SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefTuesday, July 07, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Critical Exploits & State-Sponsored Attacks | CRITICAL |
|
5 C2 IPs | 40 OTX IOCs | 34 ARTICLES |
|
■ ANALYST TLDR Today's intelligence highlights critical vulnerabilities in Linux KVM (CVE-2026-53359), Gitea Docker (CVE-2026-20896), and Adobe ColdFusion (CVE-2026-48282), all actively exploited or with PoCs available. Additionally, sophisticated phishing campaigns leveraging Microsoft Teams and fake job interviews are delivering EtherRAT and stealing Google credentials, while state-sponsored groups like North Korean hackers and Iran-linked actors continue to deploy backdoors and new C2 frameworks. |
|
■ CRITICAL STORIES 16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems This is a critical hypervisor escape vulnerability (CVE-2026-53359) affecting widely used Linux KVM on Intel and AMD systems, allowing guest VMs to compromise the host kernel. |
Max severity Adobe ColdFusion flaw now exploited in attacks A maximum-severity Adobe ColdFusion vulnerability (CVE-2026-48282) is now being actively exploited, posing an immediate threat to organizations using the product. |
North Korean Hackers Target Open Source Developers in Supply Chain Attacks The PolinRider campaign by North Korean hackers is compromising open-source packages to deliver backdoors and info stealers, representing a significant supply chain risk to developers and downstream users. |
Fake IT support calls on Microsoft Teams push EtherRAT malware Threat actors are abusing Microsoft Teams for social engineering, impersonating IT support to deploy EtherRAT, providing initial access to corporate networks. |
|
■ CVEs IDENTIFIED CVE-2026-53359 Linux KVM — Guest VM escape to host (use-after-free) |
CVE-2026-20896 Gitea Docker — Remote Code Execution |
CVE-2026-48282 Adobe ColdFusion — Remote Code Execution |
[CVE-TBD] Linux 'Bad Epoll' — Root access/Privilege Escalation |
|
■ THREAT ACTORS Iran-Linked Hackers (MOIS affiliated) | State-Sponsored |
Wielding Cavern C2 framework against Israeli organizations. |
Armored Likho APT | State-Sponsored / Financially Motivated |
Targeting Government and Electric Power entities with modular RATs and information stealers. |
North Korean Hackers (PolinRider campaign) | State-Sponsored |
Compromising open-source packages to deliver backdoors and information stealers to developers. |
|
|
|
■ ATT&CK TTPs | T1566.002 | | Phishing: Spearphishing Link | Phishing for Google accounts, prompt injection via malicious websites. |
| T1078 | | Valid Accounts | Stolen Google account credentials. |
| T1566.001 | | Phishing: Spearphishing Attachment | Microsoft Teams calls pushing EtherRAT, fake Indian tax utility pushing DcRAT. |
| T1204.002 | | User Execution: Malicious File | Employees installing EtherRAT, users executing fake tax utility. |
| T1102.002 | | Web Service: Blogspot | Used for C2 and payload hosting in Veil#Drop attacks. |
| T1059.001 | | Command and Scripting Interpreter: PowerShell | Used for execution in Veil#Drop attacks. |
|
■ PATCH PRIORITY Linux KVM — Guest VM escape (CVE-2026-53359) — THN |
Linux — Root access/Privilege Escalation ('Bad Epoll') — SW |
Adobe ColdFusion — Active exploitation, RCE (CVE-2026-48282) — BC |
Gitea Docker — Active probing, RCE (CVE-2026-20896) — THN |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Immediately patch all Linux KVM hypervisors to address CVE-2026-53359 and the 'Bad Epoll' root access vulnerability, prioritizing systems hosting critical virtual machines. |
| 2 | [P1] Apply patches for Adobe ColdFusion (CVE-2026-48282) and Gitea Docker (CVE-2026-20896) immediately, as these critical vulnerabilities are actively being exploited or probed. |
| 3 | [P2] Implement robust email and communication platform (e.g., Microsoft Teams) security awareness training to educate employees about phishing, social engineering, and fake IT support calls to prevent EtherRAT and credential theft. |
| 4 | [P2] Review and secure software supply chain processes, especially for open-source dependencies, to mitigate risks from campaigns like PolinRider by North Korean hackers. |
| 5 | [P3] For organizations using autonomous AI agents, implement authorization controls like AWS Cedar to enforce least-privilege and prevent prompt injection attacks leading to unauthorized actions. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |