daily cyber × ai intelligence

index

July 4, 2026

Silent Active Directory Recon and a Near-Perfect Linux Root Exploit Lead the Offensive Beat

32 sources 316 gathered 316 triaged 43 clustered 43 written

Huntress detailed an LDAP Ping technique that enumerates Active Directory usernames without touching Windows audit logs, and a new “Bad Epoll” kernel flaw gives unprivileged users root on Linux and Android with a 99%-reliable PoC. Elsewhere, indirect prompt injection moved from theory to fraud, and researchers found Pegasus on the phone of an EU lawmaker who was investigating spyware.

Offensive & Red Team

  • LDAP Ping (cLDAP) is a blind spot for AD detection. Huntress researchers (@HuntressLabs, @4ndr3w6S) showed that using LDAP Ping to enumerate AD usernames leaves no trace in Windows audit logs — requests are handled by netlogon.dll rather than ntdsa.dll, so the usual Event 1644 never fires. The pre-auth, no-credentials technique yields confirmed account names for follow-on password spraying and BloodHound/PowerView recon; traffic is still visible at the network level (UDP/389, WFP traces). Huntress
  • AppDomainManager injection delivers a new .NET backdoor. Unit 42 tracked a campaign against energy and government entities in Southeast Asia that used AppDomainManager injection to load TinyRCT, a previously undocumented .NET backdoor. Unit 42

Vulnerabilities & Exploits

  • “Bad Epoll” (CVE-2026-46242) gives local users root on Linux 6.4+ and newer Android. The kernel flaw sits in the same stretch of code where Anthropic’s Mythos model recently found a different bug; the PoC reached 99% reliability and may be triggerable from the Chrome renderer sandbox. A fix is out. The Hacker News
  • DirtyClone (CVE-2026-43503) exploitation dissected. JFrog published a technical teardown of a Linux LPE variant, walking through how the bug is triggered and exploited for privilege escalation. JFrog Research
  • Windows Netlogon critical RCE reported exploited. CERT-EU flagged a critical flaw affecting Windows Server domain controllers that lets an unauthenticated attacker execute arbitrary code over the network; Belgium’s CCB reports active exploitation. Patch DCs immediately. CERT-EU 2026-007
  • PAN-OS unauth root-RCE under limited exploitation. Palo Alto’s advisory covers a critical PAN-OS flaw allowing unauthenticated arbitrary code execution with root privileges; the vendor has observed limited in-the-wild activity. CERT-EU 2026-006
  • watchTowr posts a full ColdFusion APSB26-68 analysis. Following last week’s seven CVSS-10 patches, watchTowr published a deep-dive on the ColdFusion “CVE bonanza,” while Denmark’s CERT warned the bugs open the door to full server takeover. watchTowr · CERT.dk
  • KDE Plasma sandbox escape. A researcher documented arbitrary code execution that breaks out of sandboxes in KDE Plasma. kimiblock
  • The “OpenSSL error-handling pandemic.” An analysis argues that widespread incomplete OpenSSL error handling in production code creates a broad, under-appreciated class of security bugs. jak-linux blog
  • Ivanti Sentry and EPMM unauth RCE. CERT-EU reiterated critical flaws enabling unauthenticated remote code execution across Ivanti Sentry and EPMM products, one of which has seen limited exploitation. CERT-EU 2026-008

Cloud & Identity

  • Alleged M365 pre-auth, zero-click RCE listed on a dark-web forum. An unknown actor is advertising what they claim is an unauthenticated, zero-click initial-access exploit against Microsoft 365’s core routing/Exchange Online infrastructure — with claimed authentication bypass and HTTP response hijacking — starting at $1M in Monero. Claims are unverified, but the listing underscores the underground market for high-value enterprise exploits. Ido Cohen
  • ARToken PhaaS exposes the EvilTokens M365 toolkit. A new phishing-as-a-service platform operating as an EvilTokens affiliate gave researchers a look at an extensive Microsoft 365 kit; Cisco Talos details advanced evasion, post-exploitation, and device-code phishing using legitimate-looking SharePoint lures. BleepingComputer · The Register

AI & Model Security

  • Indirect prompt injection weaponized via SEO poisoning. Zscaler ThreatLabz found malicious sites using SEO poisoning to lure AI agents to attacker-controlled pages carrying hidden instructions; in testing, several popular LLMs could be tricked into making fraudulent payments. Zscaler ThreatLabz
  • Attackers probe LLMs for “hallucinated” domains to pre-register for phishing. In the Montana Empire incident, actors used adversarial hallucination probing — crafting prompts to learn which fake brand domains models most reliably generate — then registered the highest-value ones and stood up phishing kits within hours. blackorbird
  • Claude Fable 5 returns “nerfed.” Anthropic says Fable 5 will leave subscription plans after July 7 but return outside usage-based pricing; independent BridgeBench re-runs show sharp drops (debugging 86.2→25.9, refactoring 73.6→38.4) that testers attribute to new guardrails falling back to Opus 4.8. BleepingComputer
  • Claude Code caught in a two-sided China squeeze. Anthropic is trying to block Chinese firms like ByteDance and Ant Financial from Claude Code (they route around it via VPNs and overseas subsidiaries), while Alibaba banned its own staff from the tool after finding hidden code that could identify Chinese users. The Decoder

Threat Intelligence

  • Pegasus found on the phone of an EU lawmaker probing spyware. Citizen Lab reports former MEP Stelios Kouloglou was infected twice with Pegasus while serving on the European Parliament committee investigating commercial spyware abuse. Citizen Lab · The Record
  • NCSC-FI: North Korea stole ~$643M in crypto in H1 2026. Finland’s NCSC highlighted a TRM Labs report finding roughly two-thirds of all crypto stolen worldwide this year went to North Korea-linked groups, out of nearly $1B in total losses. NCSC-FI / Yle
  • Lazarus-linked npm campaign is still running. JFrog tied fresh packages (“rollup-packages-polyfill-core,” “rollup-runtime-polyfill-core”) impersonating Rollup polyfill tooling to North Korea; Nextron reports new JSONKeeper URLs and a new C2 (147.189.172.105) dropping and executing 0001.dat via node. The Hacker News · Nextron
  • ChocoPoC RAT targets exploit researchers via trojanized GitHub PoCs. The RAT isn’t in the exploit code — the repos pull malicious PyPI packages that fetch the payload, which can run commands and steal browser data, files, and shell history. BleepingComputer
  • Anubis ransomware adopts Citrix Bleed 2 for initial access. Affiliates are exploiting CVE-2025-5777 and leaning on legitimate RMM tooling and hands-on-keyboard tradecraft. CERT-EU separately advised on multiple NetScaler ADC/Gateway flaws. The Hacker News · CERT-EU 2026-003
  • FortiBleed credential theft tied to INC and Lynx ransomware. An operator linked to FortiBleed infrastructure was found working negotiation panels for both groups, connecting mass FortiGate credential theft directly to ransomware deployment. The Hacker News
  • PamStealer targets macOS with clever tradecraft. Jamf Threat Labs flagged a stealer distributed as a compiled AppleScript impersonating the open-source Maccy clipboard manager, using PAM checks to grab macOS login passwords. The Hacker News · Ars Technica
  • Armored Likho deploys BusySnake Stealer. Kaspersky attributed a global, Python-based obfuscated malware campaign — blending financially motivated and espionage activity — to government and power-sector targets in Russia, Brazil, and Kazakhstan. Securelist
  • APT28 covert-attack analysis. A write-up details APT28 activity leveraging Explorer hijacking, LSB steganography, and related techniques. blackorbird
  • Medtronic breach hits 3.8M people. The medtech firm is notifying patients that ShinyHunters accessed corporate IT systems in April and stole personal and medical data; the company says device safety was unaffected. SecurityWeek
  • Stormous ransomware says it’s shutting down. After 180+ published victims, the group posted a leak-site notice pledging to erase hosted data within 60 days — though prior “shutdowns” have preceded rebrands. Ido Cohen
  • Malaysia’s LHDN tax portal data offered for sale. A threat actor is advertising 10M+ alleged MyTax records — including TINs, filing history, and bank details — for $20,000; authenticity is unverified. Daily Dark Web

New Tools & Releases

  • PayloadsAllTheThings gets an official web front-end. The maintainer released a browsable web UI for the widely used offensive payloads-and-bypasses reference, making the collection easier to search during engagements. swisskyrepo

Industry & Policy

  • Google loses final appeal on €4.1B Android antitrust fine. The CJEU upheld the €4.125B penalty for abusing Android’s dominance to favor Google Search and Chrome. BleepingComputer
  • Yarbo robot mowers ship with a backdoor. Researchers found a built-in remote-access loophole with identical passwords across all devices, allowing full hijack of a mower. Kaspersky