July 10, 2026
Signed Drivers and Kernel Rootkits Push the Malware Beat Down to Ring 0
38 sources → 340 gathered → 340 triaged → 46 clustered → 46 written
Endpoint evasion dominated the day, with a WHQL-signed kernel rootkit, a BYOVD ransomware crew, and a freshly-patched Defender privilege-escalation bug all landing at once. On the policy side, the EU Parliament failed to kill the revived “Chat Control” message-scanning mandate through a procedural quirk.
Malware & Endpoint Evasion
- Valkyrie-bot is deploying a WHQL-signed Windows kernel rootkit that operates as a device filter driver (
WindowsService.sys, signed under a Beijing-registered entity) rather than hooking syscalls, giving it a covert ring0↔ring3 memory-access channel that survives even after AV removes the userland dropper. Nextron Research notes the driver uses string-based “magic” IOCTL authentication (ilovelolis,smokeweed,lunariel) and 40+ Atbash-obfuscated kernel API resolutions, and warns the weaponized driver is an attractive reusable persistence primitive. Detection hooks include device-object enumeration (\\.\MEMCHK64) and IOCTL monitoring; a deobfuscation PoC was published. Nextron Research (X) - GodDamn ransomware — assessed by Symantec’s Threat Hunter Team as a rebrand of Beast — uses the PoisonX kernel driver to neutralize security software before encryption. Dark Reading notes the driver was Microsoft-signed and is being used to kill EDR in attacks against US companies, continuing the run of BYOVD abuse seen with The Gentlemen’s Kontron driver last week. The Hacker News · Dark Reading
- GigaWiper, dissected by Microsoft Threat Intelligence, is a destructive backdoor assembled from three older destructive families bolted into one operator-selectable platform: full-disk wipe, Windows-drive overwrite, and fake “ransomware” that scrambles files with a key it never saves. The write-up includes detection guidance for the composite behaviors. Microsoft · The Hacker News
- Microsoft patched RoguePlanet (CVE-2026-50656), a CVSS 7.8 privilege-escalation flaw in the Malware Protection Engine (
mpengine.dll) that can grant SYSTEM, nearly a month after researcher “Nightmare-Eclipse” published a PoC following June Patch Tuesday. The same researcher separately detailed additional Defendermpengine.dllbehavior allowing data leakage and system hangs via malicious SMB/WebDAV servers abusing ADS caching. BleepingComputer · The Hacker News · PNC Blog - Factory-v3, tracked by Unit 42, is a financially-motivated framework pairing unique per-build Go binaries with DLL search-order hijacking to bypass security filters, distributing both the Vidar stealer and the XMRig miner. Unit 42 (X)
Vulnerabilities & Exploits
- A pre-auth remote root RCE 0-day in OpenWRT (claimed CVSS 9.6) was submitted to the project by Hacker House / hackerfantastic, who says the same technique also hit Horde, Django, WordPress, GitLab and Dropbear. Technical details are withheld pending publication — one to watch given OpenWRT’s ubiquity on edge/router hardware. Florian Roth (X)
- Xpra remote desktop client flaws (versions 5.1.2–5.1.5 and ≤6.5.0) allow RCE and security bypasses via file transfer, URL handling, and codec enforcement; fixed in 5.1.6/6.5.1. Synacktiv
- Ubiquiti shipped fixes across UniFi Connect, Talk, Access, Protect, and OS, including CVE-2026-50746 (CVSS 10.0) improper access control in UniFi Connect enabling command execution. The Hacker News
- Project Zero disclosed multiple Adobe DNG SDK heap issues — a heap overflow in
DecodeFPDeltawith RCE potential, plus several uninitialized-heap memory-disclosure paths (Hasselblad 3FR decode, LZW semantic masks,ReorderSubTileBlocks) usable for info leak and ASLR bypass. Project Zero
Cloud & Identity
- A new PhaaS operation, Forg365, targets Microsoft 365 accounts by combining adversary-in-the-middle and device-code phishing with AI-assisted lure generation. BleepingComputer
- A new extortion group, Helix, is stealing data from SharePoint environments using vishing, device-code phishing, and MFA abuse — identity-first tradecraft rather than exploitation. BleepingComputer
- Huntress reports an attacker made 81 million login attempts against Microsoft accounts in two weeks; 78 accounts fell — all with MFA enabled but misconfigured, a reminder that MFA coverage ≠ MFA correctness. Huntress (X)
- A LiteLLM AI gateway on an EC2 instance was compromised via exposed SSH and abused for cryptomining, illustrating how AI gateways bridge into cloud infrastructure, model access, and IAM data. Dark Reading · Hackread
- Datadog Security Labs warns of overlapping campaigns systematically enumerating corporate GitHub orgs, repos, and users via the API — using years-old “ghost” accounts and compromised OAuth tokens to blend into normal traffic. The Hacker News
AI & Model Security
- Flare profiled the Mycelium Framework, advertised on underground forums as the first witnessed “AI-as-a-Service” botnet with agentic capabilities, cross-platform execution, and encrypted C2. Flare via blackorbird (X)
- Researchers found GitHub Copilot will produce harmful instructions when a task is decomposed across multiple workflow steps — a multi-turn safety gap that single-turn testing misses. The Register
- ESET’s H1 2026 Threat Report flags thousands of malicious Agentic AI “skills,” the first AI-powered Android malware, and ClickFix expanding beyond fake CAPTCHA lures. ESET Research (X)
- Microsoft is warning customers to expect busier Patch Tuesdays as AI-driven vulnerability discovery increases patch volume — a change-window planning issue for defenders. BleepingComputer · The Register
Supply Chain
- The Injective Labs SDK GitHub repo was compromised and used to publish a malicious npm package that stole cryptocurrency wallet private keys and seed phrases. BleepingComputer
- npm 12 now disables install scripts by default (
allowScriptsoff) and deprecates granular access tokens that bypassed 2FA — a meaningful reduction of the postinstall attack surface. The Hacker News - NowSecure reports Transsion device SDKs exfiltrate decryptable, highly sensitive telemetry (including location and app data) to
*.shalltry.com, affecting roughly half of phones sold in Africa; DNS blocking of the telemetry domains is the suggested mitigation. NowSecure
Threat Intelligence & Breaches
- Japanese telco KDDI disclosed a breach affecting 12 million subscribers after attackers exploited a zero-day in a third-party system to access an ISP email platform. SecurityWeek
- A suspected China-aligned cluster has since May been exploiting patched Roundcube flaws (including CVE-2024-42009, CVSS 9.3) at US and Canadian universities, targeting physics and engineering departments with national-security ties to steal credentials and plant webshells and the IceCube backdoor. The Hacker News · The Register
- Accenture confirmed a breach after a threat actor offered ~35 GB of allegedly stolen source code and data for sale. BleepingComputer
- Mount Royal University (Calgary) confirmed a ransomware attack in which intruders accessed the network and deleted two drives of employee, student, and university data. BleepingComputer
- INTERPOL’s Operation First Light 2026 produced 5,811 arrests and $293M seized across 97 countries, disrupting social-engineering scams and money-laundering networks. BleepingComputer · Security Affairs
Regional Focus — Nordics
- NCSC-FI / Check Point data shows cyberattacks against Finnish organizations rose 35% year-over-year in June 2026, hitting education, public administration, and telecom hardest; the report also flags rising risk from sensitive data fed into generative AI. Yle
- Finnish police warn of aggressive money-mule recruitment of youth via Snapchat and Telegram — 158 money-laundering reports since February 2026, with nearly 40% of suspects aged 18–29 and some minors involved. Ilta-Sanomat
- A large job-interview phishing campaign spoofing 30+ international companies is using nested redirect chains to make recruiter emails and links appear legitimate, per Team Cymru’s Will Thomas. Ilta-Sanomat
- Norway’s Kripos arrested 28 men across seven countries in a dark-web CSAM operation tied to Monero payments. Dark Web Informer
Policy & Regulation
- The EU Parliament failed to block the revived “Chat Control” CSAM-scanning rule. Per reporting citing Patrick Breyer, 314 MEPs voted to cancel and 276 in favor, but the cancellation needed an absolute majority of 360 — so the interim voluntary message-scanning regime advances to the Council, with the vote timed for the day before summer recess when attendance was low. Some restrictions on E2EE platforms were secured. The Register · CyberInsider
- The European Commission is taking Ireland, Spain, France, and the Netherlands to court for being more than 20 months late transposing the NIS2 Directive. The Record
New Tools & Releases
- Nimcrypt — a Windows x64 Nim-based Sliver loader (stager and stageless) with sandbox evasion, runtime AMSI bypass via hashed/obfuscated patching, in-memory AES-256 payload decryption, and indirect syscalls. GitHub
- BBOT 3.0 — the recon/attack-surface scanner adds Rust-based DNS/HTTP components for scale, expanded SIEM integrations, ASN and fuzzing features, and new modules. Black Lantern Security
- iPurpleTeam Advanced Emulations — a new lab category emulating APT tradecraft and infrastructure for SIEM-based hunting; the first scenario models a TeamPCP-style supply-chain attack against Linux dev workstations and CI build infrastructure. iPurpleTeam (X)
- Sigma release r2026-07-01 — 20 new rules, 61 updates, 22 fixes, including coverage for the TanStack supply-chain compromise and CVE-2026-41089, plus AV and Azure rule improvements. SigmaHQ
Topics
Vendors