Summary & highlights
Dell BIOS Flaw (CVE-2026-40639 / DSA-2026-197) Lets Attackers Recover Admin Passwords From SPI Flash. DCloud Uni-App Scam Network Powers RainbowEx-Style Crypto Fraud Across 236,000+ Domains. Rapid7 Policy Paper 'Modernizing Global Vulnerability Standards' Warns AI-Driven Vulnerability Discovery Is Outpacing CVE/CVSS/NVD Standards.
Highlights
- TL-2026-1201 — EvilTokens Phishing-as-a-Service Kit Abuses Microsoft Device Code Authentication with AES-GCM "Ghost Code" to Breach Finance, Tech, and Managed Security Firms
- TL-2026-1202 — Forg365: Telegram-Distributed Phishing-as-a-Service Abusing Microsoft Device-Code Flow and AiTM to Hijack Microsoft 365/Entra Sessions
- TL-2026-1203 — CVE-2026-20251: Splunk Secure Gateway jsonpickle Deserialization RCE with Public PoC
- TL-2026-1205 — CVE-2025-60727: Microsoft 365 Apps Excel Out-of-Bounds Read Enables Remote Code Execution
- TL-2026-1207 — StegoAd Campaign: 119 Malicious Microsoft Edge Extensions Deliver Steganographic Malware to 2.6M Users
Theme of the day
Unattributed actors exploited vulnerabilities in government systems and router firmware, posing risks to sensitive information. Access token theft and account takeover were notable tactics used today.
- credential-theft
- remote-code-execution
- cisa-kev
- financially-motivated
- supply-chain-attack
Threats published
48 threat lines in the 2026-07-11 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- Dell Wyse Management Suite Critical RCE Chain (CVE-2026-41120, CVE-2026-49506)CRITICAL
- Critical Gemini CLI Vulnerability (CVE-2026-12537) Enables Remote Code Execution via Malicious .env Workspace Trust BypassCRITICAL
- Zimbra Collaboration Suite Classic Web Client Stored XSS (patched in 10.1.19, no CVE yet)CRITICAL
- Broken Object-Level Authorization (BOLA) in Airline GraphQL Booking API Exploited via Autonomous AI Red-Team AgentCRITICAL
- Australia (ACSC) Warns of Global Campaign Exploiting Vulnerable CMS Platforms to Deploy WebshellsCRITICAL
- Public PoC Released for Critical libssh2 Client-Side SSH Flaw (CVE-2026-55200)CRITICAL
- CVE-2026-20230: Cisco Unified Communications Manager WebDialer SSRF Actively Exploited to Drop Tor-Routed JSP Webshells via Rogue Apache Axis Service, CISA Sets June 28 DeadlineCRITICAL
- Compromised jscrambler npm Package v8.14.0 Drops Rust Infostealer via Preinstall HookCRITICAL
- Cisco Unified CM / Unified CM SME SSRF Vulnerability (CVE-2026-20230) — WebDialer File-Write to Root, Actively Exploited, Added to CISA KEVCRITICAL
- ShinyHunters (UNC6240) Exploits Oracle PeopleSoft PeopleTools CVE-2026-35273 Zero-Day to Compromise 100+ Higher-Education Organizations (update)CRITICAL
- CVE-2026-46817: Unauthenticated Arbitrary File Read in Oracle E-Business Suite Payments File Transmission Exploited Before Public PoC (update)CRITICAL
- SimpleHelp Authentication Bypass via Forged OIDC Tokens (CVE-2026-48558) Actively Exploited, Added to CISA KEV (update)CRITICAL
- CISA KEV Adds CVE-2026-12569 (PTC Windchill/FlexPLM Unauthenticated RCE via Deserialization) and CVE-2026-20230 (Cisco Unified CM WebDialer SSRF to Root) (update)CRITICAL
- EvilTokens Phishing-as-a-Service Kit Abuses Microsoft Device Code Authentication with AES-GCM "Ghost Code" to Breach Finance, Tech, and Managed Security FirmsHIGH
- Forg365: Telegram-Distributed Phishing-as-a-Service Abusing Microsoft Device-Code Flow and AiTM to Hijack Microsoft 365/Entra SessionsHIGH
- CVE-2026-20251: Splunk Secure Gateway jsonpickle Deserialization RCE with Public PoCHIGH
- CVE-2025-60727: Microsoft 365 Apps Excel Out-of-Bounds Read Enables Remote Code ExecutionHIGH
- StegoAd Campaign: 119 Malicious Microsoft Edge Extensions Deliver Steganographic Malware to 2.6M UsersHIGH
- FulcrumSec Double-Extortion Data Theft of Global Schools Foundation (GSF) EdTech Network via Unrotated 2022 MongoDB CredentialsHIGH
- Gamaredon (Primitive Bear / Shuckworm) APT Profile: Russia-Aligned Espionage Against Ukraine and NATO, Now Exploiting CVE-2025-8088 (WinRAR)HIGH
- 236,493 DCloud Uni-App-Built Sites Weaponized in Global Crypto Scam, Wallet-Drainer and Phishing Economy (RainbowEx, LSSC, Yuechi)HIGH
- ClawHub Marketplace Skills Expose OpenClaw AI Agents to RCE, Data Theft, and Supply-Chain Backdoors (CVE-2026-25253)HIGH
- Operation Turb00: Multi-Stage HijackLoader (IDAT Loader) Campaign Delivers Vidar v2.1 Infostealer and SnappyClient RAT via PNG-IDAT SteganographyHIGH
- PolinRider DPRK npm Supply-Chain Loader Uses Blockchain Dead Drops for C2 (BeaverTail/InvisibleFerret)HIGH
- Indirect Prompt Injection in AI Coding Agents Enables Reverse Shell via Malicious GitHub Repos (Mozilla 0DIN "axiom" PoC)HIGH
- The Gentlemen RaaS (Storm-2697) — Multi-Platform Ransomware-as-a-Service with BYOVD Defense Evasion and Self-Propagating Go EncryptorHIGH
- StegoAd Campaign: 119 Malicious Edge Extensions Hid Malware in Images, Fonts, and Config Files, Up to 2.6M InstallsHIGH
- Millenium RAT v4: C++ Rewrite Fuels Y2K Operators' MaaS Campaign (62,289 Devices, 160+ Countries)HIGH
- UNC1151 (Ghostwriter/FrostyNeighbor) Real-Time WebSocket MFA-Bypass Credential-Phishing Campaign Targets Belarusian Opposition Politician Yury HubarevichHIGH
- Rokarolla Android Banking Trojan Intercepts SMS OTPs and Enables Full Device Takeover Across 217+ Banking and Crypto AppsHIGH
- SystemBC (Coroxy / DroxiDat) Malware: Multi-Purpose SOCKS5/Tor Proxy Backdoor Enabling Ransomware OperationsHIGH
- Domestic APT Spear-Phishing Campaigns (May 2026) — LNK/HTA/CHM/JSE Loaders Deploying XenoRAT, Suspected KimsukyHIGH
- Cryptojacking Campaign Exploiting Gogs (CVE-2026-52806) and Argo Workflows (CVE-2026-42296/CVE-2026-42295) Targets Managed Kubernetes ClustersHIGH
- GhostCommit: PNG-Steganography Prompt Injection Bypasses AI Code Reviewers and Coding Agents to Exfiltrate SecretsHIGH
- FortiBleed: Mass Credential Compromise Campaign Against Internet-Exposed Fortinet FortiGate Devices (86,644 Devices, 194 Countries)HIGH
- jscrambler npm Package Supply Chain Compromise (v8.14.0 Malicious Release)HIGH
- KDDI Zero-Day Exploit in Third-Party Software Exposes Up to 14.2 Million Email Accounts at Six Japanese ISPs (STNet, JCOM, Chubu Telecommunications, NIFTY, BIGLOBE, KDDI Web Communications)HIGH
- StrikeShark Campaign: SharkLoader Dropper Targets Governments and Software Developers via N-Day Exploits and Trojanized Installers to Deploy Cobalt StrikeHIGH
- Multi-Actor Espionage Campaign Weaponizes Balochistan Police Complaint Management Portal (PlugX, ShadowPad, Cobalt Strike, Remcos/TAG-179)HIGH
- Counterfeit China-Made USB Drives with Self-Replicating Malware Infect 50+ Japan Ground Self-Defense Force Computers (Nikkei Investigation)HIGH
- python.org Release Management API Authentication Bypass (Patched, No Exploitation Confirmed)HIGH
- JetBrains Marketplace Supply Chain Attack: 15 Malicious AI-Assistant Plugins Exfiltrate DeepSeek/OpenAI API Keys to 39.107.60.51HIGH
- Binding.gyp "Phantom Gyp" Supply Chain Attack (Miasma Worm) Enables CI/CD Worm Propagation Across 57 npm Packages (update)HIGH
- Dell BIOS Flaw (CVE-2026-40639 / DSA-2026-197) Lets Attackers Recover Admin Passwords From SPI FlashMEDIUM
- DCloud Uni-App Scam Network Powers RainbowEx-Style Crypto Fraud Across 236,000+ DomainsMEDIUM
- Compromised RD Session Host Used to Stage Boots-Themed Phishing Campaign via Gammadyne Mailer (update)MEDIUM
- Rapid7 Policy Paper 'Modernizing Global Vulnerability Standards' Warns AI-Driven Vulnerability Discovery Is Outpacing CVE/CVSS/NVD Standards
- Zhipu AI's GLM-5.2 Matches Export-Controlled Claude Mythos on IDOR Vulnerability Detection
Techniques observed
276 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T1001
- T1001.002
- T1003
- T1005
- T1007
- T1008
- T1012
- T1014
- T1016
- T1018
- T1020
- T1021
- T1021.001
- T1021.007
- T1022
- T1025
- T1027
- T1027.002
- T1027.003
- T1027.006
- T1027.011
- T1027.013
- T1033
- T1036
- T1036.004
- T1036.005
- T1036.007
- T1037.001
- T1039
- T1040
- T1041
- T1046
- T1047
- T1048
- T1048.003
- T1053
- T1053.005
- T1055
- T1055.012
- T1056
- T1056.001
- T1056.003
- T1057
- T1059
- T1059.001
- T1059.003
- T1059.004
- T1059.005
- T1059.006
- T1059.007
- T1068
- T1069
- T1070
- T1070.004
- T1071
- T1071.001
- T1071.003
- T1071.004
- T1072
- T1074
- T1074.001
- T1078
- T1078.002
- T1078.004
- T1080
- T1082
- T1083
- T1087
- T1087.001
- T1087.004
- T1090
- T1090.002
- T1090.003
- T1091
- T1095
- T1098
- T1102
- T1102.001
- T1102.002
- T1104
- T1105
- T1106
- T1110
- T1110.001
- T1111
- T1112
- T1113
- T1114
- T1114.003
- T1115
- T1119
- T1120
- T1123
- T1124
- T1125
- T1132
- T1132.001
- T1132.002
- T1133
- T1135
- T1136
- T1137
- T1137.001
- T1140
- T1176
- T1185
- T1187
- T1189
- T1190
- T1195
- T1195.001
- T1195.002
- T1195.003
- T1199
- T1200
- T1203
- T1204
- T1204.001
- T1204.002
- T1204.003
- T1205.002
- T1210
- T1211
- T1212
- T1213
- T1217
- T1218
- T1218.001
- T1218.005
- T1218.010
- T1219
- T1222
- T1414
- T1417
- T1418
- T1426
- T1476
- T1480
- T1480.001
- T1481
- T1482
- T1485
- T1486
- T1489
- T1490
- T1491
- T1495
- T1496
- T1497
- T1497.001
- T1499
- T1505
- T1505.003
- T1513
- T1516
- T1517
- T1518
- T1518.001
- T1525
- T1526
- T1528
- T1529
- T1530
- T1531
- T1537
- T1539
- T1541
- T1542
- T1542.001
- T1543
- T1543.001
- T1546
- T1546.001
- T1546.016
- T1547
- T1547.001
- T1547.006
- T1547.013
- T1547.014
- T1548
- T1548.002
- T1548.003
- T1550
- T1550.001
- T1552
- T1552.001
- T1552.002
- T1552.005
- T1552.007
- T1553
- T1554
- T1555
- T1555.003
- T1556
- T1557
- T1560
- T1562
- T1562.001
- T1564
- T1564.003
- T1565
- T1565.001
- T1566
- T1566.001
- T1566.002
- T1567
- T1567.002
- T1568
- T1568.002
- T1569
- T1570
- T1571
- T1572
- T1573
- T1573.001
- T1574
- T1574.002
- T1580
- T1582
- T1583
- T1583.001
- T1583.003
- T1583.004
- T1583.006
- T1584
- T1584.001
- T1584.006
- T1585
- T1586
- T1586.002
- T1587
- T1587.001
- T1588
- T1588.001
- T1588.002
- T1588.005
- T1588.006
- T1589
- T1589.002
- T1590
- T1591
- T1591.003
- T1592
- T1592.002
- T1593
- T1594
- T1595
- T1595.002
- T1596
- T1598
- T1598.003
- T1602
- T1606
- T1608
- T1608.001
- T1609
- T1610
- T1611
- T1613
- T1614
- T1614.001
- T1616
- T1620
- T1624
- T1626
- T1628.002
- T1629.003
- T1636
- T1637
- T1642
- T1646
- T1655
- T1656
- T1657
- T1660
- T1678
Threat actors
18 named threat actors across the reports.
- DCloud Uni-App Scam Network
- EvilTokens
- Forg365 operators
- DarkSpectre
- FulcrumSec
- Gamaredon
- Lazarus Group
- The Gentlemen
- Y2K Operators
- UNC1151
- Periwinkle Tempest
- Kimsuky
- ASSET Research Group — disclosure research team
- Lynx)
- StrikeShark
- TAG-179
- TeamPCP
- ShinyHunters
Nation-state attribution
- China
- Russia
- China (suspected, based on tooling/language; unconfirmed)
- North Korea (DPRK)
- Belarus
- RU
- China / India
Threat categories
- VULNERABILITY
- FRAUD
- THREAT_INTEL
- PHISHING
- MALWARE
- RANSOMWARE
- THREAT_ACTOR
- SUPPLY_CHAIN
- CAMPAIGN
- DATA_BREACH
- APT
Severity breakdown
- critical13
- high30
- medium3
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- behavioral 229
- file 228
- network 222
- entity 148
- tool 83
- infrastructure 82
- malware 64
- package 63
- technique 34
- vulnerability 16