ctipilot.ch
Sun · 19 Jul 2026
All daily briefs ↗
Daily brief · UTC day

Sunday, 19 July 2026

3 verified findings from 2 runs · the settled record for this UTC day, in the classic brief order.

Criticality
Kind
Topic
Region
TL;DR · the day in one read
  1. 01EY discloses client tax-data exposure after a third-party ITSM support-ticket platform was breached. Ernst & Young LLP filed breach notifications (2026-07-15) after detecting that an unauthorized party accessed a third-party IT service-management (ITSM) support-ticket platform used by its tax practice between 28 March and 12 April 2026 and downloaded documents belonging to multiple tax clients. Support tickets on the platform carried attached client tax and financial information; EY has not disclosed the access vector, the platform, or how many are affected. The transferable lesson for any organization — public-sector included — that outsources IT helpdesk/ticketing: sensitive attachments accumulate inside support-ticket systems that data-classification and DLP programs routinely overlook.
  2. 02Romanian land-registry authority ANCPI down for days after a cyberattack; data-leak operator ByteToBreach claims theft and ransomware. Romania's National Agency for Cadastre and Real Estate Publicity (ANCPI) — the government authority running the national land-registry and cadastre systems (e-Terra, RENNS) used by citizens, notaries, banks and other authorities — has had all IT systems down since 14 July 2026 after what it confirmed is a cyberattack. A data-leak operator using the alias ByteToBreach, tracked by KELA and with a cross-country victimology spanning government, banking and other sectors, claims to have stolen Romanian-citizen data and the e-Terra/RENNS source code from a copied GitLab server, deployed ransomware, and begun deleting backups; ANCPI disputes that its data was compromised. A live, unresolved EU public-sector incident.
  3. 03ClickLock: a modular macOS stealer that locks the desktop by killing every app until the user surrenders their password — Europe is the top victim region. Group-IB has documented ClickLock Stealer, a previously undetected modular macOS infostealer delivered via ClickFix social engineering (paste-into-Terminal) that needs no exploit and no elevated privilege. Its signature move: on next login, a module kills every visible application every ~210 ms, leaving only a fake password dialog on screen — for up to ~83 hours — until the victim types their macOS password (validated locally so only the correct one is exfiltrated); a parallel module uses the same coercion to force a real Keychain-authorization dialog and steal Chrome's Safe Storage key. More than 50% of the ~100 identified victims across 33 countries are in Europe, making this directly relevant to any Swiss or European organization issuing macOS endpoints.
01Active threats, incidents & disclosures2 items
NOTABLENATOB2

Romania's national cadastre agency ANCPI hit by a multi-day cyberattack; ByteToBreach claims citizen-data and e-Terra source-code theft plus ransomware

Romania's National Agency for Cadastre and Real Estate Publicity (ANCPI) — the government body operating the national land-registry and cadastre platforms (the e-Terra cadastral application and RENNS) that citizens, notaries, lawyers, banks and other authorities depend on for property transactions — has had all of its IT systems, including institutional email, offline since Tuesday 14 July 2026, in what it first called a "technical incident" before confirming a cyberattack; as of 17 July the systems remained down pending investigation (Help Net Security, 2026-07-16; Public Record, 2026-07-17). A threat actor using the alias ByteToBreach posted ANCPI data for sale on a dark-web forum on 15 July, claiming to hold Romanian-citizen records and various ANCPI databases, a copied GitLab server carrying the source code for e-Terra and RENNS, and to have deployed a ransomware variant (Help Net Security, 2026-07-16); in a screenshot the attacker published, he also states he began deleting the available backups (Public Record, 2026-07-17). ANCPI states the data it administers "has not been compromised as a result of this incident" — a position not yet reconciled with the attacker's claims.

KELA, which profiles ByteToBreach as a persistent data-leak operator active since June 2025, documents the actor's general initial-access tradecraft as "exploiting known vulnerabilities in cloud and corporate infrastructure, reusing stolen credentials harvested from infostealers and phishing, and at times resorting to brute force," with a victim list spanning government, banking and other sectors across multiple countries — a bank in Poland among the organizations that acknowledged their breaches (KELA Cyber, 2026-07-17). Public Record's investigation reports that ANCPI's ~1.5-million-lei framework contract for cybersecurity services required constant active services — a 24/7 call-centre, at-least-annual technical audits, and ongoing monitoring and intervention over 48 months — yet the contracted vendor's owner now characterises the firm as "just a license provider… like buying Microsoft licences on eMAG" and says he had no contractual obligation to detect an attack, a self-characterisation Public Record reports the contract's own terms directly contradict; the same reporting notes a similar December 2025 cyberattack on Romania's National Water Administration (ANAR, roughly 1,000 systems affected), an agency the same security vendors had also supplied (Public Record, 2026-07-17).

They claim to have compromised data of Romanian citizens and various ANCPI databases, made a copy of the agency's GitLab servers and the source code contained within, and deployed ransomware.

ANCPI stated that the data administered through its IT systems has not been compromised as a result of this incident.

Help Net Security 2026-07-16

Exploiting known vulnerabilities in cloud and corporate infrastructure, reusing stolen credentials harvested from infostealers and phishing, and at times resorting to brute force

KELA Cyber 2026-07-17
incident19 Jul 04:24Zmulti-sourceOpen finding ↗
NOTABLENATOA2

Ernst & Young discloses a breach of a third-party IT support-ticket platform used by its tax practice, exposing client tax and financial documents

Ernst & Young LLP (EY), one of the "Big Four" audit/tax/consulting networks, filed data-breach notifications with the California and Vermont Attorneys General on 2026-07-15 after determining that an unauthorized third party had accessed a third-party IT service-management (ITSM) platform used by its tax practice (California OAG, 2026-07-15). EY detected anomalous activity on 2026-04-23 and an external forensics firm concluded that the intruder had access "between March 28 and April 12 and downloaded multiple documents" belonging to multiple tax clients — a roughly two-week access window, detected about eleven days after the intruder's access ended (BleepingComputer, 2026-07-17). The platform manages IT support tickets for tax-engagement work, and "support tickets submitted through the platform may include documents containing client tax information" — the financial information used to prepare tax filings (CyberInsider, 2026-07-17); the regulatory notice letter itself redacts the specific data elements involved. EY has not disclosed the initial-access vector, named the compromised third-party platform, stated how many individuals are affected, or said whether non-US clients are impacted; no extortion or ransomware group has claimed the intrusion, and EY is offering 24 months of identity monitoring to affected individuals (BleepingComputer, 2026-07-17).

an unauthorized third party had accessed the said platform between March 28 and April 12 and downloaded multiple documents

BleepingComputer 2026-07-17

Support tickets submitted through the platform may include documents containing client tax information.

CyberInsider 2026-07-17

Sample of Notice: EY Notice Letter US General.pdf Organization Name: Ernst & Young LLP Date(s) of Breach (if known): Saturday, March 28, 2026 Thursday, April 23, 2026

California Office of the Attorney General (breach-notification filing) 2026-07-15
incident19 Jul 04:25Zmulti-sourceOpen finding ↗
02Deep dive1 item
NOTABLENATOB2

ClickLock Stealer — a macOS ClickFix infostealer that force-kills every visible app until the victim types their login password

macOS endpoint malware is usually treated as rare and, when it appears, as a stealthy background stealer; ClickLock Stealer — documented by Group-IB after a shell script with zero VirusTotal detections was uploaded on 9 June 2026 — inverts both assumptions with an overtly coercive design that forces the victim to hand over their own password, and it is landing disproportionately in Europe (Group-IB, 2026-07-16). Group-IB's telemetry counts "at least 100 victims in 33 countries, with more than 50% from Europe," active since roughly May 2026 (Group-IB, 2026-07-16). It sits in the same ClickFix-delivered macOS-stealer lineage as AMOS, Poseidon and Banshee but is mechanically distinct in how it obtains credentials — it does not defeat the operating system's protections, it defeats the user.

Delivery and execution (T1204.004, T1059.004, T1105). The victim reaches a ClickFix page — a fake Cloudflare "verifying you are not a bot" flow — and is instructed to paste a command into Terminal. That orchestrator shell script disables keyboard interrupts, renders a fake Cloudflare progress-bar animation as cover, and downloads four modules from compromised WordPress infrastructure: a credential stealer, a Keychain stealer, a cross-platform crypto stealer, and a backdoor installer (Group-IB, 2026-07-16). Nothing here needs an exploit or elevated privilege — the whole chain runs at the logged-in user's level.

The coercion mechanism (T1056.002, T1685). The orchestrator first tries a "soft" approach: a fake macOS password dialog built with osascript, styled with a downloaded Apple icon to look genuine. Any password entered is checked locally against the directory service — "validated against the local directory service via dscl /Local/Default -authonly… ensuring only the correct password is exfiltrated" — so the operator receives only a working credential (Group-IB, 2026-07-16). If the victim cancels, the script installs persistence and exits; on the next login the credential-stealer module "activates killing every visible application every 210 milliseconds, leaving only a password dialog on screen until the user is forced to comply" (Group-IB, 2026-07-16). The kill loop deliberately includes Finder, Dock, SystemUIServer, Spotlight, Terminal, all common browsers and — critically — Activity Monitor and Console, so the victim cannot investigate or terminate the malware; the credential loop is configured to run for approximately 83 hours. A parallel Keychain-stealer module uses the identical technique at a ~0.2-second cadence to force approval of a real macOS Keychain-authorization prompt, capturing Chrome's Safe Storage AES key (which decrypts the browser's saved passwords and cookies offline). A separate background loop kills NotificationCenter for roughly six hours to suppress any Gatekeeper or security alerts.

Collection and exfiltration (T1555.001, T1555.003, T1552.001, T1119, T1567, T1102). While the coercion loops run, a data harvester performs a full scan across eight browsers, 31 crypto-wallet browser extensions, seven password-manager extensions, eight desktop wallet applications, blockchain addresses across six chains, the macOS Keychain, shell history and FTP credentials, archives everything into a ZIP, and pushes it to a Telegram bot via the bot API — Telegram serving as a no-infrastructure exfiltration channel with encrypted transport unlikely to be blocked by network filters (Group-IB observed no dedicated command-and-control infrastructure; ongoing remote access comes from the GSocket backdoor below). To widen access, the orchestrator checks whether Terminal holds Full Disk Access and, if not, opens System Settings straight to the Full Disk Access pane with step-by-step instructions to add Terminal, unlocking TCC-protected paths including the Keychain database.

Persistence and anti-forensics (T1543.001, T1053.003, T1546.004, T1564.001, T1036.005, T1070.004, T1070.006). The credential and Keychain modules stage into a hidden ~/.cacheb/ directory and install two LaunchAgents so they re-arm on every login even if the victim cancels the dialog, closes Terminal or reboots. The backdoor installer deploys a lightly modified open-source GSocket build — a persistent gs-netcat reverse shell disguised as an iCloud process — and, unlike the self-deleting stealer modules, keeps a durable foothold via crontab injection, shell-RC-file modification and a LaunchAgent, phoning its connection secret home over three redundant channels. Every stealer module self-deletes after running and copies file modification times from a default macOS directory onto its artifacts to blunt timeline-based forensics.

On subsequent login, the zsh.txt module activates killing every visible application every 210 milliseconds, leaving only a password dialog on screen until the user is forced to comply.

If the user enters a password, it is validated against the local directory service via dscl /Local/Default -authonly “$USER” “$PASS” ensuring only the correct password is exfiltrated.

A ClickLock Stealer operation has already targeted at least 100 victims in 33 countries, with more than 50% from Europe, and has been active for approximately two months, since May 2026.

Alert on rapid, repeated pkill or killall activity targeting system processes (Finder, Dock, SystemUIServer, NotificationCenter) at sub-second intervals, this behavior is unique to forced-interaction malware and has no legitimate use case.

Group-IB
threat19 Jul 04:23Zmulti-sourceOpen finding ↗
Verification & coverage notes2 runs

2026-07-19T1308Z-audit · audit · Opus 4.8 · 0 entries published

Verification & coverage notes

Duplicate-audit guard tripped — this fire stood down at Phase 0 (no audit passes run).

The most recent audit record on origin/main is runs/2026-07-18/2026-07-18T1208Z-audit.md — a full weekly quality audit (window 166 h / gap 143 h ≈ 6 days, 3 audit-recovered entries), started 2026-07-18T12:08:23Z. The gap from that anchor to this fire's start (2026-07-19T13:08:40Z) is 25.00 h — under the Phase 0 step-2 threshold of 72 h. This fire is a scheduled routine, not an explicit interactive operator directive, so the guard applies and the audit does not run: a complete weekly audit swept the trailing week ~25 h ago, and re-auditing now would re-sweep that same week against a window (2026-07-18T12:08Z → now) far too thin to hold a new week's signal. This is the guard working exactly as designed — the full weekly audit ran Saturday, and Sunday's scheduled slot fired before a week has elapsed (the same Saturday-audit / Sunday-slot pattern that stood down the 2026-07-12 fire against the 2026-07-11 audit).

No sub-agents were spawned; no truth passes, coverage re-sweeps, systemic review, or calibration ran. No entries recovered. The audit report is intentionally not written — there is no audit to report, and a report documenting a non-audit would manufacture content (A-INV-2). This run record is the mandatory artifact of the fire (A-INV-3, run-record-per-fire): it records that the fire happened, why it stood down, and what the next audit must pick up.

Pipeline-health snapshot (situational, not an audit finding). The scheduled intel cadence is running normally on the operator-owned single-daily schedule: the most recent fire 2026-07-19T0408Z-intel is publish_status: ok on origin/main. Nothing about the current pipeline state is operationally alarming; the stand-down is a cadence artifact, not a failure.

Carried forward to the next qualifying audit (nothing lost by standing down). The 2026-07-18 weekly audit's open items remain the next audit's duty. Operator closures from the 2026-07-18 operator-response addendum are final (v3.27) and are NOT re-opened or re-checked: recommendation 1 (scheduler cadence — the single daily fire is the intended, operator-owned schedule), recommendation 2 (double-CLEAN gate room — adopted as the 5→8 iteration-cap raise shipped in v3.27), and watch item bd.zh.ch (Kanton Zürich Baudirektion MedusaLocker listing — closed; any new development flows through the normal intel runs as an update_of, not audit tracking).

Still open, carried to the next audit that clears the guard:

  • Recommendation 3 — populate the org-profile product/supplier watchlists (carried from 07-11 and 07-18; still open). The product and supplier sweeps remain no-ops until the config is populated.
  • Watch item — Roundcube 1.6.17/1.7.2 patch fold-in (from 07-11): open, dormant; the next Roundcube entry with any delta should reference the patched versions.
  • Watch item — KELA "ByteToBreach" claim naming Romania's ANCPI (national land registry): single-source criminal-marketplace claim; constituency-relevant if true; awaits corroboration from ANCPI / Romanian authorities / Admiralty A–B journalism.
  • Watch item — PD-11 margin-class (unexploited vulnerabilities whose mechanics justify an out-of-band response, the Moodle local_o365 miss class): one judgment-call miss at 07-18, not yet a pattern; the next audit checks whether the class recurs.
  • Watch item — weekly citation-date discipline (the v3.26 fix): effectiveness unverified until the next weekly runs; the next audit truth-passes the first post-v3.26 weekly batch (citation dates must match source publication dates).
  • Fix-effectiveness — the v3.26/v3.27 machinery fixes the 07-18 audit shipped (weekly citation-date + per-fact-attribution duty; the 5→8 verifier-cap raise) each need their behavior confirmed to have actually changed in the trailing window.

Monthly priority-calibration status. The 2026-07-18 report already carries a ## Priority calibration section discharging the July monthly duty. Per Phase 0 step 4 (one calibration pass per calendar month, self-healing), July is satisfied — the next qualifying audit does NOT own Phase 3b for July, and the duty next falls due in August.

Verifier scope. Iteration 1 verifies this run record only (there are no entries and no audit report): a cold reader confirms the duplicate-audit claim holds on disk — that runs/2026-07-18/2026-07-18T1208Z-audit.md is the latest -audit record on origin/main, that its started is 2026-07-18T12:08:23Z, and that the 25.00 h gap is under the 72 h threshold.

2026-07-19T0408Z-intel · Claude Opus 4.8 · window 24 h · 3 entries published

Verification & coverage notes

Standard 24 h window (gap 16 h to the previous run, the 2026-07-18T1208Z-audit). The national-CERT / government source layer was genuinely quiet across the window (weekend — Sat/Sun): every essential source (NCSC-CH CSH, NCSC-NL, BSI CERT-Bund, CERT-FR, CERT-EU, NCSC-UK, CISA advisories/directives/KEV, ENISA EUVD) was fetched live but carried no in-window items — verified against catalog version numbers and post timestamps (CISA KEV catalogVersion still 2026.07.16, no new additions; freshest CERT content clusters on Fri 2026-07-17), not assumed. Three entries published; one is the day's deep dive.

Published

  • 2026-07-19/clicklock-stealer-macos-clickfix-forced-password-coercion — deep dive (category other). Novel, active macOS ClickFix infostealer (Group-IB) with >50% of victims in Europe; coercion-by-app-killing tradecraft, rich behavioral detection surface, no IOCs. Deep dive earned on the "substantive new technical analysis, actionable" criterion with a strong home-region concentration; no deep dive had been published today.
  • 2026-07-19/ancpi-romania-cadastre-cyberattack-bytetobreach — live, unresolved EU public-sector incident (Romanian national cadastre/land-registry authority); tracked data-leak operator ByteToBreach with a documented cross-country victimology spanning government, banking and other sectors (KELA). Clears the incident gate on a direct home-region/coverage-focus + public-sector nexus.
  • 2026-07-19/ernst-young-third-party-itsm-platform-breach-client-tax-data — Big Four (global significance) confirmed regulatory disclosure; third-party ITSM support-ticket platform breached, client tax/financial documents exfiltrated. Included on the out-of-nexus breach gate's global-significance criterion, framed around the transferable ITSM-attachment exposure lesson (public-sector helpdesk outsourcing).

Single-source / carve-outs

  • ANCPI and EY entries are multi-source but the load-bearing actor/scope claims are single-origin: ByteToBreach's theft/ransomware claims are the actor's own dark-web assertions (disputed by ANCPI); EY's undisclosed vector/scope leaves credibility at 2. Both rated and sourcing-noted accordingly.

Borderline drops (recoverable)

  • borderline-drop: @fastify/http-proxy prefix-rewrite bypass CVE-2026-16117 (CVSS 10.0, S1) — genuine fresh pre-auth access-control bypass, but no exploitation, no public PoC, no scanning; the fix is a routine dependency upgrade (11.6.0). Fails the vulnerability gate's "action beyond the regular patch cycle" test; high CVSS alone does not carry it. Recover if exploitation/PoC/scanning emerges.
  • borderline-drop: WP2Shell WordPress pre-auth RCE exploitation update (S1) — the only new element is a single-source, unconfirmed watchTowr-CEO "first indications of in-the-wild exploitation" claim (no CISA KEV, no named victim, no independent telemetry). The prior 2026-07-18 entry already carries the dual-route WAF mitigation (/wp-json/batch/v1 and ?rest_route=/batch/v1) and correctly declines to assert ITW. No material new development; fails the two-source/fake-news bar for asserting an exploitation-status change.
  • borderline-drop: July 2026 SharePoint exploitation-chain update (S1 + S3) — the prior 2026-07-17 entry already carries CISA's named AMSI/MDAV signatures (SuspSignoutReqBody.A, ToolPaneAuthBypass.A/.C, LeakFang.A!dha), the machine-key-theft framing, and the hunt-before-rotate guidance. The only incremental content is Resecurity's farm-account SQL-role lateral-movement narrative — from a reliability-C source whose "Operation FarmKey" case study is explicitly fictional/illustrative — which is deeper analysis of already-covered exploitation, not a material new development (no new CVE, victim, or exploitation-status change).
  • borderline-drop: Abbott LabCentral / ShadowByt3$ second incident (S4) — already covered in the 2026-07-18 Abbott entry from the same BleepingComputer source; the additional API-endpoint-exfil detail is same-source backfill, not a new development.
  • borderline-drop: SFR "NOVA" internal-tool data-theft claim (S2 + S4) — unconfirmed criminal/leak claim, no SFR confirmation, no independent Admiralty A/B verification; a widely-circulated "SFR confirmed" quote traces to a recycled December 2025 SFR breach (aggregator conflation). Fails the leak-site-claim verification bar.
  • borderline-drop: German mid-July cluster — Wiesbaden/Mülheim DDoS + Netze BW/Stuttgart Netze meter-installer supply-chain breach (S2) — the DDoS thread is low-value municipal availability (restored; Mainz was a DNS-provider fault, not an attack). The Netze BW/Stuttgart Netze meter-contractor breach is 2.5–3 days old and its transferable third-party-meter-supplier lesson duplicates the already-covered IWB Basel entry; the recurring-German-pattern framing is strategic material for the weekly, not an operational entry.

Coverage gaps: cert-eu (advisory series stale since 2026-06, may need a wider endpoint), team-cymru (per-post schema.org datePublished unreliable — recipe review), cisa-kev (quiet, no additions since 2026-07-16), apple-security (bridge returned unrendered head only, no positive lead). FortiSandbox KEV additions (CVE-2026-25089 / CVE-2026-39808, added 2026-07-16) are absent from the 14-day index — a genuine earlier-run miss, outside this window and with no fresh development; flagged for the quality audit / next relevant cycle to recover.

Watchlist: not configured for this deployment (product and supplier watchlists empty) — sweep is a no-op; line omitted from telemetry.

Essential-coverage: all essential national-CERT/government sources attempted and reachable; no misses.

Deep-dive rotation: category other (macOS endpoint malware) — not used in the trailing 7 days (recent picks: firewall-vpn-rce, apt-campaign, identity-infra, linux-lpe). No prior deep dive today.

Verification. Five iterations (Opus/Sonnet/Opus/Sonnet/Opus rotation); confirmed CLEAN published (double-CLEAN gate: iteration 4 Sonnet + iteration 5 Opus, two consecutive CLEANs on two different models). Residuals fell monotonically — iter1 (Opus) 4 truth, iter2 (Sonnet) 3 truth, iter3 (Opus) 1 truth, iter4 (Sonnet) CLEAN, iter5 (Opus) CLEAN — a benign convergence where each cold cross-model read surfaced a distinct, low-severity, fully-remediable defect the others missed. The ClickLock deep dive was clean from iteration 1 (all evidence verbatim, T1685 confirmed as the active v19.1 rename of revoked T1562.001, no IOCs); every defect was confined to the two incident entries plus the registry/run-record prose, and every one was a precision fix (a wrong ~6-week→~11-day arithmetic on EY; a Poland-as-a-bank-not-a-government mischaracterization that recurred across entry/registry/run-record and was chased down in all three; a backup-deletion citation re-pointed to the source that actually carries it; an inverted vendor-contract framing corrected against the Romanian primary re-read directly; an unsupported SSN/payment-card overstatement removed; a Telegram-as-module-delivery error corrected to exfiltration-only). All remediated before commit. entries_dropped_by_verification: 0; verification_residual_count: 0.