Two Oj JSON bugs lead to GitLab RCE, vBulletin exploit goes public
A researcher chained an out‑of‑bounds write and a heap‑pointer leak in the native Oj JSON parser to achieve remote code execution on GitLab CE/EE versions 15.2‑19.0.1. The flaw required only push access, exposing self‑managed GitLab installations to full system compromise until patches were released.
A public proof‑of‑concept released on July 27 demonstrates an unauthenticated request reaching PHP’s eval() in vBulletin’s template engine, allowing remote code execution on any server running vBulletin 6.2.1 or earlier (and 6.1.6‑). The flaw was patched in vBulletin 6.2.2, but sites still on older versions remain fully exploitable.
A recent Defender for Endpoint Linux update (build 101.26042) may disable the endpoint agent after a reboot, leaving affected machines unprotected. A second issue stops installation on FIPS‑enabled RHEL 8/9 systems. Microsoft has paused rollout and advises verification before deployment.
Zscaler ThreatLabz discovered a July 2026 campaign targeting Middle‑East government networks, deploying three previously unknown malware families, TELESHIM, MIXEDKEY and BINDCLOAK. TELESHIM uses the Telegram API as a covert C2 channel, blending traffic with legitimate messages, while heavy obfuscation and environment‑keyed encryption make detection hard. The operation is tied to an actor with East‑Asian links.
Recorded Future reports that TAG‑195’s Golden Chickens MaaS has added TinyEgg, ChonkyChicken, a modular ChonkyChicken variant, and ChromEggscalator. The tools share a common C2, persistence, and obfuscation stack, and the modular design lets operators load up to 14 capability plugins on demand. This evolution widens the group’s reach, giving affiliates more flexible credential‑theft and surveillance capabilities.
Proofpoint’s latest analysis reveals Cruciferra, a Mono‑based crypter‑as‑a‑service sold since late 2025 that now powers RATs and infostealers for dozens of unrelated threat groups. It cloaks payloads with indirect system calls, API/IAT unhooking, BYOVD driver abuse and a custom process‑ghosting routine, plus over 90 dynamically assembled encryption variants, rendering static signatures and most EDR sensors ineffective.
A Cl0p affiliate is weaponizing CVE‑2026‑12569, an unsafe‑deserialization RCE flaw in PTC Windchill and FlexPLM, to drop JSP webshells and steal engineering data from aerospace, automotive and manufacturing firms. Patched on June 17, the bug is still being abused, leading CISA to list it in its KEV catalog. Apply PTC’s patches and hunt with the published IoCs.
ReliaQuest uncovered a campaign that hijacks captive‑portal routers in hotels, airports and conference centers to DNS‑poison visitors and siphon Microsoft 365 credentials from traveling employees. The attackers reuse APT28‑style tradecraft but target any industry, exposing a new attack surface for organizations that run public Wi‑Fi.
The RAT opens a legitimate Chrome, Edge or Firefox instance on a hidden Windows desktop, letting attackers browse, capture screens, and hijack clipboard without the user noticing. It loads via a multi‑stage encrypted payload, persists in the Startup folder, and talks to a hard‑coded C2. Detection now hinges on spotting unexplained outbound traffic.
In May 2026 DentaQuest detected unauthorized access to its network, compromising names, SSNs, Medicaid IDs and dental health data. The company began notifying at least 15 million people, potentially rising to over 23 million, and offered two years of free credit monitoring. The leak underscores the scale of health‑care data risk.
The top UK court ruled 3‑2 that Bahrain cannot invoke state immunity for a 2011 hack that installed FinFisher spyware on two dissidents’ laptops in London. The decision means the activists can pursue damages for the breach of privacy and psychiatric harm. It sets a precedent that foreign states are not shielded when surveillance occurs on UK soil.
Subscribe free