This 24-hour period (2026-07-25 to 2026-07-26) saw significant threat activity across multiple vectors. Critical vulnerabilities emerged in widely-used software including a CVSS 10.0 authorization bypass in SiYuan (CVE-2026-66012) and high-severity flaws in WPForms Pro, Knot Resolver, and Redis that enable remote code execution and arbitrary file upload. Gaming communities face targeted ClickFix social engineering attacks deploying XMRig cryptominers through Steam forums, while a massive malvertising campaign leverages JavaScript to assemble malware directly in browser memory. Ransomware operators remained highly active with 24 new victim disclosures, led by Deadlock (11 victims) and Qilin (7 victims) targeting organizations across manufacturing, healthcare, transportation, and critical infrastructure sectors. The ShinyHunters breach data is now being weaponized in sextortion campaigns demanding $2,000 in Bitcoin. Malware distribution infrastructure shows continued Amadey botnet activity and widespread mobile APK campaigns, alongside infostealer operations (Stealc, SalatStealer) and remote access trojans (RemcosRAT).
Organizations should prioritize patching the critical SiYuan vulnerability and other disclosed CVEs immediately. Security teams must enhance user awareness around ClickFix attacks and social engineering tactics, particularly in gaming and financial contexts. The combination of active exploitation, credential theft weaponization, and sustained ransomware campaigns indicates a heightened threat environment requiring increased defensive posture across all sectors.
Four high-impact vulnerabilities disclosed, including a critical CVSS 10.0 authorization bypass and multiple remote code execution flaws
SiYuan versions before v3.7.2 contain a missing authorization vulnerability in the POST /mcp kernel endpoint exposing 31 MCP tools with file manipulation capabilities (list/read/write/delete/rename/copy). Only gated by general auth check with no admin-role enforcement. CVSS 10.0 CRITICAL severity demands immediate patching.
WPForms Pro plugin for WordPress versions up to 1.10.1.1 vulnerable to arbitrary file upload via ajax_chunk_upload_finalize function. File type validation occurs after chunk metadata and contents already written to disk. CVSS 8.1 HIGH severity enables web shell deployment.
Knot Resolver before 6.4.1 allows remote code execution via heap-based buffer overflow in DoQ (DNS-over-QUIC) receive path. CVSS 8.1 HIGH severity affects DNS infrastructure. Patch immediately to version 6.4.1 or later.
Redis before 8.8.0 vulnerable to RCE when authenticated attacker can execute RESTORE command. Exploitation through RESTORE payload where same NACK is referenced by multiple consumers, causing double free when consumers deleted via XGROUP DELCONSUMER. CVSS 7.5 HIGH severity.
Multiple malware families being distributed including cryptominers, infostealers, RATs, and mobile malware via ClickFix attacks, malvertising, and compromised infrastructure
Steam discussion forums exploited in ClickFix social engineering attacks disguising XMRig cryptominers as fixes for game/computer problems. Attackers post malicious 'solutions' that trick users into executing PowerShell commands to download and install miners.
Massive malvertising campaign uses fake Solana, Luno, and TradingView pages with malicious JavaScript that instructs browsers to assemble malware directly in memory. Fileless technique evades traditional detection by never writing malicious files to disk.
Multiple malware download URLs on 91.92.242.236 distributing payloads tagged as 'dropped-by-amadey'. Amadey is a botnet/loader typically used to deploy secondary payloads including stealers, miners, and ransomware. Five distinct files observed.
Active distribution of SalatStealer (193.221.200.26:5001) and Stealc/StealcV2 (konterlink.hippamsas.com) infostealers. These credential theft malware families target browser passwords, cryptocurrency wallets, and authentication tokens.
RemcosRAT remote access trojan being distributed via GuLoader from Google Drive and customcreationsmaine.com. GuLoader is a sophisticated shellcode-based downloader using anti-analysis techniques. RemcosRAT provides full remote control capabilities.
Domain semprecardsecure.com hosting 20 different APK variants (variant_01.apk through variant_20.apk), likely targeting financial/banking applications. Multiple variants suggest evasion attempts or targeted delivery for different device configurations.
ClickFix payloads distributed from 158.94.211.92 with geofencing (CHE, ua-ps tags) indicating Swiss and Ukrainian targeting. PowerShell-based delivery mechanism consistent with broader ClickFix campaign tactics.
Multiple ELF binaries for different architectures (ARM, ARM7, MPSL) distributed from 205.237.110.232 and 129.121.114.124, consistent with Mirai botnet propagation targeting IoT devices and Linux systems.
24 new ransomware victims disclosed across multiple threat groups, plus credential theft data being weaponized in sextortion campaigns
Deadlock ransomware group disclosed 11 new victims including critical infrastructure (KeNHA - Kenya National Highways Authority), manufacturing (HİDROMEK heavy machinery, Enedo Power systems), healthcare research (BioResearch clinical trials), and logistics (Carrier AB, Relesa). Geographic spread across Europe, Middle East, Africa, and Latin America.
Qilin ransomware group listed 7 victims including manufacturing (Guntert & Zimmerman construction equipment, Myers Y Cooper), healthcare (Principle Diagnostics Laboratory), critical infrastructure (Plitvička Jezera National Park), and sealing technology (GURR Abdichtungstechnik). Multi-sector targeting across US and Europe.
Principle Diagnostics Laboratory, a clinical diagnostics company, compromised by Qilin ransomware. Healthcare sector breaches pose elevated risk due to potential exposure of protected health information (PHI) and patient records.
Securotrop ransomware group claims compromise of Advantage Sintered Metals with 503 GB of data exfiltrated. Large data volume suggests extensive intellectual property, manufacturing processes, and business records stolen.
Six additional ransomware groups disclosed victims: Nova (SistNet IT services), Kairos (Thermalex aluminum extrusion), Blackwater (MSGas Brazil), Bravox (A&A Safety), MoneyMessage (Yourway Transportation), TheGentlemen (Advanced Marketing Mexico). Diverse targeting across IT, manufacturing, energy, transportation, and publishing sectors.
Threat actors using email addresses from ShinyHunters data breaches to send sextortion emails demanding $2,000 in Bitcoin. Emails falsely claim attackers have compromising information. Demonstrates secondary exploitation of previously leaked credentials.
Pope-endorsed prayer app Click to Pray leaked users' names and email addresses for months or longer. While not a traditional breach, unsecured data exposure affects hundreds of thousands globally and enables phishing/social engineering attacks.
NSW Health employee (registered nurse) charged after allegedly accessing and downloading patient information without authorization. Insider threat case highlighting healthcare data protection challenges.
Social engineering attacks leveraging ClickFix methodology and advanced evasion through in-memory malware assembly
Advanced evasion technique uses browser JavaScript to assemble malware directly in memory, avoiding disk writes that trigger AV/EDR detection. Malvertising campaign demonstrates increasing sophistication in delivery mechanisms and anti-analysis capabilities.
ClickFix attacks abuse trusted platforms (Steam forums) to social engineer users into executing malicious PowerShell commands disguised as technical fixes. Technique exploits user trust in community support forums and bypasses traditional email-based phishing detection.
US House extends critical cyberthreat information sharing legislation for 10 years
US House of Representatives voted to extend key cyberthreat information sharing law for another decade, attached to the $1.15 trillion FY2027 National Defense Authorization Act. Extension ensures continued public-private sector threat intelligence collaboration framework through 2036.
These briefings are compiled from publicly available threat-intelligence feeds, which may include CISA KEV, NIST NVD, the GitHub Advisory Database (OSV), abuse.ch, and Wordfence Intelligence. Data-breach and credential-leak items may include data from Have I Been Pwned and ransomware.live.
CVE® is a registered trademark of The MITRE Corporation. CVE Records are © The MITRE Corporation, reproduced under the CVE Program Terms of Use. WordPress vulnerability data is provided by Wordfence Intelligence, © Defiant, Inc. Breach data from Have I Been Pwned is licensed under CC BY 4.0.