Summary & highlights
700+ Typosquatted/Lookalike Domains Targeting Oil and Gas Brands (Chevron, ExxonMobil, Shell) for Phishing, BEC, and Recruitment Fraud. Pokémon Brand-Spoofing Campaign: 1,352 Lookalike Domains Ahead of 30th Anniversary. ChatGPT Plus Billing Phishing Campaign Spoofs Stripe Checkout to Harvest Payment Card Data.
Highlights
- TL-2026-1506 — Ransomware Attack on Coca-Cola's Fairlife Dairy Halts U.S. Production Systems
- TL-2026-1507 — CVE-2025-12480: Triofox HTTP Host Header Authentication Bypass Exploited by UNC6485 for SYSTEM-Level Code Execution
- TL-2026-1508 — GTIG: Threat Actor Usage of AI Tools — 'Just-in-Time' AI-Enabled Malware (PROMPTFLUX, PROMPTSTEAL/LAMEHUG, PROMPTLOCK, FRUITSHELL, QUIETVAULT) Deployed by State Actors
- TL-2026-1509 — UNC6229: Vietnamese Actors Use Fake Job Posting Campaigns to Deliver RATs and Steal Credentials
- TL-2026-1510 — COLDRIVER (UNC4057/Star Blizzard) Re-Tools with NOROBOT/BAITSWITCH/YESROBOT/MAYBEROBOT/SIMPLEFIX Malware Chain After LOSTKEYS Disclosure
Theme of the day
- social-engineering
- remote-code-execution
- credential-harvesting
- unauthenticated-rce
- phishing
Threats published
48 threat lines in the 2026-07-19 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- Four Chained Exploit Paths in LiteLLM Proxy (Pre-Auth RCE to Master Key Exfiltration) — STAR Labs Pwn2Own ResearchCRITICAL
- Pixel 10 VPU Driver mmap Boundary-Check Flaw Enables Root Exploit Chain (CVE-2025-54957)CRITICAL
- CVE-2026-47291: Remote Code Execution in Windows HTTP.sys (Kernel-Mode Integer Overflow)CRITICAL
- React2Shell CVE-2025-55182 — Multiple Threat Actors Actively Exploiting React Server Components RCE (CVSS 10.0) (update)CRITICAL
- Ivanti EPMM Dual-CVE Unauthenticated RCE Chain (CVE-2026-1281 + CVE-2026-1340) — CVSS 9.8, CISA KEV, Dutch Government Breached, Bulletproof Hosting IAB, Sleeper Webshells, 28K+ Attacking IPs (update)CRITICAL
- CVE-2026-21902: Juniper PTX Series Junos OS Evolved Unauthenticated Remote Code Execution as Root via On-Box Anomaly Detection Framework (CVSS 9.8) (update)CRITICAL
- CVE-2026-3055 & CVE-2026-4368: Citrix NetScaler ADC/Gateway Pre-Auth Memory Overread and Session Mixup (update)CRITICAL
- CVE-2026-33824: Windows IKE Extensions Unauthenticated RCE via Double Free (update)CRITICAL
- Sorry Ransomware Mass Exploitation of cPanel/WHM Authentication Bypass CVE-2026-41940 (44,000+ Servers Compromised) (update)CRITICAL
- Q1 2026 Ransomware Landscape: Qilin Dominance, LockBit 5.0 Comeback, and FortiGate (CVE-2024-55591) / Oracle EBS (CVE-2025-61882) Mass Exploitation (update)CRITICAL
- CVE-2026-8037: Pre-Auth Command Injection RCE in Progress Kemp LoadMaster via Uninitialized-Heap escape_quotes() Flaw on /accessv2 (update)CRITICAL
- CVE-2026-20253: Critical Unauthenticated Remote Code Execution in Splunk Enterprise via PostgreSQL Sidecar Service (update)CRITICAL
- CitrixBleed 2.0: CVE-2026-8451 NetScaler SAML IDP Memory Overread Under Active Exploitation (update)CRITICAL
- F5 Patches Multiple NGINX Vulnerabilities: Heap Overflow, Memory Disclosure, and Use-After-Free (CVE-2026-42533, CVE-2026-60005, CVE-2026-56434) (update)CRITICAL
- CVE-2026-63030 (wp2shell): Unauthenticated Remote Code Execution in WordPress Core REST API Batch Endpoint via Chained SQL Injection (CVE-2026-60137) (update)CRITICAL
- Progress ShareFile Pre-Auth RCE Chain via Auth Bypass (CVE-2026-2699, CVE-2026-2701) (update)CRITICAL
- Ransomware Attack on Coca-Cola's Fairlife Dairy Halts U.S. Production SystemsHIGH
- CVE-2025-12480: Triofox HTTP Host Header Authentication Bypass Exploited by UNC6485 for SYSTEM-Level Code ExecutionHIGH
- GTIG: Threat Actor Usage of AI Tools — 'Just-in-Time' AI-Enabled Malware (PROMPTFLUX, PROMPTSTEAL/LAMEHUG, PROMPTLOCK, FRUITSHELL, QUIETVAULT) Deployed by State ActorsHIGH
- UNC6229: Vietnamese Actors Use Fake Job Posting Campaigns to Deliver RATs and Steal CredentialsHIGH
- COLDRIVER (UNC4057/Star Blizzard) Re-Tools with NOROBOT/BAITSWITCH/YESROBOT/MAYBEROBOT/SIMPLEFIX Malware Chain After LOSTKEYS DisclosureHIGH
- DPRK's UNC5342 Adopts EtherHiding to Deliver JADESNOW and INVISIBLEFERRET via Blockchain Smart ContractsHIGH
- SleeperGem: RubyGems Supply Chain Attack via Compromised Dormant Maintainer AccountsHIGH
- CVE-2026-32746: Pre-Auth BSS Buffer Overflow in GNU inetutils telnetd LINEMODE SLC HandlingHIGH
- Coordinated Domain Impersonation Campaign Exploits Fable 5/Mythos 5 AI Model Export-Control Ban — 117+ Malicious Domains Targeting Anthropic, Claude, and Fable BrandsHIGH
- Mass Phishing/Fraud Campaign Impersonating Anthropic Claude and Mythos Brands (3,188 Malicious Domains)HIGH
- MetaChat Brand Impersonation Phishing Campaign Targets AI API Keys and Credentials via EdgeOne PagesHIGH
- APT37 Pretexting Campaign: Facebook Social Engineering Delivers RokRAT via Tampered PDFelement InstallerHIGH
- UAC-0145 (Sandworm/APT44, GRU) Uses ClickFix Fake-CAPTCHA Lures and EtherHiding to Deploy Multi-Stage GHETTOVIBE/SCOUTCURL/FLUIDLEECH/FREAKYPOLL/COWARDDUCK Toolset Against UkraineHIGH
- HelloNet Campaign Abuses ViPNet Update Mechanism to Deploy HelloInjector/HelloProxy/HelloBackdoor Toolset Against Russian Government AgenciesHIGH
- MuddyWater APT (Iran MOIS-linked, G0069) abuses legitimate RMM tools, VBA macro loaders, and Rust-compiled payloads in ongoing global espionage campaignHIGH
- SleeperGem: Compromised RubyGems Packages (git_credential_manager, Dendreo, fastlane-plugin-run_tests_firebase_testlab) Drop Persistent Multi-Stage Backdoor via Dormant Maintainer AccountsHIGH
- Lumma Infostealer (LummaC2): MaaS Credential Theft via NSIS/AutoIt/ClickFix Evasion ChainHIGH
- CVE-2025-62507: Unauthenticated Stack-Based Buffer Overflow RCE in Redis XACKDEL CommandHIGH
- Pre-Auth Remote Code Execution in Enterprise Network Printer Firmware via Fuzzed Management Protocol (STAR Labs Research)HIGH
- Pwn2Own Berlin 2026 Day Three: Zero-Days Demonstrated in VMware ESXi, Microsoft SharePoint, Windows 11, Red Hat Linux, and Anthropic Claude CodeHIGH
- CVE-2025-6978: Authenticated Diagnostics Command Injection Leading to Root RCE in Arista NG FirewallHIGH
- ClickFix, CrashFix, InstallFix, FileFix & GhostClaw: Growing Family of Copy-and-Paste Social Engineering AttacksHIGH
- Infostealer-Enabled ClickFix Campaign Compromises Artlist via EtherHiding C2 and DLL Side-Loaded RATHIGH
- CVE-2026-8461 (PixelSmash): Heap Out-of-Bounds Write in FFmpeg libavcodec MagicYUV Decoder (update)HIGH
- Google Chrome 150.0.7871.114/.115 Patches 27 Vulnerabilities Including Two Critical Use-After-Free Flaws (CVE-2026-15112, CVE-2026-15129) (update)HIGH
- IonStack: One-Click Firefox JIT-to-Linux-Kernel Root Exploit Chain (CVE-2026-10702 + CVE-2026-43499 "GhostLock") Demonstrated Against Android 17 (update)HIGH
- Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability (CVE-2026-58525) (update)HIGH
- CVE-2026-26133: Cross-Prompt Injection in Microsoft Copilot Email/Teams Summarization Enables AI-Mediated Phishing (update)HIGH
- 700+ Typosquatted/Lookalike Domains Targeting Oil and Gas Brands (Chevron, ExxonMobil, Shell) for Phishing, BEC, and Recruitment FraudMEDIUM
- Pokémon Brand-Spoofing Campaign: 1,352 Lookalike Domains Ahead of 30th AnniversaryMEDIUM
- ChatGPT Plus Billing Phishing Campaign Spoofs Stripe Checkout to Harvest Payment Card DataMEDIUM
- Winter Olympics 2026 Domain Impersonation and Phishing Infrastructure Campaign (update)MEDIUM
Techniques observed
253 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T1003
- T1005
- T1007
- T1008
- T1014
- T1016
- T1018
- T1020
- T1021
- T1021.001
- T1021.004
- T1025
- T1027
- T1027.002
- T1027.007
- T1033
- T1036
- T1036.003
- T1036.005
- T1036.008
- T1037.001
- T1040
- T1041
- T1046
- T1047
- T1048
- T1049
- T1053
- T1053.003
- T1053.005
- T1055
- T1055.012
- T1056
- T1056.001
- T1056.003
- T1057
- T1059
- T1059.001
- T1059.003
- T1059.004
- T1059.005
- T1059.006
- T1059.007
- T1059.011
- T1068
- T1069
- T1070
- T1070.001
- T1070.003
- T1070.004
- T1071
- T1071.001
- T1071.004
- T1074
- T1074.001
- T1078
- T1078.003
- T1080
- T1082
- T1083
- T1087
- T1087.001
- T1087.002
- T1090
- T1090.002
- T1090.003
- T1090.004
- T1091
- T1095
- T1098
- T1098.007
- T1102
- T1102.001
- T1102.002
- T1104
- T1105
- T1106
- T1110
- T1110.002
- T1111
- T1112
- T1113
- T1114
- T1115
- T1119
- T1120
- T1123
- T1125
- T1129
- T1133
- T1134
- T1134.003
- T1134.005
- T1136
- T1136.001
- T1137
- T1140
- T1176
- T1185
- T1187
- T1189
- T1190
- T1195
- T1195.001
- T1195.002
- T1199
- T1203
- T1204
- T1204.001
- T1204.002
- T1204.004
- T1210
- T1211
- T1212
- T1213
- T1217
- T1218
- T1218.011
- T1219
- T1222
- T1417
- T1480
- T1482
- T1485
- T1486
- T1489
- T1490
- T1491
- T1491.002
- T1495
- T1496
- T1497
- T1497.001
- T1498
- T1499
- T1499.004
- T1505
- T1505.003
- T1517
- T1518
- T1518.001
- T1525
- T1526
- T1528
- T1529
- T1530
- T1531
- T1534
- T1539
- T1543
- T1543.002
- T1543.003
- T1546
- T1546.004
- T1546.016
- T1547
- T1547.001
- T1547.011
- T1548
- T1548.001
- T1548.003
- T1550
- T1550.001
- T1550.004
- T1552
- T1552.001
- T1554
- T1555
- T1555.001
- T1555.003
- T1556
- T1557
- T1560
- T1560.001
- T1562
- T1562.001
- T1562.004
- T1563
- T1564
- T1564.003
- T1565
- T1565.001
- T1566
- T1566.001
- T1566.002
- T1566.003
- T1567
- T1567.001
- T1567.002
- T1568
- T1569
- T1569.002
- T1570
- T1571
- T1572
- T1573
- T1573.001
- T1573.002
- T1574
- T1574.001
- T1574.002
- T1580
- T1583
- T1583.001
- T1583.003
- T1583.004
- T1583.005
- T1583.006
- T1583.008
- T1584
- T1584.004
- T1584.006
- T1585
- T1585.001
- T1585.002
- T1586
- T1586.002
- T1587
- T1587.001
- T1587.003
- T1587.004
- T1588
- T1588.001
- T1588.005
- T1588.006
- T1589
- T1589.001
- T1590
- T1590.005
- T1591
- T1591.003
- T1592
- T1592.002
- T1593
- T1594
- T1595
- T1595.001
- T1595.002
- T1596
- T1596.005
- T1598
- T1598.003
- T1606
- T1608
- T1610
- T1611
- T1613
- T1614
- T1620
- T1621
- T1656
- T1657
- T1685
Threat actors
13 named threat actors across the reports.
Nation-state attribution
- Russia
- Vietnam
- North Korea (DPRK)
- North Korea
- China (low-confidence, disputed/possible false flag)
- Iran
- China, Iran
- China
Threat categories
- PHISHING
- RANSOMWARE
- VULNERABILITY
- MALWARE
- SUPPLY_CHAIN
- APT
- THREAT_ACTOR
- SOCIAL_ENGINEERING
Severity breakdown
- critical16
- high28
- medium4
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- network 387
- behavioral 293
- file 257
- entity 110
- infrastructure 86
- malware 86
- technique 76
- tool 75
- package 36
- vulnerability 17
- host 3
- software 1