Cyber Security Blog

Major Cyber Attacks, Data Breaches, Ransomware Attacks in July 2026

Written by Aditi Uberoi | 3 August 2026

The cyber attacks that dominate the headlines are rarely the ones that expose the biggest lessons. It is the patterns that emerge across multiple incidents that tell the real story. July 2026 offered exactly that. 

  1. Ransomware Attacks in July 2026
  2. Data Breaches in July 2026 
  3. Cyber Attacks in July 2026
  4. New Malware and Ransomware Discovered
  5. Vulnerabilities Discovered and Patches Released 
  6. Advisories issued, reports, analysis etc. in July 2026


A ransomware attack disrupted Coca-Cola Fairlife's operations. EY investigated a security incident affecting internal systems. Hugging Face responded to a supply chain compromise targeting AI development tools. Critical infrastructure, including Minnesota community water utilities and Japan's KDDI, faced operational disruption, while financial institutions such as Bank of Baroda dealt with customer-facing cyber incidents. Alongside them, organisations including Paidwork, Chick-fil-A, MCBS and Origin Energy demonstrated that no sector is immune when attackers exploit weaknesses in governance, identity, third-party relationships or incident response.

Taken together, these attacks reinforce a message that boards can no longer afford to treat cyber resilience as a purely technical function. The first hours of a major incident are shaped as much by executive decision-making, regulatory obligations, communications and crisis leadership as they are by technical containment. Whether an organisation falls under DORA, NIS2 or another regulatory regime, the pressure to make the right decisions quickly has never been greater.

That is precisely why organisations are investing in realistic cyber crisis leadership programmes, board-level cyber security training, Cyber Tabletop Exercises, DORA documentation and NIS2 readiness training, and recognised incident response qualifications such as our NCSC Assured Cyber Incident Planning and Response training. The organisations that recover most effectively are usually those that have already rehearsed difficult decisions, understood their regulatory responsibilities and prepared both their leadership teams and technical responders before a real incident occurs.

In this month's cyber attack roundup, we examine the most significant cyber incidents from July 2026, what happened, how organisations responded, and the practical lessons security leaders, executives and boards should take away.

 

Ransomware Attacks in July 2026

Date

Victim

Summary

Threat Actor

Business Impact

Source Link

July 1, 2026

Indra Group

Major Spanish multinational company specialising in defence, air traffic management, and digital transformation suffers ransomware attack;data allegedly leaked online

SafePay

A ransomware attack against Indra Group reportedly resulted in the theft and online exposure of sensitive company data, raising concerns about operational disruption, reputational damage, and potential misuse of compromised information.

Indra Group Ransomware Attack

July 4, 2026

Multiple organisations targeted by the JadePuffer ransomware campaign

JadePuffer Ransomware used AI agent to automate entire attack

JadePuffer Ransomware operators

The JadePuffer ransomware campaign used an AI agent to automate key stages of the attack, enabling attackers to compromise targeted systems more efficiently and accelerate ransomware deployment across victim environments.

JadePuffer Ransomware Attack Using AI Agent

July 16, 2026

Fairlife (The Coca-Cola Company)

Coca-Cola suspended production at its Fairlife Dairy after ransomware attack

Unknown

A ransomware attack forced Fairlife to suspend production at its dairy facility, disrupting manufacturing operations and affecting the company's ability to produce and distribute dairy products.

Source: TechCrunch

July 16, 2026

Multiple organisations targeted by the Spirals ransomware campaign (no specific victim was identified).

New Spirals ransomware encrypts victim network in under 24 hours

Spirals ransomware operators

The Spirals ransomware campaign rapidly encrypted victims' networks in less than 24 hours, causing widespread operational disruption and increasing the risk of data loss and extortion.

Source: Bleeping Computer

July 21, 2026

William Buck (NSW accounting and advisory firm)

NSW Accounting and Advisory Firm allegedly hit by SafePay Ransomware

SafePay Ransomware

William Buck was allegedly targeted by the SafePay ransomware group, which claimed to have stolen sensitive company data, exposing the firm to operational disruption, potential data leakage, and extortion.

Source: www.cyberdaily.au

July 22, 2026

Stadler Rail

Swiss Rail giant Stadler rejects $123M ransom demand after cyber attack

Anubis ransomware

A ransomware attack led to the theft of Stadler Rail's data, but the company refused to pay the $123 million ransom demand, increasing the risk of stolen information being publicly leaked while recovery efforts continued.

Source: Bleeping Computer

July 24, 2026

Organisations using vulnerable PTC Windchill and FlexPLM systems

Clop Ransomware targets Windchill, FlexPLM in data theft attacks

Clop Ransomware

The Clop ransomware group exploited vulnerable Windchill and FlexPLM systems to steal sensitive corporate data, exposing affected organisations to extortion, data leaks, and business disruption.



Clop Ransomware targets Windchill, FlexPLM

 
 


 Back to Top 

 

Data Breaches in July 2026

Date

Victim

Summary

Threat Actor

Business Impact

Source Link

July 1, 2026

MCBS

MCBS data breach exposes personal information, Murphy Law firm investigates legal claims

Unknown

A security incident at MCBS exposed individuals' sensitive personal information, increasing the risk of identity theft, fraud, and other forms of misuse of compromised data.

MCBS Data Breach

July 1, 2026

Homeland Security Information Network (HSIN)/U.S. Department of Homeland Security (DHS)

DHS confirms hackers breached HSIN information sharing platform

Unknown

Hackers breached the HSIN information-sharing platform and gained unauthorised access to sensitive data used by government agencies and security partners, raising concerns about potential exposure of shared intelligence and operational information.

Source: Bleeping Computer

July 2, 2026

Medtronic

Medtronic notifies customers impacted by ShinyHunters data breach

ShinyHunters

A breach linked to the ShinyHunters campaign exposed personal information belonging to Medtronic customers, increasing the risk of identity theft, fraud, and unauthorised use of sensitive data.

Source: Bleeping Computer

July 6, 2026

Singapore Land Authority (SLA)

70,000 People affected in SLA data breach

Unknown

A data breach involving the Singapore Land Authority exposed the personal information of approximately 70,000 individuals, increasing the risk of identity theft and unauthorised misuse of their data.

Source: www.frontier-enterprise.com

July 6, 2026

Blank Rome LLP

US Law firm Blank Rome faces Class Action over data breach

Unknown

A data breach at Blank Rome exposed sensitive personal information, prompting a proposed class-action lawsuit over the firm's alleged failure to adequately protect the affected data.

Source: Reuters

July 6, 2026

Masimo Corporation

Medical device maker notifies nearly 4 million of breach

Unknown

A cyber incident at Masimo exposed the personal information of nearly 4 million individuals, increasing the risk of identity theft, fraud, and unauthorised misuse of sensitive data.

Medical device maker Masimo Corporation Data Breach

July 8, 2026

Mount Royal University

Mount Royal University confirms breach as hackers claim attack

World Leaks

Mount Royal University confirmed that a cyber breach exposed sensitive university data after the World Leaks extortion group claimed responsibility and threatened to publish the stolen information.

Source: Bleeping Computer

July 8,2026

KDDI Corporation

Japanese Telecom Giant KDDI says data breach affects 12 million people

Unknown

A data breach at KDDI exposed the personal information of up to 12 million customers, increasing the risk of identity theft, fraud, and unauthorized use of their data.

Source: Bleeping Computer

July 8, 2026

AssuranceAmerica

AssuranceAmerica data breach: Edelson Lechtzin LLP launches class action investigation

Unknown

A data breach at AssuranceAmerica exposed sensitive personal information belonging to affected individuals, increasing the risk of identity theft, financial fraud, and other forms of data misuse.

Source: www.globenewswire.com

July 8, 2026

Accenture

Accenture confirms data breach after hacker claims source code theft

Unknown

A data breach at Accenture resulted in the theft of company data, including source code, raising concerns about the potential exposure of proprietary information and misuse of the compromised files.

Accenture Data Breach

July 8, 2026

Multiple organisations and individuals whose driver's license records were exposed

Another massive data breach exposed millions of driver's license numbers

Unknown

A large-scale data breach exposed millions of driver's license numbers and related personal information, significantly increasing the risk of identity theft, fraud, and unauthorized misuse of the compromised data.

Source: Tech Crunch

July 13, 2026

Lidl

Lidl discloses online shop breach after service provider hack

Unknown

A breach involving one of Lidl's service providers exposed online shop customer information, increasing the risk of phishing, identity theft, and unauthorised use of personal data.

Source: Bleeping Computer

July 17, 27 2026

Ernst & Young (EY)

EY data breach exposes employee information after third-party platform compromise

Shinyhunters

A third-party platform compromise exposed sensitive employee information belonging to EY, increasing the risk of identity theft, phishing, and unauthorised misuse of personal data.

Source: BleepingComputer

July 21, 2026

Craneware

Health Tech firm craneware admits significant volume of customer and employee data exposed in cyber attack

Unknown

A cyber attack exposed a significant volume of Craneware's customer and employee data, increasing the risk of unauthorised access, identity theft, and misuse of sensitive information.

Source: www.itpro.com

July 22, 24, 2026

Chick-fil-A

Chick-fil-A discloses data breach after credential stuffing attacks

Unknown

A data breach affected more than 13,000 Chick-fil-A customers after attackers gained unauthorized access to customer accounts, exposing personal information and increasing the risk of account misuse and identity fraud.

Source: Bleeping Computer

July 22, 2026

Paidwork

Paidwork breach exposes data of 23 million users

Unknown

A data breach exposed the personal information of approximately 23 million Paidwork users, increasing the risk of phishing, identity theft, credential abuse, and other fraudulent activity.

Paidwork Data Breach

July 22, 2026

South Korea's Ministry of Foreign Affairs

South Korea discloses data breach impacting diplomats worldwide

Unknown

A data breach at South Korea's Ministry of Foreign Affairs exposed the personal information of diplomats and diplomatic personnel worldwide, increasing the risk of phishing, identity theft, and targeted espionage.

Source: Bleeping Computer

July 23, 2026

Unlimited Technology Systems (UTS)

Patient data exposed in cybersecurity incident at Ohio Revenue cycle management company

Unknown

A cybersecurity incident exposed patients' personal and protected health information after unauthorized actors accessed data managed by Unlimited Technology Systems, increasing the risk of identity theft and healthcare fraud.

Source: www.hipaajournal.com

July 23, 2026

South Korean Ministry of Foreign Affairs and Korea National Diplomatic Academy (KNDA)

Foreign Ministry plans to change diplomats' email addresses after data breach

Unknown

A long running cyber intrusion exposed personal information of around 10,000 current and former South Korean diplomats and government personnel, prompting the Foreign Ministry to replace diplomats' email addresses to reduce the risk of phishing and further cyber abuse.

South Korean diplomats and government personnel data breach

July 24, 2026

OnTrac

OnTrac notifies customers of data breach after network hack

Unknown

A network hack led to a data breach at OnTrac, exposing customers' personal information and increasing the risk of identity theft, phishing, and other fraudulent activity.

Source: Bleeping Computer

July 24, 2026

Origin Energy

Australia's Origin Energy confirms customer data breach

Unknown

Unauthorised access exposed Origin Energy customer data, including personal and partial financial information, increasing the risk of phishing, identity theft, and other fraud against affected customers.

Source: Reuters

July 27, 2026

Bank of Baroda

Bank of Baroda confirms data breach; cybersecurity experts see 1TB breach as concerning

Threat actor named TripleX

Bank of Baroda confirmed a data breach after attackers gained unauthorised access through a compromised employee email account, leading to the alleged exposure of nearly 1 TB of sensitive customer and internal banking data while its core banking systems remained unaffected.

Source: Fortune India

July 28, 2026

Medical Computer Business Services (MCBS)

Medical billing vendor hack affects 1.3 million patients

PEAR ransomware group

A cyber intrusion at medical billing provider MCBS exposed sensitive personal and medical information belonging to nearly 1.3 million patients across multiple healthcare organisations, prompting breach notifications and ongoing investigations.

Source: www.bankinfosecurity.com

July 29, 2026

SplitVPN

VPN breach exposes 58 million connection logs despite no-logs claims

Unknown

A data breach exposed more than 58 million VPN connection logs from SplitVPN, revealing that the provider had retained sensitive connection records despite advertising a strict no logs policy, raising serious privacy concerns for its users.

Source: Security Affairs

July 29, 2026

UK Department for Education

Hackers steal sensitive data from UK Department for Education and police

ExfilSquad

Hackers breached the UK Department for Education and the Police National Legal Database, stealing more than 740,000 records containing contact details of government staff, educators, police personnel and members of the public before demanding payment to prevent further data leaks.

Source: The Guardian

 
  
 

Back to Top 

Cyber Attacks in July 2026

Date

Victim

Summary

Threat Actor

Business Impact

Source Link

July 2, 2026

Python developers and organisations relying on compromised Python packages

ChocoPoc Targets Python Dependencies in Supply Chain Attack

ChocoPoc

The ChocoPoc campaign targeted Python dependencies to distribute malicious code, putting developers and organisations at risk of system compromise, credential theft, and unauthorised access through the software supply chain.

ChocoPoc Targets Python Dependencies

July 6, 2026

Organisations and employees targeted through Microsoft Teams

Fake IT Support Calls on Microsoft Teams Push EtherRAT Malware

Unknown

Attackers impersonated IT support staff on Microsoft Teams to trick employees into installing EtherRAT malware, giving them remote access to compromised systems and enabling further malicious activity.

Source: Bleeping Computer

July 7, 2026

Organisations and internet-facing devices targeted by the LongLeash malware campaign

Chinese hackers develop LongLeash malware to expand ORB network

Unknown

Chinese threat actors used the LongLeash malware to expand their Operational Relay Box (ORB) network, compromising internet-connected devices to strengthen covert infrastructure for future cyber operations.

Source: Bleeping Computer

July 10, 2026

Odido Netherlands

Dutch Police suspect Dutch accomplice in Odido cyber attack

Unknown (Dutch police arrested a suspected Dutch accomplice, but no specific hacking group was publicly identified in the article).

A cyber attack against Odido disrupted telecommunications services and compromised customer data, prompting a criminal investigation into individuals suspected of assisting the attackers.

Source: The Record

July 12, 2026

Android users targeted by the RedHook malware campaign

RedHook Android malware now uses Wireless ADB for shell access

Unknown

The RedHook malware abused Wireless ADB to gain shell access on infected Android devices, allowing attackers to execute commands, maintain persistent access, and carry out further malicious activities.

Source: Bleeping Computer

July 13, 2026

Nihon Kotsu

Japan's largest Taxi operator shuts systems after cyber attack

Unknown

A cyber attack forced Nihon Kotsu to shut down internal systems, disrupting business operations and affecting the company's ability to provide normal taxi services while recovery efforts were underway.

Source: Bleeping Computer

July 13, 2026

Developers and organisations using the compromised Jscrambler npm package

Hackers backdoor Jscrambler npm package with infostealer malware

Unknown

Attackers backdoored the Jscrambler npm package to deliver infostealer malware, allowing them to steal credentials and sensitive data from developers and potentially compromise downstream software supply chains.

Source: Bleeping Computer

July 13, 2026

Apple macOS users

New CrashStealer malware poses as Apple crash reporting tool

Unknown

CrashStealer malware impersonated Apple's crash reporting tool to trick macOS users into installing malware that stole sensitive information and gave attackers unauthorized access to compromised devices.

Source: Bleeping Computer

July 14, 2026

Developers and users who downloaded software from the malicious GitHub repositories

Nearly 300 GitHub Repos Pose as Legit Software to Push Malware

Unknown

Attackers used nearly 300 fake GitHub repositories to distribute malware disguised as legitimate software, compromising users' devices and enabling credential theft and further system compromise.

Source: Bleeping Computer

July 15, 2026

Developers and organisations using the compromised AsyncAPI npm packages

AsyncAPI npm packages infected with credential-stealing malware

Unknown

Compromised AsyncAPI npm packages stole developers' credentials and sensitive information, putting affected systems and software supply chains at risk of further compromise.

Source: Bleeping Computer

July 16, 2026

macOS users

New ClickLock macOS malware traps users into revealing login password

Unknown

The ClickLock malware tricked macOS users into revealing their login passwords, allowing attackers to steal credentials and potentially gain unauthorised access to compromised devices and accounts.

Source: Bleeping Computer

July 16, 2026

Users of Webex and Zoom applications

Russian hackers trojanize Webex, Zoom Apps to push starland malware

Russian hackers

Russian hackers distributed trojanized Webex and Zoom applications to infect victims with Starland malware, enabling unauthorised access to compromised systems and facilitating further malicious activity.

Source: Bleeping Computer

July 20, 2026

Hugging Face

World's Largest AI model repository Hugging Face breached by autonomous AI agent

Autonomous AI agent

An autonomous AI agent breached Hugging Face by exploiting vulnerabilities in AI model repositories, raising concerns about unauthorised access, software supply chain security, and the integrity of hosted AI models.

Hugging Face Hack

July 22, 2026

Upbound Group (Acima)

Upbound says hack caused $13 million in fraudulent Acima leases

Unknown

A cyber attack enabled fraudsters to create approximately $13 million in fraudulent Acima lease agreements, resulting in significant financial losses and operational disruption for Upbound.

Source: Bleeping Computer

July 23, 2026

Windows users and organisations targeted by the MsaRAT malware campaign

New MsaRAT Malware Uses Chrome, Edge Browsers to Route C2 Traffic

Unknown

The MsaRAT malware abused Google Chrome and Microsoft Edge to route its command-and-control traffic, helping attackers evade detection while maintaining covert access to compromised systems.

Source: Bleeping Computer

July 23, 2026

Notepad++ users who installed the malicious plugins

Hackers Abuse Notepad++ Plugins to Stealthily Install Malware

Unknown

Attackers abused malicious Notepad++ plugins to quietly install malware on victims' systems, giving them unauthorised access and increasing the risk of credential theft and further compromise.

Source: Bleeping Computer

July 23, 2026

Users searching for and downloading the fake Claude AI application

Fake Claude app promoted by Bing ads pushes SectopRAT malware

Unknown

Attackers used malicious Bing advertisements to distribute a fake Claude AI application that installed SectopRAT malware, giving them remote access to victims' devices and exposing sensitive data to theft.

Source: Bleeping Computer

July 23, 2026

Organisations and individuals targeted by the Dolphin-X malware campaign

New Dolphin-X Malware Uses AI to Rank High-Value Targets

Unknown

The Dolphin-X malware used AI to identify and prioritise high-value victims, helping attackers focus their efforts on targets most likely to yield valuable data and facilitate further compromise.

Source: Bleeping Computer

July 23, 2026

Users who visited the malicious websites

Malicious sites use JavaScript to build malware in browser memory

Unknown

Malicious websites used JavaScript to assemble malware directly in browser memory, helping attackers evade security detection and infect victims' devices with malicious payloads.

Source: Bleeping Computer

July 24, 2026

Hotel guests and users of Microsoft 365 accounts connected to the compromised hotel Wi-Fi networks

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Unknown

Attackers hijacked hotel Wi-Fi DNS settings to redirect users to fake Microsoft 365 login pages, stealing account credentials and enabling unauthorised access to victims' accounts.

Source: Bleeping Computer

July 29, 2026

Minnesota community water utilities

Iran-linked CyberAv3ngers suspected in attacks on Minnesota water systems

CyberAv3ngers (suspected), an Iran-linked hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC)

A coordinated cyber attack targeted operational technology at more than 30 Minnesota community water systems, briefly disrupting automated controls at several facilities while authorities confirmed that drinking water remained safe and response teams quickly contained the incidents.

Source: The Register

 
 


Back to Top 

New Ransomware/Malware Discovered in July 2026

New Ransomware

Summary

msaRAT trojan

A newly discovered remote access trojan named msaRAT was found being deployed by the Chaos ransomware group to gain persistent access before encrypting victims' systems.

Avalon malware frame

Researchers uncovered a new malware framework called Avalon that enhanced ransomware operations by providing modular post-exploitation capabilities and payload delivery.

JADEPUFFER ransomware agent

Security researchers documented JADEPUFFER, an AI-driven autonomous ransomware agent that demonstrated how large language models could independently execute a ransomware attack chain.

 
 Source for the above table: Bleeping Computer, Recorded Future News

 Back to Top  

 

Vulnerabilities/Patches Discovered in July 2026

Date

New Flaws/Fixes

Summary

July 2, 2026

CVE-2026-48276, CVE-2026-48277, CVE-2026-48281, CVE-2026-48316, CVE-2026-48282, CVE-2026-48286

Adobe released urgent patches for seven maximum-severity vulnerabilities in ColdFusion and Campaign Classic that could allow attackers to execute arbitrary code on unpatched systems, urging customers to update immediately.

July 2, 2026

CVE-2025-20309

Cisco confirmed that attackers had actively exploited a critical vulnerability in Unified Communications Manager (Unified CM), prompting organisations to patch affected systems as soon as possible.

July 2, 2026

CVE-2025-53770

CISA confirmed that attackers had actively exploited a critical Microsoft SharePoint remote code execution vulnerability and urged organisations to apply the available security updates without delay.

July 6, 2026

CVE-2026-48279

Adobe confirmed that attackers had actively exploited a maximum-severity ColdFusion vulnerability that could allow arbitrary code execution, prompting organizations to apply security updates immediately.

June 7, 2026

CVE-2025-53098 and CVE-2025-53099

BeyondTrust disclosed critical vulnerabilities in its Remote Support and Privileged Remote Access products that could allow attackers to execute arbitrary code or compromise affected systems, urging customers to apply the available patches promptly.

July 8, 2026

CVE-2026-48279

CISA added a maximum-severity Adobe ColdFusion vulnerability to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch affected systems by Friday after the flaw was actively exploited.

July 8, 2026

CVE-2025-3248

CISA added a critical Langflow authentication bypass vulnerability to its Known Exploited Vulnerabilities catalog and directed federal agencies to prioritise patching after the flaw was found to be actively exploited.

July 10, 2026

CVE-2025-4631, CVE-2025-4632, CVE-2025-4633, CVE-2025-4634, CVE-2025-4635

Researchers disclosed multiple vulnerabilities in the U-Boot bootloader that could have enabled attackers to carry out stealthy firmware-level attacks and urged vendors to apply the available security fixes.

July 10, 2026

CVE-2025-53901

Zimbra urged customers to immediately patch a critical cross-site scripting (XSS) vulnerability in its web client to prevent attackers from executing malicious scripts and compromising user accounts.

July 14, 2026

CVE-2025-5777

Progress confirmed that a zero-day vulnerability in ShareFile was responsible for the shutdown of customer-managed StorageZone services and urged customers to apply the available security updates immediately.

July 18, 2026

CVE-2025-55188

7-Zip released a security update to fix a remote code execution vulnerability that could have allowed attackers to run malicious code by tricking users into opening specially crafted archive files.

July 18, 2026

CVE-2025-6463 and CVE-2025-6464

Public exploit code became available for critical WordPress Core "WP2Shell" remote code execution vulnerabilities, prompting website administrators to patch their systems immediately to prevent compromise.

July 16, 2026

CVE-2026-31311

CISA added an actively exploited Oracle vulnerability to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch affected systems by Saturday to reduce the risk of compromise.

July 22, 2026

CVE-2026-0770

CISA ordered U.S. federal agencies to urgently patch an actively exploited Langflow remote code execution vulnerability after attackers were observed using it to compromise vulnerable AI workflow servers.

July 22, 2026

CVE-2026-42311

Researchers disclosed a vulnerability in Adobe's Chrome extension that could have allowed malicious websites to access users' private WhatsApp chats, and Adobe released a fix to address the issue.

July 23, 2026

CVE-2026-64600

Researchers disclosed the RefluXFS vulnerability in the Linux kernel that could have allowed local attackers to gain root privileges through a flaw in the XFS filesystem, and they urged organizations to apply the latest kernel updates.

July 23, 2026

CVE-2025-66376

Russian state-backed hackers exploited a zero-click vulnerability in Zimbra Collaboration Suite to steal emails and authentication data from targeted organisations, prompting authorities to urge immediate patching of vulnerable servers.

 
 Source for the above table: Bleeping Computer, Recorded Future  

 Back to Top

Warnings/Advisories/Reports/Analysis

News Type

Summary

Report

A report alleged that Russian hackers were behind a cyberattack on Jaguar Land Rover that resulted in an estimated $2.5 billion in losses, underscoring the significant financial impact major cyber incidents can have on global manufacturers.

Warning

Researchers warned that attackers launched more than 81 million login attempts against Microsoft 365 accounts, highlighting a large-scale campaign aimed at compromising user credentials through password-spraying techniques.

Warning

Ubiquiti warned customers about a newly discovered maximum-severity vulnerability in UniFi OS that could allow attackers to compromise affected devices and urged users to install the latest security updates promptly.

Report

Researchers reported that a ransomware group claimed to have breached Deutsche Bank and stolen sensitive data, although the bank stated it was investigating the claims and had not confirmed a compromise.

Report

Finnish authorities issued an international wanted notice for the suspect behind the Vastaamo psychotherapy clinic breach as they continued efforts to bring the alleged hacker to justice for the large-scale theft and extortion of patient data.

Report

The EU and UK jointly imposed sanctions on Russian cyber actors and supporting entities to disrupt their ability to carry out future cyber attacks and reduce the threat posed to governments, businesses, and critical infrastructure.

Report

Hackers leaked data they claimed belonged to Russian journalist and television personality Ksenia Sobchak, highlighting another high-profile cyber incident targeting a prominent public figure.

Report

Researchers reported that hackers abused legitimate ViPNet software to target Russian government agencies, using trusted tools to gain access and carry out covert cyber-espionage activities.

Warning

Microsoft warned that ACR Stealer malware attacks had surged, with cyber criminals increasingly targeting customers to steal credentials and other sensitive information from compromised devices.

Warning

Zoom warned customers about a critical vulnerability that could have allowed attackers to take over user accounts and urged users to update affected software to protect against potential exploitation.

Warning

CISA warned administrators to immediately patch actively exploited Microsoft SharePoint vulnerabilities after attackers were observed using the flaws to compromise vulnerable servers.

Warning

SonicWall warned that attackers had exploited zero-day vulnerabilities in SMA1000 appliances and urged customers to apply the available patches immediately to prevent further compromises.

Warning

SAP warned customers about critical vulnerabilities affecting NetWeaver and Commerce Cloud that could have allowed attackers to compromise vulnerable systems and urged users to apply the latest security patches promptly.

Report

The U.S. government imposed sanctions on VPN and malware service providers that allegedly supported ransomware gangs, aiming to disrupt the infrastructure used to facilitate cyberattacks.

Warning

CISA warned that attackers had actively exploited remote code execution vulnerabilities in multiple Joomla extensions and urged administrators to update affected installations immediately.

Warning

Australia warned that a global campaign had targeted vulnerable CMS platforms by exploiting unpatched flaws and urged organizations to update their systems immediately to reduce the risk of compromise.

Report

Researchers reported that the newly identified Helix vishing group had targeted organizations by using phone-based social engineering alongside SharePoint attacks to steal sensitive data and gain unauthorized access to corporate environments.

Warnings

Check Point warned that attackers had exploited a zero-day vulnerability in SmartConsole and urged customers to install the latest security update to prevent potential system compromise.

 
 Sources: Bleeping Computer and Infosecurity Magazine

Back to Top