Skip to main content
New AI-powered DMARC analysis + open REST API See how → →
Intermediate

Ernst Receives Warning, RingCentral Named Leak, GitHub Slashes Bounties

Brad Slavin
Brad Slavin General Manager

Quick Answer

This week's cybersecurity news covers the EY and RingCentral extortion threats, GitHub bug bounty cuts, critical vulnerabilities, AI-driven attacks, and supply-chain risks. Organizations should strengthen defenses with DMARC, SPF, DKIM, timely patching, and phishing awareness.

cybersecurity news

Here’s a quick roundup of the latest cybersecurity developments grabbing eyeballs this week — from a major beverage giant’s dairy subsidiary getting hit by ransomware, to extortion gangs racing toward deadlines at EY and RingCentral, to GitHub slashing its bug bounty payouts. It’s another week that shows how supply-chain trust, AI-accelerated vulnerability discovery, and old-fashioned extortion are all converging on the same threat landscape.

Ernst & Young hit with a “final warning” from ShinyHunters

The ShinyHunters extortion gang publicly claimed responsibility for the EY data breach, alleging it stole employee credentials and files through a supply-chain compromise of a third-party IT support platform, and set a leak deadline of July 31, 2026 if EY doesn’t negotiate. EY had disclosed the breach earlier this month, saying attackers accessed a third-party support-ticket system between March 28 and April 12 and downloaded documents containing client tax information.

RingCentral also named on the ShinyHunters leak site

ShinyHunters claims to have compromised an unspecified volume of RingCentral data, with a final extortion deadline of July 30, 2026 — a reminder that a single extortion crew can be running several corporate victims through the same playbook at once.

GitHub slashes public bug bounty payouts

Dmarc Check 9710 Starting July 27, GitHub is cutting public bug bounty payouts by at least half at every severity level, with critical findings dropping from the $20,000–$30,000+ range to a flat $10,000, while reserving the biggest rewards for an invite-only VIP tier.

GitHub and PyPI add supply-chain “cooldown” protections

Dependabot now gets a three-day cooldown window before opening pull requests, and PyPI rejects file uploads to releases older than 14 days — both aimed at slowing down malicious package updates before they spread automatically through dependency trees.

High-severity n8n workflow-automation flaw disclosed

A vulnerability tracked as GHSA-gv7g-jm28-cr3m affects n8n versions before 2.31.5 and between 2.32.0–2.32.1, rated High with a CVSS 4.0 score of 8.7. Exploitation requires only a valid account with permission to create or modify workflows, so admins are urged to patch rather than rely on interim access restrictions.

East Asia-linked threat actor targets Middle East governments

Zscaler ThreatLabz flagged fresh malicious activity from a threat actor with ties to East Asia targeting government entities in the Middle East, deploying three previously unreported malware families nicknamed TELESHIM, MIXEDKEY, and BINDCLOAK.

PoC exploit released for critical Active Directory CS flaw

A proof-of-concept exploit was released for a critical Active Directory Certificate Services domain-takeover flaw, tracked as CVE-2026-54121 — the kind of bug that can hand attackers full domain control once weaponized.

Google overhauls how it names threat actors

Google announced it’s changing its naming convention for cyber threat actors, part of a broader industry push toward more consistent threat-actor attribution across vendors. Dmarc Report 3107

Tech giants team up on AI for cyber defense

A coalition of tech companies announced an alliance aimed at putting open AI tools directly into the hands of cyber defenders, as AI increasingly shows up on both sides of the attacker/defender equation.

ChatGPT becomes a top phishing lure

ChatGPT has joined the ranks of the most impersonated brands in phishing attacks, underscoring how attackers are riding the popularity of AI tools to trick users into handing over credentials.

Ubuntu snap-confine flaw allows root access

Researchers disclosed a local privilege escalation vulnerability in snap-confine, tracked as CVE-2026-8933 with a CVSS score of 7.8, letting an unprivileged user gain root on default installs of Ubuntu Desktop 24.04, 25.10, and 26.04.

vBulletin patches a critical flaw, no active exploitation confirmed

What Is Dmarc 6411 vBulletin confirmed its Cloud sites are already patched against a newly disclosed flaw, tracked as CVE-2026-61511, and as of July 27 no source had confirmed real-world attacks — a good outcome, but worth watching given how quickly PoCs tend to circulate.

Russian state actors targeting Zimbra Collaboration Suite users

CISA warned that a group of Russian state-supported cyber actors, tracked as LAUNDRY BEAR, has been targeting and compromising Western government and commercial organizations using Zimbra Collaboration Suite since at least July 2025.

Steam forums abused for cryptominer “fix” scams

Steam discussion forums are being abused in ClickFix attacks that pose as fixes for game and computer problems but actually infect devices with cryptominers — a good reminder to never run “fix” scripts posted by strangers in gaming forums.

Massive malvertising campaign hits crypto and trading sites

A large-scale malvertising campaign is using fake Solana, Luno, and TradingView pages loaded with malicious JavaScript that assembles malware directly in the browser’s memory, making it harder for traditional antivirus tools to catch. Dmarc Analyzer 6170

AI is doubling the pace of vulnerability discovery

Software security flaws discovered in popular tech products are on pace to roughly double in 2026 compared to 2025, driven by increasingly capable AI systems, with the U.S. National Vulnerabilities Database recording over 45,000 flaws between January and late July — a count already approaching all of 2025’s total.

A European country’s land registry wiped by a hacker

A hacker wiped an entire European country’s land registry database, paralyzing its real-estate market — a stark example of how a single destructive intrusion can ripple across an entire national economy.

Strengthen your cybersecurity with DMARC, DKIM, and SPF to prevent phishing, protect your email domain, and reduce the risk of credential theft and email-based cyberattacks.

Brad Slavin
Brad Slavin

General Manager

Founder and General Manager of DuoCircle. Product strategy and commercial lead for DMARC Report's 2,000+ customer base.

LinkedIn Profile →

Take control of your DMARC reports

Turn raw XML into actionable dashboards. Start free - no credit card required.