Phishing Campaign Abuses eCards to Deploy RMM Tools

2026-07-16T02:52:12Zfe7aa1972882f29611b567094f3118f06bc9a41ac80f0b96cd828529ef54a157
agentic-aicloud-securitycredential-theftdeveloper-id-abuseevilginxincident-responsemacos-malwaremfa-bypassmicrosoftoauth-spoofingpatch-tuesdayphishingransomwarermmrouterssecure-bootsharefilestate-sponsoredsupply-chainuefi-shimsvulnerability-management

What happened

A collection of impactful July 2026 infosec stories: a six-month phishing campaign used seasonal eCard lures to deliver legitimate RMM tools and enable post-exploitation; researchers disclosed eleven Microsoft-signed UEFI shims that can bypass Secure Boot on many systems; credential-based attacks (phishing, brute force, compromised logins) are now the dominant ransomware vector; Microsoft shipped a record 570 CVE fixes in Patch Tuesday as AI accelerates vulnerability discovery; and multiple active campaigns and malware families (CrashStealer for macOS, GodDamn/PoisonX, Vidar, RedWing) plus MFA

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
fe7aa1972882f29611b567094f3118f06bc9a41ac80f0b96cd828529ef54a157
Enrichment time
2026-07-16T02:52:12Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.