threat-intel Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge The Chaos ransomware group is utilizing a sophisticated technique involving msaRAT, a Rust-based implant, to establish a command-and-control channel. msaRAT leverages a headless Chrome or Edge browser, communicating thro… The Hacker News · Jul 23, 2026 High ransomwarec2webrtc
threat-intel China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks A China-nexus operation, tracked by Group-IB, dubbed JadeProx, is using a new loader called TriBack Loader to target government, healthcare, and education organizations across Asia and Latin America. The operation levera… The Hacker News · Jul 23, 2026 High CVE-2018-11511CVE-2021-24139CVE-2021-31755CHHOVIloaderspear-phishingvulnerability
vulnerability Weintek cMT3092X Weintek’s cMT3092X HMI and EasyWeb software versions are vulnerable to privilege escalation and credential exposure. A non-privileged user can modify cookies to gain elevated privileges, and user passwords are stored in… CISA Advisories · Jul 23, 2026 High CVE-2026-60134CVE-2026-61892CVE-2026-61886patchplaintextprivilege escalation
vulnerability Panduit IntraVUE Pronetiqs has identified and reported several vulnerabilities in Panduit IntraVUE software versions 3.2.1a14 and earlier, posing significant risks to industrial control systems. These vulnerabilities include plaintext st… CISA Advisories · Jul 23, 2026 High CVE-2026-40430CVE-2026-42933CVE-2026-44955industrial control systemsot securitypassword vulnerability
vulnerability Johnson Controls C-CURE 9000 and Victor application server Johnson Controls has issued security advisories regarding critical vulnerabilities in its C-CURE 9000 and Victor application servers, as well as the victor Web application. Exploitation could allow an unauthenticated att… CISA Advisories · Jul 23, 2026 High CVE-2026-21655CVE-2026-21653CVE-2026-34496cve-2026-21653cve-2026-21655cve-2026-34496
threat-intel Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite A group of Russian state-supported cyber actors, known as LAUNDRY BEAR, has been aggressively targeting Western organizations using the Zimbra Collaboration Suite (ZCS) since July 2025, seeking to gather sensitive inform… CISA Advisories · Jul 23, 2026 High CVE-2025-66376MOPOSPphishingsupply-chainmalware
vulnerability Johnson Controls XAAP Android A vulnerability exists in the Johnson Controls XAAP Android application, version 1.53 and earlier. Attackers with physical access to a device could potentially read sensitive data stored locally without encryption. This… CISA Advisories · Jul 23, 2026 High CVE-2026-34490vulnerabilityandroidcleartext storage
vulnerability MZ Automation libIEC61850 MZ Automation libIEC61850 versions 1.0.0 through 1.6.1 are vulnerable to several stack and heap-based buffer overflows, potentially allowing an unauthenticated attacker to crash critical IEC 61850 services or execute arb… CISA Advisories · Jul 23, 2026 High CVE-2026-50039CVE-2026-49035CVE-2026-50103iec61850buffer overflowindustrial control systems
threat-intel How Synthetic Identity Fraud is Coming for Machine Identities Synthetic identity fraud is a growing threat targeting machine identities, not just human users. Attackers are creating fabricated machine identities – fake accounts that appear legitimate – to gain unauthorized access a… The Hacker News · Jul 23, 2026 High machine identitiessynthetic identity fraudnhis
threat-intel Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers A sophisticated campaign leveraging compromised GitHub repositories is targeting cPanel and WHM servers. Attackers are using malicious GitHub Actions workflows to launch GitHub-hosted runners that scan for vulnerable ser… The Hacker News · Jul 23, 2026 High CVE-2026-41940githubmalwarecpanel
threat-intel Agentic AI Challenges Progress in Confidential Computing Artificial intelligence is driving increased adoption of confidential computing, but the proliferation of AI agents within enterprises poses a new security challenge. These agents can retain sensitive data and secrets, e… Dark Reading · Jul 23, 2026 High UNaiconfidential computingsecurity
threat-intel Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel The Chaos ransomware group is utilizing a new Rust-based remote access Trojan (RAT) called ‘msaRAT’ to infiltrate networks. MsaRAT leverages browser debugging protocols (CDP), specifically Chrome DevTools Protocol, to es… Cisco Talos · Jul 23, 2026 High ransomwarebrowserwebrtc
vulnerability Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs A nine-year-old vulnerability (CVE-2026-64600) in the Linux kernel's XFS filesystem allows unprivileged local users to gain root access on default Red Hat Enterprise Linux, CentOS Stream, and Amazon Linux installations.… The Hacker News · Jul 23, 2026 High CVE-2026-64600CVE-2026-8933linuxxfskernel
threat-intel Brazilian Banking Trojan Actively Spreading in Portugal A long-standing Brazilian banking Trojan, Lampion, is actively targeting Portuguese organizations, leveraging the shared language and cultural connection between Brazilian hackers and Portuguese businesses. The malware,… Dark Reading · Jul 23, 2026 High BRPTESbanking trojanphishinggeofencing
threat-intel US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices The US government has issued an updated cybersecurity advisory warning of ongoing Iranian-linked attacks targeting industrial control systems (ICS) manufactured by Siemens, Schneider Electric, and Rockwell Automation. Ha… SecurityWeek · Jul 23, 2026 High IRicsindustrial control systemsplc
threat-intel State Department imposes visa restrictions on foreign cyber scammers The State Department is implementing new visa restrictions targeting individuals involved in foreign cybercrime networks, specifically those linked to scams like sextortion and human trafficking. This follows a broader e… The Record · Jul 23, 2026 High PHCACHcybercrimevisa restrictionssoutheast asia
threat-intel ISC Stormcast For Thursday, July 23rd, 2026 https://isc.sans.edu/podcastdetail/10020, (Thu, Jul 23rd) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions with sophisticated spear-phishing attacks. The campaigns leveraged stolen credentials and a new, highly c… SANS Internet Storm Center · Jul 23, 2026 High phishingspear-phishingcredential-stuffing
threat-intel Ransomware Attack Puts a Chill On Japanese Frozen-Food Chain A ransomware attack targeting Nichirei, a Japanese frozen-food supplier and logistics firm, has disrupted its operations and impacted thousands of clients, including Kentucky Fried Chicken franchises in Japan. Russia-lin… Dark Reading · Jul 23, 2026 High JPransomwaresupply chainjapan
vulnerability Multiples vulnérabilités dans les produits Check Point (23 juillet 2026) Multiple vulnerabilities have been discovered in Check Point products, allowing attackers to elevate privileges and bypass security policies. Check Point reports that CVE-2026-16232 is actively being exploited. Users are… CERT-FR · Jul 23, 2026 High CVE-2026-16232CVE-2026-62144CVE-2026-62145vulnerabilitycheck pointsecurity
vulnerability Multiples vulnérabilités dans Oracle Database Server (23 juillet 2026) Multiple vulnerabilities have been discovered in Oracle Database Server, potentially leading to data integrity compromise, data confidentiality breaches, and remote denial-of-service attacks. These vulnerabilities affect… CERT-FR · Jul 23, 2026 High CVE-2025-7962CVE-2026-28387CVE-2026-28388oracledatabasevulnerability