Weekly Review, 2026-07-13
Weekly Review - July 13, 2026
Covers 7 daily digests (2026-07-07 to 2026-07-13).
All summaries, analysis, and story clustering are done by an LLM. It may make mistakes and say incorrect things. Check the sources and support the actual journalists.
Top Stories
1. #### Summary
Karen Serobovich Vardanyan, an Armenian national, pleaded guilty in an Oregon federal court to conspiracy and computer fraud related to the deployment of Ryuk ransomware against U.S
3 outlets, 2026-07-11 - severity 3/5
Summary
Karen Serobovich Vardanyan, an Armenian national, pleaded guilty in an Oregon federal court to conspiracy and computer fraud related to the deployment of Ryuk ransomware against U.S. organizations. Vardanyan provided initial access to networks between November 2019 and April 2020, contributing to a broader Ryuk ransomware campaign that extorted millions of dollars in cryptocurrency.
Key Players
- Karen Serobovich Vardanyan (threat actor)
- Levon Georgiyovych Avetisyan (threat
Sources
- Ryuk ransomware member pleads guilty in the US, faces 15 years in prison - BleepingComputer, 2026-07-10 (quality: 19/21)
- Ryuk operator pleads guilty; Blackcat/AlphV conspirator gets nearly 6-year sentence - The Record from Recorded Future News, 2026-07-10 (quality: 20/21)
- Armenian national pleads guilty to Ryuk ransomware attacks - CyberScoop, 2026-07-10 (quality: 19/21)
2. #### Summary
Threat actors are conducting two distinct phishing campaigns: a DEBULL device-code phishing campaign targeting Microsoft 365 accounts and a job-recruitment scam targeting marketing professionals to steal Google credentials
3 outlets, 2026-07-08 - severity 3/5
Summary
Threat actors are conducting two distinct phishing campaigns: a DEBULL device-code phishing campaign targeting Microsoft 365 accounts and a job-recruitment scam targeting marketing professionals to steal Google credentials. The DEBULL campaign utilizes a reusable tooling layer to exploit the Microsoft device login flow, while the job scam uses nested redirects through legitimate platforms like PeopleForce and Salesforce to impersonate major brands.
Key Players
- Storm-2372 (th
Sources
- DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts - The Hacker News, 2026-07-07 (quality: 20/21)
- Big Brand Jobs Scam Targets Marketing Pros' Google Accounts - darkreading, 2026-07-07 (quality: 19/21)
- Fake Netflix, Coca-Cola, and FIFA job scams target marketers - Malwarebytes, 2026-07-07 (quality: 12/21)
3. #### Summary
A contractor for the Cybersecurity and Infrastructure Security Agency (CISA) accidentally leaked privileged Amazon Web Services (AWS) GovCloud keys and other sensitive credentials to a public GitHub repository
2 outlets, 2026-07-11 - severity 3/5
Summary
A contractor for the Cybersecurity and Infrastructure Security Agency (CISA) accidentally leaked privileged Amazon Web Services (AWS) GovCloud keys and other sensitive credentials to a public GitHub repository. Following the discovery of the CISA GitHub credential leak, the agency conducted a forensic analysis and released an after-action report detailing its response and planned improvements to its security processes.
Key Players
- Cybersecurity and Infrastructure Security Ag
Sources
- CISA looks to remedy ailments from big May credential leak - CyberScoop, 2026-07-10 (quality: 20/21)
- CISA details security lapses that led to GitHub leak of passwords, cloud access keys - Cybersecurity Dive - Latest News, 2026-07-10 (quality: 20/21)
4. #### Summary
A suspected China-aligned threat cluster, tracked as UNK_MassTraction, is conducting an UNK_MassTraction campaign targeting physics and engineering departments at U.S
2 outlets, 2026-07-07 - severity 3/5
Summary
A suspected China-aligned threat cluster, tracked as UNK_MassTraction, is conducting an UNK_MassTraction campaign targeting physics and engineering departments at U.S. and Canadian universities. The attackers exploit a chain of vulnerabilities in the Roundcube open-source email client to steal credentials and establish persistent access to mail servers via webshells or backdoors.
Key Players
- UNK_MassTraction (threat actor)
- Proofpoint (researcher)
- Greg Lesnewich (research
Sources
- Suspected Chinese espionage group used a Roundcube exploit chain to burrow into universities - CyberScoop, 2026-07-07 (quality: 20/21)
- Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities - The Hacker News, 2026-07-07 (quality: 20/21)
5. #### Summary
The Cavern Manticore campaign involves an Iranian-linked threat actor using a modular command-and-control (C2) framework named Cavern to target Israeli organizations, specifically within the government and IT provider sectors
2 outlets, 2026-07-07 - severity 3/5
Summary
The Cavern Manticore campaign involves an Iranian-linked threat actor using a modular command-and-control (C2) framework named Cavern to target Israeli organizations, specifically within the government and IT provider sectors. The actor leverages software supply chain vulnerabilities, such as SysAid's update feature, to deploy the framework and move laterally through trusted service-provider relationships.
Key Players
- Cavern Manticore (threat actor)
- Ministry of Intelligenc
Sources
- Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations - The Hacker News, 2026-07-06 (quality: 20/21)
- Iran-Linked Hackers Using Modular C&C Framework in Cyberattacks - SecurityWeek, 2026-07-07 (quality: 20/21)
6. #### Summary
The threat actor UAT-7810 is expanding its Operational Relay Box (ORB) network by compromising internet-facing networking devices, specifically Ruckus and ASUS routers
2 outlets, 2026-07-08 - severity 3/5
Summary
The threat actor UAT-7810 is expanding its Operational Relay Box (ORB) network by compromising internet-facing networking devices, specifically Ruckus and ASUS routers. To support this expansion, the actor has developed LONGLEASH, an upgraded version of the previously documented SHORTLEASH malware, alongside several other new tools.
Key Players
- UAT-7810 (threat actor)
- UAT-5918 (threat actor)
- Cisco Talos (researcher)
- Google Mandiant (researcher)
- SecurityScorecard (res
Sources
- Chinese hackers develop LONGLEASH malware to expand ORB network - BleepingComputer, 2026-07-07 (quality: 19/21)
- China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware - The Hacker News, 2026-07-08 (quality: 20/21)
7. #### Summary
Spanish National Police arrested a man in Palencia suspected of being an active member of the pro-Russian hacktivist groups CyberArmy of Russia Reborn (CARR) and Z-Pentest
2 outlets, 2026-07-08 - severity 3/5
Summary
Spanish National Police arrested a man in Palencia suspected of being an active member of the pro-Russian hacktivist groups CyberArmy of Russia Reborn (CARR) and Z-Pentest. The suspect is alleged to have provided logistical support to a Ukrainian hacker and participated in actions attributed to NoName057(16).
Key Players
- CyberArmy of Russia Reborn / Cyber Army of Russia Reborn (threat actor)
- Z-Pentest (threat actor)
- NoName057(16) / NoName (threat actor)
- APT44 / Sandwor
Sources
- Spain arrests suspected member of pro-Russian hacktivist groups - BleepingComputer, 2026-07-07 (quality: 19/21)
- Spain arrests suspected hacker linked to Russian hacktivist campaign - CyberScoop, 2026-07-07 (quality: 20/21)
8. #### Summary
A threat actor using the handle 888 claimed to have stolen approximately 35GB of data from Accenture, including source code and various access keys
2 outlets, 2026-07-09 - severity 3/5
Summary
A threat actor using the handle 888 claimed to have stolen approximately 35GB of data from Accenture, including source code and various access keys. Accenture confirmed the incident but stated that the source has been remediated and there is no impact to its operations or service delivery.
Key Players
- 888 (threat actor)
- Accenture (victim)
- Peter Soh (Accenture spokesperson)
- SOCRadar (threat intelligence firm)
- Ross Filipek (CISO, Corsica Technologies)
Sequence of
Sources
- Accenture faces massive data breach that could put clients at risk - Cybersecurity Dive - Latest News, 2026-07-08 (quality: 20/21)
- Accenture Confirms Data Breach After Hacker Claims Source Code Theft - SecurityWeek, 2026-07-08 (quality: 18/21)
Under the Radar
High-severity stories that received limited coverage this period.
No high-severity under-covered stories this period.
All Stories by Category
Other Cybersecurity
- Supreme Court Allows Enforcement of the Texas App Store Accountability Act (2026-07-08, 2 outlets, severity 3/5)
- Supreme Court allows Texas app law requiring age verification to take effect - The Record from Recorded Future News
- SCOTUS Broadens White House Influence Over ‘Independent’ Agencies - Corporate Compliance Insights
- GigaWiper malware performs destructive wiping activity against compromised environments (2026-07-10, 3 outlets, severity 3/5)
- GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware - Threat intelligence | Microsoft Security Blog
- New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware - The Hacker News
- GigaWiper Combines Multiple Malware for System-Level Sabotage - SecurityWeek
- Rossen G. Iossifov Allegedly Stole Cryptocurrency From United States Government Account (2026-07-11, 2 outlets, severity 3/5)
- Money launderer accused of stealing seized crypto while in prison - BleepingComputer
- License plate cameras may be next target after Supreme Court reins in location tracking - The Record from Recorded Future News
- Attackers exploit Cordyceps and GitLost to target GitHub workflows and agents (2026-07-08, 2 outlets, severity 3/5)
- The GitHub Actions Attack Pattern Your CI Security Scanners Miss - BleepingComputer
- Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data - The Hacker News
- Forg365 and O-UNC-066 Target Microsoft 365 Customers via Phishing and Vishing (2026-07-10, 3 outlets, severity 3/5)
- New Forg365 phishing platform uses AI to target Microsoft 365 accounts - BleepingComputer
- Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access - The Hacker News
- Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers - SecurityWeek
- Attackers exploit zero-day vulnerability to breach KDDI email platform and ISPs (2026-07-08, 2 outlets, severity 3/5)
- Telco giant KDDI says data breach affects over 12 million people - BleepingComputer
- Major Japanese telco says cyberattack exposed 12 million emails - The Record from Recorded Future News
- Angelo John Martino III Extorted Five U.S. Companies With BlackCat Affiliates (2026-07-10, 2 outlets, severity 3/5)
- Meta Muse Image uses public Instagram accounts for AI image generation (2026-07-09, 2 outlets, severity 3/5)
- CMD Organization steals and deletes data from Mount Royal University systems (2026-07-09, 2 outlets, severity 3/5)
- Mount Royal University confirms breach as hackers claim attack - BleepingComputer
- Mount Royal University Confirms Data Stolen in Ransomware Attack - SecurityWeek
- O-UNC-066 Targets Microsoft 365 Users With Fraudulent Entra Passkey Enrollment Campaign (2026-07-09, 2 outlets, severity 3/5)
- Entra passkey enrollment vishing targets Microsoft 365 users - BleepingComputer
- SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users - The Hacker News
- GitHub 'Verified' Commits Vulnerable to Signature Malleability Attacks (2026-07-08, 1 outlet, severity 3/5)
- Venezuela Earthquake: Mass Graves and Identification Challenges Amid Uncertainty (2026-07-07, 1 outlet, severity 3/5)
- Hyadina uses GodDamn ransomware and PoisonX driver to disable security software (2026-07-09, 2 outlets, severity 3/5)
- GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses - The Hacker News
- 'GodDamn' Ransomware Uses BYOVD to Smite US Companies - darkreading
- UK Government Launches Cyber Resilience Pledge for Large Listed Companies (2026-07-08, 2 outlets, severity 3/5)
- Cloudflare proudly joins the UK government's Cyber Resilience Pledge - The Cloudflare Blog
- UK cyber pledge draws only a handful of top firms despite ministerial appeal - The Record from Recorded Future News
- Microsoft changes Windows settings backup defaults for Microsoft Entra joined systems (2026-07-07, 1 outlet, severity 3/5)
- Microsoft to enable Windows settings backup by default for orgs - BleepingComputer
- Microsoft testing new Cloud Rebuild Windows 11 recovery feature - BleepingComputer
- Miasma worm targets Microsoft repositories via GhostApproval symlink vulnerability (2026-07-09, 1 outlet, severity 3/5)
- Ghost Accounts Exploit GitHub API for Mass Reconnaissance Campaign (2026-07-12, 1 outlet, severity 3/5)
- Ghost Accounts Abuse GitHub API in Mass Recon Campaign - SecurityWeek
- Jscrambler npm packages 8.14.0–8.20.0 compromised with Rust infostealer (2026-07-12, 1 outlet, severity 3/5)
- Mysterious Elephant Uses PlugX to Target Balochistan Police Portal (2026-07-12, 1 outlet, severity 3/5)
- Ghostcommit uses hidden image prompts to steal AI agent secrets (2026-07-11, 1 outlet, severity 3/5)
- STAC3725 Uses CitrixBleed2 Flaw to Deploy DragonForce Ransomware (2026-07-11, 1 outlet, severity 3/5)
- Initial access broker linked to weaponization of CitrixBleed2 flaw - Cybersecurity Dive - Latest News
- Tangem Wallet Cards Vulnerable to Unpatchable Laser Fault Injection Attacks (2026-07-11, 1 outlet, severity 3/5)
- Healthcare Businesses Face 35% Surge in Cyberattack Targeting Third-Party Vendors (2026-07-11, 1 outlet, severity 3/5)
- CryptWare CryptoPro Secure Disk Flaws Risk ATM Encryption Bypass (2026-07-11, 1 outlet, severity 3/5)
- Fresh ATM Crypto Software Bugs: Jackpot or Bust? - darkreading
- Australia, Canada, and UK Move to Ban Minors From Social Media (2026-07-11, 1 outlet, severity 3/5)
- More Countries Jump on the Social Media 'Ban Wagon' - darkreading
- GhostApproval Vulnerabilities and Secret Leakage Threat AI Coding Productivity (2026-07-11, 1 outlet, severity 3/5)
- Alexis Aldair Chavez Sentenced to 40 Years for 764 Crimes (2026-07-10, 1 outlet, severity 3/5)
- Greek citizens sue Intellexa for €7.6 million over Predator spyware (2026-07-09, 1 outlet, severity 3/5)
- Greek victims file lawsuit against Intellexa over Predator spyware - The Record from Recorded Future News
- Xiamen Empress Information Technology linked to Taiwan espionage charges (2026-07-09, 1 outlet, severity 3/5)
- Taiwan charges two businessmen over alleged role in Chinese espionage campaign - The Record from Recorded Future News
- Spanish Police Arrest NoName057(16) Supporter Following FBI Tip (2026-07-09, 1 outlet, severity 3/5)
- Spain arrests alleged supporter of pro-Russian hacktivist groups after FBI tip - The Record from Recorded Future News
- GhostApproval attack tricks AI coding tools into hacking developer machines (2026-07-09, 1 outlet, severity 3/5)
- Mexico's National Cybersecurity Plan Faces Trial During 2026 World Cup (2026-07-09, 1 outlet, severity 3/5)
- Mexico's New Cyber Plan Faces Its First Real Test - darkreading
- AI-Driven Attacker Breaches AWS Cloud Environment in 72 Hours (2026-07-09, 1 outlet, severity 3/5)
- Vidar Stealer Campaign Uses Code Signing Abuse to Evade Detection (2026-07-08, 1 outlet, severity 3/5)
- Windows Device ID Links Scattered Spider Hacker to Jewelry Breach (2026-07-08, 1 outlet, severity 3/5)
- TAG-179 Conducts Cyberespionage Campaigns Against Balochistan Police Using Remcos Malware (2026-07-10, 2 outlets, severity 3/5)
- One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement - SentinelLabs - We are hunters, reversers, exploit developers, and tinkerers shedding light on the world of malware, exploits, APTs, and cybercrime across all platforms.
- China, India-Linked Hackers Both Targeted Same Pakistani Police Force - SecurityWeek
- The Gentlemen Ransomware Targets Global Sectors With Custom Go Backdoors (2026-07-11, 1 outlet, severity 3/5)
- EU Reinstates Chat Control 2.0 to Scan Tech Messages (2026-07-11, 1 outlet, severity 3/5)
- Europe revives law allowing big tech to scan for CSAM - The Record from Recorded Future News
- China and India targeted Balochistan Police in separate spying campaigns (2026-07-11, 1 outlet, severity 3/5)
- China, India ran separate spying campaigns against same Pakistani police force - The Record from Recorded Future News
- Progress Tells ShareFile Users to Shut Down Storage Zone Controllers (2026-07-11, 1 outlet, severity 3/5)
- Injective Labs GitHub Breach Distributes Malicious Wallet-Key-Stealing npm Packages (2026-07-11, 1 outlet, severity 3/5)
- Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages - The Hacker News
- Silver Fox Uses MODBEACON RAT With gRPC Streaming for C2 Traffic (2026-07-11, 1 outlet, severity 3/5)
- New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic - The Hacker News
- HTML Comment Stuffing Evades AI-Based Phishing Detection Filters (2026-07-10, 1 outlet, severity 3/5)
- "Comment stuffing" in an HTML phishing attachment as a mechanism for evading AI-based detection?, (Fri, Jul 10th) - SANS Internet Storm Center, InfoCON: green
- Cloudflare urges immediate migration to post-quantum signature algorithms (2026-07-10, 1 outlet, severity 3/5)
- Why we cannot wait for better post-quantum signature algorithms - The Cloudflare Blog
- Injective SDK npm package compromised to steal cryptocurrency wallet keys (2026-07-10, 1 outlet, severity 3/5)
- Injective SDK on npm infected with cryptocurrency wallet stealer - BleepingComputer
- Cash App owner Block settles security allegations for $45 million (2026-07-09, 1 outlet, severity 3/5)
- Cash App owner to pay $45 million to settle allegations of lax security - The Record from Recorded Future News
- UAT-7810 Deploys New Leash Backdoors via SOHO Router Vulnerabilities (2026-07-09, 1 outlet, severity 3/5)
- China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors - SecurityWeek
- Vidar Infostealer Targets SMBs Through Malicious Software Advertisements (2026-07-09, 1 outlet, severity 3/5)
- Vidar Infostealer Hammers SMBs via Malvertising Campaign - darkreading
- NCSC to launch AI-driven Cyber Shield for national defense (2026-07-08, 1 outlet, severity 3/5)
- Britain plans to build autonomous AI 'Cyber Shield' to defend nation - The Record from Recorded Future News
- GitHub Copilot Bypassed via Workflow-Level Jailbreaks to Generate Harmful Code (2026-07-08, 1 outlet, severity 3/5)
- Google Dialogflow CX Flaw Allowed Hijacking of Chatbot Conversations (2026-07-08, 1 outlet, severity 3/5)
- Russian hackers target Ukrainian media outlets in new cyberattacks (2026-07-07, 1 outlet, severity 3/5)
- Ukrainian media outlets now among 'priority targets' for Russian hackers - The Record from Recorded Future News
- Scattered Spider suspect Peter Stokes extradited to US for fraud (2026-07-07, 1 outlet, severity 3/5)
- Alleged member of Scattered Spider extradited to US - Cybersecurity Dive - Latest News
- North Korean PolinRider Campaign Targets Developers With DEV#POPPER Malware (2026-07-07, 1 outlet, severity 3/5)
- NetNut Proxy Disruption, Scattered Spider Extradition, and AI Agent Attacks (2026-07-07, 1 outlet, severity 3/5)
- Jen Ellis Bridges Cybersecurity Research and Federal Policy Reform (2026-07-11, 1 outlet, severity 3/5)
- Global crackdown targets widespread cybercrime and betting scams. (2026-07-10, 1 outlet, severity 3/5)
- INTERPOL’s Operation First Light 2026 Arrests 5,800 Fraud Suspects (2026-07-09, 1 outlet, severity 3/5)
- Police arrests 5,800 suspects in global anti-fraud crackdown - BleepingComputer
- AssuranceAmerica breach exposes personal data of 6.9 million drivers (2026-07-09, 1 outlet, severity 3/5)
- AssuranceAmerica data breach exposes records of 6.9 million drivers - BleepingComputer
- UNK_MassTraction exploits Roundcube flaws to target academic researchers (2026-07-09, 1 outlet, severity 3/5)
- Hackers exploit Roundcube flaw to spy on academic researchers - BleepingComputer
- Union County Reportedly Paid Kairos $1 Million Bitcoin Ransom (2026-07-08, 1 outlet, severity 3/5)
- Nigeria's Lack of Whistleblower Laws Weakens Corporate Reporting Systems (2026-07-08, 1 outlet, severity 3/5)
- Your Whistleblower Hotline Does Not Work the Same Way in Nigeria - Corporate Compliance Insights
- UAT-7810 Uses LONGLEASH Malware to Build ORB Networks via Ruckus (2026-07-07, 1 outlet, severity 3/5)
- UAT-7810 continues building ORB networks using new malware - Cisco Talos Blog
- EtherRAT malware spreads via fake Microsoft Teams IT support calls (2026-07-07, 1 outlet, severity 3/5)
- Fake IT support calls on Microsoft Teams push EtherRAT malware - BleepingComputer
- US Army subdomains defaced with pro-Kurdish messages and political insults (2026-07-07, 1 outlet, severity 3/5)
- CSE Disrupts Three Criminal Groups and Ten Ransomware Gangs (2026-07-07, 1 outlet, severity 3/5)
- Canadian spy agency reports hacking three criminal groups in 2025 - The Record from Recorded Future News
- Unauthorized third party uses phishing attack to breach AssuranceAmerica systems (2026-07-10, 2 outlets, severity 3/5)
- Data breach hits car insurance provider - Cybersecurity Dive - Latest News
- 6.9 million driver’s license numbers stolen from AssuranceAmerica - Malwarebytes
- ACSC Warns of Global CMS Exploitation Targeting Vulnerable Plugins (2026-07-12, 1 outlet, severity 3/5)
- Australia warns of global campaign targeting vulnerable CMS platforms - BleepingComputer
- OpenMandriva Linux reports sabotage attempt by internal contributor (2026-07-10, 1 outlet, severity 3/5)
- OpenMandriva Linux says contributor tried to sabotage the project - BleepingComputer
- Helix vishing group targets SharePoint environments for data extortion (2026-07-10, 1 outlet, severity 3/5)
- New Helix vishing group emerges in SharePoint data theft attacks - BleepingComputer
- HELP_ME_ESCAPE_FROM_BELARUS_PLEASE' Bot Performs Reconnaissance and SSH Attacks (2026-07-09, 1 outlet, severity 3/5)
- _HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_ [Guest Diary], (Tue, Jul 7th) - SANS Internet Storm Center, InfoCON: green
- Microsoft to Retire Exchange Server OWA Light Client by 2026 (2026-07-09, 1 outlet, severity 3/5)
- Microsoft to retire the OWA Light client in Exchange Server - BleepingComputer
- Paris Peace Forum Launches INTAiC to Combat AI Cyber Threats (2026-07-09, 1 outlet, severity 3/5)
- John Edwards to sue whistleblower following sexual harassment investigation (2026-07-09, 1 outlet, severity 3/5)
- Former UK privacy chief preparing legal action against woman who reported him, minister says - The Record from Recorded Future News
- KDDI Data Breach Exposes 12 Million Users via Zero-Day Exploit (2026-07-09, 1 outlet, severity 3/5)
- 12 Million Impacted by Data Breach at Japanese Telco KDDI - SecurityWeek
- Smarsh and FTI Research: Only 26% of AI Governance Aligned (2026-07-09, 1 outlet, severity 3/5)
- Only 26% of Companies Say Governance Frameworks Are Fully Aligned With AI Adoption - Corporate Compliance Insights
- Netherlands Phishing Arrests Follow Surge in European Payment Fraud (2026-07-08, 1 outlet, severity 3/5)
- xAI and Stability AI Face Expanded Lawsuit Over Grok Deepfakes (2026-07-08, 1 outlet, severity 3/5)
- Deepfake CSAM lawsuit against xAI, Grok expands - CyberScoop
- RedWing Malware-as-a-Service Targets Russian Banks via Telegram Rental Kits (2026-07-08, 1 outlet, severity 3/5)
- RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service - The Hacker News
- Google Account Phishing Uses Fake Job Interviews to Steal Credentials (2026-07-07, 1 outlet, severity 3/5)
- Phishing poses as big-brand job interview to steal Google accounts - BleepingComputer
- Vietnam arrests seven suspects behind HiAnime piracy operation (2026-07-07, 1 outlet, severity 3/5)
- Vietnam arrests suspects behind HiAnime anime piracy service - BleepingComputer
- BonkDAO attackers steal $20 million via malicious governance vote (2026-07-07, 1 outlet, severity 3/5)
- Attackers vote themselves $20 million in BONK cryptocurrency - The Record from Recorded Future News
- Medtronic data breach exposes 3.8 million people to ShinyHunters (2026-07-07, 1 outlet, severity 3/5)
- Major medical device manufacturer notifies nearly 4 million of breach - The Record from Recorded Future News
- Teen arrested for using ChatGPT to attack Bandai Channel (2026-07-07, 1 outlet, severity 3/5)
- Japanese teen arrested over cyberattack that disrupted anime streaming service - The Record from Recorded Future News
- TPO Group CISO Tarah Wheeler on Leadership and Human Behavior (2026-07-07, 1 outlet, severity 3/5)
- Netflix and OpenAI impersonation scams target Google account credentials (2026-07-10, 1 outlet, severity 3/5)
- Microsoft to use AI agents to find more Windows vulnerabilities (2026-07-10, 1 outlet, severity 3/5)
- Microsoft expects more Windows security updates from AI-discovered flaws - BleepingComputer
- Fake Paysafe and Skrill SDKs on NPM Steal Developer Credentials (2026-07-09, 1 outlet, severity 3/5)
- Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials - BleepingComputer
- U.S. Enterprises Integrate Cyber Risk Into Strategic Business Planning (2026-07-09, 1 outlet, severity 3/5)
- US enterprises incorporate cyber risk into larger strategic focus - Cybersecurity Dive - Latest News
- macOS NetBIOS Broadcasts Trigger False NIMLOC DNS Alerts in Zeek (2026-07-08, 1 outlet, severity 3/5)
- More Odd DNS Records: NIMLOC, (Tue, Jul 7th) - SANS Internet Storm Center, InfoCON: green
- Accenture confirms data breach after hacker 888 offers stolen files (2026-07-08, 1 outlet, severity 3/5)
- Accenture confirms breach after hacker offers stolen data for sale - BleepingComputer
- Cisco Report: AI Network Expansion Increases Security Blind Spots (2026-07-08, 1 outlet, severity 3/5)
- Businesses modernizing networks for AI fear expanding attack surface, limited visibility - Cybersecurity Dive - Latest News
- EU and US Driver-Monitoring Rules Spark Biometric Privacy Concerns (2026-07-08, 1 outlet, severity 3/5)
- Your next car could be watching your face - Malwarebytes
- Use SynthID and Content Credentials to Spot AI Image Scams (2026-07-07, 1 outlet, severity 3/5)
- How to tell if an image is AI-generated - Malwarebytes
- GigaWiper malware grants remote access and wipes Windows disks (2026-07-11, 1 outlet, severity 3/5)
- DHS Database Hacked and Canada Disrupts Major Ransomware Operations (2026-07-11, 1 outlet, severity 3/5)
- UAT-7810 Uses LONGLEASH Malware to Expand Router Relay Networks (2026-07-10, 1 outlet, severity 3/5)
- Winning 54% of the time - Cisco Talos Blog
- GitHub Dormant Accounts Used to Map Corporate Organizations (2026-07-10, 1 outlet, severity 3/5)
- Chainguard Launches Athena to Automate Open Source Vulnerability Remediation (2026-07-09, 1 outlet, severity 3/5)
- Summer of Clearinghouses - The Hacker News
- CISA and Treasury AI Clearinghouse Must Prioritize Patching Over Discovery (2026-07-08, 1 outlet, severity 3/5)
- Reddit and Discord scammers use false reports to steal accounts (2026-07-08, 1 outlet, severity 3/5)
- How the Reddit and Discord false report scam steals accounts - Malwarebytes
- Veil#Drop Attacks Use Blogspot Payloads to Deploy PureLog Stealer (2026-07-07, 1 outlet, severity 3/5)
- Blogspot-Hosted Payloads Delivered in ‘Veil#Drop’ Attacks - SecurityWeek
- Anthropic removes Claude Code location tracker after privacy concerns. (2026-07-07, 1 outlet, severity 3/5)
- EU Anti-Corruption Directive: A Compliance Roadmap for Corporate Liability (2026-07-07, 1 outlet, severity 3/5)
- Operationalizing the EU Anti-Corruption Directive: A Practical Roadmap for Compliance Teams - Corporate Compliance Insights
- Shefaly Yogendra on Boardroom Evolution and Predictive Stewardship by 2030 (2026-07-07, 1 outlet, severity 3/5)
- Anticipating & Acting on the Challenges for the Chair & Board of 2030 - Corporate Compliance Insights
- RCS Service Discovery via NAPTR DNS Records and SIP URIs (2026-07-07, 1 outlet, severity 3/5)
- RCS and DNS: The NAPTR Record, (Mon, Jul 6th) - SANS Internet Storm Center, InfoCON: green
- AI-Generated Fake Flowers Deceive Shoppers on Amazon and eBay (2026-07-07, 1 outlet, severity 3/5)
- Scammers are using AI to sell impossible flowers - Malwarebytes
- Consumentenbond warns WhatsApp users against reusing Meta social handles (2026-07-07, 1 outlet, severity 3/5)
- Choose your WhatsApp username carefully - Malwarebytes
- Assent Acquires IPOINT to Boost Automotive Compliance and Sustainability (2026-07-11, 1 outlet, severity 3/5)
- Assent Acquires Automotive Compliance & Sustainability Software Provider IPOINT - Corporate Compliance Insights
- Tangos Raises $20M Seed Round for AI Financial Crime Tools (2026-07-11, 1 outlet, severity 3/5)
- Tangos Secures $20M in Seed Round - Corporate Compliance Insights
- Lurking Lizard Uses Fake 7-Zip Installers to Build Proxy Networks (2026-07-09, 1 outlet, severity 3/5)
- Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes - The Hacker News
- Shai-Hulud Campaign Targets AI-Driven Software Supply Chain Vulnerabilities (2026-07-07, 1 outlet, severity 3/5)
- Kaspersky Reports Three-Year Low in Blocked Industrial Automation Malware (2026-07-07, 1 outlet, severity 3/5)
- UNC6395 Exploits OAuth Tokens to Target Growing AI Machine Identities (2026-07-11, 1 outlet, severity 3/5)
- The Replicant in Your Directory: AI Agents and the Identity Security Gap - BleepingComputer
- WP-SHELLSTORM Malware Backdoors Thousands of WordPress Sites via Exposed Server (2026-07-10, 1 outlet, severity 3/5)
- Free Android VPN Apps Leak Data and Track Users (2026-07-10, 1 outlet, severity 3/5)
- AI-Driven Service Desk Attacks: How to Prevent Impersonation Risks (2026-07-09, 1 outlet, severity 3/5)
- 3 Ways AI Powers Service Desk Attacks and How to Prevent Them - BleepingComputer
- Vibe Coding Accelerates Software Development While Increasing Security Risks (2026-07-07, 1 outlet, severity 3/5)
- Software Is Now Written at the Speed of Thought. Security Isn't. - BleepingComputer
- Business-Aligned Risk Management Links Technical Vulnerabilities to Financial Impact (2026-07-07, 1 outlet, severity 3/5)
- The Shift Toward Business-Aligned Risk Management - SecurityWeek
- Xavier Mertens Releases Stack Simulator for Assembly and Malware Students (2026-07-11, 1 outlet, severity 3/5)
- My Stack Simulator, (Wed, Jul 8th) - SANS Internet Storm Center, InfoCON: green
- Summer IT Staffing Gaps Increase Cyberattack Dwell Time Risks (2026-07-10, 1 outlet, severity 3/5)
- The Hidden Security Risks of Reduced Summer IT Coverage - BleepingComputer
- Cyberwarfare Lessons: How Businesses Must Prepare for Digital Conflict (2026-07-10, 1 outlet, severity 3/5)
- 8Layers Secures $2.9 Million to Expand Identity Security Platform (2026-07-09, 1 outlet, severity 3/5)
- 8Layers Raises $2.9 Million for Identity Security Platform - SecurityWeek
- DuckDuckGo Browser Now Automatically Blocks YouTube Video Advertisements (2026-07-08, 1 outlet, severity 3/5)
- DuckDuckGo browser now blocks YouTube video ads - BleepingComputer
- Keyfactor Secures $1 Billion to Advance Post-Quantum Security Solutions (2026-07-07, 1 outlet, severity 3/5)
- NSA Rebrands Elite Hacking Unit as Tailored Access Operations (2026-07-10, 1 outlet, severity 3/5)
- NSA revives 'Tailored Access Operations' name for elite hacking unit - The Record from Recorded Future News
- EU sues Ireland, Spain, France, and Netherlands over NIS2 delays (2026-07-10, 1 outlet, severity 3/5)
- EU takes member states to court over unimplemented cybersecurity law - The Record from Recorded Future News
- npm 12 Disables Install Scripts to Mitigate Supply Chain Risks (2026-07-10, 1 outlet, severity 3/5)
- npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk - The Hacker News
- HalluSquatting Uses AI Hallucinations to Deliver Malicious Botnets (2026-07-10, 1 outlet, severity 3/5)
- GitHub Repository Network Used to Spread Malware via Go Modules (2026-07-10, 1 outlet, severity 3/5)
- QIZ Security Secures $17 Million for Cryptographic Governance Platform (2026-07-10, 1 outlet, severity 3/5)
- HalluSquatting Attack Exploits AI Hallucinations to Install Botnet Malware (2026-07-09, 1 outlet, severity 3/5)
- EvilTokens Campaign Uses Ghost Phishing to Bypass Email Security (2026-07-09, 1 outlet, severity 3/5)
- New Ghost Phishing Wave Is Breaking Traditional Email Security - The Hacker News
- Data Brokers and the Illusion of Effective Data Scrubbing Services (2026-07-09, 1 outlet, severity 3/5)
- CISA Uses Anthropic’s Mythos to Scan Government Software for Vulnerabilities (2026-07-08, 1 outlet, severity 3/5)
- Estonia Plans State ID System for Autonomous AI Agents (2026-07-08, 1 outlet, severity 3/5)
- State IDs for AI Agents: Will Estonia Set a Precedent? - darkreading
- JadePuffer Ransomware Uses LLM Agents to Breach Langflow Systems (2026-07-07, 1 outlet, severity 3/5)
- BuildwellAI Launches Compliance Platform for UK Building Safety Act (2026-07-11, 1 outlet, severity 3/5)
- BuildwellAI Launches Construction Compliance Platform - Corporate Compliance Insights
- LexisNexis, Sovos, and SpeakUp Lead Latest GRC Industry Updates (2026-07-11, 1 outlet, severity 3/5)
- GRC News Roundup: LexisNexis, SpeakUp, LogicGate & more - Corporate Compliance Insights
- Latvian forestry firm continues system recovery after ransomware attack (2026-07-10, 1 outlet, severity 3/5)
- Latvian forestry company still restoring systems weeks after ransomware attack - The Record from Recorded Future News
- Ransomware Ecosystem Expands as Four Major Groups Dominate Landscape (2026-07-10, 1 outlet, severity 3/5)
- Ransomware ecosystem grows, but ‘four-headed monster’ dominates - Cybersecurity Dive - Latest News
- Lumen Technologies Scales Asset Inventory to 1.1 Million for Exposure Management (2026-07-10, 1 outlet, severity 3/5)
- UK Government Launches Agentic AI Defense Plan and Industry Pledge (2026-07-10, 1 outlet, severity 3/5)
- Iranian Cyber Threats Expand Targets Beyond Critical Infrastructure (2026-07-10, 1 outlet, severity 3/5)
- AI Agents Demand New Identity Management Strategies for Organizations (2026-07-10, 1 outlet, severity 3/5)
- SANS ISC Stormcast Summarizes Weekly Cybersecurity Developments and Activity (2026-07-10, 1 outlet, severity 3/5)
- ISC Stormcast For Friday, July 10th, 2026 https://isc.sans.edu/podcastdetail/10002, (Fri, Jul 10th) - SANS Internet Storm Center, InfoCON: green
- Cloud Bucket Hijacking and Windows LPE Chain Highlight Weekly Threats (2026-07-10, 1 outlet, severity 3/5)
- European Security Leaders Overestimate Collaboration Tool Safety, Survey Finds (2026-07-09, 1 outlet, severity 3/5)
- ISC Stormcast Podcast Delivers Daily Cybersecurity Intelligence Digest (2026-07-09, 1 outlet, severity 3/5)
- ISC Stormcast For Thursday, July 9th, 2026 https://isc.sans.edu/podcastdetail/10000, (Thu, Jul 9th) - SANS Internet Storm Center, InfoCON: green
- JadePuffer: The First Fully Autonomous AI-Driven Ransomware Attack (2026-07-09, 1 outlet, severity 3/5)
- SANS Institute Releases July 8th ISC Stormcast Podcast Digest (2026-07-08, 1 outlet, severity 3/5)
- ISC Stormcast For Wednesday, July 8th, 2026 https://isc.sans.edu/podcastdetail/9998, (Wed, Jul 8th) - SANS Internet Storm Center, InfoCON: green
- SANS Institute Releases July 7th ISC Stormcast Daily Podcast Briefing (2026-07-07, 1 outlet, severity 3/5)
- ISC Stormcast For Tuesday, July 7th, 2026 https://isc.sans.edu/podcastdetail/9996, (Tue, Jul 7th) - SANS Internet Storm Center, InfoCON: green
- Someone Is Scanning for Your MCP Servers and AI Assistant Credentials, (Mon, Jul (2026-07-13, 1 outlet, severity 3/5)
- Someone Is Scanning for Your MCP Servers and AI Assistant Credentials, (Mon, Jul 13th) - SANS Internet Storm Center, InfoCON: green
- ISC Stormcast For Monday, July 13th, 2026 https://isc.sans.edu/podcastdetail/100 (2026-07-13, 1 outlet, severity 3/5)
- ISC Stormcast For Monday, July 13th, 2026 https://isc.sans.edu/podcastdetail/10004, (Mon, Jul 13th) - SANS Internet Storm Center, InfoCON: green
- EU sanctions Russian GRU military hackers over cyberattacks (2026-07-13, 1 outlet, severity 3/5)
- EU sanctions Russian GRU military hackers over cyberattacks - BleepingComputer
- US and allies warn of Russian critical infrastructure attacks (2026-07-13, 1 outlet, severity 3/5)
- US and allies warn of Russian critical infrastructure attacks - BleepingComputer
- OpenAI temporarily relaxes GPT-5.6 Sol usage limits (2026-07-13, 1 outlet, severity 3/5)
- OpenAI temporarily relaxes GPT-5.6 Sol usage limits - BleepingComputer
- Claude Fable 5 stays free for paid users until July 19 as Anthropic buys more ti (2026-07-13, 1 outlet, severity 3/5)
- RedHook Android malware now uses Wireless ADB for shell access (2026-07-13, 1 outlet, severity 3/5)
- RedHook Android malware now uses Wireless ADB for shell access - BleepingComputer
- AI-generated code has made security debt a governance problem (2026-07-13, 1 outlet, severity 3/5)
- When cybercriminals outrun the feed (2026-07-13, 1 outlet, severity 3/5)
- When cybercriminals outrun the feed - Cybersecurity Dive - Latest News
- Copy-paste might be the riskiest thing your enterprise employees do all day (2026-07-13, 1 outlet, severity 3/5)
- Copy-paste might be the riskiest thing your enterprise employees do all day - Cybersecurity Dive - Latest News
- RabbitMQ Vulnerability Threatens Enterprise Systems (2026-07-13, 1 outlet, severity 3/5)
- RabbitMQ Vulnerability Threatens Enterprise Systems - SecurityWeek
- Zimbra Patches Critical Code Execution Vulnerability (2026-07-13, 1 outlet, severity 3/5)
- Zimbra Patches Critical Code Execution Vulnerability - SecurityWeek
- EU Targets Russian Intelligence Officers Accused of Running a Yearslong Cyber Sp (2026-07-13, 1 outlet, severity 3/5)
- Organizations Warned of Exploited Joomla Extension Vulnerabilities (2026-07-13, 1 outlet, severity 3/5)
- Progress Prompts ShareFile Storage Zone Controller Shutdown Amid Security Concer (2026-07-13, 1 outlet, severity 3/5)
- Centers Laboratory Data Breach Affects 540,000 Individuals (2026-07-13, 1 outlet, severity 3/5)
- Centers Laboratory Data Breach Affects 540,000 Individuals - SecurityWeek
- Meta Files Patent for AI That Can Listen All Day and Track How You're Feeling (2026-07-13, 1 outlet, severity 3/5)
- Thinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Ana (2026-07-13, 1 outlet, severity 3/5)
- Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory (2026-07-13, 1 outlet, severity 3/5)
- Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Micros (2026-07-13, 1 outlet, severity 3/5)
- iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days (2026-07-13, 1 outlet, severity 3/5)
- NIST Database Change Rebalances Burden of Risk (2026-07-13, 1 outlet, severity 3/5)
- NIST Database Change Rebalances Burden of Risk - Corporate Compliance Insights
- Bosch Case Provides First Glimpse of NatSec Application of Department-Wide CEP (2026-07-13, 1 outlet, severity 3/5)
- Bosch Case Provides First Glimpse of NatSec Application of Department-Wide CEP - Corporate Compliance Insights
- Fake crypto gift card sites are getting harder to spot (2026-07-13, 1 outlet, severity 3/5)
- Fake crypto gift card sites are getting harder to spot - Malwarebytes
- AI Gateways Provide Attackers Direct Access to Sensitive Data (2026-07-10, 1 outlet, severity 3/5)
- AI Gateways Offer Attackers the Keys to the Kingdom - darkreading
- Google Chrome 150 Update Fixes 27 Security Vulnerabilities (2026-07-09, 1 outlet, severity 3/5)
- Chrome 150 Update Patches 27 Vulnerabilities - SecurityWeek
- Verification Processes Become the Primary ATO Battleground in 2026 (2026-07-08, 1 outlet, severity 3/5)
- The Verification Step Is the New ATO Battleground in 2026 - The Hacker News
- Linux KVM Flaw Allows Guest VM Escape on x86 Systems (2026-07-07, 1 outlet, severity 3/5)
Reported Data Breaches
Breaches reported via Have I Been Pwned this period.