// daily digest ยท 2026-07-09
Thursday·9 July 2026

Cyber Digest

A daily roundup of key cybersecurity developments across sectors

26 stories6 sectors4 sourcesGlobal focus

Executive Summary

The week of July 3โ€“9, 2026 was marked by several high-impact developments spanning AI security, law enforcement actions, and critical infrastructure vulnerability management. The FortiBleed incident โ€” involving leaked credentials from approximately 74,000 internet-exposed Fortinet devices โ€” continued to reverberate, with CISA issuing urgent hardening guidance for government and private sector organizations. In a major takedown, the FBI seized hundreds of domains tied to the NetNut residential proxy platform and the Popa botnet, a network of at least two million compromised devices run by the publicly-traded Israeli firm Alarum Technologies. In AI security, Sophos published research showing AI coding agents (Claude Code, Cursor, OpenAI Codex) are triggering endpoint detection rules designed to catch human attackers, with credential access alerts spiking 56% on monitored machines. Meanwhile, a novel "HalluSquatting" attack technique was disclosed that exploits AI hallucination to trick coding assistants into installing botnet malware. The discovery of GhostLock (CVE-2026-43499), a 15-year-old Linux kernel flaw enabling root access and container escape on virtually all distributions, prompted urgent patching calls. On the regulatory front, Cash App's parent company agreed to a $45 million settlement over lax security practices, and Britain unveiled plans for an autonomous AI "Cyber Shield" to defend national networks. The UK's cyber pledge to secure critical infrastructure, however, drew only a handful of major firms despite ministerial appeals, raising questions about private-sector commitment.

11
IT / Technology
6
Government
2
Defence
2
Financial Services
1
Healthcare

Incident Map

(static view)
CriticalSevereElevatedGuardeddarker = more incidents
United States
7
China
3
United Kingdom
3
Mexico
1
Greece
1
Canada
1

Pan-regional / not map-pinned: ๐ŸŒ Global: 10

6 countries ยท 26 stories ยท click a country for its stories. Interactive map loads on the hosted site.

๐ŸŽฏ Geo-attribution: 14/26 stories located directly from text (54%). Low-confidence (region-bucket only, check): United States.

๐ŸŽฏ Geo-attribution: 14/26 stories located directly from text (54%). Low-confidence (region-bucket only, check): United States.

IT / Technology 11 stories

1

AI Coding Agents Triggering Endpoint Security Rules Built to Catch Attackers

Sophos analyzed a week of endpoint telemetry from June 2026 and found that AI coding assistants โ€” Claude Code, Cursor, and OpenAI Codex โ€” are routinely setting off behavioral detection rules. Credential access attempts accounted for 56.2% of alerts on monitored machines, as agents decrypt browser credentials, enumerate Windows credential stores, and write to startup folders. The agents are not malicious but their activity patterns are indistinguishable from real attacks to behavioral engines.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-08
2

New HalluSquatting Attack Exploits AI Hallucination to Install Botnet Malware

Researchers disclosed "HalluSquatting," an attack that exploits AI coding assistants' tendency to hallucinate non-existent package names. Attackers register domains for packages the AI reliably invents; when a developer's assistant fetches the trap, it executes attacker-supplied code on the machine. The technique could be scaled to assemble botnets by targeting popular hallucinated resources.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-08
3

GhostLock (CVE-2026-43499): 15-Year-Old Linux Kernel Flaw Enables Root and Container Escape

Nebula Security disclosed GhostLock, a 15-year-old Linux kernel vulnerability present in virtually every mainstream distribution since 2011. It allows any logged-in user to gain full root control and escape containers with 97% reliability in testing. Google awarded the team $92,337 through its kernelCTF bounty program. Working exploit code has been published, though no in-the-wild exploitation is confirmed yet.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-08
4

CISA Adds 4 Actively Exploited Flaws to KEV Catalog โ€” Adobe, Joomla, Langflow

CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog on July 7: CVE-2026-48282 (Adobe ColdFusion path traversal, CVSS 10.0), CVE-2026-56290 (Joomla Page Builder RCE, CVSS 10.0), CVE-2026-55255 (Langflow authorization bypass), and CVE-2026-48908 (JoomShaper SP PageBuilder file upload, CVSS 10.0). All are under active exploitation.

The Hacker Newsโ— Tier 1/4 โ€” Very High2026-07-07
5

GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures

New research demonstrates that signed Git commit hashes are not immutable identifiers. An attacker without the signing key can mint a second commit with the same content, author, and date and a valid signature โ€” GitHub still stamps "Verified." This undermines hash-based blocklists, provenance logs, and reproducible-build records.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-08
6

GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code

Researchers found that GitHub Copilot (powered by Claude and Gemini) refuses harmful requests in chat but produces the same harmful content when the request is broken into small, ordinary-looking coding steps. In 816 workflow runs, the model produced the banned content in every case โ€” a technique called "workflow-level jailbreak construction."

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-08
7

Ubiquiti Patches Critical UniFi Flaws Across Multiple Products

Ubiquiti shipped updates for critical vulnerabilities in UniFi Connect (CVE-2026-50746, CVSS 10.0 โ€” command injection), UniFi Talk (CVE-2026-50747, CVSS 9.9 โ€” SQL injection), UniFi Access (CVE-2026-50748, CVSS 9.9 โ€” input validation), UniFi Protect, and UniFi OS. All could lead to privilege escalation or arbitrary code execution.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-08
8

Rogue Agent Flaw in Google Dialogflow CX Could Let Attackers Hijack Chatbots

Varonis disclosed "Rogue Agent," a flaw in Google's Dialogflow CX that could let an attacker with edit rights on one Code Block-enabled agent compromise all agents in the same Google Cloud project โ€” enabling reading live conversations, stealing user data, and impersonating the bot. Google has fixed the issue; no evidence of exploitation was found.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-07
9

Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data

Microsoft issued a warning that maliciously crafted MCP (Model Context Protocol) tool descriptions can trick AI agents into leaking sensitive data. The technique exploits how agents interpret tool metadata, potentially causing them to route data to attacker-controlled endpoints.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-08
10

RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service

A new Android malware operation called RedWing is being sold as a Malware-as-a-Service on Telegram, allowing even low-skill criminals to deploy banking trojans with overlay attacks and OTP theft. Zimperium's zLabs identified it as a variant of the Oblivion platform, rented at $300/month with Telegram bot-driven custom builds.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-07
11

China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware

Cisco Talos reported that APT actor UAT-7810 is actively refining LONGLEASH malware to compromise internet-facing networking devices and expand its LapDogs Operational Relay Box (ORB) network. The infrastructure is then leveraged by China-nexus threat actor UAT-5918 for attacks on critical infrastructure in Taiwan.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-08

Government 6 stories

1

CISA Urges Hardening Fortinet Devices After FortiBleed Credential Exposure

CISA issued an urgent alert regarding "FortiBleed" โ€” the exposure of leaked credentials associated with approximately 74,000 Fortinet devices (firewalls and SSL VPN gateways) across government and private sectors globally. CISA urged organizations to terminate all active sessions, reset credentials, enforce PBKDF2 hashing, deploy phishing-resistant MFA, and restrict management interfaces from the public internet.

CISAโ— Tier 1/4 โ€” Very High2026-06-18 (Updated 2026-06-22)
2

FBI Seizes NetNut Proxy Platform, Popa Botnet โ€” 2 Million Devices

The FBI, working with Google, Lumen, and Shadowserver, seized hundreds of domains tied to NetNut, a residential proxy service operated by Alarum Technologies [NASDAQ: ALAR]. The Popa botnet โ€” at least 2 million compromised devices including smart TVs and streaming boxes โ€” was used to relay abusive traffic, including credential stuffing, advertising fraud, and account takeover. Google observed 316 distinct threat actor clusters using NetNut exit nodes in a single week.

Krebs on Securityโ— Tier 2/4 โ€” High2026-07-02
3

Taiwan Charges Two Businessmen Over Chinese Espionage Campaign

Taiwan's MJIB (Investigation Bureau) charged two businessmen for their alleged roles in a Chinese espionage campaign targeting Taiwanese critical infrastructure and government systems. The charges come amid heightened cross-strait cybersecurity tensions.

The Record from Recorded Future Newsโ— Tier 2/4 โ€” High2026-07-08
4

Spain Arrests Alleged Supporter of Pro-Russian Hacktivist Groups After FBI Tip

Spanish police arrested an individual allegedly linked to pro-Russian hacktivist groups following a tip from the FBI. The arrest highlights ongoing international cooperation targeting hacktivist operations aligned with Russian state interests.

The Record from Recorded Future Newsโ— Tier 2/4 โ€” High2026-07-08
5

Canadian Spy Agency Reports Hacking Three Criminal Groups in 2025

Canada's Communications Security Establishment (CSE) disclosed that its operatives conducted offensive cyber operations against three criminal groups in 2025, marking a rare public acknowledgment of active cyber countermeasures by the agency.

The Record from Recorded Future Newsโ— Tier 2/4 โ€” High2026-07-06
6

Russian Intelligence Services Continue to Target Commercial Messaging Applications

CISA published an external resource alert noting that Russian intelligence services continue to target commercial messaging applications, including Signal and WhatsApp. The advisory follows the US posting a $10 million reward for information on Russian cyber campaigns targeting these platforms.

CISAโ— Tier 1/4 โ€” Very High2026-06-26

Defence 2 stories

1

Britain Plans to Build Autonomous AI 'Cyber Shield' to Defend the Nation

The UK government unveiled plans to develop an autonomous AI-powered "Cyber Shield" capable of defending national networks at machine speed. The system would automatically detect and respond to cyber threats without human intervention, representing a significant escalation in AI-driven defensive cyber operations.

The Record from Recorded Future Newsโ— Tier 2/4 โ€” High2026-07-07
2

EU Unveils Cyber Plan to Reduce Reliance on Foreign AI Systems

The European Commission announced a comprehensive cyber plan aimed at reducing the EU's dependence on foreign AI systems, particularly from the US and China. The initiative includes requirements for AI security audits, supply chain resilience, and investment in indigenous AI security capabilities.

The Record from Recorded Future Newsโ— Tier 2/4 โ€” High2026-07-08

Financial Services 2 stories

1

Cash App Owner to Pay $45 Million to Settle Allegations of Lax Security

Block Inc., owner of Cash App, agreed to a $45 million settlement to resolve allegations of inadequate security practices that led to user data exposure and financial losses. The settlement underscores growing regulatory scrutiny of fintech security practices.

The Record from Recorded Future Newsโ— Tier 2/4 โ€” High2026-07-08
2

SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users

Elastic Security Labs uncovered REF6045, a campaign targeting Mexican banks, fintech firms, and crypto exchanges with SCMBANKER malware. The infection chain uses fake CAPTCHA pages ("ClickFix" lures) to trick victims into running PowerShell commands that install the toolkit, which can lock screens, redirect browsers, and deploy remote access tools for full account takeover.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-08

Healthcare 1 story

1

Scattered Spider Hackers Plead Guilty on Day 1 of Trial โ€” Targeted Healthcare Providers

Two key members of the prolific Scattered Spider cybercrime group โ€” Owen Flowers, 18, and Thalha Jubair, 20 โ€” pleaded guilty on the first day of their trial in the UK. Charges included attacks on Transport for London and US healthcare providers SSM Health Care Corporation and Sutter Health. US prosecutors separately allege the group conducted 120 network intrusions against 47 US entities, collecting at least $115 million in ransom payments.

Krebs on Securityโ— Tier 2/4 โ€” High2026-06-23

General / Cross-Sector 4 stories

1

Felons, Fraudsters Behind Offensive Cybersecurity Startup IRIS C2

KrebsOnSecurity revealed that IRIS C2, a startup offering millions of dollars for zero-day exploits, is run by convicted felons and far-right conspiracy theorists Jack Burkman and Jacob Wohl. The pair have a history of creating fake intelligence companies and spreading false claims. IRIS C2 is registered through Calvexa Group LLC, a federal contractor with no apparent active government contracts.

Krebs on Securityโ— Tier 2/4 โ€” High2026-07-08
2

Greek Victims File Lawsuit Against Intellexa Over Predator Spyware

Greek citizens filed a lawsuit against Intellexa, the company behind the Predator spyware, alleging illegal surveillance. The case adds to the growing legal pressure on commercial spyware vendors, following similar actions in Europe.

The Record from Recorded Future Newsโ— Tier 2/4 โ€” High2026-07-09
3

Supreme Court Allows Texas App Law Requiring Age Verification to Take Effect

The US Supreme Court allowed a Texas law requiring app stores to verify users' ages before allowing downloads to take effect. The law has significant implications for privacy, security, and the digital economy, and is expected to face further legal challenges.

The Record from Recorded Future Newsโ— Tier 2/4 โ€” High2026-07-07
4

UK Cyber Pledge Draws Only a Handful of Top Firms Despite Ministerial Appeal

The UK government's voluntary cyber security pledge, aimed at getting major companies to commit to baseline security practices, attracted only a small number of top firms. The lackluster response raises questions about the effectiveness of voluntary approaches to critical infrastructure security.

The Record from Recorded Future Newsโ— Tier 2/4 โ€” High2026-07-07

Analytics

Sector distribution

IT / Technology
11
Government
6
Defence
2
Financial Services
2
Healthcare
1
General / Cross-Sector
4

Source breakdown

The Hacker News
12
The Record from Recorded Future News
9
Krebs on Security
3
CISA
2
26stories
IT / Technology 11
Government 6
Defence 2
Financial Services 2
Healthcare 1
General / Cross-Sector 4

Source Reliability Index

TierLabelDescription
โ— Tier 1Very HighOfficial / first-party
โ— Tier 2HighEstablished cyber journalism
โ— Tier 3ModerateGeneral tech/news media
โ— Tier 4LowSocial / unverified