United States: cybersecurity landscape, July 2026
July ended with OT incidents in water, ransomware in health care and retail, and 7 regulatory moves; SharePoint and AD FS led exploitation.
Key findings
- The dominant signal in July in the USA was incidents, with 23 of 73 verified events and a strong concentration in OT, water, and local government.
- Minnesota accounted for the month’s most sensitive case: more than 30 water systems affected, with operational disruptions but no confirmed contamination.
- Fairlife confirmed a ransomware event with a temporary production shutdown in the United States, while other cases in the month remained only on leak sites or without final classification.
- Active exploitation of SharePoint and AD FS increased technical pressure, and the critical CVEs mentioned rose from 4 in June to 8 in July.
- CIRCIA, the NDAA, and the GAO show an active regulatory front, but the month was more marked by incident response than by new rules.
- Local governments and public utilities remain recurring targets, with multiple claims in ransomware trackers and low public confirmation in several cases.
- The exposure of public services, persistent weak credentials, and the lack of OT/IT segmentation continue to be common factors behind the month’s events.
Monthly reference modules
These modules are completed automatically with the verified dated facts within the period. Each one states its basis and counting criterion, so the figures reconcile across modules. They are the recurring month-to-month reading; the analysis that follows develops the cases without repeating this summary.
Indicator window: 73 dated facts in July 2026. Facts from earlier months are used only as a comparative frame in the analysis, never as volume for this period.
Executive monthly summary in USA
July 2026 left the United States with an uneasy mix, coordinated attacks against operational technology at more than 30 water systems in Minnesota, a ransomware and extortion wave that again hit local governments and health care, and an active regulatory push around incident notification, cybersecurity maturity, and AI risk management. The month was driven more by incidents than by new rules. Of the 73 verified events in the period, 23 were classified as untyped incidents and 22 as cases with ransomware or extortion as the primary focus.
The case that best frames the month is Minnesota. Minnesota IT Services confirmed a coordinated cyberattack against community water systems, with outages in Braham, Plymouth, South St. Paul, and other localities. The available material indicates operational impact on controls and pumping, but no water contamination and no classic ransomware campaign with confirmed encryption. Formal attribution remained open throughout the month, although several sources linked the pattern to the Iranian campaign against industrial devices that CISA, FBI, NSA, and the Department of Energy had already described in public alerts.
At the same time, ransomware activity continued to concentrate in health care and local government. Fairlife, Coca-Cola’s US subsidiary, paused production after a ransomware event that compromised manufacturing systems. RingCentral appeared on leak sites claimed by ShinyHunters. Greene County, Georgia, and the City of Atlanta were listed in ransomware trackers. The July material also includes The Morton Grove Park District, City of Houston, and other local entities, although in several cases the source only supports a leak-site appearance or claims not publicly confirmed.
The vulnerability layer was the busiest part of the month. CISA warned about active exploitation of three flaws in SharePoint on-premises, and July’s overall set increased pressure on AD FS, SharePoint, and other internet-exposed products. The contrast with June was clear, there were 8 critical CVEs mentioned in the period’s material, compared with 4 the month before. That does not mean there were no other exploited flaws in the country, only that the July corpus focused attention on these cases.
On the regulatory side, the focus shifted less by volume than by operational density. CIRCIA continued moving toward its final rule, the House passed the NDAA with an extension of the Cybersecurity Information Sharing Act, the GAO released a report questioning duplicate reporting requirements, and the White House launched Gold Eagle as a coordination mechanism for vulnerabilities discovered with AI. The result is a month marked by sharp friction between reporting, coordination, and the real absorption capacity of critical entities.
National Risk Snapshot for the U.S. in July 2026
The U.S. risk reading in July 2026 is high. Not because there was a single major breach, but because three material signals converged: attacks on critical water infrastructure, ransomware and extortion targeting health organizations and local government, and active exploitation of high-impact vulnerabilities in widely used software. The number of verified incidents was high for a single month, and the operational severity of several of them was real, not theoretical.
Tactically, the month showed a preference for targets where the effect is measured quickly. Water, health, public services, and exposed portals. Minnesota carried the story line for physical disruption and OT. Fairlife added the manufacturing and business continuity angle. Leak site and extortion campaigns against municipalities and service providers reinforced that economic pressure remains focused on entities with little tolerance for downtime and unavoidable public exposure.
A comparison with Latin America helps frame the context, even though the report focuses on the U.S. In the same period, there was ransomware activity using relatively rudimentary tools and abuse of Windows environments in the region, along with campaigns exploiting exposed remote services and configuration errors. The pattern repeated on both sides of the hemisphere is less sophisticated than public discourse sometimes suggests: weak credentials, exposed systems, poorly segmented collaboration and operations software, and a regulatory response that trails the incident.
From a defensive perspective, the month leaves one clear takeaway for the U.S.: the critical attack surface is no longer limited to email and endpoints. The mix of OT, SharePoint, AD FS, VPNs, routers, and identity systems pushed teams to look at the full chain of access, persistence, and recovery. Public exposure of administration services and the continued presence of default credentials or weak configuration kept appearing as common factors.
US period indicators
| Indicator | Value | Note |
|---|---|---|
| Verified facts for the period | 73 | Base of all indicators; only facts dated July 2026 |
| Time window for the indicators | 73 facts dated July 2026 | Closed period window |
| Unclassified incidents (breaches or outages) | 23 | Breaches, outages, or other incidents with no closed classification |
| Cases with ransomware or extortion as the primary focus | 22 | Period count, not mixed with other impact types |
| Confirmed asset encryption | 1 | Ransomware subtype with verified encryption |
| Exfiltration without encryption (simple extortion) | 1 | Ransomware subtype with verified exfiltration |
| Leak site mention only | 5 | Claims or listings without confirmed public impact |
| Impact subtype cannot be determined from the material | 15 | The source does not allow the impact subtype to be closed |
| Documented fraud or phishing cases | 1 | Isolated fact in the period |
| Documented regulatory moves | 7 | Regulatory, legislative, or compliance actions |
| Critical CVEs mentioned | 8 | Only the critical ones mentioned in the analyzed material |
| Sectors with at least one documented fact | 7 | One fact may affect more than one sector |
| Predominant threat of the month | Incidents | 23 of 73 facts |
| Facts with direct source confirmation | 81% | Direct confirmation over the total verified facts |
Relevant incidents in the USA
Coordinated attack on Minnesota water systems
Minnesota IT Services confirmed that between July 26 and 27, more than 30 community water systems were affected by a coordinated attack against operational technology. Available reporting describes disruptions in Braham, Plymouth, South St. Paul, and other localities, with impacts on water towers, pumping stations, and treatment plants. In Braham, the water plant was out of service for several hours. The sources agree on one key point, there were no signs of contamination or lasting changes in water quality.
Attribution remained open. The joint advisory from CISA, FBI, NSA, and the Department of Energy had already warned about Iran-linked actors exploiting exposed PLCs in water, power, and municipal services. Several later reports suggested the pattern matched CyberAv3ngers, but the material from the period does not record a closed official attribution. For a monthly report, that means separating the confirmed operational impact from the attribution hypothesis.
Fairlife, production halted after ransomware
Coca-Cola said Fairlife temporarily paused production in the United States after a ransomware attack that compromised part of the systems used for manufacturing. The company itself confirmed the case, and later coverage said unauthorized access reached production systems. At the time of the material, it had not been resolved whether the incident also met a financial materiality threshold for the group.
Public pressure increased when the Anubis group appeared on leak sites claiming responsibility and threatening to publish data. Even so, the month’s source material allows this case to be classified as ransomware with confirmed encryption or operational disruption, because production was suspended. It should not be mixed with leak site cases that do not show verified impact.
DHS and the HSIN exchange network
DHS confirmed it was investigating an incident in a legacy classified information-sharing environment. Reuters and other reports linked it to HSIN, the platform used to share sensitive information among federal, state, and local agencies. Available material did not allow for a determination of the exfiltration type or public attribution, so the case remains an unclassified incident, with high institutional risk because it involves a government coordination system.
AssuranceAmerica and the exposure of millions of records
TechCrunch reported, and Check Point later repeated, that AssuranceAmerica notified a breach exposing personal data and driver’s license numbers of nearly 7 million people. The corpus does not include a full technical breakdown of the intrusion vector or whether ransomware was involved. In risk terms, it remains one of the month’s largest privacy events by affected volume.
RingCentral and ShinyHunters’ claim
RingCentral appeared on ShinyHunters’ leak site with claims involving employee data, user data, and credentials. Available material does not include independent public confirmation from the company about the incident, so the case can only be described as a leak site mention. That distinction matters, because a claim is not the same as a verified breach, much less confirmation of full exfiltration.
Greene County, Georgia, and other listed municipalities
Greene County, Georgia, appears in ransomware trackers as a presumed victim of Incransom. The City of Atlanta, City of Houston, West Chester Township, and Town of Vienna also appear in records from the same tracking ecosystem. In several of these cases, the public evidence consists of the leak site listing or trackers such as ransomware.live, with no official municipal statement or detail on the real scope. The monthly picture shows persistent pressure on local governments, but it does not allow all of those records to be treated as equivalent incidents.
Active threats and campaigns in the USA
Ransomware, encryption and simple extortion
The only case the material allows to classify as confirmed encryption is Fairlife, because of production disruptions at plants in the United States. The rest of the ransomware or extortion cases are split between exfiltration without encryption, leak site only mentions, and cases that cannot be classified. That spread does not reduce their operational value, but it does prevent grouping everything under one label without losing precision.
| Subtype | Cases | Monthly reading |
|---|---|---|
| Confirmed asset encryption | 1 | Verified direct operational impact |
| Exfiltration without encryption | 1 | Simple extortion with claimed data |
| Leak site only mention | 5 | Public claim without independent confirmation |
| Cannot be determined | 15 | Not enough detail to lock the subtype |
Fraud and phishing
Only one case was documented as fraud or phishing during the period. That should not be read as the absence of fraudulent activity in the country, but as the absence of events dated July 2026 and with sufficient confirmation within the body of work used for this report.
APT, hacktivism and campaigns against OT
The campaign linked to Iran against industrial devices remains the month’s main sign of operational APT or hacktivism in the USA. CISA, FBI, NSA and the Department of Energy said the actors are exploiting exposed PLCs and other OT equipment in water, energy and municipal services. Minnesota fits that frame based on the type of impact and the use of operational technology as the incident vector. The material does not settle final attribution, but it does make clear that the focus is critical infrastructure with public exposure.
Critical vulnerabilities with U.S. impact
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| CVE-2026-32201 | Microsoft SharePoint Server on-premises | Active exploitation, unauthorized access and possible authentication bypass | CISA |
| CVE-2026-45659 | Microsoft SharePoint Server on-premises | Active exploitation, deserialization and persistent access | CISA |
| CVE-2026-56164 | Microsoft SharePoint Server on-premises | Active exploitation, missing authentication for critical function | CISA |
| CVE-2026-56155 | Active Directory Federation Services | Active exploitation, local privilege escalation | CISA |
| CVE-2026-50522 | Microsoft SharePoint | Added to KEV for evidence of active exploitation | knutmichael.com |
| CVE-2026-16232 | Check Point SmartConsole | Exploitation in the wild, authentication bypass | Rapid7 |
| CVE-2026-15409 | SonicWall SMA 1000 | Added to KEV, actively exploited | Secarma |
| CVE-2026-15410 | SonicWall SMA 1000 | Added to KEV, actively exploited | Secarma |
This month’s material puts SharePoint at the center of the defensive agenda. CISA did not just warn about active exploitation, it also recommended blocking exposed central administration, rotating IIS keys, and looking for known deserialization and persistence techniques. In AD FS, the issue was no less serious, because the exposure affects identity, authentication, and remote access, three layers many organizations still treat separately.
Regulation and compliance in the USA
July brought seven documented regulatory moves in the United States. The most important thread was CIRCIA, whose final rule CISA expects to close in September 2026. That rule will require reporting substantial cyber incidents within 72 hours and ransomware payments within 24 hours. The deadline is no longer theoretical. CISA has been holding town halls with critical sectors to define implementation, and the public debate shows the tension between more reporting and less operational friction.
The House of Representatives approved its version of the fiscal 2027 NDAA with a nine-year extension of the Cybersecurity Information Sharing Act of 2015. That matters because it keeps the information-sharing architecture alive as a core part of the US model. At the same time, the GAO released a report that found 117 cybersecurity regulations issued by 37 agencies, with 80 of them containing potentially duplicative reporting requirements. The message is clear: the regulatory ecosystem keeps growing, but it is still not organized.
The White House also pushed Gold Eagle, a coordination initiative for vulnerabilities discovered by AI. It is not yet a law or a new regulator, but rather a coordination platform among agencies, companies, and critical operators. At the same time, FINRA and the Treasury advanced AI risk management frameworks for the financial sector, confirming that the discussion is no longer limited to traditional cybersecurity, but also includes model governance.
| Regulatory move | Date | Scope |
|---|---|---|
| CIRCIA moves toward final rule | July 2026 | Incident and ransomware payment reporting |
| Fiscal 2027 NDAA approved in the House | 23 July | Nine-year extension of CISA 2015 |
| GAO report on duplication | 22 July | 117 regulations in 9 sectors |
| Gold Eagle launched | 14 July | AI vulnerability coordination |
| FINRA AI risk guidance | 10 July | GenAI risk in financial services |
Most affected sectors in the USA
Local public sector was among the hardest hit this month. Minnesota put water utilities and municipal governments in the spotlight. Greene County, Houston, Atlanta, Vienna, and other names that appear in ransomware trackers reinforce the same point, local governments remain recurring targets, often with limited capacity to absorb prolonged incidents and with high public exposure by design.
Healthcare was again among the most affected sectors, although July's corpus shows both direct attacks and large-scale collateral impacts. Fairlife is not healthcare in the strict sense, but it is food and manufacturing, and its case adds to the persistence of breaches and extortion targeting hospitals, clinics, and vendors. The material also includes references to hospitals in other regulatory and criminal contexts, confirming that the sector remains under sustained pressure.
Critical water and energy infrastructure was the other block of structural relevance. The novelty there was not a single isolated campaign, but the repetition of a pattern: exposed PLCs, weak authentication, operation interfaces accessible from the internet, and an attacker's ability to alter or disrupt physical operations. When the flaw is exposure, the attack surface depends not only on the equipment manufacturer, but on the entire management architecture.
Trends and signals to watch in the USA
The comparison with the previous month shows that regulation fell from 19 to 7 documented events, while the critical CVEs mentioned rose from 4 to 8. That shift does not mean regulatory risk disappeared or that technical exploitation is anything new. It does show that the July corpus was weighted toward concrete operations, incidents, campaigns, and vulnerabilities being actively exploited.
The leading threat category moved from regulation in the previous month to incidents in July, with 23 of 73 events. That shift matters. In practice, the month’s pressure was no longer centered on policy debate, but on responding to events with real operational impact, especially water, health care, manufacturing, and local government.
The fraud or phishing figure did not change from the previous month. There was one case in June and one in July. There is not enough basis to say fraud went down or up in the country based on the available corpus, only that the material analyzed kept a marginal presence compared with incidents and vulnerabilities.
The vulnerabilities section deserves close monitoring. SharePoint continued to appear as an entry and persistence vector, AD FS as a sensitive identity point, and Check Point SmartConsole as an example of in-the-wild exploitation. In other words, the month left a short but highly sensitive list of products that should be high priority for patching and compromise hunting.
Security recommendations for teams in USA
First, review public exposure of management and collaboration services. SharePoint on-premises, AD FS, VPNs, routers, and OT portals should not be reachable from the Internet unless there is a strict need and compensating controls are in place. If an instance must be exposed, hardening has to happen before publication, not after an incident.
Second, rotate credentials and secrets tied to IIS, SharePoint farms, edge devices, and remote access services. The July material keeps repeating the same pattern: attackers do not need exotic malware if they can steal machine keys, abuse valid accounts, or exploit weak configurations.
Third, segment OT from IT based on operational need, not just on paper. The Minnesota case sends a clear signal for water, energy, and public services: remote administration, PLCs, and HMI monitoring cannot share a trust boundary with standard corporate systems.
Fourth, prepare active hunting for persistence. In SharePoint, that means looking for anomalous deserialization, web shells, configuration changes, new machine keys, and suspicious outbound connections. In OT, it means reviewing remote access, logic changes, screen alterations, and after-hours events.
Fifth, align legal, continuity, and technical response before an incident. With CIRCIA moving forward, the 72-hour and 24-hour deadlines for certain reports will require traceability, evidence, and early decision-making. The team that waits for forensic closure before notifying will probably be too late.
Material limitations
This report was prepared exclusively from the facts dated July 2026 included in the provided material. The indicator window covers 73 facts dated July 2026, and no aggregated telemetry or material outside that cutoff was included. Facts from earlier months were used only when relevant to compare trends, and always with their explicit month.
An indicator at 0, especially in the CVE section or any other category, means only that it did not appear in the material analyzed for this period, not that the fact does not exist in the USA or in the region. The same applies when the ransomware classification could not be closed, the absence of a subtype does not mean the absence of an incident.
The material excluded consumer social networks, LinkedIn posts, and sponsored or commercial content that was not within the enabled sources. As an integrity criterion, attempts, blocks, scans, and other forms of telemetry that do not constitute verifiable incidents for the period were also left out. When attribution was only suggested by a tracker or by a secondary source without official confirmation, it was treated as such and not as certainty.
Sources
- Coordinated Cyberattack Targets 30+ Minnesota Water SystemsThe Hacker News
- Estados Unidos sospecha que Irán pudo estar tras el ciberataque a los sistemas de agua de MinnesotaLa Tercera
- Government & Defense — USRansomware.live
- Ransomware Wing — víctimas, grupos y patrones · PulsePulse (Kalir.io)
- Ransomware Radar - Victim Tracker - ShellCodeXShellCodeX
- Ciberataque coordinado afectó a más de 30 sistemas de agua en MinnesotaNivel4
- Более 30 объектов водоснабжения в США пострадали от скоординированной кибератакиXakep
- Victim: American Hospice & Home Health Services (Ahhh Care) – CRPxOransomware.live
- Cyberattacks target several Minnesota water facilities, state officials sayFOX 9 Minneapolis-St. Paul
- "Coordinated cyberattack" targeted 30-plus Minnesota water systems; malware shut down Braham water plantCBS News Minnesota
- Ataque cibernético coordenado atinge 30 estações de água nos Estados Unidos e mobiliza força-tarefaTecMundo
- City of Atlanta Listed by ExfilSquad Ransomware GroupGalaxyWarden
- La IA dirigida a la tecnología operativa: perspectivas sobre amenazas emergentesThe Cryptonomist
- Victim: City of Houston @ Exfilsquadransomware.live
- https://nayaritnoticias.com/2026/07/23/washington-acuso-a-hackers-de-iran-por-ataques-a-los-sistemas-de-agua-y-electricidadNayarit Noticias (cita a CISA/FBI y Cybersecurity Dive)
- EEUU alerta: hackers iraníes vinculados al IRGC están atacando infraestructura crítica de agua y energíaWWWhat's New
- OpenAI revela un ciberataque de agentes de IALa Ecuación Digital
- Hackers apagan alarmas de emergencia en plantas de EE. UU.Qore
- Ransomware gangs go after EMEA healthcare's supply chainHelp Net Security
- Authorities investigating a coordinated cyberattack against Minnesota community water systemsCybersecurity Dive
- CISA, FBI warn that Iran-linked hackers are expanding target set for water, energyCybersecurity Dive
- Golpe da falsa central bancária fica mais sofisticado e liga o alerta da FebrabanO Banco Digital Notícias
- AA26-097A: Ciberdelincuentes vinculados a Irán explotan dispositivos en sectores de infraestructura crítica de EE.UU.CISA
- Agente de IA da OpenAI invadiu sistema do Hugging Face e empresa só percebeu dias depois, diz investigaçãoG1 (Brasil)
- Una IA dirigió sola un hackeoYucatán
- El inédito ataque de la IA a una base de datos alarma a los programadoresEl Correo
- Caso da OpenAI mobiliza Casa Branca e leva Congresso americano a discutir controle sobre IAsG1 (Brasil)
- IA pode decidir atacar empresas?Entenda invasão por modelo da OpenAI em detalheg1
- EE.UU. advierte que operativos rusos atacan los correos electrónicos de científicos nucleares y contratistas de defensaCNN en Español
- Sophos AI Security Report 2026itwarelatam
- Ransomware Attacks Using Corporate Printers Found in LATAMRTM World
- US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS DevicesSecurityWeek
- 🔴 CISA expands Iran PLC threat to Schneider, Siemens 🔴YouTube
- Iranian-Affiliated Actors Expand PLC Targeting to Siemens and Schneider Electric: What CISA’s Updated Advisory Means for CNIIOActive
- Iranian Hackers Infiltrate Siemens and Schneider PLCs, Blinding Operators With Fake ReadingsTechTimes
- Hacker Iran Serang Sistem Air dan Listrik AS, Target PLC Rockwell hingga SiemensInfobulungan
- Estados Unidos alerta de una campaña de ciberdelincuentes iraníes contra dispositivos industriales de Siemens, Schneider y RockwellEscudo Digital
- Siemens, Schneider e Rockwell nell’allerta CISA-FBI: nuovo avviso sugli hacker legati all’IranSoftonic (sección IT)
- Extorsión BitLocker: el esquema XEntry con impresorasHelpRansomware / Securelist (Kaspersky)
- BitLocker Extortion: The XEntry Printer Ransom SchemeHelpRansomware / Securelist (Kaspersky)
- OpenAI aún investiga cómo sistema se salió de ámbito de prueba y hackeó a otra empresaChicago Tribune
- Boletín Semanal de Ciberseguridad, 18-24 de julioTelefónica Tech
- Centro de seguridad de IA: EE. UU. avanza la medidaEl Solitario
- 570 fallas en un martes: el Patch Tuesday más grande de julio 2026CodigoVigia
- Ep.696 - RadioCSIRT Édition Spéciale Patch Tuesday 14 juillet 2026RadioCSIRT (YouTube)
- EE. UU. acusa a operadores rusos de alojar ciberataques que causaron daños por USD $62 millonesDiarioBitcoin
- EUA acusam três cidadãos russos de facilitar ataques de ransomware com danos de 57 milhõesTugaTech
- La fuga de GPT-5.6 Sol: la llamada de atención que América Latina no puede ignorarTuring Magazine
- Las inundaciones en Texas impulsan un proyecto de ley para un sistema de alerta de emergencia por satéliteUnivision
- Microsoft Patch Tuesday, July 2026 Security Update ReviewQualys
- Microsoft July 2026 Security Updates — Record 570 vulnerabilities including two actively exploited zero-daysGMCSIRT
- 旨在应对中国和伊朗等国在美国境内的跨国镇压行动VOA Chinese
- 美跨黨派議員提《停止跨境鎮壓法案》 首度立法將跨境鎮壓列刑事犯罪Taiwan News
- Microsoft corregge 570 falle nel Patch Tuesday, 622 nel conteggio estesoMatrice Digitale
- CISA warns that multiple vulnerabilities in SharePoint are being exploitedCybersecurity Dive
- Casa Blanca lanza Gold Eagle, un sistema pionero de ciberseguridad basado en IA para infraestructuras críticasMoncloa.com
- CISA urges immediate SharePoint hardening as exploits mountComputerworld
- Legisladores de Estados Unidos impulsan una ley para frenar las tácticas de represión de China e Irán en territorio nacionalInfobae
- Diputados pide informes sobre supuestos ciberataques de China al Gobierno de Santiago PeñaABC Color
- China nega acusação de ataque hacker contra o ParaguaiExame
- Tesoro de EE.UU. sanciona a First VPN por facilitar ataques ransomware contra hospitalesMoncloa
- CISA Urges SharePoint Hardening After New ExploitationsCybersecurity and Infrastructure Security Agency (CISA)
- CISA Warns of Active Exploitation of Three Microsoft SharePoint Server Vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164)Threadlinqs Intelligence
- CISA Says Three SharePoint Flaws Are Being Chained Right Now. We Wrote the Hunt for One of Them in May.DugganUSA
- Critical Patches Issued for Microsoft Products, July 14, 2026Center for Internet Security
- Microsoft Patch Tuesday | Threat Intel Reports – July 2026Smarttech247
- CVE-2026-56164: SharePoint Missing Authentication for Critical FunctionPenligent AI
- Governo dos EUA lançará grupo de coordenação de IA e cibersegurançaMitrade
- US AI Regulation July 2026: Federal Policy and State AI LawsVorplabs
- Federal AI Regulation Landscape: Where Things Stand in 2026Astraea Law
- Media Land : le DOJ inculpe les opérateurs du BPH russeAyine Djimi Consultants
- США обвинили в международных киберпреступлениях троих петербуржцев и две компании из РоссииFontanka
- Patch Tuesday - July 2026Kirin
- Multiples vulnérabilités dans Microsoft Windows (incluant mention de CVE-2026-56155)Vulnerability-Lookup
- Estados Unidos se sumó a la alarma internacional por el hackeo de routers: la NSA atribuye los ataques a RusiaInfobae
- Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting (AA26-194A)CISA
- Rusia usa routers inseguros para atacar infraestructuras críticasMenteHackers
- UK and Allies Warn on Russian Targeting of Network DevicesSt James Briefing Room
- NSA-Advisory AA26-194A: FSB greift Router via SNMP anlapalutschi.de
- Actividad Maliciosa Activa en GlobalProtect y Nuevos CVEs en Infraestructura Perimetral de Palo AltoDevel Group
- Karen Vardanyan se declara culpable de ataques ransomware Ryuk contra hospitales en EE.UU.Moncloa.com
- AI in the Crosshairs: New Guidance From FINRA and TreasuryTaft Law
- Vulnerability Database — EPSS, CISA KEV & exploit statuso3.security
- Paraguay atribuye ciberataques a China y abre una nueva disputa con PekínNotiPress
- Estados Unidos y Paraguay detectaron infiltraciones cibernéticas de actores vinculados a China en sistemas estatales paraguayosInfobae
- Resumen vulnerabilidades críticas – 27 elementos (09 jul 2026 Europe/Madrid)Iurlek Blog
- El Departamento de Seguridad Nacional de EE. UU. sufre un ciberataque: datos confidenciales en riesgoZamin.uz
- Gobierno de EE. UU. investiga nuevo hackeo contra plataforma HSIN y alerta por riesgo a la seguridad nacionalDiarioBitcoin
- Alertan explotación activa de falla crítica en Microsoft SharePoint (CVE-2026-45659)Nivel 4
- CVE-2026-45659: SharePoint en KEV y ransomware WarlockHard2Bit
- Cómo un país europeo consiguió derrotar un ciberataque contra sus hospitales gracias al lápiz y al papelBBC Mundo
- LATAM Malware Variants - 2023 Technical UpdatesCrowdStrike
- US healthcare Archives (cobertura del ataque a Change Healthcare)Security Boulevard
- 2026 Data Breaches: Cybersecurity Incidents ExplainedPKWARE
- Data Breaches Announced by Four Hospitals and Surgery CentersUtopiaTS / DataBreaches.net
- Cómo un país europeo consiguió derrotar un ciberataque contra sus hospitales gracias al lápiz y al papelYahoo Noticias
- AHA Statement to Senate HELP Committee on CybersecurityASHRM / American Hospital Association
- Recent posts (incluye entrada [DISCLOSED] Prince George County)RansomLook.io
- US Department of Homeland Security says it is probing a cyber breach in information-sharing networkReuters
- Another massive data breach exposed millions of driver's license numbersTechCrunch
- 13th July – Threat Intelligence ReportCheck Point Research
- Weekly Cyber Threats & Breaches Report: 13 Jul-19 Jul 2026FireCompass
- Hackers claim attack on Coca-Cola's Fairlife, threaten to leak dataThe Atlanta Journal-Constitution
- Cl0p Mass Extortion, Anubis Hits Fairlife, AI Hacks ...DuoCircle
- 'Coordinated cyberattack' targets over 30 water systems in MinnesotaUSA Today
- Coordinated Cyberattack Disrupts Operational Technology in 30+ Minnesota Water Utilities: Incident Analysis and ResponseRescana
- U.S. Sees Iran as Likely Behind Cyberattack on Minnesota Water SystemsThe New York Times
- Iran-linked CyberAv3ngers suspected in attacks on Minnesota water systemsThe Register
- Iranian hackers suspected in cyber attack on US water systemsABC News (Australia)
- US government says Iran-linked hackers are disrupting American water and energy providersTechCrunch
- US cyber defense agency warns hackers are increasingly targeting water systemsReuters
- US officials warn of cyber attacks: Hackers are targeting essential servicesThe Times of India
- White House Launches Gold Eagle Initiative for Unprecedented Cybersecurity Vulnerability CoordinationThe White House
- White House launches cybersecurity clearinghouse to patch software flaws discovered by AIPolitico
- House advances fiscal 2027 NDAA with provisions to extend major info-sharing law, require CMMC reportsInside Cybersecurity
- CISA Eyes September Date for Final Cyber Incident Reporting RuleHomeland Security Today
- CIRCIA, other big cyber rules expected to get finalized this fallFederal News Network
- 117 Cyber Rules, 37 Agencies: GAO Finds 70% of Federal Cyber Regulations DuplicativeGovConFeed
- Microsoft security advisory – July 2026 monthly rollupCanadian Centre for Cyber Security
- CISA Adds First AI Agent Platform to KEV, Sets Thursday Deadline for 4 CVEsTechTimes
- CISA Directs Federal Agencies to Patch Langflow Vulnerability Under BOD 26-04Govly
- CISA warns of three actively exploited vulnerabilities in popular web platformsSeCarma
- CISA adds four actively exploited vulnerabilities to known exploited vulnerabilities catalogueSeCarma
- CISA KEV Catalog Update July 14 2026: Four VulnerabilitiesQuasa
- CISA KEV: FortiSandbox and SharePoint Due 19 JulyHelpRansomware
- CISA Gives Feds 3 Days to Patch SharePoint, FortinetVerdice News
- CISA KEV — Live TableChange Risk Intel
- Healthcare ransomware attacks up 14%: 5 things to knowBecker's Hospital Review
- Minnesota Water Cyber Attack and CISA Advisory AA26-097A: What You Need to KnowTenable
- Urgent warning over water system cyberattacksNBC News
- Cyberattacks targeted Minnesota water systemsAssociated Press
- Feds issue warning to local water systems over increased cyberattacks following Minnesota incidentABC7 New York
- Coca-Cola's dairy company fairlife hit with a ransomware attackEngadget
- Fairlife Ransomware Attack Stops All US Milk Production: IT-OT Breach UnconfirmedTechTimes
- White House Launches Gold Eagle Initiative for Cybersecurity Vulnerability CoordinationMayer Brown
- Cybercrime Wire For Jul 28, 2026. Cyberattacks Strike ...Cybercrime Magazine (Cybercrime Wire)
- Hacked, leaked, and held for ransom: The worst breaches of 2026 so farTechCrunch
- Cyber Attack News - Risk Roundup - Top Stories for July 2026Xage Security
- Hackers Got Into the US Government's Sensitive Information-Sharing NetworkThe Cipher
- Data Breach Roundup (July 3 - 9, 2026)PrivacyGuides
- Top 10 Cybersecurity News (July 07, 2026)Innovate Cybersecurity
- 20th July – Threat Intelligence ReportCheck Point Research
- SWK Cybersecurity News Recap July 2026SWK Technologies
- With 3 states changing their privacy laws, more than half the US population is now coveredKEYT
- Weekly Compliance Brief: July 6 – 10, 2026Clym
- CISA plans to finalize incident reporting rulemaking in SeptemberInside Cybersecurity
- CISA expects to finalize key cyber reporting rule by SeptemberNextgov
- US to Finalize Mandatory Cyber Incident Reporting Rule (CIRCIA) by SeptemberNetSecOps
- The Federal Cyber Rulemaking Stack: Five Rules Landing July–September 2026 — GovConCyberGovConCyber
- Actualizaciones de seguridad de Microsoft – Julio 2026Centro Nacional de Respuesta a Incidentes de Seguridad Informática (Uruguay)
- “Patch Tuesday” Histórico de Microsoft (Julio 2026) Corrige 570 Fallos y 3 Zero DaysDevel Group
- CVE-2026-16232 – Critical Check Point SmartConsole Authentication Bypass Exploited in the WildRapid7
- CISA Adds Two Known Exploited Vulnerabilities to Catalogknutmichael.com
- RingCentral Listed by ShinyHuntersGalaxy Warden
- ShinyHunters Ransomware Claims Target RingCentralCyPro
- RingCentral, Inc. — SHINYHUNTERS Ransomware Attack | Breach HouseBreach House
- Victim: RingCentral, Inc. – shinyhuntersransomware.live
- RingCentralBreachSense
- ShinyHunters Adds EY, RingCentral, and Brinks Home to data leak siteBreachNews
- Ernst Receives Warning, RingCentral Named Leak, GitHub ...DMARC Report
- ShinyHunters Breach RingCentral, Inc. in Latest Ransomware AttackDexpose
- Victim: greenecountyga.gov – incransomransomware.live
- greenecountyga.gov Data Breach (2026) — What Leaked & Am I Affected?Recent Breaches
- greenecountyga.gov data breach — Incransom ransomware leak (2026)Darkfield
- Industry's message on CIRCIA: Please ask us fewer ...CyberScoop
- The CIRCIA town halls could be a watershed moment for critical infrastructureShieldworkz
