- LegacyHiveWindows privilege escalation exploit targeting User Profile Service
- GreenPlasmaWindows vulnerability patched June 2026
- YellowKeyWindows vulnerability patched June 2026
- MiniPlasmaWindows vulnerability patched June 2026
- BlueHammerWindows zero-day exploit previously disclosed by Nightmare Eclipse
- RoguePlanetWindows Defender zero-day vulnerability patched July 2026
ThreatNoir Afternoon Brief — July 17
Afternoon Review in IT Security — July 17, 2026
The threat landscape continues to shift rapidly as researchers disclose critical vulnerabilities and threat actors actively exploit newly patched systems. Today's security briefing covers emerging zero-day exploits, sophisticated espionage campaigns targeting government entities, and active exploitation of recently disclosed flaws affecting widely deployed enterprise software.
New Windows LegacyHive Zero-Day Grants Admin Privileges
A security researcher operating under the handle "Nightmare Eclipse" has publicly released a Windows zero-day exploit designated LegacyHive that enables attackers to escalate privileges on fully updated Windows systems. The vulnerability represents a significant threat to organizations maintaining current patch levels, as the exploit bypasses standard security protections to grant administrative access to compromised systems. Associated malware families including BlueHammer, GreenPlasma, MiniPlasma, RoguePlanet, and YellowKey have been observed in conjunction with this vulnerability. Source: New Windows LegacyHive zero-day gives hackers admin privileges
ACR Stealer Exploits ClickFix Social Engineering to Harvest Enterprise Data
ACR Stealer, an infostealer malware family active since 2024, continues to extract sensitive data from enterprise networks by leveraging ClickFix social engineering lures that trick users into executing commands via the Windows Run dialog. The malware successfully harvests saved browser passwords, active session tokens, PDF documents, Microsoft 365 files, and data from synced OneDrive and SharePoint folders. Microsoft's Defender Experts team has documented two distinct delivery chains being used to distribute this threat, with associated infrastructure including domains such as claude-desktop.gitlab.io, creativecommunityinfo.art, enhanceblabber.cc, and sphere-api.dialectosphere.in.net. Source: ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files
GoSerpent Malware Targets Southeast Asian Government and Diplomatic Entities
Researchers have identified a previously unknown malware family called GoSerpent that has been deployed in targeted attacks against government and diplomatic organizations throughout Southeast Asia since late 2025. Kaspersky discovered the activity in February 2026 and assessed the campaign as focused on establishing persistent access and conducting long-term intelligence gathering operations. The malware toolkit incorporates several secondary tools including McMx RAT, Mimikatz, QuarksDumpLocalHash, Stowaway, ThumbcacheService, and TmcLoader for post-exploitation and credential harvesting activities. Source: New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage
Critical SharePoint Vulnerability Actively Exploited Following Public Disclosure
A critical-severity vulnerability in SharePoint that permits remote authenticated attackers to execute arbitrary code on affected servers has been exploited in the wild shortly after disclosure and patching. The rapid weaponization of this flaw demonstrates the narrow window organizations have to deploy security updates before threat actors begin active exploitation campaigns. Multiple related CVE identifiers including CVE-2026-25089, CVE-2026-39808, CVE-2026-55040, CVE-2026-56164, and CVE-2026-58644 have been associated with SharePoint security defects. Source: Fresh SharePoint Vulnerability Exploited Soon After Disclosure
The convergence of disclosed vulnerabilities, active exploitation, and sophisticated targeted campaigns underscores the critical importance of maintaining rapid patching cycles and implementing defense-in-depth strategies across enterprise infrastructure. Organizations should prioritize immediate assessment and remediation of exposed systems while monitoring for indicators of compromise associated with the malware families and infrastructure detailed in today's threat intelligence.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- ACR StealerInfostealer malware stealing browser credentials, tokens, and Microsoft 365 documents
creativecommunityinfo.artACR Stealer payload host and C2 server (Campaign 2)enhanceblabber.ccACR Stealer payload host and C2 server (Campaign 2)sphere-api.dialectosphere.in.netWebDAV share host for DLL payload deliveryclaude-desktop.gitlab.ioFake Claude Code page hosting ACR Stealer via GitLab
- GoSerpentPrimary Go-based backdoor and RAT targeting Southeast Asian government entities since late 2025
- QuarksDumpLocalHashTool for extracting local account password hashes from SAM registry
- MimikatzCredential dumping tool for extracting LSASS memory
- TmcLoaderC++ loader module containing encrypted TmcPayload for data exfiltration
- McMx RATLightweight Go-based proxy tool with SOCKS5 and file transfer capabilities
- ThumbcacheServiceDLL for sophisticated file collection and sensitive data staging
- StowawayEvolved proxy and remote access tool deployed May 2026 with SOCKS5 proxying and SSH tunneling
- Critical SharePoint RCE deserialization vulnerability actively exploited
- Fortinet FortiSandbox OS command injection exploited in the wild
- Critical SharePoint security bypass allowing file disclosure and data modification
- SharePoint zero-day exploited in the wild
- Fortinet FortiSandbox OS command injection exploited in the wild