Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
2026-07-20T19:24:07Z•f3be71c52622f25250276ff668259f37ce3dc0dc7e7b13a824035cd4b7fe8933
ACR StealerAI-assisted attacksCISA KEVCVE-2026-14266CVE-2026-42533CVE-2026-58644ClickFixHollowGraphHugging Face breachMicrosoft 365 abuseNadMeshOpenSSLRubyGemsSonicWallWebDAVbotnetcloud-credential-theftespionageinfostealernpmphishingsupply-chainvulnerabilities
What happened
This collection of headlines highlights a surge of high-impact threats and disclosed vulnerabilities: an exposed delivery server revealed an AI-assisted phishing toolkit delivering WebDAV-based infostealers; HollowGraph espionage malware is abusing Microsoft 365 calendar events (dated 2050) for C2 and data exfiltration; multiple critical product flaws were disclosed (including nginx and 7‑Zip code-execution/overflow bugs and a high‑severity SharePoint RCE added to CISA KEV); OpenSSL denial-of-service (HollowByte) and SonicWall SMA zero-days were observed in the wild. It also documents growing,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- f3be71c52622f25250276ff668259f37ce3dc0dc7e7b13a824035cd4b7fe8933
- Enrichment time
- 2026-07-20T19:24:07Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.