<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>ctipilot.ch · Finance</title><link>https://ctipilot.ch/</link><atom:link href="https://ctipilot.ch/feed-finance.xml" rel="self" type="application/rss+xml"/><description>Items affecting financial services, banks, insurance, fintech.</description><language>en</language><lastBuildDate>Sat, 18 Jul 2026 04:35:00 +0000</lastBuildDate><item><title>Broadcom patches a pre-auth authentication bypass on the VMware Avi Load Balancer control plane (CVE-2026-47865), reported by NATO NCSC</title><link>https://ctipilot.ch/entries/2026-07-18/vmware-avi-load-balancer-cve-2026-47865-auth-bypass/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-18/vmware-avi-load-balancer-cve-2026-47865-auth-bypass/</guid><pubDate>Sat, 18 Jul 2026 04:35:00 +0000</pubDate><dc:date>2026-07-18T04:35:00Z</dc:date><category>vulnerabilities</category><category>auth-bypass</category><category>pre-auth</category><category>no-patch</category><category>cloud</category><category>global</category><category>europe</category><category>patch-available</category><category>CVE-2026-47865</category><category>CVE-2026-47867</category><category>CVE-2026-47871</category><category>CVE-2026-47868</category><category>CVE-2026-47866</category><category>CVE-2026-47869</category><category>CVE-2026-47870</category><description><![CDATA[<p>Broadcom advisory VMSA-2026-0005 (2026-07-14) discloses seven flaws in VMware Avi Load Balancer (formerly NSX Advanced Load Balancer); the headline flaw CVE-2026-47865 (CVSS 9.8) lets an unauthenticated remote attacker reach the Avi Controller control plane by bypassing authentication entirely, with no workaround available. Affected: 22.1.1–22.1.7, 30.1.1–30.2.6, 31.1.1–31.2.2 and 32.1.1; fixed in 32.1.2, 31.2.2-2p3 and 30.2.7. No in-the-wild exploitation is reported, but the bug was reported by NATO NCSC and the control plane governs traffic routing and TLS termination for whatever sits behind the load balancer.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-18/vmware-avi-load-balancer-cve-2026-47865-auth-bypass" data-tags="vulnerabilities auth-bypass pre-auth no-patch cloud" data-regions="global europe" data-kind="vulnerability" data-priority="high" data-discovered="2026-07-18T04:35:00Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-47865/">CVE-2026-47865 +6</a><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 2: Probably true"><span class="k">NATO</span>A2</span></div><h3 class="f-h" id="vmware-avi-load-balancer-cve-2026-47865-auth-bypass"><a href="https://ctipilot.ch/entries/2026-07-18/vmware-avi-load-balancer-cve-2026-47865-auth-bypass/">CVE-2026-47865 — VMware Avi Load Balancer: unauthenticated control-plane authentication bypass (CVSS 9.8), no workaround</a></h3><p>Broadcom&#39;s VMSA-2026-0005 (2026-07-14, last updated 2026-07-15) patches seven vulnerabilities in VMware Avi Load Balancer — the load-balancing/application-delivery product formerly sold as NSX Advanced Load Balancer and widely deployed in enterprise and government data-centre fabric across Europe. The load-bearing flaw, <strong>CVE-2026-47865</strong> (CVSS 9.8), is an authentication bypass on the Avi Controller: &quot;a malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism&quot; — no credentials, no user interaction (<a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926" target="_blank" rel="noopener noreferrer">Broadcom PSIRT, 2026-07-14</a>). The advisory ships six companion flaws that require a prior foothold: two high-privilege remote code-execution bugs (CVE-2026-47867, CVE-2026-47869, both CVSS 8.7, PR:H), a low-privilege authenticated directory traversal (CVE-2026-47871, CVSS 8.8), an authorization bypass (CVE-2026-47866, CVSS 8.3), a local-to-root privilege escalation (CVE-2026-47868, CVSS 7.8) and a further privilege escalation (CVE-2026-47870, CVSS 7.1). Broadcom states no workarounds exist (<a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926" target="_blank" rel="noopener noreferrer">Broadcom PSIRT, 2026-07-14</a>); the German trade press summarised it as attackers being able to bypass authentication and authorization (<a href="https://www.heise.de/news/VMware-Avi-Load-Balancer-Kritische-Luecke-erlaubt-Umgehung-von-Anmeldung-11368661.html" target="_blank" rel="noopener noreferrer">heise Security, 2026-07-17</a>).</p>
<p>No in-the-wild exploitation has been reported, but two facts raise this above the routine patch cycle: the reporter is the NATO NCSC (a direct constituency-provenance signal), and there is no mitigation short of upgrading. Because the Avi Controller is the management and orchestration plane for the load-balancing fabric, an unauthenticated bypass there is a direct path to reconfiguring traffic routing and TLS termination for every service behind the load balancer — an interception and traffic-manipulation position, not merely appliance compromise.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">Upgrade the Avi Controller to a fixed release — 32.1.2 (recommended), 31.2.2-2p3 or 30.2.7; the 22.1.x branch must move to at least 30.2.7. Because no workaround exists, until the upgrade lands restrict Controller management-plane reachability to trusted management VLANs/jump hosts and treat any exposure of the Avi Controller to broad or untrusted network segments as the finding in its own right. Detection concept, telemetry-class first: Avi Controller admin/API authentication logs showing control-plane session establishment or API calls with no preceding successful login event, particularly from source ranges outside the management network.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism.</p><figcaption class="entry-cite__attr"><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926" target="_blank" rel="noopener noreferrer">Broadcom / VMware PSIRT (VMSA-2026-0005)</a> <span class="entry-cite__date mono">2026-07-14</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>18 Jul 04:35Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-18/vmware-avi-load-balancer-cve-2026-47865-auth-bypass/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926" target="_blank" rel="noopener noreferrer">Broadcom / VMware PSIRT (VMSA-2026-0005)</a> · <a href="https://www.heise.de/news/VMware-Avi-Load-Balancer-Kritische-Luecke-erlaubt-Umgehung-von-Anmeldung-11368661.html" target="_blank" rel="noopener noreferrer">heise Security</a></div></article>]]></content:encoded></item><item><title>Volexity attributes the SonicWall SMA 1000 zero-day exploitation to UTA0533 and details the SSRF-to-root chain, on-appliance implants and LDAP credential theft</title><link>https://ctipilot.ch/entries/2026-07-18/sonicwall-sma1000-uta0533-exploitation-kill-chain/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-18/sonicwall-sma1000-uta0533-exploitation-kill-chain/</guid><pubDate>Sat, 18 Jul 2026 04:35:00 +0000</pubDate><dc:date>2026-07-18T04:35:00Z</dc:date><category>vulnerabilities</category><category>actively-exploited</category><category>zero-day</category><category>pre-auth</category><category>rce</category><category>auth-bypass</category><category>global</category><category>europe</category><category>exploited</category><category>cisa-kev</category><category>patch-available</category><category>CVE-2026-15409</category><category>CVE-2026-15410</category><description><![CDATA[<p>Volexity has reconstructed the intrusion behind the actively-exploited SonicWall SMA 1000 zero-days (CVE-2026-15409 SSRF, CVE-2026-15410 path-traversal command injection), attributing it to an actor it tracks as UTA0533 with the earliest compromise on 2026-06-22. The chain: an unauthenticated /wsproxy request tunnels to a localhost-only service for initial code execution, a hotfix-rollback path traversal escalates to root, then the actor injects a proxy (Suo5) and a Java webshell (ORANGETAIL) into the appliance&#39;s legitimate workplace process, persists via an init script, captures cleartext LDAP credentials with tcpdump, and pivots into the internal network. Stolen credentials survive patching — the hotfix alone does not remediate a pre-patch compromise.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-18/sonicwall-sma1000-uta0533-exploitation-kill-chain" data-tags="vulnerabilities actively-exploited zero-day pre-auth rce auth-bypass" data-regions="global europe" data-kind="threat" data-priority="high" data-discovered="2026-07-18T04:35:00Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-15409/">CVE-2026-15409 +1</a><span class="b exp">exploited</span><span class="b upd">update</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 1: Confirmed"><span class="k">NATO</span>B1</span></div><h3 class="f-h" id="sonicwall-sma1000-uta0533-exploitation-kill-chain"><a href="https://ctipilot.ch/entries/2026-07-18/sonicwall-sma1000-uta0533-exploitation-kill-chain/">SonicWall SMA 1000 zero-day exploitation (CVE-2026-15409/-15410): Volexity reconstructs UTA0533&#39;s full appliance-to-network kill chain</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited/">CVE-2026-15409 — SonicWall SMA1000: unauthenticated SSRF (CVSS 10.0) chained to post-auth code injection, actively exploited</a> <span class="mono muted">(2026-07-14)</span></p><p>The original entry recorded SonicWall&#39;s confirmation that CVE-2026-15409/-15410 were being exploited as zero-days and directed emergency patching. Volexity has now published the reconstructed intrusion, attributed it to an actor it tracks as <strong>UTA0533</strong>, and shown that patching alone is insufficient — the delta below is the full kill chain, the on-appliance implants, and the compromise-response guidance the terse advisory did not carry (<a href="https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/" target="_blank" rel="noopener noreferrer">Volexity, 2026-07-17</a>).</p>
<p>Volexity was engaged after suspect authentication and lateral movement were seen originating <em>from</em> SonicWall SMA 1000 appliances (models 6210/7210/8200v); the earliest sign of compromise was 2026-06-22, weeks before SonicWall&#39;s 2026-07-14 disclosure (<a href="https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/" target="_blank" rel="noopener noreferrer">Volexity, 2026-07-17</a>). SonicWall&#39;s PSIRT confirms it &quot;has investigated multiple cases indicating the active exploitation of the vulnerabilities described in this advisory&quot; (<a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008" target="_blank" rel="noopener noreferrer">SonicWall SNWLID-2026-0008, 2026-07-14</a>), and Rapid7&#39;s MDR team independently found the same two zero-days under attack (<a href="https://www.rapid7.com/blog/post/etr-rapid7-mdr-team-discovers-new-sonicwall-sma1000-zero-days-being-actively-exploited-cve-2026-15409-cve-2026-15410/" target="_blank" rel="noopener noreferrer">Rapid7, 2026-07-16</a>).</p>
<p><strong>Initial access (T1190, T1133).</strong> CVE-2026-15409 is a pre-authentication server-side request forgery in the SMA 1000 <code>/wsproxy</code> endpoint. A crafted WebSocket-upgrade request establishes a tunnel from the unauthenticated external attacker straight to services that are supposed to be reachable only on the appliance&#39;s own loopback — Volexity confirms &quot;no valid SMA session cookie was required during this process&quot; (<a href="https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/" target="_blank" rel="noopener noreferrer">Volexity, 2026-07-17</a>). Through the tunnel the actor reached the appliance&#39;s bundled CouchDB/Erlang services and a localhost-only control service; the shipped CouchDB carries hardcoded <code>admin:admin</code> credentials, and the control service&#39;s authentication password is derivable from a device UUID, so the SSRF turns both into part of the external attack surface.</p>
<p><strong>Privilege escalation (T1068).</strong> CVE-2026-15410 is a path traversal in the hotfix-rollback workflow: the <code>sysCtrl.execRemoveHotfix</code> operation builds a rollback path from caller-controlled input and hands it to <code>/usr/local/bin/remove_hotfix</code>, which then executes it. A rollback name containing directory-traversal sequences resolves outside the intended rollback directory and runs an attacker-staged script as root.</p>
<p><strong>Persistence and implants (T1055, T1505.003, T1090.003, T1037.004).</strong> With root, UTA0533 dropped a setuid helper and a Python loader Volexity calls <strong>KNUCKLEBALL</strong>, which injects two JAR archives into the appliance&#39;s legitimate <code>workplace</code> process: the open-source <strong>Suo5</strong> HTTP proxy-forwarder and a Behinder-like Java webshell Volexity calls <strong>ORANGETAIL</strong>. Persistence was established by adding a call to the loader inside the appliance&#39;s <code>workplace</code> init script, and the NGINX Unit configuration was rewritten to add routes that proxy attacker-chosen (arbitrary) request paths to the injected webshell and proxy — so hunting for a fixed URL is the wrong shape; the behaviour is unexpected route entries in the appliance&#39;s own reverse-proxy configuration.</p>
<p><strong>Credential access and lateral movement (T1040, T1059).</strong> The actor ran <code>tcpdump</code> from a script staged in the appliance&#39;s temp directory to capture unencrypted LDAP traffic (TCP 389), harvesting directory credentials off the wire (<a href="https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/" target="_blank" rel="noopener noreferrer">Volexity, 2026-07-17</a>). Rapid7&#39;s engagement observed the actor then &quot;quickly shifted to lateral movement, pivoting from the compromised appliance directly into the internal corporate network&quot; (<a href="https://www.rapid7.com/blog/post/etr-rapid7-mdr-team-discovers-new-sonicwall-sma1000-zero-days-being-actively-exploited-cve-2026-15409-cve-2026-15410/" target="_blank" rel="noopener noreferrer">Rapid7, 2026-07-16</a>). How far that onward movement reached differs across the two IR firms&#39; cases: Volexity concludes that in the appliances <em>it</em> investigated, &quot;available evidence suggests the threat actor was less successful moving laterally or gaining access to other systems&quot; (<a href="https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/" target="_blank" rel="noopener noreferrer">Volexity, 2026-07-17</a>) — so treat a foothold on the appliance as a demonstrated launch point for internal movement, but not evidence that deep lateral movement always succeeds.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">Patching to the hotfix (12.4.3-03453 / 12.5.0-02835) closes the two CVEs but does nothing about credentials already captured or implants already planted, so any appliance that was exposed and unpatched must be handled as an assume-compromise: SonicWall and both IR firms recommend re-imaging on any indicator, and resetting all account passwords and TOTP seeds. Detection concepts, telemetry-class first: in the appliance&#39;s web/access logs, unauthenticated <code>/wsproxy</code> WebSocket-upgrade requests that return a 101 protocol-upgrade status with no valid session cookie and target an internal (loopback-facing) service port; in the control-service log, hotfix-rollback operations carrying path-traversal sequences in the rollback name; on the network, LDAP binds and other authentication originating <em>from</em> the SMA appliance&#39;s own address, and any egress or lateral connection from an appliance that should only ever terminate inbound VPN sessions. <strong>Triage:</strong> an SMA 1000 legitimately proxies authenticated user sessions inbound — the discriminators are a <code>/wsproxy</code> upgrade with no session cookie reaching a loopback service, and the appliance itself <em>initiating</em> authentication or connections into the internal network, which a remote-access gateway has no benign reason to do.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">No valid SMA session cookie was required during this process.</p><figcaption class="entry-cite__attr"><a href="https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/" target="_blank" rel="noopener noreferrer">Volexity</a> <span class="entry-cite__date mono">2026-07-17</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">SonicWall PSIRT has investigated multiple cases indicating the active exploitation of the vulnerabilities described in this advisory.</p><figcaption class="entry-cite__attr"><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008" target="_blank" rel="noopener noreferrer">SonicWall PSIRT (SNWLID-2026-0008)</a> <span class="entry-cite__date mono">2026-07-14</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">the threat actors quickly shifted to lateral movement, pivoting from the compromised appliance directly into the internal corporate network</p><figcaption class="entry-cite__attr"><a href="https://www.rapid7.com/blog/post/etr-rapid7-mdr-team-discovers-new-sonicwall-sma1000-zero-days-being-actively-exploited-cve-2026-15409-cve-2026-15410/" target="_blank" rel="noopener noreferrer">Rapid7</a> <span class="entry-cite__date mono">2026-07-16</span></figcaption></figure></div><div class="prov"><span>threat</span><span>18 Jul 04:35Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-18/sonicwall-sma1000-uta0533-exploitation-kill-chain/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/" target="_blank" rel="noopener noreferrer">Volexity</a> · <a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008" target="_blank" rel="noopener noreferrer">SonicWall PSIRT (SNWLID-2026-0008)</a> · <a href="https://www.rapid7.com/blog/post/etr-rapid7-mdr-team-discovers-new-sonicwall-sma1000-zero-days-being-actively-exploited-cve-2026-15409-cve-2026-15410/" target="_blank" rel="noopener noreferrer">Rapid7</a></div></article>]]></content:encoded></item><item><title>NCSC-CH flags an unauthenticated RCE (CVSS 9.8) in Abacus ERP — reachable endpoint is the only prerequisite</title><link>https://ctipilot.ch/entries/2026-07-17/abacus-erp-unauth-rce-path-traversal-ncsc-ch/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-17/abacus-erp-unauth-rce-path-traversal-ncsc-ch/</guid><pubDate>Fri, 17 Jul 2026 04:35:00 +0000</pubDate><dc:date>2026-07-17T04:35:00Z</dc:date><category>vulnerabilities</category><category>rce</category><category>pre-auth</category><category>path-traversal</category><category>patch-available</category><category>switzerland</category><description><![CDATA[<p>Abacus Research AG shipped a hotfix on 2026-07-15 for an unauthenticated critical RCE (vendor-rated CVSS 9.8, no CVE assigned) in the server-side component of its proprietary client-server protocol, plus an authenticated path-traversal file-read flaw (CVSS 7.7) in the AbaClik / AbaClik.ai mobile-app APIs; NCSC-CH flagged both on 2026-07-16. Abacus is one of the most widely-deployed ERP/accounting/HR platforms across Swiss SMEs, associations and public-sector-adjacent organizations. Every on-prem installation — including End-of-Life V2023 builds — is affected; WebPortal/cloud-hosted deployments are not. No in-the-wild exploitation is known (found via the vendor&#39;s bug-bounty program).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-17/abacus-erp-unauth-rce-path-traversal-ncsc-ch" data-tags="vulnerabilities rce pre-auth path-traversal patch-available" data-regions="switzerland" data-kind="vulnerability" data-priority="high" data-discovered="2026-07-17T04:35:00Z"><div class="badges"><span class="b pri">HIGH</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 2: Probably true"><span class="k">NATO</span>A2</span></div><h3 class="f-h" id="abacus-erp-unauth-rce-path-traversal-ncsc-ch"><a href="https://ctipilot.ch/entries/2026-07-17/abacus-erp-unauth-rce-path-traversal-ncsc-ch/">Abacus ERP: unauthenticated RCE (CVSS 9.8, no CVE) and authenticated path traversal in a widely-deployed Swiss ERP platform — flagged by NCSC-CH</a></h3><p>Abacus Research AG (Wittenbach, SG) patched two unrelated flaws on 2026-07-15 that NCSC-CH surfaced the following day (<a href="https://security-hub.ncsc.admin.ch/#/posts/12766" target="_blank" rel="noopener noreferrer">NCSC-CH, 2026-07-16</a>). The critical one is an unauthenticated remote code execution in the server-side handler of the proprietary Abacus client-server communication protocol: &quot;the vulnerability allows remote code execution on the abacus server without user authentication,&quot; and &quot;reachable Abacus Endpoints are the only prerequisite for an attack&quot; — no credentials, no user interaction (<a href="https://security.abacus.ch/en/2026-84b5ca67-a46f-639c-5784-ce3c72065a34" target="_blank" rel="noopener noreferrer">Abacus Research AG, 2026-07-15</a>). The vendor states the flaw is not limited by license or option: every on-prem Abacus ERP installation is affected, and End-of-Life V2023-and-earlier builds remain vulnerable with no fix planned. The second flaw (CVSS 7.7) is a path traversal in two APIs tied to the AbaClik / AbaClik.ai mobile companion apps that lets an authenticated caller read a subset of server files outside the application&#39;s security realm; NCSC-CH&#39;s load-bearing point is that these APIs are network-exposed by default even for customers who do not use the mobile apps (<a href="https://security.abacus.ch/en/2026-8b29ce3e-c211-1f4d-9e50-a94d4d6659d1" target="_blank" rel="noopener noreferrer">Abacus Research AG, 2026-07-15</a>).</p>
<p>Both were found through Abacus&#39;s own bug-bounty program and the vendor reports no indication of exploitation in the wild. Internet-facing on-prem deployments are the acute case; an internal-only Abacus still carries the flaw but with the attack surface reduced to the internal network.</p><aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">with no CVE, no public PoC and no vendor-published indicators of compromise (&quot;At this moment we have no clear Indicator of Compromise for this vulnerability&quot;), there is nothing to hunt on yet — the correct posture is to patch/hotfix immediately and shrink exposure, not to wait for detection content. Because the fix ships either as a full update or a ServiceManager SilentHotfix that itself depends on AbaClient ≥ 4.2, treat the client-version prerequisite as a change-management gate: a SilentHotfix pushed to a fleet on an older AbaClient will leave the Abacus unable to start until the client is upgraded or the hotfix reverted.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">If successfully exploited, the vulnerability allows remote code execution on the abacus server without user authentication.</p><p class="entry-cite__quote">Reachable Abacus Endpoints are the only prerequisite for an attack.</p><p class="entry-cite__quote">No, the vulnerability was found in our bugbounty program. We have no indications of a successful attack in the wild.</p><figcaption class="entry-cite__attr">Abacus Research AG</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>17 Jul 04:35Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-17/abacus-erp-unauth-rce-path-traversal-ncsc-ch/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://security-hub.ncsc.admin.ch/#/posts/12766" target="_blank" rel="noopener noreferrer">NCSC Switzerland (Cyber Security Hub / GovCERT.ch)</a> · <a href="https://security.abacus.ch/en/2026-84b5ca67-a46f-639c-5784-ce3c72065a34" target="_blank" rel="noopener noreferrer">Abacus Research AG (vendor PSIRT)</a></div></article>]]></content:encoded></item><item><title>Nayax&#39;s board formally rejects The Syndicate&#39;s extortion and says the exfiltrated data excludes sensitive payment-authentication details</title><link>https://ctipilot.ch/entries/2026-07-16/nayax-the-syndicate-board-refuses-extortion-scope-narrowed/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-16/nayax-the-syndicate-board-refuses-extortion-scope-narrowed/</guid><pubDate>Thu, 16 Jul 2026 04:46:00 +0000</pubDate><dc:date>2026-07-16T04:46:00Z</dc:date><category>data-breach</category><category>europe</category><description><![CDATA[<p>In a 2026-07-14 update to its cloud-account incident, Nayax Ltd. (whose Nayax Europe UAB is a Bank-of-Lithuania-licensed EEA payment institution) said its board resolved not to comply with The Syndicate&#39;s criminal extortion demand, narrowed the disclosed exfiltrated data to a backup of scanned documents and payment-transaction records that it says exclude sensitive payment authentication data, and confirmed remediation is complete with systems cleared of unauthorized access. The update sharpens the contrast with the group&#39;s original — and internally inconsistent — 1-billion-card claim.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-16/nayax-the-syndicate-board-refuses-extortion-scope-narrowed" data-tags="data-breach" data-regions="europe" data-kind="incident" data-priority="routine" data-discovered="2026-07-16T04:46:00Z"><div class="badges"><span class="b ">ROUTINE</span><span class="b upd">update</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 2: Probably true"><span class="k">NATO</span>A2</span></div><h3 class="f-h" id="nayax-the-syndicate-board-refuses-extortion-scope-narrowed"><a href="https://ctipilot.ch/entries/2026-07-16/nayax-the-syndicate-board-refuses-extortion-scope-narrowed/">Nayax refuses The Syndicate&#39;s extortion demand and narrows its disclosed breach scope</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-07-09/nayax-cloud-account-incident-the-syndicate-claim/">Nayax (Bank-of-Lithuania-licensed EEA payment institution) discloses a cloud-account incident; &quot;The Syndicate&quot; claims 1B card records — claim unverified and contradicted by the filing</a> <span class="mono muted">(2026-07-09)</span></p><p>Nayax Ltd. — whose Nayax Europe UAB subsidiary is a Bank-of-Lithuania-licensed payment institution serving EEA enterprises — issued a 14 July status update on the cloud-account incident The Syndicate claimed. Its board of directors &quot;has resolved not to comply with criminal extortion demands,&quot; on the stated grounds that compliance would not serve customers&#39;, partners&#39;, employees&#39; or shareholders&#39; long-term interests (<a href="https://www.globenewswire.com/news-release/2026/07/14/3326635/0/en/Nayax-information-security-incident-update.html" target="_blank" rel="noopener noreferrer">Nayax Ltd., 2026-07-14</a>). Nayax narrowed the disclosed exfiltrated data to a backup of scanned documents, other business information, and mainly a backup of payment-transaction records that it says excludes sensitive payment-authentication data (cardholder names, CVV, ID information), adding that most affected transactions used digital-wallet single-use tokens it describes as valueless if disclosed. It also states remediation is complete and its systems are confirmed free of unauthorized access (<a href="https://www.globenewswire.com/news-release/2026/07/14/3326635/0/en/Nayax-information-security-incident-update.html" target="_blank" rel="noopener noreferrer">Nayax Ltd., 2026-07-14</a>).</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the operative development is the sharpened gap between the company&#39;s account and The Syndicate&#39;s original claim of ~1 billion card records with a ~9-month dwell — a claim already flagged as internally inconsistent with an &quot;immediately contained&quot; account. For defenders triaging extortion coverage, this is a reminder to weight a victim&#39;s own scoped disclosure over a leak-site actor&#39;s volume claims, which are routinely inflated; the reciprocal caution is that &quot;confirmed free of unauthorized access&quot; is a self-assessment pending any actor data release. No new defender action follows from this status update.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">The Company&#39;s Board of Directors has resolved not to comply with criminal extortion demands.</p><p class="entry-cite__quote">The Company&#39;s systems have been cleared and based on its investigation to date, confirmed to be free of unauthorized access.</p><figcaption class="entry-cite__attr">Nayax Ltd.</figcaption></figure></div><div class="prov"><span>incident</span><span>16 Jul 04:46Z</span><span class="p-warn">single-source · victim disclosure</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-16/nayax-the-syndicate-board-refuses-extortion-scope-narrowed/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.globenewswire.com/news-release/2026/07/14/3326635/0/en/Nayax-information-security-incident-update.html" target="_blank" rel="noopener noreferrer">Nayax Ltd. (press release)</a></div></article>]]></content:encoded></item><item><title>AsyncAPI npm compromise: Microsoft finds the malicious versions carried valid npm/OIDC provenance attestations, with an import-time (not install-hook) trigger</title><link>https://ctipilot.ch/entries/2026-07-16/asyncapi-npm-compromise-valid-provenance-attestations-delta/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-16/asyncapi-npm-compromise-valid-provenance-attestations-delta/</guid><pubDate>Thu, 16 Jul 2026 04:44:00 +0000</pubDate><dc:date>2026-07-16T04:44:00Z</dc:date><category>supply-chain</category><category>global</category><description><![CDATA[<p>Microsoft Threat Intelligence&#39;s forensic timeline of the 2026-07-14 AsyncAPI npm compromise adds a load-bearing detail: because the attacker pushed to a branch that triggered AsyncAPI&#39;s own legitimate release workflow, the five trojanized versions were published via npm trusted publishing over GitHub OIDC and carry cryptographically valid provenance attestations that correctly name the real repo, commit and workflow — even though the triggering commit was unauthorized. The payload also executes at import time, not through an install lifecycle hook, so <code>--ignore-scripts</code> does not stop it. Provenance verification confirms which pipeline built an artifact, not that the triggering commit was authorized.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-16/asyncapi-npm-compromise-valid-provenance-attestations-delta" data-tags="supply-chain" data-regions="global" data-kind="incident" data-priority="notable" data-discovered="2026-07-16T04:44:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b upd">update</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 1: Confirmed"><span class="k">NATO</span>B1</span></div><h3 class="f-h" id="asyncapi-npm-compromise-valid-provenance-attestations-delta"><a href="https://ctipilot.ch/entries/2026-07-16/asyncapi-npm-compromise-valid-provenance-attestations-delta/">AsyncAPI npm compromise — the trojanized packages shipped valid npm/OIDC provenance attestations (Microsoft forensic timeline)</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-07-14/asyncapi-npm-supply-chain-compromise-github-actions/">AsyncAPI npm packages backdoored via a GitHub Actions pull_request_target token theft, delivering a multi-stage IPFS implant (M-RED-TEAM)</a> <span class="mono muted">(2026-07-14)</span></p><p>Microsoft Threat Intelligence published a forensic timeline of the AsyncAPI npm compromise that adds a detail with broad supply-chain-defence implications (<a href="https://www.microsoft.com/en-us/security/blog/2026/07/15/unpacking-asyncapi-npm-supply-chain-compromise-import-time-payload-delivery/" target="_blank" rel="noopener noreferrer">Microsoft Threat Intelligence, 2026-07-15</a>). Once the attacker held push access as the AsyncAPI service account (via the <code>pull_request_target</code> misconfiguration covered in the original entry), no npm-token theft was needed: a direct push to a release-triggering branch ran the project&#39;s <strong>own legitimate</strong> <code>release-with-changesets</code> workflow, which published the packages via npm trusted publishing over GitHub OIDC. As a result the five trojanized versions carry cryptographically valid provenance attestations that correctly identify the real repository, commit and workflow — even though the triggering commit was unauthorized (<a href="https://www.microsoft.com/en-us/security/blog/2026/07/15/unpacking-asyncapi-npm-supply-chain-compromise-import-time-payload-delivery/" target="_blank" rel="noopener noreferrer">Microsoft Threat Intelligence, 2026-07-15</a>).</p>
<p>Two further deltas: the payload triggers at <strong>import time</strong> (embedded in one file per package — <code>index.js</code> for the specs package, <code>validator.js</code>/<code>utils.js</code>/<code>ErrorHandling.js</code> for the generator family) and unwraps an IPFS-fetched bundle through three static-key crypto layers to an <code>eval()</code>, so <code>npm install --ignore-scripts</code> provides no protection; and Microsoft recovered all three self-identifying strings — <code>M-RED-TEAM v6.4</code>, <code>miasma-train-p1</code> and <code>miasma-test-org</code> — from one binary, resolving the identifier ambiguity across the original reporting. Unit 42 independently corroborates the timeline and identifies the payload as a descendant of the same Miasma RAT deployed in the June 2026 Red Hat supply-chain operation (<a href="https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacks/" target="_blank" rel="noopener noreferrer">Unit 42, 2026-07-15</a>).</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the load-bearing lesson for CI/CD and supply-chain-security reviewers is that SLSA / npm-OIDC provenance attests <strong>which pipeline</strong> built an artifact, not whether the commit that triggered the pipeline was authorized — so provenance verification alone would not have flagged these packages. The control gap is branch-protection coverage on every branch capable of triggering a publish workflow, not only the default branch. Because delivery is import-time, detection belongs at runtime (a build/CI or developer host resolving IPFS gateways or performing a multi-stage decrypt-then-<code>eval</code> on module import), not at the install-hook layer.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">All five malicious versions were published through npm trusted publishing using GitHub OIDC and carried valid provenance attestations. The attestations accurately identified the legitimate repositories, commits, and workflows that created the packages, even though the triggering commits were unauthorized.</p><p class="entry-cite__quote">Do not rely on npm install –ignore-scripts as a mitigation; this campaign executes when the module is imported, not through a lifecycle hook.</p><figcaption class="entry-cite__attr"><a href="https://www.microsoft.com/en-us/security/blog/2026/07/15/unpacking-asyncapi-npm-supply-chain-compromise-import-time-payload-delivery/" target="_blank" rel="noopener noreferrer">Microsoft Threat Intelligence</a> <span class="entry-cite__date mono">2026-07-15</span></figcaption></figure></div><div class="prov"><span>incident</span><span>16 Jul 04:44Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-16/asyncapi-npm-compromise-valid-provenance-attestations-delta/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.microsoft.com/en-us/security/blog/2026/07/15/unpacking-asyncapi-npm-supply-chain-compromise-import-time-payload-delivery/" target="_blank" rel="noopener noreferrer">Microsoft Threat Intelligence</a> · <a href="https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacks/" target="_blank" rel="noopener noreferrer">Palo Alto Networks Unit 42</a></div></article>]]></content:encoded></item><item><title>Elastic details TELEPUZ, a MaaS RAT hiding syscalls in patched Windows DLLs, with C2 discovery via Telegram, Steam, DNS and a Polygon smart contract</title><link>https://ctipilot.ch/entries/2026-07-16/telepuz-modular-windows-rat-maas-clickfix-vidar/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-16/telepuz-modular-windows-rat-maas-clickfix-vidar/</guid><pubDate>Thu, 16 Jul 2026 04:40:00 +0000</pubDate><dc:date>2026-07-16T04:40:00Z</dc:date><category>phishing</category><category>infostealer</category><category>global</category><description><![CDATA[<p>Elastic Security Labs is tracking TELEPUZ, a full-featured modular Windows RAT active since late April 2026 and spreading via a ClickFix→Vidar chain that ends in a rundll32-loaded DLL. It executes indirect syscalls from the .text section of a randomly chosen legitimate DLL to bypass user-mode hooking, patches AMSI/ETW, escalates via UAC bypass and token theft, and discovers its WebSocket C2 through four decentralized fallbacks (a Telegram bio, a Steam profile, a DNS TXT record and a Polygon smart contract). It ships a keylogger, stealer and a CDP/WebDriver-BiDi banking web-injection module. Relevant to any Windows fleet exposed to ClickFix lures; Elastic released a public YARA rule.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-16/telepuz-modular-windows-rat-maas-clickfix-vidar" data-tags="phishing infostealer" data-regions="global" data-kind="threat" data-priority="notable" data-discovered="2026-07-16T04:40:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="telepuz-modular-windows-rat-maas-clickfix-vidar"><a href="https://ctipilot.ch/entries/2026-07-16/telepuz-modular-windows-rat-maas-clickfix-vidar/">TELEPUZ — a modular Windows RAT/MaaS spread through ClickFix→Vidar chains, executing syscalls from patched trusted DLLs</a></h3><p>Elastic Security Labs is tracking <strong>TELEPUZ</strong>, a full-featured, fast-evolving modular Windows RAT active since late April 2026 and, on Elastic&#39;s telemetry, a likely malware-as-a-service given the daily volume of new builds uploaded to VirusTotal (<a href="https://www.elastic.co/security-labs/telepuz-maas-malware-clickfix" target="_blank" rel="noopener noreferrer">Elastic Security Labs, 2026-07-16</a>). Delivery runs through a <strong>ClickFix</strong> social-engineering lure that pastes a PowerShell one-liner into the Run dialog, which downloads a Go variant of the Vidar stealer; Vidar then fetches a small stager (<code>install.exe</code>) that loads the main payload — a 64-bit DLL executed via <code>rundll32</code> from domain-rotating staging infrastructure (<a href="https://www.elastic.co/security-labs/telepuz-maas-malware-clickfix" target="_blank" rel="noopener noreferrer">Elastic Security Labs, 2026-07-16</a>).</p>
<p>The payload&#39;s headline evasion is an indirect-syscall engine: it maps a fresh copy of <code>ntdll.dll</code>, parses syscall numbers from its export table, then patches the <code>.text</code> section of a randomly chosen legitimate DLL (<code>dfscli.dll</code>, <code>davhlpr.dll</code>, <code>msdtclog.dll</code>, <code>dsrole.dll</code> or <code>secur32.dll</code>) with syscall trampolines so calls execute from inside a trusted-looking module, defeating user-mode API hooking and ETW (<a href="https://www.elastic.co/security-labs/telepuz-maas-malware-clickfix" target="_blank" rel="noopener noreferrer">Elastic Security Labs, 2026-07-16</a>). It additionally patches AMSI/ETW to neutered return values, unhooks NTDLL, reflectively loads modules and runs downloaded PEs via process hollowing, escalates through two UAC-bypass techniques and SYSTEM token theft, and persists as a service named <code>CipherAllocator</code>. Command-and-control runs over WebSocket (optionally SChannel TLS) at a <code>/cdn/health?sid=</code> URI, with four fallback address-discovery channels — a Telegram channel bio, a Steam profile, a DNS TXT record and a Polygon smart-contract call (also a kill switch). Modules include a keylogger, an infostealer with a Chrome App-Bound-Encryption cookie helper, and a browser web-injection module that uses Chrome DevTools Protocol / Firefox WebDriver BiDi (not code injection) to swap IBAN/amount fields in banking web forms; the malware also runs anti-analysis checks — debugger evasion (<code>ProcessDebugPort</code>/<code>ThreadHideFromDebugger</code>) and sandbox/host geofencing on CIS country, sandbox hostnames and usernames.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">signature and user-mode-hook-based detection degrade against the indirect-syscall-from-patched-DLL design, so hunt on behaviour and lineage — process-creation telemetry showing <code>rundll32</code> (or a service process) making outbound network connections it never normally makes, and integrity anomalies where a signed system DLL&#39;s <code>.text</code> section has been modified in memory. ClickFix delivery means the earliest observable is a user-spawned <code>PowerShell.exe</code> from the Run dialog (<code>explorer.exe</code> parent) fetching a remote binary. <strong>Triage:</strong> a legitimate <code>rundll32</code>-hosted process does not open outbound WebSocket connections; a <code>rundll32</code> (or <code>CipherAllocator</code> service) process reaching a <code>/cdn/health?sid=</code> WebSocket endpoint, combined with fixed-return-value AMSI/ETW patch stubs in that process, is the distinguishing sequence — either signal alone is weaker than the two together. Elastic published a YARA rule (<code>Windows_Trojan_Telepuz</code>) alongside the write-up.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Given the significant number of builds uploaded to VirusTotal daily, it is likely that we are dealing with a MaaS.</p><p class="entry-cite__quote">Finally, the malware selects a random library from a set of standard libraries (dfscli.dll, davhlpr.dll, msdtclog.dll, dsrole.dll, and secur32.dll) and loads it via LoadLibrary. It then patches the library&#39;s .text section with the previously generated trampolines, so indirect syscalls are now executed from this location.</p><figcaption class="entry-cite__attr"><a href="https://www.elastic.co/security-labs/telepuz-maas-malware-clickfix" target="_blank" rel="noopener noreferrer">Elastic Security Labs</a> <span class="entry-cite__date mono">2026-07-16</span></figcaption></figure></div><div class="prov"><span>threat</span><span>16 Jul 04:40Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-16/telepuz-modular-windows-rat-maas-clickfix-vidar/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.elastic.co/security-labs/telepuz-maas-malware-clickfix" target="_blank" rel="noopener noreferrer">Elastic Security Labs</a></div></article>]]></content:encoded></item><item><title>Oracle E-Business Suite Payments pre-auth takeover (CVE-2026-46817) confirmed exploited and KEV-listed — patch or pull exposed instances off the internet</title><link>https://ctipilot.ch/entries/2026-07-16/cve-2026-46817-oracle-ebs-payments-preauth-rce-kev-listed/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-16/cve-2026-46817-oracle-ebs-payments-preauth-rce-kev-listed/</guid><pubDate>Thu, 16 Jul 2026 04:35:00 +0000</pubDate><dc:date>2026-07-16T04:35:00Z</dc:date><category>vulnerabilities</category><category>rce</category><category>pre-auth</category><category>actively-exploited</category><category>cisa-kev</category><category>patch-available</category><category>global</category><category>exploited</category><category>cisa-kev</category><category>patch-available</category><category>CVE-2026-46817</category><description><![CDATA[<p>CISA added CVE-2026-46817 to its Known Exploited Vulnerabilities catalog on 2026-07-15, the first formal confirmation of active exploitation for an unauthenticated flaw in the File Transmission component of Oracle Payments (the payment engine inside Oracle E-Business Suite 12.2.3–12.2.15) that Oracle patched quietly in its May 2026 Critical Patch Update. It is reachable over plain HTTP with no authentication (CVSS 9.8); any internet-facing EBS instance not on the May fix should be patched or taken off the public internet now, and treated as potentially compromised if it was exposed after 2026-05-28.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-16/cve-2026-46817-oracle-ebs-payments-preauth-rce-kev-listed" data-tags="vulnerabilities rce pre-auth actively-exploited cisa-kev patch-available" data-regions="global" data-kind="vulnerability" data-priority="high" data-discovered="2026-07-16T04:35:00Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-46817/">CVE-2026-46817</a><span class="b exp">exploited</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 1: Confirmed"><span class="k">NATO</span>A1</span></div><h3 class="f-h" id="cve-2026-46817-oracle-ebs-payments-preauth-rce-kev-listed"><a href="https://ctipilot.ch/entries/2026-07-16/cve-2026-46817-oracle-ebs-payments-preauth-rce-kev-listed/">CVE-2026-46817 — Oracle E-Business Suite (Payments): unauthenticated RCE now CISA KEV-listed after quiet in-the-wild exploitation (CVSS 9.8)</a></h3><p>CISA added <strong>CVE-2026-46817</strong> to its Known Exploited Vulnerabilities catalog on 15 July 2026, the first formal confirmation of active exploitation for a flaw Oracle patched without fanfare in its May 2026 Critical Patch Update (<a href="https://www.cisa.gov/news-events/alerts/2026/07/15/cisa-adds-two-known-exploited-vulnerabilities-catalog" target="_blank" rel="noopener noreferrer">CISA, 2026-07-15</a>). The bug sits in the File Transmission component of <strong>Oracle Payments</strong> — the payment-processing engine built into Oracle E-Business Suite — and Oracle characterises it as improper privilege management, improper authentication and missing authentication for a critical function that an unauthenticated attacker with HTTP network access can use to compromise and take over Oracle Payments (CVSS 9.8; <a href="https://www.oracle.com/security-alerts/cspumay2026.html" target="_blank" rel="noopener noreferrer">Oracle CPU, 2026-05-28</a>). Affected releases are EBS 12.2.3 through 12.2.15.</p>
<p>Threat-intelligence firm Defused recorded the first in-the-wild exploitation against its EBS honeypot decoys on <strong>27 June 2026</strong> — roughly six weeks after the patch and before any public proof-of-concept existed — as a single source running an unauthenticated file read against the Payments component rather than broad scanning (<a href="https://www.helpnetsecurity.com/2026/06/30/oracle-payments-cve-2026-46817-exploitation/" target="_blank" rel="noopener noreferrer">Help Net Security, 2026-06-30</a>). The observed technique calls the <code>ibytransmit</code> endpoint in the File Transmission component, invoking an internal Oracle Java function directly and redirecting it to read <code>/etc/passwd</code>; the same primitive can be pointed at configuration files holding database credentials, encryption keys or payment-processor API keys (<a href="https://www.helpnetsecurity.com/2026/06/30/oracle-payments-cve-2026-46817-exploitation/" target="_blank" rel="noopener noreferrer">Help Net Security, 2026-06-30</a>). This is the same EBS product family already under sustained ShinyHunters/UNC6240 extortion pressure and the latest in a now-annual cadence of critical, remotely exploitable EBS flaws.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">EBS is a common finance and public-sector back-office platform across Europe, and this is a pre-auth, no-interaction path to full compromise on the exposed web tier. In web-access-log telemetry, surface POST requests to <code>/OA_HTML/ibytransmit</code> — especially from unexpected sources against any instance that was internet-reachable after the 28 May patch date — and treat such an instance as potentially compromised, investigating before (not after) rotating the credentials and keys stored on the host. The recurring exploitation pattern is itself reason to question whether any EBS component needs to remain internet-facing. The CISA KEV entry is the exploitation signal used here; the associated federal remediation deadline is a US-agency compliance date and carries no operational weight for this audience.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">On 27 June 2026 our Oracle E-Business Suite decoys recorded the first in-the-wild exploitation of CVE-2026-46817 — roughly six weeks after Oracle&#39;s May 2026 patch and before any public proof-of-concept existed.</p><figcaption class="entry-cite__attr"><a href="https://www.helpnetsecurity.com/2026/06/30/oracle-payments-cve-2026-46817-exploitation/" target="_blank" rel="noopener noreferrer">Help Net Security (citing Defused)</a> <span class="entry-cite__date mono">2026-06-30</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">The exploit targets the ibytransmit endpoint in Oracle Payments&#39; File Transmission component, and calls an internal Oracle Java function directly, redirecting it to read a file (/etc/passwd) from the server.</p><figcaption class="entry-cite__attr">Help Net Security</figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.</p><figcaption class="entry-cite__attr"><a href="https://www.cisa.gov/news-events/alerts/2026/07/15/cisa-adds-two-known-exploited-vulnerabilities-catalog" target="_blank" rel="noopener noreferrer">CISA</a> <span class="entry-cite__date mono">2026-07-15</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>16 Jul 04:35Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-16/cve-2026-46817-oracle-ebs-payments-preauth-rce-kev-listed/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.oracle.com/security-alerts/cspumay2026.html" target="_blank" rel="noopener noreferrer">Oracle (Critical Patch Update Advisory, May 2026)</a> · <a href="https://www.cisa.gov/news-events/alerts/2026/07/15/cisa-adds-two-known-exploited-vulnerabilities-catalog" target="_blank" rel="noopener noreferrer">CISA</a> · <a href="https://www.helpnetsecurity.com/2026/06/30/oracle-payments-cve-2026-46817-exploitation/" target="_blank" rel="noopener noreferrer">Help Net Security (citing Defused)</a></div></article>]]></content:encoded></item><item><title>A fake client_id on Entra ID&#39;s ROPC token endpoint lets attackers enumerate and validate credentials while leaving a blank application name in the sign-in log</title><link>https://ctipilot.ch/entries/2026-07-15/proofpoint-oauth-client-id-spoofing-entra-id-evasion/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-15/proofpoint-oauth-client-id-spoofing-entra-id-evasion/</guid><pubDate>Wed, 15 Jul 2026 04:36:00 +0000</pubDate><dc:date>2026-07-15T04:36:00Z</dc:date><category>identity</category><category>cloud</category><category>phishing</category><category>global</category><description><![CDATA[<p>Proofpoint (2026-07-13) documented OAuth client ID spoofing against Microsoft Entra ID, independently weaponised by two clusters. An attacker POSTs credentials to the /common/oauth2/token endpoint using the legacy ROPC flow with an arbitrary unregistered GUID as client_id; Entra ID&#39;s differential AADSTS error responses leak username and password validity, and AADSTS700016 (&quot;application not found&quot;) is returned when the credentials are BOTH correct — turning a code defenders read as a harmless misconfiguration into a credential-validity oracle. Because the client_id is unregistered, the sign-in log entry (where one appears at all) carries a blank application name, defeating detections that correlate authentication spikes by app. The concrete fix is to block the ROPC grant type outright, because Conditional Access policies scoped to specific applications are the exact control this technique sidesteps.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-15/proofpoint-oauth-client-id-spoofing-entra-id-evasion" data-tags="identity cloud phishing" data-regions="global" data-kind="research" data-priority="notable" data-discovered="2026-07-15T04:36:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="proofpoint-oauth-client-id-spoofing-entra-id-evasion"><a href="https://ctipilot.ch/entries/2026-07-15/proofpoint-oauth-client-id-spoofing-entra-id-evasion/">Proofpoint: OAuth client ID spoofing validates stolen Entra ID credentials at scale without writing a successful sign-in log</a></h3><p>Proofpoint&#39;s Threat Research team documented a stealthy authentication-evasion technique — <strong>OAuth client ID spoofing</strong> — being independently weaponised by two distinct clusters against <strong>Microsoft Entra ID</strong> (<a href="https://www.proofpoint.com/us/blog/threat-insight/oauth-client-id-spoofing-why-fake-client-ids-are-gaining-traction-stealthy" target="_blank" rel="noopener noreferrer">Proofpoint, 2026-07-13</a>). The mechanism abuses the legacy Resource Owner Password Credentials (ROPC) flow: an attacker POSTs a username and password to Entra ID&#39;s <code>/common/oauth2/token</code> endpoint while supplying an arbitrary, unregistered GUID as the <code>client_id</code> parameter instead of a real application ID. Entra ID&#39;s differential error responses then leak validity regardless of whether the client_id is legitimate — <code>AADSTS50034</code> for a non-existent username, <code>AADSTS50126</code> for a valid username with the wrong password, and, critically, <code>AADSTS700016</code> (&quot;application not found in directory&quot;) when the username <em>and</em> password are both correct, because Entra ID validates the credential before it fails on the unrecognised client. The result is a credential-validity oracle that most defenders misread: <code>AADSTS700016</code> is ordinarily dismissed as a harmless misconfigured-app error, which is precisely the blind spot both clusters exploited (<a href="https://www.helpnetsecurity.com/2026/07/13/entra-id-oauth-client-id-spoofing/" target="_blank" rel="noopener noreferrer">Help Net Security, 2026-07-13</a>).</p>
<p>The evasion value is in the telemetry: none of these code paths writes a successful sign-in event, and because the client_id is unregistered, the sign-in log entry carries no application name at all — &quot;detections that look for surges against a specific application name may miss this activity entirely, as the field is blank&quot; (<a href="https://www.proofpoint.com/us/blog/threat-insight/oauth-client-id-spoofing-why-fake-client-ids-are-gaining-traction-stealthy" target="_blank" rel="noopener noreferrer">Proofpoint, 2026-07-13</a>). Proofpoint attributes two campaigns of opportunistic mass enumeration: <strong>UNK_pyreq2323</strong> (January–March 2026, AWS-hosted, 700,000+ distinct spoofed client IDs) and <strong>UNK_OutFlareAZ</strong> (December 2025–March 2026, Cloudflare-fronted, 3.7M distinct spoofed IDs), whose divergent tooling and client-ID-generation strategies point to parallel invention rather than shared code (<a href="https://thehackernews.com/2026/07/oauth-client-id-spoofing-lets-attackers.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-07-13</a>).</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the concrete detection-logic change is to stop treating <code>AADSTS700016</code> against a valid username as harmless and start treating a burst of them — especially from a single ASN or cloud-hosting range across many usernames — as equivalent in severity to a successful credential-stuffing hit; sign-in entries with a blank application ID on ROPC token requests are the anomaly to hunt. <strong>Triage:</strong> legitimate ROPC usage (some line-of-business apps, service accounts and CI/CD pipelines still use it deliberately) shows a registered, named application in the sign-in log — a genuinely blank application-name field on a <code>/common/oauth2/token</code> request, at volume against many distinct usernames, is what separates the attack from benign legacy authentication. The durable fix is to block the ROPC grant type outright, since per-application Conditional Access scoping is the exact control this technique defeats.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">When a spoofed client ID is used, no corresponding application name is recorded in the sign-in log. This means that detections that look for surges against a specific application name may miss this activity entirely, as the field is blank.</p><p class="entry-cite__quote">By fragmenting authentication attempts across many fictional applications, activity becomes harder to correlate and may evade per-application detections and rate limiting.</p><figcaption class="entry-cite__attr"><a href="https://www.proofpoint.com/us/blog/threat-insight/oauth-client-id-spoofing-why-fake-client-ids-are-gaining-traction-stealthy" target="_blank" rel="noopener noreferrer">Proofpoint Threat Research</a> <span class="entry-cite__date mono">2026-07-13</span></figcaption></figure></div><div class="prov"><span>research</span><span>15 Jul 04:36Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-15/proofpoint-oauth-client-id-spoofing-entra-id-evasion/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.proofpoint.com/us/blog/threat-insight/oauth-client-id-spoofing-why-fake-client-ids-are-gaining-traction-stealthy" target="_blank" rel="noopener noreferrer">Proofpoint Threat Research</a> · <a href="https://www.helpnetsecurity.com/2026/07/13/entra-id-oauth-client-id-spoofing/" target="_blank" rel="noopener noreferrer">Help Net Security</a> · <a href="https://thehackernews.com/2026/07/oauth-client-id-spoofing-lets-attackers.html" target="_blank" rel="noopener noreferrer">The Hacker News</a></div></article>]]></content:encoded></item><item><title>Beyond the two exploited zero-days, July&#39;s Microsoft set hides a Pwn2Own SharePoint auth-bypass and a pre-auth Dynamics 365 RCE rated Exploitation More Likely</title><link>https://ctipilot.ch/entries/2026-07-15/microsoft-july-patch-tuesday-sharepoint-dynamics-followup/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-15/microsoft-july-patch-tuesday-sharepoint-dynamics-followup/</guid><pubDate>Wed, 15 Jul 2026 04:36:00 +0000</pubDate><dc:date>2026-07-15T04:36:00Z</dc:date><category>vulnerabilities</category><category>rce</category><category>auth-bypass</category><category>pre-auth</category><category>patch-available</category><category>global</category><category>patch-available</category><category>CVE-2026-55040</category><category>CVE-2026-55944</category><category>CVE-2026-50522</category><category>CVE-2026-58644</category><description><![CDATA[<p>An update to the 2026-07-14 Patch Tuesday coverage: three further SharePoint fixes and a Dynamics fix in the same cycle carry pre-auth risk. CVE-2026-55040 (CVSS 9.1) is a SharePoint JWT authentication bypass from Rapid7&#39;s Pwn2Own Berlin chain — an unauthenticated attacker who knows a target&#39;s AD SID or UPN can act as that user or administrator; Rapid7 demonstrated the chain at Pwn2Own and is holding full technical details and the PoC under a 30-day disclosure embargo, and the chained RCE half will not be patched until August, so applying the July fix now is the only break in the chain. CVE-2026-55944 (CVSS 9.8) is an unauthenticated deserialization RCE in Dynamics NAV / Dynamics 365 Business Central (on-prem) that Microsoft rates &quot;Exploitation More Likely.&quot; Two SharePoint deserialization RCEs (CVE-2026-50522, CVE-2026-58644, both CVSS 9.8) round out the set. None is confirmed exploited in the wild yet.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-15/microsoft-july-patch-tuesday-sharepoint-dynamics-followup" data-tags="vulnerabilities rce auth-bypass pre-auth patch-available" data-regions="global" data-kind="vulnerability" data-priority="high" data-discovered="2026-07-15T04:36:00Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-55040/">CVE-2026-55040 +3</a><span class="b upd">update</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 2: Probably true"><span class="k">NATO</span>A2</span></div><h3 class="f-h" id="microsoft-july-patch-tuesday-sharepoint-dynamics-followup"><a href="https://ctipilot.ch/entries/2026-07-15/microsoft-july-patch-tuesday-sharepoint-dynamics-followup/">July Patch Tuesday follow-through: a SharePoint pre-auth JWT bypass from a Pwn2Own chain (CVE-2026-55040) and a pre-auth Dynamics 365 RCE Microsoft expects to be exploited (CVE-2026-55944)</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-07-14/microsoft-july-2026-patch-tuesday-two-exploited-zero-days/">Microsoft July 2026 Patch Tuesday ships two actively-exploited zero-days — AD FS local EoP (CVE-2026-56155) and unauthenticated SharePoint EoP (CVE-2026-56164)</a> <span class="mono muted">(2026-07-14)</span></p><p>the July Patch Tuesday entry covered the two KEV-listed exploited zero-days (AD FS CVE-2026-56155, SharePoint CVE-2026-56164). Four further high-severity fixes in the same cycle carry pre-auth risk and warrant separate attention. <strong>CVE-2026-55040</strong> (CVSS 9.1, weak authentication) is a SharePoint JWT token-validation bypass that Rapid7&#39;s Stephen Fewer built into a two-vulnerability chain for Pwn2Own Berlin 2026: a remote unauthenticated attacker who knows a target&#39;s Active Directory SID or User Principal Name can forge identity and operate as that SharePoint user or administrator (<a href="https://www.rapid7.com/blog/post/ve-cve-2026-55040-microsoft-sharepoint-jwt-token-authentication-bypass-fixed" target="_blank" rel="noopener noreferrer">Rapid7 Labs, 2026-07-14</a>). Rapid7 chained it to a still-undisclosed RCE that Microsoft will not patch until the August 2026 cycle — but &quot;patching CVE-2026-55040 will successfully break this exploit chain,&quot; so the July update is the available defense today even with the RCE half outstanding (<a href="https://www.rapid7.com/blog/post/ve-cve-2026-55040-microsoft-sharepoint-jwt-token-authentication-bypass-fixed" target="_blank" rel="noopener noreferrer">Rapid7 Labs, 2026-07-14</a>).</p>
<p><strong>CVE-2026-55944</strong> (CVSS 9.8) is an unauthenticated deserialization RCE in <strong>Microsoft Dynamics NAV / Dynamics 365 Business Central (on-premises)</strong> — &quot;deserialization of untrusted data ... allows an unauthorized attacker to execute code over a network,&quot; triggered by a crafted login request before any session exists (vector AV:N/AC:L/PR:N/UI:N), and rated &quot;Exploitation More Likely&quot; (<a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-55944" target="_blank" rel="noopener noreferrer">Microsoft MSRC, 2026-07-14</a>). It is easy to overlook against SharePoint or Exchange in a busy Patch Tuesday, yet on-prem Dynamics back-office instances are frequently exposed. Two more SharePoint deserialization RCEs — <strong>CVE-2026-50522</strong> and <strong>CVE-2026-58644</strong> (both CVSS 9.8, &quot;Exploitation More Likely&quot;) — require Site-Owner-level access per Microsoft&#39;s FAQ; CVE-2026-50522 is fixed in the July cumulative update, while CVE-2026-58644&#39;s patch actually shipped in the June cumulative update and the CVE was only documented on 14 July after being omitted from June&#39;s release notes — so a SharePoint estate patched through June is already covered for 58644 (<a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-50522" target="_blank" rel="noopener noreferrer">Microsoft MSRC, 2026-07-14</a>).</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the JWT-bypass path is invisible to normal sign-in and Conditional-Access telemetry because no credential is presented — hunt SharePoint web-server access logs for requests bearing anomalous JWT bearer tokens referencing SIDs/UPNs that do not match the session&#39;s authenticated principal, and audit-log operations performed &quot;as&quot; a user with no corresponding interactive or API sign-in in the same window. For the deserialization RCEs, the durable signal is the classic .NET deserialization-to-RCE lineage — anomalous <code>w3wp.exe</code> (SharePoint app-pool) or the Dynamics service host spawning child processes following list/webpart operations or an inbound login request. <strong>Triage:</strong> legitimate SharePoint operations are tied to a preceding authenticated sign-in for the acting principal; an operation attributed to a user or administrator with no matching sign-in event, or a service-account process spawn outside normal batch/report windows, is the discriminator.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Patching CVE-2026-55040 will successfully break this exploit chain; this underscores the importance of patching vulnerabilities such as authentication bypasses, which can break complex and high-impact exploit chains.</p><figcaption class="entry-cite__attr">Rapid7 Labs</figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network.</p><figcaption class="entry-cite__attr"><a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-55944" target="_blank" rel="noopener noreferrer">Microsoft MSRC</a> <span class="entry-cite__date mono">2026-07-14</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>15 Jul 04:36Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-15/microsoft-july-patch-tuesday-sharepoint-dynamics-followup/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.rapid7.com/blog/post/ve-cve-2026-55040-microsoft-sharepoint-jwt-token-authentication-bypass-fixed" target="_blank" rel="noopener noreferrer">Rapid7 Labs (Stephen Fewer)</a> · <a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-55944" target="_blank" rel="noopener noreferrer">Microsoft MSRC</a></div></article>]]></content:encoded></item><item><title>Microsoft maps a year of Salesforce OAuth abuse — vishing consent, supply-chain secret reuse, guest-access Aura abuse — invisible to sign-in detection</title><link>https://ctipilot.ch/entries/2026-07-14/microsoft-maps-shinyhunters-salesforce-oauth-abuse/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-14/microsoft-maps-shinyhunters-salesforce-oauth-abuse/</guid><pubDate>Tue, 14 Jul 2026 20:22:57 +0000</pubDate><dc:date>2026-07-14T20:22:57Z</dc:date><category>identity</category><category>cloud</category><category>phishing</category><category>supply-chain</category><category>data-breach</category><category>global</category><description><![CDATA[<p>Microsoft Threat Intelligence documented a year (mid-2025 to mid-2026) of campaigns using ShinyHunters-associated tradecraft (registry alias UNC6240) against Salesforce-integrated SaaS environments via three intrusion paths: vishing-driven malicious-OAuth-consent (a fake Data Loader app), SaaS supply-chain OAuth-secret reuse (Salesloft Drift, Gainsight, and Storm-3138&#39;s June 2026 Klue compromise), and guest-access Aura abuse. None exploited a Salesforce flaw — all abuse trusted OAuth relationships, so sign-in-anomaly detection gives limited visibility.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-14/microsoft-maps-shinyhunters-salesforce-oauth-abuse" data-tags="identity cloud phishing supply-chain data-breach" data-regions="global" data-kind="research" data-priority="notable" data-discovered="2026-07-14T20:22:57Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="microsoft-maps-shinyhunters-salesforce-oauth-abuse"><a href="https://ctipilot.ch/entries/2026-07-14/microsoft-maps-shinyhunters-salesforce-oauth-abuse/">Microsoft maps three ShinyHunters-tradecraft OAuth-abuse paths against Salesforce customers — none exploiting a Salesforce vulnerability</a></h3><p>Microsoft Threat Intelligence documented a year-long (mid-2025 to mid-2026) set of campaigns using tradecraft commonly associated with ShinyHunters (registry alias UNC6240) against Salesforce-integrated environments, through three distinct paths rather than any Salesforce product vulnerability (<a href="https://www.microsoft.com/en-us/security/blog/2026/07/13/defending-saas-based-applications-against-shinyhunters-oauth-abuse/" target="_blank" rel="noopener noreferrer">Microsoft Threat Intelligence, 2026-07-13</a>). First, vishing-driven OAuth-consent abuse: attackers impersonating IT support socially engineer employees through the OAuth authorization workflow into granting a malicious connected app — disguised as the legitimate Salesforce Data Loader — full API access inherited from the victim&#39;s own privileges, letting them enumerate and exfiltrate CRM data through sanctioned application access that never trips a sign-in anomaly. Second, SaaS supply-chain compromise: compromised Salesloft Drift credentials (August 2025) exposed OAuth connection secrets reused across customer tenants; a November 2025 campaign abused Gainsight-published Salesforce apps the same way; and in June 2026 an actor Microsoft tracks as Storm-3138 compromised the Klue competitive-intelligence platform and reused harvested Salesforce credentials to query and exfiltrate customer CRM data. Third, guest-access abuse: requests chained against Salesforce&#39;s Aura framework via misconfigured guest-user accounts pulled far more data than a guest session should reach (<a href="https://thehackernews.com/2026/07/microsoft-maps-year-long-shinyhunters.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-07-14</a>). Microsoft observed the activity across retail, education and manufacturing tenants and states existing authentication-focused detections gave &quot;limited visibility&quot; because the traffic is indistinguishable from legitimate integration.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">for CH/EU public-sector and enterprise orgs running Salesforce for case-management or citizen-service workloads, the lesson is that OAuth-consent and connected-app trust — not credentials or malware — is the attack surface here, and it evades sign-in-based detection; visibility requires OAuth/connected-app and data-access telemetry (Microsoft points to Defender for Cloud Apps real-time event monitoring and Salesforce Shield). <strong>Triage:</strong> the discriminator is <em>pattern</em>, not any single authentication event — bulk or systematic SOQL querying and report exports, connected-app activity from a new IP or user-agent for an established app, anomalous OAuth-scope combinations, and guest-user access reaching non-public objects; a legitimate integration exhibits a stable client fingerprint and a bounded query profile, so the deviation in volume and client identity is the signal.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Threat actors socially engineered employees into authorizing attacker-controlled connected apps within their Salesforce tenant.</p><p class="entry-cite__quote">This activity was not the result of a vulnerability inherent to Salesforce.</p><p class="entry-cite__quote">malicious activity often appeared indistinguishable from legitimate Salesforce usage because threat actors operated through trusted identities, approved OAuth applications, and authorized integrations.</p><figcaption class="entry-cite__attr"><a href="https://www.microsoft.com/en-us/security/blog/2026/07/13/defending-saas-based-applications-against-shinyhunters-oauth-abuse/" target="_blank" rel="noopener noreferrer">Microsoft Threat Intelligence</a> <span class="entry-cite__date mono">2026-07-13</span></figcaption></figure></div><div class="prov"><span>research</span><span>14 Jul 20:22Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-14/microsoft-maps-shinyhunters-salesforce-oauth-abuse/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.microsoft.com/en-us/security/blog/2026/07/13/defending-saas-based-applications-against-shinyhunters-oauth-abuse/" target="_blank" rel="noopener noreferrer">Microsoft Threat Intelligence</a> · <a href="https://thehackernews.com/2026/07/microsoft-maps-year-long-shinyhunters.html" target="_blank" rel="noopener noreferrer">The Hacker News</a></div></article>]]></content:encoded></item><item><title>Progress names the ShareFile Storage Zone Controller root cause — a path-traversal flaw — and ships the fix; a CVE is reserved but withheld for two weeks</title><link>https://ctipilot.ch/entries/2026-07-14/progress-sharefile-szc-path-traversal-zero-day-patched/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-14/progress-sharefile-szc-path-traversal-zero-day-patched/</guid><pubDate>Tue, 14 Jul 2026 20:21:02 +0000</pubDate><dc:date>2026-07-14T20:21:02Z</dc:date><category>vulnerabilities</category><category>path-traversal</category><category>zero-day</category><category>patch-available</category><category>global</category><category>europe</category><category>us</category><description><![CDATA[<p>Progress has confirmed the root cause behind its emergency ShareFile Storage Zone Controller (SZC) shutdown: a high-severity path-traversal flaw in SZC 5.x/6.x that an authenticated administrative user can use to read arbitrary service-account files, write to server directories, and enumerate the filesystem. Progress shipped patched versions 5.12.5 and 6.0.2 and is restoring customer access; a CVE identifier is reserved but will not be published for two weeks. On-prem SZC operators should patch and follow Progress&#39;s recovery steps now.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-14/progress-sharefile-szc-path-traversal-zero-day-patched" data-tags="vulnerabilities path-traversal zero-day patch-available" data-regions="global europe us" data-kind="vulnerability" data-priority="high" data-discovered="2026-07-14T20:21:02Z"><div class="badges"><span class="b pri">HIGH</span><span class="b upd">update</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 1: Confirmed"><span class="k">NATO</span>B1</span></div><h3 class="f-h" id="progress-sharefile-szc-path-traversal-zero-day-patched"><a href="https://ctipilot.ch/entries/2026-07-14/progress-sharefile-szc-path-traversal-zero-day-patched/">Progress confirms the ShareFile Storage Zone Controller shutdown was forced by a path-traversal zero-day; patches 5.12.5 / 6.0.2 ship and service is restored</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-07-14/progress-sharefile-szc-active-exploitation-confirmed/">Progress ShareFile Storage Zone Controller — Shadowserver confirms active exploitation of CVE-2026-2699; exposed instances collapse ~30,000 to ~1,000</a> <span class="mono muted">(2026-07-14)</span></p><p>Progress Software has confirmed the root cause behind its emergency ShareFile Storage Zone Controller (SZC) shutdown order: a high-severity path-traversal vulnerability affecting SZC versions 5.x and 6.x that lets an authenticated administrative user read arbitrary files accessible to the application&#39;s service account, write malicious content to server directories, and enumerate the filesystem layout (<a href="https://www.bleepingcomputer.com/news/security/progress-confirms-sharefile-zero-day-flaw-behind-storage-zone-shutdown/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-07-14</a>) — a CWE-22-class flaw reachable through the SZC&#39;s internet-facing IIS component. Progress has shipped patched versions 5.12.5 and 6.0.2, and a CVE identifier is reserved but will not be published for two weeks. The vendor states it has &quot;no indication of unauthorized access to any ShareFile customer account or data,&quot; a claim that sits alongside this run&#39;s earlier finding that Shadowserver honeypots recorded in-the-wild exploitation attempts against the same component from 2026-07-10. Progress&#39;s status page confirms Storage Zone Controller customer access &quot;is currently being restored,&quot; with recovery instructions issued directly to account owners (<a href="https://status.sharefile.com/" target="_blank" rel="noopener noreferrer">Progress — ShareFile Status Page, 2026-07-14</a>), closing out the multi-day outage that began with the 2026-07-10 shutdown order.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the new detail is the fix — patched versions (5.12.5, 6.0.2) and a named vulnerability class (path traversal, authenticated-admin scope) that the two prior entries in this thread lacked. Any organization that took SZC offline under the shutdown order should patch to the fixed build and complete Progress&#39;s recovery procedure before re-exposing the component; do not re-enable an unpatched controller. <strong>Triage:</strong> path-traversal exploitation of this component surfaces in the SZC&#39;s IIS/web request telemetry as requests carrying directory-traversal sequences to the storage-controller endpoints and in file-access telemetry as the service account reading or writing paths outside its normal content directories — legitimate SZC operation confines the service account to its configured storage paths, so out-of-tree file access under that account is the discriminator.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">An authenticated administrative user can read arbitrary files accessible to the application&#39;s service account</p><p class="entry-cite__quote">Currently, we have no indication of unauthorized access to any ShareFile customer account or data</p><figcaption class="entry-cite__attr"><a href="https://www.bleepingcomputer.com/news/security/progress-confirms-sharefile-zero-day-flaw-behind-storage-zone-shutdown/" target="_blank" rel="noopener noreferrer">BleepingComputer</a> <span class="entry-cite__date mono">2026-07-14</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">Storage Zones Controller customer access is currently being restored. Recovery instructions have been provided directly to account owners.</p><figcaption class="entry-cite__attr"><a href="https://status.sharefile.com/" target="_blank" rel="noopener noreferrer">Progress — ShareFile Status Page</a> <span class="entry-cite__date mono">2026-07-14</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>14 Jul 20:21Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-14/progress-sharefile-szc-path-traversal-zero-day-patched/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bleepingcomputer.com/news/security/progress-confirms-sharefile-zero-day-flaw-behind-storage-zone-shutdown/" target="_blank" rel="noopener noreferrer">BleepingComputer</a> · <a href="https://status.sharefile.com/" target="_blank" rel="noopener noreferrer">Progress — ShareFile Status Page</a></div></article>]]></content:encoded></item><item><title>SonicWall confirms active exploitation of an unauthenticated SMA1000 SSRF chained to code injection for full appliance takeover</title><link>https://ctipilot.ch/entries/2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited/</guid><pubDate>Tue, 14 Jul 2026 20:19:53 +0000</pubDate><dc:date>2026-07-14T20:19:53Z</dc:date><category>vulnerabilities</category><category>actively-exploited</category><category>zero-day</category><category>pre-auth</category><category>rce</category><category>cisa-kev</category><category>patch-available</category><category>global</category><category>exploited</category><category>cisa-kev</category><category>patch-available</category><category>CVE-2026-15409</category><category>CVE-2026-15410</category><description><![CDATA[<p>SonicWall&#39;s PSIRT confirms active exploitation of two SMA1000 flaws (SNWLID-2026-0008), both added to CISA KEV on 2026-07-14: CVE-2026-15409 (CVSS 10.0), an unauthenticated server-side request forgery in the SMA1000 Work Place interface, and CVE-2026-15410 (CVSS 7.2), a post-authentication OS-command code injection in the Appliance Management Console. Any organization running an internet-facing SMA1000 (6210/7210/8200v) must apply the platform hotfix now.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited" data-tags="vulnerabilities actively-exploited zero-day pre-auth rce cisa-kev patch-available" data-regions="global" data-kind="vulnerability" data-priority="high" data-discovered="2026-07-14T20:19:53Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-15409/">CVE-2026-15409 +1</a><span class="b exp">exploited</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 2: Probably true"><span class="k">NATO</span>A2</span></div><h3 class="f-h" id="sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited"><a href="https://ctipilot.ch/entries/2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited/">CVE-2026-15409 — SonicWall SMA1000: unauthenticated SSRF (CVSS 10.0) chained to post-auth code injection, actively exploited</a></h3><p>SonicWall&#39;s PSIRT advisory SNWLID-2026-0008 (first published 2026-07-14) states it has investigated &quot;multiple cases indicating the active exploitation&quot; of two new SMA1000 flaws (<a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008" target="_blank" rel="noopener noreferrer">SonicWall PSIRT, 2026-07-14</a>); both CVEs carry a same-day CISA KEV listing (recorded in this entry&#39;s CVE status, confirmed against the KEV feed). <strong>CVE-2026-15409</strong> (CVSS 10.0, CWE-918) is a server-side request forgery in the SMA1000 Work Place interface that lets a remote, unauthenticated attacker force the appliance to issue requests to an attacker-chosen location; the scope-changed CVSS vector (S:C) indicates the SSRF reaches beyond the vulnerable component&#39;s own security boundary. <strong>CVE-2026-15410</strong> (CVSS 7.2, CWE-94) is a post-authentication code-injection flaw in the SMA1000 Appliance Management Console (AMC) that lets an authenticated administrator-level session run arbitrary OS commands — read together with the pre-auth SSRF, the pair forms a chain from zero access toward root-equivalent appliance control. The affected firmware is SMA1000 6210/7210/8200v on 12.4.3-03245/03387/03434 and 12.5.0-02283/02624/02800; the fix is platform-hotfix 12.4.3-03453 or 12.5.0-02835, and SonicWall explicitly states neither flaw affects SSL-VPN running on SonicWall firewalls or the SMA100 series (<a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008" target="_blank" rel="noopener noreferrer">SonicWall PSIRT, 2026-07-14</a>).</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">this is the SSL-VPN edge-appliance exploitation pattern that turns into a foothold fast — patch now and, because exploitation is already live, treat an unpatched exposed SMA1000 as a compromise-assessment candidate rather than a clean patch. <strong>Triage:</strong> the pre-auth SSRF surfaces in the appliance&#39;s own request telemetry as outbound requests from the Work Place interface to unexpected internal or external hosts (a legitimate Work Place session does not initiate arbitrary outbound fetches); the code-injection stage surfaces in the control-service log as configuration or hotfix-state manipulation from an admin session — SonicWall&#39;s own detection guidance points at hotfix-rollback entries carrying path-traversal-style names as the anomaly, so rollback activity that does not match a change-managed maintenance window is the discriminator. Per policy no IOCs are reproduced here; consult the vendor advisory for the indicator set.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">SonicWall PSIRT has investigated multiple cases indicating the active exploitation of the vulnerabilities described in this advisory. Customers are strongly urged to upgrade to the hotfix release as soon as possible to remediate these vulnerabilities.</p><p class="entry-cite__quote">A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.</p><p class="entry-cite__quote">Sean Koessel and Steven Adair of Volexity - helped advance SonicWall&#39;s PSIRT investigation, leading to the identification of an additional IOC.</p><figcaption class="entry-cite__attr"><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008" target="_blank" rel="noopener noreferrer">SonicWall PSIRT</a> <span class="entry-cite__date mono">2026-07-14</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>14 Jul 20:19Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008" target="_blank" rel="noopener noreferrer">SonicWall PSIRT</a></div></article>]]></content:encoded></item><item><title>SAP patches an unauthenticated Approuter request-smuggling flaw and a Commerce Cloud public-default-credential exposure; NCSC-CH flags all three</title><link>https://ctipilot.ch/entries/2026-07-14/sap-july-2026-patch-day-netweaver-approuter-commerce-cloud/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-14/sap-july-2026-patch-day-netweaver-approuter-commerce-cloud/</guid><pubDate>Tue, 14 Jul 2026 20:19:53 +0000</pubDate><dc:date>2026-07-14T20:19:53Z</dc:date><category>vulnerabilities</category><category>pre-auth</category><category>patch-available</category><category>auth-bypass</category><category>global</category><category>switzerland</category><category>europe</category><category>patch-available</category><category>CVE-2026-44747</category><category>CVE-2026-27690</category><category>CVE-2026-44761</category><description><![CDATA[<p>SAP&#39;s July 2026 Security Patch Day carries three critical flaws NCSC Switzerland relayed to its constituents: CVE-2026-44747 (CVSS 9.9) memory corruption in the NetWeaver AS ABAP kernel; CVE-2026-27690 (CVSS 9.1) an unauthenticated HTTP request-smuggling flaw in SAP Approuter (non-Cloud-Foundry); and CVE-2026-44761 (CVSS 9.1) a public, hardcoded sample OAuth2 credential left active in SAP Commerce Cloud. No exploitation is reported yet, but the Commerce Cloud item is a config exposure a patch alone does not close.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-14/sap-july-2026-patch-day-netweaver-approuter-commerce-cloud" data-tags="vulnerabilities pre-auth patch-available auth-bypass" data-regions="global switzerland europe" data-kind="vulnerability" data-priority="notable" data-discovered="2026-07-14T20:19:53Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-44747/">CVE-2026-44747 +2</a><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 1: Confirmed"><span class="k">NATO</span>B1</span></div><h3 class="f-h" id="sap-july-2026-patch-day-netweaver-approuter-commerce-cloud"><a href="https://ctipilot.ch/entries/2026-07-14/sap-july-2026-patch-day-netweaver-approuter-commerce-cloud/">SAP July 2026 Security Patch Day: three CVSS ≥9.1 flaws in NetWeaver AS ABAP, Approuter and Commerce Cloud — two reachable without authentication</a></h3><p>SAP&#39;s July 2026 Security Patch Day (14 July) carries three critical flaws NCSC Switzerland&#39;s Cyber Security Hub relayed directly to Swiss constituents, none with reported exploitation at publication (<a href="https://security-hub.ncsc.admin.ch/#/posts/12763" target="_blank" rel="noopener noreferrer">NCSC-CH, 2026-07-14</a>; <a href="https://onapsis.com/blog/sap-security-patch-day-july-2026/" target="_blank" rel="noopener noreferrer">Onapsis Research Labs, 2026-07-14</a>). <strong>CVE-2026-44747</strong> (CVSS 9.9) is a memory-corruption flaw in the SAP NetWeaver Application Server ABAP kernel; SecurityWeek characterises successful exploitation as allowing an attacker to access and modify data and cause system unavailability, and SAP&#39;s only interim workaround (disabling the affected ICF nodes) is impractical because it breaks SAP GUI for HTML, so patching the kernel is the real mitigation (<a href="https://www.securityweek.com/sap-patches-critical-vulnerabilities-in-netweaver-approuter-commerce-cloud/" target="_blank" rel="noopener noreferrer">SecurityWeek, 2026-07-14</a>). <strong>CVE-2026-27690</strong> (CVSS 9.1) is an HTTP request-smuggling flaw in SAP Approuter&#39;s non-Cloud-Foundry deployments: an unauthenticated request desynchronises the request/response stream on a shared front-end, a primitive usable to poison or hijack another user&#39;s request. <strong>CVE-2026-44761</strong> (CVSS 9.1) is a hardcoded sample OAuth2 credential in SAP Commerce Cloud — any customer that ran SAP&#39;s own documented sample configuration and never rotated the shipped secret exposes a publicly-known credential an unauthenticated attacker can use to obtain a valid OCC-API access token (<a href="https://onapsis.com/blog/sap-security-patch-day-july-2026/" target="_blank" rel="noopener noreferrer">Onapsis Research Labs, 2026-07-14</a>).</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">for a Swiss/EU public-sector, finance or utilities SAP estate, sequence by reachability, not CVSS: the Approuter smuggling flaw is unauthenticated and network-reachable, so it patches first; the NetWeaver kernel flaw is authenticated but has enormous blast radius given ABAP&#39;s centrality; and the Commerce Cloud item is an environment-specific configuration exposure — a publicly-known default credential that a routine note roll-out does not remediate, because the exposed secret must be rotated. <strong>Triage:</strong> the Commerce Cloud exposure is a config-audit question (did we deploy the sample OAuth2 client, and is its secret still the shipped default?), answerable from configuration review rather than telemetry; the Approuter smuggling flaw manifests in front-end HTTP access logs as request/response desynchronisation anomalies (ambiguous content-length/transfer-encoding framing, responses mismatched to the requesting session) on a shared Approuter, distinct from the well-formed request stream of normal traffic.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">The vulnerability affects SAP Approuter deployments in non-Cloud Foundry environments and allows an unauthenticated attacker to send a specially crafted HTTP request that leads to request-response desynchronization.</p><p class="entry-cite__quote">Exploitation requires that the customer execute the sample script and retain the resulting OAuth2 client in production without replacing the hardcoded secret.</p><p class="entry-cite__quote">Successful exploitation of the security defect could allow an attacker to access and modify data, and cause system unavailability, SAP security firm Onapsis explains.</p><figcaption class="entry-cite__attr"><a href="https://www.securityweek.com/sap-patches-critical-vulnerabilities-in-netweaver-approuter-commerce-cloud/" target="_blank" rel="noopener noreferrer">SecurityWeek</a> <span class="entry-cite__date mono">2026-07-14</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>14 Jul 20:19Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-14/sap-july-2026-patch-day-netweaver-approuter-commerce-cloud/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://onapsis.com/blog/sap-security-patch-day-july-2026/" target="_blank" rel="noopener noreferrer">Onapsis Research Labs</a> · <a href="https://security-hub.ncsc.admin.ch/#/posts/12763" target="_blank" rel="noopener noreferrer">NCSC Switzerland — Cyber Security Hub</a> · <a href="https://www.securityweek.com/sap-patches-critical-vulnerabilities-in-netweaver-approuter-commerce-cloud/" target="_blank" rel="noopener noreferrer">SecurityWeek</a> · <a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news/july-2026.html" target="_blank" rel="noopener noreferrer">SAP Support Portal</a></div></article>]]></content:encoded></item><item><title>Microsoft patches two exploited zero-days on-prem: an AD FS privilege escalation and an unauthenticated SharePoint EoP, both KEV-listed same day</title><link>https://ctipilot.ch/entries/2026-07-14/microsoft-july-2026-patch-tuesday-two-exploited-zero-days/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-14/microsoft-july-2026-patch-tuesday-two-exploited-zero-days/</guid><pubDate>Tue, 14 Jul 2026 20:19:53 +0000</pubDate><dc:date>2026-07-14T20:19:53Z</dc:date><category>vulnerabilities</category><category>actively-exploited</category><category>zero-day</category><category>priv-esc</category><category>cisa-kev</category><category>identity</category><category>patch-available</category><category>global</category><category>exploited</category><category>cisa-kev</category><category>patch-available</category><category>CVE-2026-56155</category><category>CVE-2026-56164</category><description><![CDATA[<p>Microsoft&#39;s July 2026 Patch Tuesday (its largest ever by CVE count) fixes two zero-days Microsoft confirms were exploited in the wild and CISA added to KEV the same day: CVE-2026-56155, a local elevation-of-privilege in Active Directory Federation Services (AD FS), and CVE-2026-56164, an unauthenticated, network-reachable elevation-of-privilege in on-prem SharePoint Server 2016/2019/Subscription Edition. Any organization running on-prem AD FS or SharePoint should treat both as emergency patches.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-14/microsoft-july-2026-patch-tuesday-two-exploited-zero-days" data-tags="vulnerabilities actively-exploited zero-day priv-esc cisa-kev identity patch-available" data-regions="global" data-kind="vulnerability" data-priority="high" data-discovered="2026-07-14T20:19:53Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-56155/">CVE-2026-56155 +1</a><span class="b exp">exploited</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 1: Confirmed"><span class="k">NATO</span>A1</span></div><h3 class="f-h" id="microsoft-july-2026-patch-tuesday-two-exploited-zero-days"><a href="https://ctipilot.ch/entries/2026-07-14/microsoft-july-2026-patch-tuesday-two-exploited-zero-days/">Microsoft July 2026 Patch Tuesday ships two actively-exploited zero-days — AD FS local EoP (CVE-2026-56155) and unauthenticated SharePoint EoP (CVE-2026-56164)</a></h3><p>Microsoft&#39;s July 2026 Patch Tuesday is its largest ever by CVE count and carries two zero-days Microsoft confirms were exploited before a fix existed, both added to CISA&#39;s Known Exploited Vulnerabilities catalog the same day (<a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-07-14</a>). <strong>CVE-2026-56155</strong> (CVSS 7.8, CWE-1220) is a local elevation-of-privilege in Active Directory Federation Services: an attacker who already holds a low-privileged authorized session on the AD FS host escalates to administrator (<a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-56155" target="_blank" rel="noopener noreferrer">Microsoft MSRC, 2026-07-14</a>). It is a post-foothold escalation rather than an initial-access vector, and Microsoft&#39;s advisory credits its own DART incident-response team in the acknowledgements — meaning it surfaced during a live intrusion, so an exposed AD FS host should be treated as a candidate for compromise assessment, not merely patched (<a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-56155" target="_blank" rel="noopener noreferrer">Microsoft MSRC, 2026-07-14</a>). <strong>CVE-2026-56164</strong> (CVSS 5.3, CWE-306) is the more exposed of the two: a missing-authentication flaw in on-prem SharePoint Server that lets an unauthenticated attacker elevate privileges over the network with no user interaction (<a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-56164" target="_blank" rel="noopener noreferrer">Microsoft MSRC, 2026-07-14</a>). Microsoft&#39;s mitigation guidance — enable AMSI on the SharePoint/IIS worker processes with Request Body Scan set to Full — indicates the trigger is a crafted HTTP POST body, the same class of exposure this pipeline tracked for the CVE-2026-45659 SharePoint deserialization RCE on 2026-07-02, so operators who already tuned AMSI for that flaw have partial coverage.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">patch both now; for AD FS the low CVSS understates the risk because the bug was caught in real-world incident response — treat internet- or partner-reachable AD FS servers as potentially targeted and pair the patch with a hunt of local process activity on those hosts. <strong>Triage:</strong> the AD FS escalation manifests in host-local process-execution and privilege-transition telemetry on the AD FS server itself (a low-privileged service account acquiring administrator context), not in network logs — normal AD FS operation does not spawn privilege transitions from its service account, so that lineage is the discriminator; the SharePoint escalation surfaces in IIS/SharePoint worker-process telemetry as an unauthenticated request preceding an unexpected privilege context, which AMSI full-body scanning is positioned to catch. No IOCs or exploiting cluster have been published for either.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.</p><p class="entry-cite__quote">Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.</p><figcaption class="entry-cite__attr"><a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-56155" target="_blank" rel="noopener noreferrer">Microsoft MSRC</a> <span class="entry-cite__date mono">2026-07-14</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">It&#39;s a missing-authentication flaw, meaning an unauthenticated attacker can hit it over the network with no user interaction required. When something this reachable is being actively abused, patch it now and worry about the score later.</p><figcaption class="entry-cite__attr"><a href="https://www.zerodayinitiative.com/blog/2026/7/14/the-july-2026-security-update-review" target="_blank" rel="noopener noreferrer">Zero Day Initiative (Trend Micro)</a> <span class="entry-cite__date mono">2026-07-14</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>14 Jul 20:19Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-14/microsoft-july-2026-patch-tuesday-two-exploited-zero-days/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-56155" target="_blank" rel="noopener noreferrer">Microsoft MSRC</a> · <a href="https://www.zerodayinitiative.com/blog/2026/7/14/the-july-2026-security-update-review" target="_blank" rel="noopener noreferrer">Zero Day Initiative (Trend Micro)</a> · <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/" target="_blank" rel="noopener noreferrer">BleepingComputer</a> · <a href="https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flaws/" target="_blank" rel="noopener noreferrer">Krebs on Security</a></div></article>]]></content:encoded></item><item><title>Honeypots record in-the-wild exploitation of the ShareFile Storage Zone Controller auth bypass the same day Progress ordered shutdowns</title><link>https://ctipilot.ch/entries/2026-07-14/progress-sharefile-szc-active-exploitation-confirmed/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-14/progress-sharefile-szc-active-exploitation-confirmed/</guid><pubDate>Tue, 14 Jul 2026 12:50:00 +0000</pubDate><dc:date>2026-07-14T12:50:00Z</dc:date><category>vulnerabilities</category><category>actively-exploited</category><category>rce</category><category>pre-auth</category><category>auth-bypass</category><category>global</category><category>europe</category><category>us</category><category>exploited</category><category>poc-public</category><category>patch-available</category><category>CVE-2026-2699</category><description><![CDATA[<p>Update to the 2026-07-13 ShareFile shutdown entry. Shadowserver Foundation honeypots first recorded active, in-the-wild exploitation attempts against the ShareFile Storage Zone Controller pre-auth authentication bypass CVE-2026-2699 on Friday 2026-07-10 — the same day Progress issued its emergency power-off order — and the internet-exposed instance count fell from watchTowr&#39;s April tally of ~30,000 to roughly 1,000 by 2026-07-13. A Recorded Future analyst publicly assessed possible Clop involvement; Progress has named no actor and disclosed no root cause. On-prem operators still running Storage Zone Controllers should keep them off.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-14/progress-sharefile-szc-active-exploitation-confirmed" data-tags="vulnerabilities actively-exploited rce pre-auth auth-bypass" data-regions="global europe us" data-kind="incident" data-priority="high" data-discovered="2026-07-14T12:50:00Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-2699/">CVE-2026-2699</a><span class="b exp">exploited</span><span class="b upd">update</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 1: Confirmed"><span class="k">NATO</span>B1</span></div><h3 class="f-h" id="progress-sharefile-szc-active-exploitation-confirmed"><a href="https://ctipilot.ch/entries/2026-07-14/progress-sharefile-szc-active-exploitation-confirmed/">Progress ShareFile Storage Zone Controller — Shadowserver confirms active exploitation of CVE-2026-2699; exposed instances collapse ~30,000 to ~1,000</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-07-13/progress-sharefile-storage-zone-controller-shutdown/">Progress orders ShareFile Storage Zone Controller shutdown over a &#39;credible external threat&#39; — day three, no patch or root cause disclosed</a> <span class="mono muted">(2026-07-13)</span></p><p>Two developments harden the picture around Progress&#39;s emergency ShareFile Storage Zone Controller (SZC) shutdown order. First, the shutdown was not precautionary in the abstract: the alert &quot;arrived the same day that independent honeypots began detecting active, in-the-wild attempts to exploit&quot; the pre-auth authentication-bypass flaw CVE-2026-2699, with Shadowserver Foundation honeypots first recording those attempts on Friday 2026-07-10 (<a href="https://www.bankinfosecurity.com/progress-urges-sharefile-shutdown-over-credible-threat-a-32210" target="_blank" rel="noopener noreferrer">BankInfoSecurity, 2026-07-13</a>). This moves the flaw&#39;s status from PoC-public to actively exploited. Second, defenders responded at scale — the number of internet-exposed Storage Zone Controllers fell from watchTowr&#39;s April count of about 30,000 to roughly 1,000 by 2026-07-13, evidence of widespread emergency power-downs (<a href="https://www.bankinfosecurity.com/progress-urges-sharefile-shutdown-over-credible-threat-a-32210" target="_blank" rel="noopener noreferrer">BankInfoSecurity, 2026-07-13</a>). Progress restored ShareFile cloud-service access for SZC customers but continues to require the on-prem controllers themselves stay powered off pending its investigation, and still reports no evidence of unauthorized access to customer data (<a href="https://www.theregister.com/security/2026/07/13/progress-orders-emergency-sharefile-server-shutdown-over-mystery-security-threat/5270281" target="_blank" rel="noopener noreferrer">The Register, 2026-07-13</a>; <a href="https://status.sharefile.com/" target="_blank" rel="noopener noreferrer">Progress ShareFile status, 2026-07-13</a>).</p>
<p>Recorded Future analyst Allan Liska publicly assessed that the pattern &quot;smells like CL0P ransomware group activity,&quot; pointing to Clop&#39;s long record of mass-exploiting secure file-transfer software (Accellion FTA, GoAnywhere, MOVEit, Cleo Harmony, and Oracle E-Business Suite) (<a href="https://www.bankinfosecurity.com/progress-urges-sharefile-shutdown-over-credible-threat-a-32210" target="_blank" rel="noopener noreferrer">BankInfoSecurity, 2026-07-13</a>). This is a named researcher&#39;s hypothesis, not an attribution: Progress has identified no actor and disclosed no root cause.</p>
<p><strong>Defender takeaway.</strong> The one-day earlier guidance — treat any exposed SZC as untrusted and keep it powered off rather than patched — is now backed by confirmed in-the-wild exploitation, so it should carry more weight, not less, for any organisation that has not yet acted. Exposure concentrates in the US and Germany, keeping this directly relevant to European on-prem file-exchange operators. The recommended state remains a full power-off of on-prem Storage Zone Controllers until Progress publishes scope; the original entry&#39;s shutdown and bounded-compromise-check actions still stand unchanged.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">The alert arrived the same day that independent honeypots began detecting active, in-the-wild attempts to exploit a critical authentication bypass vulnerability the vendor patched earlier this year in its ShareFile Storage Zone Controller software.</p><p class="entry-cite__quote">Honeypots run by nonprofit cybersecurity organization Shadowserver Foundation first recorded active, in-the-wild attacks attempting to exploit CVE-2026-2699 on Friday.</p><p class="entry-cite__quote">This smells like CL0P ransomware group activity. If you use ShareFile, be like C-3PO and &#39;shut them all down.&#39;</p><figcaption class="entry-cite__attr"><a href="https://www.bankinfosecurity.com/progress-urges-sharefile-shutdown-over-credible-threat-a-32210" target="_blank" rel="noopener noreferrer">BankInfoSecurity (ISMG)</a> <span class="entry-cite__date mono">2026-07-13</span></figcaption></figure></div><div class="prov"><span>incident</span><span>14 Jul 12:50Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-14/progress-sharefile-szc-active-exploitation-confirmed/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bankinfosecurity.com/progress-urges-sharefile-shutdown-over-credible-threat-a-32210" target="_blank" rel="noopener noreferrer">BankInfoSecurity (ISMG)</a> · <a href="https://www.theregister.com/security/2026/07/13/progress-orders-emergency-sharefile-server-shutdown-over-mystery-security-threat/5270281" target="_blank" rel="noopener noreferrer">The Register</a> · <a href="https://status.sharefile.com/" target="_blank" rel="noopener noreferrer">Progress ShareFile (vendor status page)</a></div></article>]]></content:encoded></item><item><title>Attacker abuses an AsyncAPI GitHub Actions pwn-request to steal a publish token and backdoor five @asyncapi npm versions with a multi-stage implant</title><link>https://ctipilot.ch/entries/2026-07-14/asyncapi-npm-supply-chain-compromise-github-actions/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-14/asyncapi-npm-supply-chain-compromise-github-actions/</guid><pubDate>Tue, 14 Jul 2026 12:38:00 +0000</pubDate><dc:date>2026-07-14T12:38:00Z</dc:date><category>supply-chain</category><category>infostealer</category><category>identity</category><category>global</category><description><![CDATA[<p>On 2026-07-14 an attacker abused a misconfigured pull_request_target GitHub Actions workflow in the asyncapi/generator repository to steal the AsyncAPI org&#39;s npm/service-account token and publish five trojanized @asyncapi package versions (generator, generator-helpers, generator-components, specs — together over three million downloads a week). On import the packages fetch a multi-stage IPFS-hosted implant that self-identifies as &quot;M-RED-TEAM v6.4&quot;, persists, and reaches multi-channel command-and-control. Any CI/CD pipeline or developer host that imported an affected version should treat it as compromised and rotate exposed credentials.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-14/asyncapi-npm-supply-chain-compromise-github-actions" data-tags="supply-chain infostealer identity" data-regions="global" data-kind="incident" data-priority="high" data-discovered="2026-07-14T12:38:00Z"><div class="badges"><span class="b pri">HIGH</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 1: Confirmed"><span class="k">NATO</span>B1</span></div><h3 class="f-h" id="asyncapi-npm-supply-chain-compromise-github-actions"><a href="https://ctipilot.ch/entries/2026-07-14/asyncapi-npm-supply-chain-compromise-github-actions/">AsyncAPI npm packages backdoored via a GitHub Actions pull_request_target token theft, delivering a multi-stage IPFS implant (M-RED-TEAM)</a></h3><p>On 2026-07-14 an attacker compromised the <code>asyncapi/generator</code> GitHub repository by abusing a <code>pull_request_target</code> workflow that checked out the pull request&#39;s own code while still running &quot;in the context of the base repository with full access to secrets&quot; (<a href="https://www.wiz.io/blog/m-red-team-asyncapi-supply-chain-compromise-via-github-actions" target="_blank" rel="noopener noreferrer">Wiz, 2026-07-14</a>). The attacker opened 37 pull requests — almost all a decoy adding a fake charity-donation page — while a single one (PR #2155, 05:08 UTC) carried obfuscated JavaScript that scanned the Actions runner environment for secrets and exfiltrated them to a paste-site dead drop, capturing the token of <code>asyncapi-bot</code>, a service account with organization-wide access; by 06:58 UTC the attacker pushed a malicious commit to the <code>next</code> branch and from 07:10 UTC the release workflow published five trojanized versions across four packages — <code>@asyncapi/generator</code> 3.3.1, <code>@asyncapi/generator-helpers</code> 1.1.1, <code>@asyncapi/generator-components</code> 0.7.1, and <code>@asyncapi/specs</code> 6.11.2 and 6.11.2-alpha.1 — which &quot;combined, these packages see over three million downloads a week&quot; (<a href="https://www.wiz.io/blog/m-red-team-asyncapi-supply-chain-compromise-via-github-actions" target="_blank" rel="noopener noreferrer">Wiz, 2026-07-14</a>). A contributor had opened a fix for the vulnerable workflow on 2026-05-17; it was still unmerged 58 days later when the attack landed.</p>
<p>The injected code executes on <code>import</code>/<code>require</code>, not at install time: it spawns a detached Node child process that downloads a later stage from IPFS into a per-user application-support directory, then runs an encrypted multi-stage bundle whose runtime &quot;explicitly self-identifies as &#39;M-RED-TEAM v6.4&#39; in code comments&quot; (<a href="https://www.wiz.io/blog/m-red-team-asyncapi-supply-chain-compromise-via-github-actions" target="_blank" rel="noopener noreferrer">Wiz, 2026-07-14</a>). It establishes persistence via a systemd user service on Linux (with platform-specific equivalents on macOS and Windows) and beacons over multiple command-and-control channels — HTTP, Nostr relays, Ethereum smart contracts, and a libp2p mesh — accepting remote commands for file operations, directory listing and data exfiltration; its obfuscation uses <code>javascript-obfuscator</code> with a custom base64 alphabet matching prior incidents. The bundle carries credential-theft capabilities targeting saved browser passwords and cookies, SSH keys, npm and GitHub tokens, AWS credentials, the macOS Keychain and crypto wallets. Wiz notes technical fingerprints overlapping the Miasma framework (a <code>miasma</code>-branded persistence service and relay tags) and a dead-drop naming pattern matching the separately-tracked prt-scan pull-request-abuse campaign, but states that &quot;beyond the references and initial obfuscation method the payload contains minimal resemblance to previous Miasma and Shai-Hulud payloads&quot; and that &quot;at this time, we are not making any definitive attribution.&quot; SafeDep, tracking the same incident, reports the payload self-identifying as <code>miasma-train-p1</code> rather than Wiz&#39;s <code>M-RED-TEAM v6.4</code> and frames the Miasma link more directly — &quot;this is either a private, parallel build by the same operators or a separate group that adopted the Miasma brand after the source was published&quot; (<a href="https://safedep.io/asyncapi-generator-supply-chain-attack-miasma-rat/" target="_blank" rel="noopener noreferrer">SafeDep, 2026-07-14</a>); a team hunting code-comment strings should check for both identifiers.</p>
<p><strong>Defender takeaway.</strong> This is a recurring 2026 pattern of <code>pull_request_target</code> &quot;pwn request&quot; abuse feeding npm-ecosystem backdoors, and the load-bearing control gap is a CI/CD one: any workflow that triggers on <code>pull_request_target</code> and then checks out untrusted PR code runs attacker code with access to repository secrets. Audit your own Actions workflows for that pattern, and — because the payload runs on import rather than install — a <code>--ignore-scripts</code> install policy does not neutralise it; only pinning to known-good versions and rebuilding from a clean state does.</p>
<p><strong>Triage:</strong> a legitimate <code>require()</code> of AsyncAPI tooling performs no runtime network activity; the signal is a detached Node child process spawned from an <code>npm</code>/<code>node</code> parent at import time that reaches out to an IPFS gateway or a peer-to-peer mesh and then creates a user-level persistence service — process-lineage telemetry (a script interpreter spawning a hidden detached child with outbound egress) plus a new systemd/user-service artifact created outside a package-manager transaction is the discriminator, since benign build tooling produces neither.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">On July 14, 2026, an attacker opened 37 pull requests to the AsyncAPI generator repository. Almost all attempted to add a fake charity donation page.</p><p class="entry-cite__quote">The payload executes on import/require, not install.</p><p class="entry-cite__quote">The payload includes credential theft capabilities targeting browser saved passwords and cookies (Chrome, Brave, Firefox, Edge), SSH keys, npm and GitHub tokens, AWS credentials, macOS Keychain, and cryptocurrency wallets.</p><figcaption class="entry-cite__attr"><a href="https://www.wiz.io/blog/m-red-team-asyncapi-supply-chain-compromise-via-github-actions" target="_blank" rel="noopener noreferrer">Wiz</a> <span class="entry-cite__date mono">2026-07-14</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">This is either a private, parallel build by the same operators or a separate group that adopted the Miasma brand after the source was published.</p><figcaption class="entry-cite__attr"><a href="https://safedep.io/asyncapi-generator-supply-chain-attack-miasma-rat/" target="_blank" rel="noopener noreferrer">SafeDep</a> <span class="entry-cite__date mono">2026-07-14</span></figcaption></figure></div><div class="prov"><span>incident</span><span>14 Jul 12:38Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-14/asyncapi-npm-supply-chain-compromise-github-actions/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.wiz.io/blog/m-red-team-asyncapi-supply-chain-compromise-via-github-actions" target="_blank" rel="noopener noreferrer">Wiz</a> · <a href="https://safedep.io/asyncapi-generator-supply-chain-attack-miasma-rat/" target="_blank" rel="noopener noreferrer">SafeDep</a></div></article>]]></content:encoded></item><item><title>OFAC and the UK sanction the 1VPNS bulletproof-VPN admin and a cryptor seller after the Swiss-backed First VPN takedown</title><link>https://ctipilot.ch/entries/2026-07-14/ofac-uk-sanctions-first-vpn-1vpns-cryptor-seller/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-14/ofac-uk-sanctions-first-vpn-1vpns-cryptor-seller/</guid><pubDate>Tue, 14 Jul 2026 04:45:00 +0000</pubDate><dc:date>2026-07-14T04:45:00Z</dc:date><category>law-enforcement</category><category>ransomware</category><category>organized-crime</category><category>us</category><category>europe</category><category>switzerland</category><description><![CDATA[<p>Following the May 2026 Operation Saffron takedown of First VPN Service (1VPNS) — in which Switzerland was a joint-investigation-team partner — US Treasury OFAC and the UK FCDO on 2026-07-13 sanctioned 1VPNS, its administrator Dmytro Rashevskyi, and separately a Belarusian cryptor seller, Yegeniy Silayev, whose malware-obfuscation service is a distinct enabling layer beneath ransomware payloads. The service infrastructure is already down; the new development is the individual designations and the explicit targeting of the cryptor-as-a-service layer.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-14/ofac-uk-sanctions-first-vpn-1vpns-cryptor-seller" data-tags="law-enforcement ransomware organized-crime" data-regions="us europe switzerland" data-kind="incident" data-priority="notable" data-discovered="2026-07-14T04:45:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b upd">update</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 1: Confirmed"><span class="k">NATO</span>A1</span></div><h3 class="f-h" id="ofac-uk-sanctions-first-vpn-1vpns-cryptor-seller"><a href="https://ctipilot.ch/entries/2026-07-14/ofac-uk-sanctions-first-vpn-1vpns-cryptor-seller/">US and UK sanction First VPN Service (1VPNS), its administrator and a Belarusian cryptor seller — the sanctions follow-through on the Swiss-assisted Operation Saffron takedown</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-05-22/operation-saffron-dismantles-first-vpn-33-servers-seized-use/">Operation Saffron dismantles First VPN — 33+ servers seized, user database captured, Switzerland named JIT participant; Phobos RaaS infrastructure link confirmed</a> <span class="mono muted">(2026-05-22)</span></p><p>The May 2026 Operation Saffron takedown of First VPN Service (1VPNS) — the Russian-language, no-log criminal anonymisation service in which Switzerland sat on the Eurojust joint investigation team — has now drawn coordinated sanctions. On 2026-07-13 the US Treasury&#39;s Office of Foreign Assets Control, in an action coordinated with the UK&#39;s Foreign, Commonwealth &amp; Development Office, designated 1VPNS and its administrator <strong>Dmytro Rashevskyi</strong> (who used false identities including &quot;Maksim Sorin&quot; and &quot;Roman Chabanenko&quot; to buy infrastructure from providers that would otherwise have refused him), and separately a Belarusian national, <strong>Yegeniy Silayev</strong>, who sells &quot;cryptors&quot; (<a href="https://home.treasury.gov/news/press-releases/sb0559" target="_blank" rel="noopener noreferrer">US Treasury, 2026-07-13</a>). Treasury frames cryptors as tools &quot;built specifically to make malware stealthier and more effective by disguising it as harmless files&quot; (<a href="https://home.treasury.gov/news/press-releases/sb0559" target="_blank" rel="noopener noreferrer">US Treasury, 2026-07-13</a>) — designating the obfuscation-service vendor as a distinct enabling layer beneath the ransomware payload and the affiliate, not just the anonymisation infrastructure. The designations were made under Executive Order 13694 as amended; the FBI confirms the underlying takedown was led by France&#39;s BL2C and the Dutch NHTC &quot;with assistance from Ukraine, the United Kingdom, Switzerland, and Luxembourg,&quot; and that at least 25 ransomware groups, including Avaddon, used the service for reconnaissance and intrusions (<a href="https://www.fbi.gov/contact-us/field-offices/boston/news/fbi-boston-supports-international-takedown-of-first-vpn-service-used-by-ransomware-actors-to-compromise-businesses-worldwide" target="_blank" rel="noopener noreferrer">FBI Boston, 2026-06-09</a>).</p>
<p>Treasury describes the concrete abuse pattern: ransomware groups purchased 1VPNS infrastructure and used it &quot;to hide the origins of their attacks, deploy malware, and manage exfiltrated data&quot; — an external commercial VPN used as an anonymising relay in front of the operators&#39; own reconnaissance, delivery and exfiltration traffic (<a href="https://home.treasury.gov/news/press-releases/sb0559" target="_blank" rel="noopener noreferrer">US Treasury, 2026-07-13</a>).</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the operational picture is unchanged from May — the infrastructure is seized and historical flows to the 1vpns domains remain investigative leads through Europol channels — but the sanctions extend the disruption to the <em>cryptor-as-a-service</em> layer, a reminder that malware-obfuscation vendors are now first-class law-enforcement targets in their own right, distinct from the ransomware operators who buy from them. For finance-sector entities in the constituency the designations carry a routine SDN-screening obligation; there is no new host- or network-level defender action, and the US remediation framing does not change the operational priority of any control.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">OFAC is designating two individuals and one entity enabling ransomware actors&#39; and other cybercriminals&#39; malign activities, notably ransomware attacks against Americans.</p><p class="entry-cite__quote">cryptors are built specifically to make malware stealthier and more effective by disguising it as harmless files</p><figcaption class="entry-cite__attr"><a href="https://home.treasury.gov/news/press-releases/sb0559" target="_blank" rel="noopener noreferrer">US Department of the Treasury (OFAC)</a> <span class="entry-cite__date mono">2026-07-13</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">This takedown was conducted by France&#39;s Direction Régionale de la Police Judiciaire Brigade de Lutte Contre la Cybercriminalité (BL2C), and the Dutch National Police, National High Tech Crime Unit (NHTC), with assistance from Ukraine, the United Kingdom, Switzerland, and Luxembourg.</p><figcaption class="entry-cite__attr"><a href="https://www.fbi.gov/contact-us/field-offices/boston/news/fbi-boston-supports-international-takedown-of-first-vpn-service-used-by-ransomware-actors-to-compromise-businesses-worldwide" target="_blank" rel="noopener noreferrer">FBI Boston Field Office</a> <span class="entry-cite__date mono">2026-06-09</span></figcaption></figure></div><div class="prov"><span>incident</span><span>14 Jul 04:45Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-14/ofac-uk-sanctions-first-vpn-1vpns-cryptor-seller/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://home.treasury.gov/news/press-releases/sb0559" target="_blank" rel="noopener noreferrer">US Department of the Treasury (OFAC)</a> · <a href="https://ofac.treasury.gov/recent-actions/20260713" target="_blank" rel="noopener noreferrer">OFAC Recent Actions</a> · <a href="https://www.fbi.gov/contact-us/field-offices/boston/news/fbi-boston-supports-international-takedown-of-first-vpn-service-used-by-ransomware-actors-to-compromise-businesses-worldwide" target="_blank" rel="noopener noreferrer">FBI Boston Field Office</a></div></article>]]></content:encoded></item><item><title>Progress tells all on-prem ShareFile Storage Zone Controller customers to power off their servers over an undisclosed &#39;credible external security threat&#39;</title><link>https://ctipilot.ch/entries/2026-07-13/progress-sharefile-storage-zone-controller-shutdown/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-13/progress-sharefile-storage-zone-controller-shutdown/</guid><pubDate>Mon, 13 Jul 2026 12:45:00 +0000</pubDate><dc:date>2026-07-13T12:45:00Z</dc:date><category>vulnerabilities</category><category>rce</category><category>pre-auth</category><category>patch-available</category><category>global</category><category>europe</category><category>us</category><category>poc-public</category><category>patch-available</category><category>CVE-2026-2699</category><category>CVE-2026-2701</category><description><![CDATA[<p>Progress Software has ordered every customer running an on-premises ShareFile Storage Zone Controller (SZC) — the internet-facing IIS component bridging ShareFile&#39;s cloud to customer-managed storage — to physically shut the hosting server down over &quot;a credible external security threat,&quot; first notified 2026-07-10 and still unresolved on the vendor status page as of 2026-07-13. No CVE, root cause, patch or restart timeline has been published; the shutdown-not-patch instruction signals no fix yet exists. Exposure of the component concentrates in the US and Germany, giving Swiss/European on-prem file-exchange operators direct reason to act.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-13/progress-sharefile-storage-zone-controller-shutdown" data-tags="vulnerabilities rce pre-auth patch-available" data-regions="global europe us" data-kind="incident" data-priority="high" data-discovered="2026-07-13T12:45:00Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-2699/">CVE-2026-2699 +1</a><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 2: Probably true"><span class="k">NATO</span>A2</span></div><h3 class="f-h" id="progress-sharefile-storage-zone-controller-shutdown"><a href="https://ctipilot.ch/entries/2026-07-13/progress-sharefile-storage-zone-controller-shutdown/">Progress orders ShareFile Storage Zone Controller shutdown over a &#39;credible external threat&#39; — day three, no patch or root cause disclosed</a></h3><p>Progress Software has told every customer running an on-premises ShareFile Storage Zone Controller (SZC) — the self-hosted IIS component that lets ShareFile&#39;s SaaS front end store files on customer-controlled storage (local filesystem, SMB, SharePoint, S3/Azure) rather than in Progress&#39;s cloud — to manually power off the Windows server hosting it, citing &quot;a credible external security threat&quot; first notified to customers on 2026-07-10 (<a href="https://www.bleepingcomputer.com/news/security/progress-urges-sharefile-customers-to-shut-down-servers-over-credible-threat/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-07-10</a>). Three days on, the vendor status page still lists the Storage Zone Controller service as not operational and under investigation (<a href="https://status.sharefile.com/" target="_blank" rel="noopener noreferrer">Progress ShareFile status, 2026-07-13</a>), and Progress has disclosed neither a CVE, a root cause, nor a patch or safe-restart timeline; the mitigation on offer is a full shutdown rather than an update, with no fix published as of this run (<a href="https://www.heise.de/en/news/Progress-warns-admins-Deactivate-ShareFile-11362439.html" target="_blank" rel="noopener noreferrer">heise online, 2026-07-13</a>; <a href="https://www.securityweek.com/progress-prompts-sharefile-storage-zone-controller-shutdown-amid-security-concerns/" target="_blank" rel="noopener noreferrer">SecurityWeek, 2026-07-13</a>). heise characterises the shutdown as a precautionary measure during an ongoing investigation. Progress states it has no indication of unauthorized access to any ShareFile account or data so far. Only on-premises SZC deployments are affected; cloud-only ShareFile tenants are not.</p>
<p>This sits on top of a chainable pre-auth RCE that watchTowr Labs disclosed in the same component in April 2026: CVE-2026-2699 (CVSS 9.8) is a CWE-698 execution-after-redirect authentication bypass in <code>/ConfigService/Admin.aspx</code>, where <code>Response.Redirect()</code> is called with the terminate flag set to false, so the admin page body still renders and executes after the browser is told to redirect to login; CVE-2026-2701 (CVSS 9.1) chains from that access, because the storage-location validation only checks writability, letting an attacker repoint the storage repository at the IIS web root and land an ASPX web shell (<a href="https://labs.watchtowr.com/youre-not-supposed-to-sharefile-with-everyone-progress-sharefile-pre-auth-rce-chain-cve-2026-2699-cve-2026-2701/" target="_blank" rel="noopener noreferrer">watchTowr Labs, 2026-04-02</a>). Both were fixed in Storage Zone Controller 5.12.4 (the 6.x .NET-Core branch was unaffected); watchTowr counted roughly 30,000 internet-facing SZC instances at disclosure. Progress has not said whether the current threat relates to this chain or to a separate issue.</p>
<p><strong>Defender takeaway.</strong> This is the same on-prem, internet-facing, managed-file-transfer-adjacent architecture class (ShareFile, MOVEit, GoAnywhere, Cleo) that has repeatedly produced mass pre-auth exploitation, and a vendor ordering customers to pull the plug rather than patch is a strong signal to treat any exposed SZC as untrusted until Progress publishes scope. Regardless of whether the July threat proves related to CVE-2026-2699/2701, any instance still on SZC 5.x below 5.12.4 carries a known, PoC-backed pre-auth RCE and should be upgraded or taken offline now. Since Progress has confirmed no mechanism, treat the CWE-698 chain as the working hunt hypothesis.</p>
<p><strong>Triage:</strong> an authenticated administrator legitimately hits <code>/ConfigService/Admin.aspx</code> and receives a normal authenticated session; the anomaly for the known chain is a request to that path that returns a 302 whose response body nonetheless carries the full admin-panel HTML (the execution-after-redirect behaviour) rather than the redirect being honoured, followed by configuration changes to Zone/Primary-Zone-Controller/storage-repository fields outside a change window — and, downstream, an <code>.aspx</code> file appearing under a StorageCenter webroot subdirectory that is not part of the vendor&#39;s shipped file set.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">We have reason to believe there is a credible external security threat targeting Progress Software&#39;s ShareFile Storage Zone Controllers.</p><p class="entry-cite__quote">Currently, we have no indication of unauthorized access to any Progress ShareFile accounts or data.</p><figcaption class="entry-cite__attr">Progress Software (via BleepingComputer)</figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">ShareFile customers with Storage Zone Controllers are not operational at this time.</p><figcaption class="entry-cite__attr"><a href="https://status.sharefile.com/" target="_blank" rel="noopener noreferrer">Progress ShareFile (vendor status page)</a> <span class="entry-cite__date mono">2026-07-13</span></figcaption></figure></div><div class="prov"><span>incident</span><span>13 Jul 12:45Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-13/progress-sharefile-storage-zone-controller-shutdown/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://status.sharefile.com/" target="_blank" rel="noopener noreferrer">Progress ShareFile (vendor status page)</a> · <a href="https://www.bleepingcomputer.com/news/security/progress-urges-sharefile-customers-to-shut-down-servers-over-credible-threat/" target="_blank" rel="noopener noreferrer">BleepingComputer</a> · <a href="https://www.heise.de/en/news/Progress-warns-admins-Deactivate-ShareFile-11362439.html" target="_blank" rel="noopener noreferrer">heise online</a> · <a href="https://www.securityweek.com/progress-prompts-sharefile-storage-zone-controller-shutdown-amid-security-concerns/" target="_blank" rel="noopener noreferrer">SecurityWeek</a> · <a href="https://labs.watchtowr.com/youre-not-supposed-to-sharefile-with-everyone-progress-sharefile-pre-auth-rce-chain-cve-2026-2699-cve-2026-2701/" target="_blank" rel="noopener noreferrer">watchTowr Labs</a></div></article>]]></content:encoded></item><item><title>19-agency advisory details FSB Centre 16 router hijacking via SNMP and Cisco Smart Install as the UK and EU attribute Poland&#39;s Dec-2025 grid sabotage</title><link>https://ctipilot.ch/entries/2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory/</guid><pubDate>Mon, 13 Jul 2026 12:40:00 +0000</pubDate><dc:date>2026-07-13T12:40:00Z</dc:date><category>nation-state</category><category>espionage</category><category>actively-exploited</category><category>cisa-kev</category><category>wiper</category><category>law-enforcement</category><category>ot-ics</category><category>russia-nexus</category><category>global</category><category>europe</category><category>exploited</category><category>cisa-kev</category><category>patch-available</category><category>CVE-2018-0171</category><description><![CDATA[<p>A joint Cybersecurity Advisory from 19 agencies across 13 countries (2026-07-13) details how Russian FSB Centre 16 (Static Tundra / Berserk Bear) opportunistically compromises internet-facing routers across energy, government, telecom, finance and healthcare — chiefly by abusing default/weak SNMP community strings and the seven-year-old Cisco Smart Install flaw CVE-2018-0171 (CISA KEV) to exfiltrate device configurations. On the same day the UK and EU formally attributed the destructive 29 Dec 2025 attack on Poland&#39;s energy grid to this FSB unit and imposed their first joint cyber-sanctions package. Swiss and European critical-infrastructure operators running Cisco IOS/IOS XE or legacy SNMP on exposed network devices should treat router hygiene as an active-exploitation priority.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory" data-tags="nation-state espionage actively-exploited cisa-kev wiper law-enforcement ot-ics russia-nexus" data-regions="global europe" data-kind="threat" data-priority="high" data-discovered="2026-07-13T12:40:00Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2018-0171/">CVE-2018-0171</a><span class="b exp">exploited</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 1: Confirmed"><span class="k">NATO</span>A1</span></div><h3 class="f-h" id="fsb-centre-16-static-tundra-router-hijacking-advisory"><a href="https://ctipilot.ch/entries/2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory/">FSB Centre 16 (Static Tundra) router-hijacking campaign: 19-agency joint advisory, formal Poland energy-grid attribution and first joint EU/UK cyber sanctions</a></h3><p><strong>Background.</strong> The FSB Centre 16 network-device cluster is not new — it has a decade-plus public record under the vendor labels Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly and Ghost Blizzard, and Cisco Talos profiled it in August 2025 as &quot;Static Tundra,&quot; documenting long-term compromise of unpatched and end-of-life network gear for configuration theft and persistent collection (<a href="https://blog.talosintelligence.com/static-tundra/" target="_blank" rel="noopener noreferrer">Cisco Talos, 2025-08-20</a>). What is new is a same-day trio of actions on 2026-07-13: a much fuller TTP disclosure, a formal government attribution of a destructive attack, and the first coordinated EU/UK cyber-sanctions package.</p>
<p>A joint Cybersecurity Advisory carrying 19 authoring and co-sealing agencies across 13 countries — NSA, CISA, FBI and DC3 (US) alongside the cyber and intelligence authorities of Australia, Canada, New Zealand, the UK, Czech Republic, Denmark, Estonia, Finland, France, Italy, Poland and Sweden — describes FSB Centre 16 opportunistically compromising poorly configured routers across communications, defense industrial base, energy, financial services, government (especially state/local), and healthcare sectors (<a href="https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF" target="_blank" rel="noopener noreferrer">NSA/CISA/FBI joint advisory, 2026-07-13</a>; <a href="https://www.ncsc.gov.uk/news/uk-and-allies-urge-critical-sectors-to-improve-defences-against-russian-intelligence-targeting" target="_blank" rel="noopener noreferrer">NCSC-UK, 2026-07-13</a>). The advisory notes these TTPs overlap with Salt Typhoon activity, so the hardening below counters more than one actor.</p>
<p>The primary access vector is not a novel exploit but weak SNMP hygiene. The actors scan internet IP ranges for SNMP agents that accept common or default community strings, then issue spoofed-source SNMP Set-Requests carrying object identifiers that instruct the device to copy its running configuration to a file (commonly <code>config.bkp</code> or <code>output.txt</code>) and transfer it, usually over TFTP, to a leased VPS or a compromised FTP server (<a href="https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF" target="_blank" rel="noopener noreferrer">joint advisory, 2026-07-13</a>). The advisory names the exact OIDs abused — <code>1.3.6.1.4.1.9.9.96.1.1</code> (Cisco Config Copy) and <code>1.3.6.1.4.1.9.9.96.1.1.1.1.5</code> (the destination address for the copied config). A stolen configuration frequently discloses further credentials and additional community strings, feeding lateral movement. Talos&#39;s profile records the actor guessing or reusing insecure read-write community strings such as <code>public</code> and <code>anonymous</code> (<a href="https://blog.talosintelligence.com/static-tundra/" target="_blank" rel="noopener noreferrer">Cisco Talos, 2025-08-20</a>). Secondarily — &quot;occasionally,&quot; per the advisory — the actors exploit known Cisco bugs and the Smart Install (SMI) feature, naming CVE-2018-0171 (the Smart Install pre-auth RCE, in CISA KEV since 2021) and CVE-2008-4128 (end-of-life devices only, no patch). Persistence has historically included the SYNful Knock IOS firmware implant.</p>
<p><strong>The Poland grid attribution.</strong> On the same day, the UK together with EU member states formally attributed the destructive 29 December 2025 attack on Poland&#39;s energy grid to FSB Centre 16 (<a href="https://www.ncsc.gov.uk/news/uk-and-allies-urge-critical-sectors-to-improve-defences-against-russian-intelligence-targeting" target="_blank" rel="noopener noreferrer">NCSC-UK, 2026-07-13</a>). CERT Polska&#39;s own incident report describes coordinated destructive activity against 30-plus wind and photovoltaic grid-connection substations — RTU, HMI and protection-relay firmware damaged or system files deleted — and a combined heat-and-power plant serving roughly half a million people, where wiper malware was blocked by the operator&#39;s EDR before detonation; CERT Polska tied the activity to the Static Tundra / Berserk Bear / Ghost Blizzard / Dragonfly cluster via VPS, router and anonymizing-infrastructure overlap and called it &quot;the first publicly described destructive activity attributed to this activity cluster&quot; (<a href="https://cert.pl/en/posts/2026/01/incident-report-energy-sector-2025/" target="_blank" rel="noopener noreferrer">CERT Polska, 2026-01-30</a>). Note the attribution is contested at the cluster-label level: earlier ESET reporting attributed the same DynoWiper attack to the GRU&#39;s Sandworm (<a href="https://www.bleepingcomputer.com/news/security/sandworm-hackers-linked-to-failed-wiper-attack-on-polands-energy-systems/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-01-24</a>), and the EU Council statement names FSB Centre 16 as the parent controlling several groups including Turla — so treat &quot;FSB Centre 16&quot; as an umbrella unit rather than a single team.</p>
<p>The sanctions package is the policy layer: the EU designated 9 individuals and 4 entities and the UK designated 24, covering senior GRU figures, the front company IMPULS accused of recruiting hackers for GRU Unit 29155, Lumma Stealer operators, and the disinformation outlet Rybar LLC (<a href="https://www.gov.uk/government/news/uk-and-eu-strike-russian-cyber-networks-with-new-sanctions" target="_blank" rel="noopener noreferrer">UK Government, 2026-07-13</a>; <a href="https://www.bleepingcomputer.com/news/security/eu-and-uk-hit-russia-with-first-joint-cyber-sanctions-package/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-07-13</a>).</p>
<p><strong>Detection.</strong> The telemetry classes to prioritise on network gear: network-flow and firewall logs for inbound SNMP Set-Requests (especially with spoofed or unfamiliar source addresses) and for outbound TFTP sessions initiated from a router/switch management interface to non-management destinations; device syslog and AAA/TACACS+ logs for unexpected &quot;config copy&quot; events, new local-account creation, and unexplained drops in logging volume — Talos documents the actor tampering with TACACS+ configuration to blind logging and standing up GRE tunnels to redirect victim traffic (<a href="https://blog.talosintelligence.com/static-tundra/" target="_blank" rel="noopener noreferrer">Cisco Talos, 2025-08-20</a>); and IDS rules keyed to inbound SNMP Set-Requests carrying the config-copy OIDs above, as the advisory recommends (<a href="https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF" target="_blank" rel="noopener noreferrer">joint advisory, 2026-07-13</a>). Baseline NetFlow for the new GRE tunnel endpoints Talos describes.</p>
<p><strong>Defender takeaway.</strong> For a Swiss or European CI operator this is a router-hygiene mandate with a live destructive precedent next door. Disable Smart Install where it is not in active use, confirm CVE-2018-0171 is patched, migrate management SNMP to v3 with authPriv and disable SNMPv1/v2c (or, where legacy SNMP is unavoidable, replace every default/weak community string and enforce read-only), restrict all management protocols to known stations via out-of-band ACLs, use Cisco password hashing type 8 (never 0/4/7), and treat the device configuration held in your management system — not the device itself — as the source of truth so a tampered config is detectable.</p>
<p><strong>Triage:</strong> legitimate network-management stations poll SNMP on a predictable cadence from a known IP set, almost always read-only GET/GET-NEXT. The signal is a <em>write</em> (SNMP Set-Request) — particularly one carrying the config-copy OIDs — from a source outside the management range or with an inconsistent/spoofed source address, followed by an outbound TFTP transfer from the device; either alone is weak, the sequence config-write-then-TFTP-egress is the discriminator.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">The actors scan for Internet IP ranges with active Simple Network Management Protocol (SNMP) agents that accept common or default community strings for authentication</p><figcaption class="entry-cite__attr"><a href="https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF" target="_blank" rel="noopener noreferrer">NSA / CISA / FBI / DC3 joint Cybersecurity Advisory (19 agencies, 13 countries)</a> <span class="entry-cite__date mono">2026-07-13</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">The UK together with EU member states has also today formally attributed the December 2025 attack on Poland&#39;s energy grid to Russia&#39;s FSB Centre 16.</p><figcaption class="entry-cite__attr"><a href="https://www.ncsc.gov.uk/news/uk-and-allies-urge-critical-sectors-to-improve-defences-against-russian-intelligence-targeting" target="_blank" rel="noopener noreferrer">NCSC-UK</a> <span class="entry-cite__date mono">2026-07-13</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">This is, however, the first publicly described destructive activity attributed to this activity cluster.</p><figcaption class="entry-cite__attr"><a href="https://cert.pl/en/posts/2026/01/incident-report-energy-sector-2025/" target="_blank" rel="noopener noreferrer">CERT Polska</a> <span class="entry-cite__date mono">2026-01-30</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">This reckless attack failed but could have caused 500,000 citizens to lose electricity in the depths of winter.</p><figcaption class="entry-cite__attr"><a href="https://www.gov.uk/government/news/uk-and-eu-strike-russian-cyber-networks-with-new-sanctions" target="_blank" rel="noopener noreferrer">UK Government (FCDO)</a> <span class="entry-cite__date mono">2026-07-13</span></figcaption></figure></div><div class="prov"><span>threat</span><span>13 Jul 12:40Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.ncsc.gov.uk/news/uk-and-allies-urge-critical-sectors-to-improve-defences-against-russian-intelligence-targeting" target="_blank" rel="noopener noreferrer">NCSC-UK</a> · <a href="https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF" target="_blank" rel="noopener noreferrer">NSA / CISA / FBI / DC3 joint Cybersecurity Advisory (19 agencies, 13 countries)</a> · <a href="https://www.gov.uk/government/news/uk-and-eu-strike-russian-cyber-networks-with-new-sanctions" target="_blank" rel="noopener noreferrer">UK Government (FCDO)</a> · <a href="https://cert.pl/en/posts/2026/01/incident-report-energy-sector-2025/" target="_blank" rel="noopener noreferrer">CERT Polska</a> · <a href="https://blog.talosintelligence.com/static-tundra/" target="_blank" rel="noopener noreferrer">Cisco Talos</a> · <a href="https://www.bleepingcomputer.com/news/security/eu-and-uk-hit-russia-with-first-joint-cyber-sanctions-package/" target="_blank" rel="noopener noreferrer">BleepingComputer</a></div></article>]]></content:encoded></item><item><title>Looking ahead — 2026-W28: items already in motion for the coming weeks</title><link>https://ctipilot.ch/entries/2026-07-12/looking-ahead-2026-w28/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-12/looking-ahead-2026-w28/</guid><pubDate>Sun, 12 Jul 2026 23:56:00 +0000</pubDate><dc:date>2026-07-12T23:56:00Z</dc:date><category>vulnerabilities</category><category>law-enforcement</category><category>ransomware</category><category>switzerland</category><category>europe</category><category>global</category><description><![CDATA[<p>Items already in motion, not predictions: the Dutch NIS2 Cyberbeveiligingswet enters into force 15 August 2026 (five weeks out) and the EU Cyber Resilience Act&#39;s 11 September vulnerability/incident-reporting obligation is ~60 days away; FINMA&#39;s post-quantum expectation-setting may harden into a binding circular; the Joomla extension file-upload wave&#39;s newest members (RSFiles!/Phoca) are patched but not yet exploited, and prior wave members reached CISA KEV within days; Unit 42 references an Expel write-up of The Gentlemen&#39;s suspected EDR-disable zero-day that has not yet published; and the STAC3725 initial-access broker continues weaponising CitrixBleed 2 against un-session-terminated NetScaler.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-12/looking-ahead-2026-w28" data-tags="vulnerabilities law-enforcement ransomware" data-regions="switzerland europe global" data-kind="outlook" data-priority="notable" data-discovered="2026-07-12T23:56:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="looking-ahead-2026-w28"><a href="https://ctipilot.ch/entries/2026-07-12/looking-ahead-2026-w28/">Looking ahead — 2026-W28</a></h3><p>Items already in motion for the coming weeks — each with a dated source or an in-week entry, none a prediction:</p>
<ul><li><strong>EU regulatory clocks.</strong> The Dutch NIS2 <strong>Cyberbeveiligingswet</strong> enters into force <strong>15 August 2026</strong> — now a fixed date after the 7 July Senate passage (<a href="https://www.rijksoverheid.nl/actueel/nieuws/2026/07/07/cyberbeveiligingswet-en-wet-weerbaarheid-kritieke-entiteiten-vanaf-15-augustus-2026-van-kracht" target="_blank" rel="noopener noreferrer">Rijksoverheid.nl, 2026-07-07</a>). The <strong>EU Cyber Resilience Act</strong> vulnerability/incident-reporting obligation lands <strong>11 September 2026</strong>, roughly 60 days out and previously covered in this store — the reporting-platform readiness is the item to watch next.</li><li><strong>FINMA post-quantum guidance may harden.</strong> FINMA&#39;s Aufsichtsmitteilung 05/2026 is supervisory expectation-setting, not yet a binding circular; the open question is whether it converts into a Rundschreiben revision (<a href="https://www.finma.ch/news/2026/07/20260709-mm-am-05-26/" target="_blank" rel="noopener noreferrer">FINMA, 2026-07-09</a>).</li><li><strong>Joomla file-upload wave — the newest members await exploitation.</strong> RSFiles! and Phoca Download are patched but not yet exploited, whereas earlier members of the same CWE-434 wave reached CISA KEV within days (<a href="https://mysites.guru/blog/rsfiles-unauthenticated-file-upload-rce/" target="_blank" rel="noopener noreferrer">mySites.guru, 2026-07-11</a>) — treat these as likely-imminent-KEV, not resolved.</li><li><strong>The Gentlemen EDR-disable zero-day.</strong> Unit 42 references an Expel analysis of a suspected zero-day the group uses to disable EDR, distinct from the GentleKiller BYOVD framework; that write-up had not published at the time of Unit 42&#39;s report (<a href="https://unit42.paloaltonetworks.com/the-gentlemen-ransomware/" target="_blank" rel="noopener noreferrer">Unit 42, 2026-07-10</a>).</li><li><strong>CitrixBleed 2 broker activity continues.</strong> Huntress&#39; STAC3725 reconstruction shows an initial-access broker actively weaponising CVE-2025-5777; organisations that patched but did not terminate live sessions remain exposed to token replay and downstream DragonForce deployment (<a href="https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware" target="_blank" rel="noopener noreferrer">Huntress, 2026-07-10</a>).</li></ul><p class="entry-references"><strong>Builds on:</strong> <a class="mono" href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-netherlands-nis2-in-force/">2026-07-12/weekly-w28-netherlands-nis2-in-force</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-finma-post-quantum-guidance/">2026-07-12/weekly-w28-finma-post-quantum-guidance</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-joomla-file-upload-rce-wave/">2026-07-12/weekly-w28-joomla-file-upload-rce-wave</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-the-gentlemen-status/">2026-07-12/weekly-w28-the-gentlemen-status</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-exploited-edge-enterprise-software/">2026-07-12/weekly-w28-exploited-edge-enterprise-software</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-06-29/eu-cyber-resilience-act-75-days-to-the-11-september-vulnerab/">2026-06-29/eu-cyber-resilience-act-75-days-to-the-11-september-vulnerab</a></p><div class="prov"><span>outlook</span><span>12 Jul 23:56Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-12/looking-ahead-2026-w28/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.rijksoverheid.nl/actueel/nieuws/2026/07/07/cyberbeveiligingswet-en-wet-weerbaarheid-kritieke-entiteiten-vanaf-15-augustus-2026-van-kracht" target="_blank" rel="noopener noreferrer">Rijksoverheid.nl (Dutch national government)</a> · <a href="https://www.finma.ch/news/2026/07/20260709-mm-am-05-26/" target="_blank" rel="noopener noreferrer">FINMA</a> · <a href="https://mysites.guru/blog/rsfiles-unauthenticated-file-upload-rce/" target="_blank" rel="noopener noreferrer">mySites.guru</a> · <a href="https://unit42.paloaltonetworks.com/the-gentlemen-ransomware/" target="_blank" rel="noopener noreferrer">Palo Alto Networks Unit 42</a> · <a href="https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware" target="_blank" rel="noopener noreferrer">Huntress</a></div></article>]]></content:encoded></item><item><title>FINMA AM 05/2026 — Swiss financial institutions lack a post-quantum migration roadmap; FINMA sets crypto-inventory and crypto-agility expectations</title><link>https://ctipilot.ch/entries/2026-07-12/weekly-w28-finma-post-quantum-guidance/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-12/weekly-w28-finma-post-quantum-guidance/</guid><pubDate>Sun, 12 Jul 2026 23:54:00 +0000</pubDate><dc:date>2026-07-12T23:54:00Z</dc:date><category>law-enforcement</category><category>switzerland</category><category>europe</category><description><![CDATA[<p>FINMA published Aufsichtsmitteilung 05/2026 on 9 July 2026, reporting a survey of 60 Swiss financial institutions on cryptographically-relevant quantum computing risk: institutions are aware of the threat but &#39;mostly lack a clear roadmap&#39; for migrating to quantum-safe encryption. FINMA names &#39;harvest now, decrypt later&#39; as the operative near-term threat and, under existing operational-risk expectations (not a new binding circular), expects institutions to build a PQC migration strategy, run an institution-specific risk analysis, maintain a cryptographic inventory, adopt crypto-agility, and extend this to outsourced providers. No new mandatory deadline is set — this is expectation-setting ahead of a possible future circular.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-12/weekly-w28-finma-post-quantum-guidance" data-tags="law-enforcement" data-regions="switzerland europe" data-kind="policy" data-priority="notable" data-discovered="2026-07-12T23:54:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 1: Confirmed"><span class="k">NATO</span>A1</span></div><h3 class="f-h" id="weekly-w28-finma-post-quantum-guidance"><a href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-finma-post-quantum-guidance/">FINMA sets post-quantum crypto expectations for the Swiss financial sector — Aufsichtsmitteilung 05/2026 flags &#39;harvest now, decrypt later&#39; and a missing migration roadmap</a></h3><p>FINMA published <strong>Aufsichtsmitteilung (supervisory communication) 05/2026</strong> on 9 July 2026, presenting the results of a November 2025–January 2026 survey of 60 Swiss financial institutions on cryptographically-relevant quantum computing (CRQC) risk. Its core finding: institutions are aware of the threat but &quot;meist fehlt aber eine klare Roadmap und eine ausreichend vorausschauende Planung für die Migration zu quantensicherer Verschlüsselung&quot; — most lack a clear roadmap and sufficiently forward-looking planning for the migration to quantum-safe encryption (<a href="https://www.finma.ch/news/2026/07/20260709-mm-am-05-26/" target="_blank" rel="noopener noreferrer">FINMA, 2026-07-09</a>). FINMA explicitly names <strong>&quot;harvest now, decrypt later&quot;</strong> — capture-and-store-for-future-decryption of today&#39;s encrypted traffic and data — as the operative near-term threat model, and sets, under existing operational-risk-and-resilience supervisory expectations rather than a new binding circular, that institutions should produce a PQC migration strategy and roadmap, run an institution-specific risk analysis, &quot;die Erstellung eines kryptographischen Inventars&quot; (build a cryptographic inventory), adopt crypto-agility, and extend the planning to outsourced service providers. No mandatory deadline accompanies the communication (<a href="https://www.swissinfo.ch/eng/various/finma-to-banks-further-measures-are-needed-to-tackle-quantum-computers/91726878" target="_blank" rel="noopener noreferrer">swissinfo.ch, 2026-07-10</a>).</p>
<p><strong>Why this belongs in the strategic view:</strong> it is the home financial-sector regulator setting a direction of travel that a Swiss/EU public-sector or CI reader will encounter next as a compliance expectation, and it reframes post-quantum readiness as a near-term data-protection issue, not a distant cryptographic curiosity — because the &quot;harvest now, decrypt later&quot; risk accrues from <em>today&#39;s</em> captured traffic regardless of when a CRQC actually arrives.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the defensible near-term action for finance-sector (and CI) readers is to start the cryptographic inventory now — enumerate which systems, protocols (TLS/VPN/at-rest) and applications use which algorithms and key lengths — because that inventory is the prerequisite for any migration and the only way to reason about HNDL exposure; watch for whether FINMA converts this into a binding circular and whether NCSC-CH or ENISA issue parallel public-sector PQC guidance.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Die Institute sind sich der Cyberrisiken von kryptografisch relevanten Quantum Computern bewusst. Meist fehlt aber eine klare Roadmap und eine ausreichend vorausschauende Planung für die Migration zu quantensicherer Verschlüsselung.</p><p class="entry-cite__quote">Dazu gehört eine klare Strategie und Roadmap für die Migration zu quantensicheren Verschlüsselungen, eine institutsspezifische Risikoanalyse, die Erstellung eines kryptographischen Inventars, der Schutz kritischer Daten vor &#39;harvest now, decrypt later&#39; Angriffen.</p><figcaption class="entry-cite__attr">FINMA</figcaption></figure></div><div class="prov"><span>policy</span><span>12 Jul 23:54Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-finma-post-quantum-guidance/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.finma.ch/news/2026/07/20260709-mm-am-05-26/" target="_blank" rel="noopener noreferrer">FINMA (Swiss Financial Market Supervisory Authority)</a> · <a href="https://www.swissinfo.ch/eng/various/finma-to-banks-further-measures-are-needed-to-tackle-quantum-computers/91726878" target="_blank" rel="noopener noreferrer">SWI swissinfo.ch</a></div></article>]]></content:encoded></item><item><title>W28 incidents cluster on third-party / cloud-account exposure — Accenture, Deutsche Bank vendor, KDDI, Nayax cloud account, Odido vishing, Nextcloud misconfig</title><link>https://ctipilot.ch/entries/2026-07-12/weekly-w28-third-party-cloud-account-exposure/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-12/weekly-w28-third-party-cloud-account-exposure/</guid><pubDate>Sun, 12 Jul 2026 23:34:00 +0000</pubDate><dc:date>2026-07-12T23:34:00Z</dc:date><category>data-breach</category><category>supply-chain</category><category>cloud</category><category>organized-crime</category><category>switzerland</category><category>europe</category><category>global</category><description><![CDATA[<p>The week&#39;s confirmed incidents share a structural theme: the initial exposure sat in a cloud account, a third-party vendor, or a supplier platform rather than the victim&#39;s own perimeter. Accenture confirmed data theft after &#39;888&#39; advertised internal source code; Deutsche Bank disclosed a third-party vendor incident after &#39;Unsafe&#39; ransomware claims; KDDI named a third-party-software zero-day as the root cause of its 12M-record ISP email breach; Nayax (an EEA payment institution) disclosed a cloud-account incident claimed by &#39;The Syndicate&#39;; ShinyHunters&#39; Odido (NL telecom) breach drew Dutch-national-involvement attribution from police voice analysis; and Nextcloud GmbH&#39;s own hosting exposed 367K records via a misconfigured Elasticsearch. Supplier and cloud-account risk, not perimeter RCE, drove the week&#39;s disclosures.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-12/weekly-w28-third-party-cloud-account-exposure" data-tags="data-breach supply-chain cloud organized-crime" data-regions="switzerland europe global" data-kind="incident" data-priority="notable" data-discovered="2026-07-12T23:34:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 1: Confirmed"><span class="k">NATO</span>B1</span></div><h3 class="f-h" id="weekly-w28-third-party-cloud-account-exposure"><a href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-third-party-cloud-account-exposure/">This week&#39;s disclosures clustered on third-party, cloud-account and vendor exposure — the breach rarely started inside the victim</a></h3><p>Read as a set, the week&#39;s confirmed incidents point away from the classic perimeter-RCE story and toward exposure that lives in someone else&#39;s account, platform or supply chain.</p>
<p>The <strong>third-party / vendor</strong> strand: Accenture confirmed a data-theft incident after the handle &quot;888&quot; advertised roughly 35 GB of internal source code (<a href="https://www.bleepingcomputer.com/news/security/accenture-confirms-breach-after-hacker-offers-stolen-data-for-sale/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-07-08</a>); Deutsche Bank disclosed a third-party-vendor incident after the &quot;Unsafe&quot; ransomware group posted claims (<a href="https://www.computing.co.uk/news/2026/security/deutsche-bank-probes-supplier-cyber-incident-after-ransomware-gang-claims-breach" target="_blank" rel="noopener noreferrer">Computing, 2026-07-09</a>); and KDDI named a zero-day in third-party email-platform software as the root cause of a breach affecting about 12 million people (<a href="https://www.bleepingcomputer.com/news/security/japanese-telecom-giant-kddi-says-data-breach-affects-12-million-people/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-07-09</a>). The <strong>cloud-account</strong> strand: Nayax, a Bank-of-Lithuania-licensed EEA payment institution, disclosed a cloud-account incident (claimed by &quot;The Syndicate&quot;) in its own SEC Form 6-K (<a href="https://www.sec.gov/Archives/edgar/data/1901279/000117891326003440/zk2635660.htm" target="_blank" rel="noopener noreferrer">Nayax, 2026-07-09</a>); ShinyHunters&#39; Odido (Netherlands telecom) breach drew a Dutch-national-involvement assessment from police voice analysis (<a href="https://www.politie.nl/nieuws/2026/juli/8/onderzoek-naar-hack-odido-wijst-op-mogelijke-betrokkenheid-nederlanders.html" target="_blank" rel="noopener noreferrer">Politie, 2026-07-08</a>); and Nextcloud GmbH&#39;s own hosting infrastructure exposed roughly 367,000 internal records through a misconfigured public Elasticsearch (<a href="https://cybernews.com/security/nextcloud-cloud-provider-data-leak/" target="_blank" rel="noopener noreferrer">Cybernews, 2026-07-10</a>).</p>
<p><strong>Why the pattern matters for the constituency:</strong> several victims are directly relevant classes — an EEA-licensed payment institution, an EU telecom, a European cloud vendor — and the shared root cause is exactly the exposure a Swiss/EU public-sector or CI organisation inherits through its suppliers and cloud tenancy. The transferable lesson is that a mature internal patch posture does not cover a vendor&#39;s zero-day, a supplier&#39;s compromised account, or a misconfigured datastore in your own cloud footprint.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">treat third-party and cloud-account exposure as first-class incident surface — maintain a supplier inventory with incident-notification clauses, apply the same internet-exposure and misconfiguration scanning to cloud-hosted datastores as to on-prem, and monitor cloud-account sign-in anomalies with the same rigour as endpoint alerts. <strong>Triage:</strong> a supplier-origin compromise typically first surfaces as anomalous data access via a legitimate integration or service account rather than a malware alert — the discriminator is access volume and pattern on that account against its baseline, and exfiltration to an unexpected destination class.</div></aside><p class="entry-references"><strong>Builds on:</strong> <a class="mono" href="https://ctipilot.ch/entries/2026-07-08/accenture-confirms-data-theft-888-azure-devops-claim/">2026-07-08/accenture-confirms-data-theft-888-azure-devops-claim</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-09/deutsche-bank-unsafe-ransomware-third-party-vendor-incident/">2026-07-09/deutsche-bank-unsafe-ransomware-third-party-vendor-incident</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-09/kddi-isp-email-breach-zero-day-root-cause-update/">2026-07-09/kddi-isp-email-breach-zero-day-root-cause-update</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-09/nayax-cloud-account-incident-the-syndicate-claim/">2026-07-09/nayax-cloud-account-incident-the-syndicate-claim</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution/">2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-10/nextcloud-gmbh-elasticsearch-exposure-msb-nrw/">2026-07-10/nextcloud-gmbh-elasticsearch-exposure-msb-nrw</a></p><div class="prov"><span>incident</span><span>12 Jul 23:34Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-third-party-cloud-account-exposure/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bleepingcomputer.com/news/security/accenture-confirms-breach-after-hacker-offers-stolen-data-for-sale/" target="_blank" rel="noopener noreferrer">BleepingComputer</a> · <a href="https://www.sec.gov/Archives/edgar/data/1901279/000117891326003440/zk2635660.htm" target="_blank" rel="noopener noreferrer">Nayax Ltd. — SEC Form 6-K</a> · <a href="https://www.politie.nl/nieuws/2026/juli/8/onderzoek-naar-hack-odido-wijst-op-mogelijke-betrokkenheid-nederlanders.html" target="_blank" rel="noopener noreferrer">Politie (Dutch National Police)</a> · <a href="https://www.computing.co.uk/news/2026/security/deutsche-bank-probes-supplier-cyber-incident-after-ransomware-gang-claims-breach" target="_blank" rel="noopener noreferrer">Computing (UK)</a> · <a href="https://cybernews.com/security/nextcloud-cloud-provider-data-leak/" target="_blank" rel="noopener noreferrer">Cybernews</a></div></article>]]></content:encoded></item><item><title>Exposed enterprise software under active attack this week — ColdFusion (KEV), CitrixBleed 2 → DragonForce, Gitea escalated to actively-exploited</title><link>https://ctipilot.ch/entries/2026-07-12/weekly-w28-exploited-edge-enterprise-software/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-12/weekly-w28-exploited-edge-enterprise-software/</guid><pubDate>Sun, 12 Jul 2026 23:22:00 +0000</pubDate><dc:date>2026-07-12T23:22:00Z</dc:date><category>vulnerabilities</category><category>actively-exploited</category><category>pre-auth</category><category>rce</category><category>ransomware</category><category>cisa-kev</category><category>switzerland</category><category>europe</category><category>global</category><description><![CDATA[<p>Three separate internet-facing enterprise products crossed into confirmed exploitation in 2026-W28: Adobe ColdFusion CVE-2026-48282 (one of the 1 July CVSS 10.0 RCEs) was exploited within two hours of public detail and added to CISA KEV; Citrix NetScaler&#39;s CitrixBleed 2 (CVE-2025-5777) was reconstructed by Huntress into a repeatable initial-access-broker kill chain ending in DragonForce ransomware, where stolen session tokens survive patching; and NCSC-CH escalated the Gitea Docker reverse-proxy auth bypass (CVE-2026-20896) to actively exploited. The operational reality: any exposed unpatched instance of these should be treated as compromised, not merely vulnerable — and for CitrixBleed 2, patching alone is insufficient.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-12/weekly-w28-exploited-edge-enterprise-software" data-tags="vulnerabilities actively-exploited pre-auth rce ransomware cisa-kev" data-regions="switzerland europe global" data-kind="synthesis" data-priority="high" data-discovered="2026-07-12T23:22:00Z"><div class="badges"><span class="b pri">HIGH</span><span class="b exp">exploited</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 1: Confirmed"><span class="k">NATO</span>B1</span></div><h3 class="f-h" id="weekly-w28-exploited-edge-enterprise-software"><a href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-exploited-edge-enterprise-software/">Confirmed in-the-wild exploitation of internet-facing enterprise software converged this week — ColdFusion, Citrix NetScaler and Gitea all moved from &#39;at risk&#39; to &#39;under attack&#39;</a></h3><p><strong>If you did nothing this week:</strong> three classes of internet-facing enterprise software you likely have somewhere in the estate moved from theoretical risk to confirmed exploitation. An unpatched, exposed ColdFusion, Citrix NetScaler Gateway or Gitea instance should be handled as an incident, not a maintenance ticket — and for NetScaler, applying the patch does not evict an attacker who already has your session tokens.</p>
<p>The week&#39;s exploitation signal converged on the perimeter. <strong>Adobe ColdFusion</strong> CVE-2026-48282 — one of the six unauthenticated CVSS 10.0 RCEs Adobe patched on 1 July, and exactly the item last week&#39;s outlook flagged as awaiting weaponisation — was confirmed exploited in the wild and added to CISA KEV on 7 July; KEVIntel reported catching exploitation &quot;within under two hours of CVE-2026-48282 public details being released&quot; against its honeypots (<a href="https://www.bleepingcomputer.com/news/security/max-severity-adobe-coldfusion-flaw-now-exploited-in-attacks/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-07-08</a>). <strong>Citrix NetScaler</strong> saw the most operationally consequential development: Huntress reconstructed a mechanically identical intrusion chain across at least six unrelated organisations, run by an initial-access broker (Sophos: STAC3725) that steals pre-auth session tokens via CitrixBleed 2 (CVE-2025-5777) — &quot;sift[ing] through the heap fragments for valid session tokens of someone who is currently logged in&quot; (<a href="https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware" target="_blank" rel="noopener noreferrer">Huntress, 2026-07-10</a>) — then escalating via a registry-symlink privilege-escalation tool to SYSTEM, persisting with ScreenConnect/Zoho Assist, and in the most progressed case deploying DragonForce ransomware. Because the stolen tokens survive patching, remediation requires terminating live sessions as well. Finally, <strong>NCSC-CH</strong> escalated the Gitea Docker reverse-proxy authentication bypass (CVE-2026-20896) — full unauthenticated admin control &quot;via a single custom HTTP header&quot; — to &quot;Actively Exploited, Proof of Concept Available&quot; (<a href="https://security-hub.ncsc.admin.ch/#/posts/12755" target="_blank" rel="noopener noreferrer">NCSC-CH Cyber Security Hub, 2026-07-10</a>). A fourth strand — Langflow&#39;s cross-tenant IDOR (CVE-2026-55255) chained with pre-auth RCE, first exploited 25 June and now KEV-listed (<a href="https://www.sysdig.com/blog/understanding-langflow-cve-2026-55255-and-why-higher-cvss-vulnerabilities-arent-always-the-most-exploited" target="_blank" rel="noopener noreferrer">Sysdig, 2026-07-08</a>) — reinforces the same lesson: exploitation, not CVSS, is what set this week&#39;s priorities.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">exposure plus a confirmed exploitation record is the trigger, and for token-theft classes (CitrixBleed 2) the post-patch step — session termination and a hunt for broker-stage persistence (ScreenConnect/Zoho Assist installs, registry-symlink LPE artifacts) — is what actually closes the door. <strong>Triage:</strong> for NetScaler, benign session activity originates from expected client IP ranges and device postures; the broker signal is a burst of malformed pre-auth requests to the vulnerable endpoint followed by authenticated actions from a session whose token was never issued to that source, then a remote-support agent install under an anomalous parent.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Within under two hours of CVE-2026-48282 public details being released, KEVIntel captured in-the-wild exploitation within our global honeypot network.</p><figcaption class="entry-cite__attr">KEVIntel, via BleepingComputer</figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">By spraying enough of those requests, an adversary can then sift through the heap fragments for valid session tokens of someone who is currently logged in.</p><figcaption class="entry-cite__attr"><a href="https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware" target="_blank" rel="noopener noreferrer">Huntress</a></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">Current exploitation status: Actively Exploited, Proof of Concept Available</p><figcaption class="entry-cite__attr"><a href="https://security-hub.ncsc.admin.ch/#/posts/12755" target="_blank" rel="noopener noreferrer">NCSC-CH Cyber Security Hub</a></figcaption></figure></div><p class="entry-references"><strong>Builds on:</strong> <a class="mono" href="https://ctipilot.ch/entries/2026-07-08/cve-2026-48282-adobe-coldfusion-actively-exploited-kev/">2026-07-08/cve-2026-48282-adobe-coldfusion-actively-exploited-kev</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725/">2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-10/gitea-cve-2026-20896-ncsc-ch-actively-exploited-update/">2026-07-10/gitea-cve-2026-20896-ncsc-ch-actively-exploited-update</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-08/cve-2026-55255-langflow-idor-kev-chained-with-rce/">2026-07-08/cve-2026-55255-langflow-idor-kev-chained-with-rce</a></p><div class="prov"><span>synthesis</span><span>12 Jul 23:22Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-exploited-edge-enterprise-software/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bleepingcomputer.com/news/security/max-severity-adobe-coldfusion-flaw-now-exploited-in-attacks/" target="_blank" rel="noopener noreferrer">BleepingComputer</a> · <a href="https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware" target="_blank" rel="noopener noreferrer">Huntress</a> · <a href="https://security-hub.ncsc.admin.ch/#/posts/12755" target="_blank" rel="noopener noreferrer">NCSC-CH Cyber Security Hub</a> · <a href="https://www.sysdig.com/blog/understanding-langflow-cve-2026-55255-and-why-higher-cvss-vulnerabilities-arent-always-the-most-exploited" target="_blank" rel="noopener noreferrer">Sysdig Threat Research Team</a></div></article>]]></content:encoded></item><item><title>CERT-FR flags three new MOVEit Transfer CVEs — a pre-auth SFTP memory-leak DoS is reachable on any exposed instance (no exploitation yet)</title><link>https://ctipilot.ch/entries/2026-07-11/moveit-transfer-certfr-cve-2026-10699-10698-11903/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-11/moveit-transfer-certfr-cve-2026-10699-10698-11903/</guid><pubDate>Sat, 11 Jul 2026 13:05:00 +0000</pubDate><dc:date>2026-07-11T13:05:00Z</dc:date><category>vulnerabilities</category><category>dos</category><category>pre-auth</category><category>patch-available</category><category>global</category><category>europe</category><category>switzerland</category><category>patch-available</category><category>CVE-2026-10699</category><category>CVE-2026-10698</category><category>CVE-2026-11903</category><description><![CDATA[<p>France&#39;s CERT-FR/ANSSI advisory CERTFR-2026-AVI-0856 (2026-07-10) covers three newly-patched flaws in Progress MOVEit Transfer, the managed file-transfer product with a history of mass exploitation (Cl0p, 2023): CVE-2026-10699 (CVSS 7.5) is an unauthenticated SFTP-service memory leak an attacker can drive to denial of service; CVE-2026-10698 (CVSS 7.2) lets an admin-level user bypass Custom Reports table-scope restrictions to read or manipulate data outside scope; CVE-2026-11903 (CVSS 8.0) is a low-privilege stored XSS in the Ad Hoc module. No exploitation or public PoC is reported. Fixed in 2026.0.2 (and the 2025.0.8 / 2025.1.4 branch releases); Swiss/EU public-sector and finance operators running internet-facing MOVEit should prioritise the upgrade given the product&#39;s exposure profile and exploitation history.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-11/moveit-transfer-certfr-cve-2026-10699-10698-11903" data-tags="vulnerabilities dos pre-auth patch-available" data-regions="global europe switzerland" data-kind="vulnerability" data-priority="notable" data-discovered="2026-07-11T13:05:00Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-10699/">CVE-2026-10699 +2</a><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 2: Probably true"><span class="k">NATO</span>A2</span></div><h3 class="f-h" id="moveit-transfer-certfr-cve-2026-10699-10698-11903"><a href="https://ctipilot.ch/entries/2026-07-11/moveit-transfer-certfr-cve-2026-10699-10698-11903/">Progress MOVEit Transfer: pre-auth SFTP DoS (CVE-2026-10699), admin table-scope bypass (CVE-2026-10698) and stored XSS (CVE-2026-11903), patched 2026.0.2</a></h3><p>France&#39;s national CERT (CERT-FR/ANSSI) published advisory <a href="https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0856/" target="_blank" rel="noopener noreferrer">CERTFR-2026-AVI-0856</a> on 2026-07-10 for three newly-disclosed vulnerabilities in Progress MOVEit Transfer, a managed file-transfer product whose 2023 Cl0p mass-exploitation campaign against roughly 2,600 organisations makes any internet-facing MOVEit flaw worth prompt attention. The most exposure-relevant is <strong>CVE-2026-10699</strong> (CVSS 3.1 7.5, <a href="https://cve.threatint.eu/CVE/CVE-2026-10699" target="_blank" rel="noopener noreferrer">Progress CNA record</a>), a missing-release-of-memory flaw in the SFTP service: memory is not freed after its effective lifetime, letting an unauthenticated remote attacker exhaust memory and force a denial of service on any instance whose SFTP listener is reachable. <strong>CVE-2026-10698</strong> (CVSS 7.2, <a href="https://cve.threatint.eu/CVE/CVE-2026-10698" target="_blank" rel="noopener noreferrer">Progress CNA record</a>) is a query-logic flaw in the Custom Reports module that lets an attacker already holding admin-level privileges bypass a report&#39;s table-scope restrictions to read or manipulate data outside its intended scope, and <strong>CVE-2026-11903</strong> (CVSS 8.0, <a href="https://cve.threatint.eu/CVE/CVE-2026-11903" target="_blank" rel="noopener noreferrer">Progress CNA record</a>) is a stored cross-site-scripting flaw in the Ad Hoc module that a low-privileged authenticated user can plant to run script in another user&#39;s session. CERT-FR gives the fixed release as MOVEit Transfer 2026.0.2, with the 2025.0.8 and 2025.1.4 branch releases carrying the same fixes; no active exploitation or public proof-of-concept is reported for any of the three.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender note</span><div class="callout__body">the actionable driver here is exposure, not exploitation — this is a prompt patch-prioritisation item for a product with a documented mass-exploitation history, not an active-incident response. Rank internet-facing instances by whether their SFTP port is reachable (the only pre-authentication path, CVE-2026-10699), and treat MOVEit as the kind of edge MFT asset where a future exploitation wave would move fast. <strong>Detection:</strong> for the DoS, watch MOVEit host memory/RSS growth and SFTP session churn for abnormal unauthenticated connection patterns that precede service degradation; for the stored XSS, monitor Ad Hoc-module content for injected script and administrative-session anomalies. The benign-lookalike discriminator for the DoS is that legitimate SFTP clients complete authentication and transfer, whereas the abuse pattern is repeated pre-auth connection/allocation churn from a source that never progresses to a successful transfer.</div></aside><div class="prov"><span>vulnerability</span><span>11 Jul 13:05Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-11/moveit-transfer-certfr-cve-2026-10699-10698-11903/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0856/" target="_blank" rel="noopener noreferrer">CERT-FR / ANSSI</a> · <a href="https://cve.threatint.eu/CVE/CVE-2026-10699" target="_blank" rel="noopener noreferrer">CVE record (Progress CNA, via THREATINT)</a></div></article>]]></content:encoded></item><item><title>Symantec: a driver built malicious from the outset — yet WHCP-signed — defeats code-signing allowlisting to kill EDR before GodDamn encrypts</title><link>https://ctipilot.ch/entries/2026-07-11/goddamn-ransomware-poisonx-microsoft-signed-driver/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-11/goddamn-ransomware-poisonx-microsoft-signed-driver/</guid><pubDate>Sat, 11 Jul 2026 04:30:43 +0000</pubDate><dc:date>2026-07-11T04:30:43Z</dc:date><category>ransomware</category><category>organized-crime</category><category>identity</category><category>global</category><description><![CDATA[<p>Symantec attributes GodDamn ransomware (first seen 2026-05-21) to the Hyadina developer behind the Monster→Beast lineage, and documents a June 2026 intrusion where the operators loaded PoisonX (g11.sys) — a kernel driver they got signed under Microsoft&#39;s Windows Hardware Compatibility Publisher program despite it being malicious by design — to terminate security processes and strip user-mode API hooks before encrypting. The signed-malicious-driver twist means code-signing allowlisting will not stop it; detection must be behavioural.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-11/goddamn-ransomware-poisonx-microsoft-signed-driver" data-tags="ransomware organized-crime identity" data-regions="global" data-kind="threat" data-priority="notable" data-discovered="2026-07-11T04:30:43Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="goddamn-ransomware-poisonx-microsoft-signed-driver"><a href="https://ctipilot.ch/entries/2026-07-11/goddamn-ransomware-poisonx-microsoft-signed-driver/">GodDamn ransomware (Beast/Monster rebrand) blinds EDR with &#39;PoisonX&#39;, a malicious kernel driver Microsoft signed</a></h3><p>Symantec&#39;s Threat Hunter Team assesses that GodDamn — surfaced as a &quot;new&quot; ransomware, first observed 2026-05-21 — is the latest rebrand in a lineage it tracks to a developer called Hyadina: Monster (2022) → Beast → GodDamn, the last sharing significant code overlap with Beast (<a href="https://www.security.com/threat-intelligence/goddamn-ransomware-beast-rebrand" target="_blank" rel="noopener noreferrer">Symantec/Broadcom, 2026-07-09</a>). The investigated early-June intrusion is a conventional human-operated ransomware kill chain with one standout component. AnyDesk appeared on the first host staged under the user&#39;s Music folder — a placement Symantec reads as manual attacker delivery, not a normal install — and began beaconing to relay infrastructure. The operators then dropped a defence-evasion binary masquerading as a Symantec product, which installed the PoisonX kernel driver (<code>g11.sys</code>) into the system driver store, staged a 14-tool credential-harvesting kit (13 NirSoft utilities plus Mimikatz) under the profile, moved laterally across 10-plus hosts via PsExec while re-installing AnyDesk on each for unattended access (writing <code>ad.security.interactive_access=2</code> to suppress the consent prompt and registering it as auto-start services), disabled Windows Defender real-time monitoring, and finally deployed the encrypter (<a href="https://www.security.com/threat-intelligence/goddamn-ransomware-beast-rebrand" target="_blank" rel="noopener noreferrer">Symantec/Broadcom, 2026-07-09</a>; <a href="https://thehackernews.com/2026/07/goddamn-ransomware-uses-poisonx-driver.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-07-09</a>).</p>
<p>PoisonX is what distinguishes this case from routine bring-your-own-vulnerable-driver tradecraft. Rather than abusing a flaw in a legitimate signed driver, PoisonX is a driver built to be malicious that its developers nonetheless got signed under Microsoft&#39;s &quot;Windows Hardware Compatibility Publisher&quot; program; once loaded it terminates security-product processes and strips user-mode API hooks, so it disables EDR visibility rather than merely evading it. It was first documented earlier in 2026 killing the CrowdStrike Falcon service via a crafted IOCTL to an undocumented driver interface (<a href="https://www.security.com/threat-intelligence/goddamn-ransomware-beast-rebrand" target="_blank" rel="noopener noreferrer">Symantec/Broadcom, 2026-07-09</a>).</p><aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">because the driver carries a valid Microsoft signature, code-signing allowlists and reputation checks pass it — detection has to be behavioural. <strong>Triage:</strong> legitimate driver installs do not co-occur with mass termination of security services, so the load of a rarely-seen driver immediately followed by security-product process/service stops and the loss of user-mode hooks on the same host is the discriminator; AnyDesk running from a personal media folder (versus IT-managed Program Files) and configured for unattended access is a second, independent pivot.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">the PoisonX driver seems to be slightly more unusual, in that it appears to be a malicious driver that its developers succeeded in getting signed by Microsoft, and it is now being used by ransomware attackers.</p><p class="entry-cite__quote">Placing AnyDesk under the user Music folder rather than a standard installation directory is consistent with manual delivery by an attacker who had already obtained access to the host by an earlier means.</p><figcaption class="entry-cite__attr"><a href="https://www.security.com/threat-intelligence/goddamn-ransomware-beast-rebrand" target="_blank" rel="noopener noreferrer">Symantec Threat Hunter Team (Broadcom)</a> <span class="entry-cite__date mono">2026-07-09</span></figcaption></figure></div><div class="prov"><span>threat</span><span>11 Jul 04:30Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-11/goddamn-ransomware-poisonx-microsoft-signed-driver/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.security.com/threat-intelligence/goddamn-ransomware-beast-rebrand" target="_blank" rel="noopener noreferrer">Symantec Threat Hunter Team (Broadcom)</a> · <a href="https://thehackernews.com/2026/07/goddamn-ransomware-uses-poisonx-driver.html" target="_blank" rel="noopener noreferrer">The Hacker News</a> · <a href="https://www.infosecurity-magazine.com/news/ransomware-removes-cybersecurity/" target="_blank" rel="noopener noreferrer">Infosecurity Magazine</a></div></article>]]></content:encoded></item><item><title>Microsoft dissects GigaWiper — destruction dressed as extortion, driven over RabbitMQ/Redis/MinIO with an &#39;OneDrive Update&#39; persistence tell</title><link>https://ctipilot.ch/entries/2026-07-11/gigawiper-golang-destructive-backdoor-modular-wiper/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-11/gigawiper-golang-destructive-backdoor-modular-wiper/</guid><pubDate>Sat, 11 Jul 2026 04:30:43 +0000</pubDate><dc:date>2026-07-11T04:30:43Z</dc:date><category>wiper</category><category>ransomware</category><category>nation-state</category><category>infostealer</category><category>global</category><description><![CDATA[<p>Microsoft Threat Intelligence documented GigaWiper (2026-07-09), a Go destructive backdoor that combines a raw-disk wiper, a Crucio-derived encryptor whose keys are never saved, and a FlockWiper-derived secure-wipe module as on-demand commands, tasked over RabbitMQ/Redis with MinIO exfiltration. First seen October 2025; concrete low-noise hunt pivots exist. Relevant to any Windows critical-infrastructure estate as transferable destructive tradecraft.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-11/gigawiper-golang-destructive-backdoor-modular-wiper" data-tags="wiper ransomware nation-state infostealer" data-regions="global" data-kind="threat" data-priority="notable" data-discovered="2026-07-11T04:30:43Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="gigawiper-golang-destructive-backdoor-modular-wiper"><a href="https://ctipilot.ch/entries/2026-07-11/gigawiper-golang-destructive-backdoor-modular-wiper/">GigaWiper: a Golang backdoor that folds a disk wiper, fake-ransomware encryptor and secure-wipe module into one modular implant</a></h3><p>Microsoft Threat Intelligence first identified GigaWiper in October 2025 and has now published a code-level analysis of it: a Golang backdoor notable less for any single capability than for its construction — at least three previously separate destructive families folded into one implant as on-demand commands, so an operator can pick the mode of destruction at task time (<a href="https://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malware/" target="_blank" rel="noopener noreferrer">Microsoft Threat Intelligence, 2026-07-09</a>). The raw-disk wiper command enumerates physical drives over WMI, identifies and spares the Windows installation drive, strips partition metadata from the other drives via <code>DeviceIoControl</code>/<code>IOCTL_DISK_CREATE_DISK</code>, overwrites disk content in 0xA00000-byte chunks (randomising only the first byte of each buffer to dodge naïve all-zero-wipe detections), then forces an immediate reboot. A second command reuses Crucio ransomware code to AES-encrypt files with per-run keys that are never saved and drops no ransom note — destruction wearing an extortion costume — while a third reimplements the C-based FlockWiper in Go for multi-pass secure wiping of the Windows drive. Microsoft ties the families together by code overlap and assesses that the same developer built GigaWiper and Crucio; it withholds actor attribution beyond that lineage. Google&#39;s Threat Intelligence Group and Binary Defense track the same activity as BLUERABBIT (<a href="https://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malware/" target="_blank" rel="noopener noreferrer">Microsoft Threat Intelligence, 2026-07-09</a>; <a href="https://www.infosecurity-magazine.com/news/new-gigawiper-espionage-destructive/" target="_blank" rel="noopener noreferrer">Infosecurity Magazine, 2026-07-10</a>).</p>
<p>Operationally the implant is quieter than its payload. It persists as a scheduled task named <code>OneDrive Update</code> (configured to run roughly every minute and once at startup) and tracks its own execution count in a <code>HKCU\SOFTWARE\OneDrive\Environment</code> registry value, masquerading as Microsoft&#39;s sync client. For command-and-control it skips ordinary HTTP: tasking arrives over RabbitMQ/AMQP — a fanout exchange named <code>All</code> for broadcast to every infected client plus a topic exchange for targeted commands — status and output are polled back through a Redis server, and MinIO object storage carries exfiltration, alongside keylogging and screen-capture modules.</p><aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the persistence footprint and the C2 protocol mix are both high-value, low-false-positive hunt anchors — legitimate OneDrive never lives under that task name or registry path, and a standard workstation has no reason to speak AMQP, Redis and MinIO outbound. <strong>Triage:</strong> genuine OneDrive does run scheduled sync tasks, so the discriminator is the exact task name (<code>OneDrive Update</code>) and the <code>HKCU\SOFTWARE\OneDrive\Environment</code> key rather than the presence of a OneDrive-named task per se; pair that with outbound RabbitMQ/Redis/MinIO from a host with no such workload and the two together are the signal. Because the encryptor discards its keys, defence is recovery-first: this is a data-destruction threat, and the only meaningful mitigation for an exposed Windows estate is tested, offline backups.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">It&#39;s not a single, purpose-built tool, but an amalgamation of separate malware families that were folded into GigaWiper as on-demand backdoor commands, giving threat actors the flexibility to choose their mode of destruction</p><p class="entry-cite__quote">The key and initialization vector (IV) that the malware uses to encrypt files are random and are not saved anywhere</p><figcaption class="entry-cite__attr"><a href="https://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malware/" target="_blank" rel="noopener noreferrer">Microsoft Threat Intelligence</a> <span class="entry-cite__date mono">2026-07-09</span></figcaption></figure></div><div class="prov"><span>threat</span><span>11 Jul 04:30Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-11/gigawiper-golang-destructive-backdoor-modular-wiper/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malware/" target="_blank" rel="noopener noreferrer">Microsoft Threat Intelligence</a> · <a href="https://www.infosecurity-magazine.com/news/new-gigawiper-espionage-destructive/" target="_blank" rel="noopener noreferrer">Infosecurity Magazine</a></div></article>]]></content:encoded></item><item><title>ZDI details the HTTP.sys integer-overflow trigger — weaponisation bar drops for a pre-auth RCE reachable on any IIS/HTTPS listener</title><link>https://ctipilot.ch/entries/2026-07-11/cve-2026-47291-httpsys-zdi-exploitation-mechanics/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-11/cve-2026-47291-httpsys-zdi-exploitation-mechanics/</guid><pubDate>Sat, 11 Jul 2026 04:30:43 +0000</pubDate><dc:date>2026-07-11T04:30:43Z</dc:date><category>vulnerabilities</category><category>rce</category><category>pre-auth</category><category>poc-public</category><category>global</category><category>poc-public</category><category>patch-available</category><category>CVE-2026-47291</category><description><![CDATA[<p>Zero Day Initiative published a full technical write-up (2026-07-10) of CVE-2026-47291, the HTTP.sys pre-auth kernel RCE patched in Microsoft&#39;s June 2026 cycle, documenting the exact integer-overflow arithmetic and the TLS-record-fragmentation trigger. Not yet exploited in the wild, but the mechanics — and a concrete network-detection heuristic — are now public, so anyone running an internet-facing IIS/HTTPS listener that missed the June patch should treat it as newly weaponisable.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-11/cve-2026-47291-httpsys-zdi-exploitation-mechanics" data-tags="vulnerabilities rce pre-auth poc-public" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-07-11T04:30:43Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-47291/">CVE-2026-47291</a><span class="b upd">update</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="cve-2026-47291-httpsys-zdi-exploitation-mechanics"><a href="https://ctipilot.ch/entries/2026-07-11/cve-2026-47291-httpsys-zdi-exploitation-mechanics/">CVE-2026-47291 — Windows HTTP.sys pre-auth RCE (CVSS 9.8): ZDI publishes full exploitation mechanics and a detection signature</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-06-10/cve-2026-47291-microsoft-june-patch-tuesday-http-sys-pre-aut/">CVE-2026-47291 — Microsoft June Patch Tuesday: HTTP.sys pre-auth RCE (CVSS 9.8) headlines the largest-ever release (198 CVEs)</a> <span class="mono muted">(2026-06-10)</span></p><p>CVE-2026-47291 shipped in the June 2026 Patch Tuesday as a headline pre-auth RCE in HTTP.sys, the kernel-mode HTTP driver that terminates HTTP/1.x and TLS for IIS and every service built on the HTTP Server API. The delta is a full exploitation write-up from Zero Day Initiative&#39;s TrendAI Research team, published a month after the patch, that documents the precise defect and trigger and materially lowers the weaponisation bar (<a href="https://www.zerodayinitiative.com/blog/2026/7/9/cve-2026-47291-remote-code-execution-in-the-windows-httpsys" target="_blank" rel="noopener noreferrer">Zero Day Initiative, 2026-07-10</a>).</p>
<p>The bug is a 16-bit integer overflow in the buffer-reference array that HTTP.sys grows while parsing HTTP/1.x headers: the capacity counter is incremented by five on each growth without a bounds check, and after 13,107 growths it reaches <code>0xFFFB</code>, so the next increment wraps to <code>0x0000</code>; the subsequent reference addition then allocates a 40-byte buffer but <code>memmove</code>s roughly 524,256 bytes into it — a ~500 KB kernel-pool heap overflow. Because SChannel delivers each TLS record to the parser as its own buffer, an attacker who places exactly one header line per TLS application-data record establishes a 1:1 record-to-reference correspondence and drives the counter to overflow with a single ~262 KB request. Successful exploitation crashes the box (kernel memory-access exception) and, under favourable pool layout, can execute code in kernel context. Critically, the path is reachable only via HTTP/1.x-over-TLS — HTTP/2 and HTTP/3 use a different parser and are unaffected (<a href="https://www.zerodayinitiative.com/blog/2026/7/9/cve-2026-47291-remote-code-execution-in-the-windows-httpsys" target="_blank" rel="noopener noreferrer">Zero Day Initiative, 2026-07-10</a>).</p>
<p>The write-up also corrects the exposure picture the original advisory left fuzzy: the default <code>MaxRequestBytes</code> of 16,384 bytes caps a request at roughly 4,000 header lines — far short of the ~65,536 references needed — so only hosts that raised <code>MaxRequestBytes</code> to at least 262,144 bytes can be driven to the overflow. Microsoft rates the CVE &quot;Exploitation More Likely&quot;; no in-the-wild exploitation is reported as of ZDI&#39;s publication (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47291" target="_blank" rel="noopener noreferrer">Microsoft MSRC, 2026-06-09</a>).</p><aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the patch remains the only reliable fix, but the newly-public mechanics hand defenders a durable network signature — a single HTTP/1.x request bearing more than ~1,000 header lines (visible with TLS inspection), or an HTTPS connection emitting more than ~1,000 tiny TLS records over ~11 minutes (visible without decryption). <strong>Triage:</strong> ordinary browsers and proxies coalesce headers into a few records and never approach that line count, so a single long-lived HTTPS connection feeding one IIS/HTTP.sys request with hundreds-to-thousands of one-line TLS records is the discriminator; a kernel bugcheck on an internet-facing IIS box following such traffic warrants triage against this CVE.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">The vulnerability is only reachable through HTTP/1.x header parsing over TLS connections. HTTP/2 and HTTP/3 use different parser paths that do not interact with the buffer reference array.</p><p class="entry-cite__quote">If the number of header field lines in a single request exceeds 1,000, the traffic should be considered suspicious; an attack exploiting this vulnerability is likely underway.</p><figcaption class="entry-cite__attr">Zero Day Initiative</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>11 Jul 04:30Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-11/cve-2026-47291-httpsys-zdi-exploitation-mechanics/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.zerodayinitiative.com/blog/2026/7/9/cve-2026-47291-remote-code-execution-in-the-windows-httpsys" target="_blank" rel="noopener noreferrer">Zero Day Initiative (Trend Micro)</a> · <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47291" target="_blank" rel="noopener noreferrer">Microsoft MSRC</a></div></article>]]></content:encoded></item><item><title>SOCRadar finds a webshell-brokerage crew&#39;s own open staging server — 5,700+ live shells, 27 weaponized CVEs, and a parallel Nacos/Spring Boot credential heist</title><link>https://ctipilot.ch/entries/2026-07-10/wp-shellstorm-webshell-brokerage-exposed-toolkit/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-10/wp-shellstorm-webshell-brokerage-exposed-toolkit/</guid><pubDate>Fri, 10 Jul 2026 20:34:32 +0000</pubDate><dc:date>2026-07-10T20:34:32Z</dc:date><category>actively-exploited</category><category>botnet</category><category>organized-crime</category><category>rce</category><category>china-nexus</category><category>global</category><description><![CDATA[<p>SOCRadar found a webshell access-brokerage operation&#39;s own Python SimpleHTTPServer left open for 22 days, exposing its full toolkit, target lists and logs. The crew (tracked as WP-SHELLSTORM, assessed as financially-motivated and Chinese-speaking) fired 27 weaponized CVEs at ~1.4M WordPress/Joomla domains, confirming 5,700+ active webshells, with a WordPress caching-plugin flaw the single highest-yield exploit. A separate, earlier track abused an Apache Nacos auth bypass with JDumpSpider to steal cloud credentials and DB connection strings from Java heap dumps. The breadth-first, FOFA-driven targeting puts any exposed Swiss/European CMS or Nacos/Spring Boot estate in scope.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-10/wp-shellstorm-webshell-brokerage-exposed-toolkit" data-tags="actively-exploited botnet organized-crime rce china-nexus" data-regions="global" data-kind="threat" data-priority="notable" data-discovered="2026-07-10T20:34:32Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b exp">exploited</span><span class="b cls cls-med" title="NATO Admiralty code · source reliability C: Fairly reliable · information credibility 2: Probably true"><span class="k">NATO</span>C2</span></div><h3 class="f-h" id="wp-shellstorm-webshell-brokerage-exposed-toolkit"><a href="https://ctipilot.ch/entries/2026-07-10/wp-shellstorm-webshell-brokerage-exposed-toolkit/">WP-SHELLSTORM: an exposed webshell-brokerage toolkit reveals 27 weaponized CVEs fired at 1.4M WordPress/Joomla sites plus a parallel Nacos/Spring Boot credential-theft track</a></h3><p>SOCRadar&#39;s Threat Intelligence Team spotted an unauthenticated open directory — a Python SimpleHTTPServer left running for 22 days on a US-based VPS — that exposed the complete toolkit, target lists, bash history and C2 configuration of a webshell access-brokerage operation it names WP-SHELLSTORM (<a href="https://socradar.io/blog/wp-shellstorm-expose-1-4m-wordpress-sites/" target="_blank" rel="noopener noreferrer">SOCRadar, 2026-07-09</a>). The operation weaponized 27 CVEs (14 critical, 9 high) against roughly 1.4 million WordPress and Joomla domains sourced via FOFA, confirming more than 5,700 live webshells; the single highest-yield exploit was a Breeze Cache Cleaner flaw (CVE-2026-3844) at 45,000+ targets and 17,000+ confirmed shells, followed by a ThemeREX Addons vulnerability (CVE-2026-1969), while a Joomla JCE flaw fired at 560,000+ targets yielded only 77 shells — a reminder that raw target count and success rate diverge with how patched an ecosystem is. The Hacker News independently cites a second team, Ctrl-Alt-Intel, whose deduplicated count reached 25,195 compromised sites; SOCRadar reads the crew as financially motivated rather than state-directed (<a href="https://thehackernews.com/2026/07/exposed-hacker-server-reveals-wp.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-07-10</a>). A parallel, earlier track abused the Apache Nacos authentication bypass (CVE-2021-29441 — a request with a &quot;Nacos-Server&quot; User-Agent header skips auth entirely) to exfiltrate hundreds of Nacos configuration files, yielding cloud credentials, database connection strings and API keys; a separate technique scanned Spring Boot for exposed heap dumps and used the open-source JDumpSpider to pull credentials from those Java memory dumps. Because Nacos config routinely holds XXL-Job admin tokens, one Nacos bypass chains to RCE across connected executor nodes (<a href="https://socradar.io/blog/wp-shellstorm-expose-1-4m-wordpress-sites/" target="_blank" rel="noopener noreferrer">SOCRadar, 2026-07-09</a>).</p>
<p>The webshell payloads include a multi-layer-obfuscated BestShell-derived <code>down.php</code>, a Godzilla-framework variant, and a shell that returns HTTP 404 to normal visitors and blocks crawler user-agents; remote access uses a WebSocket-delivered dropper (SNOWLIGHT) fetching an architecture-matched VShell implant that renames its own process to mimic a Linux kernel worker thread (<a href="https://socradar.io/blog/wp-shellstorm-expose-1-4m-wordpress-sites/" target="_blank" rel="noopener noreferrer">SOCRadar, 2026-07-09</a>).</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the breadth-first FOFA targeting means exposure is a function of unpatched plugins and internet-reachable Java-stack management interfaces, not of being individually targeted — any Swiss or European public-sector, SME or fintech estate running the named CMS plugins or an exposed Nacos/XXL-Job/Spring Boot instance is a candidate. The durable, vendor-neutral detections are file-integrity monitoring flagging unexpected PHP files under CMS upload/plugin directories, and web-server logs showing scanner-pattern requests at volume against plugin endpoints. <strong>Triage:</strong> the VShell implant masquerades as a kernel worker by renaming its process to a <code>[kworker/X:Y]</code> form — the discriminator is that a genuine kernel thread has no backing executable, so a process presenting that name whose <code>/proc/&lt;pid&gt;/exe</code> resolves to a real on-disk binary (rather than a kernel path) is the implant, not a kernel worker; a <code>ps aux</code> name match alone is not the signal. On the Java side, an unauthenticated request bearing a <code>Nacos-Server</code> User-Agent that returns cluster data, or an out-of-band <code>/actuator/heapdump</code> generation, is the exposure to hunt.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">a Python SimpleHTTPServer instance, left open for 22 days, exposed the full toolkit, logs, and target lists</p><p class="entry-cite__quote">The most productive single exploit was a Breeze Cache Cleaner flaw (45,000+ targets, 17,000+ confirmed shells), followed by a ThemeREX Addons vulnerability (3,378 shells from 46,600 targets).</p><figcaption class="entry-cite__attr"><a href="https://socradar.io/blog/wp-shellstorm-expose-1-4m-wordpress-sites/" target="_blank" rel="noopener noreferrer">SOCRadar</a> <span class="entry-cite__date mono">2026-07-09</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">Ctrl-Alt-Intel&#39;s deduplicated count found 25,195 sites with confirmed or validated compromise evidence, while SOCRadar, counting active webshells, put the live figure at 5,700-plus.</p><figcaption class="entry-cite__attr"><a href="https://thehackernews.com/2026/07/exposed-hacker-server-reveals-wp.html" target="_blank" rel="noopener noreferrer">The Hacker News</a> <span class="entry-cite__date mono">2026-07-10</span></figcaption></figure></div><div class="prov"><span>threat</span><span>10 Jul 20:34Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-10/wp-shellstorm-webshell-brokerage-exposed-toolkit/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://socradar.io/blog/wp-shellstorm-expose-1-4m-wordpress-sites/" target="_blank" rel="noopener noreferrer">SOCRadar</a> · <a href="https://thehackernews.com/2026/07/exposed-hacker-server-reveals-wp.html" target="_blank" rel="noopener noreferrer">The Hacker News</a></div></article>]]></content:encoded></item><item><title>ZeroBEC details Forg365 — a Telegram-sold M365 PhaaS that survives MFA and keeps operator access alive via a ForgCookie browser extension</title><link>https://ctipilot.ch/entries/2026-07-10/forg365-m365-phaas-aitm-devicecode-forgcookie/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-10/forg365-m365-phaas-aitm-devicecode-forgcookie/</guid><pubDate>Fri, 10 Jul 2026 20:34:32 +0000</pubDate><dc:date>2026-07-10T20:34:32Z</dc:date><category>phishing</category><category>identity</category><category>cloud</category><category>ai-abuse</category><category>global</category><description><![CDATA[<p>ZeroBEC documented Forg365, a Telegram-distributed, subscription-priced Microsoft 365 phishing-as-a-service platform that pairs an OAuth device-code phishing path with an adversary-in-the-middle session-theft path, an in-panel AI lure generator, and a companion browser extension (ForgCookie) that silently refreshes the stolen Microsoft SSO cookie so access persists without the victim re-authenticating. Both paths yield a valid, MFA-satisfied token because the victim completes the real Microsoft login. It is a distinct kit and operator from the Railway/EvilTokens device-code campaign covered earlier — same primitive, productized.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-10/forg365-m365-phaas-aitm-devicecode-forgcookie" data-tags="phishing identity cloud ai-abuse" data-regions="global" data-kind="threat" data-priority="notable" data-discovered="2026-07-10T20:34:32Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="forg365-m365-phaas-aitm-devicecode-forgcookie"><a href="https://ctipilot.ch/entries/2026-07-10/forg365-m365-phaas-aitm-devicecode-forgcookie/">Forg365: a commercial Microsoft 365 phishing-as-a-service kit bundling device-code + AiTM phishing, in-panel AI lure drafting, and a browser extension for SSO-cookie persistence</a></h3><p>ZeroBEC&#39;s teardown, corroborated by BleepingComputer and a CSA Labs research note, describes Forg365 as a Telegram-distributed, subscription-priced (5-day trial, $400/month, $3,800/year) Microsoft 365 phishing-as-a-service platform that packages two independent credential-theft paths behind one operator console (<a href="https://zerobec.com/blog/inside-forg365-telegram-distributed-sneaky2fa-style-phaas" target="_blank" rel="noopener noreferrer">ZeroBEC, 2026-07-09</a>; <a href="https://www.bleepingcomputer.com/news/security/new-forg365-phishing-platform-uses-ai-to-target-microsoft-365-accounts/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-07-09</a>). The device-authorization branch presents a Microsoft-styled verification-code page and drives the legitimate Microsoft Authentication Broker flow; the adversary-in-the-middle branch classifies inbound traffic to decide whether to serve the phishing page or a benign decoy. Both converge on a valid, MFA-satisfied refresh token or session cookie because the victim completes the genuine Microsoft authentication — as CSA Labs puts it, &quot;multifactor authentication does not stop the attack because the victim, not the attacker, is the one completing the MFA challenge&quot; (<a href="https://labs.cloudsecurityalliance.org/research/csa-research-note-forg365-ai-phishing-service-20260710-csa-s/" target="_blank" rel="noopener noreferrer">CSA Labs, 2026-07-10</a>). Two capabilities stand out beyond the already-covered device-code primitive: an AI lure-drafting assistant embedded directly in the panel alongside SMTP rotation, OAuth-app configuration and token vaulting, and ForgCookie — a Chrome/Edge/Brave extension that silently triggers OAuth flows to refresh the stolen SSO cookie so operator access outlives its normal expiry (<a href="https://zerobec.com/blog/inside-forg365-telegram-distributed-sneaky2fa-style-phaas" target="_blank" rel="noopener noreferrer">ZeroBEC, 2026-07-09</a>). ZeroBEC&#39;s Entra telemetry tied observed device-code activity to a residential ISP address, with a campaign-linked backend node later performing Microsoft Graph device-registration calls.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the durable, kit-independent detections are in Entra sign-in and audit telemetry, not on the lure — surface device-code authentication events (device-code client-id patterns in sign-in logs), OAuth app consent grants and mailbox-rule changes clustered immediately after a sign-in, and browser-extension installs on managed endpoints that programmatically refresh SSO cookies. Forg365 is a distinct product and operator from the Railway/EvilTokens device-code campaign, so it is a new entry rather than an update; the shared abused primitive (device-authorization-grant phishing) is already covered and not re-taught here. <strong>Triage:</strong> legitimate device-code sign-ins are real (CLI tools, smart-TV and headless-device apps) — the discriminator is a verification-code prompt reached via an unsolicited email lure or phone call rather than a user-initiated CLI/device flow, and a subsequent refresh-token or cookie reuse from an origin, ASN or device posture that does not match the user&#39;s baseline. Because the token is MFA-satisfied, revocation (<code>revokeSignInSessions</code>), not a password reset, is what actually evicts the operator.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Forg365 is a mature Microsoft 365-focused phishing-as-a-service platform that combines device-auth phishing, AiTM delivery, AntiBot evasion, campaign delivery, session persistence, AI-assisted lure creation, and post-compromise mailbox operations inside a commercial operator ecosystem.</p><p class="entry-cite__quote">ForgCookie, the browser extension associated with the platform, is designed for Microsoft SSO cookie refresh, browser-based access, and persistent session workflows after compromise.</p><figcaption class="entry-cite__attr"><a href="https://zerobec.com/blog/inside-forg365-telegram-distributed-sneaky2fa-style-phaas" target="_blank" rel="noopener noreferrer">ZeroBEC</a> <span class="entry-cite__date mono">2026-07-09</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">multifactor authentication does not stop the attack because the victim, not the attacker, is the one completing the MFA challenge</p><figcaption class="entry-cite__attr"><a href="https://labs.cloudsecurityalliance.org/research/csa-research-note-forg365-ai-phishing-service-20260710-csa-s/" target="_blank" rel="noopener noreferrer">Cloud Security Alliance (CSA Labs)</a> <span class="entry-cite__date mono">2026-07-10</span></figcaption></figure></div><p class="entry-references"><strong>Builds on:</strong> <a class="mono" href="https://ctipilot.ch/entries/2026-07-10/m365-conditional-access-gaps-railway-lshiy-campaigns/">2026-07-10/m365-conditional-access-gaps-railway-lshiy-campaigns</a></p><div class="prov"><span>threat</span><span>10 Jul 20:34Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-10/forg365-m365-phaas-aitm-devicecode-forgcookie/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://zerobec.com/blog/inside-forg365-telegram-distributed-sneaky2fa-style-phaas" target="_blank" rel="noopener noreferrer">ZeroBEC</a> · <a href="https://www.bleepingcomputer.com/news/security/new-forg365-phishing-platform-uses-ai-to-target-microsoft-365-accounts/" target="_blank" rel="noopener noreferrer">BleepingComputer</a> · <a href="https://labs.cloudsecurityalliance.org/research/csa-research-note-forg365-ai-phishing-service-20260710-csa-s/" target="_blank" rel="noopener noreferrer">Cloud Security Alliance (CSA Labs)</a></div></article>]]></content:encoded></item><item><title>Aikido: compromised @injectivelabs npm package hooks key-derivation at runtime, carries no postinstall script, and exfiltrates disguised as normal SDK traffic</title><link>https://ctipilot.ch/entries/2026-07-10/injectivelabs-npm-runtime-keyhook-supply-chain-evasion/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-10/injectivelabs-npm-runtime-keyhook-supply-chain-evasion/</guid><pubDate>Fri, 10 Jul 2026 12:53:00 +0000</pubDate><dc:date>2026-07-10T12:53:00Z</dc:date><category>supply-chain</category><category>infostealer</category><category>cloud</category><category>global</category><description><![CDATA[<p>Aikido Security dissected a malicious npm release of @injectivelabs/sdk-ts (~50k weekly downloads) whose stealer runs no install-time (postinstall) script at all — so install-time scanners and sandboxes that only watch lifecycle scripts saw a clean package. Instead it inserts one-line hooks into the SDK&#39;s own key-derivation functions that fire on every legitimate call at runtime, encodes the captured secret to defeat plaintext string search, and exfiltrates it inside a request header crafted to mimic the SDK&#39;s normal API traffic. The attacker also republished the poisoned version number across 17 sibling packages so dependents pulled it transitively. The transferable lesson is the evasion pattern, not the crypto package: runtime-triggered credential hooking blinds the install-time SCA scanning most dependency-security programmes rely on.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-10/injectivelabs-npm-runtime-keyhook-supply-chain-evasion" data-tags="supply-chain infostealer cloud" data-regions="global" data-kind="research" data-priority="notable" data-discovered="2026-07-10T12:53:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="injectivelabs-npm-runtime-keyhook-supply-chain-evasion"><a href="https://ctipilot.ch/entries/2026-07-10/injectivelabs-npm-runtime-keyhook-supply-chain-evasion/">npm supply-chain payload hides as runtime &#39;telemetry&#39; with no install hook — defeating install-time dependency scanners</a></h3><p>Aikido Security published (2026-07-09) a teardown of a compromised npm release of <strong>@injectivelabs/sdk-ts</strong> — an SDK pulling ~50,000 weekly downloads — that is notable less for its payload&#39;s purpose than for how it hid (<a href="https://www.aikido.dev/blog/compromised-injectivelabs-exfiltrates-keys" target="_blank" rel="noopener noreferrer">Aikido Security, 2026-07-09</a>). Introduced via what Aikido assesses as a GitHub account takeover (commits from an account with an established history), the malicious version was live for under an hour on 2026-06-08 before the maintainer reverted it, but in that window the attacker also republished the same version number across 17 other packages in the scope, each pinning the poisoned SDK — so any project depending on one of them resolved the stealer transitively without naming it directly.</p>
<p>The payload runs no install-time script. Diffed against the clean build, the artifacts differ by one injected block and two one-line hooks placed inside the SDK&#39;s own key-derivation entry points; each hook &quot;fires before the real derivation runs, so the secret is captured on every legitimate call&quot; during normal application use (<a href="https://www.aikido.dev/blog/compromised-injectivelabs-exfiltrates-keys" target="_blank" rel="noopener noreferrer">Aikido, 2026-07-09</a>). Because &quot;the trigger is key derivation at runtime and not a lifecycle script, install-time scanners and sandboxes that only watch postinstall see a clean package&quot; — the single most important detail for defenders, since it defeats the exact control (install-hook / postinstall inspection) that most software-composition-analysis programmes lean on. The exfiltration was built to blend in: the destination host was stored as an array of character codes and reassembled at runtime to defeat plaintext string search, the captured material was base64-batched and sent inside an HTTP request header (not the body) with a content type matching the SDK&#39;s own gRPC-web API calls, and every failure path swallowed errors silently. The injected block was even documented in its own comment as &quot;anonymized usage metrics for SDK optimization&quot;.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the specific package is blockchain-wallet tooling with limited public-sector footprint, but the tradecraft generalises to any npm consumer — a supply-chain payload that carries no lifecycle hook, triggers only on genuine runtime use of the library&#39;s own API, and exfiltrates over a channel shaped like the library&#39;s normal traffic will pass install-time scanning and plaintext IOC search. The durable controls are artifact-vs-source diffing, transitive-dependency auditing with pinned versions and build provenance, and runtime egress monitoring keyed on protocol-mimicking destinations rather than known-bad strings.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Because the trigger is key derivation at runtime and not a lifecycle script, install-time scanners and sandboxes that only watch postinstall see a clean package.</p><p class="entry-cite__quote">Each hook fires before the real derivation runs, so the secret is captured on every legitimate call</p><p class="entry-cite__quote">The malicious <code>1.20.21</code>was published at 22:59 GMT+2 on June 8, 2026, the maintainer reverted the change at 23:18, and a clean version was published at 23:48.</p><figcaption class="entry-cite__attr"><a href="https://www.aikido.dev/blog/compromised-injectivelabs-exfiltrates-keys" target="_blank" rel="noopener noreferrer">Aikido Security</a> <span class="entry-cite__date mono">2026-07-09</span></figcaption></figure></div><div class="prov"><span>research</span><span>10 Jul 12:53Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-10/injectivelabs-npm-runtime-keyhook-supply-chain-evasion/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.aikido.dev/blog/compromised-injectivelabs-exfiltrates-keys" target="_blank" rel="noopener noreferrer">Aikido Security</a></div></article>]]></content:encoded></item><item><title>ReliaQuest: new &#39;Helix&#39; extortion cluster (BlackFile/ShinyHunters lineage) vishes staff into device-code sign-ins, then bulk-loots SharePoint</title><link>https://ctipilot.ch/entries/2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil/</guid><pubDate>Fri, 10 Jul 2026 12:53:00 +0000</pubDate><dc:date>2026-07-10T12:53:00Z</dc:date><category>identity</category><category>phishing</category><category>cloud</category><category>data-breach</category><category>organized-crime</category><category>global</category><description><![CDATA[<p>ReliaQuest documented a previously unreported data-extortion cluster it calls Helix, assessed as a likely continuation of the BlackFile (UNC6671) and ShinyHunters ecosystems on shared registrar and hosting infrastructure. Operators phone a target impersonating their named manager (spoofed caller-ID), walk them through an Entra ID device-code sign-in that captures a session token without a password and sidesteps Conditional Access, register a new Authenticator within minutes for persistence, then run automated SharePoint enumeration and bulk exfiltration. SharePoint + Entra ID is the default identity/collaboration stack across Swiss and EU public-sector tenants, so the playbook is directly reachable; disabling the device-code flow is the single highest-impact control.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil" data-tags="identity phishing cloud data-breach organized-crime" data-regions="global" data-kind="threat" data-priority="high" data-discovered="2026-07-10T12:53:00Z"><div class="badges"><span class="b pri">HIGH</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="helix-data-extortion-devicecode-vishing-sharepoint-exfil"><a href="https://ctipilot.ch/entries/2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil/">&#39;Helix&#39; data-extortion cluster pairs manager-impersonation vishing with device-code phishing and automated SharePoint exfiltration</a></h3><p>ReliaQuest&#39;s Threat Research team published (2026-07-08) a spotlight on <strong>Helix</strong>, a data-extortion cluster it assesses as a likely continuation of the now-fragmented <strong>BlackFile</strong> (UNC6671) operation and the broader <strong>ShinyHunters</strong> ecosystem — an assessment resting on a shared credential-harvesting-domain registrar (also used by the Scattered Spider/&quot;The Com&quot; community) and an exfiltration host four addresses away, on the same autonomous system, from a confirmed BlackFile address two months earlier (<a href="https://reliaquest.com/blog/threat-spotlight-helix-new-name-in-data-extortion-ecosystem" target="_blank" rel="noopener noreferrer">ReliaQuest, 2026-07-08</a>). ReliaQuest is explicit that this is likely-ecosystem-continuation, not confirmed attribution — but &quot;organizations already tracking those groups should treat Helix as an extension of the same data extortion campaigns.&quot;</p>
<p>The device-code-phishing-defeats-Conditional-Access primitive itself was covered earlier today in the Huntress Railway/LSHIY analysis (see references); Helix&#39;s contribution is the full extortion kill chain wrapped around it. Initial contact is voice phishing in which the operator impersonates the target&#39;s actual manager by name on a spoofed caller-ID and talks them through entering a device code into Chrome — the session token is captured without any password crossing the phone line, and the device-code flow bypasses Conditional Access (<a href="https://reliaquest.com/blog/threat-spotlight-helix-new-name-in-data-extortion-ecosystem" target="_blank" rel="noopener noreferrer">ReliaQuest, 2026-07-08</a>; <a href="https://www.bleepingcomputer.com/news/security/new-helix-vishing-group-emerges-in-sharepoint-data-theft-attacks/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-07-09</a>). Persistence is deliberately minimal and hard to spot: the operator registers a new MFA Authenticator on the account, typically within minutes of sign-in, from the same residential proxy used for access — &quot;the only persistence artifact is a legitimate MFA registration.&quot; Sign-in infrastructure is geo-matched to the target&#39;s real city to avoid impossible-travel alerts, rotating through 15+ residential IPs against a single mailbox. Collection is automated and identical across incidents — the operator issues <code>contentclass:STS_Site</code> and wildcard SharePoint searches to inventory reachable content, then bulk-downloads, using a <code>python-requests</code> user-agent from an IP reserved for exfiltration and never used for access. Dwell before mass exfil ranged from under an hour to over a week, a deliberate tuning to each environment&#39;s value and detectability. In at least one case the operator actively tested containment after the account was disabled, re-attempting MFA registration and a password reset.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the identity-based entry techniques (vishing, device-code phishing, MFA-registration persistence) are now shared tradecraft across the fragmenting data-extortion ecosystem, so detections built for Helix apply to BlackFile/ShinyHunters successors too. <strong>Triage:</strong> legitimate device-code authentication is rare in modern tenants (mostly CLI/headless flows), and a new MFA registration or a manager phone call can each be benign alone — the signal is the <em>sequence</em> within a short window: an unfamiliar manager-impersonation call, then a device-code sign-in from a never-seen residential IP, then a new Authenticator registered minutes later, then automated <code>python-requests</code> SharePoint enumeration and bulk download disproportionate to the user&#39;s baseline.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Helix likely emerged from the “BlackFile” and “ShinyHunters” ecosystem. Groups fragment and rebrand, but the techniques and infrastructure persist across every iteration.</p><p class="entry-cite__quote">Device code phishing then sidesteps Conditional Access policies, and automated tools enumerate and mass-download SharePoint libraries before bulk exfiltration triggers an alert.</p><p class="entry-cite__quote">Disabling device code authentication is the single highest-impact action.</p><figcaption class="entry-cite__attr"><a href="https://reliaquest.com/blog/threat-spotlight-helix-new-name-in-data-extortion-ecosystem" target="_blank" rel="noopener noreferrer">ReliaQuest</a> <span class="entry-cite__date mono">2026-07-08</span></figcaption></figure></div><p class="entry-references"><strong>Builds on:</strong> <a class="mono" href="https://ctipilot.ch/entries/2026-07-10/m365-conditional-access-gaps-railway-lshiy-campaigns/">2026-07-10/m365-conditional-access-gaps-railway-lshiy-campaigns</a></p><div class="prov"><span>threat</span><span>10 Jul 12:53Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://reliaquest.com/blog/threat-spotlight-helix-new-name-in-data-extortion-ecosystem" target="_blank" rel="noopener noreferrer">ReliaQuest</a> · <a href="https://www.bleepingcomputer.com/news/security/new-helix-vishing-group-emerges-in-sharepoint-data-theft-attacks/" target="_blank" rel="noopener noreferrer">BleepingComputer</a></div></article>]]></content:encoded></item><item><title>SANS ISC: a phishing page pads itself with ~430k repeated characters to dilute the payload below an AI classifier&#39;s threshold or exhaust an LLM&#39;s token budget</title><link>https://ctipilot.ch/entries/2026-07-10/comment-stuffing-html-phishing-ai-email-scanner-evasion/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-10/comment-stuffing-html-phishing-ai-email-scanner-evasion/</guid><pubDate>Fri, 10 Jul 2026 12:53:00 +0000</pubDate><dc:date>2026-07-10T12:53:00Z</dc:date><category>phishing</category><category>ai-abuse</category><category>global</category><description><![CDATA[<p>A SANS Internet Storm Center diary analysed a phishing email whose HTML attachment was ~2.5 MB but whose functional credential-harvesting payload was only ~11 KB — the remainder a single HTML comment of ~430,000 repeated &quot;X&quot; characters placed after the payload. The analyst assesses the padding is aimed at AI/NLP-based email security: either diluting the malicious content&#39;s statistical weight until a probability classifier drops below its flag threshold, or inflating the token count until an LLM-based scanner exceeds its per-message time/size budget and cuts analysis short. The concept matters as AI content-scoring spreads across public-sector mail gateways; the defence is a non-AI fallback rule keyed on the anomalous oversized-single-character-run signature.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-10/comment-stuffing-html-phishing-ai-email-scanner-evasion" data-tags="phishing ai-abuse" data-regions="global" data-kind="research" data-priority="notable" data-discovered="2026-07-10T12:53:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 3: Possibly true"><span class="k">NATO</span>B3</span></div><h3 class="f-h" id="comment-stuffing-html-phishing-ai-email-scanner-evasion"><a href="https://ctipilot.ch/entries/2026-07-10/comment-stuffing-html-phishing-ai-email-scanner-evasion/">&#39;Comment stuffing&#39; — HTML phishing attachments padded to ~2.5 MB to dilute or exhaust AI/NLP email scanners</a></h3><p>A SANS Internet Storm Center diary (2026-07-10, Jan Kopriva) dissects a phishing email that presented as a Microsoft Teams/SharePoint document notification and carried a <code>.xls.html</code> double-extension attachment weighing ~2.5 MB — anomalously large for a self-contained HTML page (<a href="https://isc.sans.edu/diary/33144" target="_blank" rel="noopener noreferrer">SANS ISC, 2026-07-10</a>). Decoded from a <code>\uXXXX</code>-escaped <code>document.write()</code> wrapper, the file was ~431 KB, of which only the first ~11 KB was a working SharePoint-themed credential-harvesting page; the rest was a single HTML comment holding roughly 430,000 repeated &quot;X&quot; characters, placed <em>after</em> the functional payload, accounting for ~97% of the file.</p>
<p>The placement rules out the classic goal. Padding after the payload does nothing to conceal the malicious code, and at 2.5 MB the file falls well short of the tens-of-megabytes scan-size limits modern mail security uses, so this is not the MITRE &quot;Binary Padding&quot; scan-size-evasion play. The handler&#39;s assessment — explicitly flagged as informed speculation — is that the target is AI/NLP-based content scanning, which a growing number of gateways now run. Citing KnowBe4&#39;s earlier &quot;NLP obfuscation&quot; work, the diary notes that &quot;if a message contains enough innocuous material, the weight of the malicious portion can be diluted to the point where the model no longer flags it with sufficient confidence&quot;, and that &quot;the same bulk can also make a message large enough so that scanning it using AI-based mechanisms takes too long, leading some solutions to release it rather than delay delivery indefinitely&quot; (<a href="https://isc.sans.edu/diary/33144" target="_blank" rel="noopener noreferrer">SANS ISC, 2026-07-10</a>). The author judges the token-budget-exhaustion goal the more likely of the two here, since a featureless block of one character works as well as crafted filler for that purpose. He is candid that against a well-tuned model the tactic is blunt — &quot;the padding is also about as low-entropy as any data can get, which means it wouldn&#39;t help the file blend in with benign content on a statistical level either&quot; — which is precisely why a simple non-AI signature catches it.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">as AI/NLP scoring becomes a load-bearing control in mail security, adversaries gain an incentive to attack the classifier&#39;s decision budget rather than hide from signatures — dilution below a confidence threshold, or token-count inflation past a per-message time budget that makes the gateway fail open. <strong>Triage:</strong> benign HTML mail and marketing content can be large, but a single repeated-character run or one HTML comment in the hundreds of kilobytes is not something legitimate senders produce — that oversized low-entropy block, and a large decompressed-vs-declared-size ratio, are the discriminators, and both are detectable without relying on the AI layer the padding is trying to defeat.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">If a message contains enough innocuous material, the weight of the malicious portion can be diluted to the point where the model no longer flags it with sufficient confidence.</p><p class="entry-cite__quote">The same bulk can also make a message large enough so that scanning it using AI-based mechanisms takes too long, leading some solutions to release it rather than delay delivery indefinitely.</p><p class="entry-cite__quote">The padding is also about as low-entropy as any data can get, which means it wouldn’t help the file blend in with benign content on a statistical level either</p><figcaption class="entry-cite__attr"><a href="https://isc.sans.edu/diary/33144" target="_blank" rel="noopener noreferrer">SANS Internet Storm Center</a> <span class="entry-cite__date mono">2026-07-10</span></figcaption></figure></div><div class="prov"><span>research</span><span>10 Jul 12:53Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-10/comment-stuffing-html-phishing-ai-email-scanner-evasion/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://isc.sans.edu/diary/33144" target="_blank" rel="noopener noreferrer">SANS Internet Storm Center</a></div></article>]]></content:encoded></item><item><title>Huntress: device-code phishing and ROPC token-spray defeat M365 tenants by routing around the auth paths Conditional Access actually inspects</title><link>https://ctipilot.ch/entries/2026-07-10/m365-conditional-access-gaps-railway-lshiy-campaigns/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-10/m365-conditional-access-gaps-railway-lshiy-campaigns/</guid><pubDate>Fri, 10 Jul 2026 04:36:19 +0000</pubDate><dc:date>2026-07-10T04:36:19Z</dc:date><category>identity</category><category>phishing</category><category>cloud</category><category>ai-abuse</category><category>global</category><description><![CDATA[<p>Huntress published a comparative root-cause analysis of two 2026 Microsoft 365 account-takeover campaigns that both bypassed Conditional Access policies requiring MFA — not by defeating MFA but by using auth flows CA rarely covers. &quot;Railway&quot; (March 2026, 344 orgs incl. Germany) used device-code phishing to harvest 90-day OAuth tokens; &quot;LSHIY&quot; (June 2026, 78 accounts across 64 orgs) ran 81M+ ROPC login attempts against Azure CLI through the /token endpoint. Of the 78 LSHIY-compromised accounts, 55 had active CA policies requiring MFA that failed because of scoping gaps. Every M365 tenant should block the device-code flow and ensure CA covers all cloud apps and all client app types including legacy auth.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-10/m365-conditional-access-gaps-railway-lshiy-campaigns" data-tags="identity phishing cloud ai-abuse" data-regions="global" data-kind="research" data-priority="high" data-discovered="2026-07-10T04:36:19Z"><div class="badges"><span class="b pri">HIGH</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="m365-conditional-access-gaps-railway-lshiy-campaigns"><a href="https://ctipilot.ch/entries/2026-07-10/m365-conditional-access-gaps-railway-lshiy-campaigns/">Two 2026 M365 account-takeover campaigns (Railway device-code phishing, LSHIY ROPC spray) beat Conditional Access without breaking MFA</a></h3><p>Huntress compared two structurally different but strategically identical 2026 Microsoft 365 account-takeover campaigns, both of which got through tenants whose Conditional Access (CA) policies required MFA — because each used an authentication path CA typically does not inspect (<a href="https://www.huntress.com/blog/conditional-access-misconfigurations" target="_blank" rel="noopener noreferrer">Huntress, 2026-07-09</a>). The &quot;Railway&quot; campaign (March 2026) abused Microsoft&#39;s OAuth device-code flow: attackers generate a legitimate device-authorization code, embed it in a lure, and collect the resulting OAuth token (valid up to 90 days) when the victim enters the code at the real Microsoft endpoint — the victim may complete MFA, but the token is already gone, so the flow sidesteps MFA rather than defeating it (<code>T1528</code>). The operation ran from clean Railway.com PaaS IP ranges with trusted reputation (three IPs accounted for ~84% of traffic), used construction-RFP lure themes and in some chains triple-wrapped URLs through Cisco, Trend Micro and Microsoft SafeLinks in sequence, and reached 344 organisations across the US, Canada, Australia, New Zealand and Germany before Huntress published; it was attributed to a commercial phishing-as-a-service operation Huntress tracks as EvilTokens — a subscription platform with a storefront, a support team and AI-assisted lure generation (<a href="https://www.huntress.com/blog/conditional-access-misconfigurations" target="_blank" rel="noopener noreferrer">Huntress, 2026-07-09</a>).</p>
<p>The &quot;LSHIY&quot; campaign (active mid-June 2026) took the opposite approach: no phishing, just 81M+ login attempts from an IPv6 range against Azure CLI using the deprecated Resource Owner Password Credentials (ROPC) OAuth flow, which posts credentials straight to the <code>/token</code> endpoint and never touches the authorization endpoint where most CA policies are enforced (<code>T1110.003</code>, <code>T1078.004</code>, <a href="https://thehackernews.com/2026/07/azure-cli-password-spray-hits-at-least.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-07-01</a>). It compromised at least 78 accounts across 64 organisations; the finding that matters for defenders is that 55 of those had active CA policies requiring MFA that failed for predictable scoping reasons (<code>T1556.006</code>): MFA scoped to specific apps such as Admin Portals but not &quot;All Cloud Apps&quot;, so Azure CLI slipped through; MFA scoped to specific user groups that omitted the compromised accounts; MFA required only from &quot;untrusted&quot; locations, bypassed by an attacker IP that geolocated inconsistently to the US; and two policies left in report-only mode. Huntress notes one tenant had a CA policy explicitly named &quot;Block Azure CLI&quot; that did not, in fact, block Azure CLI.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">MFA presence is not the control surface — CA policy <em>scope</em> is. Block the device-code flow tenant-wide (a victim who enters a code into the genuine Microsoft endpoint achieves nothing if the flow is disabled), and ensure MFA-requiring CA policies target all users, all cloud apps and all client app types including legacy/ROPC, backed by client-level strong-auth enforcement (<code>userStrongAuthClientAuthNRequired</code>) that blocks ROPC even with correct credentials. <strong>Triage:</strong> legitimate developer use of Azure CLI from a known device is the benign lookalike for the LSHIY pattern; the discriminators are volume (thousands of attempts), single-ASN concentration, and a successful legacy-auth/ROPC sign-in to a resource app with no interactive MFA event in the same session — and for device-code phishing, a device-code completion originating from something that is plainly not an input-constrained device.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Device code phishing is effective because it doesn&#39;t try to beat MFA. It sidesteps it.</p><p class="entry-cite__quote">Of the 78 compromised accounts, 55 had active Conditional Access policies requiring MFA.</p><figcaption class="entry-cite__attr"><a href="https://www.huntress.com/blog/conditional-access-misconfigurations" target="_blank" rel="noopener noreferrer">Huntress</a> <span class="entry-cite__date mono">2026-07-09</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">One glaring error here is that legacy protocols like ROPC can bypass some poorly-configured CAPs entirely since they don&#39;t go through the authorization endpoint where policies are enforced.</p><figcaption class="entry-cite__attr"><a href="https://thehackernews.com/2026/07/azure-cli-password-spray-hits-at-least.html" target="_blank" rel="noopener noreferrer">The Hacker News</a> <span class="entry-cite__date mono">2026-07-01</span></figcaption></figure></div><div class="prov"><span>research</span><span>10 Jul 04:36Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-10/m365-conditional-access-gaps-railway-lshiy-campaigns/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.huntress.com/blog/conditional-access-misconfigurations" target="_blank" rel="noopener noreferrer">Huntress</a> · <a href="https://thehackernews.com/2026/07/azure-cli-password-spray-hits-at-least.html" target="_blank" rel="noopener noreferrer">The Hacker News</a></div></article>]]></content:encoded></item><item><title>Huntress reconstructs a productised CitrixBleed 2-to-DragonForce runbook: token theft, a registry-symlink SYSTEM escalation, then ransomware</title><link>https://ctipilot.ch/entries/2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725/</guid><pubDate>Fri, 10 Jul 2026 04:36:19 +0000</pubDate><dc:date>2026-07-10T04:36:19Z</dc:date><category>ransomware</category><category>vulnerabilities</category><category>actively-exploited</category><category>pre-auth</category><category>lpe</category><category>identity</category><category>global</category><category>exploited</category><category>patch-available</category><category>CVE-2025-5777</category><description><![CDATA[<p>Huntress reconstructed a single, mechanically identical intrusion chain across at least six unrelated organisations in H1 2026, run by an initial-access broker (tracked by Sophos as STAC3725): pre-auth session-token theft via CitrixBleed 2 (CVE-2025-5777) on internet-facing Citrix NetScaler Gateway/AAA appliances, a portable registry-symlink local-privilege-escalation tool that abuses the Group Policy engine and the AppMgmt service to reach SYSTEM, ScreenConnect/Zoho Assist persistence, and — in the most progressed case — DragonForce ransomware. Any organisation running an unpatched NetScaler Gateway must patch and terminate all live sessions, because stolen tokens survive patching.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725" data-tags="ransomware vulnerabilities actively-exploited pre-auth lpe identity" data-regions="global" data-kind="threat" data-priority="high" data-discovered="2026-07-10T04:36:19Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2025-5777/">CVE-2025-5777</a><span class="b exp">exploited</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="citrixbleed-2-dragonforce-iab-kill-chain-stac3725"><a href="https://ctipilot.ch/entries/2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725/">CitrixBleed 2 (CVE-2025-5777) weaponised into a repeatable IAB kill chain ending in DragonForce ransomware (STAC3725)</a></h3><p>Across the first half of 2026 the Huntress Tactical Response unit worked at least six intrusions at unrelated organisations that reproduced the same seven-step kill chain so faithfully that analysts could predict the next artefact before pulling the log — the basis for their high-confidence assessment that an initial-access broker (IAB) has productised the path from an internet-facing Citrix box to domain-wide encryption, a cluster Sophos independently tracks as STAC3725 (<a href="https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware" target="_blank" rel="noopener noreferrer">Huntress, 2026-07-09</a>; <a href="https://www.sophos.com/en-us/blog/qemu-abused-to-evade-detection-and-enable-ransomware-delivery" target="_blank" rel="noopener noreferrer">Sophos X-Ops, 2026-04-16</a>). Initial access is pre-auth exploitation of CitrixBleed 2 (<code>CVE-2025-5777</code>), a memory over-read in NetScaler ADC/Gateway configured as a Gateway or AAA virtual server: a POST to the login endpoint (<code>/p/u/doAuthentication.do</code> and equivalents) with the login form variable present but empty makes the appliance serialise roughly 127 bytes of adjacent process memory into the response, and sprayed at volume this yields live session tokens (<code>T1190</code>, <code>T1550.001</code>). In one reconstructed case a user authenticated normally over LDAP+MFA from a known-good IP at 13:07 UTC; twenty-one minutes later the same session was driven from the attacker&#39;s IP with no successful authentication from that IP anywhere in the logs — token replay, with MFA already satisfied and therefore irrelevant (<a href="https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware" target="_blank" rel="noopener noreferrer">Huntress, 2026-07-09</a>).</p>
<p>The privilege-escalation primitive is what makes the cluster unmistakable, because the hijacked session usually belongs to an unprivileged employee and the operator carries a portable, unsigned LPE tool (dropped to working paths such as <code>C:\temp</code> and renamed per victim — <code>eng.exe</code>, <code>legal.exe</code>, <code>as.exe</code> — often inside a password-protected archive pulled from <code>temp.sh</code>). The tool plants a <code>REG_LINK</code> <code>SymbolicLinkValue</code> under the RdpBus device-class key <code>{28d78fad-5a12-11d1-ae5b-0000f803a8c2}</code> that redirects into the Group Policy state hierarchy (<code>T1112</code>); running <code>gpupdate</code> forces the SYSTEM-context Group Policy engine to write through the planted link into a protected key, and <code>sc start AppMgmt</code> then makes the Service Control Manager relaunch the dropper as <code>NT AUTHORITY\SYSTEM</code>, which creates a backdoor administrator via <code>net user … /add</code> and <code>net localgroup Administrators … /add</code> (<code>T1068</code>, <code>T1136.001</code>, <code>T1098</code>). AppMgmt is chosen because it is always present, normally dormant, and plausibly related to policy processing. Before detonating, the tool snapshots the original key tree and restores it afterwards, leaving the registry indistinguishable from its pre-exploit state to erase the artefacts a responder would key on (<code>T1070</code>). Persistence then rides legitimate remote-management software — ScreenConnect and Zoho Assist, in one case Netbird plus Atera (<code>T1219</code>) — and in the most advanced case the operator used PsExec, Impacket and Mimikatz for lateral movement and credential access (<code>T1003</code>, <code>T1570</code>) before deploying DragonForce ransomware, contained to a single host (<code>T1486</code>). Huntress declines a firm DragonForce-affiliate-versus-IAB attribution given the tactic overlap, and ruled out an alternative NetScaler session-management race-condition flaw because the affected build and the required already-authenticated session to race against did not fit the evidence.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">patch NetScaler to the fixed builds and, critically, terminate every live session afterwards — harvested tokens survive the patch, which is the single most common post-patch reinfection path for this bug. On the appliance, the load-bearing detection is not the paired diagnostic breadcrumbs (&quot;Login request is not expected to be encrypted&quot;, &quot;X509 cert not found&quot;), which Huntress calls necessary but nowhere near sufficient, but the binary/unprintable data leaking through the ns.log AAA <code>LOGIN_FAILED</code> User field and — the cleanest signal — an authenticated session that has no corresponding successful login event. A default Citrix behaviour also fingerprints the operator: published-desktop sessions auto-create client printer mappings that embed the client workstation name (the same <code>WIN-</code> hostnames recurred case after case), correlatable by pivoting the <code>Microsoft-Windows-TerminalServices-LocalSessionManager/Operational</code> channel (source IP + session ID) against the <code>MetaFrameEvents</code> provider in the Application log (session ID + leaked client name). <strong>Triage:</strong> a NetScaler login flood looks like ordinary password spraying and is routinely dismissed as such — the discriminator is that the &quot;usernames&quot; are leaked heap memory (unprintable bytes, X.509/ASN.1 fragments, internal <code>Citrix-ns-orig-srcip</code> proxy headers), not guessed account names; and on the endpoint, a <code>gpupdate</code> → <code>AppMgmt</code> start → new-SYSTEM-process → local-admin-creation sequence within seconds is the signal, whereas legitimate Group Policy refreshes do not spawn a fresh SYSTEM binary that immediately creates an account.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">By spraying enough of those requests, an adversary can then sift through the heap fragments for valid session tokens of someone who is currently logged in.</p><p class="entry-cite__quote">The cleanup serves to evade detection: by leaving the registry indistinguishable from its pre-exploit state, the tool removes the artifacts a responder would normally key on.</p><figcaption class="entry-cite__attr"><a href="https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware" target="_blank" rel="noopener noreferrer">Huntress</a> <span class="entry-cite__date mono">2026-07-09</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">Huntress assesses with high confidence that the activity is the work of an initial access broker (IAB) weaponising CVE-2025-5777 to gain footholds in Citrix environments before selling or handing off access, ultimately for the purpose of ransomware deployment.</p><figcaption class="entry-cite__attr"><a href="https://www.itsecurityguru.org/2026/07/09/citrixbleed-2-exploited-in-repeatable-attack-chain-culminating-in-dragonforce-ransomware-researchers-find/" target="_blank" rel="noopener noreferrer">IT Security Guru</a> <span class="entry-cite__date mono">2026-07-09</span></figcaption></figure></div><div class="prov"><span>threat</span><span>10 Jul 04:36Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware" target="_blank" rel="noopener noreferrer">Huntress</a> · <a href="https://www.itsecurityguru.org/2026/07/09/citrixbleed-2-exploited-in-repeatable-attack-chain-culminating-in-dragonforce-ransomware-researchers-find/" target="_blank" rel="noopener noreferrer">IT Security Guru</a> · <a href="https://www.sophos.com/en-us/blog/qemu-abused-to-evade-detection-and-enable-ransomware-delivery" target="_blank" rel="noopener noreferrer">Sophos X-Ops</a></div></article>]]></content:encoded></item><item><title>Microsoft ships the engine fix for RoguePlanet (CVE-2026-50656), the Defender SYSTEM-level LPE NCSC-CH has tracked with a public PoC since June</title><link>https://ctipilot.ch/entries/2026-07-09/ncsc-ch-rogueplanet-cve-2026-50656-defender-lpe-fixed/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-09/ncsc-ch-rogueplanet-cve-2026-50656-defender-lpe-fixed/</guid><pubDate>Thu, 09 Jul 2026 20:38:00 +0000</pubDate><dc:date>2026-07-09T20:38:00Z</dc:date><category>vulnerabilities</category><category>lpe</category><category>priv-esc</category><category>poc-public</category><category>patch-available</category><category>switzerland</category><category>global</category><category>poc-public</category><category>patch-available</category><category>CVE-2026-50656</category><description><![CDATA[<p>NCSC-CH&#39;s Nightmare Eclipse tracker was updated on 2026-07-09 to record that a CVE has been assigned to RoguePlanet (CVE-2026-50656), a link-following (CWE-59) local privilege escalation in the Microsoft Malware Protection Engine behind Defender that lets a local attacker reach SYSTEM; Microsoft&#39;s MSRC record shows the engine fix has now shipped. A public PoC existed from 2026-06-10 and the CVE sat in &quot;no fix&quot; for over three weeks. The engine auto-updates, so most estates are already current — but WSUS-gated, offline or OT-adjacent estates should explicitly verify the installed engine build.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-09/ncsc-ch-rogueplanet-cve-2026-50656-defender-lpe-fixed" data-tags="vulnerabilities lpe priv-esc poc-public patch-available" data-regions="switzerland global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-07-09T20:38:00Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-50656/">CVE-2026-50656</a></div><h3 class="f-h" id="ncsc-ch-rogueplanet-cve-2026-50656-defender-lpe-fixed"><a href="https://ctipilot.ch/entries/2026-07-09/ncsc-ch-rogueplanet-cve-2026-50656-defender-lpe-fixed/">CVE-2026-50656 — Microsoft Defender engine &#39;RoguePlanet&#39; local privilege escalation now patched; NCSC-CH tracks the ongoing &#39;Nightmare Eclipse&#39; zero-day series</a></h3><p>NCSC-CH&#39;s running tracker on the &quot;Nightmare Eclipse&quot; (aka Chaotic Eclipse) researcher&#39;s 2026 zero-day PoC series was updated on 2026-07-09 to record that a CVE has been assigned to <strong>RoguePlanet</strong>: <strong>CVE-2026-50656</strong>, a local privilege-escalation vulnerability (CWE-59, improper link resolution before file access / &quot;link following&quot;) in the Microsoft Malware Protection Engine that underpins Microsoft Defender, System Center Endpoint Protection and Microsoft Security Essentials (<a href="https://security-hub.ncsc.admin.ch/#/posts/12622" target="_blank" rel="noopener noreferrer">NCSC-CH, 2026-07-09</a>). The researcher first disclosed RoguePlanet as an unpatched zero-day on 2026-06-10, describing a race condition in Defender that lets a local attacker &quot;execute arbitrary code or spawn a command shell with SYSTEM-level privileges&quot; (<code>T1068</code>), at which point NCSC-CH logged its status as &quot;Proof of Concept Available, no patch available&quot; (<a href="https://security-hub.ncsc.admin.ch/#/posts/12622" target="_blank" rel="noopener noreferrer">NCSC-CH, 2026-07-09</a>). Microsoft&#39;s own record shows the CVE was published 2026-06-16 (CVSS 3.1 7.8, <code>AV:L/AC:L/PR:L/UI:N</code>, rated &quot;Exploitation More Likely&quot;, exploitation status &quot;No&quot;) and remained without a fix for over three weeks; a revision dated 2026-07-08 confirms Microsoft has now shipped an engine update that closes it — last vulnerable Malware Protection Engine build <strong>1.1.26050.11</strong>, first fixed build <strong>1.1.26060.3008</strong> (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50656" target="_blank" rel="noopener noreferrer">Microsoft MSRC, 2026-07-08</a>).</p>
<p>Because the Malware Protection Engine (<code>mpengine.dll</code>) auto-updates multiple times a day by default, most estates will already carry the fixed build — Microsoft&#39;s guidance is that no manual action is normally required. The operational nuance for this constituency is the exception set: any environment where engine updates are pinned, WSUS-gated, air-gapped, or centrally deferred (System Center Endpoint Protection deployments, offline or OT-adjacent Windows hosts) should explicitly verify the installed engine version rather than assume auto-remediation occurred (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50656" target="_blank" rel="noopener noreferrer">Microsoft MSRC, 2026-07-08</a>). Microsoft also notes that hosts with Defender disabled are not in an exploitable state even though vulnerability scanners flag the on-disk binaries. <strong>Triage:</strong> the exploit abuses a symlink/junction race against files Defender is actively scanning, so the telemetry class is symlink/junction creation targeting Defender scan paths and, on success, <code>MsMpEng.exe</code> (the engine&#39;s scan host) spawning an unexpected child process with a SYSTEM token outside the normal signature/engine-update cadence — the update-cadence anchoring is the discriminator from routine engine activity. This closes RoguePlanet specifically; NCSC-CH continues to track the wider Nightmare Eclipse PoC series as a home-region authority, which is the reason a single-host LPE closure like this one is worth surfacing to this constituency at all.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Microsoft has released an update to the Microsoft Malware Protection Engine that addresses the vulnerability identified by CVE-2026-50656.</p><p class="entry-cite__quote">Improper link resolution before file access (&#39;link following&#39;) in Microsoft Defender allows an authorized attacker to elevate privileges locally.</p><figcaption class="entry-cite__attr"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50656" target="_blank" rel="noopener noreferrer">Microsoft Security Response Center</a> <span class="entry-cite__date mono">2026-07-08</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>09 Jul 20:38Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-09/ncsc-ch-rogueplanet-cve-2026-50656-defender-lpe-fixed/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://security-hub.ncsc.admin.ch/#/posts/12622" target="_blank" rel="noopener noreferrer">NCSC-CH / GovCERT.ch Cyber Security Hub</a> · <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50656" target="_blank" rel="noopener noreferrer">Microsoft Security Response Center</a></div></article>]]></content:encoded></item><item><title>Deutsche Bank says its own network is untouched, pointing to a German marketing-platform vendor, after &#39;Unsafe&#39; claims a breach and leaks employee records</title><link>https://ctipilot.ch/entries/2026-07-09/deutsche-bank-unsafe-ransomware-third-party-vendor-incident/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-09/deutsche-bank-unsafe-ransomware-third-party-vendor-incident/</guid><pubDate>Thu, 09 Jul 2026 12:35:00 +0000</pubDate><dc:date>2026-07-09T12:35:00Z</dc:date><category>ransomware</category><category>data-breach</category><category>supply-chain</category><category>organized-crime</category><category>dach</category><category>europe</category><description><![CDATA[<p>The ransomware/extortion group &#39;Unsafe&#39; listed Deutsche Bank on its leak site and published screenshots of alleged employee records (emails, password hashes, addresses), claiming access to the bank&#39;s internal systems. Deutsche Bank&#39;s own statement says the incident is at an external German vendor running a marketing/incentive platform for its sales partners, with no indication its own network was affected. The transferable lesson: a vendor-side compromise can surface as an apparent client-brand breach, and leaked employee directories are a ready spear-phishing/credential-stuffing list regardless of who was actually compromised.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-09/deutsche-bank-unsafe-ransomware-third-party-vendor-incident" data-tags="ransomware data-breach supply-chain organized-crime" data-regions="dach europe" data-kind="incident" data-priority="notable" data-discovered="2026-07-09T12:35:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="deutsche-bank-unsafe-ransomware-third-party-vendor-incident"><a href="https://ctipilot.ch/entries/2026-07-09/deutsche-bank-unsafe-ransomware-third-party-vendor-incident/">Deutsche Bank confirms a third-party vendor incident after &#39;Unsafe&#39; ransomware group posts alleged employee data</a></h3><p>The ransomware/extortion group &quot;Unsafe&quot; listed Deutsche Bank on its dark-web leak site and published screenshots of alleged database exports, terminal commands and employee records — email addresses, password hashes, physical addresses — as proof of a claimed breach of the bank&#39;s &quot;internal systems&quot; (<a href="https://cybernews.com/security/deutsche-bank-ransomware-data-breach/" target="_blank" rel="noopener noreferrer">Cybernews, 2026-07-07</a>; <a href="https://www.cybersecurity-insiders.com/unsafe-ransomware-allegedly-targets-deutsche-bank/" target="_blank" rel="noopener noreferrer">Cybersecurity Insiders, 2026-07-08</a>). Deutsche Bank&#39;s own spokesperson, in a statement carried on 2026-07-08/09, said the incident did not involve the bank&#39;s own network but instead affected a third-party company in Germany that runs a marketing and incentive platform for the bank&#39;s sales partners, with &quot;no indication that Deutsche Bank&#39;s internal systems or networks were or are affected&quot; (<a href="https://www.computing.co.uk/news/2026/security/deutsche-bank-probes-supplier-cyber-incident-after-ransomware-gang-claims-breach" target="_blank" rel="noopener noreferrer">Computing UK, 2026-07-09</a>). Researchers assessing the leaked samples said the data appears to relate to bank employees but that they could not determine whether any customer information was included.</p>
<p>Unsafe operates a ransomware-as-a-service, double-extortion model; after a relatively quiet 2024–2025 it re-emerged in 2026 with reported targets in Germany, the United States, Switzerland and France — the same-actor reach into this constituency&#39;s home region being the reason the item is in scope rather than the victim&#39;s name. The actual initial-access vector into the German vendor has not been disclosed by any party, and generic secondary profiling of Unsafe&#39;s tooling should be treated as unverified for this specific intrusion.</p><aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the operational lesson is third-party exposure, not Deutsche Bank specifically — an outsourced sales/marketing/incentive platform holding employee PII can be compromised and surface as an apparent breach of the client brand while the client&#39;s own network stays untouched, and the leaked employee directory is immediately useful to attackers for credential stuffing and targeted phishing. EU financial and public-sector bodies should inventory such SaaS relationships and rehearse the &quot;vendor breached, our brand in the headline&quot; incident-response and notification path in advance.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">&quot;We have been informed of a cybersecurity incident at an external service provider,&quot; the spokesperson said, adding that there was &quot;no indication that Deutsche Bank&#39;s internal systems or networks were or are affected&quot; and no evidence of unauthorised access to the bank&#39;s network.</p><figcaption class="entry-cite__attr"><a href="https://www.computing.co.uk/news/2026/security/deutsche-bank-probes-supplier-cyber-incident-after-ransomware-gang-claims-breach" target="_blank" rel="noopener noreferrer">Computing (UK)</a> <span class="entry-cite__date mono">2026-07-09</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">Based on the available samples, it&#39;s not possible to determine whether customer data is included in the alleged breach</p><figcaption class="entry-cite__attr"><a href="https://cybernews.com/security/deutsche-bank-ransomware-data-breach/" target="_blank" rel="noopener noreferrer">Cybernews</a> <span class="entry-cite__date mono">2026-07-07</span></figcaption></figure></div><div class="prov"><span>incident</span><span>09 Jul 12:35Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-09/deutsche-bank-unsafe-ransomware-third-party-vendor-incident/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.computing.co.uk/news/2026/security/deutsche-bank-probes-supplier-cyber-incident-after-ransomware-gang-claims-breach" target="_blank" rel="noopener noreferrer">Computing (UK)</a> · <a href="https://cybernews.com/security/deutsche-bank-ransomware-data-breach/" target="_blank" rel="noopener noreferrer">Cybernews</a> · <a href="https://www.cybersecurity-insiders.com/unsafe-ransomware-allegedly-targets-deutsche-bank/" target="_blank" rel="noopener noreferrer">Cybersecurity Insiders</a></div></article>]]></content:encoded></item><item><title>RedHook shows a no-exploit Android privilege path: Accessibility automation silently enables Wireless Debugging for a shell-uid helper</title><link>https://ctipilot.ch/entries/2026-07-09/redhook-android-rat-adb-wireless-debugging-privilege-abuse/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-09/redhook-android-rat-adb-wireless-debugging-privilege-abuse/</guid><pubDate>Thu, 09 Jul 2026 12:30:00 +0000</pubDate><dc:date>2026-07-09T12:30:00Z</dc:date><category>mobile</category><category>infostealer</category><category>phishing</category><category>identity</category><category>apac</category><category>global</category><description><![CDATA[<p>Group-IB documents an upgraded RedHook Android RAT that, after tricking a victim into granting Accessibility, uses UI automation to silently enable Developer Options and ADB Wireless Debugging, connects its own ADB client over loopback, and launches a Shizuku-derived helper running as shell uid 2000 — granting itself permissions, modifying secure settings and running shell commands with no exploit and no user dialogs. Targeting has expanded from Vietnam to Indonesia; the technique is directly relevant to MDM/BYOD-managed Android fleets everywhere.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-09/redhook-android-rat-adb-wireless-debugging-privilege-abuse" data-tags="mobile infostealer phishing identity" data-regions="apac global" data-kind="threat" data-priority="notable" data-discovered="2026-07-09T12:30:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="redhook-android-rat-adb-wireless-debugging-privilege-abuse"><a href="https://ctipilot.ch/entries/2026-07-09/redhook-android-rat-adb-wireless-debugging-privilege-abuse/">RedHook Android RAT abuses ADB Wireless Debugging to self-grant shell (uid 2000) privileges without an exploit</a></h3><p>Group-IB documents a significantly upgraded variant of RedHook, an Android RAT first described by Cyble in July 2025 and previously focused on Vietnamese banking users (<a href="https://www.group-ib.com/blog/redhook-android-rat-upgraded/" target="_blank" rel="noopener noreferrer">Group-IB, 2026-07-09</a>). The notable new capability is self-service privilege abuse over ADB Wireless Debugging with no exploit involved. After the victim is socially engineered — via impersonation calls/messages and a fake Play-Store-styled site — into installing the APK and granting Accessibility through a &quot;required setup&quot; walkthrough, the malware uses Accessibility-driven UI automation to silently navigate Settings, enable Developer Options and Wireless Debugging, then embeds its own ADB client to connect to the device&#39;s own ADB daemon over the loopback interface (127.0.0.1) — no PC or USB cable needed. It launches a Shizuku-derived privileged helper that runs under shell uid 2000, from which it grants itself runtime permissions, sets <code>WRITE_SECURE_SETTINGS</code>, installs/uninstalls apps and executes shell commands with no user-facing confirmation dialogs. Group-IB states plainly that &quot;there is no exploit here&quot; — this is abuse of a legitimate developer feature, the same primitive tools like Shizuku have long used, weaponised for the first time by malware.</p>
<p>Persistence is layered: a 1×1-pixel foreground activity, silent MediaSession audio, a foreground-service WakeLock, two mutually cross-rebinding services (<code>bindService</code> with <code>BIND_AUTO_CREATE</code>) that resurrect each other, <code>oom_score_adj</code> tuning to -1000, <code>mlock()</code> memory pinning, and a <code>BOOT_COMPLETED</code> receiver that re-establishes Wireless ADB and the helper on every reboot; screen streaming runs over WebSocket with a parallel RTMP stream once shell privileges exist, bypassing the MediaProjection consent dialog. The command set has grown to 53 server-issued commands, APK payloads are hosted on GitHub and AWS S3 for delivery reliability, and OEM-specific UI-automation routines (Google, Huawei, Meizu, Oppo, Samsung, Vivo, Xiaomi) are present but not yet invoked — suggesting planned device-coverage expansion. Mapped for mobile defenders to <code>T1453 Abuse Accessibility Features</code>, <code>T1541 Foreground Persistence</code>, <code>T1512 Video Capture</code>, <code>T1417 Input Capture</code>, and — closest available mapping for the shell-uid grab — <code>T1626 Abuse Elevation Control Mechanism</code>.</p><aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">targeting is currently Vietnam and Indonesia, but the ADB-Wireless-Debugging self-enablement technique is device- and region-agnostic and directly transferable to any Android estate; the defensible control surface is MDM policy disabling debugging features and hunting for an app enabling Developer Options or binding a loopback ADB connection outside an IT-initiated flow.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">This, however, is the first time we have seen it used by a malware to abuse privileges on a victim&#39;s device.</p><p class="entry-cite__quote">There is no exploit here, &quot;merely&quot; turning a debugging interface into a path to shell-level privileges.</p><figcaption class="entry-cite__attr"><a href="https://www.group-ib.com/blog/redhook-android-rat-upgraded/" target="_blank" rel="noopener noreferrer">Group-IB</a> <span class="entry-cite__date mono">2026-07-09</span></figcaption></figure></div><div class="prov"><span>threat</span><span>09 Jul 12:30Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-09/redhook-android-rat-adb-wireless-debugging-privilege-abuse/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.group-ib.com/blog/redhook-android-rat-upgraded/" target="_blank" rel="noopener noreferrer">Group-IB</a></div></article>]]></content:encoded></item><item><title>Sygnia IR: an AI-assisted AWS intrusion ran four parallel workstreams per stolen key and used four accounts&#39; keys in one second</title><link>https://ctipilot.ch/entries/2026-07-09/sygnia-ai-orchestrated-aws-cloud-intrusion-72h/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-09/sygnia-ai-orchestrated-aws-cloud-intrusion-72h/</guid><pubDate>Thu, 09 Jul 2026 04:32:59 +0000</pubDate><dc:date>2026-07-09T04:32:59Z</dc:date><category>ai-abuse</category><category>cloud</category><category>organized-crime</category><category>global</category><description><![CDATA[<p>Sygnia&#39;s incident response into a financially-motivated AWS intrusion found no novel malware or zero-day — every technique maps to a known MITRE ATT&amp;CK ID — but the tempo and parallelism point to AI-assisted/agentic tooling: initial access to broad compromise in ~72h, and four access keys from four separate accounts used from one source IP and user-agent within a single observed second. The detection signal is the orchestration, not the individual actions. Defenders should pre-build minutes-not-hours containment and alert on one source authenticating with multiple distinct keys in a tight window.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-09/sygnia-ai-orchestrated-aws-cloud-intrusion-72h" data-tags="ai-abuse cloud organized-crime" data-regions="global" data-kind="research" data-priority="notable" data-discovered="2026-07-09T04:32:59Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 3: Possibly true"><span class="k">NATO</span>B3</span></div><h3 class="f-h" id="sygnia-ai-orchestrated-aws-cloud-intrusion-72h"><a href="https://ctipilot.ch/entries/2026-07-09/sygnia-ai-orchestrated-aws-cloud-intrusion-72h/">Sygnia: an AI-orchestrated AWS intrusion reached broad compromise in ~72 hours — four keys from four accounts used from one source in the same second</a></h3><p>Sygnia&#39;s incident-response investigation of a financially-motivated AWS cloud intrusion found no novel malware or zero-day — every individual technique maps to a long-tracked MITRE ATT&amp;CK ID — but the operationalisation was materially faster than typical manual intrusions, which Sygnia attributes to AI-assisted or agentic tooling (<a href="https://www.sygnia.co/blog/inside-an-ai-assisted-cloud-attack/" target="_blank" rel="noopener noreferrer">Sygnia, 2026-07-08</a>). After obtaining an initial access key via a weakness in an internet-facing application, the actor ran four workstreams in parallel — secrets theft (ECS/EC2 environment variables, GitHub/Bitbucket CI/CD runner env vars, S3 plaintext secrets, Secrets Manager, SSM Parameter Store); persistence (new IAM users, EC2/ECS reverse shells, modified deployment files); RDS exfiltration via several hundred distinct SQL queries across dozens of databases; and reversible impact (S3 access denial, ECS scaled to zero, SQS purges) used purely as extortion leverage — and repeated the full playbook on every newly obtained credential rather than progressing linearly. The most striking artefact: four different AWS access keys from four separate accounts were used from the same source IP and user-agent within a single observed second, which Sygnia assesses is very hard to explain as manual operation (<a href="https://www.sygnia.co/blog/inside-an-ai-assisted-cloud-attack/" target="_blank" rel="noopener noreferrer">Sygnia, 2026-07-08</a>).</p>
<p>Scripts, structured reporting output, and commit messages/branch names framing the activity as an authorized &quot;pentest&quot;/&quot;red team&quot; with a fabricated CEO sign-off are consistent with LLM-generated tooling — possibly including prompt-framing meant to reduce refusal from AI assistants being abused by the operator. Sygnia maps the case onto the same tactic distribution (Execution, Discovery, Credential Access, Collection, Defense Evasion) that Anthropic&#39;s June 2026 LLM ATT&amp;CK research found concentrated in banned AI-abuse accounts. Relevant IDs per Sygnia include <code>T1651 Cloud Administration Command</code>, <code>T1552/T1528</code> (credential/token harvesting), <code>T1087/T1580/T1619</code> (account/cloud-infra/storage discovery re-run per key), <code>T1578</code> (modify cloud compute infra) and <code>T1078 Valid Accounts</code>.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">for a Swiss/EU public-sector estate mid-cloud-migration running AWS with GitHub/Bitbucket CI/CD, the lesson is tempo. The ATT&amp;CK-mappable individual actions are not the alarm — the orchestration is: one source authenticating with multiple distinct keys/accounts in seconds, and the same secrets-harvesting sequence re-firing on each new credential. Because manual response cannot keep pace, containment (network isolation, credential rotation, session revocation) has to be pre-built to run in minutes, and every exposed credential must be assumed used instantly and at scale.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">In one observed second, four different access keys belonging to four separate accounts were used from the same source IP address and the same user-agent</p><p class="entry-cite__quote">The intrusion progressed from initial access to broad cloud compromise within approximately 72 hours.</p><p class="entry-cite__quote">multiple attacker-created artifacts were framed as part of a &#39;pentest&#39; or a &#39;red team&#39;. This framing appeared in branch names, commit messages, and other artifacts, including references suggesting the activity was approved by a non-existent CEO.</p><figcaption class="entry-cite__attr"><a href="https://www.sygnia.co/blog/inside-an-ai-assisted-cloud-attack/" target="_blank" rel="noopener noreferrer">Sygnia</a> <span class="entry-cite__date mono">2026-07-08</span></figcaption></figure></div><div class="prov"><span>research</span><span>09 Jul 04:32Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-09/sygnia-ai-orchestrated-aws-cloud-intrusion-72h/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.sygnia.co/blog/inside-an-ai-assisted-cloud-attack/" target="_blank" rel="noopener noreferrer">Sygnia</a></div></article>]]></content:encoded></item><item><title>Nayax SEC 6-K reports a contained cloud-account incident; &quot;The Syndicate&quot; claims 1B card records — no proof, conflicts with the filing</title><link>https://ctipilot.ch/entries/2026-07-09/nayax-cloud-account-incident-the-syndicate-claim/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-09/nayax-cloud-account-incident-the-syndicate-claim/</guid><pubDate>Thu, 09 Jul 2026 04:32:59 +0000</pubDate><dc:date>2026-07-09T04:32:59Z</dc:date><category>data-breach</category><category>cloud</category><category>organized-crime</category><category>europe</category><category>global</category><description><![CDATA[<p>Nayax Ltd. — a cashless-payment-terminal provider and Bank-of-Lithuania-licensed payment institution (Nayax Europe UAB) serving enterprises across the EEA — filed an SEC Form 6-K on 2026-07-08 disclosing &quot;unusual activity&quot; in a subsidiary cloud account that it says it immediately blocked and contained, with production/core payment systems unaffected. Separately, extortion group &quot;The Syndicate&quot; claims 1B+ card records, ~1 year of dwell and 100 TB exfiltrated — unproven and internally inconsistent with the &quot;immediately contained&quot; account. Treat as an incident to watch for a material update, and a prompt to audit third-party/subsidiary cloud accounts touching card-data pipelines.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-09/nayax-cloud-account-incident-the-syndicate-claim" data-tags="data-breach cloud organized-crime" data-regions="europe global" data-kind="incident" data-priority="notable" data-discovered="2026-07-09T04:32:59Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 3: Possibly true"><span class="k">NATO</span>A3</span></div><h3 class="f-h" id="nayax-cloud-account-incident-the-syndicate-claim"><a href="https://ctipilot.ch/entries/2026-07-09/nayax-cloud-account-incident-the-syndicate-claim/">Nayax (Bank-of-Lithuania-licensed EEA payment institution) discloses a cloud-account incident; &quot;The Syndicate&quot; claims 1B card records — claim unverified and contradicted by the filing</a></h3><p>Nayax Ltd. — an Israeli-headquartered fintech (Nasdaq/Tel Aviv-listed) providing cashless payment terminals and management platforms, and, through Nayax Europe UAB, a Bank-of-Lithuania-licensed payment institution serving more than 23 million enterprises across the EEA (<a href="https://www.nayax.com/news/payment-institute-license/" target="_blank" rel="noopener noreferrer">Nayax, 2018-07-17</a>) — filed a Form 6-K with the SEC on 2026-07-08 disclosing that it detected &quot;unusual activity&quot; in a cloud account belonging to one of its subsidiaries, which it &quot;immediately blocked and contained&quot; (<a href="https://www.sec.gov/Archives/edgar/data/1901279/000117891326003440/zk2635660.htm" target="_blank" rel="noopener noreferrer">Nayax SEC Form 6-K, 2026-07-08</a>). Nayax states its production environment and core payment-processing systems were unaffected and business operations continue normally, with the scope still under investigation alongside Israeli and US law enforcement (<a href="https://databreaches.net/2026/07/08/nayax-investigating-breach-the-syndicate-claims-it-acquired-1-billion-card-records-and-other-important-data/" target="_blank" rel="noopener noreferrer">DataBreaches.net, 2026-07-08</a>).</p>
<p>Separately, an extortion group calling itself <strong>&quot;The Syndicate&quot;</strong> posted leak-site claims — surfaced by DataBreaches.net on 2026-07-08 — asserting it acquired more than 1 billion card records, had been inside Nayax&#39;s infrastructure for &quot;almost a year&quot;, and exfiltrated over 100 TB, with a threatened ~11-day countdown to a public data portal. No evidence has been published for any of these figures, and DataBreaches.net notes the claims are internally inconsistent with Nayax&#39;s &quot;immediately blocked and contained&quot; characterisation — a familiar extortion pattern of inflating scope for leverage. Nayax&#39;s stock reportedly fell after the claims surfaced, but the company has not confirmed the attacker&#39;s figures (<a href="https://www.calcalistech.com/ctechnews/article/rjpeasiqfg" target="_blank" rel="noopener noreferrer">Calcalistech, 2026-07-08</a>). The filing does not disclose the initial-access vector, the cloud provider, or which subsidiary was involved — a material gap for deriving any concrete detection lever from the disclosure alone.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">this is in scope on a European payments-infrastructure nexus — Nayax Europe is a Bank-of-Lithuania-licensed payment institution serving enterprises across the EEA, so any confirmed card-data exposure carries fraud implications for European merchants and cardholders using Nayax terminals. The correct posture right now is to watch for a material 6-K update rather than to action the attacker&#39;s unverified figures, and, as due diligence on payment processors generally, to audit subsidiary/third-party cloud accounts with access to card-data pipelines for anomalous sign-ins and bulk exports. Note for analysts running SEC-filing sweeps: Nayax filed as a foreign private issuer via 6-K, not an 8-K Item 1.05 — cybersecurity disclosures from foreign issuers are a blind spot if monitoring only Item 1.05.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">As part of the company&#39;s ongoing monitoring, an unusual activity was detected in relation to one of Nayax&#39;s subsidiaries, in one of the company&#39;s cloud accounts, which was immediately blocked and contained.</p><p class="entry-cite__quote">The company&#39;s production environment and its core systems have not been affected by the event. The company&#39;s business activity continues as normal, without impact to the company&#39;s business operations.</p><figcaption class="entry-cite__attr"><a href="https://www.sec.gov/Archives/edgar/data/1901279/000117891326003440/zk2635660.htm" target="_blank" rel="noopener noreferrer">Nayax Ltd. — SEC Form 6-K</a> <span class="entry-cite__date mono">2026-07-08</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">One claim is that they have acquired over 1 billion card records. Another claim is that they have been inside Nayax&#39;s servers for almost a year, and have exfiltrated more than 100 TB of data. That claim appears to conflict with a claim that something was immediately blocked and contained or that it was detected quickly.</p><figcaption class="entry-cite__attr"><a href="https://databreaches.net/2026/07/08/nayax-investigating-breach-the-syndicate-claims-it-acquired-1-billion-card-records-and-other-important-data/" target="_blank" rel="noopener noreferrer">DataBreaches.net</a> <span class="entry-cite__date mono">2026-07-08</span></figcaption></figure></div><div class="prov"><span>incident</span><span>09 Jul 04:32Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-09/nayax-cloud-account-incident-the-syndicate-claim/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.sec.gov/Archives/edgar/data/1901279/000117891326003440/zk2635660.htm" target="_blank" rel="noopener noreferrer">Nayax Ltd. — SEC Form 6-K</a> · <a href="https://databreaches.net/2026/07/08/nayax-investigating-breach-the-syndicate-claims-it-acquired-1-billion-card-records-and-other-important-data/" target="_blank" rel="noopener noreferrer">DataBreaches.net</a> · <a href="https://www.calcalistech.com/ctechnews/article/rjpeasiqfg" target="_blank" rel="noopener noreferrer">Calcalistech (Ctech)</a> · <a href="https://www.nayax.com/news/payment-institute-license/" target="_blank" rel="noopener noreferrer">Nayax (company announcement)</a></div></article>]]></content:encoded></item><item><title>Mandiant recovers a live ADFS signing key from Machine DPAPI — a Golden SAML variant that sidesteps the WID/DKM path and LSASS-watching detection</title><link>https://ctipilot.ch/entries/2026-07-09/mandiant-adfs-machine-dpapi-golden-saml-key-recovery/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-09/mandiant-adfs-machine-dpapi-golden-saml-key-recovery/</guid><pubDate>Thu, 09 Jul 2026 04:32:59 +0000</pubDate><dc:date>2026-07-09T04:32:59Z</dc:date><category>identity</category><category>espionage</category><category>cloud</category><category>global</category><category>europe</category><category>switzerland</category><description><![CDATA[<p>Mandiant documented an ADFS Golden SAML variant: when AutoCertificateRollover is disabled and certificates are rotated manually, the WID configuration database drifts to a stale &quot;ghost&quot; certificate while the active token-signing key sits in the machine CAPI store protected by Machine DPAPI. A SYSTEM-level attacker recovers it with SharpDPAPI /machine — without touching the WID/DKM path or LSASS — and forges a Global Administrator SAML assertion that Entra ID accepts, bypassing MFA and conditional access. The drift is observable via ADFS Event ID 385; treat ADFS as Tier 0.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-09/mandiant-adfs-machine-dpapi-golden-saml-key-recovery" data-tags="identity espionage cloud" data-regions="global europe switzerland" data-kind="research" data-priority="notable" data-discovered="2026-07-09T04:32:59Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="mandiant-adfs-machine-dpapi-golden-saml-key-recovery"><a href="https://ctipilot.ch/entries/2026-07-09/mandiant-adfs-machine-dpapi-golden-saml-key-recovery/">Mandiant &quot;Ghost in the Database&quot;: recovering an active ADFS token-signing key from Machine DPAPI when the WID/DKM Golden SAML path fails</a></h3><p><strong>Background.</strong> Golden SAML — forging SAML assertions by stealing an identity provider&#39;s token-signing key — has been public tradecraft since CyberArk&#39;s 2017 disclosure (<a href="https://www.cyberark.com/resources/threat-research-blog/golden-saml-newly-discovered-attack-technique-forges-authentication-to-cloud-apps" target="_blank" rel="noopener noreferrer">CyberArk, 2017</a>), and Mandiant previously documented network-based extraction of ADFS secrets during the UNC2452/SolarWinds intrusions (<a href="https://cloud.google.com/blog/topics/threat-intelligence/abusing-replication-stealing-adfs-secrets-over-the-network" target="_blank" rel="noopener noreferrer">Mandiant</a>). The standard extraction path pulls the encrypted signing key from the ADFS Windows Internal Database (WID) and decrypts it with Distributed Key Manager (DKM) material stored in Active Directory. This new Mandiant write-up documents a variant that defeats that assumption when ADFS configuration has drifted.</p>
<p>During a red-team engagement, Mandiant found that ADFS deployments with <code>AutoCertificateRollover</code> disabled (<code>Get-AdfsProperties</code> → <code>AutoCertificateRollover: False</code>) and certificates rotated manually can leave the WID configuration database holding only a stale &quot;ghost&quot; certificate record, while the ADFS service actually signs tokens with a newer certificate whose private key lives in the machine CAPI store (<a href="https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi" target="_blank" rel="noopener noreferrer">Mandiant, 2026-07-07</a>). In that state the classic path still &quot;works&quot; mechanically — the WID blob decrypts via DKM — but Entra ID rejects the resulting token with <strong>AADSTS500172</strong> because the key is no longer the one in use.</p>
<p><strong>The key&#39;s real location and protection.</strong> The active private key sits under <code>C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\</code>, with the certificate enrolled in the <code>LocalMachine\My</code> store. It is protected by <strong>Machine DPAPI</strong> (not user-bound DPAPI): the <code>DPAPI_SYSTEM</code> LSA secret plus machine masterkeys under the <code>S-1-5-18</code> (SYSTEM) context at <code>C:\Windows\System32\Microsoft\Protect\S-1-5-18\</code>. Machine-scoping is deliberate — it keeps the key usable across service-account password changes, gMSA rotations and reboots — but it also means a SYSTEM-level actor can recover the key entirely from the host. Mandiant confirmed recovery with <code>SharpDPAPI /machine</code>, which enumerated the active key material under that path (the CNG <code>Crypto\Keys</code> store was not in use in the assessed environment) — no interaction with the live ADFS process or LSASS is required, reducing visibility for defenses that watch only credential-dumping/process-memory access (<a href="https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi" target="_blank" rel="noopener noreferrer">Mandiant, 2026-07-07</a>).</p>
<p><strong>Kill chain (ATT&amp;CK).</strong> SYSTEM-level foothold on the ADFS host → recover Machine-DPAPI-protected masterkeys and the CAPI signing key (<code>T1552 Unsecured Credentials</code>, via <code>SharpDPAPI /machine</code>) → forge a SAML assertion impersonating a Global Administrator (<code>T1606.002 Forge Web Credentials: SAML Tokens</code>) → Entra ID accepts it as a valid federated authentication assertion, yielding Global Administrator access to the Microsoft 365 tenant with MFA and conditional access fully bypassed (<code>T1078.004 Valid Accounts: Cloud Accounts</code>). Because the forged assertion is honoured for <strong>all SAML relying-party trusts</strong>, the blast radius extends to every SaaS platform federated through the same ADFS, not just Microsoft services.</p>
<p><strong>Hunt and detection.</strong> The drift condition itself is observable: <strong>ADFS Event ID 385</strong> fires when the WID record and the actively-used signing certificate diverge, and self-resolves only once <code>AutoCertificateRollover</code> is re-enabled and a rollover runs. For key-theft detection, Mandiant recommends SACL-based object-access auditing (Security <strong>Event ID 4663</strong>) on <code>C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\</code> and <code>C:\Windows\System32\Microsoft\Protect\S-1-5-18\</code>, treated as correlation evidence rather than a standalone signal. The strongest analytic is cross-source: correlate ADFS token-issuance/claims events (Event IDs 299 and the 1200-series, version-dependent) against Entra ID sign-in logs to surface federated sign-ins with no matching upstream authentication context, baselining claim sets, IP ranges and user-agents per relying-party trust for privileged accounts — neither log source alone is sufficient (<a href="https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi" target="_blank" rel="noopener noreferrer">Mandiant, 2026-07-07</a>).</p>
<p><strong>Hardening.</strong> Migrate token-signing certificates to an HSM to eliminate the software-accessible key and thus the Machine DPAPI extraction path entirely; run ADFS under gMSA to reduce manual-rotation drift; govern ADFS servers as <strong>Tier 0</strong> (restricted admin paths, dedicated PAWs, separation from general server administration). When <code>AutoCertificateRollover</code> is disabled, a manual rotation must include <code>Set-AdfsCertificate</code> — installing the certificate alone is insufficient — and be validated with <code>Get-AdfsCertificate</code>; a subsequent Event ID 385 signals lingering inconsistency. Organisations migrating to native OIDC federation remove this attack path altogether (<a href="https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi" target="_blank" rel="noopener noreferrer">Mandiant, 2026-07-07</a>). ADFS remains widely deployed for on-prem/hybrid identity across Swiss and EU public-sector estates mid-migration to Entra ID, making this a direct Tier 0 hardening item for the constituency.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Successfully obtaining this active key allows an attacker to forge valid SAML assertions for any user, bypassing the need for user credentials and multi-factor authentication</p><p class="entry-cite__quote">The recovered key was used to forge a SAML assertion impersonating a Global Administrator identity, which Entra ID accepted as a valid authentication assertion</p><p class="entry-cite__quote">Configure object access auditing via SACLs on C:\\ProgramData\\Microsoft\\Crypto\\RSA\\MachineKeys\\ and C:\\Windows\\System32\\Microsoft\\Protect\\S-1-5-18\\. When configured correctly, this generates Security Event ID 4663 for file access attempts.</p><figcaption class="entry-cite__attr"><a href="https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi" target="_blank" rel="noopener noreferrer">Mandiant (Google Cloud Blog / GTIG)</a> <span class="entry-cite__date mono">2026-07-07</span></figcaption></figure></div><div class="prov"><span>research</span><span>09 Jul 04:32Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-09/mandiant-adfs-machine-dpapi-golden-saml-key-recovery/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi" target="_blank" rel="noopener noreferrer">Mandiant (Google Cloud Blog / GTIG)</a> · <a href="https://itbrief.co.uk/story/mandiant-finds-way-to-recover-active-adfs-signing-keys" target="_blank" rel="noopener noreferrer">itbrief.co.uk</a></div></article>]]></content:encoded></item><item><title>Research: signature malleability lets anyone forge a second &quot;Verified&quot; GitHub commit under a new hash, bypassing SHA-based supply-chain controls</title><link>https://ctipilot.ch/entries/2026-07-09/git-signature-malleability-github-verified-commit-ghost-twin/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-09/git-signature-malleability-github-verified-commit-ghost-twin/</guid><pubDate>Thu, 09 Jul 2026 04:32:59 +0000</pubDate><dc:date>2026-07-09T04:32:59Z</dc:date><category>supply-chain</category><category>poc-public</category><category>no-patch</category><category>global</category><description><![CDATA[<p>Jacob Ginesin (CMU / Cure53) showed that Git/GitHub&#39;s &quot;Verified&quot; commit badge is not a unique identifier: given any signed commit, an attacker without the signing key can mint a second, distinct commit with the same tree, author and date and a still-valid signature — differing only in its hash. The cause is signature malleability (ECDSA (r,s)→(r,n−s); ignorable OpenPGP subpackets; S/MIME encoding), not a hash collision. Hash-based incident-response blocklists and push-protection rules can be trivially bypassed. A public PoC tool exists; no CVE and no Git/GitHub fix as of disclosure.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-09/git-signature-malleability-github-verified-commit-ghost-twin" data-tags="supply-chain poc-public no-patch" data-regions="global" data-kind="research" data-priority="notable" data-discovered="2026-07-09T04:32:59Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="git-signature-malleability-github-verified-commit-ghost-twin"><a href="https://ctipilot.ch/entries/2026-07-09/git-signature-malleability-github-verified-commit-ghost-twin/">Git commit-signature malleability mints a second &quot;Verified&quot; GitHub commit with a different hash — defeating hash-based blocklists</a></h3><p>Jacob Ginesin (Carnegie Mellon PhD student, Cure53 auditor) published research on 2 July, amplified by The Hacker News on 8 July, showing that Git/GitHub&#39;s <strong>&quot;Verified&quot; commit badge is not a unique identifier</strong>: given any signed commit, an attacker without the signing key can mint a second, distinct commit with an identical tree, identical author/date metadata, and a valid signature that still shows &quot;Verified&quot; — differing only in its resulting hash (<a href="https://thehackernews.com/2026/07/github-verified-commits-can-be.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-07-08</a>; <a href="https://arxiv.org/abs/2607.02820" target="_blank" rel="noopener noreferrer">Ginesin, arXiv, 2026-07-02</a>). The root cause is <strong>signature malleability</strong>, not a hash collision. A commit&#39;s SHA is computed over everything inside it, including the raw signature bytes in its header, and many signatures can be rewritten into a different-but-valid form.</p>
<p>Three malleation routes are demonstrated: (1) for ECDSA, the classical algebraic symmetry that turns a valid pair <code>(r,s)</code> into <code>(r, n−s)</code> using only public curve parameters, producing a second equally-valid signature over the same payload with different bytes and therefore a different commit hash; (2) for RSA and EdDSA under OpenPGP, appending an ignorable experimental subpacket in the unhashed subpacket region defined in RFC 4880 §5.2.3; (3) an analogous X.509/S-MIME path. GitHub does not normalize or canonicalize a signature before verifying it — no strict encoding enforcement on S/MIME, no stripping of the manipulable OpenPGP fields, and non-canonical ECDSA values accepted as-is (<a href="https://thehackernews.com/2026/07/github-verified-commits-can-be.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-07-08</a>). A public exploitation tool implementing all three attacks, plus demo repos where the malleated commits still show &quot;Verified&quot;, is released (<a href="https://github.com/JakeGinesin/git-chain-malleator" target="_blank" rel="noopener noreferrer">Ginesin, git-chain-malleator</a>). Ginesin reported to GNU/Git in January and GitHub in March 2026; neither had shipped a fix at publication, and no CVE is assigned. Maps to <code>T1195.002 Compromise Software Supply Chain</code> as a control-bypass primitive.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">any organisation — including government CI/CD pipelines — that keys incident-response or push-protection controls off a specific commit SHA should treat those controls as bypassable. After taking down a known-malicious commit, an operator can re-push a content-identical &quot;ghost twin&quot; under a fresh, equally-&quot;Verified&quot; hash that is not on the blocklist. Move integrity decisions to tree hash + author + content diff, allowlist content rather than commit identity, and read &quot;Verified&quot; as provenance rather than uniqueness until Git/GitHub canonicalize signatures.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Given any signed commit, someone without the signing key can mint a second commit with the same files, author, and date, and a valid signature, GitHub still stamps &#39;Verified.&#39;</p><p class="entry-cite__quote">GitHub does not normalize a signature before checking it. No strict encoding on S/MIME, no stripping of those OpenPGP fields, and non-canonical ECDSA values accepted as-is.</p><figcaption class="entry-cite__attr">The Hacker News, summarising Jacob Ginesin&#39;s research</figcaption></figure></div><div class="prov"><span>research</span><span>09 Jul 04:32Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-09/git-signature-malleability-github-verified-commit-ghost-twin/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://thehackernews.com/2026/07/github-verified-commits-can-be.html" target="_blank" rel="noopener noreferrer">The Hacker News</a> · <a href="https://arxiv.org/abs/2607.02820" target="_blank" rel="noopener noreferrer">Jacob Ginesin (CMU / Cure53) — arXiv preprint</a> · <a href="https://github.com/JakeGinesin/git-chain-malleator" target="_blank" rel="noopener noreferrer">Jacob Ginesin — public PoC tool (git-chain-malleator)</a></div></article>]]></content:encoded></item><item><title>Wiz &quot;GhostApproval&quot;: malicious repos escape the workspace sandbox of six AI coding assistants via symlink + fake confirmation dialog</title><link>https://ctipilot.ch/entries/2026-07-09/ghostapproval-ai-coding-assistant-symlink-trust-boundary/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-09/ghostapproval-ai-coding-assistant-symlink-trust-boundary/</guid><pubDate>Thu, 09 Jul 2026 04:32:59 +0000</pubDate><dc:date>2026-07-09T04:32:59Z</dc:date><category>vulnerabilities</category><category>supply-chain</category><category>ai-abuse</category><category>rce</category><category>poc-public</category><category>patch-available</category><category>global</category><category>poc-public</category><category>patch-available</category><category>CVE-2026-12958</category><category>CVE-2026-50549</category><description><![CDATA[<p>Wiz Research disclosed GhostApproval, a pattern combining symlink-following (CWE-61) with confirmation-dialog UI misrepresentation (CWE-451) across Amazon Q Developer, Cursor, Google Antigravity, Augment, Windsurf and Anthropic Claude Code. A malicious repository plants an in-workspace symlink resolving to a sensitive path (e.g. ~/.ssh/authorized_keys); the agent writes to the true target while the approval dialog shows the harmless in-workspace name — enabling host compromise. AWS (CVE-2026-12958) and Cursor (CVE-2026-50549) shipped fixes; Augment and Windsurf were unpatched at disclosure.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-09/ghostapproval-ai-coding-assistant-symlink-trust-boundary" data-tags="vulnerabilities supply-chain ai-abuse rce poc-public patch-available" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-07-09T04:32:59Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-12958/">CVE-2026-12958 +1</a></div><h3 class="f-h" id="ghostapproval-ai-coding-assistant-symlink-trust-boundary"><a href="https://ctipilot.ch/entries/2026-07-09/ghostapproval-ai-coding-assistant-symlink-trust-boundary/">GhostApproval (CVE-2026-12958, CVE-2026-50549) — symlink + confirmation-UI misrepresentation lets a malicious repo write outside six AI coding assistants&#39; workspace sandbox</a></h3><p>Wiz Research published <strong>GhostApproval</strong> on 8 July, a systematic vulnerability pattern combining <code>CWE-61</code> (symbolic-link following) with <code>CWE-451</code> (UI misrepresentation of critical information) found, in varying severity, across six AI coding assistants: Amazon Q Developer, Cursor, Google Antigravity, Augment, Cognition Labs&#39; Windsurf and Anthropic&#39;s Claude Code (<a href="https://www.wiz.io/blog/ghostapproval-a-trust-boundary-gap-in-ai-coding-assistants" target="_blank" rel="noopener noreferrer">Wiz Research, 2026-07-08</a>). A malicious repository plants a symlink inside the workspace that resolves to a sensitive path outside it — e.g. a file named <code>project_settings.json</code> that is actually a link to <code>~/.ssh/authorized_keys</code> — then a README or prompt instructs the agent to &quot;update&quot; the file. In several tools the agent&#39;s own reasoning identifies the true target, yet the confirmation dialog still shows the harmless in-workspace name, so the user rubber-stamps a write to the real target, enabling persistent passwordless SSH access or other host compromise. Windsurf exhibited a <strong>pre-authorization write</strong> — the file was modified on disk before the Accept/Reject buttons even rendered, making the prompt an &quot;undo&quot; button rather than a gate.</p>
<p>AWS assigned <strong>CVE-2026-12958</strong> (missing symlink validation in Language Servers for AWS, CVSS 8.5, fixed in language-servers 1.69.0 / <code>@aws/lsp-codewhisperer</code> 0.0.117) and Cursor assigned <strong>CVE-2026-50549</strong> (sandbox escape via symlink + failed path canonicalization, fixed in Cursor 3.0), both confirming arbitrary out-of-workspace file write as the impact (<a href="https://github.com/aws/language-servers/security/advisories/GHSA-6v3r-4p5c-mrp5" target="_blank" rel="noopener noreferrer">AWS GHSA-6v3r-4p5c-mrp5, 2026-06-23</a>; <a href="https://github.com/cursor/cursor/security/advisories/GHSA-3v8f-48vw-3mjx" target="_blank" rel="noopener noreferrer">Cursor GHSA-3v8f-48vw-3mjx, 2026-06-05</a>). Google fixed Antigravity (CVE pending at publication). Augment and Windsurf acknowledged the report but were still testable-vulnerable at disclosure (<a href="https://www.wiz.io/blog/ghostapproval-a-trust-boundary-gap-in-ai-coding-assistants" target="_blank" rel="noopener noreferrer">Wiz Research, 2026-07-08</a>). Anthropic assessed the report as outside its threat model for Claude Code — its stated rationale is that a user who starts a session in a directory has already extended trust to it — while noting it had shipped a symlink warning in the Edit/Write permission dialog in v2.1.32 (5 Feb 2026) as unrelated proactive hardening (<a href="https://www.wiz.io/blog/ghostapproval-a-trust-boundary-gap-in-ai-coding-assistants" target="_blank" rel="noopener noreferrer">Wiz Research, 2026-07-08</a>). Mapped to <code>T1195.002 Compromise Software Supply Chain</code>, <code>T1222 File and Directory Permissions Modification</code> (via symlink) and <code>T1552.004 Unsecured Credentials</code> (authorized_keys write).</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">any public-sector or enterprise engineering team running these assistants against externally-sourced repositories is exposed regardless of the tool&#39;s own confirmation-dialog behaviour. Beyond patching, the durable control is to treat every AI-coding-assistant file write to credential/dotfile paths as high-severity and to canonicalize symlink targets before trusting an &quot;Accept&quot; prompt — the confirmation must be a gate, not an undo.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">The user approves what they believe is a harmless local edit; the agent writes to a sensitive file outside of the project workspace.</p><figcaption class="entry-cite__attr"><a href="https://www.wiz.io/blog/ghostapproval-a-trust-boundary-gap-in-ai-coding-assistants" target="_blank" rel="noopener noreferrer">Wiz Research</a> <span class="entry-cite__date mono">2026-07-08</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of the workspace trust boundary.</p><figcaption class="entry-cite__attr"><a href="https://github.com/aws/language-servers/security/advisories/GHSA-6v3r-4p5c-mrp5" target="_blank" rel="noopener noreferrer">AWS GitHub Security Advisory (GHSA-6v3r-4p5c-mrp5)</a> <span class="entry-cite__date mono">2026-06-23</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">A malicious agent could write arbitrary files outside the workspace under the user&#39;s privileges. This enables non-sandboxed Remote Code Execution.</p><figcaption class="entry-cite__attr"><a href="https://github.com/cursor/cursor/security/advisories/GHSA-3v8f-48vw-3mjx" target="_blank" rel="noopener noreferrer">Cursor GitHub Security Advisory (GHSA-3v8f-48vw-3mjx)</a> <span class="entry-cite__date mono">2026-06-05</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>09 Jul 04:32Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-09/ghostapproval-ai-coding-assistant-symlink-trust-boundary/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.wiz.io/blog/ghostapproval-a-trust-boundary-gap-in-ai-coding-assistants" target="_blank" rel="noopener noreferrer">Wiz Research</a> · <a href="https://github.com/aws/language-servers/security/advisories/GHSA-6v3r-4p5c-mrp5" target="_blank" rel="noopener noreferrer">AWS GitHub Security Advisory (GHSA-6v3r-4p5c-mrp5)</a> · <a href="https://github.com/cursor/cursor/security/advisories/GHSA-3v8f-48vw-3mjx" target="_blank" rel="noopener noreferrer">Cursor GitHub Security Advisory (GHSA-3v8f-48vw-3mjx)</a></div></article>]]></content:encoded></item><item><title>ESET Threat Report H1 2026: PromptSpy runs Gemini in its own execution flow, ClickFix 2x, QR-phishing at record levels, 100+ EDR-killers catalogued</title><link>https://ctipilot.ch/entries/2026-07-09/eset-threat-report-h1-2026/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-09/eset-threat-report-h1-2026/</guid><pubDate>Thu, 09 Jul 2026 04:32:59 +0000</pubDate><dc:date>2026-07-09T04:32:59Z</dc:date><category>ai-abuse</category><category>phishing</category><category>mobile</category><category>ransomware</category><category>infostealer</category><category>global</category><category>europe</category><description><![CDATA[<p>ESET&#39;s semi-annual threat report (Dec 2025–May 2026 telemetry) flags four items for a Tier 2/3 team: PromptSpy, described as the first Android malware to use generative AI (Google Gemini) at runtime to interpret UI and adapt behaviour; ClickFix detections more than doubling H2 2025→H1 2026 and expanding beyond fake CAPTCHA into AI-help-page and cloud-auth lures; QR-code phishing at record levels (~11% of detected phishing emails); and 100+ distinct EDR-killer tools now catalogued in the wild.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-09/eset-threat-report-h1-2026" data-tags="ai-abuse phishing mobile ransomware infostealer" data-regions="global europe" data-kind="annual-report" data-priority="notable" data-discovered="2026-07-09T04:32:59Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="eset-threat-report-h1-2026"><a href="https://ctipilot.ch/entries/2026-07-09/eset-threat-report-h1-2026/">ESET Threat Report H1 2026: first Android malware using generative AI at runtime, ClickFix detections more than double, record QR-phishing, 100+ EDR-killers</a></h3><p>ESET&#39;s semi-annual threat-landscape report (telemetry December 2025–May 2026) flags four developments a Tier 2/3 team should track (<a href="https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/" target="_blank" rel="noopener noreferrer">ESET / WeLiveSecurity, 2026-07-08</a>; <a href="https://www.globenewswire.com/news-release/2026/07/08/3323874/0/en/ESET-Threat-Report-AI-boosts-cyber-attackers-efficiency.html" target="_blank" rel="noopener noreferrer">ESET press release, 2026-07-08</a>).</p>
<p>First, ESET analysed roughly 900,000 &quot;AI skills&quot; — small functional components used by AI agents — and found tens of thousands suspicious and thousands outright malicious, an expanding attack surface in the emerging agentic-AI ecosystem. Second, it identified <strong>PromptSpy</strong>, described as the first known Android malware to use generative AI (specifically Google&#39;s Gemini) inside its own execution flow to interpret UI elements and adapt behaviour across devices at runtime rather than relying on hardcoded logic — following the first AI-powered ransomware disclosed in 2025 (<a href="https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/" target="_blank" rel="noopener noreferrer">ESET, 2026-07-08</a>). Third, <strong>ClickFix</strong> (the fake-error social-engineering technique) has expanded beyond fake CAPTCHA prompts into AI-themed help pages, browser extensions and cloud-authentication scenarios, with ESET detections more than doubling between H2 2025 and H1 2026. Fourth, <strong>QR-code phishing</strong> (&quot;quishing&quot;) reached record levels, with roughly 11% of all ESET-detected phishing emails in H1 2026 using QR codes to move victim interaction onto mobile devices and evade cursory inspection. Ransomware activity continued unabated with over <strong>100 distinct EDR-killer tools</strong> now catalogued by ESET, though a declining share of victims are reportedly paying.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">this is a single reference entry for ESET&#39;s semi-annual H1/H2 report cadence (predecessor: ESET Threat Report H2 2025). The operational reads for the constituency: the volume of EDR-killer tooling argues for prioritising driver/process-tampering and protected-process telemetry over ransomware-binary signatures; QR codes in email bodies deserve the same handling as embedded URLs; and ClickFix awareness material must now cover AI-help-page and browser-extension-install variants, not just the fake-CAPTCHA lure. PromptSpy and the malicious-&quot;AI-skills&quot; finding are early indicators that runtime GenAI is moving into the malware execution path itself, worth tracking as a developing class rather than an immediate control change.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">ESET researchers identified PromptSpy, the first known Android malware to use generative AI in its execution flow</p><p class="entry-cite__quote">ESET detections of this vector more than doubled between H2 2025 and H1 2026</p><p class="entry-cite__quote">ESET Research has documented over 100 EDR killers used in the wild, with new variants appearing regularly</p><figcaption class="entry-cite__attr"><a href="https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/" target="_blank" rel="noopener noreferrer">ESET / WeLiveSecurity</a> <span class="entry-cite__date mono">2026-07-08</span></figcaption></figure></div><div class="prov"><span>annual-report</span><span>09 Jul 04:32Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-09/eset-threat-report-h1-2026/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/" target="_blank" rel="noopener noreferrer">ESET / WeLiveSecurity</a> · <a href="https://www.globenewswire.com/news-release/2026/07/08/3323874/0/en/ESET-Threat-Report-AI-boosts-cyber-attackers-efficiency.html" target="_blank" rel="noopener noreferrer">GlobeNewswire (ESET press release)</a></div></article>]]></content:encoded></item><item><title>Januscape (CVE-2026-53359): 16-year-old KVM shadow-MMU UAF gives a guest root a host escape on both Intel and AMD</title><link>https://ctipilot.ch/entries/2026-07-09/cve-2026-53359-januscape-kvm-x86-guest-to-host-vm-escape/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-09/cve-2026-53359-januscape-kvm-x86-guest-to-host-vm-escape/</guid><pubDate>Thu, 09 Jul 2026 04:32:59 +0000</pubDate><dc:date>2026-07-09T04:32:59Z</dc:date><category>vulnerabilities</category><category>lpe</category><category>priv-esc</category><category>poc-public</category><category>patch-available</category><category>global</category><category>poc-public</category><category>patch-available</category><category>CVE-2026-53359</category><description><![CDATA[<p>Januscape (CVE-2026-53359) is a use-after-free in the KVM/x86 shadow-MMU emulation (arch/x86/kvm/mmu/mmu.c) that lay dormant in the Linux kernel for ~16 years and lets a root user inside any KVM guest escape to the host on both Intel and AMD. A public PoC panics the host kernel (DoS against every co-tenant); a working host-RCE exploit exists but is withheld. Fixed upstream 2026-06-16 — patch KVM host kernels to the fixed trains now; there is no guest-side mitigation.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-09/cve-2026-53359-januscape-kvm-x86-guest-to-host-vm-escape" data-tags="vulnerabilities lpe priv-esc poc-public patch-available" data-regions="global" data-kind="vulnerability" data-priority="high" data-discovered="2026-07-09T04:32:59Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-53359/">CVE-2026-53359</a></div><h3 class="f-h" id="cve-2026-53359-januscape-kvm-x86-guest-to-host-vm-escape"><a href="https://ctipilot.ch/entries/2026-07-09/cve-2026-53359-januscape-kvm-x86-guest-to-host-vm-escape/">CVE-2026-53359 — Linux KVM/x86 &quot;Januscape&quot;: shadow-MMU use-after-free enables guest-to-host VM escape on Intel and AMD</a></h3><p>Researcher Hyunwoo Kim (V4bel) disclosed <strong>Januscape (CVE-2026-53359)</strong>, a use-after-free in the shadow-MMU emulation of KVM/x86 (<code>arch/x86/kvm/mmu/mmu.c</code>) whose root cause traces to a 2010 commit — roughly 16 years dormant before the fix landed upstream on 16 June 2026 (<a href="https://www.bleepingcomputer.com/news/linux/new-januscape-linux-kernel-flaw-allows-vm-escape-on-intel-amd-devices/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-07-07</a>). The bug fires when <code>kvm_mmu_get_child_sp()</code> reuses a shadow page without comparing its role, producing a mismatched direct/indirect flag and an incorrect GFN computation; orphaned rmap entries survive memslot deletion and are later dereferenced after the backing memory is freed (<a href="https://github.com/V4bel/Januscape" target="_blank" rel="noopener noreferrer">V4bel, 2026-07-07</a>). The upstream fix is commit <code>81ccda30b4e8</code> (16 June 2026); the researcher gives the vulnerable range as commit <code>2032a93d66fa</code> (2010-08-01) through that fix (<a href="https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=81ccda30b4e8" target="_blank" rel="noopener noreferrer">kernel.org, 2026-06-16</a>; <a href="https://github.com/V4bel/Januscape" target="_blank" rel="noopener noreferrer">V4bel, 2026-07-07</a>).</p>
<p>This is a genuine <strong>guest-to-host escape</strong>: a root user inside a KVM guest can trigger the UAF from purely guest-side actions, on both Intel and AMD hosts — the researcher calls it &quot;the first guest-to-host exploit research triggerable on both&quot; vendors (<a href="https://github.com/V4bel/Januscape" target="_blank" rel="noopener noreferrer">V4bel, 2026-07-07</a>). Januscape was submitted as a live 0-day against Google&#39;s kvmCTF program. A public PoC that panics the host kernel — a denial of service against every co-tenant on the same physical host — is released; a full working host-compromise/RCE exploit exists but the researcher is deliberately withholding it (<a href="https://www.bleepingcomputer.com/news/linux/new-januscape-linux-kernel-flaw-allows-vm-escape-on-intel-amd-devices/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-07-07</a>). Mapped to <code>T1611 Escape to Host</code>.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">any Swiss/EU public-sector or critical-infrastructure estate running KVM-backed private cloud or renting KVM capacity is in scope — a single hostile tenant (or a tenant whose guest root is compromised) can take down or take over the physical host. Prioritise the host-kernel patch above (guest patching does not help), and until every KVM host is on a fixed train, watch for host kernel-panic/oops events correlated with one tenant&#39;s VM as the DoS signature; not-yet-public RCE would surface as unexpected host-level process execution or new host accounts with no corresponding admin action.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">With guest-side actions alone, an attacker can compromise the host that runs their VM. For example, an attacker who has rented just a single instance on a public cloud could panic the host kernel to take down every other tenant VM on the same physical machine (DoS), or run code with root privilege on the host to take over the host and all the guests on it (RCE).</p><figcaption class="entry-cite__attr"><a href="https://www.bleepingcomputer.com/news/linux/new-januscape-linux-kernel-flaw-allows-vm-escape-on-intel-amd-devices/" target="_blank" rel="noopener noreferrer">BleepingComputer</a> <span class="entry-cite__date mono">2026-07-07</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">This is the first guest-to-host exploit research triggerable on both Intel and AMD</p><figcaption class="entry-cite__attr"><a href="https://github.com/V4bel/Januscape" target="_blank" rel="noopener noreferrer">Hyunwoo Kim (V4bel) — researcher write-up + PoC</a> <span class="entry-cite__date mono">2026-07-07</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>09 Jul 04:32Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-09/cve-2026-53359-januscape-kvm-x86-guest-to-host-vm-escape/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bleepingcomputer.com/news/linux/new-januscape-linux-kernel-flaw-allows-vm-escape-on-intel-amd-devices/" target="_blank" rel="noopener noreferrer">BleepingComputer</a> · <a href="https://github.com/V4bel/Januscape" target="_blank" rel="noopener noreferrer">Hyunwoo Kim (V4bel) — researcher write-up + PoC</a> · <a href="https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=81ccda30b4e8" target="_blank" rel="noopener noreferrer">Linux kernel upstream fix commit</a></div></article>]]></content:encoded></item><item><title>Netherlands NIS2 (Cyberbeveiligingswet) slips — Senate vote 7 July, entry into force now 15 August 2026</title><link>https://ctipilot.ch/entries/2026-07-05/weekly-w27-netherlands-nis2-slip/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-05/weekly-w27-netherlands-nis2-slip/</guid><pubDate>Sun, 05 Jul 2026 23:42:00 +0000</pubDate><dc:date>2026-07-05T23:42:00Z</dc:date><category>law-enforcement</category><category>europe</category><description><![CDATA[<p>The Dutch NIS2 transposition (Cyberbeveiligingswet) missed the 1 July 2026 entry-into-force target reported in prior coverage. The Eerste Kamer (Senate) tabled its response to the second committee report on 29 June — the last written step before debate — and its bill-tracking page now sets the floor vote for 7 July, with the government&#39;s revised entry-into-force target 15 August 2026. Substantive scope is unchanged (NCSC-NL supervisor, 24h/72h/1-month notification, fines to EUR 10M/2%, board liability, ~1,000→~8,000 in-scope entities).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-05/weekly-w27-netherlands-nis2-slip" data-tags="law-enforcement" data-regions="europe" data-kind="policy" data-priority="notable" data-discovered="2026-07-05T23:42:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b upd">update</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 2: Probably true"><span class="k">NATO</span>A2</span></div><h3 class="f-h" id="weekly-w27-netherlands-nis2-slip"><a href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-netherlands-nis2-slip/">Netherlands NIS2 transposition slips past its 1 July target — Senate vote set for 7 July, entry into force now 15 August 2026</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-06-29/netherlands-nis2-cyberbeveiligingswet-clears-the-lower-house/">Netherlands NIS2 (Cyberbeveiligingswet) clears the lower house — entry into force targeted for 1 July 2026</a> <span class="mono muted">(2026-06-29)</span></p><p>the Dutch NIS2 transposition — the Cyberbeveiligingswet (Cbw) plus the companion Wet weerbaarheid kritieke entiteiten — has missed the 1 July 2026 entry-into-force target the prior weekly reported as the government&#39;s goal.</p>
<p>The Eerste Kamer (Senate) tabled its government response to the second committee report (&quot;nota naar aanleiding van het tweede verslag&quot;) on 29 June 2026 — the last written-preparation step before plenary debate — and the Senate&#39;s own bill-tracking page now states the floor vote will take place on <strong>7 July 2026</strong>, noting the bill was adopted by the Tweede Kamer on 15 April 2026 (<a href="https://www.eerstekamer.nl/wetsvoorstel/36764_cyberbeveiligingswet" target="_blank" rel="noopener noreferrer">Eerste Kamer, bill 36764</a>). iBestuur reports the government&#39;s revised entry-into-force target is now <strong>15 August 2026</strong>, roughly six weeks later than previously communicated (<a href="https://ibestuur.nl/digitale-weerbaarheid/digitale-veiligheid/eerste-kamer-stemt-7-juli-over-cyberbeveiligingswet" target="_blank" rel="noopener noreferrer">iBestuur, 2026-07-01</a>).</p>
<p>The substantive scope is unchanged from prior coverage: NCSC-NL as designated supervisor, a three-step 24h/72h/one-month incident-notification protocol, essential-entity fines up to EUR 10M or 2% of global turnover, personal board liability for security-measure oversight, and an expansion of in-scope Dutch entities from roughly 1,000 to roughly 8,000. This is the fourth documented slip in the Dutch NIS2 timetable (originally targeted Q3 2025).</p><aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the only action for a Swiss/EU reader is administrative — re-anchor readiness milestones and contractual compliance-date references onto 15 August 2026 for any Dutch group entities, hosting, or counterparties. No technical control change follows from the date shift itself.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">De stemming in de Eerste Kamer vindt plaats op 7 juli 2026.</p><p class="entry-cite__quote">Het voorstel (EK, A) is op 15 april 2026 aangenomen door de Tweede Kamer.</p><figcaption class="entry-cite__attr"><a href="https://www.eerstekamer.nl/wetsvoorstel/36764_cyberbeveiligingswet" target="_blank" rel="noopener noreferrer">Eerste Kamer der Staten-Generaal (official bill page)</a></figcaption></figure></div><div class="prov"><span>policy</span><span>05 Jul 23:42Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-netherlands-nis2-slip/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.eerstekamer.nl/wetsvoorstel/36764_cyberbeveiligingswet" target="_blank" rel="noopener noreferrer">Eerste Kamer der Staten-Generaal (official bill page)</a> · <a href="https://ibestuur.nl/digitale-weerbaarheid/digitale-veiligheid/eerste-kamer-stemt-7-juli-over-cyberbeveiligingswet" target="_blank" rel="noopener noreferrer">iBestuur</a></div></article>]]></content:encoded></item><item><title>FortiBleed status — now attributed to INC Ransom / Lynx; 409 admin-access, 12 ransomware deployments</title><link>https://ctipilot.ch/entries/2026-07-05/weekly-w27-fortibleed-inc-lynx-attribution/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-05/weekly-w27-fortibleed-inc-lynx-attribution/</guid><pubDate>Sun, 05 Jul 2026 23:41:00 +0000</pubDate><dc:date>2026-07-05T23:41:00Z</dc:date><category>ransomware</category><category>data-breach</category><category>organized-crime</category><category>identity</category><category>global</category><category>europe</category><category>dach</category><description><![CDATA[<p>SOCRadar&#39;s Threat Research Unit published attribution evidence this week tying the FortiBleed FortiGate credential-theft infrastructure to the INC Ransom / Lynx ransomware operation — an operator was found logged into both groups&#39; negotiation panels and FortiBleed victim data overlaps INC&#39;s leak site. STRU revised the scale to ~11,250 FortiGate portals scanned, 409 admin-level, 354 full-domain compromises and at least 12 ransomware deployments, and claims the group holds an undisclosed Nextcloud zero-day (single-source, pending vendor disclosure — track, do not action).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-05/weekly-w27-fortibleed-inc-lynx-attribution" data-tags="ransomware data-breach organized-crime identity" data-regions="global europe dach" data-kind="synthesis" data-priority="notable" data-discovered="2026-07-05T23:41:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b upd">update</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="weekly-w27-fortibleed-inc-lynx-attribution"><a href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-fortibleed-inc-lynx-attribution/">FortiBleed status update — the FortiGate credential-theft campaign is now attributed to INC Ransom / Lynx, with a scaled-up victim count and an unconfirmed Nextcloud zero-day claim</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-06-29/fortibleed/">FortiBleed</a> <span class="mono muted">(2026-06-29)</span></p><p>FortiBleed — the FortiGate credential-exposure campaign the prior two weeklies tracked from disclosure (86,644+ then 73,932+ exposed credentials) through the Golang &quot;FortigateSniffer&quot; tool (abusing FortiOS&#39;s native <code>diagnose sniffer packet</code>) and an AD-domain-takeover at a NATO-aligned defence contractor — gained a ransomware attribution and a scale revision this week.</p>
<p><strong>Attribution to INC Ransom / Lynx.</strong> SOCRadar&#39;s Threat Research Unit published evidence tying FortiBleed&#39;s infrastructure directly to two active ransomware operations: an operator with access to FortiBleed infrastructure was found logged into the negotiation panels of both <strong>INC Ransom</strong> and <strong>Lynx</strong> (which SOCRadar assesses, per other researchers, to be an INC rebrand rather than a distinct group), and FortiBleed victim data overlaps victims on INC Ransom&#39;s leak site — the first direct evidence linking the mass FortiGate credential theft to a specific ransomware-deployment pipeline (<a href="https://socradar.io/blog/fortibleed-inc-lynx-ransomware-link/" target="_blank" rel="noopener noreferrer">SOCRadar STRU, 2026-07-01</a>; <a href="https://www.bleepingcomputer.com/news/security/fortibleed-credential-theft-campaign-linked-to-lynx-ransomware/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-07-01</a>). STRU characterises the operation as an ~20-person Initial Access Broker business with a tiered internal structure exposed via an opsec lapse.</p>
<p><strong>Scale revision.</strong> STRU reports scanning against ~11,250 FortiGate portals across 150+ countries, admin-level access confirmed on 409 targets, full domain compromise on 354, and at least 12 confirmed ransomware deployments to date — sharpening the risk picture from &quot;credential exposure&quot; to &quot;credential exposure feeding an active RaaS deployment pipeline.&quot;</p>
<p><strong>Unconfirmed Nextcloud zero-day (track, do not action).</strong> STRU further states the group possesses at least one undisclosed Nextcloud zero-day, with SOCRadar coordinating responsible disclosure. This is a single-source claim pending vendor confirmation and carries no CVE — but given Nextcloud&#39;s data-sovereignty-driven prevalence in Swiss and German public-sector and SME estates, it belongs on the watch list for an immediate patch once Nextcloud publishes. The durable defender action is unchanged: treat any FortiGate exposed in the May–June window as having leaked credentials, rotate, and hunt the sniffer technique. New registry entity this run: <code>actor:inc-ransom</code> (aliases INC Ransomware, Lynx).</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Scanning activity against roughly 11,250 FortiGate portals in more than 150 countries, with admin-level access confirmed on 409 targets</p><figcaption class="entry-cite__attr"><a href="https://socradar.io/blog/fortibleed-inc-lynx-ransomware-link/" target="_blank" rel="noopener noreferrer">SOCRadar (STRU)</a></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">During the investigation of that server, analysis of the collected artifacts revealed that the threat actor had accessed the ransomware negotiation panels of both the Lynx / INC ransomware group.</p><figcaption class="entry-cite__attr">BleepingComputer (citing SOCRadar)</figcaption></figure></div><div class="prov"><span>synthesis</span><span>05 Jul 23:41Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-fortibleed-inc-lynx-attribution/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://socradar.io/blog/fortibleed-inc-lynx-ransomware-link/" target="_blank" rel="noopener noreferrer">SOCRadar (STRU)</a> · <a href="https://www.bleepingcomputer.com/news/security/fortibleed-credential-theft-campaign-linked-to-lynx-ransomware/" target="_blank" rel="noopener noreferrer">BleepingComputer</a></div></article>]]></content:encoded></item><item><title>ShinyHunters / UNC6240 Oracle campaign status — Nissan named, notifications still landing</title><link>https://ctipilot.ch/entries/2026-07-05/weekly-w27-shinyhunters-oracle-campaign-status/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-05/weekly-w27-shinyhunters-oracle-campaign-status/</guid><pubDate>Sun, 05 Jul 2026 23:40:00 +0000</pubDate><dc:date>2026-07-05T23:40:00Z</dc:date><category>data-breach</category><category>actively-exploited</category><category>organized-crime</category><category>zero-day</category><category>global</category><category>europe</category><category>us</category><description><![CDATA[<p>The ShinyHunters/UNC6240 Oracle PeopleSoft campaign (CVE-2026-35273) added Nissan as its largest named victim this week — employee HR/payroll PII across four countries — while GTIG notifications keep landing across the ~100-organisation tail. Separately, Medtronic is notifying ~9M people of a ShinyHunters-claimed April corporate-IT breach (not attributed to the PeopleSoft path). The campaign remains an active, victim-acquiring, zero-day-capable ERP-extortion operation.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-05/weekly-w27-shinyhunters-oracle-campaign-status" data-tags="data-breach actively-exploited organized-crime zero-day" data-regions="global europe us" data-kind="synthesis" data-priority="notable" data-discovered="2026-07-05T23:40:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b exp">exploited</span><span class="b upd">update</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 1: Confirmed"><span class="k">NATO</span>B1</span></div><h3 class="f-h" id="weekly-w27-shinyhunters-oracle-campaign-status"><a href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-shinyhunters-oracle-campaign-status/">ShinyHunters / UNC6240 Oracle campaign — status update: Nissan is the largest named victim, notifications keep landing, and a separate Medtronic claim surfaces</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-06-29/shinyhunters-unc6240-oracle-peoplesoft-campaign/">ShinyHunters / UNC6240 Oracle PeopleSoft campaign</a> <span class="mono muted">(2026-06-29)</span></p><p>the ShinyHunters/UNC6240 Oracle PeopleSoft campaign (CVE-2026-35273, unauthenticated RCE in PeopleTools Environment Management) kept acquiring named victims this week — the delta since the prior weekly&#39;s status.</p>
<p><strong>Nissan is the largest named victim yet.</strong> SecurityWeek reported Nissan disclosed a breach tied to the Oracle PeopleSoft attacks, exposing current and former employee HR/payroll PII across four countries — a different exposure profile than the NAIC breach the W26 weekly led with (<a href="https://www.securityweek.com/nissan-employee-data-breached-in-oracle-peoplesoft-hack/" target="_blank" rel="noopener noreferrer">SecurityWeek, 2026-06-30</a>; § references). It confirms the &quot;still acquiring victims&quot; throughline the W26 looking-ahead flagged, and that named victims now span beyond the education sector GTIG originally emphasised.</p>
<p><strong>A separate Medtronic claim — attribution precision matters.</strong> Medtronic is notifying ~9 million people of a ShinyHunters-<em>claimed</em> breach of corporate IT systems from April 2026 (names, DOB, SSNs, health data), with medical devices reported unaffected (<a href="https://www.bleepingcomputer.com/news/security/medtronic-notifies-customers-impacted-by-shinyhunters-data-breach/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-07-02</a>; § references). This is a <em>distinct</em> incident from the PeopleSoft campaign — a corporate-IT breach the brand claimed, not tied to the Oracle zero-day path — and the weekly notes it to keep the ShinyHunters cluster&#39;s several concurrent operations from being conflated: the PeopleSoft ERP zero-day campaign is one line of effort; opportunistic corporate-IT data extortion under the same brand is another.</p>
<p><strong>Status:</strong> GTIG&#39;s ~100-organisation notification set (68% higher education) is still landing, so more European education and public-finance victims are likely in the un-notified tail (<a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit" target="_blank" rel="noopener noreferrer">Google GTIG</a>). The separate, unattributed Oracle E-Business Suite RCE now exploited in the wild (this week&#39;s Oracle top story) compounds the message: internet-facing Oracle application tiers are a priority patch-and-isolate class regardless of which actor is behind any single CVE.</p><p class="entry-references"><strong>Builds on:</strong> <a class="mono" href="https://ctipilot.ch/entries/2026-07-01/nissan-is-the-largest-named-victim-yet-in-the-shinyhunters-o/">2026-07-01/nissan-is-the-largest-named-victim-yet-in-the-shinyhunters-o</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-03/medtronic-notifies-9-million-people-of-a-shinyhunters-claime/">2026-07-03/medtronic-notifies-9-million-people-of-a-shinyhunters-claime</a></p><div class="prov"><span>synthesis</span><span>05 Jul 23:40Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-shinyhunters-oracle-campaign-status/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.securityweek.com/nissan-employee-data-breached-in-oracle-peoplesoft-hack/" target="_blank" rel="noopener noreferrer">SecurityWeek</a> · <a href="https://www.bleepingcomputer.com/news/security/medtronic-notifies-customers-impacted-by-shinyhunters-data-breach/" target="_blank" rel="noopener noreferrer">BleepingComputer</a> · <a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit" target="_blank" rel="noopener noreferrer">Google GTIG / Mandiant</a></div></article>]]></content:encoded></item><item><title>This week&#39;s tradecraft: abusing trusted primitives — OAuth tokens, signed binaries, native APIs, legit SaaS</title><link>https://ctipilot.ch/entries/2026-07-05/weekly-w27-tradecraft-trusted-primitives/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-05/weekly-w27-tradecraft-trusted-primitives/</guid><pubDate>Sun, 05 Jul 2026 23:34:00 +0000</pubDate><dc:date>2026-07-05T23:34:00Z</dc:date><category>identity</category><category>espionage</category><category>infostealer</category><category>phishing</category><category>global</category><description><![CDATA[<p>Five independent research disclosures this week share a through-line: attackers are increasingly operating through trusted, native mechanisms rather than custom-malware signatures — ToddyCat&#39;s Umbrij steals OAuth tokens via Chromium remote-debugging; Talos&#39;s ARToken automates M365 device-code phishing and Primary-Refresh-Token persistence; Blackpoint&#39;s Avalon chains a signed MSBuild loader with ETW/AMSI patching; Jamf&#39;s PamStealer validates stolen macOS passwords through pam_authenticate; and Mustang Panda uses Zoho WorkDrive as a dead-drop C2. Signature-based detection degrades against all of them; the hunt surface is anomalous use of the trusted mechanism.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-05/weekly-w27-tradecraft-trusted-primitives" data-tags="identity espionage infostealer phishing" data-regions="global" data-kind="research" data-priority="notable" data-discovered="2026-07-05T23:34:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="weekly-w27-tradecraft-trusted-primitives"><a href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-tradecraft-trusted-primitives/">The week&#39;s tradecraft converged on abusing trusted primitives — OAuth tokens, signed binaries, native auth APIs and legitimate SaaS</a></h3><p>Five otherwise-unrelated research disclosures this week point the same direction: capable actors — from a Chinese APT to commodity BEC and ransomware crews — are increasingly operating <em>through</em> trusted, native mechanisms rather than dropping signatureable custom malware. For a detection-engineering audience, that is the strategic note, because it tells you where the hunt surface is moving.</p>
<p><strong>OAuth tokens as the target.</strong> Kaspersky GReAT documented <strong>Umbrij</strong>, a .NET tool the ToddyCat APT uses to automate theft of Google Workspace OAuth tokens via a technique GReAT calls Shadow Token via Remote Debug (STRD) — driving Chromium&#39;s remote-debugging interface to lift live tokens (<a href="https://securelist.com/toddycat-apt-umbrij-tool-and-oauth/120251/" target="_blank" rel="noopener noreferrer">Kaspersky Securelist, 2026-06-30</a>). Cisco Talos exposed <strong>ARToken</strong>, an EvilTokens-lineage BEC-as-a-service panel (80+ API endpoints) automating Microsoft 365 device-code phishing, Primary-Refresh-Token persistence that survives password resets, and mailbox/SharePoint exfiltration (<a href="https://blog.talosintelligence.com/artoken-inside-an-eviltokens-affiliate-panel-targeting-microsoft-365/" target="_blank" rel="noopener noreferrer">Cisco Talos</a>). Both defeat password-centric defences: the credential is no longer the secret worth stealing, the token is.</p>
<p><strong>Signed binaries and native APIs as the execution and validation layer.</strong> Blackpoint&#39;s <strong>Avalon</strong> framework chains a signed-binary MSBuild loader with ETW/AMSI patching (in-process telemetry tampering) and the CrownX ransomware payload (<a href="https://blackpointcyber.com/blog/avalons-path-from-legal-lure-to-crownx-ransom-capabilities/" target="_blank" rel="noopener noreferrer">Blackpoint Cyber</a>); Jamf&#39;s <strong>PamStealer</strong> impersonates the Maccy clipboard app and confirms a stolen macOS password through the native <code>pam_authenticate</code> API before exfiltrating it (<a href="https://www.jamf.com/blog/pamstealer-macos-infostealer-applescript-rust/" target="_blank" rel="noopener noreferrer">Jamf Threat Labs</a>) — using the OS&#39;s own auth path to guarantee the loot is valid.</p>
<p><strong>Legitimate SaaS as C2.</strong> Mustang Panda (TA416 / HIVE0154) used <strong>Zoho WorkDrive</strong> as a dead-drop C2 channel (ZOHOMURK) against government and energy targets (<a href="https://www.acronis.com/en/tru/posts/mustang-panda-targets-indias-government-and-energy-sectors/" target="_blank" rel="noopener noreferrer">Acronis TRU, 2026-06-29</a>) — command traffic riding a trusted, hard-to-block SaaS host.</p>
<p><strong>Weekly takeaway:</strong> the common defensive failure mode across all five is reliance on signatures and on the password as the crown jewel. The hunt has to move to <em>anomalous use of the trusted mechanism</em> — remote-debugging flags on browser processes, token issuance/reuse surviving resets, signed LOLBins loading unexpected code, ETW/AMSI tampering, native auth-API calls from non-auth processes, and server egress to consumer SaaS storage. Per-tool detail and detection concepts in § references.</p><p class="entry-references"><strong>Builds on:</strong> <a class="mono" href="https://ctipilot.ch/entries/2026-07-01/kaspersky-great-toddycat-s-umbrij-automates-gmail-workspace/">2026-07-01/kaspersky-great-toddycat-s-umbrij-automates-gmail-workspace</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-02/cisco-talos-artoken-exposes-a-full-bec-as-a-service-toolkit/">2026-07-02/cisco-talos-artoken-exposes-a-full-bec-as-a-service-toolkit</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-04/avalon-framework-msbuild-etw-loader-crownx-ransomware/">2026-07-04/avalon-framework-msbuild-etw-loader-crownx-ransomware</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-04/pamstealer-macos-infostealer-pam-api-password-validation/">2026-07-04/pamstealer-macos-infostealer-pam-api-password-validation</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-06-30/mustang-panda-abuses-zoho-workdrive-as-a-dead-drop-c2-channe/">2026-06-30/mustang-panda-abuses-zoho-workdrive-as-a-dead-drop-c2-channe</a></p><div class="prov"><span>research</span><span>05 Jul 23:34Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-tradecraft-trusted-primitives/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://securelist.com/toddycat-apt-umbrij-tool-and-oauth/120251/" target="_blank" rel="noopener noreferrer">Kaspersky Securelist (GReAT)</a> · <a href="https://blog.talosintelligence.com/artoken-inside-an-eviltokens-affiliate-panel-targeting-microsoft-365/" target="_blank" rel="noopener noreferrer">Cisco Talos</a> · <a href="https://blackpointcyber.com/blog/avalons-path-from-legal-lure-to-crownx-ransom-capabilities/" target="_blank" rel="noopener noreferrer">Blackpoint Cyber</a> · <a href="https://www.jamf.com/blog/pamstealer-macos-infostealer-applescript-rust/" target="_blank" rel="noopener noreferrer">Jamf Threat Labs</a></div></article>]]></content:encoded></item><item><title>Disruption momentum this week — NetNut proxy botnet dismantled, StegoAd extensions killed, $10M bounty</title><link>https://ctipilot.ch/entries/2026-07-05/weekly-w27-law-enforcement-momentum/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-05/weekly-w27-law-enforcement-momentum/</guid><pubDate>Sun, 05 Jul 2026 23:33:00 +0000</pubDate><dc:date>2026-07-05T23:33:00Z</dc:date><category>law-enforcement</category><category>botnet</category><category>organized-crime</category><category>global</category><description><![CDATA[<p>Three coordinated disruption actions landed this week: the FBI, Google, Lumen and Shadowserver dismantled the NetNut (Popa) residential-proxy botnet (~2M devices, abused by 316 distinct threat clusters in a single June week); Microsoft killed the StegoAd cluster of 119 malicious Edge extensions; and the US posted a $10M bounty on Russia-nexus Signal/WhatsApp phishing crews. The defender lesson is attrition, not elimination — residential-proxy abuse and extension-based delivery shift providers rather than stopping.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-05/weekly-w27-law-enforcement-momentum" data-tags="law-enforcement botnet organized-crime" data-regions="global" data-kind="incident" data-priority="notable" data-discovered="2026-07-05T23:33:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 1: Confirmed"><span class="k">NATO</span>B1</span></div><h3 class="f-h" id="weekly-w27-law-enforcement-momentum"><a href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-law-enforcement-momentum/">Law-enforcement and platform-disruption momentum this week — NetNut/Popa proxy botnet dismantled, StegoAd extension cluster killed, $10M bounty on Russia-nexus crews</a></h3><p>Three disruption actions this week are worth consolidating not as wins to celebrate but for what each says about the durability of the abused technique.</p>
<p><strong>NetNut (Popa) residential-proxy botnet dismantled.</strong> The FBI — with Google, Lumen and Shadowserver — seized NetNut/Popa infrastructure on 2026-07-02; Google disabled the Google accounts used for C2 and updated Play Protect to block apps bundling the malicious SDKs, while the FBI seized <code>netnut.com</code> (<a href="https://cloud.google.com/blog/topics/threat-intelligence/google-continued-disruption-residential-proxy-networks" target="_blank" rel="noopener noreferrer">Google GTIG, 2026-07-02</a>; <a href="https://krebsonsecurity.com/2026/07/fbi-seizes-netnut-proxy-platform-popa-botnet/" target="_blank" rel="noopener noreferrer">Krebs on Security, 2026-07-02</a>). The strategic figure GTIG surfaces is that in a single June week it observed <strong>316 distinct threat clusters</strong> — criminal and suspected-espionage — routing traffic through suspected NetNut exit nodes to mask origin IPs during password-spray, credential-stuffing and infrastructure access. That confirms residential-proxy relay as shared criminal/state infrastructure, and Google&#39;s own caution is the key defender note: degraded operators buy capacity from rivals, so proxy-based anonymisation volumes shift providers rather than dropping (§ references, operational coverage 07-04).</p>
<p><strong>StegoAd extension cluster.</strong> Microsoft disrupted StegoAd — 119 Edge extensions that hid payloads inside image and font files via steganography (<code>campaign:stegoad-darkspectre-119-edge-extensions-steganography</code>) — reinforcing browser-extension marketplaces as a recurring, disruptable delivery surface (this week&#39;s operational coverage, § references).</p>
<p><strong>$10M bounty on Russia-nexus crews.</strong> The US added a $10M bounty on the Russia-nexus Signal/WhatsApp phishing crews and folded Signal Backup-Recovery-Key theft into the advisory (this week&#39;s operational coverage, § references).</p>
<p><strong>Weekly takeaway:</strong> all three targets abuse infrastructure that is cheap to re-provision — residential proxies, browser extensions, messaging-app social engineering — so the correct posture for a SOC is to keep the <em>behavioural</em> detections (implausible residential-ASN auth sequences, extension-install governance, Signal backup-key hygiene for high-risk staff) running past the headlines, because the operators displaced this week reappear behind new providers. This week&#39;s Mustang Panda dead-drop-C2-via-Zoho-WorkDrive case (§ references) is the same lesson from the offensive side: abuse of legitimate, hard-to-block infrastructure is the through-line.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">In a single week during June 2026, GTIG observed 316 distinct threat clusters using suspected NetNut exit nodes, including cybercriminal and espionage groups.</p><p class="entry-cite__quote">Google Threat Intelligence Group (GTIG) estimates the size of the NetNut network to be at least 2 million devices, distributed across the world.</p><figcaption class="entry-cite__attr"><a href="https://cloud.google.com/blog/topics/threat-intelligence/google-continued-disruption-residential-proxy-networks" target="_blank" rel="noopener noreferrer">Google Cloud (GTIG)</a></figcaption></figure></div><p class="entry-references"><strong>Builds on:</strong> <a class="mono" href="https://ctipilot.ch/entries/2026-07-04/netnut-popa-residential-proxy-botnet-disrupted-by-google-fbi/">2026-07-04/netnut-popa-residential-proxy-botnet-disrupted-by-google-fbi</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-06-30/microsoft-disrupts-stegoad-119-edge-extensions-hid-payloads/">2026-06-30/microsoft-disrupts-stegoad-119-edge-extensions-hid-payloads</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-06-30/us-posts-10m-bounty-on-the-russia-nexus-signal-whatsapp-crew/">2026-06-30/us-posts-10m-bounty-on-the-russia-nexus-signal-whatsapp-crew</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-06-30/mustang-panda-abuses-zoho-workdrive-as-a-dead-drop-c2-channe/">2026-06-30/mustang-panda-abuses-zoho-workdrive-as-a-dead-drop-c2-channe</a></p><div class="prov"><span>incident</span><span>05 Jul 23:33Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-law-enforcement-momentum/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://cloud.google.com/blog/topics/threat-intelligence/google-continued-disruption-residential-proxy-networks" target="_blank" rel="noopener noreferrer">Google Cloud (GTIG)</a> · <a href="https://krebsonsecurity.com/2026/07/fbi-seizes-netnut-proxy-platform-popa-botnet/" target="_blank" rel="noopener noreferrer">Krebs on Security</a> · <a href="https://www.bleepingcomputer.com/news/security/netnut-proxy-network-disrupted-2-million-infected-devices-cut-off/" target="_blank" rel="noopener noreferrer">BleepingComputer</a></div></article>]]></content:encoded></item><item><title>Vuln status roll-up 2026-W27 — exploited, KEV-listed, working-exploit, and weaponisation-likely items</title><link>https://ctipilot.ch/entries/2026-07-05/weekly-w27-vuln-status-rollup/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-05/weekly-w27-vuln-status-rollup/</guid><pubDate>Sun, 05 Jul 2026 23:30:00 +0000</pubDate><dc:date>2026-07-05T23:30:00Z</dc:date><category>vulnerabilities</category><category>actively-exploited</category><category>cisa-kev</category><category>rce</category><category>patch-available</category><category>global</category><category>europe</category><description><![CDATA[<p>The week&#39;s vulnerability status at a glance for a public-sector estate: newly exploited/KEV (SimpleHelp CVE-2026-48558, Oracle EBS CVE-2026-46817, SharePoint CVE-2026-45659, Kemp LoadMaster CVE-2026-8037); working-exploit or PoC (DirtyClone Linux LPE CVE-2026-43503, libssh2 CVE-2026-55200, Citrix NetScaler CVE-2026-8451); and weaponisation-likely-but-not-yet-exploited (six CVSS 10.0 Adobe ColdFusion RCEs, Control Web Panel CVE-2026-57517, Coolify CVE-2026-34038).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-05/weekly-w27-vuln-status-rollup" data-tags="vulnerabilities actively-exploited cisa-kev rce patch-available" data-regions="global europe" data-kind="vulnerability" data-priority="high" data-discovered="2026-07-05T23:30:00Z"><div class="badges"><span class="b pri">HIGH</span><span class="b exp">exploited</span></div><h3 class="f-h" id="weekly-w27-vuln-status-rollup"><a href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-vuln-status-rollup/">Vulnerability status roll-up — 2026-W27: what moved, what to patch on the exploited-flaw clock vs the monthly cycle</a></h3><p>This is the week&#39;s vulnerability state as a single scannable view — the CVE detail and full sourcing live in the operational entries that first covered each item (§ references); the value here is the current status and the patch-priority framing.</p>
<p><strong>Newly exploited / KEV-listed this week (assume-compromise if exposed and unpatched).</strong> SimpleHelp RMM <strong>CVE-2026-48558</strong> (CVSS 10.0 OIDC auth bypass) moved to active exploitation + CISA KEV, deploying the Djinn infostealer (this week&#39;s top story). Oracle E-Business Suite <strong>CVE-2026-46817</strong> (pre-auth RCE) saw its first in-the-wild exploitation. Microsoft SharePoint Server <strong>CVE-2026-45659</strong> (CWE-502 deserialization, Site-Member RCE) was added to CISA KEV on 2026-07-01 — the first public confirmation of exploitation, and notable because Microsoft&#39;s own advisory still rates it &quot;Exploitation Less Likely,&quot; a contradiction defenders should resolve toward the exploitation evidence (<a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-45659" target="_blank" rel="noopener noreferrer">Microsoft MSRC</a>; <a href="https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json" target="_blank" rel="noopener noreferrer">CISA KEV feed, 2026-07-01</a>). Progress Kemp LoadMaster <strong>CVE-2026-8037</strong> (pre-auth RCE) drew exploitation attempts the day its PoC dropped (covered in this week&#39;s edge-appliance entry).</p>
<p><strong>Working exploit or public PoC (patch on emergency cadence).</strong> DirtyClone Linux-kernel LPE <strong>CVE-2026-43503</strong> now has a confirmed working exploit on default Debian/Fedora; the libssh2 pre-auth heap write <strong>CVE-2026-55200</strong> has a public PoC; Citrix NetScaler <strong>CVE-2026-8451</strong> has a public susceptibility-testing artefact.</p>
<p><strong>Weaponisation-likely, not yet exploited (patch before the PoC lands).</strong> Adobe&#39;s APSB26-68 fixed <strong>six CVSS 10.0</strong> unauthenticated RCE paths in ColdFusion 2025/2023 — two unrestricted-file-upload, three input-validation, one path-traversal — all Adobe Priority 1 (&quot;high risk of being targeted&quot;), with Adobe stating no known in-the-wild exploits yet; ColdFusion&#39;s history of rapid weaponisation of unauth file-upload primitives makes this a same-week patch priority for any internet-facing instance (<a href="https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html" target="_blank" rel="noopener noreferrer">Adobe PSIRT APSB26-68, 2026-06-30</a>). Control Web Panel <strong>CVE-2026-57517</strong> (pre-auth SQLi→RCE) and Coolify <strong>CVE-2026-34038</strong> (authenticated command injection, CVSS 9.9) round out the high-impact patch set.</p>
<p><strong>Also patched this week (standard cycle, no exploitation):</strong> Gogs <strong>CVE-2026-52806</strong> (now abused for cryptojacking), the SzafirHost e-signature client JAR parser-confusion RCE <strong>CVE-2026-13165</strong> (CERT Polska — EU public-sector e-signature relevance), Altium Enterprise Server <strong>CVE-2026-14439</strong>, and cve-search <strong>CVE-2026-59509</strong>. Full per-CVE detail in § references.</p><p class="entry-references"><strong>Builds on:</strong> <a class="mono" href="https://ctipilot.ch/entries/2026-06-30/cve-2026-48558-simplehelp-rmm-oidc-sso-authentication-bypass/">2026-06-30/cve-2026-48558-simplehelp-rmm-oidc-sso-authentication-bypass</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-01/oracle-e-business-suite-cve-2026-46817-pre-auth-rce-in-the-p/">2026-07-01/oracle-e-business-suite-cve-2026-46817-pre-auth-rce-in-the-p</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-02/cve-2026-45659-microsoft-sharepoint-server-authenticated-des/">2026-07-02/cve-2026-45659-microsoft-sharepoint-server-authenticated-des</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-02/kemp-loadmaster-cve-2026-8037-exploitation-attempts-confirme/">2026-07-02/kemp-loadmaster-cve-2026-8037-exploitation-attempts-confirme</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-06-30/dirtyclone-linux-kernel-lpe-cve-2026-43503-now-has-a-confirm/">2026-06-30/dirtyclone-linux-kernel-lpe-cve-2026-43503-now-has-a-confirm</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-06-30/public-poc-released-for-the-libssh2-pre-auth-heap-write-cve/">2026-06-30/public-poc-released-for-the-libssh2-pre-auth-heap-write-cve</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-01/cve-2026-8451-citrix-netscaler-adc-gateway-pre-auth-saml-mem/">2026-07-01/cve-2026-8451-citrix-netscaler-adc-gateway-pre-auth-saml-mem</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-02/cve-2026-48276-48277-48281-48282-48283-48316-adobe-coldfusio/">2026-07-02/cve-2026-48276-48277-48281-48282-48283-48316-adobe-coldfusio</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-03/cve-2026-57517-control-web-panel-pre-auth-sqli-to-rce/">2026-07-03/cve-2026-57517-control-web-panel-pre-auth-sqli-to-rce</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-03/cve-2026-34038-coolify-authenticated-command-injection-to-rc/">2026-07-03/cve-2026-34038-coolify-authenticated-command-injection-to-rc</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-06-29/gogs-cve-2026-52806-moves-from-no-observed-exploitation-to-a/">2026-06-29/gogs-cve-2026-52806-moves-from-no-observed-exploitation-to-a</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-06-30/cert-polska-discloses-a-jar-parser-confusion-rce-in-the-szaf/">2026-06-30/cert-polska-discloses-a-jar-parser-confusion-rce-in-the-szaf</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-02/cve-2026-14439-altium-enterprise-server-altium-365-authentic/">2026-07-02/cve-2026-14439-altium-enterprise-server-altium-365-authentic</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-05/cve-2026-59509-cve-search-fetch-cve-data-nosql/">2026-07-05/cve-2026-59509-cve-search-fetch-cve-data-nosql</a></p><div class="prov"><span>vulnerability</span><span>05 Jul 23:30Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-vuln-status-rollup/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html" target="_blank" rel="noopener noreferrer">Adobe PSIRT (APSB26-68)</a> · <a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-45659" target="_blank" rel="noopener noreferrer">Microsoft MSRC</a> · <a href="https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json" target="_blank" rel="noopener noreferrer">CISA KEV feed</a></div></article>]]></content:encoded></item></channel></rss>