Apt
Lazarus Burned a Windows Kernel Zero-Day to Deploy FudModule Before Patch Tuesday Shipped
CVE-2026-68820, a use-after-free in the Windows AFD.sys WinSock driver, was exploited by North Korea's Lazarus group to deploy an upgraded FudModule rootkit weeks before Microsoft's August Patch Tuesday fix shipped.
Head Mare Exploits Unpatched TrueConf Servers to Trojanize Client Installers with PhantomCore and PhantomGraph
Head Mare is chaining two unpatched TrueConf videoconferencing server flaws to reach SYSTEM, then replacing legitimate client installers with trojanized builds that drop the PhantomCore and PhantomGraph backdoors.
CVE-2026-34486: Apache Tomcat's EncryptInterceptor Fix Was Incomplete — Now Under Active Exploitation
A second, incomplete patch for a Tomcat clustering flaw lets attackers bypass pre-shared-key encryption and reach Java deserialization on the cluster port — CISA gave federal agencies until today to fix it.
QuickFox VPN Installer Trojanized for a Year to Deliver Mustang Panda's FDMTP Backdoor
A trojanized QuickFox VPN Windows installer quietly delivered the FDMTP backdoor for roughly a year, with Fortinet linking the campaign to Chinese state-sponsored actor Mustang Panda.
Adform Ad-Tech Script Hijacked to Swap Crypto Wallet Addresses, Linked to a Midnight Blizzard Sub-Cluster
Attackers compromised an Adform JavaScript library served across thousands of customer sites, silently swapping copied crypto wallet addresses in an operation researchers track as CaptiveCrunch and attribute to a Midnight Blizzard (APT29) sub-cluster.
OctLurk and SilkLurk: New Backdoors Hit Central Asian Government Networks
Kaspersky attributes a year-plus cyberespionage campaign against Central Asian and Syrian government networks to a suspected Chinese-speaking actor wielding two new memory-resident backdoors, OctLurk and SilkLurk, plus a custom proxy tool called LurkProxy.
TELESHIM: An East Asia-Linked APT Hides Its C2 Inside Telegram to Backdoor Middle East Governments
Zscaler ThreatLabz uncovers TELESHIM, MIXEDKEY, and BINDCLOAK — a new East Asia-linked malware toolset that abuses the Telegram Bot API for command-and-control against Middle East government targets.
AA26-194A: NSA, CISA, FBI Warn Russian FSB Center 16 Is Harvesting Router Configs via Weak SNMP and an 18-Year-Old Cisco CSRF Bug
A 19-agency joint advisory (AA26-194A) details a years-long Russian FSB Center 16 campaign that scans for default SNMP community strings and an 18-year-old Cisco IOS CSRF flaw (CVE-2008-4128, now in CISA KEV) to exfiltrate router configs and pivot into critical infrastructure.
Zimbra Patches Classic Web Client Stored XSS Reported by Google TAG
Zimbra shipped 10.1.19 to fix an unauthenticated stored XSS in the Classic Web Client, reachable by simply opening a crafted email — no CVE assigned yet, reported by Google's Threat Analysis Group.
Oracle E-Business Suite Payments Flaw Under Active Exploitation Before Patch Window Closed
CVE-2026-46817, a CVSS 9.8 unauthenticated takeover flaw in Oracle E-Business Suite's Payments module, is being mass-exploited via the ibytransmit endpoint — patched in May but hit in the wild before any public PoC existed.
Velvet Ant's Operation Highland: A China-Nexus APT Backdoored the Linux Auth Stack for a Decade
Sygnia's Operation Highland report details how the China-nexus group Velvet Ant hid in an isolated network for nearly a decade by backdooring pam_unix.so and OpenSSH binaries — no exploit, no dropped malware, no anomalous logs.
GREYVIBE: Russia's AI-Assisted APT Is Vibe-Coding Its Way Through Ukraine
WithSecure attributes a year-long espionage campaign against Ukraine to GREYVIBE, a Russia-nexus group that runs generative AI through nearly every phase of its operation — lure art, obfuscators, full-stack RAT development, and post-compromise commands.
Lazarus RemotePE: Memory-Only RAT Behind $577M Crypto Theft Surfaces in Fox-IT Disclosure
Fox-IT and The Hacker News detail RemotePE, a fileless C++ RAT used by North Korea's Lazarus Group against fintech and crypto firms via a DPAPI-bound loader chain. Tied to $577M in 2026 crypto theft.
MuddyWater Wears Chaos Ransomware as a Disguise — Teams Screen-Sharing Funnels Iranian Espionage Through Fake Extortion
Rapid7 attributes a Chaos-branded ransomware intrusion to Iran's MuddyWater. No files were ever encrypted — the ransom note was cover for Stagecomp/Darkcomp espionage delivered via Microsoft Teams screen-share.
North Korea's Contagious Interview Campaign Hits 1,700 Malicious Packages Across Five Ecosystems
DPRK-linked Contagious Interview operation now spans npm, PyPI, Go Modules, crates.io, and Packagist with 1,700+ poisoned packages delivering BeaverTail and InvisibleFerret malware.
Storm-1175 Chains Zero-Days to Deploy Medusa Ransomware in Under 24 Hours
Microsoft exposes Storm-1175 as a primary Medusa ransomware affiliate, weaponizing zero-days in SmarterMail and GoAnywhere MFT with sub-24-hour dwell times.
TrueConf Zero-Day Weaponized by Chinese-Nexus APT to Backdoor Southeast Asian Governments
Operation TrueChaos exploited CVE-2026-3502 in TrueConf's update mechanism to push Havoc C2 payloads across government networks via a compromised on-premises server.