Meet Cyware at Black Hat
Daily Threat Briefing
Diamond Trail

Cyware Daily Threat Intelligence - July 21, 2026

shutterstock 1262243092

Attackers are turning a single authentication bypass into a full-scale ransomware breach, as Qilin ransomware exploits a flaw in Palo Alto Networks’ GlobalProtect to slip past VPN defenses. Cyware highlights how intrusions starting on May 17 have led to stolen Active Directory secrets, business disruption, and systems taken offline, with attackers staging payloads as win.exe in C:\PerfLogs\. A patch is available, but the window for exploitation remains open for unpatched organizations.

A single tainted npm package can now compromise entire CI/CD pipelines, as the Miasma backdoor infiltrated AsyncAPI’s ecosystem on July 14, 2026. Developers and automation systems risk credential theft and remote access, with attackers leveraging IPFS, BitTorrent, and Ethereum smart contracts to maintain control. For software teams, the impact can cascade to customers and partners, not just internal systems.

Threat actors are using AI to sharpen their lures, as APT42 targets senior defense and government officials with multilingual phishing in the SpearSpecter campaign. The group’s TAMECAT backdoor focuses on browser credential theft and persistent access, raising the stakes for national security and policy decision-makers.

Top Malware Reported in the Last 24 Hours

Qilin ransomware via CVE-2026-0257

Qilin is a ransomware strain that leverages a critical authentication-bypass flaw to gain unauthorized access to corporate networks. Qilin establishes persistence and remote control using tools such as AnyDesk, Ngrok, and LogMeIn. Qilin moves laterally with PsExec, steals credentials and data, and ultimately encrypts systems to disrupt business operations. Qilin is delivered by exploiting CVE-2026-0257 in Palo Alto Networks PAN-OS GlobalProtect, specifically where authentication override cookies are enabled with certain certificate configurations. Qilin targets organizations using affected PAN-OS versions, resulting in stolen Active Directory secrets and systems taken offline. Rapid7 and Arctic Wolf reported live exploitation beginning on May 17, with ransomware staged as win.exe from C:\PerfLogs\.

Miasma backdoor in AsyncAPI npm packages

Miasma is a backdoor deployed through a supply-chain attack on the AsyncAPI npm ecosystem. Miasma activates during builds and CI jobs, providing attackers with remote access and credential theft capabilities. Miasma maintains control by rotating endpoints and fallback configurations using IPFS, BitTorrent, and Ethereum smart contracts. Miasma is delivered via trusted GitHub Actions workflows and affects versions @asyncapi/[email protected], @asyncapi/[email protected], @asyncapi/[email protected], and @asyncapi/[email protected]. Miasma targets developer and CI/CD environments, risking downstream incidents for customers and partners. The campaign was reported on July 14, 2026.

EncForge ransomware by JadePuffer

EncForge (also referenced as ENCFORGE) is a ransomware payload deployed by the JadePuffer threat actor to target AI infrastructure by encrypting model data. EncForge exploits a Langflow flaw (CVE-2025-3248) via the /api/v1/validate/code endpoint to execute attacker-supplied Python code. EncForge abuses the Docker API to spin up privileged containers and run ransomware on the host. EncForge targets AI file types including PyTorch, TensorFlow, and Hugging Face SafeTensors, marking encrypted files with a .locked extension and leaving a ransom note. EncForge impacts organizations building or hosting AI systems, risking stalled development and unrecoverable model assets if backups are lacking.

Top Vulnerabilities Reported in Last 24 hours

CVE-2026-0257 in Palo Alto Networks PAN-OS

CVE-2026-0257 is a critical authentication bypass vulnerability in Palo Alto Networks PAN-OS GlobalProtect portal and gateway, with a CVSS score not specified in the source. Successful exploitation allows attackers to establish unauthorized VPN sessions and deploy Qilin ransomware. CVE-2026-0257 is actively exploited in the wild, with Rapid7 observing exploitation beginning on May 17 and Arctic Wolf analyzing intrusions involving registry Run keys, remote access tools, credential dumping, and lateral movement. Security updates released on May 13 provide a fix, and response actions include terminating active GlobalProtect sessions, rotating domain credentials, monitoring execution from C:\PerfLogs, and forwarding Windows Event Logs to a SIEM.

WP2Shell vulnerabilities in WordPress (CVE-2026-63030, CVE-2026-60137)

CVE-2026-63030 and CVE-2026-60137 are WP2Shell vulnerabilities in WordPress that allow attackers to take full control of vulnerable sites. Successful exploitation enables unauthenticated access, with no requirement for specific plugins or themes. CVE-2026-63030 and CVE-2026-60137 are already exploited in the wild, with proof-of-concept code released almost immediately after patches. Wordfence described this as one of the biggest WordPress issues in the past decade. Fixes are available in WordPress 6.8.6, 6.9.5, and 7.0.2.

Linux kernel UDP corking vulnerabilities (CVE-2026-53362, CVE-2026-53366)

CVE-2026-53362 and CVE-2026-53366 are vulnerabilities in the UDP corking path of the Linux kernel that can allow a local, unprivileged user to trigger a heap out-of-bounds write and escalate privileges. Successful exploitation can turn a local foothold into higher-level control, especially on systems with IPv6 (CONFIG_IPV6=y) and IPv4 (USERNS) enabled. No active exploitation has been observed in the provided source. Researchers @physicube and @qwerty (Wongi Lee) are credited, with IPv4 exploitability confirmed by Sultan Alsawaf (CIQ). Fixes are available via patches 736b380e28d0 (IPv6) and eca856950f7c (IPv4).

Top Threat Actors Reported in Last 24 hours

APT42 (SpearSpecter campaign)

APT42 is a suspected Iran-linked threat actor focused on espionage and credential theft. APT42 uses AI-assisted phishing for target research, persona development, and multilingual lure writing. APT42 deploys multi-stage Windows infection chains involving .lnk shortcut files and fileless PowerShell activity, using Windows features like search-ms and WebDAV for delivery. APT42 targets senior defense and government officials, risking account compromise and sensitive data theft. The group’s TAMECAT backdoor provides persistence, fallback domain generation, and Telegram-bot-based configuration, focusing on browser credential theft and off-screen data exfiltration.

Famous Chollima

Famous Chollima is a suspected North Korea-linked threat group motivated by financial gain. Famous Chollima runs fraudulent job interviews to plant remote-access trojans and steal cryptocurrency assets from Web3 professionals. Famous Chollima uses psychological tactics such as countdown timers and automated warnings during fake assessments. Famous Chollima targets individuals across LinkedIn, Telegram, Discord, and email, with risk extending to organizations when interviews occur on corporate devices. The group deploys PylangGhost on Windows and GolangGhost on macOS, targeting browser extensions and cryptocurrency wallets.

Gentlemen ransomware group

Gentlemen is a financially motivated ransomware group operating a Ransomware-as-a-Service model. Gentlemen uses a custom Go-based backdoor to collect intelligence and execute remote commands before launching encryption. Gentlemen may collaborate with Initial Access Brokers to accelerate intrusions. Gentlemen targets manufacturing, healthcare, and finance organizations, increasing the risk of deep disruption and high-impact data exposure. The group recently claimed an attack on Mercado Libre and developed a new C-based ransomware variant for Windows systems.

Frequently Asked Questions

  1. What is Qilin? CVE-2026-0257, a critical authentication-bypass flaw in Palo Alto Networks PAN-OS GlobalProtect, is being actively exploited to deliver Qilin ransomware by letting attackers establish unauthorized VPN sessions. The intrusions hinge on environments where authentication override cookies are enabled with specific certificate configurations, turning a convenience feature into a direct path into corporate networks.

  2. What is Miasma? A supply-chain attack hit the AsyncAPI npm ecosystem on July 14, 2026, pushing the Miasma backdoor into developer and CI/CD environments through trusted GitHub Actions workflows. The affected versions named in the report include @asyncapi/[email protected], @asyncapi/[email protected], @asyncapi/[email protected], and @asyncapi/[email protected], meaning routine installs could quietly introduce remote access and credential theft into build pipelines.

  3. What is JadePuffer? The JadePuffer threat actor has been tied to EncForge (also referenced as ENCFORGE) ransomware attacks that go after AI infrastructure by encrypting model data instead of just business documents. It exploits a Langflow flaw (CVE-2025-3248) via the /api/v1/validate/code endpoint to run attacker-supplied Python, using base64-encoded scripts as the operation progresses.

  4. What is CVE-2026-0257? A critical authentication bypass in Palo Alto Networks PAN-OS GlobalProtect portal and gateway (CVE-2026-0257) is being actively exploited to let attackers slip into corporate networks and ultimately deploy Qilin ransomware. The abuse hinges on environments where authentication override cookies are enabled with certain certificate configurations, allowing unauthorized VPN sessions against affected PAN-OS versions 12.1, 11.2, 11.1, and 10.2, plus certain Prisma Access releases.

  5. What is CVE-2026-63030? Wordfence warned that the WP2Shell vulnerabilities in WordPress (CVE-2026-63030 and CVE-2026-60137) were exploited within hours of a patch release, giving attackers a fast path to take full control of vulnerable sites. The issue stands out because attacks don’t require authentication—or even specific plugins or themes—making the exposed surface area unusually broad for WordPress deployments.

  6. What is CVE-2026-53362? Two Linux kernel flaws in the UDP corking path (CVE-2026-53362 and CVE-2026-53366) can let a local, unprivileged user trigger a heap out-of-bounds write and potentially escalate privileges on affected systems. In practical terms, this turns a foothold on a machine into a chance to gain higher-level control, especially on configurations involving IPv6 (CONFIG_IPV6=y) and IPv4 (USERNS), according to the report.

  7. What is APT42? APT42, an Iran-linked threat actor, is using AI-assisted phishing in a campaign dubbed SpearSpecter to draw in senior defense and government figures, turning personalized outreach into a fast path for intrusion. They use AI for target research, persona development, and multilingual lure writing, then push victims into a multi-stage Windows infection chain.

  8. What is Famous Chollima? Famous Chollima, a North Korea-linked threat group, is running fraudulent job interviews to plant remote-access trojans and steal cryptocurrency assets from Web3 professionals. They lure targets across LinkedIn, Telegram, Discord, and email, then pressure them through fake “assessments” that use psychological tactics like countdown timers and automated warnings when a victim switches tabs.

  9. What is Gentlemen? Gentlemen, a financially motivated ransomware group operating a Ransomware-as-a-Service model, is spending more time inside networks to gain control before launching encryption. They use a custom Go-based backdoor to collect intelligence and run remote commands, shaping intrusions into more tailored, high-leverage attacks.

Discover Related Resources