2026-07-10
Population: stories the tracker first saw on this Coordinated Universal Time (UTC) calendar day; publisher date is used only if first-tracked time is unavailable and remains on each item.
Friday Squid Blogging: “Squidbleed” Vulnerability
- ransomware
No Manners Here: The Ruthless Rise of The Gentlemen Ransomware
Unit 42 published analysis of The Gentlemen ransomware operations and its affiliate model structure that has enabled rapid expansion. The report examines how the group's business model has driven its growth in the threat landscape.
Why it matters: Organizations targeted by Gentlemen affiliates need to understand this group's operational structure and recruitment tactics to assess ransomware risk and inform incident response planning.
- regulatory
Europe revives law allowing big tech to scan for CSAM
The European Parliament approved Chat Control 2.0, legislation that authorizes major technology companies including Google, Meta, and Microsoft to scan user messages for child sexual abuse material (CSAM). The law enables automated detection systems to identify and report such content to authorities.
Why it matters: Organizations providing messaging and communication services across the EU must prepare technical scanning capabilities and compliance processes to meet the new legal mandate for CSAM detection.
- government policy
Jen Ellis: Connecting Cyber Community With Political Machinery
This article profiles Jen Ellis, who recently received an MBE honor. The piece examines the events and advocacy work that led to her recognition within the security research community.
Why it matters: Security practitioners should understand how advocates shape policy conversations and industry direction, particularly those building bridges between technical expertise and political influence.
- ransomware
Ryuk ransomware member pleads guilty in the US, faces 15 years in prison
A 34-year-old Armenian national pleaded guilty to hacking U.S. companies and deploying Ryuk ransomware to encrypt their systems. The defendant faces up to 15 years in prison as part of a U.S. prosecution. This case represents a law enforcement action against a member of the ransomware-as-a-service operation.
Why it matters: Organizations targeted by Ryuk should review incident response procedures and threat intelligence on this gang's current infrastructure, while security teams can assess whether this prosecution impacts ongoing threats from the group.
- breaches incidents
Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages
Unknown threat actors compromised the Injective Labs SDK GitHub repository and published a malicious npm package version 1.20.21 containing fake telemetry code designed to steal cryptocurrency wallet private keys and seed phrases. The compromised package was distributed through the public npm registry.
Why it matters: Developers using the Injective Labs SDK face immediate risk of wallet compromise; anyone who installed @injectivelabs/sdk-ts@1.20.21 should rotate affected cryptocurrency keys and seed phrases immediately.
- ransomware
Ryuk operator pleads guilty; Blackcat/AlphV conspirator gets nearly 6-year sentence
A Ryuk ransomware operator pleaded guilty to conspiracy and computer fraud in Oregon federal court, while a separate defendant received a 70-month federal prison sentence in Florida for assisting the Blackcat/AlphV ransomware gang in extortion campaigns against multiple victims.
Why it matters: Practitioners should track these cases as examples of law enforcement action against major ransomware operations; organizations hit by Ryuk or Blackcat/AlphV may benefit from following the judicial outcomes and evidence disclosed.
- threat intel
Cybercriminals Flock to Healthcare Businesses as Attacks Surge
Cyberattacks against hospitals and clinics increased modestly in the first half of 2026, while attacks targeting healthcare service providers and related businesses more than doubled during the same period.
Why it matters: Healthcare IT teams and service providers face accelerating threat pressure; practitioners should prioritize monitoring and incident response readiness given the rapid shift in attacker focus to administrative and support functions.
- government policy
License plate cameras may be next target after Supreme Court reins in location tracking
The Supreme Court's recent restrictions on location tracking may extend to automatic license plate recognition (ALPR) systems, potentially requiring warrants for ALPR searches. Such a requirement would significantly constrain how law enforcement agencies deploy these camera networks in routine policing.
Why it matters: Law enforcement, privacy advocates, and legal teams should monitor how courts apply location tracking precedent to ALPR systems, as warrant requirements could reshape surveillance capabilities and investigative workflows.
- breaches incidents
Progress urges ShareFile customers to shut down servers over "credible" threat
Progress Software has urged ShareFile customers using Storage Zone Controllers to immediately shut down their servers due to identification of a credible external security threat targeting the on-premises file sharing solution. The company issued the directive via email to affected customers but has not disclosed specific details about the nature or scope of the threat.
Why it matters: ShareFile Storage Zone Controller deployments are at immediate risk; organizations running this software should assess their exposure and follow Progress guidance to determine if they are affected and whether shutdown is necessary.
- government policy
Securing our future: July 2026 progress report on Microsoft’s Secure Future Initiative
Microsoft released its July 2026 Secure Future Initiative progress report detailing security improvements across three areas: secure foundations, proactive defense, and future-ready security. The company deployed phishing-resistant multifactor authentication (MFA) across 99.97% of user/device pairs, revoked public access from 732,000 resources, decommissioned 1.4 million unused apps, and used artificial intelligence (AI) agents to discover vulnerabilities in cloud services. The report emphasizes continuous validation of security controls and the use of AI to identify composite attack paths faster than manual methods.
Why it matters: Security teams should review Microsoft's architectural approach to secure foundations, proactive AI-driven vulnerability discovery, and post-quantum readiness, as these patterns apply broadly to enterprise security programs.
- vulnerabilities
Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot
Binarly researchers discovered six vulnerabilities in U-Boot, the bootloader used across diverse hardware including routers, smart cameras, and data-center management chips. Four flaws enable denial of service through device crashes, while two allow code execution at boot time if an attacker can provide a malicious image to the bootloader.
Why it matters: Device manufacturers and firmware maintainers relying on U-Boot across IoT, networking, and data-center infrastructure must patch these flaws to prevent remote code execution and service disruptions in production environments.
- breaches incidents
Money launderer accused of stealing seized crypto while in prison
A Bulgarian national, currently incarcerated for money laundering related to fraud, has been charged with stealing $290,000 in government-seized cryptocurrency. The alleged theft occurred while the individual was serving a 121-month sentence for helping launder millions of dollars from American fraud victims.
Why it matters: Law enforcement and asset management teams overseeing seized crypto holdings need to strengthen access controls and audit procedures, as this case demonstrates that even imprisoned individuals can access and steal government custody assets.
- ransomware
In Other News: DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Disrupts Ransomware Ops
A Department of Homeland Security database was compromised, Adobe announced an accelerated patch release schedule, and Canadian authorities disrupted ransomware operations. The article also references a lawsuit between Abnormal Security and Anthropic, a data breach affecting AssuranceAmerica customers, and the National Security Agency's reactivation of its Tailored Access Operations unit.
Why it matters: Organizations relying on DHS systems face potential data exposure; software teams must track Adobe's new patch cadence; law enforcement actions against ransomware groups affect threat landscape visibility and attribution for defenders.
- vulnerabilities
Laser Attack Resets Tangem Wallet Passwords on Cards That Can't Be Patched
Researchers at Ledger's Donjon security team demonstrated a laser-based attack that can reset passwords on Tangem cryptocurrency wallet cards by targeting the embedded chip. Once the password is reset, an attacker gains control of the wallet and can transfer the stored cryptocurrency. The attack requires precise timing and physical access to the card hardware.
Why it matters: Tangem wallet card users face a permanent vulnerability that cannot be patched: physical possession of the card is the only defense against an attacker with laser equipment, making hardware-based crypto wallets potentially less secure than previously assumed.
- vulnerabilities
Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws
A researcher documented three high-severity vulnerabilities in the OpenClaw personal artificial intelligence (AI) assistant that have since been patched. The flaws could permit credential theft, privilege escalation, and arbitrary code execution on affected hosts when chained together in an attack originating from WhatsApp.
Why it matters: Organizations and individuals using OpenClaw should verify the patches have been applied, as the attack chain presents a direct path from a common messaging platform to full system compromise.
- identity access
The Replicant in Your Directory: AI Agents and the Identity Security Gap
Artificial intelligence (AI) agents are multiplying non-human identities across enterprise environments, creating blind spots in visibility and access control. Organizations struggle to track these identities, their ownership, and their permissions, widening the attack surface. Stronger identity governance and visibility mechanisms are needed to manage this emerging security gap.
Why it matters: Security and identity teams need to inventory and govern non-human identities created by AI agents to prevent unauthorized access and privilege escalation attacks.
- vulnerabilities
Fresh ATM Crypto Software Bugs: Jackpot or Bust?
Security researchers have identified vulnerabilities in a Microsoft BitLocker security wrapper that could expose organizations and ATM systems to compromise. The specific technical details and attack vectors are not elaborated in the available information.
Why it matters: Organizations operating ATMs and other systems relying on BitLocker protection need to assess their exposure to these holes and apply patches or workarounds to prevent attackers from bypassing disk encryption protections.
- vulnerabilitiesCVE-2026-47291
CVE-2026-47291: Remote Code Execution in the Windows HTTP.sys
A remote code execution vulnerability exists in Windows HTTP.sys, the kernel-mode HTTP protocol driver used by Internet Information Services (IIS). The flaw stems from an integer overflow in buffer reference array handling during HTTP/1.x header parsing, allowing unauthenticated attackers to send crafted HTTP packets to achieve denial-of-service or kernel-level code execution.
Why it matters: Organizations running IIS or applications using HTTP.sys must verify that systems are patched; this vulnerability allows remote code execution with kernel privileges without authentication, making it critical for any exposed HTTP/HTTPS services.
- government policy
More Countries Jump on the Social Media Ban Wagon
Multiple countries are implementing age restrictions and social media bans, though compliance efforts by technology companies are proving difficult to execute effectively. Industry observers note that current restrictions may function as temporary measures rather than comprehensive solutions to concerns about youth social media use.
Why it matters: Compliance officers and policy teams should monitor emerging age verification and content restriction requirements across jurisdictions, as regulatory fragmentation will require platform-specific implementations and potential business model adjustments.
- threat intel
New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic
Silver Fox, a China-linked cybercrime group, has deployed a new Rust-based remote access trojan called MODBEACON that uses gRPC streaming to encrypt command-and-control traffic. The group distributes malware through counterfeit installers and SEO poisoning despite appearing as a low-sophistication operation.
Why it matters: Organizations targeted by SEO poisoning and counterfeit software downloads face infection with a difficult-to-detect RAT; monitor for gRPC-based C2 traffic and validate software authenticity before installation.
- ai security
AI Coding: Do Security Risks Outweigh Productivity Gains?
Artificial intelligence (AI) coding tools range in cost from $19 to $200 per month per user, with organizations facing additional expenses from security scanning, remediation, and managing false positives. The article examines whether productivity improvements justify the total cost of ownership.
Why it matters: Development and security teams need to evaluate whether AI coding tools deliver net value when accounting for licensing, infrastructure overhead, and the time spent addressing security issues and alert fatigue.
- identity access
Incode brings on-device processing to age estimation for privacy-focused verification
Incode has released an on-device age estimation feature that processes facial analysis for age verification directly on a user's device without transmitting facial data to external servers. The offering includes liveness detection and spoofing resistance, addressing growing regulatory requirements for age assurance across more than 30 jurisdictions worldwide.
Why it matters: Organizations subject to age verification laws (including the UK Online Safety Act) need privacy-respecting verification solutions; on-device processing reduces data exposure and compliance risk while maintaining effectiveness against deepfakes.
- vulnerabilitiesCVE-2026-48939CVE-2026-56291
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA added two file upload vulnerabilities (CVE-2026-48939 in iCagenda and CVE-2026-56291 in Balbooa Forms) to its Known Exploited Vulnerabilities Catalog based on active exploitation evidence. These vulnerabilities allow unrestricted uploads of dangerous file types and represent a common attack vector. Federal agencies must prioritize patching under Binding Operational Directive 26-04, which requires rapid remediation of high-risk KEV Catalog vulnerabilities on publicly exposed assets.
Why it matters: Federal agencies must treat these two vulnerabilities as critical priorities for remediation on exposed systems; organizations running iCagenda or Balbooa Forms should verify whether these file upload flaws have been exploited before patching and conduct incident investigation if compromise occurred.
- threat intel
China, India-Linked Hackers Both Targeted Same Pakistani Police Force
Security researchers at SentinelOne identified that both China-linked and India-linked hacking groups have targeted Pakistan's Balochistan Police force over a period of at least two years. The simultaneous targeting of the same Pakistani law enforcement agency by adversaries reflects broader regional cyber espionage activity.
Why it matters: Organizations in South Asia managing law enforcement systems need to assess whether they face similar multi-nation-state targeting and review their detection capabilities for advanced persistent threats from multiple threat actors.
- vulnerabilities
Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers
A vulnerability in XQUIC, Alibaba's QUIC and HTTP/3 library, allows unauthenticated remote clients to crash servers with legitimate traffic of approximately 260 bytes. The flaw, disclosed by FoxIO researcher Sébastien Féry and nicknamed XRING, stems from a single incorrect variable assignment and currently has no patch available.
Why it matters: Organizations running XQUIC-based HTTP/3 servers face denial of service risk from any network client; teams should identify affected deployments and assess alternative QUIC implementations or network mitigations until a patch is released.
- vulnerabilities
Zimbra urges customers to patch critical web client XSS flaw
Zimbra has advised customers to patch a critical cross-site scripting (XSS) vulnerability in its Classic Web Client component of the Zimbra Collaboration suite. The flaw could allow attackers to execute malicious scripts in users' browsers and compromise email accounts and data.
Why it matters: Organizations running Zimbra Collaboration are at immediate risk of account compromise and data theft if they do not apply the patch; administrators should prioritize this update.
- research
From 17,000 to 1.1 Million Assets: How Lumen Technologies Rebuilt Exposure Management at Scale
Lumen Technologies expanded its asset inventory from 17,000 to 1.1 million assets by consolidating and improving exposure management capabilities. The article references survey data showing that only 45 percent of organizations consolidate asset and exposure data into a single view, and notes that inaccurate inventories cascade through downstream security programs.
Why it matters: Security leaders managing asset inventory and exposure programs need to understand that fragmented asset data undermines all downstream controls; Lumen's scale demonstrates the gap between assumed and actual asset visibility.
- threat intel
Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
A misconfigured server belonging to a cybercrime group was left publicly accessible for three weeks, exposing hacking tools, activity logs, and a target list of over 1.4 million websites. The exposure revealed operational details of a mass site-hacking campaign, though the actual number of compromised sites was significantly smaller than the target list. Researchers were able to analyze the backdoor tool (WP-SHELLSTORM) and understand the group's infrastructure and tactics.
Why it matters: WordPress site operators and hosting providers need to assess whether their domains appear in the exposed target list and patch known vulnerabilities to prevent backdoor installation, while security teams should monitor for indicators of compromise from this operation.
- research
AI Surveillance and Social Progress
Artificial intelligence (AI)-powered surveillance systems integrate facial recognition, real-time data linking, and automated enforcement to monitor public and private behavior and instantly alert authorities to rule violations. Such systems are being deployed in China and are undergoing trials in the United States and other regions, where they generate chilling effects on civil liberties and prompt concerns about bias, accountability, and social control.
Why it matters: Government agencies and private organizations using AI surveillance expose citizens to pervasive monitoring and possible rights violations, requiring practitioners to review data‑protection controls and compliance obligations.
- research
Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking
Researchers analyzed 281 popular free Android virtual private network (VPN) apps from the Google Play Store and identified widespread security failures including traffic leaks, unencrypted data transmission, and user tracking. The problematic apps have been installed over 2.4 billion times, with at least 29 allowing user traffic to bypass the VPN entirely.
Why it matters: Android users relying on free VPN apps for privacy may have their data exposed to networks and third parties instead of being protected, requiring immediate review of any free VPN currently installed.
- threat intel
GigaWiper Combines Multiple Malware for System-Level Sabotage
GigaWiper is a backdoor combining multiple malicious capabilities including a standalone wiper, ransomware encryption, and multi-pass wiping commands designed for system-level sabotage. The malware combines destructive techniques that can both encrypt and completely erase victim systems. Organizations face exposure to coordinated data extortion and system destruction attacks.
Why it matters: Practitioners should understand this multi-stage threat combines encryption and wiping tactics, requiring detection strategies that identify both ransomware behavior and destructive wiping activities before execution.
- threat intel
"Comment stuffing" in an HTML phishing attachment as a mechanism for evading AI-based detection?
A phishing campaign employed HTML attachments padded with comment code to evade artificial intelligence (AI)-based email security detection. The oversized attachment, combined with malformed email headers lacking standard Date and DKIM fields, indicated a homemade sending script designed to bypass authentication checks and AI filtering mechanisms.
Why it matters: Email security teams need to monitor for inflated HTML attachment sizes and malformed headers as indicators of evasion tactics targeting AI detection, since adversaries are actively adapting to overcome machine learning-based email filters.
- vulnerabilities
Attackers Exploit 'Ill Bloom' Vulnerability to Drain $3.1 Million From Cryptocurrency Wallets
Security firm Coinspect disclosed a vulnerability called Ill Bloom affecting cryptocurrency wallet software that generates recovery phrases with weak randomness, allowing attackers to derive wallet credentials and steal funds. Attackers have already exploited the flaw in at least one coordinated attack that drained $3.1 million from affected wallets.
Why it matters: Cryptocurrency users and wallet providers need to immediately audit recovery phrase generation in their software and migrate funds from affected wallets to those with cryptographically secure randomness implementation.
- ai security
‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism
Researchers demonstrate that adversarial hallucination squatting can manipulate popular artificial intelligence (AI) assistants to execute arbitrary code. The technique injects crafted prompts that cause the model to hallucinate malicious package names, which attackers then register to deliver botnet payloads.
Why it matters: Organizations using AI assistants are exposed to remote code execution via malicious prompt injection, requiring validation of model outputs and prompt monitoring.
- threat intel
Network of 200 GitHub Repositories Used for Malware Infection
A network of approximately 200 GitHub repositories is being exploited to distribute Windows malware through a Go module that loads PowerShell code and retrieves payloads from dead drops. This abuse of GitHub's infrastructure demonstrates how legitimate code hosting platforms can be weaponized for malware delivery at scale.
Why it matters: Windows developers and DevOps teams need to audit their GitHub dependencies and code supply chains immediately, as malicious repositories can masquerade as legitimate packages and compromise build pipelines and systems.
- ai security
Workato expands Agent Studio with Headless API, AI guardrails
Workato announced two new features for Agent Studio: a Headless application programming interface (API) enabling Workato's artificial intelligence (AI) agents (called Genies) to be embedded across web, mobile, and multi-agent environments, and Agent Guardrails that enforce data privacy policies, identity tracking, and compliance controls. These capabilities allow enterprises to deploy AI agents while maintaining security and auditability across different application surfaces.
Why it matters: Platform and application teams using Workato for AI agent automation should evaluate whether the Headless API and guardrails meet their requirements for embedding AI agents into business applications while satisfying compliance and data governance mandates.
- research
The open source library holding up your stack might have one maintainer
A new research paper examines how open source libraries vary dramatically in their maintenance models and governance, from well-resourced projects to those maintained by a single person in spare time. Despite carrying the same label, these differences can significantly affect the behavior and security posture of software that depends on them.
Why it matters: Development teams need to assess the maintenance status and resource levels of open source dependencies to understand the risk of supply chain vulnerabilities, unpatched flaws, and abandonment that could affect their own products and customers.
- regulatory
Most data brokers won’t tell you what happened to your deletion request
UC Irvine researchers tested deletion requests with California's data broker registry to understand compliance. The study found that most data brokers fail to provide confirmation or transparency about what happened to consumer deletion and sales-stop requests.
Why it matters: California residents and other practitioners should know that exercising statutory deletion rights against data brokers may not result in verifiable action, limiting the practical value of privacy regulations without enforcement.
- vulnerabilities
Microsoft is rewriting Windows patch guidance because of AI
Microsoft is advising organizations to accelerate Windows update deployment timelines because artificial intelligence is enabling attackers to identify and exploit vulnerabilities more quickly after patches are released. The company recommends shortening the period between patch release and deployment, particularly for critical security updates on systems where faster rollouts are operationally feasible.
Why it matters: Windows administrators and security teams need to reassess their patch deployment windows now, as AI-accelerated vulnerability analysis means the traditional weeks-long grace period between patch release and active exploitation is shrinking.
- threat intel
Turning software supply chain security into a daily habit
Anastasia Tikhonova from Group-IB discusses operationalizing software supply chain risk by using Software Bill of Materials (SBOMs) as active tools rather than static compliance documents. SBOMs should be integrated into daily security workflows including vulnerability triage, vendor access reviews, identity monitoring, and incident response, while recognizing how supply chain attacks increasingly connect phishing, ransomware, and data breaches through inherited trust relationships.
Why it matters: Security practitioners need to shift SBOMs from compliance artifacts to operational tools to detect and respond to supply chain risks that threaten their organization through trusted vendors and dependencies.
- cloud saas
AWS gives its ERP agent deny-by-default rules and a separate identity
AWS has released enhancements to its ERP agent that include deny-by-default authorization rules and a separate identity mechanism. These improvements aim to address security concerns while allowing the agent to automate exception handling in enterprise resource planning workflows across finance operations.
Why it matters: Finance and operations teams using AWS ERP agents need to evaluate the security posture of agentic automation; deny-by-default rules and separate identities reduce the risk of unauthorized transactions or data access in sensitive financial processes.
- identity access
Only 28% of financial workforce MFA is phishing-resistant
A Secret Double Octopus report found that only 28% of multifactor authentication (MFA) deployments in financial organizations use phishing-resistant methods, with most relying on passwords combined with one-time passwords (OTP) that remain vulnerable to credential theft and phishing attacks. Financial institutions continue to mix legacy authentication approaches with more secure technologies, leaving significant portions of their workforce exposed to identity-based threats.
Why it matters: Financial services practitioners need to accelerate migration to phishing-resistant MFA (such as FIDO2) across their workforce, as the majority still depend on vulnerable password-plus-OTP combinations that create actionable targets for attackers seeking account compromise and lateral movement.
- industry
New infosec products of the week: July 10, 2026
A weekly roundup of recent information security product releases featured Codenotary's AgentMon 3, an enterprise artificial intelligence (AI) security platform that uses adaptive runtime security policies to learn from AI agent behavior within organizations. The article highlighted releases from Attestiv, Automox, Codenotary, and First Recon AI during the week of July 10, 2026.
Why it matters: Security practitioners evaluating AI governance and runtime protection tools should review these new offerings to understand emerging capabilities for monitoring and controlling AI agent activities in their environments.
- threat intel
Risky Bulletin: India bans app used to hack e-rickshaws in viral videos
The Indian government ordered Apple and Google to remove a battery management app that was weaponized to remotely disable electric rickshaws in a viral social media trend called the Tirri Challenge. Videos documented the attacks, which stranded drivers and caused traffic disruptions across the country over a two to three week period.
Why it matters: Mobile app stores and platform operators need to monitor for misuse of seemingly benign applications in coordinated attack trends, and governments are moving quickly to intervene when public transport and livelihoods are at risk.
- threat intel
ISC Stormcast For Friday, July 10th, 2026
This is a podcast episode announcement from the SANS Internet Storm Center that provides daily cybersecurity news and updates.
Why it matters: Practitioners should check the ISC Stormcast feed daily for curated threat intelligence, vulnerability updates, and incident summaries relevant to their defensive operations.
- ai security
Why AI Governance Without Guardrails Is Theater
The article examines the ineffectiveness of artificial intelligence (AI) governance frameworks that lack enforcement mechanisms and measurable accountability. Without concrete guardrails and compliance requirements, governance efforts remain symbolic rather than substantive.
Why it matters: Security and compliance practitioners must understand that governance frameworks without enforcement teeth provide no actual protection against AI-related risks in their organizations or supply chains.
- ransomware
Former DigitalMint ransomware negotiator who duped clients sentenced to 70 months in jail
Angelo John Martino III, a ransomware negotiator at DigitalMint, was sentenced to 70 months in prison for conspiring with BlackCat affiliates to extort $75.3 million from five U.S. companies he was hired to help during ransomware incidents. Martino shared confidential negotiating positions and insurance policy limits with his co-conspirators to maximize ransom demands, effectively playing both sides of negotiations between April and September 2023. His co-conspirators, including fellow DigitalMint negotiator Kevin Tyler Martin and Sygnia incident response manager Ryan Clifford Goldberg, received four-year sentences for their roles in deploying BlackCat ransomware against additional victims.
Why it matters: Ransomware victims and negotiation firms need to understand that insider threats from negotiators with access to sensitive client data pose a severe risk, requiring stronger vetting, access controls, and separation of duties to prevent co-conspirators from exploiting confidential negotiating positions and insurance information.
- breaches incidents
Dutch police trace Odido telco cyberattack to suspected local accomplice
Dutch police have identified evidence linking Dutch criminals to the cyberattack on telecommunications provider Odido that exposed personal data of over 6 million customers in early 2026. The investigation suggests local involvement rather than exclusively foreign threat actors.
Why it matters: Odido customers whose data was exposed face identity theft and fraud risk; telecom companies must assess whether domestic criminal networks pose comparable threats to their infrastructure as international groups.
- breaches incidents
OpenMandriva Linux says contributor tried to sabotage the project
OpenMandriva Linux project reported an attempted sabotage incident stemming from a dispute between contributors. The project disclosed the incident publicly and took steps to address the internal conflict.
Why it matters: Open source project maintainers and users should monitor for similar internal threats to critical infrastructure projects, as compromised build systems or repositories could distribute malicious code to downstream users.
- threat intel
Iran's Cyber Crosshairs Focus Beyond Critical Infrastructure
An article discussing how Iranian threat actors are expanding their targeting beyond critical infrastructure to broader internet-facing systems. The piece emphasizes that obscurity provides no protection against multiple concurrent threats.
Why it matters: Security teams at any organization with internet-facing assets should assume Iranian threat actors may probe their infrastructure, regardless of whether they operate critical systems, and need robust vulnerability management and threat detection capabilities.
- threat intel
Injective SDK on npm infected with cryptocurrency wallet stealer
Hackers compromised the Injective Labs SDK repository on GitHub and published a malicious package to npm that targeted cryptocurrency wallet credentials, specifically private keys and mnemonic seed phrases. The attack exploited the trust developers place in open-source dependencies to distribute wallet-stealing malware.
Why it matters: Developers using the compromised Injective SDK package face immediate risk of cryptocurrency wallet theft; practitioners should audit npm dependencies and check for the malicious package version in their supply chains.
- identity access
AI Agents Are a New Kind of Identity & Most Organizations Aren't Ready
Organizations are treating artificial intelligence (AI) agents as service accounts or application programming interface (API) tokens, an approach that falls short of their security requirements. AI agents represent a distinct identity type that demands specialized access control and management strategies. Current practices do not adequately address the unique risks these entities introduce.
Why it matters: Security teams and identity administrators need to reassess how they govern AI agents in production systems, as traditional service account controls leave organizations exposed to unauthorized actions and privilege escalation.
- identity access
Conditional Access Misconfigurations Exposed 55 Orgs with MFA On
Two organizations experienced successful attacks against Microsoft 365 systems despite having Conditional Access policies and multifactor authentication (MFA) enabled, suggesting configuration gaps in their policies. Huntress Managed ISPM identified these misconfigurations and found the issue affected 55 organizations. The article highlights how standard conditional access controls can fail when improperly configured.
Why it matters: Security teams relying on Conditional Access and MFA as primary defenses need to audit their policy configurations immediately, as these controls can be bypassed through misalignment of rules that appears secure on surface review.
- threat intel
AI-Coded Malware | Analyzing Vibe-Coded AD Enumeration | Huntress
Threat actors are leveraging artificial intelligence to generate custom PowerShell scripts targeting Active Directory environments. Huntress researchers analyzed real-world AI-generated malware samples to understand the implications for defenders.
Why it matters: Organizations managing Active Directory need to monitor for custom, AI-generated reconnaissance scripts that may evade traditional signature-based detection and adapt quickly to defensive measures.
- threat intel
LoTL Abuse: How to Spot It vs. Normal Admin Activity | Huntress
Living off the land (LoTL) attacks abuse legitimate system tools and remote management software to evade detection, making them difficult to distinguish from normal administrative activity. The article discusses methods for identifying suspicious LoTL abuse patterns versus routine IT operations.
Why it matters: Security practitioners need to develop detection strategies that differentiate between malicious use of PowerShell and RMM tools versus legitimate admin activity to catch intrusions that bypass traditional endpoint tools.
- threat intel
Meta Phishers Abuse Business Account Manager Service | Huntress
Huntress identified threat actors leveraging Meta's Business Account Manager service to conduct phishing attacks. The adversaries are using this legitimate Facebook feature as a delivery mechanism for initial phishing messages, representing an evolution in their social engineering tactics.
Why it matters: Practitioners should understand that legitimate platform features can be weaponized for phishing; monitor for unsolicited Business Account Manager communications and educate users to verify unexpected account management requests.
- research
5 Cybersecurity Lessons From Taylor & Travis’s Wedding
This article draws cybersecurity lessons from Taylor Swift and Travis Kelce's wedding, discussing concepts like layered defense and multifactor authentication (MFA) through the lens of event security.
Why it matters: Security practitioners can review fundamental defense principles, though the celebrity context limits direct applicability to most organizational environments.
- industry
AI Arms Race in Recruiting
Recruiters and candidates are leveraging artificial intelligence to gain advantages in the hiring process. The widespread adoption of AI in recruiting creates concerns about the integrity and effectiveness of talent selection methods.
Why it matters: Hiring managers and security teams need to understand how AI manipulation in recruiting affects the quality of candidates, including those hired into security-critical roles.
- cloud saas
Guide to Cloud Application Security: Must-Knows and No-No’s | Huntress
A guide discussing cloud application security practices and protective measures to prevent unauthorized access to data. The resource covers practical approaches to securing cloud applications and their relevance to security teams.
Why it matters: Security practitioners responsible for cloud applications need actionable guidance on protective measures to reduce data exposure from threat actors.
- threat intel
Celebrating Canada Day with Localized Managed Phishing
Huntress announced that its Managed Security Awareness Training now includes localized phishing simulations for Canada, featuring Canadian-specific brands and scenarios to improve the effectiveness of security awareness training for Canadian organizations.
Why it matters: Canadian security teams can now conduct more relevant phishing simulations that employees will recognize as realistic, improving the likelihood that awareness training translates to better detection and avoidance of actual phishing threats.
- ransomware
How the RaaS Business Model Actually Works
The article explains how Ransomware-as-a-Service (RaaS) operates as a scalable criminal business model, describes the disruption it causes, and identifies defensive chokepoints before encryption occurs. RaaS lowers barriers to entry for attackers by separating specialized roles and infrastructure, enabling mass-market extortion campaigns.
Why it matters: Security teams need to understand the RaaS operational model to prioritize defenses against affiliate-driven attacks and recognize where intervention is possible before payload detonation.
- threat intel
No (Bad) CAP: Inside an Ongoing LSHIY Password Spray Attack
Huntress researchers have identified an ongoing password spray campaign targeting Microsoft Azure CLI that originates from an IPv6 address range operated by LSHIY LLC. The attackers are attempting to compromise Azure accounts through brute force authentication attempts.
Why it matters: Organizations using Azure CLI are at risk of unauthorized account access if weak or default credentials are in use; practitioners should review access logs, enforce conditional access policies, and ensure strong password practices.
- threat intel
Airport Cybersecurity: Defend Data from Juice Jacking & Public Wi-Fi Threats
Huntress published guidance on airport cybersecurity best practices, covering juice jacking attacks via charging stations, evil twin wireless networks, and device security measures for travelers.
Why it matters: Practitioners advising end users on travel security need current awareness of airport-specific threats and mitigation tactics to reduce credential and data theft risk while mobile.