← Carolina Clear Tech

Cyber Threat Brief

2026-07-10

Listen to this brief (30:34)

Download MP3
Show Notes

Show Notes - 2026-07-10

Stories Covered

CVEs Referenced

CVE-2025-5777, CVE-2026-14480, CVE-2026-2399, CVE-2026-2400, CVE-2026-2401, CVE-2026-2403, CVE-2026-2404, CVE-2026-2405, CVE-2026-33825, CVE-2026-41091, CVE-2026-45498, CVE-2026-4832, CVE-2026-50656, CVE-2026-56288, CVE-2026-56289, CVE-2026-59818, CVE-2026-9181

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cybersecurity Brief - July 10, 2026

Today: CitrixBleed 2 (CVE-2025-5777) is being weaponized by Initial Access Brokers leading to Dragonforce ransomware, with CISA's deadline expiring tomorrow. Microsoft patched the RoguePlanet Defender zero-day but the fix introduces a disk exhaustion risk. GodDamn ransomware is leveraging a Microsoft-signed malicious driver to kill EDR.

Critical Alerts

CitrixBleed 2 Exploited by Initial Access Broker Leading to Dragonforce Ransomware (CVE-2025-5777)

Huntress documented a half-dozen intrusions across unrelated organizations following an identical seven-step attack chain: exploit CVE-2025-5777 on internet-facing Citrix NetScaler gateways, escalate privileges, create a fake "Citrix" admin account, deploy AnyDesk, and ultimately deploy Dragonforce ransomware. The attacks are mechanically identical across victims (same account names, same workstation names in printer mappings, same privilege escalation primitive), indicating a productized Initial Access Broker operation. Sophos tracks the same cluster as STAC3725. CISA added CVE-2025-5777 to the KEV catalog with a remediation deadline of July 11, 2026 (tomorrow). EPSS score is 0.999 (100th percentile).

Windows / AD Security

Microsoft Patches RoguePlanet Defender Zero-Day But Introduces Disk Exhaustion Risk (CVE-2026-50656)

Microsoft released an out-of-band patch for CVE-2026-50656, a privilege escalation vulnerability in the Microsoft Malware Protection Engine that allows escalation to SYSTEM via a race condition (CVSS 7.8). The vulnerability was disclosed June 9 by researcher Nightmare Eclipse with a public PoC and works on fully patched Windows 10/11 systems even with real-time protection disabled. The patch is delivered via Microsoft Malware Protection Engine version 1.1.26060.3008 and deploys automatically. However, the researcher reports the fix introduces a new issue: the defense-in-depth updates can cause Defender to write unlimited-size files via SpyNet's handling of Zone.Identifier ADS data, potentially exhausting all disk space. An attacker with a custom SMB server can trigger this by serving a malicious executable followed by a massive Zone.Identifier ADS file. EPSS score is 0.034 (87th percentile). No evidence of active exploitation, and CISA has not added it to KEV. RoguePlanet is the fourth Defender exploit from this researcher; three prior vulnerabilities (BlueHammer CVE-2026-33825, UnDefend CVE-2026-45498, RedSun CVE-2026-41091) were added to CISA KEV and exploited in the wild.

AI-Generated Active Directory Enumeration Tool Observed in the Wild

Huntress recovered a PowerShell script from a June 3 intrusion that is unmistakably AI-generated, titled "100% Working AD Information Gathering Script - FULLY FIXED." The script uses an over-engineered five-step cascading fallback to identify domain controllers (DNS, nltest, AD module, environment variables, hardcoded fallback) and massive repetitive try/catch blocks to dump AD users, computers, groups, OUs, and GPOs. The attack chain was otherwise conventional: RDP access via VPN with pre-compromised credentials, tool staging in C:\ProgramData, followed by the vibe-coded recon script, then s5cmd for S3 exfiltration and SharpShares for lateral enumeration. The script's structure (verbose comments, defensive redundancy, inconsistent coding style) indicates it was iteratively prompted into existence rather than written by hand. This represents a trend where mediocre threat actors can now generate bespoke, single-use scripts that evade signature-based detections built around known tools like BloodHound.

Conditional Access Bypass Campaigns Exploiting Device Code Phishing and ROPC (55 Orgs with MFA Bypassed)

Huntress documented two large-scale campaigns that bypassed MFA-enforced Conditional Access policies in Microsoft 365. The Railway.com campaign (344 organizations compromised) used device code phishing from legitimate Railway PaaS infrastructure (three Railway IPs accounted for 84% of attack traffic), generating OAuth device codes and embedding them in construction-themed phishing lures. The victim completes MFA, but the attacker harvests the 90-day OAuth token. The LSHIY campaign (78 accounts across 64 organizations) used Resource Owner Password Credentials (ROPC) flow to replay credentials directly to the /token endpoint via Azure CLI, bypassing MFA because most Conditional Access policies omit Azure resources by default. The critical finding: of the 78 compromised accounts in LSHIY, 55 had active Conditional Access policies requiring MFA. The policies were configured but ineffective because they did not block legacy authentication flows or Azure management endpoints.

Ransomware & Extortion

GodDamn Ransomware Leverages Microsoft-Signed Malicious Driver to Kill EDR

Symantec identified GodDamn ransomware, a rebrand of Beast (itself an enhanced version of Monster ransomware from March 2022), deploying the PoisonX kernel driver (g11.sys) to disable endpoint security. PoisonX is unusual because it is a malicious driver that was signed by Microsoft, allowing Windows to load it automatically. The attack chain observed in early June 2026 involved AnyDesk for remote access, a NirSoft credential harvester (targeting browsers, Windows Credential Manager, cached domain creds, VNC, email clients, Wi-Fi profiles, and live network traffic), a fake Symantec user-mode defense evasion tool (symantec.exe), and the PoisonX driver for bring-your-own-vulnerable-driver (BYOVD) attacks to kill AV/EDR processes. The threat actors used PsExec for lateral movement, deployed AnyDesk on each compromised host with auto-start persistence, and deployed GodDamn ransomware on June 3. Symantec tracks the developer as Hyadina. PoisonX is also used by The Gentlemen RaaS in their GentleKiller tool. Ransom notes instruct victims to contact via email or qTox.

GigaWiper Windows Backdoor Combines Disk Wiping, Fake Ransomware, and Spyware

Microsoft documented GigaWiper, a Go-based Windows backdoor that consolidates three destructive payloads: a raw disk wiper (overwrites physical drives and partition tables), fake ransomware derived from Crucio (encrypts files with .candy extension but never saves the key, making decryption impossible), and a multi-pass wiper reimplementing FlockWiper. GigaWiper also includes full backdoor capabilities: screenshots, screen recording, hidden VNC sessions, system enumeration, registry editing, and event log wiping. It persists via a scheduled task named "OneDrive Update" and uses RabbitMQ for tasking, Redis for results, and MinIO for exfiltration. Microsoft traces Crucio back to CyberAv3ngers, an Iran-nexus group linked to IRGC that compromised water and energy ICS in 2023. Binary Defense tracks the same samples as BLUERABBIT and ties them to a likely Iran-nexus group targeting Israeli organizations. Google's Threat Intelligence Group supports this attribution.

Mount Royal University Confirms Data Stolen in CMD Ransomware Attack

Mount Royal University (MRU) in Alberta, Canada confirmed a ransomware attack discovered June 17 that deleted two file storage systems and exfiltrated employee and student data from the "H drive" (individual file storage). The attack disrupted internal systems, online services, and internet access. CMD Organization ransomware group claimed responsibility on their Tor leak site, published screenshots, and demands $1.9 million in cryptocurrency. CMD claims to have stolen over 10 TB of data. MRU is offering 24 months of identity theft and credit monitoring to all current employees and those employed in the past five years. CMD has claimed 32 attacks but only four are confirmed; the group auctions stolen data. MRU did not disclose the initial access vector or patching status.

Ransomware Negotiator Sentenced to 70 Months for Colluding with BlackCat

Angelo Martino, 41, a ransomware negotiator at DigitalMint, was sentenced to 70 months in prison for conspiring with BlackCat/ALPHV ransomware operators to extort five victims between April and September 2023. Martino shared confidential information (victims' negotiating positions, insurance policy limits) with BlackCat affiliates in backchannel communications, maximizing ransom payments. The five victims paid ransoms totaling $75.3 million, including a nonprofit ($26.8M), a financial services company ($25.7M), and a hospitality company ($16.5M). Martino also conspired with Kevin Martin (another DigitalMint negotiator) and Ryan Goldberg (Sygnia incident response manager) to deploy BlackCat ransomware against five additional victims; one medical company paid $1.3M. Martin and Goldberg were each sentenced to 48 months in April 2026. Law enforcement seized $10M in assets from Martino, including digital currency, vehicles, a food truck, and a luxury fishing boat. Restitution hearing scheduled for September 17, 2026.

Business & Infrastructure Threats

Network of 200 GitHub Repositories Used for Malware Distribution (Operation Muck and Load)

Socket identified 222 lure repositories across 190 GitHub accounts delivering Windows malware via a malicious Go module posing as a DNS scanning tool. The module contains hidden PowerShell code (concealed with excessive horizontal whitespace) that fetches a resolver from public dead drops (Pastebin, Rlim, YouTube, Instagram, Telegram, Google Docs, GitCode) to deploy AsyncRAT, Quasar RAT, Remcos-style RAT, Vidar infostealer, XMRig cryptominers, and other spyware. The threat actor published over 1,200 versions of the package (700 malicious) since January 24, 2026, using GitHub Actions to generate timestamp commits surfaced as Go pseudo-versions. At least 14 unique confirmed malware files were identified across the repositories. The campaign overlaps with activity associated with the email address ischhfd83, which also used Muck-themed domains. This is a supply chain attack targeting developers who might clone or import these repositories.

12 Million Affected by Data Breach at Japanese Telco KDDI via Zero-Day

Japanese telecom KDDI confirmed a June 17 breach affecting 12.2 million email addresses and 7.6 million passwords across five ISPs (STNet, JCOM, Chubu Telecommunications, NIFTY, BIGLOBE). A zero-day vulnerability in software implemented in the email infrastructure was exploited. KDDI's automated translation indicates the zero-day was exploited at several ISPs since May, and the vendor is developing a patch. KDDI evicted the attackers immediately after discovery and reports no evidence of ongoing activity. Mandatory password resets are being completed for all affected accounts within the following days. KDDI and affected ISPs are transitioning to more secure communication technologies.

17 Malicious npm and PyPI Packages Typosquat Payment SDKs

Socket identified 17 malicious packages typosquatting Paysafe, Skrill, and Neteller SDKs to steal system information and developer secrets via an Ngrok endpoint. The malware skips machines with fewer than two CPU cores or hostnames/usernames containing sandbox analysis keywords (sandbox, analyzer, cuckoo, virus, malware, vmware, vbox). The threat actor used unique obfuscation keys for each version and package to prevent signature-based tracking, resulting in different hashes for each file. The packages targeted payment app SDKs, indicating financial motive or intent to monetize payment accounts.

AI Gateways Becoming High-Value Targets for Attackers

Darktrace investigated an incident where a threat actor compromised an EC2 server hosting an AI gateway connected to Amazon Bedrock services. The attacker used the access for cryptomining but could have accessed connected AI models, manipulated AI workflows, stolen API keys and IAM credentials, queried proprietary RAG knowledge bases, or pivoted deeper into the cloud environment. The attacker gained initial access via brute-force login attempts. AI gateways aggregate capabilities that traditionally existed in separate systems: centralized access to multiple AI providers, high-value API credentials, enterprise identity integration, and privileged IAM roles. Depending on permissions, an attacker with gateway access can exfiltrate sensitive prompts and model outputs, steal cloud credentials, generate financial impact through abuse of AI inference services, or establish cloud persistence.

Patch Priority

Vulnerability Disclosures

Schneider Electric PowerChute Serial Shutdown Multiple Vulnerabilities (6 CVEs)

CISA published an ICS advisory for Schneider Electric PowerChute Serial Shutdown versions 1.4 and earlier, disclosing six CVEs (CVE-2026-2399, CVE-2026-2400, CVE-2026-2401, CVE-2026-2403, CVE-2026-2404, CVE-2026-2405). The vulnerabilities allow attackers to overwrite critical files, forge or inject malicious log data, gain unauthorized account access, trigger denial-of-service conditions, truncate or alter logging information, reset user credentials, or expose sensitive information. Affected sectors: Communications, Critical Manufacturing, Energy, Healthcare, IT, Transportation. Remediation: Upgrade to PowerChute Serial Shutdown version 1.5 (available for Windows and Linux). EPSS scores range from 0.001 to 0.002 (1st to 16th percentile).

Schneider Electric Easergy MiCOM Px40 Series SNMP Hardcoded Credentials (CVE-2026-4832)

CISA disclosed a hardcoded credentials vulnerability (CVE-2026-4832) in Schneider Electric Easergy MiCOM Px40 Series protection relays. An unauthenticated attacker can interrogate the SNMP port to access sensitive device information. Affected products: Easergy MiCOM P14x, P24x, P341, P342, P343, P344, P345, P442, P443, P444, P445, P446, P543, P544, P545, P546, P643, P642, P645, P741, P742, P743, P746, P841, P849 (all versions prior to specified fixed versions). Affected sectors: Critical Manufacturing, Energy, Transportation. EPSS score: 0.003 (19th percentile).

OpenPLC v3 Authenticated Arbitrary File Write (CVE-2026-14480)

CISA disclosed an authenticated arbitrary file write vulnerability (CVE-2026-14480) in OpenPLC Runtime v3. The legacy web UI program-upload workflow stores an attacker-supplied filename directly into the database and later uses it as the destination path without validation. Because Python os.path.join() honors attacker-controlled absolute paths, an authenticated user can write arbitrary files anywhere writable by the webserver process. In the default build pipeline, all C++ source files within the OpenPLC runtime core directory are compiled into the executable, allowing an attacker to escalate the file write into arbitrary native code execution by writing a malicious .cpp file and triggering a program compilation. Affected sectors: Critical Manufacturing, Energy, Transportation, Water/Wastewater. OpenPLC v3 is end-of-life and will not receive patches.

Esri ArcGIS Server Unauthenticated File Access (CVE-2026-9181)

Horizon3.ai disclosed a critical vulnerability (CVE-2026-9181, CVSS 9.8/7.5) in Esri ArcGIS Server 12.0 and prior allowing unauthenticated remote attackers to access sensitive files via crafted path parameters to the ArcGIS Server REST Uploads resource. Insufficient validation of path parameters allows directory traversal outside the intended boundary. EPSS score: 0.007 (50th percentile).

Microsoft Azure etcd gRPC Client CRL Bypass (CVE-2026-59818)

Microsoft published CVE-2026-59818, a vulnerability in etcd where the gRPC client listener does not enforce --client-crl-file certificate revocation. EPSS score: 0.004 (29th percentile). No additional details provided in the MSRC advisory.

GNU patch Vulnerabilities (CVE-2026-56288, CVE-2026-56289)

Microsoft published two CVEs in GNU patch: CVE-2026-56288 (NULL pointer dereference) and CVE-2026-56289 (loop with unreachable exit condition). No EPSS scores or additional details provided in MSRC advisories.

General Security News

npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk

GitHub announced npm 12 with install scripts disabled by default. The following behaviors that previously ran automatically are now opt-in: allowScripts defaults to off (dependency lifecycle scripts preinstall/install/postinstall and implicit node-gyp builds no longer run unless explicitly allowed); --allow-git defaults to none (Git dependencies are no longer resolved unless explicitly allowed); --allow-remote defaults to none (dependencies from remote URLs like HTTPS tarballs are no longer resolved unless explicitly allowed). Developers must run npm approve-scripts --allow-scripts-pending to review and approve trusted scripts, then commit the allowlist in package.json. Additionally, npm granular access tokens (GATs) will no longer bypass 2FA for sensitive operations (effective August 2026) and will lose direct publishing capability (effective January 2027). GitHub recommends migrating to trusted publishing (OIDC) or staged publishing with human approval.

INTERPOL Operation First Light 2026 Arrests 5,811 in Global Fraud Bust

A global anti-fraud operation involving 97 countries resulted in the arrest of 5,811 individuals and the interception of $293 million in illicit assets between January 15 and April 30, 2026. The operation targeted social engineering scams and associated money laundering. Over 142,000 victims were identified, and more than 23,000 cases were solved. In Eswatini, authorities arrested 82 people and dismantled a criminal network running illegal online gambling, money laundering, and impersonation scams. Thai police uncovered a money laundering scheme converting romance scam proceeds into cryptocurrencies using cross-chain token swaps.

Cisco Talos Documents UAT-7810 ORB Network Expansion with New Malware

Cisco Talos identified China-nexus threat actor UAT-7810 expanding their Operational Relay Box (ORB) networks with upgraded "LONGLEASH" and "DOGLEASH" backdoors. The group exploits known vulnerabilities in unpatched Ruckus and ASUS routers to deploy custom malware and build covert proxy networks that provide infrastructure for other APT groups to launch attacks against high-value targets. ORB networks allow secondary threat actors to mask their origins and route malicious traffic through compromised edge devices, bypassing traditional perimeter defenses.

HTML Phishing Attachment Uses Comment Stuffing to Evade AI-Based Detection

SANS ISC documented a phishing message with a 2.6 MB HTML attachment (unusually large for self-contained HTML phishing) designed to evade AI-based email security. The attachment contained massive amounts of HTML comments stuffed into the file to inflate its size, potentially to bypass size-based analysis heuristics or AI models trained on smaller samples. The email headers indicated it was sent via a homemade script (empty envelope sender, missing Date header, invalid X-Priority: 0 value) directly to the receiving server without a standard mail path. The attachment posed as an Excel file (double extension: .xls.html) and contained a credential-stealing page. The technique suggests adversaries are experimenting with evasion methods specifically targeting AI-based detection systems.

Interlock Ransomware Operation Linked to TAG-124 via Tooling Overlap

IBM X-Force documented strong overlaps between Interlock ransomware (Hive0163) and TAG-124 (aka KongTuke, Landupdate808) malware variants. The Interlock operation uses custom malware including NodeSnake, Interlock RAT, JunkFiction downloader (aka Dormouse), Supper (aka SocksShell, WINDYTWIST), and JunkFiction cryptor. IBM identified code-level similarities across NodeSnake, ModeloRAT, JunkFiction downloader, Interlock RAT, and Supper, indicating a shared developer or infrastructure.

Trends & Context

Three themes dominate today's threat landscape. First, the productization of initial access: CitrixBleed 2 exploitation follows a mechanically identical playbook across unrelated victims, indicating a mature Initial Access Broker operation selling access to ransomware affiliates. Second, the convergence of destruction and espionage: GigaWiper and GodDamn ransomware bundle multiple destructive payloads (disk wipers, fake ransomware, EDR killers) into modular backdoors, reflecting threat actors optimizing for operational efficiency rather than single-purpose tools. Third, the maturation of AI-assisted threats: vibe-coded AD enumeration tools and comment-stuffed phishing attachments demonstrate adversaries leveraging AI for bespoke evasion while defenders struggle to detect novel, signature-less malware.