Security Digest

Zero-Day Pairs, Arctic Satellites, and Ten Nights Over Tehran

Issue 024 covers two SonicWall SMA 1000 zero-days (CVE-2026-15409 and CVE-2026-15410, both CVSS 10.0, exploited before vendor disclosure), a 2.25-million-downloads-per-week AsyncAPI npm supply chain compromise with IPFS-hosted C2, joint EU and UK sanctions naming the FSB 16th Center and GRU officer Yevgeny Bashev for a decade of European infrastructure attacks, ten consecutive nights of US airstrikes against Iran with US military fatalities reported (uncorroborated in tier-one Nordic press) and Houthi maritime escalation at Bab al-Mandeb, and Ukraine's 400-drone strike on Moscow alongside Russia's largest ballistic barrage on Kyiv.

Security Digest 024 — Audio

Listen to the audio version of this digest, voiced by Brian.

0:00 0:00

This digest was researched and drafted by an automated pipeline (fetch, summarise, draft) and voiced by a synthetic narrator. Every claim is sourced; single-source and contested items are flagged throughout. — FTRCRP

This Week in Brief

Issue 024 covers 13 July through 21 July 2026, picking up from where issue 023 closed on 13 July. Two threads define the window. On the infrastructure side, SonicWall disclosed a CVSS 10.0 vulnerability pair already exploited in the wild before the advisory published, and a GitHub Actions misconfiguration in the AsyncAPI project pushed malicious packages to a weekly download pool exceeding 2.25 million. On the geopolitical side, the US-Iran conflict passed ten consecutive nights of American airstrikes by 21 July, with US military fatalities reported (uncorroborated in tier-one Nordic press), a Houthi maritime embargo announced at Bab al-Mandeb, and US gasoline clearing $4 per gallon. The EU and UK simultaneously sanctioned the FSB’s 16th Center and GRU officer Yevgeny Bashev for a decade of attacks on European critical infrastructure, the most coordinated Russia cyber attribution action either bloc has produced.

The next major EU AI Act enforcement milestone, covering expanded high-risk AI system and GPAI obligations, falls on 2 August 2026, twelve days from publication.

Security

SonicWall SMA 1000 Zero-Days, CVE-2026-15409 and CVE-2026-15410

SonicWall’s SMA 6210, 7210, and 8200v appliances carry two CVSS 10.0 vulnerabilities: CVE-2026-15409, a server-side request forgery, and CVE-2026-15410, remote code injection. Both served as confirmed initial access vectors before Rapid7’s Managed Detection and Response team published its disclosure in the week of 14 July, with custom malware deployed on compromised targets post-exploitation (Rapid7; The Hacker News; BleepingComputer). Exploitation in the wild is confirmed.

Operational read: Isolate or shut down externally exposed SMA 1000 management interfaces immediately. Review firewall egress logs from mid-July on appliance IPs. Patch on vendor’s timeline with no deferral.

AsyncAPI npm Supply Chain Compromise

A compromised GitHub Actions workflow in the AsyncAPI project pushed five malicious package versions delivering payload at import time rather than at install, bypassing install-time scanning controls. The affected packages combined for more than 2.25 million weekly downloads. Command-and-control infrastructure was hosted on IPFS, a distributed censorship-resistant network, making C2 layer takedown resistant to conventional domain seizure (Microsoft Security Blog, 15 July; Wiz). Discovery was confirmed 14 July.

Operational read: Audit AsyncAPI dependency pins against the affected version list. Harden GitHub Actions workflows to least-privilege tokens and pinned SHA refs across all repositories. Add IPFS endpoint egress to network detection rules; this C2 pattern is repeatable and will recur.

Kudankulam Nuclear Plant Data Breach

World Leaks ransomware published 14.3 gigabytes from India’s Kudankulam Nuclear Power Plant in Tamil Nadu, comprising 858,000 files and 19,000 documents including engineering blueprints and operational materials. The breach originated at Reliance Infrastructure, a third-party contractor compromised on 29 May, with data transiting Yotta Data Services before dark web publication by 11 June (Reuters). Attribution points to the contractor access path, not Kudankulam’s own control systems, a distinction that matters for remediation scope but does not reduce the exposure.

Other Security Items

AssuranceAmerica disclosed 6.9 million driver’s licence numbers plus insurance data exposed in a breach covering 17 to 18 March 2026 (TechCrunch; PCMag). Coca-Cola subsidiary Fairlife halted all US dairy production lines after ransomware reached production systems through a suspected IT-to-OT boundary crossing, first disclosed 17 July (TechCrunch; ABC7 Chicago). Ecopetrol, Colombia’s state oil company, had data from 3,300 accounts stolen across 15 subsidiaries with a ransom demand received, the company describing the breach as contained (Reuters; CNA). xAI’s Grok Build coding agent silently uploaded complete Git repositories, including private keys, to xAI and Google Cloud Storage; researcher @cereblab disclosed the behaviour on 12 July, Elon Musk confirmed it, and the exfiltration code remained present in the post-disclosure open-source release (The Hacker News; CyberNews; TechTimes). Scattered Spider-linked Owen Flowers, 18, and Thalha Jubair, 20, each received five-and-a-half-year sentences for the 2024 Transport for London cyberattack, with remediation costs reaching £29 million (The Guardian, single-source). Microsoft’s July 2026 Patch Tuesday addressed over 722 vulnerabilities, three actively exploited in Active Directory Federation Services and SharePoint Server, with both SQL Server and SharePoint Server reaching end-of-support simultaneously. CertiK’s half-year report put crypto losses to hacks and exploits at $1.32 billion for H1 2026, down 47 percent year-on-year, though the comparison is flattered by early 2025’s outsized Bybit theft; infrastructure and key compromises, roughly 15 percent of incidents, drove about 76 percent of the losses (CertiK; Forbes; Immunefi counts $972 million on a narrower methodology).

Norway and the Nordics

Arctic Posture and Alliance Signals

German Foreign Minister Johann Wadephul visited Bodø on 11 July and called for enhanced NATO Arctic deterrence, citing Russian military repositioning in the northern theatre (Anadolu Agency, single-source). Satellite imagery circulating from the week of 14 July reportedly confirms Russia redeployed 72 S-300 and S-400 air defence battalions away from Arctic positions toward other operational fronts, a reported material degradation of Russian Arctic air defence coverage (single-source, not corroborated in SearXNG). Norway and Iceland agreed to join two EU military satellite programs: GovSatCom, providing government secure connectivity, and Iris², the EU broadband constellation, making them the first non-EU NATO nations in Iris² and extending EU space infrastructure into the Arctic (single-source). France and Iceland signed an Arctic and security cooperation roadmap in Reykjavik on 20 July covering defence, Arctic research, energy, and digital technologies (Anadolu Agency, single-source). Lithuania and Norway signed a Memorandum of Understanding on multi-purpose ship development at the NATO Ankara Summit (single-source).

Arctic Commercial Shipping and Russian LNG

Singapore-linked Sealegend Shipping announced the first regular commercial Arctic container service, eight departures between 12 August and 27 October 2026 connecting Ningbo-Zhoushan to Felixstowe, Rotterdam, Wilhelmshaven, and Gdynia via seven vessels ranging 1,528 to 4,890 TEU (TrasportoEuropa). The first sailing departs 15 August. The announcement marks the transition from experimental to routine Arctic commercial shipping and carries strategic implications for European port traffic and Arctic governance.

Russia’s Arctic LNG pivot faces a tanker crunch. Post-EU LNG ban, Russia cannot efficiently replace European-bound volumes on Asian routes, lacking conventional tankers under sanctions. One documented transit: the Vladimir Rusanov transferred cargo to the conventional tanker Geneva, routed via Cape Horn to China, a detour of over five weeks. By late 2025, roughly half of Russian LNG exports to Europe relied on ice-class tankers Russia cannot replace under current sanctions constraints (The Parliament Magazine, single-source).

Regulatory and Policy

EU and UK Sanction Russian Cyber Operators

On 13 July, the EU and UK jointly sanctioned Russian state actors responsible for a documented decade of attacks on European critical infrastructure: the FSB 16th Center (Cyber Security Unit), GRU officer Yevgeny Bashev, the company Impuls, nine named individuals, and four entities in total. Attribution covers sabotage against European energy grids, Baltic state government networks, and critical services (France24; UK Government; OCCRP; Politico EU).

23andMe, NATO Spending, and Defence Industry

The 2023 23andMe genetic data breach, covering 6.9 million users, produced three parallel settlement tracks: a $150 million total multistate settlement led by the Texas AG, a $46 million consumer class-action approved by courts, and $18 million recovered from 23andMe’s Chapter 11 bankruptcy claims by 42 state AGs. Genetic ancestry data was the primary exposure.

At the Ankara Summit, NATO members agreed to a new defence spending target of five percent of GDP by 2035, up from the prior two percent (Reuters; BBC). Ericsson received a role in the UK’s £8 billion defence communications framework RM6393 through 2034, covering Project Morpheus private 5G for military deployments, the first frontline private 5G commitment in UK defence (RCR Wireless, single-source). The White House announced “Gold Eagle” on 15 July, an initiative to apply AI to automated vulnerability patching across US federal systems; no implementation timeline was available in open-source reporting at time of writing (single-source).

Epstein

Swedish outlet Expressen reported on 15 July that Ebba P Karlsson filed a police report against Daniel Siad, identified in the article as a scout for Jeffrey Epstein, for sexual assault alleged to have occurred 36 years before the filing. Presumption of innocence applies to Daniel Siad. SearXNG returned no corroborating results for the article, the named complainant, or the named subject; the Expressen piece was not indexed at time of compilation (Expressen, single-source).

From US public reporting across the window: Kathryn Ruemmler, former White House counsel and Goldman Sachs partner, testified to House Oversight on her Epstein relationship; Warren Buffett described Bill Gates’ Epstein association as “distasteful” and redirected $6 billion away from the Gates Foundation; JD Vance stated publicly that Epstein had CIA and Mossad connections. One released Epstein document reportedly shows Trump’s name removed, a claim marked as contested across multiple US outlets. Leon Black testified under deposition that he was “duped” by an Epstein advisor, while Les Wexner, founder of L Brands, remains a central figure in the House Oversight inquiry. All US items sourced from US regional and digital outlets; no Nordic tier-one press corroborated any item in the window. Presumption of innocence applies throughout.

Conflicts

US-Iran: Ten Nights of Airstrikes

By 21 July the United States had conducted more than ten consecutive nights of airstrikes against Iran, targeting military command centres, air defence systems, coastal surveillance infrastructure, and maritime capabilities. The stated objective is reopening the Strait of Hormuz. Iranian President Pezeshkian declared full-scale war with the United States on 20 July. US military fatalities were reported as of 21 July, including personnel killed on 19 July in an attack on a US base in Jordan (France24; Reuters; ABC7 Chicago; Fox News). Casualty totals and identities were not corroborated in tier-one Nordic press; individual names are withheld pending confirmation, and Jordan/anti-IS (Operation Inherent Resolve) losses should not be conflated with Iran-strike casualties. The US issued a worldwide caution alert to citizens on 21 July. Yemen’s Houthis announced a maritime embargo on Saudi Arabia at Bab al-Mandeb on the same date. A US naval blockade of Iranian ports redirected seven commercial vessels and disabled one. Gasoline cleared $4 per gallon at US pumps. A tanker crew abandoned ship near Oman’s Limah coast after a projectile strike.

Ukraine: 400 Drones on Moscow, Russia’s Largest Kyiv Barrage

Ukraine launched over 400 drones toward Moscow on 20 and 21 July, targeting an oil depot in Podolsk, the Yuzhnye Vrata industrial park, and logistics facilities, described by multiple outlets as one of the largest Ukrainian drone strikes of the war (The Guardian; Reuters). Ukraine also struck two Russian shadow fleet tankers in the Black Sea and an oil depot in Stavropol. Russia responded with approximately 40 Iskander-M and Zircon ballistic missiles against Kyiv, killing six. A Russian strike on a Turkish cargo vessel near Odesa killed six crew including Syrian and Indian nationals. The Institute for the Study of War assessed Russia is firing more missiles in July 2026 than its estimated monthly production rate. Vladimir Putin publicly thanked North Korean soldiers for their contributions to Russian operations, confirming deployed North Korean forces (The Guardian). Germany and France announced a nuclear cooperation agreement during the window, with reporting noting discussions of potential French strategic warhead deployment in northern Europe (MSN; France24; multiple briefing dates; single-source, contested details). MBDA unveiled a new interceptor designed specifically to counter mass drone attacks, a direct industrial response to attrition tactics demonstrated in Ukraine and the Middle East (Reuters, 20 July).

By the Numbers

Figure Item
2 SonicWall CVSS 10.0 zero-days, both actively exploited before disclosure
2.25M Weekly npm downloads in affected AsyncAPI packages
14.3 GB Data published from Kudankulam nuclear plant breach
858,000 Files in the World Leaks Kudankulam dataset
6.9M Driver’s licences exposed in AssuranceAmerica breach
722+ Vulnerabilities in July 2026 Patch Tuesday
£29M TfL cyberattack remediation cost
$150M Total multistate 23andMe settlement
5% New NATO GDP defence spending target, to be reached by 2035
400+ Ukrainian drones in the 20 to 21 July Moscow strike
~40 Russian Iskander-M and Zircon missiles fired at Kyiv
12 Days to next EU AI Act enforcement milestone, 2 August 2026

What to Do This Week

  1. SonicWall SMA 1000: Patch CVE-2026-15409 and CVE-2026-15410 on vendor’s available timeline. Isolate management interfaces. Audit egress logs from mid-July forward on appliance IPs.
  2. AsyncAPI npm: Pin dependencies to known-good versions. Lock GitHub Actions to least-privilege tokens and SHA refs. Add IPFS egress detection to network monitoring.
  3. EU AI Act, 2 August: Confirm your high-risk AI system and GPAI compliance posture. Twelve days remain to the next enforcement milestone.
  4. July Patch Tuesday: Prioritise the three actively exploited CVEs in ADFS and SharePoint Server. Plan migration away from the now end-of-support SQL Server and SharePoint Server.
  5. Third-party contractor access: The Kudankulam breach traced to a third-party contractor path (Reliance Infrastructure), not the plant’s own systems. Scope your own supplier and third-party boundary exposure.
  6. Strait of Hormuz: If your organisation carries energy commodity exposure, Gulf logistics dependencies, or regional operations, the conflict timeline is active and escalating. Update contingency plans.

Researched against the local SearXNG instance and cross-checked against named outlets. Single-source and contested claims are marked throughout. Presumption of innocence applies throughout the Epstein coverage. Sources cited: The Hacker News, Rapid7, BleepingComputer, Microsoft Security Blog, Wiz, Reuters, CyberNews, TechTimes, TechCrunch, ABC7 Chicago, PCMag, The Guardian, ComputerWorld, France24, UK Government, OCCRP, Politico EU, Anadolu Agency, TrasportoEuropa, The Parliament Magazine, RCR Wireless, BBC, Expressen, Fox News, MSN, CNN, CBS News, The Washington Times, US Army public affairs, CertiK, Forbes, Immunefi.

Issue 024, 13 to 21 July 2026, published 21 July 2026.

AI disclosure

This article is generated by an automated pipeline that handles source collection, summarisation, and drafting end-to-end. Human review is light-touch and limited to publication gating. Editorial responsibility: Thomas A. Kleppestø.

Pipeline stages: fetch, summarise, draft.