CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (22 July 2026)

Published: Loading…

At a Glance

  • German and US authorities dismantled the Kratos phishing-as-a-service platform, disabling over 200 servers and arresting its administrator in Indonesia.
  • SonicWall SMA 1000 zero-days CVE-2026-15409 and CVE-2026-15410 were exploited from 22 June 2026, weeks before public disclosure.
  • JadePuffer deployed ENCFORGE ransomware via a Langflow flaw to encrypt AI model weights, vector indexes, and training datasets.
  • A data breach at AI music platform Suno exposed over 55 million user accounts, including emails and partial Stripe payment data.
  • Attackers exploited CVE-2026-6875, a ServiceNow AI Platform sandbox escape flaw, for unauthenticated remote code execution days after disclosure.
  • Qilin ransomware actors exploited CVE-2026-0257, a Palo Alto GlobalProtect authentication bypass, to breach networks in multiple June 2026 intrusions.

Editorial Analysis

Two incidents today involve attackers abusing functionality already built into the target system rather than deploying custom malware: dealer-installed anti-theft devices sharing a single hardcoded key across millions of vehicles, and BitLocker combined with office printers to extort organisations in Latin America. Both lower the cost of attack by relying on components the victim already trusts.

Cisco and Google release competing small language models for vulnerability discovery on the same day — Antares and Gemini 3.5 Flash Cyber, respectively — suggesting vendors are converging on lightweight, task-specific models rather than general-purpose LLMs for this role.

German and US authorities dismantle the Kratos phishing-as-a-service platform, disabling more than 200 servers and arresting its administrator in Indonesia, while other actors continue to expand phishing capabilities through AiTM session theft and campaigns targeting software developers.

Highlights of the Day

Bluetooth Flaw in Dealer Anti-Theft Devices Exposes 2.2 Million Cars

UC San Diego researchers found at least 2.2 million vehicles fitted with dealer-installed KARR or SWDS anti-theft devices are vulnerable to a Bluetooth attack allowing remote door unlocking and engine immobilisation from up to five yards away. The devices, manufactured by Acrisure and installed mainly at Honda, Toyota, Mazda, Ford, and Jeep dealerships in Southern California since 2017, share a single hardcoded secure key across all units, letting attackers who crack it access every affected vehicle. Acrisure released a firmware patch on 20 July 2026, while researchers found similar devices from Rockledge may also be vulnerable but require an attacker to intercept and replay a driver's session.

Estée Lauder Confirms Data Theft From Oracle EBS Zero-Day Attack

Estée Lauder began notifying employees that personal data was stolen from its Oracle E-Business Suite HR system during a campaign that started in early August 2025. The Cl0p group exploited CVE-2025-61882, an unauthenticated remote code execution zero-day in Oracle EBS, with CrowdStrike dating in-the-wild exploitation to 9 August 2025 and Cl0p later leaking 870GB of allegedly stolen archive files. Compromised data included names, addresses, dates of birth, Social Security numbers, passport numbers, bank account numbers, health information, and payroll records, and the company is offering affected individuals 24 months of free identity monitoring.

Attackers Abuse BitLocker and Printers in Latin America Extortion Cases

Kaspersky's Securelist detailed two Latin American incidents in which attackers weaponised Windows' built-in BitLocker feature to encrypt drives, then printed ransom notes via compromised office printers rather than deploying dedicated ransomware. In a June case in Colombia, attackers exploited an internet-exposed RDP service to access an 8TB storage device and demanded $3,000, while endpoint protection had been disabled due to application compatibility issues. In a May case in Mexico, attackers exploited a misconfigured MSSQL service enabling xp_cmdshell command execution, then deployed multiple RMM tools including ManageEngine Endpoint Central, Mesh Agent, and Tactical RMM to enable BitLocker via Group Policy across systems synchronised with the domain controller.

AiTM Phishing Campaign Hijacks Sessions at Global Institutions

Infoblox detailed an adversary-in-the-middle phishing campaign targeting universities, enterprises, and multinational bodies including EU and UN agencies, using procurement-themed lures sent from compromised Outlook accounts. The actor rotates between AiTM phishing kits EvilProxy, FlowerStorm, and Kali365 to intercept MFA-protected session tokens in real time, routing victims through fake document portals, CAPTCHA stages, and cloned login pages impersonating Microsoft, OpenGov, and European financial institutions. The campaign relies on aged, likely compromised domains averaging over six years old, injected with a malicious PHP file, with associated phishing infrastructure following identifiable domain generation algorithm patterns.

Source: Infoblox

German Police Dismantle Kratos Phishing-as-a-Service Operation

German authorities, led by the Frankfurt Public Prosecutor's Office and the Federal Criminal Police Office, working with US law enforcement, took down the core infrastructure of the Kratos phishing-as-a-service platform. Indonesian authorities arrested the developer and technical administrator, while more than 200 servers were disabled and roughly 850 victims across 35 countries were identified. Kratos supplied a toolkit for building fake Microsoft authentication pages, was rented to over 1,800 criminal affiliates running around 15,000 phishing campaigns monthly, and had generated more than €300,000 since 2024.

Cisco Releases Small AI Models for Vulnerability Detection

Cisco released Antares-350M and Antares-1B, open-weight small language models designed to locate known vulnerabilities in existing codebases, available on Hugging Face to vetted users only. The models run locally rather than sending code to external servers, and Cisco said Antares-1B outperforms Google's Gemini 3 Pro while matching Z.ai's GLM-5.2 on its vulnerability-detection benchmark. Cisco stated the models scanned 500 repositories in 15 minutes at under $1 in cost, compared with roughly five hours and $100 to $150 for frontier models, and said a forthcoming 3-billion-parameter version will remain gated from public release.

Google Launches Gemini 3.5 Flash Cyber for Vulnerability Hunting

Google introduced Gemini 3.5 Flash Cyber, a lightweight cybersecurity model built on Flash and fine-tuned to find, validate, and patch software vulnerabilities, powering its CodeMender code security agent. The model will initially be restricted to governments and trusted partners through a limited-access pilot, while CodeMender's foundational capabilities become generally available via the Gemini Enterprise Agent Platform. On the V8 JavaScript engine, Google reported 3.5 Flash Cyber found 55 unique confirmed vulnerabilities against a fixed number of invocations, compared with 47 for mainline 3.5 Flash and 36 for Claude Opus 4.6, and separately used the model to uncover a memory-corruption flaw in a production service within two hours, generating a working remote-code-execution exploit that bypassed ASLR and W^X protections.

Daily Coverage

Developments
Servicenow CVE-2026-6875Qilin/Pan-Os ExploitationKratos TakedownSonicwall Sma Zero-Days
Vulnerabilities
CVE-2026-6875Servicenow Ai Platform (Critical)CVE-2026-50522Microsoft Sharepoint Enterprise Server 2016 16.0.0 (Critical)CVE-2026-63030Wordpress 6.9.0 (Critical)CVE-2026-60137Wordpress 6.8.0 (Medium)CVE-2026-15409Sma1000 12.4.3-03245 (Critical)CVE-2026-15410Sma1000 12.4.3-03245 (High)CVE-2026-0257Pan-Os 12.1.0 (Critical)CVE-2026-53359Linux 2032A93D66Fa282Ba0F2Ea9152Eeff9511Fa9A96CVE-2026-8933A Local Privilege Escalation Vulnerability Exists In Snap-Confine, A Set-Capabilities Core Component Used Internally By Canonical Snapd To Construct The Secure Execution Environment For Snap Applications. This Vulnerability Uniquely Affects Versions Of Snap-Confine Configured With Set-Capabilities (Rather Than Standard Set-Uid-Root Installations). Due To A Flaw In How Privilege Boundaries Or Security Sandboxes Are Initialized When The Binary Runs Under Limited Ambient Capabilities, A Local, Unpr…CVE-2025-61882Concurrent_Processing 12.2.14 (Critical)