DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
100 RECORDS
// Search all intelligence records
SEARCHING ACROSS 100 RECORDS // INTEL FEED · CVE TRACKER · ADVISORIES · DARK WEB
// SEV
CRITICAL8
HIGH12
MEDIUM6
LOW2
INFO2
// CAT
CVE9
ADVISORY7
RANSOMWARE4
APT5
DARK WEB3
SUPPLY CHAIN2
ZERO-DAY2
// SRC
DMZ ORIGINAL15
CISA5
NVD4
VENDOR6
// DATE
LAST 7 DAYS12
LAST 30 DAYS16
LAST 90 DAYS22
20245
20233
// VENDOR
MICROSOFT7
CISCO4
FORTINET4
GOOGLE2
LINUX2
SHOWING 10 OF 100 RECORDS
SORT:
2026
CRITICAL#RANSOMWARE2026-08-02
Qilin RaaS Affiliates Weaponize PAN-OS GlobalProtect Auth-Bypass (CVE-2026-0257) for Credential-Free VPN Entry Leading to Full Domain Compromise
Arctic Wolf documented multiple June 2026 intrusions in which Qilin ransomware affiliates exploited CVE-2026-0257 — an authentication bypass in PAN-OS GlobalProtect triggered by misconfigured override cookies — to establish legitimate-looking VPN sessions without credentials, followed by LSASS dumping, NTDS.dit extraction, PsExec-based lateral movement, and enterprise-wide encryption. Palo Alto Networks patched on May 13, Rapid7 confirmed broad exploitation by May 17, and CISA ordered federal agencies to patch within three days on May 29; however, unpatched internet-facing deployments across PAN-OS 10.2–12.1 and Prisma Access remain actively targeted. The attack surface is significant given Palo Alto's footprint across 70,000+ customers including 90% of Fortune 10 companies.
qilincve-2026-0257pan-osglobalprotectauthentication-bypass
READ →
HIGH#SUPPLY-CHAIN2026-08-02
AUR Package Adoption Suspended After Coordinated Malicious Takeover Campaign Injects Tor-Based Credential-Stealing Payload Across 200+ Packages, Including openconnect-sso
Arch Linux suspended AUR package adoption on July 30 after investigators confirmed a coordinated campaign in which threat actors adopted orphaned packages and injected a two-stage, Tor-routed payload that steals browser data, cryptocurrency wallets, SSH keys, and API keys, then spreads laterally via SSH. The campaign — beginning with the VPN package openconnect-sso and potentially spanning over 200 packages — follows the June 2026 'Atomic Arch' incident in which 400+ packages were similarly hijacked; with roughly 13,000 orphaned packages still in the AUR, the structural attack surface remains wide open. Developer and CI/CD environments that pull AUR packages during builds should treat any recently adopted or newly active packages as untrusted until the adoption freeze is lifted and all affected packages are audited.
arch-linuxaursupply-chainopenconnect-ssopackage-hijacking
READ →
HIGH#DARK-WEB2026-08-02
Amgen Files Material SEC 8-K: Attackers Exfiltrate Patient PHI and Proprietary Drug R&D Data from Multiple Third-Party Cloud Environments
Amgen disclosed a material cybersecurity incident via SEC Form 8-K on July 31, confirming that threat actors exfiltrated patient protected health information (PHI), proprietary corporate data, and R&D information from cloud environments operated by unnamed third-party service providers — not Amgen's own internal infrastructure. The company identified the unauthorized activity in July 2026, determined materiality based on volume and sensitivity of affected records on July 29, and has not yet named the cloud providers, the initial access vector, the threat actor, or the number of affected individuals. The breach fits a documented 2026 pattern of pharmaceutical and life sciences attackers targeting third-party cloud tenants, consistent with campaigns attributed to ShinyHunters and other data-theft extortion groups active in the sector this year.
amgenthird-party-cloudphihealthcaresec-8k
READ →
HIGH#APT2026-08-02
Kimsuky (APT43) Supply Chain Campaign: BirdTroy and DriveTroy Linux Backdoors Hidden Inside South Korean Groupware Vendors, Google Drive Abused for C2 over HTTP/3 QUIC
ENKI WhiteHat published a full technical analysis on July 20 revealing that Kimsuky compromised at least two South Korean collaborative-work software vendors from November 2025 into early 2026 — gaining initial access via mail-server RCE and employee social engineering — then used those footholds to silently reach downstream SaaS customers. Two previously unknown Go-based Linux backdoors, BirdTroy and DriveTroy (Gomir family variants), were deployed: BirdTroy uses HTTP/3 QUIC to blind TCP-based network monitoring tools, while DriveTroy routes all C2 and exfiltration through legitimate Google Drive OAuth API calls encrypted with TLS, making network-layer detection structurally impossible without QUIC-aware inspection. The actors also tampered with vendor login pages to harvest employee credentials and stole customer server infrastructure data for downstream targeting.
kimsukyapt43north-koreabirdtroydrivetroy
READ →
HIGH#RANSOMWARE2026-08-01
INC Ransomware Rust Rewrite Adds Salted-DPAPI Veeam Credential Dumper Targeting Modern Backup Deployments Across Windows and ESXi
INC ransomware, now the fourth most active RaaS globally with 830+ victims since 2023, has completed a full Rust-based rewrite of both Windows and Linux/ESXi encryptors and deployed a modified Veeam-Get-Creds.ps1 variant with hardcoded SQL parameters specifically engineered to defeat Veeam's newer salted DPAPI credential encryption — effectively neutralizing a defense that organizations commonly rely upon for backup security. The group exfiltrates data via rclone to attacker-controlled storage before encrypting, and Linux/ESXi variants enumerate VMware volumes to maximize encryption speed and impact. With LockBit and BlackCat disrupted, INC has absorbed former affiliates and now concentrates fire on healthcare, legal, and manufacturing targets where downtime translates directly into ransom leverage.
inc-ransomwarerustveeamesxibackup-targeting
READ →
HIGH#DARK-WEB2026-08-01
Unverified 75M-Record Revolut Dataset Listed on Cybercrime Forum; Samples Contain Partial Card Data, Hashed Credentials, Device Metadata
A threat actor listed an alleged 75-million-record Revolut customer database on an underground forum on July 25 for $500 — a suspiciously low price — containing files labeled cards.csv, credentials.csv, devices.csv, users.csv, and accounts.csv with partial card details, hashed credentials, email addresses, phone numbers, and device information. Cybernews researchers confirmed sample data appears current through approximately May 2025, found no link to prior documented Revolut incidents, and suspect possible aggregation from multiple sources. Revolut denies any evidence of a new breach, but the combination of partial card metadata and PII in the sample creates a credible phishing and social-engineering threat surface for affected users regardless of provenance.
revolutfintechforum-listingcredential-exposuredark-web
READ →
HIGH#DARK-WEB2026-08-01
TripleX Leaks 1TB Bank of Baroda Data Free on Dark Web — Aadhaar, KYC, Loan Records Confirmed in Samples; Email Compromise Vector Admitted
Emerging extortion group TripleX listed India's second-largest public-sector bank, Bank of Baroda, on Ransomware.live on July 24, publishing approximately 1TB of data for free download including customer KYC forms, Aadhaar and PAN copies, loan files, branch audit records, and internal communications. The bank confirmed the root cause was a compromised employee email account granting unauthorized access to internal files, while maintaining core banking systems were unaffected. TripleX previously breached Indonesia's PT Bank Negara Indonesia in May 2026, establishing a pattern of targeting state-owned banks in Asia with public data dumps rather than ransom demands — making negotiation-based containment impossible.
triplexbank-of-barodaindiaaadhaarfinancial-sector
READ →
HIGH#APT2026-08-01
Lazarus Group Weaponizes Mandatory South Korean Banking Software AnySign4PC in Zero-Day Watering-Hole Campaign; 72 Orgs Compromised
KISA and AhnLab disclosed a state-sponsored watering-hole campaign exploiting a zero-day buffer-overflow in AnySign4PC (versions 1.1.4.4–1.1.4.6), mandatory certificate-based signing software required by South Korean banking and government portals, enabling silent backdoor installation with no user interaction. Compromised pages on 15 legitimate South Korean news and healthcare websites delivered SIGNBT (v3.0/'Struggle') and COPPERHEDGE ('Brandoor') backdoors, with AhnLab attributing a March 2026 cluster to Lazarus under the RGB. Evidence of related attacks spans 72 organizations throughout 2026, with some intrusion chains overlapping with Gunra ransomware deployments sharing identical initial-access TTPs, SSH key fingerprints, and C2 infrastructure.
lazarus-groupdprkanysign4pcwatering-holesignbt
READ →
CRITICAL#ZERO-DAY2026-08-01
Wiz Discloses CosmosEscape: Azure Cosmos DB Gremlin Sandbox Escape Yielded Platform-Wide Master Key Enabling Full Cross-Tenant DB Takeover
Wiz Research disclosed CosmosEscape, an exploit chain beginning with a crafted Gremlin API query that escaped the sandbox, gained code execution on a multi-tenant gateway, and retrieved a platform-wide signing secret granting read/write access to every Cosmos DB account on the service — including internal Microsoft databases backing Entra ID, Teams, and Copilot. Microsoft patched the Gremlin entry point within 48 hours of the November 2025 report and completed a full architectural fix eliminating the Cosmos Master Key across all regions in July 2026. No CVE or CVSS score was assigned, and Microsoft states no unauthorized customer access occurred, but the duration of potential exposure prior to the hotfix remains unknown.
azurecosmos-dbcloud-escapemulti-tenantwiz-research
READ →
CRITICAL#APT2026-08-01
Iran-Linked Actors Hit 30+ Minnesota Water Utilities via Internet-Exposed PLCs; CISA Issues Emergency Alert
A coordinated cyberattack disrupted OT systems across more than 30 Minnesota community water systems on July 26–27, with threat actors targeting internet-exposed PLCs to change passwords and modify IP addresses — locking out operators and forcing manual operations and boil-water notices. Federal investigators are probing a possible Iran connection aligned with CISA Advisory AA26-097A, which was updated July 22 to expand scope to Schneider Electric and Siemens devices alongside Rockwell Automation PLCs and to document a new project-file exfiltration tactic. CISA's acting director issued an emergency call for all water utilities to immediately remove PLCs and OT from internet exposure, warning that nearly half of exposed Rockwell devices are reachable via cellular modems representing a critical blind spot.
iranics-otplc-exploitationwater-sectorcyberav3ngers
READ →