CVE-2023-24489, CVE-2023-37580, CVE-2024-27443, CVE-2024-55591, CVE-2025-27915, CVE-2025-32433, CVE-2025-33073, CVE-2025-55182, CVE-2025-7771, CVE-2026-14380, CVE-2026-14461, CVE-2026-14739, CVE-2026-14740, CVE-2026-20214, CVE-2026-20216, CVE-2026-20244, CVE-2026-42530, CVE-2026-48939, CVE-2026-56291, CVE-2026-58207, CVE-2026-58208, CVE-2026-58209, CVE-2026-58250, CVE-2026-58251, CVE-2026-59856, CVE-2026-59869, CVE-2026-59890, CVE-2026-59922, CVE-2026-59925, CVE-2026-59926, CVE-2026-59928, CVE-2026-59930, CVE-2026-59998
Domains:
injective[.]network.
Get tomorrow's brief in your inbox
Today: Progress Software ordered ShareFile customers to shut down Storage Zone Controllers over an undisclosed security threat with no patch available. The Gentlemen ransomware group claimed 117 victims in June alone, nearly 4x their January total, while CISA added two Joomla file upload flaws to the KEV catalog. Zimbra fixed a critical XSS bug that could let crafted emails execute code in user sessions.
Progress ShareFile Storage Zone Controller Immediate Shutdown Order
Progress Software issued an emergency order on July 10 requiring all ShareFile customers to shut down Windows servers running Storage Zone Controllers. The company confirmed to The Hacker News it is responding to a "credible external security threat" but has not disclosed what the threat is or who is behind it. Progress temporarily disabled access to affected accounts and says it has no indication of unauthorized access to ShareFile accounts or data. The shutdown order, rather than a patch directive, suggests either a newly discovered flaw the company is racing to fix or a threat that patches cannot address, such as stolen keys or a problem on Progress's own infrastructure. Only the Storage Zone Controller is affected, not standard cloud-only ShareFile accounts. The controller typically sits at the network edge, internet-accessible, making it both useful and a target.
CISA Adds Two Joomla File Upload Vulnerabilities to KEV Catalog
CISA added two Joomla extension file upload vulnerabilities to the Known Exploited Vulnerabilities catalog on July 10 based on evidence of active exploitation. CVE-2026-48939 (iCagenda Unrestricted Upload, EPSS 0.6%) and CVE-2026-56291 (Balbooa Forms Unrestricted Upload, EPSS 0.3%) allow attackers to upload files with dangerous types. Federal agencies must remediate KEV vulnerabilities on publicly exposed assets that grant total control post-exploitation under BOD 26-04.
The Gentlemen Ransomware Claims 580 Victims Across 77 Countries
The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service program active since at least July 2025 that has claimed 580 victims across 77 countries through July 7, 2026. The group offers an unprecedented 90% affiliate payout, compared to the typical 70-80% split. June 2026 was their highest month with 117 claimed victims, nearly 4x their January total. When comparing the last six months of 2025 to the first six months of 2026, victim counts increased by more than 6x. Manufacturing is the most targeted sector (103 victims) due to operational uptime requirements. The operators morphed from a private entity (previously affiliates of Qilin RaaS) into a RaaS model around September 2025. Unit 42 observed The Gentlemen using exploitation of edge devices (firewalls, VPNs), brute force attacks, stolen credentials, and collaboration with initial access brokers. Recent campaigns feature a custom Go-based backdoor, an EDR killer framework dubbed "GentleKiller," and suspected use of an unspecified zero-day vulnerability. The group partnered with HasanBroker's BreachForums in May 2026 to recruit affiliates, penetration testers, and initial access brokers. The ransomware is written in both C and Go, enabling spread across different operating systems and virtual infrastructure. Unit 42 analysis indicates The Gentlemen is now the second most active RaaS program of 2026 by victim count.
Three US Security Experts Sentenced for Helping BlackCat Ransomware
Angelo Martino, 41, of Florida, was sentenced July 10 to 70 months in prison after pleading guilty to helping BlackCat/Alphv ransomware operators while working as a ransomware negotiator. Martino is the third of three cybersecurity professionals charged last year for their role in ransomware attacks. Kevin Martin (Texas) and Ryan Goldberg (Georgia) were each sentenced to 4 years in prison in late April. Martino began working with BlackCat in April 2023 and helped extort at least five victims by providing confidential information about his employer's clients' negotiating positions and strategies, enabling the ransomware actors to maximize ransoms. Authorities seized $10 million in assets from Martino, including cryptocurrency, vehicles, a food truck, and a fishing boat. Over 1,000 organizations were targeted in BlackCat attacks between 2021 and December 2023, when the criminal enterprise was disrupted. In February 2024, the hackers received a $22 million ransom from a victim and executed an exit scam. The US offers $10 million for information leading to the identification of key BlackCat members.
Armenian National Pleads Guilty to Ryuk Ransomware Attacks
Karen Serobovich Vardanyan, 34, pleaded guilty July 10 to computer fraud and conspiracy charges for participating in Ryuk ransomware attacks from November 2019 to April 2020. Vardanyan and co-conspirators deployed Ryuk ransomware against hundreds of compromised servers and workstations while living in Ukraine and Russia. Victims include a Michigan company that paid nearly $1.2 million in January 2020, a Watsonville, Oregon technology company attacked in December 2019, and a Texas school breached in February 2020. Vardanyan and co-conspirators received about 1,160 bitcoins (valued at more than $15 million at the time) in ransom payments. Vardanyan was extradited from Ukraine to the US last year. He agreed to pay nearly $1.2 million in restitution and faces up to 15 years in jail. Ryuk ransomware infected thousands of victims globally from 2019-2020, including Hollywood Presbyterian Medical Center, Universal Health Services, Electronic Warfare Associates, a North Carolina water utility, and multiple US newspapers.
Fake Microsoft Entra Passkey Enrollment Used in Vishing Attacks
A threat actor tracked as O-UNC-066 (also known as CL-CRI-1147 and Pink) has targeted organizations in food and beverage, technology, healthcare, automotive, construction, and aviation industries with voice-based phishing campaigns since April 2026. Attackers call victims and persuade them to register a new Microsoft Entra passkey, directing them to a phishing kit that mirrors the Microsoft passkey enrollment process. The kit is an operator-controlled PHP panel that adapts the user experience in real-time to each victim's MFA requirements (TOTP, push notification with number matching, SMS OTP). Unlike adversary-in-the-middle phishing kits, this panel does not automatically harvest credentials. Instead, the threat actor guides the victim through multiple authentication stages while simultaneously registering their own passkey in the victim's Microsoft 365 account. The attack abuses Microsoft's passkey registration campaign feature, which nudges users to register passkeys during sign-in to drive adoption at scale. Once the attacker enrolls their passkey, they receive a legitimate Microsoft email notification that can be named to appear benign to the victim.
Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages
Unknown threat actors compromised the Injective Labs SDK project's GitHub repository on July 8 and published malicious package @injectivelabs/[email protected] to npm with fake telemetry functionality that exfiltrated cryptocurrency wallet private keys and mnemonic seed phrases. The malicious version has been deprecated but release artifacts remain available on GitHub. The threat actor submitted commits through a GitHub account belonging to a developer (thomasRalee) with an established contribution history to the repository. The attacker also published version 1.20.21 across 17 additional @injectivelabs scoped packages that depended on the malicious SDK version, putting transitive users at risk. The malware modifies legitimate private key generation functions to invoke a "trackKeyDerivation()" function disguised as anonymized usage metrics collection. The function captures mnemonic phrases and private keys, queues multiple key derivations over a two-second window, and exfiltrates them via HTTPS POST to testnet.archival.chain.grpc-web.injective[.]network. The malicious release was facilitated through the repository's own trusted-publisher (OIDC) pipeline. The malware avoids lifecycle scripts and does not launch during installation, helping it evade detection.
Microsoft Secure Future Initiative July 2026 Progress Report
Microsoft released its July 2026 Secure Future Initiative (SFI) progress report covering security improvements across identity, network isolation, access governance, and proactive defense. Key metrics: phishing-resistant MFA now protects 99.97% of user/device pairs; 732,000 resources had public access revoked; network isolation scaled across 1 million resources; 1.4 million unused apps were decommissioned; cross-boundary credential isolation reached 98.7%; engineering defaults prevent 83% of pipelines from accessing unapproved package endpoints. Microsoft built a multi-agent AI system that assesses cloud service source code, identity configurations, network topology, and runtime state to surface composite vulnerabilities that single-layer reviews miss. More than 90% of findings were confirmed by security engineers. The system builds on Microsoft's MDASH multi-model agentic scanning system for source code vulnerability identification. Microsoft added more than 100 new detections this year (more than 350 total), shifting from signature-based to behavior- and baseline-driven detection. More than 550,000 critical and high-risk open-source vulnerabilities were remediated, with about 3 million container vulnerabilities patched per month through automation. The report addresses preparation for post-quantum cryptography as AI reshapes both attacker and defender capabilities.
CVE-2026-59998: OpenSSH GSSAPIStrictAcceptorCheck Ineffective in Windows Active Directory
OpenSSH versions before 10.4 have an undocumented security-relevant behavior where GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory. EPSS score is 0.2% (8th percentile). Microsoft Security Response Center published information about the vulnerability.
Critical Zimbra Stored XSS in Classic Web Client
Zimbra is urging customers to patch a critical stored cross-site scripting (XSS) vulnerability in the Classic Web Client that could allow specially crafted emails to execute malicious scripts in a user's session. No CVE has been assigned yet. The flaw allows emails to run malicious code when opened, potentially granting access to mailbox information, session data, or account settings. Zimbra makes no mention of active exploitation, but XSS flaws in Zimbra have been exploited since December 2021. In October 2025, CVE-2025-27915 (CVSS 5.4, CISA KEV, EPSS 4.2%, due Oct 28 2025) was alleged to have been exploited as a zero-day targeting the Brazilian military, though Zimbra found no evidence. Other exploited Zimbra XSS flaws include CVE-2023-37580 (CISA KEV, EPSS 59.0%, due Aug 17 2023) and CVE-2024-27443 (CISA KEV, EPSS 19.5%, due Jun 9 2025).
XRING: Unpatched Remote Crash in Alibaba XQUIC Library
A single variable error in Alibaba's XQUIC QUIC and HTTP/3 library (CVE-2026-42530) allows any remote client to crash the server with approximately 260 bytes of legal QPACK traffic. No login or malformed packets are required. FoxIO researcher Sébastien Féry disclosed the flaw July 8 and nicknamed it XRING. Every release through v1.9.4 (latest) is affected. No fix or CVE has been assigned as of July 10. The bug is in QPACK dynamic table resizing logic where the code sizes leftover tail data against the new buffer's capacity instead of the old one's, causing an integer underflow and out-of-bounds memory copy. In FoxIO's release build on Ubuntu 26.04, glibc's _FORTIFY_SOURCE=2 caught the bad length and killed the process. Without that check, the copy writes out of bounds. Any server embedding XQUIC and serving HTTP/3 with default QPACK settings is exposed, including Tengine (Alibaba's Nginx-based web server) fronting Alibaba cloud, CDN, Taobao, and Alipay. The bug has existed since XQUIC's first public release in January 2022.
Three OpenClaw Flaws Enable WhatsApp-to-Host Attack Chain
Security researcher Chinmohan Nayak disclosed three high-severity vulnerabilities in the OpenClaw personal AI assistant (all patched in version 2026.6.6) that enable credential theft, privilege escalation, and arbitrary code execution on the host. GHSA-hjr6-g723-hmfm and GHSA-9969-8g9h-rxwm (both CVSS 8.8) are OS command injection flaws impacting the host execution environment filtering mechanism. GHSA-575v-8hfq-m3mc (CVSS 8.4) is a path traversal and link following vulnerability that bypasses parent-directory denylist checks. Unlike the Claw Chain vulnerabilities disclosed by Cyera in May, these bugs do not require prior foothold. The path traversal flaw allows mounting parent directories like /home or /var, undermining individual blocks for ~/.ssh, ~/.aws, and ~/.gnupg. Mounting /home exposes all users' SSH keys, AWS credentials, and GPG secrets. Mounting /var exposes the Docker socket, enabling full host escape from inside the sandbox. Nayak demonstrated triggering host code execution from an external message sent via WhatsApp.
Wireshark 4.6.7 Released
Wireshark 4.6.7 fixes 12 vulnerabilities and 16 bugs. No specific CVE details provided.
Multiple MSRC Security Updates
Microsoft Security Response Center published information on 15 CVEs affecting Vim, ClamAV, DBI for Perl, Mistune, setuptools, NATS Server, mtr, and js-yaml. All have low EPSS scores (0.1% to 0.7%) and no CISA KEV listings. Highlights include CVE-2026-59856 (Vim arbitrary code execution via PHP omni-completion), CVE-2026-20214 (ClamAV FSG file format out-of-bounds memory corruption), CVE-2026-20216 (ClamAV InstallShield resource exhaustion), CVE-2026-20244 (ClamAV DMG file DoS), CVE-2026-14380 (DBI code injection via caller-influenced Profile), CVE-2026-14739/14740 (DBI heap overflow and out-of-bounds read), CVE-2026-59926 (Mistune XSS via unescaped class option), CVE-2026-59925/59928/59922 (Mistune quadratic-time parsing), CVE-2026-59890 (setuptools MANIFEST.in exclusion bypass), CVE-2026-58207/58251/58208/58209/58250 (NATS Server crashes and authz bypass), CVE-2026-14461 (mtr out-of-bound read), and CVE-2026-59869 (js-yaml quadratic CPU consumption).
DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Disrupts Ransomware Ops
SecurityWeek's weekly roundup includes: Canada's Communications Security Establishment (CSE) disclosed it actively hacked ransomware operations, drug traffickers, and extremist organizations over the past year, successfully degrading criminal syndicates' technological capabilities; a subscription-based RAT platform named QuimaRAT v2.0 is being advertised on dark web forums with multi-architecture binaries targeting Windows, macOS, and Linux, offering lifetime access for $1,200; security researcher discovered a critical vulnerability dubbed WriteOut in Writer AI that allows bypassing sandbox restrictions to read proprietary workspace data across tenants (now patched); US insurance company AssuranceAmerica suffered a breach affecting nearly 7 million people (names, contact information, driver's license numbers), discovered in March; the NSA officially revived its Tailored Access Operations (TAO) division; enterprise security firm Abnormal AI publicly refuted Anthropic's trademark infringement lawsuit, clarifying its slash-based wordmark was independently designed in April 2021 before Claude AI's commercialization; fraudsters Jacob Wohl and Jack Burkman were exposed by Brian Krebs as operating a clandestine exploit brokering startup called IRIS C2 under Calvexa Group, publicly offering million-dollar payouts for zero-day vulnerabilities despite having no apparent government contracts.
Ledger Researchers Demonstrate Laser Attack on Tangem Crypto Wallets
Ledger's Donjon security team demonstrated that a precisely timed laser pulse aimed at the Samsung S3D232A chip inside a Tangem crypto wallet card can reset the card's password without the old password or backup card. The attack requires the physical card, a lab Donjon estimates at around $250,000, cutting the card open (leaving visible damage), and about two hours per card. Tangem cards cannot take software updates, so every card already sold carries the flaw permanently. The attack exploits the password reset feature by firing a laser at the exact moment the chip runs a recovery mode check, causing the check to misfire and accept a new password without requiring the old one or a second card. Tangem pushed back, calling it a lab-only physical method that works against secure element chips in general and noting an attacker spending $250,000 has no way to tell whether a stolen card holds $50 or $50 million. Tangem also noted no one has lost funds to a laser attack on any hardware wallet so far. Donjon reported the flaw to Tangem on February 10, 2026.
Countries Expand Social Media Age Restrictions
Australia, Canada, and the UK have implemented or announced plans to ban social media for users under 16, with several US states following suit. Supporters cite mental health risks, doom-scrolling addictions, and safety concerns. The US Department of Health and Human Services warned in 2023 that minors spending more than three hours daily on social media face double the risk of mental health problems. Australia's Online Safety Amendment Bill defined a Social Media Minimum Age (SMMA) of 16, with enforcement taking effect in December 2025. However, eSafety commissioner raised compliance concerns in March 2026, citing one platform's age verification approach that seemed "obvious" children would bypass, and errors in facial age estimation technology. Companies face challenges balancing user retention with legal compliance, often requiring sensitive information like driver's licenses or credit card numbers for age verification. Privacy and implementation challenges abound as resourceful, technically savvy minors will likely bypass controls.
Today's coverage highlights the operational security gap between detection and response. Progress Software's emergency ShareFile shutdown demonstrates the difference between discovering a threat and having a fix ready. The Gentlemen ransomware's 6x victim increase in six months shows how lucrative affiliate payouts (90% vs the typical 70-80%) can rapidly scale operations. The convergence of vishing and legitimate security features (Microsoft's passkey enrollment campaigns being abused for phishing) illustrates how attackers exploit trusted upgrade processes to bypass phishing-resistant controls.