This briefing covers significant threats observed between July 3-4, 2026, highlighted by a landmark incident involving the first documented fully autonomous AI-driven cyber attack executed without human oversight. Critical vulnerabilities dominate the landscape with 2 CRITICAL-severity CVEs (CVE-2026-58426 affecting Gitea and CVE-2026-58289 in Microsoft Edge) alongside 28 HIGH-severity vulnerabilities primarily targeting Microsoft Edge. The Moody Bible Institute breach exposed 2.3 million records in a ShinyHunters extortion campaign, while eight additional ransomware incidents targeted organizations across manufacturing, government, and retail sectors. Infrastructure disruption efforts achieved a major success with the takedown of the NetNut proxy network, severing access to 2 million compromised Android devices. Malware distribution remains active with 50 URLs distributing Mozi botnet, Mirai variants, ClearFake, Gafgyt, and Stealc payloads.
Phishing-as-a-Service platforms continue evolving, with the ARToken platform exposing EvilTokens' comprehensive Microsoft 365 compromise toolkit. Social engineering tactics are increasingly preferred over technical exploits, evidenced by verified X (Twitter) ads distributing macOS malware and ConsentFix campaigns targeting Microsoft accounts. The emergence of advanced Chinese LLMs capable of competing with Western frontier models raises concerns about asymmetric advantages for threat actors. Organizations should prioritize patching the two critical CVEs immediately, review Microsoft Edge deployments given the concentration of vulnerabilities, and strengthen authentication controls against sophisticated phishing campaigns.
Defensive priorities include monitoring for signs of AI-augmented attacks, implementing enhanced detection for PhaaS campaigns, and assessing exposure to proxy network abuse. The Moody Bible Institute breach underscores the continued effectiveness of extortion-based attacks against educational and nonprofit institutions.
Two CRITICAL-severity vulnerabilities and 28 HIGH-severity flaws identified, primarily affecting Microsoft Edge and Gitea platforms
CRITICAL (CVSS 9.6) vulnerability in Gitea allows signed URL HMAC ambiguity to facilitate unauthorized cross-repository artifact reads and cross-task upload-state writes. Affects Gitea CI/CD pipelines and artifact management.
CRITICAL (CVSS 9.0) type confusion vulnerability in Microsoft Edge (Chromium-based) permits unauthorized remote code execution over network. Represents highest severity among 30 Edge vulnerabilities disclosed this period.
HIGH (CVSS 8.9) vulnerability allows bypassing workflow approval gates in forked repository pull requests, enabling unauthorized code execution in CI/CD pipelines.
HIGH (CVSS 7.7) authentication bypass in Git LFS (Large File Storage) allows unauthorized read access to private repositories through malformed SSH sub-verb exploitation.
Mass disclosure of 28 HIGH-severity vulnerabilities (CVSS 7.1-8.8) affecting Microsoft Edge Chromium-based and Android versions. Vulnerabilities include multiple use-after-free flaws (CVE-2026-58294, CVE-2026-58288, CVE-2026-58287, CVE-2026-58276, CVE-2026-57992, CVE-2026-57986, CVE-2026-57984, CVE-2026-57981), type confusion issues, XSS, SSRF, information disclosure, and spoofing vectors. Broad attack surface requires urgent patching across enterprise browser deployments.
Major breach at Moody Bible Institute exposed 2.3M records via ShinyHunters extortion; 8 ransomware victims added to leak sites including government and manufacturing targets
Educational institution targeted in June 2026 pay-or-leak extortion resulted in public disclosure of 2,303,416 unique email addresses along with names, physical addresses, phone numbers, dates of birth, genders, and marital statuses. Data pertains to donors, students, and community members. ShinyHunters threat actor group responsible.
Municipal government of Oak Park (30,000 residents, Oakland County) compromised by IncRansom ransomware group. City government data published to leak site, potentially impacting resident records and municipal operations.
One of Switzerland's largest family-owned manufacturing businesses compromised by Anubis ransomware group. Data breach at critical industrial target with potential supply chain implications.
Hong Kong-based diversified conglomerate founded 1953 suffered March 2026 compromise encrypting 1.05M files affecting 920,000 customers and staff. Ransomware attack on established business enterprise with 73-year history.
Six additional organizations published to ransomware leak sites: Redeplast (Brazilian footwear, Blackfield group), Aydeniz Group (Turkish manufacturing, apt73), AC Beverage (draft beer services, pear group), CNW Electronics Singapore (wire harness, pear), MAJUHOME Malaysia (furniture retail, krybit), DUFLO Colombia (facility management, krybit). Multi-industry targeting across manufacturing, retail, and services sectors.
Major proxy botnet disruption, PhaaS platform exposure, and emergence of AI-driven autonomous attacks mark significant developments in threat actor capabilities and law enforcement response
Security researchers documented the first instance of an artificial intelligence agent executing a complete cyber attack from start to finish without any human assistance. Milestone represents significant escalation in AI-enabled offensive capabilities and automation of attack chains.
Joint operation involving Google dismantled NetNut residential proxy network providing access to millions of compromised Android devices including smart TVs and streaming boxes. Major infrastructure disruption removes significant cybercriminal resource for anonymization and distributed attacks.
Newly identified phishing-as-a-service platform ARToken operates as EvilTokens affiliate, revealing extensive toolkit designed specifically for Microsoft 365 compromise. Platform provides turnkey phishing infrastructure lowering barriers for credential theft campaigns.
Two new Chinese large language models compete with top US mainstream and frontier models, raising concerns about asymmetric advantages in AI-augmented offensive operations. Advanced language models enable more sophisticated social engineering, code generation, and automated vulnerability discovery.
Two campaigns demonstrate shift toward social engineering over exploit-based attacks. Verified Twitter/X advertisement delivers Mac malware while ConsentFix framework targets Microsoft account credentials. Abuse of platform verification badges and OAuth consent flows for initial access.
50 malicious URLs identified distributing Mozi botnet, Mirai variants, ClearFake, Gafgyt, Stealc, and Amadey payloads targeting IoT devices and endpoint systems
Over 40 URLs distributing Mozi botnet payloads targeting MIPS and ARM architectures. Malware primarily delivered via shell scripts (bin.sh) to compromise routers, smart TVs, and IoT devices. Mirai co-infections observed in several samples indicating multi-malware campaigns.
Six URLs identified delivering ClearFake malware targeting both Windows and macOS platforms via social engineering. Domains abuse various TLDs (.vip, .live, .pro, .com, .click) with hexadecimal UUID-based paths suggesting automated generation infrastructure.
Two executables (file_442596ff0102b558.exe, file_b333ba0349392594.exe) hosted on 91.92.242.236 delivering Stealc information stealer dropped by Amadey loader. Multi-stage infection chain with automated C2 monitoring indicators.
Multiple ELF binaries for Gafgyt botnet distributed from 141.11.88.113 using Sakura-themed filenames. Targets various architectures (ARM, MIPS, x86, SH4, i586, M68K, MPSL) with user-agent based wget delivery. DDoS botnet expansion campaign.
WordPress vulnerabilities, emerging AI offensive capabilities, and evolving social engineering techniques dominate tactical landscape
23 CVEs disclosed affecting WordPress plugins and themes, including 1 CRITICAL (CVE-2026-9725, CVSS 9.1) and 3 HIGH-severity flaws (CVE-2026-9148, CVE-2026-14352, CVE-2026-14327, CVE-2026-13040). Broad targeting of WordPress ecosystem continues with XSS, authentication bypass, and arbitrary file access vulnerabilities. Organizations running WordPress installations should prioritize updates.
These briefings are compiled from publicly available threat-intelligence feeds, which may include CISA KEV, NIST NVD, the GitHub Advisory Database (OSV), abuse.ch, and Wordfence Intelligence. Data-breach and credential-leak items may include data from Have I Been Pwned and ransomware.live.
CVE® is a registered trademark of The MITRE Corporation. CVE Records are © The MITRE Corporation, reproduced under the CVE Program Terms of Use. WordPress vulnerability data is provided by Wordfence Intelligence, © Defiant, Inc. Breach data from Have I Been Pwned is licensed under CC BY 4.0.