Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (8 July 2026)
Published: Loading…
At a Glance
- A suspected China-aligned cluster, UNK_MassTraction, exploited Roundcube vulnerabilities to breach US and Canadian university networks and steal credentials.
- Attackers exploited the critical Adobe ColdFusion flaw CVE-2026-48282 within hours of public disclosure, a maximum severity path traversal vulnerability.
- BeyondTrust patched two critical authentication bypass flaws in Remote Support and Privileged Remote Access allowing unauthenticated attackers to bypass access controls.
- CERT/CC warned that Tenda router firmware contains an undocumented admin backdoor, tracked as CVE-2026-11405, bypassing password verification.
- Attackers exploited a critical Gitea authentication bypass flaw, CVE-2026-20896, using a single HTTP header to access private repositories.
- Chinese actor UAT-7810 expanded its LapDogs ORB network with new LONGLEASH, DOGLEASH and JARLEASH malware targeting unpatched Ruckus routers.
Summary
A suspected China-aligned cluster tracked as UNK_MassTraction has exploited Roundcube webmail vulnerabilities, including CVE-2024-42009 and CVE-2025-49113, against physics and engineering departments at US and Canadian universities since May 2026. The campaign used multiple post-exploitation tools, including credential stealers, SquareShell webshells, and the VShell backdoor, across observed intrusions. Talos separately reported that UAT-7810 continues expanding its LapDogs Operational Relay Box network using new LONGLEASH, DOGLEASH and JARLEASH malware against unpatched Ruckus routers.
Attackers began exploiting the maximum severity Adobe ColdFusion flaw CVE-2026-48282 within hours of its disclosure. The path traversal vulnerability, patched on June 30, carries a CVSS score of 10.0. Honeypot sensors detected exploitation attempts shortly after a public technical analysis was released.
BeyondTrust patched two critical pre-authentication flaws in its Remote Support and Privileged Remote Access products, including CVE-2026-40138 with a CVSS score of 9.2. Separately, attackers began exploiting a critical Gitea Docker image flaw, CVE-2026-20896, to bypass authentication with a single HTTP header. CERT/CC also warned that multiple Tenda router firmware versions contain an undocumented admin backdoor, CVE-2026-11405.
Scattered Spider was described as a decentralized cybercrime collective rather than a unified gang, linking subclusters to Okta phishing and SIM swapping. A separate court filing revealed that a Windows Global Device Identifier helped the FBI trace an alleged Scattered Spider hacker, Peter Stokes, to a jewelry retailer breach.
Researchers disclosed AI platform flaws including Rogue Agent in Google's Dialogflow CX, which could let attackers hijack chatbot conversations across tenants, and GitLost, a prompt injection flaw letting public GitHub issues trick Agentic Workflows into leaking private repository data. Sophos also found that AI coding agents such as Claude Code and Cursor trigger endpoint detection rules through credential access and persistence behaviors.
Highlights of the Day
Attackers Exploit Critical Adobe ColdFusion Flaw
Adobe's ColdFusion vulnerability CVE-2026-48282 is a critical path traversal flaw with a CVSS score of 10.0 that can enable arbitrary code execution. SecurityWeek reported that attackers exploited the flaw in attacks after KEVIntel observed exploitation within two hours of public disclosure through its global honeypot network. The vulnerability was patched in ColdFusion 2025 update 10 and ColdFusion 2023 update 21, released by Adobe on 30 June alongside five other maximum severity flaws.
Scattered Spider Revealed as Decentralised Cybercrime Collective
Group-IB identified Scattered Spider as a decentralised cybercrime collective of independent subclusters sharing tactics, tools, and communication channels rather than a single organised group. The report links subclusters to Okta phishing campaigns, SIM swapping, cryptocurrency theft, ransomware activity, and social engineering attacks targeting multiple industries. Group-IB observed attackers using identity provider impersonation, vishing, smishing, remote access tools, and stolen employee information to compromise organisations across targeted sectors.
China-Aligned Actor Exploits Roundcube Servers at Universities
Proofpoint tracked UNK_MassTraction, a suspected China-aligned threat cluster exploiting Roundcube vulnerabilities against physics and engineering departments at US and Canadian universities since May 2026. The campaign used CVE-2024-42009 cross-site scripting flaws to deploy the IceCube credential stealer, then exploited CVE-2025-49113 deserialisation issues to install SquareShell webshells or load the VShell backdoor in memory. Proofpoint observed compromised email senders and spoofable domains used to deliver phishing messages containing malicious JavaScript targeting vulnerable Roundcube instances.
Spain Arrests Suspected Pro-Russian Hacktivist Member
Spanish police arrested a man in Palencia suspected of supporting CyberArmy of Russia Reborn and Z-Pentest, pro-Russian hacktivist groups linked to attacks on critical infrastructure in the US and Europe. Investigators said the suspect provided logistical and operational support to a CARR member and participated in activities attributed to NoName057(16), while authorities seized computers and cryptocurrency storage devices during a March 2026 raid.
Attackers Exploit Critical Gitea Authentication Flaw
Threat actors are exploiting CVE-2026-20896, a critical Gitea Docker image vulnerability with a CVSS score of 9.8 that allows authentication bypass using a single HTTP header. The flaw affects Gitea Docker images up to version 1.26.2, where reverse-proxy authentication settings trust any source IP and allow attackers to impersonate users with known usernames. Security researchers observed exploitation 13 days after public disclosure, with vulnerable internet-accessible instances exposed to potential repository and secret theft.
AI Agents Trigger Security Detections in Endpoint Telemetry
Sophos analysed telemetry from AI coding agents including Claude Code, Cursor, and Codex, finding endpoint detections triggered by behaviours involving credential access, execution, and command-line activity. The research identified GStack browser automation using PowerShell and DPAPI to decrypt browser credentials, while other agents accessed credential stores and attempted downloads using certutil and bitsadmin. Sophos observed Cursor writing a VBScript file to the Windows startup folder, triggering a persistence detection rule during the analysed activity.
Malicious Packages Target Payment SDK Developers
Socket detected 17 malicious npm and PyPI packages published on 7 July 2026 that impersonated PaySafe, Skrill and Neteller SDKs to target developers with credential and token theft malware. The packages used fake payment SDK functions to collect environment variables containing keys, secrets and tokens, then exfiltrated stolen data to AWS infrastructure through an encoded command-and-control domain. The malware included sandbox evasion checks and affected npm releases contained multiple malicious versions.
Mandiant Finds ADFS Key Recovery Path for SAML Attacks
Mandiant identified a method to recover active ADFS token-signing keys from Machine DPAPI when certificate rotation leaves stale configuration records after manual certificate changes. The technique allows attackers with sufficient SYSTEM-level access to forge SAML assertions, impersonate users including administrators, and bypass MFA for SAML-federated applications. Mandiant demonstrated the recovery process during a red team assessment and used the recovered key to create a SAML assertion accepted by Entra ID.
UAT-7810 Expands Malware for ORB Network Operations
Cisco Talos identified new UAT-7810 malware families used to expand the LapDogs Operational Relay Box network, including LONGLEASH, DOGLEASH, and JARLEASH backdoors. The China-nexus threat actor exploited unpatched Ruckus wireless router vulnerabilities including CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 to compromise devices and deploy payloads. LONGLEASH provides proxying, tunnelling, and C2 capabilities, while DOGLEASH executes shell commands and code on compromised Linux devices.
BeyondTrust Patches Critical Remote Access Flaws
BeyondTrust disclosed four vulnerabilities affecting Remote Support and Privileged Remote Access products, including CVE-2026-40138 and CVE-2026-40139 with CVSS v4 scores of 9.2. The critical authentication flaws could allow unauthenticated remote attackers to bypass access controls and gain unauthorised appliance access under specific configurations. Additional vulnerabilities CVE-2026-40140 and CVE-2026-40141 could cause denial of service or allow limited authenticated users to access unintended resources.
Daily Coverage