August 3, 2026 Emerging Threats Weekly
This week’s briefing covers:
00:00 – Intro
00:50 [SUPPLY CHAIN] GitHub and PyPI Introduce Time-Based Controls Against Malicious Packages
GitHub and the Python Package Index introduced new time-based controls intended to reduce exposure to software supply-chain attacks. The measures address the period immediately after a package is released, when malicious or compromised updates may be distributed before maintainers and security services can react.
04:15 [THREAT ACTOR] Laundry Bear Expands Half-click Tradecraft With OWAReaper on Outlook Web
A joint international advisory reports that the Russian state-supported actor Laundry Bear has targeted Western government and commercial organizations using Zimbra Collaboration Suite since at least July 2025. Also tracked as Void Blizzard, TA488 and CL-STA-1114, the group is assessed to collect sensitive information for the Russian government, with a particular focus on covertly acquiring email data.
08:18 [THREAT ACTOR] Nimbus Manticore Deployed NightLedger and Custom Tunnelers across MEA and South Asia
Nimbus Manticore, an Iran state-backed threat actor, was linked to a new toolset development related to the NightLedger backdoor and WebSocket tunnelers, BridgeHead and ArcBridge. The threat actor has been observed targeting entities in Egypt, Jordan, Tanzania, Pakistan, Ethiopia and Burkina Faso. The critical infrastructure sectors targeted included government, aviation, telecommunications, and finance.
10:50 [SOCIAL ENGINEERING] UNC6692 Combined Email Bombing, Teams Impersonation, and a Malicious Edge Extension
A new campaign by UNC6692 that combines email bombing with fake internal IT support over Microsoft Teams to gain access to targets in the software sector. The campaign relies on overwhelming the target victim with a high volume of spam emails, with the threat actor then using this confusion as a pretext to initiate a support conversation.
14:45 [CRITICAL INFRASTRUCTURE] Minnesota Water Utility Disruptions Followed Updated Warnings on Iranian-linked PLC Exploitation
A cyber attack has disrupted water and wastewater operations across more than 30 communities across the U.S. state of Minnesota, according to recent public reporting. Multiple cities were forced to shut down or initiate manual fallback for some utility processes, in what is being considered by Minnesota IT Services as a coordinated attack on community water systems across the state.
Dive deeper:
Kroll’s Monthly Threat Intelligence Spotlight Report: https://www.kroll.com/en/reports/cyber/threat-intelligence-reports/cti-spotlight-trends-report
Kroll’s Cyber Threat Intelligence: https://www.kroll.com/en/services/cyber/threat-intelligence-services
Kroll’s Q4 2024 Cyber Threat Landscape: https://www.kroll.com/en/reports/cyber/threat-intelligence-reports/q4-2024-threat-landscape-report-phishing
Kroll’s 2025 Cyber Threat Landscape Report: Cybercrime in the Crypto Era: https://www.kroll.com/Reports/Cyber/Threat-Intelligence-Reports/Threat-Landscape-Report-Lens-on-Crypto
Playlist of Kroll's Weekly Cyber Threat Intelligence Briefings: https://www.youtube.com/playlist
Kroll Cyber Blog: https://www.kroll.com/en/insights/cyber
Kroll Cyber Threat Intelligence: https://www.kroll.com/en/services/cyber/threat-intelligence-services
Kroll Threat Intelligence Reports: https://www.kroll.com/en/reports/cyber/threat-intelligence-reports
Kroll Cyber and Data Resilience: https://www.kroll.com/en/services/cyber
#krollcyber #threatintelligence #cyberthreats