Black Arrow Cyber Threat Intelligence Briefing 31 July 2026

Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.

Executive Summary

Cyber resilience requires organisations to prepare and rehearse how they will respond to a serious cyber incident, and this week we reinforce the need for organisations to strengthen their resilience. This is achieved by the leadership team, not just the technology team, planning and rehearsing how to investigate and coordinate various response activities that affect everyone.

We also continue to look at cyber security, which is where organisations take a structured approach to help prevent an incident from occurring. Attackers continue to target employees through email and Teams phishing, while AI is making personalised deception faster and easier to scale. We continue to look at other AI-driven risks that business leaders need to address, including evolving risks with agentic AI and browsers.

Addressing these risks requires a leadership team that is regularly upskilled on the risks and the proportionate controls that they can ensure are implemented to reduce the risks. Resilience is strengthened through cross-functional incident response exercises that test decision-making, authority, coordination and business dependencies. Contact us to discuss how we support organisations across the world to achieve this.


Top Cyber Stories of the Last Week

73% of Organisations Say They Are Not Fully Ready for a Major Cyberattack

New research found that 73% of organisations would not be fully prepared for a major cyberattack, despite most having response plans, tools and technical teams in place. Of the 600 senior security decision makers surveyed, 76% had experienced at least one cyberattack in the past year, while 90% expected difficulties coordinating internal stakeholders during a serious incident. Limited executive involvement, delays engaging legal and communications teams, and poor visibility across systems were identified as major obstacles, showing that effective response depends on rehearsed decision-making and coordination, not technology alone.

https://thehackernews.com/2026/07/73-of-organizations-say-they-are-not.html

Why the Biggest AI-Driven Cyber Threat Is Still Human Nature

AI can rapidly identify software weaknesses and produce convincing messages, but manipulating people may still give criminals an easier route into organisations than overcoming technical defences. A technical flaw still requires suitable access and conditions to become a breach, while a single employee can be deceived through an urgent phishing email, fake security alert or impersonation attempt. AI makes these attacks faster, cheaper and more convincing in any language. Organisations should not expect employees to identify every convincing AI-generated deception and need broader technical defences to support them.

https://www.forbes.com/councils/forbestechcouncil/2026/07/29/why-the-biggest-ai-driven-cyber-threat-is-still-human-nature/

Phishing Dominates as Initial Entry Method for Cyberattacks, as Hackers Hone Evasion Techniques

Phishing was the initial entry point in just over half of the cyber incidents investigated by Cisco Talos between March and June 2026, up from one third in the previous quarter. Attackers are increasingly using QR codes, trusted cloud services and tailored documents to bypass email security and steal Microsoft 365 credentials. Phishing-as-a-service kits can also help criminals bypass multi-factor authentication and retain access after compromise, reinforcing the need for phishing-resistant authentication, centralised logging and controls that limit attack propagation.

https://www.infosecurity-magazine.com/news/phishing-dominates-initial-entry/

AI Is Gaining Ability to Personalise Cyberattacks, Enabling Phishing at Scale

AI is enabling criminals to create highly personalised phishing attacks at scale by researching targets, impersonating trusted contacts and adapting conversations when questioned. Unlike generic scam messages, these attacks can reflect an employee’s role, relationships and current responsibilities, making them far harder to identify. Researchers estimate that some business email compromise attacks could be fully automated by late 2026, with more complex cyberattacks potentially automated from start to finish as early as 2027. This significantly increases the risk that employees will be manipulated into revealing credentials or downloading malicious software.

https://www.washingtonpost.com/opinions/2026/07/28/ai-is-gaining-ability-personalize-cyberattacks-enabling-phishing-scale/

Microsoft Detects 7.6 Billion Email Phishing Threats as Teams Vishing Attacks Increases 10-Fold

Microsoft detected approximately 7.6 billion email phishing threats between April and June 2026, with credential theft accounting for up to 96% of attacks involving malicious content. Attackers are also increasingly targeting employees through Microsoft Teams, often posing as IT support staff. Weekly malicious call attempts increased by roughly 80% from the start of 2026 and reached almost ten times the mid-2025 level by late June. One automated email fraud campaign reached more than 67,000 users across 42,000 organisations in under three hours, highlighting how attackers combine trusted workplace channels with convincing impersonation to steal access or redirect payments.

https://cybersecuritynews.com/email-phishing-threats-as-teams-vishing-attacks/

Year-Long Russian Attacks Infect Users as Soon as They Look at an Email

Russian state-linked attackers have exploited a weakness in Zimbra email systems since July 2025, compromising users simply when they viewed a malicious email, without requiring a click or attachment. The campaign targeted government, defence, energy, education, media and technology organisations, stealing up to 90 days of emails, passwords, contact directories and authentication details. The flaw was fixed in November 2025, but unpatched systems remain exposed. Organisations using Zimbra should update immediately, limit access to webmail until secure, and review systems for signs of compromise.

https://www.theregister.com/patches/2026/07/23/year-long-russian-attacks-infect-users-as-soon-as-they-look-at-an-email/5277358

Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

A malicious advertising campaign targeting retail traders and cryptocurrency investors has operated since late 2024 across 12 countries and 25 languages. Fraudulent adverts impersonate services including TradingView, Solana and Luno, directing victims to convincing fake websites. Rather than downloading a complete malicious program, the victim’s browser assembles it from separate components, which can produce a different file for each session and reduce the value of basic file matching. There is no specific software patch to apply, reinforcing the importance of downloading trading and wallet applications only from official vendor websites and monitoring the wider advertising and download chain.

https://thehackernews.com/2026/07/malvertising-sends-malware-in-pieces.html

Ransomware Groups Increasingly Deploy EDR Kill Techniques

Ransomware groups are increasingly disabling endpoint security tools before encrypting systems, reducing the time available to detect and contain attacks. Halcyon recorded 1,988 publicly claimed attacks across 101 countries in the second quarter of 2026. Although claims fell by 5.7%, the methods used became more sophisticated, with greater automation and some groups progressing from initial access to ransomware deployment in under an hour. Manufacturing accounted for 19.8% of cyber extortion attacks, while criminals also expanded their use of artificial intelligence to support access, negotiation and other stages of attacks.

https://www.infosecurity-magazine.com/news/ransomware-q2-2026-edr-kill/

Agentic Browsers Rewind Web Security by 20 Years

Agentic browsers are AI-enabled web browsers that can navigate websites and take actions on a user’s behalf, rather than simply displaying pages. Researchers found that every commercial agentic browser they tested could be manipulated into harmful activity, including account takeover, unauthorised purchases and, in some cases, control of the underlying device. Some weaken established protections that stop one website triggering actions on another, allowing malicious online content to redirect the agent. Organisations considering adoption should assess the risks and use separate, isolated accounts and credentials rather than connecting agentic browsers to employees’ normal accounts.

https://www.darkreading.com/endpoint-security/agentic-browsers-rewind-web-security-20-years

OpenAI's Rogue AI Hacked Four More Platforms besides Hugging Face

Following the recent report that an OpenAI security test led an autonomous AI agent to access Hugging Face, OpenAI has confirmed that the agent also reached four other external services. The evaluation was designed to test what the models could do without safety filtering; the agent escaped its controlled environment and used exposed credentials to access outside systems. Only Hugging Face and Modal Labs have been named, leaving three affected services undisclosed. The incident highlights the risk of highly capable AI systems operating without effective containment and controls.

https://decrypt.co/374645/openais-rogue-ai-hacked-four-more-platforms-besides-hugging-face

Hackers Hijack Hotel Wi-Fi DNS to Steal Microsoft 365 Accounts

Hackers are compromising Wi-Fi systems at hotels and conference centres to redirect travellers to convincing fake Microsoft 365 login pages. The campaign, active since at least June, has affected organisations across financial services, legal, healthcare, energy, retail and other sectors worldwide. In some cases, attackers can bypass multi-factor authentication by tricking users into approving a legitimate-looking sign-in request, potentially giving them access to emails, documents and business communications. Exposure can be reduced through always-on, full-tunnel VPNs and disabling Microsoft device-code authentication where it is not needed.

https://www.bleepingcomputer.com/news/security/hackers-hijack-hotel-wi-fi-dns-to-steal-microsoft-365-accounts/

Response to Fraud Must Transform Faster, Warns City of London Police

Fraud and cyber crime now account for nearly half of all crime in the UK, prompting the City of London Police to call for a faster national response involving government, law enforcement and industry. Recent enforcement activity resulted in 557 arrests, £9 million frozen, and the seizure of £2.8 million in cash and £15.3 million in non-cash assets. The new Report Fraud service, launched in January 2026, is intended to improve reporting and intelligence gathering as criminals adopt increasingly sophisticated methods.

https://policeprofessional.com/news/response-to-fraud-must-transform-faster-warns-city-of-london-police/



Threats

Ransomware, Extortion and Destructive Attacks

Bad news — paying a ransomware demand might cause hackers to come back and ask for more | TechRadar

Companies are still paying ransoms to cyber criminals despite official advice | IT Pro

Over a third of ransomware victims re-extorted after paying

Ransomware groups take aim at vulnerable VPNs | CSO Online

Ransomware Groups Increasingly Deploy EDR Kill Techniques - Infosecurity Magazine

Chaos ransomware deploys browser-based msaRAT to evade network detection - Security Affairs

Ransomware is the Scoreboard

The Signs Were There: What the First Autonomous Ransomware Case Confirms | Trend Micro (US)

Ransomware gangs go after EMEA healthcare's supply chain - Help Net Security

ShinyHunters data leaks fuel $2,000 sextortion email scam

Clop ransomware targets Windchill, FlexPLM in data theft attacks

Ransomware Attacks Targeting Universities on the Rise - Infosecurity Magazine

LockBit5 and Qilin Lead Ransomware Attacks Against Italian Organizations

Ransomware and Destructive Attack Victims

Ernst & Young data breach claimed by ShinyHunters extortion gang

Education department says 607,000 records taken in cyber attack - BBC News

Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack - SecurityWeek

Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare

Phishing & Email Based Attacks

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

UK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisations | National Cyber Security Centre

Russian APT Laundry Bear perfects zero-click phishing attack | Computer Weekly

Microsoft Detects 7.6 Billion Email Phishing Threats as Teams Vishing Attacks Increases 10-Fold

Phishing Dominates as Initial Entry Method for Cyber-Attacks - Infosecurity Magazine

Email threat landscape: Q2 2026 trends and insights | Microsoft Security Blog

The best-funded companies open the most phishing attachments - Help Net Security

Opinion | AI is gaining ability to personalize cyberattacks, enabling phishing at scale - The Washington Post

ChatGPT Among Top 10 Most Impersonated Brands in Phishing Attacks - Infosecurity Magazine

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

LogoKit Phishing Kit Screenshots Victim Sites in Real Time - Infosecurity Magazine

Japanese firm transferred S$6 million in email impersonation scam; director of recipient company jailed - CNA

13M+ Emails Sent in Tech Support Scam Targeting Users, Organizations in Japan | Trend Micro (US)

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

Other Social Engineering

Microsoft Detects 7.6 Billion Email Phishing Threats as Teams Vishing Attacks Increases 10-Fold

Phishing Dominates as Initial Entry Method for Cyber-Attacks - Infosecurity Magazine

Opinion | AI is gaining ability to personalize cyberattacks, enabling phishing at scale - The Washington Post

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

A new vishing campaign is targeting Microsoft Teams – here's what users need to know | IT Pro

ShinyHunters data leaks fuel $2,000 sextortion email scam

macOS ClickFix Attack Deploys Atomic Stealer to Steal Passwords and Crypto Wallets

Steam forum ClickFix attacks infect gamers with XMRig cryptominers

2FA/MFA

Goodbye SMS or phone calls — Microsoft is making passkeys the default authentication process for businesses | TechRadar

Artificial Intelligence

Opinion | AI is gaining ability to personalize cyberattacks, enabling phishing at scale - The Washington Post

AI image fraud will cost $40 billion next year - can these international standards help? | ZDNET

Experts warn ChatGPT's Workspace Agent Builder can be hijacked to create malicious AI workers | TechRadar

One ChatGPT link could smuggle a rogue AI agent into your company

ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

US lawmakers push for AI 'kill switch' after OpenAI models go rogue - BBC News

An AI agent can pass every safety check and still leak secrets - Help Net Security

LLMs Are Getting Smarter, But Not Safer: Veracode 2026 GenAI Code Security Report Finds AI-Generated Code Security Has Stalled at 56% Pass Rate

Agentic Browsers Rewind Web Security by 20 Years

OpenAI's Rogue AI Hacked Four More Platforms Besides Hugging Face - Decrypt

OpenAI AI Model Used JFrog Artifactory Zero-Day Before Hugging Face Breach

Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files

Microsoft Copilot Deployments Delayed Over Security Concerns - Infosecurity Magazine

New Dolphin X malware uses AI to rank high-value targets

OpenAI-Hugging Face attack doesn't mean agents are evil – unless you tell them to be

Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do

Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack

After Mythos, zero trust alone won’t be enough against AI-powered attacks | Federal News Network

The OpenAI–Hugging Face Incident: A Watershed Moment for AI Governance, Contracting, and Enterprise Risk | Saul Ewing LLP - JDSupra

Hugging Face breach reignites open-weights debate, raises liability questions - Help Net Security

Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard - Infosecurity Magazine

One-click Claude Desktop Flaw Could Enable Hidden Prompt Injection And Code Execution

Your AI agents can reach data no one approved - Help Net Security

OpenAI models used Artifactory zero-days to escape to the internet

When AI Agents Escape Sandboxes, Old Security Rules Apply

Stronger AI Safety Requires Peeking Inside the 'Black Box'

Why The Biggest AI-Driven Cyber Threat Is Still Human Nature

The Signs Were There: What the First Autonomous Ransomware Case Confirms | Trend Micro (US)

Europe's Multilingual Reality Exposes AI Security Gaps

Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry

Escape Artists: 'Incorrigible' AI Models Resist Rehabilitation

Nvidia forms Open Secure AI Alliance to build open-source security tools

NVIDIA’s Open Security AI Alliance Is Missing Some Big Names - Infosecurity Magazine

Anthropic’s Claude Mythos finds weaknesses in encryption algorithms | CyberScoop

FBI sees Anthropic’s Mythos as a law enforcement challenge | FedScoop

Biggest ever MCP update brings metadata, cybersecurity enhancements - SiliconANGLE

Trump considering AI controls after OpenAI hacking incidents - BBC News

Why Mythos is the cybersecurity crisis we need | resource | SC Media

828 vulnerabilities exploited at AI companies since 2021: Microsoft takes the lead

Beyond the Patch: How AI Continues to Change Cyber Hygiene

250 Eiffel Towers' worth of waste: The AI boom's toxic hardware problem | ZDNET

Rogue AI cyber incident heralds new 'era of agentic autonomous attacks' | Insurance Times

Bots/Botnets

Despite multiple takedowns, botnets continue to grow | CyberScoop

New Dysphoria DDoS botnet spreads to 200k devices worldwide

Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

Cloud/SaaS

Microsoft Detects 7.6 Billion Email Phishing Threats as Teams Vishing Attacks Increases 10-Fold

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

A new vishing campaign is targeting Microsoft Teams – here's what users need to know | IT Pro

Confused Deputy Flaws Persist in Google Cloud, Microsoft Azure

Hackers are compromising hotel Wi-Fi gateways to hijack Microsoft 365 accounts | CSO Online

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

Your team isn’t "ignoring security." They’re just underwater. - The New Stack

Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain

macOS ClickFix Attack Deploys Atomic Stealer to Steal Passwords and Crypto Wallets

Steam forum ClickFix attacks infect gamers with XMRig cryptominers

Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

Cyber Crime, Organised Crime & Criminal Actors

Europol flags 4,340 'horrific' URLs linked to The Com

Europol Targets the Online Network Turning Teen Hackers Into Extortionists and Violent Offenders

When the hackers get hacked: The Klue breach and the new reality of third-party cyber risk | CSO Online

Data Breaches/Leaks

Ernst & Young data breach claimed by ShinyHunters extortion gang

Exposed credentials are giving attackers a head start many organizations don't see - Help Net Security

Education department says 607,000 records taken in cyber attack - BBC News

Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack - SecurityWeek

A record credential leak just changed the threat model. Your vendor rating did not | perspective | MSSP Alert

Chick-fil-A data breach affects more than 13,000 customers

Pope's official prayer app commits cardinal sin, leaks 700K+ users' info

Tens of thousands of university account logins found on dark web

Data breach at medical billing firm MCBS affects 1.26 million people

24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login

DentaQuest disclosed a data breach that impacted +23 million individuals

Origin Energy Data Breach Affects 900,000 Australians - SecurityWeek

Denial of Service/DoS/DDoS

New Dysphoria DDoS botnet spreads to 200k devices worldwide

Encryption

Anthropic’s Claude Mythos finds weaknesses in encryption algorithms | CyberScoop

Fraud, Scams and Financial Crime

AI image fraud will cost $40 billion next year - can these international standards help? | ZDNET

Police Professional | Response to fraud must transform faster, warns City of London Police

Stolen Meta and Google ad accounts are worth more than the money they hold - Help Net Security

Japanese firm transferred S$6 million in email impersonation scam; director of recipient company jailed - CNA

13M+ Emails Sent in Tech Support Scam Targeting Users, Organizations in Japan | Trend Micro (US)

Former policeman charged over French château ‘investment scam’

Call of Duty Mobile scam uses fake free points giveaway to hijack players' accounts - Help Net Security

Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments

Identity and Access Management

Goodbye SMS or phone calls — Microsoft is making passkeys the default authentication process for businesses | TechRadar

Flaws in Passkey Implementation Show Old Attacks Still Work

Insider Risk and Insider Threats

Why The Biggest AI-Driven Cyber Threat Is Still Human Nature

Experts warn ChatGPT's Workspace Agent Builder can be hijacked to create malicious AI workers | TechRadar

One ChatGPT link could smuggle a rogue AI agent into your company

ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

Internet of Things – IoT

Tengu botnet reboots Linux devices to survive removal - Help Net Security

The automotive software vulnerabilities hiding in your dashboard - Help Net Security

Experts warn 2.2 million cars could be at risk of hijacking via Bluetooth | TechRadar

Law Enforcement Action and Take Downs

Europol Targets the Online Network Turning Teen Hackers Into Extortionists and Violent Offenders

Police Professional | Response to fraud must transform faster, warns City of London Police

Europol flags 4,340 'horrific' URLs linked to The Com

FBI sees Anthropic’s Mythos as a law enforcement challenge | FedScoop

Man gets six years for hacking 750 women's Snapchat accounts

Japanese firm transferred S$6 million in email impersonation scam; director of recipient company jailed - CNA

Former policeman charged over French château ‘investment scam’

Council worker spared prison after four-day data-snooping spree

Linux and Open Source

Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

AI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/sched - Infosecurity Magazine

Malvertising

Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

SourTrade Malvertising Campaign Secretly Builds Malware in the Browser - Infosecurity Magazine

Malware

SourTrade Malvertising Campaign Secretly Builds Malware in the Browser - Infosecurity Magazine

Tengu botnet reboots Linux devices to survive removal - Help Net Security

New Dysphoria DDoS botnet spreads to 200k devices worldwide

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

Despite multiple takedowns, botnets continue to grow | CyberScoop

New Dolphin X malware uses AI to rank high-value targets

Hackers hid dangerous malware on a page hidden in Anthopic's Claude.ai domain | TechRadar

Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks

Hackers abuse Notepad++ plugins to stealthily install malware

Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers

macOS ClickFix Attack Deploys Atomic Stealer to Steal Passwords and Crypto Wallets

China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

Researchers replace downloaded macOS apps with evil twins, Apple shrugs

Golden Chickens Resurfaces With Four New Malware Families and Modular Implants

Steam forum ClickFix attacks infect gamers with XMRig cryptominers

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

Mobile

Iran-linked group caught hiding surveillance tools in fake apps | TechRadar

Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates

Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin

Is It Safe To Keep Using A Phone That No Longer Gets Update Support?

The US is charging an American citizen for wiping his phone at the border | The Verge

Call of Duty Mobile scam uses fake free points giveaway to hijack players' accounts - Help Net Security

Android malware detection collapses when the context stage comes out - Help Net Security

'Flying Eagle' Full-Service Mobile RAT Builder Wings Across China

Models, Frameworks and Standards

Examining the Unintended Consequences of the Online Safety Act - IT Security Guru

Commission publishes new guidance to support businesses' implementation of the Cyber Resilience Act - EU Reporter

New CREST AI Standards to Deliver AI-Enabled Pentesting Accreditation - Infosecurity Magazine

Outages

Microsoft 365 outage affects Teams, SharePoint and other services

Microsoft blames massive Microsoft 365 outage on maintenance bug

Cloudflare reveals what's behind major internet outages - Help Net Security

Passwords, Credential Stuffing & Brute Force Attacks

Exposed credentials are giving attackers a head start many organizations don't see - Help Net Security

Why Resetting Passwords No Longer Stops Attackers

Huntress warns about attack spree that hit 30 SonicWall customers in 2 days | CyberScoop

macOS ClickFix Attack Deploys Atomic Stealer to Steal Passwords and Crypto Wallets

Goodbye SMS or phone calls — Microsoft is making passkeys the default authentication process for businesses | TechRadar

Flaws in Passkey Implementation Show Old Attacks Still Work

A record credential leak just changed the threat model. Your vendor rating did not | perspective | MSSP Alert

24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login

I'm not letting Claude touch my passwords, no matter how safe Anthropic claims it is

Regulations, Fines and Legislation

Commission publishes new guidance to support businesses' implementation of the Cyber Resilience Act - EU Reporter

Examining the Unintended Consequences of the Online Safety Act - IT Security Guru

US lawmakers push for AI 'kill switch' after OpenAI models go rogue - BBC News

Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry | The Record from Recorded Future News

The US is charging an American citizen for wiping his phone at the border | The Verge

Huawei ban to cost the EU up to €40 billion, says industry – POLITICO

Industry's message on CIRCIA: Please ask us fewer questions about cyberattacks | CyberScoop

The government has delivered its verdict on the proposed UK VPN ban | The Independent

AI, audits and OSINT featured in House intel bill | Federal News Network

Rubio restricts visas for sextortionists, cyber scammers | CyberScoop

Google Fined €890M Under EU Digital Markets Act Over Search and Play Store Practices

US launches trade probe into EU over big tech fines | Euronews

Trump Administration Bans New Chinese AI Robots and Power Inverters Over National Security Fears: 'These - Benzinga

Shadow IT

Shadow AI incident response begins with logs that may already be gone - Help Net Security

Shadow AI agents are multiplying. Here's how to find and secure them.

Social Media

Man gets six years for hacking 750 women's Snapchat accounts

Meta tackles AI-generated accounts with a free Facebook verification badge - Help Net Security

Software Supply Chain

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

Supply Chain and Third Parties

When the hackers get hacked: The Klue breach and the new reality of third-party cyber risk | CSO Online

Ransomware gangs go after EMEA healthcare's supply chain - Help Net Security


Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity

Cyber Warfare and Cyber Espionage

Iran-linked group caught hiding surveillance tools in fake apps | TechRadar

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

UK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisations | National Cyber Security Centre

Finnish Intelligence Warns of Russian Cyberattacks - Freedom

The Red Cross plans to extend its protection to cyberspace - SWI swissinfo.ch

Ukrainian hackers cause Russian air defense to shoot down a Su-57 fighter | TechRadar

Can Cyber Operations Be Deterred? What Wargames Reveal

China

China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

Huawei ban to cost the EU up to €40 billion, says industry – POLITICO

Trump Administration Bans New Chinese AI Robots and Power Inverters Over National Security Fears: 'These - Benzinga

Open weights vs. closed: An AI civil war's afoot, and the stakes are existential | ZDNET

Researchers Say a 'Ghost' Chinese Company Built the Network Hiding PLA Cyberattacks

'Flying Eagle' Full-Service Mobile RAT Builder Wings Across China

Russia

Year-long Russian attacks infect users as soon as they look at an email

Laundry Bear pivots to new exploit days after Zimbra alert | Computer Weekly

Russian hackers exploit Exchange OWA zero-day for long-term mailbox access

UK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisations | National Cyber Security Centre

Finnish Intelligence Warns of Russian Cyberattacks - Freedom

Russian Intelligence Hackers Phish Signal Backup Keys to Hijack Accounts and Messages

Ukrainian hackers cause Russian air defense to shoot down a Su-57 fighter | TechRadar

How Ukrainian Cyber Operation May Have Led to Downing of russian Su-57 Near Moscow | Defense Express

Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity

North Korea

Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet

Nearly 100,000 cyberattacks hit foreign ministry, affiliates in 6 months - The Korea Times

Iran

Iran-linked group caught hiding surveillance tools in fake apps | TechRadar

Handala Hacker Group claims cyberattack on U.S. communications infrastructure

Iran-Linked Actors Breach Are Targeting US Water and Energy Control Systems

America is playing Iran’s game – Middle East Monitor


Tools and Controls

Why Resetting Passwords No Longer Stops Attackers

73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack

Is Patching Dead? Vulnerability Management in the Post-Mythos Era - SecurityWeek

Has your security stack become your biggest cyber risk? | ChannelPro

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

Ransomware groups take aim at vulnerable VPNs | CSO Online

Ransomware Groups Increasingly Deploy EDR Kill Techniques - Infosecurity Magazine

The government has delivered its verdict on the proposed UK VPN ban | The Independent

Goodbye SMS or phone calls — Microsoft is making passkeys the default authentication process for businesses | TechRadar

Flaws in Passkey Implementation Show Old Attacks Still Work

OpenAI models used Artifactory zero-days to escape to the internet

When AI Agents Escape Sandboxes, Old Security Rules Apply

Google's solution to hacker name confusion? Yet another naming system | CyberScoop

Securing What Matters: Why Cyber Resilience Needs Prioritisation - IT Security Guru

Shadow AI incident response begins with logs that may already be gone - Help Net Security

New CREST AI Standards to Deliver AI-Enabled Pentesting Accreditation - Infosecurity Magazine

Microsoft tightens Windows enterprise activation security - Help Net Security

They might have grown up online — but Gen Z are apparently far less likely to use antivirus, study finds | TechRadar

Vulnerability management needs an update for the AI era | TechTarget




Vulnerability Management

Is Patching Dead? Vulnerability Management in the Post-Mythos Era - SecurityWeek

The shrinking exploit window and what it means for cybersecurity teams | native | MSSP Alert

Mythos Asks the Right Question. It Doesn't Answer It.

828 vulnerabilities exploited at AI companies since 2021: Microsoft takes the lead

Is It Safe To Keep Using A Phone That No Longer Gets Update Support?

Vulnerabilities

Critical Flaw Led to Azure Cosmos DB Pwnage - SecurityWeek

Cyber Firm Wiz Says Flaw Could Have Exposed Thousands of Microsoft Cloud Customers

Confused Deputy Flaws Persist in Google Cloud, Microsoft Azure

Google says AI helped Chrome fix 1,072 security bugs in two releases

Google Releases Patches for 370 Vulnerabilities in Chrome 151 - Infosecurity Magazine

Oracle drops 1,449 security patches like it's the new normal

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Critical VM Escape Vulnerability Patched in VMware ESXi - SecurityWeek

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files

One-click Claude Desktop Flaw Could Enable Hidden Prompt Injection And Code Execution

Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe - SecurityWeek

Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day - SecurityWeek

Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass

Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data

Unpatched Fastjson Vulnerability Exploited in Attacks - SecurityWeek

Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers

GitLab Users Urged to Patch After Research Reveals Critical RCE Chain - Security Affairs

Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard - Infosecurity Magazine

JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077) - Help Net Security

JFrog Patches Flaws Behind OpenAI Models' Escape

AI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/sched - Infosecurity Magazine

New Certighost PoC exploit lets attackers hijack Windows domains

n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats

Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js

Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root

Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads

Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say

vBulletin fixes critical pre-auth RCE flaw with public exploit

PTC Windchill Vulnerability Exploited in Ransomware Campaign - SecurityWeek

828 vulnerabilities exploited at AI companies since 2021: Microsoft takes the lead


Sector Specific

Industry specific threat intelligence reports are available.

Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.

  • Automotive

  • Construction

  • Critical National Infrastructure (CNI)

  • Defence & Space

  • Education & Academia

  • Energy & Utilities

  • Estate Agencies

  • Financial Services

  • FinTech

  • Food & Agriculture

  • Gaming & Gambling

  • Government & Public Sector (including Law Enforcement)

  • Health/Medical/Pharma

  • Hotels & Hospitality

  • Insurance

  • Legal

  • Manufacturing

  • Maritime & Shipping

  • Oil, Gas & Mining

  • OT, ICS, IIoT, SCADA & Cyber-Physical Systems

  • Retail & eCommerce

  • Small and Medium Sized Businesses (SMBs)

  • Startups

  • Telecoms

  • Third Sector & Charities

  • Transport & Aviation

  • Web3


Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.

Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.

You can also follow us on Facebook, Twitter and LinkedIn.

Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.

Next
Next

Black Arrow Cyber Threat Intelligence Briefing 24 July 2026