
Introduction
The July edition of the security drop is here, covering events happening in Africa and across the globe. This edition covers how Europol flagged 4,340 URLs tied to one of the internet's most disturbing networks, how the Trump administration is probing Chinese AI models for IP theft, and how an Illinois hacker was jailed for hacking 750 women's Snapchat accounts.
Also, Nigeria's Zenith Bank faced a ransomware claim affecting 90 million records, and a malicious Adobe extension could have been secretly reading your WhatsApp conversations.
We have covered what you need to do to stay protected.

Europol Just Flagged 4,340 URLs Tied to One of the Most Disturbing Networks on the Internet
Between June and July, Europol concluded weeks of coordinated action, which was dubbed “Referral Action Days” across nine countries. The action flagged 4,340 URLS tied to TheCom, a cybercriminal network known for various cybercriminal activities. As part of the EU’s broader counterterrorism agenda, hosting providers have been notified to take down the network, which has been discovered to recruit vulnerable youths to engage in self-harm, sex crimes and violent attacks.
For parents and individuals, one key takeaway remains adequate monitoring of their children’s online activities. Know what platforms they are using and who they are talking to. For organisations and platforms operating within the online gaming and social spaces, the EU’s ProtectEU initiative is tightening expectations around how illegal content should be handled. This includes proactive content moderation, reporting pathways and mandatory collaboration with law enforcement.
Russia is Targeting Zimbra Email Users, and You Don’t Even Have to Click a Link
A joint alert from over a dozen Western cybersecurity agencies has flagged an active Russian cyberespionage campaign targeting users of the Zimbra Collaboration Suite. The threat actor behind it, tracked as Laundry Bear by Dutch intelligence –and also known as TA488 and Void Blizzard– has been quietly running this campaign since at least July 2025, targeting organisations across the US, Europe and Ukraine.
The vulnerability at the centre of it all is CVE-2025-66376, and when successfully exploited, the malicious script runs silently in the background and harvests credentials, session tokens, backup two-factor authentication codes, etc. Targets have included Ukrainian government entities, US government and defence industrial base organisations.
If you are running Zimbra collaboration suite, updating your version is not optional. It is important to update to the latest version, which is 10.1.20. For security teams, now is the time to review logs for any unusual script execution, unexpected data exfiltration over DNS or HTTPS, or even logins from unfamiliar locations and devices. Where patching cannot happen immediately, consider temporarily disabling HTML email rendering in your Zimbra webmail client.
The White House is Coming for Chinese AI Models
The US-China AI rivalry just escalated in a direction that has real implications for every enterprise using AI tools.
Treasury Secretary Scott Bessent confirmed this week that the Trump administration is actively probing Chinese AI models for evidence of Intellectual Property (IP) theft from US systems, and is threatening sanctions against developers found to have built their models by copying American ones. The accusation isn't vague either. Bessent stated that investigators are already finding watermarks from US large language models inside Chinese releases and that Chinese firms may have run hundreds of millions of queries against US models in a process called distillation. Essentially, the Chinese AI developers are training their models on the outputs of a more capable existing system. This will enable the Chinese models to absorb the abilities of the existing systems at a fraction of the cost.
For enterprises currently using or evaluating Chinese AI models, this is a signal to commence documenting your AI tooling decisions. This may be a proactive measure against prospective disclosure requirements that may emerge from this incident.
Chick-fil-A Got Hit with Credential Stuffing…Again
Chick-fil-A has confirmed that over 13,000 customers had their accounts compromised in a wave of credential stuffing attacks targeting its website and mobile app between June 17 and June 19, 2026. Attackers used automated tools and credentials sourced from third-party breaches to break into Chick-fil-A One loyalty accounts.
Here’s the part worth noting: this is the second time Chick-fil-A has been hit with a credential stuffing attack, with the first incident occurring in 2023 and affecting over 70,000 customer accounts. Therefore, if you have a Chick-fil-A One account, change your password. For organisations running customer-facing apps, this incident continues to be a reminder to ensure adequate protective methods like rate limiting on login attempts, CAPTCHA, anomaly detection, etc. are in place to significantly reduce the possibility of such attacks.
A Man Just Got Six Years Imprisonment for Hacking 750 Women’s Snapchat Accounts
Kyle Svara, a 26-year-old from Illinois, was sentenced this week to 76 months in prison and three years of supervised release after pleading guilty to hacking the Snapchat accounts of over 750 women to steal intimate photos, which he then traded and sold online. Between May 2020 and February 2021, he targeted more than 4,500 women in total, and investigators found approximately 530 images and 600 videos of child abuse material in his online storage.
What’s worse: Svara ran this criminal activity as a service, offering to hack into Snap accounts of various women. One of his clients, a former track and field coach, was sentenced to five years in 2024 for cyber fraud, cyber stalking and sextortion.
What’s important to take away is understanding how to detect phishing activities. Legitimate platforms will never contact you randomly to ask for your login code,m verification code,m or one-time password. Finally, enable two-factor authentication on your accounts to stave off possible phishing attacks.
Hackers Spent Ten Months Inside South Korea’s Diplomatic Training System, and No One Noticed
An unknown threat actor has had access to South Korea’s National Diplomatic Academy’s online education system for ten months, leaking the data of at least 6,000 current and former Ministry of Foreign Affairs employees, including 350 active diplomats stationed abroad.
The data exposed include IDs, names, email addresses and encrypted passwords of those enrolled in the platform. Korean media reports suggest official job titles and departmental affiliations were also leaked, and that the true number of affected individuals could be as high as 10,000. The Ministry says no national identification numbers, mobile numbers, or even home addresses were taken. However, it was noted that the cause of this leak stemmed from a compromised server that was excluded from regular scrutiny because it was originally used to support remote training during the COVID-19 pandemic.
Therefore, for governments and institutions, it is important to always audit and scrutinise their servers and systems. Every server, regardless of where it sits physically or how it's classified, should be subject to the same monitoring and patch management as core systems
Your Adobe Acrobat Extension Might be Letting Strangers Read Your WhatsApp Messages
Researchers at Guardio Labs have discovered and disclosed a chain of vulnerabilities in the Adobe Acrobat Chrome extension, tracked as CVE-2026-48294. Dubbed “Hermetic Reader”, the vulnerability allows any malicious website to access a user’s WhatsApp Web conversation without any authentication.
The good news in this story is how quickly it was caught and fixed. Giardio’s researchers spotted the flaw just four hours after Adobe inadvertently introduced it through an update. Adobe was notified, responded over a weekend, and had a patch out within two days. The fix is in version 26.5.2.3.
What you should do is ensure that your Adobe Acrobat Chrome extension version is 26.5.2.3 or later. For organisations, consider reviewing which extensions are permitted on company-issued devices and whether those extensions are necessary or otherwise.

Unitel nationwide telecom outage after cyberattack — Angola (July 28–29)
Angola’s largest telco, Unitel, said a cyberattack detected at 2:20 a.m. on July 28 knocked out voice, mobile data, and internet nationwide, with severe disruption continuing into a second day.
Zenith Bank Plc ransomware claim — Nigeria (July 26)
Ransomware group ExfilSquad claimed a breach of Zenith Bank, alleging access to ~90 million records including PII, account information, and financial data, and threatening a leak.
Presidential website defacement & ransom demand — Kenya (July 18–19)
Hackers defaced president.go.ke, posted messages targeting President William Ruto, and demanded 5 BTC (~KSh 41m / ~$320k); the site was taken offline, then restored, with officials saying no evidence of sensitive data loss.
Reatile Group ransomware attack — South Africa (July 18)
Incransom announced it had breached Reatile Group, a major energy-sector investment holding company, and threatened to publish stolen data unless contacted.
Multiple South African ransomware victims (ongoing, July)
Ransomware tracking sites recorded multiple South African organisations claimed in mid‑July, including reatile.co.za on July 18, indicating a broader cluster of incidents in the country that month.
Nigeria telecom fraud syndicate follow‑on coverage (June bust, July context)
Although the police bust was announced June 17, July reporting and analysis continued to highlight the case as a major cyber‑enabled telecom fraud incident with ~₦7.7bn in losses, underscoring the threat landscape into July.
Liberia cybercrime threat rating upgrade (July 5)
SafeHaven’s July 5, 2026 report classified cybercrime in Liberia as a Medium‑High and “rising sharply” threat, reflecting increased incident pressure on digital infrastructure and services.
Pan‑Africa cybercrime enforcement context (Operation Red Card, published July 19)
A July 19 article highlighted INTERPOL’s Operation Red Card (16 African countries, late‑2025 to early‑2026), with 651 arrests and ~$45m in fraud exposure, framing the operational backdrop for July’s incidents.
Kenya’s broader cyber‑attack surge (June report, July relevance)
A June 2026 government report cited >3 billion cyber attacks on Kenyan systems over three months; July’s presidential website incident amplified concerns about the scale and persistence of threats.
Ghana higher‑education sector warning (June advisory, July relevance)
Ghana’s Cyber Security Authority warned universities to harden defences after a large overseas university breach; July coverage kept this in focus as a regional risk for African higher‑ed institutions.