Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (11 July 2026)
Published: Loading…
At a Glance
- A former DigitalMint ransomware negotiator was sentenced to 70 months for aiding BlackCat/ALPHV attacks on five US organisations.
- Progress Software told ShareFile customers to shut down Storage Zone Controllers over a credible external security threat.
- Microsoft detailed GigaWiper, a Golang backdoor combining ransomware encryption, wiping commands and espionage capabilities since October 2025.
- SentinelOne found China- and India-linked actors both breached Pakistan's Balochistan Police Complaint Management System using PlugX and AsyncRAT.
- Binarly disclosed six U-Boot bootloader flaws in FIT Signature Verification enabling code execution or crashes at boot.
- A study of 281 free Android VPN apps found traffic leaks and unencrypted data across 2.4 billion installs.
Summary
A former DigitalMint negotiator, Angelo Martino, received a 70-month prison sentence for aiding BlackCat/ALPHV ransomware attacks on five US organisations. Prosecutors said he shared confidential insurance and negotiation details with the operators. Separately, a Ryuk ransomware operator pleaded guilty to hacking US companies in an Oregon federal court.
Progress Software instructed ShareFile customers running Storage Zone Controllers to shut down their Windows servers over a credible external security threat. The company temporarily disabled affected accounts and reported no evidence of unauthorised data access. The nature of the threat and any available fix remain undisclosed.
Microsoft detailed GigaWiper, a Golang-based Windows backdoor combining ransomware encryption, multiple wiping commands and espionage features like screen capture and VNC-style remote control. The malware has been observed in intrusions since October 2025 and merges previously separate tools including Crucio ransomware and FlockWiper.
SentinelOne reported that suspected China- and India-linked espionage groups both breached the Balochistan Police Complaint Management System in Pakistan between February 2024 and April 2026. Attackers deployed PlugX, ShadowPad, Cobalt Strike, Remcos and AsyncRAT against police and citizen targets across multiple provincial forces.
Binarly disclosed six vulnerabilities in the U-Boot bootloader's FIT Signature Verification, affecting code dating back to 2013. Two flaws could allow arbitrary code execution during boot, while four others cause denial-of-service conditions on affected devices.
Researchers analysed 281 free Android VPN apps using the MVPNalyzer framework, finding 61 transmitted unencrypted data and 29 leaked traffic outside VPN tunnels. The affected apps collectively exceed 2.4 billion Google Play installs. Separately, hackers exploited a critical authentication bypass in the official Gitea Docker image allowing user impersonation.
Highlights of the Day
Former DigitalMint employee Angelo Martino was sentenced to 70 months in prison after pleading guilty to participating in BlackCat (ALPHV) ransomware attacks against at least five US organisations between April 2023 and April 2025. Court documents state Martino, alongside Ryan Clifford Goldberg and Kevin Tyler Martin, encrypted victims' systems, demanded ransoms including a $1 million payment in one attack, and shared confidential insurance limits and negotiation details with BlackCat operators while acting as a ransomware negotiator.
Ryuk Ransomware Suspect Pleads Guilty in US Extortion Case
Armenian national Karen Serobovich Vardanyan pleaded guilty to conspiracy and computer fraud charges for deploying Ryuk ransomware against US organisations between November 2019 and April 2020. Court documents state Vardanyan and co-conspirators encrypted systems at companies and a Texas school, receiving approximately 1,610 bitcoins in ransom payments valued at more than $15 million.
China and India Spy Groups Breached Pakistani Police Systems
SentinelLABS reported that suspected China- and India-linked espionage groups targeted Pakistani law enforcement organisations between February 2024 and April 2026, using PlugX, ShadowPad, Cobalt Strike and Remcos against Balochistan Police, Islamabad Police, Khyber Pakhtunkhwa Police and the Punjab Safe Cities Authority. A suspected China-linked actor compromised the Balochistan Police Complaint Management System by hosting malicious cms_plugin.exe implants disguised as portal updates, deploying AsyncRAT and custom malware capable of infecting both police personnel and citizens using the public-facing service.
Progress Shuts Down ShareFile Storage Controllers Over Security Threat
Progress Software instructed ShareFile customers using self-hosted Storage Zone Controllers to shut down their Windows servers after identifying a credible external security threat, while temporarily disabling affected accounts and stating it has no evidence of unauthorised access to customer accounts or data. The incident affects only Storage Zone Controllers rather than cloud-only ShareFile deployments, and Progress has not disclosed the nature of the threat, whether it involves active exploitation, or any available security fix.
NHS Warns Staff Over Unauthorised Patient Record Access
The NHS has launched a staff awareness campaign and new guidance warning that employees who access patient records without a legitimate reason may face criminal prosecution, referral to the Information Commissioner’s Office and police, and dismissal from healthcare roles. The guidance follows multiple recent incidents, including the dismissal of 11 staff for unlawfully accessing records linked to the 2023 Nottingham attacks, and recommends monitoring, regular audits, least-privilege access, multi-factor authentication and role-based access controls.
Study Finds Widespread Security Flaws in Free Android VPN Apps
Researchers from the University of Michigan, the University of New Mexico and IIT Delhi analysed 281 popular free Android VPN apps using the MVPNalyzer framework, finding that 61 transmitted unencrypted data, 29 leaked user traffic outside VPN tunnels, and five exposed configuration files that enabled VPN tunnel hijacking through man-in-the-middle attacks. The study also found that 76 apps transmitted users' Advertising IDs, 246 contacted advertising or tracking domains, 169 failed to obfuscate VPN traffic against blocking, and 107 used insecure VPN configurations, with the affected apps collectively exceeding 2.4 billion Google Play installs.
OpenClaw Flaws Enable AI Agent Host Code Execution
Security researcher Chinmohan Nayak disclosed three high-severity OpenClaw vulnerabilities in version 2026.6.1, including an environment variable filter bypass, Git ext:: transport RCE and sandbox bypass. The flaws allowed an attacker sending messages through integrated channels such as WhatsApp to trigger arbitrary code execution on the host with command execution enabled. OpenClaw patched the issues in version 2026.6.6, with affected vulnerabilities tracked as GHSA-hjr6-g723-hmfm, GHSA-9969-8g9h-rxwm and GHSA-575v-8hfq-m3mc, exposing risks from command execution and sandbox isolation failures.
U-Boot Flaws Break Firmware Signature Verification
Binarly researchers disclosed six vulnerabilities in U-Boot FIT Signature Verification affecting code present since version v2013.07, including two flaws that could enable arbitrary code execution and four denial-of-service issues during processing of untrusted FIT images. The vulnerabilities, tracked as BRLY-2026-037 through BRLY-2026-042, affect the bootloader's validation of firmware components and were patched in the U-Boot master branch after disclosure to maintainers.
Daily Coverage