Info
2026-07-07 06:03Z · last 24h · 18 findings
· glm-5.2:cloud
Threat Brief — 2026-07-07 — Active Exploitation Escalates Across Critical CVEs
Executive Summary
Two critical vulnerabilities are now under active exploitation in the wild: a maximum-severity Adobe ColdFusion flaw (CVE-2026-48282KEV) and a Citrix NetScaler memory-disclosure bug with a public PoC. Threat actors are also probing a 9.8-rated Gitea Docker vulnerability 13 days post-disclosure, underscoring a shrinking patch window. Separately, an LLM-driven ransomware attack dubbed JadePuffer marks a concerning milestone as agentic AI threats move from theory to production compromise.
Top Items
- Adobe ColdFusion CVE-2026-48282KEV — Max severity, actively exploited. The Canadian Center for Cyber Security confirmed in-the-wild exploitation of a maximum-severity ColdFusion vulnerability. Immediate patching is essential for any exposed ColdFusion instance. BleepingComputer
- Gitea Docker CVE-2026-20896 (CVSS 9.8) — Threat actors probing. Sysdig reports active probing of this critical Gitea Docker image flaw 13 days after disclosure. Self-hosted Git platforms are high-value targets for supply-chain pivot. The Hacker News
- Citrix NetScaler memory-disclosure flaw — PoC published, under attack. Attackers are actively exploiting the latest NetScaler memory disclosure vulnerability (dubbed "CitrixBleed") following release of a proof-of-concept exploit. Any unpatched NetScaler ADC or gateway is at immediate risk. Dark Reading
- Linux KVM CVE-2026-53359 ("Januscape") — 16-year-old VM escape. A use-after-free bug in KVM's shadow-page handling allows a malicious guest VM to escape to the host on Intel and AMD x86 systems. Relevant to multi-tenant cloud and hosting environments. The Hacker News
- JadePuffer — First complete LLM-driven ransomware attack. An "agentic threat actor" exploited a Langflow flaw to exfiltrate data from a production database and encrypt additional systems, demonstrating autonomous AI-driven attack chaining end-to-end. Dark Reading
- EtherRAT via fake Teams IT-support calls — Active social engineering. Attackers impersonate corporate IT staff over Microsoft Teams voice calls to trick employees into installing EtherRAT, providing initial access. Targets helpdesk trust patterns. BleepingComputer
- "BusySnake" infostealer — Targeting critical infrastructure. Threat group "Armored Likho" has compromised government and electrical-power entities in Russia, Brazil, and Kazakhstan using a new infostealer. Dark Reading
- QuimaRAT — Cross-platform Java-based MaaS. A new malware-as-service RAT built in Java targets Windows, Linux, and macOS simultaneously, lowering the barrier for broad-platform compromise. The Hacker News
- SkillCloak — Malicious AI agent skills evading static scanners. Researchers demonstrated self-extracting packing techniques that bypass static scanners for AI coding-agent "skills," leaving functional malware undetected. Relevant to any team using AI coding assistants with third-party extensions. The Hacker News
- Opera GX browser flaw — Silent add-on installation. A flaw allowed malicious websites to silently install browser mods that exfiltrate data from visited pages. Patched but highlights browser-extension attack surface. The Hacker News
- Fake Indian tax-filing utility deploys DcRAT — Suspected China-nexus cluster. A multi-stage campaign targets Indian taxpayers and finance professionals with a trojanized tax utility delivering DcRAT for data theft. The Hacker News
- Phishing as fake job interviews — Stealing Google credentials. Campaign impersonates 30+ major brands (Adobe, Netflix, Coca-Cola, OpenAI) targeting marketing professionals' Google accounts via fake interview lures. BleepingComputer
- Iran-linked Cavern C2 framework — Targeting Israeli organizations. An Iranian MOIS-affiliated group is using a previously undocumented modular C2 framework called Cavern (aka Cav3rn) against Israeli targets. The Hacker News
Themes
- Actively exploited critical CVEs converging: Three separate critical-severity vulnerabilities (ColdFusion, Gitea Docker, Citrix NetScaler) are simultaneously under active attack or probing. Prioritise patching internet-facing infrastructure immediately — the gap between disclosure and exploitation continues to compress.
- AI/LLM as both attack vector and attack tool: JadePuffer demonstrates agentic AI conducting full ransomware chains, while SkillCloak shows malicious AI-agent extensions evading detection. Meanwhile, commentary highlights that AI-accelerated software development is outpacing security review. Teams deploying AI tooling should expect adversarial exploitation of the same agentic capabilities.
- Social engineering via trusted collaboration platforms: EtherRAT delivery via Teams voice calls and the fake job-interview phishing campaign both exploit trust in familiar platforms (Microsoft Teams, major brand names) rather than technical vulnerabilities. Reinforce verification procedures for unsolicited IT-support contact.
