Summary & highlights
Browser-Only Ransomware (InfernoGrabber v9.0) Abuses Chrome File System Access API to Encrypt Android Photos. AI-Generated Browser-Only Ransomware Abuses Chrome File System Access API (InfernoGrabber 9000 / DeepSeek). Nebula — AI-Integrated Open-Source Penetration Testing Tool (BerylliumSec) — Dual-Use Tool Tracking, No CVE/Active Exploitation.
Highlights
- TL-2026-1104 — PamStealer: Rust-Based macOS Infostealer Masquerades as Maccy Clipboard Manager, Validates Stolen Passwords via PAM
- TL-2026-1105 — Bad Epoll (CVE-2026-46242): Use-After-Free Zero-Day in Linux Kernel epoll Subsystem Enables Root Privilege Escalation
- TL-2026-1106 — "Bad Epoll" Linux Kernel Use-After-Free (CVE-2026-46242) Enables Unprivileged Root Escalation, Impacts Android
- TL-2026-1107 — ARToken PhaaS Platform Exposes EvilTokens-Affiliated Microsoft 365 Device Code Phishing Toolkit
- TL-2026-1111 — North Korea-Linked "Contagious Interview"/Famous Chollima Actors Hide JavaScript Loaders (PolinRider) in Open-Source Packages
Theme of the day
- defense-evasion
- credential-theft
- social-engineering
- data-exfiltration
- financially-motivated
Threats published
30 threat lines in the 2026-07-05 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- Pegasus Spyware Used Against Former MEP Stelios Kouloglou While Serving on PEGA CommitteeCRITICAL
- JADEPUFFER: AI Agent Exploits Langflow RCE (CVE-2025-3248) to Automate Database Ransomware/Extortion AttackCRITICAL
- FortiBleed Credential Theft Campaign Linked to INC and Lynx Ransomware OperationsCRITICAL
- SimpleHelp Authentication Bypass via Forged OIDC Tokens (CVE-2026-48558) Actively Exploited, Added to CISA KEVCRITICAL
- CVE-2026-8037: Pre-Authentication Remote Code Execution in Progress Kemp LoadMaster via escape_quotes() Heap Out-of-Bounds ReadCRITICAL
- CVE-2026-20253: Critical Unauthenticated Remote Code Execution in Splunk Enterprise via PostgreSQL Sidecar Service (update)CRITICAL
- JADEPUFFER Agentic Ransomware Exploits Langflow CVE-2025-3248 and Nacos CVE-2021-29441 via Base64-Encoded Python Payloads (update)CRITICAL
- PolinRider: North Korea-Linked Supply Chain Campaign Expands Across npm, Packagist, Go Modules, and Chrome Extensions (update)CRITICAL
- CISA KEV Addition: Microsoft SharePoint Server Deserialization RCE (CVE-2026-45659) Actively Exploited by Storm-2603 / Warlock Ransomware (update)CRITICAL
- FortiBleed Credential Theft Campaign: FortigateSniffer Tool Deployed Against 430,000+ FortiGate Firewalls, Linked to INC Ransom and Lynx Ransomware (update)CRITICAL
- PamStealer: Rust-Based macOS Infostealer Masquerades as Maccy Clipboard Manager, Validates Stolen Passwords via PAMHIGH
- Bad Epoll (CVE-2026-46242): Use-After-Free Zero-Day in Linux Kernel epoll Subsystem Enables Root Privilege EscalationHIGH
- "Bad Epoll" Linux Kernel Use-After-Free (CVE-2026-46242) Enables Unprivileged Root Escalation, Impacts AndroidHIGH
- ARToken PhaaS Platform Exposes EvilTokens-Affiliated Microsoft 365 Device Code Phishing ToolkitHIGH
- North Korea-Linked "Contagious Interview"/Famous Chollima Actors Hide JavaScript Loaders (PolinRider) in Open-Source PackagesHIGH
- Microsoft Exchange SSRF Vulnerability (CVE-2026-45504) — Public PoC Exploit Enables Authenticated Arbitrary File ReadHIGH
- ClickFix Social-Engineering Technique Becomes Dominant Malware Delivery and Defense-Evasion Vector (CrashFix, FileFix, ConsentFix Variants)HIGH
- EvilTokens/ARToken Device-Code Phishing Kit Bypasses MFA to Compromise Microsoft 365 AccountsHIGH
- ClickFix / KongTuke Clipboard-Hijacking Social-Engineering Technique (MITRE T1204.004) — Fake-CAPTCHA Lures Delivering Infostealers, RATs, and RansomwareHIGH
- Remcos RAT: Technical Analysis of Windows Remote Access Trojan OperationsHIGH
- Armored Likho APT Targets Government and Power Sector with New BusySnake Stealer via CVE-2025-9491 LNK Abuse (update)HIGH
- AsyncRAT Campaign Abuses TryCloudflare Tunnels and Python Scripts for Malware Delivery (AsyncRAT/VenomRAT/XWorm) (update)HIGH
- ChocoPoC: Python RAT Distributed via Trojanized PoC Exploits Targeting Security Researchers (update)HIGH
- Cross-Platform Phishing Campaigns Auto-Adapt Payloads to Victim Device/OS via Fingerprinting (update)HIGH
- GuardFall: Shell-Injection Guardrail Bypass Exposes Open-Source AI Coding Agents to Supply-Chain Attacks (update)HIGH
- Browser-Only Ransomware (InfernoGrabber v9.0) Abuses Chrome File System Access API to Encrypt Android PhotosMEDIUM
- AI-Generated Browser-Only Ransomware Abuses Chrome File System Access API (InfernoGrabber 9000 / DeepSeek)MEDIUM
- Claude Cowork Sandbox Escape: RPC Parameter Bypass Enables Root Command Execution (update)MEDIUM
- Nebula — AI-Integrated Open-Source Penetration Testing Tool (BerylliumSec) — Dual-Use Tool Tracking, No CVE/Active Exploitation
- La Trobe University research: network-based detection of SMB shared-storage ransomware encryption
Techniques observed
253 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T1003
- T1003.001
- T1003.008
- T1005
- T1008
- T1014
- T1016
- T1018
- T1020
- T1021
- T1021.001
- T1021.002
- T1027
- T1027.002
- T1033
- T1036
- T1036.003
- T1036.005
- T1036.008
- T1037
- T1039
- T1040
- T1041
- T1046
- T1047
- T1048
- T1049
- T1053
- T1053.003
- T1053.005
- T1055
- T1055.012
- T1056
- T1056.001
- T1056.002
- T1057
- T1059
- T1059.001
- T1059.002
- T1059.003
- T1059.004
- T1059.005
- T1059.006
- T1059.007
- T1068
- T1069
- T1070
- T1070.004
- T1070.006
- T1071
- T1071.001
- T1071.002
- T1072
- T1074
- T1074.001
- T1078
- T1078.001
- T1082
- T1083
- T1087
- T1087.001
- T1087.004
- T1090
- T1090.001
- T1090.002
- T1090.004
- T1098
- T1102
- T1102.001
- T1102.002
- T1105
- T1106
- T1110
- T1110.001
- T1111
- T1112
- T1113
- T1114
- T1115
- T1119
- T1123
- T1125
- T1127
- T1129
- T1132
- T1132.001
- T1133
- T1136
- T1136.001
- T1137
- T1140
- T1176
- T1185
- T1187
- T1189
- T1190
- T1195
- T1195.001
- T1195.002
- T1199
- T1202
- T1203
- T1204
- T1204.001
- T1204.002
- T1204.004
- T1210
- T1211
- T1212
- T1213
- T1217
- T1218
- T1218.003
- T1218.005
- T1218.007
- T1218.011
- T1219
- T1404
- T1407
- T1409
- T1414
- T1420
- T1421
- T1424
- T1426
- T1429
- T1430
- T1456
- T1480.001
- T1482
- T1484
- T1485
- T1486
- T1489
- T1490
- T1491.001
- T1497
- T1497.001
- T1498
- T1505
- T1505.003
- T1512
- T1517
- T1518
- T1518.001
- T1521
- T1526
- T1528
- T1531
- T1533
- T1537
- T1539
- T1542
- T1543
- T1543.003
- T1547
- T1547.001
- T1547.014
- T1547.015
- T1548
- T1548.001
- T1548.002
- T1548.003
- T1550
- T1550.001
- T1552
- T1552.001
- T1552.004
- T1553
- T1553.001
- T1553.002
- T1554
- T1555
- T1555.001
- T1555.003
- T1556
- T1558
- T1560
- T1561
- T1562
- T1562.001
- T1562.004
- T1564
- T1564.001
- T1564.003
- T1565
- T1565.002
- T1566
- T1566.001
- T1566.002
- T1566.003
- T1567
- T1567.002
- T1567.004
- T1568
- T1568.002
- T1569
- T1570
- T1571
- T1572
- T1573
- T1573.001
- T1573.002
- T1574
- T1574.002
- T1583
- T1583.001
- T1583.004
- T1583.006
- T1583.008
- T1584
- T1585
- T1585.001
- T1585.003
- T1586
- T1587
- T1587.001
- T1587.004
- T1588
- T1588.001
- T1588.002
- T1588.003
- T1588.005
- T1588.006
- T1588.007
- T1589
- T1591
- T1592
- T1592.002
- T1595
- T1595.002
- T1596
- T1598
- T1600
- T1606
- T1608
- T1608.001
- T1611
- T1613
- T1614
- T1614.001
- T1616
- T1619
- T1620
- T1622
- T1629
- T1631
- T1636
- T1637
- T1639
- T1646
- T1656
- T1657
Threat actors
12 named threat actors across the reports.
- LockBit — referenced only as the illustrative test sample in the cited detection research
- WageMole
- EvilTokens PhaaS Operators
- KongTuke
- Unidentified NSO Group Pegasus Customer
- JADEPUFFER
- FortiBleed Initial Access Broker
- Armored Likho
- not attributed to a named APT)
- Contagious Interview
- Storm-2603
- INC Ransom
Nation-state attribution
- Russia (affiliate nationals per 2024 DOJ/Operation Cronos indictments; LockBit is a financially motivated criminal RaaS operation, not confirmed state-sponsored)
- North Korea
- Russia
- North Korea (DPRK)
- China
Threat categories
- MALWARE
- RANSOMWARE
- THREAT_INTEL
- VULNERABILITY
- PHISHING
- SUPPLY_CHAIN
Severity breakdown
- critical10
- high15
- medium3
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- behavioral 182
- file 174
- network 167
- tool 109
- entity 71
- malware 62
- infrastructure 56
- package 32
- technique 12