Cyber Digest
A daily roundup of key cybersecurity developments across sectors
Executive Summary
This weekend's cybersecurity landscape is defined by three major themes: software supply chain attacks hitting critical infrastructure, EU regulatory escalation on cybersecurity and AI, and evolving state-sponsored cyber espionage tactics. The most urgent story is the compromised jscrambler npm package (v8.14.0) โ a code-obfuscation tool trusted by thousands of applications โ which was silently dropping a Rust-based infostealer via its install hook before Socket Research flagged it within six minutes. Separately, the European Commission escalated NIS2 enforcement by referring four member states to the Court of Justice of the European Union, while also unveiling a new Cybersecurity and AI Action Plan. In the Indo-Pacific, the ACSC issued a critical alert over a large-scale exploitation campaign targeting web content management systems, and Australia's signals intelligence arm published new guidance on the cyber implications of frontier AI models.
Incident Map
IT / Technology 5 stories
Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
The jscrambler npm package โ a widely-used JavaScript obfuscation tool โ was compromised in its 8.14.0 release with a `preinstall` hook that drops and executes a native Rust infostealer binary targeting Windows, macOS, and Linux. Socket Research flagged the malicious release within six minutes of publication. The payload (disguised as `intro.js`) is a ~7.8 MB container packing three gzip-compressed binaries. Any build system that pulled the package in that window is compromised.
Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions
Zimbra is urging customers to patch a critical stored cross-site scripting (XSS) vulnerability in the Classic Web Client that allows specially crafted emails to execute arbitrary JavaScript in a user's session, enabling session hijacking, credential theft, and account compromise. No CVE has been assigned yet.
Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
A cybercrime crew left one of its command servers exposed for three weeks, revealing the inner workings of a mass site-hacking operation tracked as WP-SHELLSTORM. The server logs showed target lists of more than 1.4 million websites, with the crew exploiting out-of-date plugins (notably Breeze caching and Joomla's JCE editor) to plant webshell backdoors for resale as an access brokerage.
Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access
A threat actor tracked as O-UNC-066 by Okta is targeting organizations across food & beverage, healthcare, and technology sectors with voice phishing calls urging users to enroll a new Entra passkey. The calls direct victims to a convincing phishing kit that mirrors the Microsoft passkey enrollment process, enabling data extortion attacks.
Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking
Researchers at the University of Michigan, University of New Mexico, and IIT Delhi tested 281 popular free VPN apps on Google Play using a new system called MVPNalyzer. They found 29 apps leaking user traffic outside the encrypted tunnel, 61 apps sending data in plaintext, and five apps exposing configuration files in the clear โ collectively installed more than 2.4 billion times.
Legal / Regulatory 4 stories
EU Takes 4 Member States to Court Over NIS2 Transposition Delays
On July 8, the European Commission referred Ireland, Spain, France, and the Netherlands to the Court of Justice of the European Union for failing to fully transpose the NIS2 Directive into national law. The move is the Commission's most aggressive enforcement action on the landmark cybersecurity directive, signalling that transposition delays will no longer be tolerated.
European Commission Unveils Cybersecurity and AI Action Plan
On July 7, the European Commission presented an Action Plan on Cybersecurity and Artificial Intelligence aimed at supporting safe and responsible AI use while strengthening cyber resilience across the EU. The plan addresses the intersection of AI system security and the growing attack surface from AI adoption.
EDPB Opens Public Consultation on New Personal Data Breach Notification Template
The European Data Protection Board has opened a public consultation on a new standardized template for personal data breach notifications, aiming to harmonise breach reporting across EU member states and reduce administrative burden for organisations operating cross-border.
Ryuk Operator Pleads Guilty; Blackcat/AlphV Conspirator Gets Nearly 6-Year Sentence
A Ryuk ransomware operator has pleaded guilty to charges, while a conspirator in the Blackcat (AlphV) ransomware group received a sentence of nearly six years. The convictions mark continued law enforcement success in dismantling major ransomware operations.
General / Cross-Sector 3 stories
ACSC: Large-Scale Exploitation Campaign Targeting Website CMS โ Critical Alert
The Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) issued a critical alert tracking a large-scale exploitation campaign targeting vulnerabilities in web content management systems. The campaign is affecting small & medium businesses, organisations, critical infrastructure, and government entities. This mirrors a global trend of CMS-based attacks accelerating in volume.
Europe Revives Law Allowing Big Tech to Scan for CSAM
The European Parliament has revived proposed legislation that would require big technology companies to scan private communications for child sexual abuse material (CSAM). The law had faced significant privacy objections but has been reintroduced amid renewed debate over encryption, child safety, and fundamental rights.
CISA Joint Advisory: Russian Intelligence Services Continue to Target Commercial Messaging Applications
CISA published a joint advisory warning that Russian intelligence services continue to target commercial messaging applications as part of an ongoing espionage campaign. The advisory provides indicators of compromise and mitigation recommendations for organisations using these platforms.
Defence 2 stories
NSA Revives 'Tailored Access Operations' Name for Elite Hacking Unit
The U.S. National Security Agency has revived the "Tailored Access Operations" (TAO) designation for its elite hacking unit, a name historically associated with some of the agency's most sensitive offensive cyber operations. The revival signals a renewed focus on offensive cyber capabilities under the current administration.
CISA Adds Known Exploited Vulnerabilities to Catalog / Urges Hardening Fortinet Devices
CISA continues to expand its Known Exploited Vulnerabilities catalog with multiple new entries, and separately issued an alert urging organisations to harden Fortinet devices following reports of widespread credential exposure affecting Fortinet firewalls and VPN gateways โ a finding corroborated by the Australian ACSC.
Government 1 story
China and India Ran Separate Spying Campaigns Against Same Pakistani Police Force
SentinelOne SentinelLABS disclosed details of sustained cyber espionage activity targeting Pakistani law enforcement organisations by suspected China- and India-aligned threat actors between February 2024 and April 2026. Compromised assets included servers managing police biometric records, criminal case files, and personnel data. A China-nexus actor deployed a custom implant masquerading as an update to the Balochistan Police's Complaint Management System.
Financial Services 1 story
Cash App Owner to Pay $45 Million to Settle Allegations of Lax Security
The owner of Cash App has agreed to pay $45 million to settle allegations of inadequate security practices that exposed user financial data. The settlement resolves claims that the company failed to implement basic cybersecurity controls and did not adequately respond to known security incidents affecting its digital payment platform.
Analytics
Source Reliability Index
| Tier | Label | Description |
|---|---|---|
| โ Tier 1 | Very High | Official / first-party |
| โ Tier 2 | High | Established cyber journalism |
| โ Tier 3 | Moderate | General tech/news media |
| โ Tier 4 | Low | Social / unverified |