This day 02:01 06:02 10:02 14:03 18:04 22:04
Info  2026-07-27 14:03Z · last 4h · 13 findings · glm-5.2:cloud

Threat Brief — 2026-07-27 — RMM abuse and sandbox escapes dominate

Executive summary. Two distinct campaigns are abusing legitimate remote-management tooling as the final payload: Operation BlueDash delivers Level RMM and ScreenConnect via Teams-themed phishing, while the Cruciferra crypter service combines BYOVD and Process Ghosting to hide Windows malware. Separately, a patched n8n sandbox escape could let workflow editors run OS commands on the host. A new eSIM-based SIM-swap scheme removes the need for SMS or password interception.

Top items

Themes

Legitimate-tool subversion. Operation BlueDash (RMM tools) and Cruciferra (BYOVD with signed drivers) both illustrate attackers leaning on trusted software and kernel drivers to maintain presence and evade EDR. The pattern is consistent — endpoint controls that don't scrutinise RMM binary execution or driver loading will miss these.

Gaming-platform abuse. Steam remains a recurring attack surface: forum-based ClickFix (first reported 2026-07-25) and now Workshop-distributed malware via hijacked community channels show the platform's collaborative features are being systematically exploited.

Public exploits · latest from the exploit feed

ArcadeDB < 26.7.2 Cross-Database Authorization Bypass (IDOR) 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0-7.0.8 & 7.0-rc-7.0-rc7 - Use After Free Exploit 2026-08-02 15:45Z · RSS:cxsecurity-wlb MODX.3.2.1 TLS cookie without secure flag set - COOKIE PHPSESSID HIJACK 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0 DRM UAF LPE Exploit published for CVE-2026-46215 CVE-2026-46215 2026-07-22 14:05Z · CXSecurity / Exploit-DB (RSS) ZTE ZXHN H188A V6 Authentication Bypass 2026-07-22 13:28Z · RSS:cxsecurity-wlb OpenEMR 7.0.2 Arbitrary File Read 2026-07-22 13:28Z · RSS:cxsecurity-wlb PHP Link Directory (phpLD) 2.1.3 - SQL Injection, IDOR, CSRF 2026-07-22 13:28Z · RSS:cxsecurity-wlb KNX visualisering - Broken Access Control 2026-07-22 13:28Z · RSS:cxsecurity-wlb D-Link DSL2600U rom-0 Admin Password Disclosure 2026-07-22 13:28Z · RSS:cxsecurity-wlb Windows Defender (MsMpEng.exe) Race Condition -> LPE / SYSTEM / Use-After-Free -> Crash 2026-07-22 13:28Z · RSS:cxsecurity-wlb