CYBERSECURITY WEEKLY REPORT: WEEK OVERVIEW
Welcome to this week’s cybersecurity weekly report. Scale and speed both broke records this week. Microsoft shipped 570 patched vulnerabilities in a single Patch Tuesday – nearly triple June’s already record-setting release while SonicWall confirmed two SMA 1000 zero-days had been under active exploitation since late June, giving federal agencies a five-day KEV remediation window.
On the geopolitical front, France and the European Union formally attributed a decade-plus cyberespionage campaign to Russia’s FSB Center 16 (Turla), backing the attribution with EU/UK sanctions on 24 individuals and entities and a joint NSA/CISA/FBI advisory on router-hygiene failures being exploited by the same actor set.
Third-party and cloud exposure was the connective tissue running through this week’s breach disclosures. EY’s client tax documents, Ecopetrol’s cloud file storage, and Lidl’s customer database were all compromised through vendor or platform relationships rather than direct network intrusion.
At the same time, AI tooling kept sliding from productivity aid toward offensive infrastructure: researchers documented a suspected China-linked campaign that used Claude Code and DeepSeek as working parts of an active intrusion chain, and industry discussion of Sysdig’s JadePuffer findings hasn’t slowed – still cited this week as the first ransomware operation reported to have run end-to-end under autonomous AI control.
The throughline for security leaders reading this cybersecurity weekly report: patch backlogs, vendor risk, and AI-accelerated tradecraft are no longer arriving as separate problems. They’re compounding each other.
MAJOR INCIDENTS
1. Ernst & Young (EY) – third-party IT platform breach exposes client tax data
Attackers accessed a third-party IT service management platform used by EY’s tax practice between March 28 and April 12, 2026, downloading documents containing client tax information. EY detected the anomalous activity on April 23, filed breach notifications with the California Attorney General’s office on July 15 and Vermont regulators the following day, and began mailing individual notice letters dated July 13.
Exposed data may include Social Security numbers, financial account codes, and credit/debit account information tied to a number of tax clients; the total affected count has not been disclosed. EY says it has found no evidence the data has been misused and is offering Experian identity monitoring. Why this matters: Support-ticket platforms routinely carry sensitive attachments as a matter of workflow convenience a pattern replicated across professional-services firms that a single compromised vendor can turn into a mass-disclosure event months after the fact. Read More
2. Ecopetrol – cloud storage breach and blocked ransomware attempt across 15 subsidiaries
Colombia’s state-controlled energy giant disclosed on July 17 that an external actor gained unauthorized access to cloud-based file storage used by roughly 15 group entities, downloading data tied to approximately 3,300 user accounts before attempting to deploy ransomware. Ecopetrol says its cybersecurity controls blocked the encryption attempt, and it has found no material disruption to operations or production. The attacker has since issued extortion demands threatening to publish the stolen data.
Ecopetrol filed a criminal complaint with Colombia’s Attorney General’s office and says it cannot yet rule out a “material adverse effect” on its business or financial condition. Why this matters: Ecopetrol accounts for more than 60% of Colombia’s hydrocarbon production — a blocked ransomware payload doesn’t eliminate the exposure risk from the data already exfiltrated, and critical-infrastructure operators should read this as a near-miss, not a non-event. Read More
3. Lidl – third-party IT provider breach exposes online shop customers in three countries
Lidl confirmed on July 13 that a cyberattack on an external IT service provider exposed personal data belonging to online shop customers in Germany, Belgium, and the Netherlands. Stolen data includes names, phone numbers, email addresses, dates of birth, and customer numbers, pulled from a separately stored file; Lidl says passwords, payment details, and shipping/billing addresses were not affected and that the shop platform itself was not breached.
The retailer has not disclosed the number of affected customers or named the compromised provider, and has notified Dutch and Belgian data protection authorities. Why this matters: This is the second major EU retail supply-chain disclosure in recent months (Lidl joins a pattern documented after Deutsche Bank ransomware claims earlier in July), reinforcing that GDPR notification obligations increasingly hinge on vendor incident response, not just first-party controls. Read More
4. Government of Kenya – presidential website defaced with Bitcoin ransom demand
On July 18, hackers defaced the official website of President William Ruto, replacing the homepage with insulting messages and a five-Bitcoin (~KSh41.3 million / ~$320,000) ransom demand, threatening to leak government information if unpaid by a set deadline. Kenya’s ICT Authority restricted public access to contain the incident and begin forensic analysis; Cabinet Secretary William Kabogo stated no evidence of data exfiltration or loss has been found so far, though the investigation into backend system access continues. Why this matters: This is at least the second high-profile Kenyan government web defacement in under a year, and a ransom-timed defacement targeting a head-of-state domain signals attackers are treating government reputational damage, not just data theft, as monetizable leverage. Read More
ANALYST INSIGHT: Three of this week’s four major incidents – EY, Ecopetrol, and Lidl – trace back to a vendor, cloud storage layer, or third-party platform rather than the victim’s own perimeter. None involved a novel technique; all involved data that was one degree removed from the named organization’s direct control. Security teams that have mapped their own attack surface but not their vendors’ incident-response maturity are working from an incomplete threat model, and this week is a reminder that “we weren’t breached, our provider was” is rapidly becoming a distinction without a difference for affected individuals.
NEW VULNERABILITIES & PATCHES
[CVE] CVE-2026-15409 / CVE-2026-15410 – SonicWall SMA 1000 Series (actively exploited)
CVE-2026-15409 is a critical (CVSS 10.0) unauthenticated SSRF flaw in the SMA1000 Workplace interface; CVE-2026-15410 is a high-severity (CVSS 7.2) post-authentication code injection bug in the Appliance Management Console. SonicWall confirmed both were chained together in zero-day attacks observed by Rapid7 as early as June 22 and July 9, with attackers extracting credentials, session databases, and TOTP MFA seeds before pivoting into internal Active Directory via VPN-less authentications. CISA added both to the KEV catalog on July 14 with a federal remediation deadline of July 17. Mitigation: Apply hotfixes 12.4.3-03453 or 12.5.0-02835; where indicators of compromise are present, SonicWall recommends re-imaging hardware appliances, resetting all passwords, and rotating TOTP tokens rather than trusting an in-place patch alone.
[CVE] CVE-2026-56164 – Microsoft SharePoint Server Elevation of Privilege (actively exploited zero-day) Part of July’s record 570-flaw Patch Tuesday, this missing-authentication flaw lets a remote attacker elevate privileges over the network with no disclosed exploitation details released by Microsoft. Mitigation includes enabling Antimalware Scan Interface (AMSI) with Request Body Scan set to Full mode as an interim compensating control. Risk: SharePoint continues to be one of the most consistently targeted enterprise platforms; an EoP bug being exploited before broad awareness of the flaw compresses the available patch window for defenders.
[CVE] CVE-2026-53565 / CVE-2026-53566 – Citrix Secure Access Client & Endpoint Analysis Client for Windows
CVE-2026-53565 (CVSS v4.0: 8.5) is an improper privilege management flaw letting a standard local user escalate to full SYSTEM with no user interaction; CVE-2026-53566 (CVSS v4.0: 6.8) is an out-of-bounds read affecting Secure Access Client where the DNE driver isn’t installed. Disclosed in Citrix Bulletin CTX696734 on July 14. Mitigation: Upgrade Citrix Secure Access Client for Windows to 26.6.1.20+ and Endpoint Analysis Client to 26.5.1.7+; treat shared workstations and VDI images as priority patch targets given the low bar for exploitation.
[CVE] OpenSSL “HollowByte” memory-exhaustion DoS (no CVE assigned)
Disclosed by Okta’s Red Team, an 11-byte crafted TLS handshake payload can trigger pre-validation memory allocation of up to 131KB per connection, and repeated connections with randomized claimed sizes cause severe glibc heap fragmentation that persists even after the offending connections close. OpenSSL fixed the issue through incremental buffer growth in v4.0.1, silently backported to 3.6.3, 3.5.7, 3.4.6, and 3.0.21 – notably without a CVE identifier, which several researchers flagged as a discoverability problem for standard vulnerability scanning. Mitigation: Upgrade OpenSSL regardless of CVE status; separately audit embedded OpenSSL copies bundled inside language runtimes (Node.js, Python, Ruby, PHP), since OS-level package updates won’t reach those.
[CVE] Fortinet – seven flaws across FortiOS, FortiProxy, FortiPAM, FortiSASE, and FortiSandbox
Fortinet’s July patch cycle addressed seven vulnerabilities spanning nearly its entire security product line, alongside SAP’s July Patch Day fixes for critical NetWeaver, Approuter, and Commerce Cloud flaws, and F5’s patches for three NGINX issues (RCE, memory disclosure, DoS). Mitigation: Prioritize FortiOS and FortiProxy given their internet-facing exposure and history as initial-access vectors in ransomware intrusions this year (INC Ransom’s FortiBleed exploitation earlier this month is a recent precedent).
PRIORITY ACTION: If your organization runs SonicWall SMA1000 appliances, that patch supersedes everything else on this list – assume compromise if the appliance has been internet-facing since June 22 and follow SonicWall’s re-imaging guidance rather than a simple in-place update. Everyone else should treat this month’s SharePoint and Citrix fixes as 48-hour, not next-sprint, priorities.
RANSOMWARE ACTIVITY
UK prosecutors landed the country’s largest cybercrime conviction to date this week. Two Scattered Spider members received 66-month sentences after disrupting Transport for London, a breach that caused an estimated $39 million in losses and recovery costs. Separately, U.S. authorities charged three Russian nationals over Media Land and ML.Cloud, bulletproof-hosting services tied to roughly $62 million in losses across multiple ransomware campaigns, and the U.S. Treasury sanctioned a VPN provider and cryptor seller linked to billions in ransomware-facilitated losses.
On the technical side, ShinyHunters-linked actors (operating under the “Trinity of Chaos” branding alongside Scattered Spider and Lapsus$-associated affiliates) launched a new Tor leak site listing 39 companies tied to earlier Salesforce-instance compromises, extending a shift toward pure data-theft extortion without encryption. Leak-site tracking this week also recorded continued high-tempo activity from Deadlock (11 victims in a single 24-hour window, concentrated in construction/engineering and professional services) and INC Ransom’s ongoing exploitation of FortiBleed against government and professional-services targets.
Industry discussion hasn’t let up around Sysdig’s JadePuffer disclosure (published July 1, still actively cited across this week’s coverage). Researchers assess it as the first ransomware operation executed end-to-end by an autonomous LLM agent from initial access via a Langflow RCE (CVE-2025-3248) through credential harvesting, lateral movement to a Nacos configuration server, and destructive encryption of 1,342 configuration items, adapting in real time (one observed sequence went from failed login to working exploit in 31 seconds). Sysdig found the agent had accessed API keys for OpenAI, Anthropic, DeepSeek, and Gemini during the operation.
CYBERINFOS TAKEAWAY: The Scattered Spider sentencing and the JadePuffer case sit at opposite ends of the same trend line: as human-operated ransomware crews face longer sentences and harder attribution, the skill floor for running a comparable attack is dropping toward whatever it costs to rent an LLM agent. If the single thing you remember from this week is one number, make it 31 seconds – that’s how fast an autonomous agent adapted from a failed login to a working exploit path with no human at the keyboard.

THREAT INTELLIGENCE
France’s Cyber Crisis Coordination Centre (C4) – combining ANSSI, COMCYBER, DGA, DGSE, and DGSI – formally attributed a cyberespionage campaign dating to at least 2014 to Turla (aka Secret Blizzard, Venomous Bear), tied to the FSB’s 16th Center (Military Unit 71330). Targets spanned French ministries, the French Embassy in Moscow, defense-linked technology firms, and justice-sector organizations.
[TTP] Turla still leans on Kazuar, a multi-platform backdoor active since 2016, alongside compromised WordPress sites, peer-to-peer relay infrastructure, and satellite communications for C2 – evidence the group updates tooling rather than retiring it. The EU and UK followed with coordinated sanctions on 24 Russian individuals and entities the same day, also tying FSB Center 16 to a failed December 2025 attack on Poland’s energy grid that could have cut power to roughly half a million people.
That attribution was reinforced by a joint advisory from NSA, CISA, FBI, DC3, and more than a dozen allied agencies (Australia, Canada, New Zealand, UK, and several EU states), warning that FSB Center 16 – also tracked as Ghost Blizzard, Energetic Bear, and Static Tundra – keeps up opportunistic scanning for poorly configured routers across communications, energy, financial services, healthcare, and government-facilities sectors.
[TTP] The group primarily abuses default SNMP community strings and Cisco’s Smart Install feature to exfiltrate device configurations, credentials, and VPN details over TFTP to leased infrastructure; CISA added a 2008-era Cisco IOS flaw (CVE-2008-4128) to its KEV catalog this week specifically because Center 16 is still exploiting it on unsupported devices.
In a different theater entirely, researchers at Hunt.io disclosed a suspected China-linked espionage campaign that embedded Claude Code and DeepSeek-v4-pro directly into an active intrusion chain targeting government systems in Afghanistan, Thailand, and Taiwan, with reconnaissance-only probing against U.S. targets (no confirmed U.S. breach). An exposed operator directory containing 2,431 files revealed a split-model workflow: Claude Code handled agentic execution bash commands, session persistence, task parallelization while DeepSeek-v4-pro handled attack reasoning, exploit adaptation, and phishing-page generation.
The Thailand intrusion shows what that workflow looks like in practice. Attackers used SQLMap to compromise a government administrative system via SQL injection, then deployed a web shell disguised as a GIF file. This marks the second publicly reported case of Claude Code implicated in state-linked intrusion activity, following Anthropic’s November 2025 disclosure.
CYBERINFOS analyst note: the France/EU Turla attribution and the FSB Center 16 router advisory describe the same actor set from two different angles one diplomatic and legal, one technical released on the same day. Treat them as a single intelligence package: the router-hygiene mitigations in the joint advisory are the concrete defensive response to the campaign France just attached a name and a decade of history to.
INDUSTRY NEWS
FSB Center 16 attribution triggers coordinated Western response.
Beyond the sanctions and advisory detailed above, the joint action represents one of the broader multilateral cyber-attribution efforts of the year, spanning legal (EU/UK sanctions), diplomatic (French summons of Russia’s chargé d’affaires), and technical (18-agency advisory) tracks simultaneously. Why security teams should care: attribution of this scope typically precedes follow-on retaliatory or opportunistic activity from affiliated groups expect continued targeting of routers and edge devices at organizations in the named critical-infrastructure sectors through Q3.
Microsoft’s AI-assisted vulnerability discovery is reshaping patch volume, not just this month’s count.
Microsoft attributed July’s record 570-flaw release partly to an AI-powered scanning system now deployed against its own codebase; year-to-date, Microsoft has patched 1,308 vulnerabilities through July 2026 almost double the same period last year. Patch management teams should expect this volume increase to be structural rather than a one-off spike, and budget testing and deployment cycles accordingly rather than treating July as an anomaly.
Regulatory pressure on ransomware payment facilitation keeps building.
The U.S. Treasury’s sanctions against a VPN provider and cryptor seller, layered onto this week’s Media Land/ML.Cloud bulletproof-hosting indictments, extend a pattern of targeting ransomware’s infrastructure suppliers rather than only the operators themselves. The practical takeaway: organizations with cyber-insurance policies or incident-response retainers should confirm their negotiators are actively screening against updated OFAC lists, since sanctioned-infrastructure exposure can complicate or block a ransom payment even when an organization is otherwise willing to pay.
Kenya’s National Computer and Cybercrime Coordination Committee reported over 3 billion cyberattacks against government, cloud, and critical-sector systems in a three-month window
in 2026, alongside this week’s presidential website defacement underscoring that government digital-services expansion in emerging markets is currently outpacing defensive investment. For organizations operating in East Africa, or any market on a similar digitization trajectory, the “government website ransom defacement” pattern is likely to recur rather than staying an isolated event.
TOOL UPDATES
ANY.RUN: Merged its threat intelligence feeds directly into its interactive malware sandbox this week, letting analysts pivot from detonation output to attribution data inside a single workflow rather than switching platforms mid-investigation – a meaningful time saver for SOC teams handling high sample volumes.
Cloudflare Application Security: Shipped new managed detection rules this week targeting an unauthenticated memory-disclosure flaw in Citrix NetScaler ADC/Gateway (CVE-2026-8451) and a pre-authentication RCE in Progress Kemp LoadMaster (CVE-2026-8037), giving WAF-layer virtual patching to organizations still testing vendor fixes.
Proofpoint’s Emerging Threats ruleset: Kept up its typical high-cadence releases, adding detection coverage this period for a Langflow AI path-traversal file-write vulnerability and an Exchange EWS SSRF flaw both relevant given Langflow’s role as JadePuffer’s initial-access vector earlier this month.
Next.js: Announced a formal, pre-scheduled monthly security release program starting this week, following the model long used by Node.js, PHP, and major Linux distributions – a practical shift for any team currently treating framework security patches as ad-hoc events rather than a predictable release train.
LOOKING AHEAD
Expect continued fallout from the record Patch Tuesday well into next week, as organizations work through 570 patched flaws across Windows, SharePoint, Exchange, and Office testing backlogs at this scale typically extend remediation timelines by two to three weeks beyond a normal cycle. CISA’s federal remediation deadline for the SonicWall SMA1000 KEV entries has already passed (July 17), so expect follow-up reporting on post-compromise indicators at organizations that missed the window.
[WATCH] Ecopetrol’s extortion threat remains unresolved. As of this report, the attacker behind the Ecopetrol breach had not yet published any of the roughly 3,300 accounts’ worth of stolen data, and the company has not disclosed whether it intends to negotiate. Watch for either a leak-site posting or a formal “no payment” statement in the coming week, which will materially change the incident’s regulatory and reputational trajectory.
Also worth monitoring: further scope disclosures from EY as state attorneys general publish their own breach-notification filings, and whether additional Center 16-linked router compromises surface now that the joint advisory has put defenders on alert globally.
BY THE NUMBERS
| Metric | Figure | Source context |
|---|---|---|
| Vulnerabilities patched, Microsoft July 2026 Patch Tuesday | 570 (59 Critical) | Record-breaking; up from June’s prior record |
| Microsoft CVEs patched year-to-date (through July 2026) | 1,308 | Nearly double the same period in 2025 |
| SonicWall SMA1000 KEV remediation deadline | July 17, 2026 | CISA BOD 26-04 |
| Ecopetrol accounts affected | ~3,300, across ~15 subsidiaries | Company disclosure, July 17 |
| Scattered Spider sentencing | 66 months each, 2 defendants | UK’s largest cybercrime prosecution |
| Bulletproof hosting losses tied to Media Land/ML.Cloud indictment | ~$62 million | U.S. DOJ |
| London TfL disruption cost (Scattered Spider) | ~$39 million | UK prosecution disclosure |
| EU/UK sanctioned individuals/entities (FSB Center 16) | 24 | Joint EU/UK sanctions, July 13 |
| JadePuffer failed-login-to-exploit adaptation time | 31 seconds | Sysdig Threat Research Team |
| Deadlock ransomware victims in 24 hours | 11 | Leak-site tracking, July 11 |
| Verified public data on total ransomware victims this reporting week | Unavailable at reporting time | Leak-site aggregation varies by tracker methodology |
This cybersecurity weekly report was compiled from publicly available security research, government advisories, and vendor disclosures published between July 13–19, 2026. CyberInfos.in will continue tracking developing items – including the Ecopetrol extortion timeline and further EY breach-scope disclosures – in next week’s report.
