Daily Security Intel

Archives
Log in
Subscribe
July 9, 2026

[SecurityIntel] 09 Jul | CISA: Patch Actively Exploited Critical Flaws NOW

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Thursday, July 09, 2026

INTEL CONFIDENCE  70%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

CISA: Patch Actively Exploited Critical Flaws NOW

CRITICAL

5

C2 IPs

0

OTX IOCs

36

ARTICLES

■ ANALYST TLDR

Today's intelligence highlights immediate patching urgency for critical, actively exploited vulnerabilities in Adobe ColdFusion, Langflow, and Joomla, as well as multiple critical flaws in Ubiquiti UniFi products. A China-linked APT continues targeted espionage via Roundcube exploitation and new SOHO router backdoors. Emerging threats include sophisticated prompt injection attacks against GitHub Agentic Workflows and Google Dialogflow CX, alongside supply chain compromises through fake NPM/PyPI packages and AI coding assistants recommending malicious software.

■ CRITICAL STORIES

CRITICAL#1

CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws

CISA has added critical, actively exploited vulnerabilities in Adobe ColdFusion, Langflow, and Joomla extensions to its KEV catalog, mandating federal agencies patch by July 10th. This indicates ongoing, real-world attacks with severe impact.

CRITICAL#2

Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS

Ubiquiti released patches for multiple critical security flaws impacting UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS that could result in privilege escalation and arbitrary command execution, leading to full system compromise.

HIGH#3

Hackers exploit Roundcube flaw to spy on academic researchers

A China-linked threat cluster is actively exploiting vulnerable Roundcube servers at U.S. and Canadian universities to steal credentials and deploy backdoor malware, indicating targeted espionage against academic institutions.

CRITICAL#4

Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection

A critical prompt injection flaw in GitHub Agentic Workflows allows attackers to exfiltrate data from private repositories without authentication, highlighting a significant and novel risk in AI-powered development environments.

■ CVEs IDENTIFIED

[CVE-TBD]

Adobe ColdFusion — Actively exploited, arbitrary code execution

Critical

[CVE-TBD]

Langflow — Actively exploited, authentication bypass, arbitrary code execution

Critical

[CVE-TBD]

Joomla (extension flaws) — Actively exploited, arbitrary code execution, privilege escalation

Critical

[CVE-TBD]

UniFi Connect — Privilege Escalation, Arbitrary Command Execution

Critical

■ THREAT ACTORS

China-linked threat cluster

State-sponsored APT

Exploiting Roundcube flaws, deploying new 'Leash' backdoors on SOHO routers.

REF6045

Cybercriminal

Targeting Mexican banking users with SCMBANKER malware via ClickFix lures.

EvilTokens

Cybercriminal

Conducting "ghost phishing" campaigns against US and European businesses.

■ ATT&CK TTPs

T1190
T1190 — Exploit Public-Facing Application | Exploitation of Adobe ColdFusion, Langflow, Joomla, Roundcube, Ubiquiti UniFi flaws.
T1566
T1566 — Phishing | Entra passkey enrollment vishing, "ghost phishing" by EvilTokens, SCMBANKER ClickFix lures.
T1195.001
T1195.001 — Compromise Software Supply Chain | Fake SDKs on npm/PyPI, HalluSquatting tricking AI coding assistants.
T1642
T1642 — Prompt Injection | Against GitHub Agentic Workflows, Google Dialogflow CX, and GitHub Copilot.
T1003
T1003 — Credential Dumping | Roundcube exploitation, fake SDKs, KDDI data breach, SCMBANKER.
T1041
T1041 — Exfiltration Over C2 Channel | Mount Royal University, Accenture, GitHub Agentic Workflows, Google Dialogflow CX.

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

Adobe ColdFusion — actively exploited critical vulnerabilities — CISA KEV

[P1 PATCH NOW]≤24h

Langflow — actively exploited critical authentication bypass flaw — CISA KEV

[P1 PATCH NOW]≤24h

Joomla (extensions) — actively exploited critical vulnerabilities — CISA KEV

[P1 PATCH NOW]≤24h

Ubiquiti UniFi Connect — privilege escalation, arbitrary command execution — Ubiquiti

■ RECOMMENDED ACTIONS TODAY

1[P1] **Patch Now:** Immediately apply security updates for Adobe ColdFusion, Langflow, and Joomla extensions as mandated by CISA, given active exploitation.
2[P1] **Patch Now:** Update all Ubiquiti UniFi products (Connect, Talk, Access, Protect, OS) to address critical privilege escalation and arbitrary command execution vulnerabilities.
3[P1] **Patch Now:** Prioritize patching Roundcube servers, especially in academic sectors, to mitigate active exploitation by China-linked threat actors.
4[P2] **Implement AI Security Controls:** Review and implement robust prompt injection mitigations for all generative AI applications, including Google Dialogflow CX and GitHub Agentic Workflows, to prevent data exfiltration and unauthorized access.
5[P2] **Enhance Supply Chain Security:** Implement strict validation for third-party packages from repositories like npm and PyPI, and educate developers on the risks of AI coding assistants recommending non-existent or malicious packages (HalluSquatting).
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 10 Jul | Critical Patches & Supply Chain Attacks Older → [SecurityIntel] 08 Jul | Critical RCEs and VM Escape Under Active Exploitation
Powered by Buttondown, the easiest way to start and grow your newsletter.