This daily summary highlights significant cybersecurity developments, including an update on the Ernst & Young data breach, where the cybercrime group ShinyHunters has claimed responsibility and threatened to leak sensitive client data by July 31, 2026, if a ransom is not paid. The group alleges a supply-chain attack compromised credentials, allowing access to EY's internal environments.
Ransomware attacks continue to be a major concern, with Q2 seeing a 3% increase. VPNs remain a primary initial access vector, with groups like Qilin and The Gentlemen actively exploiting vulnerabilities in products like Palo Alto Networks' GlobalProtect. Attackers are also employing legitimate remote access tools and 'EDR killer' tools to evade detection. Ransomware attacks have reached record highs in 2026, with the US being the primary target. Top ransomware groups are responsible for a significant portion of incidents, and phishing and stolen credentials are key initial access methods.
Several critical vulnerabilities have been disclosed and patched. VMware has addressed a critical VM escape flaw in ESXi (CVE-2026-47876) and other critical flaws in vCenter. JetBrains has patched a critical unauthenticated RCE flaw in TeamCity (CVE-2026-63077), and Dassault Systèmes has patched a critical RCE in its 3DEXPERIENCE platform. An unpatched FastJson RCE zero-day (CVE-2026-16723) is actively being exploited, affecting unsupported versions.
AI tools are accelerating software vulnerability discovery, leading to increased patch volumes, though exploitation rates for AI-found flaws remain low. However, AI is also reducing the time from discovery to weaponization. In critical infrastructure, CISA has released guidance urging OT isolation from IT networks during cyber crises. The EU has published its first guidance for the Cyber Resilience Act, outlining new cybersecurity obligations for businesses.
Data breach notices in the US for H1 2026 have already surpassed the total for all of 2025, driven by mega-breaches and supply chain attacks. Houston City College is notifying 832,000 individuals of a data breach impacting sensitive personal information. A malicious npm package, joyfill-fe-bel, has been discovered in a supply-chain attack, deploying a RAT and stealing credentials. Additionally, Russian APT28 has been linked to a campaign hijacking routers for DNS poisoning to steal credentials and tokens.
Help others stay informed about cybersecurity threats
Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.
Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.
Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.