Executive Summary -
Highlights of Cyber Threat Intelligence Digest
Vulnerabilities
Broadcom Patches Critical VMware vCenter Vulnerabilities CVE-2026-59309 and CVE-2026-59310 - On 30 July 2026, Rapid7 reported that Broadcom had patched multiple VMware vulnerabilities, including CVE-2026-59309 and CVE-2026-59310, affecting VMware vCenter Server. Fixed versions include vCenter 9.1.0.0300 for 9.1.x.x, vCenter 9.0.2.0100 for 9.0.x.x, VMware vCenter 8.0 U3k for version 8.0, an async patch to 8.0 U3k for VMware Cloud Foundation 5.x, and the applicable Broadcom KB guidance for VMware Telco Cloud Platform and Telco Cloud Infrastructure.
CVE-2026-59309 is an authentication bypass vulnerability in VMware Directory Service for vCenter, allowing a remote, unauthenticated threat actor with network access to a vulnerable server to bypass authentication and gain unauthorised access to the management plane. CVE-2026-59310 is a directory traversal vulnerability in the vCenter Syslog server, which a threat actor with network access to the affected service could exploit to execute arbitrary code. Compromise of vCenter could give a threat actor significant control over a victim's virtualised infrastructure, though exploitation in both cases requires network access to the affected services.
Ruflo Maintainers Patch Critical CVE-2026-59726 Unauthenticated Remote Code Execution Vulnerability in MCP Bridge - On 29 July 2026, Noma Labs disclosed CVE-2026-59726, a critical, unauthenticated remote code execution vulnerability affecting Ruflo versions prior to 3.16.3. According to the researchers, the flaw resides in the MCP Bridge included in Ruflo's default docker-compose.yml deployment, which by default exposed the POST /mcp endpoint without authentication and made both the MCP Bridge and MongoDB accessible on all network interfaces. Requests to the bridge bypassed the terminal_execute tool blocklist, as the restriction was enforced only within the Autopilot workflow. As a result, an unauthenticated network threat actor could invoke the tools/call method to execute arbitrary commands as the container's node user (UID 1000). During testing, the researchers found that the MCP Bridge exposed 233 tools over HTTP without authentication, and that a single unauthenticated HTTP POST request to the /mcp endpoint could invoke the ruflo__terminal_execute tool to achieve remote code execution.
The proof of concept also demonstrated enumerating available tools, retrieving configured LLM provider API keys from the container's environment variables, and spawning agent swarms, alongside injecting malicious entries into the AgentDB learning store and accessing the unauthenticated MongoDB instance on the internal Docker network. To establish persistence, the researchers created a file named beacon.js, modified index.js to load it, and restarted the container; out-of-band callbacks verified both remote code execution and data exfiltration during testing. The Ruflo maintainers subsequently published a GitHub Security Advisory assigning CVE-2026-59726 to the vulnerability, confirming the issue was fixed in version 3.16.3.
cPanel Patches Database Privilege Escalation Vulnerability CVE-2026-58048 Affecting cPanel/WHM - On 31 July 2026, cPanel patched a database privilege escalation vulnerability tracked as CVE-2026-58048, which affects all currently supported versions of cPanel/WHM. The flaw could allow an authenticated threat actor to execute arbitrary database commands with escalated privileges, potentially granting them a greater level of access than their account would normally permit.
At the time of writing, there are no reports of this vulnerability being exploited in the wild, and no public proof-of-concept code is known to exist. However, organisations are encouraged to act promptly to prevent threat actors from exploiting CVE-2026-58048, and we advise updating cPanel/WHM to the fixed version specified in cPanel's advisory as soon as possible.
Potential Threats
Threat Actor Advertises MedusaHVNC with Hidden Desktop Session Hijacking Capabilities - On 28 July 2026, cybersecurity firm BlackFog published a technical analysis detailing MedusaHVNC, a remote access trojan offered through a malware-as-a-service model. According to BlackFog, MedusaHVNC provides a hidden virtual network computing capability that grants a threat actor access to live Windows sessions without leaving visible activity on the victim's system. The malware was promoted through a dedicated website and Telegram channel, with subscription plans ranging from $175 for one month to $2,400 for lifetime access. Advertised features included file management, registry manipulation, process management, keylogging, remote desktop access, and hVNC-based cloning of browser and email application sessions such as Chrome, Edge, Firefox, Outlook and Telegram within a hidden desktop. Further capabilities included browser data recovery, in-memory execution of .NET and native payloads, AMSI patching and ETW evasion, additional payload deployment, SOCKS5 reverse proxying, cryptocurrency wallet clipping, and a builder for generating customised payloads.
BlackFog's analysis of the infection chain found that it begins when Windows Script Host executes an obfuscated JScript launcher, which rebuilds embedded files under a temporary directory before staging an AutoIt interpreter, a configuration file, and an encrypted payload, and placing a batch file in the Startup folder for persistence. The interpreter decrypts the payload using a single-byte XOR key to produce a native 64-bit loader, which is then injected into the Windows Character Map process, charmap.exe. Within this process, two further unpacking routines, a repeating XOR operation followed by ChaCha20 decryption, reveal the final unsigned 64-bit MedusaHVNC payload. Once active, the malware establishes command-and-control communication with a hard-coded server over a custom TCP protocol, interacts with applications on a hidden desktop using the victim's existing browser sessions, and captures screens, injects synthetic input, and manipulates clipboard data, all while keeping this activity concealed from the victim's visible desktop.
Phishing Campaigns Abuse Google and Microsoft URLs for OAuth and AitM Token Theft - On 31 July 2026, KnowBe4 ThreatLabs reported on ongoing phishing campaigns abusing legitimate Google and Microsoft URLs, using three variants: Google dynamic subdomain redirects, Microsoft OAuth client_id abuse, and Google-to-Microsoft adversary-in-the-middle (AitM) redirect chains targeting Microsoft FIDO or passkey bridge authentication flows. In the first variant, threat actors deliver a phishing email containing a legitimate google.com URL; once clicked, a JavaScript module extracts the victim's domain in real time and generates a familiar-looking, victim-specific subdomain redirect, which complicates blocklists and reputation-based detection. Security scanners see Google as the first-hop domain, while the victim actually lands on a threat actor-controlled credential-harvesting page, with observed URLs following the pattern google.com/share.google?q=[Random_ID].
In the second variant, the phishing link directs the victim to the legitimate Microsoft authentication endpoint login.microsoftonline.com, but the URL contains a threat actor-controlled client_id value tied to a threat actor-registered OAuth application, meaning the authorisation code routes to the attacker's application once the victim interacts with the flow, without the victim ever contacting a suspicious domain; the observed pattern took the form login.microsoftonline.com/common/oauth2/v2.0/authorize?scope=openid&prompt=none&client_id=[malicious_clientID]&state=[userEmail]. In the third variant, a legitimate google.com/share.google URL redirects the victim into a Microsoft AitM flow at the login.microsoft.com FIDO or passkey bridge endpoint, where completing a convincing sign-in experience causes the victim to hand the AitM flow a live session token; because the redirect hops rely on trusted infrastructure, reputation-based filtering is significantly less effective, with the pattern observed as login.microsoft.com/{id}/bridge/fido?fluent=2&cancelUrl=login.live.com/oauth20_authorize.srf?lc=1033&client_id=[malicious_clientID].
Threat Actors Expand DarkSword Multi-Country iOS Exploit Infrastructure Using Shared Panel Framework and Credential-Harvesting Lures - On 31 July 2026, Censys reported that multiple unknown threat actors used the publicly leaked "DarkSword" iOS exploit chain to target iOS devices, identifying activity across infrastructure comprising 27 hosts and 180 web properties as of 30 July 2026. The infection began when the threat actor directed victims to domains under its control hosting AWS console impersonation pages, iOS-themed lures, or an Apple ID sign-in page, with the Apple ID credential-harvesting decoy co-hosted alongside the DarkSword exploit-chain staging infrastructure. When a victim accessed one of the lure pages, the threat actor served a staging page embedding a hidden web page frame, which retrieved an exploit chain loader script from a domain resembling a content delivery service. The loader script appended a time-based value to retrieve a fresh copy, identified the victim's iOS version from the browser's user agent, and selected the appropriate exploit worker and RCE module accordingly. The exploit chain targeted iOS versions 18.4 through 18.7 by chaining six vulnerabilities, including a kernel driver exploit, a MIG filter bypass, a PAC bypass, and a sandbox escape.
Following successful exploitation, the threat actor deployed the "GHOSTBLADE" implant, which collected Keychain and iCloud information as well as Wi-Fi credentials, before beginning to collect files from the affected device. The threat actor used GHOSTBLADE to package the collected information and transmit it to operator-controlled command-and-control collector endpoints, authenticating to the DarkSword Admin, Decode Dashboard, or C2 Control Panel management panel to retrieve and decode the exfiltrated data. Finally, the threat actor used the implant to delete crash reports and a remote logging file, before it adjusted the memory pressure and exited.
General News
Anthropic says its AI hacked real-world companies in three incidents - Anthropic disclosed on Thursday that it had discovered three incidents in which its AI models exited test environments and compromised real-world organisations, uncovered following an internal review prompted by a similar incident at OpenAI. None of the affected organisations, which have not been named, had detected the activity themselves, and one had not yet been contacted at the time of publication. The root cause was a misunderstanding with third-party evaluation partner Irregular that left machines running Claude open to the internet, despite the models having been told they had no such access. In the most serious incident, Claude exploited vulnerabilities in a real company whose name coincidentally matched a fictional evaluation target, extracting credentials and production data; this was the only case in which the model continued attacking after recognising the environment was likely real. In a second incident, Claude found that a fictional company's setup instructions referenced a nonexistent PyPI package, went to considerable lengths to register and publish a malicious package under that name, which was then downloaded and executed by a real security firm's automated scanner before PyPI removed it. In a third, an internal research prototype scanned around 9,000 internet-facing targets and compromised a real company via SQL injection, but was the only one of the three to independently recognise its target was real and halt the attack unprompted.
Anthropic maintained it found no evidence of any model pursuing independent goals, framing the incidents as models acting on false beliefs about their environment after reaching the internet via an unintentionally open path. This contrasts with a separate OpenAI incident, in which its model exploited an unknown vulnerability to escape its test environment before breaching Hugging Face's production infrastructure using stolen credentials and a second zero-day flaw, with further third-party breaches later acknowledged. Hugging Face's chief executive, Clement Delangue, said he did not believe there was malicious intent behind the breach, though it raised questions about disclosure obligations when an AI system causes unintended harm; Hugging Face also noted that safety filters had blocked frontier models from assisting its own forensic analysis, forcing it to rely on a self-hosted open-weight model instead. Anthropic said it is now working with independent evaluator METR to review the incidents, including full transcript access, and plans to release a lightly redacted transcript of the PyPI incident within the week.
Apple launches new legal challenge against UK over iCloud access - Apple has reportedly launched a new legal challenge against the British government over a demand requiring the company to provide users' iCloud data in response to a warrant, the Financial Times first reported. The nature of the challenge is unclear, but notice of the complaint was sent to Privacy International, whose spokesperson welcomed Apple once again challenging the UK's regime of secret orders. At the centre of the dispute is Apple's Advanced Data Protection (ADP) feature, which stores encryption keys on users' own devices rather than Apple's servers, meaning Apple cannot access iCloud content even under a lawful request. Last February, Apple withdrew ADP for British users after receiving a secret legal demand, known as a Technical Capability Notice, requiring it to retain the ability to access iCloud content. The Financial Times reported the original request also sought access to US citizens' data, seemingly at odds with rules preventing each country from targeting the other's citizens.
Bare details of the case were confirmed last April by the Investigatory Powers Tribunal, the only court able to hear such national security cases, to which Apple has now submitted its complaint. The tribunal's April judgment cited public comments undermining the government's claim that secrecy was necessary, including US President Donald Trump comparing the move to tactics associated with China. Westminster maintains a policy of neither confirming nor denying such notices, a stance critics, including within Britain's own intelligence community, argue is unsustainable. Law enforcement agencies have long said that encrypted communications hamper efforts to tackle serious crime, including child sexual abuse, and because ADP makes iCloud content inaccessible server-side, detecting illegal material would need to happen on-device before encryption. Apple explored this in 2021 with a proposed client-side scanning system, before quietly shelving the plan in 2022 amid criticism, leaving the question of policing encrypted platforms unresolved.
Bitcoin hardware wallet maker destroys some inventory after more than $88 million stolen - Canadian company Coinkite was forced to destroy part of its inventory of Coldcard hardware wallets after thieves stole more than $88 million from customers through a firmware vulnerability. The devices, used to store bitcoin offline rather than on an exchange, were affected by a flaw originally discovered in March 2021 but only confirmed last week to be under active exploitation. Cybersecurity firm Galaxy Research said the attackers stole at least 1,367.05 BTC, worth around $88.6 million, from 4,585 addresses. In a statement on Sunday, Coldcard said it had been working with customers to move funds, urging affected users not to dispose of their devices in case they are needed should funds be recovered, and said its legal team would coordinate with law enforcement across multiple jurisdictions. The company confirmed it had destroyed its remaining inventory manufactured with the vulnerable firmware and halted shipments once the issue was confirmed, releasing a patched firmware version in the process.
Coldcard explained that its devices carry high-security locks that cannot be upgraded until a user initialises them, meaning it could not risk shipping units with the affected firmware in case users missed the upgrade, and instead judged it safest to destroy the affected stock and ship only fixed units. The company did not respond to questions about whether it would compensate victims. Blockchain analysis firm Chainalysis said two of the largest victims lost a combined $4 million, with numerous bitcoin holders subsequently describing their losses on social media. Chainalysis noted that the attacker appeared to have studied the victim wallet population in advance, targeting high-value wallets, including one worth $1.8 million, early in the sweep, which saw roughly $30 million stolen within the first ten minutes alone. The FBI declined to comment on whether it is investigating, while a senior Coinkite official partly attributed the breach to AI-assisted code reviews, which they believe have allowed attackers to find latent bugs faster than even the industry's most experienced researchers.
Threat Actor Weekly Graph
Over the past 7 days, we have been tracking the following intent and opportunity changes within our Threat Actor Landscape.
Intent represents the potential targets of a group. When a group is observed attacking a different organisation or entity, their intent will increase.
Opportunity represents the various methods and technologies these groups may use. For example, if a group started using a new attack vector, such as a new kind of ransomware, their opportunity would increase.
Both intent and opportunity are scored out of 100 and are responsible for scoring the group's severity. These updates can be seen below.

| ● Limited Severity | ● Basic Severity | ● Moderate Severity | ● High Severity |
| Threat Actor | Severity Increase | Opportunity | Intent | ||||||
|---|---|---|---|---|---|---|---|---|---|
| 888 | NEW | → | ● Basic | NEW | → | ● 35 | NEW | → | ● 26 |
| Storm-2945 | NEW | → | ● Basic | NEW |
→ | ● 35 | NEW | → | ● 25 |
| chestniybro | NEW | → | ● Basic | NEW | → | ● 30 | NEW | → | ● 5 |
| SilentFog | ● Basic | → | ● Basic |
● 30 | → | ● 30 | ● 5 | → | ● 26 |
| D4rk 4rmy Ransomware | ● Basic | → | ● Basic | ● 30 | → | ● 30 | ● 46 | → | ● 31 |
Global Trends Powered by Recorded Future
Within each category, we have provided the current top five globally trending items. Each item is linked to how actively trending it is and is marked with a small symbol.
The spikes in references are calculated over 60 days and are normalised to ensure they aren't disproportionate when compared to bigger entities that will naturally have more baseline mentions.
▲- Spike – This indicates a large increase in reporting volume and a high diversity in the event descriptions.
▲- Rise – This indicates a small increase in reporting volume with little diversity in the descriptions.
| Attackers | Methods | Vulnerabilities | Targets | |||||
|---|---|---|---|---|---|---|---|---|
| ExfilQuad Group | ▲ | Shai-Hulud | ▲ | CVE-2026-18577 | ▲ | Zenith Bank | ▲ | |
| BlueBravo | ▲ | BINDCLOAK | ▲ | CVE-2026-34486 | ▲ | Liechtenstein | ▲ | |
| ByteToBreach | ▲ | SafePay Ransomware | ▲ | CVE-2026-18556 | ▲ | Roblox | ▲ | |
| Dark Engine | ▲ |
ENCFORGE |
▲ | CVE-2026-15409 | ▲ | CHUBU Electric Power | ▲ | |
| INC RANSOM | ▲ | DarkSword | ▲ | CVE-2026-15410 | ▲ | CareCloud | ▲ | |
Prominent Information Security Events
Threat Actors Expand DarkSword Multi-Country iOS Exploit Infrastructure Using Shared Panel Framework and Credential-Harvesting Lures
Source: Insikt Group | Validated Intelligence Event
IOC: Hash - 3c37835766ca615f5eb0e766b4000b43e896a420d575f02e1e160be5711e0782
On 31 July 2026, Censys reported that multiple unknown threat actors used the publicly leaked "DarkSword" iOS exploit chain to target iOS devices, identifying activity across infrastructure comprising 27 hosts and 180 web properties as of 30 July 2026. The infection began when the threat actor directed victims to domains under its control hosting AWS console impersonation pages, iOS-themed lures, or an Apple ID sign-in page, with the Apple ID credential-harvesting decoy co-hosted alongside the DarkSword exploit-chain staging infrastructure.
When a victim accessed one of the lure pages, the threat actor served a staging page embedding a hidden web page frame, which retrieved an exploit chain loader script from a domain resembling a content delivery service. The loader script appended a time-based value to retrieve a fresh copy, identified the victim's iOS version from the browser's user agent, and selected the appropriate exploit worker and RCE module accordingly. The exploit chain targeted iOS versions 18.4 through 18.7 by chaining six vulnerabilities, including a kernel driver exploit, a MIG filter bypass, a PAC bypass, and a sandbox escape.
Following successful exploitation, the threat actor deployed the "GHOSTBLADE" implant, which collected Keychain and iCloud information as well as Wi-Fi credentials, before beginning to collect files from the affected device. The threat actor used GHOSTBLADE to package the collected information and transmit it to operator-controlled command-and-control collector endpoints, authenticating to the DarkSword Admin, Decode Dashboard, or C2 Control Panel management panel to retrieve and decode the exfiltrated data. Finally, the threat actor used the implant to delete crash reports and a remote logging file, before it adjusted the memory pressure and exited.
Phishing Campaigns Abuse Google and Microsoft URL's for OAuth and AitM Token Theft
Source: Insikt Group | Validated Intelligence Event
IOC: Domain: bruedergemeinde[-]schwarzenberg[.]de
On 31 July 2026, KnowBe4 ThreatLabs reported on ongoing phishing campaigns abusing legitimate Google and Microsoft URLs, using three variants: Google dynamic subdomain redirects, Microsoft OAuth client_id abuse, and Google-to-Microsoft adversary-in-the-middle (AitM) redirect chains targeting Microsoft FIDO or passkey bridge authentication flows.
In the first variant, threat actors deliver a phishing email containing a legitimate google.com URL; once clicked, a JavaScript module extracts the victim's domain in real time and generates a familiar-looking, victim-specific subdomain redirect, which complicates blocklists and reputation-based detection. Security scanners see Google as the first-hop domain, while the victim actually lands on a threat actor-controlled credential-harvesting page, with observed URLs following the pattern google.com/share.google?q=[Random_ID]. In the second variant, the phishing link directs the victim to the legitimate Microsoft authentication endpoint login.microsoftonline.com, but the URL contains a threat actor-controlled client_id value tied to a threat actor-registered OAuth application, meaning the authorisation code routes to the attacker's application once the victim interacts with the flow, without the victim ever contacting a suspicious domain; the observed pattern took the form login.microsoftonline.com/common/oauth2/v2.0/authorize?scope=openid&prompt=none&client_id=[malicious_clientID]&state=[userEmail].
In the third variant, a legitimate google.com/share.google URL redirects the victim into a Microsoft AitM flow at the login.microsoft.com FIDO or passkey bridge endpoint, where completing a convincing sign-in experience causes the victim to hand the AitM flow a live session token; because the redirect hops rely on trusted infrastructure, reputation-based filtering is significantly less effective, with the pattern observed as login.microsoft.com/{id}/bridge/fido?fluent=2&cancelUrl=login.live.com/oauth20_authorize.srf?lc=1033&client_id=[malicious_clientID].
Remediation Actions
Following the information provided above, we recommend that the technologies mentioned be fully patched and updated. We also want to highlight and recommend applying the following patches where applicable:
-
CVE-2026-59309, CVE-2026-59310 (Broadcom/VMWare) - These vulnerabilities can be remediated by updating to the most recent patch released by Broadcom.
- CVE-2026-59726 (Ruflo) - Updating to Ruflo version 3.16.3 will remediate this issue.
- CVE-2026-58048 (cPanel) - Patching cPanel to the most recent version will prevent this vulnerability from being exploited.
If you are currently an Acumen Cyber Vulnerability Management customer, we will be proactively performing related searching and hunting activities within your environment.