SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefThursday, July 09, 2026 INTEL CONFIDENCE 70% | THREAT LEVEL CRITICAL |
| THREAT OF THE DAY CISA: Patch Actively Exploited Critical Flaws NOW | CRITICAL |
| 5 C2 IPs | 0 OTX IOCs | 36 ARTICLES |
| ■ ANALYST TLDR Today's intelligence highlights immediate patching urgency for critical, actively exploited vulnerabilities in Adobe ColdFusion, Langflow, and Joomla, as well as multiple critical flaws in Ubiquiti UniFi products. A China-linked APT continues targeted espionage via Roundcube exploitation and new SOHO router backdoors. Emerging threats include sophisticated prompt injection attacks against GitHub Agentic Workflows and Google Dialogflow CX, alongside supply chain compromises through fake NPM/PyPI packages and AI coding assistants recommending malicious software. |
| ■ CRITICAL STORIES CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws CISA has added critical, actively exploited vulnerabilities in Adobe ColdFusion, Langflow, and Joomla extensions to its KEV catalog, mandating federal agencies patch by July 10th. This indicates ongoing, real-world attacks with severe impact. |
Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS Ubiquiti released patches for multiple critical security flaws impacting UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS that could result in privilege escalation and arbitrary command execution, leading to full system compromise. |
Hackers exploit Roundcube flaw to spy on academic researchers A China-linked threat cluster is actively exploiting vulnerable Roundcube servers at U.S. and Canadian universities to steal credentials and deploy backdoor malware, indicating targeted espionage against academic institutions. |
Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection A critical prompt injection flaw in GitHub Agentic Workflows allows attackers to exfiltrate data from private repositories without authentication, highlighting a significant and novel risk in AI-powered development environments. |
| ■ CVEs IDENTIFIED [CVE-TBD] Adobe ColdFusion — Actively exploited, arbitrary code execution |
[CVE-TBD] Langflow — Actively exploited, authentication bypass, arbitrary code execution |
[CVE-TBD] Joomla (extension flaws) — Actively exploited, arbitrary code execution, privilege escalation |
[CVE-TBD] UniFi Connect — Privilege Escalation, Arbitrary Command Execution |
|
■ THREAT ACTORS China-linked threat cluster | State-sponsored APT |
Exploiting Roundcube flaws, deploying new 'Leash' backdoors on SOHO routers. |
Targeting Mexican banking users with SCMBANKER malware via ClickFix lures. |
Conducting "ghost phishing" campaigns against US and European businesses. |
|
|
| ■ ATT&CK TTPs | T1190 | | T1190 — Exploit Public-Facing Application | Exploitation of Adobe ColdFusion, Langflow, Joomla, Roundcube, Ubiquiti UniFi flaws. |
| T1566 | | T1566 — Phishing | Entra passkey enrollment vishing, "ghost phishing" by EvilTokens, SCMBANKER ClickFix lures. |
| T1195.001 | | T1195.001 — Compromise Software Supply Chain | Fake SDKs on npm/PyPI, HalluSquatting tricking AI coding assistants. |
| T1642 | | T1642 — Prompt Injection | Against GitHub Agentic Workflows, Google Dialogflow CX, and GitHub Copilot. |
| T1003 | | T1003 — Credential Dumping | Roundcube exploitation, fake SDKs, KDDI data breach, SCMBANKER. |
| T1041 | | T1041 — Exfiltration Over C2 Channel | Mount Royal University, Accenture, GitHub Agentic Workflows, Google Dialogflow CX. |
|
■ PATCH PRIORITY Adobe ColdFusion — actively exploited critical vulnerabilities — CISA KEV |
Langflow — actively exploited critical authentication bypass flaw — CISA KEV |
Joomla (extensions) — actively exploited critical vulnerabilities — CISA KEV |
Ubiquiti UniFi Connect — privilege escalation, arbitrary command execution — Ubiquiti |
|
|
| ■ RECOMMENDED ACTIONS TODAY | 1 | [P1] **Patch Now:** Immediately apply security updates for Adobe ColdFusion, Langflow, and Joomla extensions as mandated by CISA, given active exploitation. |
| 2 | [P1] **Patch Now:** Update all Ubiquiti UniFi products (Connect, Talk, Access, Protect, OS) to address critical privilege escalation and arbitrary command execution vulnerabilities. |
| 3 | [P1] **Patch Now:** Prioritize patching Roundcube servers, especially in academic sectors, to mitigate active exploitation by China-linked threat actors. |
| 4 | [P2] **Implement AI Security Controls:** Review and implement robust prompt injection mitigations for all generative AI applications, including Google Dialogflow CX and GitHub Agentic Workflows, to prevent data exfiltration and unauthorized access. |
| 5 | [P2] **Enhance Supply Chain Security:** Implement strict validation for third-party packages from repositories like npm and PyPI, and educate developers on the risks of AI coding assistants recommending non-existent or malicious packages (HalluSquatting). |
|
| | C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
| FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
| IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |
|