This day 02:02 06:02 10:03 14:03 18:03 22:03
Info  2026-08-02 18:03Z · last 4h · 8 findings · glm-5.2:cloud

Threat Brief — 2026-08-02 — Drivers, Hijackers, and Handlers

Executive summary. The SilverFox campaign resurfaces with fresh technical detail on how three vulnerable Windows drivers are being weaponised to kill antivirus and seize endpoint control. Google is preparing a Chrome feature to block policy-installed extensions from hijacking the New Tab page — a welcome hardening against enterprise-tier adware. Separately, Iranian intelligence handlers are reportedly assigning collection tasks to recruits directly via Telegram, including during ambulance shifts, marking an escalation in operational tradecraft.

Top items

Themes

Driver-based defence evasion remains a live problem. The SilverFox update reinforces a pattern seen across multiple campaigns this year: attackers increasingly rely on legitimately signed but vulnerable kernel drivers to disable security tooling rather than writing custom rootkits. Restricting driver loading via WDAC or similar policies continues to be the most effective mitigation.

Messaging platforms as operational infrastructure. Telegram-based tasking by Iranian handlers echoes broader trends in platform-mediated recruitment and C2 — a pattern also visible in the Europol child-recruitment network reported last week. Securing or monitoring employee presence on consumer messaging platforms remains difficult but increasingly relevant for organisations in sensitive sectors.

Public exploits · latest from the exploit feed

ArcadeDB < 26.7.2 Cross-Database Authorization Bypass (IDOR) 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0-7.0.8 & 7.0-rc-7.0-rc7 - Use After Free Exploit 2026-08-02 15:45Z · RSS:cxsecurity-wlb MODX.3.2.1 TLS cookie without secure flag set - COOKIE PHPSESSID HIJACK 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0 DRM UAF LPE Exploit published for CVE-2026-46215 CVE-2026-46215 2026-07-22 14:05Z · CXSecurity / Exploit-DB (RSS) ZTE ZXHN H188A V6 Authentication Bypass 2026-07-22 13:28Z · RSS:cxsecurity-wlb OpenEMR 7.0.2 Arbitrary File Read 2026-07-22 13:28Z · RSS:cxsecurity-wlb PHP Link Directory (phpLD) 2.1.3 - SQL Injection, IDOR, CSRF 2026-07-22 13:28Z · RSS:cxsecurity-wlb KNX visualisering - Broken Access Control 2026-07-22 13:28Z · RSS:cxsecurity-wlb D-Link DSL2600U rom-0 Admin Password Disclosure 2026-07-22 13:28Z · RSS:cxsecurity-wlb Windows Defender (MsMpEng.exe) Race Condition -> LPE / SYSTEM / Use-After-Free -> Crash 2026-07-22 13:28Z · RSS:cxsecurity-wlb