Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (2 July 2026)
Published: Loading…
At a Glance
- Citrix patched six NetScaler flaws including a new HTTP/2 Bomb attack and a CitrixBleed-style information disclosure bug.
- Adobe patched seven maximum-severity CVSS 10.0 flaws in ColdFusion and Campaign Classic enabling arbitrary code execution.
- Anubis ransomware affiliates exploited CitrixBleed 2 (CVE-2025-5777) and abused ScreenConnect, Zoho Assist and cloudflared for lateral movement.
- A password-spray campaign made over 81 million login attempts against Azure CLI and Microsoft 365, compromising dozens of accounts.
- Cisco Talos uncovered the ARToken phishing-as-a-service panel targeting Microsoft 365 via device-code phishing linked to EvilTokens.
- The FortiBleed credential-theft campaign targeting 430,000+ FortiGate firewalls was linked to INC Ransom and Lynx ransomware operations.
Summary
Citrix released patches for six NetScaler ADC and Gateway flaws, including a new HTTP/2 Bomb denial-of-service attack and a CitrixBleed-style information disclosure bug. Adobe separately patched seven maximum-severity CVSS 10.0 vulnerabilities in ColdFusion and Campaign Classic that could enable arbitrary code execution and privilege escalation. Google patched 382 Chrome vulnerabilities, fifteen rated critical.
Anubis ransomware affiliates exploited the CitrixBleed 2 flaw (CVE-2025-5777) alongside valid VPN credentials for initial access. Intrusions used legitimate RMM tools including ScreenConnect, Zoho Assist and MeshAgent, plus cloudflared tunnelling, before data exfiltration and encryption. A separate ScreenConnect campaign distributed AsyncRAT through spoofed software installer sites across 90 domains.
A password-spraying campaign generated more than 81 million login attempts against Azure CLI and Microsoft 365 accounts, compromising at least 78 accounts. The ARToken phishing-as-a-service panel, identified by Cisco Talos, targets Microsoft 365 through device-code phishing and shares infrastructure with the EvilTokens platform. The FortiBleed credential-theft campaign, which harvested access from over 430,000 FortiGate firewalls, was linked to the INC Ransom and Lynx ransomware operations.
The Ousaban banking trojan targeted Windows users in Spain and Portugal through phishing PDFs disguised as corrupted files, using geofencing and steganography to hide payloads. The VEIL#DROP campaign abused Google Blogspot pages to deliver the PureLogs infostealer in memory.
Researchers demonstrated browser-only ransomware generated using DeepSeek, exploiting Chrome's File System Access API on Windows and Android without native payloads. Unit 42 documented "phantom squatting," where attackers register AI-hallucinated domains for phishing and malware delivery. Two critical flaws in the Cursor AI code editor, tracked as CVE-2026-50548 and CVE-2026-50549, could let prompt injection escape the sandbox.
The U.S. Commerce Department lifted export controls on Anthropic's Fable 5 and Mythos 5 models, restoring global access after a three-week suspension tied to a jailbreak technique. A 19-year-old Scattered Spider suspect was extradited from Finland to face U.S. hacking charges. DHS confirmed hackers breached the Homeland Security Information Network (HSIN).
Highlights of the Day
Anubis Ransomware Uses CitrixBleed 2 and RMM Tools
Arctic Wolf investigated Anubis ransomware intrusions using valid VPN credentials and exploitation of CitrixBleed 2 (CVE-2025-5777) for initial access across multiple environments. Affiliates used ScreenConnect, Zoho Assist, MeshAgent and other RMM tools alongside RDP, SMB and PsExec for lateral movement and persistence establishment. Activity included cloudflared tunnelling, credential theft, Active Directory database extraction and data exfiltration preceding encryption of systems with .anubis ransomware payloads.
Browser-Only Ransomware Uses File System Access API
Check Point Research described browser-only ransomware concept derived from LLM-generated malware ideas, using Chrome File System Access API for directory-level access after user approval. Technique on Android Chrome leverages File System Access API with social engineering lures such as fake image upscalers, requiring no native payload installation. Researchers demonstrated LLM-generated proof-of-concept that can enumerate, encrypt and overwrite user-selected files, while displaying ransom overlays, highlighting cross-platform browser security implications.
FortiBleed Credential Theft Linked to INC and Lynx Ransomware
SOCRadar links FortiBleed credential-harvesting campaign targeting 430,000+ FortiGate firewalls using FortigateSniffer to INC Ransom and Lynx ransomware operations. STRU identified operator access to negotiation panels for both ransomware groups, alongside scanning of 11,250 portals, 409 admin-level compromises across 150 countries. Investigation reports at least 12 ransomware deployments from FortiBleed-derived access, with victim overlap and internal documentation indicating structured ~20-person operation.
US Lifts Export Controls on Anthropic Cybersecurity Models
US authorities lifted export controls on Anthropic’s Fable 5 cybersecurity model, restoring global access after a three-week shutdown that had restricted foreign nationals. Anthropic also reinstated access to Mythos 5 under Project Glasswing for vetted US organisations, while negotiations continue for broader domestic and international availability. The initial restriction followed a reported jailbreak technique based on code-fixing prompts, later mitigated by a classifier blocking over 99% of cases and endorsed by US evaluators.
Adobe Patches CVSS 10 ColdFusion Campaign Classic Flaws
Adobe has released updates for ColdFusion and Campaign Classic addressing multiple CVSS 10.0 vulnerabilities enabling arbitrary code execution, privilege escalation, file system read, and security bypass. The ColdFusion fixes address CVE-2026-48276–48316 involving unrestricted upload, input validation and path traversal, while Campaign Classic CVE-2026-48286 is an incorrect authorisation flaw enabling remote code execution on on-premise instances; Adobe reports no in-the-wild exploitation and will move to twice-monthly updates due to vulnerability discovery compressing disclosure-to-exploitation timelines.
AI Hallucinated Domains Fuel Phantom Squatting Attacks
Unit 42 researchers identified “phantom squatting” where attackers register LLM-hallucinated domains and weaponise them for phishing and malware delivery across multiple sectors. Analysis of 913 brands and 2.1 million LLM-generated URLs found 13,229 malicious URLs and approximately 250,000 unregistered phantom domains available for preemptive registration. Case studies including the “Montana Empire” phishing kit show adversaries exploiting hallucinated domains up to 51 days after prediction, with overlaps between AI-generated URL patterns and real-world credential theft infrastructure.
Threat actors increasingly use platform-aware phishing campaigns that fingerprint operating systems and browsers to deliver tailored malware, credential phishing, or remote access tools. These campaigns rely on user-agent collection, Cloudflare redirection, and phishing kits that gather browser, and device before delivering tools including ConnectWise RAT and Itarian RAT. Attackers optimise campaigns for return on investment by reusing infrastructure across platforms and monetising access through initial access broker resale after credential theft or compromise.
Daily Coverage