Jul 20, 2026 · Covering Jul 13, 2026 – Jul 19, 2026
This Week in Threats: July 13–July 19, 2026
Critical vulnerabilities in NGINX, WordPress, and OpenSSL exploited in the wild; supply chain attacks target RubyGems and npm; APT actors target government and critical infrastructure.
Overview
This week saw active exploitation of critical vulnerabilities in widely used software including NGINX, WordPress, and OpenSSL, alongside multiple supply chain attacks targeting developer ecosystems. Threat actors leveraged zero-days in SonicWall and SharePoint, while new malware campaigns targeted government and enterprise networks. Patching urgency was emphasized across multiple platforms due to public exploits and active intrusions.
Active Threat Actors
UAC-0145, a Russian state-sponsored threat actor affiliated with GRU, conducted cyberattacks against Ukrainian targets using the ClickFix social engineering technique, injecting fake CAPTCHA prompts to execute malicious PowerShell commands and deploy malware such as GHETTOVIBE, SCOUTCURL, and COWARDDUCK UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware. A previously undocumented actor tracked as UTA0533 exploited two zero-day vulnerabilities in SonicWall SMA 1000 series appliances to gain root access and deploy custom malware and web shells SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access. CylindricalCanine, linked to GoldenEyeDog (APT-Q-27), was responsible for a breach at DigiCert in April 2026, compromising support analysts via a malicious .scr file and stealing code-signing certificates used to sign Zhong Stealer and Golden Gh0st RAT GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft. Earth Lamia, a China-nexus APT, targeted organizations in Latin America, the Middle East, and Southeast Asia, exploiting web application vulnerabilities and deploying backdoors such as PULSEPACK and BypassBoss Hackers abuse ViPNet software to target Russian govt agencies. TIDRONE, linked to Chinese-speaking groups, targeted drone manufacturers in Taiwan through ERP software and remote desktops using advanced malware variants CXCLNT and CLNTEND Hackers abuse ViPNet software to target Russian govt agencies. UNC6040, a financially motivated cluster, used vishing to access Salesforce environments and exfiltrate data, later moving laterally to Okta and Microsoft 365 Microsoft warns of surge in ACR Stealer attacks on customers.
Notable Malware
ACR Stealer, an infostealer delivered via social engineering lures such as fake Claude AI assistant pages and malvertising, stole browser credentials, session tokens, and sensitive files from Microsoft 365, OneDrive, and SharePoint using obfuscated PowerShell scripts and steganographic images ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files. Remcos, a remote access trojan, was deployed as part of a multi-stage malware chain delivered through a malicious Go module that leveraged 222 GitHub repositories to distribute deceptive software projects Malicious Go Module Exposes GitHub Malware Lure Network Spanning 222 Repositories. Vidar, an information stealer, was included in the same campaign, targeting credentials, clipboard data, and cryptocurrency wallets Malicious Go Module Exposes GitHub Malware Lure Network Spanning 222 Repositories. GoSerpent, a previously undocumented malware, was used in espionage campaigns targeting Southeast Asian governments and diplomatic entities since late 2025, enabling credential dumping and data exfiltration using tools like Mimikatz and QuarksDumpLocalHash New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage. ClickLock, a new macOS malware, used fake authentication dialogs to trick users into revealing login passwords, establishing persistence via LaunchAgents and exfiltrating data through Telegram New ClickLock macOS malware traps users into revealing login password. OtterCookie malware was distributed via fake coding challenges targeting software developers, hiding steganographic payloads in SVG images to steal browser credentials and cryptocurrency wallets Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images.
Key CVEs & Campaigns
CVE-2026-42533, a critical heap buffer overflow vulnerability in NGINX, allows unauthenticated attackers to trigger denial of service or remote code execution via crafted HTTP requests, particularly under configurations involving regex-based maps and capture overwrites; F5 has released patches, but downstream products remain unpatched Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution. CVE-2026-63030 and CVE-2026-60137, collectively known as ‘wp2shell’, are critical unauthenticated remote code execution vulnerabilities in WordPress Core affecting versions 6.9.0–6.9.4 and 7.0.0–7.0.1, stemming from a REST API batch-route confusion and SQL injection flaw, now under active exploitation WordPress Core “wp2shell” RCE flaws get public exploits, patch now. CVE-2026-15409 and CVE-2026-15410 were exploited in the wild before disclosure to achieve arbitrary command execution and root access on SonicWall SMA 1000 series appliances SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access. CVE-2026-58644, an actively exploited SharePoint Server remote code execution zero-day, allows authenticated attackers with Site Owner privileges to execute arbitrary code and has been added to CISA’s Known Exploited Vulnerabilities catalog CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV. CVE-2026-39808 and CVE-2026-25089, critical unauthenticated remote code execution flaws in Fortinet’s FortiSandbox, are under active exploitation, prompting CISA to mandate patching by July 19 CISA urges immediate action on actively exploited Fortinet flaws. The HollowByte flaw in OpenSSL, patched without a CVE or advisory, allows denial-of-service via 11-byte TLS handshake requests that cause memory exhaustion due to unvalidated message length fields OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests. CVE-2026-15409 and CVE-2026-15410 were exploited in the wild before disclosure to achieve arbitrary command execution and root access on SonicWall SMA 1000 series appliances SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access. The SleeperGem campaign compromised three RubyGems packages—git_credential_manager, Dendreo, and fastlane-plugin-run_tests_firebase_testlab—installing a persistent backdoor on developer machines by downloading payloads from a Forgejo instance SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor. The ViteVenom campaign targeted the Vite JavaScript ecosystem via seven malicious npm packages using a blockchain-based C2 infrastructure across Tron, Aptos, and Binance Smart Chain to deliver a remote access trojan Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT. The AsyncAPI supply chain attack compromised four npm packages under the @asyncapi namespace via a malicious pull request that stole credentials, leading to credential exfiltration and persistence via IDE hooks Compromised AsyncAPI npm packages: inside a CI supply-chain attack.
Sources
- Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution — hacker-news
- SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor — step-security
- SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access — hacker-news
- UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware — hacker-news
- Hackers abuse ViPNet software to target Russian govt agencies — bleeping-computer
- Update now: 7-Zip fixes RCE flaw exploitable with malicious archives — bleeping-computer
- WordPress Core “wp2shell” RCE flaws get public exploits, patch now — bleeping-computer
- Microsoft warns of surge in ACR Stealer attacks on customers — bleeping-computer
- The Future of Age Verification: Your Face Never Leaves Your Device — bleeping-computer
- Compromised AsyncAPI npm packages: inside a CI supply-chain attack — datadog-security-labs
- Malicious Go Module Exposes GitHub Malware Lure Network Spanning 222 Repositories — socket-dev
- White House Launches Gold Eagle Initiative to Manage Surge in AI-Discovered Vulnerabilities — socket-dev
- New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code — hacker-news
- OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests — hacker-news
- Abbott Laboratories probes two cyber incidents amid extortion claims — bleeping-computer
- Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT — hacker-news
- HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload — bleeping-computer
- GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft — hacker-news
- New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens — hacker-news
- Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images — hacker-news
- Inside the Search for “Clean” Residential Proxies for Carding — bleeping-computer
- Ernst & Young discloses data breach after support system hack — bleeping-computer
- M-Red-Team: AsyncAPI Supply Chain Compromise via GitHub Actions — wiz
- Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy — unit42
- New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage — hacker-news
- ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files — hacker-news
- Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man — hacker-news
- The Race to Field Military Autonomy Is On, Can Trusted Information Infrastructure Keep Pace? — hacker-news
- E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants — hacker-news
- New Windows LegacyHive zero-day gives hackers admin privileges — bleeping-computer
- CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV — hacker-news
- CISA urges immediate action on actively exploited Fortinet flaws — bleeping-computer
- US charges two over laundering $43 million from investment fraud — bleeping-computer
- Windows Server 2022 reach end of mainstream support in 90 days — bleeping-computer
- AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report — unit42
- New ClickLock macOS malware traps users into revealing login password — bleeping-computer
- Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack — hacker-news
- Claude Chrome extension flaw lets malicious extensions trigger AI actions — bleeping-computer
- Coca-Cola says Fairlife ransomware attack halts US dairy production — bleeping-computer