Weekly review

ThreatNoir Morning Brief — July 20

2026-07-20Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — July 20, 2026

Today's threat landscape brings critical infrastructure vulnerabilities, nation-state targeting of government networks, and active exploitation campaigns affecting millions of web administrators and Ukrainian users. Organizations must prioritize immediate patching and user awareness as public exploits become available and sophisticated social engineering tactics spread.

Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

F5 has released patches addressing a critical vulnerability in NGINX that allows remote, unauthenticated attackers to trigger a heap buffer overflow in worker processes through crafted HTTP requests. Identified as CVE-2026-42533, this flaw was patched on July 15 across multiple versions including NGINX 1.30.4 (stable), 1.31.3 (mainline), and NGINX Plus 37.0.3.1. Exploitation of this vulnerability can crash or restart worker processes, resulting in denial of service conditions and potentially enabling remote code execution. Organizations running earlier builds must upgrade immediately to mitigate exposure. Source: The Hacker News

Hackers Abuse ViPNet Software to Target Russian Government Agencies

Advanced threat actors have been observed exploiting the update mechanism of ViPNet, a private networking product suite, to compromise Russian organizations including government agencies. The campaign utilizes multiple malware components including HelloBackdoor, HelloCleaner, HelloExecutor, HelloInjector, and HelloProxy to establish persistence and maintain access within targeted networks. This supply chain attack demonstrates how legitimate software update channels can be weaponized to deliver sophisticated payloads to high-value targets. Source: Bleeping Computer

WordPress Core "wp2shell" RCE Flaws Get Public Exploits, Patch Now

Public exploits have been released for critical remote code execution vulnerabilities affecting WordPress Core, designated as CVE-2026-60137 and CVE-2026-63030. The availability of working exploits significantly increases the risk of mass exploitation against unpatched WordPress installations. Website administrators are urged to apply patches immediately to prevent unauthorized code execution on their systems. The rapid public disclosure of functional exploits means that attackers have lowered barriers to launching widespread campaigns against vulnerable sites. Source: Bleeping Computer

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices with Malware

Russian state-sponsored threat actors affiliated with Sandworm and the GRU have deployed the ClickFix social engineering technique to deceive Ukrainian users into executing malware on their own systems. The Computer Emergency Response Team of Ukraine (CERT-UA) has attributed this campaign to UAC-0145, a sub-cluster within the broader Sandworm operation. The attack leverages fake CAPTCHA prompts to trick users into running malicious PowerShell scripts that deploy data-stealing malware including COWARDDUCK, FLUIDLEECH, FREAKYPOLL, GHETTOVIBE, LOADLOOP, SCOUTCURL, and SMARTAXE. This campaign demonstrates the continued effectiveness of social engineering tactics when combined with geopolitical targeting. Source: The Hacker News

The convergence of critical infrastructure vulnerabilities, supply chain attacks, and active exploitation campaigns underscores the need for immediate defensive action. Organizations should prioritize patching NGINX and WordPress installations while enhancing user awareness training to combat sophisticated social engineering tactics.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Hackers abuse ViPNet software to target Russian govt agencies
Malware5
  • HelloCleaner
    Module for removing ViPNet log data to hide malicious activity
  • HelloBackdoor
    Rust-based implant supporting file transfer and command execution on port 443
  • HelloInjector
    First-stage DLL loader (wtsapi32.dll) sideloaded via itcsrvup64.exe
  • HelloProxy
    In-memory payload communicating with C2 server on ports 5003, 5060
  • HelloExecutor
    Backdoor module supporting command execution and network reconnaissance
UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware
Malware7
  • GHETTOVIBE
    VBS file downloaded via PowerShell command, saved to Startup autorun directory
  • SCOUTCURL
    PowerShell reconnaissance script harvesting machine details
  • FLUIDLEECH
    Loader malware masquerading as antivirus software
  • LOADLOOP
    Loader malware deployed via ClickFix campaign
  • FREAKYPOLL
    Python backdoor used in campaign
  • COWARDDUCK
    Android backdoor distributed via APK files, collects contacts, files, geolocation
  • SMARTAXE
    Custom tool used to dynamically alter web page content and inject malicious CAPTCHAs
Domain1
  • steamcommunity[.]com
    Legitimate domain abused by COWARDDUCK for command/data retrieval