// daily digest ยท 2026-07-11
Saturday·11 July 2026

Cyber Digest

A daily roundup of key cybersecurity developments across sectors

16 stories5 sectors4 sourcesGlobal focus

Executive Summary

A busy 48 hours in cyber: Progress Software urgently told ShareFile customers to shut down Storage Zone Controllers over a "credible external security threat" โ€” the third major Progress incident (MOVEit, WS_FTP) in as many years. Europe revived its controversial CSAM-scanning law, pushing big tech to deploy client-side scanning. In law enforcement wins, a Ryuk ransomware operator pleaded guilty in the UK and a BlackCat/AlphV conspirator received a nearly 6-year sentence, while a former ransomware negotiator was sentenced to 70 months for feeding victim intel to the BlackCat gang. The ACSC issued a critical alert over a large-scale CMS exploitation campaign targeting Australian infrastructure. Meanwhile, the Injective Labs GitHub compromise pushed wallet-key-stealing npm packages, and researchers uncovered a massive WP-SHELLSTORM webshell brokerage that backdoored thousands of WordPress sites.

5
IT / Technology
4
Government
3
Financial Services
2
Defence
2
General / Cross-Sector

Incident Map

(static view)
CriticalSevereElevatedGuardeddarker = more incidents
United States
4
China
2
Australia
1
United Kingdom
1
Netherlands
1

Pan-regional / not map-pinned: ๐ŸŒ Global: 5๐Ÿ‡ช๐Ÿ‡บ Europe: 2

5 countries ยท 16 stories ยท click a country for its stories. Interactive map loads on the hosted site.

๐ŸŽฏ Geo-attribution: 7/16 stories located directly from text (44%). Low-confidence (region-bucket only, check): United States.

๐ŸŽฏ Geo-attribution: 7/16 stories located directly from text (44%). Low-confidence (region-bucket only, check): United States.

IT / Technology 5 stories

1

Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat

Progress Software has told ShareFile customers to shut down the Windows servers running their Storage Zone Controllers, responding to what it described as a "credible external security threat." The company temporarily disabled affected accounts "out of an abundance of caution" while working with security experts. No unauthorized access to ShareFile accounts or data has been confirmed. The order became public after a customer posted the company's email to Reddit's r/sysadmin on July 10. This follows Progress's history of high-profile incidents including the MOVEit Transfer and WS_FTP Server breaches.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-10
2

Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages

Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and published a malicious @injectivelabs/sdk-ts@1.20.21 package on npm designed to steal cryptocurrency wallet private keys and mnemonic seed phrases. The malicious code โ€” pushed via commits from a compromised developer account โ€” also published the tainted version across 17 additional @injective packages. Socket identified the supply chain attack, which has since been deprecated but remains downloadable from GitHub.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-10
3

Six New U-Boot Flaws Could Let Attackers Crash Devices or Run Code at Boot

Binarly researchers discovered six vulnerabilities in U-Boot, the widely-used bootloader powering everything from home routers to datacenter servers. Four can crash a device; the other two let an attacker who slips a malicious FIT image past signature verification execute arbitrary code before the OS loads. All six flaws are reachable before signature checking completes, fundamentally undermining U-Boot's secure boot guarantees.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-10
4

New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic

QiAnXin attributed a new Rust-based remote access trojan called MODBEACON to the China-linked Silver Fox cybercrime group. MODBEACON uses gRPC streaming for encrypted C2 communication, with infrastructure hosted on Amazon and Cloudflare CDN. The group distributes malware via counterfeit software installers using SEO poisoning, targeting technology, education, and state-owned enterprises across Asia.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-10
5

Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites

A cybercrime crew left its command server exposed for three weeks, revealing the inner workings of a webshell access brokerage tracked as WP-SHELLSTORM. The exposed server showed target lists of over 1.4 million websites, with active backdoors installed via compromised WordPress sites running outdated plugins โ€” particularly the Breeze caching plugin and Joomla's JCE editor. SOCRadar identified the operation after spotting the exposed folder on June 11.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-10

Government 4 stories

1

Europe Revives Law Allowing Big Tech to Scan for CSAM

The European Parliament revived legislation that would require major technology platforms to scan private communications (including encrypted messages) for child sexual abuse material (CSAM). The revived bill rekindles the long-running debate between child safety advocates and privacy defenders, with encryption experts warning the scanning requirements would fundamentally weaken end-to-end encryption for all users.

The Recordโ— Tier 2/4 โ€” High2026-07-11
2

EU Takes Member States to Court Over Unimplemented Cybersecurity Law

The European Commission has taken several EU member states to court for failing to transpose the NIS2 cybersecurity directive into national law. The directive, which strengthens security requirements for critical infrastructure operators and expands the sectors covered, was due for implementation by October 2024. The court action signals growing EU frustration with slow member-state adoption of harmonised cyber resilience rules.

The Recordโ— Tier 2/4 โ€” High2026-07-09
3

ACSC Warns of Large-Scale Exploitation Campaign Targeting Website CMS

The Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) issued a critical-rated alert tracking a large-scale exploitation campaign targeting multiple vulnerabilities in web content management systems. The campaign poses a significant threat to Australian small & medium businesses, organisations and critical infrastructure, and government agencies. Specific vulnerabilities and mitigations were detailed in the advisory.

ACSC (Cyber.gov.au)โ— Tier 1/4 โ€” Very High2026-07-09
4

CISA Adds Multiple Known Exploited Vulnerabilities to Catalog

CISA continued updating its Known Exploited Vulnerabilities (KEV) catalog, adding several new entries requiring federal agency remediation. The agency's recent advisories also included a joint alert on Russian intelligence services targeting commercial messaging applications, and guidance urging hardening of Fortinet devices after reports of credential exposure.

CISAโ— Tier 1/4 โ€” Very High2026-07-09

Financial Services 3 stories

1

Ryuk Operator Pleads Guilty; BlackCat/AlphV Conspirator Gets Nearly 6-Year Sentence

In a major law enforcement double-header, a Ryuk ransomware operator pleaded guilty in the UK while a co-conspirator in the BlackCat/AlphV ransomware group was sentenced to nearly six years in prison. The cases demonstrate ongoing international cooperation in dismantling ransomware operations โ€” Ryuk caused hundreds of millions in damages globally, including significant healthcare sector disruptions.

The Recordโ— Tier 2/4 โ€” High2026-07-11
2

Cash App Owner to Pay $45 Million to Settle Allegations of Lax Security

The parent company of Cash App has agreed to pay $45 million to settle regulatory allegations of inadequate security practices. The settlement comes amid broader scrutiny of financial technology companies' security postures, particularly regarding customer data protection and incident response procedures.

The Recordโ— Tier 2/4 โ€” High2026-07-09
3

Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat

Angelo Martino, 41, of Florida was sentenced to 70 months in prison for conspiring with the BlackCat ransomware group while working as a paid ransomware negotiator. Federal prosecutors described him as a "double agent" who provided victim negotiating positions and strategies to the attackers without victim knowledge. Martino worked on behalf of five victims while covertly assisting the cybercriminals.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-10

Defence 2 stories

1

China, India Ran Separate Spying Campaigns Against Same Pakistani Police Force

Researchers detailed that both Chinese and Indian state-sponsored cyber espionage groups ran separate, independent intelligence-gathering campaigns targeting the same Pakistani police force. The parallel targeting highlights the complex geopolitical dynamics in South Asia, with both nations seeking intelligence on Pakistani law enforcement operations and capabilities.

The Recordโ— Tier 2/4 โ€” High2026-07-10
2

NSA Revives 'Tailored Access Operations' Name for Elite Hacking Unit

The National Security Agency has revived its storied "Tailored Access Operations" (TAO) designation for its elite offensive hacking unit. TAO, long considered one of the US government's most advanced cyber operations units, originally operated under that name before being reorganised. The revival signals renewed emphasis on offensive cyber capabilities and sustained access operations.

The Recordโ— Tier 2/4 โ€” High2026-07-10

General / Cross-Sector 2 stories

1

Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access

A threat actor tracked as O-UNC-066 by Okta is using voice-based phishing ("vishing") to trick Microsoft 365 users into enrolling a fake Entra passkey. Attackers call targets, claim they need to register a new passkey, and direct them to a phishing kit identical to the legitimate Microsoft passkey enrollment flow. The campaign targets food & beverage, technology, healthcare, automotive, construction, and aviation sectors โ€” anyone with a Microsoft 365 tenant is potentially at risk.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-10
2

Dutch Police Trace Odido Telco Cyberattack to Suspected Local Accomplice

Dutch police have identified a suspected local accomplice in connection with the cyberattack that disrupted telecommunications provider Odido. The investigation traces the intrusion โ€” which affected mobile and fixed-line services โ€” to a Dutch national who allegedly facilitated the attackers' access to the telco's internal systems.

The Recordโ— Tier 2/4 โ€” High2026-07-10

Analytics

Sector distribution

IT / Technology
5
Government
4
Financial Services
3
Defence
2
General / Cross-Sector
2

Source breakdown

The Hacker News
7
The Record
7
ACSC (Cyber.gov.au)
1
CISA
1
16stories
IT / Technology 5
Government 4
Financial Services 3
Defence 2
General / Cross-Sector 2

Source Reliability Index

TierLabelDescription
โ— Tier 1Very HighOfficial / first-party
โ— Tier 2HighEstablished cyber journalism
โ— Tier 3ModerateGeneral tech/news media
โ— Tier 4LowSocial / unverified