Home  /  Episodes  /  Jul 13, 2026

Episode show notes

Jul 13's Top Cyber News NOW! - Ep 1172

Aired Jul 13, 2026 Daily Cyber Threat Brief Hosted by Dr. Gerald Auger

At a glance

Microsoft identified Giga Wiper, a Golang-based backdoor combining ransomware encryption with multiple destructive wiping features. Progress Software warned of a credible security threat affecting Share File storage zone controllers. Australian authorities flagged a widespread exploitation campaign targeting vulnerable CMS platforms. The NSA rebranded its elite hacking division back to Tailored Access Operations after a decade-long reorganization.

Stories covered

Is the Windows Giga Wiper backdoor actually a Swiss Army knife or an AI mess?

What happened: Microsoft's threat intelligence team identified a newly-named Golang-based backdoor called Giga Wiper that bundles ransomware-like encryption, multiple data-wiping features, and command-and-control capabilities first spotted in October 2025. The malware includes file encryption without decryption keys alongside wiper functionality that destroys data outright.

Why it matters: Destructive malware combining encryption and wiping capabilities is unusual and suggests either sophisticated threat actors building an all-in-one malware-as-a-service tool, or less experienced attackers adding features without clear operational rationale. Either way, the presence of persistence mechanisms and multiple payload options indicates real threat actor sophistication.

What to do: Ensure your detection rules catch both encryption-based and destructive wiper behaviors. Monitor for Golang-based malware in your environment. Maintain strong immutable backups and network segmentation to limit damage from either encryption or wiper attacks.

---

Why did NSA rebrand its elite hacking unit back to Tailored Access Operations?

What happened: The NSA reversed a 2016 organizational decision and re-established Tailored Access Operations (TAO) as a standalone unit after a decade of dispersing offensive operations across broader directorates. The move is part of a broader reorganization to better counter evolving threats from China, Russia, and others.

Why it matters: This is organizational restructuring at the federal level—it doesn't directly change day-to-day operational security posture, but it signals the agency's assessment that centralized elite offensive capability was more effective than distributed models.

What to do: Monitor for now. This is not actionable at the practitioner level, but it's worth understanding the structure of adversaries you may face.

---

What's the real threat behind Progress Software's Share File emergency shutdown order?

What happened: Progress Software issued an urgent alert Friday directing customers to manually shut down Windows servers running Share File storage zone controllers due to a credible external security threat. The company disabled affected accounts while investigating but has not disclosed the specific vulnerability or threat actor. Only on-premises storage zone controllers are affected, not cloud-only deployments.

Why it matters: This is the same vendor behind the Move It breach exploited heavily by Clop ransomware in 2024. The requirement for manual shutdown—not remote shutdown—suggests either a persistence mechanism or wake-on-LAN vulnerability. Internet-facing storage controllers are trivially discoverable via IPv4 scanning.

What to do: If you run Progress Share File storage zone controllers, immediately shut down affected servers physically or via direct access. If running cloud-only Share File, you are unaffected. Begin forensic investigation for unauthorized access or lateral movement. Do not wait; this is a credible active threat.

---

How are threat actors exploiting vulnerable CMS platforms globally?

What happened: The Australian Cyber Security Center (ACSC) warned of an active global exploitation campaign targeting content management systems (WordPress, Joomla, and others) and associated plugins. Attackers are deploying webshells on vulnerable sites; multiple Australian businesses have already been compromised.

Why it matters: CMS platforms and their plugins introduce significant unmanaged attack surface. Most organizations lack comprehensive software inventory beyond top-level systems and rarely remove outdated or unnecessary plugins. Webshell deployment is the first stage of persistent access.

What to do: Conduct a full software inventory of all CMS instances and plugins across your environment—including versions and last update dates. Prioritize patching of known CMS and plugin vulnerabilities. Consider disabling unused plugins. Implement file integrity monitoring and webshell detection rules. Review web server logs for suspicious access patterns.

---

Should you worry about steganographic prompt injection attacks on AI code reviewers?

What happened: Researchers at UMKC demonstrated a proof-of-concept exploit hiding malicious prompts inside PNG image metadata, which automated AI code reviewers treat as binary blobs and fail to inspect. The exploit successfully extracted repository secrets while evading detection, even with explicit "malicious prompt injection" labels embedded in the image.

Why it matters: This is a novel attack vector on AI-driven code review and security scanning tools. As organizations automate more security functions with AI agents, prompt injection attacks—the 2026 equivalent of SQL injection—will proliferate. The attack shows that input validation on non-traditional data formats (image metadata) is critical.

What to do: If using AI-based code review or repository scanning, treat image files and other binary assets as potential attack vectors. Implement metadata filtering and validation before passing to AI agents. Consider sandboxing AI-driven security tools. This is emerging research; monitor for real-world exploitation.

---

How did a ransomware negotiator become a double agent extorting his own clients?

What happened: Angelo John Martino III, a ransomware negotiator for Digital Mint, was sentenced to 70 months in prison for working as a Black Cat ransomware affiliate. He fed confidential victim information to co-conspirators, effectively negotiating ransom payments with himself while appearing to represent victims. He and his co-conspirators extorted $75.3 million from five U.S. victims across nonprofit, financial services, and hospitality sectors. Law enforcement seized $10 million in cash, two homes, and a luxury fishing boat.

Why it matters: This is an extreme breach of trust by an insider with legitimate access and victim confidence. It demonstrates that financial incentive can override professional ethics, even among experienced cybersecurity professionals. The attack was only stopped by law enforcement investigation and asset seizure.

What to do: Implement strict segregation of duties for anyone with access to sensitive victim or incident information. Monitor for unusual lifestyle changes or financial behavior among negotiators and incident responders. Conduct periodic background checks and financial audits for high-trust roles.

---

Why is the Dutch police releasing audio to catch a telecom social engineer?

What happened: Dutch police announced they had identified a Dutch-speaking man who impersonated an Odido IT employee and called customer service to reset credentials, enabling the theft of personal data from 6+ million customers in February 2026. Police indicated they may release a recording of the caller's voice to identify him.

Why it matters: Social engineering via phone remains effective against help desk operations. However, releasing audio for voice identification in 2026 is dubious—voice cloning and spoofing tools are commercially available and trivial to use. The attacker likely did not use their real voice.

What to do: Educate help desk staff on identity verification protocols that don't rely solely on phone verification. Implement callback verification to known employee extensions. Require secondary authentication (email, SMS to known number) before credential resets. Assume any voice-based verification can be spoofed.

---

Are big tech data centers really producing as much carbon as a third of France?

What happened: Microsoft, Amazon, and Google's collective carbon emissions increased nearly 20% in the past year, driven largely by data center construction and AI model training. The three companies now produce carbon equivalent to one-third of France's annual emissions (a country of 69 million people).

Why it matters: Data center energy consumption and water usage are becoming critical infrastructure concerns. Large companies are outsourcing their digital carbon footprint to cloud providers while obscuring their own environmental liability. This is not a cybersecurity issue but a supply chain and operational resilience concern for practitioners in regulated industries.

What to do: Monitor for now. If your organization is subject to environmental reporting or ESG requirements, audit your cloud provider's carbon footprint and water usage. Consider the long-term sustainability implications of continued AI workload expansion.

Key takeaways

  • Active threats require immediate action: Progress Share File storage zone controllers face credible exploitation; manual shutdown is required. CMS platforms are actively being targeted for webshell deployment globally.
  • Social engineering and insider threats remain the highest-impact attack vectors. Help desk credential resets and insider access abuse bypass all technical controls. Invest in verification protocols and access segregation.
  • Prompt injection attacks are the SQL injection of 2026. As AI agents proliferate in security tools, treat all input—including image metadata—as potentially malicious and validate before ingestion.
  • The NSA's organizational restructuring signals that centralized elite offensive capability is more effective than distributed models, though this has no immediate tactical impact for practitioners.
  • Crime does not pay (legally speaking): the Digital Mint negotiator's $75+ million in ill-gotten gains was seized, and he was convicted. Lifestyle creep and luxury asset purchases are how insiders get caught.

Topics covered

ransomware, malware, giga wiper, prompt injection, steganography, progress software, share file, cms vulnerabilities, wordpress, joomla, social engineering, help desk security, insider threat, nsa tailored access operations, data centers, carbon emissions, zero trust, webshell deployment, ai security risks

Show notes generated from the live transcript using AI on Mon, 13 Jul 2026 16:57:04 GMT. Errors? Open the YouTube replay for the source of truth.

Want the live experience? The Daily Cyber Threat Brief airs live every weekday at 5am PT / 8am ET on YouTube. 400+ practitioners join the chat in real time.