Weekly review

ThreatNoir Afternoon Brief — July 28

2026-07-28Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — July 28, 2026

The threat landscape continues to shift as critical vulnerabilities emerge across multiple platforms and nation-state actors expand their operational reach. Today's security briefing covers a significant healthcare data breach affecting over a million individuals, newly documented malware campaigns targeting the Middle East and Africa, and active exploitation of unpatched critical vulnerabilities in widely-deployed systems.

Data Breach at Medical Billing Firm MCBS Affects 1.26 Million People

Medical Computer Business Services (MCBS), a healthcare billing company, has disclosed a network breach from 2025 that exposed sensitive information belonging to more than 1.26 million people. The incident involved the PEAR ransomware family, underscoring the continued threat that ransomware poses to the healthcare sector and the organizations that support it. Source: Data breach at medical billing firm MCBS affects 1.26 million people

The breach represents a significant privacy incident with potential HIPAA implications for affected patients and healthcare entities relying on MCBS services. Healthcare organizations should review their vendor security assessments and incident response procedures to ensure adequate protections against similar attacks.

Mirage Kitten Targets Middle East and Africa Region with New Malware

Kaspersky researchers have identified previously undocumented malware tools attributed to Mirage Kitten, a nation-state threat actor also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore. The newly discovered toolkit includes the NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools, with the campaign primarily targeting the Middle East and Africa regions. Source: Mirage Kitten targets Middle East and Africa region with new malware

The malware suite demonstrates sophisticated capability for persistent access and lateral movement within compromised networks. Organizations in targeted regions should implement enhanced monitoring for the identified indicators of compromise, including the domains realhealthshop.com and tjconsultingservices.com, and strengthen defenses against spear-phishing attacks that serve as initial access vectors for this group.

Unpatched Fastjson Vulnerability Exploited in Attacks

A critical remote code execution vulnerability in Fastjson is being actively exploited in the wild, with attackers able to execute arbitrary code without authentication under the library's default configurations. Source: Unpatched Fastjson Vulnerability Exploited in Attacks

The vulnerability, tracked as CVE-2026-16723, poses an immediate risk to any organization deploying Fastjson in production environments. Organizations should prioritize patching efforts and conduct rapid inventory assessments to identify affected systems, as the active exploitation indicates threat actors are weaponizing this flaw at scale.

Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day

A critical OS command injection vulnerability in Arista VeloCloud Orchestrator affecting on-premises deployments has been exploited as a zero-day, allowing attackers to access privileged internal functionality. Source: Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day

This vulnerability, designated CVE-2026-16812, joins a growing list of critical flaws in VeloCloud infrastructure, with related CVEs including CVE-2022-42475, CVE-2023-27997, CVE-2024-21762, and CVE-2025-68686. Organizations operating VeloCloud Orchestrator instances should treat this as a critical priority and implement patches immediately, as nation-state actors are known to target network infrastructure components for persistent access.

The convergence of healthcare breaches, nation-state malware campaigns, and critical infrastructure vulnerabilities reflects an increasingly complex threat environment. Security teams should prioritize vulnerability management, vendor risk assessment, and threat intelligence integration to maintain effective defenses against these multifaceted threats.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Mirage Kitten targets Middle East and Africa region with new malware
Malware3
  • NightLedger
    Windows backdoor attributed to Mirage Kitten, masquerades as SspiCli.dll for DLL search-order hijacking
  • ArcBridge
    WebSocket-based tunneling tool attributed to Mirage Kitten for covert network access
  • BridgeHead
    WebSocket-based tunneler attributed to Mirage Kitten, deployed during post-exploitation in Egypt and Pakistan
Domain2
  • realhealthshop.com
    Primary C2 server for NightLedger backdoor, contacted via HTTPS GET requests to /edfcvfgbhnjmkqwasderfgg endpoint
  • tjconsultingservices.com
    Fallback C2 server for NightLedger backdoor