// daily digest ยท 2026-07-14
Tuesday·14 July 2026

Cyber Digest

A daily roundup of key cybersecurity developments across sectors

19 stories6 sectors5 sourcesGlobal focus

Executive Summary

A major joint international advisory warns that Russia's FSB Center 16 continues to exploit poorly configured routers globally, co-signed by 15 Five Eyes and European intelligence agencies โ€” the broadest such coalition in recent memory. In a related geopolitical cyber escalation, the UK and EU imposed their first-ever joint cyber sanctions against Russia following attribution of the Poland power grid attack to the FSB. On the supply-chain front, the jscrambler npm package was compromised in a covert Rust infostealer campaign, and Google and Microsoft jointly pulled the ModHeader browser extension (1.6M installs) after a dormant data collector was discovered in its official store code. CISA published a postmortem on a contractor-exposed GitHub leak that left AWS GovCloud keys exposed for six months, revealing systemic reporting-channel failures. The European Commission referred four member states to the CJEU over NIS2 transposition delays and unveiled a new Cybersecurity and AI Action Plan.

4
Defence
1
Government
7
IT / Technology
5
Legal / Regulatory
1
Financial Services

Incident Map

(static view)
CriticalSevereElevatedGuardeddarker = more incidents
United States
8
United Kingdom
1
France
1
Latvia
1
China
1

Pan-regional / not map-pinned: ๐ŸŒ Global: 5๐Ÿ‡ช๐Ÿ‡บ Europe: 2

5 countries ยท 19 stories ยท click a country for its stories. Interactive map loads on the hosted site.

๐ŸŽฏ Geo-attribution: 8/19 stories located directly from text (42%). Low-confidence (region-bucket only, check): United States.

๐ŸŽฏ Geo-attribution: 8/19 stories located directly from text (42%). Low-confidence (region-bucket only, check): United States.

Defence 4 stories

1

Russia's FSB Blamed for Poland Grid Attack as UK and EU Impose First Joint Cyber Sanctions

The UK and EU jointly attributed a cyberattack on Poland's power grid to Russia's FSB and imposed coordinated sanctions โ€” the first such joint action of its kind. The attack targeted energy infrastructure, marking a significant escalation in state-sponsored cyber operations against critical infrastructure in NATO/EU member states.

The Record from Recorded Future Newsโ— Tier 2/4 โ€” High2026-07-14
2

CISA, FBI, NSA & 12 Allied Agencies Warn: Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting (AA26-194A)

A joint Cybersecurity Advisory co-signed by 15 intelligence and cybersecurity agencies from the Five Eyes plus the Czech Republic, Denmark, Estonia, Finland, France, Italy, Poland, and Sweden details ongoing FSB Center 16 exploitation of poorly configured and vulnerable networking devices across critical infrastructure sectors globally.

CISAโ— Tier 1/4 โ€” Very High2026-07-13
3

NSA Revives 'Tailored Access Operations' Name for Elite Hacking Unit

The NSA has reinstated the "Tailored Access Operations" (TAO) designation for its elite offensive cyber unit, signalling a renewed focus on the operational identity that was historically responsible for some of the agency's most sophisticated cyber operations.

The Record from Recorded Future Newsโ— Tier 2/4 โ€” High2026-07-14
4

China and India Ran Separate Spying Campaigns Against Same Pakistani Police Force

Researchers at SentinelOne detailed sustained cyber espionage activity by suspected China- and India-aligned threat actors targeting Pakistani law enforcement organizations, including the Balochistan Police, between February 2024 and April 2026, compromising servers managing biometric and criminal records.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-11

Government 1 story

1

Lessons Learned from CISA's Recent GitHub Leak โ€” Postmortem Reveals 6-Month Exposure

CISA published a postmortem on a May 2026 incident where a contractor published 844 MB of internal CISA data โ€” including AWS GovCloud keys โ€” in a public GitHub repo for nearly six months. The agency admitted it ignored 9 automated alerts from GitGuardian and took over 48 hours to rotate credentials after notification by KrebsOnSecurity. The report highlights failures in key management and incident response reporting channels.

Krebs on Securityโ— Tier 2/4 โ€” High2026-07-13

IT / Technology 7 stories

1

Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install

The jscrambler npm package was compromised โ€” version 8.14.0 carried a preinstall hook that drops and executes a Rust-based infostealer on Windows, macOS, and Linux. Socket Security flagged the malicious release six minutes after publication. The payload (7.8MB) contained three gzip-compressed native binaries targeting all three platforms.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-11
2

Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found

A hidden browsing-history collector was discovered in the official ModHeader browser extension on both Chrome and Edge Web Stores (1.6M combined installs). The collector was dormant โ€” an empty allowlist kept it from activating โ€” but analysis confirmed it shipped inside the genuine signed extension, not a counterfeit. Microsoft pulled the listing July 3; Google followed July 10.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-13
3

CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks

Researchers at Jamf Threat Labs detailed a new macOS information stealer called CrashStealer, written in native C++ and distributed via a signed, Apple-notarized dropper ("Werkbit.app"). It validates the victim's login password, harvests browser/crypto wallet/password manager/keychain data, encrypts with AES-GCM, and exfiltrates via libcurl.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-13
4

URGENT โ€” Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat

Progress Software instructed ShareFile customers to shut down Windows servers running Storage Zone Controllers in response to a "credible external security threat." The company temporarily disabled affected accounts but has not disclosed the nature of the threat or the threat actor behind it.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-10
5

iCagenda and Balbooa Forms Joomla Flaws Exploited as Zero-Days โ€” CISA Adds to KEV Catalog

CISA added two CVSS 10.0 vulnerabilities (CVE-2026-48939, CVE-2026-56291) in iCagenda and Balbooa Forms Joomla extensions to its Known Exploited Vulnerabilities catalog following reports of active zero-day exploitation since June 15, 2026. Both allow arbitrary file upload leading to remote code execution.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-13
6

Forg365 PhaaS Targets Microsoft 365 With Device Code and AitM Session Theft

A new Phishing-as-a-Service operation, Forg365, combines device code phishing, adversary-in-the-middle tactics, AI-assisted lure creation and post-compromise mailbox operations targeting Microsoft 365. Distributed via Telegram at $400/month ($3,800/year), it uses legitimate email delivery infrastructure (Amazon SES, Twilio SendGrid) for phishing distribution.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-13
7

Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions

Zimbra urged customers to patch a critical stored XSS vulnerability in its Classic Web Client that allows specially crafted emails to execute malicious scripts when opened, potentially leading to session hijacking, credential theft, and account compromise.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-11

Financial Services 1 story

1

Cash App Owner to Pay $45 Million to Settle Allegations of Lax Security

The parent company of Cash App agreed to a $45 million settlement with regulators over allegations of inadequate security practices that exposed user financial data. The settlement underscores increasing regulatory scrutiny on fintech security postures.

The Record from Recorded Future Newsโ— Tier 2/4 โ€” High2026-07-09

Manufacturing 1 story

1

Latvian Forestry Company Still Restoring Systems Weeks After Ransomware Attack

A Latvian forestry company continues recovery efforts weeks after a ransomware attack crippled its operations. The protracted downtime illustrates the severe operational impact of ransomware on manufacturing and industrial enterprises.

The Record from Recorded Future Newsโ— Tier 2/4 โ€” High2026-07-10

Analytics

Sector distribution

Defence
4
Government
1
IT / Technology
7
Legal / Regulatory
5
Financial Services
1
Manufacturing
1

Source breakdown

The Hacker News
8
The Record from Recorded Future News
7
Hunton Andrews Kurth Privacy & Cybersecurity Law Blog
2
CISA
1
Krebs on Security
1
19stories
Defence 4
Government 1
IT / Technology 7
Legal / Regulatory 5
Financial Services 1
Manufacturing 1

Source Reliability Index

TierLabelDescription
โ— Tier 1Very HighOfficial / first-party
โ— Tier 2HighEstablished cyber journalism
โ— Tier 3ModerateGeneral tech/news media
โ— Tier 4LowSocial / unverified