← Carolina Clear Tech

Cyber Threat Brief

2026-07-27

Listen to this brief (11:09)

Download MP3
Show Notes

Show Notes - 2026-07-27

Stories Covered

CVEs Referenced

CVE-2024-14040, CVE-2026-16461, CVE-2026-16723, CVE-2026-64530, CVE-2026-8450

Indicators of Compromise

Domains: hypersnet[.]com., hypersnet[.]com

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Today: A Fastjson remote code execution bug (CVE-2026-16723) is under active exploitation against banks and government networks, and Alibaba still has not shipped a patch. Two ransomware groups posted 13 new victim claims in the last 48 hours, including Microsoft, Zenith Bank, and the UK Department for Education. TELESHIM, a new backdoor abusing Telegram for command and control, is hitting Middle East government targets. Healthcare breach disclosures continue: MCBS confirms 1.2 million affected, DentaQuest more than 23 million.

Critical Alerts

Fastjson RCE Under Active Exploitation, No Patch Available (CVE-2026-16723)

Threat actors are exploiting an unauthenticated remote code execution vulnerability in Alibaba's Fastjson, one of the most widely used JSON libraries in the Java ecosystem. Exploitation began the day after FearsOff publicly disclosed the flaw, and Imperva and ThreatBook have both documented attacks in the wild. The bug works in Fastjson's default configuration and in its most common deployment model, as a Spring Boot executable component. Imperva has detected exploitation attempts against customers across finance, healthcare, computing, and retail, with most targets in the US. The flaw affects only the older 1.x branch; the current 2.x branch is not vulnerable. Fastjson 1.2.83, the final 1.x release, shipped in May 2022, but the library remains embedded in bank and government software supply chains. Alibaba has not released a patch and is instead urging developers to enable the library's SafeMode setting or migrate to 2.x.

Ransomware Claims (Last 48h)

13 claims tracked across 2 groups in the last 48 hours.

Group Victim Sector Country
Exfilsquad Microsoft Technology US
Exfilsquad Zenith Bank Plc Banking / Financial Services Nigeria
Exfilsquad Allstate Insurance US
Exfilsquad Frontier Airlines Airlines / Transportation US
Exfilsquad UK Department for Education Government / Education UK
Exfilsquad TaylorMade & Sun Day Red Golf Retail / Consumer Goods US
Exfilsquad Police National Legal Database Government / Law Enforcement UK
Exfilsquad District of Columbia Public Schools Government / Education US
Exfilsquad Newcastle University Education UK
Exfilsquad Viavi Solutions Technology / Manufacturing US
Global Secret Group Novum Energy Energy / Fuel Retail US
Global Secret Group Uniview Technologies Manufacturing / Electronics China
Global Secret Group OFS Furniture / Manufacturing US

These are unverified claims from ransomware leak sites, not confirmed breaches. Exfilsquad's posts for Microsoft, Zenith Bank, Frontier Airlines, Allstate, and TaylorMade & Sun Day Red Golf all carry an August 5, 2026 contact deadline, consistent with the group's standard extortion pattern.

IOCs & Detection

TELESHIM Backdoor Abuses Telegram C2 in Middle East Government Attacks

Zscaler ThreatLabz identified a multi-stage campaign, attributed with moderate confidence to an East Asia-linked actor, deploying three previously unreported malware families against Middle East government entities. The chain begins with an ISO file containing a legitimate executable, RegSchdTask.exe, which sideloads a rogue DLL, AsTaskSched.dll, to install TELESHIM, a 32-bit Windows backdoor that uses the Telegram API for command and control to blend in with normal traffic. TELESHIM retrieves further payloads including GoProAlertService.exe and pthreadVC2.dll, the latter acting as a reflective loader (MIXEDKEY) that decrypts and executes an encrypted payload file. A second implant, BINDCLOAK, is a 64-bit C++ backdoor contacting an external server at cert.hypersnet[.]com. All payloads use heavy obfuscation including string encryption, control flow flattening, and mixed boolean arithmetic, plus virtualization-detection checks (hypervisor detection via CPUID, RAM speed checks via WMI) to evade sandbox analysis. Observed post-compromise activity ran between July 7 and July 9, 2026, with C2 commands executed only between 4 a.m. and 12 p.m. UTC.

Business & Infrastructure Threats

GitHub Adds 3-Day Dependabot Cooldown; PyPI to Follow With 14-Day Freeze

GitHub has added a cooldown mechanism to Dependabot that waits at least three days after a package version is published before opening a pull request to adopt it, aimed at reducing exposure to short-lived poisoned package versions that get pulled quickly after publication but still spread through automated dependency bots in the meantime. The cooldown applies only to routine version updates; security updates still trigger an immediate alert and pull request. Similar cooldown controls have already shipped across VS Code, Ruby, Bun, npm, pnpm, and Yarn. Separately, the Python Package Index plans to block maintainers from adding new files to a package release more than 14 days after publication, intended to stop attackers who compromise publishing tokens from poisoning old, trusted releases.

Scanners Target ESAFENET CDG Document Management Default Passwords

SANS ISC is tracking active scanning against ESAFENET CDG 3, a Chinese-market document management and data leakage prevention product, targeting well-known default credentials shipped with the product (secadmin / Est@Spc820). The password meets typical complexity checks (length, mixed case, special characters, numbers) but is a documented default that ships with the product and appears in public exploit tooling, including a 2023 Nuclei template. CDG has previously shown SQL injection and XSS vulnerabilities as well.

General Security News

MCBS Data Breach Affects 1.2 Million Individuals

Atlanta-based medical billing company MCBS (Medical Computer Business Services) disclosed that attackers had access to its systems between September 22 and September 26, 2025, potentially stealing names, addresses, Social Security numbers, dates of birth, health insurance information, and medical information. HHS's breach tracker lists 1,261,464 affected individuals across seven named healthcare organizations. The PEAR ransomware group claimed the attack, alleging theft of more than 3 TB of data including financials, HR records, partner and vendor data, and patient PII/PHI. PEAR has also claimed the Motility Software Solutions breach (766,000 people) and the Tri-Century Eye Care breach (200,000 people).

DentaQuest Data Breach Potentially Impacts Over 23 Million People

Dental insurer DentaQuest disclosed that hackers stole personal and dental health information from its network in May 2026, potentially affecting more than 23 million people. Details on the specific data types and attack vector remain limited.

Tribeca Film Festival Data Leak Exposes Celebrity Records

Researcher Jeremiah Fowler found a publicly accessible, unencrypted database associated with the Tribeca Film Festival, along with three additional unsecured databases, including a "development" database with more than 200,000 records. The exposure reportedly includes data tied to A-list directors, actors, and celebrities.

AnMed Health Reports Phone and Internet Outage Across All Hospital Locations

AnMed, a not-for-profit health system serving Upstate South Carolina and northeast Georgia with four hospitals, is experiencing a phone and internet outage affecting all locations. Emergency rooms remain open. The cause has not been confirmed as a cyberattack as of this writing.

Patch Priority

Vulnerability Disclosures

HTTP::Daemon Command Injection (CVE-2026-8450)

Versions of the Perl HTTP::Daemon module before 6.17 allow OS command injection through send_file(). EPSS is 0.014 (70th percentile), notably higher than the other CVEs disclosed today.

Low-EPSS Kernel and Network CVEs

Three additional low-priority CVEs were disclosed today with minimal exploitation likelihood: CVE-2024-14040 (net: nexthop weight handling, EPSS 4th percentile), CVE-2026-64530 (net/sched: cls_api TC_ACT_CONSUMED handling, EPSS 7th percentile), and CVE-2026-16461 (rpcbind stack buffer overflow in rpcinfo short-mode formatting, EPSS 14th percentile). None currently show signs of active exploitation.

Trends & Context

Today's stories reinforce that unpatched, deeply embedded libraries remain the highest-value targets: Fastjson 1.x has no fix and is still running inside bank and government Java stacks four years after its last release. Supply chain defenses continue maturing at the ecosystem level, with GitHub, PyPI, and other registries adding time-delay cooldowns to blunt fast-moving poisoned-package attacks, though this does nothing against dormant backdoors or compromised build systems. Healthcare remains the sector absorbing the largest breach disclosures by individual count, with MCBS and DentaQuest together accounting for more than 24 million affected people this week alone.