Cyber Digest
A daily roundup of key cybersecurity developments across sectors
Executive Summary
A busy 48 hours in cyber: Progress Software urgently told ShareFile customers to shut down Storage Zone Controllers over a "credible external security threat" โ the third major Progress incident (MOVEit, WS_FTP) in as many years. Europe revived its controversial CSAM-scanning law, pushing big tech to deploy client-side scanning. In law enforcement wins, a Ryuk ransomware operator pleaded guilty in the UK and a BlackCat/AlphV conspirator received a nearly 6-year sentence, while a former ransomware negotiator was sentenced to 70 months for feeding victim intel to the BlackCat gang. The ACSC issued a critical alert over a large-scale CMS exploitation campaign targeting Australian infrastructure. Meanwhile, the Injective Labs GitHub compromise pushed wallet-key-stealing npm packages, and researchers uncovered a massive WP-SHELLSTORM webshell brokerage that backdoored thousands of WordPress sites.
Incident Map
IT / Technology 5 stories
Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat
Progress Software has told ShareFile customers to shut down the Windows servers running their Storage Zone Controllers, responding to what it described as a "credible external security threat." The company temporarily disabled affected accounts "out of an abundance of caution" while working with security experts. No unauthorized access to ShareFile accounts or data has been confirmed. The order became public after a customer posted the company's email to Reddit's r/sysadmin on July 10. This follows Progress's history of high-profile incidents including the MOVEit Transfer and WS_FTP Server breaches.
Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages
Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and published a malicious @injectivelabs/sdk-ts@1.20.21 package on npm designed to steal cryptocurrency wallet private keys and mnemonic seed phrases. The malicious code โ pushed via commits from a compromised developer account โ also published the tainted version across 17 additional @injective packages. Socket identified the supply chain attack, which has since been deprecated but remains downloadable from GitHub.
Six New U-Boot Flaws Could Let Attackers Crash Devices or Run Code at Boot
Binarly researchers discovered six vulnerabilities in U-Boot, the widely-used bootloader powering everything from home routers to datacenter servers. Four can crash a device; the other two let an attacker who slips a malicious FIT image past signature verification execute arbitrary code before the OS loads. All six flaws are reachable before signature checking completes, fundamentally undermining U-Boot's secure boot guarantees.
New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic
QiAnXin attributed a new Rust-based remote access trojan called MODBEACON to the China-linked Silver Fox cybercrime group. MODBEACON uses gRPC streaming for encrypted C2 communication, with infrastructure hosted on Amazon and Cloudflare CDN. The group distributes malware via counterfeit software installers using SEO poisoning, targeting technology, education, and state-owned enterprises across Asia.
Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
A cybercrime crew left its command server exposed for three weeks, revealing the inner workings of a webshell access brokerage tracked as WP-SHELLSTORM. The exposed server showed target lists of over 1.4 million websites, with active backdoors installed via compromised WordPress sites running outdated plugins โ particularly the Breeze caching plugin and Joomla's JCE editor. SOCRadar identified the operation after spotting the exposed folder on June 11.
Government 4 stories
Europe Revives Law Allowing Big Tech to Scan for CSAM
The European Parliament revived legislation that would require major technology platforms to scan private communications (including encrypted messages) for child sexual abuse material (CSAM). The revived bill rekindles the long-running debate between child safety advocates and privacy defenders, with encryption experts warning the scanning requirements would fundamentally weaken end-to-end encryption for all users.
EU Takes Member States to Court Over Unimplemented Cybersecurity Law
The European Commission has taken several EU member states to court for failing to transpose the NIS2 cybersecurity directive into national law. The directive, which strengthens security requirements for critical infrastructure operators and expands the sectors covered, was due for implementation by October 2024. The court action signals growing EU frustration with slow member-state adoption of harmonised cyber resilience rules.
ACSC Warns of Large-Scale Exploitation Campaign Targeting Website CMS
The Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) issued a critical-rated alert tracking a large-scale exploitation campaign targeting multiple vulnerabilities in web content management systems. The campaign poses a significant threat to Australian small & medium businesses, organisations and critical infrastructure, and government agencies. Specific vulnerabilities and mitigations were detailed in the advisory.
CISA Adds Multiple Known Exploited Vulnerabilities to Catalog
CISA continued updating its Known Exploited Vulnerabilities (KEV) catalog, adding several new entries requiring federal agency remediation. The agency's recent advisories also included a joint alert on Russian intelligence services targeting commercial messaging applications, and guidance urging hardening of Fortinet devices after reports of credential exposure.
Financial Services 3 stories
Ryuk Operator Pleads Guilty; BlackCat/AlphV Conspirator Gets Nearly 6-Year Sentence
In a major law enforcement double-header, a Ryuk ransomware operator pleaded guilty in the UK while a co-conspirator in the BlackCat/AlphV ransomware group was sentenced to nearly six years in prison. The cases demonstrate ongoing international cooperation in dismantling ransomware operations โ Ryuk caused hundreds of millions in damages globally, including significant healthcare sector disruptions.
Cash App Owner to Pay $45 Million to Settle Allegations of Lax Security
The parent company of Cash App has agreed to pay $45 million to settle regulatory allegations of inadequate security practices. The settlement comes amid broader scrutiny of financial technology companies' security postures, particularly regarding customer data protection and incident response procedures.
Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat
Angelo Martino, 41, of Florida was sentenced to 70 months in prison for conspiring with the BlackCat ransomware group while working as a paid ransomware negotiator. Federal prosecutors described him as a "double agent" who provided victim negotiating positions and strategies to the attackers without victim knowledge. Martino worked on behalf of five victims while covertly assisting the cybercriminals.
Defence 2 stories
China, India Ran Separate Spying Campaigns Against Same Pakistani Police Force
Researchers detailed that both Chinese and Indian state-sponsored cyber espionage groups ran separate, independent intelligence-gathering campaigns targeting the same Pakistani police force. The parallel targeting highlights the complex geopolitical dynamics in South Asia, with both nations seeking intelligence on Pakistani law enforcement operations and capabilities.
NSA Revives 'Tailored Access Operations' Name for Elite Hacking Unit
The National Security Agency has revived its storied "Tailored Access Operations" (TAO) designation for its elite offensive hacking unit. TAO, long considered one of the US government's most advanced cyber operations units, originally operated under that name before being reorganised. The revival signals renewed emphasis on offensive cyber capabilities and sustained access operations.
General / Cross-Sector 2 stories
Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access
A threat actor tracked as O-UNC-066 by Okta is using voice-based phishing ("vishing") to trick Microsoft 365 users into enrolling a fake Entra passkey. Attackers call targets, claim they need to register a new passkey, and direct them to a phishing kit identical to the legitimate Microsoft passkey enrollment flow. The campaign targets food & beverage, technology, healthcare, automotive, construction, and aviation sectors โ anyone with a Microsoft 365 tenant is potentially at risk.
Dutch Police Trace Odido Telco Cyberattack to Suspected Local Accomplice
Dutch police have identified a suspected local accomplice in connection with the cyberattack that disrupted telecommunications provider Odido. The investigation traces the intrusion โ which affected mobile and fixed-line services โ to a Dutch national who allegedly facilitated the attackers' access to the telco's internal systems.
Analytics
Source Reliability Index
| Tier | Label | Description |
|---|---|---|
| โ Tier 1 | Very High | Official / first-party |
| โ Tier 2 | High | Established cyber journalism |
| โ Tier 3 | Moderate | General tech/news media |
| โ Tier 4 | Low | Social / unverified |