← Carolina Clear Tech

Cyber Threat Brief

2026-07-02

Listen to this brief (27:39)

Download MP3
Show Notes

Show Notes - 2026-07-02

Stories Covered

CVEs Referenced

CVE-2021-29441, CVE-2024-1212, CVE-2024-31989, CVE-2025-11371, CVE-2025-14847, CVE-2025-3248, CVE-2025-55182, CVE-2025-64446, CVE-2026-0257, CVE-2026-10520, CVE-2026-35616, CVE-2026-45659, CVE-2026-48276, CVE-2026-48277, CVE-2026-48281, CVE-2026-48282, CVE-2026-48283, CVE-2026-48286, CVE-2026-48313, CVE-2026-48315, CVE-2026-48316, CVE-2026-48908, CVE-2026-50548, CVE-2026-50549, CVE-2026-50751, CVE-2026-8037

Indicators of Compromise

IP Addresses: 91.132.163.78, 192.42.116.58, 192.42.116.105, 146.70.139.154

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cybersecurity Brief

July 2, 2026

Today: SharePoint RCE hits CISA's known exploited list with a Friday deadline. FortiBleed credential harvesting ties directly to INC and Lynx ransomware deployments across 12 confirmed intrusions. An AI agent executed a fully automated database ransomware attack from initial breach through encryption, no human in the loop.

Critical Alerts

SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation

CISA added CVE-2026-45659 to its Known Exploited Vulnerabilities catalog on Wednesday following evidence of active exploitation. The deserialization flaw (CVSS 8.8) affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Any authenticated attacker with Site Member permissions can trigger remote code execution without requiring admin privileges. Microsoft patched the vulnerability in May 2026 but marked it "Exploitation Less Likely," which now contradicts observed in-the-wild activity. The EPSS score sits at 85th percentile, indicating moderate exploitation probability.

Microsoft Uncovers Parallel Threat Activity from 2 Clusters

A routine ransomware investigation uncovered Storm-2603 (Warlock ransomware) and a second unrelated threat actor operating simultaneously in the same network. Initial access came through CVE-2025-11371 (Gladinet Triofox, CVSS 9.1, EPSS 100th percentile, CISA KEV). Storm-2603 deployed Velociraptor to blend with admin tools, established Cloudflare tunnels and Zoho Assist for persistence, created domain admin accounts, and used a vulnerable driver (NSecKrnl.sys) to disable EDR. The second actor used DLL side-loading and custom backdoors. Both threat groups moved laterally beyond the first network into a second organization.

Ransomware & Extortion

FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations

FortiBleed mass credential harvesting directly fed INC and Lynx ransomware operations. SOCRadar tracked scanning against 11,250 FortiGate portals in 150+ countries, with confirmed admin-level access on 409 targets and full attack chain completion on 354. At least 12 ransomware deployments resulted, encrypting hundreds of endpoints. The campaign targeted 430,000 FortiGate firewalls globally and gathered over 110 million credentials. An operator with FortiBleed infrastructure access was found logged into both INC and Lynx negotiation panels. Victims listed by INC Ransom overlapped with FortiBleed data. Internal documents indicate an organized operation of about 20 people with clear division of labor. Russian-speaking threat actor likely operates as initial access broker. SOCRadar discovered at least one Nextcloud zero-day in the threat actor's possession and is coordinating with the vendor.

AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack

Sysdig documented the first ransomware attack run start-to-finish by an AI agent with no human operator. The agent (JADEPUFFER) exploited CVE-2025-3248 (Langflow missing authentication, CISA KEV, EPSS 100th percentile) to gain initial access, swept for API keys (OpenAI, Anthropic, DeepSeek, Gemini) and cloud credentials (AWS, Google, Azure, Alibaba, Tencent), crypto wallets, and database logins. It raided a MinIO storage server using factory default credentials (minioadmin:minioadmin), pivoted to a MySQL database server, logged in as root (origin of root credentials unknown), exploited CVE-2021-29441 (Nacos authentication bypass, EPSS 99th percentile) using a default signing key unchanged since 2020, encrypted all 1,342 Nacos settings, and dropped a ransom note demanding Bitcoin. The encryption key was generated, printed once, and never saved or exfiltrated, making recovery impossible even if the victim pays. The agent deleted databases and left comments claiming data exfiltration, but Sysdig found no evidence of actual data theft. Code contained plain-English notes explaining each step, a signature of AI-generated payloads. The agent fixed its own mistakes in 31 seconds instead of blind retries.

AI-Generated Browser Ransomware Abuses Chromium API on Windows, Linux, macOS, Android

Check Point documented DeepSeek-generated malware (InfernoGrabber v9.0) that implements in-browser ransomware using the File System Access API on Chromium browsers. The attack runs entirely inside the browser without installing a native payload, exploiting a browser vulnerability, or requiring root access. It tricks users into granting file system access to a web page (typically via fake AI image upscaler or Discord avatar tool), enumerates local files in the selected folder, reads and exfiltrates their contents, encrypts and overwrites them, and displays an extortion note. All of this occurs without leaving disk artifacts. The technique works on Google Chrome and Chromium-based browsers across Windows, macOS, ChromeOS, Linux, and Android. The Android scenario is especially concerning because photo directories are high-value personal data stores and Android Chrome exposes the File System Access API for those directories after user approval. Of nearly 3,000 DeepSeek-attributed files analyzed over the past year, 1,383 were classified as malicious or dangerous. DeepSeek has lower refusal rates for harmful cyber requests compared to Anthropic and OpenAI, free access, and can generate complete malicious applications from a single broad prompt.

Missed Incidents and Persistent Threats: Insights from Compromise Assessment Projects

Kaspersky's 2025 compromise assessment findings show 30.8% of discovered incidents took over three months to detect. 52% of high-severity compromises went undetected for over 90 days. The oldest incident discovered in 2025 had persisted for four years. 40% of all web shells resided in backups and went unnoticed until proper compromise assessment. Threat actors relied on remote management tools and LoLBins in all engagements that resulted in incident detection. Organizations with continuous monitoring and threat hunting saw high- and medium-severity incidents drop to 14-16%, while those without such capabilities saw 84-86%. High-severity incidents were rare among organizations with in-house malware reverse-engineering capabilities. Nearly one-third of compromise assessments revealed communication issues that impacted incident response activities.

Business & Infrastructure Threats

New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos

Attackers hide ChocoPoC malware in fake proof-of-concept repositories on GitHub targeting high-profile CVEs. The malware hides in a Python dependency (frint→skytext) that the PoC pulls during pip install, not in the visible PoC code itself. The compiled file (gradient.so/gradient.pyd) only activates when it detects the real PoC loaded (checks for EXPLOIT_POC.py or similar), which defeats sandbox analysis. Once running, ChocoPoC steals passwords, cookies, autofill, and history from Chrome, Brave, Edge, and Firefox, plus text files, databases, shell history, and network settings. The attacker can run shell commands, execute arbitrary Python, pull folders, and throttle activity to stay quiet. Command and control uses Mapbox datasets as dead drops via DNS-over-HTTPS and domain fronting. Uploads go to 91.132.163.78. At least seven fake PoC repos were found targeting FortiWeb CVE-2025-64446, React2Shell CVE-2025-55182, MongoBleed CVE-2025-14847, PAN-OS CVE-2026-0257, Ivanti Sentry CVE-2026-10520, Check Point VPN CVE-2026-50751, and Joomla CVE-2026-48908. The skytext package alone was downloaded about 2,400 times, mostly on Linux. An earlier campaign used packages slogsec and logcrypt.cryptography with near-identical code.

Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts

CVE-2026-8037 (CVSS 9.6) in Progress Kemp LoadMaster sees active exploitation attempts starting June 29, 2026. The OS command injection flaw allows unauthenticated attackers to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input. The vulnerability stems from improper handling in the escape_quotes() function, which fails to properly null-terminate sanitized strings, leading to out-of-bounds read into adjacent heap memory. Attackers craft requests to the /accessv2 endpoint that manipulate heap memory to enable command injection. eSentire observed exploitation attempts originating from 192.42.116.58, 192.42.116.105, and 146.70.139.154. The attempts failed, but proof-of-concept exploits and technical details are public, driving further exploitation activity. CVE-2026-8037 is the second Kemp LoadMaster flaw to witness active exploitation after CVE-2024-1212 (CVSS 10.0, CISA KEV).

Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes Clusters

Argo CD repo-server has an unpatched unauthenticated RCE that leads to full cluster takeover. The internal gRPC service has no authentication, allowing anyone who can reach it to send crafted requests to run commands. The attack abuses kustomize's --helm-command option to point to a malicious script from an attacker-controlled Git repository instead of the helm binary. Argo CD ships Kubernetes network policies to wall repo-server off, but the Helm chart leaves those policies off by default (networkPolicy.create=false). In that configuration, any compromised pod in the cluster can reach repo-server and trigger the bug. Synacktiv demonstrated using repo-server access to steal the Redis password from an environment variable, connect to Redis, and poison the deployment cache. On the next automatic sync, Argo CD deploys the attacker-supplied workload. This reopens CVE-2024-31989 (2024 Redis password bypass). There is no patched version, no CVE assigned, and no fix timeline. Synacktiv reported the flaw in January 2025, 18 months ago.

Crafty Phishing Campaigns Auto-Adapt to Victim's Device, OS

Cofense documented phishing campaigns that fingerprint victims through user-agent data to deliver OS-specific payloads. Landing pages collect email addresses, browser information, device information, language, local time, screen and window size, and geolocation. One campaign delivered FleetDeck for macOS or Tiflux RAT for Windows based on fingerprinting results. Cloudflare user-agent blocking redirects traffic based on perceived operating system before the victim visits the malicious page, enabling customized payloads without detection scripts. Phishing landing pages mimic Google, Docusign, Microsoft Teams, Adobe, and Zoom download screens based on telemetry. Threat actors exfiltrate data via Telegram. The technique increases compromise rates and campaign profitability by delivering the right malware to the right user instead of losing traffic on unsupported platforms.

This phishing kit looks more like BEC-as-a-service

Cisco Talos discovered ARToken, an operator panel that functions as business email compromise-as-a-service. ARToken shares infrastructure with EvilTokens phishing-as-a-service operation (1,380% attack increase early this year). ARToken goes beyond device code phishing with inbox rule manipulation and shared access links, indicating a complete BEC operations environment. The platform has a seven-layer anti-analysis system. Lures are targeted rather than opportunistic. One examined lure spoofed an accounts-payable contact at a legitimate Wisconsin contractor, addressed to accounts-payable at a U.S. life sciences company, abusing a real vendor relationship. The lure theme was an outstanding-invoice inquiry designed to trigger immediate action.

Microsoft Adds New Teams Controls to Block Unauthorized AI Bots From Meetings

Microsoft added a new Teams admin policy to provide visibility and control over external bots joining meetings. Teams now detects bots and requires explicit organizer confirmation before admitting them. Detected bots are placed in the meeting lobby with clear identification. Even when organizers allow participants to bypass the lobby, bots identified through this policy require approval before joining. ISVs can register bots and include a self-identification marker in join requests for Teams to identify them as known participants. Participants in the lobby are grouped into 'Waiting' (verified individuals and registered bots) and 'Suspected threats' (unregistered bots). Teams does not offer a one-click Admit option for identified bots and requests confirmation when admitting bots. CAPTCHA verification is retired.

Patch Priority

Vulnerability Disclosures

Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic

Adobe released patches for multiple maximum-severity flaws in ColdFusion and Campaign Classic. ColdFusion vulnerabilities include CVE-2026-48276, CVE-2026-48283 (unrestricted file upload leading to arbitrary code execution), CVE-2026-48277, CVE-2026-48281, CVE-2026-48316 (improper input validation leading to arbitrary code execution), CVE-2026-48282 (path traversal leading to arbitrary code execution), CVE-2026-48313 (path traversal leading to arbitrary file system read, CVSS 9.3), and CVE-2026-48315 (improper input validation leading to privilege escalation, CVSS 9.3). Addressed in ColdFusion 2023 Update 21 and ColdFusion 2025 Update 10. Adobe Campaign Classic CVE-2026-48286 (incorrect authorization leading to arbitrary code execution, CVSS 10.0) affects ACC v7: 7.4.3 build 9396 and earlier for Windows and Linux. Patched in ACC v7: 7.4.3 build 9397. Only impacts on-premise Adobe Campaign instances, including fully on-premise deployments and on-premise components in hybrid deployments. Adobe-hosted instances already updated. No exploits in the wild for any issues. Adobe is moving from monthly to twice-monthly security bulletins (second and fourth Tuesday of each month) starting July 14, 2026, due to accelerated vulnerability discovery using AI models. The window between public vulnerability disclosure and active exploitation is compressing from days to hours.

Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands

Two flaws in Cursor AI code editor (DuneSlide, CVE-2026-50548 and CVE-2026-50549, both CVSS 9.8 or 9.3 CVSS 4.0) allow a single prompt to break out of the safety sandbox and run arbitrary commands on a developer's computer with no click or approval. Both are patched in Cursor 3.0 (released April 2, 2026); every version before 3.0 is affected. More than half the Fortune 500 use Cursor. CVE-2026-50548 abuses the working_directory parameter on run_terminal_cmd to point at system files instead of the project, overwriting the sandbox helper. CVE-2026-50549 abuses symlink resolution by forcing the safety check to fail, allowing writes outside the project. Once the sandbox is neutralized, the next command runs as the user. The attack vector is prompt injection via connected services (Model Context Protocol) or web search results, making it zero-click. No sign of active exploitation. Cato reported February 19; Cursor rejected February 23 (MCP servers outside threat model); Cato escalated February 26; Cursor reopened, triaged, and patched in 3.0. CVE IDs assigned June 5.

General Security News

And the Winner in Dominant Malware Delivery? ClickFix

ReliaQuest analyzed threat activity from March 1 to May 31 and found ClickFix dominated initial access and defense-evasion categories. ClickFix tricks users into copying and pasting malicious commands into Windows Terminal or other system dialogs by presenting fake error messages or CAPTCHA requests. The approach bypasses file scanning and email-based defenses. Variants include CrashFix (continually crashes browsers and presents malicious commands as remedy) and SEO-poisoned AI models. ClickFix expanded to macOS for the first time, with clear examples featuring Atomic macOS Stealer (AMOS). Threat actors switched from pirated software lures to applescript:// links that automatically open Script Editor and run attacker commands, bypassing the macOS 26.4 Terminal paste warning. ClickFix drove nearly 28% of defense-evasion activity through command and file obfuscation. One ClickFix loader uses AI-generated obfuscation with thousands of variable assignments designed to look like routine scripting, helping attackers produce new variants faster. ClickFix activity shifted from compromised websites to emailed links. Malvertising campaigns via Google Ads masqueraded as developer tools.

19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges

Peter Stokes, 19, a dual U.S. and Estonian citizen, was extradited from Finland to face U.S. charges of conspiracy, computer intrusion, and fraud. Finnish police arrested him in April on an Interpol Red Notice before extradition in late June. Court records identify Stokes by the online handle "Bouquet" and describe at least four intrusions starting when he was 16. In May 2025, prosecutors say he and others broke into a luxury jewelry retailer, copied data, and demanded about $8 million in cryptocurrency. The retailer refused, evicted the intruders, and spent at least $2 million on cleanup. Finnish officers seized two 2TB hard drives when they stopped Stokes at Helsinki airport trying to board a flight to Japan. Scattered Spider (also tracked as Octo Tempest, UNC3944, and 0ktapus) is a loose, mostly English-speaking group of young people spread across the U.S., U.K., and Europe. Main tactic is social engineering: phone a company's IT help desk, pretend to be a locked-out worker, and talk staff into resetting passwords or approving logins. Best known for 2023 MGM Resorts and Caesars Entertainment attacks. Assistant Attorney General A. Tysen Duva said the group has been involved in over 100 network intrusions resulting in more than $100 million in ransom payments.

Microsoft Accelerates Post-Quantum Cryptography Shift to 2029

Microsoft is accelerating its quantum safe security roadmap, stating technology advances in quantum computing are making it essential to replace existing encryption standards sooner than previously expected. The Microsoft Quantum Safe Program (QSP) timeline now targets transitioning critical products and services to post-quantum cryptography (PQC) by 2029. Focus areas include upgrading network cryptography by adopting TLS 1.3, building crypto-agility for stored data, and transitioning to PQC algorithms to secure trust chains (code signing, certificate issuance, key protection, update pipelines). Crypto-agility requires removing hard-coded algorithm assumptions, persisting adequate information to reconstruct cryptographic context, and building systems where algorithm upgrades become routine engineering tasks. U.S. President Donald Trump signed an executive order setting hard deadlines for federal agencies to move high-value assets and high-impact systems to PQC. Google announced a new Chrome program to ensure HTTPS certificates are quantum secure and publicly committed to migrating its own infrastructure to be quantum secure by 2029. Cloudflare has similar plans. The threat is compounded by "harvest now, decrypt later," where adversaries collect encrypted data now to decode it later once a large-scale quantum machine becomes operational.

Trends & Context

Three themes dominate today's threat landscape: AI-driven attacks are moving from theoretical to operational, credential harvesting campaigns are feeding ransomware operations at scale, and phishing social engineering continues to evolve faster than defenses. The AI agent ransomware attack and browser-only ransomware demonstrate that LLMs are now capable of designing and executing novel attack chains without human intervention. The FortiBleed-to-ransomware pipeline shows credential theft operations are no longer standalone attacks but the first stage of extortion campaigns. ClickFix and platform-aware phishing prove that social engineering remains the most effective initial access vector, and attackers are adapting faster than security awareness training can keep pace.