Bharat Threat FeedGlobal threats, decoded for Indian defenders
Weekly Brief · 17 July 2026

Weekly Brief — 17 July 2026

Russia's FSB Centre 16 and the World Leaks ransomware group put India's infrastructure in the frame this week — one through a contractor data leak tied to the Kudankulam nuclear project, the other through a decade of router exfiltration codified in a 13-nation advisory. SonicWall's SMA1000 appliances carry a CISA remediation deadline of today; Microsoft's record July Patch Tuesday ships two actively exploited zero-days in SharePoint and Active Directory Federation Services; and a critical pre-authentication flaw in Zoom Workplace for Windows requires urgent fleet patch action before proof-of-concept code emerges.
1

World Leaks Posts 19,000 Files from Kudankulam Nuclear Project Contractor

No CVE | Data extortion — contractor supply-chain breach via third-party data centre* World Leaks, the ransomware group that previously targeted Tata Electronics and Bajaj Auto, published approximately 19,000 files totalling 14.3 GB claimed from Reliance Infrastructure, a contractor on the Kudankulam Nuclear Power Project in Tamil Nadu. Files available on the group's dark-web site since 11 June 2026 include purported blueprints for ventilation and cooling systems in Units 3 and 4, a control-room floor plan, vendor proposals, and supplier lists. Yotta Infrastructure, the third-party data centre hosting the Reliance Infrastructure server, detected suspicious activity on 29 May and states it prevented ransomware execution; Reliance Infrastructure confirmed a partial data breach. The Nuclear Power Corporation of India stated that the exposed material relates to conventional balance-of-plant systems and that nuclear safety and nuclear security systems were not affected. CERT-In is investigating.

India exposureEngineering-level documentation — ventilation layouts, supplier chains, inspection records — provides adversaries with targeting detail for secondary attacks against support systems, even where safety-critical systems remain isolated. The contractor-chain breach pattern is now the third significant India incident attributed to World Leaks in three months.
ActionCritical infrastructure operators and their tier-1 project contractors must apply data classification controls to engineering documentation, restrict blueprint-level material to need-to-know access on air-gapped or tightly segmented systems, and confirm that third-party data centre arrangements meet CERT-In baseline requirements. Breach-notification obligations under CERT-In Circular 20/2022 apply to all affected parties.
SourceBusiness Standard, 15 July 2026; Al Jazeera, 16 July 2026; Reuters (via Insurance Journal and Indian Express), 15 July 2026.
2CriticalCVSS 10.0

SonicWall SMA1000 Zero-Day Chain Exploited Since June — CVE-2026-15409 / CVE-2026-15410

CVE-2026-15409 CVSS 10.0 | CVE-2026-15410 CVSS 7.2 | CISA KEV — federal deadline today, 17 July* SonicWall confirmed on 14 July 2026 that two vulnerabilities in its SMA1000 secure remote-access appliance line (models 6210, 7210, 8200v) have been actively exploited in zero-day attacks since at least 22 June. CVE-2026-15409 is a critical server-side request forgery flaw in the Workplace interface that allows an unauthenticated attacker to force the appliance to make requests to arbitrary destinations. CVE-2026-15410 is a code-injection flaw in the Appliance Management Console. Rapid7's Managed Detection and Response team, which discovered both vulnerabilities, confirmed the pair is being chained: CVE-2026-15409 delivers unauthenticated initial access and CVE-2026-15410 enables OS command execution, yielding full pre-authentication system compromise. CISA added both to its Known Exploited Vulnerabilities catalogue on 14 July under Binding Operational Directive BOD 26-04, with a federal remediation deadline of 17 July 2026.

India exposureSonicWall SMA1000 appliances are deployed across India's mid-market and enterprise environments — BFSI, IT/ITeS, manufacturing, and managed security service providers. Internet-facing appliances that have not received the 14 July hotfix are at immediate risk of unauthenticated full compromise.
ActionApply SonicWall's 14 July security update immediately. Where patching cannot be completed today, restrict Workplace interface and management-plane access to trusted administrative source addresses or take the appliance offline. Review VPN and administrative session logs from 22 June onward for anomalous access. Rotate all credentials that were authenticated through the appliance.
SourceSonicWall Product Notice, 14 July 2026; Rapid7 blog, 14 July 2026; CISA KEV, 14 July 2026; BleepingComputer, 14 July 2026.
3CriticalCVSS 9.8

Microsoft July Patch Tuesday: SharePoint and AD FS Zero-Days Under Active Attack — CVE-2026-56164 / CVE-2026-56155

CVE-2026-56164 NVD CVSS 9.8 | CVE-2026-56155 CVSS 7.8 | CISA KEV — SharePoint deadline today, AD FS 28 July* Microsoft's July 2026 Patch Tuesday (14–15 July), the largest in the company's history at 622 CVEs, included patches for two actively exploited zero-days. CVE-2026-56164 is a missing-authentication privilege-escalation flaw in on-premises SharePoint Server (versions 2016, 2019, Subscription Edition). Despite a Microsoft CVSS score of 5.3, the National Vulnerability Database independently rated it 9.8. Mandiant discovered it during active incident response. Attackers are chaining it with previously disclosed SharePoint weaknesses to steal IIS machine keys and deploy persistent malware. CISA added CVE-2026-56164 to its Known Exploited Vulnerabilities catalogue on 14 July with a federal remediation deadline of 17 July. CVE-2026-56155 is an insufficient-access-control flaw in Active Directory Federation Services (CVSS 7.8) that allows a low-privileged local user to gain administrator access on a federation server, from which an attacker can forge tokens across the entire federated estate. The CISA deadline for CVE-2026-56155 is 28 July.

India exposureOn-premises SharePoint Server is widely deployed across Indian government ministries, public-sector banks, defence suppliers, and large enterprises. AD FS is the primary federation gateway for hybrid Microsoft environments in BFSI and government. Organisations running SharePoint Online (Microsoft 365) are not affected by CVE-2026-56164 — the risk is concentrated in on-premises deployments.
ActionDeploy Microsoft's July 2026 cumulative updates on all on-premises SharePoint Server instances without delay. Enable AMSI integration on SharePoint and set Request Body Scan mode to Full per CISA's 14 July hardening advisory. Audit IIS machine-key exposure and hunt for persistence before declaring systems clean. Patch AD FS servers before 28 July and review AD FS access logs for low-privilege account anomalies.
SourceBleepingComputer, 14 July 2026; Tenable blog, 14 July 2026; CISA KEV and SharePoint hardening advisory, 14 July 2026; The Hacker News, 16 July 2026.
4

Russian FSB Centre 16 Router Infiltration Campaign Attributed in 13-Nation Advisory — AA26-194A

No CVE (leverages CVE-2018-0171 and weak SNMP) | Nation-state espionage — long-running, global scope* On 13 July 2026, nineteen government agencies from thirteen countries — led by NSA, CISA, FBI, and DC3, with the UK NCSC, Canadian Centre for Cyber Security, Australian Cyber Security Centre, New Zealand NCSC, Czech NÚKIB, and other allied agencies — published joint advisory AA26-194A attributing a decade-long router-compromise campaign to Russian FSB Centre 16 (also tracked as Static Tundra, Berserk Bear, and Ghost Blizzard). The group scans for internet-facing routers running SNMP with default or weak community strings, then abuses the Cisco CISCO-CONFIG-COPY-MIB via SNMP Set-Requests to transfer device configurations to attacker-controlled TFTP servers — establishing persistent network mapping and access. Where Cisco Smart Install remains enabled, the actors exploit that surface directly. Targeted sectors in the advisory include communications, energy, financial services, government, healthcare, and the defence industrial base.

India exposureIndia's telecom, energy, manufacturing, port, BFSI, and public-sector networks depend on distributed router estates, many carrying legacy SNMP configurations that receive less security attention than data-centre servers. The advisory covers all major platforms: Cisco, Juniper, Aruba, Fortinet, Palo Alto Networks, WatchGuard, Barracuda, F5, Sophos, Zscaler, Versa, and VMware VeloCloud.
ActionDisable Cisco Smart Install on every network device. Migrate from SNMPv1/v2 to SNMPv3 with authentication and encryption (authPriv). Restrict SNMP management access to dedicated out-of-band interfaces. Block TFTP on perimeter devices. Audit router configurations for unauthorised community strings and unexpected management-plane exposure.
SourceCISA advisory AA26-194A, 13 July 2026; NSA press release, 13 July 2026; Australian Cyber Security Centre advisory, 14 July 2026.
5

MeitY and CERT-In Flag AI Asymmetry as Systemic Risk in India BFSI Threat Report

No CVE | Policy advisory — 2.9 million cyberattacks on India BFSI in 2025* MeitY, CERT-In, CSIRT-Fin, and SISA released the second edition of the Digital Threat Report 2025-26 for India's BFSI and digital payments ecosystem on 13–14 July 2026. The report records 2.9 million cyberattacks on Indian BFSI institutions in 2025 — a two-fold increase since 2021. The central finding is AI asymmetry: offensive applications of frontier AI models are scaling faster than defensive and regulatory frameworks, compressing the time from threat emergence to exploitation from months to hours. The dominant attack pattern has shifted from direct system compromise to trust-chain manipulation — targeting biometric onboarding, partner APIs, real-time payment rails, and AI-driven decision systems. Six of the seven threat predictions in the previous edition proved accurate.

India exposureIndia's unified payments infrastructure, biometric onboarding pipelines, and BFSI third-party API integrations are identified as the highest-risk surfaces. Controls focused on credential protection and network perimeter hardening remain necessary but insufficient against this attack pattern.
ActionBFSI security teams should map trust dependencies in third-party biometric providers and partner API integrations, review AI model access policies, and test payment-rail anomaly-detection rules against AI-generated transaction patterns. The full report and its 18-month resilience roadmap are available from CERT-In and the Press Information Bureau.
SourcePress Information Bureau, 13–14 July 2026; MediaNama, 15 July 2026; MeitY/CERT-In/CSIRT-Fin/SISA Digital Threat Report 2025-26.
6CriticalCVSS 9.8

Zoom Workplace for Windows Carries Pre-Authentication Account Takeover Flaw — CVE-2026-53412

CVSS 9.8 | No confirmed in-the-wild exploitation — patch before PoC emerges* Zoom patched CVE-2026-53412 on 14 July 2026, a critical improper-input-validation vulnerability in Zoom Workplace for Windows (before version 7.0.0) and Zoom Workplace VDI Client for Windows (before versions 7.0.10, 6.6.15, and 6.5.18). The flaw allows a remote unauthenticated attacker to take over accounts over the network with no victim interaction. No exploitation in the wild had been confirmed at time of disclosure. Zoom's internal offensive security team reported the vulnerability; a corrected advisory issued 15 July removed Zoom Meeting SDK for Windows from the affected product list.

India exposureIndia is among the largest Zoom markets by enterprise and education seat count, with widespread Windows-client deployment across financial services, IT/ITeS, healthcare, and university sectors. A CVSS 9.8 pre-authentication account takeover requiring only network access represents a near-term weaponisation risk once proof-of-concept code is published.
ActionUpdate all Windows Zoom clients to Workplace version 7.0.0 or later, and VDI Client builds to their respective fixed versions, through enterprise endpoint management. Verify that older client versions are not being reinstalled via stale deployment packages. Complete patching before proof-of-concept code is published publicly.
SourceZoom Security Bulletin ZSB-26014, 14–15 July 2026; BleepingComputer, 14 July 2026; The Hacker News, 14 July 2026.

Takeaway

This week's edge-vendor sweep covered Fortinet, Cisco, Palo Alto Networks, Check Point, Juniper, SonicWall, Sophos, Barracuda, WatchGuard, Zscaler, Citrix NetScaler, Ivanti, F5 BIG-IP, Versa, VMware VeloCloud, Aruba/HPE EdgeConnect, and Seqrite/Quick Heal UTM. SonicWall and the Microsoft SharePoint chain are the active exploitation items requiring action before this briefing is filed. The FSB router advisory is a reminder that network hygiene gaps — default SNMP community strings, Cisco Smart Install left enabled, unchanged management-plane exposure — have been providing a decade of reconnaissance access into global critical infrastructure. India's distributed router estate, particularly in energy, telecom, and public sector, warrants the same audit discipline this week. The Kudankulam contractor breach extends the pattern from previous World Leaks incidents: third-party data repositories holding project-level engineering documentation are consistently the softer target and consistently underprotected.

Nirad Threat Research