Info
2026-07-11 06:05Z · last 24h · 32 findings
· glm-5.2:cloud
Threat Brief — 2026-07-11: ShareFile Shutdown, Boot Flaws, Supply-Chain Swarms
Progress Software is urging ShareFile customers to immediately shut down Storage Zone Controllers over a credible active threat, making it the day's most urgent action item. Bootloader and supply-chain vulnerabilities dominated the research space, with six U-Boot firmware flaws and a malicious npm package pushed via a compromised Injective Labs GitHub repo. Active exploitation of a Gitea Docker auth bypass rounds out the top priorities, alongside several crypto-wallet and identity-based attack campaigns worth noting.
Top Items
- URGENT — Progress ShareFile Storage Zone Controllers under active threat: Progress told customers to immediately shut down on-prem Windows servers running Storage Zone Controllers, citing a "credible external security threat." A temporary workaround is in place but no full patch details yet. Anyone running ShareFile on-prem should act now. (The Hacker News, BleepingComputer)
- Six U-Boot bootloader flaws enable stealthy firmware compromise: Binarly disclosed six vulnerabilities (four allowing code execution at boot) in the ubiquitous U-Boot bootloader used in routers, smart cameras, and server BMCs. Patch availability is fragmented across vendors, making this a persistent supply-chain exposure for embedded and data-center fleets. (The Hacker News, BleepingComputer)
- Gitea Docker auth bypass actively exploited: Attackers are exploiting a critical authentication bypass in the official Gitea Docker image that allows impersonation of any user including admins. If you run self-hosted Gitea via Docker, pull the fixed image and audit for unauthorized access immediately. (BleepingComputer)
- Injective Labs GitHub compromise pushes wallet-stealing npm package: Threat actors compromised the Injective Labs SDK GitHub repo to publish a malicious npm package targeting crypto wallet private keys and mnemonic seeds. This is another example of repo-takeover-to-registry-poisoning; teams consuming Injective SDK dependencies should verify package provenance. (The Hacker News)
- Zimbra Classic Web Client XSS (patch now): Zimbra urged customers to patch a critical stored XSS in the Classic Web Client of Zimbra Collaboration suite. Active exploitation risk is high given Zimbra's UCGO/enterprise footprint. (BleepingComputer)
- Unpatched XQUIC XRING flaw crashes HTTP/3 servers: A single-variable bug in Alibaba's XQUIC library lets any remote client crash an HTTP/3 server with legal traffic. No patch available yet; organisations exposing XQUIC-based HTTP/3 endpoints should monitor for advisories and consider WAF/rate-limit mitigations. (The Hacker News)
- Fake Microsoft Entra passkey enrollment campaign: A multi-sector threat actor uses voice-based social engineering to trick M365 users into enrolling an attacker-controlled Entra passkey, aiming for data extortion. This is a MFA-bypass pattern worth alerting helpdesks about. (The Hacker News)
- MODBEACON RAT — China-linked Silver Fox: QiAnXin attributes a Rust-based RAT using gRPC streaming for encrypted C2 to the Silver Fox Chinese cybercrime group. Low-sophistication but stealthy; defenders watching for gRPC anomalies should add hunting logic. (The Hacker News)
- WP-SHELLSTORM — misconfigured server exposes mass WordPress backdooring: An exposed attacker server revealed tooling and logs showing backdooring of WordPress sites across a target list of 1.4M websites (fewer actually compromised). Useful IOCs for web-monitoring teams. (The Hacker News)
- "Ill Bloom" crypto wallet flaw exploited for $3.1M: Coinspect disclosed a recovery-phrase generation flaw in wallet software that attackers have already exploited to drain funds. Affects users of vulnerable wallet implementations; relevant for any team handling crypto custody. (The Hacker News)
- Tangem wallet laser attack resets passwords (unpatchable): Ledger Donjon demonstrated a fault-injection attack against Tangem card chips allowing password reset without the old password. The cards cannot be patched — a hardware-level compromise relevant to crypto-asset risk assessments. (The Hacker News)
- Free Android VPN apps leak traffic and track users: A study of 281 of the most popular free VPN apps on Google Play found widespread traffic leaks, unencrypted data, and tracking. Worth flagging to employees using personal VPNs. (The Hacker News)
Themes
- Supply-chain & build-system compromise continues: Injective Labs GitHub → npm, U-Boot firmware image handling, and the WP-SHELLSTORM tooling leak all reinforce that software supply chains remain the dominant attacker lane. Verify provenance, pin hashes, and audit build pipelines.
- Identity and MFA-bypass wave: The fake Entra passkey enrollment campaign and the Gitea Docker auth bypass both illustrate attackers pivoting away from endpoint exploitation toward identity impersonation. Strengthen identity-provider logging and break-glass procedures.
- Crypto-wallet attacks multiplying: Ill Bloom, Tangem laser fault injection, and the Injective npm package all target wallet keys/seed phrases — a noticeable cluster for any organisation with digital-asset exposure.
