Summary & highlights
CVE-2026-55407: Unbounded Heap Allocation DoS in Anthropic's Buffa Rust Protobuf Library (decode_unknown_field). Serbian 'Putevi Srbije' Traffic-Fine Smishing Campaign Using Darcula and Phoenix PhaaS Platforms. Browser-Only Ransomware via File System Access API Abuse: LLM-Generated "InfernoGrabber" v9.0 (DeepSeek-Attributed).
Highlights
- TL-2026-1023 — Xsolis Data Breach: Targeted Phishing Attack Exposes PHI/PII of 1,396,519 Individuals
- TL-2026-1024 — Malicious ClawHub Skills Threaten OpenClaw AI Agent Supply Chain (AMOS, cluw, Solana Front-Running)
- TL-2026-1027 — ClickFix Campaigns Evolve API-Driven Payload Delivery: Analysis of 3,000 Live Payloads Reveals New Evasion Techniques
- TL-2026-1028 — Microsoft AI-Assisted Investigation Links StealC and Amadey Malware-as-a-Service Operations in RICO Suit (Operation Endgame)
- TL-2026-1029 — Amadey: Commodity Loader/Botnet Evolved into RAT — Dominant LockBit 3.0 Loader, Adopted by FSB's Secret Blizzard Against Ukrainian Military
Theme of the day
Activity centered on address-exposure, adventhealth, almeida-law-group.
- credential-theft
- financially-motivated
- social-engineering
- remote-access-trojan
- credential-harvesting
Threats published
38 threat lines in the 2026-07-01 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- Active Exploitation of Cisco Unified Communications Manager WebDialer SSRF (CVE-2026-20230) and Catalyst SD-WAN Manager Root Privilege-Escalation Zero-Day (CVE-2026-20245)CRITICAL
- Chrome 151 Security Update Patches 382 Vulnerabilities, Including 15 Critical Memory-Corruption Flaws (CVE-2026-13774 to CVE-2026-13788)CRITICAL
- Adobe Patches Seven Priority-1 ColdFusion and Campaign Classic Flaws (CVE-2026-48276, CVE-2026-48277, CVE-2026-48281, CVE-2026-48282, CVE-2026-48316, CVE-2026-48286)CRITICAL
- JADEPUFFER: Agentic (LLM-Driven) Ransomware Automating Database Extortion via Langflow RCE (CVE-2025-3248) and Nacos Auth Bypass (CVE-2021-29441)CRITICAL
- CVE-2026-8037: Pre-Auth Command Injection RCE in Progress Kemp LoadMaster via Uninitialized-Heap escape_quotes() Flaw on /accessv2CRITICAL
- Cursor IDE "DuneSlide" Sandbox Escape RCE via Zero-Click Prompt Injection (CVE-2026-50548, CVE-2026-50549)CRITICAL
- Adobe Patches Nine CVSS 10.0/9.3 Flaws in ColdFusion and Campaign Classic Enabling Arbitrary Code Execution (APSB26-68, APSB26-69)CRITICAL
- Critical Cursor AI Code Editor Flaws (CVE-2026-50548, CVE-2026-50549) — "DuneSlide" Zero-Click Prompt Injection to Sandbox Escape and RCECRITICAL
- CVE-2026-46817: Critical Unauthenticated File-Read/Takeover Flaw in Oracle E-Business Suite Payments Exploited Pre-PoCCRITICAL
- PolinRider: North Korea-Linked Supply Chain Campaign Expands Across npm, Packagist, Go Modules, and Chrome ExtensionsCRITICAL
- CISA KEV Addition: Microsoft SharePoint Server Deserialization RCE (CVE-2026-45659) Actively Exploited by Storm-2603 / Warlock RansomwareCRITICAL
- FortiBleed Credential Theft Campaign: FortigateSniffer Tool Deployed Against 430,000+ FortiGate Firewalls, Linked to INC Ransom and Lynx RansomwareCRITICAL
- Xsolis Data Breach: Targeted Phishing Attack Exposes PHI/PII of 1,396,519 IndividualsHIGH
- Malicious ClawHub Skills Threaten OpenClaw AI Agent Supply Chain (AMOS, cluw, Solana Front-Running)HIGH
- ClickFix Campaigns Evolve API-Driven Payload Delivery: Analysis of 3,000 Live Payloads Reveals New Evasion TechniquesHIGH
- Microsoft AI-Assisted Investigation Links StealC and Amadey Malware-as-a-Service Operations in RICO Suit (Operation Endgame)HIGH
- Amadey: Commodity Loader/Botnet Evolved into RAT — Dominant LockBit 3.0 Loader, Adopted by FSB's Secret Blizzard Against Ukrainian MilitaryHIGH
- Lazarus-Linked npm Malware Masquerades as Rollup Polyfills (rollup-packages-polyfill-core, rollup-runtime-polyfill-core, swift-parse-stream, quirky-token, rollup-plugin-polyfill-connect, react-icon-svgs)HIGH
- Phantom Squatting: Attackers Register AI-Hallucinated Domains to Hijack LLM-Guided Traffic (Montana Empire / PhantomRaven)HIGH
- Operation Endgame Disrupts Amadey Loader and StealC Infostealer Malware-as-a-Service Infrastructure (CVE: N/A)HIGH
- ARToken: Business Email Compromise-as-a-Service Platform Targeting Microsoft 365 (Cisco Talos / EvilTokens Affiliate)HIGH
- ARToken Phishing Panel Abuses Microsoft OAuth Device Code Flow to Hijack Microsoft 365 Accounts (EvilTokens PhaaS)HIGH
- Mistic Backdoor (MLTBackdoor) Impersonates Microsoft Endpoint Security via DLL Sideloading — Woodgnat/KongTuke Access BrokerHIGH
- ScreenConnect Masked as Freeware: Large-Scale AsyncRAT Distribution Campaign via SEO-Poisoned Fake Software SitesHIGH
- Multiple Fluentd Vulnerabilities: RCE via Tag Placeholder (CVE-2026-44024), Info Disclosure (CVE-2026-44025), Decompression Bomb DoS (CVE-2026-44160), and SSRF (CVE-2026-44161)HIGH
- MacSync Stealer v1.1.2 ("claude1"): Malicious Google Ad Impersonates Claude Code Installer to Hijack macOS SystemsHIGH
- Ousaban (Javali) Banking Trojan Expands Grandoreiro-Linked Tetrade Campaign to Target Iberian Banking Users in Spain and PortugalHIGH
- Phantom Squatting: Adversaries Preemptively Register AI-Hallucinated Domains to Hijack Software Supply Chain Trust (Unit 42 "Montana Empire" Case)HIGH
- PolinRider Campaign: North Korea-Linked Supply Chain Attack Expands Across npm, Packagist, Go Modules, and Chrome Web Store (DEV#POPPER / OmniStealer)HIGH
- ChocoPoC: Python RAT Distributed via Trojanized PoC Exploits Targeting Security ResearchersHIGH
- Cross-Platform Phishing Campaigns Auto-Adapt Payloads to Victim Device/OS via FingerprintingHIGH
- Schneider Electric Floating License Manager - CVE-2024-2658 Local Privilege Escalation via Uncontrolled Search Path in FlexNet Publisher (update)HIGH
- Serbian 'Putevi Srbije' Traffic-Fine Smishing Campaign Using Darcula and Phoenix PhaaS PlatformsMEDIUM
- Browser-Only Ransomware via File System Access API Abuse: LLM-Generated "InfernoGrabber" v9.0 (DeepSeek-Attributed)MEDIUM
- Apple 'Hide My Email' Aliases Deanonymizable to Real Email Addresses (Unpatched 1+ Year)MEDIUM
- InfernoGrabber v9.0: AI-Generated In-Browser Ransomware Abusing the Chromium File System Access APIMEDIUM
- VEIL#DROP Campaign Uses Blogger-Hosted Stager to Deliver PureLogs StealerMEDIUM
- CVE-2026-55407: Unbounded Heap Allocation DoS in Anthropic's Buffa Rust Protobuf Library (decode_unknown_field)
Techniques observed
235 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T1003
- T1005
- T1007
- T1008
- T1012
- T1016
- T1018
- T1020
- T1021
- T1021.001
- T1027
- T1027.003
- T1027.013
- T1033
- T1036
- T1036.005
- T1036.007
- T1040
- T1041
- T1046
- T1047
- T1048
- T1049
- T1053
- T1053.003
- T1053.005
- T1055
- T1055.012
- T1056
- T1056.001
- T1056.002
- T1056.004
- T1057
- T1059
- T1059.001
- T1059.003
- T1059.004
- T1059.005
- T1059.006
- T1059.007
- T1068
- T1069
- T1070
- T1070.001
- T1070.004
- T1071
- T1071.001
- T1071.004
- T1074
- T1078
- T1078.001
- T1078.004
- T1082
- T1083
- T1087
- T1087.001
- T1087.002
- T1087.004
- T1090
- T1095
- T1098
- T1098.001
- T1098.005
- T1102
- T1102.001
- T1102.002
- T1105
- T1106
- T1110
- T1110.001
- T1111
- T1112
- T1113
- T1114
- T1114.002
- T1114.003
- T1115
- T1119
- T1125
- T1129
- T1132
- T1133
- T1134
- T1135
- T1136
- T1136.001
- T1140
- T1176
- T1185
- T1187
- T1189
- T1190
- T1195
- T1195.001
- T1195.002
- T1199
- T1202
- T1203
- T1204
- T1204.001
- T1204.002
- T1204.004
- T1210
- T1211
- T1212
- T1213
- T1213.002
- T1217
- T1218
- T1218.004
- T1218.007
- T1218.009
- T1218.010
- T1218.011
- T1219
- T1222
- T1222.002
- T1480
- T1482
- T1484
- T1485
- T1486
- T1489
- T1490
- T1491.001
- T1496
- T1497
- T1497.001
- T1499
- T1505
- T1505.003
- T1518
- T1518.001
- T1526
- T1528
- T1530
- T1531
- T1538
- T1539
- T1543
- T1543.001
- T1543.003
- T1546.004
- T1546.016
- T1547
- T1547.001
- T1547.013
- T1547.014
- T1548
- T1548.002
- T1550.001
- T1552
- T1552.001
- T1552.002
- T1553
- T1553.002
- T1554
- T1555
- T1555.001
- T1555.003
- T1556
- T1558
- T1558.003
- T1560
- T1561
- T1562
- T1562.001
- T1562.008
- T1564
- T1564.001
- T1565
- T1565.001
- T1566
- T1566.001
- T1566.002
- T1567
- T1567.002
- T1568
- T1569
- T1569.002
- T1570
- T1571
- T1572
- T1573
- T1573.001
- T1574
- T1574.002
- T1583
- T1583.001
- T1583.004
- T1583.006
- T1584
- T1584.001
- T1584.004
- T1584.006
- T1585
- T1585.001
- T1585.002
- T1586
- T1586.003
- T1587
- T1587.001
- T1587.004
- T1588
- T1588.002
- T1588.003
- T1588.005
- T1588.006
- T1589
- T1589.001
- T1589.002
- T1591
- T1592
- T1593
- T1593.002
- T1594
- T1595
- T1595.002
- T1596
- T1596.005
- T1597
- T1597.002
- T1598
- T1598.003
- T1606
- T1608
- T1608.001
- T1611
- T1614
- T1614.001
- T1620
- T1621
- T1622
- T1656
- T1657
Threat actors
12 named threat actors across the reports.
- Amadey
- Turla - G0010
- Lazarus Group
- InCrease
- EvilTokens
- Woodgnat
- Tetrade
- PolinRider
- JADEPUFFER
- Contagious Interview
- Storm-2603
- INC Ransom
Nation-state attribution
- Russia, Iran, North Korea
- Russia
- North Korea
- Russia (loosely associated, unconfirmed for ARToken specifically)
- Brazil
- North Korea (DPRK)
- China
Threat categories
- VULNERABILITY
- PHISHING
- MALWARE
- DATA_BREACH
- SUPPLY_CHAIN
- RANSOMWARE
Severity breakdown
- critical12
- high20
- medium5
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- network 203
- behavioral 199
- file 178
- entity 87
- malware 80
- infrastructure 58
- tool 58
- package 49
- technique 28
- vulnerability 4