The cyber attacks that dominate the headlines are rarely the ones that expose the biggest lessons. It is the patterns that emerge across multiple incidents that tell the real story. July 2026 offered exactly that.
A ransomware attack disrupted Coca-Cola Fairlife's operations. EY investigated a security incident affecting internal systems. Hugging Face responded to a supply chain compromise targeting AI development tools. Critical infrastructure, including Minnesota community water utilities and Japan's KDDI, faced operational disruption, while financial institutions such as Bank of Baroda dealt with customer-facing cyber incidents. Alongside them, organisations including Paidwork, Chick-fil-A, MCBS and Origin Energy demonstrated that no sector is immune when attackers exploit weaknesses in governance, identity, third-party relationships or incident response.
Taken together, these attacks reinforce a message that boards can no longer afford to treat cyber resilience as a purely technical function. The first hours of a major incident are shaped as much by executive decision-making, regulatory obligations, communications and crisis leadership as they are by technical containment. Whether an organisation falls under DORA, NIS2 or another regulatory regime, the pressure to make the right decisions quickly has never been greater.
That is precisely why organisations are investing in realistic cyber crisis leadership programmes, board-level cyber security training, Cyber Tabletop Exercises, DORA documentation and NIS2 readiness training, and recognised incident response qualifications such as our NCSC Assured Cyber Incident Planning and Response training. The organisations that recover most effectively are usually those that have already rehearsed difficult decisions, understood their regulatory responsibilities and prepared both their leadership teams and technical responders before a real incident occurs.
In this month's cyber attack roundup, we examine the most significant cyber incidents from July 2026, what happened, how organisations responded, and the practical lessons security leaders, executives and boards should take away.
|
Date |
Victim |
Summary |
Threat Actor |
Business Impact |
Source Link |
|
July 1, 2026 |
Indra Group |
Major Spanish multinational company specialising in defence, air traffic management, and digital transformation suffers ransomware attack;data allegedly leaked online |
SafePay |
A ransomware attack against Indra Group reportedly resulted in the theft and online exposure of sensitive company data, raising concerns about operational disruption, reputational damage, and potential misuse of compromised information. |
|
|
July 4, 2026 |
Multiple organisations targeted by the JadePuffer ransomware campaign |
JadePuffer Ransomware used AI agent to automate entire attack |
JadePuffer Ransomware operators |
The JadePuffer ransomware campaign used an AI agent to automate key stages of the attack, enabling attackers to compromise targeted systems more efficiently and accelerate ransomware deployment across victim environments. |
|
|
July 16, 2026 |
Fairlife (The Coca-Cola Company) |
Coca-Cola suspended production at its Fairlife Dairy after ransomware attack |
Unknown |
A ransomware attack forced Fairlife to suspend production at its dairy facility, disrupting manufacturing operations and affecting the company's ability to produce and distribute dairy products. |
Source: TechCrunch |
|
July 16, 2026 |
Multiple organisations targeted by the Spirals ransomware campaign (no specific victim was identified). |
New Spirals ransomware encrypts victim network in under 24 hours |
Spirals ransomware operators |
The Spirals ransomware campaign rapidly encrypted victims' networks in less than 24 hours, causing widespread operational disruption and increasing the risk of data loss and extortion. |
Source: Bleeping Computer |
|
July 21, 2026 |
William Buck (NSW accounting and advisory firm) |
NSW Accounting and Advisory Firm allegedly hit by SafePay Ransomware |
SafePay Ransomware |
William Buck was allegedly targeted by the SafePay ransomware group, which claimed to have stolen sensitive company data, exposing the firm to operational disruption, potential data leakage, and extortion. |
Source: www.cyberdaily.au |
|
July 22, 2026 |
Stadler Rail |
Swiss Rail giant Stadler rejects $123M ransom demand after cyber attack |
Anubis ransomware |
A ransomware attack led to the theft of Stadler Rail's data, but the company refused to pay the $123 million ransom demand, increasing the risk of stolen information being publicly leaked while recovery efforts continued. |
Source: Bleeping Computer |
|
July 24, 2026 |
Organisations using vulnerable PTC Windchill and FlexPLM systems |
Clop Ransomware targets Windchill, FlexPLM in data theft attacks |
Clop Ransomware |
The Clop ransomware group exploited vulnerable Windchill and FlexPLM systems to steal sensitive corporate data, exposing affected organisations to extortion, data leaks, and business disruption. |
|
Date |
Victim |
Summary |
Threat Actor |
Business Impact |
Source Link |
|
July 1, 2026 |
MCBS |
MCBS data breach exposes personal information, Murphy Law firm investigates legal claims |
Unknown |
A security incident at MCBS exposed individuals' sensitive personal information, increasing the risk of identity theft, fraud, and other forms of misuse of compromised data. |
|
|
July 1, 2026 |
Homeland Security Information Network (HSIN)/U.S. Department of Homeland Security (DHS) |
DHS confirms hackers breached HSIN information sharing platform |
Unknown |
Hackers breached the HSIN information-sharing platform and gained unauthorised access to sensitive data used by government agencies and security partners, raising concerns about potential exposure of shared intelligence and operational information. |
Source: Bleeping Computer |
|
July 2, 2026 |
Medtronic |
Medtronic notifies customers impacted by ShinyHunters data breach |
ShinyHunters |
A breach linked to the ShinyHunters campaign exposed personal information belonging to Medtronic customers, increasing the risk of identity theft, fraud, and unauthorised use of sensitive data. |
Source: Bleeping Computer |
|
July 6, 2026 |
Singapore Land Authority (SLA) |
70,000 People affected in SLA data breach |
Unknown |
A data breach involving the Singapore Land Authority exposed the personal information of approximately 70,000 individuals, increasing the risk of identity theft and unauthorised misuse of their data. |
Source: www.frontier-enterprise.com |
|
July 6, 2026 |
Blank Rome LLP |
US Law firm Blank Rome faces Class Action over data breach |
Unknown |
A data breach at Blank Rome exposed sensitive personal information, prompting a proposed class-action lawsuit over the firm's alleged failure to adequately protect the affected data. |
Source: Reuters |
|
July 6, 2026 |
Masimo Corporation |
Medical device maker notifies nearly 4 million of breach |
Unknown |
A cyber incident at Masimo exposed the personal information of nearly 4 million individuals, increasing the risk of identity theft, fraud, and unauthorised misuse of sensitive data. |
|
|
July 8, 2026 |
Mount Royal University |
Mount Royal University confirms breach as hackers claim attack |
World Leaks |
Mount Royal University confirmed that a cyber breach exposed sensitive university data after the World Leaks extortion group claimed responsibility and threatened to publish the stolen information. |
Source: Bleeping Computer |
|
July 8,2026 |
KDDI Corporation |
Japanese Telecom Giant KDDI says data breach affects 12 million people |
Unknown |
A data breach at KDDI exposed the personal information of up to 12 million customers, increasing the risk of identity theft, fraud, and unauthorized use of their data. |
Source: Bleeping Computer |
|
July 8, 2026 |
AssuranceAmerica |
AssuranceAmerica data breach: Edelson Lechtzin LLP launches class action investigation |
Unknown |
A data breach at AssuranceAmerica exposed sensitive personal information belonging to affected individuals, increasing the risk of identity theft, financial fraud, and other forms of data misuse. |
Source: www.globenewswire.com |
|
July 8, 2026 |
Accenture |
Accenture confirms data breach after hacker claims source code theft |
Unknown |
A data breach at Accenture resulted in the theft of company data, including source code, raising concerns about the potential exposure of proprietary information and misuse of the compromised files. |
|
|
July 8, 2026 |
Multiple organisations and individuals whose driver's license records were exposed |
Another massive data breach exposed millions of driver's license numbers |
Unknown |
A large-scale data breach exposed millions of driver's license numbers and related personal information, significantly increasing the risk of identity theft, fraud, and unauthorized misuse of the compromised data. |
Source: Tech Crunch |
|
July 13, 2026 |
Lidl |
Lidl discloses online shop breach after service provider hack |
Unknown |
A breach involving one of Lidl's service providers exposed online shop customer information, increasing the risk of phishing, identity theft, and unauthorised use of personal data. |
Source: Bleeping Computer |
|
July 17, 27 2026 |
Ernst & Young (EY) |
EY data breach exposes employee information after third-party platform compromise |
Shinyhunters |
A third-party platform compromise exposed sensitive employee information belonging to EY, increasing the risk of identity theft, phishing, and unauthorised misuse of personal data. |
Source: BleepingComputer |
|
July 21, 2026 |
Craneware |
Health Tech firm craneware admits significant volume of customer and employee data exposed in cyber attack |
Unknown |
A cyber attack exposed a significant volume of Craneware's customer and employee data, increasing the risk of unauthorised access, identity theft, and misuse of sensitive information. |
Source: www.itpro.com |
|
July 22, 24, 2026 |
Chick-fil-A |
Chick-fil-A discloses data breach after credential stuffing attacks |
Unknown |
A data breach affected more than 13,000 Chick-fil-A customers after attackers gained unauthorized access to customer accounts, exposing personal information and increasing the risk of account misuse and identity fraud. |
Source: Bleeping Computer |
|
July 22, 2026 |
Paidwork |
Paidwork breach exposes data of 23 million users |
Unknown |
A data breach exposed the personal information of approximately 23 million Paidwork users, increasing the risk of phishing, identity theft, credential abuse, and other fraudulent activity. |
|
|
July 22, 2026 |
South Korea's Ministry of Foreign Affairs |
South Korea discloses data breach impacting diplomats worldwide |
Unknown |
A data breach at South Korea's Ministry of Foreign Affairs exposed the personal information of diplomats and diplomatic personnel worldwide, increasing the risk of phishing, identity theft, and targeted espionage. |
Source: Bleeping Computer |
|
July 23, 2026 |
Unlimited Technology Systems (UTS) |
Patient data exposed in cybersecurity incident at Ohio Revenue cycle management company |
Unknown |
A cybersecurity incident exposed patients' personal and protected health information after unauthorized actors accessed data managed by Unlimited Technology Systems, increasing the risk of identity theft and healthcare fraud. |
Source: www.hipaajournal.com |
|
July 23, 2026 |
South Korean Ministry of Foreign Affairs and Korea National Diplomatic Academy (KNDA) |
Foreign Ministry plans to change diplomats' email addresses after data breach |
Unknown |
A long running cyber intrusion exposed personal information of around 10,000 current and former South Korean diplomats and government personnel, prompting the Foreign Ministry to replace diplomats' email addresses to reduce the risk of phishing and further cyber abuse. |
|
|
July 24, 2026 |
OnTrac |
OnTrac notifies customers of data breach after network hack |
Unknown |
A network hack led to a data breach at OnTrac, exposing customers' personal information and increasing the risk of identity theft, phishing, and other fraudulent activity. |
Source: Bleeping Computer |
|
July 24, 2026 |
Origin Energy |
Australia's Origin Energy confirms customer data breach |
Unknown |
Unauthorised access exposed Origin Energy customer data, including personal and partial financial information, increasing the risk of phishing, identity theft, and other fraud against affected customers. |
Source: Reuters |
|
July 27, 2026 |
Bank of Baroda |
Bank of Baroda confirms data breach; cybersecurity experts see 1TB breach as concerning |
Threat actor named TripleX |
Bank of Baroda confirmed a data breach after attackers gained unauthorised access through a compromised employee email account, leading to the alleged exposure of nearly 1 TB of sensitive customer and internal banking data while its core banking systems remained unaffected. |
Source: Fortune India |
|
July 28, 2026 |
Medical Computer Business Services (MCBS) |
Medical billing vendor hack affects 1.3 million patients |
PEAR ransomware group |
A cyber intrusion at medical billing provider MCBS exposed sensitive personal and medical information belonging to nearly 1.3 million patients across multiple healthcare organisations, prompting breach notifications and ongoing investigations. |
Source: www.bankinfosecurity.com |
|
July 29, 2026 |
SplitVPN |
VPN breach exposes 58 million connection logs despite no-logs claims |
Unknown |
A data breach exposed more than 58 million VPN connection logs from SplitVPN, revealing that the provider had retained sensitive connection records despite advertising a strict no logs policy, raising serious privacy concerns for its users. |
Source: Security Affairs |
|
July 29, 2026 |
UK Department for Education |
Hackers steal sensitive data from UK Department for Education and police |
ExfilSquad |
Hackers breached the UK Department for Education and the Police National Legal Database, stealing more than 740,000 records containing contact details of government staff, educators, police personnel and members of the public before demanding payment to prevent further data leaks. |
Source: The Guardian |
|
Date |
Victim |
Summary |
Threat Actor |
Business Impact |
Source Link |
|
July 2, 2026 |
Python developers and organisations relying on compromised Python packages |
ChocoPoc Targets Python Dependencies in Supply Chain Attack |
ChocoPoc |
The ChocoPoc campaign targeted Python dependencies to distribute malicious code, putting developers and organisations at risk of system compromise, credential theft, and unauthorised access through the software supply chain. |
|
|
July 6, 2026 |
Organisations and employees targeted through Microsoft Teams |
Fake IT Support Calls on Microsoft Teams Push EtherRAT Malware |
Unknown |
Attackers impersonated IT support staff on Microsoft Teams to trick employees into installing EtherRAT malware, giving them remote access to compromised systems and enabling further malicious activity. |
Source: Bleeping Computer |
|
July 7, 2026 |
Organisations and internet-facing devices targeted by the LongLeash malware campaign |
Chinese hackers develop LongLeash malware to expand ORB network |
Unknown |
Chinese threat actors used the LongLeash malware to expand their Operational Relay Box (ORB) network, compromising internet-connected devices to strengthen covert infrastructure for future cyber operations. |
Source: Bleeping Computer |
|
July 10, 2026 |
Odido Netherlands |
Dutch Police suspect Dutch accomplice in Odido cyber attack |
Unknown (Dutch police arrested a suspected Dutch accomplice, but no specific hacking group was publicly identified in the article). |
A cyber attack against Odido disrupted telecommunications services and compromised customer data, prompting a criminal investigation into individuals suspected of assisting the attackers. |
Source: The Record |
|
July 12, 2026 |
Android users targeted by the RedHook malware campaign |
RedHook Android malware now uses Wireless ADB for shell access |
Unknown |
The RedHook malware abused Wireless ADB to gain shell access on infected Android devices, allowing attackers to execute commands, maintain persistent access, and carry out further malicious activities. |
Source: Bleeping Computer |
|
July 13, 2026 |
Nihon Kotsu |
Japan's largest Taxi operator shuts systems after cyber attack |
Unknown |
A cyber attack forced Nihon Kotsu to shut down internal systems, disrupting business operations and affecting the company's ability to provide normal taxi services while recovery efforts were underway. |
Source: Bleeping Computer |
|
July 13, 2026 |
Developers and organisations using the compromised Jscrambler npm package |
Hackers backdoor Jscrambler npm package with infostealer malware |
Unknown |
Attackers backdoored the Jscrambler npm package to deliver infostealer malware, allowing them to steal credentials and sensitive data from developers and potentially compromise downstream software supply chains. |
Source: Bleeping Computer |
|
July 13, 2026 |
Apple macOS users |
New CrashStealer malware poses as Apple crash reporting tool |
Unknown |
CrashStealer malware impersonated Apple's crash reporting tool to trick macOS users into installing malware that stole sensitive information and gave attackers unauthorized access to compromised devices. |
Source: Bleeping Computer |
|
July 14, 2026 |
Developers and users who downloaded software from the malicious GitHub repositories |
Nearly 300 GitHub Repos Pose as Legit Software to Push Malware |
Unknown |
Attackers used nearly 300 fake GitHub repositories to distribute malware disguised as legitimate software, compromising users' devices and enabling credential theft and further system compromise. |
Source: Bleeping Computer |
|
July 15, 2026 |
Developers and organisations using the compromised AsyncAPI npm packages |
AsyncAPI npm packages infected with credential-stealing malware |
Unknown |
Compromised AsyncAPI npm packages stole developers' credentials and sensitive information, putting affected systems and software supply chains at risk of further compromise. |
Source: Bleeping Computer |
|
July 16, 2026 |
macOS users |
New ClickLock macOS malware traps users into revealing login password |
Unknown |
The ClickLock malware tricked macOS users into revealing their login passwords, allowing attackers to steal credentials and potentially gain unauthorised access to compromised devices and accounts. |
Source: Bleeping Computer |
|
July 16, 2026 |
Users of Webex and Zoom applications |
Russian hackers trojanize Webex, Zoom Apps to push starland malware |
Russian hackers |
Russian hackers distributed trojanized Webex and Zoom applications to infect victims with Starland malware, enabling unauthorised access to compromised systems and facilitating further malicious activity. |
Source: Bleeping Computer |
|
July 20, 2026 |
Hugging Face |
World's Largest AI model repository Hugging Face breached by autonomous AI agent |
Autonomous AI agent |
An autonomous AI agent breached Hugging Face by exploiting vulnerabilities in AI model repositories, raising concerns about unauthorised access, software supply chain security, and the integrity of hosted AI models. |
|
|
July 22, 2026 |
Upbound Group (Acima) |
Upbound says hack caused $13 million in fraudulent Acima leases |
Unknown |
A cyber attack enabled fraudsters to create approximately $13 million in fraudulent Acima lease agreements, resulting in significant financial losses and operational disruption for Upbound. |
Source: Bleeping Computer |
|
July 23, 2026 |
Windows users and organisations targeted by the MsaRAT malware campaign |
New MsaRAT Malware Uses Chrome, Edge Browsers to Route C2 Traffic |
Unknown |
The MsaRAT malware abused Google Chrome and Microsoft Edge to route its command-and-control traffic, helping attackers evade detection while maintaining covert access to compromised systems. |
Source: Bleeping Computer |
|
July 23, 2026 |
Notepad++ users who installed the malicious plugins |
Hackers Abuse Notepad++ Plugins to Stealthily Install Malware |
Unknown |
Attackers abused malicious Notepad++ plugins to quietly install malware on victims' systems, giving them unauthorised access and increasing the risk of credential theft and further compromise. |
Source: Bleeping Computer |
|
July 23, 2026 |
Users searching for and downloading the fake Claude AI application |
Fake Claude app promoted by Bing ads pushes SectopRAT malware |
Unknown |
Attackers used malicious Bing advertisements to distribute a fake Claude AI application that installed SectopRAT malware, giving them remote access to victims' devices and exposing sensitive data to theft. |
Source: Bleeping Computer |
|
July 23, 2026 |
Organisations and individuals targeted by the Dolphin-X malware campaign |
New Dolphin-X Malware Uses AI to Rank High-Value Targets |
Unknown |
The Dolphin-X malware used AI to identify and prioritise high-value victims, helping attackers focus their efforts on targets most likely to yield valuable data and facilitate further compromise. |
Source: Bleeping Computer |
|
July 23, 2026 |
Users who visited the malicious websites |
Malicious sites use JavaScript to build malware in browser memory |
Unknown |
Malicious websites used JavaScript to assemble malware directly in browser memory, helping attackers evade security detection and infect victims' devices with malicious payloads. |
Source: Bleeping Computer |
|
July 24, 2026 |
Hotel guests and users of Microsoft 365 accounts connected to the compromised hotel Wi-Fi networks |
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts |
Unknown |
Attackers hijacked hotel Wi-Fi DNS settings to redirect users to fake Microsoft 365 login pages, stealing account credentials and enabling unauthorised access to victims' accounts. |
Source: Bleeping Computer |
|
July 29, 2026 |
Minnesota community water utilities |
Iran-linked CyberAv3ngers suspected in attacks on Minnesota water systems |
CyberAv3ngers (suspected), an Iran-linked hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC) |
A coordinated cyber attack targeted operational technology at more than 30 Minnesota community water systems, briefly disrupting automated controls at several facilities while authorities confirmed that drinking water remained safe and response teams quickly contained the incidents. |
Source: The Register |
|
New Ransomware |
Summary |
|
msaRAT trojan |
A newly discovered remote access trojan named msaRAT was found being deployed by the Chaos ransomware group to gain persistent access before encrypting victims' systems. |
|
Avalon malware frame |
Researchers uncovered a new malware framework called Avalon that enhanced ransomware operations by providing modular post-exploitation capabilities and payload delivery. |
|
JADEPUFFER ransomware agent |
Security researchers documented JADEPUFFER, an AI-driven autonomous ransomware agent that demonstrated how large language models could independently execute a ransomware attack chain. |
|
Date |
New Flaws/Fixes |
Summary |
|
July 2, 2026 |
CVE-2026-48276, CVE-2026-48277, CVE-2026-48281, CVE-2026-48316, CVE-2026-48282, CVE-2026-48286 |
Adobe released urgent patches for seven maximum-severity vulnerabilities in ColdFusion and Campaign Classic that could allow attackers to execute arbitrary code on unpatched systems, urging customers to update immediately. |
|
July 2, 2026 |
CVE-2025-20309 |
Cisco confirmed that attackers had actively exploited a critical vulnerability in Unified Communications Manager (Unified CM), prompting organisations to patch affected systems as soon as possible. |
|
July 2, 2026 |
CVE-2025-53770 |
CISA confirmed that attackers had actively exploited a critical Microsoft SharePoint remote code execution vulnerability and urged organisations to apply the available security updates without delay. |
|
July 6, 2026 |
CVE-2026-48279 |
Adobe confirmed that attackers had actively exploited a maximum-severity ColdFusion vulnerability that could allow arbitrary code execution, prompting organizations to apply security updates immediately. |
|
June 7, 2026 |
CVE-2025-53098 and CVE-2025-53099 |
BeyondTrust disclosed critical vulnerabilities in its Remote Support and Privileged Remote Access products that could allow attackers to execute arbitrary code or compromise affected systems, urging customers to apply the available patches promptly. |
|
July 8, 2026 |
CVE-2026-48279 |
CISA added a maximum-severity Adobe ColdFusion vulnerability to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch affected systems by Friday after the flaw was actively exploited. |
|
July 8, 2026 |
CVE-2025-3248 |
CISA added a critical Langflow authentication bypass vulnerability to its Known Exploited Vulnerabilities catalog and directed federal agencies to prioritise patching after the flaw was found to be actively exploited. |
|
July 10, 2026 |
CVE-2025-4631, CVE-2025-4632, CVE-2025-4633, CVE-2025-4634, CVE-2025-4635 |
Researchers disclosed multiple vulnerabilities in the U-Boot bootloader that could have enabled attackers to carry out stealthy firmware-level attacks and urged vendors to apply the available security fixes. |
|
July 10, 2026 |
CVE-2025-53901 |
Zimbra urged customers to immediately patch a critical cross-site scripting (XSS) vulnerability in its web client to prevent attackers from executing malicious scripts and compromising user accounts. |
|
July 14, 2026 |
CVE-2025-5777 |
Progress confirmed that a zero-day vulnerability in ShareFile was responsible for the shutdown of customer-managed StorageZone services and urged customers to apply the available security updates immediately. |
|
July 18, 2026 |
CVE-2025-55188 |
7-Zip released a security update to fix a remote code execution vulnerability that could have allowed attackers to run malicious code by tricking users into opening specially crafted archive files. |
|
July 18, 2026 |
CVE-2025-6463 and CVE-2025-6464 |
Public exploit code became available for critical WordPress Core "WP2Shell" remote code execution vulnerabilities, prompting website administrators to patch their systems immediately to prevent compromise. |
|
July 16, 2026 |
CVE-2026-31311 |
CISA added an actively exploited Oracle vulnerability to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch affected systems by Saturday to reduce the risk of compromise. |
|
July 22, 2026 |
CVE-2026-0770 |
CISA ordered U.S. federal agencies to urgently patch an actively exploited Langflow remote code execution vulnerability after attackers were observed using it to compromise vulnerable AI workflow servers. |
|
July 22, 2026 |
CVE-2026-42311 |
Researchers disclosed a vulnerability in Adobe's Chrome extension that could have allowed malicious websites to access users' private WhatsApp chats, and Adobe released a fix to address the issue. |
|
July 23, 2026 |
CVE-2026-64600 |
Researchers disclosed the RefluXFS vulnerability in the Linux kernel that could have allowed local attackers to gain root privileges through a flaw in the XFS filesystem, and they urged organizations to apply the latest kernel updates. |
|
July 23, 2026 |
CVE-2025-66376 |
Russian state-backed hackers exploited a zero-click vulnerability in Zimbra Collaboration Suite to steal emails and authentication data from targeted organisations, prompting authorities to urge immediate patching of vulnerable servers. |
|
News Type |
Summary |
|
Report |
A report alleged that Russian hackers were behind a cyberattack on Jaguar Land Rover that resulted in an estimated $2.5 billion in losses, underscoring the significant financial impact major cyber incidents can have on global manufacturers. |
|
Warning |
Researchers warned that attackers launched more than 81 million login attempts against Microsoft 365 accounts, highlighting a large-scale campaign aimed at compromising user credentials through password-spraying techniques. |
|
Warning |
Ubiquiti warned customers about a newly discovered maximum-severity vulnerability in UniFi OS that could allow attackers to compromise affected devices and urged users to install the latest security updates promptly. |
|
Report |
Researchers reported that a ransomware group claimed to have breached Deutsche Bank and stolen sensitive data, although the bank stated it was investigating the claims and had not confirmed a compromise. |
|
Report |
Finnish authorities issued an international wanted notice for the suspect behind the Vastaamo psychotherapy clinic breach as they continued efforts to bring the alleged hacker to justice for the large-scale theft and extortion of patient data. |
|
Report |
The EU and UK jointly imposed sanctions on Russian cyber actors and supporting entities to disrupt their ability to carry out future cyber attacks and reduce the threat posed to governments, businesses, and critical infrastructure. |
|
Report |
Hackers leaked data they claimed belonged to Russian journalist and television personality Ksenia Sobchak, highlighting another high-profile cyber incident targeting a prominent public figure. |
|
Report |
Researchers reported that hackers abused legitimate ViPNet software to target Russian government agencies, using trusted tools to gain access and carry out covert cyber-espionage activities. |
|
Warning |
Microsoft warned that ACR Stealer malware attacks had surged, with cyber criminals increasingly targeting customers to steal credentials and other sensitive information from compromised devices. |
|
Warning |
Zoom warned customers about a critical vulnerability that could have allowed attackers to take over user accounts and urged users to update affected software to protect against potential exploitation. |
|
Warning |
CISA warned administrators to immediately patch actively exploited Microsoft SharePoint vulnerabilities after attackers were observed using the flaws to compromise vulnerable servers. |
|
Warning |
SonicWall warned that attackers had exploited zero-day vulnerabilities in SMA1000 appliances and urged customers to apply the available patches immediately to prevent further compromises. |
|
Warning |
SAP warned customers about critical vulnerabilities affecting NetWeaver and Commerce Cloud that could have allowed attackers to compromise vulnerable systems and urged users to apply the latest security patches promptly. |
|
Report |
The U.S. government imposed sanctions on VPN and malware service providers that allegedly supported ransomware gangs, aiming to disrupt the infrastructure used to facilitate cyberattacks. |
|
Warning |
CISA warned that attackers had actively exploited remote code execution vulnerabilities in multiple Joomla extensions and urged administrators to update affected installations immediately. |
|
Warning |
Australia warned that a global campaign had targeted vulnerable CMS platforms by exploiting unpatched flaws and urged organizations to update their systems immediately to reduce the risk of compromise. |
|
Report |
Researchers reported that the newly identified Helix vishing group had targeted organizations by using phone-based social engineering alongside SharePoint attacks to steal sensitive data and gain unauthorized access to corporate environments. |
|
Warnings |
Check Point warned that attackers had exploited a zero-day vulnerability in SmartConsole and urged customers to install the latest security update to prevent potential system compromise. |