The 48-hour period from July 7-8, 2026 saw heightened threat activity across multiple vectors. Critical vulnerabilities dominate the landscape, with 30 CVEs identified including 6 rated CRITICAL (CVSS 9+). Notable among these are authentication bypasses in enterprise platforms (Esri Portal, Dell PowerProtect, BeyondTrust remote access), and severe flaws in AI/developer tooling (GitHub Actions, mem0, LocalAI) that enable data exfiltration and code execution. The vulnerability surface extends to embedded systems, with a 16-year-old Linux kernel flaw (Januscape) enabling VM escape on Intel/AMD devices, and backdoors discovered in Tenda routers and MSI drivers.
Ransomware operations remained aggressive with 22 new victim disclosures, led by Play (4 victims), Akira (5 victims), and emerging groups targeting critical infrastructure including Mount Royal University and YMCA of Western North Carolina. The banking fraud landscape saw sophisticated evolution with REF6045's Mexican banking toolkit combining ClickFix techniques with operator-assisted fraud. Malware distribution infrastructure remained active with 50+ URLhaus entries primarily distributing Mozi botnet, information stealers (Vidar, AgentTesla, AsyncRAT, RemcosRAT), and ClearFake campaigns. State-sponsored activity included Chinese APT group UAT-7810 expanding their ORB network through router compromises, while law enforcement achieved a win with Spain's arrest of a CARR/Z-Pentest member. Data breach notifications included significant incidents at Washington DSHS (8,600 affected), Accenture (35GB source code stolen), and a Japanese telco exposing 12 million emails.
Multiple critical vulnerabilities enable unauthenticated access to enterprise systems and sensitive data
Missing authentication on critical API functions in Esri Portal for ArcGIS versions ≤12.1 allows remote unauthenticated attackers to access protected APIs. Affects Windows, Linux, and Kubernetes deployments. Administrators should configure email-based authentication and upgrade immediately.
Improper authentication in Dell PowerProtect Data Domain (versions 7.7.1.0-8.7, LTS releases through 7.13.1.70) allows unauthenticated remote attackers to gain unauthorized access. Critical for backup infrastructure security.
mem0's openmemory/api component lacks authentication middleware, allowing attackers to read, write, and delete arbitrary user memories via API endpoints. Attackers can supply arbitrary user_id parameters to access sensitive AI memory data.
Unauthenticated config endpoints in mem0 expose LLM API keys in plaintext and enable SSRF via attacker-controlled ollama_base_url parameter. Attackers can retrieve OpenAI API keys via GET /api/v1/config/ or trigger SSRF attacks.
BeyondTrust warned customers to immediately patch two critical security flaws in Remote Support (RS) and Privileged Remote Access (PRA) software that could allow attackers to bypass authentication and gain unauthorized access to privileged sessions.
Emerging vulnerabilities in AI tooling and development platforms enable data theft and code execution
Cognee before 1.2.0 allows unauthenticated attackers to overwrite global LLM provider configuration by self-registering and calling settings endpoint without admin checks. Enables redirection of all LLM requests to attacker-controlled endpoints.
GitLost flaw allows unauthenticated attackers to craft GitHub Issues in public repositories and silently exfiltrate data from private repositories through agentic workflows, bypassing access controls.
ActiveState reveals how GitHub Actions attack chains can evade traditional CI security scanners through sophisticated patterns. Passing security scans does not guarantee secure pipelines, requiring better governance of CI/CD workflows.
Varonis reported a flaw to Google in late 2025 (now addressed) that allowed unauthorized access to AI chatbot data in Dialogflow CX. Highlights need for organizations to reassess AI infrastructure security posture.
GET /api/v1/public/:accessId/portfolio endpoint accepts private access IDs without validating granteeUserId filtering, allowing unauthenticated access to full portfolio data including holdings, quantities, and valuations.
Critical flaws in network devices, embedded systems, and operating systems enable privilege escalation and remote access
A 16-year-old Linux kernel vulnerability dubbed Januscape allows attackers to escape virtual machines and execute arbitrary code on Intel and AMD hosts. Affects virtualized infrastructure security across cloud and on-premise environments.
Hidden authentication backdoor discovered in multiple Tenda router firmware versions potentially allows attackers to gain administrative access to web management panel. Affects consumer and small business network security.
KernCoreLib64.sys kernel driver in MSI Feature Manager allows any logged-on user to perform arbitrary physical memory read/write and unrestricted I/O port operations via exposed IOCTL handlers without administrator privileges.
FluxInk Color Management Driver (TcnPeripheral64.sys) 1.0.7.2 allows local privilege escalation via arbitrary physical memory mapping at \Device\PhysicalMemory. Fixed in version 1.0.7.6 available in Windows Update.
Dell PowerProtect Data Domain (versions 7.7.1.0-8.7, LTS releases) contains OS command injection vulnerability allowing authenticated attackers with high privileges to execute arbitrary OS commands.
Multiple applications vulnerable to SSRF attacks enabling internal network access and data exfiltration
9Router before 0.4.44 contains OS command injection in unauthenticated POST /api/tunnel/tailscale-install endpoint. sudoPassword field written to shell script without sanitization, enabling remote code execution.
LocalAI POST /models/apply endpoint passes unsanitized gallery URL fields directly to gallery.GetGalleryConfigFromURLWithContext without validation, allowing attackers to fetch arbitrary internal URLs.
HTTP-tool OpenAPI schema importer validates only top-level URL before passing to SwaggerParser.bundle, whose remote reference resolver fetches $ref URLs without internal-address guard and returns fetched content.
Advanced operator-assisted fraud campaigns targeting financial institutions with evolving techniques
Elastic Security Labs tracks REF6045, an active operator-assisted banking fraud operation targeting customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges. Campaign combines ClickFix social engineering with cash-out infrastructure.
Unit 42 analyzes cybercrime campaign combining loader-as-a-service framework with DLL sideloading via Go-compiled fake MpClient.dll - a novel evasion layer combination. Campaign also deploys XMRig cryptocurrency miner.
ANY.RUN malware researcher Moises Cerqueira analyzes evolution of Banana RAT through comparison of two recent branches. Analysis started with exposed public index on 198[.]245[.]53[.]26 discovered via Shodan.
Widespread distribution of credential stealers and remote access trojans via multiple delivery mechanisms
Multiple GuLoader instances distributing RemcosRAT through encoded payloads hosted on compromised infrastructure (151.241.154.141:8888). GuLoader continues to be primary delivery mechanism for RAT payloads.
AgentTesla information stealer distributed through ventaslll.com, aair.org.ro, and OpenDrive infrastructure. Campaign uses PNG disguised payloads and rev-base64-loader techniques for evasion.
AsyncRAT and XWorm variants distributed via dragonsurcing.com using RAR archives containing PowerShell stagers. Campaign targets business environments with fake purchasing order lures.
MassLogger credential stealer distributed through Cloudflare Workers infrastructure (shy-hall-9c09.cryptersandtoolsoficial.workers.dev) and compromised hosting (195.177.94.103). Targets credential theft and keylogging.
Persistent Mozi botnet activity targeting IoT devices and network infrastructure
Over 20 distinct Mozi botnet distribution URLs targeting MIPS, ARM, and x86 architectures via wget. Affects routers, IoT devices, and network equipment across multiple IP ranges. Campaign shows continued evolution of P2P botnet infrastructure.
ClearFake malware distribution via compromised sites (bet1yek.bet, site-enfejar-pooyan-mokhtari.com) delivering platform-specific payloads. Campaign uses browser update social engineering tactics.
Chinese APT infrastructure expansion and pro-Russian hacktivist arrest highlight ongoing geopolitical cyber operations
Chinese hackers tracked as UAT-7810 actively evolving LONGLEASH malware to expand Operational Relay Box (ORB) network by compromising internet-facing networking devices, primarily unpatched Ruckus routers. Represents continued targeting of edge infrastructure for persistent access.
Spanish National Police arrested suspected member of CyberArmy of Russia Reborn (CARR) and Z-Pentest pro-Russian hacktivist groups. Represents law enforcement action against geopolitically motivated DDoS and defacement operations.
22 new ransomware victims disclosed across multiple groups targeting diverse sectors including education, healthcare, and critical infrastructure
Mount Royal University, a public Canadian university established in 1910 offering bachelor programs across multiple disciplines, compromised with over 10TB of data allegedly stolen. Represents major higher education sector breach affecting student and faculty data.
YMCA of Western North Carolina - state's largest licensed school-age childcare provider operating 7 fitness centers, summer camps, food trucks, and youth sports programs - compromised by Interlock ransomware. Critical infrastructure and community services impact.
Play ransomware group disclosed 4 new victims: Preneed Funeral Programs (US), Kevin Bao Lenguyen (US accounting), United Infrastructure (UK), and an unnamed entity. Demonstrates continued aggressive operations by established ransomware actor.
Akira ransomware disclosed 5 victims including RISE Architecture (57GB), Chisholm Persson & Ball law firm, Excalibur Rentals (45GB), Edge Solutions/Stone Ridge Payments (67GB). High-value targets across professional services and construction sectors.
Sophisticated phishing operations using trusted brand impersonation and multi-stage redirect chains
Phishing campaign uses trusted brands, nested redirects, and fake Google authentication prompts to steal marketing professionals' accounts. Multi-stage attack chain designed to evade detection while harvesting credentials.
Scammers trick Reddit and Discord users into handing over login codes by claiming involvement in false reports. Social engineering exploits platform trust mechanisms and user fear of account suspension.
Phishing campaign uses several tactics including nested redirects to evade detection and steal credentials from marketing professionals. Campaign leverages brand trust and employment opportunity lures.
Major data exposures affecting government agencies, enterprise IT services, and telco sectors
Washington Department of Social and Health Services announces massive data breach from March 2026. Internal investigation revealed former DSHS employee accessed personal data of approximately 8,600 people without authorization.
IT services giant Accenture confirmed security breach after threat actor claimed to have stolen 35 GB of source code and other sensitive data from the company. Represents significant intellectual property exposure for major consulting firm.
Japanese telecommunications company reports cyberattack exposed 12 million emails. Breach affected email system managing customer email accounts, webmail services, and email storage for five Japanese ISPs.
Jacksonville, Texas took city systems offline after detecting suspicious network activity July 3, determined to be cybersecurity incident. Some online services remained unavailable as investigation continued, impacting municipal operations.
Significant policy shifts in age verification requirements and national cyber defense initiatives
Supreme Court allowed Texas App Store Accountability Act requiring age verification to take effect, declining emergency stay request from student advocacy organization and tech trade group pending lower court ruling.
UK announces plans for autonomous AI-powered Cyber Shield capability designed to counter threats moving at machine speed and greater scale. NCSC initiative aims to reduce detection and response windows against automated attacks.
UK government cyber pledge received limited uptake from top firms despite ministerial appeal. Signatories include Aviva, London Stock Exchange Group, and Marks & Spencer (which lost hundreds of millions in 2025 cyberattack), along with small cybersecurity consultancies.
New forensic tools and research on trauma exposure in digital forensics profession
Forensic Focus announces S21 CCTV v2.0 with AI-powered, offline, and secure video review capabilities. Tool designed to help investigators process hours of CCTV, body-worn, and dashcam footage in minutes to find relevant evidence faster.
Forensic Focus podcast discusses psychological safety, trauma exposure, and long-term emotional toll of working in policing and digital forensics with Ben Dimmock. Addresses critical wellness concerns for DFIR professionals.
These briefings are compiled from publicly available threat-intelligence feeds, which may include CISA KEV, NIST NVD, the GitHub Advisory Database (OSV), abuse.ch, and Wordfence Intelligence. Data-breach and credential-leak items may include data from Have I Been Pwned and ransomware.live.
CVE® is a registered trademark of The MITRE Corporation. CVE Records are © The MITRE Corporation, reproduced under the CVE Program Terms of Use. WordPress vulnerability data is provided by Wordfence Intelligence, © Defiant, Inc. Breach data from Have I Been Pwned is licensed under CC BY 4.0.