This day 02:00 06:00 10:01 14:01 18:01 22:01
Info  2026-07-26 22:01Z · last 4h · 4 findings · glm-5.2:cloud

Threat Brief — 2026-07-26 — Patient malware, resilient scams

Executive summary

A newly described Windows infostealer called Dolphin X takes a patient, reconnaissance-first approach—profiling 300+ applications, 9 browsers, and hundreds of crypto wallets before deciding whether a target is worth robbing. Separately, satellite imagery confirms that scam-compound infrastructure rebuilds within months of law-enforcement raids, underscoring how resilient the cybercrime real-estate pipeline remains. On the defensive side, AI safety filters in ChatGPT and Claude are reportedly blocking legitimate vulnerability research, adding friction to offensive security workflows.

Top items

Themes

Selective and patient malware. Dolphin X joins a recent trend of threat actors favouring reconnaissance-driven targeting over indiscriminate mass theft—similar in spirit to the BlueNoroff wallet-profiling phishing kit reported earlier this week (first reported 2026-07-24, The Hacker News). Operators are increasingly filtering victims before committing payloads, which lowers detection rates and improves ROI.

AI as double-edged sword for security work. The same AI guardrails that curb malicious exploitation are now impeding legitimate researchers—a tension that parallels the "AI pentest agents found NodeBB flaws" story from 2026-07-24 (The Hacker News). The community is simultaneously leveraging AI for defence and bumping against its safety rails.

Public exploits · latest from the exploit feed

ArcadeDB < 26.7.2 Cross-Database Authorization Bypass (IDOR) 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0-7.0.8 & 7.0-rc-7.0-rc7 - Use After Free Exploit 2026-08-02 15:45Z · RSS:cxsecurity-wlb MODX.3.2.1 TLS cookie without secure flag set - COOKIE PHPSESSID HIJACK 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0 DRM UAF LPE Exploit published for CVE-2026-46215 CVE-2026-46215 2026-07-22 14:05Z · CXSecurity / Exploit-DB (RSS) ZTE ZXHN H188A V6 Authentication Bypass 2026-07-22 13:28Z · RSS:cxsecurity-wlb OpenEMR 7.0.2 Arbitrary File Read 2026-07-22 13:28Z · RSS:cxsecurity-wlb PHP Link Directory (phpLD) 2.1.3 - SQL Injection, IDOR, CSRF 2026-07-22 13:28Z · RSS:cxsecurity-wlb KNX visualisering - Broken Access Control 2026-07-22 13:28Z · RSS:cxsecurity-wlb D-Link DSL2600U rom-0 Admin Password Disclosure 2026-07-22 13:28Z · RSS:cxsecurity-wlb Windows Defender (MsMpEng.exe) Race Condition -> LPE / SYSTEM / Use-After-Free -> Crash 2026-07-22 13:28Z · RSS:cxsecurity-wlb