This briefing covers 20 cybersecurity and geopolitics
stories published around Saturday, July 18, 2026,
including activity involving Scattered Spider, Multi-national.
Each entry links to the original reporting.
Iran is geotracking US military personnel's phones, while naval defense contractor TKMS was hit by ransomware and macOS infostealer CrashStealer emerged. The TKMS breach exposes defense-industrial supply chain risk as submarine and warship production data may be at stake.
Beijing and Pyongyang exchanged high-level diplomatic visits as China moves to maintain influence over North Korea amid its deepening military partnership with Russia. The visits signal Beijing's concern that the Pyongyang-Moscow axis is shifting the Northeast Asian balance without Chinese primacy.
China-linked GoldenEyeDog subgroup CylindricalCanine compromised DigiCert in April 2026, stealing code-signing certificates. Trusted certificate theft enables downstream supply-chain attacks, extending a pattern this group previously ran against gambling and gaming targets.
Major General Yevhenii Khmara, architect of Ukraine's long-range strike campaign against Russia, replaces outgoing defense minister amid active war. The appointment signals Ukraine is prioritizing offensive deep-strike and intelligence operations at the ministry's highest level.
US forces launched overnight strikes against Iran on day six of continuous combat operations, with Iranian state media confirming hits on multiple sites. Sustained bilateral strikes mark the most prolonged direct US-Iran military exchange on record.
Both U.S. and Iranian forces targeted civilian infrastructure including bridges, power plants, and desalination facilities, attacks that legal analysts say may constitute war crimes.
Beijing is co-opting veneration of the sea goddess Mazu, worshipped across Taiwan and coastal China, to advance cross-strait unification propaganda. The operation targets cultural and religious identity as a soft-power vector to erode Taiwanese political will.
The Trump administration alleges Cuba has acquired Iranian drones, a claim analysts say is designed to manufacture justification for US military action against Havana. If true, Iranian drone proliferation to the Western Hemisphere would mark a significant strategic red line crossed.
Ukraine is mobilizing borscht as a symbol of national identity to counter Russian narratives that claim the dish—and Ukrainian culture broadly—as Russian. The soft-power contest over food heritage reflects Kyiv's broader strategy of cultural resistance alongside kinetic defense.
The US, UK, and NATO are accelerating autonomous weapons deployment at commercial speed, outpacing the secure data infrastructure needed to underpin AI-driven battlefield decisions. The gap between operational deployment and trusted information assurance creates exploitable vulnerabilities in autonomous command chains.
Both Trump and Xi have systematically gutted the institutions and personnel that historically managed US-China crisis communication and de-escalation. The erosion of back-channel capacity raises the probability that the next flashpoint—Taiwan Strait, South China Sea—escalates without a diplomatic circuit-breaker.
The week of July 11 saw China introduce new AI regulations, the Trump administration briefly impose transit fees on the Strait of Hormuz, and Congo's Ebola outbreak expand. Each development carries independent escalation potential across technology governance, energy markets, and global health security.
Armenia detained Russian national Aleksandr Ermakov at Yerevan's Zvartnots airport June 28 on a U.S. extradition warrant targeting a REvil ransomware suspect of the same name; his family says it is the wrong man. The case tests Armenia's willingness to extradite Russian nationals to the U.S.
Ernst & Young is notifying clients after attackers compromised a third-party IT support-ticket system used by its personnel. The incident highlights persistent supply-chain risk where a single vendor's system becomes the entry point into a Big Four firm's client data.
Thalha Jubair and Owen Flowers, leaders of the Scattered Spider subset of The Com, were sentenced to 66 months in the UK; U.S. authorities linked Jubair alone to at least 120 attacks.
Seven malicious npm packages targeting the Vite ecosystem deploy a remote access trojan through a four-tier blockchain-based C2 spanning the Tron network, dubbed ChainVeil by Checkmarx.
Researcher 'Nightmare Eclipse' published a working exploit called LegacyHive that achieves local privilege escalation on fully patched Windows systems; no CVE assigned at time of reporting.