Summary & highlights
Claude Code Symlink Flaw in Startup Memory Loader Enables Silent File Exfiltration via CLAUDE.md Imports. Aftercall: Android Adware Campaign Abuses Overlay/Full-Screen Permissions to Bombard Users with Post-Call Ads. UK Supreme Court Rejects Bahrain's State Immunity Claim in FinSpy/FinFisher Spyware Surveillance Case (Shehabi v Kingdom of Bahrain).
Highlights
- TL-2026-1714 — npm Supply-Chain Compromise (chalk/debug + 17 packages, Sept 2025) — Motivates GitHub Dependabot 'Cooldown' Mitigation
- TL-2026-1716 — MCBS Ransomware Data Breach: PEAR Extortion Group Exposes PII and Health Records of 1.26 Million Individuals Across Seven Healthcare Clients
- TL-2026-1717 — SparkKitty: Cross-Platform iOS/Android Stealer Using OCR to Harvest Crypto Wallet Seed Phrases from App Store and Google Play
- TL-2026-1719 — BlueNoroff Fake Meeting Kit Captures Webcams, Disables Windows Defender, and Steals Cryptocurrency Credentials via ClickFix and AI Deepfake Social Engineering
- TL-2026-1720 — BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware via Deepfake Zoom/Teams Calls
Theme of the day
Financially motivated threat actors, including ShinyHunters, were active today. Social engineering and financial theft tactics were prominent.
- data-exfiltration
- social-engineering
- financially-motivated
- ransomware
- credential-theft
Threats published
28 threat lines in the 2026-07-27 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- AgentForger: Cross-Site Agent Forgery in ChatGPT Workspace Agent BuilderCRITICAL
- GitLab RCE Chain via Malicious Jupyter Notebooks Exploiting Oj Ruby JSON Parser FlawsCRITICAL
- CISA Adds Two Known Exploited Vulnerabilities to Catalog: Fortinet FortiOS Information Disclosure (CVE-2025-68686) and Arista VeloCloud Orchestrator OS Command Injection (CVE-2026-16812)CRITICAL
- TeamPCP Partners With Vect Ransomware Group to Escalate Cross-Ecosystem Open Source Supply Chain Attacks (update)CRITICAL
- Iranian IRGC CyberAv3ngers APT Campaign Targeting Rockwell/Allen-Bradley PLCs (CISA AA26-097A) (update)CRITICAL
- wp2shell: WordPress Core REST API Batch-Route Confusion Chained with author__not_in SQL Injection (CVE-2026-63030 / CVE-2026-60137) Yields Unauthenticated Pre-Auth RCE (update)CRITICAL
- Estée Lauder Data Breach via Oracle E-Business Suite Zero-Day (CVE-2025-61882) — Clop Exploitation (update)CRITICAL
- npm Supply-Chain Compromise (chalk/debug + 17 packages, Sept 2025) — Motivates GitHub Dependabot 'Cooldown' MitigationHIGH
- MCBS Ransomware Data Breach: PEAR Extortion Group Exposes PII and Health Records of 1.26 Million Individuals Across Seven Healthcare ClientsHIGH
- SparkKitty: Cross-Platform iOS/Android Stealer Using OCR to Harvest Crypto Wallet Seed Phrases from App Store and Google PlayHIGH
- BlueNoroff Fake Meeting Kit Captures Webcams, Disables Windows Defender, and Steals Cryptocurrency Credentials via ClickFix and AI Deepfake Social EngineeringHIGH
- BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware via Deepfake Zoom/Teams CallsHIGH
- Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors ProfiledHIGH
- MedusaHVNC: Malware-as-a-Service RAT Uses Hidden Desktop (hVNC) to Hijack Live Browser Sessions and Steal CredentialsHIGH
- AnMed Health Ransomware/Malware Disruption Closes 79-83 South Carolina/Georgia Facilities, Extortion Note Demands Payment Within 72 HoursHIGH
- SafePay Ransomware Abuses OneDrive Sync Client for Covert Data ExfiltrationHIGH
- Anubis Ransomware Group Confirms Data Theft in Coca-Cola Fairlife Attack Tied to CitrixBleed 2 (CVE-2025-5777) Exploitation WaveHIGH
- Operation BlueDash: Fake Microsoft Teams Update Deploys Dual RMM Backdoors (Level RMM + ScreenConnect)HIGH
- MedusaHVNC — Hidden Virtual Desktop RAT with AMSI/ETW Bypass and Multi-Browser Session HijackingHIGH
- TELESHIM/MIXEDKEY/BINDCLOAK: Unattributed East Asian Threat Actor Targets Middle East Government Entities via DLL Sideloading and Telegram C2 (update)HIGH
- Claude Code Symlink Flaw in Startup Memory Loader Enables Silent File Exfiltration via CLAUDE.md ImportsMEDIUM
- Aftercall: Android Adware Campaign Abuses Overlay/Full-Screen Permissions to Bombard Users with Post-Call AdsMEDIUM
- UK Supreme Court Rejects Bahrain's State Immunity Claim in FinSpy/FinFisher Spyware Surveillance Case (Shehabi v Kingdom of Bahrain)MEDIUM
- Check Point Q2 2026 Brand Phishing Report: Microsoft Leads at 23%, ChatGPT Enters Top 10 Impersonated BrandsMEDIUM
- Sen. Wyden Urges Binding Federal Mandate to Purge Internet-Facing Legacy VPNs for Zero-Trust Remote AccessMEDIUM
- Proofpoint AI Era Ransomware Report: 37% of Paying Victims Face Repeat Extortion Demands (update)MEDIUM
- Sextortion Scammers Impersonate ShinyHunters, Exploit Leaked Breach Data for Bitcoin ExtortionLOW
- Google GTIG Adopts Two-Word Threat Actor Naming Taxonomy — Sandworm/APT44 Redesignated SANDWORM RELIC
Techniques observed
288 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T0806
- T0807
- T0812
- T0813
- T0814
- T0819
- T0821
- T0826
- T0828
- T0829
- T0831
- T0836
- T0837
- T0838
- T0843
- T0846
- T0855
- T0856
- T0858
- T0861
- T0866
- T0868
- T0869
- T0878
- T0880
- T0883
- T0884
- T0885
- T0886
- T0888
- T0889
- T1003
- T1003.001
- T1003.003
- T1005
- T1010
- T1012
- T1014
- T1016
- T1018
- T1020
- T1021
- T1021.001
- T1021.002
- T1027
- T1027.002
- T1027.004
- T1027.013
- T1030
- T1033
- T1036
- T1036.005
- T1037
- T1039
- T1041
- T1046
- T1047
- T1048
- T1048.003
- T1049
- T1053
- T1053.005
- T1055
- T1055.001
- T1056
- T1056.001
- T1056.003
- T1057
- T1059
- T1059.001
- T1059.002
- T1059.003
- T1059.004
- T1059.005
- T1059.006
- T1059.011
- T1068
- T1069
- T1069.001
- T1069.002
- T1070
- T1070.001
- T1070.002
- T1070.004
- T1071
- T1071.001
- T1071.003
- T1072
- T1074
- T1074.001
- T1078
- T1078.002
- T1078.003
- T1082
- T1083
- T1087
- T1087.001
- T1087.002
- T1090
- T1090.003
- T1095
- T1098
- T1098.002
- T1098.005
- T1102
- T1102.002
- T1105
- T1106
- T1110
- T1110.002
- T1110.003
- T1110.004
- T1112
- T1113
- T1114
- T1115
- T1119
- T1123
- T1125
- T1132
- T1133
- T1134
- T1134.002
- T1135
- T1136
- T1136.001
- T1140
- T1185
- T1189
- T1190
- T1195
- T1195.002
- T1199
- T1203
- T1204
- T1204.001
- T1204.002
- T1204.004
- T1210
- T1211
- T1213
- T1213.003
- T1217
- T1218
- T1218.005
- T1218.010
- T1219
- T1404
- T1406
- T1409
- T1426
- T1429
- T1430
- T1437
- T1444
- T1474
- T1475
- T1476
- T1480
- T1481
- T1482
- T1484
- T1485
- T1486
- T1489
- T1490
- T1491
- T1491.001
- T1491.002
- T1497
- T1497.001
- T1505
- T1505.003
- T1518
- T1518.001
- T1521
- T1526
- T1528
- T1529
- T1530
- T1533
- T1534
- T1537
- T1539
- T1542
- T1543
- T1543.001
- T1546
- T1547
- T1547.001
- T1547.004
- T1548
- T1548.002
- T1550
- T1552
- T1552.001
- T1552.004
- T1553
- T1553.005
- T1554
- T1555
- T1555.001
- T1555.003
- T1557
- T1560
- T1560.001
- T1561
- T1561.001
- T1562
- T1562.001
- T1562.009
- T1564
- T1564.001
- T1564.003
- T1565
- T1565.001
- T1566
- T1566.001
- T1566.002
- T1566.003
- T1567
- T1567.002
- T1568
- T1569
- T1569.002
- T1570
- T1571
- T1572
- T1573
- T1574
- T1574.001
- T1574.002
- T1583
- T1583.001
- T1584
- T1584.001
- T1584.004
- T1585
- T1585.002
- T1586
- T1586.002
- T1587
- T1587.001
- T1587.003
- T1587.004
- T1588
- T1588.001
- T1588.005
- T1588.006
- T1589
- T1589.002
- T1591.004
- T1592.002
- T1593
- T1594
- T1595
- T1595.002
- T1596
- T1597
- T1598
- T1598.002
- T1601
- T1602
- T1608
- T1608.001
- T1608.005
- T1610
- T1611
- T1614
- T1614.001
- T1620
- T1621
- T1622
- T1624
- T1627
- T1628
- T1629
- T1636
- T1643
- T1646
- T1650
- T1655
- T1656
- T1657
- T1660
- T1680
- T1685
- T1688
Threat actors
10 named threat actors across the reports.
- Government of the Kingdom of Bahrain
- Sandworm
- PEAR
- APT38
- Safepay
- Anubis Ransomware Group
- Nitrogen
- TeamPCP
- Cyber Av3ngers
- Cl0p
Nation-state attribution
- Bahrain
- China / Russia (primary, per Wyden letter); Iran (documented in earlier exploitation of CVE-2019-11510)
- Russia
- North Korea (DPRK)
- North Korea
- North Korea (DPRK), China, Palestine, Pakistan
- Russia (suspected, unconfirmed)
- Nigeria
- Iran
Threat categories
- VULNERABILITY
- MALWARE
- THREAT_INTEL
- PHISHING
- SUPPLY_CHAIN
- DATA_BREACH
- RANSOMWARE
- APT
Severity breakdown
- critical7
- high13
- medium6
- low1
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- network 207
- file 186
- behavioral 179
- entity 121
- tool 75
- malware 70
- infrastructure 61
- package 42
- technique 21
- financial 1
- vulnerability 1