Daily Security Intel

Archives
Log in
Subscribe
July 11, 2026

[SecurityIntel] 11 Jul | Progress Urges Immediate ShareFile Server Shutdown

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Saturday, July 11, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Progress Urges Immediate ShareFile Server Shutdown

CRITICAL

5

C2 IPs

89

OTX IOCs

35

ARTICLES

■ ANALYST TLDR

Today's threat landscape is dominated by an urgent directive from Progress Software instructing ShareFile customers to immediately shut down on-premises Storage Zone Controllers due to a credible external threat. Concurrently, threat actors are actively exploiting a critical authentication bypass in Gitea's official Docker images, while newly disclosed U-Boot bootloader flaws present severe firmware-level risks. Organizations must also contend with supply chain compromises on GitHub, sophisticated vishing targeting Microsoft 365, and destructive GigaWiper malware.

■ CRITICAL STORIES

CRITICAL#1

Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat

Progress Software has taken the unprecedented step of telling customers to immediately shut down Windows servers running Storage Zone Controllers due to an active, credible threat, indicating imminent risk of compromise to on-premises secure file-sharing systems.

CRITICAL#2

Hackers exploit critical auth bypass in Gitea Docker image

Threat actors are actively exploiting a critical vulnerability in Gitea's official Docker image, allowing them to bypass authentication and completely impersonate administrators, leading to unauthorized repository access and potential supply chain manipulation.

HIGH#3

New U-Boot flaws could enable stealthy firmware attacks

Six newly discovered vulnerabilities in the widely used U-Boot bootloader allow attackers to execute arbitrary code during the boot process, bypassing traditional OS-level security controls and enabling persistent, stealthy firmware-level attacks.

HIGH#4

Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages

Attackers compromised the GitHub repository of Injective Labs to distribute a malicious npm package designed to harvest cryptocurrency private keys, highlighting the ongoing threat of software supply chain compromises targeting developers.

■ CVEs IDENTIFIED

[CVE-TBD-SHAREFILE]

Progress ShareFile Storage Zone Controller — Unspecified critical external threat prompting immediate shutdown recommendation

Critical

[CVE-TBD-GITEA]

Gitea (Official Docker Image) — Authentication bypass allowing full administrator impersonation and repository takeover

Critical

[CVE-TBD-UBOOT]

U-Boot Bootloader — Six vulnerabilities allowing boot-time arbitrary code execution and device crashes

Critical

[CVE-TBD-OPENCLAW]

OpenClaw AI Assistant — WhatsApp-to-host attack chain enabling credential theft, privilege escalation, and arbitrary code execution

High

■ THREAT ACTORS

The Gentlemen

Ransomware Affiliate Group

Actively deploying ransomware using an aggressive affiliate model

Silver Fox

China-linked Cybercrime Group

Deploying the new Rust-based MODBEACON RAT utilizing gRPC streaming for C2

China-linked APT

Nation-State

Spying campaign targeting the Balochistan Police force in Pakistan

■ ATT&CK TTPs

T1542.001
Pre-OS Boot: System Firmware | U-Boot bootloader vulnerabilities exploited to run code at boot
T1190
Exploit Public-Facing Application | Active exploitation of Gitea authentication bypass and Zimbra Classic Web Client XSS
T1195.002
Compromise Software Supply Chain | Injective Labs GitHub compromise distributing malicious npm packages
T1566.002
Spearphishing Link | Comment stuffing in HTML attachments to evade AI-based detection
T1048
Exfiltration Over Alternative Protocol | MODBEACON RAT using gRPC streaming for encrypted C2 traffic
T1486
Data Encrypted for Impact | GigaWiper and The Gentlemen ransomware encrypting or wiping target systems

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

Progress ShareFile Storage Zone Controller — Active "credible" external threat requires immediate shutdown of Windows hosts — [BC/THN]

[P1 PATCH NOW]≤24h

Gitea (Docker Image) — Active exploitation of critical authentication bypass allowing admin takeover — [BC]

[P1 PATCH NOW]≤24h

Zimbra Collaboration Suite (Classic Web Client) — Critical XSS flaw allows session hijacking; vendor urges immediate patching — [BC]

[P2 PATCH NOW]≤72h

Google Chrome — Two critical updates released in two days to address severe vulnerabilities — [MWB]

■ RECOMMENDED ACTIONS TODAY

1[P1] Immediately shut down all Windows servers running Progress ShareFile Storage Zone Controllers to mitigate the "credible external security threat" [CVE-TBD-SHAREFILE].
2[P1] Apply the latest security patches for Gitea's official Docker image to remediate the critical authentication bypass vulnerability under active exploitation [CVE-TBD-GITEA].
3[P1] Patch the Zimbra Collaboration Suite Classic Web Client immediately to address the critical XSS vulnerability [CVE-TBD-ZIMBRA].
4[P2] Update Google Chrome installations to the latest version to address critical vulnerabilities patched in the consecutive daily updates [CVE-TBD-CHROME].
5[P2] Audit software supply chains for npm dependencies, specifically ensuring the `@injective/sdk` package is verified and clean of the compromised GitHub version.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 12 Jul | Compromised Jscrambler NPM Package Drops Rust Infostealer Older → [SecurityIntel] 10 Jul | Critical Patches & Supply Chain Attacks
Powered by Buttondown, the easiest way to start and grow your newsletter.