Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

13th July – Threat Intelligence Report

0
High
Published: 07/13/2026 (07/13/2026, 13:06:08 UTC)
Source: Check Point Research

Description

For the latest discoveries in cyber research for the week of 13th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES U.S. auto insurer AssuranceAmerica has disclosed a data breach affecting approximately 7 million people. Attackers targeted an employee and used compromised credentials to access company systems, stealing names, contact information, driver’s license numbers, insurance policy and account data, vehicle information, and claims details. Latvia’s state-owned forestry company Latvijas Valsts Meži has suffered a ransomware attack that disrupted mapping, hunting, contractor, and customer systems. Attackers exploited a system that had remained unpatched for two years and leaked approximately 44GB of internal documents, credentials, cryptographic keys, source code, and email correspondence. Injective Labs, a developer of blockchain and cryptocurrency software, has experienced a supply chain compromise after attackers accessed its SDK project and published malicious npm packages. The affected releases exfiltrated cryptocurrency wallet private keys and seed phrases when developers used legitimate key-generation functions embedded in the compromised software. Moody Bible Institute, a U.S. faith-based educational institution, has disclosed a data breach affecting more than 2.3 million donors, students, alumni, and supporters. The ShinyHunters extortion group published allegedly stolen information, including names, dates of birth, residential addresses, email addresses, and phone numbers. AI THREATS Researchers profiled JadePuffer, an autonomous ransomware operation that used a large language model to conduct an intrusion without direct human control. The operation exploited CVE-2025-3248 in an exposed Langflow instance, accessed a production MySQL server, exfiltrated selected information, deleted the database, and issued an extortion demand. Researchers showed that malicious instructions hidden inside open-source project files could achieve remote code execution through Anthropic Claude Code and OpenAI Codex. When operating with automated permissions, the coding agents processed the instructions and executed attacker-controlled scripts, demonstrating a risk that may affect other autonomous development tools. Researchers disclosed Rogue Agent, a vulnerability in Google Dialogflow CX that allowed users with limited agent-editing permission to insert persistent malicious code. The injected code could capture and exfiltrate chatbot conversations. Google addressed the issue, and no known customer environments were compromised through the vulnerability. VULNERABILITIES AND PATCHES Multiple Tenda router models are affected by CVE-2026-11405, an undocumented authentication backdoor that provides administrative access through a hidden password. The flaw affects several FH1201, W15E, AC10, AC5, and AC6 firmware versions and allows attackers to bypass configured credentials and modify device and network settings. Linux maintainers have patched CVE-2026-53359, a critical vulnerability in the Kernel-based Virtual Machine hypervisor. A malicious guest virtual machine could corrupt host kernel memory and potentially escape into the host environment. The flaw affects Intel and AMD x86 systems and is particularly relevant to shared cloud infrastructure. U-Boot has addressed six vulnerabilities affecting signature verification of Flattened Image Tree files used during secure boot. Two flaws could enable arbitrary code execution while a device loads a supposedly verified image, and four could cause crashes. The affected bootloader is widely used in routers, cameras, and embedded controllers. Opera has addressed a critical vulnerability in the Opera GX browser that allowed malicious websites to install browser modifications without user confirmation. An attacker-controlled modification could inject styles across open tabs, leak information such as Gmail addresses, and crash the browser. Opera corrected the issue. TH…

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/07/2026, 05:41:44 UTC

Technical Analysis

The report covers multiple security incidents and vulnerabilities discovered in July 2026. Notable breaches include AssuranceAmerica's data breach affecting approximately 7 million people via compromised employee credentials, and Moody Bible Institute's breach exposing over 2.3 million individuals' personal data. Latvia's forestry company suffered a ransomware attack exploiting a system unpatched for two years, resulting in data leakage. Injective Labs experienced a supply chain compromise through malicious npm packages that exfiltrated cryptocurrency wallet keys. AI-driven threats include the JadePuffer ransomware autonomously exploiting CVE-2025-3248 in Langflow, and vulnerabilities in AI coding agents enabling remote code execution. Vulnerabilities patched include CVE-2026-11405, an undocumented authentication backdoor in Tenda routers; CVE-2026-53359, a critical Linux KVM hypervisor vulnerability allowing guest-to-host escape; multiple U-Boot bootloader flaws enabling code execution during secure boot; and a critical Opera GX browser flaw allowing silent browser modifications. Google Dialogflow CX vulnerability allowing persistent malicious code injection was fixed with no known exploitation. The report does not provide CVSS scores or detailed exploit code but highlights the importance of patching and supply chain security.

Potential Impact

The incidents collectively impacted millions of individuals through data breaches exposing personal and sensitive information such as names, contact details, driver’s license numbers, insurance data, and donor records. The ransomware attack on Latvia’s forestry company disrupted critical operational systems and led to leakage of internal documents and cryptographic keys. The supply chain compromise in Injective Labs risked theft of cryptocurrency wallet private keys, potentially leading to financial losses. Vulnerabilities in widely used infrastructure components like Linux KVM hypervisor and U-Boot bootloader pose risks of host compromise and arbitrary code execution, especially in cloud and embedded environments. The Opera GX browser flaw could lead to information leakage and browser instability. AI-related vulnerabilities demonstrate emerging risks from autonomous malware and malicious code injection in AI development tools. Overall, these threats affect confidentiality, integrity, and availability across diverse sectors.

Defensive Guidance

Several vulnerabilities mentioned have been officially patched: Linux maintainers have released fixes for CVE-2026-53359; U-Boot developers addressed multiple secure boot flaws; Opera fixed the critical browser vulnerability; and Google patched the Dialogflow CX issue. Users and administrators should apply these official updates promptly. The Tenda router authentication backdoor affects multiple models and firmware versions; affected users should update firmware if available or consider device replacement. Organizations should review supply chain security practices to detect and prevent malicious package insertions. For ransomware and breach incidents, standard incident response and credential hygiene measures apply. No vendor advisory indicates that no action is required; therefore, patching and remediation are recommended where fixes exist. Patch status for some vulnerabilities is confirmed by the report; for others, check vendor advisories for current guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://research.checkpoint.com/2026/13th-july-threat-intelligence-report/","fetched":true,"fetchedAt":"2026-07-13T13:09:24.058Z","wordCount":919}
Classification
{"confidence":0.75,"severitySource":"heuristic","classifier":"rss-v2"}

Threat ID: 6a54e38468715ace4307ae56

Added to database: 07/13/2026, 13:09:24 UTC

Last enriched: 08/07/2026, 05:41:44 UTC

Last updated: 08/26/2026, 11:32:52 UTC

Views: 165

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses