CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (20 July 2026)

Published: Loading…

At a Glance

  • Hijacked dormant RubyGems accounts published malicious git_credential_manager, Dendreo, and fastlane packages installing persistent backdoors on developer machines.
  • CVE-2026-42533, a 15-year-old nginx flaw, enables pre-authentication remote code execution via heap buffer overflow across thirteen call sites.
  • UAC-0145, a Sandworm sub-cluster tied to Russia's GRU, used ClickFix CAPTCHAs to infect Ukrainian devices with data-stealing malware.
  • A DPRK-aligned Contagious Interview campaign hid OTTERCOOKIE-aligned malware inside SVG flag images to steal developer credentials.
  • WordPress 7.0.2 patched critical wp2shell remote code execution flaws after public exploits were released for WordPress Core.
  • SonicWall SMA 1000 series VPN appliances were exploited as zero-days by threat actor UTA0533 before public disclosure.

Editorial Analysis

The software supply chain continues to be targeted at its source rather than its edges. The SleeperGem campaign compromised dormant RubyGems maintainer accounts, not new infrastructure, to distribute persistent backdoors directly to developer machines through packages such as git_credential_manager. It follows a pattern already established across npm and PyPI over the past year, with trusted package registries remaining an attractive point of compromise.

CVE-2026-42533 highlights a different kind of exposure: a flaw that remained hidden in nginx for fifteen years before a researcher showed it could be exploited for pre-authentication remote code execution. Old code can conceal vulnerabilities for years, particularly in software that becomes part of the internet's core infrastructure.

Nation-state operators, meanwhile, are diversifying how they reach their targets. Sandworm's UAC-0145 used fake CAPTCHAs and Android malware against Ukrainian victims, while a North Korean group concealed malware inside SVG image files to target software developers. Rather than relying on a single delivery technique, attackers continue to adapt their approach to whichever user, workflow, or trusted component offers the easiest path in.

Highlights of the Day

Hijacked RubyGems Accounts Drop Backdoor via Fake Git Tool

Attackers compromised dormant RubyGems maintainer accounts to publish malicious versions of git_credential_manager, Dendreo, and fastlane-plugin-run_tests_firebase_testlab between 18 and 19 July 2026. The loader, dubbed SleeperGem, downloads a payload from an attacker-controlled Forgejo host, evades roughly thirty CI environment checks, and on developer machines installs a daemon with systemd and cron persistence. On systems with passwordless sudo, the malware escalates privileges and plants a setuid root shell disguised as a networking utility.

Fake Coding Interviews Hide Malware Inside SVG Flag Images

Elastic Security Labs identified a Contagious Interview campaign, tracked as REF9403, that hides malicious payloads using steganography inside SVG flag images within trojanized developer repositories. Recipients targeted through fake job offers on Slack receive projects that assemble Base64-encoded fragments from SVG comments to deploy malware aligned with OTTERCOOKIE, including a browser and crypto wallet stealer, file stealer, Socket.IO-based RAT, and clipboard stealer. Exfiltrated data is sent to command-and-control domains under rightwidth[.]dev, with the campaign attributed to DPRK-aligned actors based on code and infrastructure overlap.

7-Zip Heap Overflow Flaw Enables Remote Code Execution

Zero Day Initiative disclosed a heap-based buffer overflow vulnerability in 7-Zip that arises during processing of XZ chunked data. Exploitation requires a target to open a malicious file or visit a malicious page, after which an attacker can execute code in the context of the current process. The vendor reported the flaw on 5 June 2026, and it is fixed in 7-Zip version 26.02, released alongside the advisory on 15 July 2026.

15-Year-Old nginx Flaw Enables Pre-Auth Remote Code Execution

Researcher Stan Shaw disclosed CVE-2026-42533, a missing save and restore of PCRE capture state in nginx's script engine that lets a remote unauthenticated attacker trigger a heap buffer overflow or an information leak that defeats ASLR. The flaw affects nginx 0.9.6 through 1.30.3, mainline 1.31.2, and NGINX Plus R33 through R36 and 37.0.0.1 through 37.0.2.1, spanning thirteen call sites across the HTTP and stream modules. F5 acknowledged the report on 18 May 2026 and released fixes in nginx 1.30.4, 1.31.3, and corresponding NGINX Plus builds on 15 July 2026.

Source: Cyberstan

Russian Sandworm Sub-Group Uses ClickFix to Hit Ukraine

CERT-UA attributed a campaign to UAC-0145, a Sandworm sub-cluster affiliated with Russia's GRU, using fake CAPTCHA checks on at least ten compromised websites between June and July 2026 to trick targets into running malicious PowerShell commands. The attacks deploy tools including SCOUTCURL for reconnaissance, loaders FLUIDLEECH and LOADLOOP, and a Python backdoor called FREAKYPOLL, alongside a smart-contract-based domain retrieval technique known as EtherHiding. Separately, the group distributes an Android backdoor named COWARDDUCK via messaging apps, which harvests contacts, files, and real-time geolocation and exfiltrates data through the Dropbox API.

Daily Coverage

Developments
Sleepergem RubygemsNginx CVE-2026-42533Uac-0145 ClickfixContagious Interview Svg Malware
Vulnerabilities
CVE-2026-42533Nginx Plus 37.0.0.1 (High)
Threat Groups
Contagious InterviewContagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials. Contagious Interview targets Windows, Linux, and macOS systems, with a particular focus on individuals engaged in software development and cryptocurrencyrelated activities.