The 48-hour period from July 12-13, 2026 reveals a concerning surge in critical vulnerabilities alongside persistent botnet and ransomware activity. Seven CRITICAL-severity CVEs were disclosed, including authentication bypasses in Flowise (CVE-2026-56271) using hardcoded JWT secrets and arbitrary file write vulnerabilities in Crawl4AI (CVE-2026-56260). The vulnerability landscape is dominated by OpenWrt/LuCI cross-site scripting flaws and embedded device command injection issues affecting TRENDnet and Comfast routers.
Malware distribution infrastructure remains highly active with 51 malicious URLs identified, primarily distributing Mozi botnet variants and ClearFake/ClickFix campaign payloads targeting both Windows and macOS systems. The ClearFake operation demonstrates sophisticated multi-platform targeting with AppleScript-based infostealers (SHub-Stealer) alongside traditional Windows delivery mechanisms. Mozi botnet continues exploiting IoT devices across Asian IP ranges, with ELF binaries targeting MIPS and ARM architectures.
Ransomware operations intensified with seven new victim disclosures across DragonForce, M3RX, and Titan groups. Notable victims include Al-Saidi Factory and STEP Oiltools (DragonForce), indicating continued targeting of industrial and energy sector organizations. The South Korean military reported nearly 19,000 cyberattack attempts in 2025, marking a five-year high and highlighting sustained nation-state interest in military networks.
Seven CRITICAL-severity and sixteen HIGH-severity CVEs disclosed, with authentication bypasses and remote code execution flaws across enterprise and embedded systems
Flowise versions prior to 3.1.0 ship with weak hardcoded JWT secrets ('auth_token', 'refresh_token') in enterprise passport middleware, enabling attackers to forge authentication tokens and bypass security controls entirely. CVSS 9.8 CRITICAL.
Crawl4AI before 0.8.7 allows unauthenticated attackers to write arbitrary files to any filesystem location via unvalidated output_path parameters in Docker API /screenshot and /pdf endpoints. CVSS 9.1 CRITICAL - enables complete system compromise.
Critical command injection in Comfast CF-WR631AX firmware affecting system_wl_upload_pic_file function. Remote attackers can execute arbitrary OS commands via filename parameter manipulation. CVSS 9.8 CRITICAL.
LuCI fails to encode DHCPv6 lease hostnames before rendering, allowing adjacent network attackers to inject malicious HTML/JavaScript via DHCPv6 Client FQDN fields. Executes in administrator browser context. CVSS 8.8 HIGH.
OpenWrt luci-app-upnp allows unauthenticated LAN clients to inject stored XSS payloads through UPnP IGD AddPortMapping SOAP requests, which execute when administrators view DHCP lease pages. CVSS 8.8 HIGH.
LuCI Samba4 read ACL grants file.exec on /usr/sbin/smbd, allowing authenticated users to launch Samba daemon with attacker-controlled arguments including 'message command' for root code execution. CVSS 8.8 HIGH.
Unauthenticated attackers can redirect LLM API calls to attacker-controlled endpoints and read arbitrary environment variables through Crawl4AI /md, /llm, and /llm/job endpoints, enabling credential theft. CVSS 8.2 HIGH.
Chromium-based Microsoft Edge contains untrusted pointer dereference vulnerability allowing network-based attackers to elevate privileges. CVSS 8.3 HIGH - affects all Edge users.
51 malicious URLs identified distributing Mozi botnet, ClearFake, ClickFix, and SHub-Stealer targeting IoT devices and desktop platforms
Widespread ClearFake operation delivering platform-specific payloads via fake browser update prompts. Targets include Windows (win-0x4679, win-0x0cd5) and macOS (mac-0x68dc, mac-0x76c7, mac-0xfb64) variants across jadoou[.]club, bekabet[.]casino, and bet90forward[.]win infrastructure.
SHub-Stealer infostealer delivered via ClickFix social engineering on exptersed[.]com, using AppleScript payloads (payload.applescript, loader.sh) to compromise macOS systems. Also leverages WebDAV rundll32 techniques with fake CAPTCHA prompts.
37 URLs distributing Mozi botnet ELF binaries targeting MIPS and ARM architectures across Chinese IP ranges. Payloads delivered via /bin.sh and /i endpoints on compromised IoT devices, indicating active exploitation of router and embedded system vulnerabilities.
New RedHook variant exploits Android Wireless Debugging (Wireless ADB) mechanism to gain shell-level privileges without requiring physical computer connection, representing novel persistence technique for Android banking trojans.
New Mirai distribution campaign from 94.154.43.42 serving ar15.x86 ELF binaries through multiple paths (/hiddenbin/, /bins/, /bin/, root). Additional ARM-based Mirai samples from igmc.ddns.net targeting ar15.arm5 architecture.
C2 monitoring detected Amadey loader activity dropping MSI payloads from 91.92.242.236, indicating ongoing botnet operations with modular malware delivery capabilities.
Sustained cyber operations targeting military infrastructure with nearly 19,000 attempts against South Korean defense networks
South Korean military targeted in 18,951 cyberattack attempts during 2025, marking the highest figure in five years and representing 62% increase from 2021 baseline of 11,700 attempts. Indicates sustained nation-state interest in military networks and critical defense infrastructure.
Seven organizations publicly listed by DragonForce, M3RX, and Titan ransomware groups spanning industrial, energy, hospitality, and construction sectors
Al-Saidi Trading and Industry, a prominent Middle East chemical and logistics provider, listed on DragonForce leak site. Company offers supply chain management and freight forwarding services across the region.
Global solids control and drilling waste management provider serving oil/gas and civil engineering industries targeted. STEP Oiltools operates across multiple international markets with specialized equipment and services.
Ireland's largest hospitality group compromised by M3RX ransomware. Eclective operates diverse hospitality and lifestyle brands across multiple venues in Dublin and nationwide.
FORECON Inc., specializing in forest management and rural brokerage services across New York, Pennsylvania, and West Virginia since 1954, added to M3RX victim list. Services include due diligence, appraisal, and analytics.
M3RX group lists WRT World Enterprises, a major purchasing and logistics provider for Latin American retailers offering supply chain management, shipping, and vendor services.
Titan ransomware group claims Cooperate Service CZ (Czech Republic) and Eureka Construction INC as victims, expanding their targeting of construction and service sector organizations.
Multiple command injection and buffer overflow vulnerabilities in TRENDnet and other embedded devices enabling remote code execution
Two buffer overflow vulnerabilities (CVE-2026-15484, CVE-2026-15483) in TRENDnet TEW-821DAP firmware v1.12B01 affecting /goform/tools_nslookup endpoint. Vendor unable to confirm vulnerability as product reached end-of-support. CVSS 8.8 HIGH.
Critical vulnerabilities in TEW-635BRM v1.00.03 enable remote command injection via ipoa_ipaddr parameter (CVE-2026-15481) and stack-based buffer overflow through device_name argument (CVE-2026-15480). Public exploits available. CVSS 8.8 HIGH.
H3C NX15 router firmware V100R017 allows weak password recovery through /api/login/modify endpoint's change_passwd function, enabling attackers to reset administrator credentials. CVSS 7.3 HIGH.
Multiple authentication, privilege escalation, and information disclosure vulnerabilities in Capgo, Zephyr RTOS, and web applications
CVE-2026-56313: Capgo before 12.128.2 allows enterprise admins to delete password identities of users in foreign organizations via SSO prelink endpoint, enabling cross-tenant attacks. CVSS 8.1 HIGH.
CVE-2026-56308: Email address changes in Capgo (pre-12.128.2) require no password verification, allowing session hijackers to permanently compromise accounts through recovery mechanism abuse. CVSS 7.3 HIGH.
CVE-2026-56241: Demoted super_admin users retain access to delete_non_compliant_bundles and count_non_compliant_bundles RPCs due to stale org_users.user_right column, enabling privilege re-escalation. CVSS 8.3 HIGH.
Three vulnerabilities in Zephyr RTOS: heap buffer overflow in obj_list iteration (CVE-2026-10667), stack buffer overflow in IPv4 parsing (CVE-2026-10666), and WireGuard buffer overflow (CVE-2026-10665). Enable DoS and potential code execution. CVSS 7.4-7.8 HIGH.
CVE-2026-56238: Supabase PostgREST global_stats endpoint exposes sensitive financial and operational metrics to unauthenticated attackers using only public apikey. CVSS 7.5 HIGH.
These briefings are compiled from publicly available threat-intelligence feeds, which may include CISA KEV, NIST NVD, the GitHub Advisory Database (OSV), abuse.ch, and Wordfence Intelligence. Data-breach and credential-leak items may include data from Have I Been Pwned and ransomware.live.
CVE® is a registered trademark of The MITRE Corporation. CVE Records are © The MITRE Corporation, reproduced under the CVE Program Terms of Use. WordPress vulnerability data is provided by Wordfence Intelligence, © Defiant, Inc. Breach data from Have I Been Pwned is licensed under CC BY 4.0.