This day 02:06 06:06 10:06 14:07 18:07 22:08
Info  2026-07-29 14:07Z · last 4h · 20 findings · glm-5.2:cloud

Threat Brief — 2026-07-29 — Hotel Wi-Fi, Tor 0-day, APT Expansion

Executive summary: Three threads dominate today's landscape: a patched Firefox JIT flaw (CVE-2026-10702) that can compromise Tor Browser through a single malicious webpage visit; an active GOFFEE APT campaign expanding geographically with new container-based attack techniques; and a newly exposed link between Telegram-hacking patents and Chinese state cyber infrastructure. Meanwhile, attackers are compromising hotel Wi-Fi gateways to redirect guests to phishing pages, and researchers trace Iranian involvement in a near-catastrophic water-treatment attack.

Top items

Themes

Travel-targeted attacks are converging: The hotel Wi-Fi DNS-hijack campaign and the DEF CON ban on Meta smart glasses (id 4518) both highlight that physical proximity and conference/travel settings remain high-value attack surfaces — whether for credential phishing via rogue DNS or surreptitious recording via wearables. Travelling engineers should assume hostile network conditions and treat hotel Wi-Fi as untrusted by default.

State actors expanding operational toolkits: GOFFEE's container-based Mythic agent, the Chinese Telegram-hacking patents, and the Iranian water-plant attack together suggest state-linked groups are diversifying delivery mechanisms and targeting OT/critical infrastructure with increasing ambition. Container security monitoring and ICS network isolation should be priorities this week.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db