01W29 breaches were third-party-mediated — IWB Basel, Kudankulam/Reliance, Ernst & Young and AsyncAPI entered through a trusted supplier, host or pipeline. The week's confirmed breaches share one mechanism above all others: the victim's own systems largely held, and the exposure came through a third party it trusted. Basel utility IWB lost ~40,000 customer meter records via a compromised external service provider, its own systems unaffected. A contractor to India's Kudankulam nuclear plant, Reliance Group, confirmed a partial breach originating from a server hosted by third-party data-centre provider Yotta — ~858,000 files leaked by World Leaks. Ernst & Young disclosed client tax-data exposure through a breach of a third-party IT/ITSM platform, filed with the California Attorney General. And the AsyncAPI npm compromise reached three-million-downloads-a-week packages by abusing the org's own CI/CD trusted-publishing pipeline, then — Microsoft's forensic timeline showed — shipped versions carrying cryptographically valid npm/OIDC provenance attestations because the malicious commit rode the legitimate release workflow. The transferable lesson for the constituency is that supplier, host and pipeline trust boundaries are now the dominant breach vector, and that provenance/attestation controls verify which pipeline built an artifact, not that the triggering change was authorized. →
02W29 home-region incidents — ANCPI Romania offline for days, IWB Basel and Geneva's IFAGE breached, Metro Mondego ransomware, Wind Tre fined EUR 1.7M. The incidents with a direct Swiss/European home-region or coverage-focus nexus this week clustered squarely on public-sector and critical-infrastructure organisations. Romania's national cadastre authority ANCPI had all IT systems down since 14 July after a confirmed cyberattack, with data-leak operator ByteToBreach claiming data theft, source-code exfiltration and ransomware. Two Swiss organisations were hit through third parties — the Basel canton utility IWB (electricity/gas/water/telecom) lost ~40,000 customer meter records via a compromised service provider, and Geneva adult-education foundation IFAGE was listed by DragonForce (850 GB claimed, unconfirmed). Portugal's Metro Mondego confirmed a 6 July ransomware attack (TheGentlemen claim) that its IT/OT segmentation kept off the transit service. Italy's Garante fined Wind Tre EUR 1.7M for a retail-staff-vishing-to-API-enumeration breach of 365,048 customers, and Ernst & Young disclosed a third-party ITSM-platform breach exposing client tax data. Underneath the incidents, NCSC-CH flagged an unauthenticated RCE (CVSS 9.8) in Abacus ERP — ubiquitous across Swiss SMEs, associations and public-sector-adjacent bodies — as the week's largest latent home-region exposure. →
03Identity attacks converged on abusing trust, not breaking it — OAuth/SSO vishing, a client_id oracle, a Moodle JWT forgery, and helpdesk-vishing resets. Five independent 2026-W29 disclosures describe the same identity-intrusion pattern from different angles: none broke authentication cryptographically — each abused a trusted OAuth grant, token, or human process to obtain valid-account access that sign-in-anomaly detection barely sees. Microsoft mapped a year of ShinyHunters-associated Salesforce OAuth abuse (vishing-driven malicious consent, SaaS supply-chain secret reuse, guest-access Aura abuse), and the same actor's vishing-to-Entra-SSO tradecraft surfaced in the Abbott/Exact Sciences intrusion. Proofpoint documented OAuth client_id spoofing that turns an Entra ID "application not found" error into a credential-validity oracle while leaving a blank application name in the sign-in log. CVE-2026-54733 in Moodle's official Microsoft 365 plugin authenticated forged JWTs without ever verifying the signature — knowing any user's email yielded full site takeover. And the Scattered Spider TfL sentencing put the credential-purchase → helpdesk-vishing → MFA-reset chain into the court record. This extends the M365 auth-flow convergence the prior weekly documented (device-code, ROPC, AiTM) into the OAuth-trust, token-forgery and helpdesk-process layer — the controls that catch it are consent governance, token/grant hardening and helpdesk identity-proofing, not stronger MFA. →
04W29 CVE trajectory — nine exploited/KEV (SonicWall, ShareFile, Oracle EBS, SharePoint/AD FS, KNX), two public-exploit (WP2Shell, Firefox), a dense critical tail. Consolidated status of the CVEs this pipeline covered operationally in ISO week 2026-W29, with each item's trajectory this week versus first coverage. Confirmed exploited / newly KEV-listed: CVE-2026-2699 (ShareFile SZC), CVE-2026-56155 (AD FS) and CVE-2026-56164 + CVE-2026-58644 (on-prem SharePoint), CVE-2026-15409 + CVE-2026-15410 (SonicWall SMA1000), CVE-2026-46817 (Oracle EBS Payments), plus two older KEV additions actively exploited now — CVE-2018-0171 (Cisco Smart Install) and CVE-2023-4346 (KNX). Public exploit code but no confirmed in-the-wild abuse: CVE-2026-63030 + CVE-2026-60137 (WordPress "WP2Shell") and CVE-2026-15718 + CVE-2026-15719 (Firefox). Critical-but-unexploited tail requiring scheduled action: SAP (CVE-2026-44747/27690/44761), VMware Avi Load Balancer (CVE-2026-47865), Siemens RUGGEDCOM ROX II (CVE-2025-40947/40948/40949), Rockwell 1715-AENTR (CVE-2026-10577, CVSS 10.0) and ABB T-MAC, plus Abacus ERP (no CVE, CVSS 9.8) and Moodle local_o365 (CVE-2026-54733). Full per-CVE detail lives in the referenced operational entries; this roll-up carries only the week's trajectory. →
05Russian FSB pre-positioning against European CI went public — router hijacking, the Turla and Poland-grid attributions, and the first joint EU/UK sanctions. 2026-W29 was the week Russian state-nexus pre-positioning against European critical infrastructure moved from tracked-but-quiet to formally attributed and sanctioned. On 2026-07-13 a 19-agency joint advisory detailed FSB Centre 16 (Static Tundra / Berserk Bear) opportunistically hijacking internet-facing routers via default/weak SNMP community strings and the seven-year-old Cisco Smart Install flaw CVE-2018-0171 (CISA KEV) to exfiltrate device configurations across energy, government, telecom, finance and healthcare; the same day, the UK and EU formally attributed the destructive 29 December 2025 attack on Poland's energy grid to this FSB unit and imposed their first joint cyber-sanctions package, while France's ANSSI published CERTFR-2026-CTI-005 attributing the Turla intrusion set to the same FSB 16th Centre with the EU sanctioning 9 individuals and 4 organisations and the UK sanctioning 24. In parallel, Dutch intelligence (AIVD/MIVD) disclosed Russia-linked compromise of internet-connected cameras — reachable through default passwords and outdated firmware — along military-supply routes to Ukraine, triggering four EU-state ambassador summons and a NATO condemnation. For any Swiss or European CI operator the operational reality is that exposed network devices and default-credential IoT are being treated as a state-actor collection grid right now, not in some future scenario. →
06Confirmed exploitation converged this week on SonicWall SMA1000, ShareFile SZC, Oracle EBS and on-prem SharePoint/AD FS — patching alone is not full remediation. Four separate classes of internet-facing enterprise software crossed into confirmed in-the-wild exploitation in 2026-W29, every one KEV-listed: SonicWall SMA1000 (CVE-2026-15409 SSRF CVSS 10.0 + CVE-2026-15410), reconstructed by Volexity into a full SSRF-to-root chain attributed to UTA0533 that harvests cleartext LDAP credentials and leaves on-appliance implants; Progress ShareFile Storage Zone Controller (CVE-2026-2699 pre-auth auth bypass), exploited in the wild the same day Progress ordered emergency shutdowns, with Clop suspected; Oracle E-Business Suite Payments (CVE-2026-46817 pre-auth RCE CVSS 9.8), exploited weeks before any public PoC; and Microsoft on-prem SharePoint/AD FS, where July's patch cycle carried two exploited zero-days (AD FS EoP CVE-2026-56155, SharePoint EoP CVE-2026-56164) and a third SharePoint RCE (CVE-2026-58644) was confirmed exploited days later. The operational reality: any exposed unpatched instance should be treated as compromised, not merely vulnerable — and for the SonicWall and SharePoint cases, stolen LDAP credentials and IIS machine keys survive the patch, so rotation and eviction are part of remediation, not optional follow-up. →
07Crimeware convergence — ClickFix delivered CrashStealer, ClickLock, ACR Stealer, TELEPUZ and Starland RAT; macOS stealers now coerce the login password. Five independently-reported crimeware families in 2026-W29 converged on the same delivery and tradecraft patterns, making the shape more useful to defenders than any one sample. ClickFix (paste-a-command-into-terminal social engineering) was the shared initial-access vector for the macOS stealers CrashStealer and ClickLock, the Windows infostealer ACR Stealer (two distinct chains), the modular Windows RAT TELEPUZ, and UAT-11795's Starland RAT. Two macOS families independently reached the same escalation — coercing the user's own login password: CrashStealer validates it locally with dscl before unlocking the keychain, and ClickLock kills every visible application every ~210 ms for up to ~83 hours until the victim types it, with more than half of ~100 identified victims in Europe. On Windows, TELEPUZ and Starland share indirect-syscall execution, AMSI/ETW tampering and — notably — a Polygon smart-contract dead-drop as a C2-resolution fallback. The transferable signal is that ClickFix removes the exploit from the intrusion, macOS is now a first-class credential-theft target for European organisations, and blockchain dead-drops are becoming a resilient C2 fallback that ordinary domain/IP blocking does not reach. →
01Highest-impact events · what's on fire if no one acted2 items
If you did nothing this week: the internet-facing routers and IP cameras in your estate are exactly the collection surface a 19-agency advisory and Dutch intelligence just documented Russian state actors harvesting at scale — default or weak SNMP community strings, unpatched Cisco Smart Install, and default-credential cameras are being enumerated and read now, not hypothetically.
The week's Russian-state thread was not one disclosure but four landing together, which is itself the signal. The router-hijacking advisory describes FSB Centre 16 (Static Tundra / Berserk Bear) doing something deliberately unglamorous at scale: "The actors scan for Internet IP ranges with active Simple Network Management Protocol (SNMP) agents that accept common or default community strings for authentication" and pair that with the seven-year-old Cisco Smart Install flaw CVE-2018-0171 (CISA KEV) to pull device configurations out of energy, government, telecom, finance and healthcare networks (joint advisory, 2026-07-13). The consequence side arrived the same day: "The UK together with EU member states has also today formally attributed the December 2025 attack on Poland's energy grid to Russia's FSB Centre 16" (NCSC-UK, 2026-07-13), with the FCDO framing that a "reckless attack ... could have caused 500,000 citizens to lose electricity in the depths of winter" and the EU and UK issuing their first joint cyber-sanctions package (UK Government, 2026-07-13). France's ANSSI simultaneously attributed the Turla espionage set (SecretBlizzard) to the same FSB 16th Centre in CERTFR-2026-CTI-005, with the EU sanctioning 9 individuals and 4 organisations and the UK 24 (CERT-FR, 2026-07-13).
Running underneath all of it, Dutch intelligence disclosed that "Russian actors had compromised 'a small number of cameras' on routes for military shipments to Ukraine" — internet-connected cameras reachable because of default passwords and outdated firmware — a physical-surveillance use of the same exposed-device class the router advisory addresses (NL Times, 2026-07-11).
The actors scan for Internet IP ranges with active Simple Network Management Protocol (SNMP) agents that accept common or default community strings for authentication
Dutch intelligence services disclosed Friday that Russian actors had compromised “a small number of cameras” on routes for military shipments to Ukraine.
If you did nothing this week: every internet-facing SonicWall SMA 1000, on-prem ShareFile Storage Zone Controller, exposed Oracle E-Business Suite web tier and unpatched on-prem SharePoint Server in your estate is now sitting behind at least one confirmed, in-the-wild-exploited pre-authentication vulnerability — and for the appliance and SharePoint cases, an attacker who reached it before you patched still holds credentials or keys that the patch does not revoke.
The common shape this week was not a single product but a category crossing the line from disclosed to exploited. SonicWall SMA 1000 is the sharpest case: Volexity reconstructed the intrusion behind the actively-exploited CVE-2026-15409 (CVSS 10.0 server-side request forgery) and CVE-2026-15410, attributing it to an actor it tracks as UTA0533 with the earliest compromise on 2026-06-22 (Volexity, 2026-07-17). An unauthenticated /wsproxy request tunnels to a localhost-only service for initial code execution, a hotfix-rollback path traversal escalates to root, and the actor then injects a Suo5 proxy and an ORANGETAIL Java webshell into the appliance's legitimate workplace process, captures cleartext LDAP credentials with tcpdump, and pivots inward — "No valid SMA session cookie was required during this process" (Volexity, 2026-07-17). SonicWall's own PSIRT confirms "the active exploitation of the vulnerabilities described in this advisory" and both CVEs are KEV-listed (SonicWall PSIRT, 2026-07-14).
Progress ShareFile ran the same play in compressed time: Shadowserver honeypots "first recorded active, in-the-wild attacks attempting to exploit CVE-2026-2699 on Friday" — the same day Progress ordered every on-prem Storage Zone Controller powered off — with an ISMG-cited analyst assessing "This smells like CL0P ransomware group activity" (BankInfoSecurity, 2026-07-13); Progress later named a path-traversal root cause and shipped 5.12.5/6.0.2. Oracle E-Business Suite Payments was exploited even earlier and quieter — decoys "recorded the first in-the-wild exploitation of CVE-2026-46817 ... roughly six weeks after Oracle's May 2026 patch and before any public proof-of-concept existed" (Help Net Security, 2026-06-30), and CISA KEV-listed it on 2026-07-15. Microsoft's on-prem stack closed the set: July's cycle patched two exploited zero-days (AD FS EoP CVE-2026-56155, SharePoint EoP CVE-2026-56164), then CISA confirmed active exploitation of a wider on-prem SharePoint cluster "enabling cyber threat actors to gain unauthorized access to on-premises SharePoint Server instances" (CISA, 2026-07-16) — theft of IIS machine keys is among the documented post-exploitation actions.
SonicWall PSIRT has investigated multiple cases indicating the active exploitation of the vulnerabilities described in this advisory.
SonicWall PSIRT (SNWLID-2026-0008)
Honeypots run by nonprofit cybersecurity organization Shadowserver Foundation first recorded active, in-the-wild attacks attempting to exploit CVE-2026-2699 on Friday.
CISA is aware of active exploitation of vulnerabilities CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644, enabling cyber threat actors to gain unauthorized access to on-premises SharePoint Server instances.
The prior weekly documented M365 account-takeover converging on auth flows Conditional Access rarely gates — device-code, ROPC and AiTM. This week the pattern moved one layer up: the intrusions abused trust that had already been granted rather than the authentication event itself, and each left detection thin in a different way.
Two strands are the same actor. Microsoft Threat Intelligence documented a year of ShinyHunters-associated (UNC6240) tradecraft against Salesforce-integrated SaaS through three paths — vishing-driven malicious OAuth consent (a fake Data Loader app), SaaS supply-chain OAuth-secret reuse (Salesloft Drift, Gainsight, and Storm-3138's Klue compromise), and guest-access Aura abuse — none of which exploited a Salesforce vulnerability; each instead abused trusted OAuth relationships (Microsoft, 2026-07-13); the same vishing-to-Entra-SSO tradecraft then appeared in Abbott's confirmed intrusion into its Cancer Diagnostics (Exact Sciences) systems. Proofpoint showed a subtler variant: an attacker POSTing credentials to the Entra ID ROPC token endpoint with an arbitrary unregistered client_id reads the differential AADSTS errors as a credential-validity oracle — AADSTS700016 ("application not found") is returned only when both username and password are correct — while the unregistered id leaves a blank application name in the sign-in log, defeating detections that correlate by app (Proofpoint, 2026-07-13).
The token-trust failure reached its extreme in Moodle's official Microsoft 365 integration: CVE-2026-54733 authenticated users from a JWT's upn claim "without ever verifying the JWT signature," so knowing or enumerating any email — an administrator's included — yielded that user's session and "effectively full site takeover" (Microsoft o365-moodle GHSA, 2026-07-06). And the human-process layer got its case-law record: at the Scattered Spider TfL sentencing, the court heard the pair purchased partial TfL credentials from "well-known criminal forums" and socially engineered a TfL helpdesk worker into resetting an employee account's password and, over multiple attempts, its 2FA, then used that access (The Register, 2026-07-16).
This roll-up tracks the week's CVEs by exploitation trajectory, not severity score. Per-CVE mechanics, affected/fixed versions and evidence are in the referenced operational entries.
Confirmed exploited / newly KEV-listed this week. Four Microsoft on-prem items moved: AD FS CVE-2026-56155 and SharePoint CVE-2026-56164 shipped 2026-07-14 as exploited zero-days KEV-listed the same day, and CVE-2026-58644 — a July SharePoint RCE first rated only "Exploitation More Likely" — was confirmed exploited and KEV-added on 2026-07-16, with CISA naming it in a cluster it is "aware of active exploitation" of (CISA, 2026-07-16). SonicWall SMA1000 CVE-2026-15409/-15410 (KEV 2026-07-14) and Oracle EBS Payments CVE-2026-46817 (KEV 2026-07-15, CISA) both carried confirmed in-the-wild exploitation, as did ShareFile SZC CVE-2026-2699. Two older CVEs joined KEV as actively exploited: Cisco Smart Install CVE-2018-0171 (the FSB Centre 16 router vector) and — notably for OT — KNX Connection Authorization CVE-2023-4346, a three-year-old account-lockout flaw whose fix is procedural, not a patch.
Public exploit code, no confirmed in-the-wild abuse (short fuse). WordPress core's "WP2Shell" chain (CVE-2026-63030 route-confusion in the unauthenticated REST batch endpoint + CVE-2026-60137 WP_Query SQL injection) reaches pre-auth RCE on a stock install; public PoC is already on GitHub and NCSC-NL assesses short-term exploitation is expected. Firefox 152.0.6 fixed a WebAssembly memory bug (CVE-2026-15718) and a site-isolation bypass (CVE-2026-15719) with public exploit code, though Mozilla states no in-the-wild abuse — contrary to some aggregator "zero-day" framing.
Critical-but-unexploited tail (scheduled, exposure-driven action). No confirmed exploitation yet, but each is a pre-auth or high-impact flaw on exposed or CI-relevant software: SAP's July set (CVE-2026-44747 NetWeaver kernel, CVE-2026-27690 Approuter request-smuggling, CVE-2026-44761 Commerce Cloud hardcoded credential — the last a config exposure a patch alone does not close); VMware Avi Load Balancer control-plane auth bypass CVE-2026-47865 (reported by NATO NCSC, no workaround); Siemens RUGGEDCOM ROX II's three-CVE chain to persistent root (CVE-2025-40947/40948/40949); Rockwell 1715-AENTR CVE-2026-10577 (CVSS 10.0 unauthenticated debug-port takeover) and the ABB T-MAC chain; Abacus ERP's unauthenticated RCE (CVSS 9.8, no CVE, NCSC-CH-flagged, ubiquitous in Switzerland); and Moodle's local_o365 JWT-signature-non-verification takeover CVE-2026-54733 across the European public-sector LMS estate.
The home-region incident load this week fell almost entirely on public administration, utilities and transport — the profiled constituency's core — and split into three recognisable shapes.
Direct public-sector disruption. Romania's National Agency for Cadastre and Real Estate Publicity (ANCPI) — the authority running the national land-registry and cadastre systems (e-Terra, RENNS) used by citizens, notaries and banks — had all IT systems offline from 14 July after a confirmed cyberattack; a data-leak operator using the alias ByteToBreach (tracked by KELA) claims to have stolen citizen data and the e-Terra/RENNS source code from a copied GitLab server, deployed ransomware and begun deleting backups, which ANCPI disputes (Help Net Security, 2026-07-16). Portugal's Metro Mondego confirmed a 6 July ransomware attack on internal systems — claimed by TheGentlemen — that its IT/OT separation kept off the Metrobus service, a clean example of segmentation limiting blast radius (Campeão das Províncias, 2026-07-17).
Swiss organisations hit through their suppliers. The Basel canton utility IWB (electricity, gas, water, telecom) disclosed that a compromised external service provider exfiltrated ~40,000 customer meter records (names, addresses, meter numbers) — IWB's own systems and supply were unaffected and the Basel-Stadt data-protection officer assessed misuse risk as low (Netzwoche, 2026-07-15). Geneva adult-education foundation IFAGE was listed by DragonForce claiming 850 GB, layered onto a narrower April breach it had already disclosed — single-sourced and unconfirmed, a watch item rather than an established breach.
Enforcement and cross-border tax-data exposure. Italy's Garante fined Wind Tre EUR 1,715,600 with an unusually complete technical account: retail-staff vishing led to valid MFA'd access, then a pivot from a protected primary API to an unprotected secondary API and ~2 million sequential customerId requests exfiltrating 365,048 customers (Garante, 2026-07-16). Ernst & Young separately disclosed a third-party ITSM-platform breach exposing client tax data.
The week's OT/ICS advisories are worth reading as a set because they hit every sector the constituency defends and because the fixes are not uniformly "patch." The most severe newly-disclosed item is Rockwell's 1715-AENTR EtherNet/IP adapter (CVE-2026-10577, CVSS 10.0): a network-reachable debug port with no authentication lets an unauthenticated attacker read and delete files, stop tasks, modify memory and change I/O states on an adapter deployed in energy and water plants, with Rockwell fixing it in firmware 3.011 and naming network isolation as the interim control (CISA ICSA-26-195-04, 2026-07-14). The same CISA batch carried the ABB T-MAC Plus fuel/chemical terminal-management chain (led by CVE-2025-14771).
Siemens RUGGEDCOM ROX II — a routing/security boundary inside rail, utility, water and manufacturing networks across Europe — drew a full Unit 42 exploit chain: file disclosure via a root-privileged xz misuse (CVE-2025-40948), command injection in the feature-key signature-verification path (CVE-2025-40947), and task-scheduler command injection for persistent, reboot-surviving root (CVE-2025-40949), all fixed in firmware V2.17.1 (Unit 42, 2026-07-17). WAGO's I/O System Field couplers exposed a hidden early-boot diagnostic interface reachable without authentication during the boot window (CVE-2026-4769, CVSS 9.8, CERT@VDE VDE-2026-031, 2026-07-13), fixed per-model in firmware.
The one confirmed-exploited item is the outlier that matters most operationally: CISA KEV-listed the KNX Connection Authorization Option-1 account-lockout flaw (CVE-2023-4346) three years after disclosure — an attacker with network or physical access to a KNX installation can purge unprotected devices and set a BCU key, permanently locking legitimate operators out with no software patch, only procedural hardening (CISA, 2026-07-15). It is directly relevant to any Swiss/EU CI or public-sector estate running KNX for HVAC, lighting, access control or building management.
Read as a set, the week's breaches make one point: the perimeter that failed was rarely the victim's own. Four disclosures, four different trust boundaries.
A service provider was the vector for Basel utility IWB — a compromised external provider exfiltrated ~40,000 customer meter records while IWB's own systems and supply were unaffected. A data-centre host was the vector for the Kudankulam nuclear-plant contractor Reliance Group, which confirmed a "partial breach" originating from a server hosted by third-party provider Yotta, after World Leaks posted ~858,000 files (their authenticity only claimed, with Reuters reviewing a sample) (The Week/Reuters, 2026-07-15). An ITSM/IT platform was the vector for Ernst & Young, whose client tax data was exposed through a third-party software breach disclosed in a California Attorney General filing (CA OAG, 2026-07-15).
The CI/CD pipeline case is the most instructive for defenders because it broke an assumed control. The AsyncAPI compromise reached packages with over three million weekly downloads by abusing the org's own trusted-publishing workflow (Wiz, 2026-07-14); Microsoft's timeline then showed the trojanized versions carried cryptographically valid npm/OIDC provenance attestations that correctly name the real repo, commit and workflow — "even though the triggering commits were unauthorized" — and executed at import time, so --ignore-scripts did not stop them (Microsoft, 2026-07-15).
The week's crimeware is best read as one pattern with five instances, because the reuse is where the detection leverage is.
ClickFix removed the exploit from the intrusion. All five families started from paste-a-command-into-a-terminal social engineering rather than a vulnerability: ClickLock and CrashStealer on macOS, ACR Stealer's two chains, TELEPUZ (via a ClickFix→Vidar hand-off), and UAT-11795's Starland RAT (a ClickFix lure running mshta.exe). When the initial access is the user pasting a command, the earliest reliable telemetry is process lineage — a shell, mshta, rundll32 or osascript spawned shortly after a browser/clipboard interaction, with no dropped-file exploit stage to catch upstream.
macOS gained a credential-coercion playbook, and Europe is the target. Two independent macOS families reached the same escalation this week. Jamf's CrashStealer prompts for the login password and "validates it locally with dscl -authonly" before unlocking the keychain and profiling installed EDR (Jamf, 2026-07-13). Group-IB's ClickLock is more aggressive: it kills every visible application roughly every 210 ms — for up to ~83 hours — leaving only a fake password dialog on screen until the victim surrenders the macOS password (validated locally, so only the correct one is exfiltrated), and a parallel module coerces a real Keychain-authorization dialog to steal Chrome's Safe Storage key; more than 50% of the ~100 identified victims across 33 countries are in Europe (Group-IB, 2026-07-16). For a constituency issuing macOS endpoints, this is the week macOS credential theft stopped being a footnote.
Windows RATs shared evasion and a blockchain fallback. Elastic's TELEPUZ executes indirect syscalls from the .text section of a randomly chosen legitimate DLL to bypass user-mode hooking, patches AMSI/ETW, and resolves its C2 through four decentralized fallbacks — a Telegram bio, a Steam profile, a DNS TXT record and a Polygon smart contract (Elastic, 2026-07-16); Talos's Starland RAT independently uses a Polygon smart-contract dead-drop as its fallback C2 and patches AMSI/ETW before injecting shellcode. Microsoft's ACR Stealer chains both end in DPAPI theft of Chromium credential stores (Microsoft, 2026-07-16).
Both of the week's notable APT disclosures share a target that is not the victim's data but the defender's ability to see the intrusion — worth surfacing together because the techniques transfer regardless of who was hit.
HelloNet blinds network EDR from below the API. Kaspersky GReAT documented an active campaign that persists by sideloading a malicious wtsapi32.dll into the auto-launched update component of the ViPNet secure-networking suite, then injects a proxy module (HelloProxy) into svchost.exe that uses Microsoft Detours to hook NtDeviceIoControlFile and intercept the raw Ancillary Function Driver IOCTLs — AFD_RECV, AFD_GET_TDI_HANDLES — which, per Kaspersky, hinders user-mode network-filtering security tools (Kaspersky, 2026-07-16). The significance for detection engineering is the layer: many endpoint tools observe network activity at the Winsock/API level, and an implant intercepting AFD IOCTLs is operating beneath that vantage, so it can proxy C2 traffic that user-mode network telemetry never records. Victimology is Russian government and CI (attributed with low confidence to an unknown Chinese-speaking group), but the technique is stack-agnostic.
GoSerpent makes dwell time a design choice. Kaspersky's analysis of the evolved GoSerpent backdoor — Go-based, used since 2021 against Southeast-Asian government and diplomatic entities — shows a chain that deploys a document-harvesting Windows service plus credential tools, then "deliberately waits a few weeks while files accumulate" before returning with the Stowaway proxy and a dedicated exfiltration toolset, talking ChaCha20 to its C2 (Kaspersky, 2026-07-16); Kaspersky notes a potential, unconfirmed link to the TetrisPhantom actor.
The prior two weeklies tracked AI moving "from target to operator." This week the reporting matured into a calibration, and the useful output for a technical defender is less the narrative than one concrete hunt technique.
The calibrated read. Recorded Future's Insikt Group synthesised cyber, information-operations and military reporting on Iran's 2026 conflict activity and concluded that "AI has almost certainly enhanced Iran's asymmetric tactics and hybrid warfare doctrine, but has not fundamentally altered the strategic logic underpinning Iran's approach" (Recorded Future / Insikt Group, 2026-07-16). GuidePoint's Q2 review, cutting directly against the alarmist framing, likewise assessed that "the prevailing concern that AI will enable a new class of catastrophic AI-native attacks remains largely unrealized" (Cybersecurity Dive on GuidePoint GRIT, 2026-07-09, pre-window background). Both frame AI as an effort-multiplier — which the week's field evidence bears out: Trend Micro's Patriot Bait analysis documented a jailbroken Gemini agent autonomously writing, deploying and self-repairing a replacement C2 server and confirming bot reconnection in six minutes, with the human operator contributing an estimated ~11% (Trend Micro, 2026-07-14).
Where the acceleration bites — and leaves a fingerprint. Insikt's technically concrete threads are reconnaissance (CloudSEK reproduced CyberAv3ngers-style LLM-agent ICS recon and found "an actor can move from intent to a list of accessible US ICS devices with known default credentials in under five minutes"), phishing (Google GTIG documented APT42 feeding Gemini a target biography to script multi-turn rapport-building conversations), and malware development. It is the last that yields a defender signal: across four independently-reporting labs, Insikt notes emoji/Unicode artefacts in compiled malware — Group-IB found the Rust-based CHAR backdoor's debug strings carried emojis, "a trait rarely seen in human-authored code," and ZScaler, Check Point and HarfangLab reported similar indicators in separate Iran-nexus toolsets — assessed as an AI-generation artefact operators failed to sanitise before compilation. Separately, Check Point's AI Security Report identifies the durable agent-compromise primitive as a planted configuration file an AI agent loads and trusts persistently, meaning any config or memory store an agent trusts is a persistence surface needing integrity monitoring (Check Point, 2026-07-14).
a trait rarely seen in human-authored code
Group-IB (via Recorded Future / Insikt Group, on emoji debug strings in the CHAR malware)
The prevailing concern that AI will enable a new class of catastrophic AI-native attacks remains largely unrealized.
The prior weekly tracked the npm supply-chain wave through the jscrambler and injectivelabs compromises, whose signature was moving the dropper out of the install hook to evade scanners. This week the wave's front edge moved again — from poisoning packages to abusing the trust machinery around them, and the developer is now squarely the target. The marquee event was AsyncAPI: the attacker rode the org's own legitimate CI/CD release workflow, so the trojanized versions carried cryptographically valid npm/OIDC provenance attestations and executed at import time "even though the triggering commits were unauthorized," defeating --ignore-scripts (Microsoft, 2026-07-15) — the detailed provenance-vs-authorization lesson is in this week's incidents recap. In parallel, the DPRK-aligned Contagious Interview campaign broadened the developer-targeting vector beyond the registry entirely: Elastic documented a fake job posting delivering a trojanized Next.js repo that hides its payload as Base64 fragments inside HTML comments across every SVG flag image in an assets directory, reassembled alphabetically and run with eval() to evade scanners that do not parse SVG comment bodies, then running an OtterCookie-aligned credential/wallet stealer on project startup (Elastic, 2026-07-18). The consolidated status: the wave the pipeline tracks now spans package poisoning, CI/CD-pipeline compromise and job-interview repos, and its through-line is that the developer's build environment and the trust signals around it (attestations, install hooks, static scanners) are the surface — so branch-protection and workflow-trigger review, import-time dependency monitoring, and treating any candidate/contractor take-home repo as untrusted code are the current counters.
The prior weekly carried Unit 42's full profile of The Gentlemen (Storm-2697) — 580 claimed victims, a Qilin-affiliate lineage, a 90% affiliate payout and a suspected EDR-disable zero-day. This week the status change is quantitative and reaches the constituency. ReliaQuest's Q2 2026 threat-spotlight reports The Gentlemen "became the most-active group, powered by aggressive affiliate recruitment and a well-packaged intrusion kit" — 300 victims in Q2 against Qilin's 289 — with affiliates receiving pre-compromised victim lists, custom EDR killers and GPO-based deployment tooling, and a "likely AI-accelerated iteration layer" letting the operators refresh tooling faster than human-developer rivals (ReliaQuest, 2026-07-16); Infosecurity Magazine independently corroborates the 300-vs-289 figures (Infosecurity Magazine, 2026-07-17). GuidePoint GRIT's pre-window Q2 review sets the same concentration in context — its "four-headed monster" is Qilin, The Gentlemen, Akira and DragonForce, and it reports the five most prolific groups collectively claimed over 40% of recorded Q2 attacks (Cybersecurity Dive on GuidePoint GRIT, 2026-07-09). Operationally, the group's claimed 6 July attack on Portugal's Metro Mondego — contained to internal systems, transport unaffected — is the fresh European public-sector datapoint. The initial-access funnel (the tracked FortiOS path and opportunistic edge exploitation) is unchanged; the practical takeaway for the constituency is that the most-active RaaS operator of the quarter is one already on its radar, now recruiting and tooling harder, so the FortiOS/edge and EDR-killer hunt posture the earlier coverage set remains the right one.
The Gentlemen became the most-active group, powered by aggressive affiliate recruitment and a well-packaged intrusion kit
The EU's two parallel resilience regimes — the product-side Cyber Resilience Act and the critical-entity-side CER Directive — both produced concrete, operator-facing milestones this week, extending the NIS2-transposition thread the prior two weeklies tracked into the product and physical-resilience tracks.
On the CRA side, ENISA published a free, Excel-based SME Cyber Resilience Maturity Assessment Model letting micro/small/medium manufacturers of products with digital elements self-score readiness across five domains (governance and documentation, risk management and secure-by-design/-by-default, vulnerability management, product lifecycle, and skills), explicit that it is diagnostic and that "reaching a higher maturity level does not replace compliance with the CRA" (ENISA via cyberresilienceact.eu, 2026-07-16; ENISA, 2026-07-13). The timing is the point: from 11 September 2026, CRA Article 14 puts manufacturers on a 24-hour early-warning / 72-hour notification / 14-day final-report clock for actively exploited vulnerabilities in their products.
On the CER side, Germany's KRITIS-Dachgesetz — in force since 17 March 2026 ("Das KRITIS-Dachgesetz ... ist am 17.03.2026 in Kraft getreten," BBK) — opened its first operator-registration window on 17 July 2026 (ChannelPartner, 2026-06-05). Roughly 1,300 identified critical operators across ten sectors must register on a joint BBK/BSI platform within three months, which starts clocks on a risk analysis (nine months) and a documented resilience plan (ten months). Reported fine figures for a registration failure diverge across secondary German trade press (EUR 100,000 vs EUR 500,000) and should be confirmed against the statutory text before being quoted as exact.
reaching a higher maturity level does not replace compliance with the CRA
ENISA (via cyberresilienceact.eu account of the ENISA model)
Das KRITIS-Dachgesetz (kurz: KRITISDachG) ist am 17.03.2026 in Kraft getreten
Items already in motion at the close of the week — each sourced, none a prediction:
WordPress "WP2Shell" pre-auth RCE (CVE-2026-63030 + CVE-2026-60137) — Searchlight Cyber withheld exploit details but published a public checker, public proof-of-concept code is already on GitHub, and NCSC-NL assesses short-term exploitation is expected; no confirmed in-the-wild abuse as of 2026-07-18 (Searchlight Cyber, 2026-07-17). Any stock WordPress not on 7.0.2 / 6.9.5 / 6.8.6 is the exposure to close first.
SharePoint JWT auth-bypass CVE-2026-55040 (Pwn2Own chain) — Rapid7 is holding full technical detail and the PoC under a 30-day disclosure embargo, and the chained RCE half is not scheduled for patch until August, so applying the July fix now is the only current break in the chain (Rapid7, 2026-07-14). Watch for the embargo lift (~mid-August) and the August RCE patch.
Firefox 152.0.6 (CVE-2026-15718 WebAssembly, CVE-2026-15719 site-isolation) — public exploit code exists; Mozilla states no in-the-wild attacks, contrary to some aggregator "zero-day" framing (NCSC-NL, 2026-07-16). A browser code-execution chain with public code on managed/ESR fleets is the watch item.
Progress ShareFile Storage Zone Controller CVE — Progress named a path-traversal root cause and shipped 5.12.5 / 6.0.2 but reserved and withheld the CVE identifier, due to publish in roughly two weeks (BleepingComputer, 2026-07-14); patch and post-exposure review should not wait for the identifier.
Oracle E-Business Suite Payments (CVE-2026-46817) — confirmed exploited from late June before any public PoC (Help Net Security, 2026-06-30); any instance exposed after 2026-05-28 is inside a live post-exposure compromise-assessment window, not merely a patch task.
EU regulatory clocks running — the CRA Article 14 24-hour vulnerability-reporting obligation begins 11 September 2026, and Germany's KRITIS-Dachgesetz operator-registration window opened 17 July 2026 (three-month registration deadline); both are covered in this week's policy entry and are obligations the constituency's supplier and cross-border tail is already inside.
2026-07-19T2310Z-weekly· weekly · Claude Opus 4.8 · 14 entries published
Weekly strategic run — 2026-W29 (2026-07-13 – 2026-07-19)
ATT&CK pin freshness
tools/attack_data.py --check: up to date — local v19.1 == upstream latest v19.1. No update required this run. Technique ids composed this run were validated against the pinned dataset; the revoked v19 ids were mapped to their survivors before composition (T1562.001 → T1685 "Disable or Modify Tools"; T1574.002 → T1574.001 "DLL"), so no dead id shipped.
Week in review (Phase 1)
51 operational entries across ISO week 2026-W29 (07-13: 7, 07-14: 14, 07-15: 3, 07-16: 7, 07-17: 8, 07-18: 9, 07-19: 3), 14 high-priority, no critical. Working lists persisted to work/<run-id>/week-review.json. Duplicate-week guard: prior -weekly record (2026-07-12) covered W28; W29 not previously covered — cleared.
Strategic output (14 entries)
top-stories (2): internet-facing enterprise software under confirmed exploitation (SonicWall SMA1000/UTA0533, ShareFile SZC, Oracle EBS Payments, on-prem SharePoint/AD FS — patching alone is not remediation where creds/machine keys survive); Russian state-nexus pre-positioning against European CI + first joint EU/UK cyber-sanctions (FSB Centre 16 router hijacking, Turla attribution, Poland grid attribution, IP-camera surveillance of NATO supply routes).
multi-day (1): identity intrusions all abused a trusted relationship rather than breaking authentication — ShinyHunters OAuth/Entra-SSO vishing, Proofpoint client_id-spoofing credential oracle, Moodle JWT-signature-non-verification takeover, Scattered Spider helpdesk-vishing court record. Builds on (does not re-list) W28's M365 device-code/ROPC/AiTM convergence.
policy (1): EU CI-resilience regulatory deadlines (ENISA SME CRA maturity model ahead of the 11 Sept Article 14 clock; Germany KRITIS-Dachgesetz CER-Directive registration window opened 17 July).
looking-ahead (1): 2026-W29 outlook — items already in motion.
Priority calibration: high reserved for the genuinely week-defining items (both top-stories, the identity multi-day, the CH/EU incident cluster, the third-party-breach recap, the ClickFix-crimeware research, the vuln-rollup); no critical — no single stop-and-act weekly item this week, bar unchanged.
Verification & coverage notes
Weekly dedup (replaces PD-8). Dedup ran against the prior weeklies' strategic entries (W28 2026-07-12, W27 2026-07-05). Two items already consolidated in W28 return only as update_of status entries with a fresh in-window delta: The Gentlemen (update_of weekly-w28-the-gentlemen-status — ReliaQuest Q2 leaderboard reversal + Metro Mondego victim) and the npm supply-chain wave (update_of weekly-w28-npm-supply-chain-wave — AsyncAPI trusted-publishing twist + Contagious Interview). The identity multi-day entry is a NEW entry, not an update_of: W28's M365 convergence covered device-code / ROPC / AiTM auth-flow abuse, whereas this week's material is a distinct OAuth-consent / SSO-vishing / JWT-forgery / helpdesk-process sub-pattern with entirely new disclosures — it references and explicitly builds on the W28 entry without re-summarising it (verifier confirmed it extends, not re-lists).
Deliberate synthesis-by-reference (the 30 dedup WARNs).check_run.py emits 30 dedup WARNs of the "confirm the non-update decision was deliberate" class because every strategic entry shares entity keys with the operational entries it synthesises via references. This is the weekly's designed function (re-framing the week's operational signal with a strategic lens), not update-masquerade; each is deliberate and confirmed by all four verifier iterations. These are the documented weekly-polarity WARNs, not fixable defects.
Priority calibration.high on both top-stories, the identity multi-day, the CH/EU incident cluster, the third-party-breach recap, the ClickFix-crimeware research and the vuln-rollup — the genuinely week-defining items. No critical: no single stop-and-act weekly item this week (bar unchanged). The AI-accelerant, EDR-blinding, OT/ICS, both long-running, policy and looking-ahead entries are notable.
Single-source items (correctly flagged). The state-nexus EDR-blinding research entry is single-source (Kaspersky GReAT for both HelloNet and GoSerpent), reliability B / credibility 2; the GoSerpent–TetrisPhantom link is Kaspersky's own potential, not confirmed, association. The Clop attribution on ShareFile and the DragonForce/IFAGE and ByteToBreach/ANCPI extortion claims are single-analyst/actor claims, attributed as such and not stated as fact.
Citation-date discipline (v3.26 F3). Every inline (Publisher, YYYY-MM-DD) uses the source's own publication date taken from the referenced operational entry's sources[] records or the W1/W2 findings, never a discovery/processing date. Verifier iterations 1, 3 and 4 spot-checked this across the quote-bearing entries.
Verification. Four iterations (Opus/Sonnet/Opus/Sonnet rotation). Iteration 1 (Opus) found 4 truth defects — all quote/attribution (a TfL narrative mis-cited to the NCA page rather than The Register; a non-verbatim ShinyHunters "None exploited a Salesforce flaw" quote; a singular/plural AsyncAPI quote in two entries; a >40%-of-Q2 figure attributed to four groups vs the source's five) — all remediated. Iteration 2 (Sonnet) confirmed all four fixes and found one minor editorial gap (a looking-ahead bullet missing its inline citation), remediated. Iterations 3 (Opus) and 4 (Sonnet) both returned CLEAN cold — a confirmed double-CLEAN on two different models. No entries dropped.
Horizon research. W1 (threat-actor/campaign/research/report) returned 2 items (The Gentlemen Q2 leaderboard delta; Insikt Iran AI playbook → new entities actor:apt42, actor:cyberav3ngers). W2 (strategic/policy) returned 2 items (ENISA SME CRA maturity model; Germany KRITIS-Dachgesetz registration window), the KRITIS fine figures held at MEDIUM confidence pending the Bundesgesetzblatt text. Both sub-agents ran on Sonnet 5 (env-reported; definitions pin research to sonnet).
ATT&CK pin.--check up to date (v19.1). Two revoked v19 ids were mapped to survivors before composition (T1562.001 → T1685; T1574.002 → T1574.001); no dead id shipped. ICS-ATT&CK (T0xxx) ids were deliberately NOT used — the pinned dataset is enterprise-attack, so OT entries map only the enterprise vector (T1190).
Coverage gaps (W1/W2): W1 logged 9 quiet/recycled-news sources (Trellix, CrowdStrike, Shadowserver, Truesec Forest-Blizzard recap, WithSecure GREYVIBE, InfoGuard, Zimperium, CSA Labs, SANS-NewsBites); W2 logged 6 (NCSC-CH focus/CSH no policy content in-window, FINMA no new cyber guidance, BAKOM/OFCOM none, Council of Europe none, DORA none — the 8 July ESRB/ECB frontier-AI warning and the EU NIS2 CJEU referral are both pre-window and were correctly not fabricated as fresh). No essential-coverage guarantee applies to the weekly.