SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefWednesday, July 08, 2026 INTEL CONFIDENCE 70% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Critical RCEs and VM Escape Under Active Exploitation | CRITICAL |
|
5 C2 IPs | 0 OTX IOCs | 37 ARTICLES |
|
■ ANALYST TLDR Today's intel highlights critical vulnerabilities under active exploitation, including RCE flaws in Adobe ColdFusion and Gitea, and a VM escape vulnerability in the Linux kernel. State-sponsored threat actors are actively targeting unpatched Ruckus routers and Roundcube webmail, while new malware operations like RedWing MaaS and Vidar Stealer pose significant cybercrime threats. |
|
■ CRITICAL STORIES Critical Adobe ColdFusion Vulnerability Exploited in Attacks A CVSS 10/10 RCE flaw is actively being exploited, demanding immediate patching. |
New Januscape Linux flaw allows VM escape on Intel, AMD devices A 16-year-old Linux kernel vulnerability allows attackers to escape virtual machines and execute arbitrary code on the host, impacting critical infrastructure. |
Critical Gitea Flaw Under Active Exploitation, Researchers Warn Attackers are bypassing authentication in Gitea via CVE-2026-20896 to access repositories and secrets. |
Chinese hackers develop LONGLEASH malware to expand ORB network UAT-7810 is actively exploiting unpatched Ruckus routers to expand their operational network. |
|
■ CVEs IDENTIFIED CVE-2026-20896 Gitea — Authentication bypass, access to repositories and secrets, actively exploited. |
CVE-2026-48282 Adobe ColdFusion — RCE, actively exploited, CVSS 10/10. |
[CVE-TBD] Tenda routers — Hidden authentication backdoor, grants admin access. |
[CVE-TBD] Google Dialogflow CX — Cross-agent compromise, read live conversations, steal tokens (now patched). |
|
■ THREAT ACTORS UAT-7810 | State-sponsored (Chinese) |
Actively evolving LONGLEASH malware, targeting unpatched Ruckus routers. |
CyberArmy of Russia Reborn (CARR) | Hacktivist (pro-Russian) |
Suspected member arrested in Spain. |
Z-Pentest | Hacktivist (pro-Russian) |
Suspected member arrested in Spain. |
|
|
|
■ ATT&CK TTPs | T1190 | | Exploit Public-Facing Application | Unpatched Ruckus routers, Tenda router backdoor, Gitea flaw, Adobe ColdFusion, Roundcube flaws. |
| T1537 | | Data from Local System | Accenture source code, Japanese telco emails, GitHub private repo data. |
| T1567.002 | | Exfiltration Over Web Service: Exfiltration to Cloud Storage | Accenture data offered for sale. |
| T1036.005 | | Masquerading: Match Legitimate Name or Location | Fake MpClient.dll for Vidar Stealer. |
| T1574.002 | | Hijack Execution Flow: DLL Sideloading | Vidar Stealer. |
| T1553.002 | | Subvert Trust Controls: Code Signing | Vidar Stealer code signing abuse. |
|
■ PATCH PRIORITY Adobe ColdFusion — active exploitation, CVSS 10/10 RCE — SW |
Linux kernel (KVM hypervisor) — VM escape, arbitrary code execution on host — BC/SW |
Gitea — active exploitation, authentication bypass leading to repository access — SW |
Ruckus routers — actively exploited by Chinese hackers (UAT-7810) — BC |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Immediately patch Adobe ColdFusion instances for CVE-2026-48282 due to its critical severity and active exploitation. |
| 2 | [P1] Apply the latest Linux kernel updates to systems utilizing KVM hypervisors on Intel and AMD devices to mitigate the Januscape VM escape vulnerability. |
| 3 | [P1] Update Gitea installations to address CVE-2026-20896, preventing authentication bypass and unauthorized repository access. |
| 4 | [P1] Prioritize patching and securing all internet-facing Ruckus routers and Tenda routers to prevent exploitation by state-sponsored actors and backdoor access. |
| 5 | [P2] Review and patch Roundcube webmail software, especially within university environments, given active exploitation by China-aligned threat actors. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |