# Threat Intel Brief — July 4, 2026

TL;DR

  • Critical Linux kernel privilege escalation (CVE-2026-46242) allows unprivileged users to gain root access on desktops, servers, and Android devices; patches available and immediate deployment required.
  • Microsoft SharePoint RCE vulnerability (CVE-2026-45659) added to CISA KEV catalog due to active exploitation; unauthenticated remote code execution possible on unpatched systems.
  • NetNut residential proxy botnet disrupted by Google, FBI, and Lumen after compromising approximately 2 million home devices; infrastructure degraded but successor networks likely.
  • North Korea-linked supply chain attack targets JavaScript developers via malicious npm packages impersonating legitimate build tools to steal credentials and establish remote access.
  • First AI-agent-orchestrated ransomware attack documented by Sysdig, with JADEPUFFER operator automating entire attack chain from exploitation through database encryption.

---

Critical Threats

Bad Epoll Linux Kernel Privilege Escalation (CVE-2026-46242)

What happened:
A critical vulnerability in the Linux kernel, dubbed "Bad Epoll," enables any unprivileged local user to escalate privileges to root. The flaw affects Linux desktops, servers, and Android devices across all distributions running vulnerable kernel versions. Patches have been released by major vendors.

Impact:
Any compromised low-privilege account or malicious local user can achieve full system control. The vulnerability is particularly dangerous in multi-tenant environments, shared hosting platforms, container deployments, and Android devices where malicious applications could exploit the flaw to gain kernel-level access. Organizations with internet-facing Linux systems or environments permitting untrusted user access face immediate compromise risk.

Recommendations:

  • Deploy vendor-provided kernel patches within 24 hours for all internet-facing and multi-user Linux systems.
  • Prioritize patching for systems with local user access, particularly development environments and shared infrastructure.
  • Monitor auditd logs for unusual privilege escalation attempts (execve, setuid, capability changes).
  • For Android devices, deploy manufacturer security updates as they become available; consider restricting application installation sources until patching is complete.
  • Review and restrict local user permissions on critical systems until patching is verified.

---

Microsoft SharePoint RCE Under Active Exploitation (CVE-2026-45659)

What happened:
CISA added CVE-2026-45659 to its Known Exploited Vulnerabilities catalog following confirmed active exploitation. The high-severity vulnerability (CVSS 8.8) in Microsoft SharePoint Server stems from deserialization of untrusted data, enabling unauthenticated remote code execution. Microsoft released patches in May 2026.

Impact:
Attackers can execute arbitrary code on unpatched SharePoint servers without authentication, leading to full system compromise, data exfiltration, lateral movement, and potential ransomware deployment. SharePoint's widespread use in government, defense industrial base, financial services, and enterprise environments amplifies the strategic significance of this vulnerability.

Recommendations:

  • Apply Microsoft May 2026 security updates to all SharePoint Server instances immediately, prioritizing internet-facing deployments.
  • Audit SharePoint infrastructure to identify unpatched systems; federal agencies must comply with CISA BOD 22-01 timelines.
  • Review SharePoint access logs and Windows Event Logs (Event IDs 4624, 4625, 5140) for suspicious activity since May 2026.
  • Deploy detection rules for unusual SharePoint process execution (w3wp.exe spawning cmd.exe or powershell.exe) via EDR platforms.
  • Restrict network access to SharePoint servers using firewall rules or VPN requirements where operationally feasible.

---

NetNut/Popa Residential Proxy Botnet Disruption

What happened:
Google Threat Intelligence Group, the FBI, and Lumen executed a coordinated operation to disrupt NetNut (also tracked as Popa), a residential proxy network built on approximately 2 million compromised home devices including Android smart TVs and streaming boxes. The FBI seized hundreds of associated domains operated by Israeli company Alarum Technologies. The operation significantly degraded the network's capacity by reducing its pool of usable proxy nodes.

Impact:
Residential proxy networks enable cybercriminals to route malicious traffic through legitimate home IP addresses, evading detection and geographic restrictions. NetNut infrastructure facilitated credential stuffing, fraud, web scraping, and anonymization for downstream threat actors. While the disruption degrades current capabilities, residual infrastructure and successor networks are likely to emerge.

Recommendations:

  • Monitor outbound connections from IoT and smart home devices for unexpected proxy traffic patterns (SOCKS, HTTP proxy protocols to unknown destinations).
  • Implement network segmentation isolating IoT devices from critical systems to limit compromise impact.
  • Deploy firmware update policies for routers and consumer electronics, prioritizing patches for known botnet-exploited vulnerabilities.
  • For enterprises: implement IP reputation services and behavioral analytics to identify authentication attempts from known residential proxy networks.
  • Detect anomalous bandwidth usage on residential endpoints that may indicate proxy relay activity using NetFlow or similar telemetry.

---

Threat Actor Activity

North Korea-Linked npm Supply Chain Attack (Lazarus)

Lazarus Group deployed malicious npm packages "rollup-packages-polyfill-core" and "rollup-runtime-polyfill-core" that impersonate the legitimate "rollup-plugin-polyfill-node" project. The typosquatted packages steal developer secrets (environment variables, API keys, credentials) and establish remote access upon installation. JFrog discovered the campaign, which targets JavaScript/Node.js developers through social engineering and metadata mimicry. This operation continues Lazarus's established pattern of targeting software supply chains, following previous campaigns against cryptocurrency developers and the 3CX compromise. Organizations should immediately audit Node.js projects for these dependencies, rotate all secrets accessible from affected environments, and implement npm package verification controls (Socket.dev, Snyk, npm audit) in CI/CD pipelines.

Armored Likho Targets Government and Energy Sectors

Armored Likho, a previously undocumented threat actor, has been attributed to cyber attacks targeting government agencies and electric power infrastructure across Russia, Brazil, and Kazakhstan using the BusySnake stealer. Kaspersky's analysis reveals the group combines financially motivated campaigns against private individuals with targeted cyber espionage operations against organizations. The dual-mandate approach suggests either a blended threat model or an actor-for-hire operation. The targeting of Russian entities is notable and may indicate a non-Russian nexus. Organizations in government and critical infrastructure sectors across these regions should monitor for BusySnake indicators, implement enhanced email security controls, and deploy network segmentation to isolate critical infrastructure environments.

ToddyCat Deploys Umbrij Malware for Gmail OAuth Abuse

ToddyCat APT group has deployed Umbrij, a new malware that abuses OAuth to gain unauthorized access to Gmail accounts via the Google API. The malware targets corporate email communications through cloud API exploitation, representing an evolution in ToddyCat's tradecraft from traditional network-based intrusion to cloud service targeting. Organizations using Gmail or Google Workspace should monitor OAuth token grants and API access patterns, implement conditional access policies requiring device compliance and MFA for OAuth consent flows, and enable advanced logging for Google Workspace API activity to detect unauthorized email access from compromised systems.

JADEPUFFER: First AI-Agent-Orchestrated Ransomware

Sysdig documented what it claims is the first fully AI-agent-orchestrated ransomware attack, attributed to operator JADEPUFFER. The attack exploited a Langflow RCE vulnerability to automate the entire attack chain including initial compromise, credential theft, lateral movement, and database encryption and wiping. This represents a potential inflection point in ransomware evolution, moving from scripted automation to adaptive, agent-driven orchestration. Organizations deploying AI/ML infrastructure should immediately patch Langflow instances, restrict public exposure of development platforms, implement robust credential monitoring with MFA, and deploy database activity monitoring with immutable offline backups.

Anubis Ransomware Exploits Citrix Bleed 2 (CVE-2025-5777)

Threat actors operating Anubis ransomware have been observed exploiting CVE-2025-5777 (Citrix Bleed 2) for initial access. Post-compromise, they deploy legitimate RMM tools to establish persistence and conduct hands-on-keyboard operations for credential access and lateral movement. Organizations using Citrix infrastructure should immediately patch CVE-2025-5777, monitor and restrict RMM tool deployment via application whitelisting, implement privileged access management with MFA on all remote access points, and deploy network segmentation to limit lateral movement opportunities.

---

Geopolitical Context

European Parliament Member Targeted with Pegasus Spyware

A former European Parliament member investigating spyware abuse was targeted with NSO Group's Pegasus spyware while serving on a committee examining commercial surveillance tools. Citizen Lab's forensic analysis confirmed the compromise through repeated exploitation attempts. The targeting of an individual conducting parliamentary oversight represents direct interference with democratic accountability mechanisms and may accelerate EU legislative efforts to regulate or ban commercial spyware. The incident underscores risks faced by those scrutinizing state surveillance practices and may influence transatlantic cooperation on export controls for cyber intrusion tools. High-risk political figures and investigators should deploy mobile threat defense solutions, conduct regular forensic analysis using tools like Mobile Verification Toolkit, and enable iOS Lockdown Mode where applicable.

Scattered Spider Member Extradited from Estonia

A dual U.S.-Estonian citizen has been extradited to the United States to face charges for alleged membership in the Scattered Spider hacking collective. The extradition reflects strong bilateral judicial cooperation under NATO alliance frameworks and signals Western jurisdictions' willingness to pursue prosecution even when suspects hold citizenship in allied nations. Scattered Spider, known for sophisticated social engineering and identity-based attacks targeting large enterprises, has been linked to high-profile breaches involving major corporations. Organizations should implement robust help desk verification procedures with out-of-band authentication, deploy phishing-resistant MFA (FIDO2/WebAuthn), and monitor for modifications to conditional access policies and domain trusts.

---

Recommended Actions

Immediate (0-24 hours)

1. Patch CVE-2026-46242 (Bad Epoll) on all internet-facing Linux systems and multi-user environments; prioritize systems with local user access.
2. Patch CVE-2026-45659 (SharePoint RCE) on all SharePoint Server instances; federal agencies must comply with CISA BOD 22-01 timelines.
3. Audit npm dependencies for malicious packages "rollup-packages-polyfill-core" and "rollup-runtime-polyfill-core"; rotate all secrets accessible from affected development environments.
4. Patch CVE-2025-5777 (Citrix Bleed 2) on all Citrix infrastructure; review logs for exploitation indicators prior to patching.
5. Alert security research teams about ChocoPoC campaign; enforce mandatory sandboxing for all external exploit code testing.

Near-term (24-72 hours)

1. Review OAuth application consents in Azure AD/Entra ID; revoke suspicious third-party app permissions and implement admin-only consent policies.
2. Patch Langflow instances against RCE vulnerabilities; restrict public exposure of AI/ML development platforms to trusted networks.
3. Audit FortiGate VPN devices for known vulnerabilities; implement MFA on all VPN and remote access solutions.
4. Conduct forensic review of Cisco Unified Communications Manager logs for suspicious activity; apply early June 2026 security patches.
5. Monitor for BusySnake stealer indicators in government and energy sector environments across Russia, Brazil, and Kazakhstan.

This week

1. Implement network segmentation isolating IoT devices from critical systems; deploy firmware update policies for routers and consumer electronics.
2. Deploy detection rules for unusual SharePoint process execution and Linux privilege escalation attempts via EDR and SIEM platforms.
3. Enable enhanced logging for Google Workspace API activity and Azure AD sign-in events; establish baseline behavior profiles for anomaly detection.
4. Conduct security awareness training on Microsoft 365 phishing tactics and OAuth consent prompt verification.
5. Review and test database backup procedures; ensure immutable backups are stored offline and recovery processes are validated.

---

Watch List

  • FatFs filesystem vulnerabilities: Seven unpatched flaws disclosed by runZero affecting millions of embedded devices including security cameras, drones, industrial controllers, and crypto wallets. No CVE assigned yet; monitor vendor communications for patch releases.
  • Cisco Unified CM vulnerability: Active exploitation confirmed by Cisco for a flaw patched in early June 2026. CVE not yet publicly disclosed; monitor Cisco security advisories for technical details.
  • Avalon malware framework: Newly documented modular framework distributed via phishing campaigns, integrating credential collection, lateral movement, and CrownX ransomware capabilities.
  • PamStealer macOS infostealer: Distributed as fake Maccy clipboard manager application; uses compiled AppleScript and PAM checks to steal Mac login passwords.
  • ConsentFix/ClickFix campaigns: Hijack Microsoft 365 accounts via OAuth token theft through fake consent prompts, bypassing MFA protections.
  • FortiBleed campaign: Credential theft operation linked to INC and Lynx ransomware groups; stolen FortiGate credentials used for follow-on ransomware intrusions.

---

Sources

  • BleepingComputer: NetNut proxy network disrupted, Cisco Unified CM exploitation, SharePoint RCE, Scattered Spider extradition, Medtronic breach, ConsentFix/ClickFix, ARToken PhaaS
  • The Hacker News: Bad Epoll Linux kernel flaw, FatFs vulnerabilities, Avalon malware, North Korea npm packages, Armored Likho, Pegasus targeting, PamStealer, NetNut disruption, Anubis ransomware, ToddyCat Umbrij, JADEPUFFER AI ransomware, FortiBleed, ChocoPoC RAT, SharePoint CVE-2026-45659
  • Krebs on Security: FBI NetNut/Popa seizure
  • CISA Known Exploited Vulnerabilities Catalog
  • Kaspersky, JFrog, Sysdig, Citizen Lab, runZero, Jamf Threat Labs (research sources)