Info
2026-07-27 22:04Z · last 4h · 11 findings
· glm-5.2:cloud
Threat Brief — 2026-07-27 — Botnets Go Blockchain, Two KEV CVEs Drop
Executive Summary
Two critical vulnerabilities were added to CISA's Known Exploited Vulnerabilities catalog today: an authentication bypass in Check Point Security Management products (CVE-2026-16232KEV) and an information-disclosure flaw in Fortinet FortiOS (CVE-2025-68686KEV). Separately, a proof-of-concept exploit for the "Certighost" Windows AD CS domain-hijack vulnerability has gone public, escalating the urgency for Active Directory environments. The Dysphoria IoT botnet has surged to 200,000 infected devices and evolved to use blockchain-based C2 infrastructure — a resilience shift following March's JackSkid takedown.
Top Items
- Check Point SmartConsole authentication bypass (CVE-2026-16232KEV) — actively exploited. This critical vulnerability in Check Point Security Management and Multi-Domain Management products lets attackers bypass authentication, gain admin privileges, and modify policies. It is now listed in CISA's KEV catalog, meaning active exploitation in the wild is confirmed. Organizations running affected Check Point management products should patch immediately. (src: xakep)
- CISA adds Fortinet FortiOS CVE-2025-68686KEV to KEV catalog. This information-disclosure vulnerability in FortiOS is now confirmed as actively exploited. Details are limited in the alert, but the KEV listing requires federal-agency remediation and signals in-the-wild targeting. Pair this with the recent FortiBleed disclosures for a compounding Fortinet exposure picture. (src: CISA)
- Public PoC exploit released for Certighost Windows AD CS vulnerability. A proof-of-concept exploit is now available for "Certighost," an Active Directory Certificate Services flaw that lets authenticated low-privilege users impersonate Domain Controllers and potentially compromise an entire Windows domain. This is a genuine development of a story first reported 2026-07-24 by The Hacker News (first report); the PoC release means exploitation is now within reach of less-sophisticated actors. (exploit: BleepingComputer) (src: BleepingComputer)
- Dysphoria IoT botnet reaches 200K devices with blockchain-based C2. Tracked by CNCERT and XLab, Dysphoria has compromised roughly 200,000 devices globally for DDoS and traffic relay. After March's law-enforcement operation against JackSkid infrastructure, the operators adopted blockchain-based name services and infected-device relays — a deliberate resilience play against future takedowns. This represents a meaningful C2 evolution worth monitoring for DDoS exposure across any internet-facing IoT estate. (src: The Hacker News) (src: BleepingComputer)
- FBI details how breaking affiliate trust accelerated LockBit takedown. An FBI agent's post-mortem on Operation Cronos reveals the multinational operation exploited internal distrust among LockBit affiliates to speed disruption — the largest ransomware group of its era. Lessons here are relevant for ongoing ransomware-tracking efforts, particularly around affiliate psychology and operational security failures. (src: Dark Reading)
- NVIDIA launches 37-member Open Secure AI Alliance, open-sources NOOA framework. NVIDIA and 36 partner organizations (spanning cloud, security, and AI vendors) formed the Open Secure AI Alliance to develop shared open technologies for securing AI agents and software. The NOOA framework has been open-sourced. This is an industry coordination signal worth noting for AI security strategy roadmaps. (src: The Hacker News)
- Commentary: adversaries exploit your existing rulebook, not zero-days. A Dark Reading analysis argues confidence in autonomous security tools is declining because attackers increasingly exploit documented processes and configurations rather than seeking novel exploits. This reinforces the importance of baseline hygiene over chasing exotic threats. (src: Dark Reading)
Themes
- KEV velocity remains high. Two CVEs added to CISA's KEV catalog on a single day — one a Check Point auth bypass and one a FortiOS info-disclosure — continues the pattern of network-infrastructure vendors as priority targets. Fortinet and Check Point administrators should treat management-plane patching as urgent, not routine.
- Botnet resilience through decentralisation. Dysphoria's pivot to blockchain-based C2 after JackSkid's disruption mirrors a broader trend of threat actors adopting decentralised infrastructure to survive law-enforcement actions. Traditional C2 takedown playbooks may be diminishing in effectiveness.
- Exploit democratisation in AD attacks. The Certighost PoC release follows a pattern seen with other AD CS / certificate-service vulns — initial research disclosure (2026-07-24) followed days later by weaponisation-ready public exploit code. Windows domain environments with ADCS deployed should assume active scanning is imminent.
