DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:07:52ZSOURCES: 14CRITICAL: 34
⚠ ACTIVE ALERTS
@AlvieriD CRITICAL — CORRELATED | Actor '888' listing on PwnForums: claims 35GB of Accenture source code,… /// @DarkWebInformer CRITICAL — CORRELATED | Prinz Eugen ransomware operation — actor ROOTBOY (aka avtokz / GERMANIA)… /// @MalwareHunterTeam CRITICAL — CORRELATED | PolinRider (DPRK / Famous Chollima / Contagious Interview) supply chain… /// @GossiTheDog CRITICAL — CORRELATED | CVE-2026-8037 Progress Kemp LoadMaster pre-auth RCE — exploitation attempts… /// @FalconFeedsio CRITICAL — CORRELATED | Tracking '888' forum listing for Accenture data (July 6, 2026). Dataset:…
34Critical Threats
19Active CVEs
10IOCs Tracked
7New Advisories
100 RECORDS
// Search all intelligence records
SEARCHING ACROSS 100 RECORDS // INTEL FEED · CVE TRACKER · ADVISORIES · DARK WEB
// SEV
CRITICAL8
HIGH12
MEDIUM6
LOW2
INFO2
// CAT
CVE9
ADVISORY7
RANSOMWARE4
APT5
DARK WEB3
SUPPLY CHAIN2
ZERO-DAY2
// SRC
DMZ ORIGINAL15
CISA5
NVD4
VENDOR6
// DATE
LAST 7 DAYS12
LAST 30 DAYS16
LAST 90 DAYS22
20245
20233
// VENDOR
MICROSOFT7
CISCO4
FORTINET4
GOOGLE2
LINUX2
SHOWING 10 OF 100 RECORDS
SORT:
2026
HIGH#APT2026-07-12
Silver Fox (China-Linked) Deploys MODBEACON Rust RAT With gRPC-Encrypted C2, Targeting Asian Tech and State-Owned Enterprises
QiAnXin on July 10 attributed a previously undocumented Rust-based RAT, MODBEACON, to the China-linked Silver Fox cluster, which distributes it via SEO-poisoned counterfeit software installers across Asia. MODBEACON uses gRPC streaming over TLS for command-and-control, routing traffic through Amazon and Cloudflare CDN infrastructure to blend with legitimate application traffic and defeat signature-based network detection — raising the detection bar to protocol-aware inspection and behavioral baselining. QiAnXin characterizes Silver Fox as a multi-distributor operation that despite appearing low-sophistication masks a structurally complex organization, deploying Gh0st RAT and WinOS/ValleyRAT variants in parallel and acting as both a 'cybercriminal arms dealer' and traffic broker across technology, education, and state-owned enterprise targets.
silver-foxmodbeacongrpc-c2rust-ratchina-linked
READ →
HIGH#APT2026-07-12
GigaWiper Modular Backdoor Attributed to Iran-Nexus Actor — Combines Disk Wiper, Fake Ransomware, and VNC Spyware in Single Golang Framework
Microsoft Threat Intelligence published analysis on July 9 of GigaWiper, a Golang-based Windows backdoor active since October 2025 that merges three destructive malware families — the Crucio ransomware (encrypts with unrecoverable keys), a Go reimplementation of FlockWiper (multi-pass disk overwrite), and a standalone raw-disk wiper — into a single modular framework with 20 operator-selectable commands, including continuous screen recording, VNC-like remote control, and Windows event log wiping. Binary Defense independently tracked the same files as BLUERABBIT and, citing Google TAG, attributed the activity to a likely Iran-nexus group targeting Israeli organizations — consistent with a surge in Iranian wiper operations warned about by Israel's National Cyber Directorate in March 2026. The malware establishes persistence as a fake 'OneDrive Update' scheduled task and uses RabbitMQ/Redis for C2, making it structurally difficult to remediate without full offline forensics.
gigawiperbluerabbitiran-nexuswiper-malwarecrucio-ransomware
READ →
HIGH#SUPPLY-CHAIN2026-07-12
Injective Labs GitHub Repo Compromised — 18 npm Packages Backdoored to Exfiltrate DeFi Wallet Private Keys and Mnemonics
On July 8, attackers used a hijacked trusted maintainer account ('thomasRalee') to push malicious commits into Injective Labs' official GitHub repository, triggering the project's own OIDC trusted-publisher pipeline to auto-publish version 1.20.21 of @injectivelabs/sdk-ts and 17 dependent packages — all hooked to silently capture BIP-39 mnemonic seed phrases and private keys at wallet creation and exfiltrate them disguised as gRPC-Web telemetry to Injective's own public infrastructure endpoints. The window was under one hour before reversion, but the SDK sees 50,000 weekly downloads across a DeFi ecosystem where developers routinely handle production wallet credentials. Any developer or application that instantiated a wallet during the exposure window should treat all key material as compromised and migrate funds immediately.
injective-labsnpm-supply-chaingithub-account-compromisedefi-wallet-theftcrypto-key-exfiltration
READ →
CRITICAL#SUPPLY-CHAIN2026-07-12
jscrambler npm Package Trojanized Across Five Malicious Releases — Rust Infostealer Targets CI/CD Secrets, Cloud Keys, and Crypto Wallets
On July 11, the official jscrambler npm CLI (a commercial JavaScript obfuscation tool with ~15,800 weekly downloads) was compromised via a hijacked maintainer account or build pipeline, with the attacker publishing five malicious versions (8.14.0 through 8.20.0) over approximately three hours. Each release included a preinstall hook that silently dropped and executed a cross-platform Rust infostealer targeting AWS/Azure/GCP cloud credentials, cryptocurrency wallets (MetaMask, Phantom, Exodus), Bitwarden vault contents, and browser session data — all before a single line of project code ran. Socket flagged the initial release six minutes after publication; any CI/CD pipeline that ran npm install in that window should be treated as fully compromised and all reachable secrets rotated immediately.
jscramblernpm-supply-chainrust-infostealerci-cd-compromisecloud-credential-theft
READ →
CRITICAL#RANSOMWARE2026-07-12
GodDamn Ransomware (Hyadina) Deploys Microsoft-Signed Malicious Kernel Driver PoisonX to Blind EDR Before Encryption
Symantec's Threat Hunter Team disclosed on July 9 that the Hyadina RaaS group's newest locker, GodDamn — the third iteration after Monster (2022) and Beast (2024) — weaponizes PoisonX (g11.sys), a malicious kernel driver that obtained a legitimate Microsoft Windows Hardware Compatibility Publisher signature and is now capable of terminating EDR processes, stripping API hooks, and killing CrowdStrike Falcon via crafted IOCTL before encryption begins. Unlike standard BYOVD attacks that exploit flaws in legitimate drivers, PoisonX was purpose-built for offense and has no patch surface — Microsoft's Vulnerable Driver Blocklist is the only systemic control, but updates lag days to weeks behind discovery. The driver has also been incorporated into the GentleKiller toolkit distributed to affiliates of The Gentlemen RaaS, with PoisonX now implicated across 478+ victims in 70+ countries.
hyadinagoddamn-ransomwarebyovdpoisonxkernel-driver
READ →
CRITICAL#ZERO-DAY2026-07-12
Progress ShareFile Storage Zone Controllers Taken Offline — No Patch, No CVE, Credible Zero-Day Threat Active
Progress Software ordered all on-premises ShareFile Storage Zone Controller customers to immediately shut down their Windows servers on July 10, citing a 'credible external security threat' — with no patch, no CVE, and no technical disclosure issued. The directive to fully power off rather than patch strongly implies an unmitigated vulnerability, echoing the 2023 MOVEit and Citrix ShareFile CVE-2023-24489 mass-exploitation playbooks. Internet-facing Storage Zone Controllers — of which Shadowserver identified ~784 exposed instances at the time of April 2026 CVE disclosures — should be treated as potentially implanted until Progress provides clean indicators and a verified remediation path.
progress-sharefilestorage-zone-controllerzero-daymanaged-file-transferenterprise-file-sharing
READ →
CRITICAL#ZERO-DAY2026-07-11
CVE-2026-50656 (RoguePlanet): Microsoft Defender EoP Zero-Day Patched Out-of-Band After Public PoC and Prior-Exploitation Reports
Microsoft shipped an out-of-band patch on July 8 closing RoguePlanet (CVE-2026-50656, CVSS 7.8), a race condition in the Malware Protection Engine (mpengine.dll) that allows a standard local user to spawn a SYSTEM-privileged shell — the seventh Windows zero-day dropped by researcher Nightmare-Eclipse (aka Chaotic Eclipse) amid an ongoing bug-bounty dispute with Microsoft. The PoC works regardless of whether Defender real-time protection is enabled or disabled, and Qualys claims prior in-the-wild exploitation, though Microsoft's advisory and the CISA KEV catalog do not confirm it. Defenders should verify engine version 1.1.26060.3008 or later is deployed across all endpoints, as the flaw is disproportionately useful post-initial-access for privilege escalation through the very security tooling meant to detect attackers.
cve-2026-50656rogueplanetmicrosoft-defendernightmare-eclipselocal-privilege-escalation
READ →
HIGH#RANSOMWARE2026-07-11
Qilin Ransomware Surges in Victim Volume — Multiple July 10 Postings Across U.S., Europe, and Australia as Group Maintains Top-Tier Cadence
Qilin ransomware posted at least five new victims on July 10 alone — spanning a U.S. CPA firm, a wholesale distributor, a Belgian law firm, a French municipal government, and a Calgary energy-sector manufacturer (Chemco) — sustaining one of the highest victim-posting rates among active ransomware-as-a-service operators in mid-2026. This activity coincides with continued high-volume postings from INC Ransom (multiple U.S. municipal and healthcare targets in early July) and BrainCipher (Robroy Industries), indicating a competitive and active RaaS ecosystem with no slowdown entering H2 2026. Security teams supporting law firms, local government, and SMB-segment energy and manufacturing should treat Qilin as an active and opportunistic threat requiring current patch posture validation on internet-facing assets.
qilinransomwareinc-ransombraincypherraas
READ →
HIGH#DARK-WEB2026-07-11
AssuranceAmerica Discloses Breach of 6.99M Drivers' License Records — Largest Known U.S. DL Theft of 2026
Atlanta-based auto insurer AssuranceAmerica has formally notified 6,998,886 individuals after attackers compromised a single employee credential on March 16, 2026, and exfiltrated files containing names, contact details, insurance policy data, claims information, and driver's license numbers across its 14-state, 9,500-agent network. The forensic review was not completed until June 15 — a 91-day gap between breach and conclusion — making this the largest publicly disclosed theft of U.S. driver's license data in 2026 and a high-value ingest for identity fraud, account-opening attacks, and downstream phishing operations. The company has not disclosed the specific initial access vector, though credential compromise of a single employee account is consistent with an infostealer or targeted phishing precursor.
assuranceamericadrivers-licensepii-breachinsurance-sectorcredential-compromise
READ →
HIGH#SUPPLY-CHAIN2026-07-11
Injective Labs npm SDK Compromised via Hijacked Maintainer GitHub Account — 18 Packages Backdoored to Steal DeFi Wallet Keys
On July 8, attackers hijacked a trusted maintainer's GitHub account (thomasRalee) and used the repository's own OIDC trusted-publisher pipeline to publish @injectivelabs/sdk-ts@1.20.21 and 17 co-dependent packages — each containing key-derivation-telemetry.ts, which intercepts BIP-39 mnemonic seed phrases and private keys at wallet creation and exfiltrates them via HTTPS POST to an endpoint masquerading as Injective's own public gRPC-Web infrastructure. The malicious release, detected by Socket, Ox Security, and StepSecurity, was live for under an hour and downloaded approximately 310 times before the owner reverted the commits; the package has ~50,000 weekly downloads and 87 npm dependents, meaning transitive exposure is likely broader than direct downloads suggest. Any developer environment that called wallet key-generation functions during the compromise window should treat all mnemonic phrases and private keys as fully compromised and rotate immediately to version 1.20.23.
injective-labsnpm-supply-chaingithub-account-compromisecrypto-wallet-stealerdefi
READ →