DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:01:53ZSOURCES: 14CRITICAL: 26
⚠ ACTIVE ALERTS
UAC-0145 (Sandworm) CRITICAL — UAC-0145 is a confirmed sub-cluster of Sandworm, Russia's GRU-affiliated advanced hacking… /// CYLINDRICALCANINE CRITICAL — CylindricalCanine is a newly named operational subgroup within the China-linked… /// @CrowdStrike CRITICAL — July 2026 Patch Tuesday analysis: CVE-2026-56155 (AD FS EoP, CVSS 7.8) confirmed… /// @MsftSecIntel CRITICAL — Microsoft has confirmed active exploitation of CVE-2026-56155 in Active Directory… /// @GossiTheDog CRITICAL — CVE-2026-56155 ADFS zero-day is nastier than the CVSS 7.8 suggests. Admin on your ADFS…
26Critical Threats
18Active CVEs
10IOCs Tracked
5New Advisories
100 RECORDS
// Search all intelligence records
SEARCHING ACROSS 100 RECORDS // INTEL FEED · CVE TRACKER · ADVISORIES · DARK WEB
// SEV
CRITICAL8
HIGH12
MEDIUM6
LOW2
INFO2
// CAT
CVE9
ADVISORY7
RANSOMWARE4
APT5
DARK WEB3
SUPPLY CHAIN2
ZERO-DAY2
// SRC
DMZ ORIGINAL15
CISA5
NVD4
VENDOR6
// DATE
LAST 7 DAYS12
LAST 30 DAYS16
LAST 90 DAYS22
20245
20233
// VENDOR
MICROSOFT7
CISCO4
FORTINET4
GOOGLE2
LINUX2
SHOWING 10 OF 100 RECORDS
SORT:
2026
CRITICAL#ZERO-DAY2026-07-22
CVE-2026-6875: Pre-Auth RCE Actively Exploited in ServiceNow AI Platform; Self-Hosted Orgs Unpatched
A critical unauthenticated sandbox-escape RCE flaw in the ServiceNow AI Platform (CVE-2026-6875, CVSS 9.5) has been under active exploitation since July 17–18 — just five days after patches were released for self-hosted instances on July 13. Defused confirmed a second gadget chain reaching the same code-execution primitive via a different sandbox-escape route, meaning WAF/signature-based mitigations tuned to the published PoC are insufficient. ServiceNow's advisory as of July 22 still does not acknowledge exploitation, and the platform underpins AI workflows at 85% of Fortune 500 companies — making self-hosted instances that haven't patched an immediate emergency.
cve-2026-6875servicenowpre-auth-rcesandbox-escapeenterprise-platform
READ →
HIGH#APT2026-07-22
GoSerpent APT: Unattributed Go-Based Backdoor Spent 5+ Years Harvesting SEA Government, Police Biometric, and Diplomatic Data
Kaspersky GReAT disclosed on July 16–17 a previously undocumented espionage campaign active since at least 2021, using a Go-based RAT named GoSerpent to target government, law enforcement, and diplomatic entities across Southeast Asia — including police complaint management systems and biometric databases. After months of silent credential harvesting via ThumbcacheService, operators returned in May 2026 to deploy Stowaway (a SOCKS5/AES-256-GCM proxy tool) and TmcLoader for staged exfiltration through internal network shares using stolen legitimate credentials, making detection by standard network monitoring effectively blind. The threat actor remains unattributed; C2 infrastructure was concealed behind Alibaba Cloud and UCLOUD HK.
goserpentkaspersky-greatsoutheast-asiaaptgo-rat
READ →
HIGH#RANSOMWARE2026-07-22
Gentlemen RaaS Claims 1TB Exfil from TKMS/Atlas Elektronik; Leaked Samples Show SeaFox Drone and Scout MkII Sonar Schematics
The Gentlemen ransomware group listed ThyssenKrupp Marine Systems (TKMS) and its Atlas Elektronik subsidiary — a NATO navy sonar and combat systems supplier — on its leak portal in late June, claiming over 1TB of exfiltrated data. TKMS confirmed a breach isolated to a North American subsidiary supporting U.S. military work, stating no classified data was compromised, but the group subsequently posted screenshots appearing to show proprietary PCB layouts for the Scout MkII side-scan sonar and technical manuals for the SeaFox mine-disposal UUV. Gentlemen is now the second-most-active RaaS group in 2026 by victim count, behind Qilin, with 330–580 claimed victims across 70+ countries.
the-gentlementkmsatlas-elektroniknaval-defenseraas
READ →
HIGH#DARK-WEB2026-07-22
Threat Actor '888' Lists 35GB Accenture Haul on PwnForums: Source Code, Azure PATs, SSH/RSA Keys Offered for XMR
On July 6, prolific PwnForums moderator '888' posted a one-time-sale listing claiming 35GB stolen from Accenture in July 2026, including source code, RSA keys, SSH keys, Azure Personal Access Tokens, Azure Storage access keys, and configuration files. A sample screenshot showed what appears to be an Azure DevOps repository on an accenture.com production URL. Accenture confirmed an isolated breach to multiple outlets but stated no operational impact — stopping short of validating the data types or volume claimed. The exposed Azure PATs and storage keys pose a downstream client risk, as Accenture services Microsoft, Google, AT&T, and Verizon, among others.
accenturedark-webthreat-actor-888azure-devopssource-code-theft
READ →
HIGH#SUPPLY-CHAIN2026-07-22
AsyncAPI npm Supply Chain Compromise Delivers Miasma RAT to 3M+ Weekly Downloads via GitHub Actions 'Pwn Request'
On July 14, Microsoft Threat Intelligence and multiple firms confirmed a coordinated supply chain attack against four @asyncapi npm packages collectively downloaded over 3 million times per week. The attacker flooded the AsyncAPI generator repo with 37 decoy pull requests, camouflaging a single malicious PR that exploited a misconfigured pull_request_target GitHub Actions workflow to steal a privileged PAT — publishing five trojanized package versions with valid SLSA provenance attestations. The payload (Miasma RAT, a.k.a. miasma-train-p1) executes at import time, not install, bypassing npm 12's new install-script blocking; it steals browser credentials, SSH keys, npm/GitHub tokens, cloud credentials, and crypto wallets.
asyncapinpmsupply-chaingithub-actionspwn-request
READ →
HIGH#DARK-WEB2026-07-21
Estée Lauder Discloses Cl0p Oracle EBS Breach — SSNs, Passports, Health Data Exposed Nearly 11 Months After Intrusion
Estée Lauder publicly disclosed a breach stemming from Cl0p ransomware group's zero-day exploitation of CVE-2025-61882 in Oracle E-Business Suite, with the intrusion occurring on or around August 9, 2025 — nearly 11 months before victim notification. Exposed data includes Social Security numbers, passport numbers, financial account codes, and health records belonging to current and former employees. The breach joins a confirmed list of 100+ Cl0p victims in the same Oracle EBS campaign, which also impacted Nissan, Harvard University, The Washington Post, and American Airlines subsidiary Envoy Air.
estee-laudercloporacle-ebscve-2025-61882data-breach
READ →
CRITICAL#RANSOMWARE2026-07-21
Qilin RaaS Affiliates Weaponizing CVE-2026-0257 PAN-OS GlobalProtect Auth Bypass for Domain-Wide Encryption
Arctic Wolf Labs confirmed that Qilin ransomware affiliates are actively exploiting CVE-2026-0257, an authentication bypass in PAN-OS GlobalProtect (CVSS 7.8), to establish unauthorized VPN sessions and pivot to domain-wide encryption — a chain Arctic Wolf assesses as likely ongoing. Post-exploitation tradecraft varies across intrusions, ranging from rapid encryption-only operations to full double-extortion via Rclone/MEGA, consistent with multiple affiliates sharing a common exploit. Shadowserver tracks over 167,000 GlobalProtect instances exposed online, and the CISA KEV deadline for federal remediation has already passed.
qilinpan-osglobalprotectcve-2026-0257ransomware-as-a-service
READ →
HIGH#SUPPLY-CHAIN2026-07-20
SleeperGem: Hijacked Dormant RubyGems Maintainer Accounts Used to Inject Payload-Dropping Loaders Targeting Developer Endpoints
Aikido Security and StepSecurity disclosed SleeperGem, a RubyGems supply chain attack in which adversaries reactivated two long-dormant maintainer accounts to poison three packages — including git_credential_manager (impersonating Microsoft's official tool) and fastlane-plugin-run_tests_firebase_testlab (574,000+ total downloads). Each malicious release acts as a loader that checks for CI/CD environments and skips them, exclusively targeting developer machines where it drops a native daemon, installs cron and systemd persistence, and escalates to root if sudo is passwordless. The attack surface is developer endpoints — precisely the instrumentation gap left by years of pipeline-focused hardening.
sleepergemrubygemssupply-chaindeveloper-targetingdormant-account-hijack
READ →
HIGH#APT2026-07-20
Hugging Face Production Infrastructure Breached by Autonomous AI Agent — Internal Datasets and Service Credentials Exfiltrated
Hugging Face disclosed that an autonomous AI agent framework executed over 17,000 attacker actions across a swarm of short-lived sandboxes over a single weekend, breaching production infrastructure via two code-execution paths in its dataset processing pipeline — a remote-code dataset loader and a template-injection flaw in dataset configuration. Internal datasets and service credentials were accessed; the specific LLM powering the attack framework remains unidentified. Hugging Face, used by more than 50,000 organizations and hosting over 45,000 models, has remediated the initial access paths, rebuilt compromised nodes, and rotated all affected credentials.
hugging-faceai-agent-attackml-pipelinecredential-theftsupply-chain
READ →
HIGH#APT2026-07-20
HelloNet APT Abuses ViPNet Update Mechanism to Backdoor Russian Government, Energy, and Transport Sectors
Kaspersky's Securelist disclosed the HelloNet campaign, active since at least May 2026, in which an advanced threat actor trojanizes the ViPNet VPN update directory with a malicious DLL (HelloInjector/wtsapi32.dll), sideloaded via the legitimate itcsrvup64.exe process to inject into svchost.exe. The toolset includes HelloProxy (in-memory C2), HelloExecutor (backdoor/reconnaissance), HelloBackdoor (Rust-based implant), and HelloCleaner (log wiper) — targeting Russian government, energy, transport, education, and logistics organizations. Kaspersky tentatively attributes the campaign to an unidentified Chinese-speaking APT with low confidence, explicitly noting the possibility of false flags.
hellonetvipnetdll-sideloadingrussian-governmentchinese-apt
READ →