The 26-27 July 2026 period saw significant ransomware activity with 30 organizations targeted by multiple groups, including a massive campaign by Global Secret Group affecting critical infrastructure, healthcare, and financial sectors across multiple continents. The healthcare sector faces particular risk with AnMed hospital system experiencing an active phone and internet outage of unknown origin, while SPDM (Brazil) was hit by ransomware affecting a large healthcare organization with 10,000-20,000 employees. Supply chain security received positive developments as GitHub and PyPI implemented time-based defenses against supply chain attacks in Dependabot. Six high-severity CVEs were disclosed, including critical vulnerabilities in Microsoft Edge and multiple code injection flaws in development tools. Mirai botnet activity remains elevated with 49 malicious URLs detected distributing variants across multiple architectures, indicating ongoing IoT device targeting.
Global Secret Group conducted an extensive ransomware campaign affecting 26 organizations across healthcare, finance, energy, manufacturing, and retail sectors. Additional attacks by DragonForce, Chaos, and Qilin targeted medical supply, logistics, and marketing companies.
Major Brazilian healthcare organization with 10,000-20,000 employees compromised by Global Secret Group. 847 GB of data (871,912 files) stolen including patient and operational data from hospitals and clinics. Revenue: $197 million.
Large manufacturing and electronics company breached with 1.5 TB of data stolen (2.1 million files). Global Secret Group compromised company with 1,000-5,000 employees and $610 million revenue. Potential exposure of manufacturing IP and surveillance technology data.
Energy sector company with $966 million revenue compromised by Global Secret Group. 842 GB of data stolen (971,325 files) from convenience stores and gas stations operations. Critical infrastructure exposure.
All AnMed hospital locations experiencing active phone and internet outage affecting operations. Emergency rooms remain open but communications disrupted. Cause unknown but incident pattern consistent with cyberattack. Four-hospital system serving Upstate South Carolina and northeast Georgia affected.
Furniture and transportation manufacturing company ($517 million revenue, 1K-5K employees) hit by Global Secret Group. 321 GB stolen including operational and supply chain data.
Wholesale and retail furniture company breached with 799 GB of data exfiltrated. $59.4 million revenue company with 100-300 employees targeted by Global Secret Group.
Transportation company with $120 million revenue compromised. 473 GB of logistics and operational data stolen (890,775 files), affecting 201-500 employees.
Large financial services organization (1,000-5,000 employees, £300 million revenue) breached by Global Secret Group. 209 GB of financial data stolen including 255,244 files.
Major hosting provider ($46.3 million revenue, 201-500 employees) compromised by Global Secret Group. Potential exposure of customer cloud infrastructure and backup data.
Law firm data breach exposing 328 GB of sensitive legal documents (708,816 files). Client confidentiality and attorney-client privileged communications at risk.
Accounting firm compromised with 213 GB of client tax and financial records stolen (817,209 files). Sensitive PII and financial data exposure affecting multiple clients.
Brazilian electricity, oil and gas company ($12.2 million revenue) breached with 300 GB stolen. Critical energy infrastructure data exposure.
Major food and beverage distributor ($100 million revenue, 501-1,000 employees) compromised with 138 GB stolen. Supply chain implications for Pepsi distribution network.
Healthcare supply distributor compromised by DragonForce ransomware group. Company provides mobility aids, incontinence supplies, and medical equipment to home healthcare market.
FDA-licensed medical device manufacturer specializing in rapid diagnostic tests compromised by DragonForce. Potential exposure of proprietary testing technology and regulatory data.
Industry-leading warehousing and distribution company founded in 1977 hit by Chaos ransomware group. Serves retail industry with country-wide distribution network across Canada.
Publicly accessible unprotected database exposed records associated with Tribeca Film Festival, including A-list directors, actors, and celebrities. No password protection or encryption implemented. Potential exposure of personal information and festival submission data.
Six high-severity CVEs disclosed affecting Microsoft Edge, code generation tools, and WordPress plugins. Vulnerabilities enable remote code execution, information disclosure, and PHP object injection attacks.
Critical code injection vulnerability in datamodel-code-generator prior to 0.70.0 allows attackers controlling input schemas to achieve RCE via malicious customBasePath values with embedded newlines and Python expressions. CVSS 7.5.
NoteGen before 0.32.0 renders AI chat responses using markdown-it with html:true and injects via dangerouslySetInnerHTML without sanitization. Attacker-controlled content reaching model prompts can achieve XSS. CVSS 8.1.
NoteGen before 0.32.0 grants Tauri shell plugin execution capability for bash, python, and python3 with arbitrary arguments. JavaScript in application webview can invoke plugin to run attacker-controlled commands. CVSS 8.3.
Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows unauthorized attackers to disclose information over a network. CVSS 7.4.
Origin validation error in Microsoft Edge (Chromium-based) enables unauthorized information disclosure over network. CVSS 7.4.
WordPress Fluent Forms Pro Add On Pack plugin (versions up to 6.2.6) vulnerable to PHP Object Injection via untrusted input deserialization. Authenticated attackers with Subscriber-level access can inject PHP objects. CVSS 8.8.
Significant Mirai botnet activity detected with 49 malicious URLs distributing ELF binaries across multiple architectures. Three distinct campaigns identified targeting IoT devices through vulnerable wget implementations.
Botnet domain femboykisser.sbs actively distributing Mirai variants across 14 architectures (arm, arm5, arm6, arm7, arm8, x86, x86_64, mips, mipsel, ppc, ppc64, m68k). Targets IoT devices via wget user-agent exploitation.
DuckDNS-hosted botnet infrastructure distributing 'putita' Mirai variant with shell scripts (busywget.sh, callaputa.sh, curl.sh) and multi-architecture binaries. Indicates sophisticated IoT compromise operation with staging infrastructure.
Direct IP-based Mirai distribution hosting 'flutter' variants for multiple architectures. Indicates command-and-control infrastructure potentially evading DNS-based blocking.
Compromised blog infrastructure (mail.sandystudiogh.blog and sandystudiogh.blog) hosting 'zombie' Mirai binaries targeting multiple architectures including ARM, MIPS, x86, and PPC variants.
IP address hosting ipmiv2.xml file potentially exploiting IPMI (Intelligent Platform Management Interface) vulnerabilities for remote system access.
GitHub and PyPI implemented time-based defenses in Dependabot to protect against supply chain attacks and limit impact of compromised packages.
GitHub and Python Package Index introduced time-based protection mechanisms in Dependabot dependency management tool. New defenses designed to detect and mitigate supply chain attacks by analyzing temporal patterns in package updates and dependencies.
Global Secret Group emerged as highly active ransomware operator with 26 victims in single day, demonstrating significant operational capability and targeting diverse sectors globally.
Global Secret Group conducted coordinated ransomware campaign affecting 26 organizations across 10+ countries in healthcare, finance, energy, manufacturing, retail, legal, and technology sectors. Total data stolen exceeds 5 TB. Campaign demonstrates advanced operational capability, multi-sector targeting, and global reach. Includes critical infrastructure targeting (energy, healthcare) and high-value financial targets.
DragonForce ransomware group targeted two healthcare-related organizations: Deluxe Medical Supply (home healthcare products) and Syntron Bioresearch (FDA-licensed medical device manufacturer). Focus on healthcare supply chain suggests strategic targeting of medical equipment distribution and diagnostic test manufacturing.
These briefings are compiled from publicly available threat-intelligence feeds, which may include CISA KEV, NIST NVD, the GitHub Advisory Database (OSV), abuse.ch, and Wordfence Intelligence. Data-breach and credential-leak items may include data from Have I Been Pwned and ransomware.live.
CVE® is a registered trademark of The MITRE Corporation. CVE Records are © The MITRE Corporation, reproduced under the CVE Program Terms of Use. WordPress vulnerability data is provided by Wordfence Intelligence, © Defiant, Inc. Breach data from Have I Been Pwned is licensed under CC BY 4.0.