Threat Brief — 2026-07-29 — Hotel Wi-Fi, Tor 0-day, APT Expansion
Executive summary: Three threads dominate today's landscape: a patched Firefox JIT flaw (CVE-2026-10702) that can compromise Tor Browser through a single malicious webpage visit; an active GOFFEE APT campaign expanding geographically with new container-based attack techniques; and a newly exposed link between Telegram-hacking patents and Chinese state cyber infrastructure. Meanwhile, attackers are compromising hotel Wi-Fi gateways to redirect guests to phishing pages, and researchers trace Iranian involvement in a near-catastrophic water-treatment attack.
Top items
- Tor Browser RCE via single webpage visit (CVE-2026-10702). Nebula Security demonstrated that a patched Firefox JIT bug provides arbitrary code execution inside the browser sandbox simply by visiting a malicious page — and the same flaw compromises Tor Browser. Any user of Tor or unpatched Firefox is at risk of full browser compromise without interaction. (src: The Hacker News)
- GOFFEE APT expands with new TTPs and container-based Mythic agent. Securelist documents a new GOFFEE campaign with expanded geographic targeting, previously undocumented tactics, techniques, and procedures, and deployment of a Mythic agent inside containers — a shift that complicates detection in cloud and containerised environments. (src: Securelist)
- Chinese cyber-forces linked to Telegram-hacking patents via infrastructure leak. An employee operational-security lapse led analysts to a company with no website or storefront that holds patents for hacking Telegram and has documented ties to Chinese state cyber operations — exposing hidden government infrastructure. (src: SecurityLab)
- Iranian trail in water-treatment plant attack. Intelligence agencies are hunting the culprits behind a fresh attack on water treatment facilities that nearly left residents without drinking water, with an Iranian trail emerging in the investigation. Critical infrastructure ICS security teams should review OT network segmentation. (src: SecurityLab)
- 200,000 IoT devices controlled for years via decade-old RC4 vulnerabilities. Vulnerabilities dating back to 2013 and the deprecated RC4 algorithm have allowed attackers to maintain persistent control over roughly 200,000 devices, underscoring how IoT manufacturers continue shipping inherently insecure products that become DDoS infrastructure. (src: SecurityLab)
- Hotel Wi-Fi DNS-hijacking campaign targets corporate travellers. ReliaQuest identified a campaign in which attackers compromise Wi-Fi gateways in hotels and conference centres, altering DNS settings to redirect guests and corporate-event attendees to phishing pages — a low-cost, high-yield vector for credential theft against travelling staff. (src: Xakep)
- BiP and KakaoTalk blocked in Russia after record audience growth. Two messengers that saw 120% audience growth have stopped working directly in Russia and now require VPN — a signal of tightened communications controls that may push users toward monitored channels. (src: SecurityLab)
- Finland to sever Russian internet backbone link from 2027. Fingrid will stop servicing power-line towers supporting fibre infrastructure, effectively disconnecting part of the cross-border internet backbone — an event that will alter routing for Russian traffic and may create opportunities for traffic interception. (src: SecurityLab)
- Durov formally charged by FSB (developing). Russia's FSB has filed formal charges against Telegram founder Pavel Durov for allegedly facilitating terrorist activity and failing to remove prohibited content. This follows the earlier report that the FSB placed Durov on an international wanted list, first reported earlier today by SecurityLab. (src: The Hacker News; first reported: SecurityLab)
Themes
Travel-targeted attacks are converging: The hotel Wi-Fi DNS-hijack campaign and the DEF CON ban on Meta smart glasses (id 4518) both highlight that physical proximity and conference/travel settings remain high-value attack surfaces — whether for credential phishing via rogue DNS or surreptitious recording via wearables. Travelling engineers should assume hostile network conditions and treat hotel Wi-Fi as untrusted by default.
State actors expanding operational toolkits: GOFFEE's container-based Mythic agent, the Chinese Telegram-hacking patents, and the Iranian water-plant attack together suggest state-linked groups are diversifying delivery mechanisms and targeting OT/critical infrastructure with increasing ambition. Container security monitoring and ICS network isolation should be priorities this week.
