Skip to content
feed: live
>_ 0dayNews
Vendor

Threat Intel & Field Notes

Coverage that doesn't reduce to a single vendor advisory: infostealer and RAT write-ups, threat-actor campaigns and infrastructure takedowns, tooling roundups, and industry analysis on where security practice is falling behind.

Articles
~/articles/2026-07-21-signature-was-there-trust-wasnt-week-retrospective
The signature was there. The trust wasn't.
Analysis
threat intel

The signature was there. The trust wasn't.

DigiCert's EV certs, WebEx and Zoom installers, ViPNet's signed updater. Three subverted trust chains this week, one design assumption behind them.

read →
~/articles/2026-07-21-mythos-three-months-exposure-window-triage-playbook
Mythos at three months: measure exposure, not volume
Analysis
threat intel

Mythos at three months: measure exposure, not volume

Three months after Anthropic's Mythos disclosure, the industry is still arguing about CVE queue depth. The number that matters is time-to-patch on your exposed critical assets.

read →
~/articles/2026-07-21-ai-agent-sandboxes-only-as-tight-as-host-tools
AI-agent sandboxes are only as tight as the host tools
Analysis
threat intel

AI-agent sandboxes are only as tight as the host tools

Pillar walked the same escape out of Cursor, Codex, Gemini CLI, and Antigravity in one week. The pattern isn't new — the trusted host tool is.

read →
~/articles/2026-07-20-ostium-arbitrum-off-chain-oracle-forgery-23-75m-lp-vault-drain
Ostium's LP vault down $23.75M after oracle-feed forgery
threat intel

Ostium's LP vault down $23.75M after oracle-feed forgery

Attackers compromised off-chain price signing for Ostium's Arbitrum perpetuals DEX, submitted forged price attestations, and drained $23.75M from the LP vault.

read →
~/articles/2026-07-20-pillar-week-sandbox-escapes-cursor-codex-gemini-cli-antigravity
Cursor, Codex, Gemini CLI, Antigravity: sandbox escapes
threat intel

Cursor, Codex, Gemini CLI, Antigravity: sandbox escapes

Pillar Security walks the same file out of the sandbox in four AI coding agents — each time by getting a trusted host tool to run what the agent wrote.

read →
~/articles/2026-07-20-group-ib-hollowgraph-m365-calendar-events-2050-c2-dead-drop
HollowGraph hides M365 C2 in calendar events dated 2050
threat intel

HollowGraph hides M365 C2 in calendar events dated 2050

Group-IB's HollowGraph hides M365 command-and-control in calendar events dated 2050-05-13, moving tasking and stolen files through legitimate Graph API traffic.

read →
~/articles/2026-07-20-rapid7-exposed-webdav-lab-1048-artifacts-mexico-curp-victims
Exposed WebDAV lab: 1,048 artifacts, real Mexico victims
● Breaking
threat intel

Exposed WebDAV lab: 1,048 artifacts, real Mexico victims

Rapid7 found an exposed WebDAV server with 1,048 attacker artifacts — QA'd lures, three tested CVEs, and 2,384 confirmed launch hits against Mexican targets.

read →
~/articles/2026-07-20-trend-micro-bandcampro-gemini-cli-c2-dental-clinic-eight-node-botnet
Trend Micro: 'bandcampro' ran botnet ops through Gemini CLI
● Breaking
threat intel

Trend Micro: 'bandcampro' ran botnet ops through Gemini CLI

Trend Micro forensicated 200 Google Gemini CLI sessions used by a lone Russian-speaking actor to run an eight-node dental-clinic botnet through natural-language prompts.

read →
~/articles/2026-07-20-hugging-face-autonomous-ai-agent-breach-internal-datasets
Hugging Face confirms breach by autonomous AI agent
● Breaking
threat intel

Hugging Face confirms breach by autonomous AI agent

Hugging Face disclosed unauthorized access to internal datasets and service credentials by an autonomous agent framework that ran thousands of sandboxed actions across a weekend.

read →
~/articles/2026-07-19-nginx-cve-2026-42533-map-regex-heap-overflow-worker-patch
nginx patches heap overflow in worker (CVE-2026-42533)
threat intel

nginx patches heap overflow in worker (CVE-2026-42533)

F5 shipped nginx 1.30.4/1.31.3 and NGINX Plus 37.0.3.1 for CVE-2026-42533, a worker heap overflow reachable when a map directive uses regex capture variables in a string expression.

read →
~/articles/2026-07-19-cert-ua-uac-0145-sandworm-clickfix-ukraine
CERT-UA: UAC-0145 (Sandworm) runs ClickFix on Ukraine
threat intel

CERT-UA: UAC-0145 (Sandworm) runs ClickFix on Ukraine

CERT-UA alert 6318437 attributes a June–July ClickFix campaign hitting at least 10 compromised Ukrainian sites to UAC-0145, a Sandworm sub-cluster tied to GRU.

read →
~/articles/2026-07-19-kaspersky-hellonet-vipnet-updater-dll-sideload-russian-orgs
Kaspersky details HelloNet abuse of ViPNet updater
Analysis
threat intel

Kaspersky details HelloNet abuse of ViPNet updater

Kaspersky says an unknown APT — low-confidence Chinese ties — has abused the InfoTeCS ViPNet update client to plant Russian orgs since May.

read →
~/articles/2026-07-19-metasploit-weekly-http-smb-relay-riscv-fetch-payloads
Metasploit adds HTTP-to-SMB NTLM relay, RISC-V payloads
threat intel

Metasploit adds HTTP-to-SMB NTLM relay, RISC-V payloads

Rapid7's July 17 Metasploit wrap-up ships a Windows HTTP-to-SMB NTLM relay module, RISC-V shell payloads, and 421 new fetch-style variants. Check SMB signing tonight.

read →
~/articles/2026-07-18-microsoft-acr-stealer-april-june-webdav-etherhiding
Microsoft ties ACR Stealer surge to WebDAV, blockchain C2
threat intel

Microsoft ties ACR Stealer surge to WebDAV, blockchain C2

Microsoft's July 16 writeup links a late-April through mid-June ACR Stealer surge to WebDAV-hosted payloads and a blockchain dead-drop for C2 updates.

read →
~/articles/2026-07-18-doj-chen-zhang-queens-brooklyn-43m-investment-fraud-laundering-140-accounts-45-shells
Two indicted over $43M laundered from investment scams
threat intel

Two indicted over $43M laundered from investment scams

DOJ charged two New York-based Chinese nationals with laundering $43M in investment-fraud proceeds through 140 bank accounts and roughly 45 shell companies.

read →
~/articles/2026-07-18-okta-hollowbyte-openssl-dos-june-silent-fix
HollowByte: 11-byte OpenSSL DoS, no CVE, silent June fix
threat intel

HollowByte: 11-byte OpenSSL DoS, no CVE, silent June fix

Okta's Red Team named 'HollowByte' — an OpenSSL DoS where 11 bytes of TLS pull 131 KB of process memory per shot. OpenSSL patched it in June with no CVE.

read →
~/articles/2026-07-18-choi-lee-seoul-uiuc-adi-agent-data-injection-web-coding-agents
Agent Data Injection: The Bug Under Every AI Agent
Analysis
threat intel

Agent Data Injection: The Bug Under Every AI Agent

Seoul National / UIUC / Largosoft research shows web and coding agents get steered by planted content in the pages, comments, and reviews they consume. Fix the trust boundary, not the model.

read →
~/articles/2026-07-17-flare-2889-underground-posts-clean-residential-proxies-post-netnut
Flare finds carders still hunting clean IPs post-NetNut
Analysis
threat intel

Flare finds carders still hunting clean IPs post-NetNut

Flare's read of 2,889 underground posts finds carders scrambling for 'clean' residential IPs two weeks after the FBI's NetNut seizure disrupted supply.

read →
~/articles/2026-07-17-ernst-young-third-party-support-ticket-breach-mar-apr-window
EY discloses breach via third-party IT ticket system
threat intel

EY discloses breach via third-party IT ticket system

Ernst & Young says an unauthorized party accessed a third-party support ticket platform used by its IT staff between March 28 and April 12. Detection followed on April 23; disclosure landed July 17.

read →
~/articles/2026-07-17-armenia-detains-ermakov-yerevan-revil-warrant-identity-dispute
Armenia detains Aleksandr Ermakov on US REvil warrant
threat intel

Armenia detains Aleksandr Ermakov on US REvil warrant

Russian tourist Aleksandr Ermakov has been held in Yerevan since 2026-06-28 on a US extradition request for a REvil suspect of the same name. His lawyer says the paperwork carries no patronymic.

read →
~/articles/2026-07-17-elastic-ottercookie-svg-flag-steganography-ai-tool-configs
OtterCookie's fake interview now steals AI-tool configs
Analysis
threat intel

OtterCookie's fake interview now steals AI-tool configs

Elastic Security Labs catches the DPRK's Contagious Interview crew hiding a four-stage payload in SVG country flag files — and the new file stealer specifically hunts .claude, .cursor, .gemini, and .windsurf configs.

read →
~/articles/2026-07-17-kaspersky-goserpent-go-rat-tetrisphantom-overlap-apac-diplomatic
GoSerpent: Go RAT hits APAC gov, TetrisPhantom overlap
threat intel

GoSerpent: Go RAT hits APAC gov, TetrisPhantom overlap

Kaspersky documents GoSerpent, a Go-based RAT hitting Southeast Asian government and diplomatic entities since late 2025. Operational overlap with TetrisPhantom.

read →
~/articles/2026-07-17-microsoft-defender-experts-acr-stealer-clickfix-run-box-paste-and-run
ACR Stealer, ClickFix, and why the Run box still works
Analysis
threat intel

ACR Stealer, ClickFix, and why the Run box still works

Microsoft's Defender Experts detailed two ACR Stealer chains Thursday. Both start with a Run-dialog paste — and walk out with browser tokens and M365 files.

read →
~/articles/2026-07-17-doj-chen-zhang-43m-money-laundering-140-accounts-45-shells
The plumbing behind $43M in investment-fraud losses
Analysis
threat intel

The plumbing behind $43M in investment-fraud losses

DOJ charges two in a New York-based network that laundered at least $43 million from pig-butchering-style investment scams through ~140 accounts.

read →
~/articles/2026-07-16-talos-uat-11795-starland-rat-wldr-c2-trojanized-installers
UAT-11795 hides Starland RAT in trojanized installers
threat intel

UAT-11795 hides Starland RAT in trojanized installers

Cisco Talos names UAT-11795 — a financially motivated Russian actor pushing Starland RAT and bespoke WLDR C2 via trojanized WebEx, Zoom, MobaXterm installers.

read →
~/articles/2026-07-16-sans-stephen-sims-bugcrowd-ai-triage-proof-standard
AI can find the bug. Proving it is still the job.
Analysis
threat intel

AI can find the bug. Proving it is still the job.

SANS Fellow Stephen Sims argues the noise-to-signal ratio in bug bounty has shifted, but the proof-of-exploit standard hasn't — Bugcrowd's own policy shift agrees.

read →
~/articles/2026-07-16-elastic-telepuz-clickfix-maas-vidar-stage-two
Elastic: TELEPUZ ClickFix stealer confirmed since April
threat intel

Elastic: TELEPUZ ClickFix stealer confirmed since April

Elastic Security Labs pins TELEPUZ, a modular C stealer spreading via ClickFix since late April, likely MaaS, with a Go Vidar variant as stage two.

read →
~/articles/2026-07-16-agent-data-injection-choi-snu-uiuc-probabilistic-delimiter
Agent Data Injection: SQL injection, different decade
Analysis
threat intel

Agent Data Injection: SQL injection, different decade

Seoul National, UIUC, and Largosoft show AI agents misread punctuation in trusted data as structural delimiters. No CVE, no vendor fix planned.

read →
~/articles/2026-07-16-group-ib-clicklock-macos-clickfix-launchagent-210ms-loop
ClickLock macOS stealer kills apps until user types password
threat intel

ClickLock macOS stealer kills apps until user types password

Group-IB documents ClickLock, a macOS stealer delivered via ClickFix that kills Finder, Dock, and browsers on a 210ms loop until the victim types their login password.

read →
~/articles/2026-07-16-anyrun-phantomenigma-brazil-gov-br-hijack-dmarc-inno-node
PhantomEnigma rides Brazilian .gov.br sites and mailboxes
threat intel

PhantomEnigma rides Brazilian .gov.br sites and mailboxes

ANY.RUN links a Brazilian banking crimeware operation to 20+ hijacked .gov.br sites and mailboxes, using signature-valid mail and trusted redirects.

read →
~/articles/2026-07-16-rapid7-attackerkb-public-sunset-august-18-curation
AttackerKB's public tier closes August 18
Analysis
threat intel

AttackerKB's public tier closes August 18

Rapid7 retires the public AttackerKB site and its open submissions on August 18. Analysis, writeups, and API access move behind curation and a customer login.

read →
~/articles/2026-07-16-23andme-chrome-holding-18m-43-state-ag-settlement-2023-breach
23andMe settles genetics breach: $18M, 43 states
threat intel

23andMe settles genetics breach: $18M, 43 states

Multistate AG coalition led by New York's Letitia James. Settlement resolves claims over the 2023 credential-stuffing breach that exposed 6.9M customers' genetic profiles.

read →
~/articles/2026-07-16-daxin-srt64-stupig-winlogon-taiwan-digiwin-jdk
Daxin resurfaces in Taiwan alongside new Stupig backdoor
threat intel

Daxin resurfaces in Taiwan alongside new Stupig backdoor

Symantec finds the Daxin kernel rootkit resurfacing at a Taiwan manufacturer, alongside a previously unreported pre-login SYSTEM backdoor called Stupig.

read →
~/articles/2026-07-16-scattered-spider-tfl-jubair-flowers-nca-cma-sentence
Two Scattered Spider affiliates get 5.5 years for TfL hack
threat intel

Two Scattered Spider affiliates get 5.5 years for TfL hack

Thalha Jubair, 20, and Owen Flowers, 18, pleaded guilty under the UK Computer Misuse Act. The 2024 intrusion knocked out 148 TfL systems and cost £29 million.

read →
~/articles/2026-07-16-sharkninja-tokay0-aws-iot-cert-region-root-no-patch
Unpatched Shark vacuums: regional root, no CVE, no patch
threat intel

Unpatched Shark vacuums: regional root, no CVE, no patch

tokay0 published a Shark robot vacuum flaw July 13: over-permissive AWS IoT device cert grants root on any other Shark in the same region. No patch.

read →
~/articles/2026-07-16-openai-gpt-red-internal-red-teamer-prompt-injection
OpenAI discloses GPT-Red, its internal automated red-teamer
threat intel

OpenAI discloses GPT-Red, its internal automated red-teamer

OpenAI describes GPT-Red, an internal automated red-teamer that scales prompt injection discovery and adversarially trains later models against those attacks.

read →
~/articles/2026-07-16-intruder-vending-machine-llm-code-slicing-wordpress-zero-day
Intruder ships an LLM vuln-discovery product, plus a 0-day
Analysis
threat intel

Intruder ships an LLM vuln-discovery product, plus a 0-day

Intruder shipped an LLM code-slicing pipeline that turned up a WordPress plugin zero-day, plus more bugs still under responsible disclosure.

read →
~/articles/2026-07-15-dutch-politie-100m-investment-fraud-20-call-centers-700-shills
Dutch bust €100M fraud ring, 20 call centers, 700 shills
threat intel

Dutch bust €100M fraud ring, 20 call centers, 700 shills

Dutch Politie takedown of a 2021-active investment-fraud ring — 20 call centers, ~700 fake advisers, five-country arrests, €100M+ estimated peak monthly.

read →
~/articles/2026-07-15-unit-42-tuxbot-v3-llm-chain-of-thought-iot-botnet
Unit 42: TuxBot v3 shipped LLM chain-of-thought in comments
threat intel

Unit 42: TuxBot v3 shipped LLM chain-of-thought in comments

Palo Alto Unit 42 documents TuxBot v3, an IoT botnet whose developer left an AI safety disclaimer and raw reasoning traces in the shipped binary.

read →
~/articles/2026-07-15-trend-micro-bandcampro-gemini-cli-c2-botnet-operator
Trend Micro: bandcampro ran a C2 botnet on Gemini CLI
threat intel

Trend Micro: bandcampro ran a C2 botnet on Gemini CLI

Trend Micro logs 200+ Gemini CLI sessions from a Russian-speaking actor tracked as bandcampro: C2 migration, credential work, and daily botnet ops.

read →
~/articles/2026-07-15-kaspersky-okobot-seedhunter-ledger-trezor-electron-hook
Kaspersky: OkoBot phishes seeds inside Ledger, Trezor apps
threat intel

Kaspersky: OkoBot phishes seeds inside Ledger, Trezor apps

Kaspersky's GReAT team says OkoBot has hooked Electron in Ledger and Trezor apps since April 2025 to draw a fake seed-phrase prompt inside the real wallet UI.

read →
~/articles/2026-07-15-mindgard-cursor-git-exe-workspace-root-no-patch
Mindgard: Cursor still runs git.exe from repo root
threat intel

Mindgard: Cursor still runs git.exe from repo root

Aaron Portnoy's Mindgard team went public today: Cursor 3.11 on Windows executes any git.exe sitting in a cloned repo's root — seven months, no patch.

read →
~/articles/2026-07-15-reliaquest-jalisco-omegalord-m365-device-code-mfa-bypass
Jalisco kit auto-refreshes M365 device codes on demand
threat intel

Jalisco kit auto-refreshes M365 device codes on demand

ReliaQuest maps two new M365 phishing kits: Jalisco auto-refreshes OAuth device codes to defeat the 15-min window, OmegaLord harvests phones for MFA bypass.

read →
~/articles/2026-07-15-spain-140m-bec-fraud-ring-800-accounts-67-mules
Spain Dismantles €140M BEC Ring; 800 Accounts, 67 Mules
threat intel

Spain Dismantles €140M BEC Ring; 800 Accounts, 67 Mules

Spanish National Police dismantle a €140M BEC and investment fraud network using 800 bank accounts, 120 companies, and 67 mules; four arrested across three countries.

read →
~/articles/2026-07-15-lastpass-bitwarden-compliance-lookalike-domain-phishing
LastPass, Bitwarden users hit by lookalike-domain phishing
threat intel

LastPass, Bitwarden users hit by lookalike-domain phishing

LastPass and Bitwarden users are getting phishing from lookalike "compliance" domains pushing a DocuSign-styled downloader. Delete the email; don't click.

read →
~/articles/2026-07-15-blackpoint-labubarat-rust-nvidia-sysruntime-maas
Blackpoint flags LabubaRAT: Rust MaaS RAT poses as NVIDIA
threat intel

Blackpoint flags LabubaRAT: Rust MaaS RAT poses as NVIDIA

Blackpoint Cyber's Sam Decker and Nevan Beal document LabubaRAT — a Rust MaaS trojan on Windows that ships as nvidia-sysruntime.exe with runtime config.

read →
~/articles/2026-07-14-cereblab-grok-build-0-2-93-git-repo-upload-gcs
Grok Build v0.2.93 uploaded whole repos to xAI's bucket
threat intel

Grok Build v0.2.93 uploaded whole repos to xAI's bucket

xAI's Grok Build CLI v0.2.93 uploaded whole git repos, history and all, to a GCS bucket. The "Improve the model" toggle didn't stop it. Fix is server-side.

read →
~/articles/2026-07-14-microsoft-shinyhunters-salesforce-oauth-three-paths
A year of ShinyHunters OAuth abuse, mapped by Microsoft
Analysis
threat intel

A year of ShinyHunters OAuth abuse, mapped by Microsoft

Microsoft's July 13 report maps three OAuth paths ShinyHunters-linked actors used against Salesforce customers for a year — none of them a Salesforce bug.

read →
~/articles/2026-07-14-forg365-phaas-m365-device-code-aitm-market
Forg365 shows PhaaS became a $400/mo rental market
Analysis
threat intel

Forg365 shows PhaaS became a $400/mo rental market

Analysis: Forg365's $400/mo Microsoft 365 phishing kit adds device code, AitM, and AI-drafted replies. What changed here is finish, not the underlying kind.

read →
~/articles/2026-07-13-nca-russian-coms-five-charged-1-8m-spoofed-calls
NCA charges five over Russian Coms spoofing platform
threat intel

NCA charges five over Russian Coms spoofing platform

The NCA charged five London residents over Russian Coms — a caller-ID spoofing platform behind 1.8M scam calls and 170,000 victims. Westminster court date Aug 14.

read →
~/articles/2026-07-13-meta-2026-0182881-lachlan-dunn-emotion-listening-patent
Meta patent describes an always-on emotion-reading AI
Analysis
threat intel

Meta patent describes an always-on emotion-reading AI

Meta patent 2026/0182881, published July 2, describes an always-on AI that tags voice, biometrics, and app use to score a user's emotional patterns.

read →
~/articles/2026-07-13-nihon-kotsu-japan-taxi-cyberattack-dispatch-offline
Nihon Kotsu cyberattack takes Japan taxi dispatch offline
threat intel

Nihon Kotsu cyberattack takes Japan taxi dispatch offline

Japan's largest taxi operator says a July 12 malware intrusion knocked dispatch, web booking, and labor-taxi services offline. No group has claimed.

read →
~/articles/2026-07-13-memghost-arxiv-persistent-memory-poison-openclaw
MemGhost: an email that rewrites an AI agent's memory
Analysis
threat intel

MemGhost: an email that rewrites an AI agent's memory

arXiv paper: one crafted email talks a memory-enabled AI agent into writing attacker-supplied 'facts' into its memory files. Future sessions load them.

read →
~/articles/2026-07-13-lidl-online-shop-breach-de-be-nl-service-provider
Lidl online shop breach hits DE, BE, NL via provider
threat intel

Lidl online shop breach hits DE, BE, NL via provider

Lidl says a file at an unnamed service provider was accessed; DE/BE/NL online shop customer PII taken. Passwords and payment data not yet ruled out.

read →
~/articles/2026-07-13-huntress-ai-generated-powershell-ad-enum
Huntress Flags Suspected AI-Written PowerShell in AD Case
threat intel

Huntress Flags Suspected AI-Written PowerShell in AD Case

Huntress attributes an early-June AD enumeration case to a PowerShell script with clear LLM tells — cyan-and-green banners and 'FULLY FIXED' in the title.

read →
~/articles/2026-07-13-eu-uk-first-joint-cyber-sanctions-russia-33-named
First joint EU-UK cyber sanctions name 33 Russian targets
threat intel

First joint EU-UK cyber sanctions name 33 Russian targets

The EU Council named 9 individuals and 4 entities; the UK named 24 more. FSB Center 16, Sandworm, Turla, Lumma Stealer, and Rybar LLC are on the list.

read →
~/articles/2026-07-13-lexfo-evilginx-three-crews-open-directory
Three Evilginx Crews, One Forgotten Bash History
Analysis
threat intel

Three Evilginx Crews, One Forgotten Bash History

Lexfo pulled the full toolkit from an open Python server in Budapest and pivoted to two more Evilginx operations targeting Microsoft 365 tenants.

read →
~/articles/2026-07-12-coinspect-ill-bloom-weak-prng-wallet-seed-5-1m-drained
Ill Bloom: Weak PRNG Drained $5.1M From Crypto Wallets
threat intel

Ill Bloom: Weak PRNG Drained $5.1M From Crypto Wallets

Coinspect's Ill Bloom disclosure: five unnamed wallets shipped seed-phrase code with weak randomness. Two sweeps in May and June drained $5.1M.

read →
~/articles/2026-07-11-sentinellabs-balochistan-police-china-india-converge
China, India APTs Converge on Balochistan Police
threat intel

China, India APTs Converge on Balochistan Police

SentinelLABS ties 22 months of intrusions at Balochistan Police to two separate crews: China-nexus operators using PlugX and India-linked Mysterious Elephant.

read →
~/articles/2026-07-11-acsc-cms-plugin-exploitation-advisory-18-cves
Australia's ACSC names 18 CMS bugs under exploitation
Analysis
threat intel

Australia's ACSC names 18 CMS bugs under exploitation

Australia's ACSC named 18 CVEs across WordPress plugins, Craft CMS, Joomla JCE, and more as active exploitation targets, with attackers dropping webshells.

read →
~/articles/2026-07-11-ghostcommit-png-prompt-injection-coderabbit-bugbot
Ghostcommit and the reviewers that don't open the PNG
Analysis
threat intel

Ghostcommit and the reviewers that don't open the PNG

A PNG carrying prompt injection slips past AI code reviewers that never open image files, then talks a coding agent into exfiltrating a repo's .env secrets as a list of numbers.

read →
~/articles/2026-07-11-modbeacon-silver-fox-rust-rat-grpc-c2-qianxin
Silver Fox ships MODBEACON, a Rust RAT with gRPC C2
threat intel

Silver Fox ships MODBEACON, a Rust RAT with gRPC C2

QiAnXin attributes a new Rust-based RAT called MODBEACON to Silver Fox, using gRPC streaming for encrypted C2 and SEO-poisoned installers for delivery.

read →
~/articles/2026-07-11-metasploit-weekly-flowise-csv-packagekit-modules
Metasploit Weekly Adds Flowise CSV, macOS PackageKit
threat intel

Metasploit Weekly Adds Flowise CSV, macOS PackageKit

Rapid7's Metasploit weekly drops two modules — a Flowise CSV Agent prompt-injection RCE and a macOS PackageKit LPE. New tooling, not new bugs.

read →
~/articles/2026-07-11-cisa-kev-balbooa-icagenda-joomla-file-upload
Balbooa, iCagenda Join KEV: Four Joomla RCEs in Four Days
threat intel

Balbooa, iCagenda Join KEV: Four Joomla RCEs in Four Days

CISA added Balbooa Forms and iCagenda to KEV on July 10 — two unauthenticated file-upload RCEs in Joomla extensions. Federal due date is July 13.

read →
~/articles/2026-07-10-iossifov-seized-crypto-wallet-still-had-key
A seized crypto account that moved from a cell
Analysis
threat intel

A seized crypto account that moved from a cell

Rossen Iossifov, ten years into a laundering sentence, is charged with moving $290K from a seized crypto account. The interesting part is it still moved.

read →
~/articles/2026-07-10-openclaw-2026-6-6-nayak-whatsapp-host-rce-chain
OpenClaw patched a chain that started in a chat message
Analysis
threat intel

OpenClaw patched a chain that started in a chat message

OpenClaw 2026.6.6 closes three flaws that let a WhatsApp message reach the host as command execution. No public PoC, no observed exploitation.

read →
~/articles/2026-07-10-politie-odido-dutch-speaker-vishing-shinyhunters-62m
Politie Points at Dutch Hackers in the 88GB Odido Leak
threat intel

Politie Points at Dutch Hackers in the 88GB Odido Leak

Dutch National Police say strong indications point at Dutch attackers behind February's Odido breach: a Dutch-speaking vishing call to customer service, then 6.2M records leaked.

read →
~/articles/2026-07-10-donjon-tangem-laser-fault-injection-eal6-samsung
A laser resets Tangem wallets, and there's no patch
Analysis
threat intel

A laser resets Tangem wallets, and there's no patch

Ledger Donjon's laser fault-injection attack resets a Tangem card's password without the old one. There is no patch — Tangem ships no firmware updates.

read →
~/articles/2026-07-10-foxio-xring-xquic-qpack-integer-underflow-alibaba-silence
XRING: 260 bytes, no patch, three months of Alibaba silence
Analysis
threat intel

XRING: 260 bytes, no patch, three months of Alibaba silence

FoxIO's Sébastien Féry disclosed a QPACK integer underflow in Alibaba XQUIC that crashes HTTP/3 servers with 260 bytes. Reported April 7. No reply. No patch.

read →
~/articles/2026-07-10-wp-shellstorm-socradar-exposed-server-funnel
WP-SHELLSTORM ran 22 days with its door left open
Analysis
threat intel

WP-SHELLSTORM ran 22 days with its door left open

SOCRadar and Ctrl-Alt-Intel pulled 22 days of files off an exposed WP-SHELLSTORM server: 1.4M targets, 25K compromises, 5,700 live shells.

read →
~/articles/2026-07-10-illbloom-coinspect-weak-prng-mobile-wallet-drain
Ill Bloom is a $3.1M lesson in weak randomness, again
Analysis
threat intel

Ill Bloom is a $3.1M lesson in weak randomness, again

Coinspect disclosed weak PRNG in wallet recovery-phrase generation; attackers drained $3.1M in a May sweep. The pattern — bad randomness, stolen keys — is old.

read →
~/articles/2026-07-10-meta-muse-image-instagram-public-default-impersonation-surface
Meta's Muse Image defaults on for public Instagram
Analysis
threat intel

Meta's Muse Image defaults on for public Instagram

Meta's new Muse Image model reuses public Instagram photos and reels by default — no notification, no watermark discussion, opt-out three levels deep in Sharing settings.

read →
~/articles/2026-07-10-clearinghouse-summer-athena-lightwell-old-pattern
The clearinghouse boom is not new, and neither is the fatigue
Analysis
threat intel

The clearinghouse boom is not new, and neither is the fatigue

Chainguard announced Athena. Red Hat and the White House announced Lightwell. Vulnerability clearinghouses have been getting reannounced since the 1980s.

read →
~/articles/2026-07-10-hackernews-ato-verification-step-passkey-aftermath
The ATO fight moved past credential stuffing
Analysis
threat intel

The ATO fight moved past credential stuffing

The Hacker News argues account takeover shifted from credential stuffing to attacking verification — passkeys pushed the front door shut, so attackers moved.

read →
~/articles/2026-07-10-talos-hazel-winning-54-percent-defender-cliche
Talos on 'attackers only need to be right once'
Analysis
threat intel

Talos on 'attackers only need to be right once'

Cisco Talos's Hazel argues 'attackers only need to be right once' is a cliché the defensive community should retire. It's overdue.

read →
~/articles/2026-07-10-datadog-dormant-github-ghost-accounts-org-enumeration
Datadog: 50+ dormant GitHub accounts mapping org charts
Analysis
threat intel

Datadog: 50+ dormant GitHub accounts mapping org charts

Datadog Security Labs documents 50+ dormant GitHub accounts running months-long enumeration of corporate orgs, repos, and — in some cases — private code.

read →
~/articles/2026-07-09-helix-reliaquest-sharepoint-vishing-blackfile-overlap
Helix: new data-extortion crew hits SharePoint via vishing
threat intel

Helix: new data-extortion crew hits SharePoint via vishing

ReliaQuest attributes new data-extortion crew Helix to vishing and device-code phishing against SharePoint. Infrastructure overlaps BlackFile.

read →
~/articles/2026-07-09-microsoft-gigawiper-bluerabbit-cyberav3ngers-israel-wiper
GigaWiper/BLUERABBIT: Go-based wiper, CyberAv3ngers-linked
threat intel

GigaWiper/BLUERABBIT: Go-based wiper, CyberAv3ngers-linked

Microsoft and Binary Defense concurrently disclose a Go-based Windows destructive backdoor — wipe, fake ransomware, spyware in one binary — attributed to Iran-nexus CyberAv3ngers.

read →
~/articles/2026-07-09-interpol-first-light-5811-arrests-293m-seized
INTERPOL First Light 2026: 5,811 arrests, $293M seized
threat intel

INTERPOL First Light 2026: 5,811 arrests, $293M seized

INTERPOL's Operation First Light 2026 arrested 5,811 fraud suspects across 97 countries, seized $293M and blocked 31,014 accounts over 3.5 months.

read →
~/articles/2026-07-09-ai-now-friendly-fire-claude-code-codex-review-exploit
Friendly Fire: agents review the trap, then execute it
Analysis
threat intel

Friendly Fire: agents review the trap, then execute it

AI Now Institute researchers show autonomous Claude Code and Codex can be tricked into running a hidden binary during their own security-review pass.

read →
~/articles/2026-07-09-assuranceamerica-breach-6-9m-drivers-march-intrusion
AssuranceAmerica breach: 6.9M drivers, 4-month notice gap
threat intel

AssuranceAmerica breach: 6.9M drivers, 4-month notice gap

AssuranceAmerica confirms a March 16 intrusion exposed data on 6,998,886 drivers. Notification letters went out in July — a nearly four-month gap between detection and public notice.

read →
~/articles/2026-07-09-infoblox-lurking-lizard-230-domain-fake-7zip-residential-proxy
Infoblox: Lurking Lizard runs 230-domain fake 7-Zip proxy
threat intel

Infoblox: Lurking Lizard runs 230-domain fake 7-Zip proxy

Infoblox ties a China-based residential-proxy operator to 230+ lookalike domains active since 2022, seeding fake 7-Zip and WireVPN installers.

read →
~/articles/2026-07-09-wiz-ghostapproval-symlink-six-ai-coding-assistants
GhostApproval symlink bug hits six AI coding assistants
threat intel

GhostApproval symlink bug hits six AI coding assistants

Wiz research: Amazon Q, Cursor, Claude Code, Augment, Antigravity, Windsurf all approved one file path in the dialog while writing to another via symlinks.

read →
~/articles/2026-07-08-spain-palencia-carr-noname-logistics-arrest
Spain arrests suspected CARR logistics operator
Analysis
threat intel

Spain arrests suspected CARR logistics operator

Spanish police detained a Palencia man tied to CyberArmy of Russia Reborn, Z-Pentest, and NoName057(16). The announcement lands nearly four months after the raid.

read →
~/articles/2026-07-08-iris-c2-krebs-wohl-burkman-zero-day-broker
Krebs traces zero-day broker IRIS C2 to Wohl and Burkman
Analysis
threat intel

Krebs traces zero-day broker IRIS C2 to Wohl and Burkman

Krebs ties IRIS C2, an offensive-security startup pitching zero-day acquisition, to Jacob Wohl and Jack Burkman — both convicted of felony fraud.

read →
~/articles/2026-07-08-sophos-coding-agents-tripping-edr-attacker-detections
Sophos: Coding Agents Are Tripping the Attacker Detections
Analysis
threat intel

Sophos: Coding Agents Are Tripping the Attacker Detections

Seven days of Sophos endpoint telemetry: Claude Code, Cursor, and Codex trip the same rules built to catch attackers — because behaviorally, they should.

read →
~/articles/2026-07-08-copilot-workflow-jailbreak-arxiv-kumar-maple
Refused in Chat, Written in Code: Copilot's Workflow Gap
Analysis
threat intel

Refused in Chat, Written in Code: Copilot's Workflow Gap

Kumar and Maple's new arXiv preprint says Copilot's Claude and Gemini backends refused harmful prompts in chat but produced them 816-for-816 in a workflow.

read →
~/articles/2026-07-08-scmbanker-elastic-ref6045-mexican-banking-fraud
SCMBANKER active against Mexican banks — Elastic REF6045
threat intel

SCMBANKER active against Mexican banks — Elastic REF6045

Elastic Security Labs is tracking SCMBANKER (REF6045), a PowerShell fraud toolkit hitting Mexican banks, fintechs, and crypto exchanges via ClickFix lures.

read →
~/articles/2026-07-08-kddi-japan-isp-breach-12m-third-party-zero-day
KDDI Breach: 12M Emails, 7.6M Passwords via 3rd-Party 0day
threat intel

KDDI Breach: 12M Emails, 7.6M Passwords via 3rd-Party 0day

KDDI says a May 16 zero-day in unnamed third-party software exposed 12,233,087 email addresses and 7,616,173 passwords across five Japanese ISPs.

read →
~/articles/2026-07-08-cisa-kev-langflow-joomla-page-builder-adds
CISA Adds Langflow and Two Joomla Builders to KEV
threat intel

CISA Adds Langflow and Two Joomla Builders to KEV

CISA added three vulnerabilities to KEV on July 7 — a Langflow IDOR and two Joomla page-builder RCEs. Federal due date is July 10. Priority order below.

read →
~/articles/2026-07-08-unk-masstraction-china-cluster-roundcube-universities
Proofpoint: China cluster raids university physics mail
Analysis
threat intel

Proofpoint: China cluster raids university physics mail

Proofpoint attributes a Roundcube-exploitation campaign against U.S. and Canadian university physics departments to a China-aligned cluster, UNK_MassTraction.

read →
~/articles/2026-07-07-uat-7810-longleash-orb-network-ruckus-asus
China-Linked UAT-7810 Expands ORB Net With LONGLEASH
threat intel

China-Linked UAT-7810 Expands ORB Net With LONGLEASH

Cisco Talos ties China-aligned UAT-7810 to LONGLEASH backdoor and an expanding ORB relay network built on unpatched Ruckus and ASUS routers.

read →
~/articles/2026-07-08-scattered-spider-windows-device-id-court-filing-stokes
Windows Device ID trail led FBI to Scattered Spider suspect
Analysis
threat intel

Windows Device ID trail led FBI to Scattered Spider suspect

A newly unsealed federal complaint says a Microsoft-recorded device ID tied the account behind a Scattered Spider intrusion to 19-year-old Peter Stokes.

read →
~/articles/2026-07-07-accenture-confirms-breach-source-code-claim
Accenture Confirms Breach; Attacker Claims 35 GB Stolen
threat intel

Accenture Confirms Breach; Attacker Claims 35 GB Stolen

Accenture confirmed a security incident. A threat actor is advertising 35 GB of alleged source code for sale. The volume claim is unverified — treat accordingly.

read →
~/articles/2026-07-06-operation-dragonreturn-china-nexus-dcrat-india-tax
DragonReturn Drops DcRAT on Indian Taxpayers
threat intel

DragonReturn Drops DcRAT on Indian Taxpayers

Seqrite Labs attributes an ongoing spear-phishing campaign against Indian tax filers to a suspected China-nexus actor with infrastructure and tactical overlap to Silver Fox. First observed May 18.

read →
~/articles/2026-07-06-quimarat-java-cross-platform-maas-levelblue
QuimaRAT: A $150 Cross-Platform Java RAT MaaS
threat intel

QuimaRAT: A $150 Cross-Platform Java RAT MaaS

LevelBlue profiled a new cross-platform Java RAT sold as MaaS. No confirmed campaigns yet — but the price is low, the payload runs everywhere, and the loader is built to walk past SmartScreen. Assume it lands somewhere soon.

read →
~/articles/2026-07-05-flipper-zero-firmware-maintenance-only-community-driven
Flipper Zero Firmware Goes Maintenance-Only
threat intel

Flipper Zero Firmware Goes Maintenance-Only

Flipper Devices says the Flipper Zero firmware is stable at 1.0 and full-time feature work is over. Community PRs run the future, filtered through GitHub Discussions voting and stricter review. Here's what changes.

read →
~/articles/2026-07-04-metasploit-weekly-smb-meterpreter-peyara-detection
Metasploit's July 3 Drop: SMB-to-Meterpreter, Peyara
threat intel

Metasploit's July 3 Drop: SMB-to-Meterpreter, Peyara

Rapid7 shipped an SMB-to-Meterpreter session upgrade and a Peyara Remote Mouse RCE module this week. Neither is novel research. Both change what your alerts will look like. Here's the tune.

read →
~/articles/2026-07-04-orchid-iga-ai-agents-lifecycle-gaps
IGA Was Built Around Employment Records, Not Agents
Analysis
threat intel

IGA Was Built Around Employment Records, Not Agents

A contributed piece to The Hacker News from Orchid Security lays out where the joiner-mover-leaver model quietly fails for AI agents. Vendor-adjacent, but the gap analysis holds.

read →
~/articles/2026-07-04-talos-catan-and-mouse-curiosity-defensive-skill
Talos on Curiosity: A Skill That Doesn't Scale
Analysis
threat intel

Talos on Curiosity: A Skill That Doesn't Scale

William Largent's Threat Source column this week reads as an essay on board games and pattern recognition. It's really an argument about the load-bearing skill that keeps a defender from becoming a checklist.

read →
~/articles/2026-07-03-pamstealer-macos-maccy-impersonation-jamf
PamStealer: A Fake Maccy Site Steals macOS Creds
threat intel

PamStealer: A Fake Maccy Site Steals macOS Creds

Jamf Threat Labs disclosed a new macOS credential stealer today that impersonates the Maccy clipboard app, validates the victim's login password against PAM in real time, and exfiltrates keychain and browser data. Apple Silicon only. Here's what defenders should do.

read →
~/articles/2026-07-03-fbi-netnut-popa-botnet-takedown
FBI Seizes NetNut Proxy, Google Degrades Popa Botnet
threat intel

FBI Seizes NetNut Proxy, Google Degrades Popa Botnet

The FBI seized hundreds of NetNut proxy domains on July 2; Google's Threat Intelligence Group, working with FBI and Lumen, cut the linked Popa botnet's usable device pool by millions the same day.

read →