π¨ ACTIVE EXPLOITS & INCIDENTS
-
Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei β SecurityWeek
Nichirei disconnected systems on July 13 due to a cyberattack and is now gradually restoring operations. This incident follows a recent wave of attacks targeting beverage and grocery sectors, including Coca-Colaβs US Fairlife operations suspension. -
ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files β The Hacker News
ACR Stealer, active since 2024, continues exfiltrating browser passwords, live session tokens, PDFs, and Microsoft 365 files from enterprise networks. Infection vectors include command execution via Run box commands. Microsoft Defender Experts detailed two delivery chains recently. -
New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage β The Hacker News
Discovered by Kaspersky, GoSerpent is a previously undocumented espionage malware targeting Southeast Asian government and diplomatic entities since late 2025. It focuses on long-term access and intelligence gathering.
π VULNERABILITIES & CVEs
-
Fresh SharePoint Vulnerability Exploited Soon After Disclosure β SecurityWeek
Critical RCE vulnerability CVE-2026-58644 (CVSS 9.8) in Microsoft SharePoint Server is actively exploited. It allows remote authenticated attackers to execute arbitrary code. CISA added it to the KEV catalog, mandating federal patching by July 19. -
CISA Urges Immediate Action on Actively Exploited Fortinet Flaws β BleepingComputer
CISA ordered federal agencies to urgently patch two actively exploited vulnerabilities in Fortinet FortiSandbox threat detection platform by July 18. Details on CVEs not disclosed but exploitation is confirmed in the wild. -
CVE-2026-59252: Missing gas_limit Validation in ZenHive mpp Tempo Fee-Payer β CVE ThreatInt
Allows unauthenticated remote wallet drain and DoS on fee-payer wallet, impacting blockchain payment processing. Requires immediate review if using ZenHive mpp Tempo. -
CVE-2026-59694: Unbounded Access List Inflates Gas Cost in ZenHive mpp Tempo Fee-Payer β CVE ThreatInt
Improper input validation allows unauthenticated actors to inflate gas costs per payment, degrading sponsor resources. -
CVE-2026-59695: Unbounded max_fee_per_gas Enables Single-Request Wallet Drain in ZenHive mpp Tempo β CVE ThreatInt
Unauthenticated remote attacker can drain fee-payer wallet in a single request by specifying arbitrarily high gas price. -
CVE-2026-8075: Mattermost Desktop App Crash via Malicious Markdown Image β CVE ThreatInt
Versions β€6.2 5.5.13 6.0.2.0 vulnerable to crashes triggered by crafted markdown images, enabling denial of service. -
CVE-2026-9602: Mattermost Desktop App Crash via Malformed Arguments β CVE ThreatInt
Versions β€6.2 6.0.2 5.6.13.0 vulnerable to crashes caused by malformed payloads from the Mattermost Web App, exploitable by malicious server owners. -
CVE-2026-22104: Improper Access Control in Hashtopolis Server Chunk Activity β CVE ThreatInt
Versions prior to 0.14.8 allow any user account to read all cracked hashes, exposing sensitive password cracking results. -
CVE-2026-62764: Authenticated Low-Privileged User Can Gracefully Shutdown Apache Accumulo Services β CVE ThreatInt
Allows low-privileged authenticated users to remotely issue shutdown commands, potentially disrupting service availability. -
CVE-2026-15380: Local Privilege Escalation in Symantec ITMSA via DCOM/Task Scheduler β CVE ThreatInt
Non-admin interactive users can achieve SYSTEM code execution without network or memory corruption, affecting ITMS 8.7.3. -
CVE-2026-9656: Sensitive Information Exposure in HubSpot All-In-One Marketing WordPress Plugin β CVE ThreatInt
Versions β€11.3.62 vulnerable to sensitive data exposure via wp_localize_script misuse by authenticated contributors. -
CVE-2026-15379: Arbitrary File Read as SYSTEM in Symantec ITMS Altiris WMI Provider β CVE ThreatInt
Local standard users can read any file accessible to SYSTEM by abusing AltirisAgent_Stream class, bypassing ACLs.
π΅οΈ THREAT RESEARCH & DEEP DIVES
- Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy β Palo Alto Unit 42
Technical analysis of three chained zero-days in Siemens ROX II OT switches enabling privilege escalation and persistent root access. Critical for ICS/OT defenders to review for detection and mitigation strategies.
π VENDOR BULLETINS & ADVISORIES
- Windows Server 2022 Reaches End of Mainstream Support in 90 Days β BleepingComputer
Mainstream support ends October 2026; extended security updates continue for 5 years. Organizations should plan upgrade or extended support licensing to maintain patching compliance.
π° LESSER-KNOWN / UNDER-REPORTED
-
GTA 6 Hacker Released From Secure Hospital β @metacurity@infosec.exchange
Not directly security-impacting but notable for threat actor monitoring: a high-profile hacker linked to GTA 6 leaks has been released from secure hospital custody. -
Commentary on Current Cyber Conflict Dynamics β @metacurity@infosec.exchange
Insightful analyst quote highlighting adversariesβ operational panic and weakness, relevant for strategic threat posture assessments.