
Coverage: Last 72 hours
Today’s Highlights
This week brings a blend of critical RCE disclosures, novel campaign tradecraft, and continued ransomware fallout. Highlights include unpatched exploitation against critical Java libraries, public PoCs against core developer platforms, and targeted malvertising capable of defeating network-based filtering. Ransomware-as-a-service models keep maturing, while active phishing operations now pair credential theft with real-time session hijacking.
Table of Contents
- MCBS Data Breach Affects 1.2 Million Individuals
- Rockwell Patches Code Execution Flaws in Arena Simulation Software
- Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
- CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking
- Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
- DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
- BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
- Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft’s Servers
- Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
- Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
Top Stories
MCBS Data Breach Affects 1.2 Million Individuals
Source: SecurityWeek | Risk: High | Impacted: Healthcare and insurance vendors, Patients and covered individuals, Business associates of MCBS
Summary: The PEAR ransomware group claimed to have stolen 3 TB of information from the medical business management company. The post MCBS Data Breach Affects 1.2 Million Individuals appeared first on SecurityWeek.
Why it matters: Ransomware-linked data breaches of medical management providers expose both business and regulated personal data, leading to prolonged operational, legal, and reputational harm.
Practitioner Perspective Any organization in healthcare supply chains, especially those handling third-party medical billing or records, should expect that the PEAR ransomware incident at MCBS may catalyze additional attacks and regulatory scrutiny. Large-scale data theft (3TB, 1.2M individuals) signals not just IT compromise but business process risk. Customer, patient, and insurer disclosures and notifications will drive downstream urgency. Boards and GRC functions should reassess vendor security posture, breach notification plans, and recovery runbooks specific to SaaS-driven medical operations.
Recommended Actions – Request evidence of SaaS provider security and incident response maturity in the wake of the MCBS breach – Review data flows involving MCBS or similarly situated vendors for unauthorized access or exfiltration
Rockwell Patches Code Execution Flaws in Arena Simulation Software
Source: SecurityWeek | Risk: High | Impacted: Industrial engineering firms, Critical infrastructure operators, Organizations using Rockwell Arena
Summary: A researcher has explained how an attacker could exploit these vulnerabilities to target industrial organizations. The post Rockwell Patches Code Execution Flaws in Arena Simulation Software appeared first on SecurityWeek.
Why it matters: Code execution bugs in engineering software used by industrials offer a privileged pivot point into operational environments that often lack robust segmentation or real-time detection.
Practitioner Perspective Rockwell Arena is common in industrial simulation and digital twin environments, which are often interconnected with sensitive plant operations. An attacker exploiting recent code execution flaws can bridge IT and OT environments, escalate privileges, and move laterally, a critical consideration for regulated or high-availability industries. This also highlights the urgent need to treat software used by engineers and plant designers as a primary security blind spot. Prioritize patching and access reviews on simulation and modeling software with privileged connectivity.
Recommended Actions – Apply Rockwell’s patch for Arena simulation software to all endpoints and engineering workstations – Audit cross-domain communications between Arena systems and core OT assets for unauthorized or unexpected activity
Emerging Signals
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
Source: The Hacker News | Risk: High | Impacted: Retail trading platforms, Browser security gateways, Ad-driven web properties
Summary: A malvertising operation dubbed SourTrade is making victims’ browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file from a fixed URL. Confiant, which detailed the campaign on July 23, 2026, said it has operated since late 2024 and impersonated TradingView, Solana, and Luno to target retail traders
Why it matters: Delivering malware through chunked browser-side assembly can bypass legacy web filtering and raise the likelihood of initial compromise for organizations relying solely on network controls.
Practitioner Perspective This is a threat to any organization relying on browser isolation, proxy-based controls, or legacy malware gateways: splitting executables into non-malicious fragments before in-browser reassembly makes detection much harder. Financially motivated actors are impersonating trusted fintech brands like TradingView, Solana, and Luno, showing an agile targeting capability. Browser exploitation chains that use legitimate runtimes like Bun complicate file-based detection and sandboxing. Security teams should anticipate similar techniques becoming common in future malvertising and watering-hole attacks. Your primary defense is hardened browser posture, reducing plugin surface, and rapid threat intelligence integration for emerging domains.
Recommended Actions – Update detection logic in EDR and SWG solutions for Bun runtime spawning as a child of browser processes – Block domains and network indicators associated with SourTrade and impersonated fintech brands (TradingView, Solana, Luno)
CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking
Source: The Hacker News | Risk: High | Impacted: Insurance companies, Financial institutions, Staff using SSO or browser-based sessions
Summary: For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attackers collected the credentials, and accounts were compromised later when an opportunity arose. That model is changing. Recent investigations into insurance-focused phishing operations reveal a more immediate approach. Instead of harvesting
Why it matters: Real-time phishing leads to nearly immediate account hijack, bypassing legacy detection rules that rely on delayed use of stolen credentials.
Practitioner Perspective Financial, insurance, and similarly targeted industries must now defend against phishing designed to automate session hijacking as soon as users authenticate. Traditional controls like phishing site takedown and credential use monitoring lag behind these adaptive, just-in-time adversaries. These attacks limit defenders’ dwell time for intervention close to zero. Modern 2FA and consistent session monitoring are mandatory to impede this shift. Teams must revisit incident response playbooks to reflect shortened timeframes for detection and user notification.
Recommended Actions – Deploy real-time session anomaly detection focusing on suspicious access immediately after login – Force step-up authentication for insurance or financial portals when high-risk activity is detected
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
Source: The Hacker News | Risk: Critical | Impacted: PTC Windchill/FlexPLM deployments, Product design/engineering environments, Manufacturing organizations
Summary: Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign. “Attackers chain a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet, enabling
Why it matters: Exploiting chained flaws in PTC Windchill and FlexPLM exposes industrial and design data to high-stakes data extortion, especially for organizations lacking segmentation of legacy engineering systems.
Practitioner Perspective Firms deploying PTC Windchill or FlexPLM without strong network isolation are now prime targets for ransomware affiliates like Cl0p. Attackers are combining a pre-auth info disclosure with server-side RCE for unauthenticated compromise, enabling immediate lateral movement and exfiltration. Given FIN11/Graceful Spider track record, expect both data theft and operational disruption. You must know if these apps are internet-exposed or reachable through your DMZ, and swiftly address architectural gaps. Assume that ransomware tradecraft will continue targeting software with similar architectures and segmentation weaknesses.
Recommended Actions – Isolate Windchill and FlexPLM servers from public internet and restrict access to trusted internal segments only – Apply vendor-published mitigations or hotfixes to address WSDL info disclosure and login servlet flaws immediately
DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
Source: The Hacker News | Risk: High | Impacted: Organizations with Windows endpoints, SMBs with limited SOC coverage, Victims of prior ransomware incidents
Summary: The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims. Swiss cybersecurity company PRODAFT is tracking the centrally administered RaaS operation under the name Funky Mantis. “The portal combined build generation, finance,
Why it matters: Centralized payload generation and victim management in RaaS platforms enable more rapid, scalable, and professionalized ransomware delivery, multiplying the number of capable attackers.
Practitioner Perspective Defenders should anticipate that the DevMan RaaS model, tracked as Funky Mantis, will be mimicked by other criminal groups: dumbing down ransomware deployment means more affiliates and more attacks without technical sophistication. The convergence of build automation, earnings, and victim control on a single platform substantially reduces the barrier for new operators. You cannot rely on outdated threat intelligence or traditional IOC lists, expect diverse and frequently mutated ransomware payloads. Strengthen behavioral detection of lateral movement and post-exploitation tooling indicative of RaaS playbooks.
Recommended Actions – Update anti-malware solutions with TTPs and IOCs associated with Funky Mantis and DevMan payloads – Monitor for new or unusual payload compilation signatures across Windows endpoints and file servers
BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
Source: The Hacker News | Risk: High | Impacted: Cryptocurrency-focused companies, High net-worth individuals, Collaboration platform users
Summary: The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malware. “BlueNoroff has operationalised trust abuse by combining compromised industry contacts, social engineering, wallet
Why it matters: Advanced social engineering targeting video conferencing platforms is now coupled with detailed victim profiling of crypto assets prior to malware delivery, raising the stakes for both corporate and individual targets.
Practitioner Perspective Organizations whose staff are active in cryptocurrency or financial services should treat Zoom and Teams-branded phishing as a current, elevated threat. BlueNoroff’s combination of typosquatted domains, wallet enumeration, and industry tradecraft shows North Korean actors are selecting for high-value targets. These operations are a clear sign that commodity phishing is merging with targeted collection, especially for crypto-holding organizations. Proactively identify who in your environment manages wallets and focus enhanced controls and awareness in that group.
Recommended Actions – Block access to known typosquatted Zoom and Teams domains identified in BlueNoroff campaigns – Harden endpoint defenses to detect wallet enumeration and suspicious browser extensions
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft’s Servers
Source: The Hacker News | Risk: Critical | Impacted: Microsoft Azure/Bing API consumers, SaaS vendors relying on Bing image search, Organizations integrating Bing for workflow automation
Summary: A crafted SVG submitted to Bing’s image search ran commands as NT AUTHORITY\SYSTEM on Microsoft’s production image-processing workers, and as root on the Linux machines in the same fleet. XBOW’s testing got the same result on workers across different hosts and network ranges, so the problem sat in Bing’s image tier, not on one bad machine. Microsoft issued two critical
Why it matters: Critical flaws in Bing’s image processing let attackers run code as SYSTEM on Microsoft servers, representing a scalable opportunity for supply chain or cloud compromise.
Practitioner Perspective If your organization leverages Microsoft cloud or Bing APIs for content moderation, realize upstream vulnerabilities can endanger data you process or store. SVG-based remote code execution at the SYSTEM or root level nullifies assumptions about multi-tenancy boundaries or integrity of shared infrastructure. This scenario exemplifies the need to inventory all third-party and cloud service dependencies for indirect exposure. Microsoft has issued remediations, but any lag in patching can leave your workloads exposed by association.
Recommended Actions – Confirm Microsoft has deployed the two critical patches to production Bing image workers servicing your tenant – Review API use and shared data flows for reliance on Bing image moderation or enrichment features
Exploits & CVEs
Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
Source: The Hacker News | Risk: High | Impacted: Self-hosted GitLab instances, Internal developer CI pipelines, Organizations with large code-hosting user bases
Summary: Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six weeks earlier, on June 10. It runs commands as git on any self-managed 18.11.3 server that has not taken the update. Any authenticated user who can push to a project can run it. The attacker commits a crafted Jupyter notebook and opens
Why it matters: Public exploit code for a GitLab RCE sharply increases the threat window for organizations lagging on updates, as attackers can trivially gain code execution as the git user on developer infrastructure.
Practitioner Perspective Self-managed GitLab servers on version 18.11.3 (and likely older) are now in immediate jeopardy if unpatched: any authenticated user able to push code can trigger an RCE via a crafted Jupyter notebook. This moves GitLab from ‘potential’ to ‘imminent’ enterprise risk, especially for internal instances with large user bases or weak onboarding. Rapid external publication of exploit code means defenders must assume ongoing scans and attacks. Focus on both emergency patching and reviewing access permissions for project push capabilities. Unpatched, internet-facing GitLab is now functionally low-hanging fruit.
Recommended Actions – Immediately apply the June 10 GitLab patch for self-managed 18.11.3 servers – Audit project-level push permissions and restrict to vetted users during the crisis window
Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
Source: The Hacker News | Risk: Critical | Impacted: Active Directory-managed organizations, Enterprise CA environments, SOC teams responsible for identity monitoring
Summary: Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine. They codenamed the flaw Certighost. Because Domain Controller accounts carry directory replication rights, the resulting Kerberos credential can retrieve the krbtgt secret through DCSync.
Why it matters: Low-privileged users can escalate to full domain replication rights through AD certificate abuse, threatening the integrity of the entire Active Directory forest and enabling rapid enterprise compromise.
Practitioner Perspective If your AD environment exposes certificate services, you must assume that any user can potentially obtain credentials as a Domain Controller via the Certighost exploit. This enables DCSync attacks and theft of the krbtgt secret, giving attackers near-total control. Such trust path flaws are not hypothetical, they map to patterns used in both targeted and criminal lateral escalation. Audit your enterprise CA issuance policies and hunt for suspicious certificate requests immediately. If this flaw is present, it represents a foundational identity risk, prioritize containment over business-as-usual.
Recommended Actions – Hunt for Certighost exploitation by reviewing certificate issuance logs for Domain Controller templates issued to non-DC accounts – Audit and restrict AD Certificate Services template permissions to prevent low-privilege abuse
Defensive Actions
- Apply Rockwell’s Arena simulation patch and restrict simulation platforms from core OT assets
- Update detection logic in EDR/SWG solutions for browser-based assembly techniques leveraged by SourTrade
- Deploy real-time session anomaly detection and step-up authentication for insurance and financial portals
- Block domains and indicators tied to malvertising (TradingView, Solana, Luno) and BlueNoroff phishing
- Patch and isolate internet-facing PTC Windchill and FlexPLM deployments as per vendor guidance
- Update anti-malware and behavioral rulesets for Funky Mantis/DevMan RaaS tooling
- Confirm Bing image-processing patch status and audit API dependencies for image flows
- Immediately patch self-managed GitLab servers and restrict push permissions during active exploitation windows
- Audit AD certificate services permissions, hunt for Certighost exploit, and restrict certificate templates
- Strengthen user education and training on real-time phishing and rogue agent onboarding in SaaS/AI environments
What We’re Watching
Organizations must move quickly to patch exposed code execution flaws in both core cloud platforms and industrial software, as exploits and PoCs continue to accelerate adversary access and lateral movement. Rapidly evolving phishing tradecraft now shortens the gap between initial compromise and full account hijack, while ransomware and affiliate-driven delivery models scale up attacks on service providers and critical industries. Defenders are advised to focus on segmentation, real-time detection, and up-to-date user training as campaign agility rises.
Categories: Cybersecurity Blog, Cybersecurity News
Leave a Reply