Threat Brief — 2026-07-18 — KEV Surge, Zero-Day PoCs, and OT Advisories
Executive summary: The past 24 hours delivered a heavy cadence of actively exploited vulnerabilities added to CISA's KEV catalog—including Fortinet FortiSandbox, SonicWall SMA1000, SharePoint, and a legacy Cisco IOS CSRF—alongside a PoC for a Windows registry 0-day ("LegacyHive"). A cyberespionage campaign dubbed HelloNet is compromising Russian organizations through ViPNet update mechanisms, while CISA warns of ongoing Russian state-sponsored targeting of poorly configured network devices. Multiple ICS/OT vendor advisories (Rockwell, ABB, Siemens, AutomationDirect, SALTO, NASA cFS) and a critical Zoom fix round out the operational risk picture.
Top Items
- Zoom CVE-2026-53412 (CVSS 9.8) — Unauthenticated remote account takeover. Patched in the latest Windows client/SDK updates. Exploitation required no authentication and allowed full account hijack. Prioritize patching immediately. Xakep
- Windows "LegacyHive" 0-day PoC published. Researcher "Nightmare Eclipse" released a working exploit allowing unprivileged users to access other accounts' registry hives, including administrators. No patch available yet; monitored for KEV addition. Xakep
- CISA KEV additions — multiple batches over three days. Actively exploited vulnerabilities now include CVE-2026-25089KEV (Fortinet FortiSandbox OS command injection), CVE-2026-15409KEV·R (SonicWall SMA1000 SSRF), CVE-2026-58644KEV (SharePoint), CVE-2008-4128KEV (Cisco IOS CSRF), and CVE-2023-4346KEV (KNX protocol authorization bypass), among others. All require remediation per BOD 22-01 deadlines. CISA 07/13 | CISA 07/14 | CISA 07/15 | CISA 07/16
- CISA: Russian FSB Center 16 targeting poorly configured network devices. Joint advisory urges router hygiene improvements across critical sectors; actors exploit vulnerable/unpatched devices for initial access and persistence. Review exposure of edge devices and disable unused management interfaces. CISA AA26-194A
- CISA urges SharePoint hardening amid ongoing exploitation. Multiple SharePoint CVEs under active exploitation, including CVE-2026-58644KEV added to KEV on 07/16. Organizations running on-prem SharePoint should patch and audit for indicators of compromise. CISA Alert
- HelloNet cyberespionage campaign targets Russian orgs via ViPNet updates. Kaspersky attributes attacks beginning May 2026 to a threat actor abusing ViPNet update mechanisms for initial compromise of government, industrial, energy, and transport sectors. Relevant if your environment uses ViPNet or interacts with Russian-controlled infrastructure. Xakep
- Claude for Chrome extension vulnerability — cross-extension data exfiltration. Manifold Security researchers showed a malicious co-installed extension can simulate user clicks, forcing Claude to read and expose Gmail, Google Docs, Calendar, and Salesforce data. Review browser-extension allowlists and isolate AI assistants from high-privilege extensions. Xakep
- OkoBot malware platform targeting crypto wallet holders. Kaspersky reports a modular framework (20+ modules) stealing credentials, files, and intercepting transactions from software and hardware wallet users. Distributes via phishing and loaders. Relevant for users handling cryptocurrency. Xakep
- Batch of ICS/OT advisories from CISA. Multiple Rockwell Automation products (1715-AENTR, Flex 5000, 1756-EN2/EN3/ENBT, FactoryTalk DataMosaix, CompactLogix/ControlLogix/GuardLogix, Arena), ABB (T-MAC Plus, Ability Edgenius, Advant Master Online Builder), Siemens SICAM 8, AutomationDirect Productivity Suite, SALTO ProAccess Space, and NASA cFS Health & Safety application all have new advisories covering DoS, privilege escalation, code execution, and memory corruption. Impact ranges across manufacturing, energy, and access control environments. CISA ICS Advisories (multiple)
Themes
Edge appliance and network device exploitation. The KEV additions (Fortinet, SonicWall, Cisco IOS) combined with the CISA Russian-targeting advisory signal sustained adversary interest in perimeter devices. Fortinet and SonicWall appliances are recurring favorites for ransomware-tier actors. Inventory external management interfaces and verify firmware currency.
OT/ICS patch fatigue. A single advisory batch covers eight+ Rockwell product lines alongside ABB, Siemens, and AutomationDirect—many with DoS or code-execution impact on PLCs and adapters. Environments running Rockwell ControlLogix/CompactLogix families should prioritize the DoS-class advisories, as they affect widely deployed controller families.
Supply-chain and update-channel abuse. HelloNet's abuse of ViPNet updates echoes the broader pattern of attackers co-opting trusted Update mechanisms. Combined with the Claude extension-to-extension interaction bug, both findings underscore that trust boundaries between "trusted" components (update agents, browser extensions) are increasingly exploited as lateral movement paths.
