SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefSaturday, July 11, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Progress Urges Immediate ShareFile Server Shutdown | CRITICAL |
|
5 C2 IPs | 89 OTX IOCs | 35 ARTICLES |
|
■ ANALYST TLDR Today's threat landscape is dominated by an urgent directive from Progress Software instructing ShareFile customers to immediately shut down on-premises Storage Zone Controllers due to a credible external threat. Concurrently, threat actors are actively exploiting a critical authentication bypass in Gitea's official Docker images, while newly disclosed U-Boot bootloader flaws present severe firmware-level risks. Organizations must also contend with supply chain compromises on GitHub, sophisticated vishing targeting Microsoft 365, and destructive GigaWiper malware. |
|
■ CRITICAL STORIES Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat Progress Software has taken the unprecedented step of telling customers to immediately shut down Windows servers running Storage Zone Controllers due to an active, credible threat, indicating imminent risk of compromise to on-premises secure file-sharing systems. |
Hackers exploit critical auth bypass in Gitea Docker image Threat actors are actively exploiting a critical vulnerability in Gitea's official Docker image, allowing them to bypass authentication and completely impersonate administrators, leading to unauthorized repository access and potential supply chain manipulation. |
New U-Boot flaws could enable stealthy firmware attacks Six newly discovered vulnerabilities in the widely used U-Boot bootloader allow attackers to execute arbitrary code during the boot process, bypassing traditional OS-level security controls and enabling persistent, stealthy firmware-level attacks. |
Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages Attackers compromised the GitHub repository of Injective Labs to distribute a malicious npm package designed to harvest cryptocurrency private keys, highlighting the ongoing threat of software supply chain compromises targeting developers. |
|
■ CVEs IDENTIFIED [CVE-TBD-SHAREFILE] Progress ShareFile Storage Zone Controller — Unspecified critical external threat prompting immediate shutdown recommendation |
[CVE-TBD-GITEA] Gitea (Official Docker Image) — Authentication bypass allowing full administrator impersonation and repository takeover |
[CVE-TBD-UBOOT] U-Boot Bootloader — Six vulnerabilities allowing boot-time arbitrary code execution and device crashes |
[CVE-TBD-OPENCLAW] OpenClaw AI Assistant — WhatsApp-to-host attack chain enabling credential theft, privilege escalation, and arbitrary code execution |
|
■ THREAT ACTORS The Gentlemen | Ransomware Affiliate Group |
Actively deploying ransomware using an aggressive affiliate model |
Silver Fox | China-linked Cybercrime Group |
Deploying the new Rust-based MODBEACON RAT utilizing gRPC streaming for C2 |
China-linked APT | Nation-State |
Spying campaign targeting the Balochistan Police force in Pakistan |
|
|
|
■ ATT&CK TTPs | T1542.001 | | Pre-OS Boot: System Firmware | U-Boot bootloader vulnerabilities exploited to run code at boot |
| T1190 | | Exploit Public-Facing Application | Active exploitation of Gitea authentication bypass and Zimbra Classic Web Client XSS |
| T1195.002 | | Compromise Software Supply Chain | Injective Labs GitHub compromise distributing malicious npm packages |
| T1566.002 | | Spearphishing Link | Comment stuffing in HTML attachments to evade AI-based detection |
| T1048 | | Exfiltration Over Alternative Protocol | MODBEACON RAT using gRPC streaming for encrypted C2 traffic |
| T1486 | | Data Encrypted for Impact | GigaWiper and The Gentlemen ransomware encrypting or wiping target systems |
|
■ PATCH PRIORITY Progress ShareFile Storage Zone Controller — Active "credible" external threat requires immediate shutdown of Windows hosts — [BC/THN] |
Gitea (Docker Image) — Active exploitation of critical authentication bypass allowing admin takeover — [BC] |
Zimbra Collaboration Suite (Classic Web Client) — Critical XSS flaw allows session hijacking; vendor urges immediate patching — [BC] |
Google Chrome — Two critical updates released in two days to address severe vulnerabilities — [MWB] |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Immediately shut down all Windows servers running Progress ShareFile Storage Zone Controllers to mitigate the "credible external security threat" [CVE-TBD-SHAREFILE]. |
| 2 | [P1] Apply the latest security patches for Gitea's official Docker image to remediate the critical authentication bypass vulnerability under active exploitation [CVE-TBD-GITEA]. |
| 3 | [P1] Patch the Zimbra Collaboration Suite Classic Web Client immediately to address the critical XSS vulnerability [CVE-TBD-ZIMBRA]. |
| 4 | [P2] Update Google Chrome installations to the latest version to address critical vulnerabilities patched in the consecutive daily updates [CVE-TBD-CHROME]. |
| 5 | [P2] Audit software supply chains for npm dependencies, specifically ensuring the `@injective/sdk` package is verified and clean of the compromised GitHub version. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |