HeadFlash

Security

Security Pulse: Critical CVEs, State-Sponsored Attacks & Record Sentences

Critical patches, active exploits, state-sponsored espionage, and landmark cybercrime sentences dominate today's security update.

Listen

Unauthenticated Debug Port in Rockwell Adapter Gives Attackers Plant-Floor Control

The Rockwell Automation 1715-AENTR EtherNet/IP Adapter, widely used in North American energy, water treatment, and critical manufacturing facilities, contains a debug port that requires no authentication for remote access. Through that port, an attacker can directly change physical I/O states controlling valves, actuators, and machinery on a plant floor. The vulnerability, tracked as CVE-2026-10577, received a CVSS 3.1 score of 10.0 and a CVSS 4.0 score of 10.0 – the maximum on both scales. All firmware versions at or below 3.003 are affected. Rockwell discovered the flaw internally and self-reported it to CISA. No confirmed exploitation has been reported as of publication. The fix is firmware version 3.011 or later. CISA recommends minimizing network exposure, isolating control systems behind firewalls, and using VPNs for remote access.

Unauthenticated Debug Port in Rockwell Adapter Gives Attackers Plant-Floor Control →

GoSerpent Backdoor Looted Police and Biometric Data Across Southeast Asia for Five Years

A sophisticated espionage campaign using the Go-based backdoor GoSerpent infiltrated Southeast Asian government networks for at least five years, targeting police complaint management systems, biometric databases, criminal case files, and diplomatic networks. Kaspersky’s GReAT team disclosed the operation on July 16, 2026. GoSerpent, a remote access Trojan written in Go, has been in use since at least 2021. It encrypts command-line arguments with AES-CBC and uses ChaCha20 for C2 traffic, disguising itself as lass.exe or updates.exe. A companion tool, McMx RAT, ran alongside it. Attackers typically waited days before pushing additional payloads, starting with ThumbcacheService – a malicious DLL that hunts for documents, compresses them with 7-Zip, and stores them as thumbcache_605a.db. In a second phase, they deployed the Stowaway proxy framework and TmcLoader to exfiltrate data via authenticated network shares using stolen credentials. Kaspersky assesses a probable link to TetrisPhantom but has not attributed the campaign to any nation-state. Recommended defenses include searching for thumbcache_605a.db, auditing Windows service registrations, and blocking credential-dumping tools.

GoSerpent Backdoor Looted Police and Biometric Data Across Southeast Asia for Five Years →

An Alleged Russian FSB Hacker Traveled To Thailand. Now He’s Facing 10 Years In A US Prison.

Denis Obrezko, a 35-year-old Russian IT programmer, was detained by Thai police in Phuket on November 6 on a US warrant and later extradited to Boston, where he pleaded not guilty to hacking nearly a dozen US companies and government agencies. He faces up to 10 years in prison. Obrezko worked for the FSB between 2012 and 2017 and later served as deputy director at Yutek-NN, a company licensed to sell covert surveillance equipment. US court filings state Yutek stole emails from NATO-aligned government agencies and organizations supportive of Ukraine at the behest of the Russian government. FBI investigators traced cryptocurrency transactions to an email address directly linked to Obrezko’s real name, Google account, and social media profiles. Hours after Microsoft’s May 2025 report naming the hacking group Void Blizzard, Obrezko emailed a co-conspirator to meet. His defense lawyer said he intends to defend the case vigorously.

An Alleged Russian FSB Hacker Traveled To Thailand. Now He’s Facing 10 Years In A US Prison. →

Cisco Sounds Alarm Over New Russian Malware Campaign Hitting Firms in US and Europe

Cisco Talos has identified a new Russian-speaking threat actor tracked as UAT-11795, active since June 2024, targeting victims in the US and Europe. The group uses trojanized installers for legitimate software like MobaXterm, WebEx, Zoom, and DBeaver to steal credentials and cryptocurrency. It deploys two previously undocumented tools: Starland RAT, a Python-based remote access tool, and WLDR agent, a PowerShell-based C2 memory implant. Both tools steal credentials, browser data, and cryptocurrency wallet assets while maintaining persistent access. The group hides a fallback C2 channel in a Polygon smart contract. Initial access is gained through a ClickFix social engineering technique that tricks users into executing a command. Most infections have been observed in the US, with additional victims in Germany, Romania, and Venezuela. Cisco also uncovered a private Telegram channel controlled by the same actor. Security experts warn that hiding malware inside trusted software and using ClickFix bypasses traditional defenses by exploiting human psychology.

Cisco sounds alarm over new Russian malware campaign hitting firms in US and Europe →

Vishing Call Brought Down TfL: Scattered Spider Duo Jailed in Record UK Prosecution

Two members of the Scattered Spider cybercrime collective, Owen Flowers (18) and Thalha Jubair (20), were each sentenced to five years and six months in prison on July 16, 2026, for a 2024 attack on Transport for London. The National Crime Agency called it the largest cybercrime prosecution ever brought before UK courts. The attack disabled 148 systems, forced 27,000 TfL employees to reset passwords in person, and exposed the personal data of an estimated 10 million passengers. Losses and recovery costs totaled £29 million. Flowers and Jubair purchased employee credentials from criminal forums, then called the IT helpdesk impersonating a TfL employee to reset a password and bypass two-factor authentication. Once inside, they escalated privileges and moved laterally. Court documents revealed their apparent plan to wipe access on the way out, but TfL took its network down to contain them. Both pleaded guilty on June 22, 2026, the first day of a scheduled trial. Sentencing judge Mr Justice Turner cited the sophistication and scale of the offense. Jubair also faces US federal charges for approximately 120 network intrusions with over $115 million in ransom payments. The NCA said the arrests materially degraded Scattered Spider’s operations.

Vishing Call Brought Down TfL: Scattered Spider Duo Jailed in Record UK Prosecution →

North Korea Buried Four-Stage Malware in Flag Images: Zero Antivirus Detections

North Korean state-sponsored hackers operating under the Contagious Interview campaign hid a four-stage malware payload inside HTML comment blocks of SVG country flag images, achieving zero detections from any antivirus engine at the time of discovery. Elastic Security Labs disclosed the campaign as REF9403. Attackers embedded Base64-encoded fragments into comment blocks across every SVG flag image in a project’s assets directory. A JavaScript file called serverValidation.js reconstructed the payload by reading all SVG files alphabetically, extracting comment content, and concatenating fragments into a complete Base64 string. The decoded payload executed via eval. The malware used obfuscator.io for JavaScript obfuscation. Elastic discovered the campaign after a user named Maxwell posted a fake job offer in Elastic’s Slack channel. Users who responded received a trojanized GitHub repository disguised as a coding challenge based on a legitimate e-commerce project. Once executed, the payload deployed four modules in parallel masquerading as npm-cache processes: Stage 1 targeted browser credentials and cryptocurrency wallets; Stage 2 swept filesystem for sensitive files; Stage 3 established persistent encrypted C2; Stage 4 exfiltrated clipboard content and downloaded additional binaries. Elastic attributed the campaign to North Korea’s Contagious Interview operation, linked to Lazarus Group and the Reconnaissance General Bureau. Between January 2025 and April 2026, over 1,700 malicious packages linked to this group were tracked across multiple package registries.

North Korea Buried Four-Stage Malware in Flag Images: Zero Antivirus Detections →

FortiSandbox Exploited in Wild: Patch by Sunday or Trust Chain Collapses

CISA confirmed on July 16, 2026, that two critical command injection flaws in Fortinet’s FortiSandbox threat-analysis platform are being actively exploited. Federal civilian agencies have until Sunday, July 19 to apply patches or pull affected systems offline. FortiSandbox delivers threat verdicts to Fortinet firewalls, email gateways, and other security tools; compromising it allows attackers to forge those verdicts. CVE-2026-39808 (CVSS 9.1) affects the API endpoint and allows an unauthenticated attacker to execute commands as root via a single curl command. A public proof-of-concept exploit has been available since April. CVE-2026-25089 (CVSS 9.1) targets the web UI. CISA marked ransomware association as unknown but Defused reported exploitation attempts against both CVEs in the 24 hours prior. Separately, the FortiBleed campaign has been running since February 2026, with a verified credential database of 86,644 FortiGate devices across 194 countries. SOCRadar attributed FortiBleed to operators linked to the Lynx/INC ransomware group, with at least 12 confirmed ransomware deployments traced to those credentials. FortiSandbox appliances typically reside on the same management network as FortiGate firewalls, making the two campaigns potentially sequential. Organizations must patch FortiSandbox to 4.4.9 or 5.0.6 and complete FortiBleed remediation.

FortiSandbox Exploited in Wild: Patch by Sunday or Trust Chain Collapses →

Trump Says China Stole 220 Million U.S. Voter Files in Largest Election-Data Breach

China acquired 220 million U.S. voter files in what officials called the largest election-data compromise in history, according to newly declassified documents released by Donald Trump during a primetime address on July 17, 2026. The breach began during the 2020 election cycle and exposed names, addresses, phone numbers, and political party preferences. The stolen data would be sufficient to register to vote and carry out other illicit activity. Trump stated that Beijing assigned a dedicated data exploitation unit to the effort. The disclosures formed part of a broader White House release on election integrity covering January 2020 to June 2026. Intelligence assessments warned that Russia, China, Iran, and North Korea have the capability to compromise U.S. election infrastructure and that centralized voter registration databases remain the most vulnerable to exploitation.

Trump says China stole 220 million U.S. voter files in largest election-data breach →

Cybercriminals Released 802,000 Stolen Accounts in One Day During World Cup Group Stage

HUMAN Security’s Satori Threat Intelligence team found 12 million compromised streaming accounts tied to World Cup broadcasts on the dark web, representing nearly $220 million in potential black-market sales. The accounts spanned 10 streaming services carrying tournament matches. On June 27, the final day of the group stage, threat actors released a record 802,000 accounts in a single day, generating an estimated $14.8 million in potential revenue. Stolen accounts sold for as little as $5, compared to legitimate subscriptions costing $30 to $50. The accounts were likely obtained through credential-stuffing attacks or info-stealing malware. Over 4,300 fake FIFA domains and banking malware hidden in streaming apps were targeting fans before the tournament. Fubo said it prepared for high-traffic events and monitored for suspicious geolocation patterns. Other streaming services did not respond to requests for comment.

Cybercriminals released 802,000 stolen accounts in one day during the World Cup group stage →

wp2shell: Pre-Auth RCE in WordPress Core (CVE-2026-63030)

WordPress patched a pre-authentication remote code execution chain named wp2shell in an emergency 7.0.2 release on July 17, 2026, and pushed forced auto-updates to affected sites. The chain, disclosed by Adam Kues of Assetnote and Searchlight Cyber, combines a REST batch-route confusion bug (CVE-2026-63030) with a core SQL injection (CVE-2026-60137) to achieve code execution on a stock WordPress install with no login required. The batch-route bug serves as an authentication bypass, turning an anonymous request into full site compromise. A default WordPress install with no plugins is vulnerable. Versions affected include 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1; the SQL injection also affects 6.8.x. WordPress released fixes in 6.8.6, 6.9.5, and 7.0.2. Early exploitation has been reported, and a working exploit tool named Ultimate-wp2shell is now openly hosted on GitHub under an MIT license, promoted via a Telegram channel. Site owners should verify their installed version and apply the update if not auto-applied. As a stopgap, block requests to /wp-json/batch/v1 and restrict anonymous REST API access.

wp2shell: pre-auth RCE in WordPress core (CVE-2026-63030) | Ransomnews →

Firefox Exploit Code Goes Public as Chrome, Adobe, VMware Ship Emergency Patches

On July 15, 2026, Mozilla shipped emergency security patches for Firefox, confirming that working exploit code for two critical vulnerabilities is publicly available, though no attacks have been observed in the wild. Firefox 152.0.6 patches CVE-2026-15718 (invalid pointer in JavaScript/WebAssembly) and CVE-2026-15719 (site isolation bypass in Fission architecture). The same day, Google released Chrome 150.0.7871.124/125 addressing 15 vulnerabilities, including two critical use-after-free flaws in the Ozone display layer (CVE-2026-15764 and CVE-2026-15765). Adobe patched 88 vulnerabilities, with eight critical-severity ColdFusion flaws (CVSS 9.0-9.9) remediated in ColdFusion 2025 Update 11 and 2023 Update 22. Broadcom patched CVE-2026-47865, an authentication bypass in VMware’s Avi Load Balancer with a CVSS score of 9.8. None of these vulnerabilities were on CISA’s Known Exploited Vulnerabilities catalog as of publication, though a separate Chrome V8 flaw (CVE-2026-11645) was added after confirmed exploitation. Users should apply updates immediately, especially for Firefox and Chrome where public exploit code exists.

Firefox Exploit Code Goes Public as Chrome, Adobe, VMware Ship Emergency Patches →

EY Tax Data Stolen Through Third-Party Help-Desk Platform, Four States Notified

Attackers accessed Ernst & Young’s third-party helpdesk platform from March 28 to April 12, 2026, and downloaded client tax files attached to support tickets. EY’s security team detected the intrusion on April 23, 2026. No malware or ransomware was deployed, and no threat actor had claimed responsibility as of July 17. The stolen data includes Social Security numbers, financial account codes, credit and debit account data, investment holdings, and contents of client tax filings. Regulatory filings have been made in California, Vermont, Massachusetts, and Texas, covering at least 1,366 residents across those four states. The actual affected population is likely much larger, given EY’s global client base. EY is offering 24 months of credit and identity monitoring through Experian IdentityWorks. Security professionals recommend placing credit freezes and enrolling in the IRS Identity Protection PIN program. The IRS warns that the window between data theft and fraudulent tax return filing can be as short as 48 hours.

EY Tax Data Stolen Through Third-Party Help-Desk Platform, Four States Notified →

FBI Arrests 21-Year-Old Accused of Infecting 8,000 PCs with Malware Through Fake Steam Games

The FBI arrested 21-year-old Zyaire Dontaevious Zamarion Wilkins, a Florida resident, on charges of stealing more than $220,000 in cryptocurrency through malware hidden in video games. Wilkins is accused of operating a cybercrime scheme with unnamed co-conspirators for nearly two years. The group infected approximately 8,000 PCs by embedding malware in at least eight video games and stole at least $220,000 from roughly 80 cryptocurrency wallets between May 2024 and February 2026. The infected games, including BlockBlasters, Dashverse, Lunara, and PirateFi, were available on Steam until recently. The FBI tracked the suspects by linking stolen bitcoin to more than 150 Bitrefill gift cards used primarily for Uber Eats orders. According to researchers, BlockBlasters alone accounted for roughly $150,000 of the stolen cryptocurrency, including $32,000 stolen from a Twitch streamer undergoing cancer treatment. Investigators identified a suspected malware developer and recovered Signal chats linking Wilkins to the operation. Wilkins allegedly operated under the dark web alias Sibel.eth and purchased a $10,000 remote access trojan.

FBI arrests 21-year-old accused of infecting 8,000 PCs with malware through fake Steam games →

It’s Laughably Easy to Poison Open-Weight AI Models, Researcher Finds

Open-weight AI models available for anyone to download and run can be poisoned with an attack that took less than an hour and cost less than $100 to carry out, according to cybersecurity researcher Katie Paxton-Fear of Semgrep. By training the model on just ten examples of poisoned material, the model began producing code vulnerable to remote code execution. Paxton-Fear described the result as ‘a proper backdoor.’ Backdoors involve training an AI to introduce hidden phrases that can quietly trigger a specific action. Research published by Anthropic last year showed that both small and large AI models are vulnerable using just a few hundred documents. While open-weight models offer transparency in parameters, they do not reveal training data or code, making them still function as black boxes. Semgrep researchers noted that ‘AI models are different’ from traditional software, as a compromised model does not need to break to create business risk—it only needs to influence decisions in ways that are difficult to detect. Paxton-Fear questioned whether fine-tuned open-weight models marketed as solutions can be trusted.

It’s Laughably Easy to Poison Open-Weight AI Models, Researcher Finds →