Vulnerability Watch
Deep-dives on CVEs, SCADA/ICS, and the infrastructure everyone forgets is still running.

WSUS sync fix only for new installs, old servers still stuck
WSUS servers on Windows Server 2012+ have failed to sync since roughly July 13. Microsoft's July 18 mitigation restores fresh installs; older ones wait on a metadata cleanup step.

Microsoft ships KB5121767 OOB for Dell IPF driver hold
Microsoft shipped KB5121767 on 2026-07-20 to patch the Intel IPF driver incompatibility stranding a subset of Dell PCs off July's Windows 11 security update.

SleeperGem loader hides in dormant RubyGems, skips CI/CD
StepSecurity: three RubyGems, two dormant since 2018-2020, ship a Forgejo-hosted loader that fingerprints CI runners and skips them before dropping a daemon.

Microsoft ties ACR Stealer surge to WebDAV, blockchain C2
Microsoft's July 16 writeup links a late-April through mid-June ACR Stealer surge to WebDAV-hosted payloads and a blockchain dead-drop for C2 updates.

Seven Vite-adjacent npm packages route a RAT through Tron
Checkmarx flagged a fresh cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem. Codenamed ViteVenom, they route through a four-tier blockchain C2 including Tron to drop a RAT.

Windows 11 24H2 Home and Pro: 90 days to end of updates
Microsoft has set October 13, 2026 as the last patch day for Windows 11 24H2 Home and Pro. Enterprise and Education get one more year — the usual split.

PhantomEnigma rides Brazilian .gov.br sites and mailboxes
ANY.RUN links a Brazilian banking crimeware operation to 20+ hijacked .gov.br sites and mailboxes, using signature-valid mail and trusted redirects.

Daxin resurfaces in Taiwan alongside new Stupig backdoor
Symantec finds the Daxin kernel rootkit resurfacing at a Taiwan manufacturer, alongside a previously unreported pre-login SYSTEM backdoor called Stupig.

Cursor: opening a repo runs its git.exe. No patch, 7 months.
Mindgard disclosed a Cursor zero-day July 14 after seven months without a fix. Opening a repo with a git.exe file runs it as you. Windows only. No patch.

KB5099539 lands: Windows 10 ESU carries the July zero-days
Microsoft's KB5099539 delivers July's Patch Tuesday to Windows 10 22H2 and LTSC 2021 fleets, including two exploited zero-days. Enrollment required.

Trend Micro: bandcampro ran a C2 botnet on Gemini CLI
Trend Micro logs 200+ Gemini CLI sessions from a Russian-speaking actor tracked as bandcampro: C2 migration, credential work, and daily botnet ops.

KNX account-lockout flaw added to CISA KEV, three years on
CVE-2023-4346 turns the KNX Association's account-lockout mechanism into a device-purge weapon on a building-automation bus. CISA added it to KEV under BOD 26-04.

Zyxel CVE-2023-28771: EPSS 0.99 three years after the patch
Zyxel's 2023 firewall command-injection bug still ranks EPSS 0.99 three years post-patch. Scans stay constant; unpatched SMB perimeter boxes remain plentiful.

Mindgard: Cursor still runs git.exe from repo root
Aaron Portnoy's Mindgard team went public today: Cursor 3.11 on Windows executes any git.exe sitting in a cloned repo's root — seven months, no patch.

Spain Dismantles €140M BEC Ring; 800 Accounts, 67 Mules
Spanish National Police dismantle a €140M BEC and investment fraud network using 800 bank accounts, 120 companies, and 67 mules; four arrested across three countries.

KU Leuven: 85 wallet extensions leak addresses cross-site
KU Leuven's DistriNet tested 85 Chrome crypto wallet extensions with ~35M installs. 17 link separate addresses in a single request. 22 of 36 ignore site disconnects.

ESET: 11 old signed UEFI shims still bypass Secure Boot
ESET's Martin Smolár found 11 old Microsoft-signed UEFI shims that still bypass Secure Boot — CVE-2026-8863, revoked via the June DBX update.

148 npm packages ran a browser-based DDoS botnet in May
JFrog: 148 npm packages hosted a fake student web proxy that turned visiting browsers into a DDoS botnet for about two weeks in May. Not a supply-chain attack.

Jscrambler: four npm versions hit, publish creds revoked
Jscrambler's post-incident report widens its July 11 npm compromise from one release to four (8.14, 8.16, 8.17, 8.20). 8.22 clean; publish creds revoked.

NCA charges five over Russian Coms spoofing platform
The NCA charged five London residents over Russian Coms — a caller-ID spoofing platform behind 1.8M scam calls and 170,000 victims. Westminster court date Aug 14.

MemGhost: an email that rewrites an AI agent's memory
arXiv paper: one crafted email talks a memory-enabled AI agent into writing attacker-supplied 'facts' into its memory files. Future sessions load them.

Seven years on, CVE-2018-0171 draws a 13-state advisory
US, UK, and eleven allied governments co-signed a July 13 advisory naming FSB Centre 16 as the actor still pulling configs off end-of-life Cisco routers via CVE-2018-0171.
281 free Android VPN apps: 29 leak, 246 track
MVPNalyzer, a University of Michigan / UNM / IIT Delhi tool presented at NDSS 2026, ran 281 top free Android VPN apps and found leaks, plaintext, and trackers.

PTC Windchill PLM RCE is on KEV — shells still landing
PTC Windchill PDMLink and FlexPLM ship an unauth deserialization RCE. CISA added it to KEV on 2026-06-25. Unpatched instances are still catching JSP webshells.

Six U-Boot flaws trace to one libfdt helper
Binarly disclosed six bugs in U-Boot's FIT-image parsing on July 9 — two potential RCE, four DoS — all tracing to unchecked libfdt calls present since 2013.07.

Metasploit Weekly Adds Flowise CSV, macOS PackageKit
Rapid7's Metasploit weekly drops two modules — a Flowise CSV Agent prompt-injection RCE and a macOS PackageKit LPE. New tooling, not new bugs.

npm 12 turns install scripts off by default
npm 12 defaults allowScripts to off and deprecates 2FA-bypass tokens. Closes the install-hook branch; does not touch the maintainer-account one.

Talos discloses 18 vulns in WolfSSL, GeoVision, VTK-DICOM
Cisco Talos published a bulk third-party disclosure covering 3 WolfSSL, 14 GeoVision, and 1 VTK-DICOM vulnerabilities — all patched before publication.

Infoblox: Lurking Lizard runs 230-domain fake 7-Zip proxy
Infoblox ties a China-based residential-proxy operator to 230+ lookalike domains active since 2022, seeding fake 7-Zip and WireVPN installers.

Socket: 17 fake Paysafe, Skrill, Neteller SDKs on npm and PyPI
Socket disclosed 17 malicious packages posing as Paysafe, Skrill, and Neteller SDKs across npm and PyPI. Payload steals payment API keys, AWS keys, and GitHub/npm tokens.

HalluSquatting weaponizes AI-hallucinated npm packages
Tel Aviv researchers register the fake package names AI coding assistants keep inventing. Up to 100% hit rate on skill installs, no confirmed exploitation yet.

Ubiquiti Patches Max-Severity UniFi Connect Command Injection
Ubiquiti Bulletin 066 patches seven critical UniFi flaws, headlined by a CVSS 10.0 command injection in UniFi Connect 3.4.16 and earlier. Fix: 3.4.20 or later.

Januscape (CVE-2026-53359): 16-year KVM guest-to-host escape
A 16-year-old use-after-free in KVM's shadow MMU lets a guest VM panic — or, with an unreleased exploit, root — the host on Intel and AMD. Patched June 19.

TrojPix: air-gap exfil via video-cable RF emanation
Shandong University researchers show a covert-channel technique that turns invisible pixel changes into a radio signal a nearby receiver can decode from the display cable itself.

Four More Rollup Polyfill Typosquats Surface
JFrog's disclosure names six npm packages in the Rollup polyfill typosquat cluster, not two. The extra four sit inside the same infrastructure the earlier reporting described, and the audit surface hasn't moved.

Armored Likho Ties BusySnake to Power-Sector Spying
Kaspersky attributes a previously undocumented threat actor, Armored Likho, to a campaign hitting government agencies and the electric power sector across Russia, Brazil, and Kazakhstan using the BusySnake stealer.

ConsentFix + ClickFix: M365 Grants Outlive Resets
BleepingComputer covered two M365 hijack patterns and Opera's Paste Protect defense this week. The clipboard lane can be closed. The OAuth grant substrate underneath is unchanged.

runZero Discloses Seven FatFs Firmware Flaws
runZero disclosed seven vulnerabilities in FatFs, a small filesystem library shipped inside ESP-IDF, STM32Cube, Zephyr, MicroPython, and other embedded stacks. Only one has an upstream fix.

Unpatched Argo CD Flaw Lets Unauth Cluster Takeover
Synacktiv disclosed an unpatched code-execution flaw in Argo CD's repo-server component. No fix, no CVE. Reachability of the internal port is the whole game.



