π¨ ACTIVE EXPLOITATION
β οΈ 6 | Operation CameraSwarm Compromised 14,530 Dahua IP Cameras
Attackers compromised 14,530 Dahua IP cameras in Operation CameraSwarm.
- Dahua IP cameras were targeted, mainly in Ukraine and Russia, from June 17 to July 22, 2026.
- Attackers compromised 14,530 devices, including 1,923 with a persistent p2pwn backdoor account and 283 through P2P relays.
- Credential attacks scanned TCP port 37777 and brute-forced camera logins.
- The p2pwn tool exploited CVE-2021-33044 and CVE-2021-33045 to create the p2pwn/p2password account.
- P2P access used camera serial numbers and SDK credentials embedded in Dahua applications; 89.4% of live serials reportedly exposed an unauthenticated channel.
π Source: dahuasecurity.com Β· π Coverage: securityaffairs.com Β· :eye: via SecurityWeek
β οΈ 6 | ClawHavoc Poisoned OpenClawβs ClawHub With Malicious Agent Skills
ClawHavoc used poisoned OpenClaw skills to deliver information-stealing malware.
- OpenClaw users installing skills from the ClawHub registry were targeted.
- ClawHavoc linked 1,184 malicious packages to 12 author IDs, including 341 in the initial wave.
- NovaStealer and Atomic macOS Stealer targeted crypto wallets, browser data, SSH keys, AWS credentials, tokens, and agent context.
- Malicious SKILL.md files used fake AuthTool prerequisites, ClickFix prompts, Base64-encoded shell commands, and password-protected archives.
- IOCs included 91.92.242.30, 95.92.242.30, SHA-256 998c38b430097479b015a68d9435dc5b98684119739572a4dff11e085881187e, and SHA-256 17703b3d5e8e1fe69d6a6c78a240d8c84b32465fe62bed5610fb29335fe42283.
π Source: trellix.com Β· π Coverage: gbhackers.com Β· :eye: via Cyber Security News
β οΈ 5 | Grandoreiro Resurfaces in Mexico With DLL Sideloading Campaign
Grandoreiro has resurfaced in a Mexico-focused campaign.
- Latin American financial institutions and their customers are targeted, with Mexico accounting for 40% of detections.
- The campaign delivers the Grandoreiro banking trojan through the legitimate Duplicate Files Finder application.
- A ZIP archive named Fac-BH22DC0608_RevMQKSAC.zip used DLL sideloading; malicious mingwm10.dll was loaded alongside renamed legitimate software.
- The loader used sandbox, virtualization, process, geolocation and system checks before contacting C2 and retrieving a second-stage payload.
- Archive MD5: 82f771c3ec4fe979c3ae00372e8c3ac8; mingwm10.dll MD5: f1aed8cf2adafa86927fc58d5f24073e.
π Source: acronis.com Β· π Coverage: infosecurity-magazine.com Β· :eye: via Dark Reading
β οΈ 5 | Fake CAPTCHA attack delivers malware that kills 145 security processes
Attackers are using fake CAPTCHA pages to deliver a malware loader.
- Windows users visiting compromised WordPress sites are targeted.
- The loader disables 145 security-related processes before deploying a follow-on payload.
- Compromised sites display a counterfeit browser-verification prompt.
- ClickFix tricks victims into manually executing a Windows command.
- The campaign uses ErrTraffic as a malware delivery service.
π Coverage: cybersecuritynews.com Β· :eye: via Cyber Security News
π₯ BREACHES & INCIDENTS
β οΈ 6 | Alation confirms cyberattack involving unauthorized access to its systems
Alation confirmed a cyberattack involving unauthorized activity in one system.
- Alation serves more than 500 global companies, including about half of the U.S. Fortune 1000.
- Its data-search and AI governance platform was affected by unauthorized activity in one system around August 18, 2026.
- The incident caused degraded availability for some customers and was resolved within an hour.
- Alation has not disclosed the attack vector, affected data, customer impact, or whether data was exfiltrated.
π Coverage: techcrunch.com Β· :eye: via @zackwhittaker@mastodon.social
β οΈ 6 | ClarityCheck exposed 9 million facial images in unsecured cloud storage
ClarityCheck exposed more than nine million facial image files in an unsecured cloud database.
- ClarityCheck users and people depicted in uploaded photos were affected, including adults, teens, and children.
- The database contained 9,042,977 image files totaling 450.2 GB, including faces, profiles, screenshots, and photographs.
- An unsecured Amazon S3 bucket was accessible through a URL embedded in ClarityCheckβs public website code.
- A separate API misconfiguration exposed potential email addresses, phone numbers, and physical addresses through name-based URLs.
π Source: expressvpn.com Β· π Coverage: wired.com Β· :eye: via securityboulevard.com (discovered)
β οΈ 5 | AiTM Phishing Hijacks Microsoft 365 Finance Mailbox to Divert Payments
Attackers hijacked a Microsoft 365 finance mailbox to redirect vendor payments.
- Microsoft 365 finance users and shared accounts-payable mailboxes were targeted.
- Attackers accessed Exchange Online, SharePoint, Microsoft 365 Search, and payment correspondence.
- An HR-themed PTO phishing email used SendGrid redirects and an AiTM relay to capture an MFA-approved session cookie.
- The stolen session was replayed through VPN infrastructure, while inbox rules concealed payment-related emails for about 30 days.
- IOCs included cs@bitcrazy[.]com, alerting-services[.]com, u108265739[.]ct[.]sendgrid[.]net, mauthcopilot[.]com, and portalmyadminsigninapps.experiencewithreliability[.]de.
π Source: trendaisecurity.com Β· π Coverage: cybersecuritynews.com Β· :eye: via Cyber Security News
π CVEs & KEV
CVE-2026-74018 β CVSS 9.9 β WordPress Warehouse Cargo theme through 2.6.9 - Arbitrary File Upload vulnerabilit...
CVE-2026-74016 β CVSS 9.9 β WordPress Smart Cleaning theme through 4.8.6 - Arbitrary File Upload vulnerability...
CVE-2026-74014 β CVSS 9.9 β WordPress IT Residence theme through 3.2.1 - Arbitrary File Upload vulnerabilitySu...
CVE-2026-74001 β CVSS 9.8 β WordPress User Registration & Membership Pro plugin through 5.4.5 - Account Takeov...
CVE-2026-73993 β CVSS 9.8 β WordPress FundEngine plugin through 1.7.9 - PHP Object Injection vulnerabilityUnau...
CVE-2026-11861 β CVSS 9.6 β FreeIPA Authentication Bypass & Privilege Escalation (CVE-2026-11861)
CVE-2026-68566 β CVSS 9.3 β WordPress BookingPress Appointment Booking Pro plugin through 6.0.2 - SQL Injectio...
CVE-2026-66794 β CVSS 9.3 β Critical Red Hat Kubernetes SSRF Flaw Exposes Internal Services Across Managed Clusters
CVE-2026-74013 β CVSS 8.5 β WordPress eShipper Commerce plugin through 2.16.13 - SQL Injection vulnerabilitySu...
CVE-2026-73998 β CVSS 8.5 β WordPress WP w3all phpBB plugin through 3.0.5 - SQL Injection vulnerabilitySubscri...
CVE-2026-74020 β CVSS 7.5 β WordPress Koji theme through 2.2.1 - Broken Access Control vulnerabilityUnauthenti...
CVE-2026-20320 β CVSS 7.5 β Cisco External Entity Injection Vulnerability Allows Attackers to Read Sensitive Data
CVE-2026-74019 β CVSS 7.1 β WordPress EPROLO Dropshipping plugin through 2.4.2 - Broken Access Control vulnera...
π΅οΈ RESEARCH & DEEP DIVES
π¨ 7 | UAT-10147 deploys SPECTRE cross-platform backdoor with rootkit and BYOVD
Cisco Talos has identified SPECTRE, a cross-platform backdoor used by UAT-10147.
- IIS and Linux servers targeted by the Chinese-speaking UAT-10147 intrusion actor.
- SPECTRE supports C2 operations, process injection, credential theft, and shell and file commands.
- Linux deployments include kernel rootkits, while Windows deployments use BYOVD techniques to bypass EDR.
- The implant uses runtime API resolution, encrypted strings, anti-sandbox scoring, and self-termination to evade analysis.
- C2 uses HTTP POST requests to /api/v1/register and /api/v1/output; one Windows variant reads configuration from C:\Windows\System32\drivers\etc\hosts:cache.