<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>ctipilot.ch · OT / ICS</title><link>https://ctipilot.ch/</link><atom:link href="https://ctipilot.ch/feed-ot-ics.xml" rel="self" type="application/rss+xml"/><description>Items affecting operational-technology / industrial-control-system environments · energy, water, manufacturing, transport, and any item tagged ot-ics.</description><language>en</language><lastBuildDate>Sat, 18 Jul 2026 04:35:00 +0000</lastBuildDate><item><title>Broadcom patches a pre-auth authentication bypass on the VMware Avi Load Balancer control plane (CVE-2026-47865), reported by NATO NCSC</title><link>https://ctipilot.ch/entries/2026-07-18/vmware-avi-load-balancer-cve-2026-47865-auth-bypass/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-18/vmware-avi-load-balancer-cve-2026-47865-auth-bypass/</guid><pubDate>Sat, 18 Jul 2026 04:35:00 +0000</pubDate><dc:date>2026-07-18T04:35:00Z</dc:date><category>vulnerabilities</category><category>auth-bypass</category><category>pre-auth</category><category>no-patch</category><category>cloud</category><category>global</category><category>europe</category><category>patch-available</category><category>CVE-2026-47865</category><category>CVE-2026-47867</category><category>CVE-2026-47871</category><category>CVE-2026-47868</category><category>CVE-2026-47866</category><category>CVE-2026-47869</category><category>CVE-2026-47870</category><description><![CDATA[<p>Broadcom advisory VMSA-2026-0005 (2026-07-14) discloses seven flaws in VMware Avi Load Balancer (formerly NSX Advanced Load Balancer); the headline flaw CVE-2026-47865 (CVSS 9.8) lets an unauthenticated remote attacker reach the Avi Controller control plane by bypassing authentication entirely, with no workaround available. Affected: 22.1.1–22.1.7, 30.1.1–30.2.6, 31.1.1–31.2.2 and 32.1.1; fixed in 32.1.2, 31.2.2-2p3 and 30.2.7. No in-the-wild exploitation is reported, but the bug was reported by NATO NCSC and the control plane governs traffic routing and TLS termination for whatever sits behind the load balancer.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-18/vmware-avi-load-balancer-cve-2026-47865-auth-bypass" data-tags="vulnerabilities auth-bypass pre-auth no-patch cloud" data-regions="global europe" data-kind="vulnerability" data-priority="high" data-discovered="2026-07-18T04:35:00Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-47865/">CVE-2026-47865 +6</a><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 2: Probably true"><span class="k">NATO</span>A2</span></div><h3 class="f-h" id="vmware-avi-load-balancer-cve-2026-47865-auth-bypass"><a href="https://ctipilot.ch/entries/2026-07-18/vmware-avi-load-balancer-cve-2026-47865-auth-bypass/">CVE-2026-47865 — VMware Avi Load Balancer: unauthenticated control-plane authentication bypass (CVSS 9.8), no workaround</a></h3><p>Broadcom&#39;s VMSA-2026-0005 (2026-07-14, last updated 2026-07-15) patches seven vulnerabilities in VMware Avi Load Balancer — the load-balancing/application-delivery product formerly sold as NSX Advanced Load Balancer and widely deployed in enterprise and government data-centre fabric across Europe. The load-bearing flaw, <strong>CVE-2026-47865</strong> (CVSS 9.8), is an authentication bypass on the Avi Controller: &quot;a malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism&quot; — no credentials, no user interaction (<a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926" target="_blank" rel="noopener noreferrer">Broadcom PSIRT, 2026-07-14</a>). The advisory ships six companion flaws that require a prior foothold: two high-privilege remote code-execution bugs (CVE-2026-47867, CVE-2026-47869, both CVSS 8.7, PR:H), a low-privilege authenticated directory traversal (CVE-2026-47871, CVSS 8.8), an authorization bypass (CVE-2026-47866, CVSS 8.3), a local-to-root privilege escalation (CVE-2026-47868, CVSS 7.8) and a further privilege escalation (CVE-2026-47870, CVSS 7.1). Broadcom states no workarounds exist (<a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926" target="_blank" rel="noopener noreferrer">Broadcom PSIRT, 2026-07-14</a>); the German trade press summarised it as attackers being able to bypass authentication and authorization (<a href="https://www.heise.de/news/VMware-Avi-Load-Balancer-Kritische-Luecke-erlaubt-Umgehung-von-Anmeldung-11368661.html" target="_blank" rel="noopener noreferrer">heise Security, 2026-07-17</a>).</p>
<p>No in-the-wild exploitation has been reported, but two facts raise this above the routine patch cycle: the reporter is the NATO NCSC (a direct constituency-provenance signal), and there is no mitigation short of upgrading. Because the Avi Controller is the management and orchestration plane for the load-balancing fabric, an unauthenticated bypass there is a direct path to reconfiguring traffic routing and TLS termination for every service behind the load balancer — an interception and traffic-manipulation position, not merely appliance compromise.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">Upgrade the Avi Controller to a fixed release — 32.1.2 (recommended), 31.2.2-2p3 or 30.2.7; the 22.1.x branch must move to at least 30.2.7. Because no workaround exists, until the upgrade lands restrict Controller management-plane reachability to trusted management VLANs/jump hosts and treat any exposure of the Avi Controller to broad or untrusted network segments as the finding in its own right. Detection concept, telemetry-class first: Avi Controller admin/API authentication logs showing control-plane session establishment or API calls with no preceding successful login event, particularly from source ranges outside the management network.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism.</p><figcaption class="entry-cite__attr"><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926" target="_blank" rel="noopener noreferrer">Broadcom / VMware PSIRT (VMSA-2026-0005)</a> <span class="entry-cite__date mono">2026-07-14</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>18 Jul 04:35Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-18/vmware-avi-load-balancer-cve-2026-47865-auth-bypass/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926" target="_blank" rel="noopener noreferrer">Broadcom / VMware PSIRT (VMSA-2026-0005)</a> · <a href="https://www.heise.de/news/VMware-Avi-Load-Balancer-Kritische-Luecke-erlaubt-Umgehung-von-Anmeldung-11368661.html" target="_blank" rel="noopener noreferrer">heise Security</a></div></article>]]></content:encoded></item><item><title>Volexity attributes the SonicWall SMA 1000 zero-day exploitation to UTA0533 and details the SSRF-to-root chain, on-appliance implants and LDAP credential theft</title><link>https://ctipilot.ch/entries/2026-07-18/sonicwall-sma1000-uta0533-exploitation-kill-chain/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-18/sonicwall-sma1000-uta0533-exploitation-kill-chain/</guid><pubDate>Sat, 18 Jul 2026 04:35:00 +0000</pubDate><dc:date>2026-07-18T04:35:00Z</dc:date><category>vulnerabilities</category><category>actively-exploited</category><category>zero-day</category><category>pre-auth</category><category>rce</category><category>auth-bypass</category><category>global</category><category>europe</category><category>exploited</category><category>cisa-kev</category><category>patch-available</category><category>CVE-2026-15409</category><category>CVE-2026-15410</category><description><![CDATA[<p>Volexity has reconstructed the intrusion behind the actively-exploited SonicWall SMA 1000 zero-days (CVE-2026-15409 SSRF, CVE-2026-15410 path-traversal command injection), attributing it to an actor it tracks as UTA0533 with the earliest compromise on 2026-06-22. The chain: an unauthenticated /wsproxy request tunnels to a localhost-only service for initial code execution, a hotfix-rollback path traversal escalates to root, then the actor injects a proxy (Suo5) and a Java webshell (ORANGETAIL) into the appliance&#39;s legitimate workplace process, persists via an init script, captures cleartext LDAP credentials with tcpdump, and pivots into the internal network. Stolen credentials survive patching — the hotfix alone does not remediate a pre-patch compromise.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-18/sonicwall-sma1000-uta0533-exploitation-kill-chain" data-tags="vulnerabilities actively-exploited zero-day pre-auth rce auth-bypass" data-regions="global europe" data-kind="threat" data-priority="high" data-discovered="2026-07-18T04:35:00Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-15409/">CVE-2026-15409 +1</a><span class="b exp">exploited</span><span class="b upd">update</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 1: Confirmed"><span class="k">NATO</span>B1</span></div><h3 class="f-h" id="sonicwall-sma1000-uta0533-exploitation-kill-chain"><a href="https://ctipilot.ch/entries/2026-07-18/sonicwall-sma1000-uta0533-exploitation-kill-chain/">SonicWall SMA 1000 zero-day exploitation (CVE-2026-15409/-15410): Volexity reconstructs UTA0533&#39;s full appliance-to-network kill chain</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited/">CVE-2026-15409 — SonicWall SMA1000: unauthenticated SSRF (CVSS 10.0) chained to post-auth code injection, actively exploited</a> <span class="mono muted">(2026-07-14)</span></p><p>The original entry recorded SonicWall&#39;s confirmation that CVE-2026-15409/-15410 were being exploited as zero-days and directed emergency patching. Volexity has now published the reconstructed intrusion, attributed it to an actor it tracks as <strong>UTA0533</strong>, and shown that patching alone is insufficient — the delta below is the full kill chain, the on-appliance implants, and the compromise-response guidance the terse advisory did not carry (<a href="https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/" target="_blank" rel="noopener noreferrer">Volexity, 2026-07-17</a>).</p>
<p>Volexity was engaged after suspect authentication and lateral movement were seen originating <em>from</em> SonicWall SMA 1000 appliances (models 6210/7210/8200v); the earliest sign of compromise was 2026-06-22, weeks before SonicWall&#39;s 2026-07-14 disclosure (<a href="https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/" target="_blank" rel="noopener noreferrer">Volexity, 2026-07-17</a>). SonicWall&#39;s PSIRT confirms it &quot;has investigated multiple cases indicating the active exploitation of the vulnerabilities described in this advisory&quot; (<a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008" target="_blank" rel="noopener noreferrer">SonicWall SNWLID-2026-0008, 2026-07-14</a>), and Rapid7&#39;s MDR team independently found the same two zero-days under attack (<a href="https://www.rapid7.com/blog/post/etr-rapid7-mdr-team-discovers-new-sonicwall-sma1000-zero-days-being-actively-exploited-cve-2026-15409-cve-2026-15410/" target="_blank" rel="noopener noreferrer">Rapid7, 2026-07-16</a>).</p>
<p><strong>Initial access (T1190, T1133).</strong> CVE-2026-15409 is a pre-authentication server-side request forgery in the SMA 1000 <code>/wsproxy</code> endpoint. A crafted WebSocket-upgrade request establishes a tunnel from the unauthenticated external attacker straight to services that are supposed to be reachable only on the appliance&#39;s own loopback — Volexity confirms &quot;no valid SMA session cookie was required during this process&quot; (<a href="https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/" target="_blank" rel="noopener noreferrer">Volexity, 2026-07-17</a>). Through the tunnel the actor reached the appliance&#39;s bundled CouchDB/Erlang services and a localhost-only control service; the shipped CouchDB carries hardcoded <code>admin:admin</code> credentials, and the control service&#39;s authentication password is derivable from a device UUID, so the SSRF turns both into part of the external attack surface.</p>
<p><strong>Privilege escalation (T1068).</strong> CVE-2026-15410 is a path traversal in the hotfix-rollback workflow: the <code>sysCtrl.execRemoveHotfix</code> operation builds a rollback path from caller-controlled input and hands it to <code>/usr/local/bin/remove_hotfix</code>, which then executes it. A rollback name containing directory-traversal sequences resolves outside the intended rollback directory and runs an attacker-staged script as root.</p>
<p><strong>Persistence and implants (T1055, T1505.003, T1090.003, T1037.004).</strong> With root, UTA0533 dropped a setuid helper and a Python loader Volexity calls <strong>KNUCKLEBALL</strong>, which injects two JAR archives into the appliance&#39;s legitimate <code>workplace</code> process: the open-source <strong>Suo5</strong> HTTP proxy-forwarder and a Behinder-like Java webshell Volexity calls <strong>ORANGETAIL</strong>. Persistence was established by adding a call to the loader inside the appliance&#39;s <code>workplace</code> init script, and the NGINX Unit configuration was rewritten to add routes that proxy attacker-chosen (arbitrary) request paths to the injected webshell and proxy — so hunting for a fixed URL is the wrong shape; the behaviour is unexpected route entries in the appliance&#39;s own reverse-proxy configuration.</p>
<p><strong>Credential access and lateral movement (T1040, T1059).</strong> The actor ran <code>tcpdump</code> from a script staged in the appliance&#39;s temp directory to capture unencrypted LDAP traffic (TCP 389), harvesting directory credentials off the wire (<a href="https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/" target="_blank" rel="noopener noreferrer">Volexity, 2026-07-17</a>). Rapid7&#39;s engagement observed the actor then &quot;quickly shifted to lateral movement, pivoting from the compromised appliance directly into the internal corporate network&quot; (<a href="https://www.rapid7.com/blog/post/etr-rapid7-mdr-team-discovers-new-sonicwall-sma1000-zero-days-being-actively-exploited-cve-2026-15409-cve-2026-15410/" target="_blank" rel="noopener noreferrer">Rapid7, 2026-07-16</a>). How far that onward movement reached differs across the two IR firms&#39; cases: Volexity concludes that in the appliances <em>it</em> investigated, &quot;available evidence suggests the threat actor was less successful moving laterally or gaining access to other systems&quot; (<a href="https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/" target="_blank" rel="noopener noreferrer">Volexity, 2026-07-17</a>) — so treat a foothold on the appliance as a demonstrated launch point for internal movement, but not evidence that deep lateral movement always succeeds.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">Patching to the hotfix (12.4.3-03453 / 12.5.0-02835) closes the two CVEs but does nothing about credentials already captured or implants already planted, so any appliance that was exposed and unpatched must be handled as an assume-compromise: SonicWall and both IR firms recommend re-imaging on any indicator, and resetting all account passwords and TOTP seeds. Detection concepts, telemetry-class first: in the appliance&#39;s web/access logs, unauthenticated <code>/wsproxy</code> WebSocket-upgrade requests that return a 101 protocol-upgrade status with no valid session cookie and target an internal (loopback-facing) service port; in the control-service log, hotfix-rollback operations carrying path-traversal sequences in the rollback name; on the network, LDAP binds and other authentication originating <em>from</em> the SMA appliance&#39;s own address, and any egress or lateral connection from an appliance that should only ever terminate inbound VPN sessions. <strong>Triage:</strong> an SMA 1000 legitimately proxies authenticated user sessions inbound — the discriminators are a <code>/wsproxy</code> upgrade with no session cookie reaching a loopback service, and the appliance itself <em>initiating</em> authentication or connections into the internal network, which a remote-access gateway has no benign reason to do.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">No valid SMA session cookie was required during this process.</p><figcaption class="entry-cite__attr"><a href="https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/" target="_blank" rel="noopener noreferrer">Volexity</a> <span class="entry-cite__date mono">2026-07-17</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">SonicWall PSIRT has investigated multiple cases indicating the active exploitation of the vulnerabilities described in this advisory.</p><figcaption class="entry-cite__attr"><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008" target="_blank" rel="noopener noreferrer">SonicWall PSIRT (SNWLID-2026-0008)</a> <span class="entry-cite__date mono">2026-07-14</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">the threat actors quickly shifted to lateral movement, pivoting from the compromised appliance directly into the internal corporate network</p><figcaption class="entry-cite__attr"><a href="https://www.rapid7.com/blog/post/etr-rapid7-mdr-team-discovers-new-sonicwall-sma1000-zero-days-being-actively-exploited-cve-2026-15409-cve-2026-15410/" target="_blank" rel="noopener noreferrer">Rapid7</a> <span class="entry-cite__date mono">2026-07-16</span></figcaption></figure></div><div class="prov"><span>threat</span><span>18 Jul 04:35Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-18/sonicwall-sma1000-uta0533-exploitation-kill-chain/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/" target="_blank" rel="noopener noreferrer">Volexity</a> · <a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008" target="_blank" rel="noopener noreferrer">SonicWall PSIRT (SNWLID-2026-0008)</a> · <a href="https://www.rapid7.com/blog/post/etr-rapid7-mdr-team-discovers-new-sonicwall-sma1000-zero-days-being-actively-exploited-cve-2026-15409-cve-2026-15410/" target="_blank" rel="noopener noreferrer">Rapid7</a></div></article>]]></content:encoded></item><item><title>Unit 42 publishes a full RUGGEDCOM ROX II exploit chain — file disclosure, feature-key command injection, and task-scheduler persistence to root</title><link>https://ctipilot.ch/entries/2026-07-18/siemens-ruggedcom-rox-ii-unit42-three-cve-chain/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-18/siemens-ruggedcom-rox-ii-unit42-three-cve-chain/</guid><pubDate>Sat, 18 Jul 2026 04:35:00 +0000</pubDate><dc:date>2026-07-18T04:35:00Z</dc:date><category>vulnerabilities</category><category>ot-ics</category><category>rce</category><category>priv-esc</category><category>patch-available</category><category>global</category><category>europe</category><category>patch-available</category><category>CVE-2025-40948</category><category>CVE-2025-40947</category><category>CVE-2025-40949</category><description><![CDATA[<p>Palo Alto Unit 42 published (2026-07-17) a three-stage exploit chain against Siemens RUGGEDCOM ROX II operational-technology switches: CVE-2025-40948 (CVSS 6.8) misuses a root-privileged xz invocation to read any file on the device, CVE-2025-40947 (CVSS 7.5) is command injection in the feature-key signature-verification path, and CVE-2025-40949 (CVSS 9.1) lets an authenticated attacker inject commands into the web-management task scheduler for persistent, reboot-surviving root code execution. Siemens patched all three in firmware V2.17.1 (advisories SSA-973901/-078743/-081142); no in-the-wild exploitation is reported. ROX II sits as a network-security/routing boundary inside rail, utility, water and manufacturing networks across Europe.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-18/siemens-ruggedcom-rox-ii-unit42-three-cve-chain" data-tags="vulnerabilities ot-ics rce priv-esc patch-available" data-regions="global europe" data-kind="vulnerability" data-priority="notable" data-discovered="2026-07-18T04:35:00Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2025-40948/">CVE-2025-40948 +2</a><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 1: Confirmed"><span class="k">NATO</span>B1</span></div><h3 class="f-h" id="siemens-ruggedcom-rox-ii-unit42-three-cve-chain"><a href="https://ctipilot.ch/entries/2026-07-18/siemens-ruggedcom-rox-ii-unit42-three-cve-chain/">CVE-2025-40948/-40947/-40949 — Siemens RUGGEDCOM ROX II: Unit 42 chains three OT-switch flaws to persistent root</a></h3><p>Unit 42 published a chained analysis (2026-07-17) of three vulnerabilities in Siemens RUGGEDCOM ROX II, the ruggedised OT switch/router family Siemens positions as a network-security boundary inside industrial networks — rail, utilities, water and manufacturing, including Swiss and European critical infrastructure (<a href="https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/" target="_blank" rel="noopener noreferrer">Unit 42, 2026-07-17</a>). The chain moves from information disclosure to persistent root. Stage one, <strong>CVE-2025-40948</strong> (CVSS 6.8), abuses a root-privileged daemon that invokes the <code>xz</code> utility with attacker-supplied parameters: supplying <code>-f</code>, <code>-c</code> and <code>-d</code> together turns <code>xz</code> into a <code>cat</code> equivalent, letting an attacker read any file on the device — configuration, password hashes, private keys (<a href="https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/" target="_blank" rel="noopener noreferrer">Unit 42, 2026-07-17</a>). Stage two, <strong>CVE-2025-40947</strong> (CVSS 7.5), is command injection in the feature-key signature-verification routine: the parsed signature string is inserted unsanitised into a <code>gpgv</code> command executed via <code>system()</code> as root, so a crafted feature-key file whose signature field carries a command-injection payload runs attacker code as root (typically after the attacker uploads a script through the web UI&#39;s normal feature-key upload). Stage three, <strong>CVE-2025-40949</strong> (CVSS 9.1), is command injection in the web-management task scheduler — Siemens describes it as an &quot;authenticated remote attacker&quot; injecting commands that &quot;execute arbitrary commands with root privileges&quot; (<a href="https://cert-portal.siemens.com/productcert/html/ssa-081142.html" target="_blank" rel="noopener noreferrer">Siemens ProductCERT SSA-081142, 2026-05-12</a>) — writing malicious entries into the scheduler configuration for persistent, reboot-surviving root execution.</p>
<p>Siemens patched all three in firmware <strong>V2.17.1</strong> across the ROX II family (MX5000/MX5000RE, the RX1400–RX1536 line, RX5000) and published advisories SSA-973901, SSA-078743 and SSA-081142; no in-the-wild exploitation is reported. The transferable lesson beyond this device family, per Unit 42, is the anti-pattern: a device invoking a general-purpose CLI utility (here <code>xz</code>) as root inside its own validation logic is a recurring OT/embedded-appliance weakness worth hunting for elsewhere.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">Schedule the V2.17.1 firmware update on ROX II estates; where an OT change window delays it, keep the ROX II web-management and feature-key-upload interfaces isolated from untrusted segments as the interim control. Detection concept, telemetry-class first: on devices exposing shell/audit telemetry, hunt for anomalous <code>xz</code> invocations combining the <code>-f</code>/<code>-c</code>/<code>-d</code> flags, feature-key upload activity outside maintenance windows, and unexpected entries appearing in the task-scheduler configuration (arbitrary interpreters such as <code>python</code>/<code>bash</code> or direct system calls in place of legitimate task functions). <strong>Triage:</strong> legitimate ROX II administration uses the scheduler for periodic maintenance tasks — the discriminator is a scheduled task whose command field invokes a general script interpreter or shell rather than the device&#39;s own task functions, especially one added outside a change window.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Successful exploitation of this chain would allow an attacker to achieve full privilege escalation and persistent root-level access on these devices, which are critical components of industrial control networks.</p><figcaption class="entry-cite__attr"><a href="https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/" target="_blank" rel="noopener noreferrer">Palo Alto Networks Unit 42</a> <span class="entry-cite__date mono">2026-07-17</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">Ruggedcom Rox contains an input validation vulnerability in the Scheduler functionality that could allow an authenticated remote attacker to execute arbitrary commands with root privileges on the underlying operating system.</p><figcaption class="entry-cite__attr"><a href="https://cert-portal.siemens.com/productcert/html/ssa-081142.html" target="_blank" rel="noopener noreferrer">Siemens ProductCERT (SSA-081142)</a> <span class="entry-cite__date mono">2026-05-12</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>18 Jul 04:35Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-18/siemens-ruggedcom-rox-ii-unit42-three-cve-chain/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/" target="_blank" rel="noopener noreferrer">Palo Alto Networks Unit 42</a> · <a href="https://cert-portal.siemens.com/productcert/html/ssa-081142.html" target="_blank" rel="noopener noreferrer">Siemens ProductCERT (SSA-081142)</a></div></article>]]></content:encoded></item><item><title>Metro Mondego confirms a 6 July ransomware attack on internal systems — transport operation unaffected; TheGentlemen claims data theft</title><link>https://ctipilot.ch/entries/2026-07-18/metro-mondego-thegentlemen-ransomware-portugal-transit/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-18/metro-mondego-thegentlemen-ransomware-portugal-transit/</guid><pubDate>Sat, 18 Jul 2026 04:35:00 +0000</pubDate><dc:date>2026-07-18T04:35:00Z</dc:date><category>ransomware</category><category>data-breach</category><category>organized-crime</category><category>europe</category><description><![CDATA[<p>Metro Mondego, the public operator of the Metrobus light-rail service between Lousã and Coimbra (Portugal), confirmed on 2026-07-17 that a ransomware attack on 6 July affected part of its internal systems without compromising transport operation. The RaaS group TheGentlemen (Microsoft: Storm-2697) claimed the attack and data theft on its leak site. Metro Mondego activated incident response with external experts and notified Portugal&#39;s national cyber authority (CNCS), the data-protection authority (CNPD) and criminal investigators; it cannot yet confirm whether personal data was copied, but says passenger payment data was not affected. A clean EU public-transport incident showing IT/OT segmentation holding.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-18/metro-mondego-thegentlemen-ransomware-portugal-transit" data-tags="ransomware data-breach organized-crime" data-regions="europe" data-kind="incident" data-priority="notable" data-discovered="2026-07-18T04:35:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="metro-mondego-thegentlemen-ransomware-portugal-transit"><a href="https://ctipilot.ch/entries/2026-07-18/metro-mondego-thegentlemen-ransomware-portugal-transit/">TheGentlemen ransomware hits Portugal&#39;s Metro Mondego (Coimbra light-rail); operator confirms attack, notifies CNCS and CNPD</a></h3><p>Metro Mondego — the public operator of the Metrobus light-rail line between Lousã and Coimbra, Portugal — announced on 2026-07-17 that it was hit by a ransomware attack on 6 July that affected &quot;part of its internal systems&quot; without compromising the transport service (&quot;um ataque informático a 6 de Julho que afectou &#39;parte dos seus sistemas internos&#39;, mas sem comprometer a operação do serviço de transporte&quot;) (<a href="https://www.campeaoprovincias.pt/2026/07/17/metro-mondego-foi-alvo-de-ataque-informatico-que-afectou-sistemas-internos/" target="_blank" rel="noopener noreferrer">Campeão das Províncias, 2026-07-17</a>). The operator confirms it activated incident-response procedures with external cybersecurity experts and notified the competent authorities — Portugal&#39;s National Cybersecurity Centre (CNCS), the National Data Protection Commission (CNPD) and criminal-investigation authorities — and that its investigation is examining whether the attackers copied data from the affected internal systems; it cannot yet determine whether any personal data of passengers, employees or suppliers is involved, but states passenger payment data was not affected (<a href="https://www.campeaoprovincias.pt/2026/07/17/metro-mondego-foi-alvo-de-ataque-informatico-que-afectou-sistemas-internos/" target="_blank" rel="noopener noreferrer">Campeão das Províncias, 2026-07-17</a>). The attack was claimed by the ransomware-and-extortion group <strong>TheGentlemen</strong> (Microsoft: Storm-2697; registry-tracked), which posted that it extracted confidential documentation and threatened to publish absent payment (<a href="https://tugatech.com.pt/t87569-metro-mondego-e-alvo-de-alegado-ataque-informatico-com-roubo-de-dados" target="_blank" rel="noopener noreferrer">TugaTech, 2026-07-16</a>).</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the operationally useful detail for CH/EU public-transport operators is that Metro Mondego is explicit its transport service was not compromised while corporate &quot;internal systems&quot; were — evidence that segmentation between the back-office/IT estate and the operational transport environment held, which is exactly the boundary a transit operator&#39;s ransomware playbook depends on. The disclosure also models the correct sequence: precautionary containment, national-CSIRT (CNCS) plus DPA (CNPD) notification, and staged public disclosure as the investigation progresses. <strong>Triage:</strong> the operator is also warning passengers to watch for follow-on fraud in its name — suspicious messages or calls claiming to be Metro Mondego, or requests for payment, bank-detail changes, codes or passwords — a reminder that a back-office ransomware event routinely spawns downstream social-engineering against the victim&#39;s customers regardless of whether personal data is confirmed exfiltrated.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">A Metro Mondego anunciou esta sexta-feira que foi alvo de um ataque informático a 6 de Julho que afectou “parte dos seus sistemas internos”, mas sem comprometer a operação do serviço de transporte.</p><figcaption class="entry-cite__attr">Campeão das Províncias</figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">A ação foi reivindicada pelo grupo de cibercriminosos Thegentlemen, que afirma ter conseguido extrair documentação confidencial</p><figcaption class="entry-cite__attr"><a href="https://tugatech.com.pt/t87569-metro-mondego-e-alvo-de-alegado-ataque-informatico-com-roubo-de-dados" target="_blank" rel="noopener noreferrer">TugaTech</a> <span class="entry-cite__date mono">2026-07-16</span></figcaption></figure></div><div class="prov"><span>incident</span><span>18 Jul 04:35Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-18/metro-mondego-thegentlemen-ransomware-portugal-transit/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.campeaoprovincias.pt/2026/07/17/metro-mondego-foi-alvo-de-ataque-informatico-que-afectou-sistemas-internos/" target="_blank" rel="noopener noreferrer">Campeão das Províncias (relaying Metro Mondego&#39;s statement)</a> · <a href="https://tugatech.com.pt/t87569-metro-mondego-e-alvo-de-alegado-ataque-informatico-com-roubo-de-dados" target="_blank" rel="noopener noreferrer">TugaTech</a></div></article>]]></content:encoded></item><item><title>TfL hackers sentenced; court record confirms the credential-purchase → helpdesk-vishing → MFA-reset access chain</title><link>https://ctipilot.ch/entries/2026-07-17/scattered-spider-tfl-sentencing-helpdesk-vishing/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-17/scattered-spider-tfl-sentencing-helpdesk-vishing/</guid><pubDate>Fri, 17 Jul 2026 04:35:00 +0000</pubDate><dc:date>2026-07-17T04:35:00Z</dc:date><category>law-enforcement</category><category>identity</category><category>phishing</category><category>uk</category><description><![CDATA[<p>Owen Flowers and Thalha Jubair, named by the NCA and CPS as leading Scattered Spider members, were sentenced on 2026-07-16 to five years six months each for the Aug-Sep 2024 Transport for London intrusion. The new, operationally relevant delta over the June guilty-plea coverage is the court-record intrusion chain: the pair bought partial TfL employee credentials from criminal forums, impersonated an employee to vish a TfL helpdesk worker into resetting the account password and — over multiple attempts — its 2FA, then used the reset credentials as valid-account access. TfL later confirmed ~7 million users&#39; data was accessible (not the ~5,000 first believed); 148 systems were rendered inoperable.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-17/scattered-spider-tfl-sentencing-helpdesk-vishing" data-tags="law-enforcement identity phishing" data-regions="uk" data-kind="incident" data-priority="notable" data-discovered="2026-07-17T04:35:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b upd">update</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 1: Confirmed"><span class="k">NATO</span>A1</span></div><h3 class="f-h" id="scattered-spider-tfl-sentencing-helpdesk-vishing"><a href="https://ctipilot.ch/entries/2026-07-17/scattered-spider-tfl-sentencing-helpdesk-vishing/">Scattered Spider duo sentenced to 5.5 years each over the 2024 Transport for London intrusion — court evidence details the helpdesk-vishing/MFA-reset chain</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-06-23/two-scattered-spider-members-plead-guilty-over-the-2024-tran/">Two Scattered Spider members plead guilty over the 2024 Transport for London intrusion</a> <span class="mono muted">(2026-06-23)</span></p><p>the guilty-plea entry recorded that two Scattered Spider members admitted the 2024 TfL intrusion but did not carry the access mechanics. The 2026-07-16 sentencing (five years six months each, at Woolwich Crown Court) put the chain on the court record, and it is the reason to revisit this. The pair bought partial TfL employee credentials from criminal forums, then &quot;impersonated an employee and socially engineered a TfL helpdesk worker into resetting the password for their account&quot; and, over multiple attempts, reset the account&#39;s 2FA, using the reset credentials for initial and sustained access (<a href="https://www.theregister.com/cyber-crime/2026/07/16/brit-scattered-spider-duo-handed-tickets-to-prison-over-transport-for-london-attack/5272446" target="_blank" rel="noopener noreferrer">The Register, 2026-07-16</a>). The NCA confirmed the impact scale — &quot;a total of 148 systems became inoperable, including critical ones that required significant manual workarounds and delays&quot; (<a href="https://www.nationalcrimeagency.gov.uk/news/two-sentenced-for-hacking-transport-for-london-in-uk-s-biggest-ever-cyber-crime-case" target="_blank" rel="noopener noreferrer">NCA, 2026-07-16</a>) — and TfL later established that data on roughly 7 million users had been accessible, far beyond the ~5,000 initially believed (<a href="https://www.theregister.com/cyber-crime/2026/07/16/brit-scattered-spider-duo-handed-tickets-to-prison-over-transport-for-london-attack/5272446" target="_blank" rel="noopener noreferrer">The Register, 2026-07-16</a>). The CPS put the remediation cost at £29 million (<a href="https://www.cps.gov.uk/national-news/news/cyberhackers-who-targeted-tfl-jailed-more-five-years-each" target="_blank" rel="noopener noreferrer">CPS, 2026-07-16</a>).</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the compromise never touched a technical vulnerability — the single control point was the helpdesk&#39;s password/MFA-reset process, the recurring Scattered Spider signature. Defenders should treat helpdesk-initiated credential and MFA resets as a distinct, monitorable event class rather than an implicitly trusted administrative action: capture who requested the reset, what identity verification was performed, and how quickly a privileged or unusual action followed. <strong>Triage:</strong> a legitimate reset is tied to a verified requester and is not immediately followed by anomalous access; the discriminators are a reset requested for an account whose owner did not initiate it, repeated 2FA-reset attempts on one account, and a short interval between a helpdesk reset and first sign-in from a new device/location.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">a total of 148 systems became inoperable, including critical ones that required significant manual workarounds and delays.</p><figcaption class="entry-cite__attr">UK National Crime Agency</figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">Flowers and Jubair purchased partial TfL credentials from &quot;well-known criminal forums&quot; and used those to reset the 2FA on employee accounts, a process that took multiple attempts.</p><p class="entry-cite__quote">Woolwich Crown Court heard that the pair impersonated an employee and socially engineered a TfL helpdesk worker into resetting the password for their account.</p><figcaption class="entry-cite__attr"><a href="https://www.theregister.com/cyber-crime/2026/07/16/brit-scattered-spider-duo-handed-tickets-to-prison-over-transport-for-london-attack/5272446" target="_blank" rel="noopener noreferrer">The Register</a> <span class="entry-cite__date mono">2026-07-16</span></figcaption></figure></div><div class="prov"><span>incident</span><span>17 Jul 04:35Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-17/scattered-spider-tfl-sentencing-helpdesk-vishing/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.nationalcrimeagency.gov.uk/news/two-sentenced-for-hacking-transport-for-london-in-uk-s-biggest-ever-cyber-crime-case" target="_blank" rel="noopener noreferrer">UK National Crime Agency (NCA)</a> · <a href="https://www.cps.gov.uk/national-news/news/cyberhackers-who-targeted-tfl-jailed-more-five-years-each" target="_blank" rel="noopener noreferrer">UK Crown Prosecution Service (CPS)</a> · <a href="https://www.theregister.com/cyber-crime/2026/07/16/brit-scattered-spider-duo-handed-tickets-to-prison-over-transport-for-london-attack/5272446" target="_blank" rel="noopener noreferrer">The Register</a></div></article>]]></content:encoded></item><item><title>HelloNet chains trusted-updater DLL sideloading with raw AFD-IOCTL interception to hide network C2 from user-mode EDR</title><link>https://ctipilot.ch/entries/2026-07-17/kaspersky-hellonet-vipnet-updater-sideload-afd-ioctl/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-17/kaspersky-hellonet-vipnet-updater-sideload-afd-ioctl/</guid><pubDate>Fri, 17 Jul 2026 04:35:00 +0000</pubDate><dc:date>2026-07-17T04:35:00Z</dc:date><category>espionage</category><category>supply-chain</category><category>russia-cis</category><description><![CDATA[<p>Kaspersky GReAT documented &quot;HelloNet,&quot; an active APT campaign that persists by sideloading a malicious wtsapi32.dll into the auto-launched update component of the ViPNet secure-networking suite, then injects a proxy module (HelloProxy) into svchost.exe that uses Microsoft Detours to hook NtDeviceIoControlFile and intercept the raw Ancillary Function Driver IOCTLs (AFD_RECV, AFD_GET_TDI_HANDLES) — which, per Kaspersky, hinders user-mode network-filtering security tools. Direct victimology is Russian government and critical-infrastructure orgs (attributed with low confidence to an unknown Chinese-speaking group); the transferable signal for Swiss/EU defenders is the technique class — abuse of a trusted client&#39;s update mechanism plus AFD-IOCTL interception to degrade EDR network visibility.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-17/kaspersky-hellonet-vipnet-updater-sideload-afd-ioctl" data-tags="espionage supply-chain" data-regions="russia-cis" data-kind="research" data-priority="notable" data-discovered="2026-07-17T04:35:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="kaspersky-hellonet-vipnet-updater-sideload-afd-ioctl"><a href="https://ctipilot.ch/entries/2026-07-17/kaspersky-hellonet-vipnet-updater-sideload-afd-ioctl/">Kaspersky: the HelloNet campaign blinds user-mode security tools by hooking raw AFD IOCTLs, persisting via DLL-sideload into a secure-network product&#39;s own auto-updater</a></h3><p>Kaspersky&#39;s GReAT team detailed &quot;HelloNet,&quot; an APT campaign (active since at least May 2026) that abuses the update mechanism of ViPNet — a Russian GOST-certified secure-networking suite — to persist inside targeted Russian government, energy, transport, education, logistics and industrial organizations (<a href="https://securelist.com/hellonet-vipnet/120700/" target="_blank" rel="noopener noreferrer">Kaspersky Securelist, 2026-07-16</a>). The attackers drop a malicious <code>wtsapi32.dll</code> into the ViPNet update directory that the OS-start-launched updater <code>itcsrvup64.exe</code> sideloads. That loader (&quot;HelloInjector&quot;) injects a second stage (&quot;HelloProxy&quot;) into <code>svchost.exe</code> — but only after verifying the target&#39;s name is <code>svchost.exe</code> and its command line carries <code>netsvcs</code>. HelloProxy&#39;s distinguishing move is defense evasion at the socket layer: it uses the Microsoft Detours library to hook <code>NtDeviceIoControlFile</code>, <code>closesocket</code> and <code>shutdown</code>, intercepting the raw AFD IOCTL codes <code>AFD_RECV</code> (0x12017) and <code>AFD_GET_TDI_HANDLES</code> (0x12037) so that, in Kaspersky&#39;s words, it can &quot;hinder security solutions operating in user mode for filtering network connections.&quot; It then acts as a traffic proxy or in-memory loader for further modules — recovered examples include &quot;HelloExecutor&quot; (shell-command execution) and &quot;HelloCleaner&quot; (deletes ViPNet log files to hide activity) — and on one host the operators opened an SSH reverse tunnel using a legitimate Plink binary renamed <code>frontpage.exe</code>.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">for this constituency the ViPNet-specific vector is largely irrelevant, but two technique classes generalize directly. First, any third-party secure-network/VPN client with an auto-launched updater in a writable directory is a DLL-sideload persistence surface — treat vendor-updater directories as monitored locations where an unsigned or unexpected DLL write is high-signal. Second, AFD-IOCTL interception is a portable primitive for blinding user-mode network-filtering EDR; a Detours-style hook on <code>NtDeviceIoControlFile</code> in <code>svchost.exe</code> is worth surfacing regardless of the product being abused. <strong>Triage:</strong> a <code>wtsapi32.dll</code> written into a vendor&#39;s update directory has no legitimate reason to be there (the DLL belongs in <code>System32</code>); the vendor&#39;s own updater loading a DLL whose signature does not carry the vendor&#39;s publisher name, and a Plink/PuTTY binary identified by PE metadata rather than filename opening a <code>-R port:addr:port</code> tunnel, are the discriminators Kaspersky&#39;s hunt guidance keys on.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">By placing the file in this directory, the attackers implement the DLL Sideloading technique — the ViPNet update system executable file itcsrvup64.exe, which is launched at OS startup, is susceptible to it.</p><p class="entry-cite__quote">These codes are used during socket operations — their interception allows the malware to hinder security solutions operating in user mode for filtering network connections.</p><p class="entry-cite__quote">At present, we link this campaign to the activities of an unknown Chinese-speaking APT group with a low degree of confidence.</p><figcaption class="entry-cite__attr"><a href="https://securelist.com/hellonet-vipnet/120700/" target="_blank" rel="noopener noreferrer">Kaspersky Securelist (GReAT)</a> <span class="entry-cite__date mono">2026-07-16</span></figcaption></figure></div><div class="prov"><span>research</span><span>17 Jul 04:35Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-17/kaspersky-hellonet-vipnet-updater-sideload-afd-ioctl/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://securelist.com/hellonet-vipnet/120700/" target="_blank" rel="noopener noreferrer">Kaspersky Securelist (GReAT)</a></div></article>]]></content:encoded></item><item><title>World Leaks leaks ~858k files from a Kudankulam nuclear-plant contractor breached at a third-party data-centre host — a lesson for energy-CI operators</title><link>https://ctipilot.ch/entries/2026-07-16/worldleaks-kudankulam-reliance-third-party-hosting-breach/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-16/worldleaks-kudankulam-reliance-third-party-hosting-breach/</guid><pubDate>Thu, 16 Jul 2026 04:42:00 +0000</pubDate><dc:date>2026-07-16T04:42:00Z</dc:date><category>data-breach</category><category>supply-chain</category><category>apac</category><description><![CDATA[<p>The data-theft-extortion group World Leaks (a Hunters International rebrand) posted roughly 858,000 files on its leak site attributed to Reliance Group, a contractor to India&#39;s Kudankulam Nuclear Power Plant; Reuters reviewed ~19,000 sensitive files (2016–2025) purporting to show blueprints, supplier and inspection records. Reliance confirmed a &quot;partial breach&quot; from a server hosted by third-party Indian data-centre provider Yotta; India&#39;s CERT-In is investigating and the leaked files are only claimed — not established — to be authentic. Out-of-nexus (India) but carried for its global critical-infrastructure significance and a transferable third-party-hosting lesson for European energy-CI operators.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-16/worldleaks-kudankulam-reliance-third-party-hosting-breach" data-tags="data-breach supply-chain" data-regions="apac" data-kind="incident" data-priority="notable" data-discovered="2026-07-16T04:42:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="worldleaks-kudankulam-reliance-third-party-hosting-breach"><a href="https://ctipilot.ch/entries/2026-07-16/worldleaks-kudankulam-reliance-third-party-hosting-breach/">World Leaks posts ~858,000 files tied to India&#39;s Kudankulam nuclear-plant contractor; Reliance confirms a third-party-hosting breach</a></h3><p>The data-theft-extortion group <strong>World Leaks</strong> — the rebrand of Hunters International already tracked in this store — posted roughly <strong>858,000 files</strong> on its dark-web leak site attributed to Reliance Group, a contractor involved in India&#39;s Kudankulam Nuclear Power Plant (KNPP), the country&#39;s largest nuclear facility (<a href="https://www.theweek.in/news/india/2026/07/15/india-s-nuclear-files-leaked-on-dark-web-858000-files-from-kudankulam-plant-out-reliance-group-admits-partial-breach.html" target="_blank" rel="noopener noreferrer">The Week / Reuters, 2026-07-15</a>). Reuters reviewed a subset of about 19,000 files dated 2016–2025 that purport to show facility blueprints, supplier details, meeting and inspection records, equipment reviews and insurance policies; the files are only claimed to originate from the plant and their authenticity is not established. Reliance Group confirmed to Reuters that a <strong>&quot;partial breach&quot;</strong> of its data occurred from a server hosted by <strong>Yotta</strong>, a third-party Indian data-centre provider, and that the government has been informed; India&#39;s CERT-In is investigating and a Nuclear Threat Initiative expert warned the exposure could pose a serious plant-safety risk.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the victim and jurisdiction are out of this constituency&#39;s nexus, but the structure is the recurring one — sensitive engineering, inspection and design documentation for a critical-infrastructure facility held on a subcontractor&#39;s externally hosted infrastructure, outside the operator&#39;s own security perimeter, and breached there rather than at the plant. For European energy-CI operators the transferable action is inventory: know which contractors and hosting providers hold facility design, inspection and supplier documentation, contractually bound them to breach notification and log access, and minimise how much of that documentation persists on third-party infrastructure at all. This is the same third-party-exposure pattern behind the Basel utility disclosure this window, at a far higher-consequence asset class.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">They admitted to Reuters that a &quot;partial breach&quot; of its data had taken place from a server hosted by Yotta, a third-party Indian data centre service provider, and that the government has been informed about the incident.</p><p class="entry-cite__quote">19,000 of these files appeared to be highly sensitive, the report added, noting that the documents were dated between 2016 and 2025, and reportedly featured blueprints, supplier details, meeting and inspection records, equipment reviews and insurance policies.</p><figcaption class="entry-cite__attr"><a href="https://www.theweek.in/news/india/2026/07/15/india-s-nuclear-files-leaked-on-dark-web-858000-files-from-kudankulam-plant-out-reliance-group-admits-partial-breach.html" target="_blank" rel="noopener noreferrer">The Week (India), relaying Reuters</a> <span class="entry-cite__date mono">2026-07-15</span></figcaption></figure></div><div class="prov"><span>incident</span><span>16 Jul 04:42Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-16/worldleaks-kudankulam-reliance-third-party-hosting-breach/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.theweek.in/news/india/2026/07/15/india-s-nuclear-files-leaked-on-dark-web-858000-files-from-kudankulam-plant-out-reliance-group-admits-partial-breach.html" target="_blank" rel="noopener noreferrer">The Week (India), relaying Reuters</a></div></article>]]></content:encoded></item><item><title>Swiss municipal energy/water/telecom utility IWB discloses a third-party-provider breach exposing ~40,000 customer meter records</title><link>https://ctipilot.ch/entries/2026-07-16/iwb-basel-third-party-provider-breach-40k-customer-records/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-16/iwb-basel-third-party-provider-breach-40k-customer-records/</guid><pubDate>Thu, 16 Jul 2026 04:38:00 +0000</pubDate><dc:date>2026-07-16T04:38:00Z</dc:date><category>data-breach</category><category>supply-chain</category><category>switzerland</category><description><![CDATA[<p>Industrielle Werke Basel (IWB) — the canton-owned Basel utility supplying electricity, gas, water and telecom — disclosed on 2026-07-15 that an external service provider was compromised and roughly 40,000 customer records (names, addresses, meter numbers and installation characteristics) were exfiltrated. Email addresses, phone numbers, consumption data and payment details were not exposed, IWB&#39;s own systems and supply were unaffected, and the Basel-Stadt data protection officer assessed the misuse risk as low. No provider name, actor or initial-access vector has been disclosed.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-16/iwb-basel-third-party-provider-breach-40k-customer-records" data-tags="data-breach supply-chain" data-regions="switzerland" data-kind="incident" data-priority="notable" data-discovered="2026-07-16T04:38:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="iwb-basel-third-party-provider-breach-40k-customer-records"><a href="https://ctipilot.ch/entries/2026-07-16/iwb-basel-third-party-provider-breach-40k-customer-records/">Basel utility IWB: ~40,000 customer records exfiltrated in a breach of a third-party service provider</a></h3><p>Industrielle Werke Basel (IWB) — the canton-owned Basel multi-utility supplying electricity, gas, water, district heating and telecom/fibre — disclosed on 15 July 2026 that an external service provider it uses was compromised and roughly <strong>40,000 customer records</strong> were exfiltrated from the provider&#39;s environment (<a href="https://www.netzwoche.ch/news/2026-07-15/cyberangriff-auf-dienstleister-trifft-industrielle-werke-basel" target="_blank" rel="noopener noreferrer">Netzwoche, 2026-07-15</a>). The stolen data comprises customer names and addresses plus technical smart-meter attributes (meter serial numbers and installation characteristics); IWB states that email addresses, phone numbers, energy-consumption data and billing/payment data were <strong>not</strong> part of the exposure, so no consumption-pattern inference is possible from what was taken (<a href="https://www.swisscybersecurity.net/news/2026-07-15/cyberangriff-auf-dienstleister-trifft-industrielle-werke-basel" target="_blank" rel="noopener noreferrer">SwissCybersecurity.net, 2026-07-15</a>). IWB&#39;s own IT and OT/grid systems were unaffected and energy/water supply continuity was not disrupted — the compromise is scoped to the provider&#39;s systems and the customer-data feed IWB shares with it (<a href="https://www.netzwoche.ch/news/2026-07-15/cyberangriff-auf-dienstleister-trifft-industrielle-werke-basel" target="_blank" rel="noopener noreferrer">Netzwoche, 2026-07-15</a>). The provider detected and notified IWB, which audited access, reviewed logs and pre-emptively restricted its data exchange with the affected provider; the Basel-Stadt cantonal data protection officer assessed the misuse risk as low (<a href="https://www.watson.ch/schweiz/digital/404373086-kundendaten-der-industriellen-werke-basel-entwendet" target="_blank" rel="noopener noreferrer">Watson.ch, 2026-07-15</a>). No provider name, threat-actor claim or initial-access vector has been disclosed, and no matching leak-site listing was found for Switzerland in-window.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">this is a textbook trusted-relationship exposure — a home-region critical-infrastructure operator&#39;s customer data reached attackers through a compromised external processor the utility&#39;s own SOC has no telemetry into. For any utility or public-sector body outsourcing metering/billing data, the load-bearing controls are contractual data-minimisation (share only the fields the processor needs), a right to breach notification and log access, and periodic review of what customer data actually sits outside the perimeter. The exposed name+address+meter-number combination is exactly the material for convincing pretext contact, so affected customers should be warned to treat unsolicited approaches referencing their address or meter number — especially demands for money or data under time pressure — with suspicion.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Bei einem Cyberangriff auf einen Dienstleister der Industriellen Werke Basel (IWB) haben Cyberkriminelle rund 40&#39;000 Datensätze von Kundinnen und Kunden des Energieversorgers entwendet.</p><p class="entry-cite__quote">Die IWB-Systeme blieben unversehrt, wie das Unternehmen mitteilt. Auch die Energieversorgung sei nicht beeinträchtigt gewesen.</p><figcaption class="entry-cite__attr"><a href="https://www.netzwoche.ch/news/2026-07-15/cyberangriff-auf-dienstleister-trifft-industrielle-werke-basel" target="_blank" rel="noopener noreferrer">Netzwoche</a> <span class="entry-cite__date mono">2026-07-15</span></figcaption></figure></div><div class="prov"><span>incident</span><span>16 Jul 04:38Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-16/iwb-basel-third-party-provider-breach-40k-customer-records/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.netzwoche.ch/news/2026-07-15/cyberangriff-auf-dienstleister-trifft-industrielle-werke-basel" target="_blank" rel="noopener noreferrer">Netzwoche</a> · <a href="https://www.swisscybersecurity.net/news/2026-07-15/cyberangriff-auf-dienstleister-trifft-industrielle-werke-basel" target="_blank" rel="noopener noreferrer">SwissCybersecurity.net</a> · <a href="https://www.watson.ch/schweiz/digital/404373086-kundendaten-der-industriellen-werke-basel-entwendet" target="_blank" rel="noopener noreferrer">Watson.ch</a></div></article>]]></content:encoded></item><item><title>A three-year-old KNX Connection Authorization lockout flaw joins CISA KEV as actively exploited — the fix is procedural, not a patch</title><link>https://ctipilot.ch/entries/2026-07-16/cve-2023-4346-knx-building-automation-lockout-dos-kev/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-16/cve-2023-4346-knx-building-automation-lockout-dos-kev/</guid><pubDate>Thu, 16 Jul 2026 04:36:00 +0000</pubDate><dc:date>2026-07-16T04:36:00Z</dc:date><category>vulnerabilities</category><category>dos</category><category>actively-exploited</category><category>cisa-kev</category><category>ot-ics</category><category>no-patch</category><category>europe</category><category>exploited</category><category>cisa-kev</category><category>no-patch</category><category>mitigation-only</category><category>CVE-2023-4346</category><description><![CDATA[<p>CISA added CVE-2023-4346 to its Known Exploited Vulnerabilities catalog on 2026-07-15, marking the KNX Connection Authorization Option-1 account-lockout flaw as known-exploited three years after disclosure. An attacker with network (or physical) access to a KNX installation can purge unprotected devices and set a BCU key, permanently locking legitimate operators out with no reset path; there is no software patch — the fix is procedural. Relevant to any Swiss/European critical-infrastructure or public-sector estate running KNX building automation (HVAC, lighting, access control, BMS).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-16/cve-2023-4346-knx-building-automation-lockout-dos-kev" data-tags="vulnerabilities dos actively-exploited cisa-kev ot-ics no-patch" data-regions="europe" data-kind="vulnerability" data-priority="notable" data-discovered="2026-07-16T04:36:00Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2023-4346/">CVE-2023-4346</a><span class="b exp">exploited</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 2: Probably true"><span class="k">NATO</span>A2</span></div><h3 class="f-h" id="cve-2023-4346-knx-building-automation-lockout-dos-kev"><a href="https://ctipilot.ch/entries/2026-07-16/cve-2023-4346-knx-building-automation-lockout-dos-kev/">CVE-2023-4346 — KNX building-automation protocol: account-lockout DoS added to CISA KEV, no software patch (CVSS 7.5)</a></h3><p>CISA added <strong>CVE-2023-4346</strong> to its Known Exploited Vulnerabilities catalog on 15 July 2026, alongside the Oracle E-Business Suite flaw, and updated the underlying ICS advisory to carry a <em>&quot;known public exploitation&quot;</em> note (<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-23-236-01" target="_blank" rel="noopener noreferrer">CISA ICSA-23-236-01, 2026-07-15</a>; <a href="https://www.cisa.gov/news-events/alerts/2026/07/15/cisa-adds-two-known-exploited-vulnerabilities-catalog" target="_blank" rel="noopener noreferrer">CISA KEV alert, 2026-07-15</a>). The flaw itself is three years old — reported by Felix Eberstaller of Limes Security and published in August 2023 — and had no prior KEV listing until this update. KNX is a widely deployed European building-automation bus protocol (KNX Association is headquartered in Belgium) used for HVAC, lighting, access control and BMS integration, so the exposure sits under any large public-sector or critical-infrastructure estate with smart-building controls.</p>
<p>The design flaw (CWE-645, overly restrictive account-lockout mechanism, CVSS 7.5, availability-only) is in KNX Connection Authorization Option 1: any device that has never had its BCU (Bus Coupling Unit) key set can be purged by an attacker with network access to the KNX installation, who then sets a new BCU key and permanently locks legitimate operators out — with no reset path short of the current password (<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-23-236-01" target="_blank" rel="noopener noreferrer">CISA ICSA-23-236-01, 2026-07-15</a>). An attacker with only physical access to the bus can do the same. KNX Association has issued no software fix in three years; the remediation is entirely procedural — set the BCU key during commissioning.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the exposure surface is the IP-KNX router/gateway that bridges the building bus onto an IT or internet-reachable network, so treat any such gateway as a priority segmentation target regardless of patch status. This is a configuration and behavioural signal, not a network signature: monitor KNX/ETS project-management logs and BCU-key-set events for unexpected changes, and confirm every finished project handed over to a building owner has its BCU key set. The KEV addition is the exploitation signal used here; the associated federal remediation deadline carries no operational weight for this audience.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Exploitable remotely/low attack complexity/known public exploitation</p><p class="entry-cite__quote">If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX installation, purge all devices without additional security options enabled, and set a BCU key, locking the device.</p><figcaption class="entry-cite__attr"><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-23-236-01" target="_blank" rel="noopener noreferrer">CISA (ICS Advisory ICSA-23-236-01)</a> <span class="entry-cite__date mono">2026-07-15</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>16 Jul 04:36Z</span><span class="p-warn">single-source · national CERT</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-16/cve-2023-4346-knx-building-automation-lockout-dos-kev/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-23-236-01" target="_blank" rel="noopener noreferrer">CISA (ICS Advisory ICSA-23-236-01)</a> · <a href="https://www.cisa.gov/news-events/alerts/2026/07/15/cisa-adds-two-known-exploited-vulnerabilities-catalog" target="_blank" rel="noopener noreferrer">CISA</a></div></article>]]></content:encoded></item><item><title>CISA republishes four Rockwell/ABB OT advisories led by a CVSS 10.0 debug-port takeover on an energy/water EtherNet/IP adapter, fixed in firmware 3.011</title><link>https://ctipilot.ch/entries/2026-07-15/cisa-ics-batch-rockwell-abb-energy-water-ot/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-15/cisa-ics-batch-rockwell-abb-energy-water-ot/</guid><pubDate>Wed, 15 Jul 2026 04:36:00 +0000</pubDate><dc:date>2026-07-15T04:36:00Z</dc:date><category>vulnerabilities</category><category>ot-ics</category><category>auth-bypass</category><category>patch-available</category><category>info-disclosure</category><category>priv-esc</category><category>global</category><category>patch-available</category><category>CVE-2026-10577</category><category>CVE-2025-14771</category><category>CVE-2025-14772</category><category>CVE-2025-14773</category><category>CVE-2025-14774</category><description><![CDATA[<p>CISA published four ICS advisories on 2026-07-14 landing on the energy, water and critical-manufacturing sectors and on Swiss-headquartered ABB. The headline is CVE-2026-10577 in the Rockwell Automation 1715-AENTR EtherNet/IP Adapter (all versions ≤ 3.003, CVSS 10.0): a network-reachable debug port with no authentication lets an unauthenticated attacker read/delete files, stop tasks, modify memory and change I/O states — Rockwell fixes it in firmware 3.011, with network isolation as the interim control. ABB T-MAC Plus 4.0-24 (a fuel/chemical terminal-management system, fixed in 4.0-25) is subject to a four-CVE chain led by CVE-2025-14771 (CVSS 9.9, authenticated file disclosure); ABB also shipped a fix in Ability Edgenius for the previously-disclosed &quot;Copy Fail&quot; kernel flaw (CVE-2026-31431). No in-the-wild exploitation is reported for the newly-disclosed items.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-15/cisa-ics-batch-rockwell-abb-energy-water-ot" data-tags="vulnerabilities ot-ics auth-bypass patch-available info-disclosure priv-esc" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-07-15T04:36:00Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-10577/">CVE-2026-10577 +4</a><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 2: Probably true"><span class="k">NATO</span>A2</span></div><h3 class="f-h" id="cisa-ics-batch-rockwell-abb-energy-water-ot"><a href="https://ctipilot.ch/entries/2026-07-15/cisa-ics-batch-rockwell-abb-energy-water-ot/">CISA ICS batch (14 Jul): Rockwell 1715-AENTR unauthenticated debug-port takeover (CVE-2026-10577, CVSS 10.0, fixed in firmware 3.011) and a Swiss-vendor ABB T-MAC Plus auth chain (CVSS 9.9)</a></h3><p>CISA published four Industrial Control Systems advisories on 2026-07-14, each a verbatim republication of a vendor PSIRT bulletin, that land squarely on this constituency&#39;s energy and water sectors and on a Swiss-headquartered vendor (<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-04" target="_blank" rel="noopener noreferrer">CISA, 2026-07-14</a>). The most severe is <strong>CVE-2026-10577</strong> in the <strong>Rockwell Automation 1715-AENTR EtherNet/IP Adapter</strong> (all versions ≤ 3.003), rated CVSS v3.1 10.0 for missing authentication on a critical function (CWE-306): a network-accessible debug port exposes intrusive CLI commands with no authentication, so an unauthenticated remote attacker can &quot;read or delete files, stop tasks, modify memory, and change I/O states&quot; on the device (<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-04" target="_blank" rel="noopener noreferrer">CISA / Rockwell PSIRT, 2026-07-14</a>). The advisory names the affected sectors as Energy, Water and Wastewater, and Critical Manufacturing; Rockwell fixes it in <strong>firmware version 3.011</strong> and CISA additionally recommends network isolation for devices that cannot be upgraded immediately (<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-04" target="_blank" rel="noopener noreferrer">CISA / Rockwell PSIRT SD1785, 2026-07-14</a>). No known public exploitation has been reported to CISA.</p>
<p>Separately, <strong>ABB T-MAC Plus 4.0-24</strong> (fixed in 4.0-25) — a Terminal Management System operating chemical/petroleum terminals, pipeline and refinery tankage, bulk plants and hydrogen terminals — is subject to four flaws responsibly disclosed by Angelo Catalani of Italy&#39;s national cybersecurity agency (ACN): <strong>CVE-2025-14771</strong> (CVSS 9.9, a low-privilege authenticated file disclosure via a crafted HTTP GET against the web application, CWE-552), <strong>CVE-2025-14772</strong> (CVSS 8.8, broken access control letting a low-privilege user perform administrative operations, CWE-639), <strong>CVE-2025-14773</strong> (CVSS 8.0, stored cross-site scripting) and <strong>CVE-2025-14774</strong> (CVSS 7.4, an adjacent-network denial of service of the Card Reader service caused by an unencrypted communication protocol) (<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-03" target="_blank" rel="noopener noreferrer">CISA / ABB PSIRT, 2026-07-14</a>). ABB states exploitation requires network or physical access to the terminal LAN rather than internet reachability, and that an update resolves the set. The same day, ABB shipped a fix in <strong>Ability Edgenius</strong> (fixed in 3.2.4.1) for the previously-disclosed <strong>CVE-2026-31431</strong> &quot;Copy Fail&quot; Linux-kernel <code>algif_aead</code> local root-escalation flaw — new here only in that a specific Swiss-vendor OT product is now named as an affected instance (<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-02" target="_blank" rel="noopener noreferrer">CISA / ABB PSIRT, 2026-07-14</a>) — and a low-severity (CVSS 4.4) DLL search-path fix (CVE-2025-13162) in 800xA for Advant Master / Control Builder A (<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-01" target="_blank" rel="noopener noreferrer">CISA / ABB PSIRT, 2026-07-14</a>).</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the Rockwell flaw is the one that changes work this week for OT operators — upgrade the adapter to firmware 3.011, and where an OT change window makes that non-immediate, treat network segmentation as the interim control; because the debug/CLI service is a distinct network service from the normal EtherNet/IP control protocol, the highest-signal telemetry is network-flow monitoring for any connection to that port from a host other than a known engineering workstation; no legitimate remote-management workflow should reach it. <strong>Triage:</strong> on the Rockwell adapter there is no authentication to correlate against, so any inbound session to the debug/CLI port from an unexpected source is itself the indicator; on ABB T-MAC Plus the abuses are authenticated-tier, so the hunt surface is the web-application access log — GET requests probing file paths outside the expected UI structure (the CVE-2025-14771 disclosure path) and administrative API calls issued by accounts holding only low-privilege roles (the CVE-2025-14772 authorization bypass), distinguished from benign admin activity by the mismatch between the session&#39;s role and the operation performed.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Successful exploitation of this vulnerability could allow an attacker to read or delete files, stop tasks, modify memory, and change I/O states, potentially impacting the confidentiality, integrity, and availability of the device.</p><p class="entry-cite__quote">No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p><figcaption class="entry-cite__attr"><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-04" target="_blank" rel="noopener noreferrer">CISA (ICSA-26-195-04, republishing Rockwell Automation PSIRT)</a> <span class="entry-cite__date mono">2026-07-14</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>15 Jul 04:36Z</span><span class="p-warn">single-source · national CERT</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-15/cisa-ics-batch-rockwell-abb-energy-water-ot/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-04" target="_blank" rel="noopener noreferrer">CISA (ICSA-26-195-04, republishing Rockwell Automation PSIRT)</a> · <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-03" target="_blank" rel="noopener noreferrer">CISA (ICSA-26-195-03, republishing ABB PSIRT)</a> · <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-02" target="_blank" rel="noopener noreferrer">CISA (ICSA-26-195-02, ABB Ability Edgenius)</a> · <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-01" target="_blank" rel="noopener noreferrer">CISA (ICSA-26-195-01, ABB Advant Master Online Builder)</a></div></article>]]></content:encoded></item><item><title>Microsoft maps a year of Salesforce OAuth abuse — vishing consent, supply-chain secret reuse, guest-access Aura abuse — invisible to sign-in detection</title><link>https://ctipilot.ch/entries/2026-07-14/microsoft-maps-shinyhunters-salesforce-oauth-abuse/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-14/microsoft-maps-shinyhunters-salesforce-oauth-abuse/</guid><pubDate>Tue, 14 Jul 2026 20:22:57 +0000</pubDate><dc:date>2026-07-14T20:22:57Z</dc:date><category>identity</category><category>cloud</category><category>phishing</category><category>supply-chain</category><category>data-breach</category><category>global</category><description><![CDATA[<p>Microsoft Threat Intelligence documented a year (mid-2025 to mid-2026) of campaigns using ShinyHunters-associated tradecraft (registry alias UNC6240) against Salesforce-integrated SaaS environments via three intrusion paths: vishing-driven malicious-OAuth-consent (a fake Data Loader app), SaaS supply-chain OAuth-secret reuse (Salesloft Drift, Gainsight, and Storm-3138&#39;s June 2026 Klue compromise), and guest-access Aura abuse. None exploited a Salesforce flaw — all abuse trusted OAuth relationships, so sign-in-anomaly detection gives limited visibility.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-14/microsoft-maps-shinyhunters-salesforce-oauth-abuse" data-tags="identity cloud phishing supply-chain data-breach" data-regions="global" data-kind="research" data-priority="notable" data-discovered="2026-07-14T20:22:57Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="microsoft-maps-shinyhunters-salesforce-oauth-abuse"><a href="https://ctipilot.ch/entries/2026-07-14/microsoft-maps-shinyhunters-salesforce-oauth-abuse/">Microsoft maps three ShinyHunters-tradecraft OAuth-abuse paths against Salesforce customers — none exploiting a Salesforce vulnerability</a></h3><p>Microsoft Threat Intelligence documented a year-long (mid-2025 to mid-2026) set of campaigns using tradecraft commonly associated with ShinyHunters (registry alias UNC6240) against Salesforce-integrated environments, through three distinct paths rather than any Salesforce product vulnerability (<a href="https://www.microsoft.com/en-us/security/blog/2026/07/13/defending-saas-based-applications-against-shinyhunters-oauth-abuse/" target="_blank" rel="noopener noreferrer">Microsoft Threat Intelligence, 2026-07-13</a>). First, vishing-driven OAuth-consent abuse: attackers impersonating IT support socially engineer employees through the OAuth authorization workflow into granting a malicious connected app — disguised as the legitimate Salesforce Data Loader — full API access inherited from the victim&#39;s own privileges, letting them enumerate and exfiltrate CRM data through sanctioned application access that never trips a sign-in anomaly. Second, SaaS supply-chain compromise: compromised Salesloft Drift credentials (August 2025) exposed OAuth connection secrets reused across customer tenants; a November 2025 campaign abused Gainsight-published Salesforce apps the same way; and in June 2026 an actor Microsoft tracks as Storm-3138 compromised the Klue competitive-intelligence platform and reused harvested Salesforce credentials to query and exfiltrate customer CRM data. Third, guest-access abuse: requests chained against Salesforce&#39;s Aura framework via misconfigured guest-user accounts pulled far more data than a guest session should reach (<a href="https://thehackernews.com/2026/07/microsoft-maps-year-long-shinyhunters.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-07-14</a>). Microsoft observed the activity across retail, education and manufacturing tenants and states existing authentication-focused detections gave &quot;limited visibility&quot; because the traffic is indistinguishable from legitimate integration.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">for CH/EU public-sector and enterprise orgs running Salesforce for case-management or citizen-service workloads, the lesson is that OAuth-consent and connected-app trust — not credentials or malware — is the attack surface here, and it evades sign-in-based detection; visibility requires OAuth/connected-app and data-access telemetry (Microsoft points to Defender for Cloud Apps real-time event monitoring and Salesforce Shield). <strong>Triage:</strong> the discriminator is <em>pattern</em>, not any single authentication event — bulk or systematic SOQL querying and report exports, connected-app activity from a new IP or user-agent for an established app, anomalous OAuth-scope combinations, and guest-user access reaching non-public objects; a legitimate integration exhibits a stable client fingerprint and a bounded query profile, so the deviation in volume and client identity is the signal.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Threat actors socially engineered employees into authorizing attacker-controlled connected apps within their Salesforce tenant.</p><p class="entry-cite__quote">This activity was not the result of a vulnerability inherent to Salesforce.</p><p class="entry-cite__quote">malicious activity often appeared indistinguishable from legitimate Salesforce usage because threat actors operated through trusted identities, approved OAuth applications, and authorized integrations.</p><figcaption class="entry-cite__attr"><a href="https://www.microsoft.com/en-us/security/blog/2026/07/13/defending-saas-based-applications-against-shinyhunters-oauth-abuse/" target="_blank" rel="noopener noreferrer">Microsoft Threat Intelligence</a> <span class="entry-cite__date mono">2026-07-13</span></figcaption></figure></div><div class="prov"><span>research</span><span>14 Jul 20:22Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-14/microsoft-maps-shinyhunters-salesforce-oauth-abuse/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.microsoft.com/en-us/security/blog/2026/07/13/defending-saas-based-applications-against-shinyhunters-oauth-abuse/" target="_blank" rel="noopener noreferrer">Microsoft Threat Intelligence</a> · <a href="https://thehackernews.com/2026/07/microsoft-maps-year-long-shinyhunters.html" target="_blank" rel="noopener noreferrer">The Hacker News</a></div></article>]]></content:encoded></item><item><title>SonicWall confirms active exploitation of an unauthenticated SMA1000 SSRF chained to code injection for full appliance takeover</title><link>https://ctipilot.ch/entries/2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited/</guid><pubDate>Tue, 14 Jul 2026 20:19:53 +0000</pubDate><dc:date>2026-07-14T20:19:53Z</dc:date><category>vulnerabilities</category><category>actively-exploited</category><category>zero-day</category><category>pre-auth</category><category>rce</category><category>cisa-kev</category><category>patch-available</category><category>global</category><category>exploited</category><category>cisa-kev</category><category>patch-available</category><category>CVE-2026-15409</category><category>CVE-2026-15410</category><description><![CDATA[<p>SonicWall&#39;s PSIRT confirms active exploitation of two SMA1000 flaws (SNWLID-2026-0008), both added to CISA KEV on 2026-07-14: CVE-2026-15409 (CVSS 10.0), an unauthenticated server-side request forgery in the SMA1000 Work Place interface, and CVE-2026-15410 (CVSS 7.2), a post-authentication OS-command code injection in the Appliance Management Console. Any organization running an internet-facing SMA1000 (6210/7210/8200v) must apply the platform hotfix now.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited" data-tags="vulnerabilities actively-exploited zero-day pre-auth rce cisa-kev patch-available" data-regions="global" data-kind="vulnerability" data-priority="high" data-discovered="2026-07-14T20:19:53Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-15409/">CVE-2026-15409 +1</a><span class="b exp">exploited</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 2: Probably true"><span class="k">NATO</span>A2</span></div><h3 class="f-h" id="sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited"><a href="https://ctipilot.ch/entries/2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited/">CVE-2026-15409 — SonicWall SMA1000: unauthenticated SSRF (CVSS 10.0) chained to post-auth code injection, actively exploited</a></h3><p>SonicWall&#39;s PSIRT advisory SNWLID-2026-0008 (first published 2026-07-14) states it has investigated &quot;multiple cases indicating the active exploitation&quot; of two new SMA1000 flaws (<a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008" target="_blank" rel="noopener noreferrer">SonicWall PSIRT, 2026-07-14</a>); both CVEs carry a same-day CISA KEV listing (recorded in this entry&#39;s CVE status, confirmed against the KEV feed). <strong>CVE-2026-15409</strong> (CVSS 10.0, CWE-918) is a server-side request forgery in the SMA1000 Work Place interface that lets a remote, unauthenticated attacker force the appliance to issue requests to an attacker-chosen location; the scope-changed CVSS vector (S:C) indicates the SSRF reaches beyond the vulnerable component&#39;s own security boundary. <strong>CVE-2026-15410</strong> (CVSS 7.2, CWE-94) is a post-authentication code-injection flaw in the SMA1000 Appliance Management Console (AMC) that lets an authenticated administrator-level session run arbitrary OS commands — read together with the pre-auth SSRF, the pair forms a chain from zero access toward root-equivalent appliance control. The affected firmware is SMA1000 6210/7210/8200v on 12.4.3-03245/03387/03434 and 12.5.0-02283/02624/02800; the fix is platform-hotfix 12.4.3-03453 or 12.5.0-02835, and SonicWall explicitly states neither flaw affects SSL-VPN running on SonicWall firewalls or the SMA100 series (<a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008" target="_blank" rel="noopener noreferrer">SonicWall PSIRT, 2026-07-14</a>).</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">this is the SSL-VPN edge-appliance exploitation pattern that turns into a foothold fast — patch now and, because exploitation is already live, treat an unpatched exposed SMA1000 as a compromise-assessment candidate rather than a clean patch. <strong>Triage:</strong> the pre-auth SSRF surfaces in the appliance&#39;s own request telemetry as outbound requests from the Work Place interface to unexpected internal or external hosts (a legitimate Work Place session does not initiate arbitrary outbound fetches); the code-injection stage surfaces in the control-service log as configuration or hotfix-state manipulation from an admin session — SonicWall&#39;s own detection guidance points at hotfix-rollback entries carrying path-traversal-style names as the anomaly, so rollback activity that does not match a change-managed maintenance window is the discriminator. Per policy no IOCs are reproduced here; consult the vendor advisory for the indicator set.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">SonicWall PSIRT has investigated multiple cases indicating the active exploitation of the vulnerabilities described in this advisory. Customers are strongly urged to upgrade to the hotfix release as soon as possible to remediate these vulnerabilities.</p><p class="entry-cite__quote">A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.</p><p class="entry-cite__quote">Sean Koessel and Steven Adair of Volexity - helped advance SonicWall&#39;s PSIRT investigation, leading to the identification of an additional IOC.</p><figcaption class="entry-cite__attr"><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008" target="_blank" rel="noopener noreferrer">SonicWall PSIRT</a> <span class="entry-cite__date mono">2026-07-14</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>14 Jul 20:19Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008" target="_blank" rel="noopener noreferrer">SonicWall PSIRT</a></div></article>]]></content:encoded></item><item><title>SAP patches an unauthenticated Approuter request-smuggling flaw and a Commerce Cloud public-default-credential exposure; NCSC-CH flags all three</title><link>https://ctipilot.ch/entries/2026-07-14/sap-july-2026-patch-day-netweaver-approuter-commerce-cloud/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-14/sap-july-2026-patch-day-netweaver-approuter-commerce-cloud/</guid><pubDate>Tue, 14 Jul 2026 20:19:53 +0000</pubDate><dc:date>2026-07-14T20:19:53Z</dc:date><category>vulnerabilities</category><category>pre-auth</category><category>patch-available</category><category>auth-bypass</category><category>global</category><category>switzerland</category><category>europe</category><category>patch-available</category><category>CVE-2026-44747</category><category>CVE-2026-27690</category><category>CVE-2026-44761</category><description><![CDATA[<p>SAP&#39;s July 2026 Security Patch Day carries three critical flaws NCSC Switzerland relayed to its constituents: CVE-2026-44747 (CVSS 9.9) memory corruption in the NetWeaver AS ABAP kernel; CVE-2026-27690 (CVSS 9.1) an unauthenticated HTTP request-smuggling flaw in SAP Approuter (non-Cloud-Foundry); and CVE-2026-44761 (CVSS 9.1) a public, hardcoded sample OAuth2 credential left active in SAP Commerce Cloud. No exploitation is reported yet, but the Commerce Cloud item is a config exposure a patch alone does not close.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-14/sap-july-2026-patch-day-netweaver-approuter-commerce-cloud" data-tags="vulnerabilities pre-auth patch-available auth-bypass" data-regions="global switzerland europe" data-kind="vulnerability" data-priority="notable" data-discovered="2026-07-14T20:19:53Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-44747/">CVE-2026-44747 +2</a><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 1: Confirmed"><span class="k">NATO</span>B1</span></div><h3 class="f-h" id="sap-july-2026-patch-day-netweaver-approuter-commerce-cloud"><a href="https://ctipilot.ch/entries/2026-07-14/sap-july-2026-patch-day-netweaver-approuter-commerce-cloud/">SAP July 2026 Security Patch Day: three CVSS ≥9.1 flaws in NetWeaver AS ABAP, Approuter and Commerce Cloud — two reachable without authentication</a></h3><p>SAP&#39;s July 2026 Security Patch Day (14 July) carries three critical flaws NCSC Switzerland&#39;s Cyber Security Hub relayed directly to Swiss constituents, none with reported exploitation at publication (<a href="https://security-hub.ncsc.admin.ch/#/posts/12763" target="_blank" rel="noopener noreferrer">NCSC-CH, 2026-07-14</a>; <a href="https://onapsis.com/blog/sap-security-patch-day-july-2026/" target="_blank" rel="noopener noreferrer">Onapsis Research Labs, 2026-07-14</a>). <strong>CVE-2026-44747</strong> (CVSS 9.9) is a memory-corruption flaw in the SAP NetWeaver Application Server ABAP kernel; SecurityWeek characterises successful exploitation as allowing an attacker to access and modify data and cause system unavailability, and SAP&#39;s only interim workaround (disabling the affected ICF nodes) is impractical because it breaks SAP GUI for HTML, so patching the kernel is the real mitigation (<a href="https://www.securityweek.com/sap-patches-critical-vulnerabilities-in-netweaver-approuter-commerce-cloud/" target="_blank" rel="noopener noreferrer">SecurityWeek, 2026-07-14</a>). <strong>CVE-2026-27690</strong> (CVSS 9.1) is an HTTP request-smuggling flaw in SAP Approuter&#39;s non-Cloud-Foundry deployments: an unauthenticated request desynchronises the request/response stream on a shared front-end, a primitive usable to poison or hijack another user&#39;s request. <strong>CVE-2026-44761</strong> (CVSS 9.1) is a hardcoded sample OAuth2 credential in SAP Commerce Cloud — any customer that ran SAP&#39;s own documented sample configuration and never rotated the shipped secret exposes a publicly-known credential an unauthenticated attacker can use to obtain a valid OCC-API access token (<a href="https://onapsis.com/blog/sap-security-patch-day-july-2026/" target="_blank" rel="noopener noreferrer">Onapsis Research Labs, 2026-07-14</a>).</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">for a Swiss/EU public-sector, finance or utilities SAP estate, sequence by reachability, not CVSS: the Approuter smuggling flaw is unauthenticated and network-reachable, so it patches first; the NetWeaver kernel flaw is authenticated but has enormous blast radius given ABAP&#39;s centrality; and the Commerce Cloud item is an environment-specific configuration exposure — a publicly-known default credential that a routine note roll-out does not remediate, because the exposed secret must be rotated. <strong>Triage:</strong> the Commerce Cloud exposure is a config-audit question (did we deploy the sample OAuth2 client, and is its secret still the shipped default?), answerable from configuration review rather than telemetry; the Approuter smuggling flaw manifests in front-end HTTP access logs as request/response desynchronisation anomalies (ambiguous content-length/transfer-encoding framing, responses mismatched to the requesting session) on a shared Approuter, distinct from the well-formed request stream of normal traffic.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">The vulnerability affects SAP Approuter deployments in non-Cloud Foundry environments and allows an unauthenticated attacker to send a specially crafted HTTP request that leads to request-response desynchronization.</p><p class="entry-cite__quote">Exploitation requires that the customer execute the sample script and retain the resulting OAuth2 client in production without replacing the hardcoded secret.</p><p class="entry-cite__quote">Successful exploitation of the security defect could allow an attacker to access and modify data, and cause system unavailability, SAP security firm Onapsis explains.</p><figcaption class="entry-cite__attr"><a href="https://www.securityweek.com/sap-patches-critical-vulnerabilities-in-netweaver-approuter-commerce-cloud/" target="_blank" rel="noopener noreferrer">SecurityWeek</a> <span class="entry-cite__date mono">2026-07-14</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>14 Jul 20:19Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-14/sap-july-2026-patch-day-netweaver-approuter-commerce-cloud/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://onapsis.com/blog/sap-security-patch-day-july-2026/" target="_blank" rel="noopener noreferrer">Onapsis Research Labs</a> · <a href="https://security-hub.ncsc.admin.ch/#/posts/12763" target="_blank" rel="noopener noreferrer">NCSC Switzerland — Cyber Security Hub</a> · <a href="https://www.securityweek.com/sap-patches-critical-vulnerabilities-in-netweaver-approuter-commerce-cloud/" target="_blank" rel="noopener noreferrer">SecurityWeek</a> · <a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news/july-2026.html" target="_blank" rel="noopener noreferrer">SAP Support Portal</a></div></article>]]></content:encoded></item><item><title>Microsoft patches two exploited zero-days on-prem: an AD FS privilege escalation and an unauthenticated SharePoint EoP, both KEV-listed same day</title><link>https://ctipilot.ch/entries/2026-07-14/microsoft-july-2026-patch-tuesday-two-exploited-zero-days/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-14/microsoft-july-2026-patch-tuesday-two-exploited-zero-days/</guid><pubDate>Tue, 14 Jul 2026 20:19:53 +0000</pubDate><dc:date>2026-07-14T20:19:53Z</dc:date><category>vulnerabilities</category><category>actively-exploited</category><category>zero-day</category><category>priv-esc</category><category>cisa-kev</category><category>identity</category><category>patch-available</category><category>global</category><category>exploited</category><category>cisa-kev</category><category>patch-available</category><category>CVE-2026-56155</category><category>CVE-2026-56164</category><description><![CDATA[<p>Microsoft&#39;s July 2026 Patch Tuesday (its largest ever by CVE count) fixes two zero-days Microsoft confirms were exploited in the wild and CISA added to KEV the same day: CVE-2026-56155, a local elevation-of-privilege in Active Directory Federation Services (AD FS), and CVE-2026-56164, an unauthenticated, network-reachable elevation-of-privilege in on-prem SharePoint Server 2016/2019/Subscription Edition. Any organization running on-prem AD FS or SharePoint should treat both as emergency patches.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-14/microsoft-july-2026-patch-tuesday-two-exploited-zero-days" data-tags="vulnerabilities actively-exploited zero-day priv-esc cisa-kev identity patch-available" data-regions="global" data-kind="vulnerability" data-priority="high" data-discovered="2026-07-14T20:19:53Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-56155/">CVE-2026-56155 +1</a><span class="b exp">exploited</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 1: Confirmed"><span class="k">NATO</span>A1</span></div><h3 class="f-h" id="microsoft-july-2026-patch-tuesday-two-exploited-zero-days"><a href="https://ctipilot.ch/entries/2026-07-14/microsoft-july-2026-patch-tuesday-two-exploited-zero-days/">Microsoft July 2026 Patch Tuesday ships two actively-exploited zero-days — AD FS local EoP (CVE-2026-56155) and unauthenticated SharePoint EoP (CVE-2026-56164)</a></h3><p>Microsoft&#39;s July 2026 Patch Tuesday is its largest ever by CVE count and carries two zero-days Microsoft confirms were exploited before a fix existed, both added to CISA&#39;s Known Exploited Vulnerabilities catalog the same day (<a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-07-14</a>). <strong>CVE-2026-56155</strong> (CVSS 7.8, CWE-1220) is a local elevation-of-privilege in Active Directory Federation Services: an attacker who already holds a low-privileged authorized session on the AD FS host escalates to administrator (<a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-56155" target="_blank" rel="noopener noreferrer">Microsoft MSRC, 2026-07-14</a>). It is a post-foothold escalation rather than an initial-access vector, and Microsoft&#39;s advisory credits its own DART incident-response team in the acknowledgements — meaning it surfaced during a live intrusion, so an exposed AD FS host should be treated as a candidate for compromise assessment, not merely patched (<a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-56155" target="_blank" rel="noopener noreferrer">Microsoft MSRC, 2026-07-14</a>). <strong>CVE-2026-56164</strong> (CVSS 5.3, CWE-306) is the more exposed of the two: a missing-authentication flaw in on-prem SharePoint Server that lets an unauthenticated attacker elevate privileges over the network with no user interaction (<a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-56164" target="_blank" rel="noopener noreferrer">Microsoft MSRC, 2026-07-14</a>). Microsoft&#39;s mitigation guidance — enable AMSI on the SharePoint/IIS worker processes with Request Body Scan set to Full — indicates the trigger is a crafted HTTP POST body, the same class of exposure this pipeline tracked for the CVE-2026-45659 SharePoint deserialization RCE on 2026-07-02, so operators who already tuned AMSI for that flaw have partial coverage.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">patch both now; for AD FS the low CVSS understates the risk because the bug was caught in real-world incident response — treat internet- or partner-reachable AD FS servers as potentially targeted and pair the patch with a hunt of local process activity on those hosts. <strong>Triage:</strong> the AD FS escalation manifests in host-local process-execution and privilege-transition telemetry on the AD FS server itself (a low-privileged service account acquiring administrator context), not in network logs — normal AD FS operation does not spawn privilege transitions from its service account, so that lineage is the discriminator; the SharePoint escalation surfaces in IIS/SharePoint worker-process telemetry as an unauthenticated request preceding an unexpected privilege context, which AMSI full-body scanning is positioned to catch. No IOCs or exploiting cluster have been published for either.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.</p><p class="entry-cite__quote">Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.</p><figcaption class="entry-cite__attr"><a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-56155" target="_blank" rel="noopener noreferrer">Microsoft MSRC</a> <span class="entry-cite__date mono">2026-07-14</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">It&#39;s a missing-authentication flaw, meaning an unauthenticated attacker can hit it over the network with no user interaction required. When something this reachable is being actively abused, patch it now and worry about the score later.</p><figcaption class="entry-cite__attr"><a href="https://www.zerodayinitiative.com/blog/2026/7/14/the-july-2026-security-update-review" target="_blank" rel="noopener noreferrer">Zero Day Initiative (Trend Micro)</a> <span class="entry-cite__date mono">2026-07-14</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>14 Jul 20:19Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-14/microsoft-july-2026-patch-tuesday-two-exploited-zero-days/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-56155" target="_blank" rel="noopener noreferrer">Microsoft MSRC</a> · <a href="https://www.zerodayinitiative.com/blog/2026/7/14/the-july-2026-security-update-review" target="_blank" rel="noopener noreferrer">Zero Day Initiative (Trend Micro)</a> · <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/" target="_blank" rel="noopener noreferrer">BleepingComputer</a> · <a href="https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flaws/" target="_blank" rel="noopener noreferrer">Krebs on Security</a></div></article>]]></content:encoded></item><item><title>Honeypots record in-the-wild exploitation of the ShareFile Storage Zone Controller auth bypass the same day Progress ordered shutdowns</title><link>https://ctipilot.ch/entries/2026-07-14/progress-sharefile-szc-active-exploitation-confirmed/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-14/progress-sharefile-szc-active-exploitation-confirmed/</guid><pubDate>Tue, 14 Jul 2026 12:50:00 +0000</pubDate><dc:date>2026-07-14T12:50:00Z</dc:date><category>vulnerabilities</category><category>actively-exploited</category><category>rce</category><category>pre-auth</category><category>auth-bypass</category><category>global</category><category>europe</category><category>us</category><category>exploited</category><category>poc-public</category><category>patch-available</category><category>CVE-2026-2699</category><description><![CDATA[<p>Update to the 2026-07-13 ShareFile shutdown entry. Shadowserver Foundation honeypots first recorded active, in-the-wild exploitation attempts against the ShareFile Storage Zone Controller pre-auth authentication bypass CVE-2026-2699 on Friday 2026-07-10 — the same day Progress issued its emergency power-off order — and the internet-exposed instance count fell from watchTowr&#39;s April tally of ~30,000 to roughly 1,000 by 2026-07-13. A Recorded Future analyst publicly assessed possible Clop involvement; Progress has named no actor and disclosed no root cause. On-prem operators still running Storage Zone Controllers should keep them off.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-14/progress-sharefile-szc-active-exploitation-confirmed" data-tags="vulnerabilities actively-exploited rce pre-auth auth-bypass" data-regions="global europe us" data-kind="incident" data-priority="high" data-discovered="2026-07-14T12:50:00Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-2699/">CVE-2026-2699</a><span class="b exp">exploited</span><span class="b upd">update</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 1: Confirmed"><span class="k">NATO</span>B1</span></div><h3 class="f-h" id="progress-sharefile-szc-active-exploitation-confirmed"><a href="https://ctipilot.ch/entries/2026-07-14/progress-sharefile-szc-active-exploitation-confirmed/">Progress ShareFile Storage Zone Controller — Shadowserver confirms active exploitation of CVE-2026-2699; exposed instances collapse ~30,000 to ~1,000</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-07-13/progress-sharefile-storage-zone-controller-shutdown/">Progress orders ShareFile Storage Zone Controller shutdown over a &#39;credible external threat&#39; — day three, no patch or root cause disclosed</a> <span class="mono muted">(2026-07-13)</span></p><p>Two developments harden the picture around Progress&#39;s emergency ShareFile Storage Zone Controller (SZC) shutdown order. First, the shutdown was not precautionary in the abstract: the alert &quot;arrived the same day that independent honeypots began detecting active, in-the-wild attempts to exploit&quot; the pre-auth authentication-bypass flaw CVE-2026-2699, with Shadowserver Foundation honeypots first recording those attempts on Friday 2026-07-10 (<a href="https://www.bankinfosecurity.com/progress-urges-sharefile-shutdown-over-credible-threat-a-32210" target="_blank" rel="noopener noreferrer">BankInfoSecurity, 2026-07-13</a>). This moves the flaw&#39;s status from PoC-public to actively exploited. Second, defenders responded at scale — the number of internet-exposed Storage Zone Controllers fell from watchTowr&#39;s April count of about 30,000 to roughly 1,000 by 2026-07-13, evidence of widespread emergency power-downs (<a href="https://www.bankinfosecurity.com/progress-urges-sharefile-shutdown-over-credible-threat-a-32210" target="_blank" rel="noopener noreferrer">BankInfoSecurity, 2026-07-13</a>). Progress restored ShareFile cloud-service access for SZC customers but continues to require the on-prem controllers themselves stay powered off pending its investigation, and still reports no evidence of unauthorized access to customer data (<a href="https://www.theregister.com/security/2026/07/13/progress-orders-emergency-sharefile-server-shutdown-over-mystery-security-threat/5270281" target="_blank" rel="noopener noreferrer">The Register, 2026-07-13</a>; <a href="https://status.sharefile.com/" target="_blank" rel="noopener noreferrer">Progress ShareFile status, 2026-07-13</a>).</p>
<p>Recorded Future analyst Allan Liska publicly assessed that the pattern &quot;smells like CL0P ransomware group activity,&quot; pointing to Clop&#39;s long record of mass-exploiting secure file-transfer software (Accellion FTA, GoAnywhere, MOVEit, Cleo Harmony, and Oracle E-Business Suite) (<a href="https://www.bankinfosecurity.com/progress-urges-sharefile-shutdown-over-credible-threat-a-32210" target="_blank" rel="noopener noreferrer">BankInfoSecurity, 2026-07-13</a>). This is a named researcher&#39;s hypothesis, not an attribution: Progress has identified no actor and disclosed no root cause.</p>
<p><strong>Defender takeaway.</strong> The one-day earlier guidance — treat any exposed SZC as untrusted and keep it powered off rather than patched — is now backed by confirmed in-the-wild exploitation, so it should carry more weight, not less, for any organisation that has not yet acted. Exposure concentrates in the US and Germany, keeping this directly relevant to European on-prem file-exchange operators. The recommended state remains a full power-off of on-prem Storage Zone Controllers until Progress publishes scope; the original entry&#39;s shutdown and bounded-compromise-check actions still stand unchanged.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">The alert arrived the same day that independent honeypots began detecting active, in-the-wild attempts to exploit a critical authentication bypass vulnerability the vendor patched earlier this year in its ShareFile Storage Zone Controller software.</p><p class="entry-cite__quote">Honeypots run by nonprofit cybersecurity organization Shadowserver Foundation first recorded active, in-the-wild attacks attempting to exploit CVE-2026-2699 on Friday.</p><p class="entry-cite__quote">This smells like CL0P ransomware group activity. If you use ShareFile, be like C-3PO and &#39;shut them all down.&#39;</p><figcaption class="entry-cite__attr"><a href="https://www.bankinfosecurity.com/progress-urges-sharefile-shutdown-over-credible-threat-a-32210" target="_blank" rel="noopener noreferrer">BankInfoSecurity (ISMG)</a> <span class="entry-cite__date mono">2026-07-13</span></figcaption></figure></div><div class="prov"><span>incident</span><span>14 Jul 12:50Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-14/progress-sharefile-szc-active-exploitation-confirmed/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bankinfosecurity.com/progress-urges-sharefile-shutdown-over-credible-threat-a-32210" target="_blank" rel="noopener noreferrer">BankInfoSecurity (ISMG)</a> · <a href="https://www.theregister.com/security/2026/07/13/progress-orders-emergency-sharefile-server-shutdown-over-mystery-security-threat/5270281" target="_blank" rel="noopener noreferrer">The Register</a> · <a href="https://status.sharefile.com/" target="_blank" rel="noopener noreferrer">Progress ShareFile (vendor status page)</a></div></article>]]></content:encoded></item><item><title>Dutch intelligence: Russia hijacked default-credential internet cameras along military-supply routes; four EU states summon Russian ambassadors</title><link>https://ctipilot.ch/entries/2026-07-13/russia-ip-camera-hijacking-nato-military-supply-routes/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-13/russia-ip-camera-hijacking-nato-military-supply-routes/</guid><pubDate>Mon, 13 Jul 2026 20:36:00 +0000</pubDate><dc:date>2026-07-13T20:36:00Z</dc:date><category>nation-state</category><category>espionage</category><category>russia-nexus</category><category>europe</category><category>dach</category><category>nordics</category><description><![CDATA[<p>AIVD and MIVD disclosed that Russia-linked actors compromised internet-connected cameras — reachable because they still used default passwords or outdated firmware, including cameras operated by businesses along the routes — carrying military supplies to Ukraine through the Netherlands, to watch the shipments and equipment being moved. The 2026-07-13 diplomatic escalation (NL/France/Germany/Finland ambassador summons, NATO condemnation) followed. Transferable lesson: internet-exposed cameras/IoT are treated as a state-actor surveillance grid.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-13/russia-ip-camera-hijacking-nato-military-supply-routes" data-tags="nation-state espionage russia-nexus" data-regions="europe dach nordics" data-kind="incident" data-priority="notable" data-discovered="2026-07-13T20:36:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="russia-ip-camera-hijacking-nato-military-supply-routes"><a href="https://ctipilot.ch/entries/2026-07-13/russia-ip-camera-hijacking-nato-military-supply-routes/">AIVD/MIVD: Russia-linked actors hijack default-credential IP cameras along NATO military-supply routes to monitor Ukraine-bound shipments</a></h3><p>Dutch intelligence services AIVD (General Intelligence and Security Service) and MIVD (Military Intelligence and Security Service) disclosed on 2026-07-11 that Russia-linked actors compromised &quot;a small number&quot; of internet-connected cameras positioned along routes used to move military supplies to Ukraine through the Netherlands — including cameras operated by businesses located on those routes — giving the operators remote viewing access to the shipments and equipment being moved (<a href="https://nltimes.nl/2026/07/11/dutch-spy-agencies-russia-hacked-cameras-spy-military-routes" target="_blank" rel="noopener noreferrer">NL Times/ANP, 2026-07-11</a>). The agencies state the cameras were reachable chiefly because they &quot;still us[e] default passwords or outdated firmware&quot; — weak/default-credential abuse and unpatched embedded firmware on internet-exposed devices, not a bespoke exploit chain. On 2026-07-13, after EU ministerial consultations in Brussels, the Netherlands summoned the Russian ambassador; France, Germany and Finland took the same step over related espionage and sabotage concerns, and NATO issued a joint statement condemning &quot;the persistent malicious cyber activities of Russia&quot; (<a href="https://nltimes.nl/2026/07/13/netherlands-summons-russian-ambassador-russias-hacking-military-supply-routes" target="_blank" rel="noopener noreferrer">NL Times/ANP, 2026-07-13</a>). AIVD/MIVD separately warned businesses located along military-logistics routes to harden their camera and IoT security. This is a distinct technical story from the same-day FSB Centre 16 router-hijacking advisory and the Turla espionage attribution covered separately today — here the compromised asset class is consumer/commercial IP cameras used for physical-logistics surveillance.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the transferable lesson reaches any critical-infrastructure operator, not only those on a logistics route — a state actor is treating internet-exposed cameras, DVRs/NVRs and smart-building IoT with default credentials or unpatched firmware as a physical-surveillance sensor grid. Inventory internet-reachable camera and IoT devices across your estate, and in egress/flow telemetry watch for outbound video/RTSP or streaming sessions from those devices to destinations outside the expected vendor-cloud or monitoring endpoints. <strong>Triage:</strong> many IP cameras legitimately stream to a vendor cloud or an on-prem NVR — the discriminator is a camera establishing an interactive or streaming session to an unfamiliar external destination that is neither its vendor cloud nor the site&#39;s own recorder, particularly a device still answering on a factory-default credential from the public internet.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Dutch intelligence services disclosed Friday that Russian actors had compromised “a small number of cameras” on routes for military shipments to Ukraine. The breaches allowed the hackers remote viewing access, according to statements from the General Intelligence and Security Service (AIVD) and the Military Intelligence and Security Service (MIVD).</p><p class="entry-cite__quote">We strongly condemn the persistent malicious cyber activities of Russia. The country uses its cyber ecosystem to attack allies and NATO partners.</p><figcaption class="entry-cite__attr"><a href="https://nltimes.nl/2026/07/11/dutch-spy-agencies-russia-hacked-cameras-spy-military-routes" target="_blank" rel="noopener noreferrer">NL Times (ANP)</a> <span class="entry-cite__date mono">2026-07-11</span></figcaption></figure></div><div class="prov"><span>incident</span><span>13 Jul 20:36Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-13/russia-ip-camera-hijacking-nato-military-supply-routes/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://nltimes.nl/2026/07/11/dutch-spy-agencies-russia-hacked-cameras-spy-military-routes" target="_blank" rel="noopener noreferrer">NL Times (ANP)</a></div></article>]]></content:encoded></item><item><title>WAGO patches a hidden early-boot diagnostic interface in I/O System Field couplers that lets an unauthenticated remote attacker take full control</title><link>https://ctipilot.ch/entries/2026-07-13/wago-io-system-field-cve-2026-4769-early-boot-backdoor/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-13/wago-io-system-field-cve-2026-4769-early-boot-backdoor/</guid><pubDate>Mon, 13 Jul 2026 12:50:00 +0000</pubDate><dc:date>2026-07-13T12:50:00Z</dc:date><category>vulnerabilities</category><category>ot-ics</category><category>auth-bypass</category><category>pre-auth</category><category>patch-available</category><category>global</category><category>europe</category><category>patch-available</category><category>CVE-2026-4769</category><description><![CDATA[<p>CERT@VDE published advisory VDE-2026-031 / CVE-2026-4769 (2026-07-13) for WAGO I/O System Field coupler devices: certain models activate an undocumented diagnostic capability during the initial boot sequence that is reachable without authentication for a brief early-boot window, letting an unauthenticated remote attacker with network access reach internal system processes and achieve full system compromise (CWE-912 Hidden Functionality; CVSS 9.8). No exploitation is reported (EPSS 0.0) and fixed firmware is available per model. Swiss/European energy, water and industrial-automation OT estates running these couplers should schedule the firmware update and verify these devices are segmented from untrusted networks, especially during maintenance reboots.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-13/wago-io-system-field-cve-2026-4769-early-boot-backdoor" data-tags="vulnerabilities ot-ics auth-bypass pre-auth patch-available" data-regions="global europe" data-kind="vulnerability" data-priority="notable" data-discovered="2026-07-13T12:50:00Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-4769/">CVE-2026-4769</a><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 2: Probably true"><span class="k">NATO</span>A2</span></div><h3 class="f-h" id="wago-io-system-field-cve-2026-4769-early-boot-backdoor"><a href="https://ctipilot.ch/entries/2026-07-13/wago-io-system-field-cve-2026-4769-early-boot-backdoor/">CVE-2026-4769 — WAGO I/O System Field: undocumented early-boot interface allows unauthenticated full compromise (CVSS 9.8)</a></h3><p>CERT@VDE — Germany&#39;s OT/ICS coordinating CERT, acting as CVE Numbering Authority for the vendor — published advisory VDE-2026-031 / CVE-2026-4769 on 2026-07-13 for WAGO I/O System Field series coupler devices (models 0765-110x, 0765-120x, 0765-150x, 0765-2101, 0765-2102, 0765-410x, 0765-420x, 0765-450x, all variant <code>/0100-0000</code>) (<a href="https://www.certvde.com/en/advisories/VDE-2026-031/" target="_blank" rel="noopener noreferrer">CERT@VDE, 2026-07-13</a>). Certain devices activate an undocumented internal diagnostic capability during the initial boot sequence — functionality outside the publicly documented feature set — which is reachable without authentication for a brief window before the main operating environment and its security controls become fully active (CWE-912 Hidden Functionality). If an attacker has network access to the device during that early-boot window, they can interact with internal system processes normally protected during regular operation, which CERT@VDE describes as resulting in full system compromise. The advisory carries a CVSS 3.1 vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (9.8), and the ENISA EU Vulnerability Database entry EUVD-2026-43297 lists a CVSS 4.0 base score of 9.3 (<a href="https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43297" target="_blank" rel="noopener noreferrer">ENISA EUVD, 2026-07-13</a>). No exploitation has been reported and EPSS is 0.0. WAGO has released fixed firmware for each affected model.</p>
<p>WAGO I/O System Field devices are modular fieldbus I/O couplers used in industrial automation and building-management deployments, including energy and water-utility OT environments in the constituency&#39;s additional sectors. The practical exploitability is bounded — an attacker must have network reachability to the device precisely during its early-boot window — but the impact if that condition is met is unauthenticated, full compromise of an operational field device, and OT patch cycles are slow, so the exposure can persist. Detection is best framed as OT network monitoring: correlate device power-cycle/reboot events (from maintenance logs or the device&#39;s own uptime telemetry) with any new inbound session to the device&#39;s management/diagnostic ports in the same time window — a connection arriving during a reboot, rather than steady-state operation, is the anomaly this vulnerability creates. Hardening: apply the per-model fixed firmware listed above and, until then, keep these couplers behind VLAN/ACL segmentation from any untrusted network segment, tightening reachability during planned maintenance reboots when the early-boot window is opened deliberately.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">This functionality is not formally documented and becomes accessible without authentication for a brief period in the early boot phase. During this window, an unauthenticated remote attacker can gain access to the internal system processes, resulting in full system compromise.</p><figcaption class="entry-cite__attr">CERT@VDE</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>13 Jul 12:50Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-13/wago-io-system-field-cve-2026-4769-early-boot-backdoor/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.certvde.com/en/advisories/VDE-2026-031/" target="_blank" rel="noopener noreferrer">CERT@VDE (Germany OT/ICS coordinating CERT, CNA)</a> · <a href="https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43297" target="_blank" rel="noopener noreferrer">ENISA EU Vulnerability Database (EUVD-2026-43297)</a></div></article>]]></content:encoded></item><item><title>19-agency advisory details FSB Centre 16 router hijacking via SNMP and Cisco Smart Install as the UK and EU attribute Poland&#39;s Dec-2025 grid sabotage</title><link>https://ctipilot.ch/entries/2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory/</guid><pubDate>Mon, 13 Jul 2026 12:40:00 +0000</pubDate><dc:date>2026-07-13T12:40:00Z</dc:date><category>nation-state</category><category>espionage</category><category>actively-exploited</category><category>cisa-kev</category><category>wiper</category><category>law-enforcement</category><category>ot-ics</category><category>russia-nexus</category><category>global</category><category>europe</category><category>exploited</category><category>cisa-kev</category><category>patch-available</category><category>CVE-2018-0171</category><description><![CDATA[<p>A joint Cybersecurity Advisory from 19 agencies across 13 countries (2026-07-13) details how Russian FSB Centre 16 (Static Tundra / Berserk Bear) opportunistically compromises internet-facing routers across energy, government, telecom, finance and healthcare — chiefly by abusing default/weak SNMP community strings and the seven-year-old Cisco Smart Install flaw CVE-2018-0171 (CISA KEV) to exfiltrate device configurations. On the same day the UK and EU formally attributed the destructive 29 Dec 2025 attack on Poland&#39;s energy grid to this FSB unit and imposed their first joint cyber-sanctions package. Swiss and European critical-infrastructure operators running Cisco IOS/IOS XE or legacy SNMP on exposed network devices should treat router hygiene as an active-exploitation priority.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory" data-tags="nation-state espionage actively-exploited cisa-kev wiper law-enforcement ot-ics russia-nexus" data-regions="global europe" data-kind="threat" data-priority="high" data-discovered="2026-07-13T12:40:00Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2018-0171/">CVE-2018-0171</a><span class="b exp">exploited</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 1: Confirmed"><span class="k">NATO</span>A1</span></div><h3 class="f-h" id="fsb-centre-16-static-tundra-router-hijacking-advisory"><a href="https://ctipilot.ch/entries/2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory/">FSB Centre 16 (Static Tundra) router-hijacking campaign: 19-agency joint advisory, formal Poland energy-grid attribution and first joint EU/UK cyber sanctions</a></h3><p><strong>Background.</strong> The FSB Centre 16 network-device cluster is not new — it has a decade-plus public record under the vendor labels Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly and Ghost Blizzard, and Cisco Talos profiled it in August 2025 as &quot;Static Tundra,&quot; documenting long-term compromise of unpatched and end-of-life network gear for configuration theft and persistent collection (<a href="https://blog.talosintelligence.com/static-tundra/" target="_blank" rel="noopener noreferrer">Cisco Talos, 2025-08-20</a>). What is new is a same-day trio of actions on 2026-07-13: a much fuller TTP disclosure, a formal government attribution of a destructive attack, and the first coordinated EU/UK cyber-sanctions package.</p>
<p>A joint Cybersecurity Advisory carrying 19 authoring and co-sealing agencies across 13 countries — NSA, CISA, FBI and DC3 (US) alongside the cyber and intelligence authorities of Australia, Canada, New Zealand, the UK, Czech Republic, Denmark, Estonia, Finland, France, Italy, Poland and Sweden — describes FSB Centre 16 opportunistically compromising poorly configured routers across communications, defense industrial base, energy, financial services, government (especially state/local), and healthcare sectors (<a href="https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF" target="_blank" rel="noopener noreferrer">NSA/CISA/FBI joint advisory, 2026-07-13</a>; <a href="https://www.ncsc.gov.uk/news/uk-and-allies-urge-critical-sectors-to-improve-defences-against-russian-intelligence-targeting" target="_blank" rel="noopener noreferrer">NCSC-UK, 2026-07-13</a>). The advisory notes these TTPs overlap with Salt Typhoon activity, so the hardening below counters more than one actor.</p>
<p>The primary access vector is not a novel exploit but weak SNMP hygiene. The actors scan internet IP ranges for SNMP agents that accept common or default community strings, then issue spoofed-source SNMP Set-Requests carrying object identifiers that instruct the device to copy its running configuration to a file (commonly <code>config.bkp</code> or <code>output.txt</code>) and transfer it, usually over TFTP, to a leased VPS or a compromised FTP server (<a href="https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF" target="_blank" rel="noopener noreferrer">joint advisory, 2026-07-13</a>). The advisory names the exact OIDs abused — <code>1.3.6.1.4.1.9.9.96.1.1</code> (Cisco Config Copy) and <code>1.3.6.1.4.1.9.9.96.1.1.1.1.5</code> (the destination address for the copied config). A stolen configuration frequently discloses further credentials and additional community strings, feeding lateral movement. Talos&#39;s profile records the actor guessing or reusing insecure read-write community strings such as <code>public</code> and <code>anonymous</code> (<a href="https://blog.talosintelligence.com/static-tundra/" target="_blank" rel="noopener noreferrer">Cisco Talos, 2025-08-20</a>). Secondarily — &quot;occasionally,&quot; per the advisory — the actors exploit known Cisco bugs and the Smart Install (SMI) feature, naming CVE-2018-0171 (the Smart Install pre-auth RCE, in CISA KEV since 2021) and CVE-2008-4128 (end-of-life devices only, no patch). Persistence has historically included the SYNful Knock IOS firmware implant.</p>
<p><strong>The Poland grid attribution.</strong> On the same day, the UK together with EU member states formally attributed the destructive 29 December 2025 attack on Poland&#39;s energy grid to FSB Centre 16 (<a href="https://www.ncsc.gov.uk/news/uk-and-allies-urge-critical-sectors-to-improve-defences-against-russian-intelligence-targeting" target="_blank" rel="noopener noreferrer">NCSC-UK, 2026-07-13</a>). CERT Polska&#39;s own incident report describes coordinated destructive activity against 30-plus wind and photovoltaic grid-connection substations — RTU, HMI and protection-relay firmware damaged or system files deleted — and a combined heat-and-power plant serving roughly half a million people, where wiper malware was blocked by the operator&#39;s EDR before detonation; CERT Polska tied the activity to the Static Tundra / Berserk Bear / Ghost Blizzard / Dragonfly cluster via VPS, router and anonymizing-infrastructure overlap and called it &quot;the first publicly described destructive activity attributed to this activity cluster&quot; (<a href="https://cert.pl/en/posts/2026/01/incident-report-energy-sector-2025/" target="_blank" rel="noopener noreferrer">CERT Polska, 2026-01-30</a>). Note the attribution is contested at the cluster-label level: earlier ESET reporting attributed the same DynoWiper attack to the GRU&#39;s Sandworm (<a href="https://www.bleepingcomputer.com/news/security/sandworm-hackers-linked-to-failed-wiper-attack-on-polands-energy-systems/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-01-24</a>), and the EU Council statement names FSB Centre 16 as the parent controlling several groups including Turla — so treat &quot;FSB Centre 16&quot; as an umbrella unit rather than a single team.</p>
<p>The sanctions package is the policy layer: the EU designated 9 individuals and 4 entities and the UK designated 24, covering senior GRU figures, the front company IMPULS accused of recruiting hackers for GRU Unit 29155, Lumma Stealer operators, and the disinformation outlet Rybar LLC (<a href="https://www.gov.uk/government/news/uk-and-eu-strike-russian-cyber-networks-with-new-sanctions" target="_blank" rel="noopener noreferrer">UK Government, 2026-07-13</a>; <a href="https://www.bleepingcomputer.com/news/security/eu-and-uk-hit-russia-with-first-joint-cyber-sanctions-package/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-07-13</a>).</p>
<p><strong>Detection.</strong> The telemetry classes to prioritise on network gear: network-flow and firewall logs for inbound SNMP Set-Requests (especially with spoofed or unfamiliar source addresses) and for outbound TFTP sessions initiated from a router/switch management interface to non-management destinations; device syslog and AAA/TACACS+ logs for unexpected &quot;config copy&quot; events, new local-account creation, and unexplained drops in logging volume — Talos documents the actor tampering with TACACS+ configuration to blind logging and standing up GRE tunnels to redirect victim traffic (<a href="https://blog.talosintelligence.com/static-tundra/" target="_blank" rel="noopener noreferrer">Cisco Talos, 2025-08-20</a>); and IDS rules keyed to inbound SNMP Set-Requests carrying the config-copy OIDs above, as the advisory recommends (<a href="https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF" target="_blank" rel="noopener noreferrer">joint advisory, 2026-07-13</a>). Baseline NetFlow for the new GRE tunnel endpoints Talos describes.</p>
<p><strong>Defender takeaway.</strong> For a Swiss or European CI operator this is a router-hygiene mandate with a live destructive precedent next door. Disable Smart Install where it is not in active use, confirm CVE-2018-0171 is patched, migrate management SNMP to v3 with authPriv and disable SNMPv1/v2c (or, where legacy SNMP is unavoidable, replace every default/weak community string and enforce read-only), restrict all management protocols to known stations via out-of-band ACLs, use Cisco password hashing type 8 (never 0/4/7), and treat the device configuration held in your management system — not the device itself — as the source of truth so a tampered config is detectable.</p>
<p><strong>Triage:</strong> legitimate network-management stations poll SNMP on a predictable cadence from a known IP set, almost always read-only GET/GET-NEXT. The signal is a <em>write</em> (SNMP Set-Request) — particularly one carrying the config-copy OIDs — from a source outside the management range or with an inconsistent/spoofed source address, followed by an outbound TFTP transfer from the device; either alone is weak, the sequence config-write-then-TFTP-egress is the discriminator.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">The actors scan for Internet IP ranges with active Simple Network Management Protocol (SNMP) agents that accept common or default community strings for authentication</p><figcaption class="entry-cite__attr"><a href="https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF" target="_blank" rel="noopener noreferrer">NSA / CISA / FBI / DC3 joint Cybersecurity Advisory (19 agencies, 13 countries)</a> <span class="entry-cite__date mono">2026-07-13</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">The UK together with EU member states has also today formally attributed the December 2025 attack on Poland&#39;s energy grid to Russia&#39;s FSB Centre 16.</p><figcaption class="entry-cite__attr"><a href="https://www.ncsc.gov.uk/news/uk-and-allies-urge-critical-sectors-to-improve-defences-against-russian-intelligence-targeting" target="_blank" rel="noopener noreferrer">NCSC-UK</a> <span class="entry-cite__date mono">2026-07-13</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">This is, however, the first publicly described destructive activity attributed to this activity cluster.</p><figcaption class="entry-cite__attr"><a href="https://cert.pl/en/posts/2026/01/incident-report-energy-sector-2025/" target="_blank" rel="noopener noreferrer">CERT Polska</a> <span class="entry-cite__date mono">2026-01-30</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">This reckless attack failed but could have caused 500,000 citizens to lose electricity in the depths of winter.</p><figcaption class="entry-cite__attr"><a href="https://www.gov.uk/government/news/uk-and-eu-strike-russian-cyber-networks-with-new-sanctions" target="_blank" rel="noopener noreferrer">UK Government (FCDO)</a> <span class="entry-cite__date mono">2026-07-13</span></figcaption></figure></div><div class="prov"><span>threat</span><span>13 Jul 12:40Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.ncsc.gov.uk/news/uk-and-allies-urge-critical-sectors-to-improve-defences-against-russian-intelligence-targeting" target="_blank" rel="noopener noreferrer">NCSC-UK</a> · <a href="https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF" target="_blank" rel="noopener noreferrer">NSA / CISA / FBI / DC3 joint Cybersecurity Advisory (19 agencies, 13 countries)</a> · <a href="https://www.gov.uk/government/news/uk-and-eu-strike-russian-cyber-networks-with-new-sanctions" target="_blank" rel="noopener noreferrer">UK Government (FCDO)</a> · <a href="https://cert.pl/en/posts/2026/01/incident-report-energy-sector-2025/" target="_blank" rel="noopener noreferrer">CERT Polska</a> · <a href="https://blog.talosintelligence.com/static-tundra/" target="_blank" rel="noopener noreferrer">Cisco Talos</a> · <a href="https://www.bleepingcomputer.com/news/security/eu-and-uk-hit-russia-with-first-joint-cyber-sanctions-package/" target="_blank" rel="noopener noreferrer">BleepingComputer</a></div></article>]]></content:encoded></item><item><title>Dutch NIS2 (Cyberbeveiligingswet) passed the Senate 7 July — entry into force fixed for 15 August 2026, ~8,000 organisations in scope</title><link>https://ctipilot.ch/entries/2026-07-12/weekly-w28-netherlands-nis2-in-force/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-12/weekly-w28-netherlands-nis2-in-force/</guid><pubDate>Sun, 12 Jul 2026 23:52:00 +0000</pubDate><dc:date>2026-07-12T23:52:00Z</dc:date><category>law-enforcement</category><category>europe</category><description><![CDATA[<p>The Dutch First Chamber passed the Cyberbeveiligingswet (the NIS2 transposition) and the companion Wet weerbaarheid kritieke entiteiten (CER transposition) on 7 July 2026; both enter into force 15 August 2026. This closes the &#39;slipped past 1 July&#39; status prior weeklies tracked and fixes a hard date. The Cbw covers ~8,000 organisations across 18 sectors with a duty of care including supply-chain risk management, mandatory incident reporting to the CSIRT, entity-register registration, and board-level accountability. For Swiss-domiciled organisations with Dutch subsidiaries, NL critical suppliers, or cross-border NIS2-equivalent reporting relationships, 15 August 2026 is now the operative compliance clock.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-12/weekly-w28-netherlands-nis2-in-force" data-tags="law-enforcement" data-regions="europe" data-kind="policy" data-priority="notable" data-discovered="2026-07-12T23:52:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b upd">update</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 1: Confirmed"><span class="k">NATO</span>A1</span></div><h3 class="f-h" id="weekly-w28-netherlands-nis2-in-force"><a href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-netherlands-nis2-in-force/">Netherlands NIS2 transposition confirmed: the Senate passed the Cyberbeveiligingswet on 7 July, fixing entry into force at 15 August 2026</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-netherlands-nis2-slip/">Netherlands NIS2 transposition slips past its 1 July target — Senate vote set for 7 July, entry into force now 15 August 2026</a> <span class="mono muted">(2026-07-05)</span></p><p>the Dutch NIS2 transposition status this pipeline tracked as &quot;slipped past its 1 July target, Senate vote set for 7 July&quot; has resolved. On 7 July 2026 the Eerste Kamer (First Chamber) passed both the <strong>Cyberbeveiligingswet</strong> (Cbw, the NIS2 transposition) and the companion <strong>Wet weerbaarheid kritieke entiteiten</strong> (Wwke, the CER-directive transposition) — the Tweede Kamer had passed them on 15 April — and &quot;de wetten treden op 15 augustus 2026 in werking&quot; (&quot;the laws enter into force on 15 August 2026&quot;) (<a href="https://www.rijksoverheid.nl/actueel/nieuws/2026/07/07/cyberbeveiligingswet-en-wet-weerbaarheid-kritieke-entiteiten-vanaf-15-augustus-2026-van-kracht" target="_blank" rel="noopener noreferrer">Rijksoverheid.nl, 2026-07-07</a>). The parliamentary vote record confirms broad cross-party support (<a href="https://www.eerstekamer.nl/wetsvoorstel/36764_cyberbeveiligingswet" target="_blank" rel="noopener noreferrer">Eerste Kamer, 2026-07-07</a>). The Cbw covers roughly 8,000 organisations across 18 designated essential/important sectors and imposes a cybersecurity duty of care (including supply-chain risk management), mandatory registration in the NCSC entity register, significant-incident reporting to the relevant CSIRT, and board-level accountability with director training (<a href="https://www.ncsc.nl/nieuws/de-cyberbeveiligingswet-in-laatste-fase-van-vaststelling" target="_blank" rel="noopener noreferrer">NCSC-NL</a>).</p>
<p><strong>Why this matters to the constituency:</strong> beyond direct applicability to any covered Dutch entity, this is a concrete datapoint for the deployment&#39;s standing EU NIS2-transposition watch — a member state moving from indefinite slip to a fixed enforcement date. For Swiss-domiciled organisations with Dutch subsidiaries, NL-incorporated critical suppliers, or cross-border NIS2-equivalent reporting relationships, 15 August 2026 is the operative clock, five weeks out from this brief. The next checkpoint is confirmation the NCSC-NL entity register is live and accepting registrations ahead of the date.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">De wetten treden op 15 augustus 2026 in werking.</p><figcaption class="entry-cite__attr"><a href="https://www.rijksoverheid.nl/actueel/nieuws/2026/07/07/cyberbeveiligingswet-en-wet-weerbaarheid-kritieke-entiteiten-vanaf-15-augustus-2026-van-kracht" target="_blank" rel="noopener noreferrer">Rijksoverheid.nl (Dutch national government)</a></figcaption></figure></div><div class="prov"><span>policy</span><span>12 Jul 23:52Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-netherlands-nis2-in-force/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.rijksoverheid.nl/actueel/nieuws/2026/07/07/cyberbeveiligingswet-en-wet-weerbaarheid-kritieke-entiteiten-vanaf-15-augustus-2026-van-kracht" target="_blank" rel="noopener noreferrer">Rijksoverheid.nl (Dutch national government)</a> · <a href="https://www.eerstekamer.nl/wetsvoorstel/36764_cyberbeveiligingswet" target="_blank" rel="noopener noreferrer">Eerste Kamer der Staten-Generaal</a> · <a href="https://www.ncsc.nl/nieuws/de-cyberbeveiligingswet-in-laatste-fase-van-vaststelling" target="_blank" rel="noopener noreferrer">NCSC-NL</a></div></article>]]></content:encoded></item><item><title>CH/EU government under broad attack this week — Latvia forestry ransomware, Swiss cantonal mailbox compromise, e-gov watering-hole, Ghostwriter phishing</title><link>https://ctipilot.ch/entries/2026-07-12/weekly-w28-government-public-admin-targeting/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-12/weekly-w28-government-public-admin-targeting/</guid><pubDate>Sun, 12 Jul 2026 23:30:00 +0000</pubDate><dc:date>2026-07-12T23:30:00Z</dc:date><category>data-breach</category><category>espionage</category><category>ransomware</category><category>phishing</category><category>switzerland</category><category>europe</category><description><![CDATA[<p>The constituency&#39;s core sector was hit from several directions in 2026-W28: a ransomware crew breached Latvia&#39;s state forestry operator LVM via a two-year-unpatched service (CERT.LV, an EU/NATO-shared-threat framing); Psychiatrische Dienste Aargau (a Swiss cantonal health authority) had email accounts phished and abused as a spam relay; espionage actors weaponised a citizen-facing e-government complaint portal as a watering hole; Armored Likho hit government and electric-power targets with an AI-generated loader; and UNC1151/Ghostwriter ran real-time 2FA-relay Gmail phishing against officials (CERT Polska). The common thread is not one actor but the breadth of pressure on public-sector identity, exposed services and citizen-facing web.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-12/weekly-w28-government-public-admin-targeting" data-tags="data-breach espionage ransomware phishing" data-regions="switzerland europe" data-kind="synthesis" data-priority="high" data-discovered="2026-07-12T23:30:00Z"><div class="badges"><span class="b pri">HIGH</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 1: Confirmed"><span class="k">NATO</span>B1</span></div><h3 class="f-h" id="weekly-w28-government-public-admin-targeting"><a href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-government-public-admin-targeting/">Government and public administration across Switzerland and Europe took a broad spread of attacks this week — ransomware, espionage watering-holes, AI-tooled APTs and credential-phishing</a></h3><p>Government and public administration — the profiled constituency&#39;s core — absorbed an unusually broad spread of activity in 2026-W28, notable less for any single incident than for how many different attack classes landed on the sector in one week.</p>
<p>On the <strong>ransomware</strong> front, CERT.LV disclosed that a crew breached Latvijas Valsts Meži (LVM), Latvia&#39;s state forestry operator, through a service left unpatched for roughly two years, and framed it explicitly as an EU/NATO-shared-threat matter for a state-owned critical operator (<a href="https://cert.lv/lv/2026/06/as-latvijas-valsts-mezi-kiberdrosibas-incidents-aktuala-informacija" target="_blank" rel="noopener noreferrer">CERT.LV, 2026-06</a>). In Switzerland, <strong>Psychiatrische Dienste Aargau (PDAG)</strong>, a cantonal health authority, had staff email accounts compromised via phishing and abused to relay spam — a low-sophistication but high-frequency pattern against public-sector mailboxes (<a href="https://www.swisscybersecurity.net/news/2026-07-09/psychiatrische-dienste-aargau-werden-opfer-eines-phishing-angriffs" target="_blank" rel="noopener noreferrer">SwissCybersecurity.net, 2026-07-09</a>). On the <strong>espionage</strong> axis, SentinelLabs documented converging China- and India-nexus operations weaponising a citizen-facing e-government complaint portal as a watering hole with a CMS implant (<a href="https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/" target="_blank" rel="noopener noreferrer">SentinelLabs, 2026-07-10</a>); Kaspersky profiled <strong>Armored Likho</strong> hitting government and electric-power targets with an AI-generated loader and the BusySnake stealer (<a href="https://securelist.com/tr/armored-likho-apt-with-busysnake-stealer/120292/" target="_blank" rel="noopener noreferrer">Kaspersky Securelist, 2026-07-11</a>); and CERT Polska tracked <strong>UNC1151/Ghostwriter</strong> moving to Gmail with real-time 2FA-relay phishing against officials (<a href="https://cert.pl/en/posts/2026/06/UNC1151-gmail-campaign/" target="_blank" rel="noopener noreferrer">CERT Polska, 2026-06</a>).</p>
<p><strong>Why this is a sector pattern for the constituency:</strong> two of the five strands carry a direct home-region or EU-critical-operator nexus (a Swiss cantonal authority and a Latvian state operator); the e-government watering-hole targeted a Pakistani law-enforcement programme (EU-funded but with no direct European victim nexus) and is carried for its transferable technique, while the remaining two are actors whose targeting profile — government and energy — matches the constituency. The exposed surfaces recur: unpatched internet-facing services, public-sector email identity, and citizen-facing web applications.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the week&#39;s public-sector lesson is coverage of the unglamorous basics — an authoritative patch SLA for internet-facing services (the LVM two-year gap is the cautionary case), phishing-resistant MFA on staff mail to break both spam-relay abuse and 2FA-relay phishing, and integrity monitoring on citizen-facing CMS platforms that make natural watering holes. <strong>Triage:</strong> a compromised public-sector mailbox used as a relay shows a sudden outbound-volume spike and sends to external recipients with no prior correspondence; a watering-hole CMS implant shows unexpected file writes to web-root and template/plugin directories outside a deployment window.</div></aside><p class="entry-references"><strong>Builds on:</strong> <a class="mono" href="https://ctipilot.ch/entries/2026-07-10/cert-lv-lvm-olpha-ransomware-eu-nato-shared-threat/">2026-07-10/cert-lv-lvm-olpha-ransomware-eu-nato-shared-threat</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-09/pdag-aargau-email-account-compromise-spam-relay/">2026-07-09/pdag-aargau-email-account-compromise-spam-relay</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-10/e-government-portal-watering-hole-cms-implant-espionage/">2026-07-10/e-government-portal-watering-hole-cms-implant-espionage</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-11/armored-likho-busysnake-ai-generated-loader-python-stealer/">2026-07-11/armored-likho-busysnake-ai-generated-loader-python-stealer</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-09/unc1151-ghostwriter-gmail-realtime-2fa-phishing/">2026-07-09/unc1151-ghostwriter-gmail-realtime-2fa-phishing</a></p><div class="prov"><span>synthesis</span><span>12 Jul 23:30Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-government-public-admin-targeting/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://cert.lv/lv/2026/06/as-latvijas-valsts-mezi-kiberdrosibas-incidents-aktuala-informacija" target="_blank" rel="noopener noreferrer">CERT.LV</a> · <a href="https://www.swisscybersecurity.net/news/2026-07-09/psychiatrische-dienste-aargau-werden-opfer-eines-phishing-angriffs" target="_blank" rel="noopener noreferrer">SwissCybersecurity.net</a> · <a href="https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/" target="_blank" rel="noopener noreferrer">SentinelLabs</a> · <a href="https://securelist.com/tr/armored-likho-apt-with-busysnake-stealer/120292/" target="_blank" rel="noopener noreferrer">Kaspersky Securelist</a> · <a href="https://cert.pl/en/posts/2026/06/UNC1151-gmail-campaign/" target="_blank" rel="noopener noreferrer">CERT Polska</a></div></article>]]></content:encoded></item><item><title>2026-W28 vuln roll-up — exploited: ColdFusion, CitrixBleed 2, Gitea, Langflow, Joomla wave; notable: HTTP.sys mechanics, KVM escape, Siemens SICAM 8, MOVEit</title><link>https://ctipilot.ch/entries/2026-07-12/weekly-w28-vuln-status-rollup/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-12/weekly-w28-vuln-status-rollup/</guid><pubDate>Sun, 12 Jul 2026 23:26:00 +0000</pubDate><dc:date>2026-07-12T23:26:00Z</dc:date><category>vulnerabilities</category><category>actively-exploited</category><category>cisa-kev</category><category>rce</category><category>priv-esc</category><category>ot-ics</category><category>switzerland</category><category>europe</category><category>global</category><description><![CDATA[<p>Consolidated status view of the week&#39;s vulnerabilities that demand action beyond the routine patch cycle. Confirmed exploited / KEV this week: Adobe ColdFusion CVE-2026-48282, Citrix NetScaler CitrixBleed 2 CVE-2025-5777, Gitea CVE-2026-20896, Langflow CVE-2026-55255, and the Joomla extension file-upload wave (CVE-2026-48908/56290/56291/48939). Public-exploit or full-mechanics disclosures raising urgency without confirmed ITW use: GhostLock Linux kernel LPE CVE-2026-43499 (public reliable exploit), Windows HTTP.sys CVE-2026-47291 (ZDI published exploitation mechanics), Linux KVM &#39;Januscape&#39; CVE-2026-53359 (guest-to-host escape), BeyondTrust RS/PRA CVE-2026-40138 cluster. OT/CI note: Siemens SICAM 8 grid RTU firmware-signing bypass (CVE-2026-54798-801). See the linked operational entries for per-CVE detail.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-12/weekly-w28-vuln-status-rollup" data-tags="vulnerabilities actively-exploited cisa-kev rce priv-esc ot-ics" data-regions="switzerland europe global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-07-12T23:26:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b exp">exploited</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 1: Confirmed"><span class="k">NATO</span>B1</span></div><h3 class="f-h" id="weekly-w28-vuln-status-rollup"><a href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-vuln-status-rollup/">Vulnerability status roll-up — 2026-W28: what moved into exploitation, what reached KEV, and what to patch out-of-band</a></h3><p>This roll-up consolidates the 2026-W28 vulnerabilities that cross the out-of-band-action bar — actively exploited, at imminent mass exploitation, or otherwise demanding a response the routine monthly cycle does not give. Per-CVE facts, CVSS, and affected/fixed versions live in the linked operational entries; this entry is the status trajectory a reader uses to sequence the week&#39;s patching.</p>
<p><strong>Confirmed exploited / on CISA KEV this week.</strong> <em>Adobe ColdFusion</em> CVE-2026-48282 (one of the 1 July CVSS 10.0 unauthenticated RCEs) — exploited within two hours of public detail, KEV-listed 7 July (<a href="https://www.bleepingcomputer.com/news/security/max-severity-adobe-coldfusion-flaw-now-exploited-in-attacks/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-07-08</a>). <em>Citrix NetScaler</em> CitrixBleed 2 CVE-2025-5777 — weaponised into a repeatable initial-access-broker kill chain ending in DragonForce ransomware; patch plus session termination required. <em>Gitea</em> CVE-2026-20896 — NCSC-CH escalated to &quot;Actively Exploited, Proof of Concept Available&quot; (<a href="https://security-hub.ncsc.admin.ch/#/posts/12755" target="_blank" rel="noopener noreferrer">NCSC-CH, 2026-07-10</a>). <em>Langflow</em> CVE-2026-55255 — cross-tenant IDOR chained with pre-auth RCE, first exploited 25 June, now KEV. <em>Joomla extension file-upload wave</em> — CVE-2026-48908 / 56290 / 56291 / 48939 exploited as zero-days (see the dedicated top-story), CVE-2026-57827/57828 patched without confirmed exploitation yet.</p>
<p><strong>Urgency raised by public exploit or full mechanics, no confirmed ITW use.</strong> <em>GhostLock</em> CVE-2026-43499 — Linux kernel rtmutex use-after-free with a public ~97%-reliable local-privilege-escalation exploit. <em>Windows HTTP.sys</em> CVE-2026-47291 (pre-auth RCE, CVSS 9.8) — ZDI published full exploitation mechanics for the June Patch Tuesday flaw, collapsing the reverse-engineering barrier. <em>Linux KVM/x86 &#39;Januscape&#39;</em> CVE-2026-53359 — shadow-MMU use-after-free enabling guest-to-host VM escape, relevant to multi-tenant virtualisation. <em>BeyondTrust Remote Support / Privileged Remote Access</em> — the CVE-2026-40138 pre-auth bypass cluster on a remote-access product class that is itself a high-value target.</p>
<p><strong>OT / critical-infrastructure note.</strong> <em>Siemens SICAM 8</em> grid RTUs (A8000/EGS/S8000) — a firmware-signature-validation bypass (CVE-2026-54798-801) on devices deployed in European energy grids; slow patch cycles make network isolation and OT-segment monitoring the near-term control. <em>Progress MOVEit Transfer</em> — pre-auth SFTP DoS (CVE-2026-10699) plus admin scope-bypass fixes, notable given MOVEit&#39;s history as a mass-exfiltration target.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">sequence by exploitation evidence, then exposure — the KEV/exploited set above is this week&#39;s out-of-band queue; the public-exploit set is next in line before it is weaponised; the OT items are isolate-and-monitor where an immediate patch is impractical.</div></aside><p class="entry-references"><strong>Builds on:</strong> <a class="mono" href="https://ctipilot.ch/entries/2026-07-08/cve-2026-48282-adobe-coldfusion-actively-exploited-kev/">2026-07-08/cve-2026-48282-adobe-coldfusion-actively-exploited-kev</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725/">2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-10/gitea-cve-2026-20896-ncsc-ch-actively-exploited-update/">2026-07-10/gitea-cve-2026-20896-ncsc-ch-actively-exploited-update</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-08/cve-2026-55255-langflow-idor-kev-chained-with-rce/">2026-07-08/cve-2026-55255-langflow-idor-kev-chained-with-rce</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-08/ghostlock-cve-2026-43499-linux-kernel-rtmutex-uaf-lpe/">2026-07-08/ghostlock-cve-2026-43499-linux-kernel-rtmutex-uaf-lpe</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-11/cve-2026-47291-httpsys-zdi-exploitation-mechanics/">2026-07-11/cve-2026-47291-httpsys-zdi-exploitation-mechanics</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-09/cve-2026-53359-januscape-kvm-x86-guest-to-host-vm-escape/">2026-07-09/cve-2026-53359-januscape-kvm-x86-guest-to-host-vm-escape</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-08/beyondtrust-rs-pra-preauth-bypass-cve-2026-40138-cluster/">2026-07-08/beyondtrust-rs-pra-preauth-bypass-cve-2026-40138-cluster</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-10/siemens-sicam-8-ssa-229470-firmware-signing-bypass/">2026-07-10/siemens-sicam-8-ssa-229470-firmware-signing-bypass</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-11/moveit-transfer-certfr-cve-2026-10699-10698-11903/">2026-07-11/moveit-transfer-certfr-cve-2026-10699-10698-11903</a></p><div class="prov"><span>vulnerability</span><span>12 Jul 23:26Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-vuln-status-rollup/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bleepingcomputer.com/news/security/max-severity-adobe-coldfusion-flaw-now-exploited-in-attacks/" target="_blank" rel="noopener noreferrer">BleepingComputer</a> · <a href="https://security-hub.ncsc.admin.ch/#/posts/12755" target="_blank" rel="noopener noreferrer">NCSC-CH Cyber Security Hub</a></div></article>]]></content:encoded></item><item><title>Kaspersky names Armored Likho — spear-phishing into an LLM-written loader chain that stages a full Python runtime and a PyArmor-protected stealer</title><link>https://ctipilot.ch/entries/2026-07-11/armored-likho-busysnake-ai-generated-loader-python-stealer/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-11/armored-likho-busysnake-ai-generated-loader-python-stealer/</guid><pubDate>Sat, 11 Jul 2026 17:40:00 +0000</pubDate><dc:date>2026-07-11T17:40:00Z</dc:date><category>espionage</category><category>phishing</category><category>infostealer</category><category>ai-abuse</category><category>russia-cis</category><category>latam</category><description><![CDATA[<p>Kaspersky documented (2026-07-03) Armored Likho (aka Eagle Werewolf), a previously unknown APT targeting government agencies and the electric-power sector across Russia, Brazil and Kazakhstan. Spear-phishing delivers an NSIS dropper or a ZDI-CAN-25373 LNK lure whose loader — assessed as LLM-generated — stages a bundled Python 3.12 runtime and the PyArmor-protected BusySnake Stealer from rotating GitHub repositories. Campaign active at publication; concrete low-noise hunt pivots exist. Published as an audit-recovered item: the primary fell inside the 2026-07-07 scheduler outage&#39;s backfill blind spot.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-11/armored-likho-busysnake-ai-generated-loader-python-stealer" data-tags="espionage phishing infostealer ai-abuse" data-regions="russia-cis latam" data-kind="threat" data-priority="notable" data-discovered="2026-07-11T17:40:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 3: Possibly true"><span class="k">NATO</span>B3</span></div><h3 class="f-h" id="armored-likho-busysnake-ai-generated-loader-python-stealer"><a href="https://ctipilot.ch/entries/2026-07-11/armored-likho-busysnake-ai-generated-loader-python-stealer/">Armored Likho: new APT hits government and electric-power targets with an AI-generated loader and the Python &#39;BusySnake&#39; stealer</a></h3><p>Kaspersky&#39;s threat-monitoring team published a full analysis of a previously unknown APT it dubs Armored Likho (also tracked, on circumstantial evidence, as Eagle Werewolf), which mixes financially motivated campaigns against individuals with targeted espionage against organizations — the current campaign, still active at publication, concentrates on government agencies and electric-power-sector organizations in Russia, Brazil and Kazakhstan (<a href="https://securelist.com/tr/armored-likho-apt-with-busysnake-stealer/120292/" target="_blank" rel="noopener noreferrer">Kaspersky Securelist, 2026-07-03</a>). Initial access is spear-phishing with government-notice and social-program themes carrying archive attachments. One variant drops an NSIS self-extracting dropper that shows a decoy &quot;psychological test&quot; survey, writes a legitimate <code>pnx.exe</code> to a temp directory and injects loader code into its process memory; the other abuses the ZDI-CAN-25373 Windows shortcut-display weakness — whitespace/line-break padding that hides the LNK&#39;s real command line from the user — to launch obfuscated PowerShell. Both paths converge on a loader that Kaspersky assesses was written by an LLM (verbose comments and bullet-point emojis &quot;highly uncharacteristic of human-developed malware&quot;) — a concrete case of AI-generated first-stage tooling blurring the actor&#39;s TTP fingerprint and complicating attribution (<a href="https://securelist.com/tr/armored-likho-apt-with-busysnake-stealer/120292/" target="_blank" rel="noopener noreferrer">Kaspersky Securelist, 2026-07-03</a>).</p>
<p>The loader pulls its payload packages from attacker-controlled GitHub repositories whose contents and names rotate automatically, then stages everything under <code>%APPDATA%\WindowsHelper</code>: a bundled Python 3.12 interpreter, <code>get-pip.py</code> for dependency installation, and the primary payload <code>module.pyw</code> — BusySnake Stealer, a Python infostealer obfuscated with PyArmor Pro 9.2.0 that decrypts each function&#39;s bytecode only at call time and re-encrypts it afterward. Persistence is a VBScript launcher (<code>run.vbs</code>) registered as a scheduled task re-executing the payload every five minutes; a companion <code>wh_selfdelete.vbs</code> wipes the initial loader. On tasking from its C2, the stealer harvests Chromium credentials via DPAPI and Firefox credentials via <code>PK11SDR_Decrypt</code>, steals browser cookies (in one command variant by installing a browser extension), scrapes the clipboard and local files for 64-character hex keys and <code>otpauth://</code> OTP seeds, inventories and exfiltrates user documents under 5 MB, captures screenshots, packages Telegram <code>tdata</code> session stores after force-killing <code>telegram.exe</code>, hunts cryptocurrency-wallet JSON files, opens a reverse-SSH tunnel with a C2-supplied key, and abuses RustDesk — downloading it if absent, or restarting it to make the user re-enter their ID/password while screenshotting the credentials (<a href="https://securelist.com/tr/armored-likho-apt-with-busysnake-stealer/120292/" target="_blank" rel="noopener noreferrer">Kaspersky Securelist, 2026-07-03</a>).</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the chain is long but noisy in telemetry classes most estates already collect. In process-creation telemetry, alert on script interpreters or unknown binaries spawning a bundled/user-writable Python interpreter (<code>python.exe</code>/<code>pythonw.exe</code> executing from <code>%APPDATA%</code>), on <code>.pyw</code> files registered in scheduled tasks, and on <code>wscript.exe</code> launching from <code>%APPDATA%\WindowsHelper</code>-style working directories; in network telemetry, surface hosts fetching archives from GitHub release repositories outside development context, and outbound SSH from hosts with no SSH business. <strong>Triage:</strong> developer machines legitimately run user-installed Python — the discriminators are the scheduled-task-driven five-minute re-execution cadence, the interpreter living under <code>%APPDATA%</code> rather than a managed install path, and RustDesk (re)starts the user did not initiate; any one alone is weak, the combination is the signal. For the profiled constituency this is transferable tradecraft knowledge, not an active home-region threat — no Swiss or EU targeting is reported.</div></aside>
<p><em>Provenance note: this entry was published by the 2026-07-11 full-store quality audit, which found the item had fallen into the 2026-07-07 scheduler outage&#39;s backfill blind spot (research-blog publications do not route through the KEV/CERT catch-up paths the backfill run swept — pipeline fix shipped as prompts v3.21).</em></p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">This targeted campaign focuses heavily on government agencies and the electric power sector. The geographical footprint of these attacks spans Russia, Brazil, and Kazakhstan, establishing the group as a global threat actor.</p><p class="entry-cite__quote">This coding style is highly uncharacteristic of human-developed malware. It strongly indicates that the group is leveraging LLMs to generate their malicious payloads.</p><figcaption class="entry-cite__attr"><a href="https://securelist.com/tr/armored-likho-apt-with-busysnake-stealer/120292/" target="_blank" rel="noopener noreferrer">Kaspersky Securelist</a> <span class="entry-cite__date mono">2026-07-03</span></figcaption></figure></div><div class="prov"><span>threat</span><span>11 Jul 17:40Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-11/armored-likho-busysnake-ai-generated-loader-python-stealer/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://securelist.com/tr/armored-likho-apt-with-busysnake-stealer/120292/" target="_blank" rel="noopener noreferrer">Kaspersky Securelist</a></div></article>]]></content:encoded></item><item><title>Symantec: a driver built malicious from the outset — yet WHCP-signed — defeats code-signing allowlisting to kill EDR before GodDamn encrypts</title><link>https://ctipilot.ch/entries/2026-07-11/goddamn-ransomware-poisonx-microsoft-signed-driver/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-11/goddamn-ransomware-poisonx-microsoft-signed-driver/</guid><pubDate>Sat, 11 Jul 2026 04:30:43 +0000</pubDate><dc:date>2026-07-11T04:30:43Z</dc:date><category>ransomware</category><category>organized-crime</category><category>identity</category><category>global</category><description><![CDATA[<p>Symantec attributes GodDamn ransomware (first seen 2026-05-21) to the Hyadina developer behind the Monster→Beast lineage, and documents a June 2026 intrusion where the operators loaded PoisonX (g11.sys) — a kernel driver they got signed under Microsoft&#39;s Windows Hardware Compatibility Publisher program despite it being malicious by design — to terminate security processes and strip user-mode API hooks before encrypting. The signed-malicious-driver twist means code-signing allowlisting will not stop it; detection must be behavioural.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-11/goddamn-ransomware-poisonx-microsoft-signed-driver" data-tags="ransomware organized-crime identity" data-regions="global" data-kind="threat" data-priority="notable" data-discovered="2026-07-11T04:30:43Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="goddamn-ransomware-poisonx-microsoft-signed-driver"><a href="https://ctipilot.ch/entries/2026-07-11/goddamn-ransomware-poisonx-microsoft-signed-driver/">GodDamn ransomware (Beast/Monster rebrand) blinds EDR with &#39;PoisonX&#39;, a malicious kernel driver Microsoft signed</a></h3><p>Symantec&#39;s Threat Hunter Team assesses that GodDamn — surfaced as a &quot;new&quot; ransomware, first observed 2026-05-21 — is the latest rebrand in a lineage it tracks to a developer called Hyadina: Monster (2022) → Beast → GodDamn, the last sharing significant code overlap with Beast (<a href="https://www.security.com/threat-intelligence/goddamn-ransomware-beast-rebrand" target="_blank" rel="noopener noreferrer">Symantec/Broadcom, 2026-07-09</a>). The investigated early-June intrusion is a conventional human-operated ransomware kill chain with one standout component. AnyDesk appeared on the first host staged under the user&#39;s Music folder — a placement Symantec reads as manual attacker delivery, not a normal install — and began beaconing to relay infrastructure. The operators then dropped a defence-evasion binary masquerading as a Symantec product, which installed the PoisonX kernel driver (<code>g11.sys</code>) into the system driver store, staged a 14-tool credential-harvesting kit (13 NirSoft utilities plus Mimikatz) under the profile, moved laterally across 10-plus hosts via PsExec while re-installing AnyDesk on each for unattended access (writing <code>ad.security.interactive_access=2</code> to suppress the consent prompt and registering it as auto-start services), disabled Windows Defender real-time monitoring, and finally deployed the encrypter (<a href="https://www.security.com/threat-intelligence/goddamn-ransomware-beast-rebrand" target="_blank" rel="noopener noreferrer">Symantec/Broadcom, 2026-07-09</a>; <a href="https://thehackernews.com/2026/07/goddamn-ransomware-uses-poisonx-driver.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-07-09</a>).</p>
<p>PoisonX is what distinguishes this case from routine bring-your-own-vulnerable-driver tradecraft. Rather than abusing a flaw in a legitimate signed driver, PoisonX is a driver built to be malicious that its developers nonetheless got signed under Microsoft&#39;s &quot;Windows Hardware Compatibility Publisher&quot; program; once loaded it terminates security-product processes and strips user-mode API hooks, so it disables EDR visibility rather than merely evading it. It was first documented earlier in 2026 killing the CrowdStrike Falcon service via a crafted IOCTL to an undocumented driver interface (<a href="https://www.security.com/threat-intelligence/goddamn-ransomware-beast-rebrand" target="_blank" rel="noopener noreferrer">Symantec/Broadcom, 2026-07-09</a>).</p><aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">because the driver carries a valid Microsoft signature, code-signing allowlists and reputation checks pass it — detection has to be behavioural. <strong>Triage:</strong> legitimate driver installs do not co-occur with mass termination of security services, so the load of a rarely-seen driver immediately followed by security-product process/service stops and the loss of user-mode hooks on the same host is the discriminator; AnyDesk running from a personal media folder (versus IT-managed Program Files) and configured for unattended access is a second, independent pivot.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">the PoisonX driver seems to be slightly more unusual, in that it appears to be a malicious driver that its developers succeeded in getting signed by Microsoft, and it is now being used by ransomware attackers.</p><p class="entry-cite__quote">Placing AnyDesk under the user Music folder rather than a standard installation directory is consistent with manual delivery by an attacker who had already obtained access to the host by an earlier means.</p><figcaption class="entry-cite__attr"><a href="https://www.security.com/threat-intelligence/goddamn-ransomware-beast-rebrand" target="_blank" rel="noopener noreferrer">Symantec Threat Hunter Team (Broadcom)</a> <span class="entry-cite__date mono">2026-07-09</span></figcaption></figure></div><div class="prov"><span>threat</span><span>11 Jul 04:30Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-11/goddamn-ransomware-poisonx-microsoft-signed-driver/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.security.com/threat-intelligence/goddamn-ransomware-beast-rebrand" target="_blank" rel="noopener noreferrer">Symantec Threat Hunter Team (Broadcom)</a> · <a href="https://thehackernews.com/2026/07/goddamn-ransomware-uses-poisonx-driver.html" target="_blank" rel="noopener noreferrer">The Hacker News</a> · <a href="https://www.infosecurity-magazine.com/news/ransomware-removes-cybersecurity/" target="_blank" rel="noopener noreferrer">Infosecurity Magazine</a></div></article>]]></content:encoded></item><item><title>Microsoft dissects GigaWiper — destruction dressed as extortion, driven over RabbitMQ/Redis/MinIO with an &#39;OneDrive Update&#39; persistence tell</title><link>https://ctipilot.ch/entries/2026-07-11/gigawiper-golang-destructive-backdoor-modular-wiper/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-11/gigawiper-golang-destructive-backdoor-modular-wiper/</guid><pubDate>Sat, 11 Jul 2026 04:30:43 +0000</pubDate><dc:date>2026-07-11T04:30:43Z</dc:date><category>wiper</category><category>ransomware</category><category>nation-state</category><category>infostealer</category><category>global</category><description><![CDATA[<p>Microsoft Threat Intelligence documented GigaWiper (2026-07-09), a Go destructive backdoor that combines a raw-disk wiper, a Crucio-derived encryptor whose keys are never saved, and a FlockWiper-derived secure-wipe module as on-demand commands, tasked over RabbitMQ/Redis with MinIO exfiltration. First seen October 2025; concrete low-noise hunt pivots exist. Relevant to any Windows critical-infrastructure estate as transferable destructive tradecraft.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-11/gigawiper-golang-destructive-backdoor-modular-wiper" data-tags="wiper ransomware nation-state infostealer" data-regions="global" data-kind="threat" data-priority="notable" data-discovered="2026-07-11T04:30:43Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="gigawiper-golang-destructive-backdoor-modular-wiper"><a href="https://ctipilot.ch/entries/2026-07-11/gigawiper-golang-destructive-backdoor-modular-wiper/">GigaWiper: a Golang backdoor that folds a disk wiper, fake-ransomware encryptor and secure-wipe module into one modular implant</a></h3><p>Microsoft Threat Intelligence first identified GigaWiper in October 2025 and has now published a code-level analysis of it: a Golang backdoor notable less for any single capability than for its construction — at least three previously separate destructive families folded into one implant as on-demand commands, so an operator can pick the mode of destruction at task time (<a href="https://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malware/" target="_blank" rel="noopener noreferrer">Microsoft Threat Intelligence, 2026-07-09</a>). The raw-disk wiper command enumerates physical drives over WMI, identifies and spares the Windows installation drive, strips partition metadata from the other drives via <code>DeviceIoControl</code>/<code>IOCTL_DISK_CREATE_DISK</code>, overwrites disk content in 0xA00000-byte chunks (randomising only the first byte of each buffer to dodge naïve all-zero-wipe detections), then forces an immediate reboot. A second command reuses Crucio ransomware code to AES-encrypt files with per-run keys that are never saved and drops no ransom note — destruction wearing an extortion costume — while a third reimplements the C-based FlockWiper in Go for multi-pass secure wiping of the Windows drive. Microsoft ties the families together by code overlap and assesses that the same developer built GigaWiper and Crucio; it withholds actor attribution beyond that lineage. Google&#39;s Threat Intelligence Group and Binary Defense track the same activity as BLUERABBIT (<a href="https://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malware/" target="_blank" rel="noopener noreferrer">Microsoft Threat Intelligence, 2026-07-09</a>; <a href="https://www.infosecurity-magazine.com/news/new-gigawiper-espionage-destructive/" target="_blank" rel="noopener noreferrer">Infosecurity Magazine, 2026-07-10</a>).</p>
<p>Operationally the implant is quieter than its payload. It persists as a scheduled task named <code>OneDrive Update</code> (configured to run roughly every minute and once at startup) and tracks its own execution count in a <code>HKCU\SOFTWARE\OneDrive\Environment</code> registry value, masquerading as Microsoft&#39;s sync client. For command-and-control it skips ordinary HTTP: tasking arrives over RabbitMQ/AMQP — a fanout exchange named <code>All</code> for broadcast to every infected client plus a topic exchange for targeted commands — status and output are polled back through a Redis server, and MinIO object storage carries exfiltration, alongside keylogging and screen-capture modules.</p><aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the persistence footprint and the C2 protocol mix are both high-value, low-false-positive hunt anchors — legitimate OneDrive never lives under that task name or registry path, and a standard workstation has no reason to speak AMQP, Redis and MinIO outbound. <strong>Triage:</strong> genuine OneDrive does run scheduled sync tasks, so the discriminator is the exact task name (<code>OneDrive Update</code>) and the <code>HKCU\SOFTWARE\OneDrive\Environment</code> key rather than the presence of a OneDrive-named task per se; pair that with outbound RabbitMQ/Redis/MinIO from a host with no such workload and the two together are the signal. Because the encryptor discards its keys, defence is recovery-first: this is a data-destruction threat, and the only meaningful mitigation for an exposed Windows estate is tested, offline backups.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">It&#39;s not a single, purpose-built tool, but an amalgamation of separate malware families that were folded into GigaWiper as on-demand backdoor commands, giving threat actors the flexibility to choose their mode of destruction</p><p class="entry-cite__quote">The key and initialization vector (IV) that the malware uses to encrypt files are random and are not saved anywhere</p><figcaption class="entry-cite__attr"><a href="https://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malware/" target="_blank" rel="noopener noreferrer">Microsoft Threat Intelligence</a> <span class="entry-cite__date mono">2026-07-09</span></figcaption></figure></div><div class="prov"><span>threat</span><span>11 Jul 04:30Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-11/gigawiper-golang-destructive-backdoor-modular-wiper/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malware/" target="_blank" rel="noopener noreferrer">Microsoft Threat Intelligence</a> · <a href="https://www.infosecurity-magazine.com/news/new-gigawiper-espionage-destructive/" target="_blank" rel="noopener noreferrer">Infosecurity Magazine</a></div></article>]]></content:encoded></item><item><title>ZDI details the HTTP.sys integer-overflow trigger — weaponisation bar drops for a pre-auth RCE reachable on any IIS/HTTPS listener</title><link>https://ctipilot.ch/entries/2026-07-11/cve-2026-47291-httpsys-zdi-exploitation-mechanics/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-11/cve-2026-47291-httpsys-zdi-exploitation-mechanics/</guid><pubDate>Sat, 11 Jul 2026 04:30:43 +0000</pubDate><dc:date>2026-07-11T04:30:43Z</dc:date><category>vulnerabilities</category><category>rce</category><category>pre-auth</category><category>poc-public</category><category>global</category><category>poc-public</category><category>patch-available</category><category>CVE-2026-47291</category><description><![CDATA[<p>Zero Day Initiative published a full technical write-up (2026-07-10) of CVE-2026-47291, the HTTP.sys pre-auth kernel RCE patched in Microsoft&#39;s June 2026 cycle, documenting the exact integer-overflow arithmetic and the TLS-record-fragmentation trigger. Not yet exploited in the wild, but the mechanics — and a concrete network-detection heuristic — are now public, so anyone running an internet-facing IIS/HTTPS listener that missed the June patch should treat it as newly weaponisable.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-11/cve-2026-47291-httpsys-zdi-exploitation-mechanics" data-tags="vulnerabilities rce pre-auth poc-public" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-07-11T04:30:43Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-47291/">CVE-2026-47291</a><span class="b upd">update</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="cve-2026-47291-httpsys-zdi-exploitation-mechanics"><a href="https://ctipilot.ch/entries/2026-07-11/cve-2026-47291-httpsys-zdi-exploitation-mechanics/">CVE-2026-47291 — Windows HTTP.sys pre-auth RCE (CVSS 9.8): ZDI publishes full exploitation mechanics and a detection signature</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-06-10/cve-2026-47291-microsoft-june-patch-tuesday-http-sys-pre-aut/">CVE-2026-47291 — Microsoft June Patch Tuesday: HTTP.sys pre-auth RCE (CVSS 9.8) headlines the largest-ever release (198 CVEs)</a> <span class="mono muted">(2026-06-10)</span></p><p>CVE-2026-47291 shipped in the June 2026 Patch Tuesday as a headline pre-auth RCE in HTTP.sys, the kernel-mode HTTP driver that terminates HTTP/1.x and TLS for IIS and every service built on the HTTP Server API. The delta is a full exploitation write-up from Zero Day Initiative&#39;s TrendAI Research team, published a month after the patch, that documents the precise defect and trigger and materially lowers the weaponisation bar (<a href="https://www.zerodayinitiative.com/blog/2026/7/9/cve-2026-47291-remote-code-execution-in-the-windows-httpsys" target="_blank" rel="noopener noreferrer">Zero Day Initiative, 2026-07-10</a>).</p>
<p>The bug is a 16-bit integer overflow in the buffer-reference array that HTTP.sys grows while parsing HTTP/1.x headers: the capacity counter is incremented by five on each growth without a bounds check, and after 13,107 growths it reaches <code>0xFFFB</code>, so the next increment wraps to <code>0x0000</code>; the subsequent reference addition then allocates a 40-byte buffer but <code>memmove</code>s roughly 524,256 bytes into it — a ~500 KB kernel-pool heap overflow. Because SChannel delivers each TLS record to the parser as its own buffer, an attacker who places exactly one header line per TLS application-data record establishes a 1:1 record-to-reference correspondence and drives the counter to overflow with a single ~262 KB request. Successful exploitation crashes the box (kernel memory-access exception) and, under favourable pool layout, can execute code in kernel context. Critically, the path is reachable only via HTTP/1.x-over-TLS — HTTP/2 and HTTP/3 use a different parser and are unaffected (<a href="https://www.zerodayinitiative.com/blog/2026/7/9/cve-2026-47291-remote-code-execution-in-the-windows-httpsys" target="_blank" rel="noopener noreferrer">Zero Day Initiative, 2026-07-10</a>).</p>
<p>The write-up also corrects the exposure picture the original advisory left fuzzy: the default <code>MaxRequestBytes</code> of 16,384 bytes caps a request at roughly 4,000 header lines — far short of the ~65,536 references needed — so only hosts that raised <code>MaxRequestBytes</code> to at least 262,144 bytes can be driven to the overflow. Microsoft rates the CVE &quot;Exploitation More Likely&quot;; no in-the-wild exploitation is reported as of ZDI&#39;s publication (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47291" target="_blank" rel="noopener noreferrer">Microsoft MSRC, 2026-06-09</a>).</p><aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the patch remains the only reliable fix, but the newly-public mechanics hand defenders a durable network signature — a single HTTP/1.x request bearing more than ~1,000 header lines (visible with TLS inspection), or an HTTPS connection emitting more than ~1,000 tiny TLS records over ~11 minutes (visible without decryption). <strong>Triage:</strong> ordinary browsers and proxies coalesce headers into a few records and never approach that line count, so a single long-lived HTTPS connection feeding one IIS/HTTP.sys request with hundreds-to-thousands of one-line TLS records is the discriminator; a kernel bugcheck on an internet-facing IIS box following such traffic warrants triage against this CVE.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">The vulnerability is only reachable through HTTP/1.x header parsing over TLS connections. HTTP/2 and HTTP/3 use different parser paths that do not interact with the buffer reference array.</p><p class="entry-cite__quote">If the number of header field lines in a single request exceeds 1,000, the traffic should be considered suspicious; an attack exploiting this vulnerability is likely underway.</p><figcaption class="entry-cite__attr">Zero Day Initiative</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>11 Jul 04:30Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-11/cve-2026-47291-httpsys-zdi-exploitation-mechanics/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.zerodayinitiative.com/blog/2026/7/9/cve-2026-47291-remote-code-execution-in-the-windows-httpsys" target="_blank" rel="noopener noreferrer">Zero Day Initiative (Trend Micro)</a> · <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47291" target="_blank" rel="noopener noreferrer">Microsoft MSRC</a></div></article>]]></content:encoded></item><item><title>Siemens patches a firmware-signing bypass and an insecure OPC UA default in SICAM 8 grid-protection controllers — plan the out-of-band OT update</title><link>https://ctipilot.ch/entries/2026-07-10/siemens-sicam-8-ssa-229470-firmware-signing-bypass/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-10/siemens-sicam-8-ssa-229470-firmware-signing-bypass/</guid><pubDate>Fri, 10 Jul 2026 20:34:32 +0000</pubDate><dc:date>2026-07-10T20:34:32Z</dc:date><category>vulnerabilities</category><category>ot-ics</category><category>priv-esc</category><category>auth-bypass</category><category>patch-available</category><category>europe</category><category>global</category><category>patch-available</category><category>CVE-2026-54799</category><category>CVE-2026-54801</category><category>CVE-2026-54800</category><category>CVE-2026-54798</category><description><![CDATA[<p>Siemens ProductCERT advisory SSA-229470 (2026-07-09), republished in-window by CERT-FR/ANSSI as CERTFR-2026-AVI-0860, patches four vulnerabilities in the CPCI85 and SICORE firmware of SICAM A8000, SICAM EGS and SICAM S8000 remote terminal units — controllers Siemens frames for transmission and distribution system operators. The most consequential are a firmware-update signature-validation flaw enabling persistent malicious firmware and an OPC UA default configuration that disables all OPC UA security. No exploitation is reported. Energy-sector operators running SICAM 8 should schedule the V26.20 firmware update and review OPC UA exposure.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-10/siemens-sicam-8-ssa-229470-firmware-signing-bypass" data-tags="vulnerabilities ot-ics priv-esc auth-bypass patch-available" data-regions="europe global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-07-10T20:34:32Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-54799/">CVE-2026-54799 +3</a><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 2: Probably true"><span class="k">NATO</span>A2</span></div><h3 class="f-h" id="siemens-sicam-8-ssa-229470-firmware-signing-bypass"><a href="https://ctipilot.ch/entries/2026-07-10/siemens-sicam-8-ssa-229470-firmware-signing-bypass/">Siemens SICAM 8 (A8000/EGS/S8000) grid RTUs: firmware-signature-validation bypass + OPC-UA-off-by-default among four CVEs (SSA-229470)</a></h3><p>Siemens ProductCERT&#39;s SSA-229470 covers four flaws in the SICORE base system and CPCI85 central processing/communication firmware that underpin the SICAM A8000 (CP-8010/CP-8012 on SICORE; CP-8031/CP-8050 on CPCI85), SICAM EGS (CPCI85) and SICAM S8000 (SICORE) remote terminal units (<a href="https://cert-portal.siemens.com/productcert/html/ssa-229470.html" target="_blank" rel="noopener noreferrer">Siemens ProductCERT, 2026-07-09</a>). The advisory&#39;s stated aggregate impact is denial of service, but the individual issues span further: CVE-2026-54799 (CVSS v3.1 6.7, AV:L/PR:H) is a firmware-update signature-validation flaw that lets an attacker who already holds high privileges install malicious firmware for persistent code execution; CVE-2026-54801 (v3.1 7.2) lets an authenticated attacker bypass credential validation when the web API processes administrative-account modifications and gain elevated privileges; CVE-2026-54800 (v3.1 4.8) is an insecure default that disables all OPC UA security, letting a network attacker reach control functions; and CVE-2026-54798 (v3.1 6.5) is an HTTP-reachable debug interface an authenticated attacker can use to crash the web process. All are fixed in CPCI85 V26.20 / SICORE V26.20.0. CERT-FR/ANSSI republished the advisory the next day as CERTFR-2026-AVI-0860, giving European energy-sector operators a home-region authority citation (<a href="https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0860/" target="_blank" rel="noopener noreferrer">CERT-FR/ANSSI, 2026-07-10</a>).</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">none of the four is a remote pre-authentication vector — the firmware-signing bypass requires prior high privilege on the device and the admin-API and debug flaws require authentication — so this is a defence-in-depth and supply-chain-integrity concern for grid-protection equipment rather than an emergency, but SICAM 8 sits on the power-grid boundary at TSOs and DSOs across Europe including Switzerland, where firmware updates are inherently planned out-of-band events rather than routine patch-cycle work. The load-bearing exposure to close proactively is CVE-2026-54800: because OPC UA security is off in the shipped configuration, any SICAM 8 device whose OPC UA interface is reachable from a less-trusted network segment is exposed to unauthorized control-function access without exploiting anything — a configuration review, not a patch, closes that one immediately. Siemens&#39; own guidance stresses that grid resilience through redundant secondary protection schemes limits the reliability impact of any single compromised controller.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">The affected application contains a vulnerability in its firmware update mechanism&#39;s signature validation process. This could allow an attacker to install malicious firmware, leading to persistent code execution and system compromise.</p><p class="entry-cite__quote">The affected application ships with a default configuration that disables all OPC UA security mechanisms. This could allow an attacker to gain unauthorized access and control over critical system functions.</p><figcaption class="entry-cite__attr"><a href="https://cert-portal.siemens.com/productcert/html/ssa-229470.html" target="_blank" rel="noopener noreferrer">Siemens ProductCERT (SSA-229470)</a> <span class="entry-cite__date mono">2026-07-09</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>10 Jul 20:34Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-10/siemens-sicam-8-ssa-229470-firmware-signing-bypass/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://cert-portal.siemens.com/productcert/html/ssa-229470.html" target="_blank" rel="noopener noreferrer">Siemens ProductCERT (SSA-229470)</a> · <a href="https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0860/" target="_blank" rel="noopener noreferrer">CERT-FR / ANSSI</a></div></article>]]></content:encoded></item><item><title>SANS ISC: a phishing page pads itself with ~430k repeated characters to dilute the payload below an AI classifier&#39;s threshold or exhaust an LLM&#39;s token budget</title><link>https://ctipilot.ch/entries/2026-07-10/comment-stuffing-html-phishing-ai-email-scanner-evasion/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-10/comment-stuffing-html-phishing-ai-email-scanner-evasion/</guid><pubDate>Fri, 10 Jul 2026 12:53:00 +0000</pubDate><dc:date>2026-07-10T12:53:00Z</dc:date><category>phishing</category><category>ai-abuse</category><category>global</category><description><![CDATA[<p>A SANS Internet Storm Center diary analysed a phishing email whose HTML attachment was ~2.5 MB but whose functional credential-harvesting payload was only ~11 KB — the remainder a single HTML comment of ~430,000 repeated &quot;X&quot; characters placed after the payload. The analyst assesses the padding is aimed at AI/NLP-based email security: either diluting the malicious content&#39;s statistical weight until a probability classifier drops below its flag threshold, or inflating the token count until an LLM-based scanner exceeds its per-message time/size budget and cuts analysis short. The concept matters as AI content-scoring spreads across public-sector mail gateways; the defence is a non-AI fallback rule keyed on the anomalous oversized-single-character-run signature.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-10/comment-stuffing-html-phishing-ai-email-scanner-evasion" data-tags="phishing ai-abuse" data-regions="global" data-kind="research" data-priority="notable" data-discovered="2026-07-10T12:53:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 3: Possibly true"><span class="k">NATO</span>B3</span></div><h3 class="f-h" id="comment-stuffing-html-phishing-ai-email-scanner-evasion"><a href="https://ctipilot.ch/entries/2026-07-10/comment-stuffing-html-phishing-ai-email-scanner-evasion/">&#39;Comment stuffing&#39; — HTML phishing attachments padded to ~2.5 MB to dilute or exhaust AI/NLP email scanners</a></h3><p>A SANS Internet Storm Center diary (2026-07-10, Jan Kopriva) dissects a phishing email that presented as a Microsoft Teams/SharePoint document notification and carried a <code>.xls.html</code> double-extension attachment weighing ~2.5 MB — anomalously large for a self-contained HTML page (<a href="https://isc.sans.edu/diary/33144" target="_blank" rel="noopener noreferrer">SANS ISC, 2026-07-10</a>). Decoded from a <code>\uXXXX</code>-escaped <code>document.write()</code> wrapper, the file was ~431 KB, of which only the first ~11 KB was a working SharePoint-themed credential-harvesting page; the rest was a single HTML comment holding roughly 430,000 repeated &quot;X&quot; characters, placed <em>after</em> the functional payload, accounting for ~97% of the file.</p>
<p>The placement rules out the classic goal. Padding after the payload does nothing to conceal the malicious code, and at 2.5 MB the file falls well short of the tens-of-megabytes scan-size limits modern mail security uses, so this is not the MITRE &quot;Binary Padding&quot; scan-size-evasion play. The handler&#39;s assessment — explicitly flagged as informed speculation — is that the target is AI/NLP-based content scanning, which a growing number of gateways now run. Citing KnowBe4&#39;s earlier &quot;NLP obfuscation&quot; work, the diary notes that &quot;if a message contains enough innocuous material, the weight of the malicious portion can be diluted to the point where the model no longer flags it with sufficient confidence&quot;, and that &quot;the same bulk can also make a message large enough so that scanning it using AI-based mechanisms takes too long, leading some solutions to release it rather than delay delivery indefinitely&quot; (<a href="https://isc.sans.edu/diary/33144" target="_blank" rel="noopener noreferrer">SANS ISC, 2026-07-10</a>). The author judges the token-budget-exhaustion goal the more likely of the two here, since a featureless block of one character works as well as crafted filler for that purpose. He is candid that against a well-tuned model the tactic is blunt — &quot;the padding is also about as low-entropy as any data can get, which means it wouldn&#39;t help the file blend in with benign content on a statistical level either&quot; — which is precisely why a simple non-AI signature catches it.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">as AI/NLP scoring becomes a load-bearing control in mail security, adversaries gain an incentive to attack the classifier&#39;s decision budget rather than hide from signatures — dilution below a confidence threshold, or token-count inflation past a per-message time budget that makes the gateway fail open. <strong>Triage:</strong> benign HTML mail and marketing content can be large, but a single repeated-character run or one HTML comment in the hundreds of kilobytes is not something legitimate senders produce — that oversized low-entropy block, and a large decompressed-vs-declared-size ratio, are the discriminators, and both are detectable without relying on the AI layer the padding is trying to defeat.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">If a message contains enough innocuous material, the weight of the malicious portion can be diluted to the point where the model no longer flags it with sufficient confidence.</p><p class="entry-cite__quote">The same bulk can also make a message large enough so that scanning it using AI-based mechanisms takes too long, leading some solutions to release it rather than delay delivery indefinitely.</p><p class="entry-cite__quote">The padding is also about as low-entropy as any data can get, which means it wouldn’t help the file blend in with benign content on a statistical level either</p><figcaption class="entry-cite__attr"><a href="https://isc.sans.edu/diary/33144" target="_blank" rel="noopener noreferrer">SANS Internet Storm Center</a> <span class="entry-cite__date mono">2026-07-10</span></figcaption></figure></div><div class="prov"><span>research</span><span>10 Jul 12:53Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-10/comment-stuffing-html-phishing-ai-email-scanner-evasion/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://isc.sans.edu/diary/33144" target="_blank" rel="noopener noreferrer">SANS Internet Storm Center</a></div></article>]]></content:encoded></item><item><title>Huntress reconstructs a productised CitrixBleed 2-to-DragonForce runbook: token theft, a registry-symlink SYSTEM escalation, then ransomware</title><link>https://ctipilot.ch/entries/2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725/</guid><pubDate>Fri, 10 Jul 2026 04:36:19 +0000</pubDate><dc:date>2026-07-10T04:36:19Z</dc:date><category>ransomware</category><category>vulnerabilities</category><category>actively-exploited</category><category>pre-auth</category><category>lpe</category><category>identity</category><category>global</category><category>exploited</category><category>patch-available</category><category>CVE-2025-5777</category><description><![CDATA[<p>Huntress reconstructed a single, mechanically identical intrusion chain across at least six unrelated organisations in H1 2026, run by an initial-access broker (tracked by Sophos as STAC3725): pre-auth session-token theft via CitrixBleed 2 (CVE-2025-5777) on internet-facing Citrix NetScaler Gateway/AAA appliances, a portable registry-symlink local-privilege-escalation tool that abuses the Group Policy engine and the AppMgmt service to reach SYSTEM, ScreenConnect/Zoho Assist persistence, and — in the most progressed case — DragonForce ransomware. Any organisation running an unpatched NetScaler Gateway must patch and terminate all live sessions, because stolen tokens survive patching.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725" data-tags="ransomware vulnerabilities actively-exploited pre-auth lpe identity" data-regions="global" data-kind="threat" data-priority="high" data-discovered="2026-07-10T04:36:19Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2025-5777/">CVE-2025-5777</a><span class="b exp">exploited</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="citrixbleed-2-dragonforce-iab-kill-chain-stac3725"><a href="https://ctipilot.ch/entries/2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725/">CitrixBleed 2 (CVE-2025-5777) weaponised into a repeatable IAB kill chain ending in DragonForce ransomware (STAC3725)</a></h3><p>Across the first half of 2026 the Huntress Tactical Response unit worked at least six intrusions at unrelated organisations that reproduced the same seven-step kill chain so faithfully that analysts could predict the next artefact before pulling the log — the basis for their high-confidence assessment that an initial-access broker (IAB) has productised the path from an internet-facing Citrix box to domain-wide encryption, a cluster Sophos independently tracks as STAC3725 (<a href="https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware" target="_blank" rel="noopener noreferrer">Huntress, 2026-07-09</a>; <a href="https://www.sophos.com/en-us/blog/qemu-abused-to-evade-detection-and-enable-ransomware-delivery" target="_blank" rel="noopener noreferrer">Sophos X-Ops, 2026-04-16</a>). Initial access is pre-auth exploitation of CitrixBleed 2 (<code>CVE-2025-5777</code>), a memory over-read in NetScaler ADC/Gateway configured as a Gateway or AAA virtual server: a POST to the login endpoint (<code>/p/u/doAuthentication.do</code> and equivalents) with the login form variable present but empty makes the appliance serialise roughly 127 bytes of adjacent process memory into the response, and sprayed at volume this yields live session tokens (<code>T1190</code>, <code>T1550.001</code>). In one reconstructed case a user authenticated normally over LDAP+MFA from a known-good IP at 13:07 UTC; twenty-one minutes later the same session was driven from the attacker&#39;s IP with no successful authentication from that IP anywhere in the logs — token replay, with MFA already satisfied and therefore irrelevant (<a href="https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware" target="_blank" rel="noopener noreferrer">Huntress, 2026-07-09</a>).</p>
<p>The privilege-escalation primitive is what makes the cluster unmistakable, because the hijacked session usually belongs to an unprivileged employee and the operator carries a portable, unsigned LPE tool (dropped to working paths such as <code>C:\temp</code> and renamed per victim — <code>eng.exe</code>, <code>legal.exe</code>, <code>as.exe</code> — often inside a password-protected archive pulled from <code>temp.sh</code>). The tool plants a <code>REG_LINK</code> <code>SymbolicLinkValue</code> under the RdpBus device-class key <code>{28d78fad-5a12-11d1-ae5b-0000f803a8c2}</code> that redirects into the Group Policy state hierarchy (<code>T1112</code>); running <code>gpupdate</code> forces the SYSTEM-context Group Policy engine to write through the planted link into a protected key, and <code>sc start AppMgmt</code> then makes the Service Control Manager relaunch the dropper as <code>NT AUTHORITY\SYSTEM</code>, which creates a backdoor administrator via <code>net user … /add</code> and <code>net localgroup Administrators … /add</code> (<code>T1068</code>, <code>T1136.001</code>, <code>T1098</code>). AppMgmt is chosen because it is always present, normally dormant, and plausibly related to policy processing. Before detonating, the tool snapshots the original key tree and restores it afterwards, leaving the registry indistinguishable from its pre-exploit state to erase the artefacts a responder would key on (<code>T1070</code>). Persistence then rides legitimate remote-management software — ScreenConnect and Zoho Assist, in one case Netbird plus Atera (<code>T1219</code>) — and in the most advanced case the operator used PsExec, Impacket and Mimikatz for lateral movement and credential access (<code>T1003</code>, <code>T1570</code>) before deploying DragonForce ransomware, contained to a single host (<code>T1486</code>). Huntress declines a firm DragonForce-affiliate-versus-IAB attribution given the tactic overlap, and ruled out an alternative NetScaler session-management race-condition flaw because the affected build and the required already-authenticated session to race against did not fit the evidence.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">patch NetScaler to the fixed builds and, critically, terminate every live session afterwards — harvested tokens survive the patch, which is the single most common post-patch reinfection path for this bug. On the appliance, the load-bearing detection is not the paired diagnostic breadcrumbs (&quot;Login request is not expected to be encrypted&quot;, &quot;X509 cert not found&quot;), which Huntress calls necessary but nowhere near sufficient, but the binary/unprintable data leaking through the ns.log AAA <code>LOGIN_FAILED</code> User field and — the cleanest signal — an authenticated session that has no corresponding successful login event. A default Citrix behaviour also fingerprints the operator: published-desktop sessions auto-create client printer mappings that embed the client workstation name (the same <code>WIN-</code> hostnames recurred case after case), correlatable by pivoting the <code>Microsoft-Windows-TerminalServices-LocalSessionManager/Operational</code> channel (source IP + session ID) against the <code>MetaFrameEvents</code> provider in the Application log (session ID + leaked client name). <strong>Triage:</strong> a NetScaler login flood looks like ordinary password spraying and is routinely dismissed as such — the discriminator is that the &quot;usernames&quot; are leaked heap memory (unprintable bytes, X.509/ASN.1 fragments, internal <code>Citrix-ns-orig-srcip</code> proxy headers), not guessed account names; and on the endpoint, a <code>gpupdate</code> → <code>AppMgmt</code> start → new-SYSTEM-process → local-admin-creation sequence within seconds is the signal, whereas legitimate Group Policy refreshes do not spawn a fresh SYSTEM binary that immediately creates an account.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">By spraying enough of those requests, an adversary can then sift through the heap fragments for valid session tokens of someone who is currently logged in.</p><p class="entry-cite__quote">The cleanup serves to evade detection: by leaving the registry indistinguishable from its pre-exploit state, the tool removes the artifacts a responder would normally key on.</p><figcaption class="entry-cite__attr"><a href="https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware" target="_blank" rel="noopener noreferrer">Huntress</a> <span class="entry-cite__date mono">2026-07-09</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">Huntress assesses with high confidence that the activity is the work of an initial access broker (IAB) weaponising CVE-2025-5777 to gain footholds in Citrix environments before selling or handing off access, ultimately for the purpose of ransomware deployment.</p><figcaption class="entry-cite__attr"><a href="https://www.itsecurityguru.org/2026/07/09/citrixbleed-2-exploited-in-repeatable-attack-chain-culminating-in-dragonforce-ransomware-researchers-find/" target="_blank" rel="noopener noreferrer">IT Security Guru</a> <span class="entry-cite__date mono">2026-07-09</span></figcaption></figure></div><div class="prov"><span>threat</span><span>10 Jul 04:36Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware" target="_blank" rel="noopener noreferrer">Huntress</a> · <a href="https://www.itsecurityguru.org/2026/07/09/citrixbleed-2-exploited-in-repeatable-attack-chain-culminating-in-dragonforce-ransomware-researchers-find/" target="_blank" rel="noopener noreferrer">IT Security Guru</a> · <a href="https://www.sophos.com/en-us/blog/qemu-abused-to-evade-detection-and-enable-ransomware-delivery" target="_blank" rel="noopener noreferrer">Sophos X-Ops</a></div></article>]]></content:encoded></item><item><title>Talos discloses 41 patched CVEs: wolfSSL silently ignores IP/registeredID cert name constraints, GeoVision GV-I/O boxes take a high-privilege command injection</title><link>https://ctipilot.ch/entries/2026-07-09/talos-wolfssl-geovision-vtkdicom-disclosure/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-09/talos-wolfssl-geovision-vtkdicom-disclosure/</guid><pubDate>Thu, 09 Jul 2026 20:40:00 +0000</pubDate><dc:date>2026-07-09T20:40:00Z</dc:date><category>vulnerabilities</category><category>rce</category><category>ot-ics</category><category>patch-available</category><category>poc-public</category><category>global</category><category>patch-available</category><category>poc-public</category><category>CVE-2026-7532</category><category>CVE-2026-5263</category><category>CVE-2026-6678</category><category>CVE-2026-12486</category><category>CVE-2026-13125</category><category>CVE-2026-22879</category><description><![CDATA[<p>Cisco Talos published a coordinated-disclosure roundup (2026-07-09) of 41 vendor-patched CVEs across three products relevant to this constituency: two wolfSSL flaws (CVSS 9.1 / 7.4) that make the embedded TLS library silently accept certificates violating iPAddress and registeredID name constraints — quietly defeating a sub-CA scoping control — plus a PKCS#7 heap overflow; a high-privilege (PR:H) OS command-injection cluster (CVSS 9.1) in GeoVision GV-I/O Box 4E physical-security hardware; an unauthenticated GeoWebPlayer screen-capture bug (CVSS 8.8); and a VTK-DICOM heap overflow (CVSS 8.1) on crafted medical-imaging files. No in-the-wild exploitation; all patched.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-09/talos-wolfssl-geovision-vtkdicom-disclosure" data-tags="vulnerabilities rce ot-ics patch-available poc-public" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-07-09T20:40:00Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-7532/">CVE-2026-7532 +5</a></div><h3 class="f-h" id="talos-wolfssl-geovision-vtkdicom-disclosure"><a href="https://ctipilot.ch/entries/2026-07-09/talos-wolfssl-geovision-vtkdicom-disclosure/">Cisco Talos batch disclosure: wolfSSL PKI name-constraint bypasses, GeoVision command injection, and a VTK-DICOM heap overflow (41 CVEs)</a></h3><p>Cisco Talos&#39; Vulnerability Discovery &amp; Research team published a coordinated-disclosure roundup on 2026-07-09 — three wolfSSL, 37 GeoVision (across 14 advisories) and one VTK-DICOM CVE, 41 in total, all patched by their respective vendors under Cisco&#39;s third-party disclosure policy (<a href="https://blog.talosintelligence.com/wolfssl-vulnerabilities/" target="_blank" rel="noopener noreferrer">Cisco Talos, 2026-07-09</a>). In <strong>wolfSSL 5.9.1</strong> (embedded TLS for IoT/RTOS/medical/embedded devices), two X.509 name-constraint bugs let a subordinate CA issue certificates outside its permitted scope and have them accepted anyway, subverting a trust control (<code>T1553</code>): CVE-2026-7532 (CVSS 9.1) — the iPAddress SAN branch is compiled out unless <code>WOLFSSL_IP_ALT_NAME</code> is defined, silently skipping constraint enforcement for any certificate carrying an iPAddress SAN (<a href="https://talosintelligence.com/vulnerability_reports/TALOS-2026-2409" target="_blank" rel="noopener noreferrer">Talos TALOS-2026-2409, 2026-07-09</a>) — and CVE-2026-5263 (CVSS 7.4) — <code>ConfirmNameConstraints()</code> iterates a fixed GeneralName-type array that omits <code>ASN_RID_TYPE</code>, so registeredID SANs bypass constraint checking in every build (<a href="https://talosintelligence.com/vulnerability_reports/TALOS-2026-2410" target="_blank" rel="noopener noreferrer">Talos TALOS-2026-2410, 2026-07-09</a>). A third, CVE-2026-6678 (CVSS 7.5), is an integer underflow in PKCS#7 <code>OtherRecipientInfo</code> parsing that produces a heap buffer overflow with a stated path to code execution (<a href="https://talosintelligence.com/vulnerability_reports/TALOS-2026-2408" target="_blank" rel="noopener noreferrer">Talos TALOS-2026-2408, 2026-07-09</a>).</p>
<p>Talos separately disclosed 37 CVEs across GeoVision physical-security/CCTV/access-control hardware. The most severe is an OS command-injection cluster led by CVE-2026-12486 (CVSS 9.1) in <strong>GV-I/O Box 4E 2.09</strong>: a function builds a shell command string from an attacker-controlled IP/netmask/gateway/DNS value with no sanitisation and passes it to <code>system()</code>, reachable over the network from the DVRSearch discovery service and the <code>Network.cgi</code> endpoint — though Talos scores it <code>PR:H</code>, i.e. requiring high privileges rather than fully unauthenticated (<code>T1190</code>) (<a href="https://talosintelligence.com/vulnerability_reports/TALOS-2026-2379" target="_blank" rel="noopener noreferrer">Talos TALOS-2026-2379, 2026-07-09</a>). CVE-2026-13125 (CVSS 8.8) is a missing-authentication flaw in <strong>GeoWebPlayer</strong> version 1.1.1.0 (shipped with GV-VMS/GV-Cloud): it opens an unauthenticated WebSocket server on localhost, so any webpage a victim visits can connect and invoke screen-capture APIs to exfiltrate their screen (<code>T1189</code>) (<a href="https://talosintelligence.com/vulnerability_reports/TALOS-2026-2370" target="_blank" rel="noopener noreferrer">Talos TALOS-2026-2370, 2026-07-09</a>). Finally, <strong>VTK-DICOM 9.5.2</strong> (used to parse DICOM CT/MRI data) carries CVE-2026-22879 (CVSS 8.1), an improper-array-index heap overflow where a crafted DICOM file corrupts heap-chunk metadata and aborts the process — a client-side surface for hospital PACS/imaging pipelines that ingest external DICOM (<code>T1203</code>) (<a href="https://talosintelligence.com/vulnerability_reports/TALOS-2026-2366" target="_blank" rel="noopener noreferrer">Talos TALOS-2026-2366, 2026-07-09</a>).</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">none of the 41 has confirmed in-the-wild exploitation and all are patched (the GeoVision fixes shipped 2026-04-28, ~3 months before this public disclosure), so this is not an out-of-band scramble — but two threads deserve more than patch-and-forget. The wolfSSL name-constraint bugs quietly defeat a PKI control organisations may believe they enforce, so any trust model leaning on constrained sub-CAs with IP/registeredID SANs warrants an internal cert-validation review, not just a library bump. And the GeoVision GV-I/O command-injection chain is a network-reachable command-injection RCE in facility hardware that turns up in public-sector and CI security stacks — the advisory rates it high-privilege, so weak or default management credentials are what turn it into a practical path; asset owners should confirm patched firmware, strong credentials, and network isolation of the management interfaces. <strong>Triage:</strong> for the GeoVision cluster the discriminator is a network-service process on an embedded camera/IO-box spawning a shell (network-configuration utilities via <code>system()</code>) — anomalous for that device class; for GeoWebPlayer, an unexpected local WebSocket connection originating from browser-rendered content; for VTK-DICOM, a DICOM-parsing process crashing on ingest, which should prompt a hunt for repeated malformed-file submissions.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">In some configurations wolfSSL will silently fail to add IP Address GeneralName mappings to the certificate&#39;s alternative names list, causing IP addresses outside of the permitted range to be treated as valid.</p><figcaption class="entry-cite__attr"><a href="https://talosintelligence.com/vulnerability_reports/TALOS-2026-2409" target="_blank" rel="noopener noreferrer">Cisco Talos (TALOS-2026-2409)</a> <span class="entry-cite__date mono">2026-07-09</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">The following function takes a string as an ip address, performs no sanitization and calls system. This is a classic command injection vulnerability. The function is reachable from both the network-exposed DVRSearch service and the Network.cgi endpoint.</p><figcaption class="entry-cite__attr"><a href="https://talosintelligence.com/vulnerability_reports/TALOS-2026-2379" target="_blank" rel="noopener noreferrer">Cisco Talos (TALOS-2026-2379)</a> <span class="entry-cite__date mono">2026-07-09</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adherence to Cisco&#39;s third-party vulnerability disclosure policy.</p><figcaption class="entry-cite__attr"><a href="https://blog.talosintelligence.com/wolfssl-vulnerabilities/" target="_blank" rel="noopener noreferrer">Cisco Talos</a> <span class="entry-cite__date mono">2026-07-09</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>09 Jul 20:40Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-09/talos-wolfssl-geovision-vtkdicom-disclosure/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://blog.talosintelligence.com/wolfssl-vulnerabilities/" target="_blank" rel="noopener noreferrer">Cisco Talos</a> · <a href="https://talosintelligence.com/vulnerability_reports/TALOS-2026-2379" target="_blank" rel="noopener noreferrer">Cisco Talos (TALOS-2026-2379)</a> · <a href="https://talosintelligence.com/vulnerability_reports/TALOS-2026-2409" target="_blank" rel="noopener noreferrer">Cisco Talos (TALOS-2026-2409)</a> · <a href="https://talosintelligence.com/vulnerability_reports/TALOS-2026-2410" target="_blank" rel="noopener noreferrer">Cisco Talos (TALOS-2026-2410)</a> · <a href="https://talosintelligence.com/vulnerability_reports/TALOS-2026-2408" target="_blank" rel="noopener noreferrer">Cisco Talos (TALOS-2026-2408)</a> · <a href="https://talosintelligence.com/vulnerability_reports/TALOS-2026-2370" target="_blank" rel="noopener noreferrer">Cisco Talos (TALOS-2026-2370)</a> · <a href="https://talosintelligence.com/vulnerability_reports/TALOS-2026-2366" target="_blank" rel="noopener noreferrer">Cisco Talos (TALOS-2026-2366)</a></div></article>]]></content:encoded></item><item><title>Microsoft ships the engine fix for RoguePlanet (CVE-2026-50656), the Defender SYSTEM-level LPE NCSC-CH has tracked with a public PoC since June</title><link>https://ctipilot.ch/entries/2026-07-09/ncsc-ch-rogueplanet-cve-2026-50656-defender-lpe-fixed/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-09/ncsc-ch-rogueplanet-cve-2026-50656-defender-lpe-fixed/</guid><pubDate>Thu, 09 Jul 2026 20:38:00 +0000</pubDate><dc:date>2026-07-09T20:38:00Z</dc:date><category>vulnerabilities</category><category>lpe</category><category>priv-esc</category><category>poc-public</category><category>patch-available</category><category>switzerland</category><category>global</category><category>poc-public</category><category>patch-available</category><category>CVE-2026-50656</category><description><![CDATA[<p>NCSC-CH&#39;s Nightmare Eclipse tracker was updated on 2026-07-09 to record that a CVE has been assigned to RoguePlanet (CVE-2026-50656), a link-following (CWE-59) local privilege escalation in the Microsoft Malware Protection Engine behind Defender that lets a local attacker reach SYSTEM; Microsoft&#39;s MSRC record shows the engine fix has now shipped. A public PoC existed from 2026-06-10 and the CVE sat in &quot;no fix&quot; for over three weeks. The engine auto-updates, so most estates are already current — but WSUS-gated, offline or OT-adjacent estates should explicitly verify the installed engine build.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-09/ncsc-ch-rogueplanet-cve-2026-50656-defender-lpe-fixed" data-tags="vulnerabilities lpe priv-esc poc-public patch-available" data-regions="switzerland global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-07-09T20:38:00Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-50656/">CVE-2026-50656</a></div><h3 class="f-h" id="ncsc-ch-rogueplanet-cve-2026-50656-defender-lpe-fixed"><a href="https://ctipilot.ch/entries/2026-07-09/ncsc-ch-rogueplanet-cve-2026-50656-defender-lpe-fixed/">CVE-2026-50656 — Microsoft Defender engine &#39;RoguePlanet&#39; local privilege escalation now patched; NCSC-CH tracks the ongoing &#39;Nightmare Eclipse&#39; zero-day series</a></h3><p>NCSC-CH&#39;s running tracker on the &quot;Nightmare Eclipse&quot; (aka Chaotic Eclipse) researcher&#39;s 2026 zero-day PoC series was updated on 2026-07-09 to record that a CVE has been assigned to <strong>RoguePlanet</strong>: <strong>CVE-2026-50656</strong>, a local privilege-escalation vulnerability (CWE-59, improper link resolution before file access / &quot;link following&quot;) in the Microsoft Malware Protection Engine that underpins Microsoft Defender, System Center Endpoint Protection and Microsoft Security Essentials (<a href="https://security-hub.ncsc.admin.ch/#/posts/12622" target="_blank" rel="noopener noreferrer">NCSC-CH, 2026-07-09</a>). The researcher first disclosed RoguePlanet as an unpatched zero-day on 2026-06-10, describing a race condition in Defender that lets a local attacker &quot;execute arbitrary code or spawn a command shell with SYSTEM-level privileges&quot; (<code>T1068</code>), at which point NCSC-CH logged its status as &quot;Proof of Concept Available, no patch available&quot; (<a href="https://security-hub.ncsc.admin.ch/#/posts/12622" target="_blank" rel="noopener noreferrer">NCSC-CH, 2026-07-09</a>). Microsoft&#39;s own record shows the CVE was published 2026-06-16 (CVSS 3.1 7.8, <code>AV:L/AC:L/PR:L/UI:N</code>, rated &quot;Exploitation More Likely&quot;, exploitation status &quot;No&quot;) and remained without a fix for over three weeks; a revision dated 2026-07-08 confirms Microsoft has now shipped an engine update that closes it — last vulnerable Malware Protection Engine build <strong>1.1.26050.11</strong>, first fixed build <strong>1.1.26060.3008</strong> (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50656" target="_blank" rel="noopener noreferrer">Microsoft MSRC, 2026-07-08</a>).</p>
<p>Because the Malware Protection Engine (<code>mpengine.dll</code>) auto-updates multiple times a day by default, most estates will already carry the fixed build — Microsoft&#39;s guidance is that no manual action is normally required. The operational nuance for this constituency is the exception set: any environment where engine updates are pinned, WSUS-gated, air-gapped, or centrally deferred (System Center Endpoint Protection deployments, offline or OT-adjacent Windows hosts) should explicitly verify the installed engine version rather than assume auto-remediation occurred (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50656" target="_blank" rel="noopener noreferrer">Microsoft MSRC, 2026-07-08</a>). Microsoft also notes that hosts with Defender disabled are not in an exploitable state even though vulnerability scanners flag the on-disk binaries. <strong>Triage:</strong> the exploit abuses a symlink/junction race against files Defender is actively scanning, so the telemetry class is symlink/junction creation targeting Defender scan paths and, on success, <code>MsMpEng.exe</code> (the engine&#39;s scan host) spawning an unexpected child process with a SYSTEM token outside the normal signature/engine-update cadence — the update-cadence anchoring is the discriminator from routine engine activity. This closes RoguePlanet specifically; NCSC-CH continues to track the wider Nightmare Eclipse PoC series as a home-region authority, which is the reason a single-host LPE closure like this one is worth surfacing to this constituency at all.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Microsoft has released an update to the Microsoft Malware Protection Engine that addresses the vulnerability identified by CVE-2026-50656.</p><p class="entry-cite__quote">Improper link resolution before file access (&#39;link following&#39;) in Microsoft Defender allows an authorized attacker to elevate privileges locally.</p><figcaption class="entry-cite__attr"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50656" target="_blank" rel="noopener noreferrer">Microsoft Security Response Center</a> <span class="entry-cite__date mono">2026-07-08</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>09 Jul 20:38Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-09/ncsc-ch-rogueplanet-cve-2026-50656-defender-lpe-fixed/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://security-hub.ncsc.admin.ch/#/posts/12622" target="_blank" rel="noopener noreferrer">NCSC-CH / GovCERT.ch Cyber Security Hub</a> · <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50656" target="_blank" rel="noopener noreferrer">Microsoft Security Response Center</a></div></article>]]></content:encoded></item><item><title>CISA ICS advisory: an authenticated file-write in OpenPLC&#39;s legacy web UI reaches native code execution, with no fixed version cited</title><link>https://ctipilot.ch/entries/2026-07-09/openplc-cve-2026-14480-file-write-rce/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-09/openplc-cve-2026-14480-file-write-rce/</guid><pubDate>Thu, 09 Jul 2026 20:36:00 +0000</pubDate><dc:date>2026-07-09T20:36:00Z</dc:date><category>vulnerabilities</category><category>ot-ics</category><category>rce</category><category>no-patch</category><category>global</category><category>no-patch</category><category>CVE-2026-14480</category><description><![CDATA[<p>CISA&#39;s ICS advisory ICSA-26-190-01 (2026-07-09) covers CVE-2026-14480, an authenticated arbitrary file-write in OpenPLC Runtime v3&#39;s legacy web UI that escalates to native code execution: the runtime auto-compiles every C++ source file in its core directory into the executable, so writing a malicious .cpp there and triggering a normal program compile runs attacker code as the OpenPLC runtime user. CVSS 3.1 9.9, network-facing; CISA cites no fixed version, only network-isolation mitigations — treat as unpatched. No known exploitation.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-09/openplc-cve-2026-14480-file-write-rce" data-tags="vulnerabilities ot-ics rce no-patch" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-07-09T20:36:00Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-14480/">CVE-2026-14480</a></div><h3 class="f-h" id="openplc-cve-2026-14480-file-write-rce"><a href="https://ctipilot.ch/entries/2026-07-09/openplc-cve-2026-14480-file-write-rce/">CVE-2026-14480 — OpenPLC v3 Runtime: authenticated arbitrary file write escalates to native RCE via the auto-compile pipeline (CVSS 9.9)</a></h3><p>CISA published ICS advisory <strong>ICSA-26-190-01</strong> (2026-07-09) for <strong>OpenPLC Runtime v3</strong>, the widely used open-source PLC runtime CISA tags across the Critical Manufacturing, Energy, Transportation Systems, and Water/Wastewater sectors (<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-190-01" target="_blank" rel="noopener noreferrer">CISA, 2026-07-09</a>). <strong>CVE-2026-14480</strong> (CWE-73, External Control of File Name or Path; CVSS 3.1 9.9 <code>AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</code>, CVSS 4.0 8.7) is an authenticated arbitrary file-write in the legacy web UI&#39;s program-upload workflow: the application stores an attacker-supplied filename (the <code>prog_file</code> parameter) directly into the <code>Programs.File</code> database field and later uses that value as the destination write path without validation, and because the underlying Python <code>os.path.join()</code> honors an attacker-controlled absolute path, any authenticated user can write files anywhere the webserver process can reach (<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-190-01" target="_blank" rel="noopener noreferrer">CISA, 2026-07-09</a>). The escalation is specific to OpenPLC&#39;s build model: all <code>.cpp</code> source files in the runtime&#39;s core directory are automatically compiled into the executable runtime binary, so writing a malicious <code>.cpp</code> there and then triggering a normal program compile-and-start — an ordinary operator action, not an exploit primitive — executes attacker code as the OpenPLC runtime user (<code>T1190</code>). The bug was reported to CISA by researcher Grady DeRosa, and CISA states no known public exploitation at this time.</p>
<p>CISA cites <strong>no fixed release version</strong> — its only stated mitigations are the standard ICS hardening set (minimise network exposure, keep control-system devices off the internet, place them behind firewalls isolated from business networks, use VPN for remote access) — so this should be treated as unpatched until the OpenPLC project ships guidance. Because exploitation requires authentication, the practical exposure hinges on how reachable and how loosely authenticated the web UI is: an internet-exposed or shared-credential OpenPLC instance is effectively RCE-exposed, while one confined to a trusted out-of-band network with per-operator accounts is not. <strong>Triage:</strong> the compile step itself is legitimate operator activity, so the discriminator is <em>what</em> is being compiled and <em>who</em> spawned it — new or modified <code>.cpp</code> files appearing in the runtime core directory outside a maintainer deploy, and the compiler toolchain being invoked by the OpenPLC webserver process or its children rather than by an engineer-initiated build from an authorised workstation; parent-process lineage (webserver → <code>gcc</code>/<code>g++</code>) is the signal.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to the filesystem and escalate this into arbitrary native code execution through the normal OpenPLC program compilation process, potentially resulting in code execution as the OpenPLC runtime user.</p><p class="entry-cite__quote">In the default build pipeline, all C++ source files within the OpenPLC runtime core directory are automatically compiled into the executable runtime binary.</p><figcaption class="entry-cite__attr"><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-190-01" target="_blank" rel="noopener noreferrer">CISA (ICS Advisory ICSA-26-190-01)</a> <span class="entry-cite__date mono">2026-07-09</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>09 Jul 20:36Z</span><span class="p-warn">single-source · national CERT</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-09/openplc-cve-2026-14480-file-write-rce/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-190-01" target="_blank" rel="noopener noreferrer">CISA (ICS Advisory ICSA-26-190-01)</a></div></article>]]></content:encoded></item><item><title>Two Golang DDoS botnets, Apex2 and c2c/meow, flood exposed Telnet/SSH Linux and IoT with fake-systemd persistence and passwordless-sudo escalation</title><link>https://ctipilot.ch/entries/2026-07-09/nozomi-apex2-c2c-meow-golang-iot-linux-ddos-botnets/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-09/nozomi-apex2-c2c-meow-golang-iot-linux-ddos-botnets/</guid><pubDate>Thu, 09 Jul 2026 12:33:00 +0000</pubDate><dc:date>2026-07-09T12:33:00Z</dc:date><category>botnet</category><category>ddos</category><category>ot-ics</category><category>global</category><description><![CDATA[<p>Nozomi Networks Labs details two Golang DDoS botnet families caught via honeypots this spring: Apex2 (Telnet brute-force, Linux+Windows builds, a Cloudflare-bypass HTTP flood plus UDP/TLS floods) and c2c/meow (SSH-delivered, escalates via passwordless sudo, persists as a fake systemd &#39;cpufreqd&#39; service). Neither is sophisticated, but the point for defenders is the pace: exposed Telnet/SSH management interfaces on IoT and embedded-Linux keep getting repurposed for DDoS faster than before — directly relevant to OT-adjacent estates in energy, water and transport.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-09/nozomi-apex2-c2c-meow-golang-iot-linux-ddos-botnets" data-tags="botnet ddos ot-ics" data-regions="global" data-kind="threat" data-priority="notable" data-discovered="2026-07-09T12:33:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="nozomi-apex2-c2c-meow-golang-iot-linux-ddos-botnets"><a href="https://ctipilot.ch/entries/2026-07-09/nozomi-apex2-c2c-meow-golang-iot-linux-ddos-botnets/">Nozomi documents two new Golang IoT/Linux DDoS botnets (Apex2, c2c/meow) built for speed and reuse over sophistication</a></h3><p>Nozomi Networks Labs&#39; AI-assisted honeypot triage flagged two Golang-based DDoS botnet samples this spring that stand out from the routine volume of Mirai-derived variants: Apex2 and c2c (distributed under the filename &quot;meow&quot;) (<a href="https://www.nozominetworks.com/blog/spring-botnet-floods-golang-malware-targets-exposed-iot-systems" target="_blank" rel="noopener noreferrer">Nozomi Networks Labs, 2026-07-06</a>). Apex2 is a direct structural evolution of the earlier Apex botnet: infection begins with Telnet connections and credential brute-forcing, followed by download-and-execute of the Golang payload, which registers with its C2 over a plaintext protocol (host OS/architecture) and ships builds for Linux (arm, arm64, mipsle, ppc64) and Windows (386, amd64). Its named flood commands include <code>cf</code> (an HTTP(S) flood specifically tuned to bypass Cloudflare via randomized User-Agent lists and long keep-alive timeouts), <code>udp</code>/<code>pps</code>, <code>discord</code>/<code>game</code> UDP floods, and three TLS-flood variants (<code>tls</code>, <code>tlsplus</code>, <code>tlsplusbypass</code>). c2c/meow is architecturally simpler — a Golang flooder with no built-in propagation (a separate SSH scanner handles brute-forcing and delivery) that authenticates to a hardcoded C2 over plaintext JSON-over-TCP, checks for passwordless sudo (<code>sudo -n true</code>) to self-escalate, then persists by copying itself to <code>/usr/local/bin/cpufreqd</code> and registering a fake systemd unit masquerading as a &quot;CPU Frequency Daemon&quot; — supporting ten flood-module types (icmp, dnsudp, udp, http, directhttp, fasthttp, betterhttp, tcp, tcphandshake, dnstcp).</p>
<p>Nozomi&#39;s stated point for defenders is that neither family is sophisticated — both lean on commodity Golang tooling, weak/default credentials and exposed Telnet/SSH interfaces rather than novel exploitation — and that the lack of sophistication does not reduce the risk at scale, because the build-and-deploy cycle for such botnets is getting faster. ATT&amp;CK mapping: <code>T1110 Brute Force</code> (Telnet/SSH), <code>T1105 Ingress Tool Transfer</code>, <code>T1548.003 Abuse Elevation Control Mechanism: Sudo</code> (c2c&#39;s passwordless-sudo self-escalation), <code>T1543.002 Create or Modify System Process: Systemd Service</code> with <code>T1036.005 Masquerading</code> (the fake cpufreqd unit), and <code>T1498 Network Denial of Service</code> for the flood modules.</p><aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">this is not a novel threat but a concrete hunt package for the OT-adjacent and embedded-Linux estates in the constituency&#39;s energy, water and transport remit — the fake-systemd-service naming, the <code>sudo -n true</code> escalation probe, and plaintext-JSON C2 are all cheap, durable detections, and the durable fix is the unglamorous one of removing internet-exposed Telnet/SSH and default credentials on IoT and embedded devices.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">It checks whether passwordless sudo is available by running sudo -n true and evaluating the return value. If successful, it relaunches itself with increased privileges, copies to /usr/local/bin/cpufreqd, and creates a fake systemd service named &quot;CPU Frequency Daemon&quot;</p><p class="entry-cite__quote">In both cases, the emphasis is not on sophistication, but on speed, reuse and scalability.</p><figcaption class="entry-cite__attr"><a href="https://www.nozominetworks.com/blog/spring-botnet-floods-golang-malware-targets-exposed-iot-systems" target="_blank" rel="noopener noreferrer">Nozomi Networks Labs</a> <span class="entry-cite__date mono">2026-07-06</span></figcaption></figure></div><div class="prov"><span>threat</span><span>09 Jul 12:33Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-09/nozomi-apex2-c2c-meow-golang-iot-linux-ddos-botnets/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.nozominetworks.com/blog/spring-botnet-floods-golang-malware-targets-exposed-iot-systems" target="_blank" rel="noopener noreferrer">Nozomi Networks Labs</a> · <a href="https://industrialcyber.co/ransomware/nozomi-identifies-apex2-and-c2c-golang-malware-driving-faster-iot-botnet-attacks-raising-risks-for-ot-environments/" target="_blank" rel="noopener noreferrer">Industrial Cyber</a></div></article>]]></content:encoded></item><item><title>Sygnia IR: an AI-assisted AWS intrusion ran four parallel workstreams per stolen key and used four accounts&#39; keys in one second</title><link>https://ctipilot.ch/entries/2026-07-09/sygnia-ai-orchestrated-aws-cloud-intrusion-72h/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-09/sygnia-ai-orchestrated-aws-cloud-intrusion-72h/</guid><pubDate>Thu, 09 Jul 2026 04:32:59 +0000</pubDate><dc:date>2026-07-09T04:32:59Z</dc:date><category>ai-abuse</category><category>cloud</category><category>organized-crime</category><category>global</category><description><![CDATA[<p>Sygnia&#39;s incident response into a financially-motivated AWS intrusion found no novel malware or zero-day — every technique maps to a known MITRE ATT&amp;CK ID — but the tempo and parallelism point to AI-assisted/agentic tooling: initial access to broad compromise in ~72h, and four access keys from four separate accounts used from one source IP and user-agent within a single observed second. The detection signal is the orchestration, not the individual actions. Defenders should pre-build minutes-not-hours containment and alert on one source authenticating with multiple distinct keys in a tight window.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-09/sygnia-ai-orchestrated-aws-cloud-intrusion-72h" data-tags="ai-abuse cloud organized-crime" data-regions="global" data-kind="research" data-priority="notable" data-discovered="2026-07-09T04:32:59Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 3: Possibly true"><span class="k">NATO</span>B3</span></div><h3 class="f-h" id="sygnia-ai-orchestrated-aws-cloud-intrusion-72h"><a href="https://ctipilot.ch/entries/2026-07-09/sygnia-ai-orchestrated-aws-cloud-intrusion-72h/">Sygnia: an AI-orchestrated AWS intrusion reached broad compromise in ~72 hours — four keys from four accounts used from one source in the same second</a></h3><p>Sygnia&#39;s incident-response investigation of a financially-motivated AWS cloud intrusion found no novel malware or zero-day — every individual technique maps to a long-tracked MITRE ATT&amp;CK ID — but the operationalisation was materially faster than typical manual intrusions, which Sygnia attributes to AI-assisted or agentic tooling (<a href="https://www.sygnia.co/blog/inside-an-ai-assisted-cloud-attack/" target="_blank" rel="noopener noreferrer">Sygnia, 2026-07-08</a>). After obtaining an initial access key via a weakness in an internet-facing application, the actor ran four workstreams in parallel — secrets theft (ECS/EC2 environment variables, GitHub/Bitbucket CI/CD runner env vars, S3 plaintext secrets, Secrets Manager, SSM Parameter Store); persistence (new IAM users, EC2/ECS reverse shells, modified deployment files); RDS exfiltration via several hundred distinct SQL queries across dozens of databases; and reversible impact (S3 access denial, ECS scaled to zero, SQS purges) used purely as extortion leverage — and repeated the full playbook on every newly obtained credential rather than progressing linearly. The most striking artefact: four different AWS access keys from four separate accounts were used from the same source IP and user-agent within a single observed second, which Sygnia assesses is very hard to explain as manual operation (<a href="https://www.sygnia.co/blog/inside-an-ai-assisted-cloud-attack/" target="_blank" rel="noopener noreferrer">Sygnia, 2026-07-08</a>).</p>
<p>Scripts, structured reporting output, and commit messages/branch names framing the activity as an authorized &quot;pentest&quot;/&quot;red team&quot; with a fabricated CEO sign-off are consistent with LLM-generated tooling — possibly including prompt-framing meant to reduce refusal from AI assistants being abused by the operator. Sygnia maps the case onto the same tactic distribution (Execution, Discovery, Credential Access, Collection, Defense Evasion) that Anthropic&#39;s June 2026 LLM ATT&amp;CK research found concentrated in banned AI-abuse accounts. Relevant IDs per Sygnia include <code>T1651 Cloud Administration Command</code>, <code>T1552/T1528</code> (credential/token harvesting), <code>T1087/T1580/T1619</code> (account/cloud-infra/storage discovery re-run per key), <code>T1578</code> (modify cloud compute infra) and <code>T1078 Valid Accounts</code>.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">for a Swiss/EU public-sector estate mid-cloud-migration running AWS with GitHub/Bitbucket CI/CD, the lesson is tempo. The ATT&amp;CK-mappable individual actions are not the alarm — the orchestration is: one source authenticating with multiple distinct keys/accounts in seconds, and the same secrets-harvesting sequence re-firing on each new credential. Because manual response cannot keep pace, containment (network isolation, credential rotation, session revocation) has to be pre-built to run in minutes, and every exposed credential must be assumed used instantly and at scale.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">In one observed second, four different access keys belonging to four separate accounts were used from the same source IP address and the same user-agent</p><p class="entry-cite__quote">The intrusion progressed from initial access to broad cloud compromise within approximately 72 hours.</p><p class="entry-cite__quote">multiple attacker-created artifacts were framed as part of a &#39;pentest&#39; or a &#39;red team&#39;. This framing appeared in branch names, commit messages, and other artifacts, including references suggesting the activity was approved by a non-existent CEO.</p><figcaption class="entry-cite__attr"><a href="https://www.sygnia.co/blog/inside-an-ai-assisted-cloud-attack/" target="_blank" rel="noopener noreferrer">Sygnia</a> <span class="entry-cite__date mono">2026-07-08</span></figcaption></figure></div><div class="prov"><span>research</span><span>09 Jul 04:32Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-09/sygnia-ai-orchestrated-aws-cloud-intrusion-72h/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.sygnia.co/blog/inside-an-ai-assisted-cloud-attack/" target="_blank" rel="noopener noreferrer">Sygnia</a></div></article>]]></content:encoded></item><item><title>Mandiant recovers a live ADFS signing key from Machine DPAPI — a Golden SAML variant that sidesteps the WID/DKM path and LSASS-watching detection</title><link>https://ctipilot.ch/entries/2026-07-09/mandiant-adfs-machine-dpapi-golden-saml-key-recovery/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-09/mandiant-adfs-machine-dpapi-golden-saml-key-recovery/</guid><pubDate>Thu, 09 Jul 2026 04:32:59 +0000</pubDate><dc:date>2026-07-09T04:32:59Z</dc:date><category>identity</category><category>espionage</category><category>cloud</category><category>global</category><category>europe</category><category>switzerland</category><description><![CDATA[<p>Mandiant documented an ADFS Golden SAML variant: when AutoCertificateRollover is disabled and certificates are rotated manually, the WID configuration database drifts to a stale &quot;ghost&quot; certificate while the active token-signing key sits in the machine CAPI store protected by Machine DPAPI. A SYSTEM-level attacker recovers it with SharpDPAPI /machine — without touching the WID/DKM path or LSASS — and forges a Global Administrator SAML assertion that Entra ID accepts, bypassing MFA and conditional access. The drift is observable via ADFS Event ID 385; treat ADFS as Tier 0.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-09/mandiant-adfs-machine-dpapi-golden-saml-key-recovery" data-tags="identity espionage cloud" data-regions="global europe switzerland" data-kind="research" data-priority="notable" data-discovered="2026-07-09T04:32:59Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="mandiant-adfs-machine-dpapi-golden-saml-key-recovery"><a href="https://ctipilot.ch/entries/2026-07-09/mandiant-adfs-machine-dpapi-golden-saml-key-recovery/">Mandiant &quot;Ghost in the Database&quot;: recovering an active ADFS token-signing key from Machine DPAPI when the WID/DKM Golden SAML path fails</a></h3><p><strong>Background.</strong> Golden SAML — forging SAML assertions by stealing an identity provider&#39;s token-signing key — has been public tradecraft since CyberArk&#39;s 2017 disclosure (<a href="https://www.cyberark.com/resources/threat-research-blog/golden-saml-newly-discovered-attack-technique-forges-authentication-to-cloud-apps" target="_blank" rel="noopener noreferrer">CyberArk, 2017</a>), and Mandiant previously documented network-based extraction of ADFS secrets during the UNC2452/SolarWinds intrusions (<a href="https://cloud.google.com/blog/topics/threat-intelligence/abusing-replication-stealing-adfs-secrets-over-the-network" target="_blank" rel="noopener noreferrer">Mandiant</a>). The standard extraction path pulls the encrypted signing key from the ADFS Windows Internal Database (WID) and decrypts it with Distributed Key Manager (DKM) material stored in Active Directory. This new Mandiant write-up documents a variant that defeats that assumption when ADFS configuration has drifted.</p>
<p>During a red-team engagement, Mandiant found that ADFS deployments with <code>AutoCertificateRollover</code> disabled (<code>Get-AdfsProperties</code> → <code>AutoCertificateRollover: False</code>) and certificates rotated manually can leave the WID configuration database holding only a stale &quot;ghost&quot; certificate record, while the ADFS service actually signs tokens with a newer certificate whose private key lives in the machine CAPI store (<a href="https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi" target="_blank" rel="noopener noreferrer">Mandiant, 2026-07-07</a>). In that state the classic path still &quot;works&quot; mechanically — the WID blob decrypts via DKM — but Entra ID rejects the resulting token with <strong>AADSTS500172</strong> because the key is no longer the one in use.</p>
<p><strong>The key&#39;s real location and protection.</strong> The active private key sits under <code>C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\</code>, with the certificate enrolled in the <code>LocalMachine\My</code> store. It is protected by <strong>Machine DPAPI</strong> (not user-bound DPAPI): the <code>DPAPI_SYSTEM</code> LSA secret plus machine masterkeys under the <code>S-1-5-18</code> (SYSTEM) context at <code>C:\Windows\System32\Microsoft\Protect\S-1-5-18\</code>. Machine-scoping is deliberate — it keeps the key usable across service-account password changes, gMSA rotations and reboots — but it also means a SYSTEM-level actor can recover the key entirely from the host. Mandiant confirmed recovery with <code>SharpDPAPI /machine</code>, which enumerated the active key material under that path (the CNG <code>Crypto\Keys</code> store was not in use in the assessed environment) — no interaction with the live ADFS process or LSASS is required, reducing visibility for defenses that watch only credential-dumping/process-memory access (<a href="https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi" target="_blank" rel="noopener noreferrer">Mandiant, 2026-07-07</a>).</p>
<p><strong>Kill chain (ATT&amp;CK).</strong> SYSTEM-level foothold on the ADFS host → recover Machine-DPAPI-protected masterkeys and the CAPI signing key (<code>T1552 Unsecured Credentials</code>, via <code>SharpDPAPI /machine</code>) → forge a SAML assertion impersonating a Global Administrator (<code>T1606.002 Forge Web Credentials: SAML Tokens</code>) → Entra ID accepts it as a valid federated authentication assertion, yielding Global Administrator access to the Microsoft 365 tenant with MFA and conditional access fully bypassed (<code>T1078.004 Valid Accounts: Cloud Accounts</code>). Because the forged assertion is honoured for <strong>all SAML relying-party trusts</strong>, the blast radius extends to every SaaS platform federated through the same ADFS, not just Microsoft services.</p>
<p><strong>Hunt and detection.</strong> The drift condition itself is observable: <strong>ADFS Event ID 385</strong> fires when the WID record and the actively-used signing certificate diverge, and self-resolves only once <code>AutoCertificateRollover</code> is re-enabled and a rollover runs. For key-theft detection, Mandiant recommends SACL-based object-access auditing (Security <strong>Event ID 4663</strong>) on <code>C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\</code> and <code>C:\Windows\System32\Microsoft\Protect\S-1-5-18\</code>, treated as correlation evidence rather than a standalone signal. The strongest analytic is cross-source: correlate ADFS token-issuance/claims events (Event IDs 299 and the 1200-series, version-dependent) against Entra ID sign-in logs to surface federated sign-ins with no matching upstream authentication context, baselining claim sets, IP ranges and user-agents per relying-party trust for privileged accounts — neither log source alone is sufficient (<a href="https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi" target="_blank" rel="noopener noreferrer">Mandiant, 2026-07-07</a>).</p>
<p><strong>Hardening.</strong> Migrate token-signing certificates to an HSM to eliminate the software-accessible key and thus the Machine DPAPI extraction path entirely; run ADFS under gMSA to reduce manual-rotation drift; govern ADFS servers as <strong>Tier 0</strong> (restricted admin paths, dedicated PAWs, separation from general server administration). When <code>AutoCertificateRollover</code> is disabled, a manual rotation must include <code>Set-AdfsCertificate</code> — installing the certificate alone is insufficient — and be validated with <code>Get-AdfsCertificate</code>; a subsequent Event ID 385 signals lingering inconsistency. Organisations migrating to native OIDC federation remove this attack path altogether (<a href="https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi" target="_blank" rel="noopener noreferrer">Mandiant, 2026-07-07</a>). ADFS remains widely deployed for on-prem/hybrid identity across Swiss and EU public-sector estates mid-migration to Entra ID, making this a direct Tier 0 hardening item for the constituency.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Successfully obtaining this active key allows an attacker to forge valid SAML assertions for any user, bypassing the need for user credentials and multi-factor authentication</p><p class="entry-cite__quote">The recovered key was used to forge a SAML assertion impersonating a Global Administrator identity, which Entra ID accepted as a valid authentication assertion</p><p class="entry-cite__quote">Configure object access auditing via SACLs on C:\\ProgramData\\Microsoft\\Crypto\\RSA\\MachineKeys\\ and C:\\Windows\\System32\\Microsoft\\Protect\\S-1-5-18\\. When configured correctly, this generates Security Event ID 4663 for file access attempts.</p><figcaption class="entry-cite__attr"><a href="https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi" target="_blank" rel="noopener noreferrer">Mandiant (Google Cloud Blog / GTIG)</a> <span class="entry-cite__date mono">2026-07-07</span></figcaption></figure></div><div class="prov"><span>research</span><span>09 Jul 04:32Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-09/mandiant-adfs-machine-dpapi-golden-saml-key-recovery/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi" target="_blank" rel="noopener noreferrer">Mandiant (Google Cloud Blog / GTIG)</a> · <a href="https://itbrief.co.uk/story/mandiant-finds-way-to-recover-active-adfs-signing-keys" target="_blank" rel="noopener noreferrer">itbrief.co.uk</a></div></article>]]></content:encoded></item><item><title>CISA ICSA-26-188-01: unauthenticated OCPP WebSocket in an EV-charging backend — a transferable lesson for any charge-point operator</title><link>https://ctipilot.ch/entries/2026-07-08/cve-2026-20744-hydro-quebec-ocpp-unauth-websocket/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-08/cve-2026-20744-hydro-quebec-ocpp-unauth-websocket/</guid><pubDate>Wed, 08 Jul 2026 20:35:00 +0000</pubDate><dc:date>2026-07-08T20:35:00Z</dc:date><category>vulnerabilities</category><category>ot-ics</category><category>auth-bypass</category><category>dos</category><category>no-patch</category><category>global</category><category>mitigation-only</category><category>CVE-2026-20744</category><category>CVE-2026-42952</category><category>CVE-2026-44383</category><description><![CDATA[<p>CISA advisory ICSA-26-188-01 discloses an unauthenticated OCPP WebSocket endpoint (CVE-2026-20744, CVSS 9.8) in the backend of Hydro-Québec&#39;s EV-charging network, plus two companion DoS flaws. Hydro-Québec&#39;s fix is operational (OCPP disabled / auth added), not a version patch. The transferable weakness — an unauthenticated OCPP management channel — applies to any charge-point operator, including Swiss/EU public charging infrastructure.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-08/cve-2026-20744-hydro-quebec-ocpp-unauth-websocket" data-tags="vulnerabilities ot-ics auth-bypass dos no-patch" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-07-08T20:35:00Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-20744/">CVE-2026-20744 +2</a></div><h3 class="f-h" id="cve-2026-20744-hydro-quebec-ocpp-unauth-websocket"><a href="https://ctipilot.ch/entries/2026-07-08/cve-2026-20744-hydro-quebec-ocpp-unauth-websocket/">CVE-2026-20744 — Hydro-Québec EV-charging backend: unauthenticated OCPP WebSocket endpoint enables privilege escalation</a></h3><p>CISA published ICS advisory ICSA-26-188-01 for the backend of Hydro-Québec&#39;s &quot;Le Circuit Électrique&quot; EV-charging network, disclosing three flaws reported by an anonymous researcher (<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-01" target="_blank" rel="noopener noreferrer">CISA, 2026-07-07</a>). The headline flaw, CVE-2026-20744 (CVSS v3.1 9.8, CWE-284 Improper Access Control), is in the charging-station WebSocket endpoint that speaks OCPP (Open Charge Point Protocol, the industry-standard charge-point-to-backend management protocol): the endpoint accepts connections with no authentication, letting a remote unauthenticated actor escalate privileges against the backend (<code>T1190</code>). Two companion flaws compound the exposure — CVE-2026-42952 (CVSS 7.5, CWE-307, no throttling on repeated authentication attempts → brute-force/DoS) and CVE-2026-44383 (CVSS 7.5, CWE-613, the backend allows multiple simultaneous connections under the same charging-station identifier, enabling session-exhaustion DoS via duplicate OCPP clients). There is no version-numbered software patch; Hydro-Québec&#39;s remediation is operational — OCPP has been disabled on most charging stations and authentication added for the remainder still using it — and CISA reports no known public exploitation (<a href="https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-188-01.json" target="_blank" rel="noopener noreferrer">CISA CSAF, 2026-07-07</a>).</p><aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the advisory scopes to a single Canadian operator, but the underlying weakness class — an unauthenticated OCPP WebSocket management channel — is a protocol-implementation pattern relevant to every EV-charging network operator, and OCPP is the near-universal charge-point management standard across Swiss/EU public charging infrastructure; the fix is a configuration/security-profile decision (enforce OCPP Security Profile 2/3, one session per charge-point identity), and because the hardware carries no agent, monitoring is necessarily backend/network-telemetry-based.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">The charging station websocket endpoint accepts connections without proper authentication, which could lead to privilege escalation.</p><p class="entry-cite__quote">No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p><figcaption class="entry-cite__attr"><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-01" target="_blank" rel="noopener noreferrer">CISA (ICS Advisory ICSA-26-188-01)</a> <span class="entry-cite__date mono">2026-07-07</span></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>08 Jul 20:35Z</span><span class="p-warn">single-source · national CERT</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-08/cve-2026-20744-hydro-quebec-ocpp-unauth-websocket/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-01" target="_blank" rel="noopener noreferrer">CISA (ICS Advisory ICSA-26-188-01)</a> · <a href="https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-188-01.json" target="_blank" rel="noopener noreferrer">CISA CSAF machine-readable advisory</a></div></article>]]></content:encoded></item><item><title>CrySome RAT delivered via freight-rate phishing, chaining AMSI bypass, ICMLuaUtil UAC bypass and WinDefCtl</title><link>https://ctipilot.ch/entries/2026-07-08/crysome-rat-freight-phishing-amsi-uac-defender-chain/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-08/crysome-rat-freight-phishing-amsi-uac-defender-chain/</guid><pubDate>Wed, 08 Jul 2026 20:35:00 +0000</pubDate><dc:date>2026-07-08T20:35:00Z</dc:date><category>phishing</category><category>infostealer</category><category>global</category><description><![CDATA[<p>LevelBlue SpiderLabs documented a freight-rate-confirmation phishing chain delivering CrySome, a .NET RAT, via a batch downloader, PowerShell AMSI bypass, ICMLuaUtil UAC bypass and the open-source WinDefCtl Defender-disruption utility. The operators lean almost entirely on off-the-shelf components, so detection must target the individual behaviours, not the final payload.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-08/crysome-rat-freight-phishing-amsi-uac-defender-chain" data-tags="phishing infostealer" data-regions="global" data-kind="threat" data-priority="notable" data-discovered="2026-07-08T20:35:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="crysome-rat-freight-phishing-amsi-uac-defender-chain"><a href="https://ctipilot.ch/entries/2026-07-08/crysome-rat-freight-phishing-amsi-uac-defender-chain/">CrySome RAT freight-phishing chain: AMSI bypass, ICMLuaUtil UAC bypass and an open-source Defender-disruption tool</a></h3><p>LevelBlue SpiderLabs documented a multi-stage infection chain delivering CrySome RAT — a modular .NET remote-access trojan the lab notes has been covered in prior public reporting — through spear-phishing emails impersonating freight-rate confirmations (<a href="https://www.levelblue.com/blogs/spiderlabs-blog/from-phishing-to-persistence-a-crysome-rat-infection-chain-analysis" target="_blank" rel="noopener noreferrer">LevelBlue SpiderLabs, 2026-07-06</a>). Victims reach a fake portal hosting a batch-file downloader that launches PowerShell with an AMSI bypass (<code>T1059.001</code>, <code>T1562.001</code>) to fetch a stage-1 binary, which performs a UAC bypass via the ICMLuaUtil COM interface (<code>T1548.002</code>). Stage 2 adds Microsoft Defender exclusions and drops WinDefCtl — an open-source Defender-disruption utility masquerading as <code>svchost.exe</code> from <code>%TEMP%</code> — to disable real-time protection before launching the RAT. Persistence is a scheduled task (&quot;CrysomeLoader&quot;) re-firing every five minutes (<code>T1053.005</code>); the RAT provides hidden VNC, arbitrary command execution and Chromium-browser credential theft, defeating Chrome&#39;s App-Bound Encryption via a decryptor DLL (<code>T1555.003</code>).</p><aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the operators combine almost entirely open-source/off-the-shelf components rather than custom development, so — as LevelBlue notes — detecting the individual behavioural stages (AMSI-bypass PowerShell, ICMLuaUtil COM abuse, Defender-exclusion registry writes under <code>Software\Microsoft\Windows Defender\Exclusions</code>, svchost.exe from a non-System32 path) gives multiple disruption points before the RAT establishes; freight/logistics lures make transport-sector helpdesks a natural target, but the chain is theme-agnostic and transferable.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">By combining an AMSI bypass, an open-source Defender tampering utility, and the modular CrySome RAT client, the operators minimize custom development while still achieving privilege escalation, defense evasion, persistence, credential theft, and remote access.</p><p class="entry-cite__quote">The actor then targeted host defenses by executing WinDefCtl, an open-source Defender disruption utility, masquerading as svchost.exe from %TEMP%.</p><figcaption class="entry-cite__attr"><a href="https://www.levelblue.com/blogs/spiderlabs-blog/from-phishing-to-persistence-a-crysome-rat-infection-chain-analysis" target="_blank" rel="noopener noreferrer">LevelBlue (Trustwave) SpiderLabs</a> <span class="entry-cite__date mono">2026-07-06</span></figcaption></figure></div><div class="prov"><span>threat</span><span>08 Jul 20:35Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-08/crysome-rat-freight-phishing-amsi-uac-defender-chain/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.levelblue.com/blogs/spiderlabs-blog/from-phishing-to-persistence-a-crysome-rat-infection-chain-analysis" target="_blank" rel="noopener noreferrer">LevelBlue (Trustwave) SpiderLabs</a></div></article>]]></content:encoded></item><item><title>Netherlands NIS2 (Cyberbeveiligingswet) slips — Senate vote 7 July, entry into force now 15 August 2026</title><link>https://ctipilot.ch/entries/2026-07-05/weekly-w27-netherlands-nis2-slip/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-05/weekly-w27-netherlands-nis2-slip/</guid><pubDate>Sun, 05 Jul 2026 23:42:00 +0000</pubDate><dc:date>2026-07-05T23:42:00Z</dc:date><category>law-enforcement</category><category>europe</category><description><![CDATA[<p>The Dutch NIS2 transposition (Cyberbeveiligingswet) missed the 1 July 2026 entry-into-force target reported in prior coverage. The Eerste Kamer (Senate) tabled its response to the second committee report on 29 June — the last written step before debate — and its bill-tracking page now sets the floor vote for 7 July, with the government&#39;s revised entry-into-force target 15 August 2026. Substantive scope is unchanged (NCSC-NL supervisor, 24h/72h/1-month notification, fines to EUR 10M/2%, board liability, ~1,000→~8,000 in-scope entities).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-05/weekly-w27-netherlands-nis2-slip" data-tags="law-enforcement" data-regions="europe" data-kind="policy" data-priority="notable" data-discovered="2026-07-05T23:42:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b upd">update</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 2: Probably true"><span class="k">NATO</span>A2</span></div><h3 class="f-h" id="weekly-w27-netherlands-nis2-slip"><a href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-netherlands-nis2-slip/">Netherlands NIS2 transposition slips past its 1 July target — Senate vote set for 7 July, entry into force now 15 August 2026</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-06-29/netherlands-nis2-cyberbeveiligingswet-clears-the-lower-house/">Netherlands NIS2 (Cyberbeveiligingswet) clears the lower house — entry into force targeted for 1 July 2026</a> <span class="mono muted">(2026-06-29)</span></p><p>the Dutch NIS2 transposition — the Cyberbeveiligingswet (Cbw) plus the companion Wet weerbaarheid kritieke entiteiten — has missed the 1 July 2026 entry-into-force target the prior weekly reported as the government&#39;s goal.</p>
<p>The Eerste Kamer (Senate) tabled its government response to the second committee report (&quot;nota naar aanleiding van het tweede verslag&quot;) on 29 June 2026 — the last written-preparation step before plenary debate — and the Senate&#39;s own bill-tracking page now states the floor vote will take place on <strong>7 July 2026</strong>, noting the bill was adopted by the Tweede Kamer on 15 April 2026 (<a href="https://www.eerstekamer.nl/wetsvoorstel/36764_cyberbeveiligingswet" target="_blank" rel="noopener noreferrer">Eerste Kamer, bill 36764</a>). iBestuur reports the government&#39;s revised entry-into-force target is now <strong>15 August 2026</strong>, roughly six weeks later than previously communicated (<a href="https://ibestuur.nl/digitale-weerbaarheid/digitale-veiligheid/eerste-kamer-stemt-7-juli-over-cyberbeveiligingswet" target="_blank" rel="noopener noreferrer">iBestuur, 2026-07-01</a>).</p>
<p>The substantive scope is unchanged from prior coverage: NCSC-NL as designated supervisor, a three-step 24h/72h/one-month incident-notification protocol, essential-entity fines up to EUR 10M or 2% of global turnover, personal board liability for security-measure oversight, and an expansion of in-scope Dutch entities from roughly 1,000 to roughly 8,000. This is the fourth documented slip in the Dutch NIS2 timetable (originally targeted Q3 2025).</p><aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the only action for a Swiss/EU reader is administrative — re-anchor readiness milestones and contractual compliance-date references onto 15 August 2026 for any Dutch group entities, hosting, or counterparties. No technical control change follows from the date shift itself.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">De stemming in de Eerste Kamer vindt plaats op 7 juli 2026.</p><p class="entry-cite__quote">Het voorstel (EK, A) is op 15 april 2026 aangenomen door de Tweede Kamer.</p><figcaption class="entry-cite__attr"><a href="https://www.eerstekamer.nl/wetsvoorstel/36764_cyberbeveiligingswet" target="_blank" rel="noopener noreferrer">Eerste Kamer der Staten-Generaal (official bill page)</a></figcaption></figure></div><div class="prov"><span>policy</span><span>05 Jul 23:42Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-netherlands-nis2-slip/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.eerstekamer.nl/wetsvoorstel/36764_cyberbeveiligingswet" target="_blank" rel="noopener noreferrer">Eerste Kamer der Staten-Generaal (official bill page)</a> · <a href="https://ibestuur.nl/digitale-weerbaarheid/digitale-veiligheid/eerste-kamer-stemt-7-juli-over-cyberbeveiligingswet" target="_blank" rel="noopener noreferrer">iBestuur</a></div></article>]]></content:encoded></item><item><title>FortiBleed status — now attributed to INC Ransom / Lynx; 409 admin-access, 12 ransomware deployments</title><link>https://ctipilot.ch/entries/2026-07-05/weekly-w27-fortibleed-inc-lynx-attribution/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-05/weekly-w27-fortibleed-inc-lynx-attribution/</guid><pubDate>Sun, 05 Jul 2026 23:41:00 +0000</pubDate><dc:date>2026-07-05T23:41:00Z</dc:date><category>ransomware</category><category>data-breach</category><category>organized-crime</category><category>identity</category><category>global</category><category>europe</category><category>dach</category><description><![CDATA[<p>SOCRadar&#39;s Threat Research Unit published attribution evidence this week tying the FortiBleed FortiGate credential-theft infrastructure to the INC Ransom / Lynx ransomware operation — an operator was found logged into both groups&#39; negotiation panels and FortiBleed victim data overlaps INC&#39;s leak site. STRU revised the scale to ~11,250 FortiGate portals scanned, 409 admin-level, 354 full-domain compromises and at least 12 ransomware deployments, and claims the group holds an undisclosed Nextcloud zero-day (single-source, pending vendor disclosure — track, do not action).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-05/weekly-w27-fortibleed-inc-lynx-attribution" data-tags="ransomware data-breach organized-crime identity" data-regions="global europe dach" data-kind="synthesis" data-priority="notable" data-discovered="2026-07-05T23:41:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b upd">update</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="weekly-w27-fortibleed-inc-lynx-attribution"><a href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-fortibleed-inc-lynx-attribution/">FortiBleed status update — the FortiGate credential-theft campaign is now attributed to INC Ransom / Lynx, with a scaled-up victim count and an unconfirmed Nextcloud zero-day claim</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-06-29/fortibleed/">FortiBleed</a> <span class="mono muted">(2026-06-29)</span></p><p>FortiBleed — the FortiGate credential-exposure campaign the prior two weeklies tracked from disclosure (86,644+ then 73,932+ exposed credentials) through the Golang &quot;FortigateSniffer&quot; tool (abusing FortiOS&#39;s native <code>diagnose sniffer packet</code>) and an AD-domain-takeover at a NATO-aligned defence contractor — gained a ransomware attribution and a scale revision this week.</p>
<p><strong>Attribution to INC Ransom / Lynx.</strong> SOCRadar&#39;s Threat Research Unit published evidence tying FortiBleed&#39;s infrastructure directly to two active ransomware operations: an operator with access to FortiBleed infrastructure was found logged into the negotiation panels of both <strong>INC Ransom</strong> and <strong>Lynx</strong> (which SOCRadar assesses, per other researchers, to be an INC rebrand rather than a distinct group), and FortiBleed victim data overlaps victims on INC Ransom&#39;s leak site — the first direct evidence linking the mass FortiGate credential theft to a specific ransomware-deployment pipeline (<a href="https://socradar.io/blog/fortibleed-inc-lynx-ransomware-link/" target="_blank" rel="noopener noreferrer">SOCRadar STRU, 2026-07-01</a>; <a href="https://www.bleepingcomputer.com/news/security/fortibleed-credential-theft-campaign-linked-to-lynx-ransomware/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-07-01</a>). STRU characterises the operation as an ~20-person Initial Access Broker business with a tiered internal structure exposed via an opsec lapse.</p>
<p><strong>Scale revision.</strong> STRU reports scanning against ~11,250 FortiGate portals across 150+ countries, admin-level access confirmed on 409 targets, full domain compromise on 354, and at least 12 confirmed ransomware deployments to date — sharpening the risk picture from &quot;credential exposure&quot; to &quot;credential exposure feeding an active RaaS deployment pipeline.&quot;</p>
<p><strong>Unconfirmed Nextcloud zero-day (track, do not action).</strong> STRU further states the group possesses at least one undisclosed Nextcloud zero-day, with SOCRadar coordinating responsible disclosure. This is a single-source claim pending vendor confirmation and carries no CVE — but given Nextcloud&#39;s data-sovereignty-driven prevalence in Swiss and German public-sector and SME estates, it belongs on the watch list for an immediate patch once Nextcloud publishes. The durable defender action is unchanged: treat any FortiGate exposed in the May–June window as having leaked credentials, rotate, and hunt the sniffer technique. New registry entity this run: <code>actor:inc-ransom</code> (aliases INC Ransomware, Lynx).</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Scanning activity against roughly 11,250 FortiGate portals in more than 150 countries, with admin-level access confirmed on 409 targets</p><figcaption class="entry-cite__attr"><a href="https://socradar.io/blog/fortibleed-inc-lynx-ransomware-link/" target="_blank" rel="noopener noreferrer">SOCRadar (STRU)</a></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">During the investigation of that server, analysis of the collected artifacts revealed that the threat actor had accessed the ransomware negotiation panels of both the Lynx / INC ransomware group.</p><figcaption class="entry-cite__attr">BleepingComputer (citing SOCRadar)</figcaption></figure></div><div class="prov"><span>synthesis</span><span>05 Jul 23:41Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-fortibleed-inc-lynx-attribution/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://socradar.io/blog/fortibleed-inc-lynx-ransomware-link/" target="_blank" rel="noopener noreferrer">SOCRadar (STRU)</a> · <a href="https://www.bleepingcomputer.com/news/security/fortibleed-credential-theft-campaign-linked-to-lynx-ransomware/" target="_blank" rel="noopener noreferrer">BleepingComputer</a></div></article>]]></content:encoded></item><item><title>CVE-2026-14439 — Altium Enterprise Server / Altium 365: authenticated path-traversal to RCE</title><link>https://ctipilot.ch/entries/2026-07-02/cve-2026-14439-altium-enterprise-server-altium-365-authentic/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-02/cve-2026-14439-altium-enterprise-server-altium-365-authentic/</guid><pubDate>Thu, 02 Jul 2026 04:55:21 +0000</pubDate><dc:date>2026-07-02T04:55:21Z</dc:date><category>vulnerabilities</category><category>rce</category><category>path-traversal</category><category>patch-available</category><category>europe</category><category>patch-available</category><category>CVE-2026-14439</category><description><![CDATA[<p>A CWE-22 path-traversal flaw (CVSS 9.4) in the Git Service component shared by Altium Enterprise Server and the Altium 365 SaaS platform (electronics CAD / PCB-design collaboration) lets an authenticated user with only basic git access chain a sequence of post-clone file-manipulation operations that accept …</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-02/cve-2026-14439-altium-enterprise-server-altium-365-authentic" data-tags="vulnerabilities rce path-traversal patch-available" data-regions="europe" data-kind="vulnerability" data-priority="notable" data-discovered="2026-07-02T04:55:21Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-14439/">CVE-2026-14439</a></div><h3 class="f-h" id="cve-2026-14439-altium-enterprise-server-altium-365-authentic"><a href="https://ctipilot.ch/entries/2026-07-02/cve-2026-14439-altium-enterprise-server-altium-365-authentic/">CVE-2026-14439 — Altium Enterprise Server / Altium 365: authenticated path-traversal to RCE</a></h3><p>A CWE-22 path-traversal flaw (CVSS 9.4) in the Git Service component shared by Altium Enterprise Server and the Altium 365 SaaS platform (electronics CAD / PCB-design collaboration) lets an authenticated user with only basic git access chain a sequence of post-clone file-manipulation operations that accept user-supplied paths without validation, moving arbitrary files outside the intended repository. Because moved files can land in locations later executed by the Git Service, the primitive escalates to remote code execution under the Git Service account; on multi-tenant Altium 365 the flaw could expose data belonging to other tenants sharing the same node (<a href="https://github.com/advisories/GHSA-m97g-7h77-r5pr" target="_blank" rel="noopener noreferrer">GitHub Security Advisory GHSA-m97g-7h77-r5pr, 2026-07-02</a>). Altium Enterprise Server is fixed in 8.1.1; Altium 365&#39;s shared multi-tenant deployments were remediated at the service level, with remaining deployments in progress. No exploitation reported. The low privilege bar plus cross-tenant SaaS exposure make this notable for CH/EU manufacturing and defence-industrial-base engineering firms; multi-tenant customers should confirm with Altium that their specific node received the service-level fix rather than assuming blanket coverage.</p><div class="prov"><span>vulnerability</span><span>02 Jul 04:55Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-02/cve-2026-14439-altium-enterprise-server-altium-365-authentic/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://github.com/advisories/GHSA-m97g-7h77-r5pr" target="_blank" rel="noopener noreferrer">GitHub Security Advisory GHSA-m97g-7h77-r5pr</a></div></article>]]></content:encoded></item><item><title>Nissan is the largest named victim yet in the ShinyHunters Oracle PeopleSoft campaign</title><link>https://ctipilot.ch/entries/2026-07-01/nissan-is-the-largest-named-victim-yet-in-the-shinyhunters-o/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-01/nissan-is-the-largest-named-victim-yet-in-the-shinyhunters-o/</guid><pubDate>Wed, 01 Jul 2026 04:41:20 +0000</pubDate><dc:date>2026-07-01T04:41:20Z</dc:date><category>data-breach</category><category>vulnerabilities</category><category>actively-exploited</category><category>global</category><category>exploited</category><category>CVE-2026-35273</category><description><![CDATA[<p>The ShinyHunters Oracle PeopleSoft campaign adds Nissan as its largest named victim yet — current and former employee HR/payroll PII across four countries, a different exposure profile than the NAIC breach covered 2026-06-28 (SecurityWeek, 2026-06-30).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-01/nissan-is-the-largest-named-victim-yet-in-the-shinyhunters-o" data-tags="data-breach vulnerabilities actively-exploited" data-regions="global" data-kind="vulnerability" data-priority="high" data-discovered="2026-07-01T04:41:20Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-35273/">CVE-2026-35273</a><span class="b exp">exploited</span><span class="b upd">update</span></div><h3 class="f-h" id="nissan-is-the-largest-named-victim-yet-in-the-shinyhunters-o"><a href="https://ctipilot.ch/entries/2026-07-01/nissan-is-the-largest-named-victim-yet-in-the-shinyhunters-o/">Nissan is the largest named victim yet in the ShinyHunters Oracle PeopleSoft campaign</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-06-28/naic-breached-via-oracle-peoplesoft-zero-day-shinyhunters-pu/">NAIC breached via Oracle PeopleSoft zero-day; ShinyHunters publishes 3.1 TB of US insurance-regulatory data and rating-agency feeds pause</a> <span class="mono muted">(2026-06-28)</span></p><p>Nissan disclosed that current and former employees&#39; data was exposed via CVE-2026-35273, the Oracle PeopleSoft PeopleTools pre-auth flaw exploited as a zero-day between 2026-05-27 and 2026-06-09 as part of the wider ShinyHunters campaign (<a href="https://www.securityweek.com/nissan-employee-data-breached-in-oracle-peoplesoft-hack/" target="_blank" rel="noopener noreferrer">SecurityWeek, 2026-06-30</a>). The exposure spans current and former employees in the US, Canada, Mexico and Brazil, potentially including Social Security numbers, banking/direct-deposit information and tax records.</p>
<p>This is a materially different victim profile from the previously-covered NAIC breach — employee HR/payroll PII rather than regulatory data — showing the campaign spreading across both regulatory-body and corporate-HR PeopleSoft deployments. As mitigation, Nissan restricted pay-slip viewing and direct-deposit changes to company-network/VPN-authenticated sessions and is offering credit/dark-web monitoring (<a href="https://www.bleepingcomputer.com/news/security/nissan-discloses-employee-data-breach-linked-to-oracle-zero-day-attacks/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-06-29</a>). ShinyHunters&#39; self-reported scale of &quot;over 300 PeopleSoft instances across ~100 organizations&quot; is an unverified actor claim — attribute the claim, not confirmed fact. No new technical detail beyond victim-count expansion; the operative guidance from the 2026-06-28 NAIC item stands (patch CVE-2026-35273; remove internet-exposed PeopleSoft PeopleTools from public reachability).</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">UPDATE (originally covered 2026-06-28 as the NAIC breach): Nissan disclosed that current and former employees&#39; data was exposed via CVE-2026-35273, the Oracle PeopleSoft PeopleTools pre-auth flaw exploited as a zero-day between 2026-05-27 and 2026-06-09 as part of the wider ShinyHunters campaign …</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>01 Jul 04:41Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-01/nissan-is-the-largest-named-victim-yet-in-the-shinyhunters-o/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.securityweek.com/nissan-employee-data-breached-in-oracle-peoplesoft-hack/" target="_blank" rel="noopener noreferrer">SecurityWeek</a> · <a href="https://www.bleepingcomputer.com/news/security/nissan-discloses-employee-data-breach-linked-to-oracle-zero-day-attacks/" target="_blank" rel="noopener noreferrer">BleepingComputer</a></div></article>]]></content:encoded></item><item><title>Blackfield ransomware demands $2M from Nidec&#39;s Taiwanese subsidiary after a 22 June server compromise</title><link>https://ctipilot.ch/entries/2026-07-01/blackfield-ransomware-demands-2m-from-nidec-s-taiwanese-subs/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-01/blackfield-ransomware-demands-2m-from-nidec-s-taiwanese-subs/</guid><pubDate>Wed, 01 Jul 2026 04:41:15 +0000</pubDate><dc:date>2026-07-01T04:41:15Z</dc:date><category>ransomware</category><category>data-breach</category><category>apac</category><description><![CDATA[<p>Nidec Corporation&#39;s own investor-relations disclosure (2026-06-24, Tokyo Stock Exchange 6594) confirmed that its Taiwanese subsidiary Nidec Chaun Choung Technology suffered &quot;ransomware-originated damage&quot; to part of a subsidiary server on 2026-06-22, that the affected server and network were shut down as an emergency …</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-01/blackfield-ransomware-demands-2m-from-nidec-s-taiwanese-subs" data-tags="ransomware data-breach" data-regions="apac" data-kind="incident" data-priority="notable" data-discovered="2026-07-01T04:41:15Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="blackfield-ransomware-demands-2m-from-nidec-s-taiwanese-subs"><a href="https://ctipilot.ch/entries/2026-07-01/blackfield-ransomware-demands-2m-from-nidec-s-taiwanese-subs/">Blackfield ransomware demands $2M from Nidec&#39;s Taiwanese subsidiary after a 22 June server compromise</a></h3><p>Nidec Corporation&#39;s own investor-relations disclosure (2026-06-24, Tokyo Stock Exchange 6594) confirmed that its Taiwanese subsidiary Nidec Chaun Choung Technology suffered &quot;ransomware-originated damage&quot; to part of a subsidiary server on 2026-06-22, that the affected server and network were shut down as an emergency measure, and that the subsidiary runs an independent network isolated from the wider Nidec Group so parent operations are unaffected (<a href="https://www.nidec.com/files/user/www-nidec-com/corporate/news/2026/0624-01/260624-01en.pdf" target="_blank" rel="noopener noreferrer">Nidec Corporation, 2026-06-24</a>). The in-window development: BleepingComputer reported on 2026-06-30 that the Blackfield ransomware crew claims the intrusion, is demanding $2 million to delete allegedly stolen data with a 15-day negotiation deadline, and is separately advertising the archive for immediate sale (<a href="https://www.bleepingcomputer.com/news/security/blackfield-ransomware-asks-nidec-corporation-for-2-million-ransom/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-06-30</a>). Note the gap between the actor&#39;s exfiltration claim and Nidec&#39;s own statement, which as of 2026-06-24 says no personal or confidential data had been confirmed leaked — Blackfield <em>claims</em> data theft; Nidec has not confirmed a leak.</p>
<p><strong>Why it matters to us:</strong> subsidiary/OT-adjacent segmentation is doing its job here (isolated subsidiary network limited blast radius) — a concrete counter-example worth citing when arguing for network isolation of acquired-company and regional-subsidiary estates. Attribute the extortion claim, not confirmed exfiltration.</p><div class="prov"><span>incident</span><span>01 Jul 04:41Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-01/blackfield-ransomware-demands-2m-from-nidec-s-taiwanese-subs/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.nidec.com/files/user/www-nidec-com/corporate/news/2026/0624-01/260624-01en.pdf" target="_blank" rel="noopener noreferrer">Nidec Corporation disclosure</a> · <a href="https://www.bleepingcomputer.com/news/security/blackfield-ransomware-asks-nidec-corporation-for-2-million-ransom/" target="_blank" rel="noopener noreferrer">BleepingComputer</a></div></article>]]></content:encoded></item><item><title>Bumblebee → AdaptixC2 → Akira: a full SEO-poisoning-to-ransomware kill chain with a parallel Swiss intrusion</title><link>https://ctipilot.ch/entries/2026-06-30/bumblebee-adaptixc2-akira-a-full-seo-poisoning-to-ransomware/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-30/bumblebee-adaptixc2-akira-a-full-seo-poisoning-to-ransomware/</guid><pubDate>Tue, 30 Jun 2026 05:10:44 +0000</pubDate><dc:date>2026-06-30T05:10:44Z</dc:date><category>ransomware</category><category>organized-crime</category><category>infostealer</category><category>switzerland</category><category>global</category><description><![CDATA[<p>The DFIR Report published (2026-06-29) the full reconstruction of an intrusion that began with SEO poisoning and ended in Akira ransomware in under three days.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-30/bumblebee-adaptixc2-akira-a-full-seo-poisoning-to-ransomware" data-tags="ransomware organized-crime infostealer" data-regions="switzerland global" data-kind="threat" data-priority="notable" data-discovered="2026-06-30T05:10:44Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="bumblebee-adaptixc2-akira-a-full-seo-poisoning-to-ransomware"><a href="https://ctipilot.ch/entries/2026-06-30/bumblebee-adaptixc2-akira-a-full-seo-poisoning-to-ransomware/">Bumblebee → AdaptixC2 → Akira: a full SEO-poisoning-to-ransomware kill chain with a parallel Swiss intrusion</a></h3><p>The DFIR Report published (2026-06-29) the full reconstruction of an intrusion that began with SEO poisoning and ended in Akira ransomware in under three days. The report notes the case was first shared in a 2025 threat brief and flash alert produced with Swisscom B2B CSIRT, which observed a parallel intrusion tied to the same campaign — a Swiss-nexus thread (from that 2025 collaboration) that makes the now-public full reconstruction worth the day&#39;s deep dive (<a href="https://thedfirreport.com/2026/06/29/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-3/" target="_blank" rel="noopener noreferrer">The DFIR Report, 2026-06-29</a>). It also features the open-source <strong>AdaptixC2</strong> post-exploitation framework as the Cobalt-Strike-equivalent in an Akira chain. Akira itself was deep-dived on 2026-06-23 via the SonicWall vector; this is a distinct initial-access path against the same end-stage operator.</p>
<p><strong>Initial access and loader.</strong> A poisoned Bing result for &quot;ManageEngine OpManager&quot; led to a trojanized MSI installer (<code>T1608.006</code> SEO poisoning → <a href="https://attack.mitre.org/techniques/T1204/002/" target="_blank" rel="noopener noreferrer"><code>T1204.002</code> Malicious File</a>). The <strong>Bumblebee</strong> loader established first C2 via <a href="https://attack.mitre.org/techniques/T1574/001/" target="_blank" rel="noopener noreferrer">DLL search-order hijacking (<code>T1574.001</code>)</a> — a legitimate signed binary loading a same-directory <code>msimg32.dll</code> through <code>consent.exe</code>. Within ~5 hours, AdaptixC2 shellcode was injected into a renamed legitimate Windows Address Book utility, giving persistent interactive C2.</p>
<p><strong>Escalation, discovery, lateral movement.</strong> The actor created domain accounts with Enterprise Admin privileges using RSAT (<a href="https://attack.mitre.org/techniques/T1136/002/" target="_blank" rel="noopener noreferrer"><code>T1136.002</code> Create Account: Domain Account</a>), enumerated the network with SoftPerfect Network Scanner, Zenmap, and RVTools (<code>T1046</code>), and moved laterally over <a href="https://attack.mitre.org/techniques/T1021/001/" target="_blank" rel="noopener noreferrer">RDP (<code>T1021.001</code>)</a>. A legitimate <strong>RustDesk</strong> remote-access tool was installed as a redundant access channel (<a href="https://attack.mitre.org/techniques/T1219/" target="_blank" rel="noopener noreferrer"><code>T1219</code> Remote Access Software</a>).</p>
<p><strong>Credential access and collection.</strong> Credentials were harvested by extracting <a href="https://attack.mitre.org/techniques/T1003/003/" target="_blank" rel="noopener noreferrer">NTDS.dit via <code>wbadmin.exe</code> (<code>T1003.003</code>)</a> and by dumping the Veeam backup database — the latter a recurring Akira-affiliate move that doubles as recovery sabotage. Roughly 77 GB was staged and exfiltrated over ~44 hours via FileZilla/SFTP to an external server (<code>T1048</code>/<code>T1567</code>).</p>
<p><strong>Impact.</strong> <a href="https://attack.mitre.org/techniques/T1486/" target="_blank" rel="noopener noreferrer">Akira ransomware (<code>T1486</code>)</a> was deployed across root and child domains over <a href="https://attack.mitre.org/techniques/T1047/" target="_blank" rel="noopener noreferrer">WMI (<code>T1047</code>)</a>, with shadow copies deleted via <code>vssadmin</code> (<a href="https://attack.mitre.org/techniques/T1490/" target="_blank" rel="noopener noreferrer"><code>T1490</code> Inhibit System Recovery</a>).</p>
<p><strong>Detection concepts (no IOCs).</strong> Per stage: Sysmon EID 1 for a signed binary / <code>consent.exe</code> side-loading <code>msimg32.dll</code> from a user-writable path; EID 11 for new executables written into AppData; EID 4104 for PowerShell carrying credential-access tradecraft; EID 4663 on NTDS.dit handle access; WMI-driven remote process creation (EID 4648 plus network logon type 3) from non-admin hosts; EID 4698 scheduled-task creation from unusual parents; and DLP/file-server alerts on large outbound SFTP staging. Treat any RustDesk install you did not deploy as a finding.</p>
<p><strong>Hardening.</strong> Category-block software-download SEO traps at the SWG and require signed, hash-verified installers for IT-admin tooling; constrain who can create domain accounts and alert on new Enterprise Admin members; protect NTDS.dit / enable Credential Guard; restrict remote WMI to tiered admin hosts; harden Veeam service-account credentials and isolate the backup plane; and alert on unsanctioned remote-access tools (RustDesk/AnyDesk) at the proxy and EDR.</p><div class="prov"><span>threat</span><span>30 Jun 05:10Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-30/bumblebee-adaptixc2-akira-a-full-seo-poisoning-to-ransomware/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://thedfirreport.com/2026/06/29/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-3/" target="_blank" rel="noopener noreferrer">The DFIR Report</a></div></article>]]></content:encoded></item><item><title>Mustang Panda abuses Zoho WorkDrive as a dead-drop C2 channel (ZOHOMURK) against government and energy targets</title><link>https://ctipilot.ch/entries/2026-06-30/mustang-panda-abuses-zoho-workdrive-as-a-dead-drop-c2-channe/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-30/mustang-panda-abuses-zoho-workdrive-as-a-dead-drop-c2-channe/</guid><pubDate>Tue, 30 Jun 2026 05:10:34 +0000</pubDate><dc:date>2026-06-30T05:10:34Z</dc:date><category>espionage</category><category>nation-state</category><category>china-nexus</category><category>cloud</category><category>apac</category><category>europe</category><description><![CDATA[<p>Acronis Threat Research Unit documented two coordinated June 12–22 campaigns by China-aligned Mustang Panda (also tracked TA416 / HIVE0154 / BRONZE PRESIDENT) against Indian government bodies and hydropower-sector entities (Acronis TRU, 2026-06-29 · The Hacker News, 2026-06-29).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-30/mustang-panda-abuses-zoho-workdrive-as-a-dead-drop-c2-channe" data-tags="espionage nation-state china-nexus cloud" data-regions="apac europe" data-kind="threat" data-priority="notable" data-discovered="2026-06-30T05:10:34Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="mustang-panda-abuses-zoho-workdrive-as-a-dead-drop-c2-channe"><a href="https://ctipilot.ch/entries/2026-06-30/mustang-panda-abuses-zoho-workdrive-as-a-dead-drop-c2-channe/">Mustang Panda abuses Zoho WorkDrive as a dead-drop C2 channel (ZOHOMURK) against government and energy targets</a></h3><p>Acronis Threat Research Unit documented two coordinated June 12–22 campaigns by China-aligned Mustang Panda (also tracked TA416 / HIVE0154 / BRONZE PRESIDENT) against Indian government bodies and hydropower-sector entities (<a href="https://www.acronis.com/en/tru/posts/mustang-panda-targets-indias-government-and-energy-sectors/" target="_blank" rel="noopener noreferrer">Acronis TRU, 2026-06-29</a> · <a href="https://thehackernews.com/2026/06/mustang-panda-uses-zoho-workdrive-as.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-06-29</a>). Initial access is spear-phishing with ZIP-delivered lures (a hydropower cooperation proposal; an India–Taiwan memorandum of understanding). The toolkit introduces SHARDLOADER (DLL side-loading through a legitimate Solid PDF Creator / Citrix Receiver binary, loading shellcode from fragmented files to defeat static scanning — <code>T1574.002</code>), MINIRECON (a reworked Toneshell variant beaconing over <code>wss://</code>), and ZOHOMURK, which carries hardcoded Zoho OAuth credentials to drive an attacker-controlled WorkDrive account as a dead-drop resolver (<code>T1102.001</code>) — reading operator commands from an &quot;inbox&quot; folder and writing exfiltrated output to an &quot;outbox&quot;, blending all C2 with legitimate <code>workdrive.zoho.com</code> API traffic.</p>
<p><strong>Why it matters to us:</strong> Abusing a legitimate SaaS platform&#39;s API for C2 defeats egress controls that allowlist well-known cloud providers — the traffic blends with sanctioned <code>workdrive.zoho.com</code> calls. EU public-sector SOCs should extend CASB/DLP allowlisting to less-obvious SaaS such as Zoho WorkDrive and alert on OAuth token grants for cloud apps that are not sanctioned business tools.</p><div class="prov"><span>threat</span><span>30 Jun 05:10Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-30/mustang-panda-abuses-zoho-workdrive-as-a-dead-drop-c2-channe/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.acronis.com/en/tru/posts/mustang-panda-targets-indias-government-and-energy-sectors/" target="_blank" rel="noopener noreferrer">Acronis Threat Research Unit</a> · <a href="https://thehackernews.com/2026/06/mustang-panda-uses-zoho-workdrive-as.html" target="_blank" rel="noopener noreferrer">The Hacker News</a></div></article>]]></content:encoded></item><item><title>The Gentlemen</title><link>https://ctipilot.ch/entries/2026-06-29/the-gentlemen/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-29/the-gentlemen/</guid><pubDate>Mon, 29 Jun 2026 00:21:21 +0000</pubDate><dc:date>2026-06-29T00:21:21Z</dc:date><category>ransomware</category><category>organized-crime</category><category>russia-nexus</category><category>switzerland</category><category>dach</category><category>europe</category><description><![CDATA[<p>The Gentlemen ransomware makes Switzerland the second-most-targeted European country, claims 478 victims and adds worm propagation — ESET&#39;s leaked-data deep-dive shows victims are chosen on FortiGate misconfiguration, tying the pipeline to FortiBleed reconnaissance. (daily 06-27, inside-it.ch)</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-29/the-gentlemen" data-tags="ransomware organized-crime russia-nexus" data-regions="switzerland dach europe" data-kind="synthesis" data-priority="high" data-discovered="2026-06-29T00:21:21Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="the-gentlemen"><a href="https://ctipilot.ch/entries/2026-06-29/the-gentlemen/">The Gentlemen</a></h3><p>The W25 multi-day item now has primary-evidence depth (the ESET deep-dive, § 7) and a sharp Swiss angle: Check Point data, reported by Swiss tech press, makes <a href="https://www.inside-it.ch/aufstrebende-ransomware-bande-findet-mehr-schweizer-opfer-20260626" target="_blank" rel="noopener noreferrer">Switzerland the second-most-targeted European country</a> for the operation, which now claims 478 victims and has added worm propagation. The operationally important link is that victim selection runs on FortiGate misconfiguration scanning — so a Swiss organisation&#39;s FortiBleed exposure (above) is also its Gentlemen-victim-selection exposure. Outstanding for defenders: the same FortiGate hardening that closes FortiBleed reduces Gentlemen targeting, and EDR-tamper-protection plus driver-blocklist enforcement is the GentleKiller counter.</p><div class="prov"><span>synthesis</span><span>29 Jun 00:21Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/the-gentlemen/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.inside-it.ch/aufstrebende-ransomware-bande-findet-mehr-schweizer-opfer-20260626" target="_blank" rel="noopener noreferrer">inside-it.ch</a> · <a href="https://www.welivesecurity.com/en/eset-research/killing-me-gently-inside-gentlemens-edr-killer-framework/" target="_blank" rel="noopener noreferrer">ESET WeLiveSecurity</a></div></article>]]></content:encoded></item><item><title>ESET &quot;Killing me gently&quot; — a de-facto mid-year RaaS-tooling report</title><link>https://ctipilot.ch/entries/2026-06-29/eset-killing-me-gently-a-de-facto-mid-year-raas-tooling-repo/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-29/eset-killing-me-gently-a-de-facto-mid-year-raas-tooling-repo/</guid><pubDate>Mon, 29 Jun 2026 00:21:17 +0000</pubDate><dc:date>2026-06-29T00:21:17Z</dc:date><category>ransomware</category><category>organized-crime</category><category>russia-nexus</category><category>global</category><category>europe</category><category>switzerland</category><description><![CDATA[<p>Background. The Gentlemen emerged in late 2025 as a RaaS operation founded by &quot;hastalamuerte&quot; (a former Qilin affiliate per Group-IB, previously affiliated with Embargo, LockBit, Medusa and BlackLock per PRODAFT).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-29/eset-killing-me-gently-a-de-facto-mid-year-raas-tooling-repo" data-tags="ransomware organized-crime russia-nexus" data-regions="global europe switzerland" data-kind="annual-report" data-priority="notable" data-discovered="2026-06-29T00:21:17Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="eset-killing-me-gently-a-de-facto-mid-year-raas-tooling-repo"><a href="https://ctipilot.ch/entries/2026-06-29/eset-killing-me-gently-a-de-facto-mid-year-raas-tooling-repo/">ESET &quot;Killing me gently&quot; — a de-facto mid-year RaaS-tooling report</a></h3><p><strong>Background.</strong> The Gentlemen emerged in late 2025 as a RaaS operation founded by &quot;hastalamuerte&quot; (a former Qilin affiliate per Group-IB, previously affiliated with Embargo, LockBit, Medusa and BlackLock per PRODAFT). ESET first hypothesised an in-house EDR-killer in February 2026; Group-IB and Check Point independently corroborated before the gang&#39;s own internal data leaked. By April 2026 the group accounted for ~10% of global ransomware activity, and Krebs (06-10) linked the alias to a named individual in Izhevsk, Russia.</p>
<p>ESET&#39;s 06-26 deep-dive into the leaked internal data is the most substantive published-in-window documentation of RaaS tooling structure, and reads as a mid-year complement to the W25 Check Point State of Ransomware Q1 2026. Three structural findings a detection engineer should register: (1) GentleKiller is a modular in-house framework with at least eight BYOVD variants, each impersonating a different vendor and abusing a different kernel driver — driver allow-listing alone is insufficient without process-injection-chain detection; (2) the group integrates <em>rival gangs&#39;</em> EDR killers (HexKiller from Warlock, ThrottleBlood shared with MedusaLocker/DragonForce, HavocKiller), so tooling overlap no longer implies operational overlap; (3) victims are selected centrally on FortiGate misconfiguration rather than geography, tying the Gentlemen victim pipeline directly to FortiBleed-style reconnaissance (§ 8). New BYOVD PoCs are operationalised within days of public release. (<a href="https://ctipilot.ch/briefs/2026-06-27/" target="_blank" rel="noopener noreferrer">daily 06-27</a>)</p><div class="prov"><span>annual-report</span><span>29 Jun 00:21Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/eset-killing-me-gently-a-de-facto-mid-year-raas-tooling-repo/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.welivesecurity.com/en/eset-research/killing-me-gently-inside-gentlemens-edr-killer-framework/" target="_blank" rel="noopener noreferrer">ESET WeLiveSecurity</a> · <a href="https://www.eset.com/us/about/newsroom/research/eset-research-gentlemen-ransomware-gang-edr-killers/" target="_blank" rel="noopener noreferrer">ESET Newsroom</a></div></article>]]></content:encoded></item><item><title>Attribution and accountability: Jaguar Land Rover and Scattered Spider</title><link>https://ctipilot.ch/entries/2026-06-29/attribution-and-accountability-jaguar-land-rover-and-scatter/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-29/attribution-and-accountability-jaguar-land-rover-and-scatter/</guid><pubDate>Mon, 29 Jun 2026 00:21:13 +0000</pubDate><dc:date>2026-06-29T00:21:13Z</dc:date><category>ransomware</category><category>organized-crime</category><category>law-enforcement</category><category>russia-nexus</category><category>uk</category><category>europe</category><description><![CDATA[<p>Two disclosures closed loops opened months ago.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-29/attribution-and-accountability-jaguar-land-rover-and-scatter" data-tags="ransomware organized-crime law-enforcement russia-nexus" data-regions="uk europe" data-kind="incident" data-priority="notable" data-discovered="2026-06-29T00:21:13Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="attribution-and-accountability-jaguar-land-rover-and-scatter"><a href="https://ctipilot.ch/entries/2026-06-29/attribution-and-accountability-jaguar-land-rover-and-scatter/">Attribution and accountability: Jaguar Land Rover and Scattered Spider</a></h3><p>Two disclosures closed loops opened months ago. A <a href="https://techcrunch.com/2026/06/26/russian-hackers-were-behind-2-5-billion-hack-of-jaguar-land-rover-report/" target="_blank" rel="noopener noreferrer">New York Times investigation</a> gave the first named attribution for the 2025 Jaguar Land Rover ransomware attack — a Russian state-linked criminal group — though investigators have not determined whether the operators worked for, independently of, or with the tacit approval of the Russian government. And two Scattered Spider members <a href="https://www.nationalcrimeagency.gov.uk/news/cyber-criminals-who-hacked-into-transport-for-londons-computer-network-are-convicted" target="_blank" rel="noopener noreferrer">pleaded guilty</a> over the 2024 Transport for London intrusion. Both reinforce that the dominant English-speaking extortion ecosystems are being mapped to named individuals and state-linked clusters.</p><div class="prov"><span>incident</span><span>29 Jun 00:21Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/attribution-and-accountability-jaguar-land-rover-and-scatter/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://techcrunch.com/2026/06/26/russian-hackers-were-behind-2-5-billion-hack-of-jaguar-land-rover-report/" target="_blank" rel="noopener noreferrer">TechCrunch — JLR/NYT</a> · <a href="https://www.nationalcrimeagency.gov.uk/news/cyber-criminals-who-hacked-into-transport-for-londons-computer-network-are-convicted" target="_blank" rel="noopener noreferrer">UK National Crime Agency — TfL</a></div></article>]]></content:encoded></item><item><title>CVE-2025-67038 — Lantronix EDS5000 serial-to-IP converters: unauthenticated command injection to root (BRIDGE:BREAK, CISA KEV)</title><link>https://ctipilot.ch/entries/2026-06-29/cve-2025-67038-lantronix-eds5000-serial-to-ip-converters-una/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-29/cve-2025-67038-lantronix-eds5000-serial-to-ip-converters-una/</guid><pubDate>Mon, 29 Jun 2026 00:21:00 +0000</pubDate><dc:date>2026-06-29T00:21:00Z</dc:date><category>vulnerabilities</category><category>actively-exploited</category><category>cisa-kev</category><category>pre-auth</category><category>rce</category><category>ot-ics</category><category>patch-available</category><category>global</category><category>europe</category><category>exploited</category><category>cisa-kev</category><category>patch-available</category><category>CVE-2025-67038</category><description><![CDATA[<p>Forescout Vedere Labs&#39; BRIDGE:BREAK research documented an unauthenticated OS command-injection flaw in Lantronix EDS5000-series device servers — the HTTP management interface concatenates unsanitised input into a shell call.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-29/cve-2025-67038-lantronix-eds5000-serial-to-ip-converters-una" data-tags="vulnerabilities actively-exploited cisa-kev pre-auth rce ot-ics patch-available" data-regions="global europe" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-29T00:21:00Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2025-67038/">CVE-2025-67038</a><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2025-67038-lantronix-eds5000-serial-to-ip-converters-una"><a href="https://ctipilot.ch/entries/2026-06-29/cve-2025-67038-lantronix-eds5000-serial-to-ip-converters-una/">CVE-2025-67038 — Lantronix EDS5000 serial-to-IP converters: unauthenticated command injection to root (BRIDGE:BREAK, CISA KEV)</a></h3><p>Forescout Vedere Labs&#39; <a href="https://www.forescout.com/blog/exploiting-serial-to-ethernet-converters-in-critical-infrastructure/" target="_blank" rel="noopener noreferrer">BRIDGE:BREAK research</a> documented an unauthenticated OS command-injection flaw in Lantronix EDS5000-series device servers — the HTTP management interface concatenates unsanitised input into a shell call. The in-window development is its CISA KEV listing on 2026-06-23 with confirmed in-the-wild exploitation (covered in <a href="https://ctipilot.ch/briefs/2026-06-24/" target="_blank" rel="noopener noreferrer">daily 06-24</a>) — the first BRIDGE:BREAK flaw to flip from research to active abuse. Serial-to-IP converters sit in front of OT, building-management and medical serial devices; firmware 2.0.0R1 closes it. This is an energy/water/healthcare exposure, not an IT one.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Forescout Vedere Labs&#39; BRIDGE:BREAK research documented an unauthenticated OS command-injection flaw in Lantronix EDS5000-series device servers — the HTTP management interface concatenates unsanitised input into a shell call.</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>29 Jun 00:21Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/cve-2025-67038-lantronix-eds5000-serial-to-ip-converters-una/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.forescout.com/blog/exploiting-serial-to-ethernet-converters-in-critical-infrastructure/" target="_blank" rel="noopener noreferrer">Forescout Vedere Labs — BRIDGE:BREAK</a> · <a href="https://www.securityweek.com/serial-to-ip-converter-flaws-expose-ot-and-healthcare-systems-to-hacking/" target="_blank" rel="noopener noreferrer">SecurityWeek</a></div></article>]]></content:encoded></item><item><title>CVE-2026-12569 — PTC Windchill / FlexPLM: pre-auth deserialization RCE, now confirmed exploited with JSP web shells (CISA KEV)</title><link>https://ctipilot.ch/entries/2026-06-29/cve-2026-12569-ptc-windchill-flexplm-pre-auth-deserializatio/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-29/cve-2026-12569-ptc-windchill-flexplm-pre-auth-deserializatio/</guid><pubDate>Mon, 29 Jun 2026 00:20:58 +0000</pubDate><dc:date>2026-06-29T00:20:58Z</dc:date><category>vulnerabilities</category><category>actively-exploited</category><category>rce</category><category>pre-auth</category><category>cisa-kev</category><category>global</category><category>europe</category><category>exploited</category><category>cisa-kev</category><category>patch-available</category><category>CVE-2026-12569</category><description><![CDATA[<p>When first covered (06-20) and in the W25 weekly this was a pre-auth deserialization flaw with BSI escalating to admins out-of-hours. The in-window delta: CISA added it to KEV on 06-25 and JSP web-shell deployment against the login interface is now confirmed in the wild.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-29/cve-2026-12569-ptc-windchill-flexplm-pre-auth-deserializatio" data-tags="vulnerabilities actively-exploited rce pre-auth cisa-kev" data-regions="global europe" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-29T00:20:58Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-12569/">CVE-2026-12569</a><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2026-12569-ptc-windchill-flexplm-pre-auth-deserializatio"><a href="https://ctipilot.ch/entries/2026-06-29/cve-2026-12569-ptc-windchill-flexplm-pre-auth-deserializatio/">CVE-2026-12569 — PTC Windchill / FlexPLM: pre-auth deserialization RCE, now confirmed exploited with JSP web shells (CISA KEV)</a></h3><p>When first covered (06-20) and in the W25 weekly this was a pre-auth deserialization flaw with BSI escalating to admins out-of-hours. The in-window delta: CISA <a href="https://thehackernews.com/2026/06/cisa-adds-exploited-ptc-windchill-rce.html" target="_blank" rel="noopener noreferrer">added it to KEV on 06-25</a> and JSP web-shell deployment against the login interface is now confirmed in the wild. Any internet-reachable Windchill PDMLink or FlexPLM instance should be treated as assume-compromise — manufacturing and defence-supplier PLM is exactly the externally-reachable engineering surface a Swiss/EU industrial estate forgets to inventory.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">When first covered (06-20) and in the W25 weekly this was a pre-auth deserialization flaw with BSI escalating to admins out-of-hours.</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>29 Jun 00:20Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/cve-2026-12569-ptc-windchill-flexplm-pre-auth-deserializatio/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://thehackernews.com/2026/06/cisa-adds-exploited-ptc-windchill-rce.html" target="_blank" rel="noopener noreferrer">The Hacker News</a> · <a href="https://euvd.enisa.europa.eu/enisa/eu_vulnerability_database/EUVD-2026-37831" target="_blank" rel="noopener noreferrer">ENISA EUVD EUVD-2026-37831</a></div></article>]]></content:encoded></item><item><title>Unit 42: Chinese-speaking cluster CL-STA-1062 deploys the new TinyRCT .NET backdoor against SE-Asian government and energy targets via AppDomainManager</title><link>https://ctipilot.ch/entries/2026-06-28/unit-42-chinese-speaking-cluster-cl-sta-1062-deploys-the-new/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-28/unit-42-chinese-speaking-cluster-cl-sta-1062-deploys-the-new/</guid><pubDate>Sun, 28 Jun 2026 05:05:41 +0000</pubDate><dc:date>2026-06-28T05:05:41Z</dc:date><category>nation-state</category><category>espionage</category><category>china-nexus</category><category>apac</category><category>global</category><description><![CDATA[<p>Palo Alto Unit 42 (2026-06-25) documented CL-STA-1062, a Chinese-speaking cluster overlapping with Cisco Talos&#39;s UAT-7237, targeting government and state-owned energy infrastructure across Southeast Asia (Unit 42, 2026-06-25; The Hacker News, 2026-06-26).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-28/unit-42-chinese-speaking-cluster-cl-sta-1062-deploys-the-new" data-tags="nation-state espionage china-nexus" data-regions="apac global" data-kind="research" data-priority="notable" data-discovered="2026-06-28T05:05:41Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="unit-42-chinese-speaking-cluster-cl-sta-1062-deploys-the-new"><a href="https://ctipilot.ch/entries/2026-06-28/unit-42-chinese-speaking-cluster-cl-sta-1062-deploys-the-new/">Unit 42: Chinese-speaking cluster CL-STA-1062 deploys the new TinyRCT .NET backdoor against SE-Asian government and energy targets via AppDomainManager injection</a></h3><p>Palo Alto Unit 42 (2026-06-25) documented <strong>CL-STA-1062</strong>, a Chinese-speaking cluster overlapping with Cisco Talos&#39;s UAT-7237, targeting government and state-owned energy infrastructure across Southeast Asia (<a href="https://unit42.paloaltonetworks.com/cl-sta-1062-tinyrct-backdoor/" target="_blank" rel="noopener noreferrer">Unit 42, 2026-06-25</a>; <a href="https://thehackernews.com/2026/06/chinese-speaking-apt-deploys-new.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-06-26</a>). Initial access is via internet-facing web apps and ASPX web shells (<code>T1505.003</code>), pivoting to a custom .NET backdoor, <strong>TinyRCT</strong>, delivered through AppDomainManager injection (<code>T1574.014</code>): a benign signed <code>chrome_setup.exe</code> ships in a ZIP alongside a malicious <code>chrome_setup.exe.config</code>, causing the .NET CLR to load <code>MyAppDomainManager.dll</code> from the same directory and bootstrap TinyRCT <em>in-process</em> — no child process, so it is low-visibility to EDR. TinyRCT beacons over HTTP with AES-128-CBC payloads, supports command execution via <code>cmd.exe</code>, chunked file exfiltration, and screen capture, and self-terminates unless run from <code>%LOCALAPPDATA%</code> or <code>%USERPROFILE%\Downloads</code> (anti-sandbox). Observed tooling includes Mimikatz, JuicyPotato and SoftEther VPN masqueraded as <code>vmtools.exe</code>. The defender value is the technique: <code>T1574.014</code> AppDomainManager injection is widely under-detected, and the same web-shell-to-in-process-.NET pattern is directly applicable to European public-sector web estates. Hunt for .NET <code>.config</code> files written into user-writable directories adjacent to signed executables, and DLL loads of <code>MyAppDomainManager.dll</code> from a signed PE&#39;s own directory (Sysmon EID 7).</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">TinyRCT is a .NET-based RAT with capabilities including arbitrary command execution, file enumeration and exfiltration, screen capture, and self-destruct functionality. The malware communicates via HTTP with AES-128 encrypted payloads.</p><p class="entry-cite__quote">CL-STA-1062 represents a sustained, sophisticated threat targeting critical infrastructure across Asia-Pacific.</p><figcaption class="entry-cite__attr">Unit 42</figcaption></figure></div><div class="prov"><span>research</span><span>28 Jun 05:05Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-28/unit-42-chinese-speaking-cluster-cl-sta-1062-deploys-the-new/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://unit42.paloaltonetworks.com/cl-sta-1062-tinyrct-backdoor/" target="_blank" rel="noopener noreferrer">Palo Alto Networks Unit 42</a> · <a href="https://thehackernews.com/2026/06/chinese-speaking-apt-deploys-new.html" target="_blank" rel="noopener noreferrer">The Hacker News</a></div></article>]]></content:encoded></item><item><title>NYT investigation gives first named attribution for the Jaguar Land Rover ransomware attack — a Russian state-linked criminal group</title><link>https://ctipilot.ch/entries/2026-06-28/nyt-investigation-gives-first-named-attribution-for-the-jagu/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-28/nyt-investigation-gives-first-named-attribution-for-the-jagu/</guid><pubDate>Sun, 28 Jun 2026 05:05:37 +0000</pubDate><dc:date>2026-06-28T05:05:37Z</dc:date><category>ransomware</category><category>organized-crime</category><category>russia-nexus</category><category>uk</category><category>europe</category><description><![CDATA[<p>A New York Times investigation provides the first named attribution for the August 2025 Jaguar Land Rover ransomware attack — a Russian state-linked criminal group — in an incident that halted JLR production for ~six weeks and is estimated at ~£1.9 bn / $2.5 bn in UK economic impact. Attribution is the investigators&#39; assessment, not an official UK government statement (TechCrunch, 2026-06-26).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-28/nyt-investigation-gives-first-named-attribution-for-the-jagu" data-tags="ransomware organized-crime russia-nexus" data-regions="uk europe" data-kind="threat" data-priority="high" data-discovered="2026-06-28T05:05:37Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="nyt-investigation-gives-first-named-attribution-for-the-jagu"><a href="https://ctipilot.ch/entries/2026-06-28/nyt-investigation-gives-first-named-attribution-for-the-jagu/">NYT investigation gives first named attribution for the Jaguar Land Rover ransomware attack — a Russian state-linked criminal group</a></h3><p>A New York Times investigation published 2026-06-26 provides the first named attribution for the August–October 2025 ransomware attack on Jaguar Land Rover (JLR): investigators including the FBI, the UK National Crime Agency, NCSC, Google Mandiant and Palo Alto Networks now attribute the core intrusion to a Russian state-linked criminal group (Microsoft is reported to have named the group to investigators) (<a href="https://techcrunch.com/2026/06/26/russian-hackers-were-behind-2-5-billion-hack-of-jaguar-land-rover-report/" target="_blank" rel="noopener noreferrer">TechCrunch, 2026-06-26</a>; <a href="https://thenextweb.com/news/jaguar-land-rover-hack-russian-hackers-nyt-investigation" target="_blank" rel="noopener noreferrer">The Next Web, 2026-06-26</a>). The attribution is the investigators&#39; assessment relayed through journalism — the UK government has not made it official, and investigators say they cannot establish whether the group acted on Kremlin orders, with tacit approval, or independently. The attack halted JLR manufacturing for roughly six weeks and disrupted 5,000+ supply-chain businesses, with UK economic damage estimated at ~£1.9 bn ($2.5 bn). Investigators also found a separate Jordanian actor (&quot;Rey&quot;) independently inside JLR networks, illustrating multi-actor opportunistic access to the same under-segmented victim.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">Per the fake-news guard, treat the Russian attribution as the investigators&#39;/NYT&#39;s claim, not an established fact — but the pattern (state-adjacent criminal ransomware against a NATO-aligned manufacturer, possibly retaliatory for Ukraine support) is a relevant sector signal for EU/Swiss defence-industrial and automotive supply chains. The multi-actor finding reinforces that a partially-compromised perimeter invites additional opportunistic intrusion; prioritise segmentation, credential hygiene and tested clean-recovery for high-value manufacturing/OT estates.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">investigators have not determined whether the hackers were working directly for Vladimir Putin&#39;s government, were independent criminals, or were operating with the government&#39;s tacit approval.</p><figcaption class="entry-cite__attr">TechCrunch, citing NYT</figcaption></figure></div><div class="prov"><span>threat</span><span>28 Jun 05:05Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-28/nyt-investigation-gives-first-named-attribution-for-the-jagu/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://techcrunch.com/2026/06/26/russian-hackers-were-behind-2-5-billion-hack-of-jaguar-land-rover-report/" target="_blank" rel="noopener noreferrer">TechCrunch</a> · <a href="https://thenextweb.com/news/jaguar-land-rover-hack-russian-hackers-nyt-investigation" target="_blank" rel="noopener noreferrer">The Next Web</a></div></article>]]></content:encoded></item></channel></rss>