and JFrog/OpenAI zero-day discovery (July 27-28) β three milestones in 10 days removing the human from the loop. Sysdig Β· BleepingComputer
Nation-state campaigns:
Phantom Taurus β Chinese APT, NET-STAR .NET IIS backdoor, targeting Africa/Middle East/Asia government and telecomCriticalNewly named Chinese nexus APT active since 2023, identified by Unit 42. Deploys NET-STAR (.NET backdoor suite: IIServerCore fileless backdoor + two AssemblyExecuter loaders) targeting Microsoft IIS web servers. Pivoted in 2025 from email exfiltration to directly targeting sensitive databases. Infrastructure links to broader Chinese APT ecosystem. Unit 42 Β· SecurityWeek
Armored Likho β newly identified APT targeting government and electric power with AI-assisted BusySnake stealerHighTargets government agencies and electric power organisations in Russia, Brazil, and Kazakhstan. Malware: BusySnake Stealer (Python-based infostealer with embedded reverse SSH tunneling) + Go2Tunnel for remote access. Initial access: spear-phishing disguised as government notices, psychological tests, and social programme documents. First-stage loader code shows inline comments and redundant blocks consistent with LLM-generated output. SecurityWeek Β· The Hacker News
Cl0p / PTC Windchill campaign (ongoing):
Cl0pHighMass exploitation of CVE-2026-12569 (PTC Windchill/FlexPLM unauthenticated RCE) continues across aerospace, automotive, manufacturing, and retail. Victims receiving extortion emails from compromised internal accounts. No DLS listings yet. BleepingComputer
π GEOPOLITICS¶
Analyst lens: how this week's cyber activity maps to state strategy. Defense Β· cyber Β· economics.
Iran hit 30+ Minnesota water utilities with coordinated OT attacks on July 26-27 β four days after CISA expanded its Iranian PLC advisory to Siemens and Schneider Electric β and CISA followed on July 29 with the public admission that adversaries are "already inside" US grids.CriticalThe sequencing is significant: an updated ICS advisory, a multi-site OT attack matching that advisory's threat profile, and then a public admission from the US government that hostile actors are embedded in critical infrastructure. CISA is not warning of a potential future threat; it is publicly confirming an established presence. Iran's OT campaign (CyberAv3ngers, IRGC-affiliated) targeting water and energy infrastructure has been running since at least 2023; July 2026 shows it scaling from individual facility attacks to 30+ simultaneous sites. The operational tempo is accelerating. BleepingComputer Β· TechTimes CISA Β· CISA AA26-097A
Laundry Bear pivoted from the Zimbra zero-click zero-day to a new Microsoft OWA exploit (CVE-2026-42897) within 24 hours of the CISA/NSA multi-agency joint advisory going public β this is the clearest demonstration of Russian cyber-operator retooling speed seen publicly in 2026.CriticalThe joint advisory was designed to force the group off the Zimbra zero-day by publishing IOCs and TTPs; the group responded by shifting to a new, previously undisclosed email-theft primitive before the advisory's ink dried. The strategic read: blanket advisories that burn a zero-day are only as effective as the lag between disclosure and adversary retooling. At 24 hours, Laundry Bear has closed that gap to near zero. For targets in the advisory's scope (US/EU government, telecom, financial, aerospace) the actionable takeaway is to assume Zimbra defenses alone are insufficient and to extend monitoring to OWA audit logs. The Record Β· Help Net Security Β· Computer Weekly
AnMed Health's 79-facility closure illustrates a deliberate coercive calculus: health systems serving two states are being targeted for maximum operational disruption, not because they are strategically significant, but because they cannot afford to negotiate slowly.CriticalWith Affinia Healthcare, MCBS (1.26M healthcare breach), and AnMed all in the July window, and Fairlife/Anubis and the PEAR/MCBS campaign from earlier this month, healthcare is absorbing the highest sustained volume of operationally disruptive attacks across any sector in July 2026. FBI involvement at AnMed signals the US government views this as nationally significant. The ransom-deadline model has shifted from "pay or we release data" to "pay or patients don't receive cancer treatment" β a coercion escalation that has no insurance backstop. HIPAA Journal Β· Healthcare IT News
JadePuffer's fully autonomous ransomware (Sysdig) is the third documented AI capability milestone in 10 days, completing a trajectory: AI autonomous espionage (GTG-1002, July 20-22) β AI zero-day discovery and sandbox escape (JFrog/OpenAI, July 27-28) β AI autonomous ransomware end-to-end (JadePuffer, July 2026).HighEach step removes a human from a stage of the attack chain. The aggregate picture is not "AI makes existing attacks faster" β it is that the structural requirements for a successful attack (operator skill, coordination overhead, human exposure) are all declining simultaneously. The Cisco FMC seventh-zero-day and ServiceNow second-gadget-chain patterns this week show that the defender side is not equivalently compounding: defenders patch one CVE and another appears; they block one gadget chain and another activates. The asymmetry is widening. Sysdig Β· SecurityWeek Cisco SD-WAN
The Conduent 62.2M-person breach illustrates the same structural leverage as the MOVEit and Cl0p supply-chain campaigns: compromising a single outsourcing intermediary provides attacker reach across hundreds of enterprise customers without requiring lateral movement across individual target networks.MediumThe pattern is now well-established: MSPs, BPOs, and IT outsourcers are high-value single points of compromise. Conduent's customer base includes large US government agencies and Fortune 500 enterprises. Third-party vendor risk is not a compliance checkbox problem β it is a structural attack surface that concentrates breach impact at a single node. Kaseya Week in Breach
M&A activity
Socure β Fravityβ
Brinqa β PlexTracβ
Munich Re (via HSB) β $575Mβ
Fortinet β Virtue AIβ