SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefFriday, July 10, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
| THREAT OF THE DAY Critical Patches & Supply Chain Attacks | CRITICAL |
| 5 C2 IPs | 48 OTX IOCs | 34 ARTICLES |
| ■ ANALYST TLDR | ■ CRITICAL STORIES 15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google A 15-year-old Linux kernel vulnerability, 'GhostLock', allows attackers to gain root access, affecting every major distribution since 2011. This is a severe privilege escalation flaw impacting a foundational operating system. |
New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware Microsoft has detailed GigaWiper, a destructive Windows backdoor combining multiple older destructive programs, posing a significant threat of data loss and system compromise. |
Injective SDK on npm infected with cryptocurrency wallet stealer A supply chain attack compromised the Injective Labs SDK's GitHub and npm, distributing a malicious package to steal cryptocurrency wallet private keys and seed phrases, demonstrating the ongoing risk to software development ecosystems. |
New Helix vishing group emerges in SharePoint data theft attacks The Helix group is using advanced identity-focused tactics like vishing and MFA abuse to steal data from SharePoint environments, highlighting the evolving sophistication of social engineering and credential theft. |
| ■ CVEs IDENTIFIED CVE-2026-50656 Microsoft Defender, Microsoft Malware Protection Engine — Privilege Escalation (SYSTEM) |
[CVE-TBD] Palo Alto Networks PAN-OS — Buffer overflow, DoS, command injection, SSRF, authentication bypass (RCE, DoS, Auth Bypass) |
[CVE-TBD] Linux Kernel (GhostLock) — Privilege Escalation (Root access) |
[CVE-TBD] KDDI (third-party system) — Zero-day vulnerability leading to data breach |
|
■ THREAT ACTORS Helix | Data Extortion Group |
Vishing, MFA abuse to steal SharePoint data. |
Forg365 | Phishing-as-a-Service (PhaaS) |
AiTM and device code phishing targeting Microsoft 365. |
GigaWiper | Destructive Malware Operator (implied group) |
Deploying multi-component backdoor for disk wiping, fake ransomware, spyware. |
|
|
| ■ ATT&CK TTPs | T1195.002 | | Supply Chain Compromise: Compromise Software Supply Chain | Malicious npm package published for Injective SDK. |
| T1566.002 | | Phishing: Spearphishing Link | Helix vishing, Forg365 phishing. |
| T1111 | | Multi-Factor Authentication Request Generation | Helix vishing, Forg365 AiTM/device code phishing. |
| T1078 | | Valid Accounts | Used by Helix, Forg365, involved in internal sabotage, potentially for initial access in ransomware/data breaches. |
| T1485 | | Data Destruction | GigaWiper, Mount Royal University ransomware. |
| T1561 | | Disk Wipe | GigaWiper. |
|
■ PATCH PRIORITY Linux Kernel — Privilege Escalation (Root) — SW |
Microsoft Defender, Microsoft Malware Protection Engine — Privilege Escalation (SYSTEM) — SW, MWB, THN |
Palo Alto Networks PAN-OS — RCE, DoS, Auth Bypass, Command Injection, SSRF — SW |
KDDI (third-party system) — Zero-day exploitation leading to data breach — SW |
|
|
| ■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Immediately patch Microsoft Defender and Microsoft Malware Protection Engine to address CVE-2026-50656, preventing privilege escalation to SYSTEM. |
| 2 | [P1] Apply patches for Palo Alto Networks PAN-OS to mitigate 13 vulnerabilities, including potential RCE, DoS, and authentication bypass flaws. |
| 3 | [P1] Prioritize patching the Linux kernel vulnerability 'GhostLock' (CVE-TBD) across all affected distributions to prevent root access privilege escalation. |
| 4 | [P2] Implement strict supply chain security measures, including vetting npm packages, and educate developers on risks associated with Injective SDK and similar dependencies. |
| 5 | [P2] Enhance MFA and implement conditional access policies for Microsoft 365 and SharePoint environments to defend against vishing (Helix) and AiTM phishing (Forg365) attacks. |
|
| | C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
| FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
| IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |
|