Info
2026-07-18 11:54Z · last 24h · 60 findings
· glm-5.2:cloud
Threat Brief — 2026-07-18 — Zero-Days, Supply Chains, and AI Weaponised
Executive summary: A flood of active-exploitation alerts and zero-days dominate today's feed. CISA added multiple vulnerabilities to its KEV catalog across Cisco, SonicWall, Fortinet, and SharePoint, while Mandiant disclosed a zero-day in Cisco Catalyst SD-WAN Manager. A North Korea-nexus actor compromised the widely used Axios NPM package in a supply-chain attack, and Mandiant's M-Trends 2026 report reveals mean time-to-exploit has gone negative — adversaries are exploiting flaws before patches exist. Meanwhile, AI itself is now both weapon (autonomous ransomware, malicious agent skills) and target (Splunk AI Toolkit RCE).
Top items
- Splunk AI Toolkit remote code execution (CVSS 9.1) — A high-severity vulnerability in Splunk's AI Toolkit allows remote execution of arbitrary system commands. Given Splunk's enterprise ubiquity, this demands immediate patching. Source
- North Korea-nexus supply-chain attack on Axios NPM package — Google Threat Intelligence Group reports an active compromise of the widely used Axios NPM package by a North Korea-linked threat actor. Any organisation consuming JavaScript dependencies should audit lockfiles and rotate credentials if affected. Source
- Cisco Catalyst SD-WAN Manager zero-day (CVE-2026-20245KEV) — Mandiant identified a threat actor exploiting a zero-day in Cisco Catalyst SD-WAN Manager to target SD-WAN infrastructure at a service provider. Network-edge appliances are the attack surface; prioritise detection and vendor guidance. Source
- CISA KEV additions: SonicWall, FortiSandbox, SharePoint, Cisco IOS — Over three days CISA added CVEs for SonicWall SMA1000 SSRF, Fortinet FortiSandbox command injection (CVE-2026-25089KEV), SharePoint (CVE-2026-58644KEV), and a legacy Cisco IOS CSRF (CVE-2008-4128KEV). All are known to be actively exploited; patch or compensate immediately. [Sources: 3694, 3692, 3682, 3696]
- M-Trends 2026: mean time-to-exploit now negative (-7 days) — Mandiant's annual report highlights that vulnerabilities are being exploited a week before patches ship, and AI-assisted exploitation is accelerating discovery. This reshapes patch prioritisation from "fix fast" to "hunt now." Source
- ShinyHunters targets education sector via Oracle PeopleSoft — UNC6240 (ShinyHunters) is actively exploiting Oracle PeopleSoft infrastructure for data theft and extortion, focusing on the education sector. Organisations running PeopleSoft should review perimeter logs and apply available mitigations. Source
- China-nexus actor (UNC6508) targets US medical & AI research institutions — A sophisticated PRC-linked campaign is targeting public and private medical communities, pursuing AI, cyber, medical, and national-defense research data. Relevant to any research-intensive or healthcare-adjacent organisation. Source
- Russian FSB (Center 16) exploiting poorly configured network devices — CISA and partners warn that FSB-linked actors continue to exploit vulnerable and misconfigured routers and IoT devices across critical sectors. Router hygiene and edge-device hardening are urgent. Source
- AI attack surface expanding: autonomous ransomware, malicious agent skills, image-prompt injection — Multiple findings describe JADEPUFFER (first fully autonomous AI ransomware), malicious "Skills" evading scanners to attack Claude Code and Codex, and Ghostcommit (malicious prompts hidden in images to hijack AI agents). Defenders deploying AI tooling must treat prompts and extensions as untrusted code. [Sources: 3732, 3730, 3722]
- BlackFile vishing-extortion operation (UNC6671) — GTIG details an expansive extortion campaign using voice phishing (vishing) to deploy custom malware. Social-engineering-resistant controls and vishing awareness training are recommended. Source
- Turla STOCKSTAY .NET backdoor — GTIG analysis of STOCKSTAY, a continually developed .NET backdoor in Russia-linked Turla's intelligence-gathering toolkit. Relevant to organisations in Turla's target profile (government, diplomacy, energy). Source
- Google disrupts NetNut residential proxy network — Coordinated action with FBI, Lumen, and others against the NetNut (a.k.a. Popa) residential proxy network, following earlier disruption of IPIDEA. Reduces attacker infrastructure for evasion but expect shifting to alternatives. Source
Themes
- AI as both sword and shield: AI is being weaponised for autonomous ransomware (JADEPUFFER), zero-day hunting (T3MP3ST, GPT-RED), and prompt-injection attacks against coding agents — while also being the attack surface itself (Splunk AI Toolkit RCE, malicious Claude/Codex skills). The M-Trends negative-TTE finding shows AI-assisted exploit discovery is outpacing patch cycles.
- Supply chain remains a top-tier vector: The Axios NPM compromise and ongoing ICS advisories (Rockwell, ABB, AutomationDirect) underscore that third-party and OT vendor trust is fragile.
- Active exploitation outpaces disclosure: CISA's rapid KEV additions across SonicWall, Fortinet, and SharePoint — combined with the Cisco SD-WAN zero-day — show adversaries are capitalising on the patch-disclosure gap faster than ever.
- Edge and OT devices under sustained pressure: Russian FSB targeting of routers, the Rockwell and ABB ICS advisories, and the FortiSandbox command injection all converge on network-edge and industrial-control infrastructure as a primary battleground.
