Threat Intelligence Bulletin: July 8, 2026

Cyber Security News

Scammers race to cash in on Venezuelan earthquake disaster

Scammers wasted no time exploiting Venezuela’s devastating earthquake, with researchers uncovering 212 newly-registered relief-themed domains in just five days…. Read more

Third-Party Breaches Teach Education Sector a Costly Lesson in Vendor Risk

Rising threats from third-party actors are forcing institutions to play defense to protect student data from ransomware and other attacks. Read more

CitrixBleed-ing Again? NetScaler Vulnerability Under Attack

Attackers wasted little time targeting the latest memory disclosure flaw in Citrix’s NetScaler products, after researchers published a proof-of-concept exploit … Read more

Ransomware Thugs Masquerade as Interpol to Entice Small Biz

The ransomware campaign relies on basic social engineering and stretches across multiple regions, including the US, Europe, Middle East, and elsewhere. Read more

Best Practices

Detection engineering: A programmatic approach to identifying cyber threats

Detection engineering, which was once a niche practice among mostly large companies, appears to have evolved into a capability that organ… Read more

Microsoft 365 users fall victim to one-in-a-million password spray attack

Microsoft users have been hit by a massive, automated password spray attack. Among those targeted by the attack were clients of securi… Read more

Unpatched SharePoint servers opened the door to multiple attackers Microsoft finds

What began as a routine ransomware investigation uncovered two unrelated attackers operating inside the same victim network at the same t… Read more

British public won’t tolerate cyber disruption any more

The British public’s tolerance for cyber disruption, particularly at high-profile organisations such as retailers, is wearing thin, according to a TalkTalk Busi… Read more

Canvas breach hit 160 UK unis but caused limited damage

The April 2026 ShinyHunters breach of the Canvas learning management system caused downstream impacts at more than 150 higher education institutions in the UK, … Read more

New Threats and Vulnerabilities

Defending Against China-Nexus Covert Networks of Compromised Devices

Defending against china-nexus covert networks of compromised devices executive summary Defending against China-nexus covert networks of compromised devices&nb… Read more

Your Windows 11 PC might be hiding a 500GB storage bug – how to check

A glitch in Windows 11 causes a specific system file to keep growing in size, though a patch is available. Here’s what you need to know about it. Read more

Patch Management

Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data

New Microsoft research shows how attackers can hijack AI agents that act on a user’s behalf, using nothing more than a poisoned tool description to ma… Read more

RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS

A new two-stage malware family called RustDuck is hijacking home routers, IP cameras, Android boxes, and poorly secured servers, then stitching them into a netw… Read more

Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses

Cybersecurity researchers have flagged an active browser extension campaign that is designed to steal cryptocurrency by stealthily replacing wallet addresses wh… Read more

Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input

Microsoft has found a malicious Chrome extension that posed as the AI search engine Perplexity and quietly logged what people searched for. It routed every quer… Read more

? Weekly Recap: Linux Kernel Flaws AI Malware Tricks Turla Backdoor Infostealers and More

This week was a reminder that attackers do not always need big tricks. One small mistake, one old access path, one missed patch, and suddenly the door is open. … Read more

AI and Security

How is AI changing datacenter network fabrics?

The network has become the nervous system of any organization running AI at scale. A single distributed training run can chew through thousands of GPUs for wee… Read more

OpenAI Codex bombards SSDs with needless write operations costing millions

Modern SSDs have a limited number of write cycles before they expire. Now, OpenAI is scrambling to fix a flawed logging implementation that has been shortening… Read more