STRATQUAD
CYBER THREAT INTELLIGENCE BRIEF
Daily Brief · 11 July 2026 · 24h windowRISKHIGH
StratQuad CTI Daily Brief, 11 July 2026
Compiled from 52 monitored sources · 528 articles reviewed

Today’s Briefing

CISA added two Joomla extension vulnerabilities to the Known Exploited Vulnerabilities catalog: CVE-2026-48939 in iCagenda and CVE-2026-56291 in Balbooa Forms, both allowing unauthenticated arbitrary file upload leading to remote code execution. Karen Vardanyan, an Armenian national, pleaded guilty to participation in Ryuk ransomware attacks that targeted UK healthcare organisations among others, facing up to fifteen years in federal prison and nearly $1.2 million in restitution. Microsoft released eighty-six security updates in today's Patch Tuesday cycle, and Google issued two Chrome updates within two days addressing critical vulnerabilities. The UK financial regulators begin oversight of the first designated critical third parties on Monday 13 July, with AWS among those named by HM Treasury under the new regime.

Top Stories

  1. Armenian national pleads guilty to Ryuk ransomware attacks
  2. Two Chrome updates in two days fix critical vulnerabilities
  3. CISA Adds Two Known Exploited Vulnerabilities to Catalog
  4. OpenPLC v3
  5. CC-4811 - Palo Alto Networks Releases Security Update for PAN-OS

Full brief available to subscribers

The complete operator brief — action items with patch deadlines, the vulnerability appendix and named actor activity — goes out by email each morning. Subscribe free to receive it.

Get the brief at 07:00, every weekday.

The day's UK security intelligence, read and ranked so you start informed: the stories that matter, the IOCs your SIEM needs, and the actions worth taking first.

← All briefs