Cyber Threat Intelligence Digest: Week 28

15th July 2026 - Threat Reports
Share
  • Vulnerabilities
  • Potential Threats
  • General News
  • Threat Actor Weekly Graph
  • Global Trends Powered by Recorded Future
  • Prominent Information Security Events
  • Remediation Actions

Executive Summary -
Highlights of Cyber Threat Intelligence Digest

Vulnerabilities

BeyondTrust Patches Four Vulnerabilities Affecting Remote Support and Privileged Remote Access - On 21 June 2026, BeyondTrust disclosed and patched four vulnerabilities affecting Remote Support (RS) versions 25.3.2 and earlier and Privileged Remote Access (PRA) versions 25.3.2 and earlier, all discovered internally through BeyondTrust's AI-driven vulnerability research.

The fixes were released in RS 25.3.3 and PRA 25.3.3, with cloud customers patched as of 21 April 2026. There is no evidence of active exploitation at the time of writing. CVE-2026-40138 (CVSS 9.2) and CVE-2026-40139 (CVSS 9.2) are critical improper authentication vulnerabilities (CWE-287) in the authentication subsystem that could allow a remote attacker to bypass access controls and gain unauthorised access to the appliance, including accounts with elevated privileges, where a specific authentication configuration is enabled.

CVE-2026-40140 (CVSS 8.7) is a high-severity uncontrolled resource consumption vulnerability (CWE-400) allowing a remote, unauthenticated threat actor to trigger a denial-of-service condition, and CVE-2026-40141 (CVSS 8.5) is a high-severity vulnerability (CWE-943) that could allow an authenticated attacker with limited privileges to access data beyond their authorisation scope.

Palo Alto Networks Patches CVE-2026-0288 Affecting PAN-OS - On 8 July 2026, Palo Alto Networks patched CVE-2026-0288, a high-severity vulnerability affecting the User-ID Terminal Server Agent (TSA) component of PAN-OS. The flaw affects PAN-OS 10.2 before 10.2.7-h36, 11.1 before 11.1.4-h35, 11.2 before 11.2.4-h20, and 12.1 before 12.1.4-h8, as well as earlier hotfix trains, and Prisma Access 10.2 and 11.2 at reduced severity. Fixes were released across the affected branches, with Cloud NGFW requiring no action and Panorama not impacted. There is no evidence of active exploitation at the time of writing.

CVE-2026-0288 (CVSS 7.2) comprises multiple out-of-bounds write buffer overflow vulnerabilities (CWE-787) in the User-ID Terminal Server Agent. A remote, unauthenticated threat actor could exploit the flaw by sending specially crafted network traffic to cause a denial-of-service condition or potentially execute arbitrary code. The issue affects only devices with at least one TSA entry configured, and the risk is highest when TSA connectivity is exposed to the internet or an untrusted network. Restricting TSA connectivity to trusted internal IP addresses in line with best-practice deployment guidelines reduces the severity to medium.

Zimbra Urges Customers to Patch Critical Classic Web Client XSS Flaw - On 8 July 2026, Zimbra released version 10.1.19 of Zimbra Collaboration Suite (ZCS) to patch a critical stored cross-site scripting (XSS) vulnerability affecting the Classic Web Client, also known as the Classic UI. The flaw impacts only deployments where the Ajax-based Classic Web Client is in use, and has not yet been assigned a CVE identifier. Zimbra has urged all affected customers to upgrade to ZCS 10.1.19 as soon as possible to remain secure. The vulnerability was reported by Google's Threat Analysis Group, which routinely identifies zero-day exploits used by state-sponsored actors against high-risk targets, though there is no confirmation of exploitation in the wild at the time of writing.

The vulnerability is a stored XSS flaw in the Classic Web Client, exploitable through specially crafted emails that execute malicious code when the message is opened by a victim. Successful exploitation could allow a threat actor to steal session data, account settings, or mailbox information. Only users of the Classic Web Client are affected, and no other Zimbra components are reported to be impacted. Zimbra security flaws have been a recurring target for Russian state-sponsored groups, including Winter Vivern, APT28, and APT29, making prompt patching particularly important for organisations exposed to the internet or handling sensitive communications.

Potential Threats

Adobe ColdFusion Flaw CVE-2026-48282 Now Exploited in Attacks - On 30 June 2026, Adobe patched CVE-2026-48282, a maximum-severity vulnerability affecting ColdFusion versions 2025.9, 2023.20, and earlier, warning of a high risk of exploitation and urging administrators to apply the update within 72 hours. According to vulnerability intelligence company KEVIntel, threat actors began exploiting the flaw within two hours of Adobe's public disclosure, and both the Canadian Centre for Cyber Security and open-source reporting have confirmed ongoing exploitation. Shadowserver is tracking nearly 800 ColdFusion instances exposed online, though it is unclear how many remain unpatched.

CVE-2026-48282 is a maximum-severity flaw that a remote, unauthenticated threat actor could exploit to achieve remote code execution on unpatched ColdFusion systems. It was among a set of maximum-severity ColdFusion and Campaign Classic flaws that Adobe patched, all of which were exploitable via low-complexity attacks requiring no user interaction. Administrators are strongly advised to update affected installations immediately, given confirmed in-the-wild exploitation

CISA Warns Admins to Patch Actively Exploited SharePoint Flaws - On 14th July 2026, CISA published an advisory warning that attackers are actively exploiting three vulnerabilities to compromise internet-exposed on-premises SharePoint Server instances. The flaws, tracked as CVE-2026-32201, CVE-2026-45659 and CVE-2026-56164, affect all supported self-hosted SharePoint Server versions, including the latest Subscription Edition. Attackers are chaining these vulnerabilities to bypass authentication and gain remote code execution, then conducting post-exploitation activity such as stealing Internet Information Services (IIS) machine keys and establishing persistence to deploy malware on compromised systems. CISA also flagged two further SharePoint flaws (CVE-2026-55040 and CVE-2026-58644) that Microsoft patched the same day as attractive targets, though these are not yet known to have been exploited in the wild.

Internet watchdog Shadowserver tracks nearly 10,000 internet-exposed SharePoint servers, with over 800 still unpatched against CVE-2026-32201 and CVE-2026-45659, though the number vulnerable to CVE-2026-56164 remains unclear. CISA urged security teams to closely monitor affected servers for signs of exploitation, apply Microsoft's latest patches, verify installation, shorten patching cycles, enable AMSI integration for SharePoint web applications, and use Microsoft Defender Antivirus detections to remediate compromise. Additional hardening measures include hunting for intrusion artefacts before rotating IIS machine keys, blocking external access to SharePoint Central Administration, restricting farm and database communication, and placing internet-facing servers behind a Layer 7 reverse proxy. All three actively exploited flaws have been added to CISA's Known Exploited Vulnerabilities Catalogue, with federal agencies given until 17th July to secure servers affected by CVE-2026-56164 under Binding Operational Directive 26-04.

LastPass Warns Users of Active Campaign Targeting Master Passwords - On 14th July 2026, CyberInsider reported that LastPass had warned customers of an active phishing campaign using lookalike domains and fake security notifications to trick users into revealing their master passwords or downloading malicious software. The phishing emails impersonate the password manager's security communications and are designed to create a sense of urgency by claiming users must review updated security policies, using the subject line "Action Required: Review Updated LastPass Security Policies". The attackers registered two domains closely resembling legitimate LastPass infrastructure, lastpassnewsletter[.]com and lastpasscompliance[.]com, neither of which is affiliated with the company. Emails originate from hello@lastpassnewsletter[.]com and instruct recipients to review revised policies via an embedded link.

The link leads to lastpasscompliance[.]com, which presents itself as a DocuSign-branded page that prompts visitors to download software, though LastPass says it is still investigating the nature of the downloaded file and will share further details once its analysis is complete. The company stressed that the activity has no impact on its own systems and is limited to an external phishing operation, adding that multiple security vendors have independently flagged the infrastructure as malicious and that it is working with industry partners to take the domains down. LastPass reiterated that it will never ask users for their master password, advised anyone who entered credentials on the fraudulent site to change their master password immediately from a trusted device by signing in directly through LastPass.com and reviewing their vault for unexpected activity, and encouraged suspicious emails to be forwarded to its abuse address. The campaign continues a pattern seen through 2026, following a March operation that used fake internal email threads redirecting to verify-lastpass[.]com and a January campaign that posed as vault backup and maintenance alerts routed through mail-lastpass[.]com.

General News

Microsoft Entra ID gets passkeys as default authentication from September - Microsoft has confirmed that passkeys will become the default authentication method for its Entra ID enterprise identity service from September 2026. Users currently relying on phone-based SMS and voice authentication will be automatically enabled for passkeys and prompted to register one at their next multifactor authentication, while those already using phishing-resistant methods such as Windows Hello for Business, FIDO2 security keys, or smart cards can continue with their existing setup. Microsoft-provided SMS and voice delivery will be retired across all tenants on 1 February 2027, after which organisations that still require phone-based authentication will need to configure third-party telecom providers through the Microsoft Security Store.

Administrators are being advised to identify affected users ahead of the deadline using a dedicated PowerShell scanner and to migrate everyone to phishing-resistant methods to avoid sign-in disruption. Microsoft framed the change as a direct response to the rising threat against Entra accounts, noting that AI-enabled phishing campaigns have reached click-through rates as high as 54% compared with roughly 12% for traditional campaigns. The company pointed to recent waves of SaaS data-theft attacks, including activity attributed to the ShinyHunters extortion group, as evidence that stolen passwords and phishable second factors now represent an urgent risk, arguing that making passkeys the default reduces reliance on credentials that attackers can readily steal.

Fake IT support calls on Microsoft Teams push EtherRAT malware - Threat actors are abusing Microsoft Teams voice calls to impersonate corporate IT support staff and trick employees into installing EtherRAT, granting attackers an initial foothold in corporate networks. According to Palo Alto Networks' Unit 42, the campaign begins with a phishing email featuring an "Employee Survey" lure and a malicious PDF attachment. Shortly after the document is opened, the victim receives a Teams call from an external account posing as a "System Administrator," which the researchers noted displayed the "External unfamiliar" label because the caller sat in a different Microsoft 365 tenant. Having convinced the target to grant remote control through the built-in screen-sharing feature, the attacker walks them through installing legitimate remote-access tools such as HopToDesk and AnyDesk.

Once remote access is established, a malicious MSI installer is downloaded and executed that acts as a loader, pulling down a legitimate Node.js runtime, decrypting embedded payloads, and finally launching EtherRAT. The cross-platform, Node.js-based trojan gives attackers full control over compromised systems, enabling them to run commands, manipulate files, steal data, and maintain persistence, while retrieving its command-and-control server via Ethereum smart contracts to resist takedown attempts. EtherRAT was previously deployed in state-sponsored attacks exploiting the React2Shell flaw and has since been picked up by numerous other actors. Unit 42 also found an open directory containing installer versions one through nine, suggesting active development. The activity continues a run of Teams-based intrusions that has pushed Microsoft to add protections including external-caller warnings and automatic lobby placement for suspected third-party bots.

EU and UK hit Russia with first joint cyber sanctions package - The European Union and the United Kingdom have jointly sanctioned dozens of Russian individuals and entities, accusing Moscow of coordinating a network of hacking groups behind attacks across Europe. The Council of the EU imposed measures on nine individuals and four entities, including GRU military intelligence officers and cybercriminals, while the UK separately designated 24 individuals and entities, among them senior GRU figures said to have directed cyber and hybrid operations. The EU list names the leader of the Trickbot and Conti gangs, the owner of the Media Land bulletproof hosting service, two members of the Cyber Army of Russia Reborn, two Lumma Stealer developers, and two members of GRU Unit 29155. The UK also sanctioned members of a company accused of recruiting hackers from Russian universities and ten people tied to a media outlet alleged to have spread anti-Ukraine narratives and interfered in elections in Moldova and Armenia.

The Council additionally identified the 16th Centre of Russia's FSB as controlling several threat groups, including the well-known Turla operation, which officials say has run cyberespionage campaigns against government and defence targets across at least nine European countries since 2010. The FSB hackers, tracked under names such as Static Tundra, Berserk Bear, Ghost Blizzard, and Dragonfly, were also linked to a failed strike on Poland's critical infrastructure. That late-December attack hit dozens of Polish power grid facilities and damaged operational technology equipment with the destructive DynoWiper wiper, and could have cut power to around 500,000 people during winter had it succeeded. The sanctions follow the European Commission's January proposal for new cybersecurity legislation and a March round of EU measures against Chinese and Iranian firms accused of coordinating attacks on member states' critical infrastructure.

Threat Actor Weekly Graph

Over the past 7 days, we have been tracking the following intent and opportunity changes within our Threat Actor Landscape.

Intent represents the potential targets of a group. When a group is observed attacking a different organisation or entity, their intent will increase.

Opportunity represents the various methods and technologies these groups may use. For example, if a group started using a new attack vector, such as a new kind of ransomware, their opportunity would increase.

Both intent and opportunity are scored out of 100 and are responsible for scoring the group's severity. These updates can be seen below.

 

Limited Severity Basic Severity Moderate Severity High Severity
Threat Actor Severity Increase Opportunity Intent
APT37 NEW High NEW 82 NEW 25
CL-CRI-1147 NEW Basic NEW 45 NEW 25
Citrix_one_love NEW Basic NEW 30 NEW 25
GordonFreeman NEW Basic
NEW 25 NEW 25
TAG-199 NEW  Basic NEW 25 NEW 25

Global Trends Powered by Recorded Future

Within each category, we have provided the current top five globally trending items. Each item is linked to how actively trending it is and is marked with a small symbol.

The spikes in references are calculated over 60 days and are normalised to ensure they aren't disproportionate when compared to bigger entities that will naturally have more baseline mentions.

- Spike – This indicates a large increase in reporting volume and a high diversity in the event descriptions.
- Rise – This indicates a small increase in reporting volume with little diversity in the descriptions.

Attackers Methods Vulnerabilities Targets
Federal Security Service(Russia) Arcus Media Ransomware CVE-2026-15409 Executor
CMD Organization Group Trial_recovery CVE-2026-15410 NICHIREI
Dragon Force Group Chaos Ransomware CVE-2026-56155 Kanyakumari District
Owen Flowers

Evilginx

CVE-2008-4128 Kanyakumari
Thalha Jubair WhisperGate CVE-2026-56164 Nuclear Power Corporation Of India Limited  

 

Prominent Information Security Events

Adobe ColdFusion Flaw CVE-2026-48282 Now Exploited in Attacks

Source: Insikt Group | Validated Intelligence Event

IOC: IP Address - 103[.]207[.]14[.]220

On 6 July 2026, BleepingComputer reported that attackers had begun exploiting a maximum-severity Adobe ColdFusion vulnerability, tracked as CVE-2026-48282, according to vulnerability intelligence firm KEVIntel. ColdFusion is a commercial web application development platform used to build and deploy enterprise-grade websites. The flaw affects ColdFusion versions 2025.9, 2023.20, and earlier, and can be exploited by attackers without privileges to gain remote code execution on unpatched systems. Adobe released security updates the previous day, warning that the vulnerability posed a high risk of exploitation and urging administrators to deploy patches within 72 hours. KEVIntel founder Ryan Dewhurst warned that threat actors began exploiting the flaw within two hours of Adobe's public disclosure, with in-the-wild activity captured across the firm's global honeypot network. The Canadian Centre for Cyber Security also urged defenders to secure their systems against the ongoing attacks and to apply the necessary updates.

Internet security watchdog Shadowserver was tracking nearly 800 Adobe ColdFusion instances exposed online at the time, though it was unclear how many were honeypots or had already been secured against the CVE-2026-48282 flaw. The activity followed Adobe's release the prior week of patches for six maximum-severity flaws in its ColdFusion and Campaign Classic platforms, all exploitable via low-complexity attacks requiring no user interaction and tagged as high risk of being targeted, though the company had not flagged any of those as actively exploited. In early April, Adobe had issued emergency updates to fix an Acrobat Reader vulnerability (CVE-2026-34621) that had been exploited in zero-day attacks since December 2025. Since November 2021, the US Cybersecurity and Infrastructure Security Agency has added 79 Adobe product vulnerabilities to its Known Exploited Vulnerabilities catalogue, 10 of which have also been abused in ransomware attacks.

LastPass Warns Users of Active Campaign Targeting Master Passwords 

Source: Insikt Group | Validated Intelligence Event

IOC: Hash: 8ae49ed3cb1e076fd12eb1f5489f1be0c9be4264731b3afd4175cf3284bc1b79

On 14 July 2026, CyberInsider reported that LastPass was warning customers about an active phishing campaign using lookalike domains and fake security notifications to trick users into revealing their master passwords or downloading malicious software. The company said the activity had no impact on its own systems and was limited to an external phishing operation. The attackers registered two domains closely resembling legitimate LastPass infrastructure, "lastpassnewsletter[.]com" and "lastpasscompliance[.]com," neither of which is affiliated with the company. The phishing emails originated from an address on the newsletter domain and used a subject line demanding that recipients review updated LastPass security policies, crafted to create a sense of urgency. Messages were designed to resemble official security notices and instructed recipients to review revised policies via an embedded link. That link led to the compliance domain, which presented itself as a DocuSign-branded page prompting visitors to download software, though LastPass said it was still investigating the nature of the downloaded file.

The phishing infrastructure had already been independently flagged as malicious by multiple security vendors, and LastPass said it was working with industry partners to remove the domains as quickly as possible. The company emphasised that it will never ask users for their master password, and advised recipients to avoid clicking links or downloading files. Anyone who entered their master password on the fraudulent site was told to change it immediately from a trusted device by signing in directly through the official LastPass website, then review their vault for unexpected activity, and to forward suspicious emails to LastPass's abuse address. The campaign continued a pattern of phishing attacks against LastPass users throughout 2026: in March, a campaign used fake internal email threads and a spoofed single sign-on page, while a January campaign urged users to "create a backup" of their vaults before a fabricated maintenance window, redirecting victims to fraudulent infrastructure to harvest master passwords. Because a single vault can unlock numerous accounts, LastPass remains a high-value target for such campaigns.

Remediation Actions

Following the information provided above, we recommend that the technologies mentioned be fully patched and updated. We also want to highlight and recommend applying the following patches where applicable:

  • CVE-2026-40138, CVE-2026-40139, CVE-2026-40140, and CVE-2026-40141 (Beyond Trust) - These vulnerabilities can be remediated with RS 25.3.3 & above and PRA 25.3.3 & above.

  • CVE-2026-0288 (Palo Alto) - This can be remediated by restricting your User-ID Terminal Server Agent connectivity to only trusted internal IP addresses according to Palo Alto best practices

If you are currently an Acumen Cyber Vulnerability Management customer, we will be proactively performing related searching and hunting activities within your environment.