Cyber Threat Intelligence Digest: Week 27

8th July 2026 - Threat Reports
Share
  • Vulnerabilities
  • Potential Threats
  • General News
  • Threat Actor Weekly Graph
  • Global Trends Powered by Recorded Future
  • Prominent Information Security Events
  • Remediation Actions

Executive Summary -
Highlights of Cyber Threat Intelligence Digest

Vulnerabilities

WatchGuard Patches CVE-2026-13368 Affecting Fireware OS - On 2 July 2026, WatchGuard patched CVE-2026-13368, a critical vulnerability affecting Firebox appliances running Fireware OS 11.0 through 11.12.4_Update1, 12.0 through 12.12, 12.5 through 12.5.18, and 2025.1 through 2026.2. The fix was released in Fireware OS 2026.2.1 for the 2025.1 branch and 12.12.1 for the 12.x branch. Fireware OS 12.5.x on T15 and T35 models remains unresolved, and the 11.x branch is end of life. There is no evidence of active exploitation at the time of writing.

CVE-2026-13368 is a race condition leading to a use-after-free vulnerability in LDAP authentication for Mobile User VPN with IKEv2. A remote, unauthenticated threat actor could exploit the flaw on Fireboxes configured to use Mobile VPN with IKEv2 and an external LDAP authentication server. Successful exploitation allows arbitrary code execution in the context of the "iked" process, potentially enabling administrative control of the appliance, access to sensitive firewall configuration and VPN material, and lateral movement into internal networks.

Apache Patches Two Vulnerabilities CVE-2026-54428 and CVE-2026-54399 in Apache HttpComponents - On 1 July 2026, Apache patched two vulnerabilities affecting Apache HttpComponents Core versions 5.4.2 and earlier, and 5.5-beta1 and earlier. At the time of writing, there are no reports of these vulnerabilities being exploited in the wild.

CVE-2026-54428 is an allocation of resources without limits flaw, exploitation of which could allow threat actors to cause a denial-of-service (DoS). CVE-2026-54399 is an uncontrolled resource consumption flaw, exploitation of which could allow threat actors to cause a DoS by exhausting memory.

Seiko Solutions Discloses CVE-2026-50043 Vulnerability in SkyBridge MB-A100 and MB-A110 - On 1 July 2026, Seiko Solutions patched an OS command injection vulnerability tracked as CVE-2026-50043, affecting the SkyBridge MB-A100 and SkyBridge MB-A110 devices. The flaw stems from insufficient validation of input passed to the underlying operating system, and Seiko Solutions has released updates to address the issue for both affected models.

Exploitation could allow a threat actor to execute arbitrary malicious commands on the operating system running on the affected device, potentially granting them a foothold from which to further compromise the device or pivot into connected systems.

Potential Threats

Threat Actors Reportedly Compromise Fortinet Firewalls Used by UK Government Organizations in FortiBleed Campaign - On 6 July 2026, local media outlets reported that Russian threat actors had compromised Fortinet firewalls used by UK government organisations in a campaign dubbed "FortiBleed." The attackers allegedly breached email accounts belonging to UK government officials and Foreign Office staff, subsequently offering access to the compromised accounts for sale on dark web forums for up to £44,000 (approximately $60,000 USD). Investigators have not attributed the activity directly to the Russian government, though the campaign's targeting of high-value diplomatic and governmental accounts has drawn comparisons to previous state-linked operations.

The threat actors reportedly exploited an unspecified Fortinet vulnerability in combination with previously stolen credentials to bypass security controls and gain access to the affected networks. Reported victims include British embassies in Thailand and Mauritius, as well as local government entities in Derbyshire and Waltham Forest, suggesting a broad campaign spanning both diplomatic and municipal targets. In response, the UK National Cyber Security Centre (NCSC) has urged organisations to audit their Fortinet deployments, isolate any compromised devices, and review credential hygiene given the apparent use of stolen login details alongside the exploited vulnerability.

Threat Actor Uses Malicious PyPI Dependencies to Deliver ChocoPoC RAT Through GitHub PoCs - On 1 July 2026, Sekoia reported unknown threat actors running a campaign targeting vulnerability researchers, penetration testers, and developers, using trojanised GitHub proof-of-concept (PoC) repositories to distribute malicious Python packages that deployed the "ChocoPoC RAT." At least seven malicious repositories impersonated PoCs for vulnerabilities in FortiWeb, React2Shell, MongoBleed, PAN-OS, Ivanti Sentry, Check Point VPN, and Joomla SP Page Builder. Active since late 2025, the campaign targets users who routinely run untrusted PoC code and may hold access to customer credentials, confidential reports, and sensitive infrastructure. Sekoia assessed with high confidence that the threat actor used compromised GitHub, PyPI, and email accounts to publish the repositories and two malicious PyPI packages, "frint" and "skytext," added to the repositories' installation requirements.

Running pip install downloaded frint, which installed skytext, whose compiled native library loaded before any PoC source code, evaded sandboxes via anti-analysis and filename checks, then decrypted five obfuscated Python payloads. These established persistence through a trojanised package and startup files in the Python installation directory, with altered timestamps to reduce forensic visibility. Each new Python session triggered a downloader that used DNS-over-HTTPS to fetch a Base64-encoded payload from a Mapbox dataset, delivering the ChocoPoC RAT. The RAT used Mapbox datasets and a dedicated HTTP server as command-and-control channels to harvest browser credentials, documents, database files, shell histories, and system information, and to execute further operator commands.

PhaaS ARToken Targets Microsoft 365 Accounts, Shares EvilTokens Tradecraft - On 1 July 2026, Cisco Talos published a report on ARToken, a phishing-as-a-service (PhaaS) panel sharing infrastructure and behaviour with EvilTokens, a platform documented in early 2026 that steals Microsoft 365 authentication tokens by abusing the OAuth 2.0 device authorisation flow, bypassing the need for victims' passwords. Talos found ARToken while investigating phishing tied to an incident response case, involving a spoofed invoice email sent to a US life-sciences company on 20 April 2026 that linked to a look-alike SharePoint workspace and showed failed SPF, DKIM, and DMARC checks. The unauthenticated management panel exposed its routes and API endpoints, and distributed lures via Cloudflare Workers pages themed as document viewers, OneDrive, and Adobe.

The malware uses a seven-layer anti-analysis system, requiring genuine mouse or touch interaction before releasing an XOR-encrypted payload that harvests any existing token and directs victims through a genuine Microsoft device code login flow. Successful logins let operators capture and refresh tokens, access the victim's Microsoft 365 account, and escalate to persistent access surviving password resets. With valid tokens, operators can browse live sessions, conduct business email compromise via inbox manipulation, access SharePoint and OneDrive for document theft, and deploy further phishing infrastructure directly from the dashboard.

General News

Britain plans to build autonomous AI 'Cyber Shield' to defend nation - Britain's cyber agency laid out plans on Tuesday for a "national scale, sovereign defence capability," called Cyber Shield, using agentic AI to discover and fix cybersecurity weaknesses across government networks and critical national infrastructure. The National Cyber Security Centre (NCSC) said the scheme would counter AI-aided attackers who can already compress reconnaissance and vulnerability discovery from weeks into minutes, warning separately of an AI-driven "patch wave" of vulnerabilities outpacing organisations' ability to fix them. GCHQ director Anne Keast-Butler referenced the plan earlier this year, saying the agency would "hardwire" agentic AI into machine-speed cyber defence amid a narrowing window for the UK to stay ahead of its adversaries.

The plan centres on paired "red" and "blue" AI agents, probing for weaknesses and defending in real time, under the control of the infrastructure owners themselves. The NCSC outlined six required functions, from existing automated scanning to fully autonomous fixing, which it admitted needs further research, and said the capability would be built with frontier AI developers, cyber defence organisations, and academia, starting with government and critical-sector testing before wider commercial rollout. No timeline was attached, and the agency invited outside parties to help develop the blueprint.

Spyware found on phone of European Parliament member probing it - Former European Parliament member Stelios Kouloglou's phone was infected with Pegasus spyware in October 2022 and March 2023, according to a Citizen Lab report released Friday, during his time on the parliamentary committee investigating spyware misuse. The committee's May 2023 recommendations have been largely ignored by the European Commission, a failing researcher John Scott-Railton called inexcusable, warning that further undisclosed hacks of MEPs are likely. Kouloglou believes the Greek government is responsible, though Citizen Lab found no evidence of this; NSO Group did not respond to a request for comment.

Citizen Lab linked the same Pegasus customer to a 2024-reported campaign against seven Russian and Belarusian journalists and opposition figures, via a shared targeting email used across both operations. Kouloglou had his phone checked in May 2026 after missing three prior Apple threat notifications. German MEP Hannah Neumann said the case shows "a total disregard for Parliamentarians' role to scrutinise" and doubted it would prompt Commission action. Kouloglou said he plans to sue NSO Group over the loss of years of private communications.

US Department of Homeland Security Confirms Cybersecurity Incident Affecting Information-Sharing Environment - On 30 June 2026, the US Department of Homeland Security (DHS) confirmed to Nextgov that a cybersecurity incident had targeted its unclassified legacy information-sharing environment. Citing two anonymous sources familiar with the matter, Nextgov reported that the incident involved Homeland Security Information Network (HSIN) servers and a SharePoint collaboration system used for sharing information across federal, state, and local agencies, and likely occurred between late May and early June 2026, though the exact timeline has not been officially confirmed by DHS.

According to Nextgov's sources, DHS responded by isolating the affected systems to contain the incident, mitigating an unspecified vulnerability believed to have enabled the intrusion, and launching a forensic investigation to determine the full scope and method of compromise. An initial damage assessment reportedly found no indication that classified networks were affected, suggesting the incident was contained to the unclassified environment. At the time of writing, DHS has not disclosed further technical details about the nature of the vulnerability or the identity of any threat actor involved, and the investigation remains ongoing, with further updates expected as the department's review progresses.

Threat Actor Weekly Graph

Over the past 7 days, we have been tracking the following intent and opportunity changes within our Threat Actor Landscape.

Intent represents the potential targets of a group. When a group is observed attacking a different organisation or entity, their intent will increase.

Opportunity represents the various methods and technologies these groups may use. For example, if a group started using a new attack vector, such as a new kind of ransomware, their opportunity would increase.

Both intent and opportunity are scored out of 100 and are responsible for scoring the group's severity. These updates can be seen below.

 

Limited Severity Basic Severity Moderate Severity High Severity
Threat Actor Severity Increase Opportunity Intent
ShinyHunters Moderate Moderate 49 49 ● 62 ● 63
APT32 OceanLotus Moderate Moderate 55 54 30 30
UNK_MassTraction NEW Basic NEW  35 NEW 25
Doommageddon Ransomware Group NEW Basic
NEW ● 25 NEW 30
Chaos Ransomware Group Basic Basic 30 ● 25 49 49

Global Trends Powered by Recorded Future

Within each category, we have provided the current top five globally trending items. Each item is linked to how actively trending it is and is marked with a small symbol.

The spikes in references are calculated over 60 days and are normalised to ensure they aren't disproportionate when compared to bigger entities that will naturally have more baseline mentions.

- Spike – This indicates a large increase in reporting volume and a high diversity in the event descriptions.
- Rise – This indicates a small increase in reporting volume with little diversity in the descriptions.

Attackers Methods Vulnerabilities Targets
Russian Hackers Pegasus CVE-2026-48282 Russian Volunteer Corps
UNK_MassTraction WebShell CVE-2025-3248 Accenture
Cavern Manticore ProxyShell CVE-2026-11405 Ruddick Corp.
Scattered Spider

Vshell

CVE-2026-43499 KDDI
Hossam Hassan BASHLITE CVE-2026-20896 U.S. Armed Forces  

 

Prominent Information Security Events

Threat Actors Use Malicious PyPi Dependencies to Deliver ChocoPoC RAT Through GitHub PoC's

Source: Insikt Group | Validated Intelligence Event

IOC: Hash - 17997e9e0256d0f5d5d21a4852c37f16b338e4bb9c2bec09bdfd822b24aa76b4

On 1 July 2026, Sekoia reported unknown threat actors running a campaign targeting vulnerability researchers, penetration testers, and developers, using trojanised GitHub proof-of-concept (PoC) repositories to distribute malicious Python packages that deployed the "ChocoPoC RAT." At least seven malicious repositories impersonated PoCs for vulnerabilities in FortiWeb, React2Shell, MongoBleed, PAN-OS, Ivanti Sentry, Check Point VPN, and Joomla SP Page Builder. Active since late 2025, the campaign targets users who routinely run untrusted PoC code and may hold access to customer credentials, confidential reports, and sensitive infrastructure. Sekoia assessed with high confidence that the actor used compromised GitHub, PyPI, and email accounts to publish the repositories and two malicious PyPI packages, "frint" and "skytext," added to their installation requirements.

Running pip install downloaded frint, which installed skytext, whose compiled native library loaded before any PoC source code. The library resolved API functions via Process Environment Block walking, evaded sandboxes through anti-debugging and filename checks, then decrypted five obfuscated Python payloads. It established persistence through a trojanised package and startup files in the Python installation directory, with altered timestamps to reduce forensic visibility.

Each new Python session triggered a downloader that used DNS-over-HTTPS to fetch a Base64-encoded payload from a Mapbox dataset, delivering the ChocoPoC RAT. The RAT used Mapbox datasets and a dedicated HTTP server as command-and-control channels, continuously polling for instructions while harvesting browser credentials, documents, database files, shell histories, and system information, before exfiltrating the data through whichever channel suited its volume.

PhaaS ARToken Targets Microsoft 365 Accounts

Source: Insikt Group | Validated Intelligence Event

IOC: IP: 172[.]67[.]214[.]35

On 1 July 2026, Cisco Talos published a report on ARToken, a phishing-as-a-service (PhaaS) panel sharing infrastructure and behaviour with EvilTokens, a platform documented in early 2026 that steals Microsoft 365 authentication tokens by abusing the OAuth 2.0 device authorisation flow, bypassing the need for victims' passwords. Talos found ARToken while investigating phishing tied to an incident response case, involving a spoofed invoice email sent to a US life-sciences company on 20 April 2026 that linked to a look-alike SharePoint workspace and showed failed SPF, DKIM, and DMARC checks.

The unauthenticated management panel exposed its routes and API endpoints, and distributed lures via Cloudflare Workers pages themed as document viewers, OneDrive, and Adobe. The malware uses a seven-layer anti-analysis system, requiring genuine mouse or touch interaction before releasing an XOR-encrypted payload that harvests any existing token and directs victims through a genuine Microsoft device code login flow.

Successful logins let operators capture and refresh tokens, access the victim's Microsoft 365 account, and escalate to persistent access surviving password resets. With valid tokens, operators can browse live sessions, conduct business email compromise via inbox manipulation, access SharePoint and OneDrive for document theft, and deploy further phishing infrastructure directly from the dashboard.

Remediation Actions

Following the information provided above, we recommend that the technologies mentioned be fully patched and updated. We also want to highlight and recommend applying the following patches where applicable:

  • CVE-2026-13368 (WatchGuard) – This vulnerability can be remediated by updating the 2025.1 branch to Fireware OS 2026.2.1, and the 12.x branch to 12.12.1.

  • CVE-2026-54428, CVE-2026-54399 (Apache) – These vulnerabilities can be addressed by patching to Apache HttpComponents Core version 5.4.3 or later.

  • CVE-2026-50043 (Seiko) – Updating SkyBridge to the most recent version will remediate this vulnerability.

If you are currently an Acumen Cyber Vulnerability Management customer, we will be proactively performing related searching and hunting activities within your environment.