⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More

2026-07-06T13:24:10Ze199fe5b2008e523b92982e65df14719c3482ca385216e74c52864eca151d325
ai-agent-exploitationair-gapped-exfiltrationandroidbrowser-extension-malwarecitrixcredential-theftembedded-devicesexploitlinux-kernelnpm-maliceransomwareremote-access-trojansharepointsupply-chainvulnerability

What happened

This weekly recap highlights a broad surge in active exploitation, malware campaigns, supply-chain abuse, and novel attack techniques. Notable vulnerabilities include Bad Epoll (CVE-2026-46242) — a Linux/Android local privilege escalation — and SharePoint RCE (CVE-2026-45659) added to CISA's KEV after active exploitation; ransomware actors continue to exploit Citrix Bleed 2 (CVE-2025-5777). Reported threats span cross-platform RATs and MaaS (QuimaRAT), modular ransomware-capable frameworks (Avalon/CrownX), credential-theft operations tied to FortiGate leaks, targeted campaigns delivering DcRAT

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
e199fe5b2008e523b92982e65df14719c3482ca385216e74c52864eca151d325
Enrichment time
2026-07-06T13:24:10Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.