← Carolina Clear Tech

Cyber Threat Brief

2026-07-07

Listen to this brief (37:39)

Download MP3
Show Notes

Show Notes - 2026-07-07

Stories Covered

CVEs Referenced

CVE-2024-12356, CVE-2024-42009, CVE-2025-2492, CVE-2025-3248, CVE-2025-49113, CVE-2026-10536, CVE-2026-11405, CVE-2026-12480, CVE-2026-14647, CVE-2026-1731, CVE-2026-20896, CVE-2026-40138, CVE-2026-40139, CVE-2026-40140, CVE-2026-40141, CVE-2026-43284, CVE-2026-43500, CVE-2026-46242, CVE-2026-46316, CVE-2026-46817, CVE-2026-53359, CVE-2026-54886, CVE-2026-54891, CVE-2026-55952, CVE-2026-8037, CVE-2026-8286, CVE-2026-8451, CVE-2026-8458, CVE-2026-8924, CVE-2026-8926, CVE-2026-8932, CVE-2026-9080, CVE-2026-9545

Indicators of Compromise

Hashes: c2ab9adaba93ff094b8f3fc37d906014d870582039d276b7bd03e6fd583d8a15

IP Addresses: 127.0.0.0, 159.26.98.241, 223.26.63.40, 204.194.48.250, 194.233.92.26, 217.15.160.247, 217.15.164.147, 95.182.100.231

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cybersecurity Brief

July 7, 2026

Today: Oracle E-Business Suite faces active exploitation via CVE-2026-46817 affecting 950 instances worldwide. JadePuffer demonstrates the first fully autonomous LLM-driven ransomware attack. BeyondTrust patches critical auth bypass flaws in remote access products following a history of exploitation.

Critical Alerts

Oracle E-Business Suite Remote Code Execution (CVE-2026-46817)

Oracle E-Business Suite is under active exploitation through CVE-2026-46817, a critical remote code execution flaw affecting approximately 950 internet-exposed instances globally. Successful exploitation allows attackers to gain control over enterprise resource planning systems without authentication. The vulnerability has EPSS score of 0.007 (48th percentile).

Linux Kernel KVM Guest-to-Host Escape (CVE-2026-53359)

A 16-year-old use-after-free vulnerability in Linux KVM hypervisor allows guest VMs to escape to the host on Intel and AMD x86 systems. Dubbed Januscape, the flaw affects the shadow MMU code and has been present since Linux kernel 2.6.36 (August 2010). A public proof-of-concept triggers host panic. The researcher claims a separate unreleased exploit achieves full host code execution. Any environment hosting untrusted guests with nested virtualization enabled is vulnerable. An attacker who rents a cloud instance can panic the host and take down all tenant VMs on the same physical machine. EPSS score is 0.002 (7th percentile).

Citrix NetScaler Memory Disclosure Under Active Exploitation (CVE-2026-8451)

Citrix patched CVE-2026-8451, a NetScaler ADC and NetScaler Gateway memory disclosure vulnerability affecting SAML Identity Provider configurations. Active exploitation began less than 24 hours after disclosure, with attacks leaking session tokens from vulnerable appliances. EPSS score is 0.005 (39th percentile).

Progress Kemp LoadMaster OS Command Injection (CVE-2026-8037)

Progress addressed CVE-2026-8037, a critical OS command injection flaw in Kemp LoadMaster load balancers with CVSS 9.6. Exploitation attempts started June 29 and allow unauthenticated remote code execution. EPSS score is 0.296 (98th percentile).

Linux Bad Epoll Privilege Escalation (CVE-2026-46242)

Linux kernel maintainers patched CVE-2026-46242, a Bad Epoll privilege escalation flaw affecting Linux servers, desktops, and Android devices. The race-condition use-after-free vulnerability allows unprivileged local users to gain root access. A public exploit demonstrates reliable exploitation. EPSS score is 0.001 (3rd percentile).

Langflow Unauthenticated RCE (CVE-2025-3248)

CVE-2025-3248, an unauthenticated remote code execution vulnerability in Langflow (an open source AI application builder), is confirmed exploited in the JadePuffer autonomous ransomware campaign. The flaw is on the CISA KEV catalog with due date 2025-05-26 and EPSS score of 1.000 (100th percentile).

Ransomware & Extortion

JadePuffer: First Fully Autonomous LLM-Driven Ransomware

Sysdig documented the first end-to-end ransomware operation executed autonomously by a large language model without human operator intervention. The threat actor, tracked as JadePuffer, exploited CVE-2025-3248 in an internet-facing Langflow deployment, then pivoted to a production database server running MySQL and Alibaba Nacos. The AI agent enumerated database contents, exfiltrated selected data, deleted the database, and left an extortion note demanding payment. The attack involved over 600 distinct purposeful payloads executed in rapid succession. JadePuffer demonstrated adaptive behavior, re-attempting failed steps with refined parameters and fixing a failed login in 31 seconds. The payloads were self-narrating, containing natural language reasoning and detailed annotations typical of LLM-generated code. The AI agent accessed API keys for OpenAI, Anthropic, DeepSeek, and Gemini during the operation. Evidence indicates a human still set up infrastructure (C2 server, staging server) and provisioned root credentials for the MySQL server from a prior compromise, but the operational execution was autonomous. JadePuffer is financially motivated with no overlaps to established ransomware groups or nation states.

Ransomware Incidents This Week

River Bank & Trust, a US financial institution, experienced a ransomware incident after an unauthorized actor accessed the network of parent company River Financial Corporation on June 16. Ransomware was found on portions of the server environment. The bank is assessing whether personal data was accessed or exfiltrated.

Indra Group, a Spanish defense and aerospace contractor and NATO cyber coalition member, confirmed a ransomware attack affecting one subsidiary. The Gentlemen ransomware gang threatened to leak allegedly stolen data. Indra stated the incident was contained and service continuity was maintained. Check Point Threat Emulation and Harmony Endpoint provide protection.

Nidec, a Japanese electric motor and industrial manufacturer, disclosed a ransomware attack affecting its Taiwanese subsidiary Nidec Chaun Choung Technology. BlackField group claimed responsibility and alleged theft of more than two terabytes of corporate data including employee, financial, procurement, manufacturing, legal, and IT records.

Aflac Japan Data Breach

US insurance firm Aflac disclosed a data breach affecting its Japan operations. Attackers accessed the policyholder portal between June 15 and June 25, exposing personal and financial data of nearly 4.4 million customers including policyholder information and premium payment account details.

Business & Infrastructure Threats

BeyondTrust Remote Support and PRA Critical Auth Bypass Flaws (CVE-2026-40138, CVE-2026-40139)

BeyondTrust released updates addressing two critical authentication bypass vulnerabilities in Remote Support (RS) and Privileged Remote Access (PRA) products. CVE-2026-40138 (CVSS 9.2) affects both RS and PRA, stemming from improper validation of authentication data that allows network-positioned attackers to bypass access controls and gain unauthorized access including elevated privileges. CVE-2026-40139 (CVSS 9.2) affects RS only, with improper processing of authentication requests allowing unauthenticated remote attackers to bypass access controls. Both require specific authentication configurations to be exploited. BeyondTrust identified the flaws internally using AI models including Anthropic Claude Opus 4.8. While no active exploitation is mentioned, BeyondTrust products have a history of exploitation: CVE-2024-12356 (CISA KEV due 2024-12-27, EPSS 0.880) and CVE-2026-1731 (CISA KEV ransomware-linked due 2026-02-16, EPSS 0.861) were both exploited in the wild to deploy web shells and backdoors.

Gitea Docker Authentication Bypass Under Probing (CVE-2026-20896)

Threat actors are probing CVE-2026-20896 (CVSS 9.8), a critical authentication bypass in Gitea Docker images. The flaw stems from Gitea trusting the X-WEBAUTH-USER header from any source IP address. The official Docker image hard-codes "REVERSE_PROXY_TRUSTED_PROXIES = *" in the app.ini template, trusting every source IP instead of the documented safe value of "127.0.0.0/8,::1/128". When reverse proxy authentication is enabled, any process that can reach the Gitea container's HTTP port directly can impersonate any user by sending an X-WEBAUTH-USER header. Admin accounts are obvious targets. Sysdig detected the first exploitation attempt 13 days after public disclosure, originating from ProtonVPN IP 159.26.98.241. Approximately 6,200 internet-facing Gitea instances exist.

NetNut/Popa Residential Proxy Botnet Disrupted

Google, in collaboration with the FBI, Lumen, and partners, took action against the NetNut residential proxy network (also known as Popa). The network consists of at least 2 million devices globally, populated by distributing SDKs for smart TVs and streaming boxes. NetNut's botnet plugin components were identified in large-scale botnets including BADBOX 2.0. The devices are pre-installed with malware before purchase or users unknowingly download applications containing hidden proxy code. Google disabled Google accounts and services used for C2, updated Google Play Protect, and disabled applications incorporating NetNut SDKs. Attackers leverage these devices to route traffic and mask malicious activity.

Navigate360 Anonymous Tip System Breach - Three Months Without Notification

On March 18, 2026, a hacktivist disclosed 8.3 million tips from systems operated by Navigate360 (P3 Campus, P3 Global Intel) serving Crime Stoppers, Safe2SayPA, Safe2Tell, and SandyHookPromise. The tips were advertised as anonymous but were often not. Navigate360, Safe2SayPA, Safe2Tell, and SandyHookPromise have failed to notify affected individuals three months after disclosure. The breach exposes highly sensitive information about students and youth including suicide threats, bullying, drugs on campus, sexual abuse, violence, and self-harm reports. On April 24, Senators Hassan and Banks requested specific answers from Navigate360 with a May 8 deadline, but no responses have been made public. Doug Levin of K12 Security Information eXchange calls it "the single largest breach of highly sensitive information about students the U.S. has ever experienced" and notes there are no third-party security audits, federal investigations, or state attorney general actions disclosed.

China-Nexus Threat Actors Target Universities via Roundcube Exploits

A suspected China-aligned threat cluster tracked as UNK_MassTraction is exploiting Roundcube webmail software at physics and engineering departments of U.S. and Canadian universities. The campaign targets administrators and professors in departments with national security ties or studying astrophysics and particle physics. Attackers exploit CVE-2024-42009 (CVSS 9.3, CISA KEV due 2025-06-30, EPSS 0.829) and CVE-2025-49113 (CVSS 9.9, CISA KEV due 2026-03-13, EPSS 0.895). The XSS exploit (CVE-2024-42009) executes when recipients open emails in Roundcube, delivering the IceCube payload which steals credentials, 2FA tokens, and cookies. IceCube then leverages the session's CSRF token to exploit CVE-2025-49113 for RCE, deploying either VShell or the SquareShell web shell. The campaign uses both compromised senders and domains vulnerable to spoofing due to lax DMARC policies. Reconnaissance indicates deliberate targeting of departments running vulnerable Roundcube versions. Infrastructure analysis shows use of SNOWLIGHT ELF loader and VShell tools linked to UNC5174, suggesting shared tooling among China-nexus clusters.

China-Nexus Hackers Target Indian Taxpayers with DcRAT

A suspected China-nexus threat cluster is targeting Indian taxpayers, tax professionals, and corporate finance teams with spear-phishing emails impersonating the Income Tax Department of India. Tracked as Operation DragonReturn by Seqrite Labs, the campaign was first observed May 18, 2026, coinciding with annual tax filing season. PDF attachments contain malicious links (govtop.one/incometax) leading to fake tax filing utilities that sideload malicious DLLs and deploy DcRAT. The malware establishes persistence via Windows service MixedSvc, disables AMSI scanning, and exfiltrates screenshots and data. Infrastructure analysis reveals ChinaNet IP addresses and a Chinese-language web panel on the DcRAT C2 server (223.26.63.40). The campaign shows overlaps with Silver Fox, a Chinese cybercrime group linked to ValleyRAT tax-themed phishing. The precision of lure documents, use of real legal citations, bilingual content, and active payload rotation indicate a deliberate, resourced operation focused on the Indian taxpayer ecosystem for financial gain or sensitive data theft.

North Korean PolinRider Supply Chain Campaign Targets Developers

North Korean hackers are conducting a broad supply chain campaign dubbed PolinRider, targeting open source developers across NPM, Packagist, Go modules, and Chrome extensions. Active since December 2025, the campaign has produced 162 malicious release artifacts across 108 unique packages. Attackers compromise maintainer accounts to inject JavaScript loaders into legitimate repositories, using Git history rewriting to make changes appear older. The loaders connect to blockchain and public RPC infrastructure to retrieve encrypted payloads delivering DEV#POPPER RAT and OmniStealer information stealer. The campaign is associated with Contagious Interview operation (also seen in DeceptiveDevelopment, Operation Dream Job, and ClickFake Interview). Recent expansion to Packagist targeted the sevenspan namespace, with malicious loaders hidden in configuration files that survived cleanup. Socket warns that teams installing affected packages should treat the environment as compromised, as PolinRider targets developer environments and may expose package registry, source code, cloud, and CI/CD credentials.

Veil#Drop Framework Delivers PureLog Stealer via Blogspot

Securonix uncovered Veil#Drop, a sophisticated multi-stage malware delivery framework using compromised websites and Blogspot-hosted payloads to deploy PureLog Stealer. The infection chain begins with JavaScript files posing as documents, launching PowerShell code that retrieves additional payloads from attacker-controlled Blogspot pages. The second-stage loader contains XOR-encoded .NET assemblies that are decrypted at runtime. The framework uses several fallback mechanisms and abuses trusted Microsoft-signed binaries for code execution and defense evasion. PureLog Stealer is a .NET-based infostealer targeting credentials, cookies, autofill data, session tokens, browsing histories, and cryptocurrency wallets from Chrome, Edge, Firefox, Brave, Opera, and Chromium-based browsers. It also harvests data from messaging apps, email clients, remote access software, FTP clients, cloud storage, developer tools, and password managers. In enterprise environments, stolen credentials can be leveraged for ransomware deployment, data theft, business email compromise, or long-term espionage.

ChocoPoC RAT Targets Vulnerability Researchers via Fake GitHub PoCs

Security researchers searching for Python-based proof-of-concept repositories on GitHub claiming to exploit new CVEs are being tricked into executing ChocoPoC RAT. The PoC code appears clean but pulls a malicious dependency named "skytext" containing the actual malware. ChocoPoC is a full-featured trojan harvesting passwords, cookies, autofill data, and history from Chrome, Brave, Edge, and Firefox. It also captures text files, notes, local databases, shell history, network settings, running processes, and supports arbitrary shell command or Python code execution.

IOCs & Detection

UAT-7810 ORB Network Infrastructure

Cisco Talos is tracking UAT-7810, a China-nexus APT actor maintaining LapDogs Operational Relay Box (ORB) networks. UAT-7810 continues developing custom malware including SHORTLEASH, with a newer version LONGLEASH now in development. Two new malware families have been discovered: DOGLEASH (C-based backdoor executing arbitrary shellcode on compromised Linux devices) and JARLEASH (JAVA-based backdoor for file management, FTP, SFTP, and Netcat). UAT-7810 exploits n-day vulnerabilities in unpatched Ruckus wireless routers and was observed exploiting ASUS AiCloud Routers via CVE-2025-2492 (EPSS 0.010).

C2 Infrastructure (block these IPs): - 194.233.92.26 - 217.15.160.247 - 217.15.164.147 - 95.182.100.231 (Hong Kong)

TLS Fingerprint (ports 99): - c2ab9adaba93ff094b8f3fc37d906014d870582039d276b7bd03e6fd583d8a15 - Subject DN: C=exploit, ST=exploit, L=exploit, O=exploit, OU=exploit, CN=exploit

Windows / AD Security

Cavern Manticore: Iran-Linked Modular C2 Framework Targets Israel

Check Point Research is tracking Cavern Manticore, an Iran-nexus APT group linked to Iran's Ministry of Intelligence and Security (MOIS) targeting Israeli organizations with focus on IT providers and government sectors. The threat actor shares tactical overlaps with MuddyWater and Lyceum (OilRig subgroup). Cavern Manticore deploys a modular .NET-based C2 framework called Cavern using three different compilation formats: .NET Framework (IL-only), Mixed-Mode C++/CLI (IL + Native), and .NET Native AOT (Native-only). The compilation format itself acts as the anti-analysis layer, forcing reverse engineers into multiple toolsets. The attack chain begins with abuse of SysAid's software update feature to deploy a WinDirStat DLL sideloading package. The trojanized uxtheme.dll contains the Cavern Agent, which loads a native communication module (n-HTCommp.dll) to contact C2 server hospitalinstallation.com and fetch post-exploitation modules. Five modules provide file operations (mhm.dll), SQL database enumeration (db.dll), Active Directory reconnaissance (ode.dll), network reconnaissance and SMB brute-force (n-ten.dll), and SOCKS5 proxy/WebSocket tunneling (n-sws.dll). Cavern Manticore attacks involve moving from an initial compromised IT provider to a second-hop provider before reaching the intended target, weaponizing trusted relationships in the software supply chain. The threat actor abuses Remote Monitoring and Management (RMM) solutions deployed in targeted organizations.

General Security News

Browser-Native Ransomware Technique Using Chrome File System Access API

Check Point Research demonstrated a browser-native ransomware technique generated by a large language model that abuses Chrome's File System Access API. A fake image-enhancement page convinces users to grant folder access, then reads, exfiltrates, and encrypts photos inside the browser on Android and Windows. This technique works without installing any software and operates entirely within the browser sandbox.

AI Coding Agents Fail Shell Command Injection Tests

Researchers examined shell command injection weaknesses in open source AI coding agents and found that 10 out of 11 popular tools failed to block obfuscated destructive commands. Simple rewrites bypassed filters and enabled destructive actions including file deletion. Only the Continue agent properly parsed commands.

LLM Phantom Squatting Exploited for Phishing

Researchers warn that attackers are exploiting LLM hallucinated domains by registering AI-generated domains to hijack traffic and deliver phishing. Researchers recorded 250,000 hallucinated domains and subsequent registrations including an AI-built phishing kit called Montana Empire using a postal-service domain for credential theft.

WhatsApp Usernames Raise Impersonation Concerns

WhatsApp officially announced global reservation of usernames to protect user privacy. The optional feature allows users to connect through usernames instead of phone numbers and will be generally available later this year. The rollout has drawn scrutiny in India over concerns about impersonation of public authorities, financial institutions, government departments, and prominent figures. While Meta reserves usernames for public figures, government entities, and variations, it is unclear how the company decides which lookalike usernames get reserved.

19-Year-Old Scattered Spider Suspect Extradited to U.S.

Peter Stokes (19, dual U.S./Estonian citizenship) was extradited from Finland to the U.S. to face criminal charges for involvement in Scattered Spider hacking operations.

Tenda Router Hidden Admin Backdoor (CVE-2026-11405)

CERT/CC warned that several Tenda firmware versions contain an undocumented authentication backdoor enabling administrative access to web management interfaces without valid credentials. The backdoor in the /bin/httpd login() function bypasses MD5-based password verification by calling GetValue("sys.rzadmin.password") and performing plaintext comparison. The associated "rzadmin" username is not validated, so any username succeeds when paired with the backdoor password. The vulnerability remains unpatched and affects multiple firmware versions including US_FH1201V1.0BR_V1.2.0.14(408)_EN_TD, US_W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE, US_AC10V1.0re_V15.03.06.46_multi_TDE01, US_AC5V1.0RTL_V15.03.06.48_multi_TDE01, and US_AC6V2.0RTL_V15.03.06.51_multi_T.

Alberta Centurion Project Sued Over Alleged Data Breach

A retired lawyer filed a class-action lawsuit against Alberta, its Chief Electoral Officer, and two organizations supporting secession for alleged data breach affecting 2.9 million residents. The lawsuit alleges the Centurion Project unlawfully obtained and distributed information from Alberta's list of electors. The suit targets not only organizations accused of accessing and distributing sensitive information but also the provincial government and Elections Alberta's Chief Electoral Officer for failing to implement safeguards, auditing requirements, and enforcement procedures. Domestic violence victims, healthcare professionals, and elected officials are noted as especially vulnerable.

Patch Priority

Vulnerability Disclosures

Linux Kernel CVEs

CVE-2026-53359 (Januscape): 16-year-old KVM hypervisor use-after-free enabling guest-to-host escape on Intel and AMD x86. Public PoC triggers host panic. Withheld exploit achieves full host code execution. EPSS 0.002 (7th percentile). Fixed June 19, 2026.

CVE-2026-46242 (Bad Epoll): Race-condition use-after-free privilege escalation allowing unprivileged local users to gain root on Linux servers, desktops, and Android. Public exploit available. EPSS 0.001 (3rd percentile).

CVE-2026-43284, CVE-2026-43500 (Dirty Frag): Page-cache write vulnerability chain delivering deterministic root on most major distributions, extending Dirty Pipe and Copy Fail bug class. Disclosed May 2026. EPSS 0.932 and 0.928 (both 100th percentile).

CVE-2026-46316 (ITScape): First publicly demonstrated guest-to-host escape on KVM/arm64 exploiting race condition in virtual interrupt controller. Disclosed June 2026. EPSS 0.002 (8th percentile).

Roundcube CVEs

CVE-2024-42009 (CVSS 9.3): XSS flaw requiring only email to be opened in Roundcube client. CISA KEV due 2025-06-30. EPSS 0.829 (100th percentile). Exploited by UNK_MassTraction against universities.

CVE-2025-49113 (CVSS 9.9): Post-authenticated RCE in Roundcube. CISA KEV due 2026-03-13. EPSS 0.895 (100th percentile). Chained with CVE-2024-42009 to deploy VShell and SquareShell.

Microsoft Security Update Guide CVEs

CVE-2026-8932: Incomplete mTLS config matching in connection reuse. EPSS 0.001 (3rd percentile).

CVE-2026-8286: Wrong STARTTLS connection reuse. EPSS 0.002 (9th percentile).

CVE-2026-8926: Password leak with netrc and user in URL. EPSS 0.002 (9th percentile).

CVE-2026-55952: TLS 1.3 server DoS via malformed ClientHello pre-shared key extension. EPSS 0.005 (37th percentile).

CVE-2026-54891: Plaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in ssl. EPSS 0.002 (6th percentile).

CVE-2026-9545: Exposing HTTP/3 early data. EPSS 0.001 (3rd percentile).

CVE-2026-8458: Wrong reuse for different services. EPSS 0.002 (11th percentile).

CVE-2026-8924: Trailing dot domain super cookie. EPSS 0.002 (12th percentile).

CVE-2026-10536: HTTP/2 stream-dependency tree UAF. EPSS 0.002 (11th percentile).

CVE-2026-9080: UAF after pause in socket callback. EPSS 0.002 (11th percentile).

CVE-2026-54886: SSH SFTP server DoS via extended channel data infinite loop. EPSS 0.003 (27th percentile).

CVE-2026-12480: Arbitrary HDF5 File Read via Virtual Dataset Bypass in keras-team/keras. EPSS 0.001 (3rd percentile).

CVE-2026-14647: ONNX onnxruntime old.cc convPoolShapeInference_opset19 out-of-bounds. EPSS 0.003 (17th percentile).

BeyondTrust Additional Vulnerabilities

CVE-2026-40140 (CVSS 8.7): Pre-authentication DoS in network communication subsystem from insufficient validation of client input.

CVE-2026-40141 (CVSS 8.5): Insufficient validation of user input in web application component allowing authenticated attackers with limited privileges to access unintended resources beyond authorization scope.

Trends & Context

Three distinct themes emerge today. First, the JadePuffer autonomous LLM ransomware marks a fundamental shift in attack economics where operational expertise is replaced by AI agent capability at minimal cost. Second, active exploitation continues to compress dramatically, with Citrix NetScaler attacks beginning within 24 hours of disclosure and Gitea probing starting 13 days post-disclosure. Third, China-nexus APT activity shows deliberate supply chain targeting across multiple vectors: university research departments via Roundcube exploits, Indian tax professionals via fake government utilities, open source developers via compromised maintainer accounts, and Israeli IT providers via RMM tool abuse. The convergence of AI-driven attacks, compressed exploitation timelines, and sophisticated supply chain campaigns indicates defenders must prioritize patching velocity, supply chain verification, and behavioral detection over signature-based controls.