daily cyber × ai intelligence

index

July 11, 2026

Progress Orders ShareFile Storage Controllers Offline Over Active Zero-Day Threat

33 sources 307 gathered 307 triaged 44 clustered 44 written

Progress is telling ShareFile customers to physically shut down on-prem Storage Zone Controllers over a “credible” threat that watchTowr and others attribute to active zero-day exploitation. Elsewhere, a Gitea Docker auth bypass is being exploited in the wild, and Okta is warning of vishing crews enrolling rogue Entra ID passkeys to hijack Microsoft 365 accounts.

Vulnerabilities & Exploits

  • Progress Software emailed ShareFile customers urging them to immediately power down Windows servers running Storage Zone Controllers after identifying a “credible external security threat,” and has temporarily disabled affected accounts. watchTowr says it is tracking rumors of active zero-day exploitation against exposed on-prem controllers and has notified clients with internet-facing instances. Treat any exposed Storage Zone Controller as potentially compromised. The Hacker News, BleepingComputer
  • Gitea Docker image is under active exploitation via a critical authentication bypass that lets attackers impersonate any user, including administrators, on self-hosted Git instances. A prime foothold for CI/CD and source-code supply-chain compromise. BleepingComputer
  • CVE-2026-47291 in Windows HTTP.sys allows kernel code execution or DoS through a 16-bit overflow in header parsing during TLS — triggerable with crafted HTTP/1.x requests carrying many headers over HTTPS. ZDI published the technical writeup. Zero Day Initiative
  • “Copy Fail” (CVE-2026-31431), a Linux kernel local privilege escalation affecting every mainstream distro built since 2017, has a public PoC and — per CERT-EU — no fixed vendor kernels shipped yet, making the interim mitigation urgent. CERT-EU
  • U-Boot bootloader has six new Binarly-discovered flaws; four cause crashes and two allow code execution before the OS boots, opening the door to persistent, stealthy firmware implants across routers, cameras, and server management chips. BleepingComputer, The Hacker News
  • Dell BIOS passwords stored in SPI flash use weak XOR encryption (CVE-2026-40639), allowing rapid offline recovery and full BIOS control once flash is dumped — a physical-access/evil-maid primitive. MDSec
  • XRING in Alibaba’s XQUIC (HTTP/3) library lets any unauthenticated remote client crash a server with ~260 bytes of legal QPACK traffic. No patch is available; disclosed by FoxIO’s Sébastien Féry. The Hacker News
  • Zimbra urged customers to patch a critical XSS flaw in the Classic Web Client of Zimbra Collaboration. BleepingComputer
  • Kiro IDE stored plaintext auth tokens with world-readable 0644 permissions, risking impersonation and API abuse; fixed in 0.11.133 (disclosed via AWS’s HackerOne program). HackerOne

Cloud & Identity

  • Okta is warning of vishing attacks (tracked as O-UNC-066) that call Microsoft 365 users and walk them through enrolling a fresh Entra ID passkey via a panel-controlled phishing kit mirroring the Entra login flow — establishing durable, phish-resistant-looking access for data extortion. The Hacker News, SecurityWeek
  • A single scanning operation hid behind one JA4 TLS fingerprint spread across 11,107 IPs on 147 networks, making 1.8M+ requests guessing database dump filenames — a reminder that TLS fingerprinting cuts through infrastructure rotation where IP blocking fails. HoneyLabs

Threat Activity & Malware

  • GigaWiper, flagged by Microsoft, is a modular Golang Windows backdoor bundling a standalone wiper, ransomware encryption, multi-pass wiping, and persistence, with C2 over RabbitMQ and Redis — an evolution of several prior malware families. The Register, SecurityWeek
  • MODBEACON, a new Rust-based RAT attributed by QiAnXin to China-linked Silver Fox, uses gRPC streaming for encrypted C2 and spreads via SEO-poisoned counterfeit installers. The Hacker News
  • Operation “Muck and Load” — tracked by Socket and highlighted by NCSC-FI — abuses malicious Go modules and multi-stage PowerShell loaders across 222 GitHub repositories, using commit-farming, public dead drops, and protected archives to stage RATs, infostealers, spyware, and cryptominers. Socket via NCSC-FI, SecurityWeek
  • Injective Labs’ SDK GitHub repo was compromised to push a malicious @injectivelabs/sdk-ts@1.20.21 npm package carrying fake telemetry that exfiltrated crypto wallet private keys and seed phrases. The Hacker News
  • WP-SHELLSTORM was exposed after the crew left a C2 server open for three weeks, revealing tooling, activity logs, and a target list of 1.4M+ WordPress sites (far fewer actually breached). The Hacker News
  • A fake 7-Zip site (7zip[.]com) is serving trojanized installers that drop persistent proxyware, turning home PCs into proxy nodes as part of a larger proxyware operation. Infoblox via blackorbird
  • Raton RAT, a 2.5 MB .NET commodity trojan, packs surveillance, credential theft, financial extraction, sabotage, anti-analysis, and ransomware-like features into one binary. Decoda Labs
  • SCMBANKER targets Mexican banking, fintech, and crypto customers via ClickFix fake-CAPTCHA lures dropping a PowerShell toolkit (tracked by Elastic as REF6045). The Hacker News
  • SentinelOne found China- and India-linked actors independently — and in some cases through the exact same systems — spying on Pakistan’s Balochistan Police force between February 2024 and April 2026. The Record, SecurityWeek

Threat Intelligence

  • A former DigitalMint ransomware negotiator, Angelo Martino, was sentenced to 70 months for conspiring with BlackCat/AlphV to extort victims — the third US security professional jailed for aiding the gang. Separately, a 34-year-old Armenian man pleaded guilty in Oregon to deploying Ryuk. The Record, BleepingComputer
  • DeadLock ransomware posted 11 new victims in a single burst, including Finland’s Enedo Power and Sweden’s Carrier Transport AB, signaling a high operational tempo worth monitoring. FalconFeeds
  • Qilin continues to lead the 2026 ransomware landscape by volume (708 tracked attacks), ahead of The Gentlemen, Akira, INC, and DragonForce. DarkFeed via Ido Cohen
  • Miinto Copenhagen disclosed a breach exposing order information, personal details, and payment methods, warning customers of follow-on phishing. The Register
  • Dutch National Police found strong indications that local Dutch criminals were involved in the February Odido telecom breach affecting 6.2 million customers. BleepingComputer, The Record

New Tools & Releases

  • Lucky-Arc — a stealthy reverse shell and C2 server using a Windows pseudoconsole for usability and encrypted WebSockets for covert comms. GitHub
  • klist2ccache — dumps Kerberos TGTs remotely and converts Windows klist output to ccache format (with variants klistremote/klistwinrm); notably detects Credential Guard and blocks offline session-key extraction on guarded hosts. GitHub
  • ltm — a Linux machine-history debugger recording process, file, network, memory, and block-I/O metadata via eBPF into SQLite for timeline queries; useful for hunting and DFIR (x86_64/IPv4 for now). GitHub
  • screenscrub — offline, OCR-based tool that finds credentials in screenshots and irreversibly redacts them, handy for scrubbing report and demo material. GitHub
  • Sigma release r2026-07-01 ships 20 new rules, 61 updates, and 22 fixes, including coverage for the TanStack supply-chain incident, CVE-2026-41089, and “Copy Fail,” plus ARM Sysinternals variants and Azure logic fixes. SigmaHQ via nasbench

Detection & Purple Team

  • A new iPurpleTeam writeup catalogs Windows Service abuse techniques for persistence alongside per-procedure detection strategies. ipurple.team
  • MagicSword ran a live session on why EDRs still fail to prevent “EDR killers” and how bypass techniques like EDR Choker operate in the wild. MagicSword

AI & Model Security

  • A systematic survey proposes LASM, a layered attack-surface framework classifying LLM-agent threats across seven components and four temporal horizons, with a defense taxonomy and reproducibility resources — a useful reference for anyone modeling agentic/tool-using system risk. arXiv
  • Anthropic unveiled the Jacobian lens, an interpretability technique offering its clearest look yet at internal model reasoning, revealing a hidden space where Claude works through concepts. MIT Technology Review

Policy & Regulation

  • Chat Control 2.0 passed the European Parliament, permitting platforms like Google, Meta, and Microsoft to scan user messages for CSAM. Critics note the rejection vote fell short only because it needed an absolute majority of all MEPs (360) rather than of those present — 314 voted against, 276 in favor — with the timing set for the final day before summer recess. The Record
  • The Linux Foundation launched Akrites, an industry initiative to coordinate vulnerability remediation and responsible disclosure for critical open-source software against AI-enabled threats. Linux Foundation
Models