Weekly Cybersecurity Briefing (13 July – 19 July 2026)
Published: Loading…
This briefing covers 292 reports published from 13 July to 19 July 2026.
At a Glance
- A ransomware attack forced Coca-Cola's Fairlife subsidiary to halt US dairy production after unauthorised system access.
- Microsoft's July Patch Tuesday addressed a record 622 CVEs, including three zero-days actively exploited in Active Directory Federation Services and SharePoint.
- SonicWall confirmed two SMA1000 zero-days were chained by attackers to gain root access and move laterally into Active Directory.
- A pre-authentication remote code execution flaw in WordPress Core, affecting an estimated 500 million sites, was disclosed and patched.
- Two Scattered Spider members were sentenced to over five years each for the £29 million 2024 cyberattack on Transport for London.
Editorial Analysis
Trusted access and trusted infrastructure — developer accounts, package registries, VPN and CDN services, and enterprise identity systems — were common vectors across many of the week's most damaging incidents, from Fairlife to AsyncAPI and RubyGems.
Perimeter-focused defences proved less effective against attacks entering through legitimate credentials, compromised dependencies, or third-party infrastructure, highlighting the need for detection across CI/CD pipelines and identity workflows. Multiple unrelated npm, NuGet, and RubyGems compromises suggest maintainer-account takeover and CI token theft are becoming repeatable, low-cost initial-access techniques.
Patch cadence alone is also proving insufficient as the gap between vulnerability disclosure and exploitation continues to shrink, as seen with the SharePoint, FortiSandbox, and WordPress flaws.
On the defensive side, law-enforcement action — including Treasury sanctions, the Spanish takedown, and the TfL sentencing — offers a counterpoint to the technical trends, showing that disruption and prosecution remain possible even as attack methods continue to evolve.
Highlights of the Week
Ransomware Attack Halts Coca-Cola's Fairlife Dairy Production
Coca-Cola disclosed that its Fairlife subsidiary detected unauthorised access to production-related systems connected to a ransomware attack. The company suspended US manufacturing, notified law enforcement, and confirmed Canadian operations were unaffected. No group has claimed responsibility, and data theft has not been confirmed.
Microsoft Ships Record 622-CVE Patch Tuesday With Exploited Zero-Days
Microsoft's July 2026 Patch Tuesday addressed 622 vulnerabilities, including 59 critical flaws and three publicly disclosed zero-days. Two zero-days, in Active Directory Federation Services and SharePoint Server, were under active exploitation. Microsoft also paused rollout for some Dell Intel-based devices over shutdown issues.
WordPress Core Flaw Allows Unauthenticated Remote Code Execution
Searchlight Cyber disclosed a pre-authentication remote code execution flaw in WordPress Core exploitable by an anonymous user with no plugins installed. The bug affects versions 6.9.0–6.9.4 and 7.0.0–7.0.1, spanning an estimated 500 million sites. Fixes shipped in versions 7.0.2 and 6.9.5.
SonicWall SMA1000 Zero-Days Chained for Root Access and AD Lateral Movement
SonicWall disclosed CVE-2026-15409, a maximum-severity SSRF flaw, and CVE-2026-15410, a privilege escalation bug, in SMA1000 appliances. Rapid7 observed attackers chaining both to gain root, harvest credentials and TOTP seeds, then move laterally into Active Directory. Fixes are available in hotfix versions 12.4.3-03453 and 12.5.0-02835.
Scattered Spider Members Jailed Over £29 Million TfL Cyberattack
Thalha Jubair, 20, and Owen Flowers, 18, were sentenced to five years and six months each for the 2024 Transport for London cyberattack. The intrusion cost TfL £29 million and disrupted 148 internal systems, forcing 27,000 employees into in-person password resets. The National Crime Agency named both as leading Scattered Spider members.
Threats
OAuth Client ID Spoofing Enables Silent Entra ID Account Enumeration
Proofpoint identified two campaigns spoofing OAuth client IDs against Microsoft Entra ID to enumerate accounts without generating sign-in events. UNK_pyreq2323 used over 700,000 spoofed IDs from AWS infrastructure, triggering lockouts for 28% of one million targeted users. UNK_OutFlareAZ separately targeted more than 2 million users via Cloudflare infrastructure.
CISA Flags Active Exploitation of On-Premises SharePoint Flaws
CISA confirmed active exploitation of three SharePoint Server vulnerabilities enabling remote code execution and theft of IIS machine keys via deserialization. All three were added to the Known Exploited Vulnerabilities catalogue, with CVE-2026-56164 added on 14 July. CISA published detection signatures for post-exploitation activity.
China-Linked Daxin Rootkit Resurfaces With New Stupig Backdoor
Symantec found the kernel-mode rootkit Daxin active on a Taiwan-based manufacturing subsidiary alongside a previously undocumented backdoor, Stupig, which executes commands as SYSTEM from the Windows logon screen. Both samples carry 2013 compile timestamps. Initial access likely came through an outdated Digiwin single sign-on portal.
New macOS Stealer Locks Screens Until Victims Enter Passwords
Group-IB discovered ClickLock Stealer, a modular macOS malware likely distributed via ClickFix phishing pages using compromised WordPress domains. The malware kills system processes to force victims into entering their password, then targets eight browsers, 31 crypto wallet extensions and macOS Keychain. At least 100 victims across 33 countries have been affected since May 2026.
Infrastructure & Exploits
SAP Fixes Critical NetWeaver, Approuter and Commerce Cloud Flaws
SAP released 20 security notes led by CVE-2026-44747, a memory corruption bug in NetWeaver Application Server ABAP rated 9.9. CVE-2026-27690, an HTTP request smuggling flaw in Approuter, and CVE-2026-44761, hardcoded OAuth2 credentials in Commerce Cloud, were both rated 9.1.
Chained Zero-Days in Siemens OT Switches Allow Root Takeover
Unit 42, working with Siemens, disclosed a three-vulnerability exploit chain in ROX II operational technology switches. The chain begins with an arbitrary file disclosure flaw, escalates through command injection, and achieves persistent root-level code execution via the device's task scheduler. Siemens recommends updating to firmware version V2.17.1.
15-Year-Old nginx Flaw Enables Pre-Auth Remote Code Execution
Researcher Stan Shaw disclosed CVE-2026-42533, a missing state-restore bug in nginx's script engine allowing an unauthenticated attacker to trigger a heap overflow or ASLR-defeating information leak. The flaw spans thirteen call sites across versions 0.9.6 through 1.30.3. F5 released fixes on 15 July 2026.
Progress Confirms ShareFile Zero-Day Behind Emergency Shutdown
Progress Software confirmed a path traversal vulnerability in ShareFile Storage Zone Controller prompted an emergency shutdown, affecting all 5.x and 6.x versions. The flaw let authenticated administrators read and write arbitrary files and enumerate the file system. Fixes shipped in versions 5.12.5 and 6.0.2.
Tools & Techniques
AsyncAPI npm Packages Compromised to Deliver Miasma Malware
Attackers stole a privileged GitHub Actions bot token to publish five compromised AsyncAPI npm package versions carrying an import-time loader. The loader fetches an encrypted Miasma runtime via IPFS for command-and-control and persistence. Credential-harvesting and propagation modules were present but disabled, with active C2 infrastructure identified.
Hijacked RubyGems Accounts Drop Backdoor via Fake Git Tool
Attackers compromised dormant RubyGems maintainer accounts to publish malicious versions of git_credential_manager and other packages. The loader, SleeperGem, evades roughly thirty CI environment checks and installs a daemon with systemd and cron persistence on developer machines. Systems with passwordless sudo have privileges escalated and a disguised root shell planted.
OkoBot Malware Framework Steals Cryptocurrency Wallet Data
Kaspersky identified OkoBot, a framework of more than 20 malicious payloads delivered via the TookPS downloader over an SSH tunnel, targeting cryptocurrency users since early 2025. Infection spreads through ClickFix attacks and fake GitHub repositories, deploying plugins that phish hardware wallet seed phrases and record keystrokes. Hundreds of victims were reported across more than 25 countries.
Malicious NuGet Packages Disguised as Game Cheats Deploy Downloader
Socket identified 11 malicious NuGet packages posing as game utilities and bots that fetch a second-stage Windows payload from GitHub Releases and Hugging Face. The packages resolve download hosts via DNS-over-HTTPS to bypass local resolvers and sinkholes. Recovered payloads authenticate to Google Sheets and bind activations to hardware.
Policy & Legal
US Treasury Sanctions VPN Provider and Cryptor Seller Aiding Ransomware
The US Treasury designated First VPN Service, its administrator, and a cryptor seller for supporting ransomware operations against American businesses and hospitals. First VPN Service supplied infrastructure used to hide attack origins and manage stolen data. The action follows a May 2026 takedown of the service's infrastructure by European law enforcement with FBI support.
Spanish Police Dismantle €140 Million Fraud Network
Spanish Police, with Interpol and Europol, dismantled a network that generated €140 million through investment fraud and business email compromise, arresting four suspects. The network used more than 800 bank accounts and 67 money mules to launder €94 million. Authorities raided six premises and froze €3 million in crime proceeds.
EU and UK Sanction Russian Actors, Attribute Poland Grid Attack to FSB
The EU and UK jointly sanctioned dozens of Russian individuals and entities and formally attributed the December 2025 attack on Poland's power grid to FSB Centre 16. A joint advisory from the NCSC and agencies across 12 countries detailed how Centre 16 exploits routers using weak SNMP credentials. The UK separately charged five people linked to the Russian Coms call-spoofing platform.
Former Ransomware Negotiator Sentenced for Leaking Client Data
A former DigitalMint ransomware negotiator was sentenced to 70 months in prison for leaking client data to the BlackCat ransomware group. Separately, an Armenian man extradited from Ukraine pleaded guilty to charges tied to the Ryuk ransomware operation.
Weekly Topic Distribution

Weekly Coverage
Developments
Fairlife Ransomware Attack Microsoft July Patch Tuesday Sonicwall Sma1000 Zero-Days Wordpress Core Rce (Wp2Shell)
Vulnerabilities
CVE-2026-15409Sma1000 12.4.3-03245 (Critical)CVE-2026-15410Sma1000 12.4.3-03245 (High)CVE-2026-56164Microsoft Sharepoint Enterprise Server 2016 16.0.0 (Medium)CVE-2026-44747Sap Netweaver Application Server Abap Krnl64Nuc 7.22 (Critical)CVE-2026-27690Sap Approuter Sap Approuter Node.js Package < 20.10.0 (Critical)CVE-2026-44761Sap Commerce Cloud Hy_Com 2205 (Critical)CVE-2026-42533Nginx Plus 37.0.0.1 (High)
Threat Groups
Scattered SpiderScattered Spider is a native Englishspeaking cybercriminal group active since at least 2022. The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. Scattered Spider relies heavily on social engineering, including impersonating IT and helpdesk staff, to gain initial access, bypass multifactor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. Scattered Spider had expanded into hybrid cloud and identity environments, using helpdesk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365.PlayPlay is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a doubleextortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.AkiraAkira is a ransomware variant and ransomware deployment entity active since at least March 2023. Akira uses compromised credentials to access singlefactor external access mechanisms such as VPNs for initial access, then various publiclyavailable tools and techniques for lateral movement. Akira operations are associated with "double extortion" ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Technical analysis of Akira ransomware indicates variants capable of targeting Windows or VMWare ESXi hypervisors and multiple overlaps with Conti ransomware.LAPSUS$LAPSUS$ is cyber criminal threat group that has been active since at least mid2021. LAPSUS$ specializes in largescale social engineering and extortion operations, including destructive attacks without the use of ransomware. The group has targeted organizations globally, including in the government, manufacturing, higher education, energy, healthcare, technology, telecommunications, and media sectors.APT28APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active since at least 2004. APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U. S. presidential election. In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including closeaccess operations) conducted between 2014 and 2018 against the World AntiDoping Agency (WADA), the US AntiDoping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations. Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.MuddyWaterMuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS). Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, defense, and oil and natural gas organizations, in the Middle East, Asia, Africa, Europe, and North America.CHROMIUMEarth Lusca is a suspected Chinabased cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated. Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.Salt TyphoonSalt Typhoon is a People's Republic of China (PRC) statebacked actor that has been active since at least 2019 and responsible for numerous compromises of network infrastructure at major U. S. telecommunication and internet service providers (ISP).Lazarus GroupLazarus Group is a North Korean statesponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain. North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns.Contagious InterviewContagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials. Contagious Interview targets Windows, Linux, and macOS systems, with a particular focus on individuals engaged in software development and cryptocurrencyrelated activities.