All Issues
Threat Intelligence Monthly Roundup · July 2026

July Roundup 2026: Threat Intelligence

Published August 1, 2026

The biggest story for defense contractors in July wasn't a breach — it was a policy reversal. On July 13, the Department of War suspended CMMC Phase 2, the requirement that contractors handling CUI obtain third-party (C3PAO) assessment at Level 2, and froze Phases 3 and 4 alongside it. The November 10, 2026 deadline that has anchored every compliance conversation this year is no longer an active enforcement date. That doesn't mean the bar has disappeared: Phase 1 self-assessment against NIST SP 800-171 Revision 2 remains fully enforceable, and with third-party verification paused, the liability sitting behind a self-certified SPRS score just got heavier, not lighter. Meanwhile the threat landscape didn't pause for the policy review — Microsoft shipped its largest Patch Tuesday on record, Clop-affiliated actors ran an active extortion campaign against PTC's Windchill product lifecycle management software used across aerospace and defense manufacturing, and ransomware activity climbed to its second-highest month of the year.

Major Incidents

PTC Windchill / FlexPLM: Mass Extortion Campaign Hits the Defense Supply Chain Directly: Clop-affiliated threat actors exploited CVE-2026-12569 (CVSS 9.8), an unauthenticated remote code execution flaw in PTC's Windchill and FlexPLM product lifecycle management software, likely as a zero-day starting in early June. PTC patched on June 17 and CISA added the flaw to its Known Exploited Vulnerabilities catalog on June 25, but the active extortion campaign — emails threatening to leak data under the subject line "Windchill PDMLink module serious data leak" — didn't begin until July 20, confirmed hitting organizations across aerospace, automotive, and manufacturing. The data at risk is exactly what CMMC exists to protect: product designs, bills of materials, and supplier records. PTC's customer base includes defense contractors, energy suppliers, and electronics manufacturers, making this the single most relevant story of the month for a CUI-handling readership.

Indra Group: NATO-Affiliated Contractor Hit by Top Ransomware Operator: The Gentlemen ransomware group claimed an attack on a subsidiary of Indra Group, a Spanish defense, aerospace, and air-traffic-management technology company and NATO cyber coalition member, setting an initial ransom deadline that was later extended to July 9. Indra says the incident was contained to a non-critical environment with no operational disruption, and it had not independently verified the attackers' data-theft claims as investigation continued. Whatever the outcome, it's a current, concrete example of a top-tier ransomware group directly targeting a defense-adjacent, NATO-affiliated organization.

Fairlife: Ransomware Halts Dairy Manufacturing Production: A ransomware attack on July 16 forced a production suspension at a Fairlife (Coca-Cola-owned) dairy manufacturing facility. One tracker attributes the attack to the Anubis group, though attribution isn't fully settled across sources. The specific product doesn't matter to a defense audience — the mechanism does: ransomware halting physical production is the same operational-continuity risk a defense manufacturer faces, regardless of sector.

Nidec: Industrial Manufacturer's Taiwan Subsidiary Breached: Nidec Chaun Choung Technology, the Taiwanese subsidiary of Japanese industrial motor manufacturer Nidec, was hit by the threat group BlackField, which claimed theft of more than 2TB of corporate data spanning employee, financial, procurement, manufacturing, and legal records. A reminder that overseas subsidiaries and manufacturing subcontractors are frequently the actual point of entry, not the parent company's own perimeter.

Critical Vulnerabilities

Microsoft's July Patch Tuesday: A Record 570 CVEs, Three Zero-Days: Microsoft's July 14 update patched 570 vulnerabilities — the largest Patch Tuesday on record — including 59 rated Critical. Three zero-days were addressed: two confirmed exploited in the wild (CVE-2026-56155, an Active Directory Federation Services elevation-of-privilege flaw discovered by Microsoft's own incident response team, and CVE-2026-56164, a SharePoint Server elevation-of-privilege flaw) and one publicly disclosed but not yet observed exploited (CVE-2026-50661, a BitLocker bypass requiring physical device access). Both actively exploited flaws were added to CISA's KEV catalog the same day.

CVE-2026-58644 (Microsoft SharePoint, CVSS 9.8): A Second, Separate Zero-Day: Distinct from the Patch Tuesday elevation-of-privilege flaw above, this deserialization vulnerability in on-premises SharePoint Server allows an attacker authenticated as at minimum a Site Owner to remotely execute arbitrary code. It was patched as part of the July 14 release and added to CISA's KEV catalog on July 16 as actively exploited, with a July 19 federal remediation deadline. Any organization running on-prem SharePoint should treat this as a priority patch item independent of the general Patch Tuesday rollout.

VMware vCenter: Three Critical Flaws, No Workaround Available: Broadcom's July 29 advisory (VMSA-2026-0006) disclosed three critical vCenter Server vulnerabilities: an authentication bypass in the Directory Service (CVE-2026-59309, CVSS 9.8), a directory traversal enabling arbitrary code execution via the Syslog server (CVE-2026-59310, CVSS 9.8), and a VM-escape flaw in the VMXNET3 virtual network adapter (CVE-2026-47876, CVSS 9.3). Broadcom reports no evidence of in-the-wild exploitation as of the advisory date, but two of the three have no available workaround — patching is the only mitigation.

CVE-2026-16812 (Arista VeloCloud Orchestrator, CVSS 10.0): Maximum-Severity Zero-Day: An OS command injection flaw allowing full compromise of an on-premises VeloCloud SD-WAN orchestrator and every network it manages. Arista confirmed active zero-day exploitation; CISA added it to the KEV catalog on July 27 with a July 30 federal patch deadline. Hosted and Dedicated VeloCloud deployments were pre-patched before the public advisory — only on-premises orchestrators are exposed.

A Busy Month for the KEV Catalog: Beyond the headline items above, CISA added at least 16 vulnerabilities to its Known Exploited Vulnerabilities catalog across five separate batches in July, including flaws in SonicWall's SMA1000 remote-access appliances, Fortinet FortiSandbox, and Cisco's Secure Firewall Management Center. Organizations using any of these products for remote access or network management should confirm patch status against CISA's published deadlines, not just vendor release notes.

Ransomware Trends

799 Claimed Attacks, a Second-Highest Month for 2026: According to Comparitech's monthly tracker, July saw 799 claimed ransomware attacks, up 19% from June's 668 — the second-highest month of 2026 so far. Only 51 of those claims were independently confirmed by the affected organizations themselves, a reminder that leak-site claims and confirmed breaches are two different numbers. BlackFog's stricter "publicly disclosed only" methodology counted 111 confirmed attacks in July, up 6.7% year-over-year from July 2025.

The Gentlemen and Qilin Battle for the Top Spot: The Gentlemen — a group that split from Qilin in mid-2025 — led July with 135 claimed attacks per Comparitech, with Qilin close behind at 125; together the two accounted for roughly a third of all July ransomware activity. The rivalry is more than a leaderboard curiosity: The Gentlemen's willingness to target a NATO-affiliated defense contractor (Indra Group, above) shows the group isn't limited to opportunistic soft targets.

Healthcare Bears the Brunt; Manufacturing Cools, But Not Everywhere: Healthcare was the most consistently targeted sector across every tracker reviewed this month, accounting for roughly 35% of publicly disclosed attacks per BlackFog. Traditional ransomware-as-a-service activity against manufacturing actually declined month-over-month — but as the PTC Windchill campaign above shows, manufacturing and aerospace supply-chain risk didn't disappear in July, it just moved to a different attack vector: mass software exploitation rather than opportunistic ransomware deployment.

Government Advisories and Nation-State Threats

CISA Advisory AA26-097A Updated: Iranian PLC Targeting Expands Beyond Rockwell: Originally issued in April, this joint FBI/CISA/NSA advisory on Iranian-affiliated actors exploiting programmable logic controllers was updated July 22 to add detection guidance for malicious changes to PLC project files and to expand the named manufacturer list from Rockwell Automation alone to include Schneider Electric and Siemens. The advisory is framed around critical infrastructure broadly — water, wastewater, energy, and government facilities — rather than the Defense Industrial Base specifically, but any manufacturing environment running PLC/SCADA/HMI systems from these vendors should review it regardless of sector label.

Joint International Alert: North Korean IT Worker Fraud Schemes: The FBI, State Department, and counterparts in Japan, Canada, Germany, Australia, the UK, and South Korea issued a joint alert on July 31 warning that DPRK operatives are using stolen identities and forged documents to secure remote IT contract work at private companies, funneling earnings back to fund North Korea's weapons programs. The alert describes this as an insider-threat vector enabling data exfiltration and theft of sensitive corporate information at firms generally — it does not specifically name defense contractors, but any organization hiring remote IT contractors should treat identity verification as a control worth re-examining.

AI-Enabled Threats: Social Engineering at Scale

CrowdStrike's 2026 Threat Hunting Report found voice phishing (vishing) intrusions doubled in the first half of 2026 compared to the second half of 2025, with named adversary groups impersonating IT help-desk staff to trick employees onto spoofed single sign-on pages — in one documented case, account takeover to data theft took under five minutes. Mandiant's most recent M-Trends reporting separately ranks voice phishing as the second most common initial infection vector industry-wide. We did not find a verified, specifically-July incident naming a defense contractor as a deepfake or vishing target this month, but the trend data is unambiguous: voice and video are no longer reliable authentication factors for high-stakes requests.

The practical implication hasn't changed since June: out-of-band verification — a callback to a known number established before the request, not one provided during it — remains the most reliable countermeasure for any request involving financial transfers, credential resets, or access changes, regardless of how convincingly the requester presents.

CMMC and Compliance Updates

CMMC Phase 2 Suspended: What Changed and What Didn't: On July 13, DoD Chief Information Officer Kirsten Davies signed a memo suspending CMMC Phase 2 — the third-party (C3PAO) Level 2 certification requirement — and freezing Phases 3 and 4 alongside it. The memo cites prohibitive compliance costs, a severe shortage of accredited third-party assessors, and complex regulatory timelines pushing small businesses and non-traditional entrants out of DoD contracting. The suspension was issued via internal DoD memo, not a Federal Register rule change; 32 C.F.R. Part 170 remains formally unamended. What this means in practice: the November 10, 2026 deadline that has framed every compliance conversation this year is not currently an active enforcement date. DoD has stood up a CMMC Reform Task Force to conduct a 60-day review, with a public Request for Information due August 14, 2026 and a report expected around mid-September.

What's unchanged is arguably more important than what's paused: Phase 1 obligations remain fully enforceable. Contractors handling CUI still must self-assess against all 110 NIST SP 800-171 Revision 2 controls, maintain a current SPRS score with a named senior official affirming its accuracy, and report cyber incidents to DIBNet within 72 hours. And with third-party verification on hold, self-certification carries more exposure, not less — false attestations remain an explicit target of the Department of Justice's Civil Cyber-Fraud Initiative, with False Claims Act liability including treble damages. An inaccurate SPRS score is now a bigger liability than it was in June, not a smaller one, because there's no longer a scheduled third-party assessment that would have caught the gap before it became a legal problem. Contractors should not cancel any C3PAO assessment already booked — converting it to a readiness or mock assessment preserves the value of the work — and should continue NIST 800-171 remediation regardless of how the task force review concludes. A gap assessment against all 110 controls remains the essential first step to knowing where your organization actually stands. The CGA CMMC Gap Assessment Grant provides a fully funded, $5,000 in-kind professional gap assessment against all 110 NIST SP 800-171 controls at no cost to the applicant.

Executive Order on Defense Supply Chain Security: A July 20 executive order, published in the Federal Register July 23, directs the Secretary of War to develop a regulatory process requiring covered contractors and subcontractors — at any tier — to map their supply chains back to raw-material origin and implement due-diligence screening to identify and mitigate sourcing risk. Implementation guidance is due within 180 days. Combined with expanded Foreign Ownership, Control, or Influence (FOCI) disclosure requirements moving through rulemaking this year, the direction of travel is clear even as CMMC's specific mechanics are under review: supply chain visibility and ownership transparency are becoming standing requirements, not optional documentation.

NIST SP 800-171 Revision 3: Still Not the Enforced Standard: For contractors tracking framework versions, Revision 2 remains the enforced standard under DFARS 252.204-7012, and DoD's own suspension memo explicitly reaffirms that self-assessments will continue against Rev 2 during the review period. Revision 3 was finalized in 2024 but is not expected to become the mandatory baseline via formal rulemaking until sometime between late 2026 and late 2027 — don't let a vendor's Rev 3 tooling rollout be mistaken for a new compliance deadline.

Concerned about your cybersecurity posture?

CGA offers grants to help defense contractors assess and improve their compliance with CMMC and NIST SP 800-171.

View Grant Programs