BagheeraAltered's CyberSecurity Newsletter logo

BagheeraAltered's CyberSecurity Newsletter

Archives
Subscribe
July 13, 2026

Your ransomware negotiator might be working for the attackers

This week: a cautionary tale about who you trust during a breach. A former ransomware negotiator, Angelo Martino, was sentenced to 70 months in federal prison for secretly feeding clients' confidential negotiating strategies to the BlackCat/ALPHV gang he was supposedly helping victims fight off, and for conspiring with two other former cybersecurity professionals to deploy BlackCat against additional US targets. The DOJ has seized over $10M in proceeds, from Bitcoin to a fishing boat. It's a reminder that incident response trust models need real access controls and ongoing checks and measures, not just care during the hiring process.

Subscribe to this newsletter
Bagheera Labs speaking at BlackHat this year
Explore our Services

Angelo Martino, 41, of Land O’Lakes, Florida, formerly employed as a ransomware negotiator, was sentenced today to 70 months for his role in conspiring with Blackcat/ALPHV (BlackCat) actors to extort multiple victims, as well as conspiring with other former cybersecurity professionals to attack additional victims in 2023.
https://www.justice.gov/opa/pr/florida-ransomware-negotiator-who-extorted-and-attacked-multiple-us-victims-sentenced-prison

According to cybersecurity researchers, between February 2024 and April 2026, suspected threat actors with ties to China and India engaged in persistent cyber espionage against a number of Pakistani law enforcement agencies. According to a report released this week by Aleksandar Milenkoski, principal threat researcher at SentinelOne SentinelLABS, the hacked assets at Balochistan Police comprised servers hosting web applications that manage police and citizen data, such as criminal and biometric records.
https://www.reconbee.com/hackers-weaponize-balochistan-police-portal-in-multi-group-espionage-campaigns/

Game anti-tamper app Denuvo has been completely bypassed in pre-release versions of Assassin’s Creed Black Flag Resynced, allowing pirates to distribute copies of the game days before its official release. A cracked version of the remake has been circulating since June 7 — more than a month before its July 9, 2026, release date. While the game is a remake of the original Assassin’s Creed Black Flag, which launched way back in 2013, it’s still expected to offer new content and enhanced graphics brought by newer, more capable hardware.
https://www.tomshardware.com/video-games/pc-gaming/cracked-version-of-assassins-creed-black-flag-resynced-leaked-days-prior-to-official-release-despite-denuvo-drm-protection-denuvo-unable-to-stop-crackers-with-some-finding-ways-to-completely-remove-it-from-other-titles

A newly identified malware, dubbed GigaWiper, is posing a significant threat to Windows systems by combining data-wiping functionalities with deceptive ransomware tactics. This sophisticated malware not only erases data but also employs fake ransom notices, leaving victims with irrecoverable losses. GigaWiper’s emergence marks a concerning evolution in cyber threats, as it integrates multiple attack vectors into a single, potent package. Unlike traditional ransomware that encrypts files and demands payment for decryption keys, GigaWiper goes a step further by permanently destroying data, rendering recovery impossible even if a ransom is paid.
https://thedailytechfeed.com/gigawiper-malware-targets-windows-systems-with-destructive-capabilities/

Microsoft has finally released a security update for its Microsoft Malware Protection Engine, which fixes CVE-2026-50656, the Windows Defender local privilege escalation vulnerability triggered by the RoguePlanet exploit.
https://www.helpnetsecurity.com/2026/07/09/microsoft-releases-fix-for-rogueplanet-defender-flaw-cve-2026-50656/

Chinese hackers tracked as 'UAT-7810' are actively evolving their malware to expand their Operational Relay Box (ORB) network by compromising internet-facing networking devices, primarily unpatched Ruckus routers. According to Cisco Talos researchers, the ORB network serves as a secure relay infrastructure for other China-aligned advanced persistent threats (APTs), including UAT-5918.
https://www.bleepingcomputer.com/news/security/chinese-hackers-develop-longleash-malware-to-expand-orb-network/

Microsoft Chose Profit Over Security and Left U.S. Government Vulnerable to Russian Hack, Whistleblower Says. Former employee says software giant dismissed his warnings about a critical flaw because it feared losing government business. Russian hackers later used the weakness to breach the National Nuclear Security Administration, among others.
https://www.propublica.org/article/microsoft-solarwinds-golden-saml-data-breach-russian-hackers

The LockBit ransomware gang has posted nine new victims to its dark web leak site in a single day, the latest sign that one of the world's most notorious extortion brands is still operating well over a year after an international law enforcement takedown tried to shut it down. The fresh listings, dated July 11, name organizations across Europe, the Middle East, and the Caribbean, adding to a steady drumbeat of activity that has followed the group since its infrastructure was seized in early 2024.
https://www.intelfusions.com/news/lockbit-nine-victims-europe-leak-site-july-2026

A high-severity decompress npm vulnerability lets crafted archives write files outside the extraction folder. Tracked as CVE-2026-53486, the flaw carries a CVSS score of 9.1. It sits in a library that npm serves more than 2.8 million times each week. So far, no public proof-of-concept or in-the-wild attack has been confirmed.
https://securityonline.info/decompress-npm-cve-2026-53486

Microsoft has confirmed that Secure Boot certificate updates are failing or being blocked on some Windows 11 PCs due to known issues. The company says it is working with PC makers on a patch, but you may still need to take action if the certificate is blocked for other reasons.In an updated support document first spotted by Windows Latest, Microsoft says it has paused the Secure Boot rollout for some PCs due to potential known issues. If your device is affected, you’ll now see a detailed error message in the Windows Security app.
https://www.windowslatest.com/2026/07/10/microsoft-confirms-secure-boot-update-failing-on-some-windows-11-pcs-promises-a-resolution/

When the Argentine Football Association (AFA) suffered a significant cyberattack, media outlets were quick to cover the fallout. The breach resulted in sensitive database leaks and unauthorized communications originating from official AFA domains, causing severe reputational and operational damage.
https://www.infostealers.com/article/infostealer-malware-triggers-major-database-breach-at-the-argentine-football-association/

Transsion is the world’s fourth-largest smartphone manufacturer. Its brands — TECNO, Infinix, and itel — dominate markets across Africa, South Asia, Southeast Asia, and Latin America. Every one of these devices ships with a first-party Android telemetry framework: Athena for event collection and oneID for cross-app tracking, both reporting to *.shalltry.com.
https://www.nowsecure.com/blog/2026/07/08/what-the-transsion-telemetry-research-means-for-mobile-security/

CVE-2026-15143 is a vulnerability in the file_type content detector of guardrails-detectors affecting Red Hat OpenShift AI-related packages. The flaw arises because attacker-supplied XML Schema Definition (XSD) content is processed without adequate restrictions. By supplying a crafted XSD string, a remote attacker can cause the vulnerable component to initiate server-side requests to arbitrary network locations or access local files. This behavior can expose sensitive information and create unintended access paths to internal services.
https://www.mallory.ai/vulnerabilities/CVE-2026-15143

Accenture Confirms Data Breach as Stolen Azure Keys, Source Code, and Sensitive Credentials Surface. Large consulting firms sit at the center of thousands of customer environments, making them some of the most attractive targets for cybercriminals. Every project they manage, every cloud platform they administer, and every development repository they maintain represents a potential gateway into critical infrastructure. When attackers claim to have stolen sensitive authentication secrets rather than ordinary documents, the consequences can extend far beyond a single organization.
https://undercodenews.com/accenture-confirms-data-breach-as-stolen-azure-keys-source-code-and-sensitive-credentials-surface-on-cybercrime-forums-video

The ransomware landscape continues to expand as cybercriminal groups constantly search for new organizations to compromise. According to threat intelligence monitoring activity shared by the ThreatMon Threat Intelligence Team, two ransomware operations — Bravox and SafePay — have reportedly listed new victims as part of their ongoing campaigns. The reported incidents involve PB Fiduciaire SA, a Swiss financial services organization, and SHW-FR, a Germany-based website domain. While these listings originate from ransomware monitoring sources and have not been independently confirmed by the affected organizations, such claims highlight the continued pressure businesses face from extortion-focused cybercriminal groups operating through underground networks.
https://undercodenews.com/dark-web-recent-claims-bravox-and-safepay-ransomware-groups-reportedly-add-new-victims-in-latest-cybercrime-activity-video

Pharmaceutical giant Novo Nordisk says data related to clinical trial participants was stolen as part of a cyberattack. The affected patient data was pseudonymized and not directly linked to names or other direct identifiers, the company said. The maker of the Wegovy weight-loss drug said the affected data types include patient ID, information on trial participation, gender, year of birth, biomarkers, health/immunogenicity data, and lifestyle factors including smoking status, alcohol use, and BMI.
https://www.theregister.com/security/2026/06/12/novo-nordisk-says-hackers-stole-clinical-trial-data/5254812

An alleged Ryuk ransomware member pleaded guilty in the U.S. for helping deploy attacks on American companies and faces up to 15 years in prison. Armenian national Karen Serobovich Vardanyan (34) pleaded guilty in the U.S. for his role in Ryuk ransomware attacks targeting American organizations between 2019 and 2020. Extradited from Ukraine after his 2025 arrest, he admitted providing initial access to corporate networks that enabled ransomware deployment.
https://securityaffairs.com/195216/uncategorized/ryuk-ransomware-member-pleads-guilty-over-attacks-on-u-s-organizations.html



Don't miss what's next. Subscribe to BagheeraAltered's CyberSecurity Newsletter:
← Newer One in three websites just got a skeleton key Older → Smugness won’t protect Mac Users from this new threat
Share this email:
Share on Twitter Share on LinkedIn Share via email
Powered by Buttondown, the easiest way to start and grow your newsletter.