Black Arrow Cyber Threat Intelligence Briefing 17 July 2026

Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.

Executive Summary

We start this week’s review of cyber security in the specialist and general media with news that the UK Government plans to encourage households to keep emergency supplies in case a cyber attack or other crisis disrupts essential services. This aligns with previous reports in which the Government called on businesses to prepare to continue operating if an incident causes the loss of access to technology.

We also report that CISOs are concerned that leadership teams do not fully understand the cyber risks associated with employee behaviour. Other stories highlight evolving phishing techniques, the need to manage a higher volume of security updates, and the continuing development of AI-enabled attacks and ClickFix social engineering campaigns.

A key step in managing these risks is ensuring that leadership teams understand their cyber responsibilities, can oversee risk management effectively and have rehearsed plans for responding to an incident. Contact us to hear how we support organisations across different sectors and of different sizes to achieve this.


Top Cyber Stories of the Last Week

UK Households Told to Stockpile Food, Water and Medicines as Russia Cyber Attack Threat Grows

The UK Government is preparing to launch a national resilience campaign encouraging households to keep basic supplies such as food, water and medicines in case essential services are disrupted by events including a cyber attack. The initiative follows growing concern over threats to critical national infrastructure, including energy, water and communications networks, alongside plans for a national exercise to test the Government's response to a large-scale hybrid attack. For business leaders, the campaign and exercise reinforce the need to consider how disruption to power, water or communications could affect organisational continuity.

https://www.ibtimes.co.uk/uk-government-emergency-preparedness-campaign-1808763

75% CISOs Fear Executives Don’t Understand Cyber Security Risks Employees Face

MetaCompliance has found that many organisations face a growing gap between cyber security leaders and senior executives, with 78% of Chief Information Security Officers believing board-level decision makers do not fully understand the cyber risks created by employee behaviour. Almost 80% said executive support for security awareness declines over time, while 40% are concerned employees are sharing sensitive information with generative AI tools. As AI enables more convincing fraudulent communications at scale, sustained executive engagement and clear governance are becoming essential to strengthening organisational resilience.

https://www.infosecurity-magazine.com/news/cisos-fear-execs-dont-understand/

Finance Phishing Works Because It Sounds Boringly Normal

Finance-themed phishing is a common initial access route because malicious messages closely resemble routine business correspondence and fit expected finance and procurement workflows. Cofense found that 59% to 79% of subject lines in campaigns against financial organisations referred to routine operations, while 21% to 41% used urgency. By imitating normal business processes, including invoices, payment confirmations and supplier enquiries, these emails are more likely to evade automated email security tools and persuade employees to open attachments or click malicious links.

https://www.helpnetsecurity.com/2026/07/16/cofense-finance-phishing-tactics-report/

Microsoft Warns of Increase in Number of Security Updates

Microsoft is using AI to identify software weaknesses across Windows more quickly, meaning organisations should expect a higher number of security updates in future. Microsoft says the increase reflects improved identification and remediation of weaknesses. Its multi-model scanning process validates potential findings before they reach engineers, aiming to reduce false positives and shorten the window in which zero-day vulnerabilities can be exploited. Human experts will continue to oversee the process. Business leaders should therefore expect patching demand to increase and ensure that update processes can absorb a higher volume of security releases.

https://www.infosecurity-magazine.com/news/microsoft-increase-number-security/

Destructive Windows Backdoor Stuffs Multiple Wipers and Ransomware Code into a Single Package

Microsoft has identified a new type of destructive malware that combines several attack techniques into a single tool, giving criminals greater flexibility once they gain access to a network. Rather than simply demanding payment, it can overwrite storage, encrypt files so they cannot be recovered, steal information, record user activity and disable recovery features. For business leaders, the combined capabilities broaden the potential impact of a compromise beyond data theft to remote control, permanent system damage and wider operational disruption.

https://www.theregister.com/security/2026/07/10/destructive-windows-backdoor-stuffs-multiple-wipers-and-ransomware-code-into-a-single-package/5270053

Identity Attacks Overtake Exploits as Top Ransomware Cause

Identity-related attacks have become the leading cause of ransomware, overtaking software vulnerabilities for the first time in three years. Sophos found that malicious emails, phishing and stolen login details accounted for almost three quarters of ransomware incidents, while software vulnerabilities fell to 18% of cases. Although 97% of organisations affected by credential theft had multi-factor authentication in place, attackers were still able to gain access, highlighting that this important security control must be fully deployed and supported by additional measures to detect and respond to suspicious activity.

https://www.darkreading.com/identity-access-management-security/identity-attacks-overtake-exploits-top-ransomware-cause

Companies Keep Getting Breached by Vulnerabilities They Already Knew About

A survey of 300 IT and cyber security leaders found that while organisations have become highly effective at identifying security weaknesses, many still struggle to fix them quickly. Around eight in ten experienced a security incident in the past year linked to a vulnerability already in their inventory, and about half said the relevant weakness had been known for 30 to 90 days. The biggest barriers were unclear ownership, competing business priorities and lengthy approval processes. Organisations requiring a verified follow-up scan before closing a vulnerability reported substantially fewer incidents involving weaknesses they already knew about.

https://www.helpnetsecurity.com/2026/07/16/ciso-vulnerability-remediation-gap/

ClickFix Is Changing the Economics of Social Engineering

ClickFix has evolved into a highly organised cyber crime service that allows even low skilled attackers to launch convincing social engineering campaigns. Rather than exploiting software flaws, victims are tricked into running malicious commands themselves after visiting fake CAPTCHA pages, browser updates or IT support prompts. Attack kits are available on underground forums from around $250 per month, driving a sharp rise in attacks. Researchers also identified 123 previously undetected ClickFix pages, highlighting how these campaigns can bypass traditional security tools and reinforcing the importance of user awareness alongside technical controls.

https://www.helpnetsecurity.com/2026/07/15/clickfix-social-engineering-attacks-report/

AI, Once Relegated to Helping Hackers with Certain Tasks, Can Now Power Every Stage of a Cyber Attack

Artificial intelligence is now being used across every stage of a cyber attack, marking a significant shift from simply assisting with isolated tasks. Research found that criminal groups are using AI to identify security weaknesses, generate malicious code, automate attacks and move through victim networks with far less human involvement. In one case, a single developer used AI to produce around 88,000 lines of working code in under a week. As AI accelerates both the speed and scale of attacks, organisations face much shorter windows to detect and respond to emerging threats.

https://www.nextgov.com/cybersecurity/2026/07/ai-once-relegated-helping-hackers-certain-tasks-can-now-power-every-stage-cyberattack/414744/

Ransomware Victims Rise 43% as AI Becomes a Productivity Tool for Threat Actors, GuidePoint Security Finds

GuidePoint Security has reported that ransomware activity has continued to rise, with threat actors claiming 2,279 victims, up 7% on the previous quarter and 43% compared with a year earlier. Researchers identified a record 91 active ransomware groups operating across 108 countries. AI is helping criminals process stolen information and tailor their extortion tactics, rather than creating fundamentally different ransomware attacks. Manufacturing remained the most affected sector, accounting for almost 15% of reported incidents. Business leaders should combine recovery planning with measures to understand what sensitive data could be exposed and reduce how attackers could use it as leverage.

https://www.businesswire.com/news/home/20260709079338/en/Ransomware-Victims-Rise-43-as-AI-Becomes-a-Productivity-Tool-for-Threat-Actors-GuidePoint-Security-Finds

Russian Hackers Exploit Weak Router Security to Breach Critical Infrastructure, Western Allies Warn

Western governments have warned that Russian state-backed hackers continue to target critical infrastructure by exploiting poorly secured routers and other internet connected network devices. The activity has affected organisations across financial services, healthcare, communications, defence, energy, and government. The warning follows an attempted cyber attack against Poland's power grid that could have disrupted electricity supplies to around 500,000 people. The campaign highlights the importance of replacing default passwords, keeping network equipment up to date and monitoring internet facing systems as closely as other critical business assets.

https://www.nextgov.com/cybersecurity/2026/07/russian-hackers-exploit-weak-router-security-breach-critical-infrastructure-western-allies-warn/414735/

UK Firms Make Cyber Resilience Measurable

ISG reports that UK organisations are embedding cyber security into wider business resilience, with boards increasingly expecting measurable evidence that security investments reduce risk and improve response times. As AI is used by both defenders and attackers, organisations are adopting AI supported detection while maintaining human oversight and clear decision making. Growing concerns over supply chain risk and critical infrastructure are also driving demand for continuous monitoring, real time reporting and integrated security services that strengthen resilience and support regulatory expectations.

https://www.businesswire.com/news/home/20260710009829/en/U.K.-Firms-Make-Cyber-Resilience-Measurable



Threats

Ransomware, Extortion and Destructive Attacks

Destructive Windows backdoor stuffs multiple wipers and ransomware code into a single package

Ransomware Victims Rise 43% as AI Becomes a Productivity Tool for Threat Actors, GuidePoint Security Finds

Ransomware Never Stopped: Over 9,000 Confirmed Attacks Since 2018 - Security Affairs

UK Cyber Attacks Climb 34% as Ransomware Leadership Shifts, Check Point Research Reveals - IT Security Guru

Ransom demands are down, email is the top way attackers get in - Help Net Security

Identity Attacks Overtake Exploits as Top Ransomware Cause

Extortion crew hijacks Microsoft 365 accounts via fake passkey setup - Help Net Security

New Ransomware Exploits Malicious Driver to Remove Security Protection - Infosecurity Magazine

Microsoft uncovers GigaWiper, a backdoor designed for destruction on demand | CSO Online

GigaWiper: The Windows Backdoor Built to Spy, Fake Ransomware and Erase Disks |

New Qilin Ransomware Attack Uses DCSync Technique to Abuse Active Directory Replication Protocols

CitrixBleed 2 exploited in repeatable attack chain culminating in DragonForce ransomware, researchers find - IT Security Guru

Everest Ransomware Claims 1 TB Data Theft But Encryptor Shows No Exfiltration Code

This ransomware negotiator was paid to fight hackers, he was secretly working with them instead | TechSpot

Ryuk ransomware member pleads guilty in the US, faces 15 years in prison

Ransomware ecosystem grows, but ‘four-headed monster’ dominates - TechCentral.ie

This one cyber crime group accounted for nearly a fifth of all ransomware attacks in June | IT Pro

U.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware Losses

Former ransomware negotiator gets 4 years for BlackCat attacks

Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity

Ransomware and Destructive Attack Victims

Centers Laboratory Data Breach Affects 540,000 Individuals - SecurityWeek

Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims - SecurityWeek

Phishing & Email Based Attacks

Ransom demands are down, email is the top way attackers get in - Help Net Security

Phishing Toolkits Harvest Entra Tokens in Real Time

New phishing kits target Microsoft 365 accounts, evade MFA

Finance phishing works because it sounds boringly normal - Help Net Security

Americans Are Ignoring Scam Calls, But Phishing Emails Still Fool Many

New phishing campaign hits LastPass, Bitwarden users - password manager customers warned not to fall for this scam | TechRadar

Phishing Campaign Abuses eCards to Deploy RMM Tools - Infosecurity Magazine

Open Directory Exposes Three Evilginx Phishing Operators - Infosecurity Magazine

Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft

Other Social Engineering

ClickFix and removable media lead malware delivery methods | TechTarget

ClickFix's Mushrooming Ecosystem Demands New Defense Tactics

ClickFix is changing the economics of social engineering - Help Net Security

Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers - SecurityWeek

Is that QR code a trap? How to spot quishing scams before it's too late | ZDNET

QR Codes Are the New Security Blindspots That Steal Your Card Details and Deliver Malware

Tech support scam caused massive data breach at Australian airline Qantas

Americans Are Ignoring Scam Calls, But Phishing Emails Still Fool Many

LastPass, Bitwarden users targeted with fake security alerts

Scammers are using FaceTime to steal bank account passwords - CBS News

2FA/MFA

Only 28% of financial workforce MFA is phishing-resistant - Help Net Security

AML/CFT/Money Laundering/Terrorist Financing/Sanctions

EU, UK sanction Russian cyberespionage networks over destructive attacks | CyberScoop

EU Targets Russian Intelligence Officers Accused of Running a Yearslong Cyber Spying Campaign - SecurityWeek

Money launderer accused of stealing seized crypto while in prison

U.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware Losses

EU sanctions Russian tech giant VK, state-backed messenger Max, and FSB-linked cyberattack network — The Insider

U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support

Artificial Intelligence

Ransomware Victims Rise 43% as AI Becomes a Productivity Tool for Threat Actors, GuidePoint Security Finds

99.9% of fixable AI vulnerabilities remain unpatched - Help Net Security

AI Is Changing Financial Services Security Faster Than Many Organisations Can Keep Up | Scoop News

Enterprises are rethinking where their AI applications run - Help Net Security

AI, once relegated to helping hackers with certain tasks, can now power every stage of a cyberattack - Nextgov/FCW

Huntress Uncovers 'Vibe-Coded' Malware Used to Map Active Directory Environments - IT Security Guru

A Hacker Used AI to Compromise an AWS Cloud Environment in Just 72 Hours

AI Agents Are a New Kind of Identity & Most Orgs Aren't Ready

Why the Next Big Enterprise Security Breach Will Start With an AI Agent Nobody Authorized - QR Code Press

Risk of democratic interference added to National Risk Register - GOV.UK

What are 'context bombs'? Get familiar with the new cybersecurity tool. | Mashable

AI-assisted Software Engineering Is Creating A New Delivery Paradox

Vibe-Coded Malware Caught in Active Directory Attack - Infosecurity Magazine

EU unveils AI cybersecurity action plan for AI and Cybersecurity

You Can't Secure Your Agents If You Can't See Them

The agents you use to beef up cybersecurity could be turned against you – ‘Friendly Fire’ attacks can manipulate OpenAI and Anthropic models into running malicious code | IT Pro

Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws

'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets

New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email

'The bots are alive!' Jailbroken Gemini spun up new C2 server for Russian fraudster in just 6 minutes

What is AI squatting? An emerging cyber threat targeting AI hallucinations | Artificial Intelligence News - Business Standard

Cybercriminals Plant Malicious AI Agents in Open Source Tools - Infosecurity Magazine

AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique - SecurityWeek

UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge - SecurityWeek

Attack on Amazon Bedrock-linked AI gateway highlights new cloud security risk | CSO Online

Why conversational AI is redefining your security perimeter | TechTarget

Musk promises purge after Grok Build caught sending entire repos to the cloud

Tech-xit? UK Steps Up Sovereignty Push Amid AI Strife

Bots/Botnets

'HalluSquatting' Turns AI Hallucinations Into Botnet Delivery Mechanism - SecurityWeek

Careers, Roles, Skills, Working in Cyber and Information Security

ISC2 Research Finds AI Is Reshaping Cybersecurity Roles and Increasing Human Oversight

Cloud/SaaS

Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers - SecurityWeek

Phishing Toolkits Harvest Entra Tokens in Real Time

New phishing kits target Microsoft 365 accounts, evade MFA

Extortion crew hijacks Microsoft 365 accounts via fake passkey setup - Help Net Security

Progress Told ShareFile Customers to Pull the Plug on Their Servers. Here's What We Know.

A Hacker Used AI to Compromise an AWS Cloud Environment in Just 72 Hours

European Companies Have a Collaboration Security Confidence Gap

Attack on Amazon Bedrock-linked AI gateway highlights new cloud security risk | CSO Online

Novel OAuth Client ID Spoofing Technique Targets Cloud Environments - Infosecurity Magazine

Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain

Money launderer accused of stealing seized crypto while in prison

U.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware Losses

Attackers Exploit 'Ill Bloom' Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets

Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks

London teenager who offered crypto advice to terror groups convicted | The Standard

OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps

Cyber Crime, Organised Crime & Criminal Actors

New tutorials on underground hacking forums have roughly doubled - Help Net Security

London teenager who offered crypto advice to terror groups convicted | The Standard

Dutch police bust investment fraud ring stealing over €100 million

Spanish Police take down €140 million cyber fraud ring, arrest four

Police Disrupt a €140M Euro Cyber Fraud Ring in Spain

Russian Cybercrime Trio Indicted In Alleged $62M Scheme

Teen hackers jailed after live streaming cyber attack on TfL - BBC News

Tracking Peter Stokes and The Com: Allison Nixon and Her Work Unmasking Cybercriminals

Data Breaches/Leaks

Police suspects Dutch hackers were involved in Odido breach

Finland issues wanted notice for hacker behind massive psychotherapy data breach | The Record from Recorded Future News

23andMe reaches $18 million settlement with states for massive breach | The Record from Recorded Future News

Lidl Confirms Data Breach After Third-Party IT Provider Hack - IT Security Guru

Tech support scam caused massive data breach at Australian airline Qantas

Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims - SecurityWeek

CISA credential leak prompts tighter security measures | CyberScoop

ServiceNow's requires_authentication=false: The One Boolean That Exposed Enterprise Data Worldwide - Security Boulevard

Musk promises purge after Grok Build caught sending entire repos to the cloud

Centers Laboratory Data Breach Affects 540,000 Individuals - SecurityWeek

Data/Digital Sovereignty

Tech-xit? UK Steps Up Sovereignty Push Amid AI Strife

Denial of Service/DoS/DDoS

148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet

Encryption

MEPs fail to prevent Chat Control snoopfest revival

Q&A: Businesses Are Running Out of Time to Prepare for the Quantum Threat, Warns Moona Ederveen-Schneider - IT Security Guru

Fraud, Scams and Financial Crime

Scammers are now cloning trusted news websites to steal your money - Digital Trends

UK charges five persons linked to fraud platform behind more than a million scam calls - Help Net Security

Spanish Police take down €140 million cyber fraud ring, arrest four

Dutch police bust investment fraud ring stealing over €100 million

Americans Are Ignoring Scam Calls, But Phishing Emails Still Fool Many

UK charges suspects linked to Russian Coms call spoofing platform

Tech support scam caused massive data breach at Australian airline Qantas

Scammers are using FaceTime to steal bank account passwords - CBS News

Identity and Access Management

Huntress Uncovers 'Vibe-Coded' Malware Used to Map Active Directory Environments - IT Security Guru

Identity Attacks Overtake Exploits as Top Ransomware Cause

AI Agents Are a New Kind of Identity & Most Orgs Aren't Ready

Vibe-Coded Malware Caught in Active Directory Attack - Infosecurity Magazine

A wolf in sheep’s clothing | Professional Security Magazine

Insider Risk and Insider Threats

75% CISOs Fear Executives Don’t Understand Cybersecurity Risks - Infosecurity Magazine

This ransomware negotiator was paid to fight hackers, he was secretly working with them instead | TechSpot

The negotiator was the leak: insider who betrayed ransomware victims gets 70 months | HaystackID - JDSupra

Law Enforcement Action and Take Downs

INTERPOL Operation First Light Nets 5,811 Arrests and Seizes $293 Million

This ransomware negotiator was paid to fight hackers, he was secretly working with them instead | TechSpot

Third US Security Expert Sentenced to Prison for Helping Ransomware Gang - SecurityWeek

UK charges five persons linked to fraud platform behind more than a million scam calls - Help Net Security

Spanish Police take down €140 million cyber fraud ring, arrest four

Dutch police bust investment fraud ring stealing over €100 million

UK charges suspects linked to Russian Coms call spoofing platform

Police suspects Dutch hackers were involved in Odido breach

London teenager who offered crypto advice to terror groups convicted | The Standard

Teen hackers jailed after live streaming cyber attack on TfL - BBC News

Ryuk ransomware member pleads guilty in the US, faces 15 years in prison

764 splinter group leader sentenced to 40 years in jail | CyberScoop

Finland issues wanted notice for hacker behind massive psychotherapy data breach | The Record from Recorded Future News

U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support

Welsh Doxbin admin jailed for egging on swatters from behind a screen

Linux and Open Source

Cybercriminals Plant Malicious AI Agents in Open Source Tools - Infosecurity Magazine

OpenMandriva Linux says contributor tried to sabotage the project

Malware

Destructive Windows backdoor stuffs multiple wipers and ransomware code into a single package

GigaWiper: The Windows Backdoor Built to Spy, Fake Ransomware and Erase Disks |

Huntress Uncovers 'Vibe-Coded' Malware Used to Map Active Directory Environments - IT Security Guru

ClickFix and removable media lead malware delivery methods | TechTarget

CrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper

New CrashStealer malware poses as Apple crash reporting tool

New MacOS Malware Exploits Legitimate Developer ID - Infosecurity Magazine

Threat actor impersonated hundreds of brands on GitHub to push infostealer malware - Help Net Security

Windows Bind Link Attacks Can Hide Malware From EDR Tools - SecurityWeek

Vibe-Coded Malware Caught in Active Directory Attack - Infosecurity Magazine

148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet

'HalluSquatting' Turns AI Hallucinations Into Botnet Delivery Mechanism - SecurityWeek

AI-assisted Software Engineering Is Creating A New Delivery Paradox

The agents you use to beef up cybersecurity could be turned against you – ‘Friendly Fire’ attacks can manipulate OpenAI and Anthropic models into running malicious code | IT Pro

222 GitHub Repositories Linked to Fake Go Package Malware Operation

Hackers backdoor Jscrambler npm package with infostealer malware

Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found

LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts

OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps

Compromised npm Packages in the AsyncAPI Namespace Deliver M...

Mobile

RedHook Android malware now uses Wireless ADB for shell access

US personnel faced phone-tracking campaign during Iran war – FT | Iran International

Models, Frameworks and Standards

EU sues 4 nations for leaving hospitals, banks unprotected | Cybernews

EU unveils AI cybersecurity action plan for AI and Cybersecurity

Where do SMEs stand in preparing for the Cyber Resilience Act? | ENISA

New AI Security Charter Backed by Over 70 Cyber Firms - Infosecurity Magazine

UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge - SecurityWeek

Cybersecurity Noncompliance Just Triggered Another False Claims Act Settlement for a Defense Contractor

Pentagon announces 'immediate suspension' of CMMC Phase II mandates - Breaking Defense

Passwords, Credential Stuffing & Brute Force Attacks

A Hacker Used AI to Compromise an AWS Cloud Environment in Just 72 Hours

Microsoft Entra ID authentication overhaul to start in September 2026 - Help Net Security

Don't let an AI chatbot pick your password, ever | ZDNET

Regulations, Fines and Legislation

EU sues 4 nations for leaving hospitals, banks unprotected | Cybernews

Government Updates UK’s National Risk Register with Cyber Warnings - Infosecurity Magazine

Where do SMEs stand in preparing for the Cyber Resilience Act? | ENISA

23andMe reaches $18 million settlement with states for massive breach | The Record from Recorded Future News

Risk of democratic interference added to National Risk Register - GOV.UK

MEPs fail to prevent Chat Control snoopfest revival

Nobody talks about what happens when the agency writing federal cybersecurity standards has no director, no playbook, and a third fewer staff — CISA's May 2026 leak just made it visible - Silicon Canals

More Countries Jump on the Social Media 'Ban Wagon'

Cyber Security Bill amendment to be reintroduced in House of Lords — Hong Kong Watch

Cybersecurity Noncompliance Just Triggered Another False Claims Act Settlement for a Defense Contractor

Pentagon announces 'immediate suspension' of CMMC Phase II mandates - Breaking Defense

OpenAI releases latest ChatGPT model after delay over White House cybersecurity concerns | ChatGPT | The Guardian

Social Media

More Countries Jump on the Social Media 'Ban Wagon'

Software Supply Chain

222 GitHub Repositories Linked to Fake Go Package Malware Operation

Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install

Cybercriminals Plant Malicious AI Agents in Open Source Tools - Infosecurity Magazine

AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique - SecurityWeek

Ghost Accounts Abuse GitHub API in Mass Recon Campaign - SecurityWeek

Why SBOMs, signing, and provenance still don't tell you if software is safe - Help Net Security

Supply Chain and Third Parties

Lidl Confirms Data Breach After Third-Party IT Provider Hack - IT Security Guru

Manage Vendor Risk in a Few Practical Steps

Edtech gets schooled by third-party cyberthreats | TechTarget


Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity

Cyber Warfare and Cyber Espionage

UK Households Told to Stockpile Food, Water and Medicines as Russia Cyber Attack Threat Grows | IBTimes UK

Stockpile food in case of Russian cyber attack, Government will tell public

EU adopts largest-ever cyber sanctions package against Russia

EU Targets Russian Intelligence Officers Accused of Running a Yearslong Cyber Spying Campaign - SecurityWeek

UK and EU impose sanctions on hacking groups linked to Kremlin | Computer Weekly

Europe is building resilience – but not the kind it needs for war - Friends of Europe

As Global Conflicts Go Digital, Businesses Require Wartime Plans

Government Updates UK’s National Risk Register with Cyber Warnings - Infosecurity Magazine

Nation State Actors

China

China, India-Linked Hackers Both Targeted Same Pakistani Police Force - SecurityWeek

Russia

UK government to warn the public to prepare for a cyberattack​ | Cybernews

UK Households Told to Stockpile Food, Water and Medicines as Russia Cyber Attack Threat Grows | IBTimes UK

EU sanctions Russian tech giant VK, state-backed messenger Max, and FSB-linked cyberattack network — The Insider

Officials from 13 Nations once again warn defenders that Russian hackers are targeting network devices | CyberScoop

Russian hackers exploit weak router security to breach critical infrastructure, Western allies warn - Nextgov/FCW

Weak Security Continues to Fuel Russian Cyberattacks

CISA Stresses Router Hardening Against Nation-State Hackers

UK and international allies warn critical sectors over Russian cyber threats | UKAuthority

EU adopts largest-ever cyber sanctions package against Russia

Europe is building resilience – but not the kind it needs for war - Friends of Europe

EU, UK sanction Russian cyberespionage networks over destructive attacks | CyberScoop

NATO Condemns Russian Cyber Attacks, Warns of Reprisals | Newsmax.com

UK, EU officially pin Poland energy cyberattack on Russia

UK charges suspects linked to Russian Coms call spoofing platform

Russian Cybercrime Trio Indicted In Alleged $62M Scheme

North Korea

Cyberattacks against S. Korean military top 18,000 last year: report - The Korea Herald

Iran

Iran's Cyber Crosshairs Focus Beyond Critical Infrastructure

US personnel faced phone-tracking campaign during Iran war – FT | Iran International

Other Nation State Actors, Hacktivism, Extremism, Terrorism and Other Geopolitical Threat Intelligence

London teenager who offered crypto advice to terror groups convicted | The Standard

Teenager convicted of terrorism offences after CTP London investigation | Metropolitan Police


Tools and Controls

The agents you use to beef up cybersecurity could be turned against you – ‘Friendly Fire’ attacks can manipulate OpenAI and Anthropic models into running malicious code | IT Pro

75% CISOs Fear Executives Don’t Understand Cybersecurity Risks - Infosecurity Magazine

Tech-xit? UK Steps Up Sovereignty Push Amid AI Strife

NCSC advice on vulnerable routers | Professional Security Magazine

Windows Bind Link Attacks Can Hide Malware From EDR Tools - SecurityWeek

Only 28% of financial workforce MFA is phishing-resistant - Help Net Security

New Ransomware Exploits Malicious Driver to Remove Security Protection - Infosecurity Magazine

As Global Conflicts Go Digital, Businesses Require Wartime Plans

AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique - SecurityWeek

Microsoft Entra ID authentication overhaul to start in September 2026 - Help Net Security

Phishing Campaign Abuses eCards to Deploy RMM Tools - Infosecurity Magazine

Working with the enemy: Ransomware negotiator-turned cyber criminal jailed after working with hackers to extort clients | IT Pro

AI Coding: Do Security Risks Outweigh Productivity Gains?

The best defense against AI attacks turns out to be a skeptical human - Help Net Security

New phishing campaign hits LastPass, Bitwarden users - password manager customers warned not to fall for this scam | TechRadar

Why AI 'harnesses' matter more than frontier LLMs for cybersecurity | CyberScoop

Why SBOMs, signing, and provenance still don't tell you if software is safe - Help Net Security

ISC2 Research Finds AI Is Reshaping Cybersecurity Roles and Increasing Human Oversight

OpenAI releases latest ChatGPT model after delay over White House cybersecurity concerns | ChatGPT | The Guardian

VPN service favored by ransomware groups is sanctioned by US | The Record from Recorded Future News

EU launches AI test platform to find cybersecurity flaws | Cybernews

Gold Eagle: the White House’s AI cyber clearinghouse


Reports Published in the Last Week

AI Security Report 2026 - Check Point Research



Vulnerability Management

Microsoft Warns of Increase in Number of Security Updates - Infosecurity Magazine

99.9% of fixable AI vulnerabilities remain unpatched - Help Net Security

Companies keep getting breached by vulnerabilities they already knew about - Help Net Security

Microsoft is rewriting Windows patch guidance because of AI - Help Net Security

EU launches AI test platform to find cybersecurity flaws | Cybernews

White House details ‘Gold Eagle’ clearinghouse for AI cyber threats | CyberScoop

Vulnerabilities

Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack

Microsoft discloses ‘the mother of all’ vulnerability loads, tripling June’s previous record | CyberScoop

Windows BitLocker 0‑Day Vulnerability Allows Hackers to Bypass Security Feature

CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities - SecurityWeek

Dell PCs are shutting down after Windows 11's July update, Microsoft admits and blocks it

Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday

Fresh SharePoint Vulnerability Exploited Soon After Disclosure - SecurityWeek

F5 Patches Multiple NGINX, BIG-IP Vulnerabilities - SecurityWeek

Adobe Patches Critical ColdFusion Vulnerabilities - SecurityWeek

CitrixBleed 2 exploited in repeatable attack chain culminating in DragonForce ransomware, researchers find - IT Security Guru

Critical Cursor 0-Day Flaw Allows Malicious Git Repos to Trigger Automatic Windows Code Execution

Debian 13.6 security update patches over a hundred advisories in trixie - Help Net Security

CISA urges immediate action on actively exploited Fortinet flaws

Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates - SecurityWeek

Attackers Exploit 'Ill Bloom' Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets

n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer

Progress Told ShareFile Customers to Pull the Plug on Their Servers. Here's What We Know.

Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown

RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata

SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud - SecurityWeek

ServiceNow's requires_authentication=false: The One Boolean That Exposed Enterprise Data Worldwide - Security Boulevard

Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow - SecurityWeek

Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands

Splunk, Zoom Patch Critical Vulnerabilities - SecurityWeek

These 5 Routers Are No Longer Safe To Use After A New Security Backdoor Was Discovered

Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot

11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot

U.S. CISA adds iCagenda and Balbooa Forms flaws to its Known Exploited Vulnerabilities catalog

7 Severe Vulnerabilities Patched in VMware Avi Load Balancer - SecurityWeek

Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions

Zoom issues a warning to Windows users about critical security flaw - BetaNews


Sector Specific

Industry specific threat intelligence reports are available.

Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.

  • Automotive

  • Construction

  • Critical National Infrastructure (CNI)

  • Defence & Space

  • Education & Academia

  • Energy & Utilities

  • Estate Agencies

  • Financial Services

  • FinTech

  • Food & Agriculture

  • Gaming & Gambling

  • Government & Public Sector (including Law Enforcement)

  • Health/Medical/Pharma

  • Hotels & Hospitality

  • Insurance

  • Legal

  • Manufacturing

  • Maritime & Shipping

  • Oil, Gas & Mining

  • OT, ICS, IIoT, SCADA & Cyber-Physical Systems

  • Retail & eCommerce

  • Small and Medium Sized Businesses (SMBs)

  • Startups

  • Telecoms

  • Third Sector & Charities

  • Transport & Aviation

  • Web3


Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.

Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.

You can also follow us on Facebook, Twitter and LinkedIn.

Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.

Next
Next

Black Arrow Cyber Threat Intelligence Briefing 10 July 2026