Patch & Defense
Practical, prioritized guidance — Patch Tuesday, the KEV tracker, what to actually do.

jscrambler 8.14.0 npm hijack: Rust stealer on install
Malicious jscrambler 8.14.0 on npm shipped a preinstall hook that dropped a Rust infostealer targeting cloud creds, wallets, and AI-coder configs.

Gitea Docker Auth Bypass: Patch 1.26.4, CSA Confirms
Sysdig confirms the first in-the-wild hit on Gitea Docker CVE-2026-20896; Singapore CSA now warns customers; 1.26.3 shipped with a regression, so run 1.26.4.
Silver Fox ships MODBEACON, a Rust RAT with gRPC C2
QiAnXin attributes a new Rust-based RAT called MODBEACON to Silver Fox, using gRPC streaming for encrypted C2 and SEO-poisoned installers for delivery.

Balbooa, iCagenda Join KEV: Four Joomla RCEs in Four Days
CISA added Balbooa Forms and iCagenda to KEV on July 10 — two unauthenticated file-upload RCEs in Joomla extensions. Federal due date is July 13.

Zimbra ships 10.1.19; Google TAG reported the XSS
Zimbra 10.1.19 patches a stored XSS in the Classic Web Client. No CVE yet, no confirmed exploitation — Google TAG reported it, which is the reason to patch now.

OpenMandriva ex-contributor wipes GNOME, Cosmic packages
Mumble developer Davide Beatrici used leftover admin from a repo migration to delete OpenMandriva GitHub content and obsolete GNOME, Cosmic packages.

Injective SDK 1.20.21 on npm shipped a wallet stealer
Attacker pushed @injectivelabs/sdk-ts 1.20.21 with mnemonic and private-key exfil after compromising a contributor's GitHub. 310 installs before the pull.

Forg365 PhaaS Chains AiTM + Device-Code + AI Lures at M365
ZeroBEC flagged a new phishing-as-a-service, Forg365, bundling AiTM proxying with OAuth device-code prompts and AI lures against Microsoft 365 accounts.

Microsoft patches Defender 'RoguePlanet' LPE; PoC public
Microsoft shipped an out-of-band Defender engine update for RoguePlanet (CVE-2026-50656), a race-condition LPE to SYSTEM. Public PoC. Verify auto-update landed.

SimpleHelp OIDC Auth Bypass Past CISA Deadline: Patch Now
SimpleHelp Server 5.5.15 and earlier accept forged OIDC tokens as valid technician sessions. CVSS 10.0, KEV, patch is 5.5.16 — CISA deadline was July 2.

WriteOut: One Preview Link Took Over Writer AI Accounts
SAND Security's WriteOut let a Writer AI agent preview link steal a signed-in user's session cookie across tenants. Writer has patched — the pattern hasn't.

GitLost: Public Issue Leaks Private GitHub Repo Data
Noma Security's GitLost shows how a public GitHub issue can trick Agentic Workflows into leaking private repos. Not patchable — scope your agent tokens today.

GhostLock: 15-Year Linux Kernel Root/Container Escape
Nebula Security's GhostLock (CVE-2026-43499) — a 15-year-old futex use-after-free — hits every mainstream Linux distro. Escapes containers. Patch again.

CISA Adds Langflow and Two Joomla Builders to KEV
CISA added three vulnerabilities to KEV on July 7 — a Langflow IDOR and two Joomla page-builder RCEs. Federal due date is July 10. Priority order below.

Tenda Router Backdoor Has No Patch. Here's What to Do.
CERT/CC flagged an authentication backdoor in multiple Tenda router firmware builds. Tenda didn't respond. No fix is coming — here's the mitigation.

BeyondTrust Patches Four RS/PRA Flaws — Patch Now
BeyondTrust shipped fixes on July 6 for four vulnerabilities in Remote Support and Privileged Remote Access, including a CVSS 9.8 pre-auth bypass. No in-wild exploitation reported. Here's the priority order.

Gitea Docker's Auth Bypass: Probing Already Underway
The Gitea Docker image up through 1.26.2 shipped a wildcard reverse-proxy trusted list, collapsing auth to a header. Fixed in 1.26.3. The Hacker News reports opportunistic scanning 13 days after disclosure; ~6,200 exposed instances.

Adobe ColdFusion CVE-2026-48282: CVSS 10, Exploited
A max-severity unauthenticated path-traversal-to-RCE in ColdFusion 2023 and 2025 is under active attack. Adobe's 72-hour patch window has already passed. Shadowserver counts ~800 exposed instances.

QuimaRAT: A $150 Cross-Platform Java RAT MaaS
LevelBlue profiled a new cross-platform Java RAT sold as MaaS. No confirmed campaigns yet — but the price is low, the payload runs everywhere, and the loader is built to walk past SmartScreen. Assume it lands somewhere soon.

Opera GX Patches Auto-Install Mods Flaw
Opera fixed a flaw that let a malicious website force-install a GX Mod and use CSS injection to lift data from pages you visited. Patched; no CVE; no in-wild exploitation reported.

SkillCloak: Scanners Miss 90%+ of Skill Malware
HKUST researchers show static scanners for AI agent skill marketplaces miss over 90% of malware repackaged with simple tricks. If you rely on them, that gate is broken.

Flipper Zero Firmware Goes Maintenance-Only
Flipper Devices says the Flipper Zero firmware is stable at 1.0 and full-time feature work is over. Community PRs run the future, filtered through GitHub Discussions voting and stricter review. Here's what changes.

Metasploit's July 3 Drop: SMB-to-Meterpreter, Peyara
Rapid7 shipped an SMB-to-Meterpreter session upgrade and a Peyara Remote Mouse RCE module this week. Neither is novel research. Both change what your alerts will look like. Here's the tune.

PolinRider: DPRK Seeds 108 Malicious Packages
The Hacker News reports 108 malicious npm, Packagist, Go, and Chrome extension listings tied to the DPRK Contagious Interview cluster. Here's what a dev shop actually does about it this week.

Umbrij: ToddyCat Hijacks Gmail OAuth via Browser
Kaspersky Securelist detailed Umbrij, a ToddyCat post-compromise tool that self-grants Google Workspace OAuth tokens by driving a logged-in Chromium session. Nothing to patch. Plenty to audit.

ARToken PhaaS Targets M365 Device-Code Phishing
Cisco Talos exposed ARToken, a React-panel phishing-as-a-service tied to EvilTokens. Device code flow is the mechanic. Conditional Access is the fix, and most tenants still haven't turned it on.

ChocoPoC: Fake CVE PoC Repos Ship a Stealer
YesWeHack and Sekoia disclosed a stealer campaign hiding inside GitHub PoC repos and PyPI packages, targeting the researchers who clone them. Treat every fresh 'PoC for hot CVE' repo as hostile until you've read every dependency.

Bad Epoll: Linux Kernel LPE Also Hits Android
A newly disclosed use-after-free in Linux 6.4+ kernels lets an unprivileged local user gain root. Android on affected kernels is in scope; the upstream fix is in.

PamStealer: A Fake Maccy Site Steals macOS Creds
Jamf Threat Labs disclosed a new macOS credential stealer today that impersonates the Maccy clipboard app, validates the victim's login password against PAM in real time, and exfiltrates keychain and browser data. Apple Silicon only. Here's what defenders should do.

Cisco Confirms Active Exploitation of Unified CM Flaw
Cisco updated its Unified Communications Manager advisory this week to state attackers are exploiting the flaw in the wild. Patched builds have been out for a month. If yours isn't on one, that's the whole conversation.

Kemp LoadMaster Pre-Auth RCE: PoC Is Out, Patch Now
A functional proof-of-concept for a critical pre-auth RCE in Progress Kemp LoadMaster hit the internet on June 29 and eSentire started seeing exploitation attempts the same day. Progress's fix has been available since June 4.

SharePoint RCE now on CISA KEV: patch it this week, not next
CISA added CVE-2026-45659, a high-severity SharePoint Server deserialization RCE, to the Known Exploited Vulnerabilities catalog on July 2 after confirming active exploitation. Microsoft's May patch is your remediation.



