During the 48-hour period from July 2-3, 2026, the threat landscape was dominated by multiple critical infrastructure events, widespread exploitation of newly disclosed vulnerabilities, and a surge in ransomware activity targeting diverse sectors. The FBI seized NetNut, a major residential proxy service, and the Popa botnet, disrupting infrastructure used for credential stuffing and fraud operations. Concurrently, FortiBleed exploitation actors were observed collaborating with Inc and Lynx ransomware gangs, while a Scattered Spider member faced extradition to the U.S.
Critical vulnerabilities emerged across multiple Microsoft cloud services (CVE-2026-57100, CVE-2026-45499, CVE-2026-41106) with CVSS scores of 9.9 and 9.3, enabling privilege escalation via SSRF and open redirect vectors. CISA added a Microsoft SharePoint RCE flaw to its Known Exploited Vulnerabilities catalog, confirming active exploitation. Additional zero-day activity was reported in Cisco Unified CM and Nextcloud environments. The Mozi botnet remained highly active with 50+ malware distribution URLs identified, while ClickFix/ConsentFix social engineering campaigns targeting Microsoft 365 accounts intensified. Eighteen organizations across healthcare, government, manufacturing, and hospitality sectors were added to ransomware leak sites, with incransom and apt73 groups showing elevated activity.
Major law enforcement operations disrupted cybercriminal infrastructure, including proxy services and ransomware operations.
FBI worked with industry partners to seize hundreds of domains associated with NetNut, a residential proxy service operated by Israeli company Alarum Technologies (NASDAQ: ALAR). The action comes approximately two weeks after initial investigation, disrupting a sprawling proxy network used for credential stuffing, fraud, and anonymization.
A dual U.S.-Estonian citizen has been extradited to face charges for alleged membership in the Scattered Spider hacking collective, known for sophisticated social engineering attacks targeting major organizations. This represents continued law enforcement pressure on the group.
Multiple critical SSRF and privilege escalation flaws discovered in Microsoft's cloud infrastructure enabling attackers to compromise enterprise environments.
Server-side request forgery vulnerability in Microsoft Entra Provisioning Service (SyncFabric) allows authorized attackers to elevate privileges over a network. CVSS 9.9 (Critical).
Server-side request forgery in Azure OpenAI service allows authorized attackers to elevate privileges over a network. CVSS 9.9 (Critical).
URL redirection to untrusted site vulnerability in M365 Copilot allows unauthorized attackers to elevate privileges over a network. CVSS 9.3 (Critical).
Incorrect authorization in Microsoft Exchange Online allows authorized attackers to elevate privileges over a network. CVSS 8.8 (High).
CISA warned that attackers have begun exploiting a high-severity Microsoft SharePoint remote code execution vulnerability patched in May. The flaw has been added to the Known Exploited Vulnerabilities catalog, indicating confirmed in-the-wild exploitation.
Cisco confirmed attackers are now exploiting a Unified Communications Manager (Unified CM) vulnerability patched in early June. The flaw enables unauthorized access to critical communications infrastructure.
Critical vulnerabilities identified in widely-deployed enterprise applications and open source components requiring immediate patching.
Apereo CAS 7.3.0-8.0.0-RC6 contains a cryptographic vulnerability allowing remote unauthenticated attackers to recover plaintext conversation state by exploiting AES-GCM IV reuse. Attackers can collect webflow execution tokens to decrypt session data. CVSS 9.1 (Critical).
Fast-mcp-telegram validates HTTP Bearer tokens by joining raw token strings into session-file paths without rejecting path separators, enabling attackers to bypass authentication and access privileged Telegram sessions. CVSS 9.4 (Critical).
AutoBangumi before 3.2.8 contains publicly known default credentials seeded at startup when the users table is empty, allowing unauthenticated attackers to authenticate as administrator. CVSS 9.8 (Critical).
Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability due to missing exit() after authentication redirect combined with unsanitized input to shell_exec(). CVSS 9.8 (Critical).
Shellcode injection in the mercurial handler of OBS tar_scm source service before 0.12.4 allows attackers providing _service files to execute code as the source service or local user. CVSS 10.0 (Critical).
Missing validation of valuesFrom references in Helm Deployer allows owners of one tenant to access fleet credentials of other tenants in SUSE Rancher Fleet. CVSS 9.9 (Critical).
A serious security flaw in WinRAR could allow attackers to take control of systems. Without automatic updates, many users may miss the critical patch, leaving systems vulnerable to exploitation.
Multiple ransomware groups actively targeting organizations across healthcare, government, manufacturing, and service sectors with data exfiltration and encryption operations.
After gaining footholds in thousands of Fortinet firewalls via FortiBleed exploitation, threat actors are monetizing access by partnering with Inc and Lynx ransomware operations. Attackers are also exploiting a Nextcloud zero-day vulnerability.
Ransomware campaign uses basic social engineering with Interpol lures to target small businesses across multiple regions including the US, Europe, and Middle East. The attacks rely on impersonating law enforcement to gain victim trust.
Eighteen organizations added to ransomware leak sites spanning healthcare, government, manufacturing, hospitality, and professional services sectors.
Leading Denver-area physiatry practice with multiple Front Range clinics founded in 1992. Likely exposure of protected health information (PHI) for patients receiving musculoskeletal and neurological treatment.
Pediatric clinic data breach exposing employee and patient information. Protected health information of minors and families at risk.
One of Brazil's largest wholesale distributors (founded 1949) supplying retail stores, supermarkets, and construction shops nationwide. Operates in B2B marketplace with extensive supply chain relationships.
Municipal government serving 'The Lake City' in Georgia foothills. Potential exposure of resident data, municipal records, and city infrastructure information.
Healthcare services provider breach exposing employee data and internal files with undisclosed discoveries.
Comprehensive vision care practice with Allentown and Easton locations providing routine exams, medical/surgical treatments, and MediSpa services. Patient records at risk.
Non-profit 501(c)(3) providing free early childhood education and family support across three Michigan counties through federal Office of Head Start funding. Exposure of family and child data.
Pakistani conglomerate headquartered in Lahore operating across razor blade manufacturing, textiles, and power generation. Major regional employer with extensive supply chain data.
Italian website builder platform serving business customers. Potential exposure of user account data, website content, and customer information.
Spanish hospitality property breach exposing guest information, internal documents, reports, photos, and videos.
Sophisticated social engineering campaigns using fake verification prompts to steal Microsoft 365 credentials and bypass MFA protections.
ConsentFix and ClickFix attacks steal Microsoft 365 tokens in seconds using fake prompts and malicious OAuth flows. These techniques bypass MFA by tricking users into granting application consent or executing malicious PowerShell commands.
ClickFix attacks discovered using fake Google and Cloudflare verification pages to deliver infostealers and a newly discovered malware loader. The campaign demonstrates evolution of social engineering tactics.
Opera browser rolled out Paste Protect, a security feature designed to block ClickFix-style attacks that trick users into executing malicious commands through clipboard manipulation and social engineering.
Continued high-volume Mozi botnet activity with 50+ malware distribution URLs identified targeting IoT devices.
50+ URLs identified distributing Mozi botnet malware targeting ELF-based IoT devices across multiple architectures (MIPS, ARM). URLs use wget user-agent and serve bin.sh scripts and compiled binaries. Activity concentrated across Asian and European IP ranges.
Significant regulatory actions and policy changes affecting cybersecurity operations and data protection frameworks.
Privacy advocate Max Schrems plans to sue to invalidate the EU-U.S. Data Privacy Framework following a Supreme Court decision, potentially disrupting transatlantic data flows for U.S. companies. This would be the third iteration of the data transfer mechanism to face legal challenge.
Publication of UK's National Cyber Action Plan postponed from scheduled Monday release due to uncertainty over governing Labour Party's leadership contest opening July 9. The delay impacts national cybersecurity strategy implementation.
Apple implementing more compressed patching cycles going forward as attackers leverage AI to reduce time to exploit. The policy shift represents significant change in Apple's traditionally slower update cadence.
Court of Justice of the European Union (CJEU) dismissed Google's final appeal against a €4.1 billion ($4.7 billion) antitrust fine over Android practices promoting Chrome browser and search services. The ruling sets important precedent for platform regulation.
Cutting-edge security research revealing vulnerabilities, attack techniques, and defensive capabilities.
Researcher disclosed vulnerability in Apple's Hide My Email feature one year ago; still awaiting fix. The flaw undermines privacy protections intended to shield user email addresses from third parties.
SentinelOne Labs research demonstrates compaction technique reducing input tokens by 86% across long-running agent evaluations with no quality loss. Study emphasizes context discipline importance in AI-powered security analysis.
Unit 42 researchers detail reverse-engineering journey building the first RDP client outside Windows to support WebAuthn redirection, enabling passwordless authentication in web-based remote access scenarios.
IBM and Red Hat assign 20,000 engineers to new Project Lightwell service as Anthropic's Mythos findings ignite debate over securing open-source software supply chain. Initiative represents major corporate investment in AI-powered vulnerability management.
These briefings are compiled from publicly available threat-intelligence feeds, which may include CISA KEV, NIST NVD, the GitHub Advisory Database (OSV), abuse.ch, and Wordfence Intelligence. Data-breach and credential-leak items may include data from Have I Been Pwned and ransomware.live.
CVE® is a registered trademark of The MITRE Corporation. CVE Records are © The MITRE Corporation, reproduced under the CVE Program Terms of Use. WordPress vulnerability data is provided by Wordfence Intelligence, © Defiant, Inc. Breach data from Have I Been Pwned is licensed under CC BY 4.0.