Approach
Servicehub Login
Approach
/ Industrial Mobility Solutions Rugged devices, printers, robotics, RFID and shared endpoint / Enterprise Mobility Solutions Computers, smartphones, tablets & personal endpoints / Retail Technology Solutions Payment systems, kiosks, mPOS, Contactless, Self-service, BOPIS
Explore by Partner
/ Forward Logistics We excel at finding the right endpoints and lightning-fast deployments for your business. / Cyber Security Inversion6, our sister company, is the ultimate provider of tailored cyber security solutions. / Reverse Logistics We make managing endpoint repairs, replacements and disposals a breeze. / Maintenance & Support We're your one-stop shop, dedicated to keeping your endpoints at full throttle. / Networking Services Our networking services for your wired, wireless and surveillance environments are second to none. / Unified Endpoint Management Greater numbers of BYOD, COPE and IoT devices are pushing enterprise mobility programs to the limit. / Media & Consumables Our expertise is unmatched when it comes to label materials and adhesives. / Automation & Robotics Helping your business run smarter and faster with custom automation, RFID, and IoT.
/ Payments From procurement and deployment to repair and reverse logistics, we keep ISOs, ISVs and merchants running. / White Labeling Services TRG will serve as an extension of your internal team, ensuring customer satisfaction and loyalty. / ServiceHub® Our online asset management portal, ServiceHub®, provides endpoint analytics across devices.
Explore all services/Explore all services
/ About Our mission is to lead the future of enterprise technology. / Team Learn more about the TRG team and contact individual team members. / Locations Get more information on each TRG location across the globe. / Careers & Culture From a golf simulator and basketball court to a fully-equipped gym to keep you energized, we have it all.
/ Manufacturing We streamline production environments with end-to-end technology solutions that reduce downtime, boost efficiency and keep your operations running at peak performance. / Service Providers From managed IT to field service teams, we equip service providers with the tools and infrastructure needed to deliver faster, more reliable outcomes for their clients. / Hospitality We help hotels, resorts, and restaurants deliver seamless guest experiences through reliable technology, secure networks and responsive support. / Transportation & Logistics Our solutions keep fleets connected, warehouses optimized and supply chains moving with real-time visibility and rugged, purpose-built technology. / Retail We power retail operations with point-of-sale systems, mobile devices and networking solutions designed to enhance the in-store and omnichannel customer experience. / Government We support government agencies with secure, compliant technology solutions that improve citizen services and simplify IT management across departments. / Education From classrooms to campuses, we provide schools and universities with the devices, networking and support they need to create connected learning environments. / Healthcare We deliver HIPAA-conscious technology solutions that help healthcare providers improve patient care, streamline clinical workflows and protect sensitive data.

/ Select Your Language

English (US) English (UK) French Canadian Polish Spanish Dutch
/ Insights & Events Blog News Case Studies eBooks Events Newsletter
/ Partners How to Partner With Us Google Zebra Honeywell SOTI Samsung Elo Panasonic PAX Brother
ServiceHub
Weekly Brief

TRG Cyber Intelligence Brief

A weekly read on the vulnerabilities, breaches and policy moves shaping the threat landscape.

Issue 07 14 July 2026 Prepared by TRG Solutions, Cyber Security Division
Critical
100,000+
Internet-exposed UniFi OS instances at risk from a single maximum-severity flaw

Ubiquiti ships emergency fixes for a maximum-severity UniFi OS flaw

Seven severe vulnerabilities patched across the UniFi OS ecosystem. The worst, CVE-2026-50746, lets an attacker with network access run arbitrary commands on the host device. No confirmed exploitation yet, but Censys counts over 100,000 exposed instances worldwide, roughly 50,000 of them in the US. Patch this one first.

Critical
Critical

Ubiquiti Warns of Max-Severity UniFi OS Vulnerability

Max severity
CVE-2026-50746Improper access control

Ubiquiti has released critical updates fixing seven severe vulnerabilities across UniFi OS. An attacker with network access can exploit CVE-2026-50746 to execute arbitrary commands on the host device. No confirmed in-the-wild exploitation yet, but Censys puts the exposed attack surface at over 100,000 internet-facing UniFi OS instances, about 50,000 of them in the US.

Critical

Pre-Auth Bypass in BeyondTrust Remote Access Tools

CVE-2026-40138CVE-2026-40139 CVSS 9.2

BeyondTrust has patched four vulnerabilities in its Remote Support and Privileged Remote Access on-premise appliances. Two let a remote, unauthenticated attacker bypass authentication entirely, including access to privileged accounts, contingent on a specific non-default configuration being enabled. RS and PRA sit behind remote support and privileged access for thousands of downstream MSP and ITSP client environments, so the blast radius extends well past the vendor itself.

Actively exploited

Citrix Bleed 2: Anubis Ransomware Actively Exploiting NetScaler

CVE-2025-5777 CVSS 9.3

"Citrix Bleed 2" is a critical authentication bypass in Citrix NetScaler ADC and Gateway, and it's under active exploitation. The out-of-bounds read flaw lets an unauthenticated attacker pull sensitive memory contents, including session tokens, off affected devices. Hijacked sessions bypass MFA and hand attackers initial network access.

Critical

WatchGuard Patches Critical RCE in Fireware OS and Mobile VPN Client

CVE-2026-13368 CVSS 9.2 Patched 2 Jul 2026

A race condition leading to use-after-free in IKEv2 LDAP authentication lets a remote, unauthenticated attacker execute arbitrary code on the firewall, provided Mobile VPN with IKEv2 is configured against an external LDAP server. A second, lower-severity flaw allows local privilege escalation on endpoints.

Of Interest
Breach

Accenture Confirms Fresh Breach

Accenture has confirmed a security breach after internal documents surfaced on a hacking forum. The intrusion reportedly took place this month and is attributed to the same actor who sold a separate batch of Accenture data in 2024.

Research

Windows GDID Reverse-Engineered

A Ubisoft engineer has reverse-engineered Microsoft's Windows Global Device Identifier, the per-install, per-account ID embedded in Windows telemetry. It's not new, similar identifiers have existed under other names for years, but it drew fresh attention after playing a role in tracking a member of Scattered Spider.

Sentencing

764 Offshoot Leader Sentenced to 40 Years

A 19-year-old San Antonio man who led 8884, an offshoot of the violent extremist collective 764, was sentenced to 40 years in prison for sexually exploiting children through coercion, blackmail and extortion. He had been associating with 764 since 2022.

EU / UK / Five Eyes Activity
Policy

ECB Orders Banks to Plan for AI Cyberattacks

The European Central Bank has told EU banks and financial institutions to draw up plans against AI-based cyberattacks, with internet-facing systems the stated priority: retire old technology, tighten cyber hygiene, and harden crisis management and recovery. Banks have four months to submit plans. Alongside it, the EU has published a nine-step action plan to help organizations shore up AI and cybersecurity posture together.

Enforcement

Four Member States Referred Over NIS2

The European Commission has referred Ireland, Spain, France and the Netherlands to the Court of Justice of the EU for failing to notify measures transposing the NIS2 Directive (EU 2022/2555) into national law. The transposition deadline was 17 October 2024.

UK

UK Stands Up "Cyber Shield"

The UK government is building a national, AI-powered cyber-defense capability. Cyber Shield will use agentic AI tools to hunt weaknesses and help defend critical infrastructure, built jointly by the National Cyber Security Centre and the Department for Science.

Canada

CSE Goes on the Offensive

Canada's Communications Security Establishment worked with Five Eyes partners and law enforcement to disable a notorious Ransomware-as-a-Service group's infrastructure and delete stolen data listed for sale on the dark web. CSE separately used its foreign intelligence capability to trace brokers moving fentanyl precursor chemicals into Canada, then ran cyber operations to disrupt their trade. A third operation used SIGINT against a foreign extremist group recruiting Canadians, which CSE says undermined the group's credibility and limited recruitment.

US

NSA Revives Tailored Access Operations

The NSA has renamed its elite hacking unit back to Tailored Access Operations, its original name before a 2016 reorganization folded it into the Office of Computer Network Operations. TAO built Stuxnet and the toolset later leaked by the Shadow Brokers.

Software Supply Chain: GitHub Under Attack

GitHub is taking hits from several directions at once this week.

Malware

222-Repo Malware Network Uncovered

Researchers pivoted from a single malicious Go module to a network of 222 GitHub repositories hosting tools laced with malware.

Abuse

GitHub API Abused for Account Enumeration

Multiple threat actors are abusing the GitHub API to enumerate corporate accounts, working from aged ghost accounts or compromised tokens belonging to legitimate users. The activity lists an organization's repositories, fetches commits, and probes private repository paths.

New attack

"GitLost" Prompt Injection Targets Private Repos

A new attack called GitLost abuses GitHub's Agentic Workflows feature to steal data from private repositories. It works by planting crafted data inside an issue on a public repo belonging to the same organization as the target private repo.

Outlook

Microsoft Expects More Patches as AI Enters the Pipeline

Microsoft says it expects patch volume to keep growing as AI gets folded into vulnerability discovery and code-testing processes company-wide.

And Finally
Regulation

Cars Get Mandatory Driver-Facing Cameras

Every new car sold in the EU, and in the US from next year, will need an infrared camera trained on the driver's face, tracking head position and eye movement to flag distraction. Privacy groups aren't thrilled. The requirement took effect in the EU this week under the bloc's second General Safety Regulation, GSR2.

Prepared by TRG Solutions, Cyber Security Division. For distribution to clients and partners.

My favorite websites

Recent posts

No recent posts
ServiceHub Login Contact TRG
Solutions
Enterprise Mobility Solutions Industrial Mobility Solutions Retail Technology Solutions
Services Forward Logistics Reverse Logistics Maintenance & Support Unified Endpoint Management Cyber Security Financing & Leasing Channel & White Label ServiceHub Media & Consumables Networking Services
Industries
Retail Transportation & Logistics Manufacturing Hospitality Service Providers Government Education Healthcare
About Our Approach Our Team Our Locations Careers at TRG TRG Mergers and Acquistions
Insights & Events News Blog Case Studies eBooks Events Newsletter
Terms & Conditions Privacy Notice Return Policy
©2026 TRG All Rights Reserved
Enterprise Mobility SolutionsIndustrial Mobility SolutionsRetail Technology Solutions
Forward LogisticsReverse LogisticsMaintenance & SupportUnified Endpoint ManagementCyber SecurityFinancing & LeasingChannel & White LabelServiceHubMedia & ConsumablesNetworking Services
RetailTransportation & LogisticsManufacturingHospitalityService ProvidersGovernmentEducationHealthcare
Our ApproachOur TeamOur LocationsCareers at TRGTRG Mergers and Acquistions
NewsBlogCase StudieseBooksEventsNewsletter
Terms & Conditions Privacy Notice Return Policy
©2026 TRG All Rights Reserved