Daily Security Intel

Archives
Log in
Subscribe
July 10, 2026

[SecurityIntel] 10 Jul | Critical Patches & Supply Chain Attacks

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Friday, July 10, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Critical Patches & Supply Chain Attacks

CRITICAL

5

C2 IPs

48

OTX IOCs

34

ARTICLES

■ ANALYST TLDR

Analysis unavailable.

■ CRITICAL STORIES

CRITICAL#1

15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google

A 15-year-old Linux kernel vulnerability, 'GhostLock', allows attackers to gain root access, affecting every major distribution since 2011. This is a severe privilege escalation flaw impacting a foundational operating system.

CRITICAL#2

New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware

Microsoft has detailed GigaWiper, a destructive Windows backdoor combining multiple older destructive programs, posing a significant threat of data loss and system compromise.

HIGH#3

Injective SDK on npm infected with cryptocurrency wallet stealer

A supply chain attack compromised the Injective Labs SDK's GitHub and npm, distributing a malicious package to steal cryptocurrency wallet private keys and seed phrases, demonstrating the ongoing risk to software development ecosystems.

HIGH#4

New Helix vishing group emerges in SharePoint data theft attacks

The Helix group is using advanced identity-focused tactics like vishing and MFA abuse to steal data from SharePoint environments, highlighting the evolving sophistication of social engineering and credential theft.

■ CVEs IDENTIFIED

CVE-2026-50656

Microsoft Defender, Microsoft Malware Protection Engine — Privilege Escalation (SYSTEM)

High (CVSS 7.8)

[CVE-TBD]

Palo Alto Networks PAN-OS — Buffer overflow, DoS, command injection, SSRF, authentication bypass (RCE, DoS, Auth Bypass)

Critical/High

[CVE-TBD]

Linux Kernel (GhostLock) — Privilege Escalation (Root access)

Critical

[CVE-TBD]

KDDI (third-party system) — Zero-day vulnerability leading to data breach

Critical

■ THREAT ACTORS

Helix

Data Extortion Group

Vishing, MFA abuse to steal SharePoint data.

Forg365

Phishing-as-a-Service (PhaaS)

AiTM and device code phishing targeting Microsoft 365.

GigaWiper

Destructive Malware Operator (implied group)

Deploying multi-component backdoor for disk wiping, fake ransomware, spyware.

■ ATT&CK TTPs

T1195.002
Supply Chain Compromise: Compromise Software Supply Chain | Malicious npm package published for Injective SDK.
T1566.002
Phishing: Spearphishing Link | Helix vishing, Forg365 phishing.
T1111
Multi-Factor Authentication Request Generation | Helix vishing, Forg365 AiTM/device code phishing.
T1078
Valid Accounts | Used by Helix, Forg365, involved in internal sabotage, potentially for initial access in ransomware/data breaches.
T1485
Data Destruction | GigaWiper, Mount Royal University ransomware.
T1561
Disk Wipe | GigaWiper.

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

Linux Kernel — Privilege Escalation (Root) — SW

[P1 PATCH NOW]≤24h

Microsoft Defender, Microsoft Malware Protection Engine — Privilege Escalation (SYSTEM) — SW, MWB, THN

[P1 PATCH NOW]≤24h

Palo Alto Networks PAN-OS — RCE, DoS, Auth Bypass, Command Injection, SSRF — SW

[P1 PATCH NOW]≤24h

KDDI (third-party system) — Zero-day exploitation leading to data breach — SW

■ RECOMMENDED ACTIONS TODAY

1[P1] Immediately patch Microsoft Defender and Microsoft Malware Protection Engine to address CVE-2026-50656, preventing privilege escalation to SYSTEM.
2[P1] Apply patches for Palo Alto Networks PAN-OS to mitigate 13 vulnerabilities, including potential RCE, DoS, and authentication bypass flaws.
3[P1] Prioritize patching the Linux kernel vulnerability 'GhostLock' (CVE-TBD) across all affected distributions to prevent root access privilege escalation.
4[P2] Implement strict supply chain security measures, including vetting npm packages, and educate developers on risks associated with Injective SDK and similar dependencies.
5[P2] Enhance MFA and implement conditional access policies for Microsoft 365 and SharePoint environments to defend against vishing (Helix) and AiTM phishing (Forg365) attacks.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 11 Jul | Progress Urges Immediate ShareFile Server Shutdown Older → [SecurityIntel] 09 Jul | CISA: Patch Actively Exploited Critical Flaws NOW
Powered by Buttondown, the easiest way to start and grow your newsletter.