September 16, 2026
- VectraRAT packages a Windows implant, C2 and operator panel from $250 per month. SOCRadar describes a from-scratch MaaS platform with hidden-desktop control, keylogging, clipboard hijacking, browser credential theft and promptless UAC bypass. Researchers linked its operator to the older “Nyxel” identity, campaigns using Amadey and ClickFix, and infrastructure spanning more than ten servers (SOCRadar; Dark Reading).
· Threat Activity & Malware
in CVE-2026-76461 Gives Remote Attackers Root on Cisco Email Gateways
August 26, 2026
Oracle HTTP Server and WebLogic Server Proxy Plug-in contain CVE-2026-21962, a CVSS 10.0 pre-authentication remote code execution flaw now in CISA's KEV catalog with confirmed active exploitation, despite a 1,449-patch bundle failing to address it. Zimbra Collaboration Suite has exceeded 270 compromised servers via an ongoing RCE campaign tied to CVE-2026-73570. Claude-AD and NuGuard release new frameworks for Active Directory testing and agentic AI red-teaming respectively. An exposed Ollama API in NVIDIA's NemoClaw/OpenClaw stack creates a model-poisoning attack path through unauthenticated local service access.
July 16, 2026
SpecterOps documented a new NTLM-relay egress technique enabling Active Directory privilege escalation by coercing outbound authentication through cloud relays over WebDAV, bypassing SMB egress restrictions. Bitdefender revealed that Windows bind links can create filesystem view conflicts that hide malware from EDR detection by redirecting trusted paths to attacker-controlled content. Two SonicWall SMA1000 zero-days (CVE-2026-15409 and CVE-2026-15410) are under active exploitation in the wild, with CISA adding them to the Known Exploited Vulnerabilities catalog. Four to five compromised npm packages (@asyncapi suite) delivered a multi-stage botnet loader with info-stealing and RAT capabilities via GitHub Actions and IPFS, affecting versions including generator@3.3.1 and specs@6.11.2.
June 25, 2026
- Operation Endgame dismantled the shared infrastructure behind the Amadey and StealC infostealers, with Microsoft's DCU, Europol, Bitdefender, Bitsight, and ESET taking down 300+ servers and 200+ domains, recovering ~27M stolen credentials, and seizing over $47M; Microsoft also leaned on AI to link the operations in a racketeering suit. Microsoft, The Record, The Register
· Threat Intelligence
in Cisco SD-WAN Manager Zero-Day Gives Root via a Malicious CSV as Operation Endgame Smashes Amadey and StealC