View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

UAT-10147 deploys SPECTRE cross-platform backdoor with rootkit and

🚨 ACTIVE EXPLOITATION

⚠️ 6 | Operation CameraSwarm Compromised 14,530 Dahua IP Cameras
Attackers compromised 14,530 Dahua IP cameras in Operation CameraSwarm.

  • Dahua IP cameras were targeted, mainly in Ukraine and Russia, from June 17 to July 22, 2026.
  • Attackers compromised 14,530 devices, including 1,923 with a persistent p2pwn backdoor account and 283 through P2P relays.
  • Credential attacks scanned TCP port 37777 and brute-forced camera logins.
  • The p2pwn tool exploited CVE-2021-33044 and CVE-2021-33045 to create the p2pwn/p2password account.
  • P2P access used camera serial numbers and SDK credentials embedded in Dahua applications; 89.4% of live serials reportedly exposed an unauthenticated channel.
    πŸ“„ Source: dahuasecurity.com Β· πŸ“Ž Coverage: securityaffairs.com Β· :eye: via SecurityWeek

⚠️ 6 | ClawHavoc Poisoned OpenClaw’s ClawHub With Malicious Agent Skills
ClawHavoc used poisoned OpenClaw skills to deliver information-stealing malware.

  • OpenClaw users installing skills from the ClawHub registry were targeted.
  • ClawHavoc linked 1,184 malicious packages to 12 author IDs, including 341 in the initial wave.
  • NovaStealer and Atomic macOS Stealer targeted crypto wallets, browser data, SSH keys, AWS credentials, tokens, and agent context.
  • Malicious SKILL.md files used fake AuthTool prerequisites, ClickFix prompts, Base64-encoded shell commands, and password-protected archives.
  • IOCs included 91.92.242.30, 95.92.242.30, SHA-256 998c38b430097479b015a68d9435dc5b98684119739572a4dff11e085881187e, and SHA-256 17703b3d5e8e1fe69d6a6c78a240d8c84b32465fe62bed5610fb29335fe42283.
    πŸ“„ Source: trellix.com Β· πŸ“Ž Coverage: gbhackers.com Β· :eye: via Cyber Security News

⚠️ 5 | Grandoreiro Resurfaces in Mexico With DLL Sideloading Campaign
Grandoreiro has resurfaced in a Mexico-focused campaign.

  • Latin American financial institutions and their customers are targeted, with Mexico accounting for 40% of detections.
  • The campaign delivers the Grandoreiro banking trojan through the legitimate Duplicate Files Finder application.
  • A ZIP archive named Fac-BH22DC0608_RevMQKSAC.zip used DLL sideloading; malicious mingwm10.dll was loaded alongside renamed legitimate software.
  • The loader used sandbox, virtualization, process, geolocation and system checks before contacting C2 and retrieving a second-stage payload.
  • Archive MD5: 82f771c3ec4fe979c3ae00372e8c3ac8; mingwm10.dll MD5: f1aed8cf2adafa86927fc58d5f24073e.
    πŸ“„ Source: acronis.com Β· πŸ“Ž Coverage: infosecurity-magazine.com Β· :eye: via Dark Reading

⚠️ 5 | Fake CAPTCHA attack delivers malware that kills 145 security processes
Attackers are using fake CAPTCHA pages to deliver a malware loader.

  • Windows users visiting compromised WordPress sites are targeted.
  • The loader disables 145 security-related processes before deploying a follow-on payload.
  • Compromised sites display a counterfeit browser-verification prompt.
  • ClickFix tricks victims into manually executing a Windows command.
  • The campaign uses ErrTraffic as a malware delivery service.
    πŸ“Ž Coverage: cybersecuritynews.com Β· :eye: via Cyber Security News

πŸ’₯ BREACHES & INCIDENTS

⚠️ 6 | Alation confirms cyberattack involving unauthorized access to its systems
Alation confirmed a cyberattack involving unauthorized activity in one system.

  • Alation serves more than 500 global companies, including about half of the U.S. Fortune 1000.
  • Its data-search and AI governance platform was affected by unauthorized activity in one system around August 18, 2026.
  • The incident caused degraded availability for some customers and was resolved within an hour.
  • Alation has not disclosed the attack vector, affected data, customer impact, or whether data was exfiltrated.
    πŸ“Ž Coverage: techcrunch.com Β· :eye: via @zackwhittaker@mastodon.social

⚠️ 6 | ClarityCheck exposed 9 million facial images in unsecured cloud storage
ClarityCheck exposed more than nine million facial image files in an unsecured cloud database.

  • ClarityCheck users and people depicted in uploaded photos were affected, including adults, teens, and children.
  • The database contained 9,042,977 image files totaling 450.2 GB, including faces, profiles, screenshots, and photographs.
  • An unsecured Amazon S3 bucket was accessible through a URL embedded in ClarityCheck’s public website code.
  • A separate API misconfiguration exposed potential email addresses, phone numbers, and physical addresses through name-based URLs.
    πŸ“„ Source: expressvpn.com Β· πŸ“Ž Coverage: wired.com Β· :eye: via securityboulevard.com (discovered)

⚠️ 5 | AiTM Phishing Hijacks Microsoft 365 Finance Mailbox to Divert Payments
Attackers hijacked a Microsoft 365 finance mailbox to redirect vendor payments.

  • Microsoft 365 finance users and shared accounts-payable mailboxes were targeted.
  • Attackers accessed Exchange Online, SharePoint, Microsoft 365 Search, and payment correspondence.
  • An HR-themed PTO phishing email used SendGrid redirects and an AiTM relay to capture an MFA-approved session cookie.
  • The stolen session was replayed through VPN infrastructure, while inbox rules concealed payment-related emails for about 30 days.
  • IOCs included cs@bitcrazy[.]com, alerting-services[.]com, u108265739[.]ct[.]sendgrid[.]net, mauthcopilot[.]com, and portalmyadminsigninapps.experiencewithreliability[.]de.
    πŸ“„ Source: trendaisecurity.com Β· πŸ“Ž Coverage: cybersecuritynews.com Β· :eye: via Cyber Security News

πŸ”“ CVEs & KEV

CVE-2026-74018 β€” CVSS 9.9 β€” WordPress Warehouse Cargo theme through 2.6.9 - Arbitrary File Upload vulnerabilit...
CVE-2026-74016 β€” CVSS 9.9 β€” WordPress Smart Cleaning theme through 4.8.6 - Arbitrary File Upload vulnerability...
CVE-2026-74014 β€” CVSS 9.9 β€” WordPress IT Residence theme through 3.2.1 - Arbitrary File Upload vulnerabilitySu...
CVE-2026-74001 β€” CVSS 9.8 β€” WordPress User Registration & Membership Pro plugin through 5.4.5 - Account Takeov...
CVE-2026-73993 β€” CVSS 9.8 β€” WordPress FundEngine plugin through 1.7.9 - PHP Object Injection vulnerabilityUnau...
CVE-2026-11861 β€” CVSS 9.6 β€” FreeIPA Authentication Bypass & Privilege Escalation (CVE-2026-11861)
CVE-2026-68566 β€” CVSS 9.3 β€” WordPress BookingPress Appointment Booking Pro plugin through 6.0.2 - SQL Injectio...
CVE-2026-66794 β€” CVSS 9.3 β€” Critical Red Hat Kubernetes SSRF Flaw Exposes Internal Services Across Managed Clusters
CVE-2026-74013 β€” CVSS 8.5 β€” WordPress eShipper Commerce plugin through 2.16.13 - SQL Injection vulnerabilitySu...
CVE-2026-73998 β€” CVSS 8.5 β€” WordPress WP w3all phpBB plugin through 3.0.5 - SQL Injection vulnerabilitySubscri...
CVE-2026-74020 β€” CVSS 7.5 β€” WordPress Koji theme through 2.2.1 - Broken Access Control vulnerabilityUnauthenti...
CVE-2026-20320 β€” CVSS 7.5 β€” Cisco External Entity Injection Vulnerability Allows Attackers to Read Sensitive Data
CVE-2026-74019 β€” CVSS 7.1 β€” WordPress EPROLO Dropshipping plugin through 2.4.2 - Broken Access Control vulnera...

πŸ•΅οΈ RESEARCH & DEEP DIVES

🚨 7 | UAT-10147 deploys SPECTRE cross-platform backdoor with rootkit and BYOVD
Cisco Talos has identified SPECTRE, a cross-platform backdoor used by UAT-10147.

  • IIS and Linux servers targeted by the Chinese-speaking UAT-10147 intrusion actor.
  • SPECTRE supports C2 operations, process injection, credential theft, and shell and file commands.
  • Linux deployments include kernel rootkits, while Windows deployments use BYOVD techniques to bypass EDR.
  • The implant uses runtime API resolution, encrypted strings, anti-sandbox scoring, and self-termination to evade analysis.
  • C2 uses HTTP POST requests to /api/v1/register and /api/v1/output; one Windows variant reads configuration from C:\Windows\System32\drivers\etc\hosts:cache.

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check