---
title: "Accenture Sourcecode Breached, JADEPUFFER AI Ransomware, GodDamn Disables Windows  | DMARC Report"
description: "Stay updated with this week"
image: "https://dmarcreport.com/og/blog/accenture-sourcecode-breached-jadepuffer-ai-ransomware-goddamn-disables-windows.png"
canonical: "https://dmarcreport.com/blog/accenture-sourcecode-breached-jadepuffer-ai-ransomware-goddamn-disables-windows/"
---

Quick Answer

This week's cybersecurity news covers the Accenture source code breach, the first AI-driven ransomware attack, Windows security threats, supply chain compromises, critical zero-days, ransomware campaigns, and major global law enforcement actions against cybercrime.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Faccenture-sourcecode-breached-jadepuffer-ai-ransomware-goddamn-disables-windows%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Accenture%20Sourcecode%20Breached%2C%20JADEPUFFER%20AI%20Ransomware%2C%20GodDamn%20Disables%20Windows%20&url=undefined%2Fblog%2Faccenture-sourcecode-breached-jadepuffer-ai-ransomware-goddamn-disables-windows%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Faccenture-sourcecode-breached-jadepuffer-ai-ransomware-goddamn-disables-windows%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Faccenture-sourcecode-breached-jadepuffer-ai-ransomware-goddamn-disables-windows%2F&title=Accenture%20Sourcecode%20Breached%2C%20JADEPUFFER%20AI%20Ransomware%2C%20GodDamn%20Disables%20Windows%20 "Share on Reddit") [ ](mailto:?subject=Accenture%20Sourcecode%20Breached%2C%20JADEPUFFER%20AI%20Ransomware%2C%20GodDamn%20Disables%20Windows%20&body=Check out this article: undefined%2Fblog%2Faccenture-sourcecode-breached-jadepuffer-ai-ransomware-goddamn-disables-windows%2F "Share via Email") 

![cybersecurity news](https://media.mailhop.org/dmarcreport/dmarc-check-9711-1784029121308.jpg) 

## Accenture confirms breach after hacker sells 35GB of stolen source code

A [threat actor](https://www.infosecurity-magazine.com/news/iranbacked-hackers-cni-ot-assets/) known as “888” posted on a cybercrime forum claiming to have stolen just over [35GB](https://www.helpnetsecurity.com/2026/07/08/accenture-data-breach-2026/) of source code from Accenture in July 2026, including [RSA keys](https://www.namecheap.com/support/knowledgebase/article.aspx/798/69/what-is-an-rsa-key-used-for/), [SSH keys](https://www.sectigo.com/blog/what-is-an-ssh-key), Azure personal access tokens, and **Azure Storage access keys**. Accenture confirmed an incident occurred but hasn’t verified the scope.

## JADEPUFFER: the first fully “agentic” AI-driven ransomware attack

Sysdig researchers documented what they call the first end-to-end ransomware operation run entirely by an [AI agent](https://diesec.com/2026/07/top-5-cybersecurity-news-stories-july-10-2026/), classifying the operator as an “Agentic Threat Actor.” **The standout detail:** when a [login attempt failed](https://www.fastmail.help/hc/en-us/articles/1500000277362-Failed-login-attempts) mid-attack, the agent diagnosed the failure, wrote a fix, and continued without human help, later producing plain-language reasoning comments across hundreds of payloads.

## GodDamn ransomware disables Windows security with a signed malicious driver

A new ransomware family uses a “[bring-your-own-vulnerable-driver](https://www.darkreading.com/cyberattacks-data-breaches/goddamn-ransomware-byovd-smite-companies)” technique — pairing a legitimate remote access tool with a Microsoft-signed malicious driver — to silently kill endpoint **security processes** and remove [API hooks](https://www.redfoxsec.com/blog/api-hooking-iat-inline-and-kernel-hooks-detection-exploitation-defense-guide) without triggering alarms before deploying [credential stealers](https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/from-stealers-to-systems-the-new-model-of-credential-theft) and ransomware.![Dmarc Analyzer 9004](https://media.mailhop.org/dmarcreport/dmarc-analyzer-9004-1784030907758.jpg)

## Microsoft Defender hit by another public zero-day: “RoguePlanet”

**Researcher Nightmare-Eclipse** disclosed [CVE-2026-50656](https://www.malwarebytes.com/blog/news/2026/07/microsoft-fixes-rogueplanet-zero-day-in-defender), a race-condition privilege escalation bug in Defender, continuing an ongoing dispute with Microsoft over disclosure timelines. Microsoft issued an emergency [out-of-band patch](https://help.tanium.com/bundle/DomainControllerPatch/page/KA/DomainControllerPatch/DomainControllerPatch.htm).

## July Patch Tuesday (July 14) brings a Kerberos RC4 deadline

Beyond the usual pile of CVEs, this month enforces Phase 2 of [Kerberos RC4 hardening](https://www.techtimes.com/articles/320150/20260711/july-patch-rogueplanet-tuesday-kills-windows-kerberos-rc4-rollback-service-accounts-face.htm) — after July 14, RC4 authentication is disabled by default, which could break legacy servers, **network appliances**, and older enterprise software still relying on it.

## jscrambler npm package compromised in fast-moving supply chain attack

A malicious version of the popular jscrambler **CLI client** was published July 11 with a hidden preinstall hook that drops platform-specific native binaries on Linux, [macOS](https://en.wikipedia.org/wiki/MacOS), and Windows before any application code runs. _Socket detected it within six minutes, and the campaign later expanded beyond the install hook._

From AI ransomware to supply chain attacks, strengthen [cybersecurity](https://dmarcreport.com/blog/how-to-educate-or-train-employees-on-cybersecurity/) with [DMARC](https://dmarcreport.com/), [DKIM](https://dmarcreport.com/blog/dkim-explained-how-dkim-works-and-why-is-dkim-important-for-organizations/), and [SPF](https://dmarcreport.com/what-is-spf/) to reduce email-based threats.

## Dormant “ghost” GitHub accounts used to quietly map corporate networks

**Datadog Security Labs** flagged multiple overlapping campaigns using aged or compromised [GitHub accounts](https://www.technadu.com/datadog-github-api-enumeration-campaigns-analysis-report/630739/) and _OAuth tokens to systematically enumerate corporate organizations and repositories — reconnaissance that typically precedes a targeted intrusion_.![Dmarc Report 8996](https://media.mailhop.org/dmarcreport/dmarc-report-8996-1784029648043.jpg)

## Six new U-Boot bootloader flaws could let attackers run code at boot

**Firmware security** firm Binarly found vulnerabilities affecting routers, smart cameras, and [data-center server management](https://www.vertiv.com/en-us/about/news-and-events/articles/educational-articles/what-is-data-center-management/) chips; two of the six could let an attacker with a [malicious boot image](https://thehackernews.com/2026/07/six-new-u-boot-flaws-could-let.html) execute arbitrary code before the OS even loads.

## Two major ransomware groups reportedly team up on an “unprecedented” campaign

_Cyber experts issued an alert warning that two established ransomware operations are now collaborating, a shift researchers say increases the scale and speed of attacks compared to gangs working alone._

## Former ransomware negotiator sentenced to nearly 6 years for aiding BlackCat

A 41-year-old **ex-negotiator** was sentenced to 70 months for conspiring with [BlackCat (ALPHV)](https://www.bleepingcomputer.com/news/security/us-ransomware-negotiator-gets-4-years-in-prison-for-blackcat-attacks/) operators and helping target additional ransomware victims.

## Dutch police link local hackers to February’s Odido telecom breach

The [Dutch National Police](https://www.reuters.com/business/media-telecom/hacking-group-begins-leaking-customer-data-dutch-telecom-odido-hack-2026-02-26/) said it found strong indications that Dutch hackers were behind the breach at telecom provider Odido — a domestic-actor angle that’s relatively unusual for a **telecom-scale intrusion**.

## Progress Software urges ShareFile customers to shut down servers immediately

Progress is emailing [ShareFile Storage Zone Controller](https://cybernews.com/security/progress-sharefile-storage-zone-controllers-shutdown/) customers about a “**credible external security threat**” targeting [on-premises](https://www.ionos.com/digitalguide/server/know-how/what-is-on-premises/) file-sharing deployments, urging an immediate shutdown pending more guidance.

## Nextcloud misconfiguration exposes \~367,000 customer files (8GB)

A misconfigured managed [Nextcloud instance exposed](https://www.msn.com/en-us/news/technology/european-cloud-giant-nextcloud-exposes-staff-and-clients-in-major-data-breach/ar-AA27yBYG?uxmode=ruby) a chunk of enterprise customer data — this week’s “unexpected entry” in the ongoing **weekly breach roundups**.![Dmarc Record Generator 3160](https://media.mailhop.org/dmarcreport/dmarc-record-generator-3160-1784029928361.jpg)

## “Ill Bloom” crypto wallet flaw drains over $5 million

Security firm Coinspect disclosed a vulnerability in how certain **wallet software** generates recovery phrases using weak randomness, letting attackers reconstruct seed phrases and [drain funds](https://grafa.com/en/news/crypto/coinspect-warns-ill-bloom-puts-wallets-at-risk); one coordinated sweep has already been confirmed.

## CISA orders agencies to patch Check Point VPN zero-day exploited by Qilin affiliates

Check Point released fixes for a critical [Remote Access](https://www.ricoh-usa.com/en/glossary/remote-access) VPN/Mobile Access flaw actively exploited in [zero-day attacks](https://techcrunch.com/2026/06/09/cisa-gives-us-federal-agencies-three-days-to-fix-a-vpn-bug-under-attack-by-a-ransomware-gang/) tied to Qilin ransomware affiliates, prompting a **federal patch mandate**.

## FortiBleed credential theft campaign linked to INC and Lynx ransomware

Researchers connected the large-scale [Fortinet credential-harvesting](https://www.securityweek.com/fortibleed-campaign-linked-to-inc-lynx-ransomware-attacks/) campaign to two active ransomware operations, suggesting stolen credentials are being staged for **future network** intrusions rather than immediate use.

## Operation First Light 2026: global crackdown nets 5,800 arrests

An **INTERPOL-led operation** across 97 countries resulted in over [5,800 arrests](https://www.interpol.int/en/News-and-Events/News/2026/Over-5-800-arrests-USD-293-million-intercepted-in-global-fraud-bust) and nearly $300 million in seized illicit assets tied to fraud and scam operations.![Dmarc Report 8655](https://media.mailhop.org/dmarcreport/dmarc-report-8655-1784030447049.jpg)

## Armenian national pleads guilty to Ryuk ransomware attacks on US companies

A 34-year-old extradited last year pleaded guilty to conspiracy and computer fraud tied to [Ryuk attacks](https://cyberscoop.com/karen-vardanyan-armenian-ryuk-ransomware-guilty/) that brought in over **$15 million** in ransom, agreeing to pay **$1.1 million** in restitution.

## Mount Royal University (Calgary) confirms breach, attackers claim 10TB stolen

The university says [hackers stole data](https://www.cpomagazine.com/cyber-security/cyber-attack-at-mount-royal-university-disrupts-operations-cybercrime-gang-demands-1-9-million-ransom/) from file storage systems before deleting it from their own environment; the university is investigating the scope of the claimed **10TB** haul.

## npm v12 ships this month, finally blocking auto-run install scripts

In direct response to a wave of [North Korean-linked supply chain attacks](https://www.nknews.org/pro/north-korean-hackers-expand-supply-chain-attack-campaign-across-ecosystems/) (Axios, Mastra AI), npm’s **biggest security** overhaul in 16 years blocks postinstall scripts, Git dependencies, and remote sources by default — closing off the entry point used in several of this year’s worst incidents.

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

[ Brad Slavin ](/authors/brad-slavin/) 

General Manager

Founder and General Manager of DuoCircle. Product strategy and commercial lead for DMARC Report's 2,000+ customer base.

[LinkedIn Profile →](https://www.linkedin.com/in/bradslavin) 

## Take control of your DMARC reports

Turn raw XML into actionable dashboards. Start free - no credit card required.

[Start Free Trial](https://app.dmarcreport.com/signup?plan=free) [Check Your DMARC Record](/tools/dmarc-checker/) 

## Related Articles

[  Intermediate 4m  10 Reasons Why DKIM Fails  Apr 19, 2022 ](/blog/10-reasons-why-dkim-fails/)[  Intermediate 8m  Best DMARC Reporting Tools in 2026: Honest Comparison  Mar 25, 2026 ](/blog/best-dmarc-reporting-tools-2026/)[  Intermediate 12m  DMARC Passed. The Email Was Still an Attack. Inside the Blesta Ransom Incident  Jun 28, 2026 ](/blog/blesta-ransom-email-dmarc-passed-authenticated-abuse/)[  Intermediate  CISA Warns SharePoint, SimpleHelp Auth Bypass, Russian Spies Target  Jul 8, 2026 ](/blog/cisa-warns-sharepoint-simplehelp-auth-bypass-russian-spies-target/)

```json
{"@context":"https://schema.org","@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com","logo":{"@type":"ImageObject","url":"https://dmarcreport.com/images/dmarcreport-logo.png"},"description":"DMARC reporting and email authentication management. Monitor aggregate and forensic DMARC reports, analyze authentication results, and enforce DMARC policies across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"sameAs":["https://www.wikidata.org/wiki/Q138898167","https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.g2.com/products/dmarc-report/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc","https://www.trustradius.com/products/duocircle/reviews"],"aggregateRating":{"@type":"AggregateRating","ratingValue":"4.8","reviewCount":"471","bestRating":"5","worstRating":"1","url":"https://www.g2.com/products/dmarc-report/reviews"},"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://dmarcreport.com/support/"},"knowsAbout":["DMARC","DMARC Reporting","DMARC Aggregate Reports","DMARC Forensic Reports","Sender Policy Framework","DKIM","Email Authentication","Email Security","DNS Management","Email Deliverability"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DMARC Report","url":"https://dmarcreport.com","description":"DMARC reporting and email authentication management. Monitor aggregate and forensic DMARC reports, analyze authentication results, and enforce DMARC policies across all your domains.","publisher":{"@type":"Organization","name":"DMARC Report","url":"https://dmarcreport.com","logo":{"@type":"ImageObject","url":"https://dmarcreport.com/images/dmarcreport-logo.png"},"description":"DMARC reporting and email authentication management. Monitor aggregate and forensic DMARC reports, analyze authentication results, and enforce DMARC policies across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Accenture Sourcecode Breached, JADEPUFFER AI Ransomware, GodDamn Disables Windows ","description":"Stay updated with this week's top cybersecurity news, including the Accenture breach, AI ransomware, Windows threats, supply chain attacks, and zero-days.","url":"https://dmarcreport.com/blog/accenture-sourcecode-breached-jadepuffer-ai-ransomware-goddamn-disables-windows/","datePublished":"2026-07-14T00:00:00.000Z","dateModified":"2026-07-14T00:00:00.000Z","dateCreated":"2026-07-14T00:00:00.000Z","author":{"@type":"Person","@id":"https://dmarcreport.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://dmarcreport.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin is the founder and General Manager of DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. He founded DuoCircle in 2014 and has led the company's growth to 2,000+ customers across its email security product family. Brad's focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DMARC Report","url":"https://dmarcreport.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com","logo":{"@type":"ImageObject","url":"https://dmarcreport.com/images/dmarcreport-logo.png"},"description":"DMARC reporting and email authentication management. Monitor aggregate and forensic DMARC reports, analyze authentication results, and enforce DMARC policies across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"sameAs":["https://www.wikidata.org/wiki/Q138898167","https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.g2.com/products/dmarc-report/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc","https://www.trustradius.com/products/duocircle/reviews"],"aggregateRating":{"@type":"AggregateRating","ratingValue":"4.8","reviewCount":"471","bestRating":"5","worstRating":"1","url":"https://www.g2.com/products/dmarc-report/reviews"},"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://dmarcreport.com/support/"},"knowsAbout":["DMARC","DMARC Reporting","DMARC Aggregate Reports","DMARC Forensic Reports","Sender Policy Framework","DKIM","Email Authentication","Email Security","DNS Management","Email Deliverability"]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://dmarcreport.com/blog/accenture-sourcecode-breached-jadepuffer-ai-ransomware-goddamn-disables-windows/"},"articleSection":"intermediate","keywords":"","image":{"@type":"ImageObject","url":"https://media.mailhop.org/dmarcreport/dmarc-check-9711-1784029121308.jpg","caption":"cybersecurity news"},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://dmarcreport.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://dmarcreport.com/blog/"},{"@type":"ListItem","position":3,"name":"Intermediate","item":"https://dmarcreport.com/intermediate/"},{"@type":"ListItem","position":4,"name":"Accenture Sourcecode Breached, JADEPUFFER AI Ransomware, GodDamn Disables Windows ","item":"https://dmarcreport.com/blog/accenture-sourcecode-breached-jadepuffer-ai-ransomware-goddamn-disables-windows/"}]}
```
