← Carolina Clear Tech

Cyber Threat Brief

2026-07-19

Listen to this brief (6:22)

Download MP3
Show Notes

Show Notes - 2026-07-19

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Security Brief - 2026-07-19

Today: Russians are using fake Signal support accounts for phishing campaigns, Microsoft's SharePoint patches failed leaving on-premises instances under active zero-day attack, and Joomla sites face exploitation of perfect-10 CVSS extensions vulnerabilities.

Business & Infrastructure Threats

Russians Posing as Signal Support to Launch Phishing Attacks

Threat actors with Russian ties are impersonating Signal support staff to conduct phishing attacks against users of the encrypted messaging platform. The campaign targets Signal users through social engineering, likely attempting to harvest credentials or deploy malware by convincing victims they are communicating with legitimate support personnel. Signal does not offer customer support through direct messaging, making any such contact inherently suspicious.

Joomla Sites Under Active Exploitation via Extension Vulnerabilities (CVSS 10.0)

Attackers are exploiting critical vulnerabilities in Joomla extensions iCagenda and Balbooa Forms, both scoring perfect 10.0 CVSS ratings. These flaws affect Joomla installations, a CMS powering approximately one million websites globally. The vulnerabilities in third-party extensions allow remote code execution or complete site compromise. Active exploitation has been observed in the wild.

23andMe Settles for $18 Million After Failing to Protect Genetic Data

New York Attorney General and 42 other state attorneys general secured an $18 million settlement from genetic testing company 23andMe for inadequate protection of customer genetic data. The settlement addresses failures in data security practices that left sensitive genetic information exposed. California's Attorney General has filed a separate lawsuit under state privacy laws, indicating ongoing legal action. This represents enforcement under state privacy frameworks and highlights regulatory expectations for handling biometric and genetic data.

Ransomware Claims (Last 48h)

1 claim tracked from 1 group in the last 48 hours. These are unverified claims from ransomware leak sites, not confirmed breaches.

Group Victim Sector Country
Blackout bluebellgroup.com Unspecified Unspecified

Ransomware & Extortion

Blackout Ransomware Group Claims bluebellgroup.com

The Blackout ransomware group posted a claim against bluebellgroup.com on their leak site. Blackout emerged in February 2024 and operates a double-extortion model targeting healthcare, mining, telecommunications, and food and beverage sectors across France, Canada, Mexico, Croatia, and Spain. The group uses standard cryptographic techniques, appends custom extensions to encrypted files, and operates a Tor-based leak and negotiation platform. No additional details about the claimed victim or data exposure are available.

Windows / AD Security

Microsoft SharePoint On-Premises Under Active Zero-Day Attack

Microsoft's patches for on-premises SharePoint failed to address vulnerabilities that are now being actively exploited as zero-days. The attacks target SharePoint deployments that are not cloud-hosted. Organizations running on-premises SharePoint face immediate risk from attackers leveraging these unpatched flaws. Microsoft has acknowledged the failed patches but specific CVE identifiers and the nature of the vulnerabilities have not been disclosed.

General Security News

EQT Acquires Majority Stake in Acronis

Private equity firm EQT purchased a majority share in Swiss cybersecurity company Acronis at a valuation equivalent to over $3.5 billion for the entire firm. The exact portion sold was not disclosed. Acronis provides backup, disaster recovery, and cybersecurity solutions. The acquisition reflects continued private equity investment in the cybersecurity sector, particularly in unified data protection platforms.

DEF CON Franklin Project Expands to Harden Critical Infrastructure

DEF CON announced the Franklin project, expanding the conference's infrastructure security focus beyond the voting village. The project enlists hackers to identify vulnerabilities in critical infrastructure systems. DEF CON founder Jeff Moss stated that voting village reports have been successful enough to warrant expanding the security review model across the entire conference. The initiative aims to improve security of industrial control systems and other critical infrastructure beyond election systems.

Patch Priority

Trends & Context

Today's collection shows a pattern of exploitation targeting web platforms and content management systems, with Joomla extensions and SharePoint both under active attack. The Signal phishing campaign demonstrates threat actors adapting social engineering to encrypted communication platforms, while the 23andMe settlement signals increasing state-level enforcement of data protection requirements for biometric information.