Weekly review
Week of Jun 29 - Jul 5, 2026
A week dominated by AI-weaponized attack chains and accelerating identity-layer compromise, with threat actors ranging from solo AI agents conducting autonomous ransomware runs to nation-states abusing passkeys and vishing to bypass MFA — all set against a backdrop of critical unpatched enterprise platform flaws (Oracle EBS, PAN-OS, SharePoint) and landmark governance moves in the UK and US regulatory space.
What you might have missed
Stories not surfaced in this week's daily digests.
Google, FBI, and Partners Disrupt NetNut/Popa Residential Proxy Botnet Spanning 2 Million Hijacked Devices
On July 2–3, 2026, Google's Threat Intelligence Group coordinated with the FBI, Lumen Technologies, and Shadowserver to significantly degrade the NetNut (also tracked as Popa) residential proxy botnet, which comprised at least 2 million compromised smart TVs and Android streaming boxes. In a single week in June, GTIG observed 316 distinct threat clusters — including cybercriminal and espionage groups — routing password-spray attacks and credential-stuffing campaigns through NetNut exit nodes to mask their origin IPs. The FBI seized NetNut's primary domain, and Google disabled associated Google accounts used for malware command-and-control; Google simultaneously updated Play Protect to block apps embedding NetNut SDKs.
Why it matters: NetNut's whitelabeling reseller program means many apparently independent proxy brands drew from the same 2-million-device pool, so this single takedown ripples across dozens of services used by hundreds of threat clusters to launder attack traffic — directly impacting the ability of defenders to block or attribute password-spray and credential-stuffing campaigns targeting enterprise environments.
Palo Alto Networks Patches 13 PAN-OS Vulnerabilities Including High-Severity Unauthenticated RCE in User-ID Terminal Server Agent (CVE-2026-0288)
On July 8, 2026, Palo Alto Networks published advisories for 13 vulnerabilities across PAN-OS and Prisma Access Agent. The most severe, CVE-2026-0288 (rated CVSS 9.2 for internet-exposed configurations), is a buffer overflow in the User-ID Terminal Server Agent (TSA) component that allows an unauthenticated attacker with network access to crash the firewall or achieve arbitrary code execution — no authentication required. Six additional medium-severity flaws include two Prisma Access Agent bugs enabling man-in-the-middle interception of VPN traffic and bypass of data-loss-prevention controls; Palo Alto states no active exploitation has been detected but urges immediate patching of all affected PAN-OS 10.2, 11.1, 11.2, and 12.1 branches.
Why it matters: PAN-OS firewalls are pervasive in enterprise and government network perimeters, and an unauthenticated code-execution path in the firewall itself — before any OS-level controls engage — represents the kind of pre-authentication, perimeter-level risk that could enable lateral movement into CUI or FCI environments with direct CMMC implications.
UK Government Launches Cyber Resilience Pledge at 10 Downing Street with 60+ Business Signatories
On July 7, 2026, the UK government formally launched its Cyber Resilience Pledge at 10 Downing Street, with over 60 businesses — including M&S, Nationwide, ITV, Microsoft UK, Cloudflare, Deloitte, Accenture UK, and Vodafone — committing to three timed actions: elevating cyber to board-level governance via the NCSC Cyber Governance Code of Practice, registering for the NCSC's free Early Warning alert service within 30 days, and applying a risk-based Cyber Essentials certification requirement across their supply chains within 60 days. The pledge is voluntary but specifically targets government strategic suppliers and is backed by a £90 million funding package announced at CYBERUK in April; the NCSC handled 204 nationally significant incidents in the year to September 2025, more than double the prior year's 89.
Why it matters: Although UK-specific, the Pledge's 30/60/90-day supply-chain Cyber Essentials mandate mirrors the CMMC flow-down pressure U.S. contractors face and is directly relevant to any organization operating as a UK government strategic supplier or sharing infrastructure with UK counterparts — and its governance model (board-level accountability with annual public attestation) signals the direction regulators on both sides of the Atlantic are moving.
Oracle E-Business Suite Payments Flaw CVE-2026-46817 (CVSS 9.8) Actively Exploited in the Wild Against ~950 Exposed Instances
Active exploitation of CVE-2026-46817 — an unauthenticated HTTP takeover vulnerability in the Oracle Payments File Transmission component of Oracle E-Business Suite versions 12.2.3 through 12.2.15 — was first confirmed on June 27, 2026, by Defused Cyber on its EBS honeypots, despite no public proof-of-concept existing at the time. Shadowserver identified approximately 950 internet-facing Oracle EBS instances globally (concentrated in the US and Europe), and threat intelligence attributed ongoing exploitation to initial access brokers who are selling compromised EBS environments to ransomware operators and credential-theft syndicates. Oracle patched the flaw in its May 2026 Critical Security Patch Update, but organizations that did not apply that update face unauthenticated remote takeover of payment processing infrastructure, financial data exfiltration, and manipulation of payment instructions.
Why it matters: Oracle EBS is widely deployed in defense contractors and government-adjacent organizations for financial and ERP operations; an unauthenticated, pre-PoC exploitation pattern targeting the payments module directly threatens the financial integrity and CUI boundaries of any organization that has not applied the May 2026 CPU, and the Clop ransomware group's earlier use of a related Oracle EBS flaw (CVE-2025-61882) shows this class of vulnerability is a recurring ransomware entry point.
Microsoft SharePoint Server CVE-2026-45659 Added to CISA KEV with Two-Day Patch Deadline After Microsoft Failed to Disclose Patch Existence
CISA added CVE-2026-45659 — a deserialization remote code execution vulnerability in Microsoft SharePoint Server requiring only 'Site Member' permissions — to its KEV catalog on July 1, 2026, with a July 4 deadline for federal agencies under BOD 26-04. In an extraordinary disclosure failure, Microsoft shipped the patch during the May 2026 Patch Tuesday cycle but did not publish the associated security bulletin until May 21, weeks later, having 'forgotten to report the existence of the vulnerability'; Microsoft had assessed exploitation likelihood as 'less likely,' a rating CISA's KEV addition directly contradicted. Organizations that installed the May 2026 SharePoint update may have applied the patch without knowing it addressed an actively exploited flaw, complicating audit trails and log review for prior compromise.
Why it matters: The combination of a botched vendor disclosure, an active exploitation confirmation that contradicted the vendor's own severity assessment, and a two-day federal remediation deadline is a textbook case for why relying solely on vendor bulletins for patch prioritization is insufficient — particularly for SharePoint environments that handle CUI or are scoped under CMMC, where documented patch status is an audit requirement.
Themes this week
Patterns observed across coverage.
AI as Both Attack Tool and Attack Surface
This week's digest contains at least five distinct AI-threat threads that together define an inflection point: JadePuffer conducted a fully autonomous ransomware attack end-to-end via LLM agent; a single attacker used AI workflows to compromise an AWS environment in 72 hours; Ghostcommit injected malicious prompts into PNG images to manipulate AI code-review agents; GhostApproval exploited symlink bugs in six AI coding assistants; SkillCloak evaded all static scanners for AI agent skills; and MODBEACON used gRPC to blend C2 traffic with AI application traffic. Simultaneously, AI is reshaping defense — Microsoft publicly committed to more patches driven by AI-discovered flaws, and AWS published architectural guidance for prompt-leakage and multi-agent authorization. The net result is that AI is simultaneously accelerating attacker automation, introducing new vulnerability classes in AI toolchains, and pressuring defenders to patch faster.
Identity-Layer Compromise Has Replaced Credential Phishing as the Primary M365 Threat Vector
Three separate threat clusters — O-UNC-066 (passkey enrollment vishing), Helix (vishing + device code phishing + MFA abuse targeting SharePoint), and DEBULL (device-code flow phishing with collaboration-themed lures) — all operated entirely within legitimate Microsoft authentication flows this week, requiring no malware, no stolen passwords in the classical sense, and no fake login pages. Combined with the Forg365 PhaaS platform adding AI-generated lures to AiTM + device-code attacks, the week establishes a clear pattern: the identity layer (Entra ID, MFA enrollment, OAuth device flow) is now the primary battleground for M365 compromise, and endpoint-centric detection is largely blind to these operations.
Software Supply Chain Attacks Broadened Across Ecosystems and Target Types
Supply chain attacks this week spanned npm (jscrambler 8.14.0 with Rust infostealer, Injective Labs SDK with crypto wallet stealer), GitHub (dormant ghost accounts mapping corporate orgs, forged Verified commit signatures), multi-ecosystem packages (North Korea's PolinRider dropped 108 packages across npm, Packagist, Go, and Chrome Web Store via compromised maintainer accounts), and AI agent plugin ecosystems (SkillCloak evading skill scanners). The jscrambler incident is notable because npm 12's default-off install scripts — disclosed the prior week — would have blocked the malicious preinstall hook, demonstrating that the ecosystem mitigations are lagging behind attacker adoption.
Compliance Frameworks Are Shifting From Point-in-Time Attestation to Continuous, Auditable Evidence
Multiple regulatory and governance developments this week — FedRAMP 2026's structural shift to continuous evidence pipelines, CIRCIA's expected September finalization mandating incident reporting timelines, the DoD CMMC Phase 2 milestone approaching in November 2026 (requiring C3PAO third-party assessments for applicable solicitations), the UK Cyber Resilience Pledge's annual public attestation requirement, and France's ANSSI halting certification of non-quantum-safe products — collectively signal a global regulatory direction away from periodic audit packages and toward live, auditable control evidence. For IT administrators managing defense contractor environments, the CMMC Phase 2 deadline is the most immediate operational forcing function.
Suggested new sources
Worth considering for your feed list. Review and add manually.
Cisco Talos Intelligence Blog
Threat intelligence, malware analysis, APT attribution, vulnerability research, and incident response — with particular depth on network-layer threats, RATs, and nation-state actor tracking.The existing digest draws heavily from BleepingComputer and The Hacker News for threat coverage, but Talos consistently publishes primary research on the threat clusters and malware families that appear in those outlets days later — this week, Talos was the primary source on UAT-7810's LONGLEASH ORB network expansion, a story covered in the digest only in summary form. Adding Talos provides the technical depth (YARA rules, IOCs, full TTPs) that an IT administrator needs to move from awareness to detection.
RSS: https://blog.talosintelligence.com/rss
Risky Business Newsletter (Risky Bulletin)
Concise, opinionated daily briefings on cybersecurity news with editorial context — covers threat intelligence, vulnerability disclosures, law enforcement actions, and policy developments with a practitioner's perspective.The current digest's CMMC and infrastructure coverage relies on Federal News Network and FedScoop but lacks a daily editorial voice that contextualizes why a given story matters operationally; Risky Bulletin fills that gap with short, high-signal summaries and clear 'so what' framing that complements the raw news feeds already in the rotation without duplicating them.
RSS: https://news.risky.biz/rss
Cybersecurity Dive
Enterprise cybersecurity news with a strong focus on compliance, regulatory developments, breach reporting, and vendor/product coverage — specifically oriented toward decision-makers in mid-to-large organizations.This week's missed stories (Oracle EBS exploitation, SharePoint KEV botched disclosure) were covered with strong operational context by Cybersecurity Dive but did not surface through the digest's existing BleepingComputer/Hacker News/Federal News Network feeds; Dive's coverage of compliance shifts (CIRCIA, FedRAMP, CMMC) consistently includes practitioner-relevant detail on timelines and contracting implications that would complement the existing cmmc-tagged feed without duplicating it.
RSS: https://www.cybersecuritydive.com/feeds/news/