Help AG’s Managed Security Services (MSS) team delivers 24x7x365 monitoring across complex enterprise environments, providing continuous visibility into emerging cybersecurity threats across the region.
Cyber Threat Group CyberAvengers Disrupts Over 30 Water Facilities
Security researchers at Tenable have linked the cyber threat group CyberAvengers to a coordinated cyberattack that disrupted more than 30 water facilities between 26 and 27 July.
The attack targeted Operational Technology (OT) environments, with a particular focus on programmable logic controllers (PLCs). CyberAvengers has a history of targeting Unitronics Vision Series PLCs through default passwords and has recently expanded its activity to equipment from Rockwell Automation/Allen-Bradley, Schneider Electric and Siemens.
The group uses the IOCONTROL malware kit, designed for OT and IoT environments, and has also been observed using AI tools such as ChatGPT for development.
Its attack methods include targeting internet-exposed devices and using remote-access software such as TeamViewer and AnyDesk to bypass traditional security controls.
The incident highlights the cybersecurity risks facing smaller-scale infrastructure, particularly where network segmentation is limited and dedicated cybersecurity resources are unavailable.
Recommendations
- Immediately change all default passwords on PLCs and IoT devices.
- Ensure OT environments are not directly exposed to the public internet.
- Implement strict network segmentation between IT and OT networks to prevent lateral movement.
- Secure or disable remote-access tools such as TeamViewer and AnyDesk, and protect access with multi-factor authentication (MFA).
- Regularly audit internet-facing assets and implement robust monitoring to detect unauthorised changes to PLC configurations.
APT Group Mirage Kitten Deploys New Malware Suite Across Critical Sectors
Mirage Kitten, also known as UNC1549, Smoke Sandstorm or Nimbus Manticore, is an advanced persistent threat (APT) group conducting cyber-espionage operations targeting the aerospace, aviation, defence and telecommunications sectors across the Middle East and Africa.
The group has deployed a new, previously undocumented malware suite.
This includes NightLedger, a Windows backdoor designed for Dynamic Link Library (DLL) search-order hijacking through AppVShNotify.exe. NightLedger enables reconnaissance, process execution and file operations, and specifically targets NetSetup.log for data collection.
The group also uses the WebSocket-based tunnellers BridgeHead and ArcBridge to establish covert network access and provide SOCKS5 proxy capabilities. BridgeHead has been observed in environments across North Africa and South Asia, where it uses username-based checks to avoid analysis.
The group is also moving from Azure-based infrastructure to Cloudflare-backed domains, making attribution more difficult.
The campaign uses highly targeted spear-phishing attacks and fake recruitment portals to gain initial access.
Recommendations
- Implement strict protections against DLL search-order hijacking and monitor for unusual DLL loads in legitimate processes such as AppVShNotify.exe.
- Monitor for unauthorised WebSocket connections and unusual outbound HTTPS traffic to unknown domains.
- Conduct regular audits of Windows diagnostic logs, such as NetSetup.log, to detect unauthorised access.
- Strengthen email security to detect spear-phishing attacks and recruitment-themed social engineering attempts.
- Implement robust endpoint detection and response (EDR) capabilities to identify suspicious mutex creation and process injection attempts.
Telegram-Based Malware Campaign Targets Middle East Government Entities
Cybersecurity researchers from Zscaler ThreatLabz have identified a new cyber campaign targeting government entities across the Middle East.
The attackers use the Telegram messaging platform as a command-and-control (C2) mechanism to manage their operations.
During these intrusions, the threat actor deployed several previously undocumented malware families, identified as TELESHIM, MIXEDKEY and BINDCLOAK.
The activity was detected in July, indicating an active threat targeting high-value government infrastructure across the Middle East.
Using legitimate communication platforms such as Telegram for C2 can help threat actors avoid traditional network security monitoring by blending malicious activity with legitimate traffic.
Recommendations
- Organisations, particularly government entities, should monitor for unusual Telegram traffic originating from internal networks.
- Enhance network visibility to detect unauthorised use of messaging platforms for command-and-control (C2) activities.
- Implement robust endpoint detection and response (EDR) capabilities to identify the execution of unknown malware families such as TELESHIM, MIXEDKEY and BINDCLOAK.
- Conduct regular threat hunting to identify indicators associated with this campaign.
Microsoft Addresses 16 Vulnerabilities Across Edge, Excel and Office
Microsoft has released security fixes for 16 vulnerabilities, including seven high-severity and nine medium-severity vulnerabilities.
The vulnerabilities affect Microsoft Edge (Chromium-based), Microsoft Edge for Android, Microsoft Excel and Microsoft Office products.
They include remote code execution, information disclosure, spoofing, tampering, code injection and authorisation bypass issues.
Key high-severity vulnerabilities include:
- CVE-2026-62870 – A use-after-free vulnerability in Microsoft Office Excel that could allow remote code execution.
- CVE-2026-66315 – A use-after-free vulnerability in Microsoft Edge that could allow remote code execution.
- CVE-2026-66321 – A type confusion vulnerability in Microsoft Edge that could allow remote code execution.
- CVE-2026-66310 / CVE-2026-65802 – File path control vulnerabilities in Microsoft Edge for Android that could lead to information disclosure.
Recommendations
- Ensure all affected systems are patched and updated.
Google Chrome Fixes UI Spoofing Vulnerability on iOS
Google Chrome has released a security update addressing one medium-severity vulnerability:
[Medium] CVE-2026-17913 – An inappropriate implementation issue affecting Chrome for iOS in versions prior to 151.0.7922.72 could allow a remote attacker to perform UI spoofing using a specially crafted HTML page. (Chromium security severity: Low.)
Recommendations
- Ensure all affected systems are patched and updated.
REFERENCES
https://securelist.com/mirage-kitten-new-tools/120811/
https://thehackernews.com/2026/07/teleshim-abuses-telegram-for-c2-in.html
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66326
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62870
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66315
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66317
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66313
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66321
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66316
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66312
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66325
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66310
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66314
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65804
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65802
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66311
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66318
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66322
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html
https://issues.chromium.org/issues/504209246









