Summary & highlights
CVE-2026-50661: Windows BitLocker Security Feature Bypass 0-Day. Multiple Notepad++ Vulnerabilities Enable PowerShell Command Injection, Stack Buffer Overflow, and Zip Slip Path Traversal (CVE-2026-52886, CVE-2026-54758, CVE-2026-57233). June 2026 Infostealer Campaign Trends: Remus, ACRStealer, LummaC2, Vidar Distributed via SEO Poisoning and DLL Sideloading.
Highlights
- TL-2026-1344 — AtlasRAT: Four-Stage In-Memory Loader Chain Delivers Commercial RAT via Fake Flash Player Installer (Silver Fox Overlap)
- TL-2026-1347 — Check Point 2026 AI Security Report: Autonomous AI-Driven Exploitation, CLAUDE.md Jailbreaking, and Generative Identity Fraud Fuel Scattered Spider / ShinyHunters Campaigns
- TL-2026-1349 — CVE-2026-56155: Microsoft AD FS Elevation-of-Privilege Vulnerability Actively Exploited
- TL-2026-1351 — LegacyHive: Windows 0-Day Allows Standard Users to Load Another User's Registry Hive via User Profile Service
- TL-2026-1354 — China-Linked Threat Actor Integrates Claude Code and DeepSeek-v4-pro into Active Espionage Operations Against Government, Supply-Chain, and Financial Targets
Theme of the day
Active exploitation of multiple vulnerabilities by unattributed actors and APT groups dominates the threat landscape. Ransomware and lateral movement threats are prominent.
- credential-theft
- zero-day
- financially-motivated
- cisa-kev
- patch-tuesday
Threats published
47 threat lines in the 2026-07-15 debrief, most severe first. Each links to its full profile.
- Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days in AD FS (CVE-2026-56155) and SharePoint (CVE-2026-56164), Plus Unpatched BitLocker Bypass (CVE-2026-50661)CRITICAL
- Malicious NuGet Packages Disguised as Game Cheats Deploy Remote Access Malware (pepesoft.exe)CRITICAL
- SonicWall SMA1000 Zero-Day Vulnerabilities (CVE-2026-15409, CVE-2026-15410) Actively Exploited in TandemCRITICAL
- AsyncAPI npm Supply Chain Attack: Pwn-Request GitHub Actions Compromise Deploys Miasma Tasking FrameworkCRITICAL
- CISA Warns of Active Exploitation of Three Microsoft SharePoint Server Vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164)CRITICAL
- Daxin Returns: China-Linked Kernel Rootkit Resurfaces in Taiwan Alongside New Stupig BackdoorCRITICAL
- OkoBot: Multi-Stage Malware Framework Targeting Cryptocurrency Wallets (TookPS/HDUtil/Volume2/SeedHunter)CRITICAL
- Chrome 150 Security Update Fixes 15 Vulnerabilities Including Two Critical Use-After-Free Flaws in Ozone (CVE-2026-15764, CVE-2026-15765)CRITICAL
- CVE-2026-56164: Microsoft SharePoint Server Missing-Authentication Vulnerability Actively Exploited, Added to CISA KEVCRITICAL
- Dell PowerProtect Data Domain Multiple Vulnerabilities: Improper Authentication (CVE-2026-53483) and Path Traversal (CVE-2026-53481) Allow Full Remote System AccessCRITICAL
- July 2026 Patch Tuesday: Microsoft Fixes 622 CVEs Including Three Actively-Targeted Zero-Days (CVE-2026-56155 AD FS EoP, CVE-2026-56164 SharePoint EoP, CVE-2026-50661 BitLocker Bypass)CRITICAL
- CISA Warns of Trio of Actively Exploited SharePoint Server Flaws (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164)CRITICAL
- SonicWall SMA1000 Zero-Days CVE-2026-15409 (Unauthenticated SSRF, CVSS 10.0) and CVE-2026-15410 (Post-Auth Code Injection, CVSS 7.2) Chained for Root Compromise, Actively ExploitedCRITICAL
- CVE-2026-15409 / CVE-2026-15410: SonicWall SMA 1000 Zero-Day SSRF and Code Injection Chained for Unauthenticated RCECRITICAL
- SonicWall SMA1000 SSRF (CVE-2026-15409, CVSS 10.0) Chained With Appliance Management Console Command Injection (CVE-2026-15410, CVSS 7.2) Under Active Zero-Day ExploitationCRITICAL
- F5 Patches Multiple NGINX Vulnerabilities: Heap Overflow, Memory Disclosure, and Use-After-Free (CVE-2026-42533, CVE-2026-60005, CVE-2026-56434)CRITICAL
- AtlasRAT: Four-Stage In-Memory Loader Chain Delivers Commercial RAT via Fake Flash Player Installer (Silver Fox Overlap)HIGH
- Check Point 2026 AI Security Report: Autonomous AI-Driven Exploitation, CLAUDE.md Jailbreaking, and Generative Identity Fraud Fuel Scattered Spider / ShinyHunters CampaignsHIGH
- CVE-2026-56155: Microsoft AD FS Elevation-of-Privilege Vulnerability Actively ExploitedHIGH
- LegacyHive: Windows 0-Day Allows Standard Users to Load Another User's Registry Hive via User Profile ServiceHIGH
- China-Linked Threat Actor Integrates Claude Code and DeepSeek-v4-pro into Active Espionage Operations Against Government, Supply-Chain, and Financial TargetsHIGH
- US Indicts Alleged Operators of Media Land Bulletproof Hosting Service Used by LockBit, BlackSuit, and Play RansomwareHIGH
- CrashStealer: Notarized Fake Apple CrashReporter App Steals macOS Keychain, Browser, and Crypto Wallet CredentialsHIGH
- Actively Exploited SharePoint Server Elevation of Privilege Flaw (CVE-2026-56164) Patched Alongside Critical RCE Pair in July 2026 Patch TuesdayHIGH
- TuxBot v3 Evolution: LLM-Assisted IoT Botnet Framework With a Broken Multi-CVE Exploit ChainHIGH
- LabubaRAT: Rust-Based Windows Implant Masquerading as NVIDIA Container RuntimeHIGH
- LegacyHive: Unpatched Windows User Profile Service (profsvc) Registry Hive Hijack Privilege Escalation 0-Day PoC Released by Nightmare-EclipseHIGH
- 313 Team Iran-Aligned Hacktivists Weaponize Agentic AI, Mirai-Derived Botnets, and Prompt Injection Against E-Commerce APIs (CVE-2025-39391)HIGH
- Impersonated GitHub Brand Repositories Distribute BoryptGrab-Lineage Infostealer via DLL Side-Loading (Fake Arctic Wolf + 290+ Brands)HIGH
- CVE-2026-3985: Blind SQL Injection in Creative Mail WordPress Plugin, Discovered by Fully Automated AI Exploitation PipelineHIGH
- Unpatched Cursor IDE 0-Day: Malicious git.exe in Repository Root Enables Arbitrary Code Execution on Windows (CWE-427)HIGH
- Jscrambler npm Package Compromised: IronWorm Cross-Platform Infostealer (Shai-Hulud Lineage) via Rust Native BinariesHIGH
- "PromptFiction" Claude Desktop Auto-Submit Flaw Chained With "Claudy Day" Claude.ai Exploit Chain Enables Silent Exfiltration and, via Filesystem Server MCP, Local RCEHIGH
- Compromised @injectivelabs/sdk-ts npm Package (v1.20.21) Exfiltrates Cryptocurrency Wallet Mnemonics and Private Keys via Fake TelemetryHIGH
- OkoBot Malware Framework Injects Seed-Phrase Phishing Pages Into Ledger and Trezor Wallet AppsHIGH
- MacSync Stealer: 'ClaudeFix' Malvertising Campaign Abuses Shared Claude Chat Links to Deploy macOS InfostealerHIGH
- AsyncAPI npm Supply Chain Compromise: Import-Time Payload Delivery via Miasma LoaderHIGH
- Operation Fake KickOff: Recruiter-Impersonation AitM/BitB Toolkit Abuses Salesforce, SendGrid, Zoho and Render to Harvest Google Workspace Credentials and Bypass MFAHIGH
- QuimaRAT v2.0: Cross-Platform Java-Based RAT Sold via Malware-as-a-Service ModelHIGH
- LabubaRAT: Rust-based RAT Disguised as NVIDIA Container Runtime ToolkitHIGH
- CVE-2026-50661: Windows BitLocker Security Feature Bypass 0-DayMEDIUM
- Multiple Notepad++ Vulnerabilities Enable PowerShell Command Injection, Stack Buffer Overflow, and Zip Slip Path Traversal (CVE-2026-52886, CVE-2026-54758, CVE-2026-57233)MEDIUM
- June 2026 Infostealer Campaign Trends: Remus, ACRStealer, LummaC2, Vidar Distributed via SEO Poisoning and DLL SideloadingMEDIUM
- "Patriot Bait": Solo Threat Actor 'bandcampro' Runs 5-Year AI-Automated Telegram Influence-and-Fraud CampaignMEDIUM
- Extortion Actor Pivots from Blocked Remote-Access Tool to Fake IT-Support Social Engineering for Data ExfiltrationMEDIUM
- Sophos State of Ransomware 2026: Payments Drop as Encryption Success Climbs, Identity-Based Attacks Now Dominant VectorMEDIUM
- Windows RDP Memory-Disclosure Vulnerabilities (CVE-2026-50445, CVE-2026-57982, CVE-2026-55003, CVE-2026-50497, CVE-2026-57979) — July 2026 Patch TuesdayMEDIUM
Techniques observed
265 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T1001
- T1003
- T1003.002
- T1003.004
- T1005
- T1008
- T1012
- T1014
- T1016
- T1018
- T1020
- T1021
- T1021.001
- T1021.002
- T1027
- T1027.002
- T1033
- T1036
- T1036.001
- T1036.005
- T1036.008
- T1037
- T1040
- T1041
- T1046
- T1048
- T1048.003
- T1049
- T1053
- T1053.003
- T1053.005
- T1055
- T1055.001
- T1055.003
- T1056
- T1056.001
- T1056.002
- T1056.004
- T1057
- T1059
- T1059.001
- T1059.002
- T1059.003
- T1059.004
- T1059.007
- T1068
- T1069
- T1069.001
- T1070
- T1070.002
- T1070.004
- T1071
- T1071.001
- T1071.004
- T1074
- T1074.001
- T1078
- T1078.001
- T1078.003
- T1078.004
- T1082
- T1083
- T1087
- T1087.001
- T1090
- T1090.001
- T1090.003
- T1090.004
- T1095
- T1098
- T1098.007
- T1102
- T1102.002
- T1104
- T1105
- T1106
- T1110
- T1110.001
- T1110.004
- T1111
- T1112
- T1113
- T1115
- T1119
- T1120
- T1123
- T1125
- T1129
- T1132.002
- T1133
- T1134
- T1134.002
- T1134.003
- T1136
- T1136.001
- T1140
- T1176
- T1179
- T1187
- T1189
- T1190
- T1195
- T1195.001
- T1195.002
- T1199
- T1200
- T1202
- T1203
- T1204
- T1204.001
- T1204.002
- T1204.004
- T1205
- T1210
- T1211
- T1212
- T1213
- T1215
- T1218
- T1219
- T1482
- T1484
- T1485
- T1486
- T1489
- T1490
- T1491
- T1491.001
- T1491.002
- T1496
- T1497
- T1497.001
- T1498
- T1498.001
- T1499
- T1499.003
- T1499.004
- T1505
- T1505.003
- T1518
- T1518.001
- T1526
- T1528
- T1529
- T1530
- T1531
- T1537
- T1539
- T1542.001
- T1542.005
- T1543
- T1543.001
- T1543.002
- T1543.003
- T1546.004
- T1546.015
- T1547
- T1547.001
- T1547.006
- T1547.015
- T1548
- T1548.002
- T1550
- T1550.001
- T1550.002
- T1552
- T1552.001
- T1552.002
- T1552.004
- T1552.005
- T1552.006
- T1553
- T1553.002
- T1553.005
- T1553.006
- T1554
- T1555
- T1555.001
- T1555.003
- T1555.004
- T1555.005
- T1556
- T1556.006
- T1557
- T1560
- T1560.001
- T1561
- T1561.001
- T1562
- T1562.001
- T1562.002
- T1562.004
- T1562.006
- T1564
- T1565
- T1565.001
- T1566
- T1566.002
- T1567
- T1567.002
- T1568
- T1569.002
- T1570
- T1571
- T1572
- T1573
- T1573.001
- T1574
- T1574.001
- T1574.002
- T1580
- T1583
- T1583.001
- T1583.003
- T1583.004
- T1583.005
- T1583.006
- T1583.008
- T1584
- T1584.001
- T1585
- T1585.001
- T1585.003
- T1586
- T1586.003
- T1587
- T1587.001
- T1587.004
- T1588
- T1588.001
- T1588.002
- T1588.003
- T1588.005
- T1588.006
- T1588.007
- T1589
- T1590
- T1591
- T1592
- T1592.002
- T1593
- T1595
- T1595.002
- T1596
- T1596.005
- T1597.002
- T1598
- T1598.004
- T1601
- T1601.001
- T1601.002
- T1606
- T1608
- T1608.001
- T1608.006
- T1611
- T1614
- T1614.001
- T1620
- T1621
- T1648
- T1649
- T1656
- T1657
- T1665
Threat actors
13 named threat actors across the reports.
- bandcampro
- Void Arachne
- Scattered Spider
- Nightmare-Eclipse
- Media Land
- Keksec (TuxBot/Kaitori/AISURU operator)
- Nightmare Eclipse
- 313 Team
- pepesoft
- M-Red-Team
- Storm-2603
- China-linked espionage group
- UTA0533
Nation-state attribution
- Russia
- China
- Iran
Threat categories
- VULNERABILITY
- MALWARE
- THREAT_ACTOR
- THREAT_INTEL
- RANSOMWARE
- APT
- SUPPLY_CHAIN
- PHISHING
Severity breakdown
- critical16
- high24
- medium7
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- network 246
- behavioral 217
- file 217
- entity 132
- infrastructure 91
- technique 85
- tool 79
- package 71
- malware 67
- vulnerability 15