NuGet Typosquatting Package Targets Digitain Betting Platform

Executive Summary A JFrog report published on 21 July 2026 detailed a typosquatted NuGet package, Newtonsoftt.Json.Net, that impersonated the legitimate Newtonsoft.Json library. The malicious package delivered a trojanized JSON library designed specifically to manipulate game results within Digitain’s BetOnGames FG-Crash betting platform. JFrog identified seven malicious versions that evolved across three generations, with later versions capable of…

Read More

SharePoint Remote Code Execution Vulnerabilities Enable Server-Side Code Execution

Executive Summary A ThreatLocker report published on 21 July 2026 detailed two critical deserialization vulnerabilities, CVE-2026-50522 and CVE-2026-58644, affecting on-premises Microsoft SharePoint Server deployments. The flaws can allow an authenticated attacker to submit malicious serialized data that is processed by vulnerable SharePoint components, resulting in remote code execution within the SharePoint server context. Successful exploitation could enable command execution, malware…

Read More

New AgentBaiting Campaign Delivers SmartLoader Via Fake AI Skills and MCP Servers

Executive Summary On 21 July 2026, Cyber Security News reported a novel AI-themed malware distribution campaign (AgentBaiting) has emerged alongside a sustained wave of data breaches and ransomware attacks targeting retail organizations across Europe and North America. Threat actors are exploiting both cutting-edge AI tooling ecosystems and traditional third-party/supply-chain weaknesses to exfiltrate customer data at scale. Key…

Read More

Current ClickFix Threat Landscape Developments

Executive Summary In the last two years, ClickFix tactics have moved from a one-off social engineering trick into an industrialized attack ecosystem that is outpacing conventional antivirus and endpoint defenses. The technique first appeared in late 2023 and early 2024, and it skips exploits and vulnerabilities entirely as a fake webpage impersonating a CAPTCHA check, browser update…

Read More

New ClickLock Stealer macOS Malware Spread via ClickFix Campaign

Executive Summary On 9 June 2026, Group-IB Threat Intelligence reported a malicious shell script uploaded to VirusTotal assessed as a new modular macOS stealer likely distributed via ClickFix phishing pages, relying on compromised WordPress domains and Telegram infrastructure, with a strong European victim focus. According to Group-IB, a ClickLock Stealer operation has already targeted at least 100…

Read More

ShinyHunters Abusing OAuth to Compromise SaaS Apps

Executive Summary On 13 July 2026, Microsoft researchers published details of a ShinyHunters campaign active between mid-2025 and mid-2026 targeting customer SaaS-based applications, especially Salesforce instances, through voice phishing (vishing), supply chain compromise, and misconfigured guest access. The threat actors abused trusted OAuth relationships for unauthorized access, data exfiltration, and persistence.  ShinyHunters has demonstrated a consistent pattern…

Read More

FortiBleed Credential Theft Campaign Attributed to INC and Lynx Ransomware Groups

Executive Summary On 02 July 2026, SOCRadar researchers linked the financially-motivated campaign dubbed “FortiBleed” to the Ransom and Lynx ransomware operations, marking the first confirmed instance connecting mass FortiGate credential theft to actual ransomware deployment. SOCRadar reported that an operator tied to FortiBleed infrastructure was found actively working negotiation panels for both groups, tying mass FortiGate credential theft directly…

Read More

Icarus Threat Group Claims Salesforce Data Theft in Klue Supply Chain Breach

Executive Summary  On 19 June 2026, the threat group Icarus claimed to have compromised and exfiltrated data from customers of Klue, specifically the Salesforce integration of the market intelligence platform. Salesforce has since disabled Klue integrations. Compromised Data Scope  The impacted data may consist of business names, products trialed/used, subscription details (units, pricing), business contact info (full names, work emails, job title,…

Read More

144 Mastra npm Packages Compromised Through Maintainer Phishing Attack

Executive Summary A report published by The Hacker News on 17 June 2026 detailed a software supply chain attack impacting 144 npm packages associated with the Mastra ecosystem after threat actors compromised a maintainer account through a phishing attack. The attackers leveraged the compromised account to publish malicious package versions to the npm registry. According to the…

Read More

NFCShare Android NFC Fraud Campaign Impersonating Deutsche Bank

Executive Summary In June 2026, D3 lab researchers reported on a new banking trojan. NFCShare is an Android banking trojan initially distributed as a malicious Android Package file (APK) through a phishing flow impersonating Deutsche Bank. The malware presents a fake card-verification interface, prompts the victim to place a payment card near the phone, collects the card…

Read More