Summary & highlights
Harvard/Meta Study Quantifies AI Voice-Phishing (Vishing) Persuasiveness Gap: 16.5% Compliance, 70.3% Detection, and Profitable Economics for Attackers. Armenia Detains Russian National Aleksandr Ermakov on US Extradition Request Tied to Sodinokibi/REvil Ransomware. HollowByte: OpenSSL Pre-Authentication TLS DoS Flaw Bloats Server Memory With 11-Byte Payload.
Highlights
- TL-2026-1429 — Two Scattered Spider Leaders Jailed for £29M Transport for London (TfL) Cyberattack
- TL-2026-1430 — Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days (CVE-2026-56155 AD FS, CVE-2026-56164 SharePoint) Among Record 570+ Fixes
- TL-2026-1435 — PolinRider DPRK Supply-Chain Campaign: Confirmed GitHub Footprint Grows 6.5x Since March (JADESNOW/Beavertail/InvisibleFerret Loaders, DEV#POPPER & OmniStealer Payloads)
- TL-2026-1436 — CVE-2026-59208: Cross-Issuer Impersonation in n8n Enterprise Token Exchange
- TL-2026-1439 — Ransomware Attack Halts Coca-Cola Fairlife U.S. Dairy Production
Theme of the day
Activity centered on 0ktapus, 2fa-reset-fraud, active-directory-federation-services.
- privilege-escalation
- remote-code-execution
- financially-motivated
- cisa-kev
- known-exploited-vulnerabilities
Threats published
35 threat lines in the 2026-07-17 debrief, most severe first. Each links to its full profile.
- CISA KEV: Fortinet FortiSandbox OS Command Injection Vulnerabilities Exploited (CVE-2026-39808, CVE-2026-25089)CRITICAL
- CISA Orders Federal Agencies to Patch Exploited Fortinet FortiSandbox Command Injection Flaws (CVE-2026-39808, CVE-2026-25089, CVE-2026-39813)CRITICAL
- CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV CatalogCRITICAL
- July 2026 Patch Tuesday: Actively Exploited SharePoint RCE (CVE-2026-58644) and AD FS/SharePoint Zero-DaysCRITICAL
- CVE-2026-44747: Critical Memory Corruption in SAP NetWeaver Application Server ABAP (CVSS 9.9)CRITICAL
- Siemens Ruggedcom ROX II Three-Stage Zero-Day Exploit Chain (CVE-2025-40948, CVE-2025-40947, CVE-2025-40949)CRITICAL
- CISA Orders Patch of Actively Exploited Critical FortiSandbox OS Command Injection Flaws (CVE-2026-39808, CVE-2026-25089, CVE-2026-39813)CRITICAL
- Actively Exploited SonicWall SMA1000 Zero-Days (CVE-2026-15409, CVE-2026-15410) Chained for Full Appliance Takeover Alongside Microsoft July 2026 Patch Tuesday (570 CVEs, 3 Zero-Days incl. SharePoint & AD FS EoP)CRITICAL
- CVE-2026-58644: Microsoft SharePoint Server Unauthenticated Remote Code Execution Exploited in the WildCRITICAL
- SonicWall SMA1000 Zero-Days (CVE-2026-15409, CVE-2026-15410) Chained in Active Attacks, Assessed Ransomware PrecursorCRITICAL
- wp2shell: WordPress Core REST API Batch-Route Confusion Chained with author__not_in SQL Injection (CVE-2026-63030 / CVE-2026-60137) Yields Unauthenticated Pre-Auth RCECRITICAL
- CVE-2026-63030 (wp2shell): Unauthenticated Remote Code Execution in WordPress Core REST API Batch Endpoint via Chained SQL Injection (CVE-2026-60137)CRITICAL
- Two Scattered Spider Leaders Jailed for £29M Transport for London (TfL) CyberattackHIGH
- Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days (CVE-2026-56155 AD FS, CVE-2026-56164 SharePoint) Among Record 570+ FixesHIGH
- PolinRider DPRK Supply-Chain Campaign: Confirmed GitHub Footprint Grows 6.5x Since March (JADESNOW/Beavertail/InvisibleFerret Loaders, DEV#POPPER & OmniStealer Payloads)HIGH
- CVE-2026-59208: Cross-Issuer Impersonation in n8n Enterprise Token ExchangeHIGH
- Ransomware Attack Halts Coca-Cola Fairlife U.S. Dairy ProductionHIGH
- ClickLock Stealer: macOS ClickFix Infostealer Uses 210ms Process-Kill Loops and Fake Authentication Dialogs to Coerce CredentialsHIGH
- OtterCandy (js.ottercandy) Node.js RAT/Stealer — WaterPlum's Polymarket-Themed ClickFake Interview Campaign Leaks Its Own Operator CredentialsHIGH
- GST Refund Phishing Delivers Remcos RAT via Multi-Stage .NET Bitmap-Steganography Infection ChainHIGH
- ACR Stealer (Amatera Stealer) Uses ClickFix Lures, WebDAV/pushd DLL Delivery, and EtherHiding to Harvest Browser and Microsoft 365 DataHIGH
- LegacyHive: Unpatched Windows User Profile Service (ProfSvc) Local Privilege Escalation Zero-Day — Public PoC Bypasses Fully Patched SystemsHIGH
- Spirals Ransomware Targets South Asian IT Services Firm via IIS Web Shell, Chisel Tunneling, and Sub-24-Hour EncryptionHIGH
- LegacyHive: Windows 0-Day Local Privilege Escalation via User Profile Service (ProfSvc) Arbitrary Registry Hive LoadingHIGH
- North Korea-Linked Contagious Interview Actors (REF9403) Hide OtterCookie-Aligned Malware in SVG Flag ImagesHIGH
- Qilin Ransomware: Custom Rust Loader and Kernel-Level EDR Killer via Weaponized ThrottleStop Driver (CVE-2025-7771)HIGH
- Starland RAT Campaign (UAT-11795) — Trojanized WebEx, Zoom, MobaXterm, DBeaver & FACEIT Installers Deliver Python RAT and Novel WLDR PowerShell C2 ImplantHIGH
- NadMesh Botnet Hunts Exposed AI Services (ComfyUI, Ollama, n8n, Open WebUI, Langflow, Gradio) for Credentials and MCP Tool AccessHIGH
- Ransomware Attack Halts Fairlife (Coca-Cola Subsidiary) US Dairy Production OperationsHIGH
- Iran-Linked Actors Track US Military Personnel via SS7 Roaming Abuse and Ad-Tech Location DataHIGH
- ViteVenom Campaign: Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver RATHIGH
- Harvard/Meta Study Quantifies AI Voice-Phishing (Vishing) Persuasiveness Gap: 16.5% Compliance, 70.3% Detection, and Profitable Economics for AttackersMEDIUM
- Armenia Detains Russian National Aleksandr Ermakov on US Extradition Request Tied to Sodinokibi/REvil RansomwareMEDIUM
- HollowByte: OpenSSL Pre-Authentication TLS DoS Flaw Bloats Server Memory With 11-Byte PayloadMEDIUM
- OpenSSL "HollowByte" TLS Handshake Memory-Amplification DoS (No CVE Assigned)MEDIUM
Techniques observed
270 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T0813
- T0857
- T0859
- T0871
- T1003
- T1003.001
- T1003.002
- T1003.006
- T1005
- T1007
- T1008
- T1012
- T1014
- T1016
- T1018
- T1020
- T1021
- T1021.001
- T1021.002
- T1021.004
- T1021.006
- T1027
- T1027.001
- T1027.002
- T1027.003
- T1027.011
- T1027.013
- T1033
- T1036
- T1036.004
- T1036.005
- T1036.006
- T1037
- T1039
- T1040
- T1041
- T1046
- T1047
- T1048
- T1048.003
- T1053
- T1053.003
- T1053.005
- T1055
- T1055.004
- T1056
- T1056.001
- T1056.002
- T1057
- T1059
- T1059.001
- T1059.002
- T1059.003
- T1059.004
- T1059.005
- T1059.006
- T1059.007
- T1059.011
- T1068
- T1069
- T1069.002
- T1070
- T1070.003
- T1070.004
- T1070.006
- T1070.008
- T1070.009
- T1071
- T1071.001
- T1072
- T1074
- T1074.001
- T1078
- T1078.002
- T1078.003
- T1078.004
- T1082
- T1083
- T1087
- T1087.001
- T1087.002
- T1090
- T1090.001
- T1090.002
- T1090.003
- T1098
- T1098.004
- T1102
- T1102.001
- T1102.002
- T1105
- T1106
- T1110
- T1110.001
- T1110.002
- T1110.004
- T1111
- T1112
- T1113
- T1115
- T1119
- T1123
- T1125
- T1127
- T1129
- T1132.001
- T1133
- T1134
- T1134.001
- T1134.002
- T1135
- T1136
- T1136.001
- T1140
- T1187
- T1189
- T1190
- T1195
- T1195.002
- T1199
- T1200
- T1203
- T1204
- T1204.001
- T1204.002
- T1204.004
- T1210
- T1211
- T1212
- T1213
- T1213.002
- T1218.003
- T1218.005
- T1218.011
- T1219
- T1219.002
- T1222
- T1449
- T1450
- T1451
- T1480
- T1482
- T1484
- T1484.001
- T1485
- T1486
- T1489
- T1490
- T1491
- T1491.001
- T1491.002
- T1496
- T1497
- T1497.001
- T1498
- T1498.001
- T1499
- T1499.001
- T1499.002
- T1499.003
- T1505
- T1505.003
- T1505.004
- T1518
- T1518.001
- T1526
- T1528
- T1529
- T1531
- T1539
- T1543
- T1543.001
- T1546
- T1546.001
- T1546.004
- T1546.015
- T1547
- T1547.001
- T1547.009
- T1548
- T1548.002
- T1550
- T1552
- T1552.001
- T1552.002
- T1552.004
- T1553
- T1554
- T1555
- T1555.001
- T1555.003
- T1555.005
- T1556
- T1556.006
- T1557
- T1558
- T1560
- T1562
- T1562.001
- T1562.004
- T1562.008
- T1564
- T1564.001
- T1565
- T1565.001
- T1566
- T1566.001
- T1566.002
- T1566.003
- T1566.004
- T1567
- T1567.002
- T1569
- T1569.002
- T1570
- T1571
- T1572
- T1573
- T1573.001
- T1573.002
- T1578
- T1583
- T1583.001
- T1583.004
- T1583.006
- T1584
- T1585
- T1585.001
- T1586
- T1587
- T1587.001
- T1587.004
- T1588
- T1588.001
- T1588.002
- T1588.005
- T1588.006
- T1589
- T1589.001
- T1590
- T1591
- T1592
- T1592.002
- T1593
- T1593.001
- T1595
- T1595.001
- T1595.002
- T1596
- T1598.004
- T1600
- T1606
- T1606.002
- T1608
- T1608.001
- T1609
- T1611
- T1613
- T1614
- T1614.001
- T1620
- T1621
- T1649
- T1650
- T1656
- T1657
- T1680
- T1683
- T1685
- T1688
Threat actors
14 named threat actors across the reports.
- REvil
- Scattered Spider
- PolinRider
- ClickLock Dev
- WageMole
- SheldIO
- NightmareEclipse
- REF9403
- Qilin
- UAT-11795
- Iran-linked state-nexus actors
- SuccessKey
- Storm-2603
- UTA0533
Nation-state attribution
- Russia
- North Korea (DPRK)
- North Korea
- Iran
- China
Threat categories
- THREAT_INTEL
- THREAT_ACTOR
- VULNERABILITY
- SUPPLY_CHAIN
- RANSOMWARE
- MALWARE
- APT
Severity breakdown
- critical12
- high19
- medium4
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- behavioral 228
- entity 116
- network 98
- file 84
- tool 69
- infrastructure 62
- package 58
- malware 45
- technique 40
- vulnerability 12