Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 19:19 27/07/2026 UTC
Last updated: 04:34 27/07/2026 UTC

Latest updates

Browse →

Apple App Store Sparrow Wallet impersonation campaign

Campaign

Updated: 27.07.2026 20:29 · First: 27.07.2026 20:29 · 📰 1 src / 1 articles · H score: 26

A repeated App Store impersonation campaign is driving Bitcoin theft by luring cryptocurrency users into entering seed phrases into a fraudulent Sparrow Wallet app. The operation matters because it reached three plaintiffs and is tied to losses of about $1.8 million in Bitcoin.

Fairlife hit by ransomware attack

Incident

Updated: 17.07.2026 00:09 · First: 17.07.2026 00:09 · 📰 1 src / 3 articles · H score: 25

Fairlife, the Coca-Cola dairy subsidiary, is dealing with a ransomware incident that disrupted U.S. production after the company detected unauthorized access to production-related systems on July 16 and activated incident response and business continuity plans. The company said product quality and safety were not affected and that Canadian production continued normally. On July 21, the Anubis ransomware gang added Fairlife to its leak site, claimed responsibility, alleged it stole approximately 1 TB of data, and said it had encrypted Nutanix systems. Those claims have not been independently verified.

Ernst & Young hit by network compromise linked to ShinyHunters

Incident

Updated: 27.07.2026 18:12 · First: 27.07.2026 18:12 · 📰 1 src / 1 articles · H score: 35

The Ernst & Young breach involved unauthorized access to a third-party support ticket system and the download of multiple documents, creating exposure risk for client tax data. EY said the attacker entered the platform between March 28 and April 12 and the activity was detected on April 23. The stolen files may contain personal and financial information used for tax filings, and EY says it removed the unauthorized access and notified federal law enforcement. A group calling itself ShinyHunters later claimed responsibility and threatened to publish the data.

VBulletin template engine unauthenticated RCE (CVE-2026-61511)

Vulnerability

Updated: 27.07.2026 17:40 · First: 27.07.2026 17:40 · 📰 1 src / 1 articles · H score: 29

Public exploit details for CVE-2026-61511 exposed a pre-authentication RCE in vBulletin's template engine, putting unpatched self-hosted forums at risk of code execution. The flaw affects vBulletin 6.2.1 and earlier and 6.1.6 and earlier, while 6.2.2 and branch-specific patches were released before disclosure. Cloud sites had already been patched, and no in-the-wild exploitation was confirmed at publication time.

VBulletin 6.2.2 security patch release for template-engine flaw

Security Patch Release

Updated: 27.07.2026 17:40 · First: 27.07.2026 17:40 · 📰 1 src / 1 articles · H score: 32

vBulletin released security patches for 6.2.1, 6.2.0, and 6.1.6 and shipped 6.2.2 as the fixed build, closing a template-engine remote code execution flaw on self-hosted forum servers. The update mattered because the affected branches could be reached without authentication until administrators applied the patch or upgraded. Cloud sites were already patched before public exploit details emerged on July 27.

Operation BlueDash Microsoft Teams phishing campaign delivering Level RMM and ScreenConnect

Campaign

Updated: 27.07.2026 15:37 · First: 27.07.2026 15:37 · 📰 1 src / 1 articles · H score: 45

The Operation BlueDash phishing campaign is using a fake Microsoft Teams update flow to install Level RMM and ConnectWise ScreenConnect, creating persistent remote-access risk on compromised hosts. The campaign uses compromised web infrastructure, a counterfeit Microsoft Store page at teamvem[.]com, and a loader named supportdev.exe to deploy the tools. Analysts tied the activity with moderate-to-high confidence to a Nigeria-based threat-actor group and found evidence that it has been active since at least February 2026. Related infrastructure also shows a Zoom lure and other remote-management payloads, indicating a multi-brand access operation designed to survive tool removal.

SourTrade malvertising campaign targeting retail traders and crypto investors

Campaign

Updated: 25.07.2026 18:21 · First: 25.07.2026 18:21 · 📰 3 src / 3 articles · H score: 30

The SourTrade malvertising campaign targets retail traders and cryptocurrency investors by impersonating TradingView, Solana, and Luno. It operates across 12 countries and 25 languages, with activity reported since late 2024 and concentration in Asia Pacific and Latin America. The campaign’s delivery chain assembles malware locally in the browser to reduce detection, using ServiceWorker and SharedWorker logic to build a unique payload. Earlier reporting also shows an older StreamSaver.js-based download path, indicating an evolving delivery chain that still ends in a Windows executable.

Cruciferra crypter service's underground operating model

Threat Actor Meta

Updated: 27.07.2026 13:51 · First: 27.07.2026 13:51 · 📰 1 src / 1 articles · H score: 29

Researchers observed Cruciferra operating as a paid crypter service used by multiple unrelated threat clusters, expanding the underground malware-delivery ecosystem and improving payload survival. The service was advertised for $450 to $2,000 a month and used to distribute RATs and information stealers. Its layered evasion features, including BYOVD-based EDR tampering and Process Ghosting, make malware harder to detect and analyze. The result is a more scalable concealment layer for opportunistic cybercrime.

TA4922 Operation DragonReturn tax-themed phishing campaign

Campaign

Updated: 27.07.2026 13:51 · First: 27.07.2026 13:51 · 📰 1 src / 1 articles · H score: 32

A TA4922 phishing campaign has used tax-themed lures and attacker-controlled landing pages to deliver malware to Indian taxpayers and related finance personnel. The operation, tracked as Operation DragonReturn, spans four identified campaigns between April and early June 2026 and shows a sustained delivery pattern.

TELESHIM, MIXEDKEY, and BINDCLOAK malware activity targeting Middle East government entities

Malware Activity

Updated: 27.07.2026 11:48 · First: 27.07.2026 11:48 · 📰 1 src / 1 articles · H score: 22

A new malware operation against government entities in the Middle East deployed the previously unreported families TELESHIM, MIXEDKEY, and BINDCLOAK, expanding the reach of a multi-stage intrusion chain. TELESHIM used the Telegram API for C2 and blended into legitimate traffic, while ISO-based DLL sideloading delivered the payloads. MIXEDKEY functioned as a reflective loader and BINDCLOAK served as the final 64-bit C2 implant contacting cert.hypersnet[.]com. Post-compromise activity was observed between July 7, 2026 and July 9, 2026, including reconnaissance and delivery of next-stage payloads.

East Asia-linked campaign targeting Middle East government entities

Campaign

Updated: 27.07.2026 11:48 · First: 27.07.2026 11:48 · 📰 1 src / 1 articles · H score: 32

A multi-stage campaign linked to East Asia is targeting government entities in the Middle East, using malware deployment and trusted-platform abuse to maintain access. The operation matters because it combines TELESHIM, MIXEDKEY, and BINDCLOAK with Telegram API command-and-control and obfuscation to blend into normal traffic. Activity was observed July 7-9, 2026, with post-compromise reconnaissance and payload delivery recorded on infected systems.

GitHub Dependabot adds a 3-day cooldown for version updates

Security Tool/Service

Updated: 27.07.2026 11:01 · First: 27.07.2026 11:01 · 📰 1 src / 1 articles · H score: 11

GitHub Dependabot now waits at least three days after a release before opening a pull request, reducing the chance that a poisoned package version is quickly adopted into downstream builds. Security updates still flow immediately, so the control narrows exposure without slowing urgent patch adoption. The change adds a time-based safeguard against fast-moving supply chain attacks while preserving normal dependency maintenance.

MCBS (Medical Computer Business Services) hit by ransomware attack

Incident

Updated: 27.07.2026 07:51 · First: 27.07.2026 07:51 · 📰 1 src / 1 articles · H score: 69

MCBS disclosed a data breach after attackers accessed its systems from September 22 to September 26, 2025, putting 1,261,464 people at risk of stolen personal, health insurance, and medical information. The company’s notification also says seven healthcare organizations were named as compromised in the cyberattack. The breach has been linked to a PEAR ransomware claim that says more than 3 TB of files were taken and later posted for download.

MCBS data leak claimed by PEAR ransomware group

Data Leak

Updated: 27.07.2026 07:51 · First: 27.07.2026 07:51 · 📰 1 src / 1 articles · H score: 71

A PEAR ransomware group leak made allegedly stolen MCBS files available for download, exposing personal, financial, HR, patient, payment, and email data. The leak is tied to an intrusion window of September 22-26, 2025 and affects 1,261,464 individuals. The publicly accessible dump raises the risk of identity theft, fraud, and secondary abuse of healthcare and business records.

GitHub Dependabot and PyPI add time-based supply-chain defenses

Security Tool/Service

Updated: 26.07.2026 17:13 · First: 26.07.2026 17:13 · 📰 2 src / 2 articles · H score: 11

GitHub Dependabot and PyPI added time-based controls that slow malicious package adoption and restrict late release tampering across the software supply chain. Dependabot now defaults to a 72-hour cooldown, while PyPI rejects new files for releases older than 14 days. The changes are meant to reduce exposure to newly published malicious packages and release poisoning. The rollout tightens package trust windows after a run of supply-chain attacks across both ecosystems.

XMRig cryptominer delivered via Steam ClickFix PowerShell

Malware Activity

Updated: 26.07.2026 01:37 · First: 26.07.2026 01:37 · 📰 1 src / 1 articles · H score: 21

A ClickFix lure on Steam discussion forums now turns fake troubleshooting replies into XMRig infections on Windows computers. Victims are told to run an administrator PowerShell command, and the command quietly downloads the miner from msfconfig[.]icu and launches it locally. The payload also creates a Microsoft Defender exclusion and sets up startup persistence, increasing the chance the miner stays active.

Steam discussion forums ClickFix campaign deploying XMRig miners

Campaign

Updated: 26.07.2026 01:37 · First: 26.07.2026 01:37 · 📰 1 src / 1 articles · H score: 34

An ongoing ClickFix campaign on Steam discussion forums is tricking users into running PowerShell commands that install XMRig cryptominers. The operation abuses help threads about game crashes and other problems to gain execution on victim machines. It turns a seemingly helpful fix into a malware-delivery path that can persist across reboots.

ShinyHunters impersonation sextortion email campaign

Campaign

Updated: 25.07.2026 17:16 · First: 25.07.2026 17:16 · 📰 1 src / 1 articles · H score: 17

A sextortion email campaign is using leaked email addresses and ShinyHunters impersonation to demand $2,000 in Bitcoin, broadening abuse of previously exposed breach data. The messages claim device compromise and threaten to release intimate videos, but there is no indication the sender accessed devices, installed malware, or monitored activity. The operation has reused addresses from published leaks tied to Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread, and McGraw Hill. The campaign appears to have begun in April and has generated similar reports across multiple people and organizations.

Fastjson Spring Boot unauthenticated RCE (CVE-2026-16723)

Vulnerability

Updated: 25.07.2026 15:52 · First: 25.07.2026 15:52 · 📰 1 src / 1 articles · H score: 41

CVE-2026-16723 is a Fastjson RCE affecting Spring Boot fat-JAR deployments, letting attacker-controlled JSON execute with the Java process's privileges. ThreatBook and Imperva said they saw in-the-wild exploitation, while Alibaba had not released a fixed Fastjson 1.x build as of July 25. The confirmed chain requires Fastjson 1.2.68 through 1.2.83, a network-reachable parser path, and SafeMode left disabled. Mitigations include enabling -Dfastjson.parser.safeMode=true or using com.alibaba:fastjson:1.2.83_noneautotype.

Alibaba Fastjson SafeMode mitigation for CVE-2026-16723

Advisory/Mitigation

Updated: 25.07.2026 15:52 · First: 25.07.2026 15:52 · 📰 1 src / 1 articles · H score: 44

Alibaba issued SafeMode mitigation guidance for Fastjson 1.x after CVE-2026-16723, giving affected organizations a temporary defense against unauthenticated code execution in reachable Spring Boot deployments. The advisory says operators that cannot migrate immediately should enable `-Dfastjson.parser.safeMode=true` or switch to `com.alibaba:fastjson:1.2.83_noneautotype`. Fastjson2 remains the long-term fix, and no fixed Fastjson 1.x release was available as of July 25.

Insurance provider Google Ads real-time OTP phishing campaign

Campaign

Updated: 25.07.2026 13:14 · First: 25.07.2026 13:14 · 📰 1 src / 1 articles · H score: 29

The insurance-focused phishing campaign now uses Google Ads, lookalike domains, and real-time OTP relaying to hijack sessions before victims notice. The operation spans Saudi Arabia, Europe, the United States, and India, broadening exposure across multiple insurers. Instead of delayed credential theft, attackers can complete login and take over accounts during the same browsing session. That raises the risk of immediate access to customer data, policy records, and payment information.

Clop Internet-exposed Windchill and FlexPLM data theft extortion campaign

Campaign

Updated: 24.07.2026 10:36 · First: 24.07.2026 10:36 · 📰 2 src / 2 articles · H score: 55

The Cl0p campaign is targeting internet-exposed PTC Windchill and FlexPLM deployments in a data extortion operation, with CVE-2026-12569 enabling unauthenticated remote code execution and JSP web shell deployment. Researchers said the attackers chain a FlexPLM WSDL information disclosure with a flaw in the Windchill login servlet, then enumerate file systems, stage engineering and design data, and steal sensitive product data. The activity has hit manufacturing, automotive, aerospace, and retail sectors, while PTC issued patches and CISA added the flaw to its Known Exploited Vulnerabilities catalog. Companies have also received extortion emails from [email protected].

DevMan-Funky Mantis ecosystem shift changes threat-actor operations

Threat Actor Meta

Updated: 25.07.2026 12:53 · First: 25.07.2026 12:53 · 📰 1 src / 1 articles · H score: 46

DevMan has consolidated its RaaS affiliate portal, tightening control over payload creation, victim handling, and payouts across its criminal service network. PRODAFT tracks the operation as Funky Mantis, and the portal's v3 update in January 2026 added structured victim records, lifecycle states, team controls, deadline tracking, and revenue fields. The platform also bundles build generation, finance, victim chat, support, and access brokerage, giving administrators more leverage over affiliate activity and attack tempo. That structure reduces affiliate autonomy and helps the operators scale multi-victim extortion while steering attacks toward targets outside the CIS and Serbia and toward SCADA-related operations.

DevMan ransomware locker capability update for Windows, ESXi, and Linux

Malware Activity

Updated: 25.07.2026 12:53 · First: 25.07.2026 12:53 · 📰 1 src / 1 articles · H score: 38

The DevMan ransomware locker now supports payload builds for Windows, ESXi, and Linux, expanding the operation's reach across server and workstation environments. Analysis of the Windows build shows features for privilege checks, process and service termination, recovery inhibition, event log clearing, lateral movement, and multi-threaded encryption, all of which increase the impact of an infection. The locker also uses ChaCha20-Poly1305 and can self-delete, making remediation harder after deployment.

GitLab notebook diff authenticated RCE flaw

Vulnerability

Updated: 25.07.2026 11:34 · First: 25.07.2026 11:34 · 📰 1 src / 1 articles · H score: 37

A public PoC exploit now shows an authenticated RCE path in GitLab that can run commands as git on vulnerable self-managed servers. The flaw affects GitLab CE/EE 15.2.0 through 18.10.7, 18.11.0 through 18.11.4, and 19.0.0 through 19.0.1, with the exploit demonstrated against GitLab 18.11.3. GitLab fixed the issue in 18.10.8, 18.11.5, and 19.0.2, and successful exploitation can expose source code, Rails secrets, service credentials, and CI/CD data.

Oj parser state corruption and ASLR leak analysis in the GitLab notebook diff exploit chain

Technical Analysis

Updated: 25.07.2026 11:34 · First: 25.07.2026 11:34 · 📰 1 src / 1 articles · H score: 23

Researchers published deep exploit analysis of Oj parser bugs in GitLab's notebook diff path, showing how callback-pointer corruption and a heap-address leak can be combined to drive authenticated RCE.

OnTrac hit by network compromise

Incident

Updated: 24.07.2026 22:55 · First: 24.07.2026 22:55 · 📰 1 src / 1 articles · H score: 10

OnTrac confirmed a corporate network breach that may have exposed customer personal details, creating identity-risk exposure for customers. The company detected the intrusion on March 23 and found the attacker accessed certain files between March 20 and 22. OnTrac says it is not aware of fraud or publication of stolen information, but it is offering 12 months of credit monitoring and identity protection through CyberScout.

Hotel Wi-Fi DNS hijacking Microsoft 365 phishing campaign

Campaign

Updated: 24.07.2026 20:50 · First: 24.07.2026 20:50 · 📰 1 src / 1 articles · H score: 34

Compromised Wi-Fi gateways at hotels and conference centers are redirecting travelers to fake Microsoft 365 login pages, creating a live credential-theft campaign that can expose business email, documents, and other sensitive data. The operation has been active since at least June and has reached organizations across financial services, professional services, legal, health care, energy, and retail in the U.S. and abroad. Attackers are using DNS changes, device-code authentication tricks, and in some cases WPAD abuse to push victims onto attacker-controlled login pages and bypass MFA.

Microsoft Azure and Microsoft 365 outage caused by maintenance bug

Service Disruption

Updated: 24.07.2026 18:41 · First: 24.07.2026 18:41 · 📰 1 src / 1 articles · H score: 0

A maintenance-system bug triggered a massive Microsoft outage that disrupted access to Azure and Microsoft 365 services for customers tied to West US infrastructure. The disruption affected core collaboration and admin tools, including OneDrive, SharePoint Online, Teams, and the Microsoft 365 Admin Center. Microsoft reverted the networking change and said affected services had recovered by 3:41 PM ET. The event shows how an automated maintenance workflow can create broad availability and functionality failures across a large cloud stack.

BlueNoroff ClickFix-style Zoom and Microsoft Teams phishing campaign

Campaign

Updated: 24.07.2026 18:12 · First: 24.07.2026 18:12 · 📰 1 src / 1 articles · H score: 38

BlueNoroff's ClickFix-style phishing campaign is using typosquatted Zoom and Microsoft Teams domains to deliver malware and steal Telegram sessions from high-value crypto targets. The operation combines trusted-contact compromise, wallet reconnaissance, and self-propagating messaging to turn one account takeover into the next. The result is a repeatable victim-acquisition pipeline that raises the risk of account theft, malware infection, and follow-on targeting across the cryptocurrency sector.