Breach Watch Weekly: Vishing and the Management Plane (July 25-31, 2026)
CISO PLATFORM · BREACH INTELLIGENCE
BREACH WATCH WEEKLY
The week in breach intelligence for security leaders · July 25–31, 2026

The week in one line: Across five daily editions, the fastest way in was not a zero-day, it was a phone call. ShinyHunters talked its way into Brinks Home and put Ernst & Young on a leak clock, fake IT support on Microsoft Teams ended in Chaos ransomware, and the flaws that mattered sat in the management plane you use to run security, from Check Point to Cisco to Arista, several with no clean patch to apply.

BY THE NUMBERS

Roughly eighteen significant confirmed items across five editions (July 25, 26, 27, 29, and 30), including at least seven actively exploited vulnerabilities and five CISA KEV or federal-deadline entries.

Sector tally
  • Technology, software, and security infrastructure: 8 (Check Point, Cisco, Arista, GitLab, Fastjson, vBulletin, SonicWall, JetBrains)
  • Professional services and consumer security: 2 (Ernst & Young, Brinks Home)
  • Manufacturing and semiconductors: 2 (Analog Devices, PTC Windchill / FlexPLM)
  • Energy: 1 (Origin Energy)
  • Logistics: 1 (OnTrac)
  • AI infrastructure: 1 (Hugging Face)
Four themes that repeated
  1. Vishing replaced the exploit as the initial-access vector. A single Microsoft Entra voice-phishing call opened Brinks Home, and fake IT support on Teams opened the door to Chaos ransomware. The help desk and the identity-registration flow are now the front door.
  2. The management plane itself was the target. Check Point SmartConsole, Cisco Secure Firewall Management Center, and Arista VeloCloud Orchestrator all carried critical, actively watched flaws. The consoles you use to run security became the attack surface.
  3. This was a "no patch" week. Fastjson 1.x had no fixed release, a self-hosted GitLab remote code execution shipped with no CVE, and vBulletin dropped a public exploit. When there is no patch, discovery becomes the whole game.
  4. Named extortion crews worked the enterprise. ShinyHunters hit Brinks Home and EY, Clop escalated its PTC Windchill and FlexPLM campaign, and Analog Devices disclosed exfiltration to the SEC alongside a second, overlapping extortion claim.

The week's most significant incidents

1. ShinyHunters talked its way into Brinks Home and set a leak clock on EY

CRITICAL · SOCIAL ENGINEERING

The week's throughline was a single threat actor and a telephone. ShinyHunters said it breached Brinks Home on July 13 through a Microsoft Entra voice-phishing call, socially engineering an employee through an authentication step, then claimed more than 1.1 million rows of Salesforce customer data and roughly 3.8 million support chat logs. Brinks Home detected the intrusion on July 20 and confirmed an attacker threatened to release stolen information, though the record counts remain unverified claims. The same group set a July 31 deadline to leak Ernst & Young client tax data taken through a compromised third-party IT support platform. Two of the largest named exposures of the week required no exploit at all. The lesson: the help desk and the identity-registration flow are production systems, and they need callback verification, not good intentions. See the July 30 edition and the July 27 edition. Sources: BleepingComputer, Brinks Home, SecurityWeek.

2. Check Point SmartConsole zero-day hands attackers full admin control

CRITICAL · PATCH NOW

CVE-2026-16232 is an authentication bypass in Check Point SmartConsole that lets an unauthenticated attacker obtain an application login token and act with administrator privileges over the Security Management Server or Multi-Domain Security Management Server. From there an intruder can alter admin permissions, change VPN configurations, and tamper with logging. CISA added it to the Known Exploited Vulnerabilities catalog on July 22 with a July 25 federal deadline, and by midweek Rapid7 had published a proof-of-concept, moving the flaw from confirmed exploitation to commodity risk. This is the clearest example of the week's second theme: the console you use to govern security is itself an internet-exposed target. Restrict management-server access, tighten Trusted Clients, and patch. Covered in the July 25 edition. Sources: SecurityWeek, The Hacker News.

3. A Fastjson 1.x zero-day is hitting US firms, and no patch is coming

CRITICAL · NO PATCH

CVE-2026-16723 abuses Fastjson's type-resolution logic directly, so it needs no AutoType re-enablement and no pre-existing gadget class, which strips away the guardrails organizations built after earlier Fastjson bugs. An attacker who can send a crafted request runs code without authentication or user interaction. Fastjson 1.x spent years embedded in Java and Spring Boot applications as a transitive dependency teams never chose, and there is no fixed 1.x release. CISA added it to KEV on July 29. This is the scenario a software bill of materials was built for: when there is no patch, discovery is the whole game, and an unmaintained library that stops receiving fixes does not stop running in production. Enable SafeMode or migrate to Fastjson2. Analysis in the July 29 edition. Source: The Hacker News.

4. Fake IT support on Microsoft Teams is ending in Chaos ransomware

CRITICAL · IDENTITY

Sophos tracked a campaign, STAC4749, in which attackers pose as internal IT staff over Microsoft Teams, walk an employee into granting remote access, and end the intrusion with Chaos ransomware. It is the enterprise twin of the Brinks Home vector and the week's most actionable social-engineering story, because the fix is a process, not a purchase: define how IT actually contacts staff, forbid unsolicited remote-access requests, and give employees a fast way to verify a caller. Covered in the July 30 edition. Sources: BleepingComputer, Sophos.

5. Clop's PTC Windchill and FlexPLM extortion escalated with a coordinated advisory

CRITICAL · THIRD-PARTY RISK

Clop continued its data-theft campaign against internet-exposed PTC Windchill and FlexPLM instances through CVE-2026-12569 (CVSS 9.3), and by midweek the activity carried a coordinated advisory with fresh indicators of compromise. Windchill and FlexPLM sit at the center of product-lifecycle and manufacturing data, so a single exposed instance can hand attackers a company's design and supplier records. Take internet-facing PLM offline or behind access controls, patch, and hunt for the published indicators. Covered in the July 26 edition. Sources: BleepingComputer, The Hacker News.

6. Analog Devices told the SEC data was exfiltrated, then weighed a second claim

HIGH · SEMICONDUCTOR

Analog Devices disclosed in an SEC Form 8-K that an unauthorized party exfiltrated data, while a separate group calling itself ExfilSquad made an overlapping extortion claim. The messy, competing attribution is now a normal feature of a public breach, and the 8-K is a reminder that disclosure timing and materiality judgments are part of the incident, not an afterthought. Semiconductor and hardware-design data is high-value intellectual property, so treat the filing as the start of downstream partner risk, not the end of the story. Covered in the July 30 edition. Sources: The Record, SEC EDGAR.

Also across the week

  • Origin Energy confirmed a breach exposing customer data and notified regulators. BleepingComputer
  • Parcel carrier OnTrac notified roughly 40,000 customers that hackers accessed their personal data. BleepingComputer
  • A public exploit runs code as the git user on unpatched self-hosted GitLab, with no CVE assigned, a reminder that a severe fix without a tracking ID still needs patching. The Hacker News
  • CISA moved a hard-coded credential in Cisco Secure Firewall Management Center (CVE-2026-20316) into the exploited column on July 29, and put a maximum-severity Arista VeloCloud Orchestrator flaw (CVE-2026-16812) on a July 30 federal deadline. CISA KEV
  • A public exploit landed for a pre-auth vBulletin remote code execution flaw (CVE-2026-61511), while SharePoint CVE-2026-50522 and a Palo Alto GlobalProtect VPN flaw stayed under active exploitation, the latter by the Qilin ransomware group. The Hacker News
  • JetBrains patched a critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077, CVSS 9.8) that exposes stored CI/CD credentials; no known exploitation at release. JetBrains
  • Laundry Bear (Void Blizzard) weaponized an Outlook Web Access XSS flaw (CVE-2026-42897) against government, telecom, financial, and aerospace targets. The Record

What to watch next week

  • ShinyHunters set a July 31 leak deadline for Ernst & Young client tax data. Watch for an actual data dump over the weekend, and if you are an EY tax client, treat this as active exposure and prepare customer notifications now.
  • The EU AI Act Article 50 transparency obligations become enforceable on August 2, 2026, covering AI-interaction disclosure and labeling of AI-generated and deepfake content, with fines up to 15 million euros or 3 percent of global turnover. Confirm your AI-facing products and communications meet the labeling requirement.
  • Help-desk vishing will keep spreading. Expect more ShinyHunters-style Entra and Salesforce campaigns. Require callback verification for any Entra registration, MFA reset, or remote-access request, and rehearse the script with your service desk.
  • No-patch exposure will linger. Hunt Fastjson 1.x and other end-of-life libraries in your software bill of materials, enable SafeMode or migrate to a maintained release, and treat abandoned components as standing liabilities.
  • Management-plane advisories cluster. After Check Point, Cisco FMC, and Arista, treat new CISA KEV additions for security appliances and consoles as same-week patches, and pull those systems off the public internet where you can.

FAQ

What was the biggest breach story of the week?
ShinyHunters' voice-phishing campaign. The group reached Brinks Home through a single Microsoft Entra vishing call, claiming more than 1.1 million Salesforce customer rows and 3.8 million support chat logs, and put Ernst & Young on a July 31 leak clock over stolen client tax data.

What was the common thread across the week's incidents?
Attackers bypassed patching. The largest exposures came from voice phishing against help desks and identity flows, and the vulnerabilities that mattered sat in the security management plane, several with no clean patch.

What is vishing and why did it matter this week?
Vishing is voice phishing: an attacker calls an employee and talks them through an authentication or Microsoft Entra registration step, handing over account access. It was the initial-access vector for both the Brinks Home breach and the Microsoft Teams campaign that ended in Chaos ransomware.

Which vulnerability should we prioritize?
Check Point SmartConsole CVE-2026-16232, an actively exploited admin takeover of the management plane with a public proof-of-concept and a CISA KEV listing, and Fastjson 1.x CVE-2026-16723, actively exploited with no fixed 1.x release. Patch the first, and hunt and mitigate the second.

What should security teams prioritize next week?
Harden help-desk identity verification against vishing, hunt Fastjson and other unpatchable libraries in your SBOM, patch management-plane appliances from Check Point, Cisco, and Arista, and confirm AI-content labeling before the EU AI Act Article 50 deadline on August 2.

CISO Platform Breach Intelligence Team

More from the community: the CISO Platform Breach Intelligence hub, peer resources on social engineering, vulnerability management, and third-party risk.

Stay ahead of the next breach

Join a vendor-neutral community of senior security leaders who share what actually works.

Join the CISO Platform community (free)

Subscribe to the weekly newsletter

Visit the Breach Intelligence hub

Corrections and takedown requests: CISO Platform is committed to accuracy and fairness. If any detail in this briefing is inaccurate, or if you represent an affected organization and would like a correction or removal, please contact us at pritha.aash@cisoplatform.com and we will review your request promptly.

Votes: 0
E-mail me when people leave their comments –

You need to be a member of CISO Platform to add comments!

Join CISO Platform

Join The Community Discussion