Summary & highlights
ShutterGap: Ephemeral Public Exposure of AWS RDS/DocumentDB Snapshots, AMIs & SSM Documents Evades CSPM/CNAPP Scan Cycles. 1337_GWTK: Malware-as-a-Service C2 Platform Masquerading as Server Administration Tool (Markas Escobar). CVE-2026-17059: Keycloak Admin REST API Broken Object-Level Authorization Exposes User PII.
Highlights
- TL-2026-1781 — Multiple Vulnerabilities in Citrix XenServer 8.4 and 9 Enable Guest-to-Host Escalation and Denial of Service (CVE-2026-42492, CVE-2026-62428, CVE-2026-62431, CVE-2026-62432, CVE-2026-62434, CVE-2026-62435, CVE-2026-62436)
- TL-2026-1782 — Multiple Vulnerabilities in PHP (GovCERT.HK A26-07-52): Phar Symlink DoS, Bundled-libgd GIF Memory Corruption, pgsql SQL Injection, and BCMath Out-of-Bounds Write (CVE-2026-7260, CVE-2026-9672, CVE-2026-17543, CVE-2026-17544)
- TL-2026-1783 — OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting Central Asian Government and Critical Infrastructure
- TL-2026-1785 — Astaroth (Guildma) Banking Trojan Adds WhatsApp Web Spambot Module — STAC3150 / "Boto Cor-de-Rosa" Campaign Self-Propagates Across Brazil
- TL-2026-1786 — OctLurk/SilkLurk Backdoors Target Central Asian Government Networks for Keylogging and Credential Theft
Theme of the day
Activity centered on active-exploitation, aes-encryption, agamemnon-downloader.
- credential-theft
- defense-evasion
- remote-code-execution
- data-exfiltration
- c2-infrastructure
Threats published
28 threat lines in the 2026-07-31 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- State-Sponsored Actors Exploit AnySign4PC Zero-Day via Compromised Watering-Hole Sites to Deploy SIGNBT and COPPERHEDGE BackdoorsCRITICAL
- CosmosEscape: Platform-Wide Cosmos Master Key Exposure via Gremlin API Sandbox Escape in Azure Cosmos DBCRITICAL
- CVE-2026-28323: SolarWinds Web Help Desk SAML Authentication BypassCRITICAL
- Adobe Campaign Classic Critical Incorrect Authorization Flaw Enables Unauthenticated Remote Code Execution (CVE-2026-48449) Paired With SQL Injection Memory/File Disclosure (CVE-2026-48448)CRITICAL
- CVE-2025-67649: Unauthenticated SQL Injection in PHP Jabbers Car Rental Script (<4.1)CRITICAL
- CosmosEscape: Gremlin API Sandbox Escape Exposed Platform-Wide Key for Every Azure Cosmos DB DatabaseCRITICAL
- Zimbra Collaboration Suite Stored XSS via CSS @import Active Exploitation (CVE-2025-66376) — Operation GhostMail (update)CRITICAL
- The Gentlemen Ransomware: Worm-Like Self-Propagation and Network-Wide Encryption via Storm-2697's RaaS Affiliate Program (update)CRITICAL
- Amazon: North Korea's Sapphire Sleet (Stardust Chollima/UNC1069) Compromises Axios, Debug, Chalk, and Typo-Crypto npm Packages in Supply-Chain Campaign (update)CRITICAL
- Multiple Vulnerabilities in Citrix XenServer 8.4 and 9 Enable Guest-to-Host Escalation and Denial of Service (CVE-2026-42492, CVE-2026-62428, CVE-2026-62431, CVE-2026-62432, CVE-2026-62434, CVE-2026-62435, CVE-2026-62436)HIGH
- Multiple Vulnerabilities in PHP (GovCERT.HK A26-07-52): Phar Symlink DoS, Bundled-libgd GIF Memory Corruption, pgsql SQL Injection, and BCMath Out-of-Bounds Write (CVE-2026-7260, CVE-2026-9672, CVE-2026-17543, CVE-2026-17544)HIGH
- OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting Central Asian Government and Critical InfrastructureHIGH
- Astaroth (Guildma) Banking Trojan Adds WhatsApp Web Spambot Module — STAC3150 / "Boto Cor-de-Rosa" Campaign Self-Propagates Across BrazilHIGH
- OctLurk/SilkLurk Backdoors Target Central Asian Government Networks for Keylogging and Credential TheftHIGH
- SilverFox APT Deploys Advanced ValleyRAT Campaign Against Japanese Manufacturer via DLL Sideloading and BYOVDHIGH
- XCSSET v40: Fileless macOS Xcode-Supply-Chain Malware Adds Chrome DevTools Protocol Hijacking and Telegram TrojanizationHIGH
- Device Code Phishing: OAuth Device Authorization Grant Abuse Bypasses All MFA Forms, Including PasskeysHIGH
- North Korean UNC5342 EtherHiding Campaign: Node.js RAT Delivered via Fake macOS Update Lures Using Ethereum Smart-Contract C2HIGH
- North Korea's Lazarus Group Linked to Tool-Sharing with Gunra Ransomware Operators Against South Korean Targets ("Operation Double Barrel")HIGH
- ClickFix Campaign Uses EtherHiding to Deliver Node.js RAT, Infostealer, and Malicious Chrome Extension — DPRK Wallet Trail ExposedHIGH
- Anthropic AI Agent Publishes Live Credential-Stealing Malware as PyPI Package "anthropickit"HIGH
- BlackTech Deploys BlueShell Linux Backdoor Against Japanese OrganizationsHIGH
- CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver CornFlake RAT and Steal Microsoft 365 TokensHIGH
- ShutterGap: Ephemeral Public Exposure of AWS RDS/DocumentDB Snapshots, AMIs & SSM Documents Evades CSPM/CNAPP Scan CyclesMEDIUM
- 1337_GWTK: Malware-as-a-Service C2 Platform Masquerading as Server Administration Tool (Markas Escobar)MEDIUM
- CVE-2026-17059: Keycloak Admin REST API Broken Object-Level Authorization Exposes User PIIMEDIUM
- ESET H1 2026 Threat Report: Malicious AI Agent Skills Surge Fivefold to 3,000+ Entries; PromptSpy Debuts as First Gemini-Powered Android MalwareMEDIUM
- Google AI Agents (Big Sleep, CodeMender, Gemini) Fix 1,072 Chrome Security Bugs Across Chrome 149/150, Including 13-Year-Old ANGLE Sandbox-Escape (CVE-2026-10881)
Techniques observed
264 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T1001
- T1002
- T1003
- T1003.003
- T1005
- T1007
- T1008
- T1010
- T1014
- T1016
- T1018
- T1020
- T1021
- T1021.001
- T1021.002
- T1021.004
- T1025
- T1027
- T1027.002
- T1027.003
- T1027.010
- T1027.013
- T1027.017
- T1030
- T1033
- T1036
- T1036.003
- T1036.004
- T1036.005
- T1037.004
- T1040
- T1041
- T1046
- T1047
- T1048
- T1049
- T1053
- T1053.005
- T1055
- T1055.012
- T1056
- T1056.001
- T1056.004
- T1057
- T1059
- T1059.001
- T1059.002
- T1059.003
- T1059.004
- T1059.005
- T1059.007
- T1068
- T1069
- T1070
- T1070.004
- T1071
- T1071.001
- T1071.003
- T1074
- T1074.001
- T1078
- T1078.001
- T1078.004
- T1082
- T1083
- T1087
- T1087.002
- T1090
- T1090.001
- T1090.002
- T1090.003
- T1092
- T1095
- T1098
- T1102
- T1102.001
- T1104
- T1105
- T1106
- T1110
- T1110.002
- T1110.003
- T1111
- T1112
- T1113
- T1114
- T1115
- T1119
- T1120
- T1123
- T1124
- T1125
- T1129
- T1132
- T1132.001
- T1132.002
- T1133
- T1134
- T1134.003
- T1135
- T1136
- T1136.001
- T1140
- T1176
- T1185
- T1187
- T1189
- T1190
- T1195
- T1195.001
- T1195.003
- T1197
- T1199
- T1203
- T1204
- T1204.001
- T1204.002
- T1204.004
- T1210
- T1211
- T1212
- T1213
- T1217
- T1218
- T1218.001
- T1218.007
- T1218.010
- T1219
- T1220
- T1222
- T1398
- T1417
- T1426
- T1476
- T1480
- T1482
- T1484
- T1485
- T1486
- T1489
- T1490
- T1491
- T1497
- T1497.001
- T1499
- T1499.001
- T1499.002
- T1499.004
- T1505
- T1505.003
- T1512
- T1513
- T1518
- T1518.001
- T1521
- T1526
- T1528
- T1529
- T1530
- T1531
- T1534
- T1537
- T1538
- T1539
- T1541
- T1543
- T1543.001
- T1543.003
- T1543.004
- T1546
- T1546.004
- T1547
- T1547.001
- T1547.009
- T1547.014
- T1548
- T1548.002
- T1550
- T1550.001
- T1550.004
- T1552
- T1552.001
- T1553
- T1553.002
- T1554
- T1555
- T1555.003
- T1556
- T1557
- T1557.001
- T1560
- T1560.001
- T1561.002
- T1562
- T1562.001
- T1564
- T1564.001
- T1564.003
- T1564.004
- T1565
- T1565.001
- T1566
- T1566.001
- T1566.002
- T1566.004
- T1567
- T1568
- T1568.002
- T1569
- T1570
- T1571
- T1572
- T1573
- T1573.001
- T1573.002
- T1574
- T1574.001
- T1574.002
- T1580
- T1583
- T1583.001
- T1583.003
- T1583.004
- T1583.008
- T1584
- T1584.003
- T1584.004
- T1584.006
- T1585
- T1586
- T1587
- T1587.001
- T1587.004
- T1588
- T1588.002
- T1588.006
- T1589
- T1590
- T1590.002
- T1591
- T1592
- T1592.002
- T1595
- T1595.002
- T1596
- T1596.005
- T1598
- T1599
- T1602
- T1606
- T1608
- T1608.001
- T1611
- T1614
- T1619
- T1620
- T1622
- T1628
- T1646
- T1649
- T1651
- T1656
- T1657
- T1660
Threat actors
10 named threat actors across the reports.
- Markas Escobar
- Void Arachne
- UNC5342
- Lazarus Group
- Claude "Mythos 5"
- BlackTech
- Storm-2945
- APT28
- Storm-2697 / The Gentlemen (administrator identified as Alexander Andreevich Yapaev, aka hastalamuerte/zeta88/SantaMuerte)
- Sapphire Sleet
Nation-state attribution
- Indonesia
- China (assessed, medium confidence; unattributed to a known group)
- China (assessed, medium confidence — not attributed to a named APT)
- China
- Russia (Storm-2372 attribution, medium confidence); criminal actors are not state-affiliated
- North Korea (DPRK)
- North Korea
- Russia
Threat categories
- VULNERABILITY
- MALWARE
- THREAT_INTEL
- PHISHING
- APT
- SUPPLY_CHAIN
- RANSOMWARE
Severity breakdown
- critical9
- high14
- medium4
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- network 253
- file 204
- behavioral 193
- tool 77
- entity 74
- infrastructure 64
- malware 60
- package 34
- technique 30
- financial 7