SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 107

2026-07-26T14:51:48Z0a69a3aa11e611fe0a8da8d57c25b6249d670f1946348a39eb6a7d6c5850223e
APTAgentBaitingHades implantHermes AI agentLaundry BearSleeperGemUAC-0099Zimbracredential-theftdata-breachespionagemalwareransomwaresupply-chainwifi-hijack

What happened

Security Affairs feed (26 Jul 2026) highlights multiple active and emerging threats: supply‑chain and open‑source compromises (SleeperGem: malicious git_credential_manager, Dendreo, fastlane RubyGems dropping a persistent backdoor; fake Notepad++ plugin used by UAC‑0099), large-scale credential harvesting via compromised hotel Wi‑Fi gateways redirecting guests to fake Microsoft 365 login pages, ransomware activity (Chaos with msaRAT), and mass phishing/malware distribution campaigns (AgentBaiting delivering malware via fake AI skills/MCP servers). Nation‑state and espionage activity is also a重

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
0a69a3aa11e611fe0a8da8d57c25b6249d670f1946348a39eb6a7d6c5850223e
Enrichment time
2026-07-26T14:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 107 · Baitaphish