This briefing covers the 24-hour period from July 5-6, 2026, revealing a significant volume of SQL injection vulnerabilities and active malware distribution campaigns. The period saw 30 high-severity CVEs published, predominantly SQL injection flaws in code-projects and SourceCodester applications with CVSS scores of 7.3-8.8. These vulnerabilities affect classroom management, hotel reservation, and real estate management systems, all exploitable remotely with public exploits available.
Malware distribution remains active with 50 URLhaus-listed indicators, primarily Mozi and Mirai botnet variants targeting IoT devices, alongside a sustained ClearFake campaign distributing malware across Windows and macOS platforms. Ten organizations were added to ransomware leak sites, led by the Genesis ransomware group claiming nine victims across healthcare, construction, and technology sectors. The Payload ransomware group listed Italian production company Vela Film S.r.l.
The threat landscape demonstrates continued exploitation of aging web applications with SQL injection vulnerabilities, persistent IoT botnet activity, and ongoing ransomware operations targeting mid-sized enterprises across multiple verticals. Organizations should prioritize patching web-facing applications, securing IoT infrastructure, and maintaining robust backup strategies.
30 high-severity SQL injection and code injection vulnerabilities published affecting multiple web applications
Stack-based buffer overflow in wireless configuration endpoint (/goform/ConfigWirelessBase_5g) via ssid parameter. CVSS 8.8, remotely exploitable with public exploit available.
Incorrect permission assignment and improper access control enabling DNS spoofing in Pardus-Parental-Control <=0.5.1. CVSS 8.8, affects TUBITAK BILGEM software.
Seven SQL injection vulnerabilities (CVE-2026-14772, CVE-2026-14771, CVE-2026-14770, CVE-2026-14734, CVE-2026-14733, CVE-2026-14732) affecting course, exam, room, and product management endpoints. All remotely exploitable with public exploits, CVSS 7.3.
Six SQL injection flaws (CVE-2026-14764, CVE-2026-14763, CVE-2026-14762, CVE-2026-14756, CVE-2026-14755, CVE-2026-14754) in event, tour, room, and reservation management. Remote exploitation possible with disclosed exploits, CVSS 7.3.
Code injection via eval function in calculate.php endpoint, manipulating mathematical_sentence parameter. Remotely exploitable, CVSS 7.3.
Missing authorization vulnerability in Pardus Update <=0.6.3 allows privilege escalation. CVSS 7.8.
Seven SQL injection vulnerabilities (CVE-2026-14769, CVE-2026-14768, CVE-2026-14747, CVE-2026-14746, CVE-2026-14745, CVE-2026-14744, CVE-2026-14743) across payment, property listing, and search functions. All CVSS 7.3 with remote exploitation.
Unrestricted upload vulnerability in user_auth_commit.php via upload_image parameter in Ruijie RG-UAC up to 1.0-R1.8.2.p5. CVSS 7.3, remote exploitation possible.
Code injection vulnerability in wiki worker component during Git repository import in tiddly-gittly TidGi-Desktop <=0.13.0. CVSS 7.3, remotely exploitable.
50 malicious URLs identified distributing Mozi, Mirai, and ClearFake malware families targeting IoT devices and end-user systems
35+ URLs distributing Mozi malware variants (32-bit ELF, MIPS, ARM) targeting IoT devices. Infrastructure includes compromised devices across Asian ISPs (IP ranges: 42.x.x.x, 115.x.x.x, 182.x.x.x, 125.x.x.x). Malware distributed via bin.sh and /i endpoints.
Multiple Mirai distribution URLs targeting ARM and MIPS architectures. Notable infrastructure includes 196.190.1.39:39487, 46.151.182.239 (also distributing update.exe), and various compromised Asian IP addresses. Both shell scripts and compiled binaries being distributed.
Active ClearFake malware distribution targeting Windows and macOS via compromised domains (bet303.poker, ketab.blog, 90pishbini.com, betiran.vip, ac90bet.com/net/org, fidoubet.com, bet1forward.com, btyek.christmas). Multiple variants identified (win-0x4679, win-0xa770, mac-0x68dc, mac-0x76c7, mac-0xfb64) indicating ongoing development.
Infrastructure at 2.26.75.58 distributing payload.sh and loader.sh specifically targeting macOS systems. Scripts located at /payload.sh, /loader.sh, and /debug/loader.sh endpoints.
Additional distribution servers at 31.77.189.52/tr and 46.151.182.239 (update.exe, bot binary) supporting various malware campaigns including Mirai infrastructure.
Ten organizations added to ransomware leak sites, predominantly by Genesis ransomware group across healthcare, construction, and business services sectors
Italian production company specializing in cinema and television (Rome-based). Known for TV series 'La porta rossa' and 'Volevo fare la rockstar'. Listed by Payload ransomware group on July 5, 2026.
Two healthcare organizations compromised: Mirage Endoscopy Center (mirageendoscopycenter.com) and East Texas Family Medicine (etfmed.com). Both added July 5 by Genesis group, potentially exposing protected health information (PHI).
Three construction/contracting firms listed: DICON (dicon.com - general contracting), Westgate (westgatellc.com - construction management), and Dunagan Associates (dunaganassociates.com - residential real estate/insurance). All Genesis victims from July 5.
Four business/technology organizations: Apex Agro LLC (apexagchem.com - chemical production), Bri-Tech Inc (bri-tech.com - technology integration), SBI Software (sbigrower.com - ERP provider), and Synergy Interactive (sinyc.com - staffing services). Genesis group claims from July 5.
Flipper Devices announces shift to community-driven firmware development model
Flipper Devices transitioning to smaller internal team with increased reliance on community contributions for Flipper Zero firmware development. Represents shift in development model for popular security research tool.
These briefings are compiled from publicly available threat-intelligence feeds, which may include CISA KEV, NIST NVD, the GitHub Advisory Database (OSV), abuse.ch, and Wordfence Intelligence. Data-breach and credential-leak items may include data from Have I Been Pwned and ransomware.live.
CVE® is a registered trademark of The MITRE Corporation. CVE Records are © The MITRE Corporation, reproduced under the CVE Program Terms of Use. WordPress vulnerability data is provided by Wordfence Intelligence, © Defiant, Inc. Breach data from Have I Been Pwned is licensed under CC BY 4.0.