LodeHQSubscribe →

Two Oj JSON bugs lead to GitLab RCE, vBulletin exploit goes public

Infosec · 2026-07-27

Vulnerabilities & Exploits
Two Oj JSON Parser Bugs Enable GitLab Remote Code Execution26 MIN

A researcher chained an out‑of‑bounds write and a heap‑pointer leak in the native Oj JSON parser to achieve remote code execution on GitLab CE/EE versions 15.2‑19.0.1. The flaw required only push access, exposing self‑managed GitLab installations to full system compromise until patches were released.

Public Exploit Reveals Unpatched vBulletin RCE Before Patch Deployment3 MIN

A public proof‑of‑concept released on July 27 demonstrates an unauthenticated request reaching PHP’s eval() in vBulletin’s template engine, allowing remote code execution on any server running vBulletin 6.2.1 or earlier (and 6.1.6‑). The flaw was patched in vBulletin 6.2.2, but sites still on older versions remain fully exploitable.

Defender for Endpoint Linux Update Can Kill Agent on Reboot, Blocks FIPS RHEL44 MIN

A recent Defender for Endpoint Linux update (build 101.26042) may disable the endpoint agent after a reboot, leaving affected machines unprotected. A second issue stops installation on FIPS‑enabled RHEL 8/9 systems. Microsoft has paused rollout and advises verification before deployment.

Threats & Malware
East‑Asia actor hijacks Telegram API for C2 in Middle East government attacks13 MIN

Zscaler ThreatLabz discovered a July 2026 campaign targeting Middle‑East government networks, deploying three previously unknown malware families, TELESHIM, MIXEDKEY and BINDCLOAK. TELESHIM uses the Telegram API as a covert C2 channel, blending traffic with legitimate messages, while heavy obfuscation and environment‑keyed encryption make detection hard. The operation is tied to an actor with East‑Asian links.

Golden Chickens Unveils Four New Modular Malware Families, Raising Attack Complexity3 MIN

Recorded Future reports that TAG‑195’s Golden Chickens MaaS has added TinyEgg, ChonkyChicken, a modular ChonkyChicken variant, and ChromEggscalator. The tools share a common C2, persistence, and obfuscation stack, and the modular design lets operators load up to 14 capability plugins on demand. This evolution widens the group’s reach, giving affiliates more flexible credential‑theft and surveillance capabilities.

Cruciferra Crypter’s BYOVD & Process Ghosting Lets Malware Slip Past EDR16 MIN

Proofpoint’s latest analysis reveals Cruciferra, a Mono‑based crypter‑as‑a‑service sold since late 2025 that now powers RATs and infostealers for dozens of unrelated threat groups. It cloaks payloads with indirect system calls, API/IAT unhooking, BYOVD driver abuse and a custom process‑ghosting routine, plus over 90 dynamically assembled encryption variants, rendering static signatures and most EDR sensors ineffective.

Cl0p ransomware exploits zero‑day in PTC Windchill, targeting engineering data1 MIN

A Cl0p affiliate is weaponizing CVE‑2026‑12569, an unsafe‑deserialization RCE flaw in PTC Windchill and FlexPLM, to drop JSP webshells and steal engineering data from aerospace, automotive and manufacturing firms. Patched on June 17, the bug is still being abused, leading CISA to list it in its KEV catalog. Apply PTC’s patches and hunt with the published IoCs.

Compromised Public Wi‑Fi Gateways Steal Microsoft 365 Logins from Travelers1 MIN

ReliaQuest uncovered a campaign that hijacks captive‑portal routers in hotels, airports and conference centers to DNS‑poison visitors and siphon Microsoft 365 credentials from traveling employees. The attackers reuse APT28‑style tradecraft but target any industry, exposing a new attack surface for organizations that run public Wi‑Fi.

MedusaHVNC hides browsers on invisible desktops to stay out of sight2 MIN

The RAT opens a legitimate Chrome, Edge or Firefox instance on a hidden Windows desktop, letting attackers browse, capture screens, and hijack clipboard without the user noticing. It loads via a multi‑stage encrypted payload, persists in the Startup folder, and talks to a hard‑coded C2. Detection now hinges on spotting unexplained outbound traffic.

Breaches & Industry News
DentaQuest breach exposes up to 23 million dental records, triggers mass notifications3 MIN

In May 2026 DentaQuest detected unauthorized access to its network, compromising names, SSNs, Medicaid IDs and dental health data. The company began notifying at least 15 million people, potentially rising to over 23 million, and offered two years of free credit monitoring. The leak underscores the scale of health‑care data risk.

Privacy, Policy & Governance
UK Supreme Court bars Bahrain from claiming immunity in FinFisher spyware lawsuit2 MIN

The top UK court ruled 3‑2 that Bahrain cannot invoke state immunity for a 2011 hack that installed FinFisher spyware on two dissidents’ laptops in London. The decision means the activists can pursue damages for the breach of privacy and psychiatric harm. It sets a precedent that foreign states are not shielded when surveillance occurs on UK soil.

Get Infosec in your inbox, every issue.
Subscribe free
Get the app · Privacy · Terms · About · Contact
© 2026 LodeHQ