Skip to main content
news

Iran Hits Infrastructure, EY Data Leak, CRPx0 Breaches Hyundai – Cybersecurity News [July 27, 2026]

Brad Slavin
Brad Slavin General Manager

Quick Answer

Stay informed on the latest cybersecurity threats, including ransomware, AI-powered attacks, critical vulnerabilities, and data breaches. Learn why implementing SPF, DKIM, DMARC, and email security best practices is essential to prevent phishing, spoofing, and unauthorized email activity.

cybersecurity update

Iranian hackers hit U.S. critical infrastructure PLCs

Iran-linked crews are actively exploiting internet-exposed Rockwell, Schneider Electric, and Siemens PLCs across U.S. critical infrastructure, putting water, energy, and manufacturing systems at risk of espionage or disruption.

ShinyHunters claims EY breach, threatens to leak tax data

The extortion group ShinyHunters says it stole client tax data from Big Four accounting firm EY and is threatening to leak it a high-profile hit on a major professional-services network.

CRPx0 ransomware claims Hyundai Turkey breach

Double-extortion group CRPx0 listed Hyundai’s Turkish operations on its leak site, claiming 1.5GB of exfiltrated assessment data, making Hyundai the latest automaker caught up in ransomware extortion.

Chinese-speaking hacker automates attacks with DeepSeek

A threat actor wired a DeepSeek AI agent into an autonomous attack pipeline, another sign that commercial AI models are being repurposed as always-on offensive tools.

Anti Phishing Software 1253

Fake Claude AI installation guides spread “MacSync” stealer

A new macOS campaign is weaponizing fake Claude AI installation guides to deploy a six-stage stealer and remote access trojan that steals passwords and crypto wallets proof that AI’s popularity is now a reliable phishing lure.

Google patches 1,072 Chrome flaws with AI assistance

Google used AI to identify and fix 1,072 Chrome security vulnerabilities, illustrating how machine-scale remediation is changing the patch pipeline for one of the world’s most-used browsers.

Google indexed private Claude AI shared chats

Critical JetBrains TeamCity flaw allows unauthenticated RCE

JetBrains disclosed a critical TeamCity On-Premises flaw allowing unauthenticated remote code execution, a serious risk since CI/CD servers are a direct pivot point to source code and build pipelines.

Phishing Protection 1252

VMware vCenter flaws let attackers bypass authentication

Newly disclosed vCenter flaws let remote attackers bypass authentication and execute code, effectively handing over control of an organization’s entire virtualized infrastructure.

Apple’s iOS 26.6 patches kernel-level exploit chain

Apple’s iOS 26.6 update fixes flaws that allowed kernel-level code execution and root access on iPhones a must-install update for anyone carrying sensitive data on their phone.

BlueNoroff’s fake meeting kit hijacks webcams and drains crypto

North Korea’s BlueNoroff group is using a fake meeting kit that hijacks webcams, disables Windows Defender, and steals cryptocurrency credentials, wrapped inside what looks like an ordinary video-call invite.

Bank of Baroda confirms breach via compromised employee email

The Indian bank confirmed a data breach stemming from a single compromised employee email account a reminder of how much damage one hijacked mailbox can cause at a major financial institution.

Analog Devices confirms cyberattack and data exfiltration

Semiconductor giant Analog Devices confirmed a cyberattack in which hackers exfiltrated files from company systems, adding another critical chip supplier to the growing list of victims.

Spf Record 4673

700,000 Vatican prayer app accounts left exposed

A security flaw meant anyone with a browser could access roughly 700,000 Vatican prayer-app user accounts, a stark example of a single access-control gap exposing an entire user base.

CISA urges water utilities to pull exposed PLCs offline

Amid active targeting of industrial control systems, CISA is urging water utilities to remove publicly exposed programmable logic controllers from the internet.

Russian hackers target Signal backup recovery keys

State-linked Russian hackers are going after Signal’s backup recovery keys to hijack user accounts, showing that even end-to-end encrypted apps are only as secure as their account-recovery process.

As cyber threats continue to evolve, organizations should strengthen their defenses by implementing SPF, DKIM, DMARC, and email security best practices to prevent phishing, spoofing, and unauthorized email activity.

Brad Slavin
Brad Slavin

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.