Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (22 July 2026)
Published: Loading…
At a Glance
- German and US authorities dismantled the Kratos phishing-as-a-service platform, disabling over 200 servers and arresting its administrator in Indonesia.
- SonicWall SMA 1000 zero-days CVE-2026-15409 and CVE-2026-15410 were exploited from 22 June 2026, weeks before public disclosure.
- JadePuffer deployed ENCFORGE ransomware via a Langflow flaw to encrypt AI model weights, vector indexes, and training datasets.
- A data breach at AI music platform Suno exposed over 55 million user accounts, including emails and partial Stripe payment data.
- Attackers exploited CVE-2026-6875, a ServiceNow AI Platform sandbox escape flaw, for unauthenticated remote code execution days after disclosure.
- Qilin ransomware actors exploited CVE-2026-0257, a Palo Alto GlobalProtect authentication bypass, to breach networks in multiple June 2026 intrusions.
Editorial Analysis
Two incidents today involve attackers abusing functionality already built into the target system rather than deploying custom malware: dealer-installed anti-theft devices sharing a single hardcoded key across millions of vehicles, and BitLocker combined with office printers to extort organisations in Latin America. Both lower the cost of attack by relying on components the victim already trusts.
Cisco and Google release competing small language models for vulnerability discovery on the same day — Antares and Gemini 3.5 Flash Cyber, respectively — suggesting vendors are converging on lightweight, task-specific models rather than general-purpose LLMs for this role.
German and US authorities dismantle the Kratos phishing-as-a-service platform, disabling more than 200 servers and arresting its administrator in Indonesia, while other actors continue to expand phishing capabilities through AiTM session theft and campaigns targeting software developers.
Highlights of the Day
Bluetooth Flaw in Dealer Anti-Theft Devices Exposes 2.2 Million Cars
UC San Diego researchers found at least 2.2 million vehicles fitted with dealer-installed KARR or SWDS anti-theft devices are vulnerable to a Bluetooth attack allowing remote door unlocking and engine immobilisation from up to five yards away. The devices, manufactured by Acrisure and installed mainly at Honda, Toyota, Mazda, Ford, and Jeep dealerships in Southern California since 2017, share a single hardcoded secure key across all units, letting attackers who crack it access every affected vehicle. Acrisure released a firmware patch on 20 July 2026, while researchers found similar devices from Rockledge may also be vulnerable but require an attacker to intercept and replay a driver's session.
Estée Lauder Confirms Data Theft From Oracle EBS Zero-Day Attack
Estée Lauder began notifying employees that personal data was stolen from its Oracle E-Business Suite HR system during a campaign that started in early August 2025. The Cl0p group exploited CVE-2025-61882, an unauthenticated remote code execution zero-day in Oracle EBS, with CrowdStrike dating in-the-wild exploitation to 9 August 2025 and Cl0p later leaking 870GB of allegedly stolen archive files. Compromised data included names, addresses, dates of birth, Social Security numbers, passport numbers, bank account numbers, health information, and payroll records, and the company is offering affected individuals 24 months of free identity monitoring.
Attackers Abuse BitLocker and Printers in Latin America Extortion Cases
Kaspersky's Securelist detailed two Latin American incidents in which attackers weaponised Windows' built-in BitLocker feature to encrypt drives, then printed ransom notes via compromised office printers rather than deploying dedicated ransomware. In a June case in Colombia, attackers exploited an internet-exposed RDP service to access an 8TB storage device and demanded $3,000, while endpoint protection had been disabled due to application compatibility issues. In a May case in Mexico, attackers exploited a misconfigured MSSQL service enabling xp_cmdshell command execution, then deployed multiple RMM tools including ManageEngine Endpoint Central, Mesh Agent, and Tactical RMM to enable BitLocker via Group Policy across systems synchronised with the domain controller.
AiTM Phishing Campaign Hijacks Sessions at Global Institutions
Infoblox detailed an adversary-in-the-middle phishing campaign targeting universities, enterprises, and multinational bodies including EU and UN agencies, using procurement-themed lures sent from compromised Outlook accounts. The actor rotates between AiTM phishing kits EvilProxy, FlowerStorm, and Kali365 to intercept MFA-protected session tokens in real time, routing victims through fake document portals, CAPTCHA stages, and cloned login pages impersonating Microsoft, OpenGov, and European financial institutions. The campaign relies on aged, likely compromised domains averaging over six years old, injected with a malicious PHP file, with associated phishing infrastructure following identifiable domain generation algorithm patterns.
German Police Dismantle Kratos Phishing-as-a-Service Operation
German authorities, led by the Frankfurt Public Prosecutor's Office and the Federal Criminal Police Office, working with US law enforcement, took down the core infrastructure of the Kratos phishing-as-a-service platform. Indonesian authorities arrested the developer and technical administrator, while more than 200 servers were disabled and roughly 850 victims across 35 countries were identified. Kratos supplied a toolkit for building fake Microsoft authentication pages, was rented to over 1,800 criminal affiliates running around 15,000 phishing campaigns monthly, and had generated more than €300,000 since 2024.
Cisco Releases Small AI Models for Vulnerability Detection
Cisco released Antares-350M and Antares-1B, open-weight small language models designed to locate known vulnerabilities in existing codebases, available on Hugging Face to vetted users only. The models run locally rather than sending code to external servers, and Cisco said Antares-1B outperforms Google's Gemini 3 Pro while matching Z.ai's GLM-5.2 on its vulnerability-detection benchmark. Cisco stated the models scanned 500 repositories in 15 minutes at under $1 in cost, compared with roughly five hours and $100 to $150 for frontier models, and said a forthcoming 3-billion-parameter version will remain gated from public release.
Google Launches Gemini 3.5 Flash Cyber for Vulnerability Hunting
Google introduced Gemini 3.5 Flash Cyber, a lightweight cybersecurity model built on Flash and fine-tuned to find, validate, and patch software vulnerabilities, powering its CodeMender code security agent. The model will initially be restricted to governments and trusted partners through a limited-access pilot, while CodeMender's foundational capabilities become generally available via the Gemini Enterprise Agent Platform. On the V8 JavaScript engine, Google reported 3.5 Flash Cyber found 55 unique confirmed vulnerabilities against a fixed number of invocations, compared with 47 for mainline 3.5 Flash and 36 for Claude Opus 4.6, and separately used the model to uncover a memory-corruption flaw in a production service within two hours, generating a working remote-code-execution exploit that bypassed ASLR and W^X protections.
Daily Coverage