// daily digest ยท 2026-07-13
Monday·13 July 2026

Cyber Digest

A daily roundup of key cybersecurity developments across sectors

16 stories6 sectors5 sourcesGlobal focus

Executive Summary

This weekend's cybersecurity landscape is defined by three major themes: software supply chain attacks hitting critical infrastructure, EU regulatory escalation on cybersecurity and AI, and evolving state-sponsored cyber espionage tactics. The most urgent story is the compromised jscrambler npm package (v8.14.0) โ€” a code-obfuscation tool trusted by thousands of applications โ€” which was silently dropping a Rust-based infostealer via its install hook before Socket Research flagged it within six minutes. Separately, the European Commission escalated NIS2 enforcement by referring four member states to the Court of Justice of the European Union, while also unveiling a new Cybersecurity and AI Action Plan. In the Indo-Pacific, the ACSC issued a critical alert over a large-scale exploitation campaign targeting web content management systems, and Australia's signals intelligence arm published new guidance on the cyber implications of frontier AI models.

5
IT / Technology
4
Legal / Regulatory
3
General / Cross-Sector
2
Defence
1
Government

Incident Map

(static view)
CriticalSevereElevatedGuardeddarker = more incidents
United States
4
Australia
2
Mexico
1
France
1
China
1

Pan-regional / not map-pinned: ๐Ÿ‡ช๐Ÿ‡บ Europe: 4๐ŸŒ Global: 3

5 countries ยท 16 stories ยท click a country for its stories. Interactive map loads on the hosted site.

๐ŸŽฏ Geo-attribution: 7/16 stories located directly from text (44%). Low-confidence (region-bucket only, check): United States.

๐ŸŽฏ Geo-attribution: 7/16 stories located directly from text (44%). Low-confidence (region-bucket only, check): United States.

IT / Technology 5 stories

1

Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install

The jscrambler npm package โ€” a widely-used JavaScript obfuscation tool โ€” was compromised in its 8.14.0 release with a `preinstall` hook that drops and executes a native Rust infostealer binary targeting Windows, macOS, and Linux. Socket Research flagged the malicious release within six minutes of publication. The payload (disguised as `intro.js`) is a ~7.8 MB container packing three gzip-compressed binaries. Any build system that pulled the package in that window is compromised.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-11
2

Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions

Zimbra is urging customers to patch a critical stored cross-site scripting (XSS) vulnerability in the Classic Web Client that allows specially crafted emails to execute arbitrary JavaScript in a user's session, enabling session hijacking, credential theft, and account compromise. No CVE has been assigned yet.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-11
3

Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites

A cybercrime crew left one of its command servers exposed for three weeks, revealing the inner workings of a mass site-hacking operation tracked as WP-SHELLSTORM. The server logs showed target lists of more than 1.4 million websites, with the crew exploiting out-of-date plugins (notably Breeze caching and Joomla's JCE editor) to plant webshell backdoors for resale as an access brokerage.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-10
4

Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access

A threat actor tracked as O-UNC-066 by Okta is targeting organizations across food & beverage, healthcare, and technology sectors with voice phishing calls urging users to enroll a new Entra passkey. The calls direct victims to a convincing phishing kit that mirrors the Microsoft passkey enrollment process, enabling data extortion attacks.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-10
5

Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking

Researchers at the University of Michigan, University of New Mexico, and IIT Delhi tested 281 popular free VPN apps on Google Play using a new system called MVPNalyzer. They found 29 apps leaking user traffic outside the encrypted tunnel, 61 apps sending data in plaintext, and five apps exposing configuration files in the clear โ€” collectively installed more than 2.4 billion times.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-10

General / Cross-Sector 3 stories

1

ACSC: Large-Scale Exploitation Campaign Targeting Website CMS โ€” Critical Alert

The Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) issued a critical alert tracking a large-scale exploitation campaign targeting vulnerabilities in web content management systems. The campaign is affecting small & medium businesses, organisations, critical infrastructure, and government entities. This mirrors a global trend of CMS-based attacks accelerating in volume.

ACSC / Cyber.gov.auโ— Tier 1/4 โ€” Very High2026-07-09
2

Europe Revives Law Allowing Big Tech to Scan for CSAM

The European Parliament has revived proposed legislation that would require big technology companies to scan private communications for child sexual abuse material (CSAM). The law had faced significant privacy objections but has been reintroduced amid renewed debate over encryption, child safety, and fundamental rights.

The Record by Recorded Futureโ— Tier 2/4 โ€” High2026-07-10
3

CISA Joint Advisory: Russian Intelligence Services Continue to Target Commercial Messaging Applications

CISA published a joint advisory warning that Russian intelligence services continue to target commercial messaging applications as part of an ongoing espionage campaign. The advisory provides indicators of compromise and mitigation recommendations for organisations using these platforms.

CISAโ— Tier 1/4 โ€” Very High2026-07-13

Defence 2 stories

1

NSA Revives 'Tailored Access Operations' Name for Elite Hacking Unit

The U.S. National Security Agency has revived the "Tailored Access Operations" (TAO) designation for its elite hacking unit, a name historically associated with some of the agency's most sensitive offensive cyber operations. The revival signals a renewed focus on offensive cyber capabilities under the current administration.

The Record by Recorded Futureโ— Tier 2/4 โ€” High2026-07-13
2

CISA Adds Known Exploited Vulnerabilities to Catalog / Urges Hardening Fortinet Devices

CISA continues to expand its Known Exploited Vulnerabilities catalog with multiple new entries, and separately issued an alert urging organisations to harden Fortinet devices following reports of widespread credential exposure affecting Fortinet firewalls and VPN gateways โ€” a finding corroborated by the Australian ACSC.

CISAโ— Tier 1/4 โ€” Very High2026-07-13

Government 1 story

1

China and India Ran Separate Spying Campaigns Against Same Pakistani Police Force

SentinelOne SentinelLABS disclosed details of sustained cyber espionage activity targeting Pakistani law enforcement organisations by suspected China- and India-aligned threat actors between February 2024 and April 2026. Compromised assets included servers managing police biometric records, criminal case files, and personnel data. A China-nexus actor deployed a custom implant masquerading as an update to the Balochistan Police's Complaint Management System.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-11

Financial Services 1 story

1

Cash App Owner to Pay $45 Million to Settle Allegations of Lax Security

The owner of Cash App has agreed to pay $45 million to settle allegations of inadequate security practices that exposed user financial data. The settlement resolves claims that the company failed to implement basic cybersecurity controls and did not adequately respond to known security incidents affecting its digital payment platform.

The Record by Recorded Futureโ— Tier 2/4 โ€” High2026-07-08

Analytics

Sector distribution

IT / Technology
5
Legal / Regulatory
4
General / Cross-Sector
3
Defence
2
Government
1
Financial Services
1

Source breakdown

The Hacker News
6
The Record by Recorded Future
5
Hunton Andrews Kurth
2
CISA
2
ACSC / Cyber.gov.au
1
16stories
IT / Technology 5
Legal / Regulatory 4
General / Cross-Sector 3
Defence 2
Government 1
Financial Services 1

Source Reliability Index

TierLabelDescription
โ— Tier 1Very HighOfficial / first-party
โ— Tier 2HighEstablished cyber journalism
โ— Tier 3ModerateGeneral tech/news media
โ— Tier 4LowSocial / unverified