Skip to content

Flash Briefings

critical

Oracle EBS Payments Component Hit with CVSS 9.8 Unauthenticated RCE — CISA Sets 72-Hour Federal Deadline

CVE-2026-46817 is a CVSS 9.8 unauthenticated remote code execution flaw in Oracle E-Business Suite's Payments File Transmission component. CISA added it to the Known Exploited Vulnerabilities catalogue on July 15 with a federal patch deadline of July 18 — 72 hours from disclosure to mandatory remediation.

critical

SonicWall SMA1000 Zero-Days Exploited in Tandem: CISA Sets July 17 Federal Deadline as Four Flaws Hit KEV

Two SonicWall SMA1000 zero-days — an unauthenticated SSRF (CVE-2026-15409, CVSS 10.0) chained with post-auth code injection (CVE-2026-15410, CVSS 7.2) — are confirmed exploited in the wild. CISA added both plus two Microsoft zero-days to the KEV catalogue on July 14 with a July 17 federal patch deadline.

critical

Three CVSS 10.0 Flaws Hit CISA KEV in 48 Hours: ColdFusion and Joomla Actively Exploited

Adobe ColdFusion and two Joomla-ecosystem components with CVSS 10.0 ratings were added to the CISA Known Exploited Vulnerabilities catalog between July 7 and 9, with a federal patch deadline of July 10. Langflow also added as the first AI agent platform in the catalog.

high Armored Likho

Armored Likho Deploys BusySnake Stealer Against Government and Power Sector

Russia-linked threat actor Armored Likho has launched a credential theft campaign targeting government agencies and electric power infrastructure across Russia, Kazakhstan, and Brazil. The Python-based BusySnake infostealer extracts browser credentials, Telegram sessions, and crypto wallet keys while operating in-memory to evade disk-based detection.

high MuddyWater

MuddyWater Deploys Four New Malware Families in Operation Olalampo Targeting MENA Government and Energy

Group-IB tracked MuddyWater's Operation Olalampo campaign from January 2026, uncovering four previously undocumented malware families including CHAR — a Rust backdoor using Telegram for C2 with evidence of AI-assisted development. Targets span government, energy, and telecoms across the MENA region.

high Storm-2603

SharePoint Server RCE Under Active Ransomware Exploitation: CISA Sets July 4 Federal Deadline

CVE-2026-45659, a CVSS 8.8 deserialization remote code execution flaw in on-premises SharePoint Server, is being actively exploited by Storm-2603 ransomware operators. CISA added it to the Known Exploited Vulnerabilities catalogue on July 1 with a federal patch deadline of July 4.

high

FortiBleed: 73,932 FortiGate Credentials from CVE-2022-40684 Surface Four Years After Exploitation

A dataset of valid VPN credentials harvested from 73,932 FortiGate devices during CVE-2022-40684 exploitation was published on 17 June 2026. The four-year gap between collection and release illustrates a documented threat actor pattern — credential harvesting during a mass exploitation window, then monetising the dataset years later when many organisations have forgotten to rotate.

critical ShinyHunters

ShinyHunters Weaponised Oracle PeopleSoft Zero-Day Against 100+ Universities and Enterprises: CVE-2026-35273

ShinyHunters (UNC6240) exploited a CVSS 9.8 unauthenticated RCE in Oracle PeopleSoft as a zero-day for two weeks before any patch existed, breaching more than 100 organisations — 68% of them universities. CISA added CVE-2026-35273 to its KEV catalog on 12 June 2026.

high TA4922

TA4922 Extends High-Tempo Campaign Operations to UK and Europe With Atlas RAT and Credential Stealer

Proofpoint has published intelligence on TA4922's geographic expansion into the UK, Germany, Italy, and South Africa — deploying two new malware families via tax-themed and HR-themed phishing. The group holds the highest campaign pace of any Proofpoint-tracked threat actor.

high APT10

APT10 Renews MSP Targeting in UK and Europe -- Cloud Hopper Techniques Persist

China's APT10 has resumed systematic targeting of UK managed service providers and professional services firms, using the same supply chain pivot techniques that characterised the Cloud Hopper campaign -- now adapted for cloud-managed tenants.

high APT28

APT28 Intensifies Targeting of European Government Networks Ahead of 2026 Election Cycle

Russia's GRU-linked APT28 has escalated spear-phishing and credential-harvesting operations against European government ministries, NATO-adjacent bodies, and political parties in the run-up to elections across the continent.

critical APT29

APT29 Exploiting Trusted Vendor Relationships to Reach UK and European Government Networks

Russia's SVR-linked APT29 is using compromised software vendor and IT service provider accounts to pivot into government targets -- a continuation of the SolarWinds playbook applied to UK and European supply chains.

high LockBit

LockBit Resurgence: Affiliate Network Active Across UK Healthcare and Professional Services

Despite Operation Cronos and the February 2024 infrastructure seizure, LockBit-affiliated actors continue to operate under the LockBit 3.0 and successor infrastructure. UK healthcare and professional services organisations have been among the most recent confirmed victims.

critical Volt Typhoon

NCSC Warns: Volt Typhoon Reconnaissance Extends to Tier 2 UK Government Suppliers

Intelligence confirms Volt Typhoon pre-positioning activity has moved beyond primary CNI operators into the Tier 2 supplier networks that service UK central government and defence. Smaller suppliers with privileged access to government systems are now directly in scope.

critical Volt Typhoon

Volt Typhoon Activity Confirmed Across UK Water and Energy OT Networks

NCSC and Five Eyes partners have confirmed Volt Typhoon intrusions at operational technology networks in UK water treatment and regional energy distribution. The group is not causing disruption -- it is waiting.

critical

First Confirmed AI-Built Zero-Day: Google Thwarts Mass Exploitation Campaign

A threat actor used a large language model to write a working 2FA bypass exploit for a widely deployed open-source admin tool. Google's threat intelligence team detected the planned mass exploitation campaign before it launched. The code left distinctive LLM fingerprints.

Deep Analysis

TA427 / Kimsuky 14 min read

TA427 / Kimsuky: North Korea's Intelligence-Gathering APT

TA427 (Kimsuky, Emerald Sleet) is North Korea's primary intelligence collection arm — an APT operation that has run sustained espionage campaigns against nuclear policy researchers, think tanks, and government officials for over a decade. This deep dive covers their TTPs, evolving malware toolkit, social engineering tradecraft, and what defenders should watch for.

high Lurking Lizard 12 min read

Lurking Lizard: How a China-Linked Cybercrime Group Built a Global Residential Proxy Network Through Fake Software

Infoblox and The Hacker News disclosed in July 2026 that Lurking Lizard, a China-based financially motivated threat group, operates an industrial-scale residential proxy business sustained by trojaned installers for legitimate software. The network has processed hundreds of millions of proxy requests and is actively rented to criminal and espionage-linked operators.

high Storm-2755 11 min read

Storm-2755: Inside the Malware-Free Payroll Fraud Group Redirecting Canadian Salaries to Attacker Accounts

Microsoft disclosed Storm-2755 in April 2026 — a financially motivated threat actor conducting adversary-in-the-middle phishing campaigns against Canadian employees to redirect payroll deposits to attacker-controlled bank accounts. The group operates without traditional malware, using stolen session tokens to bypass MFA and modify direct deposit settings in HR portals.

high UAT-7810 14 min read

UAT-7810 and LapDogs: Inside China's Malware Factory for Covert Relay Infrastructure

Cisco Talos has published detailed research on UAT-7810's LapDogs campaign: a China-nexus operation building Operational Relay Box networks through compromised SOHO routers. New malware families LONGLEASH, DOGLEASH, and JARLEASH reveal how far this infrastructure-as-a-service model has matured.

critical Cadet Blizzard 11 min read

Cadet Blizzard: GRU Unit 29155 and the Sabotage Doctrine

Cadet Blizzard — GRU Unit 29155's cyber arm — is the group behind WhisperGate, a wiper that preceded Russia's full-scale Ukraine invasion. Since the September 2024 DOJ indictment publicly named its officers, a clearer picture has emerged of a unit that combines destructive cyber operations with physical sabotage across NATO member states.

critical Anubis 13 min read

Anubis Ransomware: The RaaS Platform Weaponising Healthcare Regulators Against Its Own Victims

Anubis is a Go-based ransomware-as-a-service operation that emerged in late 2024 and has rapidly focused on healthcare organisations, deploying a novel pressure tactic: threatening to notify data protection regulators and HIPAA enforcement bodies unless victims pay. This deep dive covers Anubis's affiliate model, technical profile, targeting patterns, and the regulatory weaponisation that distinguishes its extortion approach.

critical Qilin 15 min read

Qilin: The Ransomware Group Behind the NHS Synnovis Attack and the Chrome Credential Theft Innovation

Qilin emerged in 2022 as Agenda ransomware and has evolved through a complete Rust rewrite, a defining attack on NHS blood supply services in 2024, a novel Chrome browser credential theft technique, and a 2026 VPN exploitation campaign hitting four major vendors simultaneously. This deep dive covers the full operational and technical profile.

high RomCom / Storm-0978 (Russia) 18 min read

RomCom / Storm-0978: Russia's Hybrid Espionage-Criminal Threat Actor

RomCom — tracked by Microsoft as Storm-0978, by Unit 42 as Tropical Scorpius, by Mandiant as UNC2596 — is a Russian threat actor that operates across the line between state-sponsored espionage and organised cybercrime. The group exploited two chained zero-days to target NATO governments in 2023, runs Underground ransomware operations for revenue, and has maintained continuous campaigns against Ukrainian government and European defence targets through 2026.

high APT42 14 min read

APT42: Iran's Elite Social Engineering Unit Targeting Western Officials and Research

APT42 is Iran's most operationally sophisticated espionage actor — an IRGC-IO-sponsored group that has compromised US presidential campaigns, nuclear researchers, journalists, and Western diplomats through highly targeted social engineering rather than technical exploitation.

high GopherWhisper 10 min read

GopherWhisper: China-Aligned APT Using Cloud Messaging C2 Against Mongolian Government

GopherWhisper is a China-aligned threat actor discovered by ESET in January 2025 and publicly disclosed in April 2026. The group operates Go-based implants that use Slack, Discord, Microsoft 365 Outlook, and legitimate file-sharing services as command-and-control channels, almost entirely avoiding traditional C2 infrastructure. Their campaigns have persistently targeted the Mongolian government.

critical Secret Blizzard (Turla) 12 min read

Secret Blizzard: Inside Russia's Most Patient Cyber Espionage Operation

A deep dive into Secret Blizzard (Turla), the FSB-linked APT that has sustained global intelligence collection for over two decades — hijacking criminal infrastructure, deploying ISP-level interception against foreign embassies, and evolving the Kazuar backdoor into a resilient P2P botnet.

critical APT28 12 min read

APT28: Russia's GRU Hacking Unit and the Twenty-Year Campaign Against Western Democracy

APT28 — Fancy Bear, Forest Blizzard, GRU Unit 26165 — is Russia's Military Intelligence cyber arm and the most prolific nation-state attacker targeting Western governments, militaries, and democratic institutions. This deep dive covers their operational history, tradecraft, tooling, and current targeting priorities.

critical Cl0p 11 min read

Cl0p: The Group That Turned File Transfer Vulnerabilities Into a Mass Exploitation Business

Cl0p is a financially motivated cybercriminal group that has systematically identified and mass-exploited zero-day vulnerabilities in enterprise file transfer software, compromising thousands of organisations globally. Their MOVEit campaign in 2023 was the largest data theft operation in the history of ransomware. This deep dive covers their operational model, technical approach, and what comes next.

critical LockBit 12 min read

LockBit: The Ransomware Operation That Survived Its Own Takedown

LockBit is the world's most prolific ransomware-as-a-service operation, responsible for more confirmed attacks than any other RaaS group. Despite Operation Cronos seizing its infrastructure and unmasking its administrator in 2024, the affiliate network remains active. This deep dive covers LockBit's operational model, technical capabilities, and what the post-Cronos resurgence means for defenders.

critical APT29 15 min read

Midnight Blizzard: A Complete Profile of Russia's SVR Espionage Apparatus

APT29 — Cozy Bear, Midnight Blizzard — is Russia's SVR-aligned intelligence collection machine, responsible for SolarWinds, the 2024 Microsoft corporate email compromise, and ongoing targeting of European governments, diplomatic missions, and defence industrial base organisations. This deep dive covers their full operational history, tradecraft, tooling, and what defenders need to be doing now.

high MuddyWater 11 min read

MuddyWater: Iran's MOIS Cyber Arm and the Blurred Line Between Espionage and Disruption

MuddyWater — Seedworm, Static Kitten, Earth Vetala — is Iran's Ministry of Intelligence and Security cyber unit conducting sustained espionage across the Middle East, Europe, and Asia, increasingly deploying ransomware as a false flag to complicate attribution and provide cover for intelligence collection.

critical Sandworm 22 min read

Sandworm: Inside Russia's Most Destructive Cyber Weapon

Sandworm -- GRU Unit 74455 -- is responsible for the most destructive cyberattacks in history: the 2015 and 2016 Ukraine power grid attacks, NotPetya, Olympic Destroyer, and continuous destructive campaigns against Ukraine since 2022. This deep-dive covers their history, capabilities, and why they remain the most dangerous threat actor operating today.

high 18 min read

AI in the Attack Chain: How Threat Actors Are Using Language Models Operationally

AI-assisted exploitation is no longer theoretical. From automated vulnerability research to AI-generated spear-phishing, the adoption of LLMs across the offensive lifecycle is accelerating. This analysis examines what is confirmed, what is emerging, and what it means for defenders.

critical Volt Typhoon 18 min read

Volt Typhoon: The Long Game in Western Critical Infrastructure

A deep analysis of Volt Typhoon's objectives, methods, and targets -- and what the sustained Chinese pre-positioning campaign in Western CNI means for how operators, regulators, and governments need to respond.

critical Salt Typhoon 16 min read

Salt Typhoon: How China Compromised the West's Wiretap Infrastructure

The Salt Typhoon campaign against US and European telecommunications carriers was not a data breach in any conventional sense. It was a strategic intelligence operation targeting the systems governments use to conduct lawful surveillance.

Commentary

7 min read

Twenty-Two Seconds: What M-Trends 2026 Says About Attacker Speed and Defender Reality

Mandiant's M-Trends 2026 report, grounded in over 500,000 hours of incident investigations, contains several findings that should recalibrate how security teams think about detection windows, initial access economics, and the real mechanics of ransomware recovery denial. The headline statistic — 22 seconds from initial access to secondary threat group handoff — isn't the most important one.

9 min read

The Attack Is Coming From Inside the Country: China's Compromised-Device Networks and Why Your Perimeter Controls Miss Them

A joint advisory from CISA, NCSC, and ten allied nations describes how China-linked threat actors have abandoned dedicated attack infrastructure in favour of networks of compromised home routers and IoT devices. The implication for defenders is worse than it sounds.

9 min read

The Public Sector Cyber Gap: Why Government's Security Posture Trails the Threat

The structural factors that make the UK public sector a persistently soft target -- fragmented IT estates, procurement cycles that optimise for cost over security, and a talent market that can't compete with private sector pay -- are not going away. Here's what the gap looks like and what's actually being done about it.

7 min read

Why Ransomware Groups Don't Die When You Arrest Their Leaders

The ransomware-as-a-service model has created a resilient criminal infrastructure that survives law enforcement actions, FBI seizures, and individual prosecutions. Understanding why is the first step to defending against it.

7 min read

Nation-State Threats: What Business Leaders Get Wrong and Why It Matters

Most executives conflate nation-state cyber activity with the ransomware threat they're more familiar with. They are different in purpose, method, and the defences required. Getting this wrong shapes your entire risk posture.