GreenCyber / Light reading / Week ending 25 July 2026
Global Debrief, week of 19 to 25 July 2026
The complete global picture of the week, at board level and at security leader level, with nothing included that could not be stood up on a reputable source.
The complete global picture of the week in cybersecurity, at board level and at security leader level. Compiled 25 July 2026. Every item is dated to the week it happened, and anything that could not be stood up on a reputable source is not here.
For the board
Very little of this week was about breaking in.
Across four continents and every sector that reported, the access the attackers used was legitimate, borrowed, or simply left switched on. An Australian energy retailer with 4.8 million customers told the market that customer data had been disclosed, and the exposure sits inside a platform operated by somebody else. Attackers who had been inside remote access appliances for three weeks before a fix existed took credentials, live sessions and multi factor authentication seeds, which are exactly the things that keep working after the patch is installed. American agencies described state affiliated actors reaching industrial controllers using the vendors' own engineering software, with no malware involved. Russian state supported actors read Western government mailboxes because a user opened an email. A ransomware group stopped a food production line.
The continuity lesson of the week did not come from the incident. It came from the plant that kept running. One dairy business suspended production in the United States and continued in Canada, and that difference was decided years earlier by somebody who drew a boundary and paid to maintain it. Segmentation is a dull line in a board paper and it is one of the few controls that pays out precisely when everything else has already failed. The same week, a Swiss rail manufacturer confirmed a breach at a supplier platform, said publicly that it would not pay, and kept its production lines and its vehicles running. Both organisations had decided in advance what they were willing to lose.
Regulatory exposure moved in the same week as the incidents, not downstream of them. Three Australian agencies were engaged on one breach within a day of it being disclosed. A New York judge allowed a state attorney general's case against a major payments operator to proceed, on the argument that the platform was designed for adoption ahead of consumer safety. American federal agencies were given remediation deadlines measured in days rather than quarters. The question regulators are asking has shifted. It is no longer only what happened to you. It is what you designed, what you knew, and how quickly you said so.
Trust turned on partial information this week, which is where it usually turns. Customer records disclosed with the last four digits of a card attached are not a fraud problem, they are a credibility problem, because those four digits are what makes the next phone call sound legitimate. A Big Four firm notified clients that tax documents had been taken from a support platform. A healthcare software vendor serving thousands of hospitals and pharmacies confirmed data theft while still working out whose data it was. In every one of those cases the organisation had to publish a sentence before it had a number, and the sentence is what the market remembers.
Three questions worth putting to your next leadership meeting.
- If our data sits in a supplier's system today, who has read the clause that says whose obligation it is when that data is disclosed? Not the policy ..... the clause, and who signed it.
- When we patch an internet facing system, what is our process for deciding whether the attacker already holds credentials that survive the patch?
- If our largest site or line stopped tomorrow, what keeps running, and can someone prove the boundary exists rather than describe it?
For the security leader
Organised by industry sector, worst first within each. Sectors with no material activity this week do not appear.
Energy and utilities
Origin Energy discloses unauthorised access and disclosure of customer data
- Origin began investigating suspicious activity on 22 July and told the market on 23 July that there had been unauthorised access and disclosure of some customers' data.
- Confirmed data types: names, residential addresses, dates of birth, phone numbers and account details, plus limited payment information, being the last four digits of credit cards and the last three digits of bank account numbers.
- Origin has 4.8 million customers and has not said how many are affected. The Australian Federal Police, the Australian Cyber Security Centre and the Office of the Australian Information Commissioner are all engaged. Chief executive Frank Calabria said the priority is supporting customers and securing systems.
- Single source and unconfirmed, flagged as lighter: a person using the name Edison Walthour told The Australian they hold more than two million customer records, that access was obtained using the credentials of a former Origin employee still active on the Kraken customer management platform, and that a private settlement has been reached. Origin has declined to comment on the settlement and on the employee's status. The source is the person claiming responsibility.
- Context worth holding regardless of that claim: Kraken Technologies runs retail energy customer experience for Origin, Ergon Energy Retail and Nectr, and the platform operator's own material puts it at close to a third of Australian households.
Sources: Origin Energy market statements, 23 July 2026; reporting in The Australian for the attacker's claims, uncorroborated.
Financial services
New York court allows the attorney general's Zelle case to proceed
- On 22 July, Justice Phaedra Perry-Bond of the New York state court in Manhattan denied Early Warning Services' bid to dismiss the New York attorney general's suit over fraud on the Zelle payments platform.
- The court found the attorney general had sufficiently alleged that Early Warning prioritised accessibility, convenience, consumer adoption and market dominance ahead of consumer safety, over objections from its own banking partners.
- The state alleges more than one billion United States dollars was taken from Zelle users between 2017 and 2023, including 150,000 induced fraud reports in 2020 alone. Early Warning is owned by seven large American banks and has indicated it will appeal.
- The security leadership read: this is a design liability case, not a breach case. The allegation is about controls that were not built, and it survives at the pleadings stage. That is a different exposure from the one most fraud programmes are reported against.
Sources: Law360, American Banker, Reuters via syndication, 22 to 24 July 2026.
Healthcare
Craneware confirms data theft affecting customer, partner and employee records
- Craneware plc, the Edinburgh headquartered healthcare financial software provider, disclosed on 20 July that an unauthorised party accessed a subset of its data environment and exfiltrated data.
- The company supplies billing and revenue cycle software to roughly 2,000 United States hospitals and close to 10,000 clinics and retail pharmacies.
- Craneware says a significant volume of file names was viewed and exfiltrated, that a percentage of employee data and a subset of customer and partner records were taken, and that a large portion of what was accessed is non sensitive or already public regulatory information.
- The company states the incident is contained, customer services were not disrupted, and external specialists found no residual indicators of compromise. No group has publicly claimed responsibility.
- Scale context, not a claim about this incident: Craneware's 2021 acquisition of Sentry brought it into contact with records relating to approximately 147 million patients. Craneware has not said whether any of that data was involved.
Sources: Craneware disclosure, 20 July 2026; TechCrunch, Cybersecurity Dive, IT Pro, 20 to 21 July 2026.
Abbott Laboratories, extortion deadline passes without publication
- Dated context rather than in window news. Abbott confirmed in mid July that it was investigating unauthorised access to legacy Exact Sciences systems in its Cancer Diagnostics business, and separately a claim involving its LabCentral portal.
- The in window development: the ShinyHunters extortion group's deadline, first set at 18 July and extended to 21 July, passed. As at 20 July no data had been published and it is not known whether any payment was made.
- The group claims manufacturing certificates, operation manuals, technical specifications, regulatory documentation and assay files, and says no customer data was taken. Abbott has not confirmed the contents of the claim.
- Initial access is reported as a voice phishing campaign against employees the prior month, reaching a corporate Microsoft Entra single sign on account.
Sources: BleepingComputer, HIPAA Journal, Malwarebytes Labs, 16 to 20 July 2026.
Manufacturing and OT
AA26-097A updated: Iranian affiliated actors reaching programmable logic controllers
- American agencies updated advisory AA26-097A on 22 July. It was first published in April. Named sectors include water and wastewater, energy and government services.
- No exploit is involved. The controllers are reachable from the internet, and the primary mitigation is to remove them from direct internet exposure and place a secure gateway and firewall in front of them.
- The tooling is legitimate engineering software: Rockwell Automation Studio 5000 Logix Designer, Schneider Electric EcoStruxure Control Expert and Siemens TIA Portal. Actors have also been observed running that configuration software from third party hosted infrastructure to extract project files.
- Scope widened at the update. Named equipment now includes Rockwell Automation and Allen-Bradley CompactLogix and Micro850, Schneider Electric BMX P34 and Modicon M340, and the Siemens S7-1200 series, with the agencies noting targeting of other manufacturers' controllers may also be occurring. An assessment closed in April on the basis of not running Rockwell has expired.
- New detection guidance covers malicious changes inside reusable code modules, including add on instructions in Rockwell programs, validated by comparing running logic against a known good copy. The advisory also describes manipulation of the data shown on operator and supervisory control displays and changes that override safety parameters. On attribution, the agencies say Iranian affiliated and say the campaign bears similarities to a November 2023 operation linked to an Islamic Revolutionary Guard Corps cyber command. Similarity is not confirmation.
Sources: joint advisory AA26-097A, updated 22 July 2026.
Anubis lists Coca-Cola and Fairlife after United States production suspended
- The Coca-Cola Company disclosed on 16 July, in a Form 8-K filing, that its dairy business Fairlife had identified unauthorised access by a third party to a portion of its systems, including production related systems, in connection with a ransomware event. United States production operations were temporarily suspended and product quality and safety were not affected.
- Canadian production operations were not affected. That boundary is the most useful detail in the incident.
- On 20 July the Anubis ransomware group listed Coca-Cola and Fairlife on its leak site, claiming a terabyte of confidential data, naming no ransom figure and providing no proof. The stated deadline was 27 July.
- Confidence levels differ and should be kept apart. Coca-Cola confirmed unauthorised access in connection with a ransomware event. It has not confirmed the group or the volume. Anubis claims both.
- Capability note on Anubis generally, not on this incident: vendor research on the ransomware as a service operation, running since December 2024, documents an optional wiper mode that overwrites file contents while leaving filenames and folder structure intact, defeating recovery even with a working decryption key.
Sources: Coca-Cola Form 8-K, 16 July 2026; Anubis leak site listing, 20 July 2026; vendor research on Anubis.
Technology and software
SonicWall SMA1000: exploited three weeks before a fix existed, credentials and MFA seeds taken
- Volexity confirmed on 20 July that intrusions began on 22 June, three weeks before the vendor fix. It tracks the intrusion set as UTA0533, chaining CVE-2026-15409 and CVE-2026-15410 to reach root on SMA1000 appliances.
- SonicWall published its advisory and hotfixes on 14 July, and CISA added both CVEs to the Known Exploited Vulnerabilities catalogue the same day.
- What was taken defeats patching: local credentials, active session databases and time based one time password seed configurations, followed by movement to Windows and Active Directory credentials. Rapid7's guidance is explicit that patching alone is not enough, and where compromise is confirmed the appliance should be re imaged or the virtual instance redeployed, with user and administrator passwords and one time password tokens reset.
- Huntress confirmed seven affected customers and reported that the activity traces to two distinct groups rather than one.
- Attribution is unresolved and the divergence is the signal. Dark Reading reported on 17 July that, on Rapid7 telemetry, an actor connected to the Inc ransomware as a service operation used the flaws as zero days. Volexity names no ransomware brand. Others have suggested a Chinese nexus. Note also that the vendor advisory scores CVE-2026-15409 at 10.0 as a server side request forgery in the Appliance Work Place interface and CVE-2026-15410 at 7.2 as a code injection requiring an authenticated administrator, which reads considerably less urgent than the researchers' unauthenticated path to root.
Sources: Volexity, 20 July 2026; SonicWall advisory and CISA KEV, 14 July 2026; Rapid7; Huntress; Dark Reading, 17 July 2026.
ServiceNow AI Platform CVE-2026-6875 exploited in the wild
- Pre authentication code injection in the ServiceNow AI Platform allowing an unauthenticated attacker to escape the script sandbox and execute code on the instance. Reported CVSS 9.5.
- Discovered by Searchlight Cyber and reported to ServiceNow in early April
- ServiceNow published its advisory on 13 July for self hosted instances, with hosted instances addressed earlier.
- Threat intelligence firm Defused observed the first real exploitation attempts on 18 July, delivered as crafted HTTP requests to the `/assessment_thanks.do` endpoint.
- Defused subsequently confirmed a second sandbox escape gadget chain that reaches the same code execution primitive by a different route, which defeats detections tuned to the published proof of concept. Signature based mitigation built from the public proof of concept should be assumed insufficient.
- No addition to the CISA Known Exploited Vulnerabilities catalogue had been confirmed for this CVE as at the time of writing, so there is no federal remediation deadline to anchor to.
Sources: ServiceNow security advisory KB3137947, 13 July 2026; BleepingComputer and Help Net Security, 20 July 2026; The Hacker News.
Two enterprise platform flaws added to CISA KEV on 22 July
- CVE-2026-16232, Check Point SmartConsole, improper authentication in the login process, CVSS 9.1. An unauthenticated remote attacker can obtain an application login token and authenticate to the management server with full administrative privileges, allowing modification of security policies and configurations. Check Point confirms exploitation in the wild against what it describes as a small number of customers. Federal remediation deadline 25 July.
- CVE-2026-50522, Microsoft SharePoint Server, deserialisation of untrusted data in supported on premises products, reported CVSS 9.8.
- Read the SharePoint precondition carefully. watchTowr reports exploitation following release of a public proof of concept, and the flaw is described as requiring Site Owner privileges. That is a materially different exposure from what a 9.8 alone implies, and the two descriptions should be reconciled before your team prioritises on the score.
- A firewall management console that hands out administrative sessions without authentication is the higher of the two. Whoever holds it can rewrite the policy that everything else depends on.
Sources: CISA KEV additions, 22 July 2026; Rapid7; Check Point advisory; Security Affairs; The Hacker News.
WordPress wp2shell and the 21 July KEV batch
- On 21 July, CISA added four vulnerabilities to the Known Exploited Vulnerabilities catalogue: WordPress Core CVE-2026-63030 at 9.8 and CVE-2026-60137 at 5.9, Langflow CVE-2026-0770 at 9.8, and DD-WRT CVE-2021-27137 at 8.1. Three carried a remediation deadline of 24 July.
- The two WordPress flaws, named wp2shell by researchers, chain to unauthenticated remote code execution on a default installation with no plugins and no login required. They were patched on 17 July, exploitation was confirmed within days, and by 20 July activity had moved from targeted probing to internet wide scanning, with web shells and malicious plugins installed.
- One vendor's telemetry found that at publication, 60 per cent of organisations running WordPress had at least one vulnerable instance and a quarter had one exposed to the internet.
- The rest of the batch. Langflow CVE-2026-0770 at 9.8 gives unauthenticated code execution as root in a tool for building applications on large language models, which typically arrives through a team experimenting rather than through procurement. DD-WRT CVE-2021-27137 was first catalogued in 2021 and is on the actively exploited list in 2026. Age is not evidence of safety.
- Dated context, not this week's news: the Australian Cyber Security Centre issued a critical alert on 9 July on large scale global exploitation of content management systems and their plugins, naming WordPress plugins as the primary vector alongside Craft CMS, Joomla, MaxSite and MetInfo, and naming small and medium businesses as particularly affected.
Sources: CISA KEV additions, 21 July 2026; ACSC critical alert, 9 July 2026; vendor telemetry reporting, 20 July 2026.
Hugging Face confirms breach of internal datasets and service credentials
- Disclosed on 20 July. Hugging Face reports that an unauthorised third party used an autonomous AI agent system to exploit vulnerabilities in its production infrastructure.
- Initial access is described as a dataset uploaded to the platform that abused a vulnerability to run malicious code on Hugging Face servers, from which the attacker escalated permissions into internal systems.
- Internal datasets and service credentials were compromised. Hugging Face has revoked and rotated the affected credentials and is urging users to rotate any keys stored on the platform and review account activity.
- The company was still investigating whether customer or partner data was taken at the time of disclosure.
- Downstream relevance: this is a model and dataset distribution point that feeds build pipelines in every sector. Treat stored tokens as exposed and check what your pipelines pull from it and with what credentials.
Sources: Hugging Face security incident disclosure, July 2026; TechCrunch and BleepingComputer, 20 July 2026.
Government and defence
AA26-204A: Russian state supported actors reading mailboxes through Zimbra
- Joint advisory AA26-204A was released on 23 July, covering targeting and compromise of Western government and commercial organisations running Zimbra Collaboration Suite since at least July 2025. Named target sets include government, defence, energy, technology, education, media, law enforcement and non governmental organisations.
- The flaw is CVE-2025-66376, a cross site scripting weakness in Zimbra webmail arising from insufficient sanitisation of CSS @import directives in email content, affecting Zimbra Collaboration 10.0 before 10.0.18 and 10.1 before 10.1.13. It was patched in November 2025 and unpatched organisations continue to be breached.
- The delivery does not require the usual click. Viewing a malicious message in a vulnerable webmail client is enough. The JavaScript capability, tracked as Ulej, harvests mailbox contents through Zimbra SOAP requests, identifies the compromised address, collects version and client information, retrieves two factor authentication scratch codes and creates new application specific passwords that allow continued access from external mail clients.
- Naming diverges across the community and all of these refer to the same activity: LAUNDRY BEAR, Void Blizzard, CL-STA-1114, and TA488, formerly UNK_PitStop. If your tooling is aliased to only one of these, you will miss reporting filed under the others.
- On 24 July the Finnish Defence Intelligence Agency and SUPO issued their own warning to Finnish organisations, assessing LAUNDRY BEAR as a serious espionage threat to public administration, critical infrastructure and the defence industry, and noting the actor's routine use of impersonation and stolen credentials alongside the Zimbra exploitation.
Sources: joint advisory AA26-204A, 23 July 2026; NSA published advisory PDF; SUPO and Finnish Defence Forces statements, 24 July 2026.
Transport and logistics
Stadler Rail refuses a 12.3 million dollar Everest demand
- Swiss rolling stock manufacturer Stadler Rail confirmed in the week of 20 July that the Everest extortion group breached a data exchange platform shared with one of its suppliers, after compromising credentials for that platform.
- Stadler stated it will not pay any ransom under any circumstances and is therefore not susceptible to extortion, and filed a criminal complaint with the Thurgau cantonal police.
- The company says its own IT systems, production lines and rail vehicles worldwide were unaffected, and describes the stolen files as technical material with no bearing on railway safety.
- Everest emerged in 2020 as a ransomware operation and has since abandoned network encryption in favour of data theft and leak threats, which is why the refusal position is viable here in a way it would not be against an encryption event.
Sources: Stadler Rail statement; BleepingComputer, The Record, Help Net Security, The Register, 23 July 2026.
Professional services
EY notifies clients of tax document theft from a third party support platform
- EY filed a data breach notification with the California Attorney General on 15 July, with detail becoming public through the week of 19 July.
- An unauthorised third party accessed a third party IT service management platform between 28 March and 12 April 2026 and downloaded documents relating to a number of EY clients. EY identified anomalous activity on 23 April and triggered incident response.
- The exposure exists because support tickets raised through that platform routinely carried attachments containing client tax information. Reported data includes names, addresses, social security numbers, card numbers, information tied to investment holdings with EY institutional clients, and financial information used to prepare tax filings.
- EY says it has no current evidence of misuse or of specific individuals being deliberately targeted. No actor has claimed responsibility and there are no public technical indicators supporting attribution.
- The control lesson is narrow and widely applicable: the ticketing system inherited the sensitivity of the work it supported, and was almost certainly not classified that way.
Sources: EY breach notification to the California Attorney General, 15 July 2026; SecurityWeek and UpGuard, 19 to 20 July 2026.
Cross sector and supply chain
ENCFORGE: ransomware built to destroy AI models and training data
- Reported on 21 July. The operator, tracked as JADEPUFFER, has moved from damaging databases to deploying ENCFORGE, a ransomware strain aimed at AI models, training data and vector databases.
- Initial access is CVE-2025-3248, the missing authentication flaw in Langflow's code validation endpoint, CVSS 9.8, in CISA's Known Exploited Vulnerabilities catalogue since 5 May 2025. Langflow versions before 1.3.0 expose `/api/v1/validate/code` without authentication.
- The default target list covers roughly 180 extensions specific to machine learning, including .ckpt, .safetensors, .onnx, .gguf, .faiss, .parquet, .pkl and .pt. Encryption is AES-256-CTR with RSA-2048 key exchange, processes holding file locks are killed first, and the binary self deletes.
- The operational detail worth noting: when the payload fetch from the command and control server failed, the operator rebuilt delivery on the fly, iterating six Python scripts through the Langflow remote code execution channel to spawn a privileged container and run the encryption pass against the host filesystem. That is adaptation during the intrusion, not a fixed script.
- Recovery planning assumes the data exists somewhere. Model checkpoints and vector indexes are frequently outside the backup scope that was designed for databases and file shares.
Sources: The Hacker News, BleepingComputer, Help Net Security, Infosecurity Magazine, 21 July 2026.
AgentForger: one link stands up an attacker controlled agent inside your tenancy
- Disclosed publicly on 23 July by Zenity Labs. A single link could be used to hijack OpenAI's ChatGPT Agent Builder and stand up an attacker controlled agent operating with a real employee's access, with approvals switched off.
- Reported to OpenAI through Bugcrowd on 4 June 2026 and remediated by 8 June, so this is a disclosure rather than a live exposure. No customer action is required against this specific flaw.
- The class is what matters. An agent provisioned inside your tenancy inherits identity, entitlements and trust, and it does not look like malware to anything watching for malware.
- Governance question this raises for any organisation running agentic tooling: who can create an agent, what identity does it run as, what approvals can be waived, and where is that logged. Most AI governance frameworks written in the last two years answer none of those.
Sources: Zenity Labs research, 23 July 2026; The Hacker News, SecurityWeek, The Register, 23 July 2026.
Circulating but not carried
Two things were moving this week that do not meet the standard for inclusion, and are recorded here rather than left out silently.
- Leak site listings naming healthcare providers appeared during the window, including a listing of an ambulance service on 19 July and of a health organisation on 22 July, both attributed to Qilin. These rest on leak site aggregator reporting with no confirmation from the named organisations and no independent reputable outlet. Extortion listings are claims, and they are wrong often enough that they are not carried as incidents.
- Reporting recirculated this week on a breach at a financial software vendor affecting a large number of United States banks and credit unions. The underlying incident and the notifications date to 2025, so it is not this week's news and is not carried as such.
Prepared by GreenCyber. Window 19 to 25 July 2026, strictly held. Primary sources first, two or more independent reputable outlets to stand an item up, and single source material flagged where it appears.
Ready before the breach ..... clear during the crisis.
Start a conversation
Want this every week?
It goes out to the organisations we work with. Ask and you are on the list, and there is nothing else attached to it.
- Every enquiry is read by a senior leader. There is no sales sequence behind this form.
- Nothing is resold to you and no vendor introduction is waiting at the other end.
- A first conversation is a conversation, not a scoping call with a proposal attached.