- RefluXFS Linux kernel vulnerability
ThreatNoir Afternoon Brief — July 23
Afternoon Review in IT Security — July 23, 2026
The security landscape continues to evolve with critical vulnerabilities emerging across multiple platforms and threat actors maintaining sophisticated operational capabilities. Today's briefing covers a nine-year-old Linux kernel flaw, an evolving malware variant leveraging DNS for command and control, a zero-day exploitation campaign targeting security appliances, and coordinated Iranian activity targeting industrial control systems.
New RefluXFS Linux Flaw Lets Attackers Gain Root Privileges
A critical race condition vulnerability in the Linux kernel's XFS filesystem has been identified after nine years in the wild. Tracked as CVE-2026-64600, this flaw allows local attackers to overwrite protected files and escalate privileges to root level on affected systems. The vulnerability represents a significant risk to Linux deployments that rely on XFS for storage management, particularly in multi-user environments where local access may be available to unprivileged users. Source: Bleeping Computer
New TrickBot Variant Spotted Using DNS to Control Infected Windows PCs
Fortinet researchers have identified a new variant of the TrickBot malware family that employs DNS traffic for command and control communications. The variant uses scheduled tasks and additional modules to maintain persistence on compromised Windows systems while evading traditional network-based detection methods. This evolution in TrickBot's operational tradecraft demonstrates the malware's continued development and adaptation to security controls. Associated indicators include the domain westurn.in and the malware variants TrickBot and W64/TrickBot.WC!tr. Source: Hackread
New Check Point Zero-Day Vulnerability Exploited in the Wild
A zero-day vulnerability in Check Point security appliances, designated CVE-2026-16232, is actively being exploited against customers with specific configurations. The vulnerability grants attackers administrative access to affected devices prior to patch availability. Additional related CVEs including CVE-2024-24919, CVE-2026-50751, CVE-2026-62144, and CVE-2026-62145 have also been identified in the security advisory. This exploitation campaign highlights the critical importance of prompt patching and configuration review for security infrastructure components. Source: SecurityWeek
US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices
Federal agencies have issued an updated advisory detailing techniques employed by Iranian threat actors targeting industrial control systems from major manufacturers including Siemens, Schneider Electric, and Rockwell Automation. The advisory provides technical details on how programmable logic controllers are being compromised. Threat actors associated with the CyberAv3ngers and Handala groups are leveraging techniques including web shell implantation and data exfiltration against exposed ICS and SCADA devices in critical infrastructure environments. Source: SecurityWeek
Organizations should prioritize vulnerability assessments for Linux XFS implementations, review endpoint detection and response capabilities for DNS-based command and control patterns, expedite patching of Check Point appliances, and implement network segmentation for industrial control systems to limit exposure to external threats.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- W64/TrickBot.WC!trDetection signature used by Fortinet antivirus for identified TrickBot samples
- TrickBotBanking trojan/modular malware platform using DNS tunneling for C2 communication
8.8.8.8Google Public DNS abused by TrickBot for command exfiltration via DNS queries
westurn.inCommand and control domain used by TrickBot variant for DNS tunneling
- Critical authentication bypass and privilege escalation flaw in Check Point Security Management and Multi-Domain Management.
- Zero-day vulnerability in Check Point Security Management and Multi-Domain Management products.
- Previously exploited zero-day in Check Point products.
- Previously exploited vulnerability in Check Point products.
- High-severity local privilege escalation flaw in Check Point Firewall, Multi-Domain Management, and Multi-Domain Log Server.