// daily digest ยท 2026-07-26
Sunday·26 July 2026

Cyber Digest

A daily roundup of key cybersecurity developments across sectors

35 stories9 sectors5 sourcesGlobal focus

Executive Summary

This weekend's cybersecurity landscape was dominated by a coordinated international advisory on Russian state-sponsored phishing targeting Zimbra webmail users, a critical unpatched RCE in Alibaba's Fastjson library (CVSS 9.0), and a 9.8-rated Bing Images vulnerability exposed by XBOW researchers. Healthcare saw the massive DentaQuest breach notification (15M+ individuals) and a report highlighting a surge in malicious insider incidents. Cl0p affiliates launched a new data extortion campaign against manufacturers using PTC Windchill/FlexPLM (CVE-2026-12569, CVSS 9.3). On the regulatory front, Connecticut AG led a 42-state settlement with 23andMe over its 2023 breach, CalPrivacy launched its first CCPA compliance audit targeting gig economy platforms, and the US State Department imposed visa restrictions on foreign cyber scammers. An Australian major energy supplier confirmed a customer data breach, and federal agencies broadened their advisory on Iran-linked OT attacks.

7
Government & Policy
5
Geopolitical & State-Sponsored Activity
2
Manufacturing & Critical Infrastructure
1
Energy & Utilities
5
Healthcare

Incident Map

(static view)
CriticalSevereElevatedGuardeddarker = more incidents
United States
7
Dem. Rep. Korea
2
United Kingdom
1
Thailand
1
Spain
1
France
1
Iran
1
Switzerland
1
Australia
1
Japan
1

Pan-regional / not map-pinned: ๐ŸŒ Global: 18

10 countries ยท 35 stories ยท click a country for its stories. Interactive map loads on the hosted site.

๐ŸŽฏ Geo-attribution: 14/35 stories located directly from text (40%). Low-confidence (region-bucket only, check): United States.

๐ŸŽฏ Geo-attribution: 14/35 stories located directly from text (40%). Low-confidence (region-bucket only, check): United States.

Government & Policy 7 stories

1

US State Department Imposes Visa Restrictions on Foreign Cyber Scammers

Secretary of State Marco Rubio announced visa restrictions targeting individuals involved in cyber scams, expanding the US government's toolkit for deterring transnational cybercrime.

The Recordโ— Tier 2/4 โ€” Established cyber journalism2026-07-24
2

Extension of CISA 2015 Info-Sharing Protections Passes as Part of House Defence Bill

The US House of Representatives passed an extension of CISA's 2015 information-sharing liability protections as part of the defence authorisation bill, ensuring continued legal safe harbour for cyber threat intelligence sharing.

The Recordโ— Tier 2/4 โ€” Established cyber journalism2026-07-23
3

Connecticut AG Leads 42-State Settlement With 23andMe Over 2023 Data Breach

A coalition of 42 state attorneys general reached a settlement with 23andMe's bankruptcy trustee, resolving claims from the company's 2023 data breach that exposed genetic and personal data of millions of customers.

Hunton Privacy & Cybersecurity Law Blogโ— Tier 1/4 โ€” Official / first-party (law firm)2026-07-23
4

CalPrivacy Targets Gig Economy Tech Platforms in First CCPA Compliance Audit

The California Privacy Protection Agency launched its first formal CCPA compliance audit, targeting gig economy tech platforms operating in California.

Hunton Privacy & Cybersecurity Law Blogโ— Tier 1/4 โ€” Official / first-party2026-07-22
5

UK Signals Continuity on Cyber Policy โ€” Minister Reappointed Despite Ministry Scrapping

Mayor Andy Burnham signalled continuity on UK cyber policy, reappointing the cyber minister despite the government's decision to scrap the dedicated ministry.

The Recordโ— Tier 2/4 โ€” Established cyber journalism2026-07-23
6

CISA Plans to Finalise Cyber Incident Reporting Regulations in September 2026

CISA continues working toward finalising regulations implementing the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) of 2022, with a final rule now expected in September 2026.

Hunton Privacy & Cybersecurity Law Blogโ— Tier 1/4 โ€” Official / first-party2026-07-17
7

French Parliament Greenlights Social Media Ban for Under-15s

France's National Assembly passed legislation banning social media access for children under 15, one of Europe's most restrictive digital age laws.

The Recordโ— Tier 2/4 โ€” Established cyber journalism2026-07-23

Geopolitical & State-Sponsored Activity 5 stories

1

CISA/FBI Joint Advisory: Russian State-Sponsored Zimbra Phishing Campaign (AA26-204A)

CISA and international partners released a joint cybersecurity advisory detailing a Russian state-sponsored phishing campaign targeting users of the Zimbra Collaboration Suite. The advisory provides IOCs, TTPs, and mitigation guidance for organisations using Zimbra.

CISAโ— Tier 1/4 โ€” Official / first-party2026-07-25
2

CISA Advisory: Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting (AA26-194A)

CISA released guidance on improving router security hygiene to defend against Russian state-sponsored targeting of network infrastructure devices.

CISAโ— Tier 1/4 โ€” Official / first-party2026-07-23
3

BlueNoroff (North Korea) Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

North Korean threat actor BlueNoroff has operationalised a sophisticated phishing platform that profiles victims' cryptocurrency wallets before delivering malware, enabling selective targeting of high-value victims via typosquatted Zoom and Microsoft Teams domains.

The Hacker Newsโ— Tier 2/4 โ€” Established cyber journalism2026-07-24
4

Federal Agencies Broaden Alert on Iran-Linked OT Attacks

US federal agencies issued a broadened alert on Iran-linked attacks targeting operational technology (OT) environments, expanding previous guidance on ICS/SCADA threats.

The Recordโ— Tier 2/4 โ€” Established cyber journalism2026-07-23
5

New Kimsuky Campaign Compromises South Korean Software Vendors

The North Korean Kimsuky group conducted a new campaign compromising South Korean software vendors as part of ongoing espionage operations.

The Recordโ— Tier 2/4 โ€” Established cyber journalism2026-07-23

Manufacturing & Critical Infrastructure 2 stories

1

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM With Unauthenticated RCE (CVE-2026-12569)

Threat actors linked to the Cl0p ransomware campaign are exploiting internet-exposed PTC Windchill and FlexPLM deployments using CVE-2026-12569 (CVSS 9.3), chaining an information disclosure with a server-side flaw for unauthenticated RCE and JSP web shell deployment. Targets include manufacturing, automotive, aerospace, and retail sectors.

The Hacker Newsโ— Tier 2/4 โ€” Established cyber journalism2026-07-25
2

Swiss Train Maker Stadler Refuses Everest $12 Million Ransomware Demand

Swiss rolling stock manufacturer Stadler Rail refused to pay a $12 million ransom demand from the Everest ransomware group following a cyberattack, choosing to restore systems from backups instead.

The Recordโ— Tier 2/4 โ€” Established cyber journalism2026-07-23

Energy & Utilities 1 story

1

Major Australian Energy Supplier Confirms Customer Data Compromised

A major Australian electricity infrastructure provider confirmed that customer data was compromised in a cybersecurity incident, underscoring ongoing threats to critical energy infrastructure in the region.

The Recordโ— Tier 2/4 โ€” Established cyber journalism2026-07-23

Healthcare 5 stories

1

DentaQuest Starts Notifying 15 Million+ Individuals About May 2026 Cyber Incident

Dental benefits administrator DentaQuest began issuing notification letters to over 15 million individuals affected by a May 2026 cybersecurity incident โ€” one of the largest healthcare data breaches of the year.

HIPAA Journalโ— Tier 2/4 โ€” Established cyber journalism2026-07-23
2

Tennessee Pathology Group Announces 170K-Record Data Breach

Anatomic and Clinical Laboratory Associates (ACLA) notified almost 170,000 patients about a cybersecurity incident that exposed protected health information.

HIPAA Journalโ— Tier 2/4 โ€” Established cyber journalism2026-07-24
3

Report Shows Surge in Malicious Insider Incidents and Mega Data Breaches

A new report highlights a general trend of increasing data breaches, with this year on track to set records for malicious insider incidents and mega breaches (1M+ records).

HIPAA Journalโ— Tier 2/4 โ€” Established cyber journalism2026-07-23
4

Heart Care Centers of Illinois Discovers Historic Phishing Attack Exposed Patient Data

Cardiovascular medical practice Heart Care Centers of Illinois announced that a historic phishing attack exposed certain patients' protected health information.

HIPAA Journalโ— Tier 2/4 โ€” Established cyber journalism2026-07-23
5

Colorado Behavioral Healthcare Provider Discovers Insider Data Breach

A Colorado behavioural healthcare provider discovered an insider data breach, with patient data accessed by an employee without authorisation.

HIPAA Journalโ— Tier 2/4 โ€” Established cyber journalism2026-07-23

Technology & Vulnerabilities 7 stories

1

Fastjson 1.x RCE Vulnerability Under Active Attack โ€” No Patch Available (CVE-2026-16723, CVSS 9.0)

A critical unauthenticated RCE vulnerability in Alibaba's Fastjson 1.x Java JSON library (CVE-2026-16723, CVSS 9.0) is being actively targeted. No fixed version for the 1.x branch has been released. Mitigations include enabling SafeMode or migrating to Fastjson2.

The Hacker Newsโ— Tier 2/4 โ€” Established cyber journalism2026-07-25
2

Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers (CVE-2026-32194/32191, CVSS 9.8)

XBOW researchers demonstrated that crafted SVG images submitted to Bing Image Search could execute commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers. Both CVEs rated 9.8, fixed server-side by Microsoft.

The Hacker Newsโ— Tier 2/4 โ€” Established cyber journalism2026-07-24
3

GitLab RCE PoC Published โ€” Authenticated Users Can Run Commands as Git

Security researchers published exploit code for a GitLab flaw allowing any authenticated user who can push to a project to execute commands as the git user. GitLab patched it in June but did not classify it as a security fix โ€” no CVE was assigned.

The Hacker Newsโ— Tier 2/4 โ€” Established cyber journalism2026-07-25
4

Certighost Exploit: Low-Privileged AD Users Can Impersonate a Domain Controller (CVE-2026-54121, CVSS 8.8)

Researchers published exploit code for an AD CS flaw (CVE-2026-54121) that lets low-privileged Active Directory users obtain a certificate for a Domain Controller and perform DCSync attacks. Patched by Microsoft ten days prior.

The Hacker Newsโ— Tier 2/4 โ€” Established cyber journalism2026-07-24
5

ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Single Phishing Link

Zenity Labs disclosed a CSRF vulnerability in OpenAI's ChatGPT Workspace Agents (dubbed AgentForger) that could allow a single phishing link to stealthily build and deploy an attacker-controlled AI agent inside a victim's organisation. Patched by OpenAI as of June 8.

The Hacker Newsโ— Tier 2/4 โ€” Established cyber journalism2026-07-24
6

SourTrade Malvertising: Browser Builds Windows Executable Using Bun Runtime

A malvertising campaign dubbed SourTrade makes victims' browsers build the final Windows executable themselves using a legitimate Bun runtime. The campaign has operated since late 2024, impersonating TradingView, Solana, and Luno.

The Hacker Newsโ— Tier 2/4 โ€” Established cyber journalism2026-07-25
7

NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats

Aikido Security's AI penetration testing agents found eight high-severity flaws in NodeBB forum software in a six-hour code review. All versions before 4.14.0 affected; fixed in 4.14.2.

The Hacker Newsโ— Tier 2/4 โ€” Established cyber journalism2026-07-24

Cybercrime & Ransomware 5 stories

1

DevMan RaaS Portal Centralises Payload Builds, Victim Management, and Affiliate Payouts

PRODAFT is tracking a centrally administered RaaS operation (Funky Mantis) with a dedicated web platform offering affiliates build generation, finance, victim chat, support, and payout functions โ€” representing an industrialisation of the ransomware service model.

The Hacker Newsโ— Tier 2/4 โ€” Established cyber journalism2026-07-25
2

Insurance Phishing Evolves Into Real-Time Account Hijacking

CTM360 research reveals a shift in insurance-focused phishing: instead of harvesting credentials for later use, attackers now synchronise activity in real time, authenticating against legitimate insurance portals as victims complete the login process within a single session.

The Hacker Newsโ— Tier 2/4 โ€” Established cyber journalism2026-07-25
3

Golden Chickens Resurfaces With Four New Malware Families

The Golden Chickens MaaS ecosystem has resurfaced with four new malware families (TinyEgg, ChonkyChicken, modular ChonkyChicken, ChromEggscalator), deployed via ClickFix social engineering campaigns.

The Hacker Newsโ— Tier 2/4 โ€” Established cyber journalism2026-07-24
4

Hermes AI Agent Used Unattended for Post-Exploitation at Thailand's Ministry of Finance

An operator deployed the open-source Hermes AI agent in YOLO mode against Thailand's Ministry of Finance infrastructure. The agent autonomously enumerated hosts, hunted for root access, and crawled personnel records. Hunt.io and Bob Diachenko discovered the exposed logs with 585 files and 470 MB of attack tooling.

The Hacker Newsโ— Tier 2/4 โ€” Established cyber journalism2026-07-24
5

'Wrench' Attacks Against Crypto Holders Appear to Be on the Rise

Physical coercion attacks ("wrench attacks") targeting cryptocurrency holders are reportedly increasing, where attackers use physical force or threats to compel victims to transfer digital assets.

The Recordโ— Tier 2/4 โ€” Established cyber journalism2026-07-26

Transportation & Logistics 1 story

1

Japanese Food Logistics Giant Nichirei Recovers as Extortion Group Claims Cyberattack

Japanese food logistics company Nichirei recovered from a cyberattack as an extortion group claimed responsibility. The incident disrupted cold-chain logistics operations.

The Recordโ— Tier 2/4 โ€” Established cyber journalism2026-07-23

Analytics

Sector distribution

Government & Policy
7
Geopolitical & State-Sponsored Activity
5
Manufacturing & Critical Infrastructure
2
Energy & Utilities
1
Healthcare
5
Technology & Vulnerabilities
7
Cybercrime & Ransomware
5
Transportation & Logistics
1
Legal & Regulatory
2

Source breakdown

The Hacker News
13
The Record
11
HIPAA Journal
5
Hunton Privacy & Cybersecurity Law Blog
4
CISA
2
35stories
Government & Policy 7
Geopolitical & State-Sponsored Activity 5
Manufacturing & Critical Infrastructure 2
Energy & Utilities 1
Healthcare 5
Technology & Vulnerabilities 7
Cybercrime & Ransomware 5
Transportation & Logistics 1
Legal & Regulatory 2

Source Reliability Index

TierLabelDescription
โ— Tier 1Very HighOfficial / first-party
โ— Tier 2HighEstablished cyber journalism
โ— Tier 3ModerateGeneral tech/news media
โ— Tier 4LowSocial / unverified