Accenture Sourcecode Breached, JADEPUFFER AI Ransomware, GodDamn Disables Windows
Quick Answer
This week's cybersecurity news covers the Accenture source code breach, the first AI-driven ransomware attack, Windows security threats, supply chain compromises, critical zero-days, ransomware campaigns, and major global law enforcement actions against cybercrime.
Accenture confirms breach after hacker sells 35GB of stolen source code
A threat actor known as “888” posted on a cybercrime forum claiming to have stolen just over 35GB of source code from Accenture in July 2026, including RSA keys, SSH keys, Azure personal access tokens, and Azure Storage access keys. Accenture confirmed an incident occurred but hasn’t verified the scope.
JADEPUFFER: the first fully “agentic” AI-driven ransomware attack
Sysdig researchers documented what they call the first end-to-end ransomware operation run entirely by an AI agent, classifying the operator as an “Agentic Threat Actor.” The standout detail: when a login attempt failed mid-attack, the agent diagnosed the failure, wrote a fix, and continued without human help, later producing plain-language reasoning comments across hundreds of payloads.
GodDamn ransomware disables Windows security with a signed malicious driver
A new ransomware family uses a “bring-your-own-vulnerable-driver” technique — pairing a legitimate remote access tool with a Microsoft-signed malicious driver — to silently kill endpoint security processes and remove API hooks without triggering alarms before deploying credential stealers and ransomware.

Microsoft Defender hit by another public zero-day: “RoguePlanet”
Researcher Nightmare-Eclipse disclosed CVE-2026-50656, a race-condition privilege escalation bug in Defender, continuing an ongoing dispute with Microsoft over disclosure timelines. Microsoft issued an emergency out-of-band patch.
July Patch Tuesday (July 14) brings a Kerberos RC4 deadline
Beyond the usual pile of CVEs, this month enforces Phase 2 of Kerberos RC4 hardening — after July 14, RC4 authentication is disabled by default, which could break legacy servers, network appliances, and older enterprise software still relying on it.
jscrambler npm package compromised in fast-moving supply chain attack
A malicious version of the popular jscrambler CLI client was published July 11 with a hidden preinstall hook that drops platform-specific native binaries on Linux, macOS, and Windows before any application code runs. Socket detected it within six minutes, and the campaign later expanded beyond the install hook.
From AI ransomware to supply chain attacks, strengthen cybersecurity with DMARC, DKIM, and SPF to reduce email-based threats.
Dormant “ghost” GitHub accounts used to quietly map corporate networks
Datadog Security Labs flagged multiple overlapping campaigns using aged or compromised GitHub accounts and OAuth tokens to systematically enumerate corporate organizations and repositories — reconnaissance that typically precedes a targeted intrusion.

Six new U-Boot bootloader flaws could let attackers run code at boot
Firmware security firm Binarly found vulnerabilities affecting routers, smart cameras, and data-center server management chips; two of the six could let an attacker with a malicious boot image execute arbitrary code before the OS even loads.
Two major ransomware groups reportedly team up on an “unprecedented” campaign
Cyber experts issued an alert warning that two established ransomware operations are now collaborating, a shift researchers say increases the scale and speed of attacks compared to gangs working alone.
Former ransomware negotiator sentenced to nearly 6 years for aiding BlackCat
A 41-year-old ex-negotiator was sentenced to 70 months for conspiring with BlackCat (ALPHV) operators and helping target additional ransomware victims.
Dutch police link local hackers to February’s Odido telecom breach
The Dutch National Police said it found strong indications that Dutch hackers were behind the breach at telecom provider Odido — a domestic-actor angle that’s relatively unusual for a telecom-scale intrusion.
Progress Software urges ShareFile customers to shut down servers immediately
Progress is emailing ShareFile Storage Zone Controller customers about a “credible external security threat” targeting on-premises file-sharing deployments, urging an immediate shutdown pending more guidance.
Nextcloud misconfiguration exposes ~367,000 customer files (8GB)
A misconfigured managed Nextcloud instance exposed a chunk of enterprise customer data — this week’s “unexpected entry” in the ongoing weekly breach roundups.

“Ill Bloom” crypto wallet flaw drains over $5 million
Security firm Coinspect disclosed a vulnerability in how certain wallet software generates recovery phrases using weak randomness, letting attackers reconstruct seed phrases and drain funds; one coordinated sweep has already been confirmed.
CISA orders agencies to patch Check Point VPN zero-day exploited by Qilin affiliates
Check Point released fixes for a critical Remote Access VPN/Mobile Access flaw actively exploited in zero-day attacks tied to Qilin ransomware affiliates, prompting a federal patch mandate.
FortiBleed credential theft campaign linked to INC and Lynx ransomware
Researchers connected the large-scale Fortinet credential-harvesting campaign to two active ransomware operations, suggesting stolen credentials are being staged for future network intrusions rather than immediate use.
Operation First Light 2026: global crackdown nets 5,800 arrests
An INTERPOL-led operation across 97 countries resulted in over 5,800 arrests and nearly $300 million in seized illicit assets tied to fraud and scam operations.

Armenian national pleads guilty to Ryuk ransomware attacks on US companies
A 34-year-old extradited last year pleaded guilty to conspiracy and computer fraud tied to Ryuk attacks that brought in over $15 million in ransom, agreeing to pay $1.1 million in restitution.
Mount Royal University (Calgary) confirms breach, attackers claim 10TB stolen
The university says hackers stole data from file storage systems before deleting it from their own environment; the university is investigating the scope of the claimed 10TB haul.
npm v12 ships this month, finally blocking auto-run install scripts
In direct response to a wave of North Korean-linked supply chain attacks (Axios, Mastra AI), npm’s biggest security overhaul in 16 years blocks postinstall scripts, Git dependencies, and remote sources by default — closing off the entry point used in several of this year’s worst incidents.
General Manager
Founder and General Manager of DuoCircle. Product strategy and commercial lead for DMARC Report's 2,000+ customer base.
LinkedIn Profile →Take control of your DMARC reports
Turn raw XML into actionable dashboards. Start free - no credit card required.