Threat Brief — 2026-07-25 — Fileless delivery and unauthenticated admin
Executive summary: Two critical infrastructure vulnerabilities demand immediate patching: Check Point Security Management Server can be accessed at admin level with no credentials, and a Windows Event Log RCE affects nearly all Microsoft systems. Meanwhile, a large malvertising campaign is assembling malware directly in browser memory via JavaScript, bypassing traditional file-based detection. ShinyHunters breach data is now actively fuelling $2,000 sextortion campaigns.
Top items
- Check Point Security Management Server — unauthenticated admin access (emergency patches). Attackers can reach admin level with no password or login on Check Point security management systems. Check Point has released emergency updates covering eleven affected SMS versions. If you run Check Point SMS in your environment, treat this as a P1 patch — an unauthenticated admin compromise of a security management appliance is about as bad as it gets. (src: securitylab-ru)
- Windows Event Log service RCE — affects Windows, Windows Server, and nearly all Microsoft systems. Microsoft has patched a remote code execution vulnerability in the Windows Event Log service that allowed arbitrary code execution on remote machines. Given the ubiquity of the Event Log service across Windows estates, this warrants enterprise-wide patch prioritisation. (src: securitylab-ru)
- Malvertising campaign builds malware in browser memory via JavaScript. A massive malvertising operation uses fake Solana, Luno, and TradingView landing pages with malicious JavaScript that instructs the victim's browser to assemble malware directly in memory — no file touched on disk. This fileless technique evades endpoint detection that relies on filesystem artifacts. Users visiting these spoofed trading/crypto sites through malvertising pipelines are the primary target. (src: BleepingComputer)
- ShinyHunters breach data fuels $2,000 Bitcoin sextortion emails. Threat actors are cross-referencing email addresses from ShinyHunters-leaked breach corpora to send sextortion emails demanding $2,000 in Bitcoin. The breach data lends credibility to the extortion claims — recipients see real account details and assume the threat is genuine. Expect user-facing awareness comms to help staff recognise and report these without paying. (src: BleepingComputer)
Themes
Credential-free exploitation and fileless delivery converge. Today's top items share a common thread: attackers are increasingly bypassing traditional security controls by either exploiting unauthenticated access paths (Check Point admin, Windows Event Log RCE) or avoiding filesystem artifacts entirely (in-browser memory malware assembly). Defence strategies should prioritise network-level exposure reduction for management interfaces and memory-scanning / behavioural EDR capabilities over signature-based file detection.
Breach data as attack fuel. The ShinyHunters sextortion campaign illustrates how leaked databases continue to generate downstream attack value long after the initial breach — not just for credential stuffing, but for socially engineered extortion. This reinforces the importance of breach-notification-driven password resets and user education.
===
THREAT-TOPICS===
[{"slug":"checkpoint-sms-unauth-admin","headline":"Check Point SMS unauthenticated admin access — emergency patches for 11 versions","findingIds":[4310],"status":"new","development":"New: unauthenticated admin-level access to Check Point Security Management Server; emergency updates released"},{"slug":"windows-event-log-rce","headline":"Windows Event Log service RCE affects nearly all Microsoft systems","findingIds":[4309],"status":"new","development":"New: RCE in Windows Event Log service patched by Microsoft"},{"slug":"js-in-memory-malware-malvertising","headline":"Malvertising assembles malware in browser memory via malicious JavaScript","findingIds":[4312],"status":"new","development":"New: fileless malware delivery via fake Solana/Luno/TradingView pages using in-browser JS assembly"},{"slug":"shinyhunters-sextortion-scam","headline":"ShinyHunters breach data fuels $2,000 Bitcoin sextortion emails","findingIds":[4311],"status":"new","development":"New: threat actors leveraging ShinyHunters-leaked email data for sextortion campaigns"}]
