Subscribe

Social Media Links

Insights

 | 3 minute read

Ankura CTIX FLASH Update – July 24, 2026


Security researchers have uncovered two (2) highly sophisticated cyber campaigns that highlight how attackers are increasingly abusing trusted technologies to evade detection and expand their reach. In the first case, the Chaos ransomware group is using a newly identified malware called msaRAT, which routes its command-and-control (C2) communications through legitimate browsers like Google Chrome and Microsoft Edge using encrypted WebRTC connections and the Chrome DevTools Protocol. By disguising traffic as normal browser activity and leveraging trusted services such as Cloudflare Workers and Twilio TURN servers, the malware becomes significantly harder for traditional security tools to identify. Separately, researchers discovered a large-scale operation abusing compromised GitHub repositories and GitHub Actions runners to automatically scan for and exploit vulnerable cPanel and WHM servers through CVE-2026-41940. Once successful, attackers attempt to steal valuable data including cloud credentials, API keys, SSH keys, database information, and payment service credentials. Together, these incidents demonstrate a growing trend where threat actors weaponize legitimate cloud platforms, developer tools, and browser technologies to conceal malicious activity, emphasizing the need for stronger phishing protections, vigilant monitoring of browser-based network behavior, and rapid review of published indicators of compromise (IoCs). CTIX analysts will continue to report on the latest malware strains and attack methodologies.


Chick-fil-a is notifying customers of a data breach after credential stuffing attacks compromised “Chick-fil-a One” accounts via its website and mobile app between June 17th and 19th, 2026. Attackers used stolen usernames and passwords from third-party sources to log in, potentially accessing names, email addresses, membership and mobile pay numbers, QR codes, Chick-fil-a credit balances, and the last four (4) digits of payment cards, plus any stored birth dates, phone numbers, and addresses. The company hasn’t disclosed total affected accounts but reported impacts to residents in multiple US states, including Texas and Massachusetts. In response, Chick-fil-a logged out impacted users, removed stored payment methods, restored account balances, and added rewards, advising customers to change passwords. This follows a similar credential stuffing incident Chick-fil-a disclosed in March 2023 that affected over 71,000 customers.


Check Point has released security updates to address three (3) high-severity vulnerabilities affecting its Security Management and Multi-Domain Security Management (MDSM) products, including the actively exploited zero-day CVE-2026-16232 (CVSS 9.3), an authentication bypass flaw that allows unauthenticated remote attackers to obtain a SmartConsole login token and authenticate with full administrative privileges. Successful exploitation enables attackers to modify security policies and configurations, though attacks require management servers to be directly exposed to the internet without firewall protections or Trusted Client IP restrictions. Check Point confirmed that a limited number of customers have been targeted, privately notified affected organizations, and published indicators of compromise (IoCs), but has not attributed the attacks, although the Qilin ransomware group has recently been observed targeting Check Point appliances. The company also patched CVE-2026-62144, a critical authentication bypass vulnerability that enables unauthenticated execution of administrative commands on management servers, and CVE-2026-62145, a high-severity privilege escalation flaw affecting Gaia Portal and related management components that allows authenticated users with limited privileges to gain root access. All three (3) vulnerabilities impact multiple product versions, and customers are urged to install the July 22 Jumbo Hotfix, restrict management access to trusted IP addresses, enable firewall protections, and review internet-exposed management interfaces. Due to confirmed in-the-wild exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-16232 to its Known Exploited Vulnerabilities (KEV) catalog, requiring U.S. federal agencies to remediate affected systems by no later than July 25, 2026.

📧 Never Miss a Briefing

Stay informed and secure. Subscribe to Ankura’s Cyber Flash Update, a bi-weekly briefing curated by our top cybersecurity experts. Receive timely insights on emerging threats, vulnerabilities and malicious actors to keep your systems secure. 


© Copyright 2026. The views expressed herein are those of the author(s) and not necessarily the views of Ankura Consulting Group, LLC., its management, its subsidiaries, its affiliates, or its other professionals. Ankura is not a law firm and cannot provide legal advice.

Let’s Connect

We solve problems by operating as one firm to deliver for our clients. Where others advise, we solve. Where others consult, we partner.

I’m interested in
I need help with