Cyber Threat Intelligence 20 July 2026
-
Industrial Sector
- Three Steps To The Terminal: A Siemens ROX II Zero-Day Trilogy
"We conducted this research in close partnership with Siemens, reflecting our shared commitment to advancing the security and resilience of critical infrastructure. This report details a critical, chained exploit comprising three zero-day vulnerabilities (CVE-2025-40948, CVE-2025-40947, and CVE-2025-40949) discovered in Siemens ROX II operational technology (OT) switches. Successful exploitation of this chain would allow an attacker to achieve full privilege escalation and persistent root-level access on these devices, which are critical components of industrial control networks. The vulnerabilities range from Medium to Critical severity, with CVSS 3.1 scores of 6.8 (CVE-2025-40948), 7.5 (CVE-2025-40947), and 9.1 (CVE-2025-40949)."
https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/
Vulnerabilities
- OpenSSL HollowByte: A DoS Hiding In 11 Bytes
"Every so often, a vulnerability reminds us how deeply our digital infrastructure relies on foundational libraries. Recently, the Okta Red Team discovered HollowByte, a Denial of Service (DoS) vulnerability in OpenSSL. By sending a malicious payload of just 11 bytes, a remote, unauthenticated attacker can force a server to allocate disproportionate chunks of memory before any security handshake even begins. Here is the breakdown of how it works."
https://sec.okta.com/articles/2026/06/openssl-hollowbtye-a-dos-hiding-in-11-bytes/
https://www.bleepingcomputer.com/news/security/hollowbyte-ddos-flaw-bloats-openssl-server-memory-with-11-byte-payload/
https://thehackernews.com/2026/07/openssl-hollowbyte-flaw-could-freeze.html
https://securityaffairs.com/195588/hacking/openssl-fixes-hollowbyte-memory-exhaustion-bug.html - Wp2shell: Pre Authentication RCE In WordPress Core
"Searchlight Cyber’s security research team has discovered a pre-authentication RCE in WordPress Core. The attack has no preconditions and can be exploited by an anonymous user in a stock install of WordPress with no plugins. It is estimated that over 500 million websites use WordPress. Given the severity of the bug and to give defenders time to patch, we are not releasing technical details at this time. We are, however, releasing a website to determine if your instance is vulnerable. You can find it here: https://wp2shell.com/"
https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core
https://wp2shell.com/
https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html
https://www.bleepingcomputer.com/news/security/wordpress-core-wp2shell-rce-flaws-get-public-exploits-patch-now/
https://securityaffairs.com/195597/hacking/attackers-can-take-over-wordpress-sites-using-newly-released-wp2shell-exploits.html
https://www.helpnetsecurity.com/2026/07/18/wordpress-vulnerabilities-wp2shell-cve-2026-60137-cve-2026-60137/
Malware
-
Proxying To Compromise: SonicWall Secure Mobile Access 0-Day Exploitation
"In early July 2026, Volexity was engaged to perform an incident response investigation where it discovered a threat actor had successfully compromised SonicWall Secure Mobile Access (SMA) VPN appliances through a chain of multiple zero-day exploits in the devices. The initial compromise was discovered after suspect authentication and lateral movement attempts were observed from the SonicWall SMA appliances. Following public disclosure by SonicWall on July 14, 2026, Volexity is now able to share details on the exploits used, when they were used, and what the threat actor did with their access."
https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/
https://thehackernews.com/2026/07/sonicwall-sma-zero-days-exploited.html -
None And Done? Kittykatkrew’s Short-Lived Ransomware Play
"kittykatkrew is a financially motivated ransomware and data-extortion threat actor that announced its operation on February 22, 2026. In the roughly two months that followed, the group claimed two victims on its leak site, appeared to release a stolen law-enforcement dataset, and then went quiet. No confirmed ransom payment, no verified breach and no further activity as of mid-2026. The data leak site was offline as of April 9, 2026."
https://blog.barracuda.com/2026/07/16/none-and-done-kitty-kat-krew-ransomware-group -
Sequel To ChainVeil Npm Malware Targets Vite Ecosystem
"When we published our ChainVeil report in June 2026, we noted something that didn’t fit: the SuccessKey campaign’s Command and Control (Command and Control (C2)) infrastructure contained a secondary server at 198.105.127[.]210 and a tertiary server at 23.27.202[.]27 that no known ChainVeil package ever called home to. We predicted additional campaigns were already running on the same backend. We were right."
https://checkmarx.com/zero-post/sequel-to-chainveil-npm-malware-targets-vite-ecosystem/
https://thehackernews.com/2026/07/seven-malicious-vite-npm-packages-use.html -
NadMesh Botnet Analysis: A Product-Grade Threat For The AI Service Era
"In early July 2026 we observed a Go-based botnet pushing bot samples onto the internet at scale. It folds scanning, exploitation, and credential/AI-service intelligence harvesting into a single autonomous platform. Because its controller calls itself n4d mesh controller in the source, we named it NadMesh. NadMesh is not a one-off worm outbreak. It is a continuously iterated, autonomous botnet aimed squarely at AI infrastructure and the MCP ecosystem. What sets it apart from traditional worms:"
https://blog.xlab.qianxin.com/nadmesh-botnet-analysis-a-product-grade-threat-for-the-ai-service-era-en/
https://thehackernews.com/2026/07/new-nadmesh-botnet-hunts-exposed-ai.html -
Introducing CylindricalCanine: The GoldenEyeDog Subgroup Responsible For The April DigiCert Incident
"In this blog, we review the behavior and capabilities of a malware we call Golden Gh0st Loader and Golden Gh0st RAT. We believe these malware are used exclusively by a sub-group dubbed “GoldenEyeDog”, a Chinese cybercrime group. In April 2026, the actors behind the malware were able to gain access to DigiCert to intercept code-signing certificates intended for DigiCert customers, and then used the certificates to sign their own malware. This piqued our interest in the malware, leading us to use DeceptionPro to monitor the malware over days in a controlled enterprise environment—and create a tool to decrypt the malware’s network communications."
https://expel.com/blog/introducing-cylindricalcanine/
https://thehackernews.com/2026/07/goldeneyedog-subgroup-linked-to.html -
New North Korean Campaign Uses Fake Coding Interviews To Steal Developer Credentials
"Elastic Security Labs found a new Contagious Interview campaign, tracked as REF9403, hiding malware inside SVG image files using steganography. To our knowledge, this specific infection chain has not been previously documented. We found it after the DPRK-aligned group targeted our own community Slack workspace with a fake job posting and a "coding challenge" project. Any user who ran the project ended up with a four-stage payload aligned with OTTERCOOKIE: a browser credential and crypto wallet stealer, a file stealer, a Socket.IO-based remote access trojan (RAT), and a clipboard stealer."
https://www.elastic.co/security-labs/contagious-interview-malware-svg-steganography
https://thehackernews.com/2026/07/north-korea-linked-hackers-hide.html -
ACR Stealer: Two Observed Intrusion Chains Amid Increased Threat Activity
"From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments. These campaigns are successfully using ClickFix lures to steal browser credentials, authentication tokens, and sensitive documents from enterprise environments. Successful compromise can expose browser credentials, session tokens, authentication artifacts, and sensitive enterprise data, potentially enabling account compromise, unauthorized access to cloud resources, and follow-on intrusion activity. Security teams should prioritize monitoring for ClickFix lures, suspicious WebDAV activity, obfuscated PowerShell execution, and attempts to access browser credential stores."
https://www.microsoft.com/en-us/security/blog/2026/07/16/acr-stealer-two-observed-intrusion-chains-amid-increased-threat-activity/
https://thehackernews.com/2026/07/acr-stealer-uses-clickfix-lures-to.html
https://www.bleepingcomputer.com/news/security/microsoft-warns-of-surge-in-acr-stealer-attacks-on-customers/ -
Inside Qilin Ransomware: Custom Rust Loader And Kernel-Level EDR Killer
"In this post we analyze Qilin ransomware’s new custom Rust loader, break down the inner workings of its sophisticated kernel-level EDR killer, and explore how organizations can defend against these aggressive defense evasion tactics. Flashpoint customers can access the full intelligence report—complete with deeper technical analysis and all associated IOCs—directly within Flashpoint Ignite."
https://flashpoint.io/blog/inside-qilin-ransomware/ -
**Breaches/Hacks/Leaks
-
Abbott Probes Two Cyber Incidents Amid Extortion Claims**
"Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate claim that attackers breached its LabCentral portal and stole company data. The company confirmed the Cancer Diagnostics incident after the ShinyHunters extortion gang added Abbott to its data leak site, initially threatening to publish allegedly stolen data after July 18 unless the company negotiated with the group, before later extending the deadline to July 21."
https://www.bleepingcomputer.com/news/security/abbott-laboratories-probes-two-cyber-incidents-amid-extortion-claims/ -
Ernst & Young Discloses Data Breach After Support System Hack
"Ernst & Young is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personnel. According to the company, support tickets submitted through the platform may have included documents containing client tax information. Ernst & Young (EY) is among the world’s four largest auditing and professional services providers, offering auditing, tax, consulting, and transaction advisory services to major organizations in more than 150 countries."
https://www.bleepingcomputer.com/news/security/ernst-and-young-discloses-data-breach-after-support-system-hack/
https://securityaffairs.com/195550/data-breach/ernst-young-ey-investigates-data-breach-involving-third-party-support-tickets.html -
Hugging Face Discloses AI-Agent-Driven Breach Of Internal Clusters
"The interesting part of Hugging Face's security incident write-up, published July 16, is not that a dataset hub got popped, but how. The company says the intrusion was "driven, end to end, by an autonomous AI agent system." A malicious dataset abused two code-execution paths in Hugging Face's dataset processing, a remote-code loader and template injection in dataset configuration, to run on a processing worker. From there the agent escalated to node access, harvested cloud and cluster credentials, and moved laterally into several internal clusters over a weekend, generating what the disclosure calls "many thousands of individual actions across a swarm of short-lived sandboxes.""
https://aiweekly.co/alerts/hugging-face-discloses-ai-agent-driven-breach-of-internal-clusters
https://huggingface.co/blog/security-incident-july-2026
General News
- Two Key Members Of Chinese Money Laundering Network Charged With Laundering $43 Million In Investment Fraud Proceeds
"A New York man and woman made an initial appearance today in Brooklyn, New York on charges of conspiracy to launder money derived from cyber investment fraud scams. According to the indictment unsealed today, between 2020 and 2022, Zhuoying Chen, 27, of Brooklyn, New York and Haojie Zhang, 38, of Queens, New York managed a network of more than a dozen individuals based in Queens and Brooklyn, who opened 140 bank accounts in the name of approximately 45 shell companies to launder at least $43 million in proceeds of investment scams. Then, Chen and Zhang allegedly conspired with China-based co-conspirators to transfer the funds involved in the fraud schemes abroad."
https://www.justice.gov/opa/pr/two-key-members-chinese-money-laundering-network-charged-laundering-43-million-investment
https://www.bleepingcomputer.com/news/security/us-charges-two-over-laundering-43-million-from-investment-fraud/ - The Real AI Threat Is Blind Trust
"A recent attack involving an autonomous AI agent exposed a growing enterprise risk many organizations are not prepared for: AI systems capable of transforming untrusted input into authorized action. No passwords were stolen. No malware was deployed. No firewall was breached. From the system's perspective, the transaction was entirely legitimate. Using a string of Morse code dots and dashes, attackers manipulated one AI agent into generating what appeared to be a legitimate instruction for another AI system authorized to move funds. The second agent complied without hesitation."
https://www.darkreading.com/application-security/real-ai-threat-blind-trust - Prompt Injection Is Becoming The XSS Of The Web Agent Era
"Autonomous web agents read whatever a page displays, and much of that content comes from strangers. Product reviews, seller listings, and advertisements sit beside trusted site menus on a single page. An agent that reads all of that text as instructions can be steered by any of it. A group at UC Berkeley describe Cross-Site Prompting, or XSP, as the agent-era version of Cross-Site Scripting. Their system, Prismata, sits between a web agent and the browser. It filters the content an agent sees and limits the actions the agent can take."
https://www.helpnetsecurity.com/2026/07/17/xss-web-agent-prompt-injection/
https://arxiv.org/pdf/2607.08147 - The Script, Not The Voice, Is What Makes AI Voice Phishing Work
"The call comes in at 4:40 on a Friday. The voice belongs to a senior manager, or sounds close enough, and she needs a password reset before a flight. She is polite, she is in a hurry, and she has the last four of the badge number. Researchers at Harvard Kennedy School, Meta and elsewhere ran a version of that moment past 4,100 US adults, using six commercial voice systems and human callers as a control. The results land in an odd place for anyone buying deepfake detection."
https://www.helpnetsecurity.com/2026/07/17/research-ai-voice-phishing/
https://arxiv.org/pdf/2607.09970 - Government Ransomware Roundup: H1 2026 Stats On Attacks, Ransoms, And Data Breaches
"From January to June 2026, Comparitech researchers logged an average of one ransomware attack on a government entity every day. Attacks jumped by over 13 percent when compared to H2 2025, increasing from 165 to 187 attacks. Of the 187 attacks recorded in H1 2026, 89 were confirmed by the targeted entities."
https://www.comparitech.com/news/government-ransomware-roundup-h1-2026-stats-on-attacks-ransoms-and-data-breaches/
https://www.infosecurity-magazine.com/news/government-ransomware-daily/ - Ransomware And Cyber Extortion In Q2 2026
"Three of Q1's dominant ransomware groups lost significant ground in Q2 2026, but the techniques driving risk across the landscape barely changed. As “Qilin,” “DragonForce,” and “Coinbase Cartel” declined in terms of named victim counts, “The Gentlemen” claimed the top spot for the first time. Overall, ransomware groups posted 2,252 victims in Q2—down 15% from Q1 but up about 51% year over year, and the top ranks are still shifting. Defenders must focus on attacker behaviors, not the leaderboard shuffle, especially as some of the most disruptive groups may never crack the top ranks at all."
https://reliaquest.com/blog/threat-spotlight-ransomware-and-cyber-extortion-in-q2-2026/
https://www.infosecurity-magazine.com/news/the-gentlemen-most-prolific/ - Armenia Detains Russian Tourist On U.S. Warrant For REvil Hacker, Lawyers Say Wrong Man
"Armenia has held a Russian tourist named Aleksandr Ermakov in a detention center since June 28, on a U.S. extradition request for a REvil ransomware suspect named Aleksandr Ermakov. His wife, Maria Yurova, told REN TV that border officers pulled him out of the departure hall at Yerevan's Zvartnots airport, held up a phone with a photo of him off his VKontakte page, and walked him into a side room. His lawyers say Washington has the wrong man."
https://thehackernews.com/2026/07/armenia-detains-russian-tourist-on-us.html
อ้างอิง
Electronic Transactions Development Agency (ETDA)
- Three Steps To The Terminal: A Siemens ROX II Zero-Day Trilogy