Summary & highlights
OpenSSL Silently Patches "HollowByte" Memory-Exhaustion DoS Vulnerability. NSFOCUS 2025 APT Group Research Annual Report: 662 Active APT Groups, 42 Newly Disclosed, AI-Weaponized Attacks Surge 89% YoY. Odyssey Piracy Scam Campaign: Malvertising and Icon-Spoofed Executables Targeting Movie Downloaders.
Highlights
- TL-2026-1553 — HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to Cavern Manticore/Lyceum (Low Confidence)
- TL-2026-1555 — HollowGraph Malware Abuses Microsoft 365 Calendars for Covert C2 via Graph API
- TL-2026-1556 — CVE-2026-52824: Kimai Docker Image Hardcoded APP_SECRET Enables Account Takeover
- TL-2026-1557 — TELEPUZ: Modular MaaS Banking WebInjector Distributed via ClickFix/VIDAR Chain
- TL-2026-1558 — ClickFix Campaign Delivers TELEPUZ Modular RAT via VIDAR-Based Second Stage
Theme of the day
Unattributed threats dominated the landscape, with multiple active threat postures. New threats emerged, totaling 20 in the latest window.
- social-engineering
- anti-analysis
- dll-sideloading
- credential-theft
- browser-credential-theft
Threats published
29 threat lines in the 2026-07-20 debrief, most severe first. Each links to its full profile.
- Critical Ubuntu Pro Client Vulnerability Enables Root Code Execution via Contract Server Spoofing (CVE-2026-11386)CRITICAL
- GoldenEyeDog / CylindricalCanine Breaches DigiCert Support System to Hijack EV Code-Signing Certificates for Golden Gh0st RAT and Zhong Stealer DistributionCRITICAL
- HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to Cavern Manticore/Lyceum (Low Confidence)HIGH
- HollowGraph Malware Abuses Microsoft 365 Calendars for Covert C2 via Graph APIHIGH
- CVE-2026-52824: Kimai Docker Image Hardcoded APP_SECRET Enables Account TakeoverHIGH
- TELEPUZ: Modular MaaS Banking WebInjector Distributed via ClickFix/VIDAR ChainHIGH
- ClickFix Campaign Delivers TELEPUZ Modular RAT via VIDAR-Based Second StageHIGH
- HollowGraph Malware Abuses Microsoft Graph API and M365 Calendar Events (Future-Dated 2050) for Stealthy Command-and-ControlHIGH
- TELESHIM/MIXEDKEY/BINDCLOAK: Unattributed East Asian Threat Actor Targets Middle East Government Entities via DLL Sideloading and Telegram C2HIGH
- FakeGit Campaign Uses 7,600 GitHub Repositories with AgentBaiting to Spread SmartLoader & StealC MalwareHIGH
- Exposed Server Reveals AI-Assisted WebDAV Phishing Kit Targeting Mexican Users (CVE-2025-33053)HIGH
- HOLLOWGRAPH: Microsoft 365 Calendar-Based C2 Malware Targeting Israeli Organizations (Cavern Manticore)HIGH
- CVE-2026-57309: Unauthenticated Blind SQL Injection in Windu CMS 4.1 (with CVE-2026-57310 Weak Password Hashing and CVE-2026-57311 Unrestricted File Upload)HIGH
- Fake Game Downloads Deliver Amatera Stealer via Ren'Py Loader, MSBuild Abuse, and EtherHiding C2HIGH
- ChainVeil and ViteVenom Malware Linked to DPRK PolinRider Supply-Chain CampaignHIGH
- North Korean Contagious Interview Campaign Deploys OtterCookie via SVG Steganography to Steal Developer CredentialsHIGH
- ViteVenom: Blockchain-C2 npm Supply Chain Malware Targets Vite Ecosystem (Sequel to ChainVeil, PolinRider Cluster)HIGH
- FIFA World Cup 2026 Fraud Ecosystem: GHOST STADIUM Phishing, Mass Typosquatting, and Vidar/Lumma Infostealer Credential TheftHIGH
- SleeperGem Supply-Chain Campaign Uses Three Malicious RubyGems Packages to Backdoor Developer MachinesHIGH
- Hugging Face Breached by Autonomous AI Agent Exploiting Dataset Code-Execution Paths (No CVE Disclosed)HIGH
- Russian Bulletproof Hosting Operators Indicted: Media Land / ML.Cloud Facilitated $62M+ in Ransomware, Phishing, and FraudHIGH
- OTTERCOOKIE Malware Hidden in SVG Flag Images Backdoors Developers via Fake Coding Tests (Contagious Interview / REF9403)HIGH
- OpenSSL Silently Patches "HollowByte" Memory-Exhaustion DoS VulnerabilityMEDIUM
- NSFOCUS 2025 APT Group Research Annual Report: 662 Active APT Groups, 42 Newly Disclosed, AI-Weaponized Attacks Surge 89% YoYMEDIUM
- Odyssey Piracy Scam Campaign: Malvertising and Icon-Spoofed Executables Targeting Movie DownloadersMEDIUM
- Odyssey Movie Piracy Scam Campaign Distributes Malware via Fake Downloads and ScarewareMEDIUM
- Patriot Bait Actor "bandcampro" Abuses Jailbroken Google Gemini CLI to Build and Operate a Dental Clinic Botnet C2MEDIUM
- Alleged Starbucks Data Breach — Threat Actor 'anes2010' Claims 176M Customer Records for Sale on Cybercrime ForumMEDIUM
- CodeTracer: Forensic Attribution Tool for Backdoored AI Code-Completion ModelsLOW
Techniques observed
242 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T1001
- T1001.002
- T1003
- T1005
- T1007
- T1008
- T1010
- T1012
- T1016
- T1018
- T1020
- T1021
- T1021.001
- T1021.002
- T1021.003
- T1021.005
- T1021.006
- T1025
- T1027
- T1027.002
- T1027.003
- T1027.010
- T1029
- T1033
- T1036
- T1036.002
- T1036.003
- T1036.005
- T1036.007
- T1039
- T1041
- T1046
- T1047
- T1048
- T1049
- T1053
- T1053.003
- T1053.005
- T1055
- T1055.012
- T1056
- T1056.001
- T1057
- T1059
- T1059.001
- T1059.003
- T1059.004
- T1059.006
- T1059.007
- T1068
- T1069
- T1069.001
- T1070
- T1070.001
- T1070.003
- T1070.004
- T1070.006
- T1071
- T1071.001
- T1071.004
- T1072
- T1074
- T1074.001
- T1074.002
- T1078
- T1078.003
- T1078.004
- T1082
- T1083
- T1087
- T1087.001
- T1087.002
- T1087.004
- T1090
- T1090.001
- T1090.002
- T1090.003
- T1090.004
- T1095
- T1098
- T1098.001
- T1102
- T1102.001
- T1102.002
- T1104
- T1105
- T1106
- T1110
- T1110.001
- T1110.002
- T1110.004
- T1112
- T1113
- T1114
- T1114.002
- T1115
- T1119
- T1123
- T1129
- T1132
- T1132.001
- T1133
- T1134
- T1135
- T1136.001
- T1140
- T1185
- T1187
- T1189
- T1190
- T1195
- T1195.001
- T1195.002
- T1199
- T1203
- T1204
- T1204.001
- T1204.002
- T1204.003
- T1212
- T1213
- T1217
- T1218
- T1218.009
- T1218.014
- T1219
- T1482
- T1486
- T1491.002
- T1497
- T1497.001
- T1499
- T1499.001
- T1499.002
- T1499.003
- T1499.004
- T1505
- T1505.003
- T1505.005
- T1518
- T1518.001
- T1525
- T1526
- T1528
- T1529
- T1530
- T1537
- T1538
- T1539
- T1543
- T1543.002
- T1546
- T1546.004
- T1547
- T1547.001
- T1547.005
- T1548
- T1548.001
- T1548.002
- T1548.003
- T1550
- T1550.001
- T1550.002
- T1550.003
- T1550.004
- T1552
- T1552.001
- T1553
- T1553.002
- T1555
- T1555.003
- T1557
- T1560
- T1562
- T1562.001
- T1564
- T1564.001
- T1564.003
- T1564.004
- T1565
- T1565.001
- T1566
- T1566.001
- T1566.002
- T1566.003
- T1567
- T1567.002
- T1568
- T1569
- T1570
- T1571
- T1572
- T1573
- T1573.001
- T1573.002
- T1574
- T1574.001
- T1574.002
- T1580
- T1583
- T1583.001
- T1583.004
- T1583.005
- T1583.006
- T1583.008
- T1584
- T1584.005
- T1585
- T1585.001
- T1586
- T1586.001
- T1587
- T1587.001
- T1588
- T1588.001
- T1588.003
- T1588.005
- T1588.006
- T1589
- T1589.002
- T1590
- T1591
- T1592
- T1592.002
- T1592.004
- T1593
- T1594
- T1595
- T1595.001
- T1595.002
- T1596
- T1598
- T1606
- T1608
- T1608.001
- T1611
- T1614
- T1620
- T1622
- T1656
- T1657
- T1685
Threat actors
12 named threat actors across the reports.
- Cleaver
- bandcampro
- anes2010
- Cavern Manticore
- Cavern backdoor framework
- FakeGit Operator
- PolinRider
- Contagious Interview
- SuccessKey
- GHOST STADIUM
- Media Land LLC
- DragonBreath
Nation-state attribution
- Iran / North Korea (Cleaver, Lazarus); TA505 is non-state financially motivated
- Russia
- Iran
- North Korea (DPRK)
- North Korea
- North Korea (assessed, via PolinRider overlap)
- China
Threat categories
- VULNERABILITY
- APT
- SCAM
- MALWARE
- DATA_BREACH
- SUPPLY_CHAIN
- FRAUD
- INTRUSION
- CYBERCRIME
Severity breakdown
- critical2
- high20
- medium6
- low1
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- network 187
- file 172
- behavioral 168
- malware 82
- package 58
- entity 57
- infrastructure 55
- tool 30
- technique 12
- vulnerability 3