Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (14 July 2026)
Published: Loading…
At a Glance
- Attackers spoof OAuth client IDs against Microsoft Entra ID to enumerate accounts and validate credentials without triggering successful sign-in events.
- A misconfigured server exposed three threat actors running Evilginx forks for adversary-in-the-middle phishing against Microsoft 365 accounts.
- The US Treasury sanctioned First VPN Service and a cryptor seller for supporting ransomware attacks against American businesses and hospitals.
- The EU and UK sanctioned dozens of Russian individuals and entities and attributed a December 2025 Poland power grid attack to FSB Centre 16.
- Progress Software ordered ShareFile customers to shut down Storage Zone Controller servers over a credible external security threat.
- CISA added maximum-severity iCagenda and Balbooa Forms Joomla extension flaws to its Known Exploited Vulnerabilities catalog after zero-day exploitation.
Summary
OAuth client ID spoofing has emerged as a technique for stealthy account enumeration against Microsoft Entra ID. Two campaigns, UNK_pyreq2323 and UNK_OutFlareAZ, together targeted over three million user accounts without generating successful sign-in events. Separately, a misconfigured server exposed three operators running Evilginx forks for adversary-in-the-middle phishing against Microsoft 365, while a new phishing-as-a-service platform called Forg365 offered similar device code and AitM capabilities via Telegram.
CISA added two maximum-severity flaws in the iCagenda and Balbooa Forms Joomla extensions to its Known Exploited Vulnerabilities catalog. Both vulnerabilities, rated 10.0 on CVSS, were exploited as zero-days for remote code execution through arbitrary file uploads. The Australian Cyber Security Centre separately warned of a global mass scanning and exploitation campaign against CMS platforms.
The US Treasury sanctioned First VPN Service and its administrator, along with a Belarusian cryptor seller, for enabling ransomware attacks against American businesses and hospitals. A former DigitalMint ransomware negotiator was sentenced to 70 months in prison for leaking client data to the BlackCat group. An Armenian man extradited from Ukraine pleaded guilty to charges tied to the Ryuk ransomware operation.
The EU and UK jointly sanctioned dozens of Russian individuals and entities and formally attributed the December 2025 attack on Poland's power grid to FSB Centre 16. A joint advisory from the NCSC and agencies across 12 countries detailed how Centre 16, also known as Berserk Bear, exploits routers using weak SNMP credentials. The UK separately charged five people linked to the Russian Coms call-spoofing platform.
Progress Software ordered ShareFile customers to manually shut down Storage Zone Controller servers over a credible external security threat, though it reported no evidence of unauthorised data access. Lidl notified customers in Germany, Belgium and the Netherlands that personal data was stolen in a breach at an IT service provider. Japan's largest taxi operator, Nihon Kotsu, shut down part of its infrastructure following a cyberattack.
A campaign using at least 292 brand-impersonation GitHub repositories, including a fake Arctic Wolf page, distributed a Windows infostealer sharing code with the BoryptGrab family. Google and Microsoft pulled the ModHeader browser extension, with 1.6 million installs, after researchers found a dormant browsing-history collector. Fake ticket and travel sites impersonating Tomorrowland 2026 harvested identity and payment data from festival-goers ahead of the sold-out event.
Highlights of the Day
OAuth Client ID Spoofing Enables Silent Entra ID Account Enumeration
Proofpoint identified attackers spoofing OAuth client IDs against Microsoft Entra ID to enumerate accounts and validate passwords without generating a successful sign-in event. The campaign UNK_pyreq2323, active from January to March 2026, used over 700,000 spoofed client IDs from AWS infrastructure and triggered account lockouts for around 28% of one million targeted users across nearly 4,000 tenants. A separate campaign, UNK_OutFlareAZ, ran from December 2025 through March 2026 using Cloudflare infrastructure, fully randomised UUIDv4 client IDs, and targeted more than 2 million users with 3.7 million spoofed application identifiers.
CISA Adds Exploited Joomla Extension Flaws to Vulnerability Catalog
CISA added CVE-2026-48939 and CVE-2026-56291 to its Known Exploited Vulnerabilities catalog, affecting the iCagenda and Balbooa Forms extensions for Joomla. Both flaws involve unrestricted upload of files with dangerous types, based on evidence of active exploitation. Under Binding Operational Directive 26-04, federal agencies must prioritise remediation of vulnerabilities that grant total control of publicly exposed assets post-exploitation.
Treasury Sanctions VPN Provider and Cryptor Seller Aiding Ransomware Gangs
The US Treasury's Office of Foreign Assets Control designated First VPN Service, its administrator Dmytro Rashevskyi, and cryptor seller Yegeniy Vladimirovich Silayev for supporting ransomware operations against American victims. First VPN Service supplied infrastructure that ransomware groups used to hide attack origins, deploy malware, and manage stolen data, with victims including US businesses, hospitals and municipal governments. The action follows a May 2026 takedown of First VPN Service's infrastructure by European law enforcement with FBI support, and coincides with the UK's Foreign, Commonwealth & Development Office sanctioning additional cybercriminals.
Open Directory Exposes Three Linked AiTM Phishing Operations Targeting Microsoft 365
Researchers at Lexfo discovered a misconfigured Python HTTP server in Budapest that exposed configuration files, logs and Telegram sessions belonging to three separate threat actors, tracked as codemado, mail-argenta and saroula01, each running custom Evilginx forks for adversary-in-the-middle phishing. Codemado operated an AiTM platform on picis[.]net with a seven-tool remote monitoring arsenal, while saroula01's Device Code Flow campaign on romnor[.]ca ran undetected for over a year, accumulating 218 victims across 12 countries with automatically refreshed OAuth tokens. Both techniques bypass multi-factor authentication, and codemado's MaDoO Blaster tool was separately identified by SOCRadar as promoted within the RockyBelling-run "The Quarry" cybercrime ecosystem.
Fake GitHub Repositories Impersonate 292 Brands to Spread Infostealer
Arctic Wolf identified 292 brand-impersonation GitHub repositories, including a fake Arctic Wolf page, distributing a Windows infostealer sharing code with the BoryptGrab family since 26 June 2026. Victims are lured through concealed links to a fake download page serving a ZIP archive that triggers DLL side-loading, deploying an in-memory stealer with 11 modules targeting over 19 browsers, cryptocurrency wallets, Telegram, Discord and Steam accounts. Stolen data is exfiltrated to a Russia-based command-and-control server, and BinDiff analysis matched 1,638 functions against a reference BoryptGrab binary.
Progress Software Warns of Security Threat to ShareFile Storage Controllers
Progress Software notified customers on July 10 of a credible external security threat targeting ShareFile Storage Zone Controllers, urging users to manually shut down affected servers. The company temporarily disabled account access and reported no evidence of unauthorised access to ShareFile accounts or data, restoring cloud service access to customers by July 12 while Storage Zone Controllers remain offline. Progress previously suffered the 2023 MOVEit Transfer breach exploited in widespread ransomware attacks, and a critical MOVEit Automation vulnerability was disclosed in April 2026.
NCSC and Allies Warn of Russian FSB Router-Exploitation Campaign
The NCSC and 18 agencies from 12 countries issued a joint advisory detailing how FSB Centre 16, also tracked as Berserk Bear and Energetic Bear, opportunistically compromises routers and network devices belonging to critical infrastructure organisations worldwide. The actor primarily scans for default or weak SNMP passwords and community strings, while also exploiting known vulnerabilities in Cisco devices, Cisco's Smart Install feature, and web-portal flaws. The advisory coincided with the UK sanctioning 24 individuals and entities tied to Russian cyber operations, and the UK and EU formally attributing a December 2025 attack on Poland's energy grid to FSB Centre 16.
Fake Ticket Sites Target Tomorrowland 2026 Buyers Before Sold-Out Festival
CloudSEK identified around a dozen fraudulent websites impersonating Tomorrowland Belgium 2026 ticket sales and travel bookings ahead of the sold-out festival's two July weekends. One fake storefront used countdown timers and a "biometric registration" checkout to harvest identity and payment data, routing victims to a Stripe payment link resolving to an unrelated Luxembourg-registered merchant. A separate French-language Shopify clone directed buyers through genuine PayPal authentication to a payee unconnected to the festival, while other lookalike domains redirected to resale platforms or affiliate accommodation listings.
Daily Coverage