Summary & highlights
CrashStealer: Novel macOS Information Stealer Disguised as Apple Crash Reporter (Jamf Threat Labs). OpenSSL "HollowByte" DoS Vulnerability — Memory Exhaustion via Malformed ClientHello (11-Byte Trigger). NanoCore RAT VBScript Loader Using Chr()/Math/Flow-Control Obfuscation to Evade Static Detection (CyberChef Analysis).
Highlights
- TL-2026-1450 — Contagious Interview (DPRK) Uses SVG Steganography to Deliver OTTERCOOKIE/BEAVERTAIL Malware (REF9403)
- TL-2026-1472 — xAI Grok Build CLI 0-Day: Trust-Boundary Bypass Chains Enable Arbitrary Code Execution via AGENTS.md/CLAUDE.md Prompt Injection (also affects Claude Code CLI)
- TL-2026-1473 — Ransomware Attack Suspends Coca-Cola Fairlife U.S. Milk Production
- TL-2026-1474 — Citrix Secure Access and Endpoint Analysis Client for Windows Privilege Escalation (CVE-2026-53565, CVE-2026-53566)
- TL-2026-1475 — SHub Stealer "Reaper" — macOS Infostealer Using applescript:// URL-Scheme Delivery, Filegrabber Module, and Google-Masquerading LaunchAgent Backdoor
Theme of the day
- credential-theft
- privilege-escalation
- detection-engineering
- social-engineering
- remote-code-execution
Threats published
55 threat lines in the 2026-07-18 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- wp2shell RCE Chain in WordPress Core (CVE-2026-60137, CVE-2026-63030) — Emergency Patch ReleasedCRITICAL
- Spirals Ransomware — New Rust-Based Family Breaches Internet-Facing IIS Server, Encrypts Entire Domain Within 24 HoursCRITICAL
- FortiGate SSO Authentication Bypass Campaign (CVE-2025-59718, CVE-2025-59719, CVE-2026-24858) (update)CRITICAL
- JADEPUFFER: AI Agent Exploits Langflow RCE (CVE-2025-3248) to Automate Database Ransomware/Extortion Attack (update)CRITICAL
- CVE-2026-50746: Critical Unauthenticated Command Injection in Ubiquiti UniFi Connect Application (CVSS 10.0) (update)CRITICAL
- Microsoft July 2026 Patch Tuesday: 570 Vulnerabilities Fixed, Including 2 Actively Exploited Zero-Days (CVE-2026-56164, CVE-2026-56155) (update)CRITICAL
- Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days in AD FS and SharePoint (CVE-2026-56155, CVE-2026-56164) (update)CRITICAL
- CISA Adds CVE-2026-46817 (Oracle E-Business Suite Payments Unauthenticated Takeover) and CVE-2023-4346 (KNX Protocol Account-Lockout) to KEV Catalog (update)CRITICAL
- Multi-Vendor Critical Patch Roundup: Firefox 152.0.6, Chrome 150, Adobe ColdFusion/Commerce/AEM (APSB26-68/73/74), and VMware Avi Load Balancer (VMSA-2026-0005) (update)CRITICAL
- Zoom Patches Critical Windows Client Flaw (CVE-2026-53412, CVSS 9.8) Enabling Unauthenticated Account Takeover (update)CRITICAL
- CISA KEV: Fortinet FortiSandbox OS Command Injection Vulnerabilities Exploited (CVE-2026-39808, CVE-2026-25089) (update)CRITICAL
- CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV Catalog (update)CRITICAL
- CVE-2026-7473: Arista EOS Tunnel Decapsulation Protocol-Confusion Bypass — No Vendor Patch, Actively Exploited (update)CRITICAL
- Contagious Interview (DPRK) Uses SVG Steganography to Deliver OTTERCOOKIE/BEAVERTAIL Malware (REF9403)HIGH
- xAI Grok Build CLI 0-Day: Trust-Boundary Bypass Chains Enable Arbitrary Code Execution via AGENTS.md/CLAUDE.md Prompt Injection (also affects Claude Code CLI)HIGH
- Ransomware Attack Suspends Coca-Cola Fairlife U.S. Milk ProductionHIGH
- Citrix Secure Access and Endpoint Analysis Client for Windows Privilege Escalation (CVE-2026-53565, CVE-2026-53566)HIGH
- SHub Stealer "Reaper" — macOS Infostealer Using applescript:// URL-Scheme Delivery, Filegrabber Module, and Google-Masquerading LaunchAgent BackdoorHIGH
- Ransomware Negotiation Tactics: ShinyHunters/Scattered LAPSUS$ Hunters Instructure Canvas Breach (280M Records, May 2026) and Historical Ragnar Locker (CWT Global) / NetWalker (UCSF) Extortion PaymentsHIGH
- IonStack: One-Click Firefox JIT-to-Linux-Kernel Root Exploit Chain (CVE-2026-10702 + CVE-2026-43499 "GhostLock") Demonstrated Against Android 17HIGH
- RedWing: Android Malware-as-a-Service Spyware Operation Targeting Russian Financial InstitutionsHIGH
- Massive Smishing Campaign Abuses Gemini AI to Target Mobile Users with Fake Toll and Delivery Texts (Outsider Enterprise / Google v. Does 1-25)HIGH
- Latrodectus Phishing Campaign Delivering LummaStealer via 302-Redirect Domain Infrastructure (lufyfeo[.]org, 36-domain cluster)HIGH
- Daxin Rootkit Resurfaces After 13 Years: China-Linked Kernel Backdoor Found Alongside New Pre-Auth 'Stupig' DLL on Taiwan Manufacturer's NetworkHIGH
- "Download Pumping" — npm Supply-Chain Trust-Signal Abuse via Mass Version Uploads (ambar-src / reverse_ssh / Apfell)HIGH
- Device Code Phishing Campaign Targets Microsoft 365 via OAuth Device Authorization Grant AbuseHIGH
- Google Sites Phishing Campaign Delivers AMOS-Variant macOS Stealer (unix32385485) to Web3 UsersHIGH
- Forbidden Hyena Adopts AI-Generated BlackReaperRAT and Milkyway (Blackout Locker) Ransomware in Telegram-C2 CampaignHIGH
- Forest Blizzard (Russian GRU Unit 26165) SOHO Router DNS-Hijacking Campaign Enables AitM Credential Theft Against Outlook Web Access — Operation MasqueradeHIGH
- Atomic Arch: Supply Chain Attack on 1,619 Arch Linux AUR Packages Deploys Rust Infostealer and eBPF RootkitHIGH
- Multiple Vulnerabilities in Google Chrome Enable Remote Code Execution and Information Disclosure (CVE-2026-15899 through CVE-2026-15905)HIGH
- LegacyHive: Public PoC for Unpatched Windows User Profile Service (ProfSvc) Arbitrary Hive Load Elevation of Privilege (No CVE Assigned)HIGH
- F5OS / Traffix SDC Information Disclosure (CVE-2026-46333) — Linux Kernel ptrace/pidfd_getfd Race Condition, Public PoC (CHARON)HIGH
- CVE-2026-46215: Linux Kernel DRM GEM_CHANGE_HANDLE Use-After-Free Local Root Privilege EscalationHIGH
- Atomic Stealer (AMOS) macOS Campaign via ClickFix Script Editor Abuse (update)HIGH
- SHub Reaper - macOS Stealer Variant Bypasses Tahoe 26.4 Terminal Mitigation via applescript:// URL Scheme, Spoofs Apple/Google/Microsoft (SentinelOne) (update)HIGH
- DriveSurge: Initial Access Broker Hijacks Thousands of Trusted Websites for ClickFix and FakeUpdate Malware Delivery via zTDS (update)HIGH
- Dell BIOS Flaw (CVE-2026-40639 / DSA-2026-197) Lets Attackers Recover Admin Passwords From SPI Flash (update)HIGH
- Russian FSB Center 16 (Static Tundra/Berserk Bear) Exploiting Unpatched Cisco Smart Install Devices — Joint NSA/FBI/13-Nation Advisory (update)HIGH
- China-Linked Threat Actor Integrates Claude Code and DeepSeek-v4-pro into Active Espionage Operations Against Government, Supply-Chain, and Financial Targets (update)HIGH
- TuxBot v3 Evolution: LLM-Assisted IoT Botnet Framework With a Broken Multi-CVE Exploit Chain (update)HIGH
- UAT-11795 (Russian) Trojanizes WebEx, Zoom, MobaXterm, DBeaver, FaceIT Installers to Deploy Starland RAT and Bespoke WLDR C2 Implant (update)HIGH
- NadMesh Botnet Hunts Exposed AI Services (ComfyUI, Ollama, n8n, Open WebUI, Langflow, Gradio) for Credentials and MCP Tool Access (update)HIGH
- macOS Info-Stealer Chains Fake Password Prompt, Telegram Session Theft, and Crypto Wallet App Replacement (update)HIGH
- CrashStealer: Novel macOS Information Stealer Disguised as Apple Crash Reporter (Jamf Threat Labs)MEDIUM
- OpenSSL "HollowByte" DoS Vulnerability — Memory Exhaustion via Malformed ClientHello (11-Byte Trigger)MEDIUM
- NanoCore RAT VBScript Loader Using Chr()/Math/Flow-Control Obfuscation to Evade Static Detection (CyberChef Analysis)MEDIUM
- HTA-Based Cobalt Strike Downloader Script Analysis (CyberChef Deobfuscation)MEDIUM
- Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure DomainsMEDIUM
- DNS Pivoting Reveals Shared Infrastructure Across LokiBot, Bagle, Xworm, and Remcos CampaignsMEDIUM
- Latrodectus Loader: Three-Stage JScript/VBScript Obfuscation Delivers WMI/msiexec MSI Payload (sokingscrosshotel[.]com)MEDIUM
- Multi-Stage NetSupport RAT Loader Using Layered Obfuscation (Decimal Arrays, AES, GZIP)MEDIUM
- W32/SkyAI (Skynet/Topozuy) — Windows Malware with Embedded LLM Prompt-Injection AV-Evasion Attempt, Six-Function Sandbox Detection, and Tor-Based C2 ProxyMEDIUM
- LegacyHive: Local Privilege Escalation PoC via Windows User Profile Service (ProfSvc) Registry Hive MountingMEDIUM
- Multiple Vulnerabilities in Cisco Identity Services Engine, ISE Passive Identity Connector, and RoomOS (GovCERT.HK A26-07-32)MEDIUM
Techniques observed
335 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T0813
- T0814
- T0831
- T1001
- T1001.002
- T1003
- T1003.001
- T1003.002
- T1003.003
- T1005
- T1008
- T1010
- T1012
- T1014
- T1016
- T1016.001
- T1018
- T1020
- T1021
- T1021.002
- T1021.004
- T1021.005
- T1025
- T1027
- T1027.001
- T1027.002
- T1027.004
- T1027.007
- T1027.010
- T1027.012
- T1027.013
- T1027.015
- T1027.016
- T1030
- T1033
- T1036
- T1036.005
- T1036.008
- T1037
- T1039
- T1040
- T1041
- T1046
- T1047
- T1048
- T1049
- T1052
- T1053
- T1053.003
- T1053.005
- T1055
- T1055.001
- T1055.004
- T1055.012
- T1056
- T1056.001
- T1056.002
- T1056.003
- T1057
- T1059
- T1059.001
- T1059.002
- T1059.003
- T1059.004
- T1059.005
- T1059.006
- T1059.007
- T1059.008
- T1059.011
- T1068
- T1069
- T1069.002
- T1070
- T1070.003
- T1070.004
- T1070.007
- T1071
- T1071.001
- T1072
- T1074
- T1074.001
- T1078
- T1078.001
- T1078.003
- T1078.004
- T1080
- T1082
- T1083
- T1087
- T1087.001
- T1087.002
- T1090
- T1090.001
- T1090.002
- T1090.003
- T1091
- T1095
- T1098
- T1098.004
- T1098.005
- T1102
- T1102.002
- T1102.003
- T1104
- T1105
- T1106
- T1110
- T1110.001
- T1110.002
- T1110.004
- T1111
- T1112
- T1113
- T1114
- T1115
- T1119
- T1120
- T1123
- T1125
- T1132
- T1132.001
- T1133
- T1134
- T1135
- T1136
- T1136.001
- T1137
- T1140
- T1176
- T1185
- T1187
- T1189
- T1190
- T1195
- T1195.001
- T1195.002
- T1199
- T1200
- T1203
- T1204
- T1204.001
- T1204.002
- T1205
- T1210
- T1211
- T1212
- T1213
- T1217
- T1218
- T1218.005
- T1218.007
- T1218.011
- T1219
- T1221
- T1406
- T1417
- T1418
- T1426
- T1429
- T1430
- T1437
- T1474
- T1480
- T1482
- T1484.001
- T1485
- T1486
- T1489
- T1490
- T1491
- T1491.001
- T1491.002
- T1495
- T1496
- T1497
- T1497.001
- T1497.003
- T1498
- T1498.001
- T1499
- T1499.001
- T1499.003
- T1499.004
- T1505
- T1505.003
- T1512
- T1513
- T1516
- T1517
- T1518
- T1518.001
- T1526
- T1528
- T1529
- T1530
- T1531
- T1533
- T1534
- T1535
- T1537
- T1539
- T1541
- T1542
- T1542.001
- T1543
- T1543.001
- T1543.002
- T1543.003
- T1546
- T1546.001
- T1546.004
- T1547
- T1547.001
- T1547.006
- T1547.011
- T1547.013
- T1548
- T1548.002
- T1550
- T1550.001
- T1552
- T1552.001
- T1552.002
- T1552.004
- T1553
- T1553.001
- T1553.002
- T1554
- T1555
- T1555.001
- T1555.003
- T1555.005
- T1556
- T1557
- T1559
- T1559.001
- T1560
- T1560.001
- T1561
- T1561.001
- T1562
- T1562.001
- T1562.004
- T1564
- T1564.001
- T1564.003
- T1564.004
- T1565
- T1565.001
- T1566
- T1566.001
- T1566.002
- T1567
- T1568
- T1568.001
- T1568.002
- T1569
- T1569.002
- T1570
- T1571
- T1572
- T1573
- T1573.001
- T1574
- T1574.012
- T1582
- T1583
- T1583.001
- T1583.003
- T1583.004
- T1583.006
- T1584
- T1584.001
- T1584.006
- T1585
- T1585.001
- T1585.003
- T1586
- T1587
- T1587.001
- T1587.003
- T1587.004
- T1588
- T1588.002
- T1588.005
- T1588.006
- T1588.007
- T1589
- T1589.002
- T1589.003
- T1590
- T1590.004
- T1590.005
- T1591
- T1592
- T1592.002
- T1592.004
- T1593
- T1595
- T1595.001
- T1595.002
- T1596
- T1598
- T1599
- T1600
- T1601
- T1602
- T1602.001
- T1602.002
- T1606
- T1608
- T1608.001
- T1608.005
- T1609
- T1610
- T1611
- T1613
- T1614
- T1616
- T1619
- T1620
- T1621
- T1622
- T1624
- T1628
- T1630
- T1636
- T1641
- T1642
- T1648
- T1656
- T1657
- T1660
- T1663
- T1685
Threat actors
17 named threat actors across the reports.
- Gamaredon Group
- TA578 - G1038
- SmartApeSG
- Nightmare Eclipse
- Contagious Interview
- SHub Stealer operators
- ShinyHunters
- Outsider Enterprise
- Forbidden Hyena
- Forest Blizzard
- AMOS MaaS Operators
- DriveSurge
- Static Tundra
- Keksec (TuxBot/Kaitori/AISURU operator)
- UAT-11795
- JADEPUFFER
- APT27
Nation-state attribution
- Russia
- North Korea (DPRK)
- China
- Iran
Threat categories
- MALWARE
- VULNERABILITY
- THREAT_ACTOR
- RANSOMWARE
- PHISHING
- SUPPLY_CHAIN
- ESPIONAGE
- APT
Severity breakdown
- critical13
- high31
- medium11
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- behavioral 364
- network 358
- file 267
- entity 133
- tool 99
- infrastructure 87
- malware 82
- technique 57
- package 56
- vulnerability 21