Why Security Teams Need To Start Earlier
2026-06-18T19:23:47Z•c095ecc2b028b83bc81c71b595da7a2fe5089cc3cf566a1cdde1bba15292ac10
CVE-2026-35273active-exploitationai-risk-translationbehavioral-detectionc2certificate-tracecritical-vulnerabilitydll-side-loadingdonut-shellcodedropping-elephantevasionfondue.exein-memory-ratkerberos-tracingmalwarememory-forensicsmetasploitnis2oracle-peoplesoftpatchingrceregulatory-compliancessrfvulnerability-management
What happened
Rapid7 published multiple posts covering active threats, critical vulnerabilities, tooling updates, and regulatory guidance. Key item: a sophisticated Dropping Elephant campaign uses a China-themed decoy to deliver a heavily reworked in-memory RAT via DLL side‑loading of a legitimate Microsoft binary (Fondue.exe) and Donut shellcode; attackers employ control‑flow flattening, runtime API reconstruction, and hardened C2 — defenders should prioritize behavioral and memory‑level detection (e.g., shortcut spawning PowerShell, files staged in C:\Users\Public\, suspicious scheduled tasks) rather than
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- c095ecc2b028b83bc81c71b595da7a2fe5089cc3cf566a1cdde1bba15292ac10
- Enrichment time
- 2026-06-18T19:23:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.