July 7, 2026
A 16-Year-Old KVM Flaw Punches Through the Hypervisor Boundary
27 sources → 284 gathered → 284 triaged → 44 clustered → 44 written
A guest-to-host escape in Linux’s KVM hypervisor with a public PoC headlines a heavy exploitation day. Attackers are also hitting a max-severity ColdFusion RCE within hours of disclosure, and a fresh wave of AI-agent attacks — hijacked coding assistants, scanner-evading malicious “skills,” and leaky creator tools — shows agentic systems are now a live attack surface.
Vulnerabilities & Exploits
- “Januscape” (CVE-2026-53359) is a use-after-free in the shadow-MMU code shared across Intel and AMD in Linux’s KVM hypervisor, triggerable from a guest VM to corrupt host-kernel shadow-page state — a 16-year-old bug enabling guest-to-host escape. The public PoC panics the host; the researcher claims a separate, unreleased exploit goes further, per The Hacker News.
- Adobe ColdFusion CVE-2026-48282 (CVSS 10.0) is under active exploitation. The path-traversal-to-RCE flaw affects ColdFusion 2025 Update 9 and 2023 Update 20 and earlier; KEVIntel reported unauthenticated arbitrary file write/read attempts less than two hours after public details dropped, and Canada’s CCCS has warned defenders to patch exposed instances fast (BleepingComputer).
- Gitea Docker CVE-2026-20896 (CVSS 9.8) is being probed in the wild 13 days after disclosure. The flaw stems from Gitea trusting the
X-WEBAUTH-USERheader from any source IP, letting an unauthenticated internet client gain elevated access, per Sysdig (The Hacker News). - BeyondTrust Remote Support and PRA CVE-2026-40138 is a critical pre-authentication access-control bypass in the products’ authentication subsystem — a notable target given BeyondTrust’s role in privileged access (Dark Web Informer).
- Veeam Backup & Replication CVE-2026-44963 is an authenticated deserialization RCE letting low-privilege domain users execute code via a BinaryFormatter-based endpoint, thanks to insecure class filtering and broad authorization. Patches add gadget-class restrictions (SecureLayer7).
- Windows Installer CVE-2025-27727 (patched April 2025) lets a low-privilege attacker register arbitrary folders for SYSTEM-level deletion via the
TempPackagesCOM interface, escalating to SYSTEM — Exodus Intelligence published the technical writeup. - Opera GX contained a flaw letting a malicious website silently install a browser add-on and lift data from visited pages. In a PoC, researchers reconstructed a signed-in user’s full Gmail address with no click; Opera has patched (The Hacker News).
- TrojPix, from Shandong University researchers, exfiltrates data from air-gapped machines by tweaking on-screen pixels imperceptibly so the video cable radiates a decodable radio signal — though it requires malware already on the target (The Hacker News).
- Additional research-grade bugs: seven flaws in the FatFs filesystem library (memory corruption, DoS, some affecting OTA updates) disclosed by runZero with remediation complicated by absent upstream patches (Security Affairs); and CVE-2025-14179 / CVE-2025-14180 in PHP’s PDO drivers — NUL-byte SQL injection in
pdo_firebirdand a null-pointer crash inpdo_pgsql(PT Swarm).
New Tools & Releases
- MDSec teased a major Nighthawk C2 release, promising new OpSec “stacks” — including three CET-compatible masking techniques — and a new cross-platform UI (Dom Chell).
- ADIDNS RPC abuse via BOFs: a writeup details escalating to domain admin by manipulating DNS-server RPC calls, with custom exception handling, impersonation, and — usefully for the blue side — detection artifacts and network indicators (Paradoxis).
- XeraLdr, a modular Windows loader built to bypass modern EDR using module stomping, stack duplication, and advanced sleep obfuscation (GitHub).
- hzgl-air-bridge exfiltrates data from air-gapped systems over the Apple Find My network using custom ESP32-C3 beacon firmware plus web tooling to read reports without owning an Apple device (GitHub).
AI & Model Security
- Agentjacking: researchers show how outsiders can covertly drive a victim’s AI coding agent to exfiltrate secrets — manipulating the agent’s workflow rather than the machine itself, defeating trust models that assume the agent acts only for its user (talk).
- SkillCloak, from HKUST researchers, uses self-extracting packing to slip malicious add-on “skills” for AI coding agents past static scanners — the strongest variant evaded every tested scanner over 90% of the time. The team also built a runtime checker that catches most cases (The Hacker News).
- YouTube’s “Ask Studio” creator assistant can be manipulated via video comments to leak private data such as unpublished video titles — a prompt-injection/data-exfiltration gap in how the assistant handles untrusted input (RuntimeWire).
- Unit 42 notes LLMs consistently hallucinate fictitious domains for legitimate brands; attackers are registering these to intercept traffic from automated AI systems and developers, and one actor was seen building a phishing kit around such a domain (Unit 42).
Threat Activity
- Cavern (aka Cav3rn / Cavern Manticore), a previously undocumented modular C2 framework tied to Iran’s MOIS, is being used against Israeli IT providers and government entities. Check Point documents custom C2 protocols, anti-analysis features, and low detection rates (The Hacker News, Check Point).
- A ClickFix malware-as-a-service operation is using the Polygon blockchain as a resilient C2 config store — 130+ compromised sites and 15 rotating C2s, with periodic victim telemetry exfiltration and a stage-3 infostealer, per Unit 42 (Unit 42).
- EtherRAT is being pushed via fake IT-support calls on Microsoft Teams, where attackers impersonate corporate helpdesk staff to trick employees into installing the RAT for initial access (BleepingComputer).
- QuimaRAT, a new Java-based cross-platform RAT (Windows/Linux/macOS), is advertised as MaaS from $150/month to $1,200 for lifetime access, per LevelBlue (The Hacker News).
- Operation DragonReturn: a suspected China-nexus cluster is impersonating India’s Income Tax Department in spear-phishing to deploy DcRAT against taxpayers, tax professionals, and finance teams, per Seqrite Labs (The Hacker News).
- Two phishing campaigns worth watching: one impersonates 30+ big brands (Adobe, Netflix, OpenAI) in fake job interviews to steal Google credentials from marketing pros (BleepingComputer); another spoofs US state government and motor-vehicle agencies across 23 jurisdictions using .one/.shop/.cc/.help/.click lookalikes copying .gov content (Unit 42).
- Ukraine’s security service says Russian hackers have made Ukrainian TV and media outlets “priority targets,” detailing two previously unreported intrusions (The Record).
Law Enforcement & Government Ops
- Operation Riptide: Spain’s National Police, acting on FBI information, arrested an alleged collaborator of pro-Russia hacktivist groups Cyber Army of Russia Reborn (CARR) and Z-Pentest in Palencia, seizing crypto storage and blocking a wallet tied to proceeds. The arrest ties into the FBI’s ongoing Operation Red Circus (Hackread, FBI).
- Canada’s CSE disclosed it conducted three state-authorized offensive cyber operations in 2025 — disrupting a ransomware-as-a-service gang, a foreign extremist group, and drug traffickers, including disabling adversary infrastructure (The Record).
Data Breaches & Extortion
- A threat actor is advertising an alleged Accenture breach — ~35GB claimed, including source-code repos, RSA and SSH keys, Azure PATs, Azure Storage access keys, and config files, with a sample showing Azure DevOps repo data. Unverified, sold for XMR only; if real, a significant supply-chain risk (Dark Web Informer).
- SafePay ransomware added nine victims to its leak site, including Germany’s Frankfurt-Hahn Airport and multiple German construction, care, and industrial firms (Dark Web Informer).
- Other alleged/confirmed leaks: Darsa AI (90–100GB claimed, incl. AI model source code, credentials, and private keys, unverified); a claimed breach of 13+ Argentine social-security/health “obras sociales” attributed to Xyr0s and Cronus Team, unverified; and Moody Bible Institute, confirmed to affect 2.3M individuals with data leaked by ShinyHunters (The Register).
Policy & Advisories
- France’s ANSSI will stop certifying security products that lack quantum-resistant encryption from 2027, and expects businesses to buy only quantum-safe products by 2030 — effectively a de facto phase-out for French government and critical-infrastructure use (Schneier).
- CERT.dk reports a sharp surge in vulnerabilities during June, warning that the pace of the threat landscape is accelerating (CERT.dk).
Topics
Vendors
Threat actors
CVEs