CVE-2025-5777, CVE-2026-13768, CVE-2026-14164, CVE-2026-14258, CVE-2026-38057, CVE-2026-38059, CVE-2026-50521, CVE-2026-50548, CVE-2026-50549, CVE-2026-52911, CVE-2026-52944, CVE-2026-53046, CVE-2026-54477, CVE-2026-55726
Domains:
maccyapp[.]com, avenger-sync[.]live, maccy[.]app
IP Addresses:
4.5.2.2, 4.5.2.1
Get tomorrow's brief in your inbox
Today: Anubis ransomware exploits Citrix Bleed 2 with CISA-mandated July 11 deadline. FortiBleed credential harvesting fuels Inc and Lynx ransomware deployments across 12 confirmed victims. SharePoint on-prem RCE added to KEV despite Microsoft rating it "less likely" to exploit.
Citrix Bleed 2 Exploited in Anubis Ransomware Campaigns (CVE-2025-5777)
Arctic Wolf observed Anubis ransomware affiliates actively exploiting CVE-2025-5777, a critical authentication bypass in Citrix NetScaler ADC and Gateway appliances configured as Gateway or AAA virtual servers. The vulnerability carries a CVSS score of 9.3, EPSS score of 0.999 (100th percentile), and appears on CISA's Known Exploited Vulnerabilities catalog with a mandatory remediation deadline of July 11, 2025. Attackers combine the exploit with compromised VPN credentials obtained through initial access brokers, credential stuffing, or information stealers. Post-exploitation tradecraft includes deployment of legitimate RMM tools (ScreenConnect, Zoho Assist, MeshAgent, Remotely, UltraVNC, Total Software Deployment) for persistent access, PsExec for lateral movement, and Cloudflare Tunnel for command and control. Data exfiltration occurs via S3 Browser, rclone, s5cmd, WinSCP, and PuTTY before ransomware deployment. Anubis claimed 91 total victims with 11 in June 2026 alone, targeting healthcare, business services, manufacturing, technology, and financial services sectors. The operation advertises an 80% affiliate profit split and includes a /WIPEMODE feature that reduces files to 0 KB regardless of ransom payment.
FortiBleed Feeds Ransomware Operations (Inc, Lynx)
SOCRadar confirmed the FortiBleed initial access broker operation is directly supplying compromised Fortinet environments to Inc Ransom and Lynx ransomware gangs. The campaign installed a Golang-based sniffer on approximately 12,000 FortiGate firewalls to harvest credentials from 430,000 targeted devices globally. An operational security lapse exposed internal tracking documents showing 409 admin-level compromises, 354 full attack chains (VPN compromise, domain controller access, domain admin privileges), and at least 12 confirmed ransomware deployments with hundreds of encrypted endpoints. Researchers observed a single operator logged into both Inc and Lynx ransom negotiation panels using infrastructure traceable to FortiBleed. The IAB group consists of approximately 20 individuals and is actively exploiting a possible Nextcloud zero-day vulnerability in addition to the FortiGate credential harvesting.
SharePoint On-Premises RCE Added to CISA KEV
CISA added an on-premises SharePoint remote code execution vulnerability to the Known Exploited Vulnerabilities catalog despite Microsoft's original assessment rating exploitation as "less likely." The vulnerability is currently under active zero-day attack. Microsoft's patches have reportedly failed to fully remediate the issue in on-premises deployments.
Interpol Impersonation Campaign Targets Small Business
Bitdefender identified a ransomware campaign targeting small businesses across the US, Europe, Asia, and the Middle East using fake Interpol notices. Phishing emails claim the recipient organization is under investigation and direct victims to download a password-protected archive from Proton Drive, purportedly containing video evidence of criminal activity. The archive delivers a rudimentary custom ransomware payload disguised as a video file. Once executed, the malware encrypts local systems and instructs victims to contact attackers via the Tox peer-to-peer messaging platform for ransom negotiation. Unlike traditional ransomware operations, the campaign does not include a fixed ransom demand. Attackers tailor the amount after victims make contact, sizing the demand based on the organization's perceived ability to pay. Targeted sectors include pharmaceuticals, food, agriculture, technology, media, and legal services.
AI Agent Conducts End-to-End Ransomware Attack
Researchers documented what they characterize as the first fully autonomous AI-driven ransomware attack, in which an AI agent executed the complete attack chain from initial access through ransomware deployment without human intervention. The development represents a significant shift in threat actor capabilities, allowing less technically skilled operators to conduct sophisticated attacks using AI-powered tooling.
Google Disrupts NetNut Residential Proxy Network
Google, in coordination with the FBI and Lumen, disabled Google accounts and services used by the NetNut (Popa) residential proxy network for malware command and control. Google Threat Intelligence Group estimates the NetNut network controlled at least 2 million devices globally, populated through distribution of SDKs embedded in smart TVs, streaming boxes, and large-scale botnets such as Badbox 2.0. The disruption disabled millions of devices in the proxy pool. NetNut operates a whitelabel reseller program, meaning many residential proxy brands are fronts for the NetNut botnet. Google Play Protect now automatically warns users and disables applications incorporating NetNut SDKs. Residential proxy networks allow attackers to route malicious traffic through hijacked home IP addresses, masking their activity behind legitimate ISP allocations. Device owners are unaware their IP addresses are being used for unauthorized activities, creating liability and security risks.
SIEM Data Volume Becomes Liability
Vensure Employer Solutions reduced SIEM ingestion costs by 83% and improved detection capabilities by filtering high-volume, low-value telemetry before ingestion. The company's SIEM costs nearly tripled over two years as acquisitions and infrastructure growth generated unsustainable log volumes. Using machine learning and large language models in the security data pipeline, Vensure automated filtering of firewall connection logs and other routine events while preserving threat, intrusion, and authentication alerts. The approach saved approximately $250,000 annually while improving analyst efficiency by removing noise that obscured genuine security events. Side-by-side validation using native firewall metrics, historical data, and simulated attack traffic confirmed that filtered logs did not result in detection gaps.
Cursor AI IDE Sandbox Escape (CVE-2026-50548, CVE-2026-50549)
Cato Networks disclosed two critical vulnerabilities (CVSS 9.8) in the Cursor AI code editor allowing remote code execution outside the IDE's sandbox. The flaws, collectively named DuneSlide, abuse automatic terminal command execution that does not prompt for user approval. CVE-2026-50548 exploits the sandbox's path validation logic by injecting a prompt that sets the working directory to an attacker-supplied path outside the project scope, allowing overwrite of the cursorsandbox executable. CVE-2026-50549 uses symbolic links to bypass out-of-bounds write protections, exploiting a path canonicalization flaw that causes Cursor to use the symlink path rather than the resolved target path. Both vulnerabilities are triggered when a victim prompts the IDE to ingest attacker-controlled content. Patches were included in Cursor 3.0 (released April 2, 2026).
macOS PamStealer Uses PAM Validation
Jamf Threat Labs identified PamStealer, a macOS information stealer distributed as a compiled AppleScript impersonating Maccy, a legitimate clipboard manager. The malware is delivered via a lookalike domain (maccyapp[.]com) and uses a two-stage infection: an AppleScript dropper that fingerprints the host and downloads a Rust-based payload. The stealer harvests data from web browsers, cryptocurrency wallets, iCloud Keychain, and clipboard content. It prompts the victim for their system password and validates it using the macOS Pluggable Authentication Modules (PAM) API, looping until the correct password is entered. The malware establishes persistence, exfiltrates encrypted data to avenger-sync[.]live, and displays a fake Gatekeeper error message claiming the app is damaged. The AppleScript dropper includes anti-analysis checks, terminating execution on Intel Macs, in sandboxed environments, or on systems with time zones, locales, or keyboards associated with Eastern European countries.
FatFs Filesystem Vulnerabilities (Seven CVEs)
runZero disclosed seven unpatched vulnerabilities in the FatFs filesystem driver affecting industrial gear and smart devices globally. The bugs allow an attacker to use a crafted filesystem image to cause memory corruption and execute malicious code. Exploitation requires physical access to insert removable media with the corrupted image, but over-the-air exploitation is possible in scenarios where firmware update channels automatically mount the malicious image. FatFs is widely used in real-time operating system (RTOS) environments due to its Windows FAT compatibility and royalty-free, open-source licensing. All FatFs versions ever released are vulnerable. The project has no CVE history, security mailing list, or patch notification mechanism, meaning downstream vendors must independently discover, triage, and patch the vulnerabilities. runZero expects remediation to span years rather than days, with tens of millions of devices affected across dozens of codebases.
ST Engineering iDirect iQ-Series Terminals (CVE-2026-38059, CVE-2026-38057)
CISA published an advisory for two vulnerabilities in ST Engineering iDirect iQ-Series satellite terminals affecting Evolution iQ-Series, 3315-Series, and 9-Series models running firmware versions 4.5.2.1 and earlier. CVE-2026-38059 exposes /api/identity and /api/ REST API endpoints without authentication, allowing retrieval of sensitive device information including serial number, Device ID (DID), Terminal Private Key identifier (TPK), MAC address, and firmware version. The DID and TPK are used for satellite network authentication and could enable terminal impersonation and network reconnaissance. CVE-2026-38057 is a CSRF vulnerability in the /api/reboot endpoint that allows an attacker to host a malicious web page triggering an unauthenticated device reboot and satellite link loss when visited by an authenticated administrator. Repeated exploitation can sustain denial of service. ST Engineering iDirect fixed both issues in firmware version 4.5.2.2.
Gardyn IoT Hub (CVE-2026-13768, CVE-2026-55726, CVE-2026-54477)
CISA disclosed three vulnerabilities in the Gardyn IoT Hub affecting Home and Studio smart gardening devices. CVE-2026-13768 exposes a hardcoded privileged iothubowner key that allows a malicious user to invoke IoTHub Registry Manager functions, returning connection information for all Gardyn devices and enabling arbitrary command execution on connected devices. The key also provides a potential pivot point to other devices on the victim's network. CVE-2026-55726 makes the Azure Blob Storage container used for device logs publicly listable without authentication, exposing device log files. CVE-2026-54477 is the absence of standard security headers on the admin panel, enabling clickjacking and cross-site scripting attacks. Gardyn deployed infrastructure updates to fix the vulnerabilities and released firmware version master.627. Devices with internet connectivity will automatically download the update.
Additional Microsoft CVE Publications
Microsoft published advisories for multiple CVEs with minimal technical detail. Notable entries include CVE-2026-14164 (libarchive double-free in RAR5 decompression), CVE-2026-50521 (Edge RCE), CVE-2026-14258 (dhcpcd infinite loop), and several Linux kernel ksmbd vulnerabilities (CVE-2026-52911, CVE-2026-53046, CVE-2026-52944). EPSS scores range from 0.002 to 0.008, indicating low predicted exploitation likelihood at this time.
Claude Cowork Sandbox Root Escape
Armadin disclosed an attack chain affecting Claude Cowork on Windows that allows an attacker with local code execution to escalate privileges to root in the Cowork sandbox and bypass network egress restrictions. The exploit plants a malicious file in Claude Desktop's application directory, hijacking a trusted process to communicate with the underlying VM service. Two unvalidated parameters in the service interface enable command execution as root and circumvention of network filtering, allowing exfiltration to attacker-controlled infrastructure. Anthropic responded that it does not consider this a security issue because exploitation requires pre-existing local code execution on the host.
Apple Hide My Email Vulnerability
Researcher Tyler Murphy disclosed an unpatched vulnerability in Apple's Hide My Email service that allows users' real email addresses to be unmasked. Murphy reported the issue to Apple over a year ago and it remains unfixed. In limited testing with volunteers, 100% of Hide My Email addresses were exploitable. Exact technical details are being withheld to prevent further exploitation.
BeepRAT Distributed via Chinese Utility
Rubrik Zero Labs identified BeepRAT, a customized version of the open-source DCRat framework distributed via a Chinese phone number management utility. The malware is packaged as a .NET application (HFY.exe) alongside legitimate-appearing database libraries. Analysis revealed a multi-stage infection chain deploying the BeepRAT payload, which establishes persistence via scheduled tasks and resolves command-and-control infrastructure using DNS-over-HTTPS (DoH). The malware beacons host information and opens a persistent communication channel for file transfers, command prompt sessions, PowerShell execution, and process/storage enumeration.
Today's stories cluster around three themes. First, the commoditization of ransomware infrastructure through access broker operations (FortiBleed, Anubis) creates a separation between initial compromise and final payload deployment, complicating attribution and extending dwell time. Second, CISA's addition of SharePoint RCE to the KEV catalog despite Microsoft's "less likely" exploitation assessment demonstrates the widening gap between vendor severity ratings and real-world threat activity. Third, the disclosure of long-lived vulnerabilities in widely deployed open-source components (FatFs, libarchive) with no centralized patching mechanism highlights the ongoing challenge of securing the embedded and IoT device ecosystem.