- malformed GPT partition table can hang the device during mount.
- file extended past its end can leak leftover data from previously deleted files.
- long filenames overflow the wrapper code many projects put around FatFs.
- exFAT volume-label field overflows a small buffer, giving an attacker a clean memory-corruption foothold.
- FAT32 mount integer overflow leading to memory corruption and possible code execution.
- exFAT divide-by-zero that crashes the device, potentially bricking hardware.
- math wrap in cache handling on fragmented volumes that can silently corrupt data.
ThreatNoir Weekend Brief — July 4
Morning Review in IT Security — July 4, 2026
The security landscape opens this morning with critical vulnerabilities spanning embedded devices, Linux kernels, and supply chain threats, alongside enforcement actions against major malicious infrastructure networks. Organizations face urgent patching demands while threat actors continue refining their tactics across phishing, malware, and proxy abuse vectors.
Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices
Security firm runZero has disclosed seven vulnerabilities affecting FatFs, a small filesystem library that enables devices to read and write FAT and exFAT formats commonly used on USB drives and SD cards. The significance of these flaws lies in FatFs's ubiquitous presence across firmware powering security cameras, drones, industrial controllers, hardware crypto wallets, and numerous other embedded systems. The disclosed vulnerabilities carry CVE identifiers CVE-2026-6682 through CVE-2026-6688, representing a supply chain risk that could affect millions of devices globally. Source: The Hacker News
New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android
A newly disclosed Linux kernel vulnerability designated CVE-2026-46242, nicknamed Bad Epoll, permits ordinary users with no special privileges to gain complete root control over affected systems. The flaw impacts Linux desktops, servers, and Android devices, with patches now available. Notably, this vulnerability resides in the same kernel code section where Anthropic's advanced AI model Mythos recently identified a separate bug, highlighting the density of security issues in this critical component. Source: The Hacker News
New Avalon Malware Framework Packs CrownX Ransomware Capabilities
Cybersecurity researchers have identified a previously undocumented modular malware framework called Avalon distributed through multi-stage phishing chains designed to bypass traditional security controls. Avalon consolidates credential collection, lateral movement, remote access, recovery disruption, and ransomware execution capabilities into a unified platform, incorporating the CrownX ransomware component. The framework's modular design enables attackers to customize their attack chains while maintaining operational flexibility across diverse victim environments. Source: The Hacker News
NetNut Proxy Network Disrupted, 2 Million Infected Devices Cut Off
A joint operation involving Google has successfully disrupted NetNut, a residential proxy network that provided attackers access to millions of compromised Android devices including smart TVs and streaming boxes. The operation severed connectivity for approximately two million infected devices that had been hijacked for proxy services. This action represents a significant blow to threat actors relying on residential proxy infrastructure for conducting attacks and evading detection. Source: Bleeping Computer
North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets
Threat actors with North Korean connections have deployed malicious npm packages masquerading as Rollup polyfill tooling to facilitate remote access and data theft from developers. According to JFrog's analysis, the packages "rollup-packages-polyfill-core" and "rollup-runtime-polyfill-core" closely mimic the legitimate "rollup-plugin-polyfill-node" project, replicating descriptions, repository metadata, and other identifying characteristics to deceive developers. The campaign targets developer credentials and intellectual property, representing a sophisticated supply chain attack leveraging trusted development ecosystems. Source: The Hacker News
FBI Seizes NetNut Domains as Google Disrupts 2M Device Proxy Network
The FBI has seized domains linked to the NetNut residential proxy network as part of a coordinated disruption effort with Google, exposing the widespread abuse of two million televisions and streaming devices globally. The enforcement action targeted the infrastructure supporting the proxy botnet's command and control operations. This seizure represents law enforcement's commitment to dismantling large-scale device hijacking operations that facilitate cybercriminal activity. Source: Hackread
ARToken PhaaS Exposes EvilTokens' Microsoft 365 Phishing Toolkit
A new phishing-as-a-service platform called ARToken has emerged as an affiliate operation of the EvilTokens phishing platform, providing researchers visibility into an extensive toolkit specifically engineered to compromise Microsoft 365 accounts. The platform enables threat actors to conduct token theft and credential harvesting at scale, facilitating persistent business email compromise attacks. ARToken's toolkit demonstrates the sophistication of modern PhaaS offerings designed to lower barriers to entry for attackers targeting enterprise cloud environments. Source: Bleeping Computer
ANSPDCP Romania Issues GDPR Fine for Inadequate Data Security Measures
Romania's National Supervisory Authority for Personal Data Processing has fined Banca Transilvania S.A. 26,172 RON (approximately €5,000) for failing to implement appropriate technical and organizational measures to protect customer data. The investigation revealed that a bank employee had unlawfully accessed a customer's account data without authorization and outside their official duties at a third party's request, exposing sensitive information including the customer's name, IBAN, account type, client code, transaction data, and account balances. The authority determined the bank violated Articles 32(1), 32(2), and 32(4) of the GDPR and ordered implementation of measures to prevent unauthorized employee access to personal data. Source: GDPR Hub
Organizations must prioritize immediate patching of FatFs and Linux kernel vulnerabilities while implementing enhanced access controls for sensitive systems. The convergence of supply chain threats, proxy infrastructure disruption, and phishing-as-a-service platforms underscores the need for comprehensive defense strategies spanning endpoint protection, email security, and privileged access management.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Copy Fail vulnerability
- Previously discovered bug in the same kernel code
- Bad Epoll vulnerability
- FUSE filesystem code vulnerability
- HTTPS for next-stage payload download
- MSBuild execution of embedded .NET assembly
- Inhibiting system recovery by terminating VSS
- Interfering with Event Tracing for Windows (ETW)
- CrownXRansomware component of the Avalon framework
- AvalonModular malware framework
helloxcherry[.]comExfiltration server and C2 communication
- NetNutResidential proxy botnet also known as Popa, controls 2M+ infected devices
- Badbox 2.0Botnet variant packaging NetNut proxy plugins
netnut.comPrimary NetNut domain seized by FBI
- OtterCookieMalware family linked to previous North Korean npm campaigns.
- BeaverTailMalware family linked to previous North Korean npm campaigns.
216.126.236.244External server to fetch encrypted JavaScript payload.
jsonkeeper.comSecond-stage packages fetch JSON objects from this domain.
netnut.comSeized domain linked to NetNut residential proxy service.proxyjet.ioSeized domain linked to NetNut residential proxy service.divinetworks.comSeized domain linked to NetNut residential proxy service, which provided static residential proxies.