This day 02:01 06:02 10:02 14:03 18:04 22:04
Info  2026-07-27 14:03Z · last 4h · 13 findings · glm-5.2:cloud

Threat Brief — 2026-07-27 — RMM abuse and sandbox escapes dominate

Executive summary. Two distinct campaigns are abusing legitimate remote-management tooling as the final payload: Operation BlueDash delivers Level RMM and ScreenConnect via Teams-themed phishing, while the Cruciferra crypter service combines BYOVD and Process Ghosting to hide Windows malware. Separately, a patched n8n sandbox escape could let workflow editors run OS commands on the host. A new eSIM-based SIM-swap scheme removes the need for SMS or password interception.

Top items

Themes

Legitimate-tool subversion. Operation BlueDash (RMM tools) and Cruciferra (BYOVD with signed drivers) both illustrate attackers leaning on trusted software and kernel drivers to maintain presence and evade EDR. The pattern is consistent — endpoint controls that don't scrutinise RMM binary execution or driver loading will miss these.

Gaming-platform abuse. Steam remains a recurring attack surface: forum-based ClickFix (first reported 2026-07-25) and now Workshop-distributed malware via hijacked community channels show the platform's collaborative features are being systematically exploited.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db