Cyber Digest
A daily roundup of key cybersecurity developments across sectors
Executive Summary
This week's standout story: Microsoft's record-breaking Patch Tuesday โ Redmond patched 570 security holes (nearly triple last month's record), including three zero-days, with 60 critical-rated bugs and ~250 elevation-of-privilege flaws. Microsoft attributed the surge to AI-assisted vulnerability discovery, signaling a new normal for patch volumes. The wp2shell WordPress flaw dominated open-source security โ two chained vulnerabilities (CVE-2026-63030 REST API batch-route confusion + CVE-2026-60137 SQL injection) allow unauthenticated remote code execution on every WordPress 6.9 and 7.0 site. WordPress shipped emergency patches 6.9.5 and 7.0.2 on Friday, with forced auto-updates enabled. A working PoC is now public. Geopolitical cyber activity intensified โ CISA, ACSC, and international partners issued a joint advisory on Russian state-sponsored targeting of network devices, while Ukraine's Sandworm group was observed using CAPTCHA tricks to lure victims. In regulatory news, the EU ordered Google to open Android's camera, mic, and screen to rival AI assistants under the DMA, and Illinois became the third US state to enact comprehensive frontier AI safety legislation.
Incident Map
IT / Technology 4 stories
Microsoft Patches a Record 570 Security Flaws
Microsoft's July 2026 Patch Tuesday fixed 570 vulnerabilities โ almost triple the previous record from June. Nearly 60 were rated "critical," and three zero-days were addressed, two actively exploited. Approximately 250 of the bugs were elevation-of-privilege flaws. Executive VP Pavan Davuluri attributed the surge to AI-assisted discovery, warning users to expect higher volumes in every future release.
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
Two chained WordPress core vulnerabilities โ CVE-2026-63030 (REST API batch-route confusion) and CVE-2026-60137 (SQL injection) โ allow unauthenticated remote code execution on every 6.9 and 7.0 site. WordPress shipped emergency patches 6.9.5 and 7.0.2 with forced auto-updates. A working PoC is now public on GitHub.
New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
A Go-based botnet discovered by QiAnXin's XLab is scanning Shodan for exposed AI services (ComfyUI, Ollama, n8n, Open WebUI, Langflow, Gradio). The operator's dashboard claims 3,811 unique AWS keys harvested and 17,700 total deploys, with stolen credentials spanning DeepSeek, GLM, and Kimi model inventories.
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
Expel researchers attributed the April 2026 DigiCert security incident to CylindricalCanine, a subgroup of the Chinese cybercrime group GoldenEyeDog (APT-Q-27). The attackers used a modified Gh0st RAT to access a DigiCert support member's device and steal code-signing certificates intended for customers.
Defence 2 stories
Joint Advisory: Russian State-Sponsored Cyber Actors Target Network Devices
CISA, ACSC (ASD), and international partners released a joint advisory detailing persistent Russian state-sponsored targeting of routers, firewalls, and other network devices. The advisory โ mirrored on both CISA's site and cyber.gov.au โ provides observed TTPs and recommends router hygiene improvements. CISA's advisory (AA26-194A) specifically calls for improved router hygiene to protect against Russian targeting.
Sandworm Hackers Have a CAPTCHA Trick for Ukrainians
Russia's Sandworm APT group has been observed using a novel social engineering technique involving fake CAPTCHA verification pages targeting Ukrainian users. The CAPTCHA prompts trick victims into running malicious PowerShell commands, granting the attackers access to the system.
Legal / Regulatory 4 stories
EU Orders Google to Open Android Mic, Camera, and Screen to Rival AI Assistants
The European Commission adopted two binding specification decisions under the Digital Markets Act on July 16, ordering Google to give rival AI assistants the same system-level access to Android as Gemini โ including camera, microphone, screen content, wake-word activation, and the ability to drive other apps. Google must ship these changes in Android 18 by August 2027.
Illinois Governor Signs Frontier AI Model Law
On July 6, 2026, Governor JB Pritzker signed SB 315 (the Artificial Intelligence Safety Measures Act), making Illinois the third US state to enact comprehensive safety and transparency requirements for developers of advanced AI systems. The law imposes testing, reporting, and risk mitigation obligations on frontier AI model developers.
CISA Plans to Finalize Cyber Incident Reporting Regulations in September 2026
CISA continues to advance the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) rulemaking, with a final rule expected September 2026. The regulation will require critical infrastructure entities to report significant cyber incidents and ransomware payments within specified timeframes.
European Commission Refers Four Member States to CJEU Over NIS2 Transposition Delays
The European Commission referred Ireland, Spain, France, and the Netherlands to the Court of Justice of the European Union for failing to notify full transposition of the NIS2 Directive into national law. This marks the Commission's most significant enforcement action yet on NIS2 compliance deadlines.
Government 2 stories
Lessons Learned from CISA's Recent GitHub Leak
CISA published a postmortem on a data leak in which a contractor published 844 MB of sensitive internal data โ including AWS GovCloud keys and plaintext passwords for dozens of internal systems โ in a public GitHub repository for nearly six months. GitGuardian had sent nine automated alerts before KrebsOnSecurity notified CISA in May 2026. CISA acknowledged it took over 48 hours to rotate keys and outlined steps to improve reporting channels.
CISA Tells US Agencies to Fix Security Bugs in as Little as 3 Days Thanks to AI Threats
CISA has updated its Binding Operational Directive (BOD) requiring Federal Civilian Executive Branch agencies to patch critical vulnerabilities on accelerated timelines, with some bugs requiring remediation within 3 days. The faster cadence reflects the increased speed of AI-driven vulnerability discovery and exploitation.
Healthcare 3 stories
All About Women's Care Data Breach Affects Up to 12,000 Patients
All About Women's Care in Colorado notified approximately 12,000 patients that their protected health information was compromised in a data breach. The incident adds to the growing tally of healthcare sector breaches in July 2026.
Atrium Health Pays Up to $1.8M to Resolve Pixel Lawsuit
Charlotte-Mecklenburg Hospital Authority (Atrium Health) agreed to pay up to $1.8 million to settle a class action lawsuit over the use of tracking pixels on its patient portal. The case highlights continued legal exposure for healthcare providers using web analytics that may disclose protected health information to third parties.
May 2026 Healthcare Data Breach Report: 61 Breaches Reported
According to HHS OCR breach portal data, 61 healthcare data breaches were reported in May 2026, affecting hundreds of thousands of patient records. The report underscores the persistent threat to healthcare data security.
Financial Services 2 stories
Cash App Owner to Pay $45 Million to Settle Allegations of Lax Security
The owner of Cash App agreed to pay $45 million to settle allegations of inadequate security practices that led to customer data exposure. The settlement, covered in The Record's BRIEFS section, underscores regulatory scrutiny of fintech security practices.
23andMe Reaches $18 Million Settlement with States for Massive Breach
Genetic testing company 23andMe reached an $18 million settlement with multiple US states following a massive data breach that exposed sensitive genetic and personal data of millions of customers. The settlement addresses state-level consumer protection claims.
Manufacturing 1 story
Dairy Company Fairlife Suspends Production in US After Cyber Incident
Dairy company Fairlife suspended production at its US facilities following a cyber incident. The disruption affected supply chains, with the company working to restore operations. The incident highlights the vulnerability of food manufacturing to cyber attacks.
Energy & Utilities 1 story
A Guide to OT Security Best Practices
SANS Institute published a comprehensive guide to operational technology (OT) security best practices, covering network segmentation, remote access controls, patch management for ICS environments, and incident response planning for industrial control systems. The guide is relevant for the energy, utilities, and manufacturing sectors.
Media & Entertainment 2 stories
Madison Square Garden Kept a List of Gay Celebrities
An investigation by Wired revealed that Madison Square Garden maintained a private list tracking the sexual orientation of celebrities and high-profile attendees. The revelation raises significant privacy concerns and has prompted scrutiny of MSG's data collection practices.
Hackers Claim to Leak Stolen Madison Square Garden Data
Following the revelation of MSG's celebrity tracking list, hackers claimed to have leaked additional stolen data from Madison Square Garden. The incident adds a data breach dimension to the ongoing privacy controversy surrounding the venue operator.
General / Cross-Sector 3 stories
Scattered Spider Hackers Sentenced to 5.5 Years for ยฃ29 Million Transport for London Hack
Owen Flowers (18) and Thalha Jubair (20) were each sentenced to five and a half years at Woolwich Crown Court for the 2024 cyberattack on Transport for London. The attack left 148 systems inoperable, forced all 27,000 employees to reset passwords in person, and cost ยฃ29 million. They are believed to be the first hackers successfully prosecuted under Section 3ZA of the UK Computer Misuse Act.
FBI Seizes NetNut Proxy Platform, Popa Botnet
The FBI seized hundreds of domains associated with NetNut, a residential proxy service operated by Israeli company Alarum Technologies [NASDAQ: ALAR]. NetNut was linked to the Popa botnet (2 million devices) used for mass content scraping, ad fraud, and account takeover. Google's Threat Intelligence Group observed 316 threat actor clusters using NetNut exit nodes in a single week.
Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man
Armenia detained a Russian tourist named Aleksandr Ermakov at Yerevan airport on a US extradition request for a REvil ransomware suspect. However, his lawyers claim the man in custody is a different Aleksandr Ermakov โ a former prisoner from Omsk โ while the actual REvil affiliate is under a separate Russian sentence. The case highlights the risks of name-based extradition requests.
Analytics
Source Reliability Index
| Tier | Label | Description |
|---|---|---|
| โ Tier 1 | Very High | Official / first-party |
| โ Tier 2 | High | Established cyber journalism |
| โ Tier 3 | Moderate | General tech/news media |
| โ Tier 4 | Low | Social / unverified |