⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-14179 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL statements. NVD description · AI analysis pending | 7.4 | <1% |
| — | ||
| CVE-2025-14180 | In PHP versions 8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1 when using the PDO PostgreSQL driver with In PHP versions 8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1 when using the PDO PostgreSQL driver with PDO::ATTR_EMULATE_PREPARES enabled, an invalid character sequence (such as \x99) in a prepared statement parameter may cause the quoting function PQescapeStringConn to return NULL, leading to a null pointer dereference in pdo_parse_params() function. This may lead to crashes (segmentation fault) and affect the availability of the target server. NVD description · AI analysis pending | 8.2 | <1% | PoC |
| — | |
| CVE-2026-0288 | Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS software allow an unauthenticated att Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic. The security risk posed by this issue is minimized when the User-ID Terminal Server Agent connectivity is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://docs.paloaltonetworks.com/ngfw/help/10-2/user-identification/device-user-identification-terminal-services-agents#:~:text=To%20minimize%20security%20risk%2C%20restrict%20TS%20Agent%20connectivity%20to%20trusted%20internal%20IP%20addresses%20only. . Panorama is not impacted by this vulnerability. NVD description · AI analysis pending | 7.2 | <1% |
| — | ||
| CVE-2026-10706 | In Adalo’s no-code app builder, (Versions 1 and 2) the attackers may extract full user records and correlate user behavior across multiple applications via dbId In Adalo’s no-code app builder, (Versions 1 and 2) the attackers may extract full user records and correlate user behavior across multiple applications via dbId enumeration. The platform does not implement data minimization, privacy by design, or implement appropriate technical safeguards, allowing sensitive information to be exposed to unauthorized parties. NVD description · AI analysis pending | 7.5 | <1% | — | — | ||
| CVE-2026-10708 | This vulnerability enables large‑scale data harvesting without requiring app‑specific secrets. This vulnerability enables large‑scale data harvesting without requiring app‑specific secrets. A single request to a minimal leaderboard component may return user records containing emails, UUIDs, and custom fields. The combination of wildcard CORS behavior, long‑lived twenty‑day JWTs, and the absence of token revocation allows attackers to gather sensitive personal information from any Adalo application. NVD description · AI analysis pending | 7.5 | <1% | — | — | ||
| CVE-2026-11405 | The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8. The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8. - The function contains a normal authentication path using MD5/hash-based password verification (prod_encode64/PasswordToMd5/check_rand_key). - After normal authentication fails, it calls GetValue("sys.rzadmin.password") to read a backdoor password from the device configuration. - It performs a direct strcmp() comparison (plaintext, not hashed) between the config value and the user-supplied password. A successful match grants role=2 (admin-level access) and creates a valid session. The rzadmin username is never checked — any username works with the backdoor NVD description · AI analysis pending | 9.8 | <1% | — | — | ||
| CVE-2026-11708 | IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console's integrated help system. IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console's integrated help system. NVD description · AI analysis pending | 9.3 group max | <1% |
| — | ||
| CVE-2026-12116 | A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings, which can be changed to a PHP interpret A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings, which can be changed to a PHP interpreter, allowing an attacker to upload PHP data that will then be executed. NVD description · AI analysis pending | 9.8 | <1% | — | — | ||
| CVE-2026-13126 | The embedded JavaScript in the PDF deleted the pages, making the object invalid. The embedded JavaScript in the PDF deleted the pages, making the object invalid. The application attempted to perform a write operation on the invalid pop-up annotations, resulting in the program crashing. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2026-6896 +1 in the same advisory: …13320 | GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain cond GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary scripts in another user's browser session due to improper sanitization of user-supplied input. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2026-13461 | When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView in the PayRange version 7.0.7 app. When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView in the PayRange version 7.0.7 app. The injection of specific JavaScript function calls allows the attacker to escape the WebView sandbox and perform a number of dangerous actions on the user's device. NVD description · AI analysis pending | 9.6 | <1% | — | — | ||
| CVE-2026-13462 | PayRange Android app, version 7.0.7 and below, contains an SSL bypass vulnerability that allows invalid certificates to be accepted in application webviews. PayRange Android app, version 7.0.7 and below, contains an SSL bypass vulnerability that allows invalid certificates to be accepted in application webviews. A remote and unauthenticated attacker can steal information that the user sends. NVD description · AI analysis pending | 7.5 | <1% | — | — | ||
| CVE-2026-13753 | Certain HP DeskJet All-in-One printers may be potentially vulnerable to information disclosure that allows an unauthenticated attacker to access sensitive infor Certain HP DeskJet All-in-One printers may be potentially vulnerable to information disclosure that allows an unauthenticated attacker to access sensitive information through exposed APIs. NVD description · AI analysis pending | 7.5 | <1% | — | — | ||
| CVE-2026-14261 | A vulnerability in the Xerte Online Tools allows for authentication bypass and remote code execution via reinstallation through the /setup/ folder, enabling att A vulnerability in the Xerte Online Tools allows for authentication bypass and remote code execution via reinstallation through the /setup/ folder, enabling attackers to reinstall the service to a remote database they control. NVD description · AI analysis pending | 9.1 | 1% | — | — | ||
| CVE-2026-14355 | In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extensio In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort. NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2026-14544 | A flaw was found in HPLIP (HP Linux Imaging and Printing Software). A flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnerability, an incomplete fix for CVE-2026-8631, may allow a remote attacker to escalate privileges or achieve arbitrary code execution. This can occur through an integer overflow in the hpcups processing path when handling specially crafted print data. NVD description · AI analysis pending | 9.8 | <1% | — | — | ||
| CVE-2026-14898 | The OpenAI Codex desktop app for macOS rendered remote images from Markdown in model responses. The OpenAI Codex desktop app for macOS rendered remote images from Markdown in model responses. An attacker who could place an indirect prompt injection in content processed by Codex, such as a connected-tool result or another untrusted source, could induce the model to construct a remote image URL containing sensitive data. The app automatically fetched that URL when rendering the response, sending the embedded data to an attacker-controlled server without a separate user click. Successful exploitation could exfiltrate secrets and other information accessible in the Codex session, including API keys, source code, and data returned by connected tools. No direct integrity or availability impact was demonstrated, and there is no known exploitation in the wild. NVD description · AI analysis pending | 6.5 | <1% | — | — | ||
| CVE-2026-15112 +1 in the same advisory: …15129 | Use after free in Ozone in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Use after free in Ozone in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2026-15146 | GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget’s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources. NVD description · AI analysis pending | 5.9 | <1% | — | — | ||
| CVE-2026-31694 | In the Linux kernel, the following vulnerability has been resolved: In the Linux kernel, the following vulnerability has been resolved: fuse: reject oversized dirents in page cache fuse_add_dirent_to_cache() computes a serialized dirent size from the server-controlled namelen field and copies the dirent into a single page-cache page. The existing logic only checks whether the dirent fits in the remaining space of the current page and advances to a fresh page if not. It never checks whether the dirent itself exceeds PAGE_SIZE. As a result, a malicious FUSE server can return a dirent with namelen=4095, producing a serialized record size of 4120 bytes. On 4 KiB page systems this causes memcpy() to overflow the cache page by 24 bytes into the following kernel page. Reject dirents that cannot fit in a single page before copying them into the readdir cache. NVD description · AI analysis pending | 7.8 | <1% | PoC |
| — | |
| CVE-2026-40139 | A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled. NVD description · AI analysis pending | 9.2 group max | <1% |
| — | ||
| CVE-2026-43499 | In the Linux kernel, the following vulnerability has been resolved: In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from futex_requeue(). In the latter case waiter::task is not current, but remove_waiter() operates on current for the dequeue operation. That results in several problems: 1) the rbtree dequeue happens without waiter::task::pi_lock being held 2) the waiter task's pi_blocked_on state is not cleared, which leaves a dangling pointer primed for UAF around. 3) rt_mutex_adjust_prio_chain() operates on the wrong top priority waiter task Use waiter::task instead of current in all related operations in remove_waiter() to cure those problems. [ tglx: Fixup rt_mutex_adjust_prio_chain(), add a comment and amend the changelog ] NVD description · AI analysis pending | 7.8 | <1% | PoC ×4 |
| — | |
| CVE-2026-46215 | In the Linux kernel, the following vulnerability has been resolved: In the Linux kernel, the following vulnerability has been resolved: drm: Set old handle to NULL before prime swap in change_handle There was a potential race condition in change_handle. The ioctl briefly had a single object with two idr entries; a concurrent gem_close could delete the object and remove one of the handles while leaving the other one dangling, which could subsequently be dereferenced for a use-after-free. To fix this, do the same dance that gem_close itself does. (f6cd7daecff5 drm: Release driver references to handle before making it available again) First idr_replace the old handle to NULL. Later, if the prime operations are successful, actually close it. create_tail required a similar dance to avoid a similar problem. (bd46cece51a3 drm/gem: Fix race in drm_gem_handle_create_tail()) It idr_allocs the new handle with NULL, then swaps in the correct object later to avoid races. We don't need to do that here, since the only operations that could race are drm_prime, and change_handle holds the prime lock for the entire duration. v2: cleanups of error paths NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2026-47291 | Unauthenticated RCE via Integer Overflow in Windows HTTP.sys CVE-2026-47291 is an integer overflow/wraparound flaw (CWE-190, leading to buffer overflow CWE-122) in HTTP.sys, the kernel-mode HTTP listener built into Windows. An unauthenticated attacker can trigger it by sending specially crafted network requests to any service that exposes an HTTP.sys endpoint, such as IIS-hosted websites or applications built on the Windows HTTP Server API/HttpListener. Successful exploitation grants remote code execution on the target host with no user interaction or privileges required. All listed Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), and Windows Server (2012, 2016, 2019, 2022) releases are affected. The flaw is not yet in CISA KEV and no public PoC exists, but its EPSS of 22.8% (98th percentile) indicates an elevated likelihood of exploitation within the next 30 days; patches shipped in Microsoft's June 2026 Patch Tuesday release (206 fixes total). Do: Apply the June 2026 Microsoft security updates for every affected Windows release, prioritizing internet-facing servers running IIS or other HTTP.sys-based services. As an interim mitigation, restrict untrusted network access to ports served by HTTP.sys. Identify hosts with active HTTP.sys listeners (e.g., via 'netsh http show servicestate' or reviewing web-server exposure) and monitor for a public PoC or CISA KEV addition given the elevated EPSS. | 9.8 | 23% |
| masshundreds of millions of Windows installations ship the affected driver; millions of internet-exposed IIS/HTTP.sys listeners are the primary attack surface | ||
| CVE-2026-50746 | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Inje A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device. NVD description · AI analysis pending | 10.0 | 2% |
| — | ||
| CVE-2026-50747 | A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi Talk Applic A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi Talk Application to escalate privileges on the host device. NVD description · AI analysis pending | 9.9 | <1% |
| — | ||
| CVE-2026-50748 +1 in the same advisory: …54400 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to ex A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device. NVD description · AI analysis pending | 9.9 group max | 2% |
| — | ||
| CVE-2026-52747 +1 in the same advisory: …52761 | ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Prior to 3.0.16, the multipart/form-data request body parser in libmodsecurity silently removes embedded line breaks from non-file form-field values before exporting them to ARGS and ARGS_POST because src/request_body_processor/multipart.cc overwrites reserved bytes in m_reserve instead of appending the current buffer. This creates a parser differential between ModSecurity and backend applications that preserve line breaks in form fields, allowing rules that inspect ARGS or ARGS_POST to miss payloads whose dangerous syntax depends on a line break. This issue is fixed in version 3.0.16. NVD description · AI analysis pending | 8.6 group max | <1% | PoC |
| — | |
| CVE-2026-52830 | fast-mcp-telegram is a Telegram MCP Server. fast-mcp-telegram is a Telegram MCP Server. Prior to 0.19.1, fast-mcp-telegram validates HTTP Bearer tokens by joining the raw token string into a session-file path. The verifier rejects the exact reserved token telegram, but it does not reject path separators or normalize the path before checking whether the session file exists. A remote HTTP client can therefore authenticate as the default legacy session with a token such as ../fast-mcp-telegram/telegram when the documented default session file ~/.config/fast-mcp-telegram/telegram.session exists. This bypasses the reserved session name control that is intended to prevent HTTP multi-user sessions from colliding with the default stdio or legacy account. With account-prefixed MCP tools enabled, the attacker still sees and calls the prefixed tools for the default account, so the prefix middleware does not stop the session selection bypass. This vulnerability is fixed in 0.19.1. NVD description · AI analysis pending | 9.4 | <1% | — | — | ||
| CVE-2026-53359 | In the Linux kernel, the following vulnerability has been resolved: In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected role Commit 0cb2af2ea66ad ("KVM: x86: Fix shadow paging use-after-free due to unexpected GFN") fixed a shadow paging mismatch between stored and computed GFNs; the bug could be triggered by changing a PDE mapping from outside the guest, and then deleting a memslot. The rmap_remove() call would miss entries created after the PDE change because the GFN of the leaf SPTE does not match the GFN of the struct kvm_mmu_page. A similar hole however remains if the modified PDE points to a non-leaf page. In this case the gfn can be made to match, but the role does not match: the original large 2MB page creates a kvm_mmu_page with direct=1, while the new 4KB needs a kvm_mmu_page with direct=0. However, kvm_mmu_get_child_sp() does not compare the role, and therefore reuses the page. The next step is installing a leaf (4KB) SPTE on the new path which records an rmap entry under the gfn resolved by the walk. But when that child is zapped its parent kvm_mmu_page has direct=1 and kvm_mmu_page_get_gfn() computes the gfn for the 4KB page as sp->gfn + index instead of using sp->shadowed_translation[] (or sp->gfns[] in older kernels). It therefore fails to remove the recorded entry. When the memslot is dropped the shadow page is freed but the rmap entry survives, as in the scenario that was already fixed. Code that later walks that gfn (dirty logging, MMU notifier invalidation, and so on) dereferences an sptep that lies in the freed page, causing the use-after-free. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2026-54402 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device. NVD description · AI analysis pending | 8.8 | 2% |
| — | ||
| CVE-2026-54432 | Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs because the attachment MIME type is not properly escaped on the attachment-validation warning page. NVD description · AI analysis pending | 4.7 | <1% | — | — | ||
| CVE-2026-55115 | A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate priv A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges on the host device. NVD description · AI analysis pending | 9.9 | <1% |
| — | ||
| CVE-2026-55116 | A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in certain de A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi OS devices. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2026-57992 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. NVD description · AI analysis pending | 7.5 | <1% |
| — |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | braintree.net | t Package Delivers Skimmer — A malicious .NET package named Braintree.Net has been found to impersonate Braintree's legitimate Braint |
Full article2,506 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananJul 13, 2026Cybersecurity / Hacking
Somewhere right now, a security tool is quietly finding bugs faster than any human can fix them. That's supposed to be the good news. The catch is that the attackers have the same tools, pointed the other way, and they don't file tickets.
That's the shape of this week. Trusted code turns on the people who installed it. Old bugs from last year are still landing because the fix sat in a queue too long. Fake installers, poisoned packages, systems left facing the open internet, and helpful little AI assistants running instructions that were never yours.
The gap between "patch exists" and "already exploited" keeps shrinking, and nobody's closing it. None of it is exotic. That's what wears you down. Same ordinary mistakes, just happening faster than we can keep up.
Here's the full mess, top to bottom.
⚡ Threat of the Week
Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers — Progress urged customers to shut down Windows servers running Storage Zone Controllers, citing a credible external security threat. The company has temporarily disabled access to the affected accounts, a step it says it took "out of an abundance of caution" while it works with internal and external security experts. The exact nature of the threat is unknown. There are no indications of unauthorized access to any ShareFile accounts or data.
🔔 Top News
- Critical Zimbra Flaw Patched — Zimbra is urging customers to apply updates to address a critical security vulnerability impacting the Classic Web Client that could result in arbitrary code execution. The vulnerability has been described as a case of stored cross-site scripting (XSS) that could allow specially crafted emails to execute malicious scripts in a user's session. It has yet to be assigned a CVE identifier. "The update fixes a security issue in the Classic Web Client where a specially crafted email could run malicious code when the email is opened," Zimbra said. "If exploited, it could allow access to mailbox information, session data, or account settings."
- Jscrambler npm Package Compromised — The Jscrambler npm package was compromised to publish multiple versions containing a Rust-based information stealer designed to steal developer secrets from Windows, macOS, and Linux machines. According to Jscrambler, the attack was pulled off using a compromised npm publishing credential. The activity overlaps with IronWorm, which was first documented by JFrog last month. "The malware has shed its Linux-only skin, deploying a three-platform CSI container to target macOS and Windows, expanding its persistence, and automating its own propagation via direct registry PUT operations," the company said.
- New GigaWiper Backdoor Detailed — Microsoft shed light on a new post-compromise backdoor called GigaWiper that comes with three distinct destructive ways to render a machine inoperable: wipe the whole disk, overwrite the Windows drive, or run fake "ransomware" that encrypts files with a key it never saves. In addition, it can take screenshots, record the screen, and launch a hidden VNC session. The malware artifacts are similar to another backdoor codenamed BLUERABBIT, which is assessed to be the work of an Iran-nexus threat actor.
- SHELLSTORM, a Modern Web Shell Access Brokerage Operation — More than 1.4 million domains have been targeted as part of a large-scale operation that exploited 27 CVEs in WordPress plugins to deploy web shells on compromised servers. The largest number of infections have been reported in Taiwan, the U.S., Germany, France, and the U.K. The access provided by the web shell is then used to deliver the SNOWLIGHT dropper and the VShell backdoor. The activity has been codenamed SHELLSTORM. The activity is assessed to be the work of a Chinese or Chinese-speaking threat actor.
- HalluSquatting Can Trick AI Coding Assistants Into Installing Botnets — While artificial intelligence (AI) tools are prone to hallucinations, new research has detailed a new iteration of slopsquatting and phantom squatting called HalluSquatting. The technique essentially involves registering legitimate-sounding resource names invented by an AI agent, registering them first, and then waiting for the assistant to run the malicious code embedded in the code. The attack pairs hallucinations with prompt injections to trick the agent into executing attacker-controlled instructions.
️🔥 Trending CVEs
Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild.
Check the list, patch what you have, and hit the ones marked urgent first — From BRLY-2026-037 through BRLY-2026-042 (U-Boot), CVE-2026-50746, CVE-2026-50747, CVE-2026-50748, CVE-2026-54400, CVE-2026-55115, CVE-2026-54402, CVE-2026-55116 (Ubiquiti Unifi), CVE-2026-40138, CVE-2026-40139, CVE-2026-40140, CVE-2026-40141 (BeyondTrust Remote Support and Privileged Remote Access), CVE-2026-11405 (Tenda), CVE-2026-43499 aka GhostLock, CVE-2026-46215 (Linux Kernel), CVE-2026-53359 aka Januscape (KVM/x86), CVE-2026-52830 (fast-mcp-telegram), CVE-2026-57992 (Microsoft Edge), CVE-2026-11712, CVE-2026-11708, CVE-2026-11595 (IBM WebSphere Application Server), CVE-2026-12184, CVE-2026-14355 (PHP), CVE-2026-52761, CVE-2026-52747 (OWASP ModSecurity), CVE-2026-14898 (OpenAI Codex for macOS), CVE-2026-13753 (HP Deskjet 2800 Printer Series), CVE-2026-10706, CVE-2026-10708 (Adalo Database API), CVE-2026-15112, CVE-2026-15129 (Google Chrome), CVE-2026-12116, CVE-2026-14261 (Xerte Online Toolkit), CVE-2026-13461, CVE-2026-13462 (PayRange Android app), CVE-2026-0288 (Palo Alto Networks PAN-OS), CVE-2026-47291 (Microsoft Windows HTTP.sys), CVE-2026-15146 (GNU Wget), CVE-2026-31694 (Linux FUSE), CVE-2026-54432 (Roundcube webmail), CVE-2026-14544 (HP Linux Imaging and Printing), CVE-2026-13126, CVE-2026-57260, CVE-2026-57248, CVE-2026-57246 (Foxit PDF Reader and PDF Editor), CVE-2026-6896, CVE-2026-13320 (GitLab CE and EE), CVE-2025-14179 (pdo_firebird), and CVE-2025-14180 (PDO PostgreSQL)
🎥 Cybersecurity Webinars
- Learn to Kill a Rogue AI Agent Before It Leaks Your Secrets → Guardrails alone won't save you. Okta Threat Intelligence Director Jeremy Kirk went hands-on with OpenClaw and watched agentic AI leak credentials, bypass safety controls, and turn into a live attack surface. In this webinar, he turns that into steps you can apply today: treat agents as first-class identities, enforce least-privilege access, use short-lived secrets, and hit the kill switch on shadow AI. Real attacks, real fixes. Save your seat.
- Your Team Ships 50x More Code. Humans Can't Review It Anymore → Frontier models like Mythos are compressing dev timelines past the point humans can review what humans build. Chainguard Field CISO John Sapp shows why that's an architectural problem, not a velocity one: your attack surface is expanding in real time, adversaries have the same models, and CVE-based remediation breaks down at machine speed. Leave with a secure-by-default strategy and the language to take it to your board. Save your seat.
📰 Around the Cyber World
- Compromising AI Gateways for Cryptomining — Threat actors have been observed compromising AI gateways such as LiteLLM Proxy connected to Amazon Bedrock services to deploy payloads that communicate with cryptomining infrastructure for unauthorized compute activity. Initial access to the LiteLLM Proxy EC2 instance is said to have been facilitated via internet-exposed SSH. "While the ultimate impact in this case appeared to be unauthorized cryptomining, the incident is notable because of where it occurred," Darktrace said. "The compromised asset sat at the intersection of cloud infrastructure, identity, and AI services. The incident demonstrates why organizations should treat AI infrastructure as part of their critical attack surface rather than as a standalone application tier."
- Exploitation of CVE-2026-1207 Reported — Threat actors are actively exploiting a security flaw in Django (CVE-2026-1207), an SQL injection flaw that could result in remote code execution. "Observed exploitation volumes remain steady week-over-week, indicating sustained interest from threat actors," CrowdSec said. "Most observed attacks involve focused reconnaissance to identify vulnerable Django and PostGIS configurations, suggesting sophisticated targeting rather than broad spraying."
- Multi-Stage Infection Leads to Node.js Backdoor — A malicious ZIP file containing a Windows shortcut (LNK) is being used to execute a hidden PowerShell command that downloads a legitimate node.exe binary and deploys a NodeJS-based backdoor. "The malware also uses the EtherHiding technique, leveraging the TON blockchain to retrieve its command-and-control (C2) address," LevelBlue said. "The campaign begins with a spam email targeting the hospitality sector using booking-themed lures. The email contains a link hosted on Google Share, which is abused by the threat actor to make it look legit and also evade email security filtering."
- Intrusions Exploit Citrix Bleed 2 — Threat actors are exploiting Citrix Bleed 2 (CVE-2025-5777) to deploy the DragonForce ransomware. "After gaining access, the attacker followed a consistent post-compromise pattern: escalate to SYSTEM through a registry-symlink/AppMgmt privilege-escalation trick, create rogue local admin accounts, and establish persistence with legitimate remote access tools like ScreenConnect and Zoho Assist," Huntress said. "In the most advanced case, the operation ended with DragonForce ransomware deployment, which is why the blog's main takeaway is urgent action: patch exposed NetScaler appliances, retain and review logs, terminate outstanding sessions, and audit for suspicious accounts and remote-management tooling." The cybersecurity company said it observed half a dozen intrusions across unrelated organizations in the first half of 2026 using the same repeatable seven-step attack chain, indicating a highly standardized operator playbook rather than one-off compromises.
- Fake Chinese VPN Drops GoodPersonRAT — An MSI file masquerading as an installer for Kuailian VPN (aka LetsVPN) has been observed dropping and executing an encrypted RAT called GoodPersonRAT that provides attackers with complete control over a victim’s machine and its data. "Several features are implemented, such as full remote control, keylogging, browser manipulation, persistence, and auto-updating," ThreatLocker said.
- Fake Braintree NuGet Package Delivers Skimmer — A malicious .NET package named Braintree.Net has been found to impersonate Braintree's legitimate Braintree SDK while deploying a multi-stage .NET implant that intercepts live payment card data, exfiltrates Braintree merchant API keys, and harvests host environment secrets upon assembly load. It also facilitates token theft, avoids sandboxes, and implements production-only gating. "This split behavior allows the attacker to deliberately target payment data in production, while environment reconnaissance casts a wider net," Socket said.
- RedHook Android Malware Uses Wireless ADB for Shell Access — A resurfaced version of the RedHook Android trojan has incorporated new, sophisticated, and malicious functionalities, including autonomous privilege abuse, expanded command-and-control capabilities, and a robust persistence stack. "While retaining core RAT functionalities, such as screen streaming and keylogging, the latest iterations demonstrate a sophisticated shift toward privilege abuse," Group-IB said. "RedHook abuses Android's ADB Wireless Debugging features to autonomously obtain shell-level access." Recent activity indicates an expansion of targeting beyond Vietnam to include users in Indonesia, suggesting a broader regional focus across Southeast Asia. The malware is distributed via spoofed government and financial websites, but the malicious APK payloads are hosted on reputable cloud and development platforms, including AWS S3 Buckets and GitHub repositories, likely in an attempt to enhance delivery reliability.
- Phishing Campaign Targets Russian Aerospace Organizations — A spear-phishing campaign disguised as a legitimate business invoice targets aerospace organizations in Russia. "The phishing email impersonates a legitimate Russian research institute associated with aerospace and aviation systems and is delivered using a spoofed domain designed to mimic the organization," Seqrite Labs said. "The malicious email contains a password-protected attachment that ultimately deploys additional payloads on the victim’s system. Analysis indicates that the threat actor’s primary objective is to establish persistent remote access by silently configuring AnyDesk for unattended access, exfiltrating AnyDesk configuration data to an attacker-controlled email account, and implementing persistence mechanisms to retain long-term control of the compromised host." The activity overlaps with previously documented campaigns attributed to Rare Werewolf (aka Librarian Ghouls), which is known to target organizations in Russia, Belarus, and Kazakhstan.
- Helix Data Extortion Crew Emerges — A new data extortion group called Helix is employing voice phishing (vishing), device code phishing, and multi-factor authentication (MFA) abuse to steal data from SharePoint environments. Helix is said to have emerged from the BlackFile (aka UNC6671) and ShinyHunters (aka UNC6661) ecosystem. BlackFile has also splintered into Pink and Redact following its shutdown in April 2026. "In the kill chain, a single compromised identity served as the throughline from initial access to exfiltration. However, we have also observed what appears to be a tactical split," ReliaQuest said. "A first user is compromised through vishing and used for data exfiltration, quietly enumerating and bulk-downloading SharePoint libraries over a period of days. A second user is then compromised separately, often days or even weeks later, and appears to be used solely to deliver the extortion message internally via Microsoft Teams and email. The second account carries no exfiltration activity. It appears to exist in the operation for one purpose, which is to post the extortion demand inside the target's own collaboration environment."
- Microsoft Warns of Increase in Number of Windows Security Updates — Microsoft has warned customers to expect a spike in the number of security updates for Windows, as it uses AI techniques like MDASH to find more zero-day vulnerabilities. "The pace of vulnerability discovery is changing with advances in AI making it possible to find more issues, faster, across more code, with new mechanisms that can accelerate both discovery and analysis," the company said. "The fastest way to reduce customer exposure is to find issues before attackers can use them. Windows is expanding its ability across the platform to find issues earlier, accelerate the engineering work to fix them, strengthen validation, and deliver timely, high-quality updates that keep customers protected."
🔧 Cybersecurity Tools
- Caeruleus → Praetorian has released Caeruleus, a free open-source toolkit that folds the whole Bluetooth Low Energy testing workflow into one Go binary. Running on Linux/BlueZ, it lets testers scan devices, read or write the GATT tree, capture notifications, fuzz characteristics, and run security checks, replacing the usual hcitool, gatttool, and bettercap mix. Every command can output JSON for scripting and AI agents.
- PhantomFS → It is a free open-source Windows honeypot that uses the Projected File System (ProjFS) to project convincing decoy files, credentials, financials, and SSH keys, into a virtual directory that lives only in memory and never hits disk. The moment an attacker or insider opens one, it writes a Windows Event Log entry and fires a desktop Toast alert with the filename, timestamp, and process context, giving high-confidence detection with no tuning, ML, or cloud.
Disclaimer: This is strictly for research and learning. It hasn't been through a formal security audit, so don't just blindly drop it into production. Read the code, break it in a sandbox first, and make sure whatever you’re doing stays on the right side of the law.
Conclusion
The lesson this week is simple. Every shortcut we took to move faster is now a door someone else can walk through. The package you trusted. The remote tool is left running. The AI that does whatever it reads. We built the shortcuts. Someone else is using them.
So patch the urgent stuff first, close the sessions you forgot were open, and go check what's still facing the internet that shouldn't be. None of it is exciting. It's just the part nobody goes back to until it's too late. See you next week, if nothing breaks before then.
(This article has been corrected to accurately attribute the discovery of the GoodPersonRAT campaign. An earlier version incorrectly credited ThreatDown. The correct attribution is ThreatLocker. The error is regretted.)
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/07/weekly-recap-sharefile-threat-citrix.html