Cybersecurity Brief – 2026-07-09
Major Incidents or Breaches
- AssuranceAmerica disclosed a data breach affecting approximately 6.9 million drivers after attackers accessed its systems earlier this year, exposing sensitive driver records [15].
- Mount Royal University in Calgary confirmed a breach in which hackers accessed and deleted data from the university’s file storage systems, including employee, student, and university data [17][35].
- Accenture confirmed a data breach following hacker claims of source code theft. The company stated the incident was contained and did not impact operations or service delivery [40].
- Japanese telecommunications company KDDI reported a breach impacting 12 million individuals, caused by attackers exploiting a zero-day in a third-party system to access an ISP email system [32].
- Madison Square Garden was found to have maintained a database categorizing celebrities, including sensitive labels such as “LGBTQIA” and risk ratings, raising privacy and surveillance concerns [28].
Newly Discovered Vulnerabilities
- Microsoft released patches for the Defender vulnerability known as RoguePlanet (CVE-2026-50656), which could allow privilege escalation to SYSTEM level. The flaw was publicly disclosed prior to patch release [5][16][34][42].
- Ubiquiti issued updates for multiple critical vulnerabilities affecting UniFi Connect, Talk, Access, Protect, and OS products, which could enable privilege escalation and arbitrary code execution [12].
- Researchers disclosed a 15-year-old Linux kernel vulnerability dubbed GhostLock, present in all major distributions since 2011, allowing attackers to gain root access [33].
- Tenda firmware was found to contain an unpatched backdoor (CVE-2026-11405) that grants unauthenticated attackers admin access to device web management interfaces [39].
- Google Chrome 150 update resolved 27 vulnerabilities, including 13 use-after-free bugs and two critical-severity flaws [37].
Notable Threat Actor Activity
- A new ransomware family named GodDamn is using the PoisonX kernel driver, signed by Microsoft, to disable endpoint security software as part of its defense evasion tactics, with attacks targeting US companies [4][23].
- The threat actor Lurking Lizard is distributing fake 7-Zip installers to turn victim devices into nodes for a malicious residential proxy network [9].
- China-linked threat clusters have exploited Roundcube vulnerabilities at US and Canadian universities to steal credentials and deploy backdoor malware [19].
- A China-linked APT associated with the LapDogs campaign has expanded its toolkit with new SOHO router backdoors: LongLeash, DogLeash, and JarLeash [41].
- Malicious packages mimicking Paysafe, Skrill, and Neteller SDKs were found on npm and PyPI, delivering stealer malware to developers and users of payment applications [18].
- The Vidar infostealer is targeting SMBs via malvertising campaigns that lure users with cracked or pirated software, delivering malware for both data theft and cryptomining [27].
Trends, Tools, or Tactics of Interest
- Multiple reports highlight the increasing speed and sophistication of AI-driven attacks, with attackers using AI models to rapidly craft targeted lures, automate testing, and pivot to new targets within minutes [2][21].
- AI coding agents and assistants are being actively exploited or manipulated:
- Proof-of-concept attacks show that code review agents can be tricked into running malicious code on developer machines [7].
- The GhostApproval attack leverages symlink flaws in six popular AI coding assistants to allow malicious repos to execute code on developer systems [8][36].
- HalluSquatting attacks trick AI coding assistants into fetching and installing non-existent, attacker-controlled packages, leading to botnet malware infections [11].
- AI coding agents have been observed triggering endpoint security rules, sometimes mimicking human attacker behaviors and causing operational confusion [10].
- AI gateways, which provide access to models and cloud infrastructure, are emerging as high-value targets, with incidents demonstrating their potential to expose IAM data and facilitate cryptomining [22].
- Attackers are chaining weaknesses in AI workflows, cloud misconfigurations, and stolen credentials to breach cloud environments, as demonstrated in a case where a lone attacker compromised an AWS environment in 72 hours [26].
- Voice phishing (vishing) campaigns are targeting Microsoft 365 users by impersonating security requests to enroll new Entra passkeys, aiming to bypass multi-factor authentication [20].
- AI-powered service desk attacks are becoming more convincing and scalable, leveraging generative AI for social engineering and impersonation [21].
- There is a growing trend of malicious software distribution through developer ecosystems, such as fake SDKs on npm and PyPI [18], and the use of cracked software as lures in malvertising [27].
Regulatory or Policy Developments Affecting the Security Industry
- Microsoft announced the upcoming retirement of the Outlook Web Access (OWA) Light client in Exchange Server, impacting organizations relying on this lightweight email client [13].
- A global anti-fraud operation led by law enforcement agencies resulted in the arrest of 5,811 suspects and the seizure of $293 million in illicit assets across 97 countries [14].
- A survey revealed that European organizations may have an inflated sense of security regarding their collaboration tools and platforms, indicating a confidence gap in collaboration security practices [24].
Sources#
- AssuranceAmerica data breach exposes records of 6.9 million drivers - bleepingcomputer.com
- Mount Royal University confirms breach as hackers claim attack - bleepingcomputer.com
- Mount Royal University Confirms Data Stolen in Ransomware Attack - securityweek.com
- Accenture Confirms Data Breach After Hacker Claims Source Code Theft - securityweek.com
- 12 Million Impacted by Data Breach at Japanese Telco KDDI - securityweek.com
- Madison Square Garden Kept a List of Gay Celebrities - wired.com
- Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges - thehackernews.com
- Microsoft patches RoguePlanet Defender zero-day vulnerability - bleepingcomputer.com
- Microsoft Patches Defender ‘RoguePlanet’ Vulnerability - securityweek.com
- Microsoft fixes RoguePlanet zero-day in Defender - malwarebytes.com
- Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS - thehackernews.com
- 15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google - securityweek.com
- Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices - securityweek.com
- Chrome 150 Update Patches 27 Vulnerabilities - securityweek.com
- GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses - thehackernews.com
- 'GodDamn' Ransomware Uses BYOVD to Smite US Companies - darkreading.com
- Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes - thehackernews.com
- Hackers exploit Roundcube flaw to spy on academic researchers - bleepingcomputer.com
- China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors - securityweek.com
- Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials - bleepingcomputer.com
- Vidar Infostealer Hammers SMBs via Malvertising Campaign - darkreading.com
- AI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps Up - thehackernews.com
- 3 Ways AI Powers Service Desk Attacks and How to Prevent Them - bleepingcomputer.com
- Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It - thehackernews.com
- GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents - thehackernews.com
- AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique - securityweek.com
- New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware - thehackernews.com
- AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers - thehackernews.com
- AI Gateways Offer Attackers the Keys to the Kingdom - darkreading.com
- Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours - darkreading.com
- Entra passkey enrollment vishing targets Microsoft 365 users - bleepingcomputer.com
- Microsoft to retire the OWA Light client in Exchange Server - bleepingcomputer.com
- Police arrests 5,800 suspects in global anti-fraud crackdown - bleepingcomputer.com
- European Organizations Have a Collaboration Security Confidence Gap - darkreading.com