// daily digest ยท 2026-07-18
Saturday·18 July 2026

Cyber Digest

A daily roundup of key cybersecurity developments across sectors

24 stories10 sectors8 sourcesGlobal focus

Executive Summary

This week's standout story: Microsoft's record-breaking Patch Tuesday โ€” Redmond patched 570 security holes (nearly triple last month's record), including three zero-days, with 60 critical-rated bugs and ~250 elevation-of-privilege flaws. Microsoft attributed the surge to AI-assisted vulnerability discovery, signaling a new normal for patch volumes. The wp2shell WordPress flaw dominated open-source security โ€” two chained vulnerabilities (CVE-2026-63030 REST API batch-route confusion + CVE-2026-60137 SQL injection) allow unauthenticated remote code execution on every WordPress 6.9 and 7.0 site. WordPress shipped emergency patches 6.9.5 and 7.0.2 on Friday, with forced auto-updates enabled. A working PoC is now public. Geopolitical cyber activity intensified โ€” CISA, ACSC, and international partners issued a joint advisory on Russian state-sponsored targeting of network devices, while Ukraine's Sandworm group was observed using CAPTCHA tricks to lure victims. In regulatory news, the EU ordered Google to open Android's camera, mic, and screen to rival AI assistants under the DMA, and Illinois became the third US state to enact comprehensive frontier AI safety legislation.

4
IT / Technology
2
Defence
4
Legal / Regulatory
2
Government
3
Healthcare

Incident Map

(static view)
CriticalSevereElevatedGuardeddarker = more incidents
United States
8
Russia
2
Australia
1
China
1
France
1
United Kingdom
1

Pan-regional / not map-pinned: ๐ŸŒ Global: 9๐Ÿ‡ช๐Ÿ‡บ Europe: 1

6 countries ยท 24 stories ยท click a country for its stories. Interactive map loads on the hosted site.

๐ŸŽฏ Geo-attribution: 10/24 stories located directly from text (42%). Low-confidence (region-bucket only, check): United States.

๐ŸŽฏ Geo-attribution: 10/24 stories located directly from text (42%). Low-confidence (region-bucket only, check): United States.

IT / Technology 4 stories

1

Microsoft Patches a Record 570 Security Flaws

Microsoft's July 2026 Patch Tuesday fixed 570 vulnerabilities โ€” almost triple the previous record from June. Nearly 60 were rated "critical," and three zero-days were addressed, two actively exploited. Approximately 250 of the bugs were elevation-of-privilege flaws. Executive VP Pavan Davuluri attributed the surge to AI-assisted discovery, warning users to expect higher volumes in every future release.

Krebs on Securityโ— Tier 2/4 โ€” High2026-07-14
2

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

Two chained WordPress core vulnerabilities โ€” CVE-2026-63030 (REST API batch-route confusion) and CVE-2026-60137 (SQL injection) โ€” allow unauthenticated remote code execution on every 6.9 and 7.0 site. WordPress shipped emergency patches 6.9.5 and 7.0.2 with forced auto-updates. A working PoC is now public on GitHub.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-18
3

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

A Go-based botnet discovered by QiAnXin's XLab is scanning Shodan for exposed AI services (ComfyUI, Ollama, n8n, Open WebUI, Langflow, Gradio). The operator's dashboard claims 3,811 unique AWS keys harvested and 17,700 total deploys, with stolen credentials spanning DeepSeek, GLM, and Kimi model inventories.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-17
4

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft

Expel researchers attributed the April 2026 DigiCert security incident to CylindricalCanine, a subgroup of the Chinese cybercrime group GoldenEyeDog (APT-Q-27). The attackers used a modified Gh0st RAT to access a DigiCert support member's device and steal code-signing certificates intended for customers.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-17

Defence 2 stories

1

Joint Advisory: Russian State-Sponsored Cyber Actors Target Network Devices

CISA, ACSC (ASD), and international partners released a joint advisory detailing persistent Russian state-sponsored targeting of routers, firewalls, and other network devices. The advisory โ€” mirrored on both CISA's site and cyber.gov.au โ€” provides observed TTPs and recommends router hygiene improvements. CISA's advisory (AA26-194A) specifically calls for improved router hygiene to protect against Russian targeting.

CISAโ— Tier 1/4 โ€” Very High2026-07-14
2

Sandworm Hackers Have a CAPTCHA Trick for Ukrainians

Russia's Sandworm APT group has been observed using a novel social engineering technique involving fake CAPTCHA verification pages targeting Ukrainian users. The CAPTCHA prompts trick victims into running malicious PowerShell commands, granting the attackers access to the system.

The Record by Recorded Futureโ— Tier 2/4 โ€” High2026-07-16

Government 2 stories

1

Lessons Learned from CISA's Recent GitHub Leak

CISA published a postmortem on a data leak in which a contractor published 844 MB of sensitive internal data โ€” including AWS GovCloud keys and plaintext passwords for dozens of internal systems โ€” in a public GitHub repository for nearly six months. GitGuardian had sent nine automated alerts before KrebsOnSecurity notified CISA in May 2026. CISA acknowledged it took over 48 hours to rotate keys and outlined steps to improve reporting channels.

Krebs on Securityโ— Tier 2/4 โ€” High2026-07-13
2

CISA Tells US Agencies to Fix Security Bugs in as Little as 3 Days Thanks to AI Threats

CISA has updated its Binding Operational Directive (BOD) requiring Federal Civilian Executive Branch agencies to patch critical vulnerabilities on accelerated timelines, with some bugs requiring remediation within 3 days. The faster cadence reflects the increased speed of AI-driven vulnerability discovery and exploitation.

Wiredโ— Tier 3/4 โ€” Moderate2026-07-18

Healthcare 3 stories

1

All About Women's Care Data Breach Affects Up to 12,000 Patients

All About Women's Care in Colorado notified approximately 12,000 patients that their protected health information was compromised in a data breach. The incident adds to the growing tally of healthcare sector breaches in July 2026.

HIPAA Journalโ— Tier 2/4 โ€” High2026-07-17
2

Atrium Health Pays Up to $1.8M to Resolve Pixel Lawsuit

Charlotte-Mecklenburg Hospital Authority (Atrium Health) agreed to pay up to $1.8 million to settle a class action lawsuit over the use of tracking pixels on its patient portal. The case highlights continued legal exposure for healthcare providers using web analytics that may disclose protected health information to third parties.

HIPAA Journalโ— Tier 2/4 โ€” High2026-07-17
3

May 2026 Healthcare Data Breach Report: 61 Breaches Reported

According to HHS OCR breach portal data, 61 healthcare data breaches were reported in May 2026, affecting hundreds of thousands of patient records. The report underscores the persistent threat to healthcare data security.

HIPAA Journalโ— Tier 2/4 โ€” High2026-07-14

Financial Services 2 stories

1

Cash App Owner to Pay $45 Million to Settle Allegations of Lax Security

The owner of Cash App agreed to pay $45 million to settle allegations of inadequate security practices that led to customer data exposure. The settlement, covered in The Record's BRIEFS section, underscores regulatory scrutiny of fintech security practices.

The Record by Recorded Futureโ— Tier 2/4 โ€” High2026-07-09
2

23andMe Reaches $18 Million Settlement with States for Massive Breach

Genetic testing company 23andMe reached an $18 million settlement with multiple US states following a massive data breach that exposed sensitive genetic and personal data of millions of customers. The settlement addresses state-level consumer protection claims.

The Record by Recorded Futureโ— Tier 2/4 โ€” High2026-07-16

Manufacturing 1 story

1

Dairy Company Fairlife Suspends Production in US After Cyber Incident

Dairy company Fairlife suspended production at its US facilities following a cyber incident. The disruption affected supply chains, with the company working to restore operations. The incident highlights the vulnerability of food manufacturing to cyber attacks.

The Record by Recorded Futureโ— Tier 2/4 โ€” High2026-07-17

Energy & Utilities 1 story

1

A Guide to OT Security Best Practices

SANS Institute published a comprehensive guide to operational technology (OT) security best practices, covering network segmentation, remote access controls, patch management for ICS environments, and incident response planning for industrial control systems. The guide is relevant for the energy, utilities, and manufacturing sectors.

SANS Institute Blogโ— Tier 2/4 โ€” High2026-07-13

Media & Entertainment 2 stories

1

Madison Square Garden Kept a List of Gay Celebrities

An investigation by Wired revealed that Madison Square Garden maintained a private list tracking the sexual orientation of celebrities and high-profile attendees. The revelation raises significant privacy concerns and has prompted scrutiny of MSG's data collection practices.

Wiredโ— Tier 3/4 โ€” Moderate2026-07-18
2

Hackers Claim to Leak Stolen Madison Square Garden Data

Following the revelation of MSG's celebrity tracking list, hackers claimed to have leaked additional stolen data from Madison Square Garden. The incident adds a data breach dimension to the ongoing privacy controversy surrounding the venue operator.

Wiredโ— Tier 3/4 โ€” Moderate2026-07-18

General / Cross-Sector 3 stories

1

Scattered Spider Hackers Sentenced to 5.5 Years for ยฃ29 Million Transport for London Hack

Owen Flowers (18) and Thalha Jubair (20) were each sentenced to five and a half years at Woolwich Crown Court for the 2024 cyberattack on Transport for London. The attack left 148 systems inoperable, forced all 27,000 employees to reset passwords in person, and cost ยฃ29 million. They are believed to be the first hackers successfully prosecuted under Section 3ZA of the UK Computer Misuse Act.

The Record by Recorded Futureโ— Tier 2/4 โ€” High2026-07-16
2

FBI Seizes NetNut Proxy Platform, Popa Botnet

The FBI seized hundreds of domains associated with NetNut, a residential proxy service operated by Israeli company Alarum Technologies [NASDAQ: ALAR]. NetNut was linked to the Popa botnet (2 million devices) used for mass content scraping, ad fraud, and account takeover. Google's Threat Intelligence Group observed 316 threat actor clusters using NetNut exit nodes in a single week.

Krebs on Securityโ— Tier 2/4 โ€” High2026-07-02
3

Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man

Armenia detained a Russian tourist named Aleksandr Ermakov at Yerevan airport on a US extradition request for a REvil ransomware suspect. However, his lawyers claim the man in custody is a different Aleksandr Ermakov โ€” a former prisoner from Omsk โ€” while the actual REvil affiliate is under a separate Russian sentence. The case highlights the risks of name-based extradition requests.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-17

Analytics

Sector distribution

IT / Technology
4
Defence
2
Legal / Regulatory
4
Government
2
Healthcare
3
Financial Services
2
Manufacturing
1
Energy & Utilities
1
Media & Entertainment
2
General / Cross-Sector
3

Source breakdown

The Hacker News
5
The Record by Recorded Future
5
Krebs on Security
3
Hunton Andrews Kurth Privacy & Cybersecurity Law Blog
3
Wired
3
HIPAA Journal
3
CISA
1
SANS Institute Blog
1
24stories
IT / Technology 4
Defence 2
Legal / Regulatory 4
Government 2
Healthcare 3
Financial Services 2
Manufacturing 1
Energy & Utilities 1
Media & Entertainment 2
General / Cross-Sector 3

Source Reliability Index

TierLabelDescription
โ— Tier 1Very HighOfficial / first-party
โ— Tier 2HighEstablished cyber journalism
โ— Tier 3ModerateGeneral tech/news media
โ— Tier 4LowSocial / unverified