Summary & highlights
SnakeKeylogger Infostealer Delivered via Phishing Emails Disguised as Project Proposals (ASEC, JS→PowerShell Fileless Loader). Misconfigured Python HTTP Server Exposes AiTM Phishing Toolkit Behind Three Active Campaigns (codemado, mail-argenta, saroula01). VEXAIoT: Autonomous Multi-Agent LLM Framework Automates End-to-End IoT Vulnerability Discovery and Exploitation (95% Success Rate).
Highlights
- TL-2026-1249 — APT-C-60 2026 Campaign: SpyGlace Backdoor Delivered via LNK Files and Abused Legitimate Services
- TL-2026-1251 — Unauthenticated RCE in Motorola MR2600 Wi-Fi Router via Firmware Upload Validation Bypass (related: CVE-2024-23630, CVE-2022-34885)
- TL-2026-1252 — Remcos RAT Delivered via CVE-2017-0199 Phishing Campaign Impersonating Payment Confirmations
- TL-2026-1253 — Claude Mythos / Project Glasswing: Autonomous AI Vulnerability Discovery Compresses the Find-to-Exploit Timeline (CVE-2026-4747 and the AI-Scale Disclosure Problem)
- TL-2026-1257 — UAT-7810 Expands ORB Networks with LONGLEASH, DOGLEASH, and JARLEASH Malware Suite (CVE-2020-22653, CVE-2020-22658, CVE-2023-25717, CVE-2025-2492)
Theme of the day
- credential-theft
- espionage
- remote-code-execution
- unauthenticated-rce
- financially-motivated
Threats published
38 threat lines in the 2026-07-13 debrief, most severe first. Each links to its full profile.
- Zero-Day Exploitation of Joomla iCagenda and Balbooa Forms Extensions via Unauthenticated Arbitrary File Upload (CVE-2026-48939, CVE-2026-56291)CRITICAL
- Critical Authentication Bypass in WordPress OAuth Single Sign-On (SSO) Plugin by miniOrange (CVE-2026-57807)CRITICAL
- CISA KEV: Joomla iCagenda (CVE-2026-48939) and Balbooa Forms (CVE-2026-56291) Unrestricted File Upload Flaws Under Active ExploitationCRITICAL
- CISA Warns of Actively Exploited RCE Flaws in Joomla Extensions — iCagenda (CVE-2026-48939) and Balbooa Forms (CVE-2026-56291) Arbitrary File UploadCRITICAL
- NSA/FBI Joint Advisory: Disable Cisco Smart Install to Block Russian FSB "Static Tundra" Exploitation of CVE-2018-0171CRITICAL
- Static Tundra (FSB Center 16) Exploits CVE-2018-0171 Cisco Smart Install Flaw Against Critical InfrastructureCRITICAL
- APT-C-60 2026 Campaign: SpyGlace Backdoor Delivered via LNK Files and Abused Legitimate ServicesHIGH
- Unauthenticated RCE in Motorola MR2600 Wi-Fi Router via Firmware Upload Validation Bypass (related: CVE-2024-23630, CVE-2022-34885)HIGH
- Remcos RAT Delivered via CVE-2017-0199 Phishing Campaign Impersonating Payment ConfirmationsHIGH
- Claude Mythos / Project Glasswing: Autonomous AI Vulnerability Discovery Compresses the Find-to-Exploit Timeline (CVE-2026-4747 and the AI-Scale Disclosure Problem)HIGH
- UAT-7810 Expands ORB Networks with LONGLEASH, DOGLEASH, and JARLEASH Malware Suite (CVE-2020-22653, CVE-2020-22658, CVE-2023-25717, CVE-2025-2492)HIGH
- Misconfigured Server Exposes Three Evilginx-Based Microsoft 365 Phishing Operations (codemado, mail-argenta, saroula01)HIGH
- UNK_MassTraction: China-Aligned Actor Exploits Roundcube CVE-2024-42009 & CVE-2025-49113 to Deploy IceCube Stealer and VShell Against University Physics DepartmentsHIGH
- Armored Likho APT (Eagle Werewolf) Deploys AI-Generated Loaders to Drop BusySnake Python Stealer Against Government and Power-Sector TargetsHIGH
- Krybit Ransomware — Babuk-Derived RaaS Operation Emerges with Double ExtortionHIGH
- Argentine Football Association (AFA) Breached via Year-Old Infostealer Credential Compromise — "All Egyptian Cyber Warriors"HIGH
- Turla (Snake/Uroburos) Exploits SharePoint Flaw to Breach French Justice-Sector ServerHIGH
- SQL Injection Leads to MSSQL Compromise, BadIIS Backdoor, and XMRig DeploymentHIGH
- CrashStealer: Native C++ macOS Infostealer Impersonating Apple's CrashReporter, Delivered via Notarized "Werkbit" Meeting-App LureHIGH
- GigaWiper (BLUERABBIT): Golang Backdoor Bundling Physical-Disk Wiping, Crucio-Derived Fake Ransomware, and FlockWiper-Derived Multi-Pass WipingHIGH
- CVE-2008-4128 Cisco IOS CSRF Vulnerability Added to CISA KEV — Exploited by Russian FSB Center 16 (Static Tundra / Berserk Bear) in Ongoing Router-Hygiene Espionage CampaignHIGH
- CrashStealer: Signed & Notarized macOS Infostealer Delivered via Fake Meeting App "Werkbit"HIGH
- CrashStealer: Native C++ macOS Infostealer Masquerading as Apple's CrashReporter via Notarized 'Werkbit' DropperHIGH
- ShinyHunters (UNC6040/UNC6395) OAuth Consent Abuse Against Salesforce and Connected SaaS IntegrationsHIGH
- FSB Center 16 (Static Tundra / Berserk Bear) Exploits Default/Weak SNMP and Unpatched Cisco Smart Install (CVE-2018-0171) to Compromise Networking Devices — AA26-194AHIGH
- Russian FSB Center 16 (Static Tundra/Berserk Bear) Exploiting Unpatched Cisco Smart Install Devices — Joint NSA/FBI/13-Nation AdvisoryHIGH
- Forg365 Phishing-as-a-Service Targets Microsoft 365 via Device Code and AitM Session TheftHIGH
- FSB Centre 16 (Berserk Bear/Static Tundra) Targets Critical Infrastructure via Weak SNMP Credentials and Cisco Smart Install Exploitation (CVE-2018-0171) — UK/EU Attribute December 2025 Poland Energy Grid AttackHIGH
- SpyGlace Malware Campaign by APT-C-60 (Naikon) Abuses Trusted Developer Services (GitHub, GitLab, jsDelivr, Codeberg, Bitbucket) to Target JapanHIGH
- Operation Capsule Vault: APT37 Weaponizes Real Academic Event Materials to Deliver RokRAT via ISO/Process InjectionHIGH
- Check Point AI Security Report 2026: AI Shifts from Attack Tool to Autonomous Intrusion Operator (VoidLink C2, Mexico Government Breach, GTG-1002)HIGH
- SnakeKeylogger Infostealer Delivered via Phishing Emails Disguised as Project Proposals (ASEC, JS→PowerShell Fileless Loader)MEDIUM
- Misconfigured Python HTTP Server Exposes AiTM Phishing Toolkit Behind Three Active Campaigns (codemado, mail-argenta, saroula01)MEDIUM
- VEXAIoT: Autonomous Multi-Agent LLM Framework Automates End-to-End IoT Vulnerability Discovery and Exploitation (95% Success Rate)MEDIUM
- Former Ransomware Negotiator Angelo Martino Sentenced to 70 Months for Colluding with BlackCat/ALPHV Operators to Extort $75.3M from Five VictimsMEDIUM
- Internet-Wide Reconnaissance Scans Target MCP Servers and Claude/Cursor AI-Agent CredentialsMEDIUM
- Suspected AI-Generated ("Vibe-Coded") PowerShell Script Used to Map Active Directory Post-RDP CompromiseMEDIUM
- Hardware Trojan Backdoors in Chip Design Detected via AI-Assisted Verification (VeriChat)
Techniques observed
238 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T1003
- T1005
- T1007
- T1010
- T1011
- T1012
- T1014
- T1016
- T1018
- T1020
- T1021
- T1021.001
- T1021.004
- T1021.005
- T1025
- T1027
- T1027.007
- T1033
- T1036
- T1036.005
- T1036.007
- T1037
- T1040
- T1041
- T1046
- T1047
- T1048
- T1048.003
- T1048.004
- T1052
- T1053.003
- T1053.005
- T1055
- T1055.001
- T1056
- T1056.001
- T1057
- T1059
- T1059.001
- T1059.004
- T1059.005
- T1059.006
- T1059.007
- T1068
- T1069
- T1070
- T1070.001
- T1070.002
- T1070.003
- T1070.004
- T1070.006
- T1071
- T1071.001
- T1071.002
- T1071.003
- T1071.004
- T1074
- T1078
- T1078.001
- T1078.004
- T1082
- T1083
- T1087
- T1087.002
- T1087.003
- T1090
- T1090.002
- T1090.003
- T1095
- T1098
- T1098.005
- T1102
- T1102.002
- T1105
- T1106
- T1110
- T1110.001
- T1110.002
- T1110.003
- T1110.004
- T1111
- T1112
- T1113
- T1114
- T1114.002
- T1115
- T1119
- T1123
- T1125
- T1132
- T1133
- T1135
- T1136
- T1136.001
- T1140
- T1176
- T1185
- T1187
- T1189
- T1190
- T1195
- T1195.003
- T1199
- T1200
- T1203
- T1204
- T1204.001
- T1204.002
- T1205
- T1210
- T1211
- T1212
- T1213
- T1213.004
- T1218
- T1218.005
- T1218.011
- T1219
- T1222
- T1482
- T1484
- T1485
- T1486
- T1489
- T1490
- T1491
- T1491.001
- T1491.002
- T1495
- T1496
- T1497
- T1497.001
- T1497.003
- T1498
- T1499
- T1505
- T1505.003
- T1518
- T1518.001
- T1526
- T1528
- T1529
- T1531
- T1538
- T1539
- T1542
- T1543
- T1546
- T1546.015
- T1547
- T1547.001
- T1547.005
- T1547.006
- T1547.015
- T1548
- T1550
- T1550.001
- T1550.004
- T1552
- T1552.001
- T1552.004
- T1552.005
- T1553
- T1555
- T1555.003
- T1556
- T1557
- T1557.003
- T1560
- T1561
- T1561.002
- T1562
- T1562.001
- T1562.004
- T1562.008
- T1564
- T1564.001
- T1565
- T1566
- T1566.001
- T1566.002
- T1566.004
- T1567
- T1567.002
- T1568
- T1569
- T1570
- T1571
- T1572
- T1573
- T1573.001
- T1573.002
- T1580
- T1583
- T1583.001
- T1583.003
- T1583.004
- T1583.006
- T1584
- T1584.005
- T1584.006
- T1585
- T1586
- T1587
- T1587.001
- T1588
- T1588.002
- T1588.005
- T1588.006
- T1589
- T1589.002
- T1589.003
- T1590
- T1591
- T1592
- T1592.002
- T1593
- T1595
- T1595.001
- T1595.002
- T1596
- T1598
- T1598.003
- T1599
- T1601
- T1601.001
- T1602
- T1606
- T1608
- T1611
- T1613
- T1614
- T1620
- T1621
- T1622
- T1656
- T1657
- T1671
Threat actors
18 named threat actors across the reports.
- codemado
- BlackCat
- APT-C-60
- UAT-7810
- UNK_MassTraction
- Armored Likho
- KryBit
- All Egyptian Cyber Warriors
- Turla
- UAT-8099
- BLUERABBIT
- Static Tundra
- ShinyHunters
- FSB Center 16
- Forg365 operators
- FSB Centre 16
- APT37
- TAT26-12
Nation-state attribution
- South Korea (assessed alignment)
- China
- Russia
- Iran
- South Korea (suspected origin/alignment)
- North Korea
Threat categories
- MALWARE
- PHISHING
- TOOL
- THREAT_ACTOR
- RECONNAISSANCE
- THREAT_INTEL
- VULNERABILITY
- CAMPAIGN
- RANSOMWARE
- DATA_BREACH
- APT
- INTRUSION
- NATION_STATE
Severity breakdown
- critical6
- high25
- medium6
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- network 206
- file 189
- behavioral 181
- entity 101
- malware 65
- tool 64
- infrastructure 44
- technique 20
- package 19
- financial 3
- vulnerability 3