← Carolina Clear Tech

Cyber Threat Brief

2026-07-13

Listen to this brief (13:34)

Download MP3
Show Notes

Show Notes - 2026-07-13

Stories Covered

CVEs Referenced

CVE-2025-12057, CVE-2025-12352, CVE-2025-32432, CVE-2025-6389, CVE-2025-7852, CVE-2026-0740, CVE-2026-2699, CVE-2026-2701, CVE-2026-3395, CVE-2026-3844, CVE-2026-48939, CVE-2026-56291

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily IT Security Brief

July 13, 2026

Today: CISA added two critical Joomla extension flaws to KEV with a same-day deadline. Progress Software took ShareFile Storage Zone Controllers offline over an unspecified credible threat. Internet scanning shows attackers systematically probing for exposed AI assistant configs and Model Context Protocol servers.

Critical Alerts

Joomla Extension Zero-Days (CVE-2026-56291, CVE-2026-48939)

CISA added two maximum-severity Joomla extension vulnerabilities to the Known Exploited Vulnerabilities catalog on July 10 with a July 13 deadline. Both flaws allow unauthenticated remote code execution through arbitrary file upload. CVE-2026-48939 affects iCagenda versions 4.x up to 4.0.7 and 3.x from 3.2.1 to 3.9.14, exploited in the wild since June 15. CVE-2026-56291 impacts Balbooa Forms versions up to 2.4.0. Both were exploited as zero-days before patches became available. The iCagenda flaw resides in the "Submit an Event" form, which accepts malicious PHP uploads to a public attachment folder. The Balbooa Forms vulnerability allows anonymous users to upload PHP files with no authentication, CSRF token, or file type validation.

Progress ShareFile Storage Zone Controller Shutdown

Progress Software prompted customers to manually shut down ShareFile Storage Zone Controller servers on Friday due to a credible external security threat. The company disabled access to ShareFile accounts using Storage Zone Controllers and is investigating with cybersecurity experts. Progress stated it has not identified unauthorized access to any accounts or customer data at this time. Users speculate threat actors are targeting CVE-2026-2699 (CVSS 9.8) and CVE-2026-2701 (CVSS 9.1), patched in March, which can be chained for unauthenticated remote code execution. Storage Zone Controllers provide private data storage, either on-premises or third-party, protected with application-specific passwords.

Business & Infrastructure Threats

AI Assistant Credential Scanning Campaign

Internet scanning logs from a small web host show attackers systematically probing for Model Context Protocol servers, AI assistant configuration files, and local LLM endpoints. Over a two-week period, scanners sent 200 requests targeting MCP servers and AI tool configs from 49 distinct source IPs. POST /mcp requests carried valid JSON-RPC 2.0 bodies performing legitimate MCP protocol initialize handshakes with correct protocol versions. The scanners also requested specific paths like /.cursor/mcp.json, /.vscode/mcp.json, /.mcp/config.json, /.claude/settings.local.json, and /.claude/.credentials.json. An exposed and unauthenticated MCP server provides a machine-readable menu of every tool and data source an AI agent can access, including databases, file systems, ticketing systems, and internal APIs.

Microsoft 365 Phishing Operations Using Evilginx

A misconfigured Python web server exposed three separate phishing campaigns targeting Microsoft 365 accounts using custom Evilginx proxy forks. One operator, tracked as codemado, left directory listing enabled on a public port, exposing phishing configs, credential-harvesting logs, RMM installers, combolists, and Telegram session files. The largest campaign ran for over a year, capturing corporate mailboxes by proxying live logins to bypass MFA. The operator's bash history showed comparisons between four Evilginx variants cloned from GitHub. One fork, red-queen, renames HTML attributes to defeat Subresource Integrity checks, adds URL rewriting to dodge path-based detection, and sets captured Microsoft session cookies to a one-year TTL (31,536,000 seconds), allowing tokens to outlast password resets. A third fork, black-queen, abuses Microsoft's OAuth device code flow, wrapping real device codes in Authenticator-themed lures that trick victims into signing in at genuine microsoft.com/devicelogin.

Global CMS Vulnerability Exploitation Campaign

The Australian Cyber Security Centre issued an alert warning of a global campaign targeting vulnerabilities in content management systems and plugins. Attackers actively scan websites to deploy web shells by leveraging flaws that allow unauthenticated file upload, remote code execution, server-side request forgery, or deserialization. Once deployed, web shells serve as conduits for remote access and control. Targeted vulnerabilities include Sneeit Framework (CVE-2025-6389, EPSS 99th percentile), WPBookit (CVE-2025-7852), Gravity Forms (CVE-2025-12352), Craft CMS (CVE-2025-32432, CISA KEV, EPSS 100th percentile), Ninja Forms (CVE-2026-0740, EPSS 99th percentile), MaxSite CMS (CVE-2026-3395), Breeze Cache (CVE-2026-3844, EPSS 98th percentile), and WavePlayer (CVE-2025-12057).

OAuth Client ID Spoofing for Stealthy Enumeration

Proofpoint researchers identified multiple campaigns using OAuth client ID spoofing to enumerate Microsoft Entra ID accounts without generating successful sign-in events. Attackers issue POST requests to Microsoft's OAuth 2.0 token endpoint using the Resource Owner Password Credentials flow with spoofed or randomly generated client_id values. Microsoft Entra ID returns different AADSTS error codes depending on whether the supplied client ID is valid and whether the username and password are correct. This allows attackers to infer account validity, password correctness, and MFA enforcement without a registered OAuth application. When a spoofed client ID is used, only the application ID is recorded in sign-in logs without a corresponding application name, making detection harder.

General Security News

Centers Laboratory Data Breach Affects 540,000

Healthcare diagnostics company Centers Laboratory discovered an August 2025 intrusion that affected 542,377 individuals. Threat actors gained limited access to systems between August 9 and August 14, 2025, exfiltrating names, dates of birth, SSNs, driver's license numbers, passport numbers, and health insurance and medical information. The WorldLeaks cybercrime group listed Centers Lab on its leak site in October 2025, releasing over 1.6 million files totaling 720 GB. WorldLeaks emerged in 2025 after the shutdown of Hunters International ransomware group. The group stopped using file-encrypting malware and focuses on data theft and extortion, with over 170 organizations listed on its leak site.

South Korea Military Faces Record Cyberattack Attempts

The South Korean military was targeted in 18,951 cyberattack attempts in 2025, the highest figure in five years. This represents a 62% increase from 11,700 attempts in 2021. The attack volume has grown steadily from 9,115 in 2022 to 13,599 in 2023 and 14,419 in 2024 before jumping to nearly 19,000 in 2025.

AI-Generated Code Creates Security Governance Problem

AI-generated code accelerates development but creates risk at machine speed while most organizations manage security with human-scale processes. The challenge is risk velocity: how quickly organizations create new software risks versus how quickly they can remediate them. AI coding tools reproduce insecure patterns from training data, including weak input validation, unsafe authentication flows, hard-coded secrets, and vulnerable dependency choices. Veracode's 2025 GenAI Code Security report found AI coding tools produce insecure code 45% of the time. AI tools can also recommend outdated packages, vulnerable libraries, or nonexistent dependencies, creating supply chain exposure when attackers register malicious packages with similar names.

Patch Priority

Vulnerability Disclosures

All vulnerability disclosures covered in sections above due to active exploitation or criticality. No additional CVEs to report.

Trends & Context

Three patterns stand out today. First, CMS and plugin vulnerabilities continue to be exploited at scale with web shell deployment as the primary objective. The Joomla extension flaws and the Australian CMS campaign warning show attackers systematically hunting for arbitrary file upload flaws. Second, attackers are targeting AI development infrastructure with unprecedented specificity. The MCP server scanning campaign shows adversaries understand how AI agents work and are building wordlists to find accidentally exposed configuration files. Third, phishing operators continue to evolve techniques to bypass MFA and extend session token lifetimes, making detection harder and allowing persistence beyond password resets.