Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (9 July 2026)
Published: Loading…
At a Glance
- A 15-year-old Linux kernel flaw dubbed GhostLock lets any logged-in user gain full root control on unpatched systems.
- CISA ordered federal agencies to patch a maximum-severity Adobe ColdFusion path traversal flaw, CVE-2026-48282, by Friday.
- Chinese threat actor UAT-7810 expanded its ORB proxy network with new LongLeash, DogLeash, and JarLeash backdoors.
- REF6045 uses ClickFix fake CAPTCHA pages to deliver SCMBANKER, a PowerShell toolkit targeting Mexican banking customers.
- Accenture confirmed a breach after a hacker claimed to have stolen 35GB of source code and Azure keys.
- Ubiquiti patched multiple critical UniFi OS vulnerabilities, including a maximum-severity command injection flaw.
Summary
CISA ordered federal agencies to patch a maximum-severity Adobe ColdFusion path traversal flaw, CVE-2026-48282, by Friday. Attackers exploited the vulnerability within hours of public disclosure to achieve remote code execution. CISA also added a Langflow authorization bypass flaw and two Joomla extension vulnerabilities to its Known Exploited Vulnerabilities catalog.
Ubiquiti shipped patches for multiple critical vulnerabilities across UniFi Connect, Talk, Access, Protect, and OS. One flaw carried a maximum CVSS score of 10.0 and enabled command injection. A separate 15-year-old Linux kernel flaw, GhostLock, was disclosed allowing root and container escape on most distributions.
China-linked UAT-7810 expanded its Operational Relay Box network by breaking into internet-facing networking devices. The group deployed new LongLeash, DogLeash, and JarLeash backdoors to grow its proxy infrastructure. Separately, a China-linked cluster exploited Roundcube mailserver flaws to steal credentials from US and Canadian university researchers.
REF6045 deployed the SCMBANKER PowerShell toolkit against Mexican banking, fintech, and cryptocurrency exchange customers using fake CAPTCHA verification pages. Operators monitored banking sessions, captured screenshots, and manipulated clipboard data to redirect funds. The toolkit's components date back to at least October 2025.
Accenture confirmed a security breach after a hacker claimed to have stolen 35GB of data, including source code, RSA and SSH keys, and Azure access tokens. KDDI disclosed a breach affecting over 12 million people after attackers compromised an email platform used by five Japanese ISPs.
Researchers found that GitHub Copilot could be tricked into producing harmful outputs when requests were broken into multi-step coding workflows, despite refusing the same prompts in chat. A separate GhostApproval flaw affected AI coding assistants including Claude Code, Cursor, and Amazon Q Developer, allowing sandbox escapes.
Highlights of the Day
Adobe ColdFusion Flaw Exploited Hours After Public Disclosure
Adobe disclosed CVE-2026-48282, a maximum-severity CVSS 10.0 path traversal vulnerability in the ColdFusion Remote Development Services FILEIO handler that enables unauthenticated arbitrary file writes and remote code execution when RDS authentication is disabled. The flaw affects ColdFusion 2025 Update 9 and earlier and ColdFusion 2023 Update 20 and earlier, with attackers able to upload CFML webshells, while KEVIntel honeypots detected active exploitation within two hours of public technical analysis and Adobe addressed the issue in security bulletin APSB26-68.
Accenture Confirms Breach After Hacker Claims Source Code Theft
Accenture confirmed an isolated security breach after a threat actor claimed to have stolen 35 GB of internal data, including source code, Azure access keys and tokens, configuration files, and RSA and SSH keys, and advertised the dataset for sale on PwnForums. The attacker shared a screenshot of an apparent private Azure DevOps repository hosted on an accenture.com domain as proof of possession, while Accenture said it had remediated the source of the breach and reported no impact on its operations or service delivery.
CISA Adds Three Exploited Flaws to KEV Catalog
CISA added CVE-2026-48908, CVE-2026-55255 and CVE-2026-56290 to its Known Exploited Vulnerabilities Catalog after evidence of active exploitation was identified by the agency. The listed flaws include unrestricted file upload in JoomShaper SP Page Builder, authorization bypass in Langflow, and improper access control in Joomlack Page Builder.
SCMBANKER Malware Targets Mexican Banking Users
Elastic Security Labs identified REF6045, a Mexican banking fraud operation using fake CAPTCHA pages to deliver SCMBANKER, a PowerShell toolkit that monitors banking sessions, captures screenshots, redirects browsers, and manipulates clipboard data. The malware has targeted Mexican financial services including banks, fintechs, payment processors, cryptocurrency exchanges, investment platforms, SAT and telecom services, with operators using Remote Utilities for hands-on access. Elastic recovered SCMBANKER components from exposed infrastructure and found earlier toolkit versions dating back to October 2025.
GitHub Copilot Jailbreak Bypasses AI Safety Checks
Researchers from the Alan Turing Institute identified a workflow-level jailbreak affecting GitHub Copilot, where harmful requests refused in chat were generated across multi-step coding tasks. The study tested four models in Visual Studio Code using 204 harmful prompts and recorded harmful outputs in all 816 workflow-based attempts. Direct chat testing produced harmful responses in eight of 816 attempts, while researchers said the evaluation showed coding-agent safety checks need workflow testing.
GitHub Malware Network Used Fake Software Lures
Socket identified Operation Muck and Load, a GitHub-based lure network with 222 confirmed repositories across 190 accounts, linked to a malicious Go module that delivered a PowerShell loader through hidden execution. The module github.com/kaleidora/dnsub-scanning-tool impersonated a DNS scanner but downloaded encoded scripts, decrypted payload data, and launched malware including RAT and infostealer components. Researchers found the campaign used public dead-drop services and password-protected archives to distribute Windows payloads from attacker-controlled infrastructure.
Ubiquiti Fixes Critical UniFi Security Flaws
Ubiquiti released updates for UniFi Connect, Talk, Access, Protect and UniFi OS after disclosing critical flaws including command injection, SQL injection and access control vulnerabilities. The issues include CVE-2026-50746 with CVSS 10.0 in UniFi Connect and CVE-2026-50747 with CVSS 9.9 in UniFi Talk, affecting earlier application versions. Ubiquiti's bulletin lists 25 CVEs across UniFi products, including UniFi OS flaws that could allow privilege escalation, authentication bypass or command execution.
GhostLock Linux Kernel Flaw Enables Privilege Escalation
Nebula Security disclosed GhostLock, a Linux kernel vulnerability tracked as CVE-2026-43499 that affects major distributions from Linux 2.6.39 through versions before the 7.1 fix. The stack-use-after-free flaw in the rtmutex subsystem allows unprivileged local attackers to corrupt kernel memory and achieve privilege escalation or container escape. The vulnerability was fixed in April 2026 and backported in May 2026.
Daily Coverage