This day 06:02 09:35 10:11 14:20 14:35 22:19
Info  2026-07-20 14:20Z · last 24h · 22 findings · glm-5.2:cloud

Threat Brief — 2026-07-20 — IP Cameras, APT Backdoors, and Mobile Zero-Days

Executive summary: Russian intelligence is systematically hijacking IP cameras across NATO states and Ukraine to track military logistics — a surveillance campaign with direct operational security implications. A new CloudAtlas APT backdoor written in Go uses WebRTC and Trello for stealthy C2, signalling continued evolution of a long-running threat group. Separately, an iPhone zero-day was reportedly rented out rather than responsibly disclosed, and a sophisticated phishing campaign used national flag images in fake job interviews to steal credentials.

Top items

Themes

Physical-digital convergence in espionage. Russian services are exploiting mundane IoT (IP cameras) for kinetic-intelligence collection — a reminder that "security camera" now means "foreign intelligence sensor." Separately, a SharkNinja cloud vulnerability (already reported 2026-07-18) demonstrated that consumer robots can be weaponised for physical space access.

APT modernisation toward cloud-native tradecraft. CloudAtlasGo's use of WebRTC and Trello mirrors a broader pattern — threat actors leveraging legitimate cloud infrastructure (Trello, WebRTC, OAuth) to dissolve C2 traffic into noise. Detection teams should assume that "trusted" cloud services are now adversarial infrastructure.

Exploit economics outpace responsible disclosure. The iPhone zero-day rental story and the SonicWall pre-disclosure exploitation both underscore that vulnerabilities are commodities — defenders cannot assume vendor-coordinated disclosure timelines will hold.

Public exploits · latest from the exploit feed

ArcadeDB < 26.7.2 Cross-Database Authorization Bypass (IDOR) 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0-7.0.8 & 7.0-rc-7.0-rc7 - Use After Free Exploit 2026-08-02 15:45Z · RSS:cxsecurity-wlb MODX.3.2.1 TLS cookie without secure flag set - COOKIE PHPSESSID HIJACK 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0 DRM UAF LPE Exploit published for CVE-2026-46215 CVE-2026-46215 2026-07-22 14:05Z · CXSecurity / Exploit-DB (RSS) ZTE ZXHN H188A V6 Authentication Bypass 2026-07-22 13:28Z · RSS:cxsecurity-wlb OpenEMR 7.0.2 Arbitrary File Read 2026-07-22 13:28Z · RSS:cxsecurity-wlb PHP Link Directory (phpLD) 2.1.3 - SQL Injection, IDOR, CSRF 2026-07-22 13:28Z · RSS:cxsecurity-wlb KNX visualisering - Broken Access Control 2026-07-22 13:28Z · RSS:cxsecurity-wlb D-Link DSL2600U rom-0 Admin Password Disclosure 2026-07-22 13:28Z · RSS:cxsecurity-wlb Windows Defender (MsMpEng.exe) Race Condition -> LPE / SYSTEM / Use-After-Free -> Crash 2026-07-22 13:28Z · RSS:cxsecurity-wlb