Jul 20, 2026 · Covering Jul 13, 2026 – Jul 19, 2026

This Week in Threats: July 13–July 19, 2026

Critical vulnerabilities in NGINX, WordPress, and OpenSSL exploited in the wild; supply chain attacks target RubyGems and npm; APT actors target government and critical infrastructure.

weekly-reportTetrisPhantomVICEROY TIGERInception FrameworkEarth LamiaKeksec

Overview

This week saw active exploitation of critical vulnerabilities in widely used software including NGINX, WordPress, and OpenSSL, alongside multiple supply chain attacks targeting developer ecosystems. Threat actors leveraged zero-days in SonicWall and SharePoint, while new malware campaigns targeted government and enterprise networks. Patching urgency was emphasized across multiple platforms due to public exploits and active intrusions.

Active Threat Actors

UAC-0145, a Russian state-sponsored threat actor affiliated with GRU, conducted cyberattacks against Ukrainian targets using the ClickFix social engineering technique, injecting fake CAPTCHA prompts to execute malicious PowerShell commands and deploy malware such as GHETTOVIBE, SCOUTCURL, and COWARDDUCK UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware. A previously undocumented actor tracked as UTA0533 exploited two zero-day vulnerabilities in SonicWall SMA 1000 series appliances to gain root access and deploy custom malware and web shells SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access. CylindricalCanine, linked to GoldenEyeDog (APT-Q-27), was responsible for a breach at DigiCert in April 2026, compromising support analysts via a malicious .scr file and stealing code-signing certificates used to sign Zhong Stealer and Golden Gh0st RAT GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft. Earth Lamia, a China-nexus APT, targeted organizations in Latin America, the Middle East, and Southeast Asia, exploiting web application vulnerabilities and deploying backdoors such as PULSEPACK and BypassBoss Hackers abuse ViPNet software to target Russian govt agencies. TIDRONE, linked to Chinese-speaking groups, targeted drone manufacturers in Taiwan through ERP software and remote desktops using advanced malware variants CXCLNT and CLNTEND Hackers abuse ViPNet software to target Russian govt agencies. UNC6040, a financially motivated cluster, used vishing to access Salesforce environments and exfiltrate data, later moving laterally to Okta and Microsoft 365 Microsoft warns of surge in ACR Stealer attacks on customers.

Notable Malware

ACR Stealer, an infostealer delivered via social engineering lures such as fake Claude AI assistant pages and malvertising, stole browser credentials, session tokens, and sensitive files from Microsoft 365, OneDrive, and SharePoint using obfuscated PowerShell scripts and steganographic images ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files. Remcos, a remote access trojan, was deployed as part of a multi-stage malware chain delivered through a malicious Go module that leveraged 222 GitHub repositories to distribute deceptive software projects Malicious Go Module Exposes GitHub Malware Lure Network Spanning 222 Repositories. Vidar, an information stealer, was included in the same campaign, targeting credentials, clipboard data, and cryptocurrency wallets Malicious Go Module Exposes GitHub Malware Lure Network Spanning 222 Repositories. GoSerpent, a previously undocumented malware, was used in espionage campaigns targeting Southeast Asian governments and diplomatic entities since late 2025, enabling credential dumping and data exfiltration using tools like Mimikatz and QuarksDumpLocalHash New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage. ClickLock, a new macOS malware, used fake authentication dialogs to trick users into revealing login passwords, establishing persistence via LaunchAgents and exfiltrating data through Telegram New ClickLock macOS malware traps users into revealing login password. OtterCookie malware was distributed via fake coding challenges targeting software developers, hiding steganographic payloads in SVG images to steal browser credentials and cryptocurrency wallets Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images.

Key CVEs & Campaigns

CVE-2026-42533, a critical heap buffer overflow vulnerability in NGINX, allows unauthenticated attackers to trigger denial of service or remote code execution via crafted HTTP requests, particularly under configurations involving regex-based maps and capture overwrites; F5 has released patches, but downstream products remain unpatched Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution. CVE-2026-63030 and CVE-2026-60137, collectively known as ‘wp2shell’, are critical unauthenticated remote code execution vulnerabilities in WordPress Core affecting versions 6.9.0–6.9.4 and 7.0.0–7.0.1, stemming from a REST API batch-route confusion and SQL injection flaw, now under active exploitation WordPress Core “wp2shell” RCE flaws get public exploits, patch now. CVE-2026-15409 and CVE-2026-15410 were exploited in the wild before disclosure to achieve arbitrary command execution and root access on SonicWall SMA 1000 series appliances SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access. CVE-2026-58644, an actively exploited SharePoint Server remote code execution zero-day, allows authenticated attackers with Site Owner privileges to execute arbitrary code and has been added to CISA’s Known Exploited Vulnerabilities catalog CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV. CVE-2026-39808 and CVE-2026-25089, critical unauthenticated remote code execution flaws in Fortinet’s FortiSandbox, are under active exploitation, prompting CISA to mandate patching by July 19 CISA urges immediate action on actively exploited Fortinet flaws. The HollowByte flaw in OpenSSL, patched without a CVE or advisory, allows denial-of-service via 11-byte TLS handshake requests that cause memory exhaustion due to unvalidated message length fields OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests. CVE-2026-15409 and CVE-2026-15410 were exploited in the wild before disclosure to achieve arbitrary command execution and root access on SonicWall SMA 1000 series appliances SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access. The SleeperGem campaign compromised three RubyGems packages—git_credential_manager, Dendreo, and fastlane-plugin-run_tests_firebase_testlab—installing a persistent backdoor on developer machines by downloading payloads from a Forgejo instance SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor. The ViteVenom campaign targeted the Vite JavaScript ecosystem via seven malicious npm packages using a blockchain-based C2 infrastructure across Tron, Aptos, and Binance Smart Chain to deliver a remote access trojan Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT. The AsyncAPI supply chain attack compromised four npm packages under the @asyncapi namespace via a malicious pull request that stole credentials, leading to credential exfiltration and persistence via IDE hooks Compromised AsyncAPI npm packages: inside a CI supply-chain attack.

Sources