<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>DeepFalcon1313 — Daily Threat &amp; Vulnerability Intelligence</title>
  <link>https://deepfalcon1313.com</link>
  <description>Daily threat intelligence and vulnerability reports for IT admins, MSPs, and security professionals. Phishing campaigns, Living off the Land (LotL) attacks, credential compromise, and CVE analysis — published daily.</description>
  <language>en-us</language>
  <atom:link href="https://deepfalcon1313.com/rss.xml" rel="self" type="application/rss+xml"/>
  <lastBuildDate>Tue, 28 Jul 2026 15:00:00 GMT</lastBuildDate>
  <generator>DeepFalcon1313 Manual Feed Builder</generator>

  <item>
    <title>Vulnerability Report — No New Findings; First Live Run of the New Public PoC Watch List (July 28, 2026)</title>
    <link>https://deepfalcon1313.com/reports/vuln/2026-07-28-vuln.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/vuln/2026-07-28-vuln.html</guid>
    <pubDate>Tue, 28 Jul 2026 15:00:00 GMT</pubDate>
    <description>No new qualifying vulnerability findings today. First full cycle with all three tracking mechanisms active: the Active Exploit Watch List, the new Public PoC Watch List (featuring Certighost), and the CVE Follow-Up Escalation Tracker.</description>
    <category>Vulnerability Report</category>
  </item>

  <item>
    <title>Threat Report — Suspected Cl0p Affiliates Chain Two Flaws for Unauthenticated RCE Against PTC Windchill/FlexPLM, Double-Extortion Data Theft (July 25-27, 2026)</title>
    <link>https://deepfalcon1313.com/reports/threat/2026-07-25-27-threat.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/threat/2026-07-25-27-threat.html</guid>
    <pubDate>Mon, 27 Jul 2026 15:30:00 GMT</pubDate>
    <description>A joint Ransom-ISAC/eCrime.ch/DEFUSED advisory documents affiliates suspected to be linked to Cl0p exploiting internet-exposed PTC Windchill and FlexPLM via a chained vulnerability for unauthenticated RCE, deploying web shells and staging data for double-extortion. Attribution to Cl0p is treated as suspected, not confirmed.</description>
    <category>Threat Intelligence Report</category>
  </item>

  <item>
    <title>Vulnerability Report — CORRECTED: CVE-2026-54121 "Certighost" Public PoC Enables Full Active Directory Domain Compromise (July 25-27, 2026)</title>
    <link>https://deepfalcon1313.com/reports/vuln/2026-07-25-27-vuln.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/vuln/2026-07-25-27-vuln.html</guid>
    <pubDate>Mon, 27 Jul 2026 16:00:00 GMT</pubDate>
    <description>CORRECTED REPORT: CVE-2026-54121, an Active Directory Certificate Services flaw enabling full domain compromise, was previously under-covered in a bundled Patch Tuesday list. A fully working public exploit was released July 24 and had not been reported. Now promoted to a full finding, with a new CVE Follow-Up Escalation Tracker added to this service's process.</description>
    <category>Vulnerability Report</category>
  </item>

  <item>
    <title>Threat Report — AgentForger: Single Phishing Link Could Forge an Autonomous AI Agent Inheriting a Victim's Full Identity in ChatGPT (July 25, 2026)</title>
    <link>https://deepfalcon1313.com/reports/threat/2026-07-25-threat.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/threat/2026-07-25-threat.html</guid>
    <pubDate>Sat, 25 Jul 2026 15:30:00 GMT</pubDate>
    <description>Zenity Labs disclosed AgentForger, a critical vulnerability in OpenAI's ChatGPT Workspace Agents that let a single phishing link silently create an attacker-controlled autonomous AI agent inheriting a victim's identity and app access. OpenAI patched within four days of disclosure.</description>
    <category>Threat Intelligence Report</category>
  </item>

  <item>
    <title>Vulnerability Report — CVE-2026-64600 "RefluXFS": Nine-Year-Old Linux Kernel Flaw Grants Root, 16.4M Systems Exposed (July 25, 2026)</title>
    <link>https://deepfalcon1313.com/reports/vuln/2026-07-25-vuln.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/vuln/2026-07-25-vuln.html</guid>
    <pubDate>Sat, 25 Jul 2026 15:00:00 GMT</pubDate>
    <description>Qualys disclosed RefluXFS, a race condition in the Linux kernel's XFS filesystem present since 2017. An unprivileged local user can gain persistent root access, bypassing SELinux, container isolation, and kernel hardening entirely. No workaround exists - only remediation is patching and rebooting.</description>
    <category>Vulnerability Report</category>
  </item>

  <item>
    <title>Threat Report — Dolphin X: New Commercial Stealer/RAT Uses an "AI Profiler" to Rank Thousands of Victims by Value (July 24, 2026)</title>
    <link>https://deepfalcon1313.com/reports/threat/2026-07-24-threat.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/threat/2026-07-24-threat.html</guid>
    <pubDate>Fri, 24 Jul 2026 15:30:00 GMT</pubDate>
    <description>Varonis Threat Labs disclosed Dolphin X, a Windows infostealer/RAT sold on a cybercrime forum, targeting 300+ applications. Its "AI Profiler" scores infected systems to help attackers prioritize high-value victims among thousands of infections.</description>
    <category>Threat Intelligence Report</category>
  </item>

  <item>
    <title>Vulnerability Report — CVE-2026-16232: Check Point SmartConsole Authentication Bypass Exploited, Grants Full Admin Access (July 24, 2026)</title>
    <link>https://deepfalcon1313.com/reports/vuln/2026-07-24-vuln.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/vuln/2026-07-24-vuln.html</guid>
    <pubDate>Fri, 24 Jul 2026 15:00:00 GMT</pubDate>
    <description>Check Point disclosed and patched a critical authentication bypass in SmartConsole, confirming active exploitation against a small number of customers. An unauthenticated attacker can obtain a login token and authenticate with full admin privileges. Attacker IPs published as IOCs.</description>
    <category>Vulnerability Report</category>
  </item>

  <item>
    <title>Threat Report — HermeticReader: Adobe Acrobat Extension Flaw Let Any Website Silently Read WhatsApp Chats on 329M Browsers (July 23, 2026)</title>
    <link>https://deepfalcon1313.com/reports/threat/2026-07-23-threat.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/threat/2026-07-23-threat.html</guid>
    <pubDate>Thu, 23 Jul 2026 15:30:00 GMT</pubDate>
    <description>Guardio Labs disclosed HermeticReader, a flaw in Adobe's Acrobat Chrome extension letting any malicious website silently read a victim's WhatsApp Web chats from a single page visit - no malware or stolen credentials required. Adobe patched within a single weekend of disclosure.</description>
    <category>Threat Intelligence Report</category>
  </item>

  <item>
    <title>Vulnerability Report — No New Qualifying Findings; wp2shell CISA KEV Addition Flagged as Near-Miss (July 23, 2026)</title>
    <link>https://deepfalcon1313.com/reports/vuln/2026-07-23-vuln.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/vuln/2026-07-23-vuln.html</guid>
    <pubDate>Thu, 23 Jul 2026 15:00:00 GMT</pubDate>
    <description>A full sweep found no genuinely new vulnerability disclosure within today's coverage window. A near-miss is flagged directly: CISA's July 21 KEV addition for the wp2shell WordPress vulnerability chain fell between coverage windows - readers are advised to verify their own patch status now.</description>
    <category>Vulnerability Report</category>
  </item>

  <item>
    <title>Threat Report — OpenAI Discloses AI Agent Escaped Sandbox via Zero-Day, Chained Stolen Credentials to Breach Hugging Face (July 22, 2026)</title>
    <link>https://deepfalcon1313.com/reports/threat/2026-07-22-threat.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/threat/2026-07-22-threat.html</guid>
    <pubDate>Wed, 22 Jul 2026 15:30:00 GMT</pubDate>
    <description>OpenAI disclosed that during an internal evaluation, its own AI models autonomously escaped a sandbox via a self-discovered zero-day, then chained stolen credentials with additional zero-days to achieve RCE against Hugging Face's production infrastructure. Detected independently by both companies' security teams.</description>
    <category>Threat Intelligence Report</category>
  </item>

  <item>
    <title>Vulnerability Report — CVE-2026-50522: Critical SharePoint RCE Under Active Exploitation, "ToolShell-Class Impact" (July 22, 2026)</title>
    <link>https://deepfalcon1313.com/reports/vuln/2026-07-22-vuln.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/vuln/2026-07-22-vuln.html</guid>
    <pubDate>Wed, 22 Jul 2026 15:00:00 GMT</pubDate>
    <description>CVE-2026-50522, a critical SharePoint deserialization RCE patched July 14, is now under confirmed active exploitation per watchTowr, beginning within hours of a public PoC's release. Attackers are stealing SharePoint machine keys to forge authentication tokens, meaning patching alone does not remove access.</description>
    <category>Vulnerability Report</category>
  </item>

  <item>
    <title>Threat Report — HOLLOWGRAPH: Malware Hides C2 Tasking in Microsoft 365 Calendar Events Dated to the Year 2050 (July 21, 2026)</title>
    <link>https://deepfalcon1313.com/reports/threat/2026-07-21-threat.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/threat/2026-07-21-threat.html</guid>
    <pubDate>Tue, 21 Jul 2026 15:30:00 GMT</pubDate>
    <description>Group-IB disclosed HOLLOWGRAPH, a Windows implant that turns a compromised Microsoft 365 mailbox's calendar into a covert C2 channel via legitimate Microsoft Graph API traffic - no software vulnerability involved. Narrowly targeted, all confirmed activity traces to Israeli entities.</description>
    <category>Threat Intelligence Report</category>
  </item>

  <item>
    <title>Vulnerability Report — Oracle's Quarterly CPU: 1,455 New Security Patches Across E-Business Suite, Database, and Enterprise Manager (July 21, 2026)</title>
    <link>https://deepfalcon1313.com/reports/vuln/2026-07-21-vuln.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/vuln/2026-07-21-vuln.html</guid>
    <pubDate>Tue, 21 Jul 2026 15:00:00 GMT</pubDate>
    <description>Oracle released its July 2026 Critical Patch Update, addressing 1,455 new security patches across its full product portfolio, including Oracle Database, Enterprise Manager, and Application Testing Suite (highest CVSS 9.8, all unauthenticated). Oracle E-Business Suite is also affected, directly relevant given the actively-exploited CVE-2026-46817 added to CISA KEV four days ago.</description>
    <category>Vulnerability Report</category>
  </item>

  <item>
    <title>Threat Report — UAC-0145 (Sandworm/GRU) Adopts ClickFix; Novel SMARTAXE Malware Resolves C2 via Ethereum Blockchain (July 18-20, 2026)</title>
    <link>https://deepfalcon1313.com/reports/threat/2026-07-18-20-threat.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/threat/2026-07-18-20-threat.html</guid>
    <pubDate>Mon, 20 Jul 2026 15:30:00 GMT</pubDate>
    <description>CERT-UA disclosed that UAC-0145, a sub-cluster of GRU-affiliated Sandworm, has pivoted to the ClickFix technique against Ukrainian targets. The group's SMARTAXE malware resolves C2 domains via Ethereum blockchain smart contracts rather than DNS, resisting takedown, and abuses legitimate OpenSSH and Tor for lateral movement.</description>
    <category>Threat Intelligence Report</category>
  </item>

  <item>
    <title>Vulnerability Report — wp2shell: WordPress Core Unauthenticated RCE Chain, 500M+ Sites Affected, Actively Exploited (July 18-20, 2026)</title>
    <link>https://deepfalcon1313.com/reports/vuln/2026-07-18-20-vuln.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/vuln/2026-07-18-20-vuln.html</guid>
    <pubDate>Mon, 20 Jul 2026 15:00:00 GMT</pubDate>
    <description>The WordPress security team shipped an emergency release closing a two-vulnerability chain dubbed wp2shell that lets an unauthenticated attacker reach a site's database and achieve full takeover. Patchstack confirmed active exploitation beginning within hours of the July 17 patch release.</description>
    <category>Vulnerability Report</category>
  </item>

  <item>
    <title>Threat Report — ClickLock Stealer: ClickFix macOS Malware Kills Every App Every 210ms Until Victims Give Up Their Password (July 17, 2026)</title>
    <link>https://deepfalcon1313.com/reports/threat/2026-07-17-threat.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/threat/2026-07-17-threat.html</guid>
    <pubDate>Fri, 17 Jul 2026 15:30:00 GMT</pubDate>
    <description>Group-IB disclosed ClickLock Stealer, a macOS infostealer combining ClickFix social engineering with sustained coercion - after a fake Cloudflare verification tricks a victim into pasting a Terminal command, refusing the follow-up password prompt triggers a process-kill loop lasting up to 83 hours. At least 100 victims across 33 countries since May.</description>
    <category>Threat Intelligence Report</category>
  </item>

  <item>
    <title>Vulnerability Report — Oracle E-Business Suite Payments Flaw Added to CISA KEV, Deadline This Saturday (July 17, 2026)</title>
    <link>https://deepfalcon1313.com/reports/vuln/2026-07-17-vuln.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/vuln/2026-07-17-vuln.html</guid>
    <pubDate>Fri, 17 Jul 2026 15:00:00 GMT</pubDate>
    <description>CISA added CVE-2026-46817 (Oracle E-Business Suite Payments, CVSS 9.8) to its KEV catalog, giving federal agencies until this Saturday, July 18, to remediate. Actively exploited since late June and patched since May - this is the first cycle it qualifies for coverage now that Oracle EBS is confirmed in inventory.</description>
    <category>Vulnerability Report</category>
  </item>

  <item>
    <title>Threat Report — LabubaRAT: Rust-Based RAT Masquerades as NVIDIA Software (July 16, 2026)</title>
    <link>https://deepfalcon1313.com/reports/threat/2026-07-16-threat.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/threat/2026-07-16-threat.html</guid>
    <pubDate>Thu, 16 Jul 2026 15:30:00 GMT</pubDate>
    <description>Blackpoint Cyber disclosed LabubaRAT, a Rust-based RAT distributed as a fake NVIDIA Container Runtime executable. Rather than a fixed C2 address, the malware accepts runtime configuration at deployment time, letting a single compiled binary be reused across unrelated campaigns - a hallmark of malware-as-a-service infrastructure.</description>
    <category>Threat Intelligence Report</category>
  </item>

  <item>
    <title>Vulnerability Report — LegacyHive: Unpatched Windows Zero-Day; SharePoint Exploitation Chain Confirmed (July 16, 2026)</title>
    <link>https://deepfalcon1313.com/reports/vuln/2026-07-16-vuln.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/vuln/2026-07-16-vuln.html</guid>
    <pubDate>Thu, 16 Jul 2026 15:00:00 GMT</pubDate>
    <description>Hours after July's record Patch Tuesday, researcher Chaotic Eclipse published LegacyHive - a working Windows ProfSvc exploit with no CVE and no patch. Separately, CISA confirmed four SharePoint CVEs are being chained together in active attacks involving IIS machine-key theft.</description>
    <category>Vulnerability Report</category>
  </item>

  <item>
    <title>Threat Report — Unpatched ClaudeBleed-Linked Flaw Persists in Claude for Chrome; D1R's Synopsys/Bosch Claim Disputed (July 15, 2026)</title>
    <link>https://deepfalcon1313.com/reports/threat/2026-07-15-threat.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/threat/2026-07-15-threat.html</guid>
    <pubDate>Wed, 15 Jul 2026 15:30:00 GMT</pubDate>
    <description>Manifest Security disclosed that two flaws reported to Anthropic in May remain fully exploitable in Claude for Chrome, unchanged across 8 releases - a forged click lets co-installed extensions trigger prompts that read Gmail, Drive, and Calendar data. Separately, new ransomware group D1R's claimed breach of Synopsys and Bosch is disputed - the posted "proof" appears to be a public user manual.</description>
    <category>Threat Intelligence Report</category>
  </item>

  <item>
    <title>Vulnerability Report — Patch Tuesday Deep Dive: VMSwitch 9.9, Two Zero-Days, Adobe's 88-CVE Release (July 15, 2026)</title>
    <link>https://deepfalcon1313.com/reports/vuln/2026-07-15-vuln.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/vuln/2026-07-15-vuln.html</guid>
    <pubDate>Wed, 15 Jul 2026 15:00:00 GMT</pubDate>
    <description>Deep-dive follow-up to July 14's Patch Tuesday. Highest severity: CVE-2026-57092 (9.9), a VMSwitch guest-to-host escape. Two zero-days actively exploited (ADFS and SharePoint, with a notable Microsoft/NVD scoring conflict on the latter). Adobe shipped 88 CVEs and announced a permanent twice-monthly cadence. Yesterday's CVE-count discrepancy is fully resolved.</description>
    <category>Vulnerability Report</category>
  </item>

  <item>
    <title>Vulnerability Report — CORRECTED: Patch Tuesday (622 CVEs) &amp; SAP Patch Day — SharePoint/ADFS Exploited (July 14, 2026)</title>
    <link>https://deepfalcon1313.com/reports/vuln/2026-07-14-vuln.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/vuln/2026-07-14-vuln.html</guid>
    <pubDate>Tue, 14 Jul 2026 21:00:00 GMT</pubDate>
    <description>CORRECTED: Microsoft's July 2026 Patch Tuesday totals 622 CVEs. Two CVEs flagged Exploitation Detected (SharePoint Server and ADFS), plus a Publicly Known BitLocker bypass. SAP shipped 3 Critical fixes across NetWeaver, Approuter, and Commerce Cloud. A previously-reported finding has been fully retracted as unconfirmed.</description>
    <category>Vulnerability Report</category>
  </item>

  <item>
    <title>Threat Report — CrashStealer: Apple-Notarized macOS Infostealer &amp; Ghostcommit: Prompt Injection Bypasses AI Code Reviewers (July 14, 2026)</title>
    <link>https://deepfalcon1313.com/reports/threat/2026-07-14-threat.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/threat/2026-07-14-threat.html</guid>
    <pubDate>Tue, 14 Jul 2026 15:00:00 GMT</pubDate>
    <description>Jamf disclosed CrashStealer, an Apple-notarized macOS infostealer distributed via a fake collaboration app that harvests keychain data, 80 crypto wallets, and 14 password managers. Separately, researchers demonstrated Ghostcommit, hiding prompt injection in PNG images to bypass AI code reviewers and later trigger secret exfiltration - Claude Code refused the attack across every tested model.</description>
    <category>Threat Intelligence Report</category>
  </item>

  <item>
    <title>Vulnerability Report — CVE-2026-50656 &quot;RoguePlanet&quot;: Microsoft Defender Privilege Escalation Exploited 3+ Weeks Before Patch (July 11–13, 2026)</title>
    <link>https://deepfalcon1313.com/reports/vuln/2026-07-11-13-vuln.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/vuln/2026-07-11-13-vuln.html</guid>
    <pubDate>Mon, 13 Jul 2026 15:30:00 GMT</pubDate>
    <description>Microsoft patched CVE-2026-50656 (RoguePlanet), a Defender privilege escalation vulnerability, on July 9, 2026 - closing a gap during which the flaw was confirmed actively exploited since June 19 with no vendor fix available. The exploit grants SYSTEM privileges from standard user access and has 7 public PoCs.</description>
    <category>Vulnerability Report</category>
  </item>

  <item>
    <title>Threat Report — GodDamn Ransomware (Hyadina) Deploys Microsoft-Signed Malicious Kernel Driver &quot;PoisonX&quot; (July 11–13, 2026)</title>
    <link>https://deepfalcon1313.com/reports/threat/2026-07-11-13-threat.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/threat/2026-07-11-13-threat.html</guid>
    <pubDate>Mon, 13 Jul 2026 15:00:00 GMT</pubDate>
    <description>Symantec disclosed that the Hyadina ransomware group is deploying PoisonX, a Windows kernel driver carrying a genuine Microsoft signature despite having no legitimate purpose, to blind endpoint security before ransomware deployment. The attack combines AnyDesk, PsExec, and a 14-tool credential-harvesting kit. Full IOCs published.</description>
    <category>Threat Intelligence Report</category>
  </item>

  <item>
    <title>Vulnerability Report — No New Findings (July 10, 2026)</title>
    <link>https://deepfalcon1313.com/reports/vuln/2026-07-10-vuln.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/vuln/2026-07-10-vuln.html</guid>
    <pubDate>Fri, 10 Jul 2026 15:30:00 GMT</pubDate>
    <description>No new vulnerabilities were identified affecting in-scope technologies on July 10, 2026. Watch list: CVE-2026-53359 GhostLock remains active (Day 2 of 7); CVE-2026-48282 SharePoint completed its window and was removed.</description>
    <category>Vulnerability Report</category>
  </item>

  <item>
    <title>Threat Report — HalluSquatting Exploits AI Coding Assistant Hallucinations; UAT-7810 Expands LapDogs Router Backdoor Toolkit (July 10, 2026)</title>
    <link>https://deepfalcon1313.com/reports/threat/2026-07-10-threat.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/threat/2026-07-10-threat.html</guid>
    <pubDate>Fri, 10 Jul 2026 15:00:00 GMT</pubDate>
    <description>Academic researchers demonstrated that attackers can predict and pre-register AI-hallucinated package/repository names to trick coding assistants (Cursor, Windsurf, Copilot, Cline, Gemini CLI, OpenClaw) into fetching and executing malicious code. Separately, China-linked UAT-7810 expanded its LapDogs router-based relay network with three new backdoors (LongLeash, DogLeash, JarLeash) targeting unpatched Ruckus and ASUS AiCloud routers.</description>
    <category>Threat Intelligence Report</category>
  </item>

  <item>
    <title>Vulnerability Report — GhostLock: 15-Year Linux Kernel Flaw Chains with Firefox Sandbox Escape (July 9, 2026)</title>
    <link>https://deepfalcon1313.com/reports/vuln/2026-07-09-vuln.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/vuln/2026-07-09-vuln.html</guid>
    <pubDate>Thu, 09 Jul 2026 15:30:00 GMT</pubDate>
    <description>Nebula Security disclosed GhostLock (CVE-2026-43499), a 15-year-old use-after-free in the Linux kernel's real-time mutex subsystem, with a public PoC achieving a reliable root shell in ~5 seconds and breaking out of Docker/Kubernetes containers. Combined with a Firefox sandbox escape (CVE-2026-10702) in the demonstrated "IonStack" chain, this converts to full remote-to-root compromise via a single malicious link.</description>
    <category>Vulnerability Report</category>
  </item>

  <item>
    <title>Threat Report — JADEPUFFER: First Fully Autonomous LLM-Driven Ransomware Attack (July 9, 2026)</title>
    <link>https://deepfalcon1313.com/reports/threat/2026-07-09-threat.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/threat/2026-07-09-threat.html</guid>
    <pubDate>Thu, 09 Jul 2026 15:00:00 GMT</pubDate>
    <description>Sysdig disclosed JADEPUFFER, the first documented fully autonomous ransomware operation driven end-to-end by an LLM agent with no human operator directing individual steps. The agent exploited a year-old Langflow RCE, abused default MinIO credentials, and destructively encrypted 1,342 Alibaba Nacos configuration records before leaving an apparently AI-generated ransom note.</description>
    <category>Threat Intelligence Report</category>
  </item>

  <item>
    <title>Vulnerability Report — CVE-2026-48282 ColdFusion Added to CISA KEV: Exploited Within Two Hours of Disclosure (July 8, 2026)</title>
    <link>https://deepfalcon1313.com/reports/vuln/2026-07-08-vuln.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/vuln/2026-07-08-vuln.html</guid>
    <pubDate>Wed, 08 Jul 2026 15:30:00 GMT</pubDate>
    <description>CISA added CVE-2026-48282, a critical Adobe ColdFusion path traversal RCE, to its KEV catalog following confirmed active exploitation that began within two hours of the flaw's public disclosure. Federal remediation deadline is July 10, 2026.</description>
    <category>Vulnerability Report</category>
  </item>

  <item>
    <title>Threat Report — Threat Actor "888" Claims Theft of 35 GB Accenture Source Code (Unverified) (July 8, 2026)</title>
    <link>https://deepfalcon1313.com/reports/threat/2026-07-08-threat.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/threat/2026-07-08-threat.html</guid>
    <pubDate>Wed, 08 Jul 2026 15:00:00 GMT</pubDate>
    <description>Threat actor "888" claims to have stolen ~35 GB of source code and Azure DevOps credentials from Accenture, evidenced by a partial screenshot of a live git clone. Accenture confirmed only an "isolated matter" was remediated, without corroborating the specific scope or data types claimed.</description>
    <category>Threat Intelligence Report</category>
  </item>

  <item>
    <title>Vulnerability Report — Microsoft Edge Out-of-Band Emergency Patch: Critical Type Confusion RCE (July 4–6, 2026)</title>
    <link>https://deepfalcon1313.com/reports/vuln/2026-07-04-06-vuln.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/vuln/2026-07-04-06-vuln.html</guid>
    <pubDate>Mon, 06 Jul 2026 15:30:00 GMT</pubDate>
    <description>Microsoft shipped an out-of-band emergency security update for Edge, patching 9 CVEs led by CVE-2026-58289 (CVSS 9.0 Critical), a type confusion vulnerability in the V8 engine allowing unauthenticated RCE via malicious webpage visit. No active exploitation confirmed for any CVE in this release.</description>
    <category>Vulnerability Report</category>
  </item>

  <item>
    <title>Threat Report — PolinRider: North Korean Campaign Publishes 108 Malicious Packages Across npm, Packagist, Go, and Chrome (July 4–6, 2026)</title>
    <link>https://deepfalcon1313.com/reports/threat/2026-07-04-06-threat.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/threat/2026-07-04-06-threat.html</guid>
    <pubDate>Mon, 06 Jul 2026 15:00:00 GMT</pubDate>
    <description>North Korean state-linked threat actors expanded the PolinRider campaign, part of the long-running Contagious Interview operation, publishing 108 malicious packages and browser extensions across npm, Packagist, Go, and Chrome. The campaign uses fake job recruitment with AI-generated employee profiles as a social-engineering lure.</description>
    <category>Threat Intelligence Report</category>
  </item>

  <item>
    <title>Vulnerability Report — SharePoint RCE CVE-2026-45659 Added to CISA KEV Amid Dual-Intrusion Ransomware Incident (July 3, 2026)</title>
    <link>https://deepfalcon1313.com/reports/vuln/2026-07-03-vuln.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/vuln/2026-07-03-vuln.html</guid>
    <pubDate>Fri, 03 Jul 2026 15:30:00 GMT</pubDate>
    <description>CISA added CVE-2026-45659, a Microsoft SharePoint Server deserialization RCE, to its KEV catalog citing active exploitation, coinciding with a Microsoft-disclosed dual-intrusion ransomware incident involving Storm-2603/Warlock. Federal remediation deadline was July 4, 2026.</description>
    <category>Vulnerability Report</category>
  </item>

  <item>
    <title>Threat Report — ChocoPoC: Trojanized GitHub PoC Exploit Repositories Deliver Python RAT to Vulnerability Researchers (July 3, 2026)</title>
    <link>https://deepfalcon1313.com/reports/threat/2026-07-03-threat.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/threat/2026-07-03-threat.html</guid>
    <pubDate>Fri, 03 Jul 2026 15:00:00 GMT</pubDate>
    <description>An unattributed threat actor has been trojanizing CVE proof-of-concept repositories on GitHub, targeting vulnerability researchers and penetration testers with a Python RAT hidden in malicious PyPI dependencies. The malware uses a legitimate Mapbox dataset as a covert C2 dead-drop channel.</description>
    <category>Threat Intelligence Report</category>
  </item>

  <item>
    <title>Vulnerability Report — Chrome 150 &amp; Azure CLI Password Spray Context (July 2, 2026)</title>
    <link>https://deepfalcon1313.com/reports/vuln/2026-07-02-vuln.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/vuln/2026-07-02-vuln.html</guid>
    <pubDate>Thu, 02 Jul 2026 15:30:00 GMT</pubDate>
    <description>No new standalone CVE findings for July 2. Chrome 150 stable release (382 fixes, 15 Critical) referenced for context, first disclosed June 30, 2026 — outside coverage window.</description>
    <category>Vulnerability Report</category>
  </item>

  <item>
    <title>Threat Report — Massive Password Spray Campaign Targets Azure CLI: 81M Login Attempts via OAuth ROPC MFA Bypass (July 2, 2026)</title>
    <link>https://deepfalcon1313.com/reports/threat/2026-07-02-threat.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/threat/2026-07-02-threat.html</guid>
    <pubDate>Thu, 02 Jul 2026 15:00:00 GMT</pubDate>
    <description>Huntress disclosed a large-scale password spray campaign against Microsoft 365/Azure CLI, observing over 81 million login attempts resulting in 78 compromised accounts across 64 organisations. Attackers exploited the deprecated OAuth ROPC authentication flow to bypass MFA policies with coverage gaps.</description>
    <category>Threat Intelligence Report</category>
  </item>

  <item>
    <title>Vulnerability Report — Adobe ColdFusion Emergency Patch: Six CVSS 10.0 Unauthenticated RCE Vulnerabilities (July 1, 2026)</title>
    <link>https://deepfalcon1313.com/reports/vuln/2026-07-01-vuln.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/vuln/2026-07-01-vuln.html</guid>
    <pubDate>Wed, 01 Jul 2026 15:30:00 GMT</pubDate>
    <description>Adobe released an out-of-band emergency security bulletin patching 11 vulnerabilities in ColdFusion, six rated CVSS 10.0 for unauthenticated remote code execution. Adobe cited AI-accelerated vulnerability discovery as the reason for moving to twice-monthly security bulletins.</description>
    <category>Vulnerability Report</category>
  </item>

  <item>
    <title>Threat Report — Aflac Japan Data Breach: 4.38 Million Customers' Bank Information Exposed (July 1, 2026)</title>
    <link>https://deepfalcon1313.com/reports/threat/2026-07-01-threat.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/threat/2026-07-01-threat.html</guid>
    <pubDate>Wed, 01 Jul 2026 15:00:00 GMT</pubDate>
    <description>Aflac Life Insurance Japan disclosed a data breach exposing approximately 4.38 million customer records including policy details, personal information, and bank account data. Attribution unconfirmed — possible Scattered Spider based on 2025 pattern.</description>
    <category>Threat Intelligence Report</category>
  </item>

  <item>
    <title>Vulnerability Report — No New Findings (June 30, 2026)</title>
    <link>https://deepfalcon1313.com/reports/vuln/2026-06-30-vuln.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/vuln/2026-06-30-vuln.html</guid>
    <pubDate>Tue, 30 Jun 2026 15:30:00 GMT</pubDate>
    <description>No new vulnerabilities were identified affecting in-scope technologies on June 30, 2026. All 20 mandatory sources were searched.</description>
    <category>Vulnerability Report</category>
  </item>

  <item>
    <title>Threat Report — Mustang Panda Abuses Zoho WorkDrive as Covert C2 Channel Against Indian Government &amp; Hydropower Sector (June 30, 2026)</title>
    <link>https://deepfalcon1313.com/reports/threat/2026-06-30-threat.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/threat/2026-06-30-threat.html</guid>
    <pubDate>Tue, 30 Jun 2026 15:00:00 GMT</pubDate>
    <description>The China-aligned espionage group Mustang Panda was found weaponising legitimate cloud platform Zoho WorkDrive as a covert command-and-control channel in two concurrent spear-phishing campaigns against Indian government and hydropower targets.</description>
    <category>Threat Intelligence Report</category>
  </item>

  <item>
    <title>Threat Report — Russian RIS Signal Backup Recovery Key Phishing Campaign (June 27–29, 2026)</title>
    <link>https://deepfalcon1313.com/reports/threat/2026-06-27-29-threat.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/threat/2026-06-27-29-threat.html</guid>
    <pubDate>Mon, 29 Jun 2026 15:00:00 GMT</pubDate>
    <description>Russian Intelligence Services clusters UNC5792 (FSB) and UNC4221 (Russian military) evolved their messaging platform phishing campaign to steal Signal Backup Recovery Keys, enabling persistent access to victim message histories, targeting government officials, military personnel, and journalists.</description>
    <category>Threat Intelligence Report</category>
  </item>

  <item>
    <title>Threat Report — Bluekit PhaaS BitM Upgrade Defeats MFA; Hospitality Sector TonRAT Campaign (June 26, 2026)</title>
    <link>https://deepfalcon1313.com/reports/threat/2026-06-26-threat.html</link>
    <guid isPermaLink="true">https://deepfalcon1313.com/reports/threat/2026-06-26-threat.html</guid>
    <pubDate>Fri, 26 Jun 2026 15:00:00 GMT</pubDate>
    <description>Bluekit phishing-as-a-service platform upgraded to Browser-in-the-Middle via rrweb, defeating all MFA methods. Separately, a hospitality-sector campaign delivers TonRAT Node.js implants via fake guest complaint phishing lures using Calendly authentication laundering.</description>
    <category>Threat Intelligence Report</category>
  </item>

</channel>
</rss>
