CVE-2025-40947, CVE-2025-40948, CVE-2025-40949, CVE-2025-66199, CVE-2026-15409, CVE-2026-15410, CVE-2026-15903, CVE-2026-15904, CVE-2026-34183, CVE-2026-47729, CVE-2026-50012, CVE-2026-60137, CVE-2026-62299, CVE-2026-62309, CVE-2026-63030
Get tomorrow's brief in your inbox
Today: Inc ransomware exploits two SonicWall zero-days in active attacks with a CISA deadline today. WordPress ships forced updates for wp2shell, an unauthenticated RCE chain hitting 6.9 and 7.0 installs. Siemens patches three chained zero-days in industrial switches that deliver root access.
Inc Ransomware Exploits SonicWall SMA Zero-Days (CVE-2026-15410, CVE-2026-15409)
Inc ransomware is exploiting two zero-day vulnerabilities in SonicWall Secure Mobile Access 1000 Series appliances to gain initial access, steal credentials, and deploy ransomware across enterprise networks. CVE-2026-15409 is a server-side request forgery flaw with a CVSS score of 10.0 that allows unauthenticated attackers to trick the appliance into making internal requests. CVE-2026-15410 is a code injection vulnerability scored 7.2 that enables OS-level command execution from the admin console. When chained, the vulnerabilities allow attackers to escalate from unauthenticated outsider to root-level insider. Rapid7 observed Inc ransomware using the flaws to establish persistence by stealing credentials, session databases, and one-time password seeds, then moving laterally to domain controllers. CISA added both CVEs to the KEV catalog on July 14 with a remediation deadline of July 17. EPSS scores are low (1.5% and 1.3%) despite active exploitation, indicating automated scanning has not yet caught up.
WordPress wp2shell RCE Chain (CVE-2026-63030, CVE-2026-60137)
WordPress shipped forced updates Friday for an unauthenticated remote code execution chain affecting all 6.9 and 7.0 installs. The wp2shell attack chains two bugs: CVE-2026-63030 (REST API batch-route confusion) and CVE-2026-60137 (SQL injection in WP_Query). An anonymous HTTP request can exploit the batch endpoint to bypass input validation and inject SQL through the author__not_in parameter, leading to code execution. WordPress 6.9.5 and 7.0.2 patch the full RCE chain, while 6.8.6 patches only the SQL injection since the batch confusion does not exist in 6.8. A working proof-of-concept is public on GitHub. The RCE path only works when sites are not running a persistent object cache, narrowing the blast radius. WordPress enabled forced auto-updates but has not confirmed whether this reaches sites with auto-updates disabled.
Siemens ROX II Zero-Day Trilogy (CVE-2025-40949, CVE-2025-40947, CVE-2025-40948)
Palo Alto Networks Unit 42 disclosed three chained zero-days in Siemens ROX II operational technology switches that allow attackers to escalate from reconnaissance to persistent root access. CVE-2025-40948 (CVSS 6.8) exploits the xz utility running with root privileges to read arbitrary files including credentials and keys. CVE-2025-40947 (CVSS 7.5) is a command injection flaw in the feature key validation function that grants root access. CVE-2025-40949 (CVSS 9.1) allows authenticated attackers to inject commands into the root cron table, establishing persistence across reboots. Siemens released firmware version 2.17.1 to patch all three vulnerabilities. EPSS scores are low (0.5%, 0.4%, 0.3%) indicating no widespread exploitation yet. Palo Alto Networks has virtual patching signatures available for Next-Generation Firewall customers.
FortiSandbox Critical Flaws Under Active Attack
Attackers are exploiting critical vulnerabilities in Fortinet FortiSandbox, prompting CISA to issue a patch order. The Register reports active exploitation but does not provide CVE details or technical specifics in the extracted content. The vulnerabilities affect FortiSandbox appliances used for malware analysis and threat detection.
ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files
ACR Stealer, active since 2024, uses ClickFix social engineering lures to trick users into pasting malicious commands that deploy an infostealer. Microsoft Defender Experts tracked campaign activity climbing from late April to mid-June 2026. Two infection chains exist: one writes to disk, the other runs almost entirely in memory. Both chains steal saved browser passwords, live session tokens, PDFs, Microsoft 365 documents, and files from synced OneDrive and SharePoint folders. The fileless chain spawns mshta.exe to pull HTA content containing a VBScript loader that decodes PowerShell, which then retrieves a JPEG from an image host with the payload hidden in the pixels using steganography. The malware targets Chrome and Edge login databases, invoking DPAPI to decrypt passwords, cookies, and tokens. Microsoft's remediation guidance instructs victims to revoke tokens, not just rotate passwords. The campaign uses fake Claude AI pages delivered via malicious Google ads and sites.google.com URLs. Red Canary observed Claude-branded lures in April 2026 delivering ACR Stealer through fake GitLab pages.
NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
A Go botnet called NadMesh is targeting exposed AI services including ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio to harvest AWS keys, Kubernetes tokens, and cloud credentials. The operator's dashboard claims 3,811 unique AWS keys captured. QiAnXin's XLab published research showing the botnet uses Shodan to populate scan queues with AI workflow tools that teams deploy quickly without firewall hardening. The malware exfiltrates cloud keys from environment variables, k8s service account tokens, and contents of ~/.aws/config, .env, and ~/.docker/config.json files. The controller prioritizes MCP (Model Context Protocol) exploitation, specifically targeting tools/call to execute_command via JSON-RPC. However, XLab's sensor data shows 30% of exploit traffic targets docker_containers_api_rce and 22% targets jenkins_scripttext_rce, indicating the botnet still relies heavily on traditional vectors despite the AI targeting. The scanning system resamples successful subnets every 5 minutes and blacklists targets that absorb 10 deployment attempts without results to evade honeypots. Five build versions run concurrently.
OpenSSL HollowByte Flaw Freezes Server Memory (CVE-2025-66199, CVE-2026-34183)
OpenSSL shipped patches in June with no CVE, no advisory, and no changelog entry for HollowByte, a denial-of-service vulnerability that allows an attacker to send 11-byte TLS handshake headers claiming up to 131 KB message bodies that never arrive. Unpatched OpenSSL servers allocate memory based on the claimed size before validating the message, then wait indefinitely for the body. On glibc systems, the memory never returns even after the connection drops because the allocator holds small and medium chunks for reuse rather than releasing them to the kernel. The attack varies claimed sizes on each connection to prevent allocator reuse, causing heap fragmentation. Okta's Red Team testing showed a 1 GB server reached OOM-kill with 547 MB frozen, and a 16 GB server lost 25% of memory without crossing connection limits. Fixed releases are OpenSSL 4.0.1, 3.6.3, 3.5.7, 3.4.6, and 3.0.21 (all dated June 9). OpenSSL's security team classified this as a "bug or hardening" fix, not a vulnerability, so no CVE was assigned and no advisory was published. Standard connection-limiting defenses do not stop HollowByte because the memory fragmentation persists after connections close.
Starland RAT Delivered via Trojanized Remote Desktop Tools
A Russian threat actor tracked as UAT-11795 is distributing trojanized installers for WebEx, Zoom, MobaXterm, DBeaver, and FaceIT to deploy the Starland remote access trojan. Active since June 2025, the actor targets users in the United States, Germany, Romania, and Venezuela. The infection chain starts with a malicious HTA file that retrieves an NSIS installer hiding a Python loader disguised as a text document. The loader modifies the Windows Registry for persistence before decrypting and deploying Starland. The malware verifies it is not running in a sandbox, creates scheduled tasks, attempts privilege escalation, and scans for browser data, cryptocurrency wallets, antivirus products, and Active Directory infrastructure including domain structure and controllers. Starland can capture desktop screenshots, execute arbitrary shell commands, and fetch secondary payloads. Depending on system architecture, the malware injects 64-bit shellcode to deliver CastleStealer or 32-bit shellcode to deploy Remcos RAT. The operators integrate redundant C2 communications to maintain persistent access.
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
Expel attributed the April 2026 DigiCert security incident to CylindricalCanine, a sub-group of the Chinese cybercrime group GoldenEyeDog (also tracked as APT-Q-27, Dragon Breath, and Miuuti Group). The threat actor used a modified Gh0st RAT variant called Golden Gh0st RAT to access a DigiCert support member's device via a malicious ZIP file disguised as a customer screenshot sent through a support chat channel. The attacker used a support portal function to intercept initialization codes for approved EV Code Signing certificate orders across customer accounts. DigiCert revoked 60 certificates across four CAs, with 27 confirmed used to sign malware. The group primarily targets gambling, gaming, and finance organizations in the Asia-Pacific region. The malware is delivered through NSIS installers masquerading as legitimate programs like Google Chrome and Microsoft Teams, and more recently through suspicious links sent to Web3 customer support staff.
Russians Sanctioned for Bulletproof Hosting Enabling Ransomware
The U.S. unsealed indictments against three Russian nationals (Aleksandr Volosovik, Yulia Pankova, and Kirill Zatolokin) for operating bulletproof hosting services that facilitated over $62 million in ransomware damages. The defendants allegedly managed "Media Land" and "ML Cloud," providing infrastructure to LockBit, Play, and BlackSuit ransomware groups. The hosting platforms actively shielded cybercriminals by ignoring victim complaints and disregarding law enforcement takedown requests. The U.S. Treasury also sanctioned First VPN Service (1VPNS) and its administrator Dmytro Rashevskyi for supplying VPN infrastructure that helped ransomware operators obscure identities and manage stolen data. The service ignored abuse complaints and maintained zero user logs. Yegeniy Silayev was sanctioned for developing cryptors to conceal malware. The State Department is offering a $10 million reward for information regarding foreign government links to these hosting providers.
Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker
Armenia has detained Aleksandr Ermakov since June 28 at Yerevan's Zvartnots airport on a U.S. extradition request for a REvil ransomware suspect with the same name. The man's lawyers argue Washington has the wrong person. The U.S. wants Aleksandr Gennadievich Ermakov, sanctioned by Australia, the US, and UK in January 2024 for stealing 9.7 million records from Medibank Private and dumping some on the dark web. That Ermakov is serving a two-year Russian sentence barring him from leaving Russia, according to TASS. The detained man is Aleksandr Yuryevich Ermakov from Omsk, a former prison-service lawyer who does not speak English. Russian passports carry a patronymic (middle name derived from father's name) that distinguishes individuals with identical given names and surnames. The U.S. charging document accuses the suspect of participating in Sodinokibi/REvil attacks from April 2019 to July 12, 2021. The Interpol notice built on the charging document identifies the suspect as one of REvil's administrators with proceeds over $13.7 million. Medibank was hacked in October 2022, fifteen months after the charging window closed. The defense's theory is that U.S. paperwork carried only a given name and surname without the patronymic, and an automated check matched the wrong person. Armenia is holding the man on a 30-day Interpol detention order while Moscow requests consular access.
OtterCookie Malware Hidden in SVG Flag Images Targets Developers
North Korean threat actors linked to Contagious Interview are using steganography in SVG image files to conceal OtterCookie malware. Elastic Security Labs tracked the campaign (REF9403) after attackers targeted members of its community Slack workspace with fake job offers in late May 2026. A user named Maxwell posted on the #jobs channel seeking a developer for an e-commerce platform upgrade using Next.js v14, NestJS, PostgreSQL, and Auth.js. Interested candidates were directed to complete a coding assessment from a trojanized GitHub repository. The repositories contain functional code but embed malicious payloads in base64 fragments inside HTML comments across SVG flag images (AE.svg, AF.svg, etc.). A JavaScript file (serverValidation.js) assembles the fragments and executes the payload on each server boot. OtterCookie has four modules: browser and crypto wallet credential harvesting, file collection matching specific extensions, Socket.IO-based RAT for remote control, and clipboard stealing. The malware targets AI coding tool extensions including .claude, .cursor, .gemini, .windsurf, .pearai, and .llama configuration files.
Microsoft at Black Hat USA 2026: Supply Chain Attack Focus
Microsoft Security will present research at Black Hat USA 2026 (August 4-6, Mandalay Bay, Las Vegas) focusing on supply chain attacks and AI-powered threats. David Weston's keynote "The End of Rare: Defending When Offense Is Cheap" examines security operations when offensive capability becomes easier to access, automate, and scale. Aarti Borkar and Tanmay Ganacharya will present "Poisoned at the Source: Inside the Hunt for Supply Chain Attacks" detailing Microsoft Threat Intelligence's investigations into ongoing npm supply chain campaigns targeting software ecosystems and developer workflows. The sessions frame the challenge that when offensive capability scales easily, security teams must understand trust paths threat actors can abuse before attacks occur. Microsoft will showcase Defender Experts Threat Intelligence and Defender Experts MDR with third-party and multicloud coverage at booth 2144.
White House Launches Gold Eagle Vulnerability Clearinghouse
The White House launched the Gold Eagle vulnerability coordination clearinghouse on July 14, 2026, to coordinate vulnerability response in anticipation of large language models fundamentally changing the vulnerability landscape. Gold Eagle is built on VINCE (Vulnerability Information and Coordination Environment) from Carnegie Mellon University's Software Engineering Institute. The clearinghouse coordinates and deconflicts scanning for software vulnerabilities, validates discoveries, and prioritizes remediation and patch distribution across open-source software partners and critical infrastructure companies. The initiative is voluntary collaboration with the AI industry and aims to leverage frontier AI capabilities to deliver faster exploit detection and prioritized threat information across sectors. Details of the ultimate implementation remain unclear. Security experts note that the cross-sector vulnerability coordination gap is real, as the KEV catalog, NVD, and ISACs do not address cross-sector prioritization. Critics describe Gold Eagle as "a coordination process wearing a technical system's clothes" rather than new infrastructure.
Google Bets 'Agentic Defense' Strategy Can Outpace Attackers
Google Cloud integrated Wiz capabilities into a new "agentic defense" platform to automate threat detection, investigation, and remediation. Following its $32 billion acquisition of Wiz, Google is positioning the platform as a shift from human-led to AI-led cyber defense. Francis deSouza, Google Cloud's COO and president of security products, cited the M-Trends 2026 report showing the average time from initial breach to handoff of access to another threat actor collapsed from 8 hours three years ago to 22 seconds. Google integrated Wiz attack surface management with Google Threat Intelligence, so Wiz ingests posture and workload telemetry from Google Cloud, enriches detections with threat intelligence, and pushes prioritized exposure data into SecOps playbooks. The integration builds on Google's AI Threat Defense launched in May, combining Gemini reasoning with Wiz's scanning, simulation, and remediation. Google claims it is the only security company with a chips-to-code-to-cloud stack including its own AI infrastructure, processors with GPUs, Gemini models, and now Wiz's platform to deliver agents.
European Commission Orders Google to Open Android to Rival AI Assistants
The European Commission on July 16 ordered Google to give rival AI assistants the same access to Android sensors and system features that Gemini has, including camera, microphone, screen contents, wake word detection with the display off, and background app automation. Google must ship the changes in Android 18 by August 1, 2027 at the latest. The decision under the Digital Markets Act opens 11 operating system features, with five requiring certification (centralized data access via AppSearch, context-aware intelligence, structured on-device integration via App Actions, screen automation via Computer Control, and system integration for settings/media/screenshots/notifications/power). Six features carry no certification requirement at all and are open to all third parties: ambient data (continuous microphone, camera, screen, location, and sensor access in the background), always-on hotword detection, long-press invocation, system-level on-device models, third-party model implementation, and background execution. Google must establish a Qualified AI Assistant Programme allowing third-party Trusted Certification Authorities to certify assistants free of charge. Google writes the TCA programme's terms and decides who gets approved as a certifier, on terms that must be reasonable and non-discriminatory and cleared with the Commission two months before changes.
Seven Malicious Vite npm Packages Use Blockchain C2
Checkmarx discovered seven malicious npm packages (codenamed ViteVenom) targeting the Vite frontend tooling ecosystem using blockchain-based command-and-control infrastructure. The campaign is an expansion of ChainVeil, which uses a four-tier blockchain C2 spanning Tron, Aptos, and Binance Smart Chain to deliver a RAT with reverse shell, credential harvesting, file exfiltration, and backdoor capabilities. The packages, published between June 29 and July 3, 2026, use scoped names to impersonate the "@vitejs/*" namespace: @uw010010/vite-tree (1070 downloads), @vite-tab/tab (289), @vite-ln/build-ts (252), @vite-mcp/vite-type (239), @vite-pro/vite-ui (200), @vitets/vite-ts (194), and @vite-ts/vite-ui (176). The malicious code executes at import time, not install time, limiting endpoint security detections. The loader queries the Tron blockchain for the latest transaction from the attacker's wallet, decodes the transaction data to obtain a BSC transaction hash, queries BSC to extract the encrypted payload, and decrypts using a hard-coded key. The blockchain infrastructure is nearly impossible to take down because payload pointers are stored as transaction data on public blockchains rather than on domains that can be seized. The packages share tier-2 infrastructure with ChainVeil including the same Tron wallet and Aptos account addresses.
GoSerpent Malware Targets Southeast Asian Governments
Kaspersky discovered GoSerpent, a Go-based malware targeting government and diplomatic entities in Southeast Asia since late 2025 for long-term access and intelligence gathering. GoSerpent contacts an external server to deploy secondary payloads focused on sensitive data collection and credential dumping. In May 2026, the threat actors returned with evolved tools including a new Stowaway RAT, proxy tool, and ThumbcacheService for exfiltrating data collected over months through network shares. The malware receives encrypted and Base64-encoded command-line arguments containing the C2 address and communication password. Once decrypted, the backdoor connects to the C2 over an encrypted connection using the SHA256 hash of the communication password as the encryption key. GoSerpent can establish SOCKS5 proxy servers to route traffic through compromised hosts, deploy additional tools including ThumbcacheService (file collection DLL), Mimikatz (credential dumping), and QuarksDumpLocalHash (local account password hash extraction). The threat actors use McMx RAT (a lightweight Go-based proxy and RAT), Stowaway (proxy and RAT with SSH-based tunneling), TmcLoader (C++ loader), and TmcPayload (data exfiltration tool). Earlier variants of the malware have been used since 2021 against Southeast Asian victims.
Spirals Ransomware Targets IT Firm
A newly discovered ransomware variant named Spirals was deployed in an attack against an IT services firm in Asia. SecurityWeek's roundup mentions the discovery but provides no technical details on capabilities, encryption methods, or attribution.
CrashStealer macOS Malware Masquerades as Crash Reporter
Security researchers uncovered CrashStealer, a novel macOS information stealer written in C++ that disguises itself as a legitimate crash reporting application. The malware exfiltrates sensitive user data, credentials, and system information from compromised Apple devices. Its stealthy design evades standard operating system defenses by mimicking native password prompts, making it difficult for users to distinguish malicious requests from legitimate system dialogs.
Steam Games Used to Drain Crypto Wallets
The FBI arrested a Florida man accused of uploading fake video games containing malware to Steam, the popular PC games platform. Once victims downloaded and installed the games, the malware infected computers, stole passwords and other data, and drained cryptocurrency wallets. The case highlights the risk of malware distribution through trusted software platforms.
CoreDNS Remote DoS Vulnerabilities
Microsoft published two CVEs for CoreDNS remote denial-of-service vulnerabilities. CVE-2026-62309 is a proxyproto plugin panic on PPv2 datagram with non-UDP transport, allowing a single 28-byte packet to crash CoreDNS remotely. CVE-2026-62299 is a rewrite-plugin EDNS0 response-revert nil-pointer panic when a downstream plugin returns a response with no OPT record. Both have low EPSS scores (0.4% and 0.3%) and Microsoft provided only minimal details.
Squid Proxy Vulnerabilities
Microsoft published two CVEs for Squid proxy. CVE-2026-47729 is a memory disclosure vulnerability in the FTP gateway with an EPSS score of 1.9%. CVE-2026-50012 is a memory corruption flaw in cache_digest reply handling with an EPSS score of 2.3%. Both vulnerabilities affect Squid proxy servers but Microsoft provided no technical details.
Chromium Vulnerabilities in Microsoft Edge
Microsoft published two CVE records for Chromium vulnerabilities affecting Microsoft Edge. CVE-2026-15904 is a use-after-free vulnerability in Ozone. CVE-2026-15903 is an out-of-bounds read and write in V8. Both were assigned by Chrome and addressed in Chromium updates that Microsoft Edge ingests.
Joomla Extension Vulnerabilities
Attackers are exploiting vulnerabilities in iCagenda and Balbooa Forms extensions with perfect 10.0 CVSS scores on Joomla websites. The flaws impact the open-source CMS that powers a million sites worldwide. The Register's roundup mentions active exploitation but the extracted content provides no CVE numbers or technical details.
Today's stories show a clear pattern of attackers following trust. Inc ransomware exploits VPN appliances that organizations already trust for remote access. WordPress's wp2shell chain abuses the REST API batch endpoint to bypass validation. DigiCert's breach leveraged support staff access to intercept code-signing certificates. North Korean actors hide malware in functional code repositories developers trust. The blockchain-based npm supply chain attacks replace domain-based C2 with immutable transaction data defenders cannot seize. Across supply chain, VPN gateways, and developer tooling, attackers are targeting the software, services, and workflows organizations already depend on rather than looking for vulnerable systems. The shift from 8 hours to 22 seconds for initial access handoff means human-led detection and response cannot keep pace with machine-speed attacks.