---
title: "Ernst Receives Warning, RingCentral Named Leak, GitHub Slashes Bounties  | DMARC Report"
description: "Weekly cybersecurity roundup: EY and RingCentral extortion, GitHub bounty cuts, new CVEs, AI threats, and why DMARC, DKIM, and SPF matter."
image: "https://dmarcreport.com/og/blog/ernst-receives-warning-ringcentral-named-leak-github-slashes-bounties.png"
canonical: "https://dmarcreport.com/blog/ernst-receives-warning-ringcentral-named-leak-github-slashes-bounties/"
---

Quick Answer

This week's cybersecurity news covers the EY and RingCentral extortion threats, GitHub bug bounty cuts, critical vulnerabilities, AI-driven attacks, and supply-chain risks. Organizations should strengthen defenses with DMARC, SPF, DKIM, timely patching, and phishing awareness.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fernst-receives-warning-ringcentral-named-leak-github-slashes-bounties%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Ernst%20Receives%20Warning%2C%20RingCentral%20Named%20Leak%2C%20GitHub%20Slashes%20Bounties%20&url=undefined%2Fblog%2Fernst-receives-warning-ringcentral-named-leak-github-slashes-bounties%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fernst-receives-warning-ringcentral-named-leak-github-slashes-bounties%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fernst-receives-warning-ringcentral-named-leak-github-slashes-bounties%2F&title=Ernst%20Receives%20Warning%2C%20RingCentral%20Named%20Leak%2C%20GitHub%20Slashes%20Bounties%20 "Share on Reddit") [ ](mailto:?subject=Ernst%20Receives%20Warning%2C%20RingCentral%20Named%20Leak%2C%20GitHub%20Slashes%20Bounties%20&body=Check out this article: undefined%2Fblog%2Fernst-receives-warning-ringcentral-named-leak-github-slashes-bounties%2F "Share via Email") 

![cybersecurity news](https://media.mailhop.org/dmarcreport/dmarc-analyzer-1287-1785238959402.jpg) 

Here’s a quick roundup of the latest [cybersecurity](https://dmarcreport.com/) developments grabbing eyeballs this week — from a major beverage giant’s dairy subsidiary getting hit by ransomware, to extortion gangs racing toward deadlines at EY and RingCentral, to GitHub slashing its bug bounty payouts. It’s another week that shows how [supply-chain trust](https://www.exiger.com/perspectives/building-trust-in-supply-chains-more-than-a-cost-saving-measure/), AI-accelerated vulnerability discovery, and old-fashioned extortion are all converging on the same threat landscape.

## Ernst & Young hit with a “final warning” from ShinyHunters

The ShinyHunters extortion gang publicly claimed responsibility for the [EY data breach](https://cybersecuritynews.com/ey-data-breach-claim-shinyhunters/), alleging it [stole employee credentials](https://www.cybersecuritydive.com/news/craneware-health-care-data-breach/825643/) and files through a supply-chain compromise of a **third-party IT support platform**, and set a leak deadline of July 31, 2026 if EY doesn’t negotiate. _EY had disclosed the breach earlier this month, saying attackers accessed a third-party support-ticket system between March 28 and April 12 and downloaded documents containing client tax information._

## RingCentral also named on the ShinyHunters leak site

ShinyHunters claims to have compromised an unspecified volume of RingCentral data, with a final extortion deadline of **July 30, 2026** — a reminder that a single extortion crew can be running several corporate victims through the same playbook at once.

## GitHub slashes public bug bounty payouts

![Dmarc Check 9710](https://media.mailhop.org/dmarcreport/dmarc-check-9710-1785239785392.jpg)Starting July 27, [GitHub is cutting public bug bounty](https://techgig.com/news/cybersecurity/github-halves-public-bug-bounty-payouts-amid-ai-report-surge/132618073) payouts by at least half at every severity level, with critical findings dropping from the **$20,000–$30,000+** range to a flat $10,000, while reserving the biggest rewards for an invite-only VIP tier.

## GitHub and PyPI add supply-chain “cooldown” protections

Dependabot now gets a three-day cooldown window before opening pull requests, and [PyPI](https://www.securityweek.com/new-github-pypi-policies-boost-supply-chain-security/) rejects file uploads to releases older than **14 days** — both aimed at slowing down malicious package updates before they spread automatically through dependency trees.

## High-severity n8n workflow-automation flaw disclosed

A vulnerability tracked as [GHSA-gv7g-jm28-cr3m](https://thehackernews.com/2026/07/n8n-sandbox-escape-lets-workflow.html) affects n8n versions before 2.31.5 and between 2.32.0–2.32.1, rated High with a **CVSS 4.0 score of 8.7**. Exploitation requires only a valid account with permission to create or modify workflows, so admins are urged to patch rather than rely on interim access restrictions.

## East Asia-linked threat actor targets Middle East governments

_Zscaler ThreatLabz flagged fresh malicious activity from a threat actor with ties to East Asia targeting government entities in the Middle East, deploying three previously unreported malware families nicknamed TELESHIM, MIXEDKEY, and BINDCLOAK._

## PoC exploit released for critical Active Directory CS flaw

A [proof-of-concept exploit](https://www.helpnetsecurity.com/2026/07/27/certighost-cve-2026-54121-poc-exploit-released/) was released for a critical [Active Directory Certificate Services](https://www.vaadata.com/en/blog/understanding-active-directory-certificate-services-ad-cs/) domain-takeover flaw, tracked as **CVE-2026-54121** — the kind of bug that can hand attackers full domain control once weaponized.

## Google overhauls how it names threat actors

**Google announced** it’s changing its naming convention for [cyber threat actors](https://cyberpress.org/google-unveils-unified-naming-system/), part of a broader industry push toward more consistent threat-actor attribution across vendors.![Dmarc Report 3107](https://media.mailhop.org/dmarcreport/dmarc-report-3107-1785239809637.jpg)

## Tech giants team up on AI for cyber defense

_A coalition of tech companies announced an alliance aimed at putting open AI tools directly into the hands of cyber defenders, as AI increasingly shows up on both sides of the attacker/defender equation._

## ChatGPT becomes a top phishing lure

ChatGPT has joined the ranks of the most [impersonated brands in phishing attacks](https://www.infosecurity-magazine.com/news/chatgpt-most-impersonated-brands/), underscoring how attackers are riding the popularity of **AI tools** to trick users into handing over credentials.

## Ubuntu snap-confine flaw allows root access

Researchers disclosed a local privilege escalation vulnerability in snap-confine, tracked as [CVE-2026-8933](https://www.opensourceforu.com/2026/07/ubuntu-snap-confine-bug-opens-door-to-root-access/) with a CVSS score of 7.8, letting an unprivileged user gain root on default installs of **Ubuntu Desktop 24.04, 25.10**, and 26.04.

## vBulletin patches a critical flaw, no active exploitation confirmed

![What Is Dmarc 6411](https://media.mailhop.org/dmarcreport/what-is-dmarc-6411-1785239888529.jpg)vBulletin confirmed its Cloud sites are already patched against a newly disclosed flaw, tracked as [CVE-2026-61511](https://gbhackers.com/vbulletin-pre-auth-rce-flaw/amp/), and as of July 27 no source had confirmed real-world attacks — a good outcome, but worth watching given how quickly PoCs tend to circulate.

## Russian state actors targeting Zimbra Collaboration Suite users

[CISA](https://www.investopedia.com/terms/c/certified-information-systems-auditor.asp) warned that a group of [Russian state-supported cyber actors](https://www.asisonline.org/security-management-magazine/latest-news/today-in-security/2026/july/laundry-bear-cyber-threat/), tracked as LAUNDRY BEAR, has been targeting and compromising Western government and commercial organizations using **Zimbra Collaboration** Suite since at least July 2025.

## Steam forums abused for cryptominer “fix” scams

**Steam discussion forums** are being abused in [ClickFix attacks](https://www.bleepingcomputer.com/news/security/steam-forum-clickfix-attacks-infect-gamers-with-xmrig-cryptominers/) that pose as fixes for game and computer problems but actually infect devices with cryptominers — a good reminder to never run “fix” scripts posted by strangers in gaming forums.

## Massive malvertising campaign hits crypto and trading sites

_A large-scale malvertising campaign is using fake Solana, Luno, and TradingView pages loaded with malicious JavaScript that assembles malware directly in the browser’s memory, making it harder for traditional antivirus tools to catch._ ![Dmarc Analyzer 6170](https://media.mailhop.org/dmarcreport/dmarc-analyzer-6170-1785239076423.jpg)

## AI is doubling the pace of vulnerability discovery

[Software security flaws discovered](https://www.bloomberg.com/news/articles/2026-07-27/ai-hunts-for-cyber-flaws-finding-record-numbers-in-tech-sector) in popular tech products are on pace to roughly double in 2026 compared to 2025, driven by increasingly capable AI systems, with the **U.S. National Vulnerabilities Database** recording over 45,000 flaws between January and late July — a count already approaching all of 2025’s total.

## A European country’s land registry wiped by a hacker

A hacker wiped an entire [European country’s land registry database](https://www.rescana.com/post/romania-ancpi-land-registry-wiped-in-credential-based-cyberattack-incident-analysis-and-mitigation-recommendations), paralyzing its real-estate market — a stark example of how a single destructive intrusion can ripple across an entire national economy.

Strengthen your cybersecurity with [DMARC](https://dmarcreport.com/), [DKIM](https://dmarcreport.com/what-is-dkim/), and [SPF](https://dmarcreport.com/what-is-spf/) to prevent phishing, **protect your email domain**, and reduce the risk of credential theft and email-based cyberattacks.

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

[ Brad Slavin ](/authors/brad-slavin/) 

General Manager

Founder and General Manager of DuoCircle. Product strategy and commercial lead for DMARC Report's 2,000+ customer base.

[LinkedIn Profile →](https://www.linkedin.com/in/bradslavin) 

## Take control of your DMARC reports

Turn raw XML into actionable dashboards. Start free - no credit card required.

[Start Free Trial](https://app.dmarcreport.com/signup?plan=free) [Check Your DMARC Record](/tools/dmarc-checker/) 

Scan Your Domain Now

Instantly scan your domain for DKIM, SPF, and DMARC issues

Check My Domain 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fdmarcreport.com%2Fblog%2Fernst-receives-warning-ringcentral-named-leak-github-slashes-bounties%2F) [ ](https://twitter.com/intent/tweet?text=Ernst%20Receives%20Warning%2C%20RingCentral%20Named%20Leak%2C%20GitHub%20Slashes%20Bounties%20&url=https%3A%2F%2Fdmarcreport.com%2Fblog%2Fernst-receives-warning-ringcentral-named-leak-github-slashes-bounties%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fdmarcreport.com%2Fblog%2Fernst-receives-warning-ringcentral-named-leak-github-slashes-bounties%2F) Copy 

Related Articles

- [ ![10 Reasons Why DKIM Fails](https://media.mailhop.org/dmarcreport/images/2022/04/dmarc-alignment-6379.jpg)  10 Reasons Why DKIM Fails Intermediate ](/blog/10-reasons-why-dkim-fails/)
- [ ![cybersecurity news](https://media.mailhop.org/dmarcreport/dmarc-check-9711-1784029121308.jpg)  Accenture Sourcecode Breached, JADEPUFFER AI Ransomware, GodDamn Disables Windows Intermediate ](/blog/accenture-sourcecode-breached-jadepuffer-ai-ransomware-goddamn-disables-windows/)
- [ ![AppRiver SPF Record](https://media.mailhop.org/dmarcreport/dmarc-check-7224-1785846270575.jpg)  AppRiver SPF Record: How To Set It Up (Owned By Zix) Intermediate ](/blog/appriver-spf-record-setup-guide-for-zix-email-security-platform/)
- [ ![Best DMARC Reporting Tools in 2026: Honest Comparison](https://media.mailhop.org/dmarcreport/images/2022/04/dmarc-report-4236.jpg)  Best DMARC Reporting Tools in 2026: Honest Comparison Intermediate ](/blog/best-dmarc-reporting-tools-2026/)

## Related Articles

[  Intermediate 4m  10 Reasons Why DKIM Fails  Apr 19, 2022 ](/blog/10-reasons-why-dkim-fails/)[  Intermediate  Accenture Sourcecode Breached, JADEPUFFER AI Ransomware, GodDamn Disables Windows  Jul 14, 2026 ](/blog/accenture-sourcecode-breached-jadepuffer-ai-ransomware-goddamn-disables-windows/)[  Intermediate  AppRiver SPF Record: How To Set It Up (Owned By Zix)  Aug 4, 2026 ](/blog/appriver-spf-record-setup-guide-for-zix-email-security-platform/)[  Intermediate 8m  Best DMARC Reporting Tools in 2026: Honest Comparison  Mar 25, 2026 ](/blog/best-dmarc-reporting-tools-2026/)

```json
{"@context":"https://schema.org","@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com","logo":{"@type":"ImageObject","url":"https://dmarcreport.com/images/dmarcreport-logo.png"},"description":"DMARC reporting and email authentication management. Monitor aggregate and forensic DMARC reports, analyze authentication results, and enforce DMARC policies across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"sameAs":["https://www.wikidata.org/wiki/Q138898167","https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.g2.com/products/dmarc-report/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc","https://www.trustradius.com/products/duocircle/reviews"],"aggregateRating":{"@type":"AggregateRating","ratingValue":"4.8","reviewCount":"471","bestRating":"5","worstRating":"1","url":"https://www.g2.com/products/dmarc-report/reviews"},"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://dmarcreport.com/support/"},"knowsAbout":["DMARC","DMARC Reporting","DMARC Aggregate Reports","DMARC Forensic Reports","Sender Policy Framework","DKIM","Email Authentication","Email Security","DNS Management","Email Deliverability"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DMARC Report","url":"https://dmarcreport.com","description":"DMARC reporting and email authentication management. Monitor aggregate and forensic DMARC reports, analyze authentication results, and enforce DMARC policies across all your domains.","publisher":{"@type":"Organization","name":"DMARC Report","url":"https://dmarcreport.com","logo":{"@type":"ImageObject","url":"https://dmarcreport.com/images/dmarcreport-logo.png"},"description":"DMARC reporting and email authentication management. Monitor aggregate and forensic DMARC reports, analyze authentication results, and enforce DMARC policies across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Ernst Receives Warning, RingCentral Named Leak, GitHub Slashes Bounties ","description":"Weekly cybersecurity roundup: EY and RingCentral extortion, GitHub bounty cuts, new CVEs, AI threats, and why DMARC, DKIM, and SPF matter.","url":"https://dmarcreport.com/blog/ernst-receives-warning-ringcentral-named-leak-github-slashes-bounties/","datePublished":"2026-07-28T00:00:00.000Z","dateModified":"2026-07-28T00:00:00.000Z","dateCreated":"2026-07-28T00:00:00.000Z","author":{"@type":"Person","@id":"https://dmarcreport.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://dmarcreport.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin is the founder and General Manager of DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. He founded DuoCircle in 2014 and has led the company's growth to 2,000+ customers across its email security product family. Brad's focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DMARC Report","url":"https://dmarcreport.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com","logo":{"@type":"ImageObject","url":"https://dmarcreport.com/images/dmarcreport-logo.png"},"description":"DMARC reporting and email authentication management. Monitor aggregate and forensic DMARC reports, analyze authentication results, and enforce DMARC policies across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"sameAs":["https://www.wikidata.org/wiki/Q138898167","https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.g2.com/products/dmarc-report/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc","https://www.trustradius.com/products/duocircle/reviews"],"aggregateRating":{"@type":"AggregateRating","ratingValue":"4.8","reviewCount":"471","bestRating":"5","worstRating":"1","url":"https://www.g2.com/products/dmarc-report/reviews"},"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://dmarcreport.com/support/"},"knowsAbout":["DMARC","DMARC Reporting","DMARC Aggregate Reports","DMARC Forensic Reports","Sender Policy Framework","DKIM","Email Authentication","Email Security","DNS Management","Email Deliverability"]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://dmarcreport.com/blog/ernst-receives-warning-ringcentral-named-leak-github-slashes-bounties/"},"articleSection":"intermediate","keywords":"","image":{"@type":"ImageObject","url":"https://media.mailhop.org/dmarcreport/dmarc-analyzer-1287-1785238959402.jpg","caption":"cybersecurity news"},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://dmarcreport.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://dmarcreport.com/blog/"},{"@type":"ListItem","position":3,"name":"Intermediate","item":"https://dmarcreport.com/intermediate/"},{"@type":"ListItem","position":4,"name":"Ernst Receives Warning, RingCentral Named Leak, GitHub Slashes Bounties ","item":"https://dmarcreport.com/blog/ernst-receives-warning-ringcentral-named-leak-github-slashes-bounties/"}]}
```
