Summary & highlights
ASEC June 2026 APT Trend Report: Nation-State Actors Pivot to Cloud/OAuth Abuse, MaaS, and Supply-Chain Compromise. US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller for Enabling Ransomware Operations (linked to FSB Center 16 Router Exploitation via CVE-2018-0171/CVE-2008-4128). OFAC Sanctions First VPN Service (1VPNS), Administrator Dmytro Rashevskyi, and Cryptor Vendor Yevgeniy Silayev for Enabling Ransomware Attacks on U.S. Critical Infrastructure.
Highlights
- TL-2026-1288 — Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Attack Paths (UNC6040/UNC6240/UNC6395/GRUB1/Storm-3138)
- TL-2026-1289 — ModHeader Chrome/Edge Extension (v7.0.17-7.0.18, 1.6M Installs) Contains Dormant AES-GCM Browsing-History Exfiltration Pipeline to api.stanfordstudies.com
- TL-2026-1292 — SolidPDFCreator: Mustang Panda Stage-1 Backdoor Targeting India via DLL Side-Loading
- TL-2026-1293 — npm Supply-Chain Attack on @asyncapi Packages Deploys Miasma Botnet via IPFS-Hosted Second-Stage Payload
- TL-2026-1294 — Insider Ransomware Negotiators Colluded with BlackCat/ALPHV, Cost Victims $75M+ — DigitalMint's Angelo Martino Sentenced to 70 Months
Theme of the day
Static Tundra and other nation-state actors drove active threat activity. Multiple new threats were tracked across various threat windows.
- credential-theft
- cisa-kev
- privilege-escalation
- patch-management
- remote-code-execution
Threats published
58 threat lines in the 2026-07-14 debrief, most severe first. Each links to its full profile.
- AsyncAPI npm Supply-Chain Compromise via GitHub Actions Pwn Request Deploys 'M-Red-Team v6.4' / Miasma-Derived Multi-Stage MalwareCRITICAL
- CVE-2026-48939 & CVE-2026-56291: Perfect-10 Joomla Extension Bugs (iCagenda, Balbooa Forms) Actively Exploited, Added to CISA KEVCRITICAL
- SAP Patches Critical NetWeaver, Approuter, and Commerce Cloud Flaws (CVE-2026-44747, CVE-2026-27690, CVE-2026-44761)CRITICAL
- SAP July 2026 Patch Day: Critical Memory Corruption in NetWeaver ABAP (CVE-2026-44747, CVSS 9.9) Among 16 Security NotesCRITICAL
- ServiceNow AI Platform Sandbox Escape Enables Unauthenticated Remote Code Execution (CVE-2026-6875)CRITICAL
- FSB Center 16 (Static Tundra) Exploits SNMP Config Exfiltration and Cisco Smart Install RCE (CVE-2018-0171) Against RoutersCRITICAL
- Unpatched Claude for Chrome Extension Flaws Enable Unauthorized Account Actions via Fake Clicks and Permission BypassCRITICAL
- AsyncAPI npm Supply Chain Compromise: GitHub Actions pull_request_target Exploit Deploys Miasma RAT to Packages with 2.9M Weekly DownloadsCRITICAL
- SonicWall SMA1000 SSRF (CVE-2026-15409) and Code Injection (CVE-2026-15410) Actively Exploited in TandemCRITICAL
- Microsoft July 2026 Patch Tuesday: 570 Flaws Fixed, 3 Zero-Days Including AD FS and SharePoint Privilege EscalationCRITICAL
- Microsoft July 2026 Patch Tuesday: 570 Vulnerabilities Fixed, Including 2 Actively Exploited Zero-Days (CVE-2026-56164, CVE-2026-56155)CRITICAL
- Microsoft July 2026 Patch Tuesday: 569 CVEs, Two Actively Exploited Zero-Days (CVE-2026-56155 AD FS EoP, CVE-2026-56164 SharePoint EoP)CRITICAL
- Langflow CVE-2025-3248 Unauthenticated RCE Exploited to Build Custom Gafgyt/BASHLITE DDoS BotnetCRITICAL
- SAP Patches CVSS 9.9 NetWeaver ABAP Out-of-Bounds Write Flaw (CVE-2026-44747), Plus Critical Approuter and Commerce Cloud BugsCRITICAL
- Microsoft July 2026 Patch Tuesday: Record 622 CVEs Include Two Actively Exploited Zero-Days in AD FS (CVE-2026-56155) and SharePoint Server (CVE-2026-56164)CRITICAL
- Microsoft July 2026 Patch Tuesday: Record 622 Flaws Fixed, Two Zero-Days Under Active Exploitation (CVE-2026-56164, CVE-2026-56155)CRITICAL
- SonicWall SMA1000 SSRF (CVE-2026-15409) and Post-Auth Code Injection (CVE-2026-15410) Exploited as Zero-DaysCRITICAL
- Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days in AD FS and SharePoint (CVE-2026-56155, CVE-2026-56164)CRITICAL
- CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (Unpatched Chain Component, PoC Public)CRITICAL
- Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Attack Paths (UNC6040/UNC6240/UNC6395/GRUB1/Storm-3138)HIGH
- ModHeader Chrome/Edge Extension (v7.0.17-7.0.18, 1.6M Installs) Contains Dormant AES-GCM Browsing-History Exfiltration Pipeline to api.stanfordstudies.comHIGH
- SolidPDFCreator: Mustang Panda Stage-1 Backdoor Targeting India via DLL Side-LoadingHIGH
- npm Supply-Chain Attack on @asyncapi Packages Deploys Miasma Botnet via IPFS-Hosted Second-Stage PayloadHIGH
- Insider Ransomware Negotiators Colluded with BlackCat/ALPHV, Cost Victims $75M+ — DigitalMint's Angelo Martino Sentenced to 70 MonthsHIGH
- 148 Malicious npm Packages ('Lucide Proxy') Disguise as School Wi-Fi Bypass / Tutoring Proxies to Hijack Browsers into a DDoS BotnetHIGH
- Operation ShadowRecruit: APT36-Linked SheetAgent RAT Campaign Abuses ControlR RMM and Google Sheets C2 to Target Indian Government Job SeekersHIGH
- Forgotten UEFI Shims Undermine Secure Boot (CVE-2026-8863, CVE-2026-10797)HIGH
- CVE-2008-4128 — Decades-Old Cisco IOS CSRF Vulnerability Added to CISA KEV After Active ExploitationHIGH
- 148 npm Packages Disguised as Student Tutoring Proxies Turn Browsers Into DDoS Botnet (Lucide Proxy)HIGH
- New Phishing Kits 'Jalisco' and 'OmegaLord' Bypass MFA on Microsoft 365 Accounts via OAuth Device Code Abuse and Fake PDF-Reader Credential HarvestingHIGH
- Cursor AI Code Editor Autorun Flaw Enables Silent Code Execution via Malicious RepositoriesHIGH
- AI-Jailbreak-Enabled C2 Automation: "bandcampro" Used Jailbroken Gemini to Build and Run Botnet in Patriot Bait Fraud CampaignHIGH
- Qilin Ransomware Abuses DCSync (MS-DRSR) to Harvest AD Domain Credentials Including KRBTGTHIGH
- ShinyHunters/UNC6040 Abuse OAuth Connected-App Approvals for Persistent Salesforce AccessHIGH
- Turkish Banking & Government-Portal Fraud Ecosystem: 8,400+ Phishing Domains, 6,700+ e-Devlet Lookalikes, and 6,600 Monthly Social Media Scam Ads (Group-IB)HIGH
- US/EU/UK Sanction Vitaly Kovalev ("Stern"), Trickbot/Conti Administrator Linked to $300M+ in Ransomware PaymentsHIGH
- US Treasury (OFAC) and UK Sanction First VPN Service (1VPNS), Administrator Dmytro Rashevskyi, and Cryptor Seller Yevgeniy Silayev for Enabling Anubis and Sinobi Ransomware OperationsHIGH
- Progress ShareFile Zero-Day Path Traversal Flaw Forces Storage Zone Controller ShutdownHIGH
- FortiSandbox VNC Server Exposure Allows Unauthenticated Access to Scanning VMs (CVE-2026-59835)HIGH
- OAuth Client ID Spoofing Enables Stealthy Enumeration and Credential Validation Against Microsoft Entra ID (UNK_pyreq2323 / UNK_OutFlareAZ)HIGH
- LabubaRAT: Rust-Based RAT Masquerades as NVIDIA Container Runtime to Backdoor Windows HostsHIGH
- Windows 10 KB5099539 Extended Security Update Patches July 2026 Patch Tuesday Zero-Days — AD FS (CVE-2026-56155), SharePoint (CVE-2026-56164) Exploited; BitLocker (CVE-2026-50661) Publicly DisclosedHIGH
- Microsoft July 2026 Patch Tuesday: 570 Vulnerabilities Including Two Under Active Exploitation (CVE-2026-56155, CVE-2026-56164)HIGH
- The Gentlemen RaaS overtakes Qilin as #1 ransomware operation, wields GentleKiller EDR-killer framework (400+ processes, 8 BYOVD variants) and 90% affiliate payoutsHIGH
- Scattered Spider (G1015): RMM-Based Persistence and Social-Engineering Intrusion TradecraftHIGH
- Unlicensed 6 GHz Wi-Fi Devices (LPI/GVP) Verified to Cause Harmful Interference to Utility Fixed Microwave Links, Threatening Grid SCADA and Public-Safety CommunicationsHIGH
- BoryptGrab Infostealer Campaign Abuses ~292 Fake GitHub Repos Impersonating Legitimate SoftwareHIGH
- July 2026 Patch Tuesday: Two Actively Exploited Microsoft Zero-Days (SharePoint EoP CVE-2026-56164, AD FS EoP CVE-2026-56155) Plus SharePoint JWT Auth Bypass CVE-2026-55040HIGH
- 11-Year-Old Linux UEFI Shim Bootloader Flaws Enable Secure Boot Bypass (CVE-2026-8863, CVE-2026-10797)HIGH
- OAuth Client ID Spoofing Enables Silent Credential Validation Against Microsoft Entra ID — UNK_pyreq2323 & UNK_OutFlareAZHIGH
- AtlasRAT: Memory-Only Multi-Stage Loader Chain Disguised as AGE Flash PlayerHIGH
- XMRig CoinMiner and ShellBot (PerlBot) Campaign Targeting Linux SSH Servers via SSH Brute-ForceHIGH
- ASEC June 2026 APT Trend Report: Nation-State Actors Pivot to Cloud/OAuth Abuse, MaaS, and Supply-Chain CompromiseMEDIUM
- US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller for Enabling Ransomware Operations (linked to FSB Center 16 Router Exploitation via CVE-2018-0171/CVE-2008-4128)MEDIUM
- OFAC Sanctions First VPN Service (1VPNS), Administrator Dmytro Rashevskyi, and Cryptor Vendor Yevgeniy Silayev for Enabling Ransomware Attacks on U.S. Critical InfrastructureMEDIUM
- US Treasury Sanctions VPN Provider 1VPNS and Crypter Seller for Enabling Ransomware OperationsMEDIUM
- Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate DDoS, Hack-and-Leak, and Credential-Theft Campaigns (Handala, 313 Team, Cyber Fattah, Dark Storm, Keymous+, and Affiliated Personas)MEDIUM
- Phishing Campaign Impersonates LastPass and Bitwarden Security Alerts to Deliver Fake DocuSign PagesMEDIUM
Techniques observed
295 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T0803
- T0804
- T0813
- T0814
- T0815
- T0826
- T0827
- T0829
- T0830
- T0837
- T0856
- T0860
- T0878
- T0880
- T1003
- T1003.004
- T1005
- T1006
- T1008
- T1012
- T1014
- T1016
- T1018
- T1020
- T1021
- T1021.001
- T1021.002
- T1021.007
- T1027
- T1027.002
- T1027.003
- T1027.010
- T1027.011
- T1029
- T1033
- T1036
- T1036.001
- T1036.004
- T1036.005
- T1040
- T1041
- T1046
- T1047
- T1048
- T1048.003
- T1053
- T1053.005
- T1055
- T1055.001
- T1056
- T1056.001
- T1056.004
- T1057
- T1059
- T1059.001
- T1059.003
- T1059.004
- T1059.006
- T1059.007
- T1059.008
- T1068
- T1069
- T1069.003
- T1070
- T1070.001
- T1070.002
- T1070.004
- T1071
- T1071.001
- T1071.004
- T1074
- T1078
- T1078.001
- T1078.004
- T1082
- T1083
- T1087
- T1087.002
- T1087.004
- T1090
- T1090.001
- T1090.002
- T1090.003
- T1091
- T1095
- T1098
- T1098.003
- T1098.007
- T1102
- T1102.002
- T1104
- T1105
- T1106
- T1110
- T1110.001
- T1110.003
- T1110.004
- T1111
- T1112
- T1113
- T1114.001
- T1115
- T1119
- T1125
- T1127
- T1129
- T1132.001
- T1133
- T1134
- T1135
- T1136
- T1136.001
- T1136.002
- T1140
- T1176
- T1185
- T1189
- T1190
- T1195
- T1195.001
- T1195.002
- T1199
- T1200
- T1201
- T1203
- T1204
- T1204.001
- T1204.002
- T1205
- T1210
- T1211
- T1213
- T1213.003
- T1219
- T1219.002
- T1222
- T1417.001
- T1418
- T1437.001
- T1480
- T1482
- T1484
- T1484.001
- T1485
- T1486
- T1489
- T1490
- T1491
- T1491.002
- T1495
- T1496
- T1497
- T1497.001
- T1498
- T1498.001
- T1498.002
- T1499
- T1499.002
- T1499.003
- T1499.004
- T1505
- T1505.003
- T1513
- T1518
- T1518.001
- T1525
- T1526
- T1528
- T1529
- T1530
- T1534
- T1537
- T1539
- T1542
- T1542.001
- T1542.003
- T1543
- T1543.003
- T1546
- T1546.015
- T1547
- T1547.001
- T1547.009
- T1548
- T1548.004
- T1550
- T1550.001
- T1550.004
- T1552
- T1552.001
- T1552.004
- T1552.005
- T1553
- T1553.002
- T1553.006
- T1555
- T1555.003
- T1555.005
- T1556
- T1557
- T1557.001
- T1558
- T1560
- T1560.001
- T1562
- T1562.001
- T1562.004
- T1562.008
- T1564
- T1564.001
- T1565
- T1565.001
- T1565.002
- T1566
- T1566.001
- T1566.002
- T1566.003
- T1566.004
- T1567
- T1567.002
- T1569.002
- T1570
- T1571
- T1572
- T1573
- T1573.001
- T1574
- T1574.002
- T1580
- T1582
- T1583
- T1583.001
- T1583.003
- T1583.004
- T1583.005
- T1583.006
- T1583.007
- T1584
- T1584.006
- T1585
- T1585.001
- T1585.002
- T1585.003
- T1586.003
- T1587
- T1587.001
- T1587.004
- T1588
- T1588.001
- T1588.002
- T1588.003
- T1588.005
- T1588.006
- T1589
- T1589.001
- T1589.002
- T1590
- T1591
- T1592
- T1593.002
- T1595
- T1595.001
- T1595.002
- T1596
- T1598
- T1598.003
- T1600
- T1601
- T1601.001
- T1602
- T1602.002
- T1606
- T1608
- T1608.001
- T1608.006
- T1611
- T1614
- T1614.001
- T1615
- T1620
- T1621
- T1623.001
- T1624.001
- T1630.001
- T1636.003
- T1636.004
- T1641
- T1646
- T1649
- T1655
- T1656
- T1657
- T1665
- T1685
- T1692
Threat actors
17 named threat actors across the reports.
- FSB Center 16
- 1VPNS
- Handala Hack
- ShinyHunters
- Mustang Panda
- Miasma npm worm operators
- BlackCat
- APT36
- bandcampro
- Qilin
- Vitaly Kovalev
- Anubis Ransomware
- UNK_pyreq2323
- The Gentlemen
- Scattered Spider
- M-RED-TEAM
- APT27
Nation-state attribution
- North Korea, China, Russia, Iran
- Russia
- Iran
- China
- Pakistan
Threat categories
- CAMPAIGN
- THREAT_INTEL
- OTHER
- PHISHING
- DATA_BREACH
- MALWARE
- SUPPLY_CHAIN
- RANSOMWARE
- VULNERABILITY
- THREAT_ACTOR
- ICS_SCADA
Severity breakdown
- critical19
- high33
- medium6
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- behavioral 242
- entity 222
- file 202
- network 145
- infrastructure 97
- malware 96
- technique 94
- package 87
- tool 78
- vulnerability 36
- financial 11