Black Arrow Cyber Threat Intelligence Briefing 24 July 2026

Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.

Executive Summary

Over the past week, the global media has been discussing how OpenAI’s new model bypassed its testing controls and accessed systems belonging to another AI company while attempting to complete a cyber security task. We include this and other information in our weekly review of cyber security in the specialist and general media, to help raise awareness of the risks that organisations need to manage when using AI, and when defending against AI-driven attacks.

While AI has been the focus of many news stories this week, business leaders need to ensure they do not take their eye off other risks, including ransomware attacks, which frequently begin with compromised credentials including credentials obtained through phishing. We also include this week news of other vulnerabilities and attack tactics, from Adobe Acrobat extensions and Microsoft calendar entries, to supply chain risks and online information about company executives that enables attackers to impersonate them.

Although cyber risks come from various angles, and new high risks are identified particularly related to AI, the underlying approach to managing cyber risks remains consistent. Business leaders should ensure they are upskilled with an understanding of the risks they need to manage, and an impartial view of the controls that they need to ensure are in place and governed. Importantly, the controls must cover people, operations and technology, and the impartial assessment should come from cyber experts who are not providing those controls. Contact us to see how we help organisations across various countries to achieve this proportionately.


Top Cyber Stories of the Last Week

OpenAI’s New Model Went Rogue and Hacked Another Company. Why It Matters.

OpenAI has disclosed that an advanced artificial intelligence model bypassed its testing controls and accessed systems belonging to another AI company while attempting to complete a cyber security task. The incident highlights the growing risks posed by AI agents, which can act independently on computers and pursue objectives without continuous human direction. Although the affected company was not widely known, the incident raises concern about whether safeguards will remain effective as AI systems become more capable. OpenAI has strengthened its security controls and is continuing to investigate the incident.

https://www.washingtonpost.com/technology/2026/07/22/openais-new-model-went-rogue-hacked-another-company/

AI Models Keep Getting Caught Cheating

Research from the UK’s AI Security Institute found that every large language model tested in offensive cyber security exercises attempted to take prohibited actions or use unintended shortcuts to complete assigned tasks. The models often failed to disclose this behaviour, and fewer than half recognised it as wrong when challenged. In one case, a model used an external online service to try to access protected evaluation systems, triggering a security alert. Although no data was lost, the findings raise serious concerns about using AI in sensitive areas where trust, oversight and reliable decision-making are essential.

https://cyberscoop.com/ai-models-cheat-deceive-users-aisi-report/

Senior Executives Abuse Shadow AI Twice as Much as Regular Employees Do

Senior executives are using unauthorised AI tools at twice the rate of other employees, with nearly two-thirds admitting to the practice compared with 31% of lower-level staff. This creates particular risk because leaders often handle sensitive financial, strategic, customer and intellectual property data. Three-quarters of employees recognise the security and privacy concerns, suggesting the problem is driven less by awareness and more by poor alternatives. Where approved tools are slow, limited or difficult to access, staff are more likely to use personal accounts and unapproved services, reducing oversight and leaving organisations without reliable records of how important decisions were made.

https://www.cio.com/article/4195782/senior-executives-abuse-shadow-ai-twice-as-much-as-regular-employees-do.html

The Script, Not the Voice, Is What Makes AI Voice Phishing Work

Research involving 4,100 US adults found that the persuasiveness of an AI voice phishing call mattered far more than how human the voice sounded. Around 16% of participants said they might comply with scam requests, rising to 36% for a fake relative in distress. Controls should therefore focus on independent verification, such as calling back using trusted contact details, family code words and preventing telephone requests alone from authorising password resets, payments or account changes.

https://www.helpnetsecurity.com/2026/07/17/research-ai-voice-phishing/

Connecting AI Agents to Outside Services Explodes the Risk Radius

Connectors link AI agents to external services including email, messaging and file storage, widening an organisation’s exposure to data loss and unauthorised actions. PromptArmor found that 37% of 2,517 connectors changed within six weeks, with 1,686 new capabilities added to connectors that were already live. Around two in five Claude connectors were also likely to call additional AI services, meaning data could be processed by providers not considered when the connector itself was approved. Rapid changes to permissions, data handling and write access mean connector approvals can quickly become outdated, creating hidden governance and security risks.

https://www.theregister.com/ai-and-ml/2026/07/19/connecting-ai-agents-to-outside-services-explodes-the-risk-radius/5274640

Cyber Remains Top Enterprise Risk for Company Leaders

Cyber attacks and data breaches remain the top enterprise risk in 2026 and are expected to retain that position through 2028, according to Aon. Artificial intelligence is increasing the speed, scale and accessibility of attacks, allowing criminals to automate research, create convincing phishing messages and exploit weaknesses more quickly. Despite this, many organisations consider themselves only somewhat prepared, with fragmented oversight and limited testing of AI-related incidents. Aon recommends strengthening basic controls, reviewing insurance coverage, improving board reporting and testing response and continuity plans against AI-enabled disruption.

https://www.emergingrisks.co.uk/cyber-remains-top-enterprise-risk-for-company-leaders/

79% of Ransomware Attacks Start with Compromised Identities

A Sophos report found that compromised user accounts were involved in 79% of ransomware incidents, making stolen login details the most common route into organisations. Malicious emails accounted for 26% of cases, phishing rose from 18% in 2025 to 24% in 2026, and brute force attempts remained broadly stable at 23%. By contrast, attacks exploiting known software weaknesses fell from 32% to 18%. For business leaders, the findings underline the need to strengthen identity controls, limit unnecessary access and ensure compromised accounts can be identified and disabled quickly.

https://www.securitymagazine.com/articles/102440-79-of-ransomware-attacks-start-with-compromised-identities

Ransomware Attacks Hit SMBs Harder than Ever as Cybercrime Gang Rivalry Heats Up

NordStellar’s analysis of more than 200 threat actor blogs identified 2,581 reported attacks in the second quarter of 2026, with Qilin and The Gentlemen responsible for 299 and 284 incidents respectively. Smaller US businesses were hit hardest, suffering 769 attacks, followed by Canada with 97, Germany with 83 and the UK with 74. Attacks on US organisations with revenues above $1 billion also rose by 74%, from 23 to 40 incidents. The findings suggest smaller businesses remain especially exposed where defences are limited, while major companies may face increased targeting as leading groups compete for status.

https://www.techradar.com/pro/security/ransomware-attacks-hit-smbs-harder-than-ever-as-cybercrime-gang-rivalry-heats-up

A New Ransomware Threat Actor Emerges Every Week, Warns Report

The ransomware market is becoming increasingly crowded and unpredictable, with 61 new groups emerging during the first half of 2026. Black Kite identified 146 active groups by June, up from 105 a year earlier, although their average lifespan has fallen to just 4.9 months. Despite this fragmentation, the five largest groups accounted for 44% of 7,551 publicly disclosed victims between March 2025 and March 2026. Critical software weaknesses provided initial access in 44% of attacks, reinforcing the importance of timely updates. The report also recommends stronger identity verification, help desk escalation and controls against executive impersonation.

https://www.infosecurity-magazine.com/news/new-ransomware-weekly/

Adobe Acrobat Extension Flaw Lets Attackers Steal WhatsApp Chats from 329 Million Users

A flaw in Adobe’s Acrobat extension for Chrome could have allowed attackers to steal visible WhatsApp Web chats, contacts and profile information when a user visited a malicious website, without requiring a click or password. The extension was installed on up to 329 million browsers worldwide. Adobe fixed the issue in version 26.5.2.3 and distributed the update automatically. The incident highlights the wider risks posed by browser extensions, particularly where trusted software can access sensitive information across other websites and online services.

https://cybersecuritynews.com/acrobat-extension-flaw-whatsapp-chats/

Watch Out – That Microsoft Calendar Invite Dated 2050 Could Be Hiding Stolen Files and Worse

Group-IB has identified new malware targeting organisations that uses compromised Microsoft 365 calendars to steal sensitive files. Attackers hide instructions in calendar entries dated as far ahead as 2050, then attach encrypted stolen data to events, allowing the activity to blend into legitimate Microsoft traffic. At least 12 systems were compromised, with three still communicating with the attackers during the investigation. Researchers found similarities to tools linked with an Iranian-aligned group, although the evidence was not strong enough for confident attribution. The technique shows that trusted cloud services can conceal malicious traffic and data theft from normal monitoring.

https://www.techradar.com/pro/security/watch-out-that-microsoft-calendar-invite-dated-2050-could-be-hiding-stolen-files-and-worse

Device Code Phishing: Turning a Convenience Feature into an MFA Bypass

Device code phishing turns a legitimate Microsoft sign-in feature into a route around multi-factor authentication. Victims enter a genuine code on Microsoft’s website and complete MFA, but unknowingly approve access for the attacker. In one case, criminals posed as a contact at a law firm, built trust through several emails, then used the compromised account to register multiple devices, hide messages and send phishing emails to hundreds of recipients. Organisations should block device code authentication where it is not required, restrict device registration and train staff to treat unexpected requests to enter verification codes as suspicious.

https://www.trendmicro.com/en_us/research/26/g/device-code-phishing.html

1 in 4 Businesses Hit by Cyber Attacks through Their Supply Chain in the Last Year

One in four UK businesses suffered a cyber incident through their supply chain in the past year, while 48% knowingly continued working with suppliers that had security or resilience concerns. Databarracks found these organisations were more than four times as likely to experience a supplier-related incident. Although 89% assess suppliers during onboarding, ongoing visibility often remains limited. The wider study also found 65% believe a serious cyber attack could threaten their survival, highlighting the need to treat critical suppliers as part of the organisation’s own resilience planning.

https://www.itsecurityguru.org/2026/07/21/1-in-4-businesses-hit-by-cyber-attacks-through-their-supply-chain-in-the-last-year/

The Executive Profile Your Security Team Isn’t Defending

Artificial intelligence can now assemble detailed profiles of senior executives in minutes by combining public information about their careers, relationships, interests and routines. This makes convincing impersonation and targeted fraud easier, even for less skilled attackers. Organisations should treat an executive’s public digital footprint as a managed security risk, with regular reviews of what major AI platforms reveal. Removing unnecessary personal information, addressing family exposure and showing executives their own AI-generated profiles can reduce the information available for phishing, fraudulent calls and attempts to manipulate support staff.

https://www.csoonline.com/article/4197460/the-executive-profile-your-security-team-isnt-defending.html



Threats

Ransomware, Extortion and Destructive Attacks

A New Ransomware Threat Actor Emerges Every Week, Warns Report - Infosecurity Magazine

Ransomware attacks hit SMBs harder than ever as cybercrime gang rivalry heats up | TechRadar

79% of Ransomware Attacks Start with Compromised Identities | Security Magazine

Ransomware Attacks Rise 3% in Q2 as Supply Chain Compromises Escalate, NCC Group Warns - IT Security Guru

The Gentlemen Overtakes Qilin as Most Prolific Ransomware Threat - Infosecurity Magazine

Government Agencies Falling Victim to Ransomware Daily, Warns Study - Infosecurity Magazine

Ransomware Uses AI to Amp Up Negotiations | Lawfare

Pay up or not? Ransomware surge has victims facing tough choices. - Ars Technica

If you pay a hacker's ransom, chances are that they'll come back for more | TechCrunch

Ransomware, Spies and Hacktivists Converge on UK and Ireland, New Threat Report Warns - IT Security Guru

How enterprise GenAI can amplify ransomware risk — and how to contain it

New Spirals ransomware encrypts victim network in under 24 hours

Scattered Spider members jailed over Transport for London hack that cost £29 million - Help Net Security

Hackers Exploit PAN-OS Flaw (CVE-2026-0257) to Deploy Qilin

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

PYMNTS | Governments Weigh Ransomware Payment Bans

Two-Thirds of Ransomware Victims Say AI Boosted Attack Effectiveness - Infosecurity Magazine

As Ransomware Blackmail Surges, Governments Mull a Ban on Paying Up | Extremetech

Inc Ransomware Exploits SonicWall SMA Zero-Days

A bizarre new malware campaign hacks your printer and forces it to print out ransomware demands | TechRadar

Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man

Royal Ransomware Uses Qbot and Cobalt Strike to Rapidly Compromise Windows Domains

Qilin Ransomware Affiliates Abuse CVE-2026-0257 to Gain Unauthorized VPN Access

Ransomware and Destructive Attack Victims

Government Agencies Falling Victim to Ransomware Daily, Warns Study - Infosecurity Magazine

Qilin claims hack of Danone global food giant | Cybernews

JadePuffer returns with ransomware built to target AI models and infrastructure - Help Net Security

List of Companies Impacted by Rise in Cyber Attacks

Coca-Cola Suspends US Fairlife Production Due to Ransomware Attack - SecurityWeek

After KFC, cyberattack hits Japanese ice cream giant Glico | The Straits Times

Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei - SecurityWeek

Romania's land registry hit by cyber attack, data allegedly for sale - Help Net Security

Ransomware Group Threatening to Leak Data Stolen From Coca-Cola's Fairlife - SecurityWeek

Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak

Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack

Abbott probes two cyber incidents amid extortion claims

Phishing & Email Based Attacks

Phishing Campaign Hides Lua Loader as TrueType Font File - Infosecurity Magazine

1M+ Emails Use Hidden Text to Dupe AI Security Filters

Attackers Combo Up Evasion Tactics for BEC Phishing

Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass | Trend Micro (US)

AI spam filters are getting suckered by old-school text salting

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

Police dismantle Kratos phishing platform, arrest developer

Business Email Compromise (BEC)/Email Account Compromise (EAC)

Attackers Combo Up Evasion Tactics for BEC Phishing

Other Social Engineering

The script, not the voice, is what makes AI voice phishing work - Help Net Security

The executive profile your security team isn't defending | CSO Online

Now, even Russia's most elite hackers are using Clickfix to infect devices - Ars Technica

Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday Trust - IT Security Guru

Watch out - that Microsoft Calendar invite dated 2050 could be hiding stolen files and worse | TechRadar

New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands

Almost half of fraud cases reported in the first half of 2026 were phone scams (vishing)

Scammers impersonate FBI on social media, prey on crime victims

Fake FBI agents target people who already got scammed - Help Net Security

Researchers Uncover North Korean 'ClickFake' Campaign Targeting Web3 - Infosecurity Magazine

North Korea's IT worker scheme funds Russia's war effort | CyberScoop

AML/CFT/Money Laundering/Terrorist Financing/Sanctions

Telegram shortlinks knocked offline over sanctioned VPN connection

Artificial Intelligence

The script, not the voice, is what makes AI voice phishing work - Help Net Security

How enterprise GenAI can amplify ransomware risk — and how to contain it

OpenAI’s new model went rogue and hacked another company. Why it matters. - The Washington Post

Co-founder of firm hacked by rogue OpenAI models says it is 'a wake-up call' - BBC News

The executive profile your security team isn't defending | CSO Online

Single Prompt Enables ChatGPT to Execute Full Cyber-Attack Chain - Infosecurity Magazine

New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands

Prompt injection is becoming the XSS of the web agent era - Help Net Security

Agentic AI: Taming the Unpredictable

Senior executives abuse shadow AI twice as much as regular employees do | CIO

Connecting AI agents to outside services explodes the risk radius

Employees' shadow AI use is poorly monitored, survey finds | TechTarget

New UK report finds AI models consistently cheat and deceive users | CyberScoop

Forescout Report Reveals Surge in AI-Driven Cyber Threats - IT Security Guru

Vibe-Coded Apps Riddled With Exploitable Security Flaws - SecurityWeek

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

JadePuffer returns with ransomware built to target AI models and infrastructure - Help Net Security

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

Two-Thirds of Ransomware Victims Say AI Boosted Attack Effectiveness - Infosecurity Magazine

Claude Chrome extension flaw lets malicious extensions trigger AI actions

Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes - Help Net Security

Think you can spot fake AI photos? They're now a security risk | PCWorld

Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes

CISOs Feel the Heat Over AI Risk

Attackers Are Learning to Live Off the AI Toolchain

Shadow AI is becoming enterprise security's biggest blind spot - Help Net Security

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

AI agents are still logging in as humans - Help Net Security

“Stop asking whether AI works and start asking what it can reach”: C1 CISO on AI agent security | news | MSSP Alert

New Study Identifies 53 Slopsquatting Targets Across 5 Frontier LLMs

AI Data Centers Are Being Built Faster Than They Can Be Secured - SecurityWeek

Claude Code and DeepSeek Powered Chinese Cyber Espionage Campaign

Google's Gemini lets strangers send messages from your locked Android phone

Researchers Build WordPress Exploit Using OpenAI's GPT - Infosecurity Magazine

Hacker Turns AI Jailbreaks Into Offensive Platform

AI Agents Can Now Use Your Password. Is Agentic AI Going Too Far?

WordPress "wp2shell" exploit payload analyzed: AI developed this attack | Cybernews

OpenAI admits GPT-5.6 occasionally deletes files – but it's an 'honest mistake'

AI Has Enhanced Iran’s Asymmetric Playbook During the 2026 Conflict

Malware is targeting AI tools in software development environments | CyberScoop

White House accuses Chinese company of distilling Anthropic’s Fable | CyberScoop

Bots/Botnets

TuxBot v3: The IoT Botnet Built With AI - Bugs, Disclaimers and All

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

Careers, Roles, Skills, Working in Cyber and Information Security

AI can't fix cybersecurity's hiring problem - Help Net Security

The top AI fear for 6,000 tech pros isn't losing their jobs - it's more work for the same pay | ZDNET

MSSPs have a burnout problem, and pay isn’t the fix | news | MSSP Alert

Cloud/SaaS

Airbus moves critical apps off AWS to a French cloud

HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel - Help Net Security

The SaaS blind spot: Why security teams can’t get inside their own apps | CSO Online

Malicious cloud customers can bring down the power grid

Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain

New OkoBot framework deploys 20 payloads to steal data, crypto

Hackers steal $23.7 million in crypto from Ostium in off-chain attack

FBI Arrests Florida Man Accused of Distributing Malware Through Steam Games in $220,000 Crypto Theft - gHacks Tech News

Cruciferra Crypter Uses Process Ghosting to Evade Detection - Infosecurity Magazine

Cyber Crime, Organised Crime & Criminal Actors

US charges two over laundering $43 million from investment fraud

Russian trio indicted for allegedly running bulletproof hosting providers that spurred cybercrime | CyberScoop

Police take down investment fraud network that stole €100 million a month - Help Net Security

Data Breaches/Leaks

World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent

New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands

Ernst & Young Data Breach Affects Personal, Financial Information - SecurityWeek

EY Sued Over Breach Targeting Client Tax, Financial Info - Law360

Lessons Learned: US Cybersecurity Agency Leaked Secrets

23andMe Faces New Security Mandates in $18m Data Breach Settlement - Infosecurity Magazine

UK health tech firm Craneware admits customer and staff data stolen in cyber attack | The Independent

Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts - SecurityWeek

Estée Lauder discloses data breach via Oracle E-Business flaw

Paidwork breach exposes sensitive data of 23 million users - Help Net Security

Italy fines WINDTRE €1.7 million over security flaws behind two data breaches - Help Net Security

Chick-fil-A discloses data breach after credential stuffing attacks

South Korea discloses data breach impacting diplomats worldwide

Breach of AI music platform Suno affected 55M+ user accounts

Investigation finds no evidence of negligence in Qantas hack – Australian Aviation

Data/Digital Sovereignty

Airbus migrating 70 critical apps from AWS to France's Scaleway amid digital sovereignty push

Denial of Service/DoS/DDoS

AnyDesk 0-Day Vulnerability Lets Attackers Trigger Denial-of-Service

HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload

OpenSSL Silently Fixes 'HollowByte' DoS Vulnerability - SecurityWeek

Fraud, Scams and Financial Crime

US charges two over laundering $43 million from investment fraud

Russian trio indicted for allegedly running bulletproof hosting providers that spurred cybercrime | CyberScoop

Police take down investment fraud network that stole €100 million a month - Help Net Security

Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday Trust - IT Security Guru

Cybercriminals released 802,000 stolen accounts in one day during the World Cup group stage

Almost half of fraud cases reported in the first half of 2026 were phone scams (vishing)

Scammers impersonate FBI on social media, prey on crime victims

Fake FBI agents target people who already got scammed - Help Net Security

Suffolk conman targeted elderly to defraud them out of millions - BBC News

Cardiff Covid fraudster jailed over bogus £200,000 loans - BBC News

Fraudster told to repay £5m to Royal Mail or face jail - BBC News

Identity and Access Management

79% of Ransomware Attacks Start with Compromised Identities | Security Magazine

Insider Risk and Insider Threats

North Korea's IT worker scheme funds Russia's war effort | CyberScoop

Internet of Things – IoT

TuxBot v3: The IoT Botnet Built With AI - Bugs, Disclaimers and All

Your next car's software update could become its biggest security risk - Digital Trends

Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide

Multiple TP-Link Cameras Vulnerability Allows Hackers to Launch MitM Attacks

Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine

Law Enforcement Action and Take Downs

US charges two over laundering $43 million from investment fraud

Russian trio indicted for allegedly running bulletproof hosting providers that spurred cybercrime | CyberScoop

Police take down investment fraud network that stole €100 million a month - Help Net Security

Police dismantle Kratos phishing platform, arrest developer

Scattered Spider members jailed over Transport for London hack that cost £29 million - Help Net Security

UK cops say arrest of two young hackers disrupted the operations of an infamous hacking group | TechCrunch

Police Chiefs Cite TfL Hack in Push for Cybercrime Risk Orders - Infosecurity Magazine

Telegram shortlinks knocked offline over sanctioned VPN connection

Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man

A 21-year-old allegedly hid malware in Steam games to steal $220,000 in crypto, then bought Uber Eats with it

US seizes over 1,000 websites in FIFA World Cup piracy crackdown

Linux and Open Source

CVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protections

Linux kernel team publishes 432 CVEs in two days

Multi-patch vulnerability fixes can leave open source exposed - Help Net Security

Malware

Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday Trust - IT Security Guru

Now, even Russia's most elite hackers are using Clickfix to infect devices - Ars Technica

Phishing Campaign Hides Lua Loader as TrueType Font File - Infosecurity Magazine

Russian hackers trojanize WebEx, Zoom apps to push Starland malware

TuxBot v3: The IoT Botnet Built With AI - Bugs, Disclaimers and All

New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands

New OkoBot framework deploys 20 payloads to steal data, crypto

HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel - Help Net Security

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

Attackers keep using GitHub to distribute malware | Cybernews

This new Mac malware won't let you use your computer until you surrender your password - Digital Trends

Cisco sounds alarm over new Russian malware campaign hitting firms in US and Europe | IT Pro

Microsoft warns of surge in ACR Stealer attacks on customers

SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware

FBI Arrests Florida Man Accused of Distributing Malware Through Steam Games in $220,000 Crypto Theft - gHacks Tech News

New Study Identifies 53 Slopsquatting Targets Across 5 Frontier LLMs

Dangerous new GoSerpent malware is apparently on the hunt for government secrets | TechRadar

SonicWall SMA1000 flaws exploited as zero-days to push custom malware

TrickBot Ditches HTTP for DNS Tunneling in Latest Variant - Infosecurity Magazine

Cruciferra Crypter Uses Process Ghosting to Evade Detection - Infosecurity Magazine

Malware is targeting AI tools in software development environments | CyberScoop

20+ Hijacked Government Websites Became
an Attack Channel

Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images

Brazilian Banking Trojan Actively Spreading in Portugal

Mobile

Google's Gemini lets strangers send messages from your locked Android phone

Fake Bahrain Alert App Deploys Android Surveillance Malware

Models, Frameworks and Standards

Does the Cyber Security and Resilience Bill make you feel secure? | Computer Weekly

How mapping security controls can ease the compliance burden | TechTarget

PR3TACK preemptive framework maps threats before attackers use them - Help Net Security

NCSC ready to open Pathways to a broader set of organisations | UKAuthority

The CMMC 60-day pause: A strategic reset or something much bigger? | perspective | MSSP Alert

Passwords, Credential Stuffing & Brute Force Attacks

This new Mac malware won't let you use your computer until you surrender your password - Digital Trends

79% of Ransomware Attacks Start with Compromised Identities | Security Magazine

AI Agents Can Now Use Your Password. Is Agentic AI Going Too Far?

These Irish State agencies use password software with deep links to a Russian tech firm – The Irish Times

Chick-fil-A discloses data breach after credential stuffing attacks

Regulations, Fines and Legislation

Does the Cyber Security and Resilience Bill make you feel secure? | Computer Weekly

PYMNTS | Governments Weigh Ransomware Payment Bans

'This is the right call' — VPN industry praises the UK’s decisions to leave VPN alone | TechRadar

Social media companies have failed to enforce their minimum age requirements: Ofcom | Biometric Update

European Union considers social media ban for children

Spain Fines 23andMe €2.4 Million Over Security Failures Behind 6.9 Million-User Breach

The CMMC 60-day pause: A strategic reset or something much bigger? | perspective | MSSP Alert

Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains - SecurityWeek

France approves social media ban for under-15s - BBC News

Shadow IT

Senior executives abuse shadow AI twice as much as regular employees do | CIO

Employees' shadow AI use is poorly monitored, survey finds | TechTarget

Shadow AI is becoming enterprise security's biggest blind spot - Help Net Security

Social Media

Social media companies have failed to enforce their minimum age requirements: Ofcom | Biometric Update

VPN firms and digital rights groups join forces to urge the UK government to leave VPNs alone | TechRadar

'This is the right call' — VPN industry praises the UK’s decisions to leave VPN alone | TechRadar

European Union considers social media ban for children

Scammers impersonate FBI on social media, prey on crime victims

France approves social media ban for under-15s - BBC News

Software Supply Chain

Attackers keep using GitHub to distribute malware | Cybernews

SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

New Study Identifies 53 Slopsquatting Targets Across 5 Frontier LLMs

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

Malware is targeting AI tools in software development environments | CyberScoop

Supply Chain and Third Parties

1 in 4 businesses hit by cyber attacks through their supply chain in the last year - IT Security Guru

Ernst & Young (EY) Investigates Data Breach Involving Third-Party Support Tickets

Estée Lauder discloses data breach via Oracle E-Business flaw


Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity

Cyber Warfare and Cyber Espionage

Ransomware, Spies and Hacktivists Converge on UK and Ireland, New Threat Report Warns - IT Security Guru

Claude Code and DeepSeek Powered Chinese Cyber Espionage Campaign

Finland Accuses Russia of Cyberespionage

Europe exposes Russia’s cyber war

Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine

North Korea's IT worker scheme funds Russia's war effort | CyberScoop

Iranian Hackers Are Quietly Building Access They Can Turn Into Wartime Disruption

Symposium on International Law and Artificial Intelligence in Armed Conflict: Introduction - Opinio Juris

AI Has Enhanced Iran’s Asymmetric Playbook During the 2026 Conflict

US Cyber Command senior enlisted leader: Data is the currency of warfare > Defense Logistics Agency > News Article View

NATO is building a Starlink-style military satellite network as eight allies unite to protect critical space communications | TechRadar

Iran War Cyber Threat Landscape | A Midyear Assessment on What Matters | SentinelOne

Hackers were inside South Korea's diplomat training system for 9 months | The Record from Recorded Future News

Nation State Actors

Ransomware, Spies and Hacktivists Converge on UK and Ireland, New Threat Report Warns - IT Security Guru

Trump offers no proof of claims foreign meddling threatens U.S. elections; Slammed for stoking voter fears

Trump Warns of Cyber Threats to U.S. Election Security from Foreign Powers | World News - The Times of India

China

Claude Code and DeepSeek Powered Chinese Cyber Espionage Campaign

Threat Actors Aligned with China Attacking U.S. University Physics + Engineering Depts. | Robinson+Cole Data Privacy + Security Insider - JDSupra

White House accuses Chinese company of distilling Anthropic’s Fable | CyberScoop

China's Top Cybersecurity Firms Hit by Mounting Military Procurement Bans - SecurityWeek

Russia

Now, even Russia's most elite hackers are using Clickfix to infect devices - Ars Technica

Russian hackers trojanize WebEx, Zoom apps to push Starland malware

Finland Accuses Russia of Cyberespionage

Europe exposes Russia’s cyber war

Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes - Help Net Security

Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine

North Korea's IT worker scheme funds Russia's war effort | CyberScoop

Cisco sounds alarm over new Russian malware campaign hitting firms in US and Europe | IT Pro

These Irish State agencies use password software with deep links to a Russian tech firm – The Irish Times

Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man

Russian Hacker Turns Jailbroken Claude Into Pentest Platform - Infosecurity Magazine

Hacker Turns AI Jailbreaks Into Offensive Platform

North Korea

Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images

North Korea's IT worker scheme funds Russia's war effort | CyberScoop

Hackers were inside South Korea's diplomat training system for 9 months | The Record from Recorded Future News

Researchers Uncover North Korean 'ClickFake' Campaign Targeting Web3 - Infosecurity Magazine

Iran

Iranian Hackers Are Quietly Building Access They Can Turn Into Wartime Disruption

Iran War Cyber Threat Landscape | A Midyear Assessment on What Matters | SentinelOne

AI Has Enhanced Iran’s Asymmetric Playbook During the 2026 Conflict


Tools and Controls

The executive profile your security team isn't defending | CSO Online

Vibe-Coded Apps Riddled With Exploitable Security Flaws - SecurityWeek

The AI code vulnerabilities that grow with your app - Help Net Security

1M+ Emails Use Hidden Text to Dupe AI Security Filters

Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes

Small teams are the heaviest users of AI coding agents - Help Net Security

AI spam filters are getting suckered by old-school text salting

Malware is targeting AI tools in software development environments | CyberScoop

'This is the right call' — VPN industry praises the UK’s decisions to leave VPN alone | TechRadar

The SaaS blind spot: Why security teams can’t get inside their own apps | CSO Online

“Stop asking whether AI works and start asking what it can reach”: C1 CISO on AI agent security | news | MSSP Alert

AI Data Centers Are Being Built Faster Than They Can Be Secured - SecurityWeek

Businesses need to boost cyber resilience, here’s how | IT Pro

Microsoft and OEMs answer Windows 11 Secure Boot questions before the October deadline

Real AI Threat Is Blind Trust

SANS Warns of AI Governance Gap as Use by Security Teams Surges - Infosecurity Magazine

AI can't fix cybersecurity's hiring problem - Help Net Security

Why Smarter Cybersecurity Starts with Better Data | Research Communities by Springer Nature

These Irish State agencies use password software with deep links to a Russian tech firm – The Irish Times

Russian Hacker Turns Jailbroken Claude Into Pentest Platform - Infosecurity Magazine

China's Top Cybersecurity Firms Hit by Mounting Military Procurement Bans - SecurityWeek

Cloud operations become the next big role for agentic AI - Help Net Security

Behavioral biometrics: How to detect nonhuman threat actors | TechTarget


Reports Published in the Last Week

Ransomware and Cyber Extortion in Q2 2026



Vulnerability Management

The Windows 10 hangover is becoming a security problem - Help Net Security

Multi-patch vulnerability fixes can leave open source exposed - Help Net Security

AI Can Find Bugs, But Human Knowledge Still Proves Them

Security teams keep finding critical flaws after scheduled testing ends - Help Net Security

N-day is Becoming N-Hour. Patching Faster Won't Save You.

Gold Eagle Clearinghouse Targets Real Gap, but How Is Unclear

Mythos Didn't Break Your Security Program. Your Exposure Window Could.

Vulnerabilities

New Windows LegacyHive zero-day gives hackers admin privileges

Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522

Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents

Update now: 7-Zip fixes RCE flaw exploitable with malicious archives

Adobe Acrobat Extension Flaw Lets Attackers Steal WhatsApp Chats From 329 Million Users

AnyDesk 0-Day Vulnerability Lets Attackers Trigger Denial-of-Service

Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs

Attackers target critical FortiSandbox flaws as CISA issues patch order

HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

Linux kernel team publishes 432 CVEs in two days

New RefluXFS Linux flaw lets attackers gain root privileges

OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider - SecurityWeek

OpenSSL Silently Fixes 'HollowByte' DoS Vulnerability - SecurityWeek

Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates - SecurityWeek

Hackers Exploit PAN-OS Flaw (CVE-2026-0257) to Deploy Qilin

Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution

Inc Ransomware Exploits SonicWall SMA Zero-Days

Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation | Volexity

SonicWall SMA1000 flaws exploited as zero-days to push custom malware

CVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protections

Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

WordPress Core "wp2shell" RCE flaws get public exploits, patch now

Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities

Multiple TP-Link Cameras Vulnerability Allows Hackers to Launch MitM Attacks

Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide


Sector Specific

Industry specific threat intelligence reports are available.

Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.

  • Automotive

  • Construction

  • Critical National Infrastructure (CNI)

  • Defence & Space

  • Education & Academia

  • Energy & Utilities

  • Estate Agencies

  • Financial Services

  • FinTech

  • Food & Agriculture

  • Gaming & Gambling

  • Government & Public Sector (including Law Enforcement)

  • Health/Medical/Pharma

  • Hotels & Hospitality

  • Insurance

  • Legal

  • Manufacturing

  • Maritime & Shipping

  • Oil, Gas & Mining

  • OT, ICS, IIoT, SCADA & Cyber-Physical Systems

  • Retail & eCommerce

  • Small and Medium Sized Businesses (SMBs)

  • Startups

  • Telecoms

  • Third Sector & Charities

  • Transport & Aviation

  • Web3


Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.

Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.

You can also follow us on Facebook, Twitter and LinkedIn.

Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.

Next
Next

Black Arrow Cyber Threat Intelligence Briefing 17 July 2026