Daily Security Intel

Archives
Log in
Subscribe
July 8, 2026

[SecurityIntel] 08 Jul | Critical RCEs and VM Escape Under Active Exploitation

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Wednesday, July 08, 2026

INTEL CONFIDENCE  70%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Critical RCEs and VM Escape Under Active Exploitation

CRITICAL

5

C2 IPs

0

OTX IOCs

37

ARTICLES

■ ANALYST TLDR

Today's intel highlights critical vulnerabilities under active exploitation, including RCE flaws in Adobe ColdFusion and Gitea, and a VM escape vulnerability in the Linux kernel. State-sponsored threat actors are actively targeting unpatched Ruckus routers and Roundcube webmail, while new malware operations like RedWing MaaS and Vidar Stealer pose significant cybercrime threats.

■ CRITICAL STORIES

CRITICAL#1

Critical Adobe ColdFusion Vulnerability Exploited in Attacks

A CVSS 10/10 RCE flaw is actively being exploited, demanding immediate patching.

CRITICAL#2

New Januscape Linux flaw allows VM escape on Intel, AMD devices

A 16-year-old Linux kernel vulnerability allows attackers to escape virtual machines and execute arbitrary code on the host, impacting critical infrastructure.

CRITICAL#3

Critical Gitea Flaw Under Active Exploitation, Researchers Warn

Attackers are bypassing authentication in Gitea via CVE-2026-20896 to access repositories and secrets.

CRITICAL#4

Chinese hackers develop LONGLEASH malware to expand ORB network

UAT-7810 is actively exploiting unpatched Ruckus routers to expand their operational network.

■ CVEs IDENTIFIED

CVE-2026-20896

Gitea — Authentication bypass, access to repositories and secrets, actively exploited.

Critical

CVE-2026-48282

Adobe ColdFusion — RCE, actively exploited, CVSS 10/10.

Critical

[CVE-TBD]

Tenda routers — Hidden authentication backdoor, grants admin access.

Critical

[CVE-TBD]

Google Dialogflow CX — Cross-agent compromise, read live conversations, steal tokens (now patched).

Critical

■ THREAT ACTORS

UAT-7810

State-sponsored (Chinese)

Actively evolving LONGLEASH malware, targeting unpatched Ruckus routers.

CyberArmy of Russia Reborn (CARR)

Hacktivist (pro-Russian)

Suspected member arrested in Spain.

Z-Pentest

Hacktivist (pro-Russian)

Suspected member arrested in Spain.

■ ATT&CK TTPs

T1190
Exploit Public-Facing Application | Unpatched Ruckus routers, Tenda router backdoor, Gitea flaw, Adobe ColdFusion, Roundcube flaws.
T1537
Data from Local System | Accenture source code, Japanese telco emails, GitHub private repo data.
T1567.002
Exfiltration Over Web Service: Exfiltration to Cloud Storage | Accenture data offered for sale.
T1036.005
Masquerading: Match Legitimate Name or Location | Fake MpClient.dll for Vidar Stealer.
T1574.002
Hijack Execution Flow: DLL Sideloading | Vidar Stealer.
T1553.002
Subvert Trust Controls: Code Signing | Vidar Stealer code signing abuse.

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

Adobe ColdFusion — active exploitation, CVSS 10/10 RCE — SW

[P1 PATCH NOW]≤24h

Linux kernel (KVM hypervisor) — VM escape, arbitrary code execution on host — BC/SW

[P1 PATCH NOW]≤24h

Gitea — active exploitation, authentication bypass leading to repository access — SW

[P1 PATCH NOW]≤24h

Ruckus routers — actively exploited by Chinese hackers (UAT-7810) — BC

■ RECOMMENDED ACTIONS TODAY

1[P1] Immediately patch Adobe ColdFusion instances for CVE-2026-48282 due to its critical severity and active exploitation.
2[P1] Apply the latest Linux kernel updates to systems utilizing KVM hypervisors on Intel and AMD devices to mitigate the Januscape VM escape vulnerability.
3[P1] Update Gitea installations to address CVE-2026-20896, preventing authentication bypass and unauthorized repository access.
4[P1] Prioritize patching and securing all internet-facing Ruckus routers and Tenda routers to prevent exploitation by state-sponsored actors and backdoor access.
5[P2] Review and patch Roundcube webmail software, especially within university environments, given active exploitation by China-aligned threat actors.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 09 Jul | CISA: Patch Actively Exploited Critical Flaws NOW Older → [SecurityIntel] 07 Jul | Critical Exploits & State-Sponsored Attacks
Powered by Buttondown, the easiest way to start and grow your newsletter.