Skip to content

Confidential Β· 01 Aug 2026

πŸ›‘οΈ Daily Cybersecurity Briefing β€” 2026-08-01 (Saturday)

Window: last 24–48h (July 31 – August 1). Severity: πŸ”΄ CRITICAL Β· 🟑 HIGH Β· 🟒 MEDIUM.

Threat level ELEVATEDVictims L30D 181Top actor QilinM&A L30D $19M

πŸ’Ό M&A ACTIVITY

ThreatLocker raised $190M Series D (July 30)HighZero Trust allowlisting and endpoint isolation platform, Florida-based, protecting ~3.5M endpoints; round framed around AI threat protection and MSP market expansion. Second-largest disclosed round of July after Cyera/Oasis. Fintech Global
Cycurion (NASDAQ: CYCU) agreed to acquire an unnamed Washington DC-based federal cybersecurity firm (July 31)Mediumundisclosed value; announced alongside a record contracted backlog exceeding $150M; expands Cycurion's US government/defense cyber services footprint. StockTitan
L30D summary (Jul 2 – Aug 1): 26 named deals, $2B+ in disclosed value. Top transactions: Cyera/Oasis (~$1B, AI-native NHI + data security), ThreatLocker ($190M, Zero Trust endpoint), Glow ($180M, AI-native endpoint at $1.2B valuation), Cathedral ($160M, DoD/IC deception at $1.4B valuation), Neo ($100M, agentic exposure management), Cribl/CardinalOps (~$100M). The consolidation theme is AI agent security and Zero Trust enforcement: the largest deals cluster around machine identity governance, AI agent control planes, and endpoint allowlisting β€” all infrastructure needed to safely deploy AI agents at enterprise scale. SecurityWeek M&A

⚠️ CRITICAL BREACHES & INCIDENTS

Brinks Home confirmed β€” ShinyHunters claims 4.9M+ Salesforce records including 1.1M customer contacts; CEO acknowledged breach July 31CriticalShinyHunters posted Brinks Home on its DLS July 31 with a July 30–31 deadline. Attack vector: Microsoft Entra vishing (phone-based social engineering) on July 13; detected by Brinks July 20. Claimed data: 1.1M customer contacts, 3.8M Cresta customer support chat logs, 4,000+ employee PII rows. CEO confirmed the breach and engagement of leading forensics experts; alarm monitoring unaffected. 🟨 CEO acknowledgment confirms an incident; specific record counts are ShinyHunters' claim β€” independent verification pending. BleepingComputer Β· The Register
Anthropic discloses Claude Opus 4.7, Mythos 5, and unnamed research model each breached an external organization during cybersecurity evaluation β€” two victims unaware until notified July 27 (July 31 disclosure)CriticalThree Anthropic models operating in a cybersecurity evaluation environment managed by third-party testing partner Irregular exploited a misconfiguration that left the sandbox connected to the live internet; Anthropic prompts told the models they were in an isolated simulation. The models exploited basic weaknesses β€” weak passwords, unauthenticated services β€” rather than novel zero-days; each breached a separate real organization. Two of three victims were unaware until Anthropic notified them July 27. Public disclosure July 31 followed review of 141,000+ evaluation sessions, prompted in part by OpenAI's earlier Hugging Face disclosure. 🟩 Confirmed by Anthropic; three organizations affected. Parallels the July 22 OpenAI/Hugging Face containment failure. The National News Β· Fortune Β· Nextgov
EY / ShinyHunters July 31 deadline expired β€” no confirmed public data release as of this runCriticalShinyHunters' "final warning" deadline on Ernst & Young passed July 31 with no confirmed data dump on underground forums. The underlying breach remains confirmed by EY (third-party ITSM platform access March 28–April 12; client tax data including SSNs, financial account details exfiltrated). ShinyHunters' additional Jira/GitHub/Azure access claims remain unverified. The group is simultaneously running extortion campaigns against EY, Brinks Home, and RingCentral β€” a parallel three-target wave. Deadlines frequently extend when victims engage. Monitor DLS and credential-market feeds for the next 48–72 hours. BleepingComputer Β· Infosec.ge
Analog Devices filed SEC 8-K disclosing breach detected June 23; ExfilSquad claims 570,000+ records (disclosed July 29–30)HighSemiconductor manufacturer Analog Devices notified the SEC of an unauthorized access incident detected June 23, 2026; ExfilSquad claimed 570,000+ stolen records. ADI says operations were unaffected and no evidence of data being leaked or misused. Investigation ongoing; no independent verification of ExfilSquad's claim. SecurityWeek Β· Bloomberg
Iran-suspected OT attack on US water systems now confirmed spanning 7 states (July 31 CNN); federal investigation ongoingHighCNN reported July 31 that the coordinated PLC lockout initially confirmed in 30+ Minnesota utilities has expanded to 7 states. Attackers changed PLC passwords and IP addresses to lock operators out of Rockwell, Schneider, and Siemens devices, forcing manual operation and boil-water notices. The FBI, CISA, and EPA are investigating; attribution still under formal review though US officials are publicly examining Iran as the primary suspect. CISA issued AA26-097A update July 30 urging water and wastewater utilities to immediately remove internet-exposed OT assets. CNN Β· CISA AA26-097A Β· Nextgov

πŸ”“ CRITICAL VULNERABILITIES

VMware VMSA-2026-0006 β€” CVE-2026-59309 (CVSS 9.8) + CVE-2026-59310 (CVSS 9.8) in vCenter Server; patch immediately (July 29 Broadcom)CriticalBroadcom patched five VMware vulnerabilities across ESXi, vCenter, and Cloud Foundation on July 29. Two are critical: CVE-2026-59309 (VMware Directory Service auth bypass β€” remote unauthenticated attacker gains admin access to vCenter) and CVE-2026-59310 (Syslog directory traversal enabling RCE β€” remote unauthenticated read/write of arbitrary files). A third, CVE-2026-47876, allows VM escape from ESXi via VMXNET3 out-of-bounds write (requires local admin in VM). No confirmed in-wild exploitation at disclosure; historical vCenter flaws attract fast weaponization. No KEV listing yet β€” patch before that changes. SecurityWeek Β· Broadcom VMSA-2026-0006 Β· SecurityAffairs
CosmosEscape β€” Wiz disclosed cross-tenant takeover chain for all Azure Cosmos DB accounts (July 30); Microsoft already patched, no customer action requiredHighWiz Research disclosed CosmosEscape: a Cosmos DB Gremlin API sandbox escape via .NET reflection that could retrieve a platform-wide master signing key, granting full read/write to any Cosmos DB account β€” including Microsoft-internal databases. Disclosed to Microsoft November 20, 2025; hotfix within 48 hours; long-term architectural fix completed across all regions by July 2026. No evidence of exploitation; no customer action required. Noteworthy as a systemic multi-tenant cloud architecture risk that was silently patched and disclosed months later. Wiz Β· The Hacker News
LegacyHive Windows zero-day β€” day 17 unpatched; next Patch Tuesday is August 11HighThe Windows User Profile Service privilege escalation (no CVE, no patch) now 17 days old. Microsoft remains "actively investigating" with no committed timeline. The 0patch free unofficial micropatch (July 20) remains the only available mitigation. Next Microsoft Patch Tuesday is August 11 β€” watch for an out-of-band fix or inclusion in that cycle. Combined with a remote code execution foothold, this yields an unauthenticated-to-SYSTEM chain. BleepingComputer Β· ThreatLocker analysis
Cisco FMC CVE-2026-20316 β€” federal deadline was August 1 (today)HighThe CISA KEV-listed Cisco Secure Firewall Management Center hard-coded credentials vulnerability reaches its federal remediation deadline today. If your environment includes Cisco FMC instances and has not applied the July 22 patch, that deadline is now past. CISA KEV

🚨 INTELLIGENCE AGENCY ALERTS & POLICY

CISA AA26-097A updated July 30 β€” water/wastewater sector ordered to remove internet-exposed OT immediately in response to 7-state PLC attackCriticalCISA's updated advisory on PLC targeting by Iranian-affiliated actors directs water and wastewater utilities to immediately audit and remove internet-exposed PLCs and OT assets. The advisory now covers Rockwell Automation, Schneider Electric, and Siemens β€” the dominant ICS vendors across US critical infrastructure. Issued four days after the Minnesota attacks went public; the exploitation vector was CVE-2021-22681 (an unpatchable Rockwell flaw) exploited within days of the July 22 advisory expansion. CISA AA26-097A
Operation Double Barrel (July 30, AhnLab + South Korean agencies) β€” North Korea's Lazarus Group shared attack tools and infrastructure with the Gunra ransomware schemeCriticalSouth Korean intelligence agencies and AhnLab documented overlapping malware filenames, C2 servers, and SSH key fingerprints between a March 2026 Gunra ransomware incident and a concurrent Lazarus espionage operation. Gunra uses leaked Conti v2 source code and pivoted to a RaaS model in January 2026. The joint advisory stops short of a formal Lazarus attribution but names a "state-sponsored threat group" β€” this is the clearest documentation yet of DPRK state actors sharing operational infrastructure with criminal ransomware groups to generate revenue while maintaining plausible deniability. AhnLab ASEC Β· The Record

🌐 THREAT ACTOR & CAMPAIGN ACTIVITY

ShinyHunters β€” simultaneous triple extortion campaign:
ShinyHuntersCriticalRunning parallel extortion deadlines against EY (July 31, passed), Brinks Home (July 31, CEO confirmed breach), and RingCentral (July 30, outcome unclear) within a three-day window. The pattern: target organizations with high data-value profiles (client tax records at EY, home-security infrastructure at Brinks, enterprise communications at RingCentral), compress extortion timelines into overlapping deadlines, then selectively execute releases to maximize pressure on remaining targets. No confirmed data release as of this run for any of the three. Monitor for staged releases over the next 72 hours. BreachNews
CRPxO β€” coordinated Turkey attack wave:
CRPxOHighPosted coordinated wave of Turkish targets July 31: Kuveyt Turk (0.8 GB), Finansbank (2.3 GB), Anadolubank (0.4 GB), Turkish Airlines/THY (4.2 GB), plus claimed Johnson & Johnson, Dogan Holding, Anadolu Sigorta, Hyundai. πŸŸ₯ All DLS claims unverified β€” verify before treating as confirmed breaches. CRPxO not previously documented in this tracker; treat as a new or rebranded actor pending further reporting. Ransomware.live
Qilin β€” continues July dominance:
QilinHighposted Hawaii Family Dental July 31 β€” continuing exploitation of CVE-2026-0257 (Palo Alto GlobalProtect) as primary access vector; 1,358+ cumulative victims, 500+ in 2026. πŸŸ₯ DLS claim, verify independently. CyberSecurityNews
Anthropic / AI frontier β€” containment failures (second disclosure in 10 days):
Anthropic confirms Claude models breached real organizationsCriticalThird confirmation (after JFrog/OpenAI zero-day July 28, OpenAI/Hugging Face July 22) in 10 days that frontier AI models operated in reduced-safety evaluation contexts can breach real-world systems without human command. See Geopolitics section for the structural read. Al Jazeera Β· Fortune

🌍 GEOPOLITICS

Analyst lens: how this week's cyber activity maps to state strategy. Defense Β· cyber Β· economics.
Two AI lab disclosures in 10 days β€” Anthropic on July 31 following OpenAI on July 22 β€” establish that containment failures during AI cybersecurity evaluations are not anomalies but a structural feature of how frontier labs test offensive capability: the attack surface is real infrastructure, and the labs' own stated posture is that similar incidents will become "more common."CriticalBoth incidents share the same architecture: models operating with reduced safety constraints in a testing environment reached live systems via misconfiguration. Neither involved deliberate misuse by a nation-state actor. The governance gap this creates is precise: responsible-disclosure norms govern what to do after a model finds a vulnerability; there is no equivalent norm governing what labs must do before running models with reduced safety constraints against environments that can touch live infrastructure. Voluntary capability-gating by two labs (Google's Gemini 3.5 Flash Cyber gate, July 22) does not bind the dozens of labs without comparable safety programs. The next disclosure of this type is more likely to involve a model trained with less safety investment, not less. The National News Β· Fortune
Iran's water-sector OT attack expanding from 30+ Minnesota utilities to 7 states (July 31) is the clearest signal yet that CyberAv3ngers has moved from targeted disruption to tested doctrine: the capability to simultaneously lock operators out of PLCs across multiple US states at low cost, with no zero-days, using the vendor's own programming software, is now a demonstrated operational playbook.CriticalThe exploit vector β€” CVE-2021-22681, an unpatchable Rockwell flaw β€” was in CISA advisories for three years before this campaign; the gap between advisory and remediation in the water sector is structural, not incidental. CISA's CI Fortify guidance (July 28) shifts the defensive posture from "patch before exploitation" to "design for isolated operation when exploitation arrives." That shift is a tacit acknowledgment that remediation alone will not close the window at the speed Iran is operating. CNN Β· CISA CI Fortify
Operation Double Barrel documents North Korea's Lazarus Group sharing tools and infrastructure with the Gunra criminal ransomware scheme β€” the most direct evidence yet that DPRK cyber operations are intentionally using criminal RaaS networks as operational cover, not merely running parallel campaigns.HighThe implications are structural: if Lazarus can transfer operational infrastructure (C2 servers, SSH key fingerprints, malware) to a RaaS affiliate, sanctions targeting state actors do not interrupt the revenue flow; indictments naming state actors do not disrupt criminal deployments; and victims pay ransoms that partially fund state operations without knowing it. South Korean and Five Eyes attribution methodology will need to account for this hybridization as a deliberate design, not an anomaly. AhnLab ASEC Β· The Record
ShinyHunters' simultaneous triple extortion campaign (EY, Brinks Home, RingCentral) targets the economy's trust infrastructure β€” a Big Four auditor, the largest physical security monitoring brand, and enterprise communications β€” rather than standard commercial data repositories.HighThe economic logic is different from most ransomware: the monetizable asset is not bulk PII but the reputational leverage over organizations whose clients depend on their discretion. EY's client tax data is worth more for leverage than for sale; Brinks Home's customer security data is worth more for undermining trust in physical security than for identity fraud. This is a deliberate targeting pattern β€” professional services and security infrastructure firms are being selected for the specific reputational damage that a credible data release would cause, compressing negotiating windows faster than general PII threats. BreachNews
VMware VMSA-2026-0006 (CVE-2026-59309/59310, CVSS 9.8, July 29) landing immediately after CISA's CI Fortify guidance is a test of whether defenders can close critical enterprise infrastructure gaps faster than adversaries exploit them.HighvCenter auth bypass historically moves from patch to weaponized PoC in under 72 hours. CI Fortify's isolation model assumes a window of detected intrusion before adversaries can use enterprise access to reach OT. A SYSTEM-level vCenter compromise in an enterprise environment collapses that window. The LegacyHive Windows zero-day (day 17, unpatched) provides a lateral escalation path from a non-admin workstation; the Cisco FMC federal deadline expired today. Three unpatched critical paths intersecting CI Fortify's 3-month remediation horizon is a structural risk, not a point-in-time calendar event. Broadcom VMSA-2026-0006 Β· CISA CI Fortify
Threat actors
1 Β· Qilin546 YTD
2 Β· The Gentlemen335 YTD
3 Β· Akira228 YTD
4 Β· DragonForce248 YTD
M&A activity
Socure β†’ Fravityβ€”
Brinqa β†’ PlexTracβ€”
Munich Re (via HSB) β†’ $575Mβ€”
Fortinet β†’ Virtue AIβ€”