ARTICLE
26 July 2026

Ankura CTIX FLASH Update – July 24, 2026

AC
Ankura Consulting Group LLC

Contributor

Ankura Consulting Group, LLC is an independent global expert services and advisory firm that delivers services and end-to-end solutions to help clients at critical inflection points related to conflict, crisis, performance, risk, strategy, and transformation. Ankura has more than 2,000 professionals serving 3,000+ clients across 55 countries. Collaborative lateral thinking, hard-earned experience, and multidisciplinary capabilities drive results and Ankura is unrivalled in its ability to assist clients to Protect, Create, and Recover ValueTM. For more information, please visit, ankura.com.
Ankura's latest insights explore critical developments across banking M&A, data center infrastructure, healthcare policy, cybersecurity threats, and enterprise data monetization. From steady deal volumes in bank acquisitions to sophisticated malware campaigns and clinical trials reform, these analyses examine how organizations navigate evolving regulatory landscapes, technological disruptions, and operational challenges in today's complex business environment.
United States Strategy
Ankura Consulting Group LLC’s articles from Ankura Consulting Group LLC are most popular:
  • within Strategy topic(s)

Malware Activity

Browser-Based Evasion and GitHub Infrastructure Abuse Signal a New Era of Cyber Threats

Security researchers have uncovered two (2) highly sophisticated cyber campaigns that highlight how attackers are increasingly abusing trusted technologies to evade detection and expand their reach. In the first case, the Chaos ransomware group is using a newly identified malware called msaRAT, which routes its command-and-control (C2) communications through legitimate browsers like Google Chrome and Microsoft Edge using encrypted WebRTC connections and the Chrome DevTools Protocol. By disguising traffic as normal browser activity and leveraging trusted services such as Cloudflare Workers and Twilio TURN servers, the malware becomes significantly harder for traditional security tools to identify. Separately, researchers discovered a large-scale operation abusing compromised GitHub repositories and GitHub Actions runners to automatically scan for and exploit vulnerable cPanel and WHM servers through CVE-2026-41940. Once successful, attackers attempt to steal valuable data including cloud credentials, API keys, SSH keys, database information, and payment service credentials. Together, these incidents demonstrate a growing trend where threat actors weaponize legitimate cloud platforms, developer tools, and browser technologies to conceal malicious activity, emphasizing the need for stronger phishing protections, vigilant monitoring of browser-based network behavior, and rapid review of published indicators of compromise (IoCs). CTIX analysts will continue to report on the latest malware strains and attack methodologies.

Threat Actor Activity

Chick-fil-a Member Loyalty Accounts Hit by Credential Stuffing Breach

Chick-fil-a is notifying customers of a data breach after credential stuffing attacks compromised “Chick-fil-a One” accounts via its website and mobile app between June 17th and 19th, 2026. Attackers used stolen usernames and passwords from third-party sources to log in, potentially accessing names, email addresses, membership and mobile pay numbers, QR codes, Chick-fil-a credit balances, and the last four (4) digits of payment cards, plus any stored birth dates, phone numbers, and addresses. The company hasn’t disclosed total affected accounts but reported impacts to residents in multiple US states, including Texas and Massachusetts. In response, Chick-fil-a logged out impacted users, removed stored payment methods, restored account balances, and added rewards, advising customers to change passwords. This follows a similar credential stuffing incident Chick-fil-a disclosed in March 2023 that affected over 71,000 customers.

Vulnerabilities

Active Exploitation of Check Point SmartConsole Authentication Bypass Prompts Urgent Patching

Check Point has released security updates to address three (3) high-severity vulnerabilities affecting its Security Management and Multi-Domain Security Management (MDSM) products, including the actively exploited zero-day CVE-2026-16232 (CVSS 9.3), an authentication bypass flaw that allows unauthenticated remote attackers to obtain a SmartConsole login token and authenticate with full administrative privileges. Successful exploitation enables attackers to modify security policies and configurations, though attacks require management servers to be directly exposed to the internet without firewall protections or Trusted Client IP restrictions. Check Point confirmed that a limited number of customers have been targeted, privately notified affected organizations, and published indicators of compromise (IoCs), but has not attributed the attacks, although the Qilin ransomware group has recently been observed targeting Check Point appliances. The company also patched CVE-2026-62144, a critical authentication bypass vulnerability that enables unauthenticated execution of administrative commands on management servers, and CVE-2026-62145, a high-severity privilege escalation flaw affecting Gaia Portal and related management components that allows authenticated users with limited privileges to gain root access. All three (3) vulnerabilities impact multiple product versions, and customers are urged to install the July 22 Jumbo Hotfix, restrict management access to trusted IP addresses, enable firewall protections, and review internet-exposed management interfaces. Due to confirmed in-the-wild exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-16232 to its Known Exploited Vulnerabilities (KEV) catalog, requiring U.S. federal agencies to remediate affected systems by no later than July 25, 2026.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

[View Source]

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More