Daily Security Intel

Archives
Log in
Subscribe
July 7, 2026

[SecurityIntel] 07 Jul | Critical Exploits & State-Sponsored Attacks

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Tuesday, July 07, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Critical Exploits & State-Sponsored Attacks

CRITICAL

5

C2 IPs

40

OTX IOCs

34

ARTICLES

■ ANALYST TLDR

Today's intelligence highlights critical vulnerabilities in Linux KVM (CVE-2026-53359), Gitea Docker (CVE-2026-20896), and Adobe ColdFusion (CVE-2026-48282), all actively exploited or with PoCs available. Additionally, sophisticated phishing campaigns leveraging Microsoft Teams and fake job interviews are delivering EtherRAT and stealing Google credentials, while state-sponsored groups like North Korean hackers and Iran-linked actors continue to deploy backdoors and new C2 frameworks.

■ CRITICAL STORIES

CRITICAL#1

16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems

This is a critical hypervisor escape vulnerability (CVE-2026-53359) affecting widely used Linux KVM on Intel and AMD systems, allowing guest VMs to compromise the host kernel.

CRITICAL#2

Max severity Adobe ColdFusion flaw now exploited in attacks

A maximum-severity Adobe ColdFusion vulnerability (CVE-2026-48282) is now being actively exploited, posing an immediate threat to organizations using the product.

HIGH#3

North Korean Hackers Target Open Source Developers in Supply Chain Attacks

The PolinRider campaign by North Korean hackers is compromising open-source packages to deliver backdoors and info stealers, representing a significant supply chain risk to developers and downstream users.

HIGH#4

Fake IT support calls on Microsoft Teams push EtherRAT malware

Threat actors are abusing Microsoft Teams for social engineering, impersonating IT support to deploy EtherRAT, providing initial access to corporate networks.

■ CVEs IDENTIFIED

CVE-2026-53359

Linux KVM — Guest VM escape to host (use-after-free)

Critical

CVE-2026-20896

Gitea Docker — Remote Code Execution

Critical (CVSS 9.8)

CVE-2026-48282

Adobe ColdFusion — Remote Code Execution

Critical (Max severity)

[CVE-TBD]

Linux 'Bad Epoll' — Root access/Privilege Escalation

Critical

■ THREAT ACTORS

Iran-Linked Hackers (MOIS affiliated)

State-Sponsored

Wielding Cavern C2 framework against Israeli organizations.

Armored Likho APT

State-Sponsored / Financially Motivated

Targeting Government and Electric Power entities with modular RATs and information stealers.

North Korean Hackers (PolinRider campaign)

State-Sponsored

Compromising open-source packages to deliver backdoors and information stealers to developers.

■ ATT&CK TTPs

T1566.002
Phishing: Spearphishing Link | Phishing for Google accounts, prompt injection via malicious websites.
T1078
Valid Accounts | Stolen Google account credentials.
T1566.001
Phishing: Spearphishing Attachment | Microsoft Teams calls pushing EtherRAT, fake Indian tax utility pushing DcRAT.
T1204.002
User Execution: Malicious File | Employees installing EtherRAT, users executing fake tax utility.
T1102.002
Web Service: Blogspot | Used for C2 and payload hosting in Veil#Drop attacks.
T1059.001
Command and Scripting Interpreter: PowerShell | Used for execution in Veil#Drop attacks.

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

Linux KVM — Guest VM escape (CVE-2026-53359) — THN

[P1 PATCH NOW]≤24h

Linux — Root access/Privilege Escalation ('Bad Epoll') — SW

[P1 PATCH NOW]≤24h

Adobe ColdFusion — Active exploitation, RCE (CVE-2026-48282) — BC

[P1 PATCH NOW]≤24h

Gitea Docker — Active probing, RCE (CVE-2026-20896) — THN

■ RECOMMENDED ACTIONS TODAY

1[P1] Immediately patch all Linux KVM hypervisors to address CVE-2026-53359 and the 'Bad Epoll' root access vulnerability, prioritizing systems hosting critical virtual machines.
2[P1] Apply patches for Adobe ColdFusion (CVE-2026-48282) and Gitea Docker (CVE-2026-20896) immediately, as these critical vulnerabilities are actively being exploited or probed.
3[P2] Implement robust email and communication platform (e.g., Microsoft Teams) security awareness training to educate employees about phishing, social engineering, and fake IT support calls to prevent EtherRAT and credential theft.
4[P2] Review and secure software supply chain processes, especially for open-source dependencies, to mitigate risks from campaigns like PolinRider by North Korean hackers.
5[P3] For organizations using autonomous AI agents, implement authorization controls like AWS Cedar to enforce least-privilege and prevent prompt injection attacks leading to unauthorized actions.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 08 Jul | Critical RCEs and VM Escape Under Active Exploitation Older → [SecurityIntel] 06 Jul | Flipper Zero Shifts to Community-Led Firmware Development
Powered by Buttondown, the easiest way to start and grow your newsletter.