<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Sandworm Watch — Weekly Research</title><description>Weekly threat research digest for historical and academic review.</description><link>https://sandworm.net/</link><item><title>Klue Integration Abused in Salesforce Data Theft | Threat Spotlight</title><link>https://otx.alienvault.com/pulse/6a33628e05ab2c2a8cced854</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a33628e05ab2c2a8cced854</guid><description>In June 2026, a compromised Klue competitive-intelligence platform integration was exploited to exfiltrate customer relationship management data from enterprise Salesforce environments. Attackers authenticated through compromised Klue service accounts, generated OAuth tokens, and executed automated Python scripts to conduct bulk data extraction via Salesforce REST API queries over approximately 24 hours. The activity included concentrated bursts of nearly a thousand queries within 15 minutes and sustained extraction windows exceeding 6 hours. This incident follows similar third-party OAuth-abuse campaigns targeting Salesforce through Salesloft Drift and Gainsight integrations throughout 2025 and 2026. While the tactics resemble operations attributed to ShinyHunters and UNC6395 threat groups, attribution remains uncertain. The initial access vector, full scope of exfiltration, and attacker intent are still under investigation, with no extortion demands observed to date.</description><pubDate>Sat, 18 Jul 2026 03:23:58 GMT</pubDate></item><item><title>Botnet Analysis: A Product-Grade Threat for the AI Service Era</title><link>https://otx.alienvault.com/pulse/6a5a11b5327ee76f3502c500</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a5a11b5327ee76f3502c500</guid><description>NadMesh is an industrial-grade Go-based botnet observed in July 2026 that autonomously scans and exploits AI infrastructure and cloud services. The botnet integrates scanning, exploitation, and intelligence harvesting into a single platform targeting over 90 cloud provider address ranges. It employs 20+ exploitation vectors against Redis, Docker, MCP, Kubernetes, and other services, with particular focus on AI platforms like ComfyUI, Ollama, and Gradio discovered via Shodan API. NadMesh features a web-based management panel, polymorphic builds using Garble obfuscation and UPX packing, and redundant persistence mechanisms including SSH backdoors, agent processes, and cron watchdogs. The operation demonstrates clear commercial intent with conversion funnel statistics, canary updates, and automated task supply loops that amplify high-yield subnets. It harvests cloud credentials, Kubernetes tokens, AI model access, and MCP service intelligence.</description><pubDate>Fri, 17 Jul 2026 21:16:37 GMT</pubDate></item><item><title>Contagious Interview malware in SVG images: DPRK campaign</title><link>https://otx.alienvault.com/pulse/6a5a8ba0229db5a5b2686baa</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a5a8ba0229db5a5b2686baa</guid><description>A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic&apos;s community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers.</description><pubDate>Fri, 17 Jul 2026 21:11:59 GMT</pubDate></item><item><title>Behind the Refund: From GST Phishing to Remcos RAT Through a Multi-Stage .NET Infection Chain</title><link>https://otx.alienvault.com/pulse/6a5a0f86e175ec219dfa17b2</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a5a0f86e175ec219dfa17b2</guid><description>A sophisticated phishing campaign targeting Indian businesses and taxpayers leverages GST-related themes to distribute Remcos RAT through a multi-stage .NET framework. Threat actors impersonate Government of India GST communications using fraudulent refund notifications with convincing ARN references. The attack chain begins with a malicious RAR archive containing a .NET executable that employs bitmap-based payload concealment techniques. Through successive stages including Windows Health Optimizer Plus.dll and perfgurd.dll, the malware deploys Remcos RAT entirely in memory, establishing persistence via PowerShell scripts and registry modifications. Command-and-control infrastructure utilizes dynamic DNS services with randomized subdomains under aofmokighoig.hath.network. The deployed Remcos RAT enables remote command execution, keylogging, credential harvesting, file manipulation, and comprehensive system reconnaissance capabilities, representing a financially motivated cybercrime ope</description><pubDate>Fri, 17 Jul 2026 21:08:32 GMT</pubDate></item><item><title>ClickFix Campaign Generated Via AI Delivers SmartRAT</title><link>https://otx.alienvault.com/pulse/6a32e5873cf59d36f41c77be</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a32e5873cf59d36f41c77be</guid><description>In March 2026, threat actors leveraged AI-powered website builders to create typosquatting domains impersonating a Brazilian bank. The campaign employed ClickFix techniques, presenting victims with fake CAPTCHA and BSOD screens to trick them into executing malicious PowerShell commands. This delivered SmartRAT, a PowerShell-based banking trojan with capabilities including encrypted C2 communications, remote control of screen/keyboard/mouse, credential theft through keylogging and banking overlays, and QR code interception for transaction fraud. The malware establishes persistence via scheduled tasks and Windows services, and targets Brazilian financial institutions, payment platforms, and cryptocurrency exchanges. The threat actors&apos; C2 panel contained critical authentication flaws allowing client-side bypass, suggesting deployment without adequate security review.</description><pubDate>Fri, 17 Jul 2026 18:07:17 GMT</pubDate></item><item><title>ACR Stealer: Two observed intrusion chains amid increased threat activity</title><link>https://otx.alienvault.com/pulse/6a59832ac2ebd9e525a462b9</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a59832ac2ebd9e525a462b9</guid><description>Between late April and mid-June 2026, Microsoft observed heightened ACR Stealer activity targeting enterprise environments through ClickFix social engineering lures. This information-stealing malware, associated with Amatera Stealer rebranding and offered as malware-as-a-service, deployed through two distinct campaigns. The first utilized WebDAV-delivered payloads with Python loaders and blockchain-based command-and-control resolution. The second employed a fileless approach using MSHTA and steganography-concealed payloads within images. Both campaigns harvested browser credentials, authentication tokens, and sensitive documents from compromised systems. Threat actors leveraged obfuscated PowerShell scripts, scheduled task persistence, and in-memory execution techniques to evade detection. Notable tactics included masquerading as legitimate software updates, utilizing Windows DPAPI for credential decryption, and targeting PDF and Microsoft 365 documents. The blockchain dead-drop techni</description><pubDate>Fri, 17 Jul 2026 10:44:44 GMT</pubDate></item><item><title>Novel Starland RAT and bespoke WLDR C2 implant deployed in financially motivated campaign</title><link>https://otx.alienvault.com/pulse/6a58c1aa702b1130710d1bfb</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a58c1aa702b1130710d1bfb</guid><description>A sophisticated Russian-speaking financially motivated adversary designated UAT-11795 has been conducting malicious operations targeting users in the United States and Europe since June 2025. The campaign delivers a Python-based remote access tool called Starland RAT and a PowerShell-based command-and-control memory implant known as the WLDR agent. The actor distributes trojanized installers disguised as legitimate software including MobaXterm, WebEx, Zoom, DBeaver, and FACEIT through likely ClickFix social engineering techniques. The operation targets victims&apos; credentials and cryptocurrency wallet assets while establishing persistent connections for additional payload delivery. Alternative payloads include CastleStealer and Remcos RAT. The infrastructure utilizes distributed staging and C2 domains, Telegram bots for notifications, and a Polygon smart contract as a fallback mechanism for C2 domain resolution. The WLDR agent features encrypted beaconing, task queuing, and a Runspace exe</description><pubDate>Fri, 17 Jul 2026 07:15:24 GMT</pubDate></item><item><title>The Patch Wars have begun</title><link>https://otx.alienvault.com/pulse/6a5947760995db41a09b5025</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a5947760995db41a09b5025</guid><description>Microsoft released an unprecedented 622 vulnerability patches in July&apos;s Patch Tuesday, with 62 critical severity issues and three zero-days, two actively exploited. This represents more vulnerabilities than all of 2018 combined and marks a dramatic shift from the typical five patches issued in July two years prior. Microsoft attributes this surge to AI frontier model-accelerated vulnerability research. While major vendors like Microsoft possess resources to handle this volume, smaller companies face significant challenges. The concern extends beyond discovery to deployment, as traditional IT patch testing and stability review processes struggle under this unprecedented load. Organizations must differentiate between temporary surges and the new normal operational tempo, as continuous high-volume patching may become standard. This situation places extraordinary pressure on IT administrators and change management teams who must adapt to a sustained flood of KEV and EPSS notifications whil</description><pubDate>Fri, 17 Jul 2026 00:35:04 GMT</pubDate></item><item><title>GoSerpent backdoor attacks in Southeast Asia</title><link>https://otx.alienvault.com/pulse/6a590384cb730e14eaafeac5</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a590384cb730e14eaafeac5</guid><description>Since late 2025, government and diplomatic entities in Southeast Asia have been targeted by sophisticated attacks involving GoSerpent, a Go-based RAT with proxy capabilities. The malware receives encrypted arguments and deploys additional tools for data collection and credential dumping. GoSerpent has been active since 2021, with newer variants using AES-CBC encryption and ChaCha20 for communications. The campaign involves multiple stages: initial deployment of GoSerpent and ThumbcacheService to collect sensitive files, credential dumping via Mimikatz and QuarksDumpLocalHash, followed by deployment of Stowaway RAT in May 2026 and TmcLoader/TmcPayload for stealthy data exfiltration through network shares. The integrated toolset demonstrates sophisticated operational planning, with attackers leveraging Alibaba Cloud and UCLOUD HK infrastructure while exhibiting possible connections to the TetrisPhantom threat actor.</description><pubDate>Fri, 17 Jul 2026 00:31:55 GMT</pubDate></item><item><title>HelloNet campaign: a threat via the ViPNet update system</title><link>https://otx.alienvault.com/pulse/6a5903832a32a07a14de0d86</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a5903832a32a07a14de0d86</guid><description>An active APT campaign discovered in May 2026 exploits the ViPNet update system to deploy previously unknown tooling against large Russian organizations. Attackers achieve persistence through DLL sideloading, placing malicious wtsapi32.dll in ViPNet directories. The campaign employs multiple components: HelloInjector loader, HelloProxy for traffic proxying and payload delivery, HelloExecutor backdoor for command execution, HelloCleaner for log file sanitization, and HelloBackdoor written in Rust for file manipulation. Attackers conduct reconnaissance activities, establish SSH tunnels using renamed PuTTY utilities, and target government, energy, transport, education, logistics, and industrial sectors. Attribution points to an unknown Chinese-speaking APT group with low confidence based on strings referencing sina.com and Chinese package repositories.</description><pubDate>Fri, 17 Jul 2026 00:30:16 GMT</pubDate></item><item><title>The TTF Trap: A Global Campaign of a Low-Detection Lua Loader</title><link>https://otx.alienvault.com/pulse/6a59018a415370b96937338d</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a59018a415370b96937338d</guid><description>Since late March 2026, a large-scale phishing campaign has been deploying malware including Agent Tesla, Remcos, XWorm, and Best Private LOGGER through fileless techniques and low-detection Lua-based loaders. Attackers impersonate well-known companies using business cooperation lures to distribute malicious archives containing obfuscated JavaScript files. These scripts deploy either AutoIt or LuaJIT interpreters alongside disguised scripts masquerading as TrueType Font (.ttf) files. The Lua loaders employ sophisticated anti-analysis techniques including custom ROT ciphers, decoy memory allocation, and Donut shellcode generation for reflective in-memory payload execution. The campaign evolved from simpler implementations in October 2025 to highly complex versions by June 2026, incorporating API unhooking and advanced debugging countermeasures. Victims are ultimately infected with Remote Access Trojans and infostealers that enable full system control and extensive data exfiltration.</description><pubDate>Fri, 17 Jul 2026 00:25:52 GMT</pubDate></item><item><title>Spirals: New Stealthy Ransomware Deployed Against Asian IT Company</title><link>https://otx.alienvault.com/pulse/6a58c2ecd43c8e98d4bdd2e0</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a58c2ecd43c8e98d4bdd2e0</guid><description>A previously unseen ransomware family named Spirals was deployed in a double extortion attack against an IT services company in South Asia in June 2026. The Rust-based payload demonstrated sophisticated capabilities including defense evasion, encryption, lateral movement, and privilege escalation. Attackers gained initial access through a compromised internet-facing IIS web server via an ASP.NET web shell, moving rapidly to deploy ransomware within 24 hours. They established persistence using multiple tunneling tools, disabled endpoint security, harvested credentials through SAM hive and LSASS dumps, and deployed reverse-SOCKS proxies for covert command-and-control. The ransomware was distributed across the network using PsExec, encrypting files with AES-128 keys and threatening data publication within six days. The skilled execution suggests potential for wider campaigns, though the threat actor remains unidentified.</description><pubDate>Fri, 17 Jul 2026 00:24:48 GMT</pubDate></item><item><title>ClickLock Stealer: Paste Once, Lose Everything</title><link>https://otx.alienvault.com/pulse/6a58c1a90a160ce1e25e78e7</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a58c1a90a160ce1e25e78e7</guid><description>A new modular macOS information stealer named ClickLock Stealer has been discovered targeting users primarily in Europe, North America, and the Middle East. The malware is likely distributed via ClickFix social engineering pages that trick victims into pasting malicious commands into Terminal. Once executed, it deploys four components: a credential stealer, a Keychain stealer targeting Chrome&apos;s encryption key, a comprehensive crypto wallet harvester, and a persistent GSocket-based backdoor. The malware employs an aggressive &apos;locker&apos; technique, killing all visible applications except password dialogs to force user compliance. It targets data from eight browsers, 31 crypto wallet extensions, seven password managers, desktop wallets, macOS Keychain, and shell history. The campaign has compromised at least 100 victims across 33 countries since May 2026, using compromised WordPress domains and Telegram for command and control and exfiltration.</description><pubDate>Fri, 17 Jul 2026 00:22:56 GMT</pubDate></item><item><title>Attackers Weaponize Microsoft Teams Relays to Stay Hidden</title><link>https://otx.alienvault.com/pulse/6a316151d9ab4af59e56576d</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a316151d9ab4af59e56576d</guid><description>Attackers deploying DragonForce ransomware against a major U.S. services firm concealed their command-and-control traffic within Microsoft Teams relay infrastructure using Backdoor.Turn, a custom Go-based remote access trojan. This novel technique leverages anonymous Teams visitor tokens and TURN relay servers to mask malicious communications as legitimate Microsoft traffic. The intrusion lasted one to two months, beginning in December 2025 with exploitation of an SQL server vulnerability. Attackers employed sophisticated defense evasion tactics including DLL side-loading with VirtualBox executables and multiple Bring Your Own Vulnerable Driver techniques. They exploited a previously unknown vulnerability in Huawei&apos;s HWAuidoOs2Ec.sys driver, along with several other vulnerable drivers, to terminate security processes at kernel level. The campaign demonstrates DragonForce&apos;s evolution into a highly capable ransomware cartel with advanced operational maturity.</description><pubDate>Thu, 16 Jul 2026 14:19:54 GMT</pubDate></item><item><title>Potemkin Loader &amp; RMMProject The Anatomy of a ClickFix Attack</title><link>https://otx.alienvault.com/pulse/6a315d670f9460fe003298a8</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a315d670f9460fe003298a8</guid><description>A ClickFix social engineering attack on an unmonitored endpoint led to a multi-stage intrusion affecting over 11 hosts. The infection chain began with a malicious HTA payload that silently installed an MSI package containing Potemkin, a custom loader with a deterministic DGA. Potemkin delivered RMMProject, a 4.4 MB Lua-scriptable RAT featuring browser credential theft with Chrome App-Bound Encryption bypass, hidden-desktop remote control, and 15 distinct task types. The attacker deployed EtherRAT, a Node.js backdoor resolving C2 addresses from Ethereum blockchain, and established a Cloudflare tunnel for persistent access. Hands-on-keyboard activity included battling Windows Defender through AMSI patches, registry modifications, and service termination, followed by lateral movement via WMIExec and SMBExec to deploy malware across the network and reach the domain controller.</description><pubDate>Thu, 16 Jul 2026 14:19:54 GMT</pubDate></item><item><title>Gamers beware: malicious wallpapers on Steam found stealing accounts</title><link>https://otx.alienvault.com/pulse/6a311c5582f3c51d5631d979</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a311c5582f3c51d5631d979</guid><description>Since late 2025, cybercriminals have been exploiting Wallpaper Engine, a popular live wallpaper application on Steam, to distribute malware through Steam Workshop. Attackers target primarily Chinese and Russian gamers by embedding malicious code within application wallpapers shared on the platform. These compromised wallpapers deliver various malware types including infostealers, backdoors, crypto miners, and ransomware. One analyzed sample dropped DarkKomet backdoor while hijacking Steam sessions to steal account credentials. The malware modifies system libraries to locate Steam installations and exfiltrate data to attacker-controlled servers. Compromised accounts are then used to upload additional malicious wallpapers. The diverse malware families suggest multiple independent hacking groups are exploiting this distribution method. Infected wallpapers received thousands of downloads before removal, with 89% of infections occurring in China.</description><pubDate>Thu, 16 Jul 2026 11:25:27 GMT</pubDate></item><item><title>Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery</title><link>https://otx.alienvault.com/pulse/6a58813c09a76d1819c69bb0</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a58813c09a76d1819c69bb0</guid><description>On July 14, 2026, a coordinated supply chain attack compromised the @asyncapi npm organization, affecting five package versions across four packages. The attack originated from a GitHub Actions workflow vulnerability that exposed privileged credentials, enabling unauthorized code injection. Unlike typical postinstall attacks, this campaign executes at module import time, bypassing common npm install --ignore-scripts protections. The malicious code spawned hidden processes that fetched a second-stage payload from IPFS, deploying the Miasma modular runtime with command-and-control capabilities, persistence mechanisms, and credential harvesting features. The payload included disabled modules for supply-chain propagation, AI-tool poisoning, and sandbox evasion. All compromised packages were published through legitimate GitHub OIDC workflows with valid provenance signatures, masking the malicious activity within trusted release processes.</description><pubDate>Thu, 16 Jul 2026 10:43:41 GMT</pubDate></item><item><title>TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains</title><link>https://otx.alienvault.com/pulse/6a584223f539e1c98cd537cb</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a584223f539e1c98cd537cb</guid><description>TELEPUZ is a newly emerged modular malware-as-a-service first detected in April 2026, spreading through CLICKFIX-VIDAR infection chains. The lightweight, full-featured threat employs sophisticated evasion techniques including indirect syscalls, NTDLL unhooking, and anti-VM checks. It establishes persistence through service installation, communicates via WebSockets with C2 servers, and downloads additional modules for keylogging, credential theft, and web injection. The infection begins with social engineering tricks prompting victims to execute PowerShell commands, deploying VIDAR as a second stage which then delivers TELEPUZ components. Despite limited C2 infrastructure, high daily build volumes indicate active development and expanding operations by likely a small team or solo developer offering malware-as-a-service.</description><pubDate>Thu, 16 Jul 2026 10:18:27 GMT</pubDate></item><item><title>​​Kratos PhaaS Targets US and EU: How to Reduce Microsoft 365 Account Takeover Risk​</title><link>https://otx.alienvault.com/pulse/6a566597c655f8331b4e00ad</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a566597c655f8331b4e00ad</guid><description>Kratos is a mature Phishing-as-a-Service operation targeting Microsoft 365 users across the United States, Europe, and other regions. The platform enables attackers to steal credentials through trusted platforms, anti-bot verification, and convincing login pages. Researchers traced three generations of the kit and uncovered 1,484 previously unattributed detonations. The operation targets organizations across more than 20 countries with particularly strong concentration in the US, Spain, and Southern Europe. Kratos includes an operator panel allowing deployment of phishing domains, configurable Telegram or email delivery, geographic restrictions, and multiple anti-bot systems. The kit has evolved through three page generations (V0, V1, V2) with different exfiltration code. Activity has been visible since January 2026, with the operator panel active since September 2025.</description><pubDate>Thu, 16 Jul 2026 10:12:37 GMT</pubDate></item><item><title>Introducing CylindricalCanine: The GoldenEyeDog subgroup responsible for the April DigiCert incident</title><link>https://otx.alienvault.com/pulse/6a584222408c03d24cc2103d</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a584222408c03d24cc2103d</guid><description>Chinese cybercrime group GoldenEyeDog has been active since 2015, regularly updating malware and leveraging code-signing certificates to bypass Windows SmartScreen since 2024. A subgroup called CylindricalCanine uses Golden Gh0st Loader and Golden Gh0st RAT, modified versions of the 2008 Gh0st RAT, primarily targeting finance organizations in the Asia Pacific region through phishing campaigns. In April 2026, these actors compromised a DigiCert support member&apos;s device and stole code-signing certificates intended for customers, which they used to sign their own malware. The malware uses DLL sideloading, custom WebSocket protocols for command and control, and includes capabilities for remote access, credential theft, keylogging, SOCKS proxy tunneling, and RDP backdoor creation. Analysis reveals consistent tactics including using legitimate executables to load malicious DLLs that decrypt payloads from files disguised as logs.</description><pubDate>Thu, 16 Jul 2026 10:10:34 GMT</pubDate></item><item><title>Investigation of email-based attack delivering MediaFire ZIP file with execution chain analysis</title><link>https://otx.alienvault.com/pulse/6a30df4495796498a192312a</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a30df4495796498a192312a</guid><description>An investigation revealed a malicious email campaign directing victims to download a ZIP file from MediaFire. The infection chain began with a Python setup executable (Setu.exe) that side-loaded a malicious 400 MB python37.dll containing repeated byte padding. The DLL performed process injection into dllhost.exe, establishing communication with a C2 server at 138.124.186.2:7000. The threat actor deployed three persistence mechanisms: a PowerShell-based path, a fake EdgeUpdate Python executable with scheduled task, and NetSupport RMM as a third access method. The analysis highlights the importance of comparing file timestamps during triage to identify malicious artifacts within compressed archives.</description><pubDate>Thu, 16 Jul 2026 05:08:43 GMT</pubDate></item><item><title>WebAssembly Malware Found in Trojanized Open VSX Extensions</title><link>https://otx.alienvault.com/pulse/6a30d0b403db287f819b47e9</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a30d0b403db287f819b47e9</guid><description>Trojanized Visual Studio Code extensions distributed via the Open VSX marketplace deliver a sophisticated WebAssembly-based attack chain. The extensions ship ChaCha20-encrypted TinyGo-compiled WebAssembly modules that poll the Solana blockchain for command-and-control instructions embedded in transaction memos. This novel dead-drop technique allows attackers to rotate infrastructure without hardcoded servers. Once activated, the modules read attacker instructions from a monitored Solana wallet address, then execute platform-specific download-and-execute commands via Node.js child_process to deploy second-stage payloads. The campaign impersonates legitimate extensions on Open VSX, exploiting cross-registry trust gaps to target VSCodium, Cursor, Windsurf, and other VS Code forks. Attribution points to GlassWorm-associated tradecraft with medium confidence, representing a new WebAssembly-based variant of previously documented supply chain compromise techniques.</description><pubDate>Thu, 16 Jul 2026 04:02:57 GMT</pubDate></item><item><title>CVE-2026-58644: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-58644</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-58644</guid><description>Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&apos;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.</description><pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-25089: Fortinet FortiSandbox OS Command Injection Vulnerability</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-25089</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25089</guid><description>Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&apos;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.</description><pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-39808: Fortinet FortiSandbox OS Command Injection Vulnerability</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-39808</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39808</guid><description>Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&apos;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.</description><pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Fake crypto scams try to piggyback off SpaceX IPO</title><link>https://otx.alienvault.com/pulse/6a57f270713faa71010c16ad</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a57f270713faa71010c16ad</guid><description>Scammers are exploiting public interest in the SpaceX IPO through fraudulent investment portals impersonating SpaceX, Elon Musk, and major financial brands including Fidelity and Robinhood. The campaign uses themed domains to lure victims into fake onboarding processes that mimic legitimate investment procedures, including W-8BEN tax forms for non-U.S. investors. Victims are asked to select investment tiers and ultimately directed to deposit funds via cryptocurrency wallets for Bitcoin, Ethereum, and USDT. The operation mirrors techniques used by threat actor TA2730 but focuses on direct cryptocurrency theft rather than credential harvesting. One Bitcoin wallet associated with the campaign received approximately $8,700. The infrastructure includes randomized domains and SpaceX-themed domains designed to appear legitimate during the investment process.</description><pubDate>Wed, 15 Jul 2026 21:58:15 GMT</pubDate></item><item><title>Operation Fake KickOff: Attackers Abuse Recruiters and SaaS to Harvest Work Credentials</title><link>https://otx.alienvault.com/pulse/6a57f26f4f7b83bede7d73d8</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a57f26f4f7b83bede7d73d8</guid><description>A sophisticated multi-stage phishing operation has been active since April 2025, systematically exploiting legitimate SaaS platforms and cloud services to steal corporate credentials. The campaign utilizes 232 phishing domains and 80 command-and-control servers, primarily impersonating human resources consulting firms, with Robert Half Inc. and Aquent LLC representing 50% of targeted brands. Attackers leverage legitimate platforms like Salesforce, SendGrid, and Zoho for email delivery, directing victims to fake Calendly interview pages that mimic real recruiter identities. The operation deploys an adversary-in-the-middle toolkit using browser-in-the-box techniques to create replica Google sign-in pages, capable of harvesting credentials and bypassing MFA through email, SMS, Google Authenticator, and prompt notifications. The campaign specifically targets corporate email accounts, filtering out personal providers, with stolen data exfiltrated to Render-hosted servers and Telegram bots.</description><pubDate>Wed, 15 Jul 2026 21:55:47 GMT</pubDate></item><item><title>11 Malicious NuGet Tools Pose as Game Cheats to Drop a Windows Host-Surveillance Payload</title><link>https://otx.alienvault.com/pulse/6a57b568d98a7ae03ccd6071</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a57b568d98a7ae03ccd6071</guid><description>Eleven malicious NuGet packages distributed as .NET command-line tools masquerade as game utilities and cheats for popular games including Albion Online, GTA5RP, GrandRP, and Throne and Liberty. Each package functions as a first-stage downloader that uses DNS-over-HTTPS to bypass local controls, requests UAC elevation to resync system time, and fetches a second-stage PyInstaller payload named pepesoft.exe from GitHub and Hugging Face under username pepegit666. The payload binds to hardware fingerprints, enforces licensing through Google Sheets telemetry, honors remote ban-lists, and in three variants exposes Telegram bot commands enabling screenshot capture and remote control. All packages share identical AWS credentials and mutex identifiers, linking them to a single Russian-speaking operator running a commercial game-automation service marketed through pepesoft.ru and Telegram channel pepesoft777.</description><pubDate>Wed, 15 Jul 2026 21:53:01 GMT</pubDate></item><item><title>Shared Claude Chats Meet ClickFix</title><link>https://otx.alienvault.com/pulse/6a57b1d61379f5309f46131d</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a57b1d61379f5309f46131d</guid><description>A ClickFix campaign has been identified that abuses Anthropic&apos;s Claude platform through shareable chat links to distribute MacSync Stealer targeting macOS users. Attackers utilized malvertising with paid Google ads to direct victims searching for Claude-related terms to malicious shared Claude chats falsely labeled as &apos;Apple Support.&apos; These chats contained obfuscated installation commands that, when executed, deployed a multi-stage infection chain. The malware steals credentials from browsers and password managers, cryptocurrency wallet data, sensitive files, and system information. The campaign ran from June 12-19, 2026, targeting primarily Mac users with Russian-language comments in the code suggesting Russian-speaking threat actors. Domains used adopted themes related to U.S. local services to appear legitimate.</description><pubDate>Wed, 15 Jul 2026 21:49:00 GMT</pubDate></item><item><title>June 2026 Infostealer Trend Report</title><link>https://otx.alienvault.com/pulse/6a5775d6071af081378a0eb9</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a5775d6071af081378a0eb9</guid><description>During June 2026, multiple infostealer families including Remus, ACRStealer, LummaC2, and Vidar were distributed through SEO poisoning techniques, disguised as illegal software such as cracks and keygens. Attacks utilized EXE files (84.5%) and DLL side-loading (15.5%) methods, with distribution primarily through Mediafire, Mega, and cloud storage platforms. Microsoft Corporation was the most frequently impersonated entity. MacOS environments were targeted through ClickFix techniques and malicious Bash scripts, with one variant dynamically obtaining C2 addresses via Polygon smart contracts. Email-based campaigns distributed AgentTesla and DarkCloud through compressed attachments, with both variants exfiltrating data via SMTP. The stolen credentials pose significant risks for dark web trading and secondary attacks.</description><pubDate>Wed, 15 Jul 2026 21:43:10 GMT</pubDate></item><item><title>OkoBot framework infection chain</title><link>https://otx.alienvault.com/pulse/6a5775d2afd24bb0357b62c1</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a5775d2afd24bb0357b62c1</guid><description>In January 2026, researchers identified a sophisticated malware framework dubbed OkoBot that targets cryptocurrency users through a multi-stage infection chain. The campaign begins with TookPS PowerShell scripts delivered via ClickFix attacks or fake software on GitHub. An automated SSH bot deploys over 20 malicious modules including HDUtil launcher, browser extension injectors installing Rilide stealer, and specialized tools like SeedHunter for wallet seed phrase theft and OkoSpyware for window capture. The framework uses VMProtect obfuscation, UAC bypass techniques, and maintains persistence through RDP access and scheduled tasks. Victims span more than 25 countries with concentrations in Brazil, Vietnam, Canada, Mexico, and Turkey. Attribution suggests Russian-speaking threat actors based on geoblocking patterns and Russian language artifacts.</description><pubDate>Wed, 15 Jul 2026 21:42:04 GMT</pubDate></item><item><title>Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor</title><link>https://otx.alienvault.com/pulse/6a5775d3b8fe983226594b7c</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a5775d3b8fe983226594b7c</guid><description>Backdoor.Daxin, a sophisticated China-linked kernel-mode rootkit first exposed in 2022, was discovered operating on a Taiwan manufacturing firm&apos;s network in 2026. The malware was found alongside Backdoor.Stupig, a previously unknown backdoor that uses a novel technique involving a Trojanized keyboard-layout DLL loaded by winlogon.exe, enabling command execution as System from the Windows logon screen without authentication. Both samples carry compile timestamps from early 2013, but the compromised host only began reporting telemetry in May 2026, suggesting a possible 13-year undetected intrusion. The victim was a Taiwan-based subsidiary of a multinational high-tech manufacturer. Daxin&apos;s defining characteristic is its ability to hijack legitimate TCP connections for command-and-control traffic, making it exceptionally difficult to detect through conventional network monitoring.</description><pubDate>Wed, 15 Jul 2026 21:37:55 GMT</pubDate></item><item><title>How attackers are jailbreaking LLMs with CTF framing and how to catch them</title><link>https://otx.alienvault.com/pulse/6a30537886784fbb90bd4a5b</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a30537886784fbb90bd4a5b</guid><description>Threat actors are bypassing AI model safety guardrails by framing exploit requests as legitimate security research, such as capture-the-flag challenges or CVE-hunting exercises. This technique manipulates upstream LLMs into generating working exploit code that attackers deploy against real targets. Multiple independent operators have been observed targeting five applications—PraisonAI, LiteLLM, FastGPT, Open-WebUI, and Gotenberg—using CVE-templated User-Agent strings and similar framing across multiple fields including passwords and AWS session names. The jailbreak framing leaks into every LLM-generated field because the model incorporates the prompt context into its output. This pattern represents a shift from manually written scanners to LLM-assisted exploit generation, creating detectable fingerprints across request headers, account aliases, and IAM session names that legitimate traffic rarely exhibits.</description><pubDate>Wed, 15 Jul 2026 19:11:54 GMT</pubDate></item><item><title>Public and Private Medical Community Targeted by Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research</title><link>https://otx.alienvault.com/pulse/6a305377d29f8bfdadc72786</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a305377d29f8bfdadc72786</guid><description>A sophisticated espionage campaign attributed to UNC6508, a China-nexus threat actor, targeted North American academic, medical, and military research institutions for over a year. The adversary exploited REDCap servers, deployed custom INFINITERED malware to harvest credentials, and maintained persistent access through trojanized legitimate files that survived software upgrades. After remaining undetected for more than a year, the threat actor pivoted to administrative accounts and created malicious content compliance rules to silently exfiltrate emails containing defense intelligence, Indo-Pacific command operations, artificial intelligence research, uncrewed vehicle systems, cyber programs, and medical research data. The operation employed sophisticated techniques including obfuscation networks routing through US-based infrastructure, compromised routers, and dedicated exfiltration accounts, demonstrating advanced operational security aligned with strategic intelligence collection r</description><pubDate>Wed, 15 Jul 2026 19:11:54 GMT</pubDate></item><item><title>Inside an IoT Botnet Framework With LLM-Assisted Development</title><link>https://otx.alienvault.com/pulse/6a5775d49e35f9a04532b24d</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a5775d49e35f9a04532b24d</guid><description>A previously undocumented modular IoT botnet framework has been identified with code partially generated using large language models. The framework consists of C-based bot agents compiled for 17 architectures, a Go-based command-and-control server with DDoS-for-hire panel, and custom exploit capabilities. Bot agents brute-force Telnet access using 1,496 credential pairs and target over 30 IoT device families. While core infection mechanisms function properly, several features are broken due to LLM-generated bugs that were shipped without manual review. The framework includes multiple fallback C2 mechanisms including domain generation algorithms, peer-to-peer gossip, IRC, and DNS TXT queries. Infrastructure analysis links this operation to the Keksec ecosystem through shared dropper servers. Development timeline spans from January 2025 to April 2026, with active C2 infrastructure observed since March 2026.</description><pubDate>Wed, 15 Jul 2026 14:36:16 GMT</pubDate></item><item><title>Miasma Worm Returns to npm</title><link>https://otx.alienvault.com/pulse/6a579712c94f47186288661d</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a579712c94f47186288661d</guid><description>Four AsyncAPI npm packages were compromised in July 2026, delivering Miasma v3, a new variant of the worm previously found in Red Hat packages. The malicious versions (@asyncapi/generator, @asyncapi/generator-helpers, @asyncapi/generator-components, and @asyncapi/specs) were published through AsyncAPI&apos;s legitimate GitHub Actions workflow using npm&apos;s OIDC integration, creating packages with valid provenance attestations. Unlike previous variants, this attack triggers when applications load the poisoned library rather than during installation. The payload downloads a second stage from IPFS, establishing a persistent Node.js backdoor with arbitrary shell command execution capabilities. While the codebase contains credential theft, propagation, and AI-tool poisoning modules, this deployment primarily functions as a remote access trojan. The attack began with an unauthorized commit to the repository&apos;s release branch, highlighting the importance of branch protection even when using trusted-p</description><pubDate>Wed, 15 Jul 2026 14:33:29 GMT</pubDate></item><item><title>Six Minutes to Compromise: How &apos;Patriot Bait&apos; Actor Used AI to Build and Deploy a C&amp;C Botnet</title><link>https://otx.alienvault.com/pulse/6a57358efddea38fc28153f6</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a57358efddea38fc28153f6</guid><description>A Russian-speaking threat actor known as &apos;bandcampro&apos; leveraged Google Gemini CLI to migrate and operate a command-and-control botnet in six minutes, with the AI handling 89% of all work including architecture, coding, deployment, and debugging. Analysis of 200 Gemini CLI session logs from March-April 2026 revealed the actor controlled eight computers in a dental clinic, accessing OpenDental databases. The actor communicated intentions in plain Russian while AI executed technical operations. The entire C&amp;C infrastructure fits in three plain-text files totaling 5KB, making it highly portable and disposable. Beyond botnet operations, the actor used AI for password cracking, WordPress compromise, and planning cryptocurrency fraud targeting elderly victims in the US and Canada. The AI proactively suggested improvements 59 times unprompted, demonstrating how AI lowers barriers for threat actors by replacing technical skill requirements with simple natural-language instructions.</description><pubDate>Wed, 15 Jul 2026 14:18:33 GMT</pubDate></item><item><title>Threat Spotlight: The Jalisco Toolkit and AI-Powered Phishing Surge</title><link>https://otx.alienvault.com/pulse/6a56e4f5789e1bf3de8e82be</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a56e4f5789e1bf3de8e82be</guid><description>Phishing attacks have surged in 2026 as AI-powered phishing-as-a-service kits enable threat actors to bypass multi-factor authentication and harvest OAuth tokens at scale. Two phishing tools were identified in active campaigns: Jalisco, a device code phishing toolkit that provisions fresh OAuth codes in real time to defeat time-based security controls, and OmegaLord, a credential harvester that captures phone numbers alongside passwords to intercept MFA. Both tools demonstrate that attackers are engineering sophisticated methods to defeat authentication controls. These toolkits are part of a broader ecosystem that includes AI-powered PhaaS kits like EvilTokens and Kali365, which leverage legitimate cloud platforms to evade detection. Following compromise, attackers establish persistence by enrolling multiple devices to victim Entra ID tenants, enabling access that survives password resets and extends the window for data exfiltration and extortion.</description><pubDate>Wed, 15 Jul 2026 14:13:57 GMT</pubDate></item><item><title>Suspected Chinese Operators Use Claude Code and DeepSeek to Breach Government Systems Across Four Countries</title><link>https://otx.alienvault.com/pulse/6a56a77a59a4d2b99d9aa87f</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a56a77a59a4d2b99d9aa87f</guid><description>In June 2026, infrastructure pivoting from TencShell C2 nodes revealed an active intrusion campaign utilizing AI language models for attack automation. Thirteen Hong Kong-based servers across four ASNs exposed an open directory containing victim source code, custom exploits, operational logs, and cloned login pages with notes in Simplified Chinese. The operation employed Claude Code for execution and DeepSeek-v4-pro for attack logic, targeting government systems in Afghanistan, Thailand, and Taiwan, along with reconnaissance against U.S. government portals. The campaign also pursued financial services firms across Europe, Australia, and Asia. Attackers deployed TencShell implants, webshells, and custom exploits including SQL injection and Laravel deserialization attacks, successfully compromising administrative systems and exfiltrating sensitive data including citizen complaints and government employee information.</description><pubDate>Wed, 15 Jul 2026 14:12:26 GMT</pubDate></item><item><title>LabubaRAT: A Rust Based Remote Access Tool Masquerading as NVIDIA Software</title><link>https://otx.alienvault.com/pulse/6a56a77949905f89b073e5fd</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a56a77949905f89b073e5fd</guid><description>A previously undocumented remote access tool named LabubaRAT has been identified, masquerading as NVIDIA software through fake metadata and runtime artifacts. This Rust-based malware creates persistent footholds enabling hands-on operator activity including host profiling, security tool identification, command execution, file transfers, screenshot capture, and traffic proxying. The implant supports multiple communication methods including HTTPS polling, WebView2-based communication, and DNS tunneling. It uses a configurable framework model with organization, group, server, and API key parameters suggesting a Malware-as-a-Service platform. The malware maintains local state in SQLite databases and provides comprehensive remote access capabilities including PowerShell and JavaScript execution, SOCKS5 proxy support, and user-level persistence through registry autoruns. Infrastructure analysis revealed LabubaPanel branding with associated command and control servers hosted on German provide</description><pubDate>Wed, 15 Jul 2026 14:11:13 GMT</pubDate></item><item><title>Analysis of APT37 NarwhalRAT Leveraging MS-Themed Phishing and Dead-drop C2</title><link>https://otx.alienvault.com/pulse/6a30130ad416e33ebf9e9417</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a30130ad416e33ebf9e9417</guid><description>A sophisticated Python-based RAT targeting Korean users through spear phishing emails disguised as Microsoft security alerts. The attack chain employs LNK files embedded in ZIP archives, BAT-based obfuscation, and multi-stage loaders culminating in NarwhalRAT deployment. This advanced malware features keylogging, screen capture, microphone recording, and USB data collection capabilities. It utilizes a dual C2 infrastructure combining Korean relay servers (daehoat.com, novel21.co.kr) with pCloud API as a dead-drop resolver. The malware creates encrypted configuration files, implements anti-VM techniques, and establishes persistence through scheduled tasks. It operates as a manually-controlled RAT with selective function activation via C2 commands, employing in-memory execution to evade file-based detection.</description><pubDate>Wed, 15 Jul 2026 14:02:33 GMT</pubDate></item><item><title>The Devil, Eight Million Emails, and a Whole Lot of Milk | Phishing Stager Exposed</title><link>https://otx.alienvault.com/pulse/6a3011d0c31292cdb59fd70b</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a3011d0c31292cdb59fd70b</guid><description>On May 15, 2026, Huntress agents detected an intrusion where threat actors compromised a terminal server to stage a massive phishing campaign rather than deploy ransomware. The attacker used legitimate bulk email software (Gammadyne Mailer) with a project file named &apos;dracii&apos; (Romanian for &apos;the devils&apos;) and six recipient lists containing 8,894,920 email addresses. Operating from Romanian IP addresses, the actor impersonated UK pharmacy chain Boots through a fake customer satisfaction survey designed to harvest personal and payment card data. The phishing kit was hosted on a compromised Bolivian government website (ipelc.gob.bo), which Huntress reported to Bolivia&apos;s national CSIRT. The campaign used direct-to-MX delivery to bypass mail relays, with the mailer configured to send from 666 threads simultaneously. Evidence suggests this Romanian operator has been running multiple UK-targeting campaigns since at least July 2025, rotating between retail, tax, and cryptocurrency themes.</description><pubDate>Wed, 15 Jul 2026 14:02:33 GMT</pubDate></item><item><title>One Misconfigured Server, Three Active Campaigns: Full exposure of three AiTM Phishing Operators</title><link>https://otx.alienvault.com/pulse/6a54bfc57c70fae743cb883e</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a54bfc57c70fae743cb883e</guid><description>A misconfigured Python HTTP server on a Budapest VPS exposed the complete operational infrastructure of three distinct phishing operators. The investigation uncovered codemado, an Egyptian threat actor operating since 2018, running a full AiTM platform with custom tools including MaDoO Blaster; saroula01, deploying OAuth Device Code Flow attacks that accumulated 218 victims across 12 countries over a year; and mail-argenta, a Nigerian operator identified through infostealer logs containing his own credentials. All three actors leveraged customized Evilginx forks and AI-assisted development to build MFA-bypass infrastructure from public GitHub repositories. The campaigns targeted Microsoft 365 accounts primarily, with codemado maintaining ties to RockyBelling&apos;s &quot;The Quarry&quot; cybercrime ecosystem. The exposed server contained phishing configurations, credential logs, RMM installers, combolists, and Telegram session files, revealing sustained operations from at least January 2025 through M</description><pubDate>Wed, 15 Jul 2026 12:16:30 GMT</pubDate></item><item><title>CVE-2026-46817: Oracle E-Business Suite Improper Privilege Management Vulnerability</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-46817</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46817</guid><description>Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&apos;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.</description><pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2023-4346: KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability</title><link>https://nvd.nist.gov/vuln/detail/CVE-2023-4346</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-4346</guid><description>KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without additional security options enabled and set a BCU key to lock the device. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&apos;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.</description><pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate></item><item><title>The Scam Will Go On: Beware of Fake Offers for Celine Dion Concert Tickets</title><link>https://otx.alienvault.com/pulse/6a566597fbaff52dd5288ce4</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a566597fbaff52dd5288ce4</guid><description>A sophisticated multi-layered scam operation targets fans seeking tickets for Celine Dion&apos;s French tour through two primary vectors. Fraudsters embed themselves in Facebook Groups and Marketplace, using social engineering to create artificial urgency and selling tickets before official presale dates. They exploit Ticketmaster&apos;s legitimate transfer feature to resell identical digital tickets to multiple victims, accepting direct bank transfers from compromised accounts. Simultaneously, threat actors deploy fraudulent websites impersonating official distributors like AXS and Ticketmaster, exploiting Shopify&apos;s payment infrastructure to appear legitimate. These sites share common technical indicators suggesting use of a recycled phishing kit previously deployed for other major concert events, including Oasis and Taylor Swift tours. The scheme combines emotional manipulation with technical deception to defraud victims desperate for concert access.</description><pubDate>Tue, 14 Jul 2026 17:38:04 GMT</pubDate></item><item><title>Compromised npm Packages in the AsyncAPI Namespace Deliver Miasma Botnet Loader</title><link>https://otx.alienvault.com/pulse/6a5665a177561cba872b779e</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a5665a177561cba872b779e</guid><description>Four npm packages in the AsyncAPI namespace were compromised to distribute a multi-stage botnet loader called Miasma. The attack utilized trusted GitHub Actions publishing but originated from a poisoned source commit. Malicious code was injected into legitimate source files that execute when imported, launching a detached Node.js process to download an 8.25 MB encrypted payload from IPFS. The final payload is a sophisticated tasking framework supporting multiple command-and-control channels including REST, Nostr relays, IPFS, Ethereum smart contracts, and BitTorrent DHT. The framework establishes persistence via systemd services on Linux and fake NodeJS directories, supporting file operations, shell execution, data collection, and cross-ecosystem propagation capabilities for npm, PyPI, RubyGems, and Cargo ecosystems.</description><pubDate>Tue, 14 Jul 2026 17:32:34 GMT</pubDate></item><item><title>Supply Chain Compromise via GitHub Actions</title><link>https://otx.alienvault.com/pulse/6a5665a03fa69522f5e6c982</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a5665a03fa69522f5e6c982</guid><description>On July 14, 2026, an attacker exploited a misconfigured GitHub Actions workflow in the AsyncAPI generator repository through a &apos;pwn request&apos; vulnerability. The attacker opened 37 pull requests, with one containing obfuscated JavaScript that exfiltrated a highly privileged Personal Access Token belonging to asyncapi-bot. Using the stolen credentials, the attacker published five malicious npm package versions under the @asyncapi namespace, which collectively receive over three million downloads weekly. The malware features a multi-stage payload that establishes persistence and connects to command and control infrastructure, executing on import rather than install. It includes capabilities for credential theft targeting browsers, SSH keys, cloud credentials, and cryptocurrency wallets. The payload shares technical characteristics with the Miasma malware framework but shows unique features including a comprehensive command framework.</description><pubDate>Tue, 14 Jul 2026 17:32:29 GMT</pubDate></item><item><title>Lucide Proxy: Turning Student Web Proxies into DDoS Bots</title><link>https://otx.alienvault.com/pulse/6a5660720f790923b2946df9</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a5660720f790923b2946df9</guid><description>A sophisticated campaign deployed 148 malicious npm packages disguised as student web proxy applications under brands like Riverbend Tutoring and Northstar Tutoring. Published by accounts terminal3airport and eerikakirk, these packages weaponized visitor browsers into distributed denial-of-service botnets while generating advertising revenue. The applications functioned as working proxies but secretly executed mutable remote code and high-performance WebSocket traffic generators compatible with the Wisp protocol. During a critical two-week period in May 2026, active deployments launched HTTP floods generating 2GB/s aggregate traffic and control-plane attacks establishing 10,240 socket connections per second against target servers. The campaign abused npm as a content delivery network, affecting users who visited proxy instances rather than through traditional dependency infection.</description><pubDate>Tue, 14 Jul 2026 16:37:26 GMT</pubDate></item><item><title>Operation ShadowRecruit: A Recruitment-Themed Malware Campaign Leveraging ControlR and Google Sheets to Target Indian Job Seekers</title><link>https://otx.alienvault.com/pulse/6a5622b97dd5ae5935298cdb</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a5622b97dd5ae5935298cdb</guid><description>A sophisticated cyber campaign targets Indian government job seekers using fake recruitment advertisements for Senior Field Officer positions in the Cabinet Secretariat. The attack chain begins with a malicious ZIP archive containing a disguised LNK file, PowerShell script, and .NET executable. Attackers abuse the legitimate ControlR remote management tool for persistent access and deploy SheetAgent RAT, a custom .NET malware that uses Google Sheets as a command-and-control channel. The malware employs multiple persistence mechanisms including scheduled tasks and startup folder entries, while incorporating extensive anti-analysis checks to detect virtualized environments. Infrastructure analysis reveals multiple web-based management panels and connections to APT36 based on targeting patterns and tradecraft similarities.</description><pubDate>Tue, 14 Jul 2026 16:17:26 GMT</pubDate></item><item><title>ModHeader Malware: Inside the Chrome Spyware Google Removed</title><link>https://otx.alienvault.com/pulse/6a55ed9b6b71e59faf2f8ea7</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a55ed9b6b71e59faf2f8ea7</guid><description>ModHeader, a popular Chrome developer extension with over 800,000 users, was flagged and removed by Google for containing hidden spyware. Version 7.0.18 included a covert SDK disguised as a date library (dayjs) that harvested visited domain names, encrypted them using AES-GCM, and was configured to upload the data daily to api.stanfordstudies.com. Although the collection remained dormant due to an empty allowlist, the complete exfiltration infrastructure was present and operational. Additionally, the extension displayed active adware behavior, opening affiliate tabs on every update including on enterprise-managed machines. The malicious code shipped with official Chrome Web Store signatures, affecting both Chrome and Edge users. Forensic analysis revealed the extension locally stored 178MB of sensitive HTTP headers from all browsing activity, though no data was successfully exfiltrated from analyzed systems.</description><pubDate>Tue, 14 Jul 2026 09:53:41 GMT</pubDate></item><item><title>CrashStealer: C++ macOS Infostealer Posing as Crash Reporter</title><link>https://otx.alienvault.com/pulse/6a55ec60c2d64907df771c4c</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a55ec60c2d64907df771c4c</guid><description>A newly discovered macOS infostealer, implemented in native C++, impersonates Apple&apos;s crash-reporting framework to harvest sensitive data. The malware is distributed through a signed and notarized dropper application that bypasses Gatekeeper, then downloads and installs the payload from attacker infrastructure. The stealer validates victim passwords locally using dscl, unlocks the login keychain, and collects browser credentials, cryptocurrency wallet extensions, password manager data, and keychain material. Collected data is encrypted using AES-GCM before being packaged into hidden ZIP archives and exfiltrated to a command-and-control server. The malware establishes persistence by copying itself to a hidden directory and installing a LaunchAgent. It employs control-flow flattening, encrypted strings, and anti-debugging techniques to resist analysis. The campaign uses GitHub for initial staging and multiple fake collaboration software domains as lures.</description><pubDate>Tue, 14 Jul 2026 09:43:04 GMT</pubDate></item><item><title>Tomorrowland 2026, Belgium: People of Tomorrow, Targets of Today</title><link>https://otx.alienvault.com/pulse/6a55e306b92e2ed9438ab45f</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a55e306b92e2ed9438ab45f</guid><description>Tomorrowland Belgium 2026, spanning two weekends in July at De Schorre in Boom, sold out rapidly, creating opportunities for cybercriminals. Investigation uncovered approximately a dozen fraudulent websites impersonating the festival brand to target ticket seekers and travellers. These scams include fake ticket shops mimicking official sales with countdown timers and fraudulent biometric checks, travel sites offering bogus accommodation and transport packages, and affiliate schemes. The operations harvest complete identity data, payment credentials, and personal information through sophisticated social engineering. Victims lose money with no recourse, face identity theft risks, and ultimately receive invalid or non-existent tickets. The scammers exploit high demand, tight supply, and rushed purchasing decisions, with sites registered weeks in advance and pushed hardest when official tickets are sold out.</description><pubDate>Tue, 14 Jul 2026 09:35:06 GMT</pubDate></item><item><title>Defending SaaS-based applications against ShinyHunters OAuth abuse</title><link>https://otx.alienvault.com/pulse/6a55a1380d4e12c0ea409b6e</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a55a1380d4e12c0ea409b6e</guid><description>Between mid-2025 and mid-2026, threat actors using tradecraft associated with ShinyHunters targeted customer SaaS applications, particularly Salesforce instances, through three primary intrusion paths. Voice phishing campaigns impersonated IT support to trick employees into authorizing malicious OAuth applications. Supply chain compromises leveraged trusted integrations including Salesloft, Gainsight, and Klue to obtain OAuth tokens for downstream customer access. Misconfigured guest access enabled exploitation of Aura framework functionality for unauthorized data queries. These techniques abused legitimate OAuth relationships to inherit user and application privileges, enabling enumeration and exfiltration of CRM data while evading authentication detections. The campaigns targeted multiple industries including retail, education, and manufacturing, highlighting risks in OAuth-connected applications and third-party integrations.</description><pubDate>Tue, 14 Jul 2026 09:32:55 GMT</pubDate></item><item><title>CVE-2026-56155: Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-56155</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-56155</guid><description>Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&apos;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-56164: Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-56164</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-56164</guid><description>Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&apos;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-15409: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-15409</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-15409</guid><description>SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&apos;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-15410: SonicWall SMA1000 Appliances Code Injection Vulnerability</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-15410</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-15410</guid><description>SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&apos;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Threat Actors Achieve Persistence After SQL Injection</title><link>https://otx.alienvault.com/pulse/6a551f28c1e094d7650c8ecd</link><guid isPermaLink="true">https://otx.alienvault.com/pulse/6a551f28c1e094d7650c8ecd</guid><description>Threat actors gaining initial access through SQL injection exploited a web application vulnerability in a technology sector organization. After compromising an MSSQL instance via inadequate input validation, the attackers deployed base64-encoded PowerShell scripts to conduct reconnaissance using tasklist commands and exfiltrated results to an external server. They established persistence by enabling Remote Desktop Services, creating an administratively privileged user account named adminweb2$, and disabling Windows Defender. The attackers installed BadIIS modules for SEO fraud, deployed XMRig cryptocurrency miner with hidden file attributes, and utilized service creation tools. Multiple PowerShell scripts and batch files were downloaded throughout the attack to facilitate various malicious operations and maintain access.</description><pubDate>Mon, 13 Jul 2026 20:52:22 GMT</pubDate></item><item><title>CVE-2008-4128: Cisco IOS Cross-Site Request Forgery Vulnerability</title><link>https://nvd.nist.gov/vuln/detail/CVE-2008-4128</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-4128</guid><description>Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain &quot;show privilege&quot; command to the /level/15/exec/- URI, and (2) a certain &quot;alias exec&quot; command to the /level/15/exec/-/configure/http URI. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&apos;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.</description><pubDate>Mon, 13 Jul 2026 00:00:00 GMT</pubDate></item></channel></rss>