This day 02:00 06:00 10:01 14:01 18:01 22:01
Info  2026-07-26 22:01Z · last 4h · 4 findings · glm-5.2:cloud

Threat Brief — 2026-07-26 — Patient malware, resilient scams

Executive summary

A newly described Windows infostealer called Dolphin X takes a patient, reconnaissance-first approach—profiling 300+ applications, 9 browsers, and hundreds of crypto wallets before deciding whether a target is worth robbing. Separately, satellite imagery confirms that scam-compound infrastructure rebuilds within months of law-enforcement raids, underscoring how resilient the cybercrime real-estate pipeline remains. On the defensive side, AI safety filters in ChatGPT and Claude are reportedly blocking legitimate vulnerability research, adding friction to offensive security workflows.

Top items

Themes

Selective and patient malware. Dolphin X joins a recent trend of threat actors favouring reconnaissance-driven targeting over indiscriminate mass theft—similar in spirit to the BlueNoroff wallet-profiling phishing kit reported earlier this week (first reported 2026-07-24, The Hacker News). Operators are increasingly filtering victims before committing payloads, which lowers detection rates and improves ROI.

AI as double-edged sword for security work. The same AI guardrails that curb malicious exploitation are now impeding legitimate researchers—a tension that parallels the "AI pentest agents found NodeBB flaws" story from 2026-07-24 (The Hacker News). The community is simultaneously leveraging AI for defence and bumping against its safety rails.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db