Ticker feed
Security researcher Justin O'Leary discovered serious "confused deputy" flaws in both Microsoft Azure and Google Cloud Platform earlier this year — and neither company properly acknowledged them. The Azure bug lets an attacker escalate from zero Kubernetes permissions to full cluster-admin access via the AKS backup service. The GCP flaw allows someone with basic Kubernetes access to silently crown themselves GCP Organization Owner, with the attack hidden from audit logs.
Microsoft appears to have quietly patched its flaw without disclosure. Google told O'Leary it might fix the issue but denied him a bug bounty. O'Leary plans to detail both vulnerabilities at Black Hat USA 2026.
Source: Dark Reading
Security researcher Justin O'Leary discovered serious "confused deputy" flaws in both Microsoft Azure and Google Cloud Platform earlier this year — and neither company properly acknowledged them. The Azure bug lets an attacker escalate from zero Kubernetes permissions to full cluster-admin access via the AKS backup service. The GCP flaw allows someone with basic Kubernetes access to silently crown themselves GCP Organization Owner, with the attack hidden from audit logs.
Microsoft appears to have quietly patched its flaw without disclosure. Google told O'Leary it might fix the issue but denied him a bug bounty. O'Leary plans to detail both vulnerabilities at Black Hat USA 2026.
Source: Dark Reading
Coca-Cola has confirmed a data breach tied to a ransomware attack on its dairy subsidiary Fairlife. The company initially disclosed the intrusion on July 16, suspending production at four U.S. Fairlife facilities. The Anubis ransomware group claimed responsibility on July 20, alleging it stole 1 TB of confidential data. Most production has since resumed, and Fairlife product availability remains largely unaffected. Coca-Cola says the breach won't materially impact finances, though it hasn't specified what data was taken. Anubis — active since December 2024 and known for double-extortion tactics — threatened to publish the stolen data publicly if no ransom is paid.
Source: SecurityWeek
Coca-Cola has confirmed a data breach tied to a ransomware attack on its dairy subsidiary Fairlife. The company initially disclosed the intrusion on July 16, suspending production at four U.S. Fairlife facilities. The Anubis ransomware group claimed responsibility on July 20, alleging it stole 1 TB of confidential data. Most production has since resumed, and Fairlife product availability remains largely unaffected. Coca-Cola says the breach won't materially impact finances, though it hasn't specified what data was taken. Anubis — active since December 2024 and known for double-extortion tactics — threatened to publish the stolen data publicly if no ransom is paid.
Source: SecurityWeek
CISA has added six Microsoft zero-day vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after confirming active exploitation in the wild. The flaws span Windows Shell, MSHTML, Office Word, Desktop Window Manager, Remote Access Connection Manager, and Remote Desktop Services — covering privilege escalation, security bypasses, and denial-of-service attacks.
Microsoft released patches in its February 2026 Patch Tuesday. Federal agencies must remediate by CISA's deadlines under Binding Operational Directive 22-01. Nation-state groups, including China's Salt Typhoon, are among those exploiting similar flaws. All organizations should apply patches immediately and audit exposure across Office, RDS, and remote access tools.
Source: Cybersecurity News
CISA has added six Microsoft zero-day vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after confirming active exploitation in the wild. The flaws span Windows Shell, MSHTML, Office Word, Desktop Window Manager, Remote Access Connection Manager, and Remote Desktop Services — covering privilege escalation, security bypasses, and denial-of-service attacks.
Microsoft released patches in its February 2026 Patch Tuesday. Federal agencies must remediate by CISA's deadlines under Binding Operational Directive 22-01. Nation-state groups, including China's Salt Typhoon, are among those exploiting similar flaws. All organizations should apply patches immediately and audit exposure across Office, RDS, and remote access tools.
Source: Cybersecurity News
A supply chain attack hit Jscrambler's popular NPM package on July 11, after a threat actor used compromised publishing credentials to push malicious versions containing hidden malware. Versions 8.16 through 8.20 were affected, along with several dependent packages including jscrambler-webpack-plugin and gulp-jscrambler. The tainted versions were downloaded 1,479 times before being deprecated.
The malware, written in Rust, steals credentials, crypto wallet seed phrases, browser data, and cloud API keys — then exfiltrates everything over encrypted TLS connections. Jscrambler has revoked all credentials and released clean version 8.22. If you installed any affected versions, remove them immediately, scan for malware, and rotate all secrets and API keys.
Source: SecurityWeek
A supply chain attack hit Jscrambler's popular NPM package on July 11, after a threat actor used compromised publishing credentials to push malicious versions containing hidden malware. Versions 8.16 through 8.20 were affected, along with several dependent packages including jscrambler-webpack-plugin and gulp-jscrambler. The tainted versions were downloaded 1,479 times before being deprecated.
The malware, written in Rust, steals credentials, crypto wallet seed phrases, browser data, and cloud API keys — then exfiltrates everything over encrypted TLS connections. Jscrambler has revoked all credentials and released clean version 8.22. If you installed any affected versions, remove them immediately, scan for malware, and rotate all secrets and API keys.
Source: SecurityWeek
A misconfigured Python HTTP server in Budapest with directory listing enabled handed researchers a full look inside three active phishing campaigns. The exposed server at 185.163.204.7 contained credential logs, phishing configs, RMM installers, combolists, and even the operator's own Telegram session files.
Three distinct threat actors were identified: codemado, an Egyptian operator running Microsoft 365 AiTM attacks since March 2026; mail-argenta, a Nigerian operator whose own credentials appeared in infostealer logs; and saroula01, whose Device Code Flow campaign quietly accumulated 218 victims across 12 countries over a year.
All three built MFA-bypassing infrastructure from public GitHub repositories. The barrier to running these attacks is effectively zero.
Source: Lexfo Security Blog
A misconfigured Python HTTP server in Budapest with directory listing enabled handed researchers a full look inside three active phishing campaigns. The exposed server at 185.163.204.7 contained credential logs, phishing configs, RMM installers, combolists, and even the operator's own Telegram session files.
Three distinct threat actors were identified: codemado, an Egyptian operator running Microsoft 365 AiTM attacks since March 2026; mail-argenta, a Nigerian operator whose own credentials appeared in infostealer logs; and saroula01, whose Device Code Flow campaign quietly accumulated 218 victims across 12 countries over a year.
All three built MFA-bypassing infrastructure from public GitHub repositories. The barrier to running these attacks is effectively zero.
Source: Lexfo Security Blog
Security firm Socket has uncovered "Operation Muck and Load" — a campaign using 222 GitHub repositories across 190 accounts to distribute Windows malware. Active since January 24, 2026, the threat actor published over 1,200 package versions, 700 of which are malicious.
The attack disguises a Go module as a legitimate DNS scanning tool. Hidden PowerShell code then pulls encrypted payloads from dead-drop platforms including Pastebin, YouTube, Instagram, Telegram, and Google Docs — making it harder to shut down.
Final payloads include AsyncRAT, Quasar RAT, Vidar infostealer, and XMRig cryptominers. GitHub users pulling Go dependencies are directly at risk.
Source: SecurityWeek
Security firm Socket has uncovered "Operation Muck and Load" — a campaign using 222 GitHub repositories across 190 accounts to distribute Windows malware. Active since January 24, 2026, the threat actor published over 1,200 package versions, 700 of which are malicious.
The attack disguises a Go module as a legitimate DNS scanning tool. Hidden PowerShell code then pulls encrypted payloads from dead-drop platforms including Pastebin, YouTube, Instagram, Telegram, and Google Docs — making it harder to shut down.
Final payloads include AsyncRAT, Quasar RAT, Vidar infostealer, and XMRig cryptominers. GitHub users pulling Go dependencies are directly at risk.
Source: SecurityWeek
Accenture confirmed a data breach this week after a hacker posted on PwnForums claiming to have stolen 35 gigabytes of internal data — including Azure access keys, SSH and RSA keys, configuration files, and source code. The threat actor posted a screenshot of a private Azure DevOps repository as proof and listed the data for sale.
Accenture said the incident has been remediated and hasn't affected operations, but offered no further details. Security experts warn the stolen data could serve as a roadmap for future attacks, given Accenture's deep access to major enterprise systems worldwide.
Source: SecurityWeek
Accenture confirmed a data breach this week after a hacker posted on PwnForums claiming to have stolen 35 gigabytes of internal data — including Azure access keys, SSH and RSA keys, configuration files, and source code. The threat actor posted a screenshot of a private Azure DevOps repository as proof and listed the data for sale.
Accenture said the incident has been remediated and hasn't affected operations, but offered no further details. Security experts warn the stolen data could serve as a roadmap for future attacks, given Accenture's deep access to major enterprise systems worldwide.
Source: SecurityWeek
A massive global cybercrime sweep has wrapped up with 5,811 arrests and $293 million in intercepted illicit assets. Operation First Light 2026 ran from January 15 to April 30, 2026, pulling in law enforcement from 97 countries under Interpol's coordination — with funding from China's Ministry of Public Security.
The operation targeted social engineering scams like romance fraud and business email compromise schemes. Authorities froze over 31,000 bank accounts, identified 15,606 suspects, and uncovered 142,000 victims worldwide. One standout bust in Eswatini revealed scammers running a full replica Brazilian police station — fake uniforms and all — to trick victims into transferring money.
Source: Infosecurity Magazine
A massive global cybercrime sweep has wrapped up with 5,811 arrests and $293 million in intercepted illicit assets. Operation First Light 2026 ran from January 15 to April 30, 2026, pulling in law enforcement from 97 countries under Interpol's coordination — with funding from China's Ministry of Public Security.
The operation targeted social engineering scams like romance fraud and business email compromise schemes. Authorities froze over 31,000 bank accounts, identified 15,606 suspects, and uncovered 142,000 victims worldwide. One standout bust in Eswatini revealed scammers running a full replica Brazilian police station — fake uniforms and all — to trick victims into transferring money.
Source: Infosecurity Magazine
A sophisticated phishing campaign is targeting marketing professionals by impersonating major brands like Coca-Cola, Netflix, OpenAI, McKinsey & Company, and Louis Vuitton. First spotted by Team Cymru's Will Thomas, the attackers send personalized job recruitment emails via legitimate HR platform PeopleForce, then route victims through nested redirects — bouncing through Salesforce's ExactTarget and real estate CRM Wise Agent — before landing on a fake Google sign-in page hosted on Netlify.
The multi-hop redirect chain bypasses basic email filters and builds false trust. Over 30 malicious domains have been identified. Password managers and advanced web filtering are recommended defenses.
Source: Dark Reading
A sophisticated phishing campaign is targeting marketing professionals by impersonating major brands like Coca-Cola, Netflix, OpenAI, McKinsey & Company, and Louis Vuitton. First spotted by Team Cymru's Will Thomas, the attackers send personalized job recruitment emails via legitimate HR platform PeopleForce, then route victims through nested redirects — bouncing through Salesforce's ExactTarget and real estate CRM Wise Agent — before landing on a fake Google sign-in page hosted on Netlify.
The multi-hop redirect chain bypasses basic email filters and builds false trust. Over 30 malicious domains have been identified. Password managers and advanced web filtering are recommended defenses.
Source: Dark Reading
Cybersecurity firm Sysdig has documented what it calls the first agentic ransomware attack — where an AI agent autonomously managed an entire extortion operation from start to finish. The late June 2026 attack, attributed to a financially motivated group called JadePuffer, exploited a Langflow vulnerability to reach a MySQL and Alibaba Nacos production server.
The AI agent ran over 600 payloads, self-corrected errors in 31 seconds, and tapped models from OpenAI, Anthropic, DeepSeek, and Gemini. A human still set up the infrastructure, but the AI handled the heavy lifting. "The skill floor for running a full ransomware operation just dropped," warned Sysdig's Michael Clark.
Source: CyberScoop
Cybersecurity firm Sysdig has documented what it calls the first agentic ransomware attack — where an AI agent autonomously managed an entire extortion operation from start to finish. The late June 2026 attack, attributed to a financially motivated group called JadePuffer, exploited a Langflow vulnerability to reach a MySQL and Alibaba Nacos production server.
The AI agent ran over 600 payloads, self-corrected errors in 31 seconds, and tapped models from OpenAI, Anthropic, DeepSeek, and Gemini. A human still set up the infrastructure, but the AI handled the heavy lifting. "The skill floor for running a full ransomware operation just dropped," warned Sysdig's Michael Clark.
Source: CyberScoop