Phishing Campaign Abuses eCards to Deploy RMM Tools
2026-07-16T02:52:12Z•fe7aa1972882f29611b567094f3118f06bc9a41ac80f0b96cd828529ef54a157
agentic-aicloud-securitycredential-theftdeveloper-id-abuseevilginxincident-responsemacos-malwaremfa-bypassmicrosoftoauth-spoofingpatch-tuesdayphishingransomwarermmrouterssecure-bootsharefilestate-sponsoredsupply-chainuefi-shimsvulnerability-management
What happened
A collection of impactful July 2026 infosec stories: a six-month phishing campaign used seasonal eCard lures to deliver legitimate RMM tools and enable post-exploitation; researchers disclosed eleven Microsoft-signed UEFI shims that can bypass Secure Boot on many systems; credential-based attacks (phishing, brute force, compromised logins) are now the dominant ransomware vector; Microsoft shipped a record 570 CVE fixes in Patch Tuesday as AI accelerates vulnerability discovery; and multiple active campaigns and malware families (CrashStealer for macOS, GodDamn/PoisonX, Vidar, RedWing) plus MFA
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- fe7aa1972882f29611b567094f3118f06bc9a41ac80f0b96cd828529ef54a157
- Enrichment time
- 2026-07-16T02:52:12Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.