Weekly Report Period: Week 30, 2026 (2026-07-13 — 2026-07-20) Summary The week's defining event was the joint EU/UK attribution on 2026-07-13 of the December 2025 Poland power grid attack to Russia's FSB Centre 16, accompanied by Council of the EU sanctions on nine individuals and four entities linked to threat clusters including Berserk Bear, Dragonfly, and Energetic Bear [5][11]. Finland's summoning of Russia's ambassador the same day confirmed a coordinated diplomatic response across multiple EU/NATO states [6]. Microsoft's July 2026 Patch Tuesday addressed 570 vulnerabilities including three zero-days, two under active exploitation, alongside CISA's addition of a Cisco IOS flaw (CVE-2008-4128) to its Known Exploited Vulnerabilities catalog [7][8][9]. A claimed but unverified data breach at France's DoinSport platform was posted by an actor linked to Qilin [4]. Patterns and Trends This week shows a shift from isolated technical incidents toward coordinated state-level response, with the Poland grid attribution and simultaneous sanctions package representing the clearest example of diplomatic and technical measures aligning against a named Russian actor. Vulnerability management continued at scale, with Microsoft's 570-flaw patch cycle and parallel CISA/Canadian cyber centre advisories reflecting a pattern of large monthly disclosures requiring rapid organizational response. Supply-chain compromise via CI/CD tooling (GitHub Actions/npm) recurred as an attack vector, consistent with prior periods' reporting on software-ecosystem targeting. Unverified dark-web breach claims (DoinSport) continue to appear alongside confirmed incidents, underscoring the need for source discipline when distinguishing claims from confirmed compromises. Domestic (K1) The period's sole domestic incident of note was a supply-chain attack disclosed by CERT-SE affecting the AsyncAPI GitHub repositories, disclosed 2026-07-14. According to CERT-SE, attackers exploited a vulnerability in GitHub Actions to compromise separate AsyncAPI repositories and pushed malicious versions of several npm packages, including @asyncapi/generator (v3.3.1), @asyncapi/generator-helpers (v1.1.1), @asyncapi/generator-components (v0.7.1), and @asyncapi/specs (v6.11.2) [1]. The malicious packages contained a multi-stage payload designed to establish persistence and connect to command-and-control infrastructure [1]. Admiralty rating A2 — Completely reliable, probably true. No other domestic incidents, breaches, law enforcement actions, or regulatory decisions with named Swedish victims or issuers were reported in the source material this period. Assessment Given that the compromised packages are part of a widely used API-documentation tooling ecosystem, and that the payload establishes persistent C2 connectivity rather than a one-off compromise, it is likely (60-90%) that organizations which integrated the affected package versions before detection retain some residual exposure until dependencies are audited and rotated. Based on a single high-reliability source (A2) with no independent domestic confirmation of downstream impact, confidence in the scope of actual compromise within Swedish organizations remains limited; further reporting from affected package consumers would be needed to assess real-world impact. International (K2/K3) The week's international picture was dominated by formal EU/UK attribution of state-backed cyberattacks on critical infrastructure, coordinated EU sanctions against Russian cyber actors, and a record-setting Microsoft patch cycle addressing hundreds of vulnerabilities across widely deployed software. On 2026-07-13, the UK and EU officially attributed the December 2025 cyberattack on Poland's power grid to Russia's Federal Security Service, specifically the FSB's Centre 16 division. The UK's Foreign, Commonwealth & Development Office described the attack as "another example of the Russian state's irresponsible attempts to sow chaos across Europe," and Poland's energy minister Milosz Motyka confirmed the attack on the country's power infrastructure. The EU and UK jointly demanded urgent action from critical infrastructure organizations following this attribution (C2 — Fairly reliable, Probably true) [5]. The same day, Finland's foreign minister Valtonen summoned Russia's ambassador, condemning "harmful Russian cyber activity," indicating a coordinated diplomatic response across multiple EU/NATO member states (A2 — Completely reliable, Probably true) [6]. This attribution was reinforced on 2026-07-13 when the Council of the EU imposed sanctions on nine individuals and four entities identified as part of Russia's cyber ecosystem, citing responsibility for enabling and facilitating malicious cyber activities against the EU, member states, and partners. Named threat clusters associated with the sanctioned entities include groups tracked as Berserk Bear, Dragonfly, and Energetic Bear (A2 — Completely reliable, Probably true) [11]. Together, the Poland grid attribution and the sanctions package represent a coordinated EU-level response linking a specific infrastructure incident to broader, named threat actor groups. Separately, France saw a claimed data breach affecting the DoinSport platform, posted on dark web forums by an actor associated with the Qilin group; researchers note such claims require independent verification before being treated as confirmed (C2 — Fairly reliable, Probably true) [4]. On the vulnerability management front, Microsoft's July 2026 Patch Tuesday (2026-07-16) addressed 570 flaws, including three zero-days, two of which were under active exploitation and one publicly disclosed. The update covered 59 "Critical" vulnerabilities, 254 of which were elevation-of-privilege issues, and prompted a parallel monthly rollup advisory (AV26-698) from Canada's cyber centre covering .NET, Windows, and other Microsoft products (A2 — Completely reliable, Probably true) [8][9]. CISA separately added CVE-2008-4128, a Cisco IOS cross-site request forgery vulnerability, to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation, triggering remediation obligations under Binding Operational Directive 26-04 for federal agencies (A2 — Completely reliable, Probably true) [7]. Microsoft Edge (Chromium-based) also received fixes for three severe vulnerabilities, including a remote code execution flaw rated CVSS 8. On the regulatory side, the European Commission announced new Digital Markets Act measures forcing Google to share search data and open up AI interoperability on Android, continuing the EU's pattern of enforcement actions against major platforms since 2024 (C2 — Fairly reliable, Probably true) [3]. A Eurobarometer survey published 2026-07-13 found that Europeans want stronger action on children's online safety and disinformation, reflecting public pressure that may inform future EU digital policy (A2 — Completely reliable, Probably true) [2]. Assessment Given that EU/UK attribution of the Poland grid attack to FSB Centre 16 was accompanied by sanctions on named Russian cyber actors within the same reporting period, it is likely (60-90%) that this represents a coordinated diplomatic-technical response rather than isolated actions, and further EU member state statements or measures against Russian-linked infrastructure targeting are likely in the near term. The scale of the July Patch Tuesday release, with active exploitation confirmed for at least two zero-days, makes it very likely (>90%) that unpatched systems across EU and global networks will face exploitation attempts before full patch adoption completes, consistent with historical patterns following large-scale Microsoft update cycles. The DoinSport breach claim remains unverified and should be treated with caution pending confirmation from French authorities or the affected organization. Follow-up Items AsyncAPI npm packages — organizations using @asyncapi/generator (v3.3.1), @asyncapi/generator-helpers (v1.1.1), @asyncapi/generator-components (v0.7.1), or @asyncapi/specs (v6.11. CVE-2008-4128 — Cisco IOS CSRF vulnerability added to CISA's Known Exploited Vulnerabilities catalog; triggers remediation obligations under Binding Operational Directive 26-04 for US federal agencies [7]. Microsoft AV26-698 — Canada's cyber centre monthly rollup advisory covering .NET, Windows, and other Microsoft products from the July 2026 Patch Tuesday cycle; tracks patch adoption status for two actively exploited zero-days [8][9]. EU sanctions package (2026-07-13) — nine individuals and four entities linked to Berserk Bear, Dragonfly, and Energetic Bear now under Council of the EU sanctions; monitor for asset freezes or further designations under this listing [11]. Warning: Automated verification detected multiple potential inaccuracies. Please verify all claims against the original articles. Generated 2026-07-20 04:41 UTC from 11 priority articles (10 cited). [1] cert.se — https://www.cert.se/2026/07/skadliga-npm-paket.html [2] european-union.europa.eu — https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1589 [3] arstechnica.com — https://arstechnica.com/gadgets/2026/07/its-official-eu-will-force-google-to-share-search-data-and-open-up-ai-on-android/ [4] undercodenews.com — https://undercodenews.com/alleged-doinsport-data-breach-raises-privacy-concerns-in-france-dark-web-recent-claims-video/ [5] theregister.co.uk — https://www.theregister.com/security/2026/07/13/uk-eu-officially-pin-poland-energy-cyberattack-on-russia/5270458 [6] svenska.yle.fi — https://yle.fi/a/7-10102080?origin=rss [7] us-cert.gov — https://www.cisa.gov/news-events/alerts/2026/07/13/cisa-adds-one-known-exploited-vulnerability-catalog [8] ncsc.fi — https://www.b [... Report truncated. View full report at link above.]