Clear Infosec weekly Threat Intelligence Bulletin for July 15, 2026. Curated cyber security news, threats, and guidance with links to the original sources.
Cyber Security News
- China-Linked Group Targets Southeast Asia Critical Systems The group compromised at least 10 regional organizations, including two state-owned entities, and deployed a new backdoor…
- GitLost Flaw Leaks Private Data From GitHubs Agentic Workflows The flaw allows an unauthenticated attacker to craft a GitHub Issue in an org’s public repository and then silently pull data from its private repos, too…
- Crafty Phishing Campaigns Auto-Adapt to Victims Device OS Attackers fingerprint victims through user-agent data to deliver OS-specific payloads, increasing compromise rates and campaign profitability…
- Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours The attacker exploited AI workflows, chained cloud weaknesses, and stolen credentials to extort a large Amazon customer…
- Weak Security Continues to Fuel Russian Cyberattacks In a first, the UK and the EU jointly imposed sanctions on Russian individuals and entities for cyberattacks and disinformation campaigns in the region…
Best Practices
- US authorities warn of Russian attacks on critical infrastructure The US authorities NSA, FBI, and CISA warn that Russian hackers have recently carried out a number of attacks on critical infrastructure…
- Attack on Amazon Bedrock-linked AI gateway highlights new cloud security risk A cloud intrusion that ended with the deployment of cryptomining malware has exposed a bigger risk for enterprises: AI gateways that conc…
- Watch out for fake support calls in Microsoft Teams Palo Alto Networks’ security division, Unit 42, is warning of yet another campaign targeting Microsoft Teams users. The new campaign b…
- Adobe premieres a second Patch Tuesday each month to deliver fixes faster Adobe will now issue security patches for its products twice as often to deal with the increasing pace of software vulnerability discover…
New Threats and Vulnerabilities
- 11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot Cybersecurity researchers have discovered 11 old, Microsoft-signed, Unified Extensible Firmware Interface (UEFI) applications that could be abused to bypass Sec…
- CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks Cybersecurity researchers have flagged a new macOS information stealer called CrashStealer that’s capable of harvesting sensitive data from compromised systems…
- Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory Cybersecurity researchers have flagged an intrusion in which an unknown threat actor leveraged a vibe-coded PowerShell script for Active Directory (AD) enumerat…
- Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions Zimbra is urging customers to apply updates to address a critical security vulnerability impacting the Classic Web Client that could result in arbitrary code ex…
- Attackers Exploit Ill Bloom Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets Security firm Coinspect has disclosed a crypto wallet flaw it calls Ill Bloom, and attackers are already using it. The flaw is in how some wallet…
Patch Management
- Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft A new phishing-as-a-service (PhaaS) operation called Forg365 is using a combination of device code phishing, adversary-in-the-middle (AitM) tactics, antibot eva…
- Azure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ Attempts Cybersecurity researchers have warned of a “massive, ongoing, automated password spray attack” aimed at Microsoft’s Azure command-line interface (CLI), compromi…
- Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service Citrix on Tuesday released security updates to address multiple flaws in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) tha…
- Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes Cybersecurity researchers have disclosed details of a new threat actor dubbed Lurking Lizard that has been operating an end-to-end malicious residential proxy b…
AI and Security
- Microsoft warns customers AI will mean busier Patch Tuesdays Microsoft has warned customers to expect more security patches for the foreseeable future, thanks to AI. “As AI helps defenders discover more issues, customers…
- Bug in top AI coding agents shows that Unix-era security headaches never really die UPDATED A “systematic vulnerability pattern” in at least six of the most widely used AI coding assistants can be abused to trick agents into accessing files ou…