← Carolina Clear Tech

Cyber Threat Brief

2026-07-17

Listen to this brief (24:45)

Download MP3
Show Notes

Show Notes - 2026-07-17

Stories Covered

CVEs Referenced

CVE-2025-11698, CVE-2025-12011, CVE-2025-12012, CVE-2026-11889, CVE-2026-12659, CVE-2026-15043, CVE-2026-15392, CVE-2026-15709, CVE-2026-15711, CVE-2026-15712, CVE-2026-15713, CVE-2026-15714, CVE-2026-25089, CVE-2026-32201, CVE-2026-39808, CVE-2026-45659, CVE-2026-48863, CVE-2026-53366, CVE-2026-54798, CVE-2026-54799, CVE-2026-54800, CVE-2026-56164, CVE-2026-56171, CVE-2026-57433, CVE-2026-58598, CVE-2026-58643, CVE-2026-58644, CVE-2026-59117, CVE-2026-59884, CVE-2026-59885, CVE-2026-59886, CVE-2026-60063, CVE-2026-60081, CVE-2026-60082, CVE-2026-61389, CVE-2026-8085, CVE-2026-8312, CVE-2026-8313, CVE-2026-8314, CVE-2026-9292, CVE-2026-9653

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cybersecurity Brief

July 17, 2026

Today: Microsoft SharePoint critical RCE zero-day CVE-2026-58644 added to CISA KEV with July 19 patch deadline. Two Fortinet FortiSandbox command injection flaws also under active exploitation. Coca-Cola subsidiary Fairlife suspends US dairy production after ransomware hit. ACR Stealer campaigns using ClickFix lures successfully stealing browser credentials and tokens from enterprise environments.


Critical Alerts

Microsoft SharePoint RCE Zero-Day CVE-2026-58644 Added to KEV

Microsoft SharePoint Server is under active exploitation through CVE-2026-58644, a critical 9.8 CVSS deserialization vulnerability allowing remote code execution. The flaw was patched July 14 but exploited as a zero-day before fixes became available. An attacker authenticated as Site Owner can write arbitrary code and execute it remotely on SharePoint Server. Attack complexity is low and the vulnerability is remotely exploitable over the internet. CISA added CVE-2026-58644 to the Known Exploited Vulnerabilities catalog on July 16 with a federal agency remediation deadline of July 19. Three additional SharePoint vulnerabilities are also under active exploitation: CVE-2026-32201 (EPSS 97th percentile), CVE-2026-45659, and CVE-2026-56164 (KEV deadline July 17). The attack chain enables post-exploitation activities including stealing IIS machine keys and performing deserialization techniques to gain persistence and deploy malware.

Fortinet FortiSandbox Command Injection Flaws Under Active Exploitation

Two critical OS command injection vulnerabilities in Fortinet FortiSandbox are being actively exploited. CVE-2026-25089 (EPSS 98th percentile) and CVE-2026-39808 (EPSS 99th percentile) allow attackers to execute arbitrary code or commands on vulnerable appliances. Both flaws were patched in April and June respectively. CISA added both to the KEV catalog on July 16 with a July 19 remediation deadline for federal agencies.


Ransomware & Extortion

Coca-Cola Suspends Fairlife US Production After Ransomware Attack

Coca-Cola disclosed a ransomware attack on its wholly owned subsidiary Fairlife that forced the company to suspend all US production operations. Attackers accessed a portion of Fairlife's systems including production-related infrastructure. Fairlife distributes ultra-filtered milk products in five flavors. The Chicago-based dairy company activated incident response and business continuity protocols and notified law enforcement. Product quality and safety have not been impacted. Canada production operations remain unaffected. The company has not disclosed how the incident occurred, who was behind it, or whether extortion demands were received. No known ransomware groups have claimed responsibility as of July 16.

Spirals Ransomware Encrypts IT Services Network Within 24 Hours

A new Rust-based ransomware family called Spirals targeted an IT services company in South Asia in June 2026. Less than 24 hours after initial breach, the ransomware payload was being pushed to machines on the network. The attacker gained initial access by compromising an internet-facing IIS web server and uploading an ASP.NET web shell. Over the next three hours, they established persistent access, conducted reconnaissance, uninstalled endpoint security software, and dumped credentials. The payload is either a new ransomware threat or purpose-built for this specific attack.


Business & Infrastructure Threats

ACR Stealer Using ClickFix Lures to Steal Browser Credentials and Tokens

Microsoft observed increased ACR Stealer activity from late April to mid-June 2026 successfully stealing browser credentials, authentication tokens, and sensitive documents from enterprise environments. The malware-as-a-service offering uses ClickFix social engineering to trick targets into running commands. Two distinct campaigns are active. The first uses WebDAV-delivered payloads, staged PowerShell, Python-based loaders, and blockchain-backed C2 resolution. The second uses a fileless approach with MSHTA, obfuscated PowerShell, and steganography-assisted in-memory execution. Both campaigns steal browser-stored credentials, session tokens, authentication artifacts, and sensitive enterprise data, potentially enabling account compromise and unauthorized access to cloud resources.

ClickLock macOS Stealer Kills Apps Until Victims Enter Password

ClickLock Stealer, a new macOS infostealer, kills applications on a loop every 210 milliseconds until victims provide their login password. The malware arrives as a command pasted into Terminal via ClickFix lures. When the victim cancels the fake system dialog requesting a password, the malware installs two LaunchAgents and exits. At the next login, Finder, Dock, Spotlight, Terminal, Activity Monitor, and major browsers die every 210 milliseconds for up to 83 hours. Activity Monitor and Terminal are killed to prevent investigation. A third loop kills NotificationCenter for six hours to suppress Gatekeeper warnings. The kill loops continue until the victim provides a working password validated against macOS. A completed run exfiltrates the macOS login password, Chrome Safe Storage AES key, browser credentials and cookies, crypto wallet extension storage, desktop wallet files, password manager vaults, Keychain, shell history, and FileZilla credentials. Group-IB counts at least 100 targets across 33 countries since May, over half in Europe. The orchestrator script uploaded to VirusTotal on June 9 had zero detections.

20+ Brazilian Government Websites Hijacked for Malware Delivery

More than 20 Brazilian government websites were compromised and used as malware delivery infrastructure in an active PhantomEnigma campaign. Attackers used fake police-themed documents presented as official notices with QR codes or links to government resources. Emails were sent through compromised mailboxes and passed SPF, DKIM, and DMARC checks. Victims were redirected through compromised .gov.br hosts including timon.ma.gov.br, loginam.sesp.es.gov.br (state public security), aplicacao.cbm.mt.gov.br (fire department), and prodoc.ap.gov.br. The campaign evolved from banking-focused activity in 2025 to abusing compromised government infrastructure in 2026. The malware evolved from a browser-extension banker into a modular Inno/Node.js backdoor capable of executing JavaScript and delivering additional payloads. The backdoor collects system data, establishes persistence, connects to rotating C2 infrastructure, and delivers stealers, loaders, RMM software, and other malware.

Fake Installers Deliver Starland RAT and WLDR Memory Implant

UAT-11795, a sophisticated Russian-speaking adversary, has been targeting users in the US and Europe since at least June 2025 using trojanized installers for developer tooling, IT administration utilities, enterprise collaboration platforms, and gaming applications. The campaign delivers Starland RAT (Python-based remote access tool) and WLDR agent (PowerShell-based C2 memory implant). WLDR agent features encrypted beaconing, task queuing, and a Runspace execution engine for executing additional payloads. The activity also deploys CastleStealer and Remcos RAT. The malware targets credentials, cryptocurrency wallet assets, Active Directory information, and establishes persistent connections for further payload delivery. The attack chain uses ClickFix lures to distribute HTA scripts, which download and run trojanized installers delivering Starland RAT, which uses curl.exe to execute a PowerShell stager for WLDR agent. The majority of infections are in the US.

Malicious NuGet Packages Drop Spyware Through Game Cheats

Eleven malicious NuGet packages published as .NET command-line tools present themselves as game utilities, bots, and panels. Each package acts as a first-stage downloader fetching a second-stage Python payload named pepesoft.exe from GitHub Releases and Hugging Face under the username pepegit666. The payloads use AWS-style key material to retrieve remote configuration, authenticate to Google Sheets, bind activations to hardware, and honor a remote hardware ID ban-list. Game-automation payloads expose Telegram bot commands that send screenshots back to configured chats.


Windows / AD Security

Windows Terminal RCE Vulnerability CVE-2026-59117

An integer overflow or wraparound vulnerability in Windows Terminal allows an unauthorized attacker to execute code over a network. No CVSS score or EPSS data provided.

Windows Backup Service Elevation of Privilege CVE-2026-58598

A race condition vulnerability in Windows Backup Engine allows an authorized attacker to elevate privileges locally. The vulnerability stems from concurrent execution using a shared resource with improper synchronization.

Windows Admin Center XSS Spoofing Vulnerability CVE-2026-58643

Improper neutralization of input during web page generation in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.

Windows RDP Information Disclosure CVE-2026-56171

Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.


General Security News

AI Vulnerability Management Requires Operational Guardrails

Mandiant released guidance on safely integrating AI agents into vulnerability management workflows after security teams inquired about risks. The M-Trends 2026 report shows mean time-to-exploit dropped to -7 days, meaning vulnerabilities are exploited a week before patches exist. Security teams exploring LLM agents for automated vulnerability discovery and remediation face new architectural risks without mature integration processes. Key risks include agents accessing sensitive data without proper controls, cloud provider limitations blocking offensive security probing, and workload isolation failures. Organizations should enforce pre-agent data security, use non-production environments with synthetic data for testing, deploy defense-in-depth with deterministic policy engines and guard models, establish zero data retention agreements with LLM providers, and execute agent workloads in strictly isolated unprivileged containers. Treat codebases as untrusted input as threat actors can embed indirect prompt injections in source code comments or third-party dependencies.

AI-Generated Bug Reports Creating Triage Burden

Bug bounty programs and maintainers are seeing a surge of low-quality AI-generated vulnerability reports with thin evidence, templated language, and little validation. Bugcrow publicly addressed this pattern in policy changes around AI-generated submissions. AI can generate convincing write-ups in seconds but unless claims are validated with demonstrated reachability, boundary crossing, and impact, the result is not better security but a larger triage queue. A finding should answer what happened, how it was reproduced, what the attacker controls, which boundary was crossed, and what the demonstrated impact is.

Microsoft Guidance on Least Privilege for AI Agents

Microsoft published best practices for AI agent identity and authorization. AI agents plan, chain actions across systems, and invoke tools in sequences without explicit human approval for each step. When an agent operates without a managed identity and least-privilege RBAC, it can access or modify sensitive data beyond intended permissions if controls are not properly configured. Organizations should treat every agent as a first-class principal with lifecycle-managed identity, explicit role assignments, tightly scoped permissions, and preconfigured tools manifests. Recommended practices include assigning managed identities to all agents, using least-privilege role-based access control, scoping each agent to narrowly defined resource sets, maintaining a preconfigured tools manifest, implementing detailed audit logging for all agent actions, and documenting whether agents act under their own identity or delegated user scope.


Patch Priority


Vulnerability Disclosures

AutomationDirect Productivity Suite Kernel Memory Corruption

Six vulnerabilities in AutomationDirect Productivity Suite v4.6.2.2 and earlier allow local or physical attackers to cause memory corruption, information disclosure, application instability, or denial-of-service. CVE-2026-60063 and CVE-2026-61389 are out-of-bounds write vulnerabilities allowing privilege escalation or system instability via crafted IOCTL requests. The software is used in critical manufacturing worldwide.

Siemens SICAM 8 Firmware Update Bypass and Insecure Defaults

Four vulnerabilities in Siemens SICAM 8 products including CPCI85 and SICORE firmware affect critical manufacturing and energy infrastructure worldwide. CVE-2026-54798 is an active debug interface accessible through HTTP endpoints allowing authenticated attackers to crash the web process. CVE-2026-54799 is a firmware update signature validation bypass allowing malicious firmware installation and persistent code execution. CVE-2026-54800 is an insecure default configuration disabling all OPC UA security mechanisms.

Rockwell Automation Arena Memory Corruption Vulnerabilities

Four out-of-bounds write vulnerabilities in Rockwell Automation Arena v17.00.00 and earlier allow attackers to execute arbitrary code by convincing a user to open a malicious file. CVE-2026-8085, CVE-2026-8312, CVE-2026-8313, and CVE-2026-8314 affect the model.exe, expmt.exe, linker.exe, and siman.exe components respectively. The software is used in critical manufacturing worldwide.

Rockwell Automation FactoryTalk DataMosaix Stored XSS

CVE-2026-9292 is a stored cross-site scripting vulnerability in FactoryTalk DataMosaix Private Cloud v8.02 and earlier. The flaw stems from improper neutralization of user-supplied input in Workflows configuration. An authenticated attacker with high privileges can inject malicious scripts permanently stored on the server, potentially allowing account takeover, credential theft, or redirection to malicious websites.

Rockwell Automation Communication Module DoS Vulnerabilities

Multiple Rockwell Automation industrial control products are affected by denial-of-service vulnerabilities. CVE-2026-9653 affects 1756-EN2, 1756-EN3, and 1756-ENBT communication modules through improper validation of CIP Implicit Connection packets. Crafted packets can continuously disrupt device connections. CVE-2026-12659 affects Flex 5000 Adapter v6.011 through improper handling of exceptional conditions when processing crafted CIP packets. Power cycle required to recover. CVE-2025-12011, CVE-2025-12012, and CVE-2025-11698 affect CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix controllers, allowing remote users to cause major non-recoverable faults.

SALTO ProAccess Space Privilege Escalation

CVE-2026-11889 is a privilege escalation vulnerability in SALTO ProAccess Space software versions before 6.13 affecting the tenancy/logical partition feature. An authenticated attacker can access any space managed by the product by bypassing authorization through user-controlled keys. The software is used in commercial facilities and critical manufacturing worldwide.

Linux and Open Source Library Vulnerabilities

Multiple Linux and open source library vulnerabilities published by Microsoft. CVE-2026-48863 is a stack-based buffer overflow in libsolv eddsa PGP signature verification (EPSS 52nd percentile). CVE-2026-53366 is an IPv4 fraggap allocation path vulnerability (EPSS 9th percentile). Multiple libsoup vulnerabilities: CVE-2026-15713 (HTTP/2 frame window exhaustion memory leak DoS, EPSS 27th percentile), CVE-2026-15714 (out-of-bounds read via oversized multipart boundary, EPSS 31st percentile), CVE-2026-15712 (HTTP/2 GOAWAY frame parsing heap buffer over-read, EPSS 39th percentile), CVE-2026-15711 (websocket oversized control frame DoS, EPSS 35th percentile), CVE-2026-15709 (websocket permessage-deflate unbounded decompression DoS, EPSS 42nd percentile). Multiple Perl DBI vulnerabilities: CVE-2026-60082 and CVE-2026-60081 (DBI statement handle and ProfileData path index issues, EPSS 47th and 46th percentiles), CVE-2026-15043 (DBI::SQL::Nano inverted operators, EPSS 40th percentile), CVE-2026-15392 (DBD::File symlink to untrusted location, EPSS 10th percentile). Perl Storable CVE-2026-57433 (signed integer overflow, EPSS 27th percentile). Multiple pyasn1 vulnerabilities: CVE-2026-59884 (unbounded long-form tag ID DoS, EPSS 28th percentile), CVE-2026-59886 (uncontrolled resource consumption on REAL values, EPSS 26th percentile), CVE-2026-59885 (quadratic complexity in OBJECT IDENTIFIER processing, EPSS 26th percentile).


Trends & Context

Three themes dominate today's threat landscape. SharePoint exploitation continues with a critical zero-day and three additional actively exploited vulnerabilities, all with federal remediation deadlines this week. ClickFix social engineering proves effective across platforms, delivering ACR Stealer to Windows enterprises, ClickLock to macOS users, and multiple RAT families through fake installers. Finally, industrial control system vulnerabilities span AutomationDirect, Siemens, Rockwell Automation, and SALTO physical access control with memory corruption, firmware bypass, insecure defaults, and privilege escalation flaws requiring immediate patching in critical manufacturing and energy infrastructure.