Summary & highlights
npm 12 Disables Install Scripts, Git Dependencies, and Remote Tarball URLs by Default to Curb Supply-Chain Worms Like Shai-Hulud. HalluSquatting: AI Coding Assistant Hallucinations Weaponized to Deliver Botnet Malware via Fake Package/Tool/Skill Names. Former DigitalMint Ransomware Negotiator Angelo Martino Sentenced to 70 Months for BlackCat/ALPHV Extortion Scheme.
Highlights
- TL-2026-1157 — RoguePlanet: Microsoft Defender Elevation of Privilege Vulnerability (CVE-2026-50656) Patched
- TL-2026-1161 — Forg365 Phishing-as-a-Service Platform Uses AI-Generated Lures and AiTM/Device-Code Phishing to Compromise Microsoft 365 Accounts
- TL-2026-1162 — UNK_MassTraction Exploits Roundcube XSS/Deserialization Flaws (CVE-2024-42009, CVE-2025-49113) to Spy on Academic Researchers
- TL-2026-1165 — Braintree.Net NuGet Typosquat Uses XOR-Obfuscated WebSocket/HTTPS C2 to Exfiltrate Live Payment Card Data and Merchant Credentials
- TL-2026-1167 — GigaWiper: Multi-Stage Destructive Windows Backdoor Combining Disk Wiping, File Encryption, and Boot Sabotage (CyberAv3ngers/Crucio/FlockWiper Lineage)
Theme of the day
- credential-theft
- privilege-escalation
- financially-motivated
- credential-harvesting
- data-exfiltration
Threats published
51 threat lines in the 2026-07-10 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- GigaWiper (aka BLUERABBIT): Golang-Based Destructive Backdoor Combining Wiper, Fake Ransomware, and C2 CapabilitiesCRITICAL
- CVE-2026-50746: Critical Unauthenticated Command Injection in Ubiquiti UniFi Connect Application (CVSS 10.0)CRITICAL
- 'Ill Bloom' Weak-Randomness Vulnerability in Legacy Crypto Wallets Actively Exploited to Drain $3.1M+CRITICAL
- Zimbra Collaboration Suite Critical Stored XSS in Classic Web Client (Patched in ZCS 10.1.19)CRITICAL
- Microsoft's MDASH AI Scanning Harness Uncovers 16 Windows CVEs, Including Four Critical RCE Flaws in TCP/IP, IKEv2, Netlogon, and DNSCRITICAL
- CVE-2026-11405: Undocumented Authentication Backdoor in Tenda Router Firmware (FH1201, W15E, AC10, AC5, AC6)CRITICAL
- CVE-2026-52830: Path Traversal in fast-mcp-telegram Bearer Token Validation Exposes Telegram Session FilesCRITICAL
- 14 Vulnerabilities Expose Citizen PII in Indian Government Systems — UPSC Portal Admin Takeover, Delhi Directorate of Education & Scholarship Portal Data ExposureCRITICAL
- CVE-2026-8037: Pre-Auth Command Injection RCE in Progress Kemp LoadMaster via Uninitialized-Heap escape_quotes() Flaw on /accessv2 (update)CRITICAL
- JADEPUFFER: AI Agent Exploits Langflow RCE (CVE-2025-3248) to Automate Database Ransomware/Extortion Attack (update)CRITICAL
- The Gentlemen Ransomware: Worm-Like Self-Propagation and Network-Wide Encryption via Storm-2697's RaaS Affiliate Program (update)CRITICAL
- CitrixBleed 2 (CVE-2025-5777) Weaponized by Initial Access Broker for DragonForce Ransomware Deployment (update)CRITICAL
- RoguePlanet: Microsoft Defender Elevation of Privilege Vulnerability (CVE-2026-50656) PatchedHIGH
- Forg365 Phishing-as-a-Service Platform Uses AI-Generated Lures and AiTM/Device-Code Phishing to Compromise Microsoft 365 AccountsHIGH
- UNK_MassTraction Exploits Roundcube XSS/Deserialization Flaws (CVE-2024-42009, CVE-2025-49113) to Spy on Academic ResearchersHIGH
- Braintree.Net NuGet Typosquat Uses XOR-Obfuscated WebSocket/HTTPS C2 to Exfiltrate Live Payment Card Data and Merchant CredentialsHIGH
- GigaWiper: Multi-Stage Destructive Windows Backdoor Combining Disk Wiping, File Encryption, and Boot Sabotage (CyberAv3ngers/Crucio/FlockWiper Lineage)HIGH
- Infostealer Campaigns (Lumma, RedLine, StealC) Harvesting AI Coding Agent and Developer Platform Credentials at ScaleHIGH
- Callback Phishing Campaign Impersonates Robinhood With Fake Sign-In Alerts (LevelBlue SpiderLabs)HIGH
- Everest Ransomware: Triple Extortion via Encryption, Access Brokering, and Insider RecruitmentHIGH
- Google Chrome 150.0.7871.114/.115 Patches 27 Vulnerabilities Including Two Critical Use-After-Free Flaws (CVE-2026-15112, CVE-2026-15129)HIGH
- SCMBANKER PowerShell Banking Trojan Targets Mexican Financial Sector via ClickFix Fake CAPTCHA Lures (REF6045)HIGH
- Linux Kernel FUSE Page-Cache Buffer Overflow (CVE-2026-31694) Enables Local Privilege EscalationHIGH
- Malicious Windows Shortcuts (LNK) Deploy Node.js Backdoor via PowerShell and TON Blockchain C2 (EtherHiding-style)HIGH
- GNU Guix 'guix substitute' and 'guix pull' Vulnerabilities Enable Arbitrary File Write, Metadata Spoofing, Local Secret Disclosure, and Path Traversal (CVE Pending)HIGH
- WP-SHELLSTORM: Exposed Chinese-Speaking Threat Actor Server Reveals Mass WordPress/Joomla Webshell Brokerage Targeting 1.4M Domains via CVE-2026-48907 (Joomla JCE) and CVE-2021-29441 (Nacos)HIGH
- MODBEACON RAT Uses gRPC Streaming C2, Deployed by Silver Fox via SEO-Poisoned Software InstallersHIGH
- Lone Attacker Uses AI-Assisted Workflows to Breach Large AWS Cloud Environment in 72 Hours (Sygnia Investigation)HIGH
- Roundcube Webmail 0-Click Stored XSS (CVE-2026-54432, CVE-2026-54433) — Versions Prior to 1.6.17 / 1.7.2HIGH
- O-UNC-066 ("Pink") Abuses Microsoft Entra Passkey Enrollment via Live-Operator Phone Phishing to Hijack Enterprise AccountsHIGH
- CVE-2026-53359 ("Januscape") - 16-Year-Old Linux KVM Shadow MMU Use-After-Free Exploited as Zero-DayHIGH
- EtherRAT: DPRK-Linked Vishing Campaign Abuses Microsoft Teams and Ethereum Smart Contracts to Deliver Blockchain-Resilient Node.js RATHIGH
- Armenian National Karen Vardanyan Pleads Guilty to Ryuk Ransomware Conspiracy (District of Oregon)HIGH
- Pegasus Spyware Re-Targets EU Parliamentarian: Stelios Kouloglou Hacked via PWNYOURHOME Zero-Click Chain While Investigating Spyware Abuse on PEGA CommitteeHIGH
- SilverFox Deploys ValleyRAT (Go-Based RAT) with Kernel Rootkit AV/EDR KillerHIGH
- Glitch SPY Android RAT Distributed via Fake Polish Rental App ("Tutaj Dom") Using Brokewell LoaderHIGH
- Malicious 'Free VPN' Chrome and Firefox Extensions (VPN Go) Deploy Clipboard-Stealing Malware via Trojanized UpdatesHIGH
- CVE-2026-33825: Microsoft Defender Local Privilege Escalation via BlueHammer TOCTOU Race Condition (update)HIGH
- CVE-2026-50656: RoguePlanet Microsoft Defender Zero-Day Local Privilege Escalation (Malware Protection Engine TOCTOU) (update)HIGH
- ARToken Phishing Panel Abuses Microsoft OAuth Device Code Flow to Hijack Microsoft 365 Accounts (EvilTokens PhaaS) (update)HIGH
- GodDamn Ransomware (Hyadina) — Third Rebrand from Monster/Beast, Deploys Signed PoisonX Kernel Driver (update)HIGH
- Operation Muck and Load: Malicious Go Module (dnsub-scanning-tool) Fronts 222-Repo GitHub Malware Lure Network Delivering AsyncRAT/Quasar and Vidar (update)HIGH
- Blackfield (BlackFL) Ransomware Demands $2 Million from Nidec Chaun-Choung Technology Corporation (Nidec Corporation Subsidiary) (update)HIGH
- npm 12 Disables Install Scripts, Git Dependencies, and Remote Tarball URLs by Default to Curb Supply-Chain Worms Like Shai-HuludMEDIUM
- HalluSquatting: AI Coding Assistant Hallucinations Weaponized to Deliver Botnet Malware via Fake Package/Tool/Skill NamesMEDIUM
- Former DigitalMint Ransomware Negotiator Angelo Martino Sentenced to 70 Months for BlackCat/ALPHV Extortion SchemeMEDIUM
- HTML Phishing Attachment Uses "Comment Stuffing" to Evade AI-Based Detection (SharePoint/Teams Credential Harvesting via Formspark)MEDIUM
- Former Ransomware Negotiator Angelo Martino Sentenced to 70 Months for Insider Collusion with BlackCat/ALPHV Affiliates Ryan Goldberg and Kevin MartinMEDIUM
- Vidar Infostealer and XMRig Cryptominer Malvertising Campaign Targeting SMBs (Factory-v3 / X3D MINER)MEDIUM
- HalluSquatting: Attacker-Registered Hallucinated Resource Names Fueling Agentic BotnetsMEDIUM
- Six AirDrop and Quick Share Proximity File-Transfer Vulnerabilities (Apple, Google, Samsung) — 'Protocol Prying' ResearchMEDIUM
Techniques observed
313 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T1001.001
- T1003
- T1003.001
- T1005
- T1007
- T1008
- T1010
- T1012
- T1014
- T1016
- T1016.001
- T1018
- T1020
- T1021
- T1021.001
- T1021.002
- T1021.004
- T1021.006
- T1027
- T1027.001
- T1027.006
- T1027.013
- T1033
- T1036
- T1036.001
- T1036.005
- T1036.008
- T1040
- T1041
- T1046
- T1047
- T1048
- T1049
- T1053
- T1053.003
- T1053.005
- T1055
- T1056
- T1056.001
- T1056.002
- T1056.003
- T1057
- T1059
- T1059.001
- T1059.003
- T1059.004
- T1059.005
- T1059.006
- T1059.007
- T1059.009
- T1068
- T1069
- T1069.001
- T1069.002
- T1069.003
- T1070
- T1070.001
- T1070.003
- T1070.004
- T1070.006
- T1071
- T1071.001
- T1074
- T1074.001
- T1078
- T1078.001
- T1078.003
- T1078.004
- T1080
- T1082
- T1083
- T1087
- T1087.002
- T1087.003
- T1087.004
- T1090
- T1090.002
- T1090.003
- T1090.004
- T1091
- T1095
- T1098
- T1098.001
- T1098.002
- T1098.003
- T1098.005
- T1102
- T1102.001
- T1102.002
- T1105
- T1106
- T1110
- T1110.001
- T1110.002
- T1111
- T1112
- T1113
- T1114
- T1114.002
- T1114.003
- T1115
- T1119
- T1120
- T1123
- T1125
- T1129
- T1132
- T1132.001
- T1133
- T1134
- T1134.002
- T1134.003
- T1135
- T1136
- T1136.001
- T1140
- T1176
- T1176.001
- T1187
- T1189
- T1190
- T1195
- T1195.001
- T1195.002
- T1195.003
- T1197
- T1199
- T1202
- T1203
- T1204
- T1204.001
- T1204.002
- T1204.003
- T1210
- T1211
- T1212
- T1213
- T1213.002
- T1217
- T1218
- T1219
- T1222
- T1222.001
- T1414
- T1417
- T1418
- T1420
- T1426
- T1429
- T1430
- T1437
- T1453
- T1471
- T1480
- T1482
- T1484
- T1485
- T1486
- T1489
- T1490
- T1491
- T1491.001
- T1495
- T1496
- T1497
- T1497.001
- T1497.003
- T1498
- T1499
- T1499.004
- T1505
- T1505.003
- T1513
- T1516
- T1518
- T1518.001
- T1525
- T1526
- T1528
- T1529
- T1530
- T1531
- T1532
- T1533
- T1537
- T1538
- T1539
- T1543
- T1543.002
- T1543.003
- T1546
- T1546.004
- T1547
- T1547.001
- T1547.013
- T1548
- T1548.001
- T1548.002
- T1550
- T1550.001
- T1550.004
- T1552
- T1552.001
- T1552.004
- T1553
- T1553.002
- T1553.003
- T1554
- T1555
- T1555.003
- T1556
- T1556.006
- T1557
- T1558
- T1559
- T1560
- T1560.001
- T1561
- T1561.001
- T1562
- T1562.001
- T1562.002
- T1562.004
- T1564
- T1564.001
- T1564.003
- T1565
- T1565.001
- T1566
- T1566.001
- T1566.002
- T1566.003
- T1566.004
- T1567
- T1567.002
- T1568
- T1569
- T1569.002
- T1570
- T1571
- T1572
- T1573
- T1573.001
- T1574
- T1574.001
- T1574.002
- T1574.009
- T1578
- T1580
- T1583
- T1583.001
- T1583.003
- T1583.004
- T1583.006
- T1583.008
- T1584
- T1584.004
- T1584.008
- T1585
- T1585.001
- T1585.002
- T1586
- T1586.002
- T1586.003
- T1587
- T1587.001
- T1587.004
- T1588
- T1588.001
- T1588.006
- T1589
- T1589.002
- T1590.004
- T1591
- T1591.002
- T1592
- T1592.004
- T1595
- T1595.001
- T1596
- T1596.005
- T1598
- T1598.002
- T1598.004
- T1601.002
- T1606
- T1608
- T1608.001
- T1608.005
- T1609
- T1610
- T1611
- T1613
- T1614
- T1615
- T1619
- T1620
- T1621
- T1622
- T1624
- T1628
- T1629
- T1636
- T1646
- T1648
- T1651
- T1655
- T1656
- T1657
- T1660
- T1662
- T1680
- T1685
Threat actors
23 named threat actors across the reports.
- BlackCat
- ALPHV
- X3D MINER
- Chaotic Eclipse
- UNK_MassTraction
- Iran-nexus actor
- Everest
- REF6045 operator
- WP-SHELLSTORM Crew
- Void Arachne
- O-UNC-066
- DPRK-linked
- Periwinkle Tempest
- NSO Group Pegasus customer
- Baron Samedit Marais
- Cyber Av3ngers
- Nightmare Eclipse
- EvilTokens (eviltokensadmin)
- Hyadina
- Blackfield
- JADEPUFFER
- Storm-2697 / The Gentlemen
- DragonForce-affiliated Initial Access Broker
Nation-state attribution
- China
- Iran (assessed, not confirmed by Microsoft)
- North Korea
- Russia
- Iran
Threat categories
- SUPPLY_CHAIN
- VULNERABILITY
- RANSOMWARE
- PHISHING
- CYBERCRIME
- MALWARE
- INTRUSION
- SURVEILLANCE
Severity breakdown
- critical12
- high31
- medium8
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- behavioral 288
- file 279
- network 233
- entity 146
- tool 92
- infrastructure 91
- malware 70
- technique 50
- package 37
- vulnerability 15