← Carolina Clear Tech

Cyber Threat Brief

2026-07-25

Listen to this brief (17:57)

Download MP3
Show Notes

Show Notes - 2026-07-25

Stories Covered

CVEs Referenced

CVE-2025-29827, CVE-2025-40947, CVE-2025-40948, CVE-2025-40949, CVE-2025-66376, CVE-2026-12569, CVE-2026-16804, CVE-2026-16807, CVE-2026-31431, CVE-2026-32191, CVE-2026-32194, CVE-2026-43284, CVE-2026-43500, CVE-2026-43503, CVE-2026-54121

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cyber Threat Brief - July 25, 2026

Today: A public exploit for Certighost (CVE-2026-54121) lets any domain user impersonate a Domain Controller and DCSync the krbtgt hash; patch AD CS now. Clop is actively exploiting PTC Windchill/FlexPLM (CVE-2026-12569) in a new data theft campaign. A GitLab memory corruption chain gives any authenticated user RCE as git on unpatched self-managed instances. An attacker deployed the Hermes AI agent in YOLO mode for autonomous post-exploitation against Thailand's Ministry of Finance, marking the first documented case of a self-directed AI agent running offensive operations unsupervised.


Critical Alerts

Certighost: AD CS Exploit Lets Domain Users Impersonate Domain Controllers (CVE-2026-54121)

Researchers published a working proof-of-concept on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine. The flaw sits in an AD CS enrollment fallback ("chase") where the CA follows requester-supplied SMB/LDAP targets without verifying they are real Domain Controllers. The resulting Kerberos credential enables DCSync to retrieve the krbtgt secret. Microsoft patched this July 14 with CVSS 8.8. EPSS is 0.008 (53rd percentile). No confirmed in-the-wild exploitation yet, but the full PoC is public. Affected: Windows Server 2012 through 2025, including Server Core editions.

Clop Targets PTC Windchill and FlexPLM (CVE-2026-12569)

Clop is exploiting a critical improper input validation vulnerability in Internet-exposed PTC Windchill and FlexPLM instances for data theft extortion. CVE-2026-12569 is in CISA KEV with a deadline of June 28 (already past). EPSS is 0.023 (81st percentile).

GitLab RCE via Jupyter Notebook Diff Chain (No CVE Assigned)

A researcher published exploit code on July 24 for a GitLab memory corruption chain affecting self-managed CE and EE, all tiers. Any authenticated user who can push to a project can achieve RCE as git by committing crafted Jupyter notebooks and opening their commit diffs. Two bugs in the Oj Ruby JSON parser (heap pointer leak via truncated key, stack overflow controlling a callback) are chained together. GitLab patched this on June 10 but listed it as a bug fix, not a security fix. There is no CVE, no CVSS, and no entry in the security-fix table.


Ransomware & Extortion

Clop's Windchill/FlexPLM Campaign

Clop continues its pattern of targeting enterprise file and data management platforms. The current campaign exploits CVE-2026-12569 in PTC Windchill and FlexPLM for data theft followed by extortion. Organizations using product lifecycle management software should treat this with the same urgency as previous Clop campaigns against MOVEit and GoAnywhere.

Stadler Rail Refuses $12M Everest Ransomware Demand

Swiss train manufacturer Stadler Rail refused a 10 million Swiss franc ($12M) extortion demand from the Everest ransomware group. Attackers breached a supplier-shared data exchange platform in mid-July and stole technical information without impacting production or IT systems. Stadler says no critical security or personal data was compromised.

Ransomware as a Defensive Barometer

Recorded Future reports 13,000 ransomware victims over the past two years across 834 unique ransomware families. The analysis highlights that ransomware success is a direct verdict on available attack paths in defensive architectures. The risk has shifted from operational disruption toward compliance and legal failure from losing protected data, as offline backup resilience has improved. Interlock's ClickFix social engineering chain (fake CAPTCHAs leading to PowerShell execution) is called out as an example of an identity-and-configuration attack path invisible to vulnerability scanning.


IOCs & Detection

HollowGraph: C2 via Microsoft 365 Calendar Events

A .NET espionage implant uses Microsoft Graph API to route C2 through M365 calendar events dated far in the future (May 2050). Commands arrive as text file attachments on hidden events; exfiltrated data is encrypted with RSA/AES-256 and uploaded the same way. A secondary DNS channel refreshes Entra ID credentials. Observed targeting an Israeli organization June-July 2026. Structural similarities to the Cavern backdoor framework used by Iranian state-sponsored groups, but no definitive attribution.

Dolphin X Infostealer with AI Behavioral Profiler

Varonis discovered an infostealer called Dolphin X that uses an AI behavioral profiler to score and prioritize infected users. It targets 300+ applications: browser passwords, cryptocurrency wallets, SSH keys, cloud tokens. A compromised developer machine could provide access to production environments.

Golden Chickens / TAG-195: Four New Malware Families

TAG-195 (Golden Chickens/Venom Spider) released TinyEgg (lightweight backdoor), ChonkyChicken (full-featured implant with Chrome DevTools Protocol session hijacking), a modular variant with 14 on-demand plugins, and ChromEggscalator (Chrome credential theft). Delivery is via ClickFix-style social engineering. The modular variant supports keylogging, screen capture, audio capture, network recon, clipboard capture, and persistence management.


Business & Infrastructure Threats

AI Agent Used for Autonomous Post-Exploitation at Thai Ministry of Finance

An attacker installed the Hermes AI agent (open-source, from Nous Research) on a rented server in YOLO mode (no human approval required) and pointed it at Thailand's Ministry of Finance. The agent autonomously ran LinPEAS, hunted privilege escalation paths, crawled file systems, and accessed personnel records dating to 2012. The operator provided customized scripts targeting four 2026 Linux kernel flaws: Copy Fail (CVE-2026-31431, CISA KEV, EPSS 0.945), Dirty Frag (CVE-2026-43284, EPSS 0.932; CVE-2026-43500, EPSS 0.929), and DirtyClone (CVE-2026-43503). The operator's logs, 585 files, and 470 MB of tooling were left on an open web server. This is the first documented case of an AI agent running offensive operations without per-command human approval.

Botnets Approaching 60 Million Victim IPs

Lumen Black Lotus Labs reports botnet populations approaching 60 million victim IPs globally, with 25% in the US. Ten distinct botnets each control about 1 million active victims daily. IPIDEA recovered to half-strength within hours of a January disruption and has since surpassed its pre-disruption size at 10 million IPs. Over 30 malicious proxy botnet clusters are tracked, most exceeding 100,000 daily victims. Residential proxy networks enable cybercriminals to blend with legitimate traffic.

ChatGPT AgentForger: Rogue Workspace Agents via Phishing Link

A CSRF vulnerability in OpenAI's ChatGPT Workspace Agent Builder allowed a single phishing link to create, authorize, and deploy an autonomous AI agent inside a victim's organization. The agent could attach all existing connectors (Outlook, Gmail, Slack, Teams), set permissions to "Never ask," schedule hourly execution, and exfiltrate data via email. Fixed by OpenAI on June 8, 2026. Agent Builder is being deprecated November 30, 2026.

BlueNoroff Zoom/Teams Phishing Kit with Wallet Profiling

North Korean BlueNoroff operates an active phishing kit impersonating Zoom and Microsoft Teams. The kit hijacks Telegram accounts of trusted contacts in the crypto space, sends Calendly meeting links leading to fake video calls, captures webcam streams via WebRTC, fingerprints cryptocurrency wallets before delivering ClickFix payloads, and uses AI-generated headshots composited over real body movements from previous meetings. Compatible with Windows and macOS.


Windows / AD Security

Azure Automation Cross-Tenant Identity Takeover (CVE-2025-29827)

A CVSS 9.9 vulnerability in Azure Automation allowed cross-tenant identity takeover through a default-public configuration combined with two code-level bugs. An attacker with their own Azure Automation account could breach the trust boundary and assume another tenant's automation identity, enabling creation/modification of automation scripts, access to credentials, and resource manipulation across cloud workloads. Microsoft changed the default setting; no known exploitation. Researcher will demo at Black Hat USA.

Kratos PhaaS Dismantled (Operation Olympus Blade)

German and US law enforcement seized 200+ servers and arrested the developer of the Kratos phishing-as-a-service platform in Indonesia. Kratos served 1,800+ cybercriminals launching 15,000 phishing campaigns monthly since late 2024, generating convincing Microsoft authentication pages with AitM session cookie interception bypassing MFA. The underlying toolkit code remains in operators' hands.


General Security News

Bing Images: SVG Command Injection as SYSTEM (CVE-2026-32194, CVE-2026-32191)

XBOW found that crafted SVGs submitted to Bing's image search executed commands as NT AUTHORITY\SYSTEM on Windows workers and root on Linux workers. Both CVEs rated 9.8. Microsoft fixed server-side before March advisories. No customer action needed, but the bug class matters: if your stack pipes uploads through ImageMagick or similar with delegates enabled, attacker-controlled content can reach shell execution. Disable delegates, restrict accepted formats, and isolate processing workers.

Siemens ROX II OT Switch Zero-Day Chain

Unit 42 identified three zero-days in Siemens ROX II switches (CVE-2025-40947, CVE-2025-40948, CVE-2025-40949) that chain for persistent root access: arbitrary file disclosure, command injection privilege escalation, and web management task scheduler code execution surviving reboots.

T-Mobile Violated WA Breach Notification Law

A King County Superior Court judge ruled T-Mobile failed to properly notify customers of the breach affecting 40 million people whose data was stolen and sold on the dark web.

432 Linux Kernel CVEs Published in 24 Hours

An unprecedented single-day drop of 432 Linux kernel CVEs requires security teams to triage affected systems and evaluate patching priorities rapidly.


Patch Priority


Vulnerability Disclosures

Chromium CVE-2026-16804 and CVE-2026-16807

Two Chromium vulnerabilities: a use-after-free in Input and an out-of-bounds write in Codecs. Microsoft Edge inherits both via Chromium ingestion. EPSS scores are low (0.002, 16th percentile). Update browsers to latest stable.

Russian APT Laundry Bear Exploiting Zimbra (CVE-2025-66376)

CISA and international partners warn that Russian state-sponsored group Laundry Bear is actively exploiting a patched Zimbra flaw. CISA KEV deadline was April 1. EPSS is 0.216 (97th percentile).

Vatican Click to Pray App IDOR (700K+ Users Exposed)

An insecure direct object reference in the Vatican's Click to Pray app exposes names, email addresses, country, and account status for 700K+ users via an unauthenticated API endpoint. Still unpatched as of publication.


Trends & Context

AI agents are crossing from defensive tools into offensive operations. The Thai Ministry of Finance intrusion marks the first documented case of an autonomous AI agent conducting post-exploitation without per-command human approval. Separately, ChatGPT's AgentForger flaw and the OpenAI/Hugging Face escape incident reinforce that AI agent security is a systemic issue across the industry. The Kratos takedown and botnet research both highlight the same pattern: cybercrime infrastructure rebuilds faster than it can be disrupted, and toolkit code outlives platform seizures.