Confidential Β· 31 Jul 2026
π‘οΈ Daily Cybersecurity Briefing β 2026-07-31 (Friday)¶
Window: last 24β48h (July 30β31). Severity: π΄ CRITICAL Β· π‘ HIGH Β· π’ MEDIUM.
Threat level ELEVATEDVictims L30D 202Top actor QilinM&A L30D $190M
πΌ M&A ACTIVITY¶
No new cybersecurity deals were announced in the July 30β31 window.
L30D summary (Jul 1 β Jul 31): 26 named deals, $2B+ in disclosed value β the busiest single month of 2026 by deal count. Top transactions: Cyera/Oasis Security (~$1B, AI-native NHI + data security), Glow ($180M, AI-native endpoint at $1.2B valuation), Cathedral ($160M, DoD/IC deception at $1.4B valuation), Qualcomm/SAM Seamless (>$150M, IoT network security), Neo ($100M, agentic exposure management), Cribl/CardinalOps (~$100M). The consolidation theme is AI agent security: four of the six largest deals target the machine identity and agent-era attack surface β NHI governance, agentic exposure management, machine access control, and AI-native SOC/SIEM. SecurityWeek M&A Β· Momentum Cyber
β οΈ CRITICAL BREACHES & INCIDENTS¶
Origin Energy confirmed 900,000 customers affected β corrects initial 4.8M-customer estimate from July 24CriticalAustralia's largest electricity and gas retailer publicly confirmed on July 28 that approximately 900,000 current and former customers had data exfiltrated, a significant downward revision from the initial "4.8 million customers at risk" framing in early reporting. Exposed: names, dates of birth, addresses, phone numbers, account details, and partial payment card or bank account data (last four card digits or last three BSB digits). Origin identified the breach on July 22 after initially failing to treat an early July threat signal as credible. Australian Cyber Security Centre, National Office of Cyber Security, Australian Federal Police, and the Office of the Australian Information Commissioner are all investigating. No attribution confirmed. SecurityWeek Β· BleepingComputer Β· Bloomberg
EY/ShinyHunters β July 31 extortion deadline reached today, no confirmed data release or negotiation as of this runCriticalShinyHunters' deadline for Ernst & Young to make contact expired today. As of this briefing, no EY data has appeared on underground forums and EY has not confirmed negotiations. The group claimed a March 28βApril 12 supply-chain compromise of a third-party ITSM platform, exfiltrating client tax documents containing SSNs, bank account details, and tax filing data. Claimed secondary access to Jira, GitHub, and Azure environments remains unverified by EY. EY is offering 24 months of Experian identity monitoring to affected clients. π₯ The next 24β48 hours are the key data-release window; monitor ShinyHunters' dark web site and downstream credential-market activity. BleepingComputer Β· SecurityAffairs
Sapphire Sleet (DPRK) β Amazon attributes debug, chalk, and axios npm supply-chain attacks to North Korean group β 10% of cloud environments hit in 2 hours (July 28-30 disclosure)CriticalAWS published a detailed attribution on July 28β30 linking three separate npm supply-chain compromises to North Korean threat actor Sapphire Sleet (BlueNoroff/Stardust Chollima): `typo-crypto` (March 2025, reconnaissance phase), `debug` and `chalk` (September 2025, simultaneous compromise of two of npm's most-downloaded packages β affected 10% of cloud environments within 2 hours), and `axios` (March 2026, 100M+ weekly downloads). Attack method: social engineering of trusted package maintainers via lookalike npm domains. The wallet-draining payload disguised as crypto utility code sat in the public record as a crypto-theft incident for 10 months before Amazon's attribution linked the campaign to Pyongyang. npm began scanning newly published packages for malware on July 28 β the scan does not retroactively cover the existing registry. The Hacker News Β· BleepingComputer Β· AWS Security Blog
TheGentlemen β DLS posting wave July 30: Indus Protech (India), Malaysian Nuclear Agency (Malaysia), MicroPhase Corp (US)MediumTheGentlemen posted three new victims July 30. Indus Protech Solutions (Chennai, India) is a bulk MRO and supply chain services provider; Malaysian Nuclear Agency is a Malaysian government nuclear research body; MicroPhase Corporation is a US defense electronics and IT company. INC_RANSOM also posted Kontact Consortium India (engineering/manufacturing) July 30. π₯ All DLS claims unverified β verify before treating as confirmed breaches. RedPacket Security Β· ransomware.live
Krybit β LAXAI Life Sciences (India, pharma/CDMO) β DLS Jul 23, highlighted in CYFIRMA Jul 31 weekly reportMediumKrybit claimed LAXAI Life Sciences Pvt. Ltd., a Contract Research, Development, and Manufacturing Organization (CRDMO) in India, on July 23. CYFIRMA's July 31 weekly intelligence report flags Krybit's continued India targeting β the group has now claimed pharma/CRDMO, manufacturing, and government targets across India, Mexico, Vietnam, Taiwan, and Italy in July. π₯ Unverified DLS claim. DeXpose Β· CYFIRMA
π CRITICAL VULNERABILITIES¶
LegacyHive Windows zero-day β 16 days unpatched, Microsoft "actively investigating" β 0patch micropatch availableHighThe Windows User Profile Service privilege escalation (no CVE, no Microsoft fix) reaches 16 days unpatched as of July 31. The free 0patch unofficial micropatch (released July 20) is the only available mitigation. Microsoft has said it is "actively investigating" but has not committed to a patch timeline or out-of-band release. Moderate standalone risk (requires local access); HIGH when chained with a remote code execution foothold β the combination produces an unauthenticated-to-SYSTEM path. The absence of a KEV listing does not reduce urgency. BleepingComputer 0patch Β· The Hacker News
ServiceNow CVE-2026-6875 β second gadget chain still not on CISA KEV, 12+ days active exploitationHighThe second sandbox-escape gadget chain bypassing defenses tuned to the original PoC has now been confirmed exploited for 12+ days with no KEV listing. Organizations that patched the known chain may still be exposed. Self-hosted instances: patch to the July 13 release immediately. Do not wait for KEV. Help Net Security
No new CISA KEV additions were announced on July 30β31. The July 29 addition (CVE-2026-20316, Cisco FMC hard-coded credential) remains the most recent; federal remediation deadline is August 19.
π¨ INTELLIGENCE AGENCY ALERTS & POLICY¶
No new CISA/FBI/NSA/NCSC advisories were published on July 30β31. Standing alerts from this week remain in effect:
CISA CI Fortify OT isolation guidance (July 28) and CISA's July 29 public statement that adversaries are "already inside" US power grids β see July 30 briefing for detail.
Laundry Bear multi-agency joint alert (July 23), including the July 29 pivot to CVE-2026-42897 (OWA) β see July 30 briefing.
Iran-attributed OT attack on 30+ Minnesota water utilities (July 26-27) β FBI investigation ongoing.
π THREAT ACTOR & CAMPAIGN ACTIVITY¶
TheGentlemen continues July's highest-volume ransomware campaign:
TheGentlemenHighJuly 30 DLS additions (Indus Protech, Malaysian Nuclear Agency, MicroPhase) extend a streak of 90+ victims in June alone and 483 total across 66 countries. Closed affiliate model; 90% affiliate cut; multi-OS worm propagation. The Malaysian Nuclear Agency listing is notable β government nuclear research infrastructure in Southeast Asia marks a sector extension beyond the group's typical commercial SMB/enterprise focus. π₯ All unverified. The Insurer Β· Halcyon
DPRK supply chain campaign β Sapphire Sleet:
Sapphire Sleet (BlueNoroff/Stardust Chollima)CriticalAmazon's attribution confirms a multi-year North Korean supply chain campaign targeting the npm JavaScript ecosystem: `typo-crypto` (March 2025) β `debug`/`chalk` (September 2025) β `axios` (March 2026). The pattern is a gradual escalation to progressively higher-download packages: debug and chalk together affect hundreds of thousands of projects; axios exceeds 100M weekly downloads. The stated goal is cryptocurrency theft, but the infrastructure compromise (10% cloud environments penetrated in 2 hours) provides a platform for broader access well beyond wallet-draining payloads. The Hacker News Β· AWS Security Blog
SafePay leads July 2026 in raw DLS volume; TheGentlemen leads in operational disruption:
SafePay: 537 cumulative victims as of July 27; highest volume against German organizations (72 claims). Closed model, SMB/MSP focus.
Qilin: 335 L3M, 546 YTD β still holds the highest cumulative 2026 victim count despite TheGentlemen surpassing it on monthly pace in June.
Cl0p PTC Windchill/FlexPLM campaign (CVE-2026-12569) ongoing β extortion emails from compromised internal accounts across aerospace, automotive, manufacturing.
π GEOPOLITICS¶
Analyst lens: how this week's cyber activity maps to state strategy. Defense Β· cyber Β· economics.
North Korea's Sapphire Sleet campaign β confirmed today after 10 months in the public record β represents a strategic shift: Pyongyang is now using trusted open-source package infrastructure as a persistent revenue and intelligence collection platform, not just a one-time supply chain lever.CriticalThe decision to target npm packages with 100M+ weekly downloads (axios, debug) is not financially motivated opportunism β it is a calculated pivot to infrastructure compromise at scale. The wallet-draining payload is the declared objective; the real asset is the 10% cloud environment penetration achieved in two hours, which gives DPRK actors a latent foothold across a significant fraction of cloud-hosted enterprise code. North Korea has used supply-chain compromise to circumvent financial sanctions before (Lazarus Group / Sony, SWIFT); Sapphire Sleet's npm campaign is the same strategic logic applied to developer tooling. AWS Security Blog Β· The Hacker News Β· The Record
ShinyHunters' July 31 deadline expiring today against EY β the world's second-largest professional services firm β extends a pattern: criminal extortion groups are specifically targeting auditors, accountants, and tax practitioners because the data they hold (SSNs, bank details, fiduciary relationships) is more monetizable than general PII and the firms have reputational exposure that compresses negotiating timelines.CriticalEY's exposure traces to a third-party ITSM platform used by tax-practice staff β a supply-chain vulnerability, not a direct intrusion β which mirrors the structural leverage the same group has used against healthcare and financial targets. The economic read: a single intermediary compromise at a Big Four firm provides access to client tax filings across thousands of corporations and individuals in a single exfiltration. Competitive intelligence value (M&A tax structures, pending transactions) compounds the financial exposure for EY's enterprise clients. BleepingComputer Β· Hackread
Origin Energy's admission that it failed to treat an early July threat signal as credible before 900,000 customers' data was exfiltrated illustrates a recurring pattern in major 2026 breaches: the gap between initial detection and confirmed breach declaration is widening, not narrowing, even for regulated critical infrastructure.HighOrigin identified what appeared to be a potential intrusion in early July, assessed it as not credible, and confirmed the breach only on July 22 β weeks later. Conduent (62.2M individuals), AnMed Health (79 facilities closed), and now Origin all show a common detection failure: the first signal is dismissed or underweighted, and response is triggered only when impact has already spread. CISA's CI Fortify guidance (July 28) is designed to change the playbook β isolation-ready systems allow faster response when the second signal confirms the first β but the window between first and second signal remains the critical vulnerability. SecurityWeek Β· Business News Australia
July 2026 closes with the cyber threat landscape producing its highest-tempo convergence of AI-driven, nation-state, and criminal-extortion incidents in a single month on record β and the defender posture has not kept pace.HighWithin 31 days: the first fully autonomous AI ransomware (JadePuffer), first AI autonomous zero-day discovery (JFrog/OpenAI), Amazon attribution of a DPRK npm campaign running undetected for 10 months, a public admission of adversary presence inside US power grids, 30+ OT systems simultaneously disrupted in Minnesota, and the Conduent breach crossing 62.2M individuals. The structural asymmetry identified in the July 30 briefing holds: each offensive milestone removes a human from the attack chain; each defensive response patches one CVE while another surfaces. Entering August with LegacyHive still unpatched at 16 days, EY data potentially in circulation, and DPRK actors holding npm infrastructure footholds across 10% of cloud environments. Sysdig Β· JFrog Β· CISA
M&A activity
Socure β Fravityβ
Brinqa β PlexTracβ
Munich Re (via HSB) β $575Mβ
Fortinet β Virtue AIβ