DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 13:15:29ZSOURCES: 14CRITICAL: 18
⚠ ACTIVE ALERTS
@GossiTheDog CRITICAL — wp2shell (CVE-2026-63030 + CVE-2026-60137) is being actively exploited in the wild —… /// @MsftSecIntel CRITICAL — Microsoft is tracking active exploitation of CVE-2026-63030 and CVE-2026-60137… /// @vxunderground CRITICAL — wp2shell PoCs are now floating around the internet. Public exploit code for the full… /// @FalconFeedsio CRITICAL — 🔴 Qilin ransomware group has now publicly claimed 2,035+ victims on its dark web leak… /// @TalosSecurity CRITICAL — Talos is tracking mass exploitation of wp2shell (CVE-2026-63030/CVE-2026-60137).…
18Critical Threats
18Active CVEs
10IOCs Tracked
6New Advisories
100 RECORDS
// Search all intelligence records
SEARCHING ACROSS 100 RECORDS // INTEL FEED · CVE TRACKER · ADVISORIES · DARK WEB
// SEV
CRITICAL8
HIGH12
MEDIUM6
LOW2
INFO2
// CAT
CVE9
ADVISORY7
RANSOMWARE4
APT5
DARK WEB3
SUPPLY CHAIN2
ZERO-DAY2
// SRC
DMZ ORIGINAL15
CISA5
NVD4
VENDOR6
// DATE
LAST 7 DAYS12
LAST 30 DAYS16
LAST 90 DAYS22
20245
20233
// VENDOR
MICROSOFT7
CISCO4
FORTINET4
GOOGLE2
LINUX2
SHOWING 10 OF 100 RECORDS
SORT:
2026
HIGH#DARK-WEB2026-07-21
Estée Lauder Discloses Cl0p Oracle EBS Breach — SSNs, Passports, Health Data Exposed Nearly 11 Months After Intrusion
Estée Lauder publicly disclosed a breach stemming from Cl0p ransomware group's zero-day exploitation of CVE-2025-61882 in Oracle E-Business Suite, with the intrusion occurring on or around August 9, 2025 — nearly 11 months before victim notification. Exposed data includes Social Security numbers, passport numbers, financial account codes, and health records belonging to current and former employees. The breach joins a confirmed list of 100+ Cl0p victims in the same Oracle EBS campaign, which also impacted Nissan, Harvard University, The Washington Post, and American Airlines subsidiary Envoy Air.
estee-laudercloporacle-ebscve-2025-61882data-breach
READ →
CRITICAL#RANSOMWARE2026-07-21
Qilin RaaS Affiliates Weaponizing CVE-2026-0257 PAN-OS GlobalProtect Auth Bypass for Domain-Wide Encryption
Arctic Wolf Labs confirmed that Qilin ransomware affiliates are actively exploiting CVE-2026-0257, an authentication bypass in PAN-OS GlobalProtect (CVSS 7.8), to establish unauthorized VPN sessions and pivot to domain-wide encryption — a chain Arctic Wolf assesses as likely ongoing. Post-exploitation tradecraft varies across intrusions, ranging from rapid encryption-only operations to full double-extortion via Rclone/MEGA, consistent with multiple affiliates sharing a common exploit. Shadowserver tracks over 167,000 GlobalProtect instances exposed online, and the CISA KEV deadline for federal remediation has already passed.
qilinpan-osglobalprotectcve-2026-0257ransomware-as-a-service
READ →
CRITICAL#CVE2026-07-21
CVE-2026-6875 Pre-Auth RCE in ServiceNow AI Platform Under Active Exploitation — Second Sandbox-Escape Gadget Chain Confirmed
Attackers began exploiting CVE-2026-6875 (CVSS 9.5), a pre-authentication sandbox-escape RCE in the ServiceNow AI Platform, on July 18 — just five days after self-hosted patches were released on July 13. Threat intelligence firm Defused confirmed a second sandbox-escape gadget chain reaching the same code-execution primitive via a different route than the published PoC, meaning organizations that blocked the known technique rather than patched are still exposed. The platform powers over 100,000 enterprise AI applications at 85% of Fortune 500 companies; unpatched self-hosted instances remain the primary target.
servicenowpre-auth-rcesandbox-escapecve-2026-6875enterprise-saas
READ →
HIGH#SUPPLY-CHAIN2026-07-20
SleeperGem: Hijacked Dormant RubyGems Maintainer Accounts Used to Inject Payload-Dropping Loaders Targeting Developer Endpoints
Aikido Security and StepSecurity disclosed SleeperGem, a RubyGems supply chain attack in which adversaries reactivated two long-dormant maintainer accounts to poison three packages — including git_credential_manager (impersonating Microsoft's official tool) and fastlane-plugin-run_tests_firebase_testlab (574,000+ total downloads). Each malicious release acts as a loader that checks for CI/CD environments and skips them, exclusively targeting developer machines where it drops a native daemon, installs cron and systemd persistence, and escalates to root if sudo is passwordless. The attack surface is developer endpoints — precisely the instrumentation gap left by years of pipeline-focused hardening.
sleepergemrubygemssupply-chaindeveloper-targetingdormant-account-hijack
READ →
HIGH#APT2026-07-20
Hugging Face Production Infrastructure Breached by Autonomous AI Agent — Internal Datasets and Service Credentials Exfiltrated
Hugging Face disclosed that an autonomous AI agent framework executed over 17,000 attacker actions across a swarm of short-lived sandboxes over a single weekend, breaching production infrastructure via two code-execution paths in its dataset processing pipeline — a remote-code dataset loader and a template-injection flaw in dataset configuration. Internal datasets and service credentials were accessed; the specific LLM powering the attack framework remains unidentified. Hugging Face, used by more than 50,000 organizations and hosting over 45,000 models, has remediated the initial access paths, rebuilt compromised nodes, and rotated all affected credentials.
hugging-faceai-agent-attackml-pipelinecredential-theftsupply-chain
READ →
HIGH#APT2026-07-20
HelloNet APT Abuses ViPNet Update Mechanism to Backdoor Russian Government, Energy, and Transport Sectors
Kaspersky's Securelist disclosed the HelloNet campaign, active since at least May 2026, in which an advanced threat actor trojanizes the ViPNet VPN update directory with a malicious DLL (HelloInjector/wtsapi32.dll), sideloaded via the legitimate itcsrvup64.exe process to inject into svchost.exe. The toolset includes HelloProxy (in-memory C2), HelloExecutor (backdoor/reconnaissance), HelloBackdoor (Rust-based implant), and HelloCleaner (log wiper) — targeting Russian government, energy, transport, education, and logistics organizations. Kaspersky tentatively attributes the campaign to an unidentified Chinese-speaking APT with low confidence, explicitly noting the possibility of false flags.
hellonetvipnetdll-sideloadingrussian-governmentchinese-apt
READ →
HIGH#APT2026-07-12
Silver Fox (China-Linked) Deploys MODBEACON Rust RAT With gRPC-Encrypted C2, Targeting Asian Tech and State-Owned Enterprises
QiAnXin on July 10 attributed a previously undocumented Rust-based RAT, MODBEACON, to the China-linked Silver Fox cluster, which distributes it via SEO-poisoned counterfeit software installers across Asia. MODBEACON uses gRPC streaming over TLS for command-and-control, routing traffic through Amazon and Cloudflare CDN infrastructure to blend with legitimate application traffic and defeat signature-based network detection — raising the detection bar to protocol-aware inspection and behavioral baselining. QiAnXin characterizes Silver Fox as a multi-distributor operation that despite appearing low-sophistication masks a structurally complex organization, deploying Gh0st RAT and WinOS/ValleyRAT variants in parallel and acting as both a 'cybercriminal arms dealer' and traffic broker across technology, education, and state-owned enterprise targets.
silver-foxmodbeacongrpc-c2rust-ratchina-linked
READ →
HIGH#APT2026-07-12
GigaWiper Modular Backdoor Attributed to Iran-Nexus Actor — Combines Disk Wiper, Fake Ransomware, and VNC Spyware in Single Golang Framework
Microsoft Threat Intelligence published analysis on July 9 of GigaWiper, a Golang-based Windows backdoor active since October 2025 that merges three destructive malware families — the Crucio ransomware (encrypts with unrecoverable keys), a Go reimplementation of FlockWiper (multi-pass disk overwrite), and a standalone raw-disk wiper — into a single modular framework with 20 operator-selectable commands, including continuous screen recording, VNC-like remote control, and Windows event log wiping. Binary Defense independently tracked the same files as BLUERABBIT and, citing Google TAG, attributed the activity to a likely Iran-nexus group targeting Israeli organizations — consistent with a surge in Iranian wiper operations warned about by Israel's National Cyber Directorate in March 2026. The malware establishes persistence as a fake 'OneDrive Update' scheduled task and uses RabbitMQ/Redis for C2, making it structurally difficult to remediate without full offline forensics.
gigawiperbluerabbitiran-nexuswiper-malwarecrucio-ransomware
READ →
HIGH#SUPPLY-CHAIN2026-07-12
Injective Labs GitHub Repo Compromised — 18 npm Packages Backdoored to Exfiltrate DeFi Wallet Private Keys and Mnemonics
On July 8, attackers used a hijacked trusted maintainer account ('thomasRalee') to push malicious commits into Injective Labs' official GitHub repository, triggering the project's own OIDC trusted-publisher pipeline to auto-publish version 1.20.21 of @injectivelabs/sdk-ts and 17 dependent packages — all hooked to silently capture BIP-39 mnemonic seed phrases and private keys at wallet creation and exfiltrate them disguised as gRPC-Web telemetry to Injective's own public infrastructure endpoints. The window was under one hour before reversion, but the SDK sees 50,000 weekly downloads across a DeFi ecosystem where developers routinely handle production wallet credentials. Any developer or application that instantiated a wallet during the exposure window should treat all key material as compromised and migrate funds immediately.
injective-labsnpm-supply-chaingithub-account-compromisedefi-wallet-theftcrypto-key-exfiltration
READ →
CRITICAL#SUPPLY-CHAIN2026-07-12
jscrambler npm Package Trojanized Across Five Malicious Releases — Rust Infostealer Targets CI/CD Secrets, Cloud Keys, and Crypto Wallets
On July 11, the official jscrambler npm CLI (a commercial JavaScript obfuscation tool with ~15,800 weekly downloads) was compromised via a hijacked maintainer account or build pipeline, with the attacker publishing five malicious versions (8.14.0 through 8.20.0) over approximately three hours. Each release included a preinstall hook that silently dropped and executed a cross-platform Rust infostealer targeting AWS/Azure/GCP cloud credentials, cryptocurrency wallets (MetaMask, Phantom, Exodus), Bitwarden vault contents, and browser session data — all before a single line of project code ran. Socket flagged the initial release six minutes after publication; any CI/CD pipeline that ran npm install in that window should be treated as fully compromised and all reachable secrets rotated immediately.
jscramblernpm-supply-chainrust-infostealerci-cd-compromisecloud-credential-theft
READ →