Cyber Digest
A daily roundup of key cybersecurity developments across sectors
Executive Summary
A major joint international advisory warns that Russia's FSB Center 16 continues to exploit poorly configured routers globally, co-signed by 15 Five Eyes and European intelligence agencies โ the broadest such coalition in recent memory. In a related geopolitical cyber escalation, the UK and EU imposed their first-ever joint cyber sanctions against Russia following attribution of the Poland power grid attack to the FSB. On the supply-chain front, the jscrambler npm package was compromised in a covert Rust infostealer campaign, and Google and Microsoft jointly pulled the ModHeader browser extension (1.6M installs) after a dormant data collector was discovered in its official store code. CISA published a postmortem on a contractor-exposed GitHub leak that left AWS GovCloud keys exposed for six months, revealing systemic reporting-channel failures. The European Commission referred four member states to the CJEU over NIS2 transposition delays and unveiled a new Cybersecurity and AI Action Plan.
Incident Map
Defence 4 stories
Russia's FSB Blamed for Poland Grid Attack as UK and EU Impose First Joint Cyber Sanctions
The UK and EU jointly attributed a cyberattack on Poland's power grid to Russia's FSB and imposed coordinated sanctions โ the first such joint action of its kind. The attack targeted energy infrastructure, marking a significant escalation in state-sponsored cyber operations against critical infrastructure in NATO/EU member states.
CISA, FBI, NSA & 12 Allied Agencies Warn: Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting (AA26-194A)
A joint Cybersecurity Advisory co-signed by 15 intelligence and cybersecurity agencies from the Five Eyes plus the Czech Republic, Denmark, Estonia, Finland, France, Italy, Poland, and Sweden details ongoing FSB Center 16 exploitation of poorly configured and vulnerable networking devices across critical infrastructure sectors globally.
NSA Revives 'Tailored Access Operations' Name for Elite Hacking Unit
The NSA has reinstated the "Tailored Access Operations" (TAO) designation for its elite offensive cyber unit, signalling a renewed focus on the operational identity that was historically responsible for some of the agency's most sophisticated cyber operations.
China and India Ran Separate Spying Campaigns Against Same Pakistani Police Force
Researchers at SentinelOne detailed sustained cyber espionage activity by suspected China- and India-aligned threat actors targeting Pakistani law enforcement organizations, including the Balochistan Police, between February 2024 and April 2026, compromising servers managing biometric and criminal records.
Government 1 story
Lessons Learned from CISA's Recent GitHub Leak โ Postmortem Reveals 6-Month Exposure
CISA published a postmortem on a May 2026 incident where a contractor published 844 MB of internal CISA data โ including AWS GovCloud keys โ in a public GitHub repo for nearly six months. The agency admitted it ignored 9 automated alerts from GitGuardian and took over 48 hours to rotate credentials after notification by KrebsOnSecurity. The report highlights failures in key management and incident response reporting channels.
IT / Technology 7 stories
Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
The jscrambler npm package was compromised โ version 8.14.0 carried a preinstall hook that drops and executes a Rust-based infostealer on Windows, macOS, and Linux. Socket Security flagged the malicious release six minutes after publication. The payload (7.8MB) contained three gzip-compressed native binaries targeting all three platforms.
Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found
A hidden browsing-history collector was discovered in the official ModHeader browser extension on both Chrome and Edge Web Stores (1.6M combined installs). The collector was dormant โ an empty allowlist kept it from activating โ but analysis confirmed it shipped inside the genuine signed extension, not a counterfeit. Microsoft pulled the listing July 3; Google followed July 10.
CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks
Researchers at Jamf Threat Labs detailed a new macOS information stealer called CrashStealer, written in native C++ and distributed via a signed, Apple-notarized dropper ("Werkbit.app"). It validates the victim's login password, harvests browser/crypto wallet/password manager/keychain data, encrypts with AES-GCM, and exfiltrates via libcurl.
URGENT โ Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat
Progress Software instructed ShareFile customers to shut down Windows servers running Storage Zone Controllers in response to a "credible external security threat." The company temporarily disabled affected accounts but has not disclosed the nature of the threat or the threat actor behind it.
iCagenda and Balbooa Forms Joomla Flaws Exploited as Zero-Days โ CISA Adds to KEV Catalog
CISA added two CVSS 10.0 vulnerabilities (CVE-2026-48939, CVE-2026-56291) in iCagenda and Balbooa Forms Joomla extensions to its Known Exploited Vulnerabilities catalog following reports of active zero-day exploitation since June 15, 2026. Both allow arbitrary file upload leading to remote code execution.
Forg365 PhaaS Targets Microsoft 365 With Device Code and AitM Session Theft
A new Phishing-as-a-Service operation, Forg365, combines device code phishing, adversary-in-the-middle tactics, AI-assisted lure creation and post-compromise mailbox operations targeting Microsoft 365. Distributed via Telegram at $400/month ($3,800/year), it uses legitimate email delivery infrastructure (Amazon SES, Twilio SendGrid) for phishing distribution.
Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions
Zimbra urged customers to patch a critical stored XSS vulnerability in its Classic Web Client that allows specially crafted emails to execute malicious scripts when opened, potentially leading to session hijacking, credential theft, and account compromise.
Legal / Regulatory 5 stories
VPN Service Favored by Ransomware Groups Sanctioned by US Treasury
The US Treasury Department sanctioned a VPN service known to be heavily used by ransomware groups for laundering and obfuscating criminal traffic. The action targets the financial infrastructure enabling ransomware operations.
European Commission Refers Ireland, Spain, France, and Netherlands to CJEU Over NIS2 Transposition Delays
The European Commission referred four member states โ Ireland, Spain, France, and the Netherlands โ to the Court of Justice of the European Union for failing to notify full transposition of the NIS2 Directive into national law, marking a major enforcement escalation on EU cyber resilience requirements.
European Commission Unveils Cybersecurity and AI Action Plan
On July 7, the European Commission presented an Action Plan on Cybersecurity and Artificial Intelligence aimed at supporting the safe and responsible use of AI while strengthening cyber resilience across the EU. The plan addresses the intersection of AI system security and broader cyber defence.
Europe Revives Law Allowing Big Tech to Scan for CSAM
EU lawmakers revived proposed legislation that would require big tech platforms to scan user communications for child sexual abuse material (CSAM), reigniting the encryption vs. child safety debate across the European digital landscape.
Ryuk Operator Pleads Guilty; BlackCat/AlphV Conspirator Gets Nearly 6-Year Sentence
A Ryuk ransomware operator pleaded guilty in US court, while a BlackCat/AlphV conspirator received a nearly six-year prison sentence. The parallel resolutions reflect ongoing law enforcement pressure on the ransomware ecosystem.
Financial Services 1 story
Cash App Owner to Pay $45 Million to Settle Allegations of Lax Security
The parent company of Cash App agreed to a $45 million settlement with regulators over allegations of inadequate security practices that exposed user financial data. The settlement underscores increasing regulatory scrutiny on fintech security postures.
Manufacturing 1 story
Latvian Forestry Company Still Restoring Systems Weeks After Ransomware Attack
A Latvian forestry company continues recovery efforts weeks after a ransomware attack crippled its operations. The protracted downtime illustrates the severe operational impact of ransomware on manufacturing and industrial enterprises.
Analytics
Source Reliability Index
| Tier | Label | Description |
|---|---|---|
| โ Tier 1 | Very High | Official / first-party |
| โ Tier 2 | High | Established cyber journalism |
| โ Tier 3 | Moderate | General tech/news media |
| โ Tier 4 | Low | Social / unverified |