Summary & highlights
Microsoft Teams Impersonation Phishing Campaign Deploys Signed RMM Installers via Fake Meeting Pages (CYFIRMA). WinRAR 7.23 Fixes Heap Overflow in RAR5 Recovery Volume Processing (CVE-2026-14191). ChatGPT File Download Flow Path Traversal / Local File Inclusion (LFI) via Guardrail Bypass Social Engineering.
Highlights
- TL-2026-1059 — Anatsa (TeaBot) Banking Trojan Distributed via Fake "File Horizon Explorer" Document Reader App on Google Play
- TL-2026-1060 — BeyondTrust Microsoft Vulnerabilities Report 2026: Critical Flaws More Than Double as Elevation of Privilege Dominates (CVE-2025-55241, CVE-2025-62557, CVE-2025-62554)
- TL-2026-1061 — CVE-2026-45659: SharePoint Deserialization RCE Added to CISA KEV Amid Storm-2603 Exploitation
- TL-2026-1062 — ChocoPoC RAT Campaign Uses Malicious PoC-Exploit Python Packages to Backdoor Security Researchers
- TL-2026-1065 — CVE-2026-45659: Microsoft SharePoint Server Deserialization RCE Added to CISA KEV
Theme of the day
Activity centered on linux, responsible-disclosure, windows.
- credential-theft
- active-exploitation
- data-exfiltration
- remote-code-execution
- cisa-kev
Threats published
64 threat lines in the 2026-07-02 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- FortiBleed Credential-Harvesting Campaign Feeds INC Ransom and Lynx Ransomware-as-a-Service OperationsCRITICAL
- Multiple Critical Adobe ColdFusion Vulnerabilities (CVE-2026-48276 et al., APSB26-68) Enable Unauthenticated Remote Code ExecutionCRITICAL
- Cisco Catalyst SD-WAN Manager Zero-Day Exploitation Chain (CVE-2026-20245, CVE-2026-20127, CVE-2026-20182)CRITICAL
- CVE-2026-45659: Microsoft SharePoint Server Deserialization RCE Actively Exploited, Added to CISA KEVCRITICAL
- CVE-2026-8037: Unauthenticated OS Command Injection in Progress Kemp LoadMaster via Uninitialized Heap in escape_quotes() (CVSS 9.6-9.8, Active Exploitation)CRITICAL
- CVE-2026-46817: Active Exploitation Against ~950 Internet-Exposed Oracle E-Business Suite Payments InstancesCRITICAL
- Fake Google/Cloudflare Verification Pages Spread Multiple Malware Families via ClickFix (HijackLoader, StealC, Remus Stealer, Amatera Stealer, CastleLoader, NetSupport RAT, ResiLoader)CRITICAL
- CitrixBleed-Class NetScaler ADC/Gateway SAML AuthnRequest Memory Disclosure (CVE-2026-8451) Exploited Within 24 Hours of DisclosureCRITICAL
- JADEPUFFER: First End-to-End Agentic Ransomware Attack Exploiting Langflow (CVE-2025-3248) and Nacos (CVE-2021-29441)CRITICAL
- FortiBleed Credential-Theft Campaign Linked to INC and Lynx Ransomware OperationsCRITICAL
- Ransomware Groups Exploit Citrix Bleed 2 (CVE-2025-5777) and Kontron Driver BYOVD for Access and Privilege EscalationCRITICAL
- CVE-2026-46817: Unauthenticated Arbitrary File Read in Oracle E-Business Suite Payments File Transmission Exploited Before Public PoCCRITICAL
- FortiBleed Credential-Harvesting Campaign Against 430,000 FortiGate Firewalls Feeds INC Ransom and Lynx Ransomware OperationsCRITICAL
- Adobe ColdFusion & Campaign Classic Priority 1 Patches for 12 Vulnerabilities Including Six Maximum-Severity RCE Flaws (APSB26-68, APSB26-69)CRITICAL
- JADEPUFFER Agentic Ransomware Exploits Langflow CVE-2025-3248 and Nacos CVE-2021-29441 via Base64-Encoded Python PayloadsCRITICAL
- SmarterMail Dual-CVE Pre-Auth RCE Chain — CVE-2026-23760 Admin Password Reset + CVE-2026-24423 ConnectToHub RCE, CISA KEV, Mass Automated Exploitation, 2-Day Patch Weaponization via .NET Decompiler (update)CRITICAL
- Malicious Next.js Repositories — Developer-Targeting C2 Campaign via VSCode Workspace Abuse, Job-Themed Lures, and Staged JavaScript Execution (update)CRITICAL
- Axios npm Supply Chain Attack via Malicious plain-crypto-js Dependency (Cross-Platform RAT Dropper) (update)CRITICAL
- Axios npm Supply Chain Attack: Cross-Platform RAT Delivery via Compromised Maintainer Credentials (GHSA-fw8c-xr5c-95f9) (update)CRITICAL
- Axios NPM Supply Chain Compromise — Cross-Platform RAT via Malicious Transitive Dependency (plain-crypto-js) (update)CRITICAL
- F5 BIG-IP APM Unauthenticated Remote Code Execution via Stack Buffer Overflow (CVE-2025-53521) — CISA KEV Active Exploitation by Chinese Nation-State Actor (update)CRITICAL
- ChipSoft HiX Healthcare EHR Ransomware Attack — Dutch Hospital Infrastructure Disruption (update)CRITICAL
- Axios npm Supply Chain Compromise — Malicious axios@1.14.1 and axios@0.30.4 Inject plain-crypto-js@4.2.1 RAT Dropper (update)CRITICAL
- Xinference PyPI Supply Chain Compromise — TeamPCP-Marked Credential Harvester (v2.6.0–2.6.2) (update)CRITICAL
- lightning PyPI Package Compromise — Versions 2.6.2 & 2.6.3 Execute Bun-Based JavaScript Credential Stealer on Import (Shai-Hulud-Overlapping) (update)CRITICAL
- PAN-OS User-ID Authentication Portal RCE Zero-Day (CVE-2026-0300) — Active Exploitation on PA-Series & VM-Series Firewalls (update)CRITICAL
- Mastra npm Supply-Chain Compromise (@mastra/* namespace) via Typosquatted 'easy-day-js' — Multi-Stage Cross-Platform Infostealer (update)CRITICAL
- Klue Supply Chain Breach: OAuth Token Harvesting & Salesforce CRM Data Exfiltration (update)CRITICAL
- Mastra NPM Packages Trojanized with Malicious Dependency Injection - 116 Packages Compromised (update)CRITICAL
- Dropping Elephant Malware Campaign - China-Themed Loader Chain for Initial Access and Payload Delivery (update)CRITICAL
- Anatsa (TeaBot) Banking Trojan Distributed via Fake "File Horizon Explorer" Document Reader App on Google PlayHIGH
- BeyondTrust Microsoft Vulnerabilities Report 2026: Critical Flaws More Than Double as Elevation of Privilege Dominates (CVE-2025-55241, CVE-2025-62557, CVE-2025-62554)HIGH
- CVE-2026-45659: SharePoint Deserialization RCE Added to CISA KEV Amid Storm-2603 ExploitationHIGH
- ChocoPoC RAT Campaign Uses Malicious PoC-Exploit Python Packages to Backdoor Security ResearchersHIGH
- CVE-2026-45659: Microsoft SharePoint Server Deserialization RCE Added to CISA KEVHIGH
- CVE-2026-45659: Microsoft SharePoint Deserialization RCE Actively Exploited, Added to CISA KEVHIGH
- Multiple JetBrains Product Vulnerabilities: Account Takeover, Privilege Escalation, and RCE Across Hub, YouTrack, IntelliJ IDEA, Kotlin, GoLand, and TeamCityHIGH
- CVE-2026-20230: Active Exploitation of Cisco Unified CM WebDialer SSRF Flaw Leading to Root-Level CompromiseHIGH
- Cisco Catalyst Center Unauthenticated Path Traversal / Arbitrary File Read Vulnerability (CVE-2026-20191)HIGH
- ToddyCat-Linked Umbrij Malware Abuses OAuth via 'Shadow Token via Remote Debug' (STRD) to Access Gmail, Drive, Calendar and ContactsHIGH
- CVE-2026-45659: Microsoft SharePoint Deserialization RCE Added to CISA KEV Despite 'Exploitation Less Likely' RatingHIGH
- AI Compute Hijacking: Stolen Ollama Server Wired Into Autonomous "VAPT" Exploit Pipeline (Sysdig)HIGH
- Ousaban Banking Trojan (Tetrade/Javali) Targets Iberian Banks via Phishing PDFs, Fake Tax Portal, and Steganographic VBS DownloaderHIGH
- Remus Stealer: 64-bit Lumma-Derived Infostealer-as-a-Service with EtherHiding Blockchain C2 and Application-Bound Encryption BypassHIGH
- AsyncRAT Campaign Uses DLL Sideloading and ScreenConnect for Stealthy Remote Access (SEO-Poisoned Fake Installer Sites)HIGH
- FBI Seizes NetNut Residential Proxy Platform Tied to Popa Botnet (2M+ Devices) — Alarum Technologies, Kimwolf/Vo1d ConvergenceHIGH
- ChocoPoC Campaign: Trojanised PoC Exploits and PyPI Packages Deliver Python RAT Using Mapbox Datasets API as Dead-Drop C2HIGH
- CVE-2026-8451: Memory Overread in Citrix NetScaler ADC/Gateway SAML IdP ('CitrixBleed'-class, CVSS 8.8) — Exploited Within 24 Hours of DisclosureHIGH
- AsyncRAT Campaign Abuses TryCloudflare Tunnels and Python Scripts for Malware Delivery (AsyncRAT/VenomRAT/XWorm)HIGH
- CVE-2026-21509 - Microsoft Office Security Feature Bypass (CISA KEV) (update)HIGH
- NginRAT/CronRAT Server-Side Magecart Campaign — NGINX LD_PRELOAD Process Parasitism, Impossible Cron Date Persistence (February 31st), Fileless Payment Card Skimming, Dropbear SSH C2 Impersonation, Chinese-Nexus eCommerce Targeting (update)HIGH
- CanisterWorm npm Supply Chain Compromise — Worm-Enabled Backdoor Across 29+ Packages via Publisher Credential Theft (update)HIGH
- ClearFake EtherHiding on BNB Smart Chain Testnet — Smart Contract C2 Delivering SectopRAT + ACRStealer via ClickFix Fake-CAPTCHA (update)HIGH
- Magecart Skimmer Abuses Stripe API + Google Tag Manager for Payload Hosting, C2 & Card Exfiltration (update)HIGH
- Lorem Ipsum Multi-Stage Loader and Backdoor Delivered via SEO-Poisoned Trojanized Microsoft Teams Installers (update)HIGH
- Deno-Based Modular RAT & Internal Proxy Delivered via Mailbombing + Microsoft Teams Vishing ("DenoJSEnv") (update)HIGH
- FortiBleed: Russian-Speaking Credential-Harvesting Campaign Against Internet-Exposed FortiGate Firewalls and SSL VPN Gateways (update)HIGH
- Microsoft Teams Impersonation Phishing Campaign Deploys Signed RMM Installers via Fake Meeting Pages (CYFIRMA)MEDIUM
- WinRAR 7.23 Fixes Heap Overflow in RAR5 Recovery Volume Processing (CVE-2026-14191)MEDIUM
- ChatGPT File Download Flow Path Traversal / Local File Inclusion (LFI) via Guardrail Bypass Social EngineeringMEDIUM
- Fake Interpol Investigation Emails Deliver Custom Ransomware to Small BusinessesMEDIUM
- Indirect Prompt Injection via Web Content Targets AI Agents (SEO Poisoning + Payment Scam / Typosquat Campaigns)MEDIUM
- Claude Cowork Sandbox Escape: RPC Parameter Bypass Enables Root Command ExecutionMEDIUM
- Panera Bread Data Breach - 5.1 Million Accounts Exposed (update)MEDIUM
Techniques observed
302 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- AML.T0031
- AML.T0043
- AML.T0047
- AML.T0051
- AML.T0051.001
- T1001
- T1001.001
- T1001.002
- T1001.003
- T1003
- T1003.001
- T1005
- T1008
- T1010
- T1012
- T1016
- T1016.001
- T1018
- T1020
- T1021
- T1021.001
- T1021.002
- T1021.004
- T1027
- T1027.002
- T1027.003
- T1027.004
- T1027.007
- T1027.013
- T1030
- T1033
- T1036
- T1036.003
- T1036.004
- T1036.005
- T1036.008
- T1037
- T1039
- T1040
- T1041
- T1046
- T1047
- T1048
- T1049
- T1053
- T1053.003
- T1053.005
- T1055
- T1055.001
- T1055.003
- T1055.012
- T1056
- T1056.001
- T1056.002
- T1056.003
- T1057
- T1059
- T1059.001
- T1059.002
- T1059.003
- T1059.004
- T1059.005
- T1059.006
- T1059.007
- T1068
- T1069
- T1069.002
- T1069.003
- T1070
- T1070.001
- T1070.002
- T1070.003
- T1070.004
- T1070.006
- T1070.007
- T1071
- T1071.001
- T1071.004
- T1072
- T1074
- T1074.001
- T1074.002
- T1078
- T1078.003
- T1078.004
- T1082
- T1083
- T1087
- T1087.001
- T1087.002
- T1087.004
- T1090
- T1090.002
- T1090.004
- T1098
- T1098.003
- T1102
- T1102.001
- T1102.002
- T1105
- T1106
- T1110
- T1110.002
- T1110.004
- T1112
- T1113
- T1114
- T1114.001
- T1115
- T1119
- T1120
- T1123
- T1127
- T1129
- T1132
- T1132.001
- T1133
- T1134
- T1135
- T1136
- T1136.001
- T1136.002
- T1137
- T1140
- T1185
- T1189
- T1190
- T1195
- T1195.001
- T1195.002
- T1199
- T1203
- T1204
- T1204.001
- T1204.002
- T1204.003
- T1204.004
- T1210
- T1211
- T1212
- T1213
- T1217
- T1218
- T1218.007
- T1218.011
- T1219
- T1406
- T1407
- T1411
- T1417
- T1418
- T1426
- T1437
- T1472
- T1475
- T1476
- T1480
- T1482
- T1484.001
- T1485
- T1486
- T1489
- T1490
- T1491
- T1491.001
- T1496
- T1497
- T1497.001
- T1497.002
- T1498
- T1499
- T1505
- T1505.003
- T1505.004
- T1509
- T1513
- T1516
- T1517
- T1518
- T1518.001
- T1521
- T1523
- T1525
- T1526
- T1528
- T1530
- T1531
- T1533
- T1534
- T1537
- T1539
- T1541
- T1543
- T1543.003
- T1546
- T1546.015
- T1547
- T1547.001
- T1548
- T1548.002
- T1550
- T1550.001
- T1550.002
- T1550.004
- T1552
- T1552.001
- T1552.004
- T1552.005
- T1552.007
- T1553
- T1553.002
- T1554
- T1555
- T1555.003
- T1556
- T1556.006
- T1557
- T1558
- T1559
- T1560
- T1560.001
- T1561
- T1562
- T1562.001
- T1562.008
- T1564
- T1564.001
- T1564.003
- T1565
- T1565.001
- T1566
- T1566.001
- T1566.002
- T1567
- T1567.002
- T1568
- T1568.002
- T1568.003
- T1569
- T1569.002
- T1570
- T1571
- T1572
- T1573
- T1573.001
- T1573.002
- T1574
- T1574.002
- T1574.005
- T1574.006
- T1578
- T1580
- T1583
- T1583.001
- T1583.004
- T1583.006
- T1584
- T1584.004
- T1584.006
- T1585
- T1585.001
- T1586
- T1587
- T1587.001
- T1587.004
- T1588
- T1588.001
- T1588.002
- T1588.003
- T1588.005
- T1588.006
- T1589
- T1590
- T1591
- T1592
- T1592.002
- T1593
- T1595
- T1595.001
- T1595.002
- T1596
- T1596.005
- T1602
- T1606
- T1608
- T1608.001
- T1608.002
- T1608.006
- T1610
- T1611
- T1613
- T1614.001
- T1620
- T1622
- T1624
- T1626
- T1629
- T1633
- T1636
- T1655
- T1656
- T1657
Threat actors
30 named threat actors across the reports.
- independent operator
- Storm-2603
- ToddyCat
- Tetrade
- REMUS MaaS operator
- NetNut
- not attributed to a named APT)
- FortiBleed IAB
- UAT-8616
- JADEPUFFER
- FortiBleed Operator
- Anubis
- FortiBleed IAB Crew
- ShinyHunters
- APT28
- Magecart
- TeamPCP
- UNC5142
- Vanilla Tempest
- MuddyWater
- INC Ransom
- Warlock
- Contagious Interview
- UNC1069
- UNC5221
- Embargo
- CL-STA-1132
- APT38
- Icarus
- Patchwork
Nation-state attribution
- China
- India (assessed, residential-ISP origin)
- Brazil
- Russia
- Iran
- North Korea
- India
Threat categories
- PHISHING
- VULNERABILITY
- RANSOMWARE
- THREAT_INTEL
- MALWARE
- APT
- BOTNET
- DATA_BREACH
- SUPPLY_CHAIN
- ZERO_DAY
Severity breakdown
- critical30
- high27
- medium7
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- behavioral 413
- network 350
- file 306
- entity 109
- tool 91
- infrastructure 86
- technique 84
- package 74
- malware 65
- host 26
- vulnerability 22