Security
Ransomware Gangs Exploit Windows Task Host Flaw; 14,000 Dahua Cameras Hit
CISA flags CVE-2025-60710 as abused by ransomware; a single operator compromises over 14,000 Dahua cameras in Ukraine and Russia.
This edition was produced with artificial intelligence. Text and voice are generated automatically.
CISA Warns Ransomware Gangs Exploit Windows Task Host Privilege Escalation Flaw
CISA has confirmed that ransomware gangs are actively exploiting a high-severity Windows Task Host vulnerability, tracked as CVE-2025-60710. The flaw, a link following weakness affecting Windows 11 and Windows Server 2025, allows local attackers with basic user permissions to gain SYSTEM privileges and take full control of unpatched devices. Microsoft patched the vulnerability in November 2025, and CISA added it to its Known Exploited Vulnerabilities Catalog on April 13, giving Federal Civilian Executive Branch agencies two weeks to secure their systems.
On Friday, CISA updated its KEV catalog to flag the vulnerability as being abused by ransomware gangs, though it has not shared details about ongoing attacks. Microsoft has yet to update its security advisory to confirm in-the-wild exploitation. CISA warned that such vulnerabilities pose significant risks to the federal enterprise and advised agencies to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Since November 2021, CISA has flagged 383 actively exploited vulnerabilities in Microsoft products, 112 of which have also been exploited in ransomware attacks.
CISA: Windows Task Host flaw now exploited by ransomware gangs →
Kimi Desktop Updater Installs Unverified Code from Mutable CDN
Moonshot AI’s Kimi Desktop ships with a group chat updater that automatically installs a separate Group Chat executable from a mutable CDN location, according to RuntimeWire. On Windows, the updater replaces that executable without checking a checksum or enforcing its publisher signature. The current 19.7MB executable carries a valid Moonshot Authenticode signature, but the updater never verifies it, and the Windows branch explicitly skips the checksum routine. The ZIP archive delivered by Moonshot contains no checksum file.
The update path depends on control of a mutable latest archive and HTTP metadata including ETag, Last-Modified, and content length. An actor with access to the associated publishing path or release process could substitute native code that Kimi would install through its ordinary update mechanism. RuntimeWire found no evidence of an active compromise.
Kimi Desktop Ships With a Group Chat Updater That Can Install Unverified Code →
Single Operator Compromises Over 14,000 Dahua Cameras in Ukraine and Russia
Between 17 June and 22 July 2026, a single operator compromised over 14,000 Dahua IP cameras, with confirmed geolocated compromises concentrated in Ukraine and Russia, Ukraine holding the largest share. The operator’s scanning was global, running masscan sweeps against Russian address space first, then the full IPv4 range. On 23 July, Hunt.io AttackCapture crawled the operator’s exposed server at 154.86[.]119.60, recovering 2,616 files across 234 subdirectories (407 MB) from an open HTTP directory. The exposure traced to a command in shell history that started a Python HTTP server bound to all interfaces.
The campaign compromised 14,530+ devices across three exploitation paths. A credential brute-force engine reached 12,324 unique IPs on port 37777, while an authentication-bypass chain (p2pwn) compromised 1,923 cameras, installing a persistent backdoor account that survives password changes and, on most firmware, factory resets. A P2P relay exploitation path reached 283 cameras by serial number alone through Dahua’s cloud relay, with 89.4 percent of live serials requiring no authentication. The operator also generated offline recovery codes granting cloud-level administrative access by serial number. The p2pwn binary chained two authentication bypasses, CVE-2021-33044 and CVE-2021-33045, both returning full administrator sessions unauthenticated in under a second. Recovered logs covered 24 runs between 17 June and 13 July, with roughly 13,000 device credentials recovered across twelve productive runs.
Operation CameraSwarm: Over 14,000 Dahua cameras compromised across Ukraine and Russia →
China-Linked APT Uses AI to Optimize Hand-Built Malware in SilkParasite Campaign
China-linked threat actors used seven malware families, five previously unknown, in a campaign dubbed SilkParasite that ran on systems of government agencies across Central Asia for almost a year in 2025, according to Bitdefender. The toolset is described as small, modular and professionally engineered, carrying traces of AI-assisted development within otherwise expert code. The main delivery method is DLL sideloading, with initial footholds gained through malicious Microsoft Office files, likely delivered via spear-phishing emails. In several cases, lure documents were packaged inside password-protected RAR archives, with the password supplied in the email body.
The seven malware families, including DriveSilkRAT, SpiceRAT, and NomadRAT, were written in four languages and nearly all support a plug-in approach allowing additional capabilities to be loaded from the attacker’s command-and-control server. Researchers found traces of AI in two families: Go-based GoginRAT had test functions left inside that would normally be stripped before deployment, and used a hardcoded AES key set to 0123456789abcdef. NomadRAT, written in C++, set the configuration field for an encryption key to change_this_key. Researchers said APT-grade malware remains firmly the work of human professionals, and that what such groups can use from AI is assistance, not generation.
China-Linked APT Uses AI to Optimize Hand-Built Malware →
Chainalysis Sues US Government Over $94.6M ICE Contract Awarded to TRM Labs
Chainalysis Government Solutions filed a bid protest on July 27 in the U.S. Court of Federal Claims challenging ICE’s roughly $94.6 million sole-source contract awarded to rival TRM Labs. The one-year deal runs from July 1, 2026, through June 30, 2027, and covers blockchain forensic software and support services for Homeland Security Task Force investigations, including scams, cybercrime, and sextortion cases. Chainalysis argues the award was arbitrary, capricious, and unreasonable, and says it submitted a capability statement after the agency signaled its intent to buy from a single provider.
The court granted Chainalysis permission on July 31 to keep its complaint under seal because it contains confidential business information and trade secrets. TRM Labs entered the case on July 28 as a defendant-intervenor alongside the government. Judge Stephen Schwartz has set oral arguments for September 2 under an expedited schedule, with the government requesting a decision by September 10. ICE justified the award by citing a roughly six-day market-research window in which eight companies responded, four of them small businesses, and the agency found none could match TRM’s capabilities.
Chainalysis Sues US Government Over $94.6M ICE Contract Handed to Rival TRM Labs →