The Signal
These stories call for separate security decisions rather than a single response: infrastructure exposure, user-mediated execution, mobile interaction, and card replacement sit at different control boundaries. The practical takeaway is to distinguish how access is gained, which asset is at risk, and who can act on the relevant control. [1][2][3][4]
Must Know
Siemens S7 controller attack advisory
What happened
Five U.S. federal agencies issued a joint advisory about an active campaign targeting Siemens S7 Series PLCs, covering S7-200 through S7-1500 F-series controllers. [1]
The advisory says actors use Internet scanning services to find exposed or poorly protected Siemens PLCs running outdated software, with activity targeting multiple U.S. critical-infrastructure sectors. [1]
Why it matters
Observed activity reportedly begins with scanning and read operations to map target environments before writes; the agencies assess this as pre-positioning against specific CPU models. [1]
StopAndProtect WordPress compromise network
What happened
Check Point Research identified StopAndProtect as an operation using nearly 2,000 compromised WordPress domains to deliver malware, control infected machines, and store stolen data. [2]
The campaign begins with a ClickFix-style fake CAPTCHA that instructs visitors to copy and run a PowerShell command, followed by .NET downloaders and loaders. [2]
Why it matters
The operation does not deploy ransomware against every victim; operators may first collect file lists and selectively exfiltrate files, with encryption or screen locking occurring later depending on their objectives. [2]
Manic Android malware analysis
What happened
ThreatFabric’s Mobile Threat Intelligence team identified Manic, an Android malware active in the wild since at least February 2026 and still under development as of July. [3]
Manic combines banking fraud and spyware, targeting 169 Android applications across banking, payments, government and identity services, cryptocurrency, messaging, browsers, email and 2FA. [3]
Why it matters
The malware provides attackers with WebRTC-based remote screen viewing and interaction, can conceal activity with black or fake screens and messages, and can remove itself from the app launcher while remaining activatable through a wrapper or deep link. [3]
Research on expired-card payment authorization
What happened
A University of Massachusetts Amherst team reported that a contactless credit card can continue working after its printed expiration date, including after the cardholder receives a replacement. [4]
The researchers called the issue the “Zombie Card” attack and presented their findings at USENIX Security 2026. [4]
Why it matters
The work was motivated by documented improper handling of expired cards; the source says issuers instruct cardholders to destroy expired cards after replacement, but cardholders routinely underestimate this risk. [4]
Also Worth Knowing
Indictments over alleged Iranian cyber espionage
What happened
The U.S. Department of Justice unsealed a superseding indictment charging 17 members of the Iran-based Mabna Institute over hacking campaigns conducted since at least 2013 on behalf of the IRGC and other Iranian government and university clients. [5]
Vulnerability patching analysis
What happened
Rapid7’s Q2 2026 Threat Landscape Report counted 8,539 high- and critical-severity vulnerability disclosures, twice the number recorded a year earlier. [6]
ThreatsDay vulnerability and incident roundup
What happened
The article says some of the week’s trouble involves trusted capabilities being used as permitted, including signed drivers turned against defenses and legitimate applications helping malware blend in. [7]