Info
2026-07-18 11:41Z · last 24h · 60 findings
· glm-5.2:cloud
Threat Brief — 2026-07-18 — ICS CVE surge, Windows 0-day, AI agent attacks
Executive summary: A heavy 24 hours for ICS/OT vulnerability disclosures, with CISA publishing a flood of Rockwell Automation, ABB, Siemens, and other advisories alongside multiple KEV catalog additions. A Windows 0-day PoC ("LegacyHive") surfaced, and Kaspersky disclosed a supply-chain espionage campaign ("HelloNet") targeting Russian organisations via ViPNet updates. Academic researchers also published a large batch of AI/LLM security papers covering jailbreaking, prompt injection, and backdoors — worth noting for any team building agent-based tooling.
Top items
- Windows "LegacyHive" 0-day PoC published — Unprivileged users can reportedly read other accounts' registry hives, including admin. PoC is now public, increasing likelihood of in-the-wild use. (xakep)
- HelloNet cyber-espionage campaign via ViPNet updates — Kaspersky reports attacks since May 2026 targeting Russian government, industrial, energy, and transport orgs through the ViPNet update mechanism — a supply-chain compromise path. (xakep)
- Zoom CVE-2026-53412 (CVSS 9.8) patched — Unauthenticated remote account takeover in Zoom Windows client/SDK; patch now if not already deployed. (xakep)
- CISA KEV additions — multiple active-exploit CVEs — Recent KEV entries include Fortinet FortiSandbox command injection (CVE-2026-25089KEV), SonicWall SMA1000 SSRF (CVE-2026-15409KEV·R), SharePoint CVEs (CVE-2026-58644KEV and others), and a legacy Cisco IOS CSRF (CVE-2008-4128KEV). All require remediation per BOD 22-01 if in inventory. (CISA KEV 1, 2, 3)
- Claude for Chrome extension vulnerability ("ClaudeBleed") — Malicious co-existing extensions can simulate clicks to force Claude to exfiltrate Gmail, Docs, Calendar, and Salesforce data. Relevant for any org permitting browser AI assistants. (xakep)
- Rockwell Automation — numerous ICS advisories — DoS, file read/delete, memory modification, and code execution across ControlLogix/CompactLogix, Flex 5000, 1756-EN2/EN3/ENBT, Arena, and FactoryTalk DataMosaix. Prioritise patches on exposed PLCs/adapters. (CISA ICSA-26-197-01 through 09)
- Siemens SICAM 8 — multiple DoS vulnerabilities — Affects SICAM A8000, CPCI85, SICORE, and EGS firmware; critical for power-sector OT. (CISA)
- ABB ICS advisories (T-MAC Plus, Advant Master, Edgenius) — Public PoC for CVE-2026-31431KEV ("Copy Fail") in Edgenius; updates available. (CISA)
- OkoBot malware targeting crypto wallets — Kaspersky reports a 20+ module framework stealing credentials, files, and crypto from software/hardware wallet users. (xakep)
- Russian state-sponsored router targeting advisory (AA26-194A) — FSB Centre 16 actors continue exploiting poorly configured/vulnerable networking devices across critical sectors; hygiene and patching guidance updated. (CISA)
- VK apps and Max messenger removed from Google Play — Not directly exploitable, but signals platform-policy shifts relevant to user communications continuity. (xakep)
- Fodcha DDoS botnet resurgence — 360 Netlab reports Fodcha returning with ransom DDoS activity; large daily active node counts observed. (netlab360)
Themes
- ICS/OT disclosure wave: The single largest cluster this cycle is CISA ICS advisories — Rockwell, Siemens, ABB, AutomationDirect, SALTO, and NASA cFS all in one day. OT asset owners should expect a heavy patch sprint.
- Supply-chain and update-channel attacks: HelloNet (ViPNet) and PureCrypter loader activity both highlight continued abuse of trusted distribution/update mechanisms as an initial-access vector.
- AI/LLM agent security research surge: A large batch of Seebug-paper translations covers multi-turn prompt injection, function-call jailbreaks, federated-learning backdoors, and AI red-teaming benchmarks — operationally relevant for any team deploying LLM-driven automation or pen-testing tools.
