Cybersecurity Daily: News & Threats

Blockchain C2, EY Tax Breach & SonicWall Root Access

6 min · I går
episode Blockchain C2, EY Tax Breach & SonicWall Root Access cover

Description

(00:00:00) Blockchain C2, EY Tax Breach & SonicWall Root Access (00:01:17) Microsoft Patch Tuesday 570 Fixes (00:01:55) ViteVenom Blockchain C2 Supply Chain (00:02:45) EY Breach Client Tax Records (00:03:14) WordPress wp2shell RCE Risk (00:03:33) AI Attack Costs and Open-Weight Models (00:03:56) LegacyHive and ModHeader Threats Today's briefing opens with one of the most technically significant stories of the week: UTA0533 exploiting a CVSS 10.0 zero-day chain in SonicWall SMA appliances — CVE-2026-15409 and CVE-2026-15410 — to achieve root access through a WebSocket proxy endpoint and CouchDB path traversal, deploying custom web shells weeks before any patch existed. North Korean-linked group PolinRider pushed seven malicious npm packages impersonating legitimate @vitejs scoped packages, delivering a remote access trojan through a four-tier command-and-control architecture built on public blockchains — Tron, Aptos, and Binance Smart Chain. The infrastructure is effectively unsinkholeable. Domain seizure doesn't apply. This is supply chain attack resilience by design. Ernst and Young confirmed its IT support ticket platform was breached from late March through mid-April, exposing client tax records and investment documents. Detection came nearly three weeks after exfiltration — a blind spot that defines the real risk of third-party privileged platforms. Microsoft's July Patch Tuesday addressed 570 vulnerabilities, two already exploited in the wild: CVE-2026-56164 in SharePoint and CVE-2026-56155 in ADFS. WordPress users face a separate RCE risk via unauthenticated REST API SQL injection across more than 500 million installations. The UK AI Safety Institute benchmarks confirm DeepSeek V4-Pro and GLM-5.2 now match frontier model capabilities for autonomous cyberattacks — at single-digit dollar costs on stripped open-weight models. Also covered: a proof-of-concept Windows User Profile Service exploit bypassing fully-patched July 2026 systems, and the ModHeader Chrome extension — 1.6 million users — pulled after dormant encryption and browsing-history upload code was discovered. This episode includes AI-generated content.

Comments

0

Be the first to comment

Sign up now and become a member of the Cybersecurity Daily: News & Threats community!

Get Started

1 month for 9 kr.

Then 99 kr. / month · Cancel anytime

  • Podcasts kun på Podimo
  • 20 lydbogstimer pr. måned
  • Gratis podcasts

All episodes

73 episodes

episode Root Access Before the Patch: SonicWall, INC Ransomware & 570 Microsoft Fixes artwork

Root Access Before the Patch: SonicWall, INC Ransomware & 570 Microsoft Fixes

(00:00:00) Root Access Before the Patch: SonicWall, INC Ransomware & 570 Microsoft Fixes (00:01:04) INC Ransomware Weaponizes SonicWall (00:01:33) Microsoft's 570-Fix Patch Tuesday (00:02:41) Craneware Healthcare Breach (00:03:20) Paidwork Data Exposure and 7-Zip Patch (00:03:56) What to Watch Next Pre-disclosure exploitation is no longer an edge case — it's a playbook. In this episode, we break down how threat actor UTA0533 chained two SonicWall zero-days, CVE-2026-15409 and CVE-2026-15410, against SMA 1000 series appliances to achieve root access via a WebSocket authentication bypass, CouchDB pivot, and privilege escalation — deploying custom web shell ORANGETAIL before any patch or advisory existed. INC Ransomware then weaponised the same chain, marking a significant shift: zero-days once reserved for nation-state actors are now being handed off to ransomware groups at scale. Microsoft's July Patch Tuesday delivered a record 570 fixes — a 316% year-over-year increase in vulnerability discovery driven by the company's AI-powered MDASH system. Two of those fixes cover zero-days already under active exploitation: CVE-2026-56155 in Active Directory Federation Services and CVE-2026-56164 in SharePoint Server. Dell systems face an additional complication: a hardware compatibility block means they cannot yet receive the update. In healthcare, the Craneware breach exposed customer, employee, and partner data across thousands of US hospitals and pharmacies that rely on its billing software — a textbook supply chain attack delivering leverage across an entire fragmented ecosystem. Also covered: 23.3 million Paidwork user records — including bank account details and bcrypt-hashed passwords — surfaced on cybercrime forums following a March intrusion, and a quietly patched heap overflow in 7-Zip's XZ archive handler is now public knowledge, narrowing the exploitation window fast. A YesWee production. Built using AI technology. This episode includes AI-generated content.

21. juli 20265 min
episode Blockchain C2, EY Tax Breach & SonicWall Root Access artwork

Blockchain C2, EY Tax Breach & SonicWall Root Access

(00:00:00) Blockchain C2, EY Tax Breach & SonicWall Root Access (00:01:17) Microsoft Patch Tuesday 570 Fixes (00:01:55) ViteVenom Blockchain C2 Supply Chain (00:02:45) EY Breach Client Tax Records (00:03:14) WordPress wp2shell RCE Risk (00:03:33) AI Attack Costs and Open-Weight Models (00:03:56) LegacyHive and ModHeader Threats Today's briefing opens with one of the most technically significant stories of the week: UTA0533 exploiting a CVSS 10.0 zero-day chain in SonicWall SMA appliances — CVE-2026-15409 and CVE-2026-15410 — to achieve root access through a WebSocket proxy endpoint and CouchDB path traversal, deploying custom web shells weeks before any patch existed. North Korean-linked group PolinRider pushed seven malicious npm packages impersonating legitimate @vitejs scoped packages, delivering a remote access trojan through a four-tier command-and-control architecture built on public blockchains — Tron, Aptos, and Binance Smart Chain. The infrastructure is effectively unsinkholeable. Domain seizure doesn't apply. This is supply chain attack resilience by design. Ernst and Young confirmed its IT support ticket platform was breached from late March through mid-April, exposing client tax records and investment documents. Detection came nearly three weeks after exfiltration — a blind spot that defines the real risk of third-party privileged platforms. Microsoft's July Patch Tuesday addressed 570 vulnerabilities, two already exploited in the wild: CVE-2026-56164 in SharePoint and CVE-2026-56155 in ADFS. WordPress users face a separate RCE risk via unauthenticated REST API SQL injection across more than 500 million installations. The UK AI Safety Institute benchmarks confirm DeepSeek V4-Pro and GLM-5.2 now match frontier model capabilities for autonomous cyberattacks — at single-digit dollar costs on stripped open-weight models. Also covered: a proof-of-concept Windows User Profile Service exploit bypassing fully-patched July 2026 systems, and the ModHeader Chrome extension — 1.6 million users — pulled after dormant encryption and browsing-history upload code was discovered. This episode includes AI-generated content.

Yesterday6 min
episode SharePoint Zero-Day, FortiBleed Pivot & 500M WordPress RCE artwork

SharePoint Zero-Day, FortiBleed Pivot & 500M WordPress RCE

(00:00:00) SharePoint Zero-Day, FortiBleed Pivot & 500M WordPress RCE (00:00:46) SharePoint IIS Key Persistence Chain (00:01:27) FortiBleed into FortiSandbox RCE (00:02:27) WordPress wp2shell 500M Sites (00:03:00) Gold Eagle Federal Scam Wave (00:03:39) AI Discovery and the Patch Capacity Problem This episode covers four major threat threads converging in a single patch cycle—and why patching alone may not be enough to close any of them. Microsoft's July Patch Tuesday set a new record at 570 vulnerabilities, including two confirmed zero-days: a privilege escalation flaw in Active Directory Federation Services (CVE-2026-56155) and an unauthenticated remote code execution bug in SharePoint Server (CVE-2026-56164). A separate SharePoint deserialization flaw scored CVSS 9.8 and has been chained with three other CVEs in active attacks. The chain includes IIS machine key theft—a persistence mechanism that survives patching if keys aren't rotated and logs aren't audited before remediation. The FortiBleed campaign, running since February, has placed over 86,000 stolen FortiGate credentials into circulation. This week those credentials became the entry point for two newly confirmed FortiSandbox vulnerabilities (CVE-2026-39808 and CVE-2026-39813), enabling unauthenticated root access to the verdict engine itself. CISA's federal remediation deadline is July 19. WordPress issued a rare emergency forced auto-update for CVE-2026-63030, a critical unauthenticated RCE flaw affecting versions 6.9 and 7.0—roughly 500 million sites. Public scanners are already active. A separate social engineering wave is cloning federal portals and using deepfake calls impersonating Treasury and CISA officials to harvest credentials from financial-sector IT staff. Underpinning all of this: Microsoft's MDASH AI tool is accelerating CVE discovery faster than enterprise patch cycles were ever designed to absorb. The bottleneck has moved from finding vulnerabilities to fixing them at scale. This episode includes AI-generated content.

19. juli 20265 min
episode LegacyHive Unpatched, AI Ransomware & SharePoint Triple Exploit artwork

LegacyHive Unpatched, AI Ransomware & SharePoint Triple Exploit

(00:00:00) LegacyHive Unpatched, AI Ransomware & SharePoint Triple Exploit (00:01:02) SharePoint Three-Flaw Exploitation Confirmed (00:01:35) Adobe VMware Browser Critical Patches (00:02:31) AI Ransomware Without a Ransom Demand (00:03:10) Bermuda Ransomware Payout Confirmed (00:03:42) Fairlife Production Halt (00:04:00) Key Watchpoints Going Forward A researcher going by Chaotic Eclipse released LegacyHive, an unpatched Windows User Profile Service zero-day enabling local privilege escalation on every supported Windows version — dropping hours after Microsoft's July Patch Tuesday. Three previous disclosures from the same researcher led to active exploitation, and the weaponization clock is already running on this one. CISA confirmed active exploitation of three simultaneous SharePoint Server vulnerabilities — CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 — covering remote code execution and data theft across on-premises deployments. The chaining risk makes this the most urgent item for enterprise defenders today. This Patch Tuesday also brought 88 Adobe patches, eight covering ColdFusion at CVSS 9.0–9.9; a CVSS 9.8 authentication bypass in VMware's Avi Load Balancer exposing the control plane; and critical browser patches from both Firefox and Mozilla on the same day, with public exploit code already circulating for Firefox. Sysdig documented what appears to be the first fully autonomous AI-driven ransomware operation — over 600 automated actions, no human operators, and deliberately no payment mechanism. The NotPetya parallel is hard to ignore: this looks like rehearsal or state-level operational testing, not a criminal campaign. Elsewhere, a parliamentary report confirmed Bermuda's government paid approximately $4.4 million following its 2023 ransomware attack, and Fairlife halted US dairy production after unauthorised system access — the first major food and beverage supply chain disruption of 2026. Two watchpoints going forward: whether LegacyHive gets weaponised before a patch ships, and whether the autonomous AI ransomware resurfaces with a payment mechanism attached. This episode includes AI-generated content.

18. juli 20265 min
episode LegacyHive Zero-Day, SonicWall CVSS 10.0 & Sandworm's Clickfix Pivot artwork

LegacyHive Zero-Day, SonicWall CVSS 10.0 & Sandworm's Clickfix Pivot

(00:00:00) LegacyHive Zero-Day, SonicWall CVSS 10.0 & Sandworm's Clickfix Pivot (00:01:09) SonicWall CVSS Ten Zero-Days (00:02:06) Microsoft's 622-Patch Cycle (00:02:41) Romania Land Registry Breach (00:03:16) Sandworm Clickfix Ukraine Campaign (00:04:01) NuGet Abuse and Spirals Ransomware A Windows zero-day called LegacyHive dropped publicly hours after Microsoft's July 2026 Patch Tuesday cycle closed — not before, after. Researcher Chaotic Eclipse published a proof of concept targeting the Windows User Profile Service that works on every fully-patched Windows version. Three previous disclosures by the same researcher led to confirmed in-the-wild exploitation. The pattern is the story. Meanwhile, two CVSS 10.0 zero-days in SonicWall SMA 1000 appliances are already being actively chained in real intrusions. CVE-2026-15409 and CVE-2026-15410 let attackers extract credentials and MFA seeds from perimeter devices, then pivot into domain controllers. A security device becomes a persistent backdoor. Patch Tuesday itself brought 622 vulnerabilities this cycle — including a no-auth SharePoint RCE and an Active Directory Federation Services flaw both flagged by CISA for federal remediation by July 17–28. Then LegacyHive arrived the same day, unpatched. Elsewhere: Romania's national land registry ANCPI was hit on July 14 by threat actor ByteToBreach, stalling real estate transactions nationwide. Russia's Sandworm group is using Clickfix — fake CAPTCHA prompts running PowerShell — to deploy FreakyPoll and FluidLeech malware against Ukrainian targets. Eleven malicious NuGet packages were found dropping Starland RAT and WLDR implants disguised as game cheats. And a ransomware variant called Spirals is achieving full network encryption within 24 hours of initial access, outpacing most recovery assumptions. Three open questions heading into the next cycle: Will LegacyHive move from theoretical to confirmed exploitation? Will SonicWall intrusions spread to new sectors? Will Microsoft issue an out-of-band patch? This episode includes AI-generated content.

17. juli 20265 min