- Critical heap buffer overflow in nginx script engine affecting versions 0.9.6–1.31.2
ThreatNoir Morning Brief — July 20
Morning Review in IT Security — July 20, 2026
Today's threat landscape brings critical infrastructure vulnerabilities, nation-state targeting of government networks, and active exploitation campaigns affecting millions of web administrators and Ukrainian users. Organizations must prioritize immediate patching and user awareness as public exploits become available and sophisticated social engineering tactics spread.
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
F5 has released patches addressing a critical vulnerability in NGINX that allows remote, unauthenticated attackers to trigger a heap buffer overflow in worker processes through crafted HTTP requests. Identified as CVE-2026-42533, this flaw was patched on July 15 across multiple versions including NGINX 1.30.4 (stable), 1.31.3 (mainline), and NGINX Plus 37.0.3.1. Exploitation of this vulnerability can crash or restart worker processes, resulting in denial of service conditions and potentially enabling remote code execution. Organizations running earlier builds must upgrade immediately to mitigate exposure. Source: The Hacker News
Hackers Abuse ViPNet Software to Target Russian Government Agencies
Advanced threat actors have been observed exploiting the update mechanism of ViPNet, a private networking product suite, to compromise Russian organizations including government agencies. The campaign utilizes multiple malware components including HelloBackdoor, HelloCleaner, HelloExecutor, HelloInjector, and HelloProxy to establish persistence and maintain access within targeted networks. This supply chain attack demonstrates how legitimate software update channels can be weaponized to deliver sophisticated payloads to high-value targets. Source: Bleeping Computer
WordPress Core "wp2shell" RCE Flaws Get Public Exploits, Patch Now
Public exploits have been released for critical remote code execution vulnerabilities affecting WordPress Core, designated as CVE-2026-60137 and CVE-2026-63030. The availability of working exploits significantly increases the risk of mass exploitation against unpatched WordPress installations. Website administrators are urged to apply patches immediately to prevent unauthorized code execution on their systems. The rapid public disclosure of functional exploits means that attackers have lowered barriers to launching widespread campaigns against vulnerable sites. Source: Bleeping Computer
UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices with Malware
Russian state-sponsored threat actors affiliated with Sandworm and the GRU have deployed the ClickFix social engineering technique to deceive Ukrainian users into executing malware on their own systems. The Computer Emergency Response Team of Ukraine (CERT-UA) has attributed this campaign to UAC-0145, a sub-cluster within the broader Sandworm operation. The attack leverages fake CAPTCHA prompts to trick users into running malicious PowerShell scripts that deploy data-stealing malware including COWARDDUCK, FLUIDLEECH, FREAKYPOLL, GHETTOVIBE, LOADLOOP, SCOUTCURL, and SMARTAXE. This campaign demonstrates the continued effectiveness of social engineering tactics when combined with geopolitical targeting. Source: The Hacker News
The convergence of critical infrastructure vulnerabilities, supply chain attacks, and active exploitation campaigns underscores the need for immediate defensive action. Organizations should prioritize patching NGINX and WordPress installations while enhancing user awareness training to combat sophisticated social engineering tactics.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- HelloCleanerModule for removing ViPNet log data to hide malicious activity
- HelloBackdoorRust-based implant supporting file transfer and command execution on port 443
- HelloInjectorFirst-stage DLL loader (wtsapi32.dll) sideloaded via itcsrvup64.exe
- HelloProxyIn-memory payload communicating with C2 server on ports 5003, 5060
- HelloExecutorBackdoor module supporting command execution and network reconnaissance
- REST API batch-route confusion vulnerability in WordPress Core 6.9+
- SQL injection in 'author__not_in' parameter of WP_Query affecting WordPress 6.8+
wp2shell.comVulnerability testing and information site created by Searchlight Cyber
- GHETTOVIBEVBS file downloaded via PowerShell command, saved to Startup autorun directory
- SCOUTCURLPowerShell reconnaissance script harvesting machine details
- FLUIDLEECHLoader malware masquerading as antivirus software
- LOADLOOPLoader malware deployed via ClickFix campaign
- FREAKYPOLLPython backdoor used in campaign
- COWARDDUCKAndroid backdoor distributed via APK files, collects contacts, files, geolocation
- SMARTAXECustom tool used to dynamically alter web page content and inject malicious CAPTCHAs
steamcommunity[.]comLegitimate domain abused by COWARDDUCK for command/data retrieval