- GhostLock vulnerability in Linux kernel
ThreatNoir Weekend Brief — July 11
Afternoon Review in IT Security — July 11, 2026
The cybersecurity landscape continues to shift rapidly as artificial intelligence reveals long-hidden vulnerabilities while simultaneously becoming a vector for sophisticated attacks. Today's threat intelligence encompasses critical discoveries in Linux kernel security, emerging AI exploitation techniques, email-based remote code execution risks, and a major supply-chain compromise targeting payment processors through NuGet package repositories.
AI Found a Root Bug in Linux That Everyone Missed for 15 Years
Artificial intelligence has uncovered a critical privilege escalation vulnerability in the Linux kernel that went undetected for over a decade and a half. The vulnerability, tracked as CVE-2026-43499, represents a significant gap in the security community's ability to identify flaws through traditional code review methods. Source: AI Found a Root Bug in Linux That Everyone Missed for 15 Years
The discovery underscores both the potential and the limitations of human-driven security auditing. While the Linux kernel has benefited from decades of scrutiny by thousands of security researchers, the persistence of this root-level flaw highlights how subtle implementation errors can evade detection across multiple major releases. The incident also raises questions about patch deployment velocity and the challenge of coordinating security fixes across the diverse Linux ecosystem.
Ghostcommit Hides Prompt Injection in Images to Fool AI Agents
Researchers have demonstrated a novel attack technique called Ghostcommit that embeds prompt injection payloads within PNG image files to compromise AI-powered code review systems. The attack successfully bypassed two major code review tools, CodeRabbit and Bugbot, which do not analyze image file contents. Source: Ghostcommit hides prompt injection in images to fool AI agents, steal secrets
Once the poisoned image was committed to a repository, a coding agent was manipulated into reading the repository's .env configuration file and exfiltrating every secret as a list of numbers embedded in the source code. This attack demonstrates a critical gap in the security assumptions underlying AI-assisted development workflows. As organizations increasingly rely on AI agents to automate code review and repository management, the ability to hide malicious instructions in non-text media represents a fundamental blind spot that could enable supply-chain compromise at scale.
Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions
Zimbra has issued an urgent advisory regarding a critical stored cross-site scripting vulnerability affecting the Classic Web Client that allows specially crafted emails to execute arbitrary code within a user's authenticated session. The flaw has not yet been assigned a CVE identifier, though related historical vulnerabilities include CVE-2023-37580, CVE-2024-27443, and CVE-2025-27915. Source: Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions
The vulnerability's severity is amplified by the fact that email is often the primary attack surface for initial compromise in enterprise environments. An attacker can craft a malicious email message that, when opened by a Zimbra user, injects and executes JavaScript code with the full privileges of that user's session. This could enable credential theft, lateral movement within the organization, or deployment of persistent backdoors. Zimbra customers are advised to apply available patches immediately and consider temporary mitigations such as disabling the Classic Web Client in favor of the newer web interface.
Fake Braintree NuGet Package Skims Credit Cards and Harvests Merchant Credentials
A sophisticated multi-stage malware campaign has compromised the NuGet package repository through a typosquatted package named Braintree.Net, designed to impersonate the legitimate Braintree payment SDK. The malicious package, first published on July 3, 2026, was detected by Socket's AI scanner within ten minutes of upload and has been analyzed to contain a complex .NET implant that intercepts live payment card data and exfiltrates Braintree merchant API credentials. Source: Fake Braintree NuGet Package Skims Credit Cards and Harvests Merchant Credentials
The attack leverages multiple exfiltration pathways that activate at different lifecycle points within a .NET application. When the poisoned assembly loads, a module initializer triggers environment and configuration analysis that harvests cloud credentials, database connection strings, and CI/CD tokens. When a developer configures the gateway with production credentials, a property setter hook exfiltrates the merchantId, publicKey, and privateKey to attacker infrastructure at api.348672-shakepay[.]com. During actual payment processing, a CardOperationLogger intercepts full primary account numbers, CVV codes, expiration dates, and customer identifiers before forwarding them to the same C2 endpoint. The implant uses production-environment gating to avoid triggering alerts during development and testing phases, ensuring that only live payment data is stolen. A companion dependency named DependencyInjector.Core, included with versions 3.36.0 and later, performs unconditional environment variable and configuration file harvesting across all .NET versions. The attackers also published related typosquatted SIP and WebRTC packages that route to the same harvester, suggesting a reusable implant framework targeting multiple NuGet ecosystems. Organizations must immediately remove Braintree.Net from all projects, rotate all Braintree merchant credentials, and treat any payment card data processed through the poisoned package as potentially compromised.
Today's threat landscape reflects a convergence of AI-enabled discovery, AI-enabled exploitation, and supply-chain targeting at the package manager level. Organizations must prioritize patch management velocity, enhance code review processes to account for non-text attack surfaces, and implement strict dependency verification controls in their software development pipelines.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Previous stored XSS flaw in Zimbra Classic Web Client
- Previously exploited XSS flaw in Zimbra
- Previously exploited XSS flaw in Zimbra
- DependencyInjector.Core (NuGet package)Companion harvester dependency; versions 1.0.0, 1.3.0, 1.4.0, 1.4.1 confirmed malicious
- Braintree.Net (NuGet package)Typosquat payment SDK stealer; versions 3.35.8, 3.35.9, 3.36.0, 3.36.1 confirmed malicious
api.348672-shakepay.comC2 infrastructure for exfiltrating payment card data, merchant credentials, and environment secrets
hxxps://api[.]348672-shakepay[.]com/api/cardEndpoint for PAN/CVV exfiltrationhxxps://api[.]348672-shakepay[.]com/api/accountEndpoint for Braintree merchant key (merchantId, publicKey, privateKey) thefthxxps://api[.]348672-shakepay[.]com/api/analytics/reportEndpoint for environment variable, configuration file, and cloud metadata exfiltration
7a9f19ed663c…Braintree.dll malicious assembly hashefec1e537445…DependencyInjector.Core.dll malicious assembly hash