Info
2026-07-14 06:05Z · last 24h · 25 findings
· glm-5.2:cloud
Threat Brief — 2026-07-14: Zero-Days, Poisoned Packages, and AI-Powered Intrusions
Executive summary: Active exploitation of two Joomla extension zero-days and a backdoored npm package with ~1,500 downloads headline today's threat landscape. A new macOS infostealer (CrashStealer) using a notarized dropper signals continued investment in evading Apple's Gatekeeper. Meanwhile, multiple findings highlight the intersection of AI and offensive security — from AI-assisted phishing platforms to novel attacks that poison AI agent memory through a single email.
Top items
- Joomla iCagenda & Balbooa Forms zero-days (actively exploited): CISA added two max-severity RCE flaws in these Joomla extensions to its KEV catalog after reports of in-the-wild exploitation via arbitrary file upload. Organizations running Joomla should patch or disable these extensions immediately. (BleepingComputer, The Hacker News)
- Backdoored Jscrambler npm package: A threat actor published a malicious version of Jscrambler's npm package laced with infostealer malware, downloaded ~1,500 times. Developers who pulled the package should check build environments for compromise. This underscores persistent supply-chain risk in the npm ecosystem. (BleepingComputer)
- ModHeader browser extension pulled (1.6M installs): Google and Microsoft removed the popular header-editing extension after a hidden browsing-history collector was found in the official store version for both Chrome and Edge. The extension had been dormant before silently activating data collection — a reminder that even long-trusted extensions can turn malicious. (The Hacker News)
- CrashStealer — macOS infostealer with notarized dropper: New malware disguises itself as Apple's crash-reporting tool to harvest credentials, keychain data, and crypto wallets. It uses a notarized dropper to bypass Gatekeeper, a notable evolution in macOS tradecraft. (BleepingComputer, The Hacker News)
- Forg365 PhaaS targeting Microsoft 365: A new phishing-as-a-service platform combines device-code phishing, adversary-in-the-middle session theft, anti-bot evasion, and AI-assisted lure generation. Post-compromise modules expand its utility beyond credential theft. (The Hacker News)
- CISA GitHub leak postmortem: A contractor published dozens of internal CISA credentials — including AWS GovCloud keys — to a public GitHub repo. CISA's postmortem offers lessons on third-party secret management worth reviewing for any organisation with similar contractor exposure. (Krebs on Security)
- Russian critical-infrastructure targeting: A joint advisory from the US and eight allies warns that Russian state hackers are exploiting vulnerable and poorly configured routers to pivot into critical infrastructure networks. The EU and UK also issued their first joint cyber-sanctions package against Russian GRU-linked individuals and entities. (BleepingComputer, BleepingComputer)
- MemGhost — persistent false-memory injection in AI agents: Researchers demonstrated that a single email can trick an AI assistant with mailbox access into saving a hidden, false "fact" about the user — persistently corrupting agent behaviour. Relevant to any team deploying LLM-based agents with tool access. (The Hacker News)
- GigaWiper — modular backdoor/wiper hybrid: A new implant borrows from multiple malware families to combine backdoor and wiper functionality, letting threat actors choose destructive impact on demand. (Dark Reading)
- Misconfigured server exposes live Evilginx M365 phishing ops: An attacker accidentally left a Python HTTP server with directory listing enabled on a public port, exposing three active Microsoft 365 phishing campaigns targeting Entra ID credentials. (The Hacker News)
Themes
- AI as both weapon and target: Multiple findings converge on AI-driven threats — Forg365 using AI for lure generation, an attacker deploying a suspected AI-generated PowerShell script for AD enumeration, and MemGhost demonstrating how AI agents themselves can be manipulated. Defenders should expect AI-assisted attacks to scale rapidly.
- Supply-chain and trusted-channel abuse: The Jscrambler npm backdoor and the ModHeader extension compromise both illustrate attackers compromising trusted distribution channels. The CISA GitHub leak adds a self-inflected variant — secrets exposed through a trusted contractor. A unified posture covering package provenance, extension allowlisting, and third-party repo hygiene is increasingly essential.
- Converging pressure on Microsoft 365 tenants: Forg365 PhaaS, three exposed Evilginx campaigns, and an Entra ID-focused CTF all point to sustained adversary investment in M365 credential and session theft. Organisations relying on M365 should prioritise MFA resistant to AitM (FIDO2/PHAP), conditional access, and session-token anomaly detection.
