Why Security Teams Need To Start Earlier

2026-06-18T19:23:47Zc095ecc2b028b83bc81c71b595da7a2fe5089cc3cf566a1cdde1bba15292ac10
CVE-2026-35273active-exploitationai-risk-translationbehavioral-detectionc2certificate-tracecritical-vulnerabilitydll-side-loadingdonut-shellcodedropping-elephantevasionfondue.exein-memory-ratkerberos-tracingmalwarememory-forensicsmetasploitnis2oracle-peoplesoftpatchingrceregulatory-compliancessrfvulnerability-management

What happened

Rapid7 published multiple posts covering active threats, critical vulnerabilities, tooling updates, and regulatory guidance. Key item: a sophisticated Dropping Elephant campaign uses a China-themed decoy to deliver a heavily reworked in-memory RAT via DLL side‑loading of a legitimate Microsoft binary (Fondue.exe) and Donut shellcode; attackers employ control‑flow flattening, runtime API reconstruction, and hardened C2 — defenders should prioritize behavioral and memory‑level detection (e.g., shortcut spawning PowerShell, files staged in C:\Users\Public\, suspicious scheduled tasks) rather than

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
c095ecc2b028b83bc81c71b595da7a2fe5089cc3cf566a1cdde1bba15292ac10
Enrichment time
2026-06-18T19:23:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.