CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (2 July 2026)

Published: Loading…

At a Glance

  • Citrix patched six NetScaler flaws including a new HTTP/2 Bomb attack and a CitrixBleed-style information disclosure bug.
  • Adobe patched seven maximum-severity CVSS 10.0 flaws in ColdFusion and Campaign Classic enabling arbitrary code execution.
  • Anubis ransomware affiliates exploited CitrixBleed 2 (CVE-2025-5777) and abused ScreenConnect, Zoho Assist and cloudflared for lateral movement.
  • A password-spray campaign made over 81 million login attempts against Azure CLI and Microsoft 365, compromising dozens of accounts.
  • Cisco Talos uncovered the ARToken phishing-as-a-service panel targeting Microsoft 365 via device-code phishing linked to EvilTokens.
  • The FortiBleed credential-theft campaign targeting 430,000+ FortiGate firewalls was linked to INC Ransom and Lynx ransomware operations.

Summary

Citrix released patches for six NetScaler ADC and Gateway flaws, including a new HTTP/2 Bomb denial-of-service attack and a CitrixBleed-style information disclosure bug. Adobe separately patched seven maximum-severity CVSS 10.0 vulnerabilities in ColdFusion and Campaign Classic that could enable arbitrary code execution and privilege escalation. Google patched 382 Chrome vulnerabilities, fifteen rated critical.

Anubis ransomware affiliates exploited the CitrixBleed 2 flaw (CVE-2025-5777) alongside valid VPN credentials for initial access. Intrusions used legitimate RMM tools including ScreenConnect, Zoho Assist and MeshAgent, plus cloudflared tunnelling, before data exfiltration and encryption. A separate ScreenConnect campaign distributed AsyncRAT through spoofed software installer sites across 90 domains.

A password-spraying campaign generated more than 81 million login attempts against Azure CLI and Microsoft 365 accounts, compromising at least 78 accounts. The ARToken phishing-as-a-service panel, identified by Cisco Talos, targets Microsoft 365 through device-code phishing and shares infrastructure with the EvilTokens platform. The FortiBleed credential-theft campaign, which harvested access from over 430,000 FortiGate firewalls, was linked to the INC Ransom and Lynx ransomware operations.

The Ousaban banking trojan targeted Windows users in Spain and Portugal through phishing PDFs disguised as corrupted files, using geofencing and steganography to hide payloads. The VEIL#DROP campaign abused Google Blogspot pages to deliver the PureLogs infostealer in memory.

Researchers demonstrated browser-only ransomware generated using DeepSeek, exploiting Chrome's File System Access API on Windows and Android without native payloads. Unit 42 documented "phantom squatting," where attackers register AI-hallucinated domains for phishing and malware delivery. Two critical flaws in the Cursor AI code editor, tracked as CVE-2026-50548 and CVE-2026-50549, could let prompt injection escape the sandbox.

The U.S. Commerce Department lifted export controls on Anthropic's Fable 5 and Mythos 5 models, restoring global access after a three-week suspension tied to a jailbreak technique. A 19-year-old Scattered Spider suspect was extradited from Finland to face U.S. hacking charges. DHS confirmed hackers breached the Homeland Security Information Network (HSIN).

Highlights of the Day

Anubis Ransomware Uses CitrixBleed 2 and RMM Tools

Arctic Wolf investigated Anubis ransomware intrusions using valid VPN credentials and exploitation of CitrixBleed 2 (CVE-2025-5777) for initial access across multiple environments. Affiliates used ScreenConnect, Zoho Assist, MeshAgent and other RMM tools alongside RDP, SMB and PsExec for lateral movement and persistence establishment. Activity included cloudflared tunnelling, credential theft, Active Directory database extraction and data exfiltration preceding encryption of systems with .anubis ransomware payloads.

Browser-Only Ransomware Uses File System Access API

Check Point Research described browser-only ransomware concept derived from LLM-generated malware ideas, using Chrome File System Access API for directory-level access after user approval. Technique on Android Chrome leverages File System Access API with social engineering lures such as fake image upscalers, requiring no native payload installation. Researchers demonstrated LLM-generated proof-of-concept that can enumerate, encrypt and overwrite user-selected files, while displaying ransom overlays, highlighting cross-platform browser security implications.

FortiBleed Credential Theft Linked to INC and Lynx Ransomware

SOCRadar links FortiBleed credential-harvesting campaign targeting 430,000+ FortiGate firewalls using FortigateSniffer to INC Ransom and Lynx ransomware operations. STRU identified operator access to negotiation panels for both ransomware groups, alongside scanning of 11,250 portals, 409 admin-level compromises across 150 countries. Investigation reports at least 12 ransomware deployments from FortiBleed-derived access, with victim overlap and internal documentation indicating structured ~20-person operation.

Source: SOCRadar

US Lifts Export Controls on Anthropic Cybersecurity Models

US authorities lifted export controls on Anthropic’s Fable 5 cybersecurity model, restoring global access after a three-week shutdown that had restricted foreign nationals. Anthropic also reinstated access to Mythos 5 under Project Glasswing for vetted US organisations, while negotiations continue for broader domestic and international availability. The initial restriction followed a reported jailbreak technique based on code-fixing prompts, later mitigated by a classifier blocking over 99% of cases and endorsed by US evaluators.

Adobe Patches CVSS 10 ColdFusion Campaign Classic Flaws

Adobe has released updates for ColdFusion and Campaign Classic addressing multiple CVSS 10.0 vulnerabilities enabling arbitrary code execution, privilege escalation, file system read, and security bypass. The ColdFusion fixes address CVE-2026-48276–48316 involving unrestricted upload, input validation and path traversal, while Campaign Classic CVE-2026-48286 is an incorrect authorisation flaw enabling remote code execution on on-premise instances; Adobe reports no in-the-wild exploitation and will move to twice-monthly updates due to vulnerability discovery compressing disclosure-to-exploitation timelines.

AI Hallucinated Domains Fuel Phantom Squatting Attacks

Unit 42 researchers identified “phantom squatting” where attackers register LLM-hallucinated domains and weaponise them for phishing and malware delivery across multiple sectors. Analysis of 913 brands and 2.1 million LLM-generated URLs found 13,229 malicious URLs and approximately 250,000 unregistered phantom domains available for preemptive registration. Case studies including the “Montana Empire” phishing kit show adversaries exploiting hallucinated domains up to 51 days after prediction, with overlaps between AI-generated URL patterns and real-world credential theft infrastructure.

Platform-Aware Phishing Expands Multi-Device Delivery

Threat actors increasingly use platform-aware phishing campaigns that fingerprint operating systems and browsers to deliver tailored malware, credential phishing, or remote access tools. These campaigns rely on user-agent collection, Cloudflare redirection, and phishing kits that gather browser, and device before delivering tools including ConnectWise RAT and Itarian RAT. Attackers optimise campaigns for return on investment by reusing infrastructure across platforms and monetising access through initial access broker resale after credential theft or compromise.

Daily Coverage

Developments
Netscaler FlawsColdfusion PatchesAnubis RansomwareAzure Cli Spray
Vulnerabilities
CVE-2025-5777Netscaler_Application_Delivery_Controller 12.1-55.328 (Critical)CVE-2026-50548Cursor < 3.0 (Critical)CVE-2026-50549Cursor < 3.0 (Critical)CVE-2026-8451Adc 14.1 (High)CVE-2026-8037Loadmaster V7.2.60.0 (Critical)CVE-2026-50052Vinyl Cache 9.0.0 (Low)CVE-2026-33017Langflow < 1.9.0 (Critical)CVE-2026-48286Adobe Campaign Classic (Acc) (Critical)CVE-2026-48276Coldfusion (Critical)
Threat Groups
Scattered SpiderScattered Spider is a native Englishspeaking cybercriminal group active since at least 2022. The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. Scattered Spider relies heavily on social engineering, including impersonating IT and helpdesk staff, to gain initial access, bypass multifactor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. Scattered Spider had expanded into hybrid cloud and identity environments, using helpdesk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365.INC RansomINC Ransom is a ransomware and data extortion threat group associated with the deployment of INC Ransomware that has been active since at least July 2023. INC Ransom has targeted organizations worldwide most commonly in the industrial, healthcare, and education sectors in the US and Europe.CHROMIUMEarth Lusca is a suspected Chinabased cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated. Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.Contagious InterviewContagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials. Contagious Interview targets Windows, Linux, and macOS systems, with a particular focus on individuals engaged in software development and cryptocurrencyrelated activities.