⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More
2026-07-06T13:24:10Z•e199fe5b2008e523b92982e65df14719c3482ca385216e74c52864eca151d325
ai-agent-exploitationair-gapped-exfiltrationandroidbrowser-extension-malwarecitrixcredential-theftembedded-devicesexploitlinux-kernelnpm-maliceransomwareremote-access-trojansharepointsupply-chainvulnerability
What happened
This weekly recap highlights a broad surge in active exploitation, malware campaigns, supply-chain abuse, and novel attack techniques. Notable vulnerabilities include Bad Epoll (CVE-2026-46242) — a Linux/Android local privilege escalation — and SharePoint RCE (CVE-2026-45659) added to CISA's KEV after active exploitation; ransomware actors continue to exploit Citrix Bleed 2 (CVE-2025-5777). Reported threats span cross-platform RATs and MaaS (QuimaRAT), modular ransomware-capable frameworks (Avalon/CrownX), credential-theft operations tied to FortiGate leaks, targeted campaigns delivering DcRAT
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- e199fe5b2008e523b92982e65df14719c3482ca385216e74c52864eca151d325
- Enrichment time
- 2026-07-06T13:24:10Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.