CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (7 July 2026)

Published: Loading…

At a Glance

  • Attackers exploit the maximum-severity Adobe ColdFusion vulnerability CVE-2026-48282.
  • Threat actors probe critical Gitea Docker flaw CVE-2026-20896, exploiting trust in the X-WEBAUTH-USER header for unauthenticated access.
  • The Januscape flaw, CVE-2026-53359, lets guest VMs escape to host via a 16-year-old Linux KVM use-after-free bug.
  • ShinyHunters leaked data on 2.3 million people from a breach of Moody Bible Institute, disclosed in June 2026.
  • Cavern Manticore is an Iran-linked group using a modular .NET C2 framework against Israeli government and IT targets.

Summary

Attackers are actively exploiting CVE-2026-48282, a maximum-severity Adobe ColdFusion vulnerability. Separately, threat actors began probing CVE-2026-20896, a critical Gitea Docker flaw involving unauthenticated header trust, within 13 days of disclosure.

A 16-year-old use-after-free bug in Linux's KVM hypervisor, dubbed Januscape and tracked as CVE-2026-53359, allows guest VMs to escape to the host on Intel and AMD systems. The flaw was used as a zero-day exploit in Google's kvmCTF and can trigger host kernel panics.

ShinyHunters leaked data on 2.3 million people tied to Moody Bible Institute after the college did not meet extortion demands. Separately, a major medical device manufacturer notified nearly 4 million individuals of a breach involving Social Security numbers and health data.

Cavern Manticore, an Iran-linked threat actor tied to Iran's Ministry of Intelligence and Security, uses a modular .NET command-and-control framework against Israeli government and IT organizations. North Korean hackers separately ran the PolinRider campaign, compromising more than 100 open source packages to deliver backdoors to developers.

Multiple remote access trojans circulated via phishing, including CrySome RAT delivered through a fake logistics document, DcRAT spread via a fake Indian tax utility, and EtherRAT pushed through fake Microsoft Teams IT support calls. Researchers also uncovered prompt injection campaigns tricking AI agents into making cryptocurrency payments.

Highlights of the Day

Attackers Exploit Critical Adobe ColdFusion Flaw

Attackers began exploiting CVE-2026-48282, a critical Adobe ColdFusion vulnerability, within two hours of public disclosure, according to KEVIntel, enabling unauthenticated remote code execution on affected systems running ColdFusion versions 2025.9, 2023.20, and earlier. Adobe released security updates for the flaw, while Shadowserver tracked nearly 800 internet-exposed ColdFusion instances and the Canadian Centre for Cyber Security confirmed ongoing exploitation reports for a vulnerability requiring no privileges or user interaction.

CrySome RAT Campaign Uses Phishing to Gain Persistent Access

LevelBlue researchers analysed a CrySome RAT infection chain that began with a spear-phishing email posing as a logistics rate confirmation and delivered a batch file from signindat[.]com. The chain used PowerShell AMSI patching, an ICMLuaUtil UAC bypass, Defender disruption through WinDefCtl, and hidden downloads of ElevatorShellCode.exe, stage.ps1, and patch_diag.exe. CrySome RAT established persistence through a scheduled task and provided remote command execution, HVNC, system reconnaissance, and Chromium browser credential theft capabilities.

Source: LevelBlue

AI Skills Bypass Scanners Through Hidden Payloads

Researchers from Hong Kong University of Science and Technology developed SKILLCLOAK, a technique that hides malicious AI agent skills through structural obfuscation and self-extracting packing while preserving their behaviour. The study tested eight scanners against 1,613 malicious skills, finding self-extracting packing bypassed every scanner above 90%, while the SKILLDETONATE runtime auditor detected 97% of attacks in controlled tests.

KVM Flaw Enables Guest-to-Host Escape

Security researcher Hyunwoo Kim disclosed Januscape (CVE-2026-53359), a use-after-free vulnerability in KVM/x86 shadow MMU emulation that allows guest-to-host escape through guest-side actions on Intel and AMD systems. The flaw affects KVM versions from commit 2032a93d66fa in 2010 to 81ccda30b4e8 in 2026, was used as a zero-day exploit in Google kvmCTF, and can cause host kernel panic or enable host privilege escalation in affected environments.

Source: V4bel

Iran-Linked Group Deploys Modular Cavern Malware Framework

Check Point Research identified Cavern Manticore, an Iran-linked threat actor targeting Israeli government and IT organisations with a modular .NET command-and-control framework. The Cavern framework uses Mixed-Mode C++/CLI and Native AOT compilation, DLL sideloading through WinDirStat, and modules for reconnaissance, database access, tunnelling, and credential-related operations. Initial access in observed intrusions involved abuse of existing Remote Monitoring and Management software deployed within targeted organisations.

Attackers Probe Critical Gitea Docker Authentication Flaw

Threat actors attempted to exploit CVE-2026-20896, a critical Gitea Docker image vulnerability caused by unrestricted trust of the X-WEBAUTH-USER header from any source IP. The flaw affected Gitea Docker images through version 1.26.2, where REVERSE_PROXY_TRUSTED_PROXIES was set to "*" by default, allowing unauthenticated users to impersonate accounts when reverse-proxy authentication was enabled.

TrojPix Leaks Air-Gapped Data Through Video Cables

Researchers from Shandong University developed TrojPix, a covert channel that uses imperceptible pixel modulation to create electromagnetic emissions from digital video cables. The technique requires malware already running on the target system and achieved peak throughput of 8.1 Mbps with a maximum measured range of 208 metres across tests involving nine monitor brands and fifteen video cables.

Daily Coverage

Developments
Coldfusion ExploitationGitea Docker FlawJanuscape Kvm EscapeMoody Bible Institute Breach
Vulnerabilities
CVE-2026-48282Coldfusion (Critical)CVE-2026-20896Gitea Open Source Git Server (Critical)CVE-2026-53359Linux 2032A93D66Fa282Ba0F2Ea9152Eeff9511Fa9A96
Threat Groups
MuddyWaterMuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS). Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, defense, and oil and natural gas organizations, in the Middle East, Asia, Africa, Europe, and North America.LyceumHEXANE is a cyber espionage threat group that has targeted oil & gas, telecommunications, aviation, and internet service provider organizations since at least 2017. Targeted companies have been located in the Middle East and Africa, including Israel, Saudi Arabia, Kuwait, Morocco, and Tunisia. HEXANE's TTPs appear similar to APT33 and OilRig but due to differences in victims and tools it is tracked as a separate entity.CHROMIUMEarth Lusca is a suspected Chinabased cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated. Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.