Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (28 July 2026)
Published: Loading…
At a Glance
- PoC exploit released for Certighost, CVE-2026-54121, a critical Active Directory Certificate Services domain-takeover flaw.
- DentaQuest data breach potentially exposed personal and dental health information of over 23 million people.
- ShinyHunters extortion gang claimed the Ernst & Young breach, alleging access to Jira, GitHub, and Azure via supply-chain credentials.
- Arista patched a maximum-severity command injection zero-day in VeloCloud Orchestrator that was actively exploited.
- Dysphoria IoT botnet expanded to over 200,000 devices using blockchain-based C2 and infected-device relays.
- Coca-Cola confirmed the Anubis group stole data from Fairlife during a ransomware attack.
Editorial Analysis
Today's incidents extract value from trusted relationships rather than raw technical exploitation. Ernst & Young's breach reportedly originated from compromised credentials linked to a third-party IT support platform, while DentaQuest's exposure of more than 23 million records and MCBS's 1.2TB data theft show extortion operations continuing to target healthcare and business-service providers at scale. Coca-Cola's confirmation that the Anubis group stole data from its Fairlife subsidiary adds another case of ransomware operators pairing data theft with disruption to increase pressure on victims.
Windows internals research published separately shows attackers and researchers abusing legitimate functionality rather than traditional software flaws. Certighost exploited an unauthenticated fallback in AD CS certificate enrolment to let a low-privileged user impersonate a Domain Controller. LegacyHive achieved persistence by manipulating offline registry hives to redirect profile paths during normal Windows sign-in. Neither required a memory-corruption bug; both relied on the CA and the profile-loading process accepting input they should have verified first.
Certighost was closed by adding target validation before the CA trusts a chase response. LegacyHive has no equivalent fix yet, since hive integrity isn't checked at load time. The gap between the two cases is a useful marker of how much work remains in hardening identity and profile-handling code against this class of abuse.
Highlights of the Day
Certighost Flaw Let Domain Users Impersonate Domain Controllers
Researchers detailed CVE-2026-54121, dubbed Certighost, an Active Directory Certificate Services flaw allowing a low-privileged user to impersonate a Domain Controller. The bug exploited an unauthenticated "chase" fallback, letting attackers direct the CA to a rogue host and return forged identity data for certificate issuance. The resulting certificate enabled DCSync access to domain secrets including the krbtgt account, before Microsoft patched the issue in July 2026.
Fairlife Resumes Most Production After Ransomware Attack
Coca-Cola's dairy subsidiary fairlife has restored the majority of production across its four US facilities. The company previously disclosed a ransomware incident involving unauthorised access to systems and theft of certain data. Retail availability remained largely unaffected due to existing inventory, and Coca-Cola stated the incident is not expected to materially impact its financial results.
ShinyHunters Claims Ernst & Young Breach via Supply Chain
Extortion group ShinyHunters claims responsibility for a breach at Ernst & Young, allegedly using credentials obtained through a supply-chain attack. EY disclosed that a third-party IT support ticket platform was compromised between March 28 and April 12, exposing client tax documents. The threat actors claim access to EY's Jira, GitHub, and Azure environments, though EY has not confirmed the group's involvement.
Dysphoria Botnet Uses Blockchain Domains to Hide C2
Researchers identified Dysphoria, a growing IoT botnet exceeding 200,000 bots that uses Ethereum and Solana domain services to conceal command-and-control infrastructure. The malware has evolved from DDoS-only functionality to include dedicated relay variants that turn infected devices into proxy nodes using UPnP port mapping. It spreads via Telnet/SSH brute-forcing and known IoT vulnerabilities, with confirmed daily active infections exceeding 240,000 devices globally.
New Windows PoC Hijacks Profiles via Offline Registry Edits
Researchers analysed LegacyHive, a proof-of-concept tool that abuses Windows profile initialisation rather than a traditional vulnerability. The technique offline-modifies a user's registry hive to redirect Local AppData into an attacker-controlled Object Manager namespace, then uses oplocks and CreateProcessWithLogonW to trigger profile loading and activate the redirection. LevelBlue reproduced the exploit on fully patched systems, noting it requires prior access to a low-privileged account and helper credentials.
CastleLoader Campaigns Add NeedleStealer Crypto Malware
Arctic Wolf Labs identified new CastleLoader campaigns delivering NeedleStealer, a framework with Rust and Golang components targeting cryptocurrency wallets and browsers. The Noidret campaign introduces a wallet spoofer harvesting seed phrases and a malicious browser extension installer, both first observed in this cluster. Researchers also found digitally signed installers using fraudulently obtained certificates, alongside NetSupport RAT and CastleStealer payloads deployed across related infection chains.
Daily Coverage