26 Belden Ave, Norwalk, CT, U.S.A info@ecsgtech.com Mon–Fri 9am–5pm | Sat 9am–2:30pm
ECSG
Get a Demo
Cybersecurity Bulletin · Live Threat Watch

Real attacks. Real lessons for your business.

ECSG tracks confirmed cyberattacks, breaches, and law-enforcement actions from around the world and translates each one into a practical takeaway for growing businesses. Updated regularly.

Issue July 2026 Next update: August 2026
ALERT7-Zip zero-day (CVE-2026-14266) under active exploitation — patch to 26.02 BREACHConduent data exposure now affects 62M+ individuals WATCHRansomware groups increasingly target trusted vendors and suppliers WINSpanish police dismantle €140M cyber fraud ring ALERT7-Zip zero-day (CVE-2026-14266) under active exploitation — patch to 26.02 BREACHConduent data exposure now affects 62M+ individuals WATCHRansomware groups increasingly target trusted vendors and suppliers WINSpanish police dismantle €140M cyber fraud ring
This Month's Cases

Confirmed incidents worth knowing about

A rundown of recent, verified cyberattacks and breaches — what happened, who it hit, and what it means if you run a small or mid-size business.

Data BreachOngoing — expanded July 2026

Conduent third-party breach tops 62 million people

A breach at business-services provider Conduent, which handles back-office work for healthcare and government clients, has grown far beyond its original scope. Regulators now put the affected population above 62 million individuals, with Social Security numbers, medical records, and insurance details among the exposed data. Notifications and lawsuits are still unfolding.

Know exactly what data your vendors and outsourcers hold on your behalf — a breach at them is a breach of your customers' trust too.
Data BreachDisclosed January 2026

Eurail passenger data offered for sale

European rail pass provider Eurail confirmed unauthorized access to its systems, with attackers claiming to have copied roughly 1.3TB of data from cloud storage and support systems. More than 300,000 travelers had names, travel companion details, and passport numbers exposed, raising the risk of follow-on phishing and identity fraud.

Attackers increasingly monetize stolen data directly through underground marketplaces — encryption and access controls on customer PII are non-negotiable.
Cloud SecurityMarch 2026

European Commission's Europa platform hit

The European Commission confirmed that the cloud infrastructure hosting its public Europa website was struck by a cyberattack, with some data taken from affected pages before the incident was contained. Internal Commission systems were reportedly unaffected — an example of a public-facing environment being properly segmented away from core operations.

Segment your public-facing web presence from internal systems — a well-isolated environment limits the blast radius when (not if) something gets hit.
Nation-StateDisclosed April 2026

FBI declares a "major cyber incident"

The FBI formally notified Congress after identifying that one of its surveillance systems had been compromised, in a breach reportedly linked to state-sponsored actors. The intrusion may have exposed phone numbers tied to individuals under federal surveillance — a reminder that even the most security-conscious organizations get breached.

If a federal agency can be breached, assume you will be targeted too. Layered defenses and fast detection matter more than any single "unbreakable" control.
HacktivismMarch 2026

Medtech manufacturer's systems wiped mid-shift

A cyberattack attributed to an Iran-aligned hacktivist group hit a major medical technology manufacturer, with employees reportedly watching office computers get wiped in real time. Operations were shut down while the security team investigated — a stark illustration of how destructive, rather than purely data-stealing, attacks can bring a business to a halt.

Backups are only useful if they're isolated from the network they protect. Test your recovery plan before you need it, not during the incident.
RansomwareJuly 2026

Manufacturer hit by the Qilin ransomware group

Chemco, a Calgary-based manufacturer serving the energy, logistics, and oil & gas sectors, was targeted by the Qilin ransomware group — one of several active operations that specialize in hitting mid-size manufacturers with limited in-house security teams.

Mid-size manufacturers and industrial firms are prime ransomware targets precisely because they're assumed to be under-defended. Don't be the easy target.
Zero-DayDisclosed July 15, 2026

Actively exploited 7-Zip zero-day

A heap-based buffer overflow in how 7-Zip processes certain archive data (CVE-2026-14266) is being exploited within days of public disclosure, according to telemetry showing exploitation attempts from multiple countries. A fix shipped in 7-Zip 26.02 on June 25 — before the flaw was even publicly detailed — underscoring the value of staying current on patches.

Patch on a schedule, not just when something makes headlines. The gap between "patch available" and "mass exploitation" keeps shrinking.
Law Enforcement Win2026

Spanish police dismantle €140M fraud ring

Spanish authorities disrupted a cyber fraud operation estimated to have moved roughly €140 million, a reminder that law enforcement cooperation across borders is increasingly effective against organized cybercrime — and that reporting incidents promptly helps investigators build these cases.

Report incidents to law enforcement even after the fact — your case may be the missing piece in a larger takedown.

Summarized from public reporting by TechCrunch, Dark Reading, The Hacker News, BrightDefense, ACI Learning, SharkStriker, and official government disclosures. Details evolve as investigations continue; always confirm specifics with primary sources before making decisions.

Threat Landscape

Patterns behind the headlines

Beyond any single incident, a few consistent patterns keep showing up across this year's breaches.

Vendors
Third-party and supply-chain compromises remain a top breach source
Identity
Credential theft and identity-based attacks now outpace many traditional exploits
Speed
Newly disclosed vulnerabilities are being weaponized within days, sometimes hours
People
Human error and gaps in security training remain root causes behind many incidents
Why This Matters For You

Translating global breaches into local action

Most SMBs won't make national headlines when something goes wrong — but the same root causes apply to a 20-person business as they do to a Fortune 500 company.

Vendor Risk

Map your third parties

Know which vendors touch your data, what they can access, and how quickly you'd hear about a breach on their end.

Patch Discipline

Close the window fast

Automated patch management shrinks the gap between "vulnerability disclosed" and "your systems are covered."

Recovery Ready

Practice the bad day

Isolated backups and a tested incident response plan turn a destructive attack into a bad afternoon instead of a bad year.

Want this bulletin, plus a check on your own exposure?

ECSG can run a free security assessment against your current environment — the same lens we use to read these headlines, pointed at your business.

Request an Assessment