Daily Digest

Cybersecurity Brief: Supply Chain Attacks, Ransomware, and APT Activity

Cybersecurity Brief: Supply Chain Attacks, Ransomware, and APT Activity

July 31, 2026
13 articles (8 new, 5 updated)
39 min read

Summary

This daily summary highlights significant cybersecurity developments, including updates on major supply chain attacks and ransomware incidents. North Korea's 'PolinRider' APT has been formally attributed to recent high-impact attacks on popular npm packages like 'axios', 'debug', and 'chalk', affecting over 100 open-source repositories and potentially impacting a significant portion of cloud environments. The Anubis ransomware attack on Coca-Cola's Fairlife dairy operations has reportedly caused over a week of production halts, with ongoing uncertainty regarding ransom payments or data leaks. The Qilin ransomware group continues its expansion, claiming new victims across diverse global sectors, with updated technical details on their tactics, techniques, and procedures (TTPs) now available for defensive review.

In other updates, Ernst & Young has confirmed a data breach claimed by ShinyHunters, where attackers gained persistent access to a third-party IT help-desk platform, exfiltrating sensitive client data. A state-backed campaign targeting South Korea has expanded its tactics to include spear-phishing and more precise watering hole attacks, impacting media, healthcare, and finance sectors.

New threats include a CISA and FBI warning about attacks on U.S. Water System PLCs, exploiting internet-exposed Rockwell Automation devices and causing operational disruptions. Pharmaceutical giant Amgen disclosed a data breach of patient and proprietary information stemming from third-party cloud environments. The SilverFox APT has been identified in an attack against a Japanese manufacturer using advanced malware, while AssuranceAmerica confirmed a breach exposing 6.9 million driver's licenses. Abbott Labs reported a breach linked to legacy systems from an acquisition, with ShinyHunters claiming responsibility. Mirage Kitten APT is deploying new malware, including the NightLedger backdoor, in a cyber-espionage campaign across the Middle East and Africa. The BlackTech APT is targeting Japanese organizations with a new Linux backdoor, 'BlueShell', designed for stealth. Finally, a new XCSSET malware variant is targeting macOS developers via Xcode, employing sophisticated supply chain attacks and advanced anti-detection capabilities.

Filter by Category

New Articles (8)

Updated Articles (5)

📢 Share This Publication

Help others stay informed about cybersecurity threats

📅 Daily Edition

Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.

🔢 Deduplication Applied

Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.

🔗 Full Articles Linked

Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.