W1RETAP Intel Report — 2026-07-10
W1RETAP INTEL REPORT
FRIDAY, 10 JULY 2026
================================================================
SEVERITY: 7/10 — HIGH
Active mass exploitation of multiple KEV-listed flaws (SharePoint, ColdFusion), a confirmed breach at a major global consultancy, and a confirmed intrusion into a DHS intelligence-sharing platform justify a HIGH rating for the day.
TOP STORY:
Accenture has confirmed a data breach after a threat actor offered stolen data for sale, claiming roughly 35 GB of exfiltrated material including source code, RSA and SSH keys, Azure personal access tokens, Azure Storage access keys, and configuration files. If the key material is genuine and unrotated, downstream access to client-facing cloud environments is a realistic follow-on risk. Watch for supply-chain fallout and credential-rotation advisories.
BREACHES & INCIDENTS:
Mount Royal University (Calgary) reported attackers stole and then deleted data from its file storage systems after breaching the university network — a destructive twist on standard exfiltration. Ford Motor Company was listed on a leak forum as a victim of the Krybit ransomware group; scope of exposed data is still under investigation. Qilin claimed a ransomware hit on Calgary-based manufacturer Chemco. The Conduent breach continued to balloon, with healthcare breach reporting now placing affected individuals above 62.2 million. In supply-chain news, malicious npm and PyPI packages were caught delivering stealer malware targeting users of Paysafe, Skrill, and Neteller payment apps. On the justice side, a 41-year-old former ransomware negotiator was sentenced to 70 months in US prison for conspiring with BlackCat operators to extort victims, and Operation First Light 2026 (97 countries) netted 5,811 arrests and $293M in intercepted assets.
VULNERABILITIES & EXPLOITS:
Microsoft SharePoint deserialization RCE CVE-2026-45659 is under active exploitation and was added to the CISA KEV catalog, with federal agencies given a tight remediation deadline. Adobe ColdFusion path traversal CVE-2026-48282 is seeing mass exploitation; CISA ordered agencies to patch by today. CISA also added three KEVs on 7 July: CVE-2026-48908 (JoomShaper SP Page Builder unrestricted file upload), CVE-2026-55255 (Langflow authorization bypass), and CVE-2026-56290 (Joomlack Page Builder improper access control). SimpleHelp remote support software carries a CVSS 10.0 auth bypass (CVE-2026-48558) flagged as exploited. Ubiquiti shipped fixes for multiple critical UniFi flaws, including a CVSS 10.0 improper access control bug in UniFi Connect. Researchers at Coinspect disclosed a crypto wallet flaw dubbed Ill Bloom that attackers are already using to drain wallets. A China-linked cluster is exploiting vulnerable Roundcube webmail servers at US and Canadian universities for credential theft and backdoor deployment. Australia's ACSC warned of a large-scale CMS exploitation campaign planting webshells on vulnerable sites, with AI reportedly accelerating campaign speed and scale.
TOOLS & TECH:
No major new offensive/defensive tool releases surfaced in the last 24-48 hours. Two adjacent items worth noting: researchers flagged a new ransomware family, GodDamn, using the PoisonX kernel driver to kill security software (BYOVD-style defense evasion continues to spread), and the FBI is warning about Kali365, an emerging phishing-as-a-service platform active since April 2026 — note the name is unrelated to the legitimate Kali Linux project.
U.S. GOVERNMENT CYBER MOVES:
DHS confirmed hackers breached the Homeland Security Information Network (HSIN), the sensitive-but-unclassified platform used by federal, state, local, and private-sector partners to share threat intel — intrusion window late May to early June, targeting HSIN servers and an inter-agency SharePoint system. No attribution yet; no classified networks impacted, but timing during World Cup security coordination raises the stakes. FBI, CISA, NSA, EPA, DOE, and CYBERCOM jointly warned of ongoing exploitation of internet-exposed OT devices, including PLCs, across critical infrastructure sectors. DOJ/FBI announced a court-authorized operation neutralizing the US portion of a GRU Unit 26165 (APT28) compromised-router network. FBI also warned of FIFA website spoofing ahead of World Cup matches and evolving Kimsuky tactics against think tanks and academia. NIST continues refining its Cybersecurity Framework AI Profile (NIST IR 8596) toward an initial public draft this year.
TRENDS TO WATCH:
AI is now cited on both sides of the ledger: agencies point to AI accelerating mass-exploitation campaigns like the ACSC-flagged CMS webshell wave, while the UK NCSC pitched an AI-enabled national Cyber Shield for machine-speed defense. Expect continued ransomware focus on edge devices, remote management tools, and identity platforms — the KEV additions this week (page builders, Langflow, SimpleHelp) all fit that internet-facing pattern. Kernel-driver abuse for EDR evasion (PoisonX/GodDamn) keeps maturing; defenders should prioritize vulnerable-driver blocklists.
END OF REPORT. Coverage window: approximately 8-10 July 2026, compiled 10 July 2026 from open-source reporting.