Spanish Police Arrest Man Linked to CARR, Z-Pentest, and NoName057(16)

2026-07-07T20:51:42Z33fd1e7637d5c5c27e7c4d1ac94c771bfac3583abdad64abfc12ac6853f9c088
adobe-coldfusionai-generated-malwareaptbad-epolldata-breachfatfsiotkernel-exploitkvmlaw-enforcementlocal-privilege-escalationphishingprompt-injectionrcerouter-backdoorshinyhunterstendavm-escape

What happened

Multiple high-impact incidents reported: Adobe ColdFusion RCE (CVE-2026-48282) is being actively exploited in the wild; CERT/CC warns of an unpatched Tenda router backdoor (CVE-2026-11405) that grants full admin access; and the Bad Epoll Linux kernel vulnerability (CVE-2026-46242) enables local privilege escalation to root. A 16-year-old Linux KVM use-after-free (Januscape) enables guest-to-host corruption and potential VM escape. Kaspersky documents a new APT (“Armored Likho”) using AI-generated malware, phishing and BusySnake stealer targeting governments and critical infrastructure. runZero

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
33fd1e7637d5c5c27e7c4d1ac94c771bfac3583abdad64abfc12ac6853f9c088
Enrichment time
2026-07-07T20:51:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Spanish Police Arrest Man Linked to CARR, Z-Pentest, and NoName057(16) · Baitaphish