# Threat Intel Brief — July 3, 2026
TL;DR
- Critical SharePoint RCE (CVE-2026-45659) added to CISA KEV catalog after active exploitation; unauthenticated attackers can execute arbitrary code on unpatched servers.
- Progress Kemp LoadMaster (CVE-2026-8037) under active attack via pre-authentication OS command injection; CVSS 9.6 severity demands immediate patching.
- Cursor AI editor vulnerabilities (CVE-2026-50548, CVE-2026-50549) enable prompt injection attacks to escape sandbox and execute commands on developer machines without user interaction.
- Anubis ransomware exploiting Citrix Bleed 2 (CVE-2025-5777) for initial access; FortiBleed credential theft campaign linked to INC and Lynx ransomware operations.
- FBI disrupts NetNut/Popa botnet spanning 2 million compromised home devices; DHS confirms breach of Homeland Security Information Network (HSIN).
---
Critical Threats
Microsoft SharePoint RCE Under Active Exploitation
What happened: CISA added CVE-2026-45659 to its Known Exploited Vulnerabilities catalog following confirmed in-the-wild attacks. The vulnerability is a deserialization flaw in Microsoft SharePoint Server with a CVSS score of 8.8, enabling unauthenticated remote code execution. The flaw was patched in May 2026, but attackers are targeting organizations that have not applied updates.
Impact: SharePoint servers often contain sensitive business data and integrate with Active Directory, making compromise a pivot point for lateral movement. Successful exploitation grants attackers arbitrary code execution without credentials, enabling data exfiltration, ransomware deployment, or persistent access to corporate networks. Federal agencies face mandatory remediation timelines under CISA Binding Operational Directive 22-01.
Recommendations:
- Apply Microsoft security updates for CVE-2026-45659 immediately (federal agencies: within 21 days per CISA directive; private sector: prioritize urgently).
- Audit SharePoint access logs for unusual authentication patterns, deserialization errors, or unexpected code execution attempts since May 2026.
- Restrict SharePoint Server network exposure; ensure instances are not directly accessible from the internet.
- Review and limit user permissions to reduce attack surface for authenticated exploitation.
---
Progress Kemp LoadMaster Pre-Auth RCE
What happened: CVE-2026-8037, a critical pre-authentication remote code execution vulnerability in Progress Kemp LoadMaster appliances, is experiencing active exploitation attempts. The flaw allows OS command injection with a CVSS score of 9.6, enabling attackers to compromise load balancers without credentials.
Impact: LoadMaster devices are deployed at network perimeters and critical infrastructure points, making compromise a high-value target for traffic interception, lateral movement, and service disruption. Successful exploitation provides full system control, potentially exposing backend application servers and sensitive traffic.
Recommendations:
- Identify all Progress Kemp LoadMaster instances and isolate from internet exposure if possible.
- Apply vendor security patches immediately when released.
- Monitor LoadMaster access logs and system logs for suspicious command execution or unauthorized access attempts.
- Implement network segmentation to restrict LoadMaster management interface access to trusted admin networks only.
- Review recent configuration changes and establish known-good baseline for incident response.
---
Cursor AI Editor Sandbox Escape Vulnerabilities
What happened: Security researchers at Cato AI Labs disclosed two critical vulnerabilities in Cursor, an AI-powered code editor. CVE-2026-50548 (CVSS 9.8) and CVE-2026-50549 (CVSS 9.3) enable prompt injection attacks to escape the editor's sandbox and execute arbitrary commands on developer machines without user interaction. The research team named the vulnerability set "DuneSlide."
Impact: Developers using Cursor risk arbitrary code execution through malicious prompts injected via code repositories, documentation, or other AI-processed content. Attackers could gain full access to developer environments, source code, credentials, and internal systems. High impact for organizations using Cursor in development workflows, especially when processing untrusted or third-party code.
Recommendations:
- Update Cursor to the latest patched version immediately; contact vendor for patch availability if not yet released.
- Restrict Cursor usage to trusted code repositories and disable AI features when reviewing untrusted code until patched.
- Monitor developer workstations for unexpected command execution or network connections originating from Cursor processes.
- Review recent Cursor activity logs for signs of exploitation, particularly unusual AI prompt patterns or sandbox escape attempts.
---
Argo CD Repo-Server RCE Enables Cluster Takeover
What happened: An unpatched vulnerability in Argo CD's repo-server component allows unauthenticated attackers with access to the internal network port to execute arbitrary code and potentially achieve full Kubernetes cluster takeover. No CVE has been assigned and no patch is currently available.
Impact: Critical risk for organizations running Argo CD in Kubernetes environments. Unauthenticated attackers with internal network access can execute arbitrary code on repo-server, potentially escalating to full cluster compromise. This affects GitOps pipelines and all workloads managed by Argo CD. Internal network access requirement reduces attack surface but does not eliminate risk from insider threats, compromised internal systems, or lateral movement scenarios.
Recommendations:
- Immediately restrict network access to Argo CD repo-server ports using network policies or firewall rules to only trusted components.
- Audit network segmentation to ensure repo-server is isolated from untrusted internal networks and user workloads.
- Enable comprehensive logging for repo-server access and monitor for unexpected connection attempts or unusual process execution.
- Review Argo CD RBAC policies and reduce privileges where possible to limit blast radius of potential compromise.
- Monitor Argo CD GitHub repository and security mailing lists for patch announcements and apply immediately when available.
---
Adobe ColdFusion and Campaign Classic Maximum-Severity Flaws
What happened: Adobe released patches for multiple maximum-severity (CVSS 10.0) vulnerabilities affecting Adobe ColdFusion and Adobe Campaign Classic. The flaws could lead to arbitrary code execution, privilege escalation, arbitrary file system read, and security feature bypass. CVE identifiers not yet publicly assigned.
Impact: Maximum-severity vulnerabilities present critical risk to organizations running Adobe ColdFusion or Campaign Classic. Arbitrary code execution could allow full system compromise. File system read and privilege escalation enable data exfiltration and lateral movement.
Recommendations:
- Apply Adobe security patches immediately for all ColdFusion and Campaign Classic instances.
- Identify all ColdFusion and Campaign Classic deployments using asset inventory.
- Review Adobe security bulletin for affected version numbers and patch applicability.
- Monitor ColdFusion and Campaign Classic access logs for suspicious activity or exploitation attempts.
- Restrict network access to ColdFusion and Campaign Classic admin interfaces to trusted IPs only.
---
Oracle E-Business Suite Instances Under Active Attack
What happened: Over 900 Oracle E-Business Suite instances have been discovered exposed online and are currently being targeted by ongoing attacks exploiting a critical security vulnerability. CVE identifier not yet assigned; patch availability unknown.
Impact: Organizations running Oracle E-Business Suite face immediate risk of compromise if instances are internet-accessible. E-Business Suite typically manages critical business functions including financials, HR, supply chain, and customer data. Successful exploitation could lead to data breach, business disruption, or ransomware deployment.
Recommendations:
- Immediately identify all Oracle E-Business Suite instances and verify their internet exposure status.
- Remove direct internet access to Oracle E-Business Suite instances; place behind VPN or zero-trust access controls.
- Review Oracle E-Business Suite access logs and authentication logs for suspicious activity or unauthorized access attempts.
- Monitor Oracle Critical Patch Update advisories and apply relevant security patches as soon as available.
- Implement network segmentation to isolate E-Business Suite from other critical systems until patching is complete.
---
Threat Actor Activity
Scattered Spider Member Extradited to U.S.
A 19-year-old dual U.S.-Estonian citizen, Peter Stokes, was extradited from Finland to face federal charges including conspiracy, computer intrusion, and fraud related to alleged involvement with Scattered Spider. He appeared in Chicago federal court on June 30 and was ordered held in custody. Scattered Spider is a financially motivated threat actor known for social engineering attacks, credential harvesting, and ransomware deployment using BlackCat/ALPHV. The group employs sophisticated techniques including help desk impersonation, MFA bypass, and cloud infrastructure compromise.
Defensive priorities: Implement robust identity verification procedures for help desk interactions, monitor for anomalous authentication patterns including impossible travel and MFA push fatigue, deploy detection rules for NTDS.dit access and credential dumping, and establish baseline monitoring for cloud infrastructure enumeration API calls.
---
Anubis Ransomware Exploits Citrix Bleed 2
Threat actors associated with the Anubis ransomware operation have been observed exploiting CVE-2025-5777 (Citrix Bleed 2) to obtain initial access. The attackers employ legitimate RMM tooling, credential access techniques, and hands-on-keyboard procedures for lateral movement and network compromise.
Defensive priorities: Immediately patch Citrix infrastructure against CVE-2025-5777, implement application allowlisting to detect unauthorized RMM tool deployment, enable enhanced logging for credential access attempts, monitor for lateral movement indicators including unusual RDP/SMB connections, and implement network segmentation to limit lateral movement.
---
FortiBleed Campaign Linked to INC and Lynx Ransomware
The FortiBleed campaign, a financially motivated credential theft operation, has been linked to INC and Lynx ransomware groups. Stolen FortiGate credentials obtained through FortiBleed are being used for follow-on ransomware intrusions, with operators managing negotiation panels for both ransomware groups.
Defensive priorities: Audit all FortiGate SSL-VPN configurations and apply latest Fortinet security patches, implement multi-factor authentication on all VPN and remote access solutions, monitor for anomalous VPN authentication patterns, deploy network segmentation to limit lateral movement from VPN entry points, and establish threat hunting procedures to identify INC and Lynx ransomware indicators.
---
ToddyCat Deploys Umbrij Malware for Gmail Hijacking
ToddyCat threat actor has deployed a new malware called Umbrij that abuses OAuth to gain unauthorized access to Gmail accounts via the Google API, targeting corporate email communications. The malware is designed to compromise email access through API exploitation.
Defensive priorities: Monitor OAuth token grants and API access patterns for anomalies, implement conditional access policies requiring device compliance and multi-factor authentication for cloud email access, deploy endpoint detection rules for ToddyCat-associated malware families, enable logging for scheduled task creation, and conduct regular audits of third-party OAuth applications with Gmail API access.
---
JADEPUFFER: First AI-Agent-Orchestrated Ransomware
Security firm Sysdig discovered what it claims is the first fully AI-agent-orchestrated ransomware attack, attributed to an operator called JADEPUFFER. The attack exploited a Langflow RCE vulnerability to automate the entire attack chain, including initial compromise, credential theft, lateral movement, and database encryption and wiping.
Defensive priorities: Immediately patch Langflow instances and conduct vulnerability assessments for all internet-facing AI/ML platforms, implement network segmentation to limit lateral movement from compromised AI workflow systems, deploy behavioral detection for unusual credential access patterns and automated tool execution sequences, enable comprehensive logging for database access and encryption events, and restrict outbound connectivity from AI agent platforms.
---
ShinyHunters Breaches Medtronic
Medtronic, a healthcare device manufacturer, is notifying customers of a data breach that exposed personal data to an unauthorized third party. The breach is attributed to ShinyHunters, a financially motivated cybercrime group known for large-scale data breaches targeting organizations across multiple sectors.
Defensive priorities: Implement comprehensive database access monitoring and anomaly detection, enforce multi-factor authentication across all external-facing applications and cloud storage services, conduct thorough security assessments of web applications and APIs, deploy data loss prevention solutions with egress filtering, and establish third-party vendor security requirements.
---
Geopolitical Context
FBI Disrupts NetNut/Popa Botnet
The FBI seized hundreds of domains associated with NetNut, a residential proxy service operated by Israeli company Alarum Technologies, following revelations that the platform was connected to the Popa botnet comprising at least two million compromised devices. Google's Threat Intelligence Group, working with the FBI and Lumen, disrupted the network, significantly degrading its operational capacity.
The operation represents a coordinated effort between private sector threat intelligence, law enforcement, and telecommunications infrastructure providers to degrade a commercial cybercrime enabler. Residential proxy networks commoditize access to compromised consumer devices, allowing threat actors to mask malicious traffic behind legitimate IP addresses.
---
DHS Confirms Breach of Homeland Security Information Network
The Department of Homeland Security confirmed a cyberattack that compromised the Homeland Security Information Network (HSIN), a sensitive information-sharing platform used by federal, state, local, and private-sector partners. DHS is investigating the breach.
The compromise represents a significant breach of critical federal information-sharing infrastructure. HSIN serves as a trusted platform for coordination among multiple levels of government and critical infrastructure sectors on matters of national security, emergency response, and critical infrastructure protection. The breach potentially exposes sensitive operational information, intelligence assessments, and coordination protocols.
---
Kubota North America Month-Long Network Intrusion
Kubota North America Corporation disclosed that unauthorized actors gained access to some of its network systems for over a month in 2024. The extended access period indicates a significant security incident affecting the agricultural equipment manufacturer.
The extended dwell time is consistent with advanced persistent threat activity, though no attribution has been disclosed. Agricultural and manufacturing sectors have increasingly become targets for both espionage and disruptive operations, given their economic significance and potential impact on supply chain resilience.
---
Recommended Actions
Immediate (0-24 hours)
- Patch CVE-2026-45659 (SharePoint RCE) and CVE-2026-8037 (Kemp LoadMaster RCE) on all affected systems.
- Audit Cisco Unified CM deployments and apply June 2024 patches; review access logs for suspicious activity.
- Identify and isolate Oracle E-Business Suite instances exposed to the internet; remove direct internet access.
- Update Cursor AI editor to patched version addressing CVE-2026-50548 and CVE-2026-50549.
- Restrict network access to Argo CD repo-server ports using network policies or firewall rules.
- Enable MFA on all Microsoft 365 accounts and disable legacy authentication protocols to counter password-spray campaigns.
- Audit GitHub repository downloads by security teams for ChocoPoC malware; scan endpoints with updated signatures.
24-72 hours
- Review OAuth application consents in Microsoft 365 admin center; revoke suspicious third-party app permissions.
- Audit FortiGate SSL-VPN configurations for exposed credentials; implement MFA on all VPN solutions.
- Monitor OAuth token grants and API access patterns for anomalies, particularly Google API calls from unexpected geolocations.
- Patch Langflow instances and conduct vulnerability assessments for all internet-facing AI/ML platforms.
- Apply Adobe security patches for ColdFusion and Campaign Classic instances.
- Review SharePoint, LoadMaster, and Unified CM logs for indicators of compromise since May 2026.
This week
- Conduct user awareness training on OAuth consent screen verification, PDF-based phishing lures, and fake PoC exploit risks.
- Implement network segmentation to isolate critical systems from VPN entry points and compromised endpoints.
- Deploy detection rules for NTDS.dit credential dumping, unusual RMM tool deployment, and cloud infrastructure enumeration.
- Establish baseline monitoring for browser-based ransomware indicators and AI-generated malware execution patterns.
- Review third-party vendor security requirements and continuous monitoring programs to prevent supply chain compromise.
---
Watch List
- Cisco Unified CM vulnerability: Monitor for CVE assignment and additional technical details; exploitation confirmed but details limited.
- Argo CD repo-server RCE: No patch available; monitor vendor GitHub repository for security updates.
- Oracle E-Business Suite attacks: CVE not yet assigned; monitor Oracle Critical Patch Update advisories.
- Adobe ColdFusion/Campaign Classic: CVE identifiers not yet publicly assigned; monitor Adobe security bulletins.
- Langflow RCE: CVE not yet assigned; monitor for technical details on JADEPUFFER AI-orchestrated ransomware.
- ConsentFix/ClickFix campaigns: OAuth token theft bypassing MFA; monitor for IOCs and detection signatures.
- ChocoPoC RAT: Targeting vulnerability researchers via fake GitHub PoC repositories; monitor for updated indicators.
- Ousaban banking trojan: Targeting Spain and Portugal via phishing; monitor for campaign expansion.
- VEIL#DROP campaign: Delivering PureLogs stealer via Blogger pages; monitor for infrastructure updates.
- Browser-based ransomware: AI-generated malware abusing Chromium APIs; monitor for additional samples and defensive guidance.
---
Sources
- BleepingComputer: ConsentFix and ClickFix, Cisco Unified CM, SharePoint RCE, Scattered Spider extradition, Medtronic breach, FortiBleed campaign, Kubota breach, ChocoPoC malware, DHS HSIN breach, Microsoft 365 password spray, Oracle E-Business Suite attacks
- The Hacker News: NetNut disruption, Citrix Bleed 2 ransomware, ToddyCat Umbrij malware, JADEPUFFER AI ransomware, FortiBleed-INC-Lynx linkage, ChocoPoC RAT, SharePoint CVE-2026-45659, Argo CD vulnerability, Scattered Spider extradition, SEO-poisoned AsyncRAT campaign, VEIL#DROP campaign, Ousaban banking trojan, Adobe patches, Cursor vulnerabilities, Kemp LoadMaster RCE, AI-generated browser ransomware
- Krebs on Security: FBI NetNut/Popa botnet seizure
