Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (4 July 2026)
Published: Loading…
At a Glance
- Citizen Lab found former European Parliament PEGA Committee member Stelios Kouloglou infected twice with NSO Group's Pegasus spyware.
- A new Linux kernel flaw called Bad Epoll, CVE-2026-46242, lets unprivileged users gain root on Linux and Android.
- ShinyHunters breached Medtronic's corporate IT systems in April, exposing personal and medical data of 3.8 million people.
- Armored Likho, a newly identified APT group, deployed BusySnake Stealer against government and energy targets in Russia, Brazil and Kazakhstan.
- AdaptHealth disclosed a breach in which attackers used social engineering against a third-party contractor to steal patient data.
Summary
Citizen Lab confirmed that former European Parliament member Stelios Kouloglou was infected twice with Pegasus spyware while serving on the committee investigating such tools. Forensic analysis linked the intrusions to the PWNYOURHOME zero-click exploit chain targeting iOS devices. Investigators found infrastructure overlap with a prior Pegasus campaign against Russian and Belarusian journalists.
A newly disclosed Linux kernel flaw, Bad Epoll (CVE-2026-46242), allows unprivileged users to escalate to root on Linux systems and Android devices. Researchers also disclosed seven unpatched vulnerabilities in FatFs, a filesystem library embedded in millions of devices including cameras and industrial controllers.
The Armored Likho APT group used spear-phishing to deploy BusySnake Stealer against government and electric power sector targets in Russia, Brazil, and Kazakhstan. A separate modular framework called Avalon delivered CrownX ransomware through a multi-stage phishing chain combining credential theft and lateral movement.
Researchers also identified North Korea-linked npm packages mimicking Rollup polyfill tools to steal developer secrets, and a phishing-as-a-service platform called ARToken targeting Microsoft 365 accounts through the EvilTokens toolkit.
Highlights of the Day
Avalon Malware Delivers CrownX Ransomware Through Multi-Stage Phishing
Blackpoint Cyber analysed a previously undocumented malware framework named Avalon, delivered through a phishing email linking to a password-protected Proton Drive archive containing an ISO image, an MSBuild project with inline C#, and an in-memory loader that bypassed AMSI and ETW before retrieving additional payloads. The final payload harvested browser, VPN, wallet and Windows credentials, communicated with the C2 endpoint helloxcherry[.]com, used WinHTTP for tasking and exfiltration, and supported lateral movement through scheduled tasks, DCOM and administrative shares. Avalon also contained the integrated CrownX ransomware, which used AES-GCM encryption, disabled Volume Shadow Copy and Windows recovery features, removed forensic artefacts, targeted virtual machine, database and engineering files, and included a direct disk destruction capability through \\.\PhysicalDrive.
Pegasus Hit EU Spyware Investigator During Parliamentary Inquiry
Citizen Lab found that former European Parliament member Stelios Kouloglou was infected with NSO Group's Pegasus spyware in October 2022 and again in March 2023 while serving on the PEGA Committee, with forensic evidence indicating exploitation through the PWNYOURHOME zero-click chain targeting iOS 15.5 devices. The investigation identified infrastructure overlap with a previously documented Pegasus campaign against Russian and Belarusian journalists, including the shared HomeKit email rauharepo888@gmail.com, but found no evidence attributing the attacks to the Greek government or any specific Pegasus customer.
Armored Likho Deploys AI-Generated BusySnake Stealer via Phishing
Kaspersky reported that the Armored Likho APT group used spear-phishing archives containing LNK and EXE payloads to deploy BusySnake Stealer, a Python-based infostealer distributed with PyArmor obfuscation and staged via PowerShell loaders, GitHub-hosted components, and scheduled tasks. The malware targets government and energy sector entities across Russia, Brazil, and Kazakhstan, harvesting clipboard data, browser credentials, screenshots, files, and cryptocurrency wallet artefacts while maintaining persistence through WindowsHelper scheduled tasks and VBScript launchers. BusySnake Stealer also integrates reverse SSH tunnelling and C2-driven command execution, with newer variants introducing COM-based task scheduling, in-memory script execution, and structured task-state tracking via SCHEDULED and IN_PROGRESS execution flows.
Linux Epoll Flaw Enables Root Privilege Escalation
Researchers disclosed Bad Epoll (CVE-2026-46242), a Linux kernel epoll subsystem race-condition use-after-free enabling unprivileged processes to escalate privileges to root on affected systems. Exploitation was demonstrated in Google kernelCTF with high reliability, with impact extending to Android devices and potential Chrome renderer sandbox escape chains. The issue originated from a 2023 kernel commit affecting epoll close paths, with fixes upstream applied via commit a6dc643c6931 across mainline Linux distributions.
Daily Coverage