← All issues
cybersecurityCyberBubbleransomware

CISA Left Its Own Passwords Public for 6 Months — Plus Today's Biggest Threats

🌐  World Intel
Europe: EU and UK Sanction Russian Military Hackers

The European Union and the United Kingdom jointly sanctioned dozens of Russian individuals and organizations, accusing Russia of running a coordinated network of hacking groups responsible for cyberattacks across Europe. The groups targeted include units linked to the GRU, Russia's military intelligence service. This is one of the broadest joint cyber-sanction actions the two blocs have taken together.

↗ BleepingComputer
United States: Treasury Sanctions VPN and Malware Seller Supporting Ransomware

The U.S. Treasury Department sanctioned a VPN service called First VPN (1VPNS) and two individuals for helping ransomware gangs hide their tracks. The VPN, operated by a Ukrainian national, was already shut down in May 2026 following a joint US-European law enforcement operation. A Belarusian national was also sanctioned for selling cryptors — tools that wrap malware in a disguise so antivirus programs can't detect it.

↗ BleepingComputer
Japan: Largest Taxi Operator Hit by Cyberattack

Nihon Kotsu, Japan's biggest taxi company, confirmed it suffered a cyberattack that forced it to shut down parts of its systems. The company has not disclosed how the attackers got in or exactly what data may have been affected. The incident is a reminder that transportation and logistics companies are increasingly in hackers' crosshairs.

↗ BleepingComputer
⚔️  Active Attacks
Microsoft Entra ID: Attackers Are Silently Checking Your Stolen Passwords

Hackers have found a clever way to test lists of stolen usernames and passwords against Microsoft's cloud login system — Microsoft Entra ID — without triggering any alerts. Normally, a failed login attempt leaves a log entry that security teams can spot. This technique uses a quirk in OAuth, a common login protocol, to quietly check whether a password is correct without ever generating a successful sign-in event. Security firm Proofpoint says at least two separate criminal groups are already using this method in the wild to quietly confirm which stolen credentials actually work before using them to break in.

🛡 What to do: Turn on multi-factor authentication (MFA) on every Microsoft account you own or manage. A correct password alone won't be enough to get in if MFA is on.
CrashStealer Malware Disguises Itself as Apple's Crash Reporter on Macs

A new piece of infostealer malware called CrashStealer is targeting Mac users by pretending to be Apple's built-in crash-reporting tool — the pop-up you sometimes see after an app quits unexpectedly. Once installed, it steals saved passwords, Keychain data, and any crypto wallet files it can find. Because it mimics a legitimate Apple process, many users won't think twice about letting it run.

🛡 What to do: Never enter your Mac password into a crash-report dialog you didn't expect. Download software only from the Mac App Store or directly from developers you trust, and keep macOS updated.
🔓  New Vulnerabilities
CVE-2026 · SAP NetWeaver SAP NetWeaver & Commerce Cloud CRITICAL

SAP patched three critical flaws in its July 2026 security update, covering NetWeaver, Commerce Cloud, and AppRouter — software used by large businesses to run their operations. One of these flaws could let an attacker take over a vulnerable server without needing a password. SAP software is common inside banks, retailers, and government agencies, making these flaws high-value targets.

Status: Patches available. If your organization runs SAP, apply the July 2026 security update immediately.

CISA KEV · Joomla Extensions iCagenda & Balbooa Forms for Joomla HIGH · Actively Exploited

CISA confirmed that attackers are actively exploiting security holes in two popular extensions for the Joomla website-building platform: iCagenda (an events calendar) and Balbooa Forms (a form builder). Both flaws allow attackers to upload malicious files to the web server and run whatever code they like — a technique called remote code execution via arbitrary file upload. Thousands of websites run these extensions.

Status: Patches available. If you run a Joomla site with either extension, update immediately or remove the extension until you can.

ADVISORY AA26-194A · Home & Office Routers Poorly Configured Routers (All Brands) HIGH · State-Sponsored

CISA and cybersecurity agencies from eight other countries issued a joint warning that Russian state-sponsored hackers are targeting routers with weak or default configurations to break into critical infrastructure networks. The attackers don't need a specific software flaw — they're walking in through unlocked doors left open by poor setup. Once inside a router, they can monitor traffic or pivot deeper into connected networks.

Status: No patch needed — this is a configuration problem. Change your router's default password, disable remote management if you don't use it, and keep router firmware updated.

🛠  New Tech
Lidl Breach Highlights Growing "Supply Chain" Privacy Risk for Shoppers

German discount supermarket chain Lidl notified customers in Germany, Belgium, and the Netherlands that their personal data was stolen — not through a hack on Lidl itself, but through a breach at one of its service providers. This is the latest example of a supply chain attack, where hackers go after a weaker link in the chain to get at a bigger company's data. It underscores a hard truth for consumers: your data can be exposed even when the company you shop with hasn't done anything wrong. The practical takeaway is to use unique email addresses and passwords per service, so a breach at one company doesn't unravel everything else.

↗ BleepingComputer
💡  Deep Dive
America's Cyber Watchdog Left Its Own Keys Under the Doormat — For Six Months

Here's an uncomfortable story: CISA, the U.S. government agency responsible for telling everyone else how to stay secure online, had its own internal credentials — including AWS cloud access keys and dozens of plaintext passwords — sitting exposed in a public GitHub repository for nearly six months. A security researcher found them and tried to warn CISA. CISA didn't respond. Then another researcher tried. Still nothing. It eventually took a reporter at KrebsOnSecurity to get action.

The exposure started when a contractor uploaded 844 MB of sensitive CISA data to a public GitHub repository called "Private CISA" — a name that suggests it was meant to stay private but did not. The files included a document literally titled "importantAWStokens" containing admin credentials to three government cloud servers, and a spreadsheet of plaintext usernames and passwords for internal systems. Security firm GitGuardian's automated scanning tools spotted the leak and sent nine separate alert emails. Every single one went unanswered.

Once KrebsOnSecurity got involved, CISA moved — but still took more than 48 hours to revoke the exposed keys, which is a long time when a set of admin credentials to government cloud servers is publicly accessible. CISA has since published a postmortem acknowledging the failures: their internal reporting channels were unclear, teams didn't know whether an alert about CISA's own infrastructure should go through the same process as a report about a bug in a product. The irony is sharp. CISA regularly publishes guidance telling businesses to rotate credentials quickly and maintain clear incident-response procedures.

The lesson here isn't just for government agencies. Any organization that uses cloud services — which is nearly everyone — should have a tested plan for what happens when credentials leak. That means scanning your own code repositories for accidentally committed secrets, knowing exactly who to call when a leak is discovered, and being able to revoke and rotate access keys in minutes, not days. The person reporting a leak is not the enemy. Making it easy for them to reach you quickly is one of the cheapest security investments you can make.

🛡️

Stay sharp. It's free.

Join thousands of readers who get daily cybersecurity news in plain English.

Subscribe Free →