đŸ›Ąïž InfoSec Blue Team Briefing

Saturday, July 25, 2026

🎧 Audio Briefing

Download MP3

Cyber security developments for Saturday the 25th of July 2026 covering articles added to the BlueTeamSec community on infosec.pub. Today we have 10 articles to cover. All attribution is by the article authors. All article analysis is automated.

The UK National Cyber Security Centre and partners have exposed LAUNDRY BEAR — also known as APT28 or Fancy Bear — conducting a zero-click espionage campaign targeting Western defence, government, energy, and technology sectors. They're exploiting Zimbra Collaboration Suite with what's called a 'Beehive' exploit that compromises victims simply by viewing a specially crafted email, with intelligence suggesting AI was used in developing the exploit code. The campaign's been running since July last year.

Proofpoint have detailed Operation RoundPress, where Russia-aligned actor TA458 is targeting government and military webmail servers across Ukraine, Albania, Greece, Moldova, and TĂŒrkiye. The campaign uses half-click exploits — so just previewing the email is enough — deploying SpyPress malware against Zimbra, Roundcube, and several other webmail platforms. One for anyone running these systems in affected regions.

Group-IB have traced JadeProx, a China-nexus threat actor, through what they're calling an operations security mistake — a misconfigured Alibaba Cloud staging server that revealed their post-exploitation toolkit and active campaigns. The operation targeted government ministries, critical infrastructure, and healthcare across South-East Asia and Latin America using custom TriBack Loader malware. Not often you get comprehensive visibility into a well-resourced espionage operation through a single server misconfiguration.

ENKI have analysed a supply-chain attack by Kimsuky against a South Korean groupware vendor using a new Gomir malware variant. The campaign targeted the vendor to potentially compromise downstream customers through the trusted software distribution channel, with technical indicators and detection rules included in the report.

Recorded Future report that TAG-195 — also tracked as Golden Chickens or Venom Spider — have upgraded their Malware-as-a-Service operation with four new modular tools including TinyEgg, ChonkyChicken, and ChromEggscalator. The toolkit uses a controller-and-plugin architecture for enhanced evasion and is being supplied to financially motivated groups including FIN6 and Cobalt Group.

Security researchers have documented attackers weaponising Windows BitLocker for extortion campaigns, encrypting corporate drives after gaining access through exposed remote desktop and database services. Kaspersky Lab report the attackers use legitimate remote management tools for persistence and print ransom notes via networked printers — a living-off-the-land approach that bypasses signature-based detection. Incidents documented in Mexico and Colombia.

Socket have exposed a campaign where threat actors compromised GitHub developer accounts to inject malicious workflow files, turning GitHub Actions runners into distributed infrastructure for attacking web hosting platforms. The operation targeted a cPanel authentication bypass vulnerability, with the malicious workflows conducting internet-wide scanning and credential harvesting across six to sixteen thousand repositories. Exfiltrated data included cloud credentials, repository tokens, and database access keys.

Oracle have released their July Critical Patch Update containing fourteen hundred and forty-nine security patches across their product portfolio. Many allow remote exploitation without authentication, and Oracle note that threat actors commonly reverse-engineer these patches to target unpatched systems — so one to prioritise if you're running Oracle infrastructure.

The Python Software Foundation have implemented a new security restriction on PyPI rejecting file uploads to releases older than fourteen days. The policy follows 2026 compromises where attackers with stolen credentials injected malicious code into established package releases — a supply chain attack method known as release poisoning. Affects only fifty-six of the top fifteen thousand packages, but should prevent this particular attack vector going forward.

And finally, the U.S. Government Accountability Office have identified one hundred and seventeen distinct cybersecurity regulations managed by thirty-seven federal agencies across nine critical infrastructure sectors, with approximately seventy percent containing overlapping reporting requirements. The fragmented regulatory environment creates compliance burdens for operators, with the Office of the National Cyber Director tasked with harmonising standards by March this year.

That concludes today's briefing.

📰 Articles Covered