DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:07:52ZSOURCES: 14CRITICAL: 34
⚠ ACTIVE ALERTS
@AlvieriD CRITICAL — CORRELATED | Actor '888' listing on PwnForums: claims 35GB of Accenture source code,… /// @DarkWebInformer CRITICAL — CORRELATED | Prinz Eugen ransomware operation — actor ROOTBOY (aka avtokz / GERMANIA)… /// @MalwareHunterTeam CRITICAL — CORRELATED | PolinRider (DPRK / Famous Chollima / Contagious Interview) supply chain… /// @GossiTheDog CRITICAL — CORRELATED | CVE-2026-8037 Progress Kemp LoadMaster pre-auth RCE — exploitation attempts… /// @FalconFeedsio CRITICAL — CORRELATED | Tracking '888' forum listing for Accenture data (July 6, 2026). Dataset:…
34Critical Threats
19Active CVEs
10IOCs Tracked
7New Advisories
20 ADVISORIES SHOWN
TLP:WHITEOPEN SOURCE ADVISORY
DOC: cisco-sa-ise-multi-G5WP8vv
CiscoCVE-2026-20181CVE-2026-201902026-06-17

Cisco ISE Remote Code Execution & Information Disclosure — Multiple CVEs (CVSS 9.1)

Multiple critical vulnerabilities in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) allow a remote attacker to achieve RCE or exfiltrate sensitive data including hashed credentials. CVE-2026-20181 (RCE, CVSS 9.1) requires authenticated access with admin privileges; CVE-2026-20190 (information disclosure) is exploitable by an unauthenticated attacker. In single-node ISE deployments, exploitation can trigger a denial-of-service, blocking endpoint network authentication. ISE is widely deployed as the backbone of enterprise network access control (NAC), making these flaws extremely high-impact. A July 15, 2026 follow-on advisory for ISE is also pre-announced.

AFFECTED:Cisco ISE all versions — fixed in ISE 3.3 Patch 11 and ISE 3.4 Patch 6; ISE 3.5 Patch 4 planned August 2026Cisco ISE Passive Identity Connector (ISE-PIC) all versionsFULL ADVISORY
TLP:WHITEOPEN SOURCE ADVISORY
DOC: CISA Alert 2026-07-10
CISACVE-2026-48939CVE-2026-562912026-07-10

CISA KEV July 10: iCagenda & Balbooa Forms Unrestricted File Upload — Actively Exploited Joomla Extensions

CISA added two Joomla extension vulnerabilities to its KEV catalog on July 10, 2026, based on confirmed active exploitation. Both CVE-2026-48939 (iCagenda) and CVE-2026-56291 (Balbooa Forms) are unrestricted file upload flaws that allow unauthenticated attackers to upload arbitrary PHP files and achieve remote code execution on Joomla-based websites. These follow a pattern of attackers mass-exploiting CMS plugin vulnerabilities to establish persistent web shells across shared hosting and enterprise Joomla deployments.

AFFECTED:Joomla iCagenda extension (affected versions — see vendor advisory)Joomla Balbooa Forms extension (affected versions — see vendor advisory)FULL ADVISORY
TLP:WHITEOPEN SOURCE ADVISORY
DOC: cisco-sa-voice-rce-mORhqY4b
Cisco PSIRT2026-07-01

Cisco Unified Communications Products Unauthenticated Remote Code Execution (Critical)

A Critical-rated unauthenticated RCE vulnerability in Cisco Unified CM, Unified CM SME, Unified CM IM&P, Unity Connection, and Webex Calling Dedicated Instance allows a remote unauthenticated attacker to execute arbitrary commands on the underlying OS and escalate to root by sending a sequence of crafted HTTP requests to the web-based management interface. Cisco explicitly escalated the Security Impact Rating to Critical beyond the base CVSS score given the unauthenticated attack surface and the widespread enterprise deployment of these platforms.

AFFECTED:Cisco Unified Communications Manager (Unified CM)Cisco Unified CM Session Management Edition (SME)Cisco Unified CM IM & Presence Service (IM&P)Cisco Unity ConnectionCisco Webex Calling Dedicated InstanceFULL ADVISORY
TLP:WHITEOPEN SOURCE ADVISORY
DOC: CISA KEV 2026-07-07 / APSB26-68
CISACVE-2026-482822026-07-07

CISA KEV: Adobe ColdFusion Path Traversal RCE (CVE-2026-48282) — Exploited Within Hours of Disclosure

Adobe ColdFusion contains a CVSS 10.0 path traversal vulnerability that leads to arbitrary code execution. CISA added it to the KEV catalog on July 7, 2026 after exploitation was observed within hours of public disclosure, with at least one attempt recorded from an IP geolocated to India. All internet-facing ColdFusion servers should be treated as a fire-drill-category patch priority.

AFFECTED:Adobe ColdFusion (all versions prior to July 2026 APSB26-68 patch)FULL ADVISORY
TLP:WHITEOPEN SOURCE ADVISORY
DOC: CVE-2026-50656
Microsoft MSRCCVE-2026-506562026-07-09

Windows Defender Privilege Escalation Zero-Day (RoguePlanet) — Emergency Out-of-Band Patch

A local privilege escalation flaw in the Microsoft Malware Protection Engine, nicknamed 'RoguePlanet', allows any local attacker on fully-patched Windows 10/11 to gain SYSTEM-level control via a race condition in the engine's file-handling logic. Working exploit code was publicly available for 29 days before Microsoft issued an emergency out-of-band engine update. No signature changes or disabling real-time protection mitigates exposure — only the engine update itself closes the vulnerability.

AFFECTED:Windows 10 (all supported versions)Windows 11 (all supported versions, including 24H2 and 25H2)Microsoft Malware Protection Engine prior to 1.1.26060.3008FULL ADVISORY
TLP:WHITEOPEN SOURCE ADVISORY
DOC: cisco-sa-cucm-ssrf-cXPnHcW
CiscoCVE-2026-202302026-06-25

Cisco Unified Communications Manager SSRF to Root – CVE-2026-20230 (Actively Exploited, CISA KEV)

A critical-rated (CVSS 8.6, vendor-escalated to Critical SIR) server-side request forgery vulnerability in Cisco Unified CM and Unified CM SME allows unauthenticated remote attackers to write arbitrary files to the underlying OS and escalate to root via the WebDialer component. Public PoC exploit code emerged within 24 hours of June 3 disclosure, active exploitation was confirmed by June 22–23 with attackers deploying multi-stage JSP web shells, and CISA added it to KEV on June 25 with a 3-day remediation deadline for federal agencies. The attack chain is fully automated, uses Tor for obfuscation, and targets enterprise telephony infrastructure across healthcare, government, and financial sectors.

AFFECTED:Cisco Unified Communications Manager (Unified CM) – versions prior to 14SU6 and 15SU5 with WebDialer enabledCisco Unified Communications Manager Session Management Edition (Unified CM SME) – same affected release trainsFULL ADVISORY
TLP:WHITEOPEN SOURCE ADVISORY
DOC: CISA Advisory Jun-18-2026 / NCSC Parallel Advisory
CISA2026-06-18

CISA / NCSC Joint Warning: FortiBleed – Large-Scale Credential Harvesting Against 86,644 Fortinet Firewalls

CISA and the UK NCSC issued joint advisories on June 18, 2026, warning of FortiBleed — an active, large-scale credential-harvesting campaign targeting internet-exposed Fortinet firewalls that has aggregated working administrator and VPN credentials for approximately 86,644 FortiGate devices across 194 countries since at least February 2026. The campaign leverages reused credentials from prior Fortinet exploitation events (FG-IR-26-060, FG-IR-25-647), brute-force attacks against devices lacking MFA, and offline cracking of legacy SHA-256 password hashes extracted from configuration files. Huntress identified 845 of its partner organizations in the exposed credential set, underscoring severe SMB and MSSP supply-chain risk. No new Fortinet vulnerability is involved — the threat is post-exploitation credential reuse at scale.

AFFECTED:All internet-facing FortiGate firewalls with credentials derived from any prior Fortinet exploitation event (FG-IR-26-060, FG-IR-25-647, SSL VPN mass-exploitation 2024)Organizations that have not rotated credentials after previous Fortinet incidentsFortiGate devices without MFA enforced on administrative and VPN accessFULL ADVISORY
TLP:WHITEOPEN SOURCE ADVISORY
DOC: CISA KEV 2026-07-07 / GHSA-qrpv-q767-xqq2
CISACVE-2026-552552026-07-07

CISA KEV: Langflow Authorization Bypass / IDOR — AI Platform Credential Theft (CVE-2026-55255)

Langflow, an AI agent orchestration platform, contains a cross-tenant IDOR (insecure direct object reference) vulnerability allowing an authenticated attacker to execute any flow belonging to another user and exfiltrate LLM provider API keys and AWS credentials. This is the first AI agent platform to appear in the CISA KEV catalog, reflecting the growing attacker focus on AI infrastructure as a high-value credential store. CISA's KEVIntel partners scored this CVSS 9.9 due to the cross-tenant scope change.

AFFECTED:Langflow all versions prior to 1.9.2FULL ADVISORY
TLP:WHITEOPEN SOURCE ADVISORY
DOC: CISA KEV 2026-07-07
CISACVE-2026-489082026-07-07

CISA KEV: JoomShaper SP Page Builder Unauthenticated File Upload RCE (CVE-2026-48908)

JoomShaper SP Page Builder contains a CVSS 10.0 unrestricted file upload vulnerability allowing unauthenticated users to upload and execute arbitrary PHP code. It was exploited as a zero-day via HTTP POST to the 'index.php?option=com_sppagebuilder&task=asset.uploadCustomIcon' endpoint, resulting in new rogue Super User accounts being created on victim Joomla sites. The threat activity is assessed as opportunistic and financially motivated.

AFFECTED:JoomShaper SP Page Builder all versions prior to 6.6.2FULL ADVISORY
TLP:WHITEOPEN SOURCE ADVISORY
DOC: cisco-sa-clamav-88cFYyxR
Cisco PSIRTCVE-2026-20216CVE-2026-20213CVE-2026-20214CVE-2026-20215CVE-2026-20217CVE-2026-20243CVE-2026-202442026-07-01

Cisco ClamAV Multiple DoS Vulnerabilities Affecting Secure Endpoint Connector for Windows (CVE-2026-20216 et al.)

Cisco disclosed seven ClamAV vulnerabilities affecting its Secure Endpoint Connector products (CVSS 7.5, High). Six are memory corruption bugs in file format parsers (PE, FSG, 7z, PESpin, ALZ, DMG) caused by improper boundary checks that trigger out-of-bounds buffer writes when processing crafted files. A seventh flaw affects the InstallShield parser via improper handling of temporary resources. On Windows, which runs the ClamAV scanning process in a privileged context, exploitation could freeze the host until reboot; the Security Impact Rating is elevated to High on Windows-based platforms specifically.

AFFECTED:Cisco Secure Endpoint Connector for Windows (all versions prior to fixed release)Cisco Secure Endpoint Connector for Linux (Medium severity)Cisco Secure Endpoint Connector for macOS (Medium severity)FULL ADVISORY
TLP:WHITEOPEN SOURCE ADVISORY
DOC: CISA-KEV-2026-07-01 / CVE-2026-45659
CISACVE-2026-456592026-07-01

CISA KEV: Microsoft SharePoint Server CVE-2026-45659 RCE via Deserialization — Storm-2603 / Warlock Ransomware Active Exploitation

Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability (CVSS 8.8) that allows any authenticated attacker with Site Member permissions or higher to execute code remotely over the network. CISA added it to KEV on July 1, 2026 with a federal deadline of July 4. Microsoft Incident Response attributed active exploitation to Storm-2603, a threat actor deploying Warlock ransomware against on-premises SharePoint, with a second unrelated threat actor co-existing in the same victim environments using DLL side-loading and custom backdoors.

AFFECTED:Microsoft SharePoint Server Subscription EditionMicrosoft SharePoint Server 2019Microsoft SharePoint Enterprise Server 2016FULL ADVISORY
TLP:WHITEOPEN SOURCE ADVISORY
DOC: FG-IR-25-1052 / CVE-2026-22153
Fortinet PSIRTCVE-2026-221532026-07-04

FortiOS LDAP Authentication Bypass in Agentless VPN & FSSO (FG-IR-25-1052)

A High-severity authentication bypass (CWE-305, CVSS 8.1) in FortiOS versions 7.6.0–7.6.4 allows an unauthenticated network attacker to completely bypass LDAP authentication for Agentless VPN or FSSO policies when the upstream LDAP server permits unauthenticated/anonymous binds — a configuration present in many Active Directory environments. Exploitation requires no credentials or user interaction. Fortinet updated this advisory on July 4, 2026, and the vulnerability is particularly critical in the context of the ongoing 'FortiBleed' ransomware campaign targeting Fortinet perimeter devices.

AFFECTED:FortiOS 7.6.0FortiOS 7.6.1FortiOS 7.6.2FortiOS 7.6.3FortiOS 7.6.4FULL ADVISORY
TLP:WHITEOPEN SOURCE ADVISORY
DOC: cisco-sa-catc-file-read-wLH2vf8X / CSCwt73509
Cisco PSIRTCVE-2026-201912026-07-01

Cisco Catalyst Center Arbitrary File Read — CVE-2026-20191 (CVSS 7.5 High)

A path traversal vulnerability (CWE-22, CVSS 7.5) in Cisco Catalyst Center (formerly DNA Center) allows unauthenticated remote attackers to read arbitrary files from a restricted container environment via crafted HTTP requests. Sensitive files including network device configurations, credentials, and system data may be exposed, enabling lateral movement and further compromise of managed enterprise networks. No workaround is available; patching is the only remediation.

AFFECTED:Cisco Catalyst Center (hardware appliances and virtual deployments) — all versions prior to patched release; see cisco-sa-catc-file-read-wLH2vf8X for specific fixed versionsFULL ADVISORY
TLP:WHITEOPEN SOURCE ADVISORY
DOC: cisco-sa-clamav-88cFYyxR
Cisco PSIRT2026-07-01

ClamAV DoS Vulnerabilities Affecting Cisco Secure Endpoint Connector for Windows — High Severity

Multiple vulnerabilities in ClamAV affect Cisco Secure Endpoint Connector for Windows at High severity because Windows deployments run the ClamAV scanning process in a privileged security context. Remote attackers can trigger denial-of-service conditions that interrupt AV scanning operations entirely. No workarounds exist; software updates are required. Linux and macOS connectors are rated Medium due to lower-privilege process context.

AFFECTED:Cisco Secure Endpoint Connector for Windows (High severity)Cisco Secure Endpoint Connector for Linux (Medium severity)Cisco Secure Endpoint Connector for Mac (Medium severity)FULL ADVISORY
TLP:WHITEOPEN SOURCE ADVISORY
DOC: CVE-2026-48558
CERT/Multi-VendorCVE-2026-485582026-06-30

SimpleHelp RMM Critical OIDC Authentication Bypass — Djinn Stealer Malware Delivery Confirmed (KEV)

A CVSS 10.0 authentication bypass in SimpleHelp RMM (versions ≤5.5.15 and all 6.0 pre-release builds) allows unauthenticated remote attackers to forge OIDC JWT tokens and create fully privileged Technician accounts, bypassing MFA entirely. Attackers have actively exploited this flaw to deploy the novel Djinn Stealer malware (cross-platform; targets cloud credentials, SSH keys, AI API tokens, cryptocurrency wallets, and browser secrets) and the TaskWeaver backdoor. With ~14,000 internet-facing SimpleHelp servers and ~7.2% configured for OIDC, MSPs and their downstream clients face severe supply-chain risk.

AFFECTED:SimpleHelp RMM 5.5.15 and earlierSimpleHelp RMM 6.0 all pre-release buildsFULL ADVISORY
TLP:WHITEOPEN SOURCE ADVISORY
DOC: CVE-2026-45659 / CISA KEV 2026-07-01
MicrosoftCVE-2026-456592026-07-01

Microsoft SharePoint Server Deserialization RCE Actively Exploited — CISA KEV (CVE-2026-45659)

Microsoft SharePoint Server (on-premises) contains a deserialization of untrusted data vulnerability (CVSS 8.8) allowing an authenticated attacker with only Site Member-level permissions to execute arbitrary code over the network. CISA added it to the KEV on July 1, 2026 — reversing Microsoft's own 'Exploitation Less Likely' rating — and mandated federal remediation by July 4. The Storm-2603 threat actor, known for deploying Warlock ransomware, has been linked to exploitation of on-premises SharePoint systems.

AFFECTED:Microsoft SharePoint Server Subscription EditionMicrosoft SharePoint Server 2019Microsoft SharePoint Enterprise Server 2016FULL ADVISORY
TLP:WHITEOPEN SOURCE ADVISORY
DOC: CISA Alert 2026-06-18 (Updated 2026-06-22) / FortiGuard FortiBleed
Fortinet PSIRT / CISA2026-07-06

FortiBleed: Mass Credential Compromise of ~86,000+ FortiGate Firewalls Across 194 Countries — CISA Alert Issued

A large-scale, fully automated campaign dubbed 'FortiBleed' has been systematically extracting configuration files from internet-facing FortiGate devices and cracking stored credential hashes, yielding a verified database of over 86,644 working administrator credentials across government and private-sector organizations in 194 countries. Attackers use compromised devices as credential-harvesting listening posts to feed back into the scanner, compounding the breach. CISA issued an urgent alert on June 18 (updated June 22) urging immediate credential resets and hardening. The campaign has been running since at least February 2026 and targets sectors including banking, telecom, hospitals, universities, and government agencies.

AFFECTED:Fortinet FortiGate Firewalls (internet-facing, all versions with weak password hashing)FortiOS SSL VPN GatewaysFULL ADVISORY
TLP:WHITEOPEN SOURCE ADVISORY
DOC: CVE-2026-46817 / Oracle May 2026 CPU
CISA KEV / OracleCVE-2026-468172026-07-06

Oracle E-Business Suite Payments Unauthenticated Takeover Actively Exploited — No Public PoC Required (CVE-2026-46817)

CVE-2026-46817 (CVSS 9.8) is a critical, easily exploitable, unauthenticated HTTP vulnerability in Oracle Payments' File Transmission component that allows full takeover of Oracle EBS Payments installations. Active exploitation was confirmed on June 27, 2026 against honeypots by Defused, notable because no public proof-of-concept existed at time of first exploitation — suggesting the actor developed the exploit via patch diffing. Approximately 950 internet-facing EBS instances remain exposed globally according to Shadowserver/Validin scans, with the Nissan payroll data breach and DriveSurge initial-access-broker campaigns among confirmed downstream impacts. Cl0p ransomware previously targeted an identical sister vulnerability in the same product line.

AFFECTED:Oracle E-Business Suite versions 12.2.3 through 12.2.15 (Oracle Payments File Transmission component)FULL ADVISORY
TLP:WHITEOPEN SOURCE ADVISORY
DOC: Genians Security Center Advisory (2026-06) / Five Eyes AI Cybersecurity Joint Advisory (June 2026)
CERT/Threat Intel2026-06-30

APT37 (ScarCruft / North Korea) Deploys NarwhalRAT via Fake Microsoft Account Security Alert Phishing

APT37 (ScarCruft/InkySquid), a North Korean state-sponsored cyber-espionage group, compiled and deployed NarwhalRAT — a sophisticated Python-based remote access trojan with 30+ command prefixes — in a targeted spear-phishing campaign beginning June 2026. The lure email convincingly impersonates an official Microsoft Account security alert warning of abnormal OTP activity, delivering a ZIP attachment containing a malicious LNK file that stages NarwhalRAT via a LNK→cmd.exe→BAT→PowerShell execution chain. Capabilities include keylogging, screen capture, microphone recording, USB data exfiltration, and in-memory PE execution, with data exfiltrated via the pCloud API — marking a documented departure from APT37's signature RokRAT tooling.

AFFECTED:Microsoft 365 / Microsoft Account users (any enterprise or government)South Korean government, academic, media, and military organizations (primary targets)Windows endpoints running Python runtime (python.org signed binary used as loader)FULL ADVISORY
TLP:WHITEOPEN SOURCE ADVISORY
DOC: CVE-2026-20262 / cisco-sa-sdwan-arbfw-c2rZvQ / CISA KEV (Added 2026-06-15, Due 2026-06-29)
CiscoCVE-2026-20262CVE-2026-20245CVE-2026-201822026-06-30

Cisco Catalyst SD-WAN Manager Arbitrary File Write (8th SD-WAN KEV of 2026) — Targeted Exploitation Confirmed

CVE-2026-20262 is an arbitrary file write vulnerability (path traversal, CWE-22) in the web UI of Cisco Catalyst SD-WAN Manager (formerly vManage) allowing an authenticated remote attacker with low-privileged write-access credentials to create or overwrite any file on the filesystem via a crafted HTTP API request, enabling subsequent privilege escalation to root. Cisco confirmed limited in-the-wild exploitation in June 2026 consistent with a sophisticated, targeted operation; CISA added it to KEV on June 15. This is the 8th Cisco SD-WAN product flaw confirmed exploited in 2026, with APT actor UAT-8616 linked to the broader SD-WAN campaign series.

AFFECTED:Cisco Catalyst SD-WAN Manager (all deployment types: on-prem ESXi/KVM/Hyper-V/bare metal, Cloud-Pro, Cisco Managed Cloud, FedRAMP) — affected release trains 20.6.x, 20.9.x, 20.12.x and earlier unfixed branchesFULL ADVISORY