Cyber security developments for Monday the 20th of July 2026 covering articles added to the BlueTeamSec community on infosec.pub. Today we have 30 articles to cover. All attribution is by the article authors. All article analysis is automated.
VMRay researchers traced a RedLine Stealer command and control server back to a maritime-focused business email compromise campaign targeting Kangrim Heavy Industries, a South Korean marine boiler manufacturer. The operation used seven fraudulent domains and distributed Formbook and RedLine via attachments masquerading as shipping correspondence, with tradecraft overlapping with the Gold Galleon cluster.
Yahoo reports that Iran's Revolutionary Guard exploited the legacy signalling system seven protocol to track U.S. military personnel across the Middle East. The IRGC used legitimate telecom interconnect agreements to intercept location data, which was then used to guide missile strikes on at least seven American military installations including Al Udeid and Camp Arifjan.
South Korea's Financial Security Institute published an analysis of state-sponsored hacking organisations targeting cross-chain bridge infrastructure in the digital asset ecosystem. The report details attack techniques and money laundering methods used by nation-state actors exploiting vulnerabilities in protocols that facilitate asset transfers between blockchain networks.
OpenSourceMalware reports that the Lazarus Group has expanded the PolinRider campaign six and a half times since March. The operation uses a fork-and-pull-request supply chain attack strategy, where attackers create malicious forks of legitimate open-source repositories and submit pull requests containing obfuscated payloads to the original maintainers.
Sophos reports that sixty-seven percent of ransomware victims in 2025 experienced incidents tied to identity compromise, with compromised credentials now the dominant attack vector. Whilst median ransom demands dropped sixty-five percent to just under seven hundred thousand dollars, recovery costs excluding the ransom itself increased eleven percent to one point seven million, and ninety-nine percent of victims reported negative team impacts including leadership replacement in a fifth of cases.
The Organized Crime and Corruption Reporting Project uncovered that Passwork, a password manager marketed as European software, maintains obscured operational ties to its Russian origins and shares a development pipeline with a Russian entity certified by the FSB and FSTEC. The software is used by European government agencies including Irish government offices and Dresden University of Technology, creating a supply chain risk where vulnerabilities could be known to Russian state actors.
Graphika documents a novel tactic from Spamouflage, the Chinese state-linked influence operation also tracked as Dragonbridge. Between June and July this year, the campaign disseminated manipulated event flyers on Facebook and X to sabotage anti-CPC events, targeting organisations critical of the Chinese government including Safeguard Defenders and pro-Tibet advocacy groups. This represents an evolution toward visual disinformation as a tool for transnational repression.
Kaspersky describes the HelloNet campaign, an advanced persistent threat targeting large Russian organisations across critical sectors since May. The attackers exploit the legitimate ViPNet software update system through DLL sideloading to establish persistence and deploy malicious modules for reconnaissance and command execution within secure networks.
Zoom disclosed a critical improper input validation vulnerability in Zoom Workplace for Windows and VDI clients, scoring nine point eight on the CVSS scale. The flaw allows unauthenticated remote attackers to achieve full account takeover without user interaction. Patches are available in version seven point zero and later.
David Carliez discovered a local privilege escalation vulnerability in Windows UI Storage DLL that allows attackers to bypass UAC and escalate from a filtered administrator account to system privileges. The flaw exploited missing authorisation checks in the App Resolver Activation class, enabling attackers to hijack the settings URI handler. Microsoft patched it in the July updates.
And another elevation of privilege flaw, this time in the Windows TCP IP driver. A researcher discovered an integer overflow in the network driver's deserialisation function that allows attackers to bypass bounds checks and trigger out-of-bounds memory access. Also patched in July.
Searchlight Cyber and ZephrFish disclosed WP2Shell, a critical pre-authentication remote code execution vulnerability in WordPress core versions six point nine through six point nine point four and seven point zero through seven point zero point one. The exploit chain combines REST API batch request deserialisation with SQL injection to exfiltrate admin credentials, then achieves code execution via malicious plugin installation. Patches are available in six point nine point five and seven point zero point two.
Researchers demonstrate Bit2Watt, a novel cyber-physical attack where untrusted cloud tenants manipulate GPU workloads to generate high-frequency power modulations that destabilise electrical grids. The attack exploits GPUs as constant power loads to create harmonic distortion in data centre power infrastructure, particularly affecting systems with high inverter-based resource penetration. Standard monitoring tools lack the resolution to detect these transients.
Apache OpenMeetings versions five through nine contain a path traversal vulnerability allowing authenticated attackers with moderator rights to read arbitrary files from the server. Fixed in nine point one point zero. Exploitation requires moderator privileges in any room but can expose sensitive system files.
A Windows eleven kernel information disclosure flaw exposes a live kernel pointer in the desktop heap, accessible to any process regardless of privilege level or sandbox restrictions. The vulnerability enables attackers to bypass kernel address space layout randomisation for the session pool and calculate exact kernel addresses of sensitive objects, serving as a reliability multiplier for memory corruption exploits.
Volexity reports that in July, a threat actor exploited a zero-day chain in SonicWall Secure Mobile Access one thousand series appliances to gain root access and steal credentials. The exploit used server-side request forgery to access internal CouchDB, then leveraged path traversal for remote code execution. The campaign targeted appliances prior to public disclosure on July the fourteenth.
The Office of the Australian Information Commissioner published findings on a Qantas data breach from June last year affecting five point six seven million customers. The incident was a vishing attack targeting an overseas third-party contact centre agent who was manipulated into authorising a malicious third-party integration with the CRM platform. The commissioner concluded Qantas took reasonable steps to protect data and responded appropriately within two days of detection.
The SingGuard team at Ant Group released an open-source AI safety framework designed to secure agentic AI systems against operational threats including prompt injection, tool misuse, and data exfiltration. The framework uses dual-mode inference with fifty millisecond latency for real-time classification and generative reasoning to detect threats across one hundred and eighty-five risk variants. One for anyone deploying autonomous agents in production environments.
Instavm released Tarit, an open-source platform for running AI agent workloads in isolated microVMs using Firecracker hypervisor technology. The project implements hardware-virtualised isolation, jailer mechanisms for process containment, egress filtering with allowlists, and per-VM resource constraints to protect against untrusted AI agent execution risks.
Project Incantation is a defensive framework that uses adversarial honeydocuments to manipulate and detect unauthorised autonomous AI agents. The toolkit exploits language model-powered bots' reliance on contextual data by poisoning their context windows, preventing lateral movement by forcing agents to operate on a manipulated version of infrastructure.
Wojciech Reguła reports that macOS twenty-seven has introduced a new privacy protection mechanism that extends a security attribute to Library Application Support folders for specific non-sandboxed applications, primarily browsers and cryptocurrency wallets. This restricts access to sensitive application data even for users or processes with broader filesystem permissions.
The White House announced the Gold Eagle initiative, a centralised federal clearinghouse for accelerated cybersecurity vulnerability management. The programme coordinates federal agencies with private sector partners in critical infrastructure and open-source software to identify and patch vulnerabilities using frontier AI capabilities.
NetSPI released AD-PathFinder, an open-source attack path mapping tool for red teamers and penetration testers. The tool analyses BloodHound data to identify attack paths across Active Directory, certificate services, configuration manager, and SQL environments, consolidating paths and cross-referencing against credential data to reveal privilege escalation routes from low-privilege accounts to high-value targets.
A researcher released Offensive-COM, a comprehensive research repository documenting Windows Component Object Model attack techniques across six core modules. The framework catalogues exploitation methodologies including distributed COM lateral movement, privilege escalation via Potato exploits, UAC bypass, COM hijacking persistence, and defence evasion techniques.
eSentire analysed a TAG-150 campaign from June that used ClickFix social engineering to deploy malicious MSI files. The campaign leverages the Deno runtime to execute a multi-stage loader, stealer, and remote access trojan with memory-only payloads and reflective injection techniques. Advanced evasion includes anti-analysis checks and abuse of Deno's foreign function interface to interact with Windows APIs.
And finally, JPCERT has announced the call for presentations for JSAC 2027, their cybersecurity conference scheduled for January nineteenth through twenty-second in Tokyo. The conference focuses on incident response, malware analysis, and threat hunting research primarily covering the Asia-Pacific region.
That concludes today's briefing.