Summary & highlights
Everest Ransomware Gang Extorts Stadler Rail via Compromised Supplier Credentials, CHF 10M Demand Refused. AI Agent Identities Emerge as the Enterprise's Fastest-Growing Attack Surface: OAuth Tokens, Shadow AI, and AI-Driven EDR Evasion (STAC6994, UNC6395, NadMesh). Proofpoint 2026 AI-Era Ransomware Report: 65% of Victims Report AI Increased Attack Effectiveness.
Highlights
- TL-2026-1679 — InsureOTP Kit: Real-Time OTP Interception Phishing Campaign Targeting Insurance Providers (CTM360)
- TL-2026-1687 — SourTrade Malvertising Campaign Assembles Windows Malware In-Browser via ServiceWorker/SharedWorker JavaScript Chain to Defeat Hash-Based Detection
- TL-2026-1691 — GitLab RCE via Chained Oj JSON Parser Memory-Safety Flaws (Code Execution as 'git' User)
- TL-2026-1692 — Exim Directory Traversal (CVE-2026-66140, CVSS 8.4) and .forward Privilege Escalation (CVE-2026-66141, CVSS 7.4) Enable Local Privilege Escalation via Queue-Name Argument and force_command Abuse
- TL-2026-1693 — Stealer Logs: Infostealer Malware Ecosystem Fuels Credential-Theft Economy (LummaC2, Rhadamanthys, Vidar 2.0, StealC, AMOS/MacSync/Poseidon/Odyssey)
Theme of the day
Routine activity — no dominant theme emerged.
- credential-theft
- data-exfiltration
- financially-motivated
- coordinated-disclosure
- privilege-escalation
Threats published
30 threat lines in the 2026-07-25 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- DevMan RaaS ("Funky Mantis") Centralizes Payload Builds, Victim Management, and Affiliate Payouts, Develops SCADA-Destructive LockerCRITICAL
- Compromised Packagist PHP Packages Weaponize GitHub Actions Runners to Target cPanel/WHM Servers (CVE-2026-41940)CRITICAL
- Fastjson 1.x RCE (CVE-2026-16723) — Gadget-Free Deserialization Bypass Actively Exploited in Spring Boot Fat-JAR DeploymentsCRITICAL
- Critical FreeRDP Clipboard Virtual Channel Heap Buffer Overflow (GHSA-cj9v-h4hq-29jr, CVSS 9.4)CRITICAL
- Iran-Linked CyberAv3ngers (BAUXITE) Exploiting Internet-Exposed Rockwell, Schneider Electric, and Siemens PLCs Across US Water, Energy, and Government Infrastructure (CISA AA26-097A)CRITICAL
- Actively Exploited SharePoint Server Elevation of Privilege Flaw (CVE-2026-56164) Patched Alongside Critical RCE Pair in July 2026 Patch Tuesday (update)CRITICAL
- SonicWall SMA1000 SSRF (CVE-2026-15409, CVSS 10.0) Chained With Appliance Management Console Command Injection (CVE-2026-15410, CVSS 7.2) Under Active Zero-Day Exploitation (update)CRITICAL
- Critical FreePBX Flaws Enable Unauthenticated RCE (UCP Socket.IO Auth Bypass) and SQL Injection Leading to Admin Takeover (update)CRITICAL
- InsureOTP Kit: Real-Time OTP Interception Phishing Campaign Targeting Insurance Providers (CTM360)HIGH
- SourTrade Malvertising Campaign Assembles Windows Malware In-Browser via ServiceWorker/SharedWorker JavaScript Chain to Defeat Hash-Based DetectionHIGH
- GitLab RCE via Chained Oj JSON Parser Memory-Safety Flaws (Code Execution as 'git' User)HIGH
- Exim Directory Traversal (CVE-2026-66140, CVSS 8.4) and .forward Privilege Escalation (CVE-2026-66141, CVSS 7.4) Enable Local Privilege Escalation via Queue-Name Argument and force_command AbuseHIGH
- Stealer Logs: Infostealer Malware Ecosystem Fuels Credential-Theft Economy (LummaC2, Rhadamanthys, Vidar 2.0, StealC, AMOS/MacSync/Poseidon/Odyssey)HIGH
- msaRAT: Rust-based RAT Hides C2 in Browser Process, Tied to Chaos Ransomware RaaSHIGH
- SourTrade Malvertising: ServiceWorker-Orchestrated In-Browser Assembly Builds a Unique Windows Executable Per VictimHIGH
- Dolphin X Stealer: AI-Profiled Windows Infostealer/RAT Targeting 300+ ApplicationsHIGH
- KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million CarsHIGH
- KARR Aftermarket Car Alarm Bluetooth Flaw Exposes 2.2M Vehicles to Remote Unlock and ImmobilizationHIGH
- Larva-26009 MS-SQL Server Intrusion Campaign Deploys XMRig, VShell, SoftEther VPN via Multi-Tool ToolkitHIGH
- RefluXFS: Linux Kernel XFS Copy-on-Write Race Condition Local Privilege Escalation (CVE-2026-64600) (update)HIGH
- CVE-2026-8933: Race Condition in Ubuntu snap-confine Enables Local Privilege Escalation to Root (update)HIGH
- CVE-2026-48294 ("HermeticReader"): Adobe Acrobat Chrome Extension Flaw Chain Enables Silent WhatsApp Web Data Theft (update)HIGH
- Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge (update)HIGH
- TrickBot Banking Trojan (Anchor_DNS) Uses DNS Tunneling Over westurn.in for Covert C2 (update)HIGH
- Redis Streams Shared-NACK Double-Free (CVE-2026-25243) & RedisBloom RESTORE/TDigest Heap Overflow (CVE-2026-25589) — Authenticated RCE, Public PoC, Patch Bypass (update)HIGH
- Dolphin X Windows Infostealer Adds AI-Driven Victim Profiling and Polymorphic Panel (update)HIGH
- Everest Ransomware Gang Extorts Stadler Rail via Compromised Supplier Credentials, CHF 10M Demand RefusedMEDIUM
- AI Agent Identities Emerge as the Enterprise's Fastest-Growing Attack Surface: OAuth Tokens, Shadow AI, and AI-Driven EDR Evasion (STAC6994, UNC6395, NadMesh)MEDIUM
- Proofpoint 2026 AI-Era Ransomware Report: 65% of Victims Report AI Increased Attack EffectivenessMEDIUM
- ShinyHunters-Impersonation Sextortion Scam Abuses Emails From 8 Prior Data Leaks, Demands $2,000LOW
Techniques observed
213 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T1001
- T1003
- T1005
- T1006
- T1008
- T1010
- T1012
- T1016
- T1018
- T1020
- T1021
- T1021.001
- T1021.004
- T1027
- T1027.002
- T1027.013
- T1033
- T1036
- T1036.005
- T1036.008
- T1040
- T1041
- T1046
- T1047
- T1053
- T1053.005
- T1055
- T1056
- T1056.001
- T1057
- T1059
- T1059.001
- T1059.003
- T1059.004
- T1059.006
- T1059.007
- T1059.010
- T1068
- T1069
- T1070
- T1070.001
- T1071
- T1071.001
- T1074
- T1074.001
- T1078
- T1078.002
- T1078.003
- T1078.004
- T1082
- T1083
- T1087
- T1090
- T1090.001
- T1090.002
- T1095
- T1098
- T1102
- T1102.001
- T1102.002
- T1105
- T1106
- T1110
- T1110.004
- T1111
- T1112
- T1113
- T1114
- T1115
- T1119
- T1120
- T1129
- T1132
- T1132.001
- T1133
- T1134
- T1135
- T1136
- T1140
- T1176
- T1185
- T1189
- T1190
- T1195
- T1195.002
- T1197
- T1199
- T1203
- T1204
- T1204.001
- T1204.002
- T1205
- T1210
- T1211
- T1213
- T1213.002
- T1217
- T1218
- T1218.005
- T1218.007
- T1218.015
- T1219
- T1222
- T1222.002
- T1482
- T1484
- T1486
- T1489
- T1490
- T1496
- T1497
- T1497.001
- T1498
- T1499
- T1499.004
- T1505
- T1505.003
- T1518
- T1518.001
- T1526
- T1528
- T1529
- T1530
- T1531
- T1539
- T1543
- T1546
- T1546.016
- T1546.017
- T1547
- T1547.001
- T1548
- T1548.001
- T1548.002
- T1550
- T1550.001
- T1552
- T1552.001
- T1552.004
- T1553
- T1553.002
- T1554
- T1555
- T1555.003
- T1555.004
- T1555.005
- T1556
- T1557
- T1559
- T1560
- T1562
- T1562.001
- T1562.004
- T1562.007
- T1564
- T1564.001
- T1564.003
- T1565
- T1566
- T1566.001
- T1566.002
- T1566.004
- T1567
- T1567.002
- T1569
- T1570
- T1571
- T1572
- T1573
- T1573.001
- T1573.002
- T1574.001
- T1574.002
- T1583
- T1583.001
- T1583.003
- T1583.008
- T1584
- T1584.001
- T1584.004
- T1585
- T1585.001
- T1586
- T1587
- T1587.001
- T1587.004
- T1588
- T1588.002
- T1588.006
- T1589
- T1591
- T1592
- T1592.001
- T1592.002
- T1592.004
- T1593
- T1595
- T1595.002
- T1596
- T1596.005
- T1597
- T1598
- T1598.003
- T1606
- T1606.002
- T1608
- T1608.001
- T1611
- T1620
- T1622
- T1650
- T1656
- T1657
Threat actors
10 named threat actors across the reports.
- Everest
- Infostealer MaaS Operators
- Chaos Ransomware-as-a-Service Group
- Kontraktnik
- Larva-26009
- DevMan
- Cyber Av3ngers
- Chaos
- Periwinkle Tempest
- UTA0533
Nation-state attribution
- Russia
- Iran
Threat categories
- RANSOMWARE
- THREAT_INTEL
- PHISHING
- MALWARE
- VULNERABILITY
- SUPPLY_CHAIN
- ICS_SCADA
Severity breakdown
- critical8
- high18
- medium3
- low1
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- behavioral 238
- entity 129
- file 113
- network 100
- tool 92
- infrastructure 55
- malware 45
- package 43
- technique 25
- vulnerability 1