Summary & highlights
Cofense Report: Finance-Sector Phishing Shifts to Operational, Non-Urgency Lures (Payment/Invoice/Contract Themes). Gemini CLI Abused as Autonomous AI Hacking Agent to Build and Operate "Patriot Bait" (bandcampro) C2 Botnet Against a Dental Clinic. TuxBot v3 Evolution: Keksec-Linked IoT/Linux Botnet with Verbatim LLM Chain-of-Thought Code Artifacts.
Highlights
- TL-2026-1386 — TELEPUZ: New Modular Malware-as-a-Service Distributed via ClickFix Social Engineering
- TL-2026-1400 — Backdoor.Stupig — Windows Login-Screen Keyboard-Layout Provider Backdoor Grants SYSTEM Access, Deployed Alongside Resurfaced Daxin
- TL-2026-1402 — ClickLock Stealer: ClickFix-Delivered macOS Infostealer with GSocket Reverse-Shell Backdoor
- TL-2026-1406 — Photo ZIP Campaign Delivers TonRAT Node.js Implant to Hospitality Sector via Authentication Laundering
- TL-2026-1408 — Kratos Phishing-as-a-Service Platform Targeting Microsoft 365 Users Across US and Europe
Theme of the day
Activity centered on social-engineering, credential-harvesting, cwe-269.
- credential-theft
- financially-motivated
- social-engineering
- privilege-escalation
- masquerading
Threats published
45 threat lines in the 2026-07-16 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- Zoom Windows Apps Critical Unauthenticated Account Takeover (CVE-2026-53412) Plus Three Chained Local Privilege Escalation FlawsCRITICAL
- CISA Adds CVE-2026-46817 (Oracle E-Business Suite Payments Unauthenticated Takeover) and CVE-2023-4346 (KNX Protocol Account-Lockout) to KEV CatalogCRITICAL
- SonicWall SMA1000 Zero-Day Vulnerabilities Chained for Full Appliance Compromise (CVE-2026-15409, CVE-2026-15410)CRITICAL
- Multi-Vendor Critical Patch Roundup: Firefox 152.0.6, Chrome 150, Adobe ColdFusion/Commerce/AEM (APSB26-68/73/74), and VMware Avi Load Balancer (VMSA-2026-0005)CRITICAL
- Daxin Kernel Rootkit Resurfaces in Taiwan Alongside New Stupig Pre-Auth SYSTEM BackdoorCRITICAL
- Zoom Patches Critical Windows Client Flaw (CVE-2026-53412, CVSS 9.8) Enabling Unauthenticated Account TakeoverCRITICAL
- CVE-2026-53412: Unauthenticated Remote Account Takeover in Zoom Desktop Client, VDI Client, and Meeting SDK for WindowsCRITICAL
- CVE-2025-54068 Exploited in Large-Scale Laravel Livewire Credential Theft CampaignCRITICAL
- CVE-2026-46817: Critical Unauthenticated File-Read/Takeover Flaw in Oracle E-Business Suite Payments Exploited Pre-PoC (update)CRITICAL
- CVE-2026-46817: Active Exploitation Against ~950 Internet-Exposed Oracle E-Business Suite Payments Instances (update)CRITICAL
- Microsoft July 2026 Patch Tuesday: 570 Flaws Fixed, 3 Zero-Days Including AD FS and SharePoint Privilege Escalation (update)CRITICAL
- CISA Warns of Trio of Actively Exploited SharePoint Server Flaws (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) (update)CRITICAL
- SonicWall SMA1000 SSRF (CVE-2026-15409, CVSS 10.0) Chained With Appliance Management Console Command Injection (CVE-2026-15410, CVSS 7.2) Under Active Zero-Day Exploitation (update)CRITICAL
- TELEPUZ: New Modular Malware-as-a-Service Distributed via ClickFix Social EngineeringHIGH
- Backdoor.Stupig — Windows Login-Screen Keyboard-Layout Provider Backdoor Grants SYSTEM Access, Deployed Alongside Resurfaced DaxinHIGH
- ClickLock Stealer: ClickFix-Delivered macOS Infostealer with GSocket Reverse-Shell BackdoorHIGH
- Photo ZIP Campaign Delivers TonRAT Node.js Implant to Hospitality Sector via Authentication LaunderingHIGH
- Kratos Phishing-as-a-Service Platform Targeting Microsoft 365 Users Across US and EuropeHIGH
- Multiple Splunk Enterprise Vulnerabilities Enable Path Traversal and Information Disclosure (CVE-2026-20296, CVE-2026-20297, CVE-2026-20298)HIGH
- Spirals Ransomware: Rust-Based Double-Extortion Family Breaches South Asian IT Services Firm via IIS Web Shell in Under 24 HoursHIGH
- UAT-11795 (Russian) Trojanizes WebEx, Zoom, MobaXterm, DBeaver, FaceIT Installers to Deploy Starland RAT and Bespoke WLDR C2 ImplantHIGH
- New "Spirals" Ransomware Encrypts Victim Network in Under 24 Hours via Exposed IIS ServerHIGH
- UAT-11795 Deploys Novel Starland RAT and Bespoke WLDR C2 Implant in Financially Motivated CampaignHIGH
- LegacyHive: Windows User Profile Service (ProfSvc) Local Privilege Escalation Zero-Day PoC (Unpatched, No CVE)HIGH
- GoSerpent Backdoor Campaign Targets Southeast Asian Government and Diplomatic EntitiesHIGH
- PhantomEnigma Campaign: 20+ Hijacked Brazilian Government Websites Distribute Banking Backdoor via Patched Electron AppsHIGH
- Iran's AI-Enhanced Asymmetric Playbook: State Actors Integrate AI Across Cyber, Influence, and Military Operations (2026 Conflict)HIGH
- The TTF Trap: Global Phishing Campaign Delivers Lua-Based Loader for Agent Tesla, Remcos RAT, XWormHIGH
- TELEPUZ Malware-as-a-Service Spreads via ClickFix Attacks and Go-Variant Vidar Stealer ChainHIGH
- ClickLock: New macOS Infostealer Uses ClickFix Lure and App-Killing LaunchAgents to Force Credential EntryHIGH
- macOS Infostealer Hijacks Telegram Desktop Sessions via tdata Theft to Bypass 2FA, Harvests Keychain, Browser Credentials, Apple Notes, and 16 Crypto WalletsHIGH
- Ransomware Attack on Coca-Cola's Fairlife Dairy Subsidiary Halts US ProductionHIGH
- CVE-2026-14266: 7-Zip Heap-Based Buffer Overflow in XZ Chunk Handling Enables Arbitrary Code ExecutionHIGH
- macOS Info-Stealer Chains Fake Password Prompt, Telegram Session Theft, and Crypto Wallet App ReplacementHIGH
- GodDamn Ransomware (Hyadina) — Third Rebrand from Monster/Beast, Deploys Signed PoisonX Kernel Driver (update)HIGH
- LabubaRAT: Rust-based RAT Disguised as NVIDIA Container Runtime Toolkit (update)HIGH
- Cofense Report: Finance-Sector Phishing Shifts to Operational, Non-Urgency Lures (Payment/Invoice/Contract Themes)MEDIUM
- Gemini CLI Abused as Autonomous AI Hacking Agent to Build and Operate "Patriot Bait" (bandcampro) C2 Botnet Against a Dental ClinicMEDIUM
- TuxBot v3 Evolution: Keksec-Linked IoT/Linux Botnet with Verbatim LLM Chain-of-Thought Code ArtifactsMEDIUM
- Coordinated GitHub API Enumeration and Access Token Abuse Campaign (Ghost Accounts + Compromised PAT/OAuth Tokens)MEDIUM
- AnyDesk "Send Support Information" Link-Following Denial-of-Service (CVE-2026-15682)MEDIUM
- FaceTime Impersonation Scam Targets Bank and Apple Support Victims ("DarkSword"-style Campaign)MEDIUM
- Text-Salting Phishing Campaigns Abuse CSS-Hidden Text to Evade AI Email Security FiltersMEDIUM
- Identity Attacks Overtake Exploits as Top Ransomware Cause (Sophos State of Ransomware 2026)
- CISA, NSA, JPCERT/CC, NCSC-NL and NCSC-UK Publish Joint Guidance: Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers
Techniques observed
261 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- AML.T0051
- AML.T0068
- T0813
- T0814
- T1003
- T1003.001
- T1005
- T1006
- T1008
- T1010
- T1012
- T1014
- T1016
- T1018
- T1020
- T1021
- T1021.001
- T1021.002
- T1027
- T1027.004
- T1027.005
- T1027.016
- T1030
- T1033
- T1036
- T1036.004
- T1036.005
- T1036.007
- T1036.008
- T1040
- T1041
- T1046
- T1047
- T1048
- T1048.003
- T1049
- T1053
- T1053.005
- T1055
- T1055.004
- T1056
- T1056.001
- T1056.002
- T1056.003
- T1057
- T1059
- T1059.001
- T1059.002
- T1059.003
- T1059.004
- T1059.005
- T1059.006
- T1059.007
- T1068
- T1069
- T1069.002
- T1070
- T1070.001
- T1070.004
- T1070.006
- T1070.009
- T1071
- T1071.001
- T1071.004
- T1074
- T1074.001
- T1078
- T1078.002
- T1078.003
- T1078.004
- T1080
- T1082
- T1083
- T1087
- T1087.001
- T1087.002
- T1090
- T1090.001
- T1090.002
- T1090.003
- T1095
- T1098
- T1102
- T1102.002
- T1102.003
- T1104
- T1105
- T1106
- T1110
- T1110.001
- T1111
- T1112
- T1113
- T1114
- T1115
- T1119
- T1123
- T1125
- T1129
- T1132
- T1132.001
- T1133
- T1134
- T1135
- T1136
- T1136.001
- T1140
- T1176
- T1185
- T1187
- T1189
- T1190
- T1195
- T1195.002
- T1199
- T1200
- T1203
- T1204
- T1204.001
- T1204.002
- T1204.004
- T1205
- T1210
- T1211
- T1212
- T1213
- T1217
- T1218
- T1218.005
- T1219
- T1222.001
- T1414
- T1482
- T1484
- T1485
- T1486
- T1489
- T1490
- T1491
- T1491.002
- T1496
- T1497
- T1497.001
- T1498
- T1499
- T1499.003
- T1499.004
- T1505
- T1505.003
- T1518
- T1518.001
- T1526
- T1528
- T1529
- T1530
- T1531
- T1538
- T1539
- T1543
- T1543.001
- T1543.003
- T1543.004
- T1546
- T1546.003
- T1547
- T1547.001
- T1547.006
- T1547.013
- T1548
- T1548.002
- T1550
- T1550.001
- T1552
- T1552.001
- T1552.002
- T1552.003
- T1552.004
- T1553.002
- T1554
- T1555
- T1555.001
- T1555.003
- T1555.004
- T1555.005
- T1556
- T1557
- T1558
- T1560
- T1560.001
- T1560.002
- T1562
- T1562.001
- T1562.002
- T1562.004
- T1564
- T1564.001
- T1564.003
- T1565
- T1565.001
- T1566
- T1566.001
- T1566.002
- T1566.003
- T1567
- T1567.002
- T1568
- T1569
- T1569.002
- T1570
- T1571
- T1572
- T1573
- T1573.001
- T1574
- T1580
- T1583
- T1583.001
- T1583.003
- T1583.006
- T1584
- T1584.001
- T1584.006
- T1585
- T1585.001
- T1586
- T1586.002
- T1586.003
- T1587
- T1587.001
- T1587.004
- T1588
- T1588.001
- T1588.002
- T1588.005
- T1588.006
- T1589
- T1590
- T1591
- T1591.004
- T1592
- T1592.002
- T1592.004
- T1593
- T1593.003
- T1594
- T1595
- T1595.002
- T1596
- T1598
- T1602
- T1606
- T1608.001
- T1608.002
- T1611
- T1614
- T1619
- T1620
- T1621
- T1622
- T1656
- T1657
Threat actors
11 named threat actors across the reports.
- bandcampro
- Keksec-affiliated developer
- China-linked threat actor
- ClickLock Dev
- UAT-11795
- Nightmare Eclipse
- TetrisPhantom
- APT42
- China-linked espionage actor
- Hyadina
- Storm-2603
Nation-state attribution
- Russia
- China
- Iran
- Indonesia
Threat categories
- PHISHING
- MALWARE
- SUPPLY_CHAIN
- VULNERABILITY
- SOCIAL_ENGINEERING
- THREAT_INTEL
- RANSOMWARE
- THREAT_ACTOR
Severity breakdown
- critical13
- high23
- medium7
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- behavioral 293
- file 261
- network 256
- entity 117
- malware 78
- tool 65
- infrastructure 56
- technique 42
- package 30
- vulnerability 2