Weekly review

ThreatNoir Weekend Brief — July 25

2026-07-25Morning8 articles
Audio
Listen to the episode

Morning Review in IT Security — July 25, 2026

July 25, 2026 brings critical security developments across multiple threat vectors, from credential-stuffing breaches affecting genetic data to advanced Active Directory exploitation techniques and the continued proliferation of botnet infrastructure. Today's landscape underscores the evolving sophistication of threat actors and the persistent challenges organizations face in securing identity systems and developer ecosystems.

Spanish DPA Fines 23andMe €2.4M for Credential-Stuffing Breach

Spain's data protection authority has issued a significant enforcement action against genetic testing company 23andMe following a credential-stuffing attack that exposed the genetic data of Spanish users. Source: AEPD (Spain) - PS-00140-2025. The fine reflects regulatory scrutiny of companies handling sensitive personal information and their responsibility to implement adequate protections against account takeover attacks. This enforcement action demonstrates the intersection of privacy compliance and cybersecurity, where breaches of genetic information trigger both regulatory penalties and reputational consequences.

Certighost Exploit Enables Domain Controller Impersonation

Researchers H0j3n and Aniq Fakhrul have released a working exploit demonstrating how low-privileged Active Directory users can obtain a certificate for a Domain Controller and authenticate as that machine, a vulnerability designated CVE-2026-54121. Source: Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller. The flaw, codenamed Certighost, leverages Active Directory Certificate Services to grant attackers directory replication rights, allowing them to retrieve the krbtgt secret through DCSync operations. This represents a critical escalation path from standard user access to domain-wide compromise and demands immediate patching across enterprise environments.

Botnets Rebound Despite Takedown Operations

Despite repeated law enforcement and industry disruption efforts, botnet infrastructure continues to expand at an alarming rate, with approximately one in four compromised IP addresses located in the United States. Source: Despite multiple takedowns, botnets continue to grow. According to Lumen's Black Lotus Labs, botnets such as IPIDEA have rebounded quickly and now exceed their pre-disruption footprints. The persistence of these networks reflects the economic incentives driving their operation and the challenge of achieving lasting disruption against distributed infrastructure.

Hermes AI Agent Automates Attack on Thai Finance Ministry

A threat actor deployed the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activities during an alleged breach of Thailand's Ministry of Finance. Source: Hermes AI agent used to automate attack on Thai Finance Ministry. This incident marks an escalation in how threat actors are leveraging AI-driven tools to expand attack scope and reduce manual operational overhead. The use of automation in post-exploitation phases highlights the risks posed by unpatched infrastructure and the growing sophistication of nation-state threat actors.

Hotel Wi-Fi DNS Hijacking Targets Microsoft 365 Credentials

Threat actors are compromising DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fraudulent Microsoft 365 login pages, harvesting credentials from unsuspecting travelers. Source: Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts. Malicious domains including m365-owa[.]com, ms365-device[.]com, ms365-live[.]com, and owa-ms365[.]com have been identified as part of this campaign. This attack vector exploits the trust users place in hotel networks and the ubiquity of cloud-based productivity tools, making it particularly effective against business travelers.

BlueNoroff Phishing Kit Targets Cryptocurrency Wallets

North Korean threat actors operating the ClickFix-style campaigns have established an active phishing kit impersonating Zoom and Microsoft Teams to conduct social engineering attacks designed to deliver malware. Source: BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery. The group has operationalized trust abuse by combining compromised industry contacts with social engineering tactics, specifically profiling cryptocurrency wallet targets before malware delivery. This campaign demonstrates the continued focus of state-sponsored actors on financial assets and their willingness to invest in sophisticated social engineering infrastructure.

Fake Corepack Site Distributes Infostealer and Proxyware to Developers

A malicious website impersonating Corepack, the Node.js package manager tool, is distributing infostealer malware and proxyware to developers searching for legitimate downloads. Source: Fake Corepack Site Distributes Infostealer and Proxyware to Developers. The fake domain corepack[.]org has been active since early 2026 and recently began serving executable downloads that install OpenShield, a tool that steals browser profiles, SSH keys, and enrolls systems in bandwidth-sharing proxy networks. The attack exploits the transition of Corepack from bundled Node.js distribution to standalone npm package installation, targeting developers who search for installation guidance. Multiple delivery paths on the site distribute both infostealers and adware, indicating a multi-channel monetization strategy. Developers are advised to install Corepack only from the official npm registry using npm install -g corepack and to treat any .exe downloads from unfamiliar domains as suspicious.

Emerging Threats: AI Malware, ICS Vulnerabilities, and Linux Kernel Flaws

Recent security research has identified several noteworthy threats including Dolphin X, an AI-powered malware variant, vulnerabilities in Siemens ROX II industrial switches, a Russian Zimbra webmail espionage campaign, and over 400 Linux kernel vulnerabilities. Source: In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws. These developments span industrial control systems, endpoint security, and core operating system infrastructure, reflecting the breadth of the threat landscape and the ongoing discovery of critical vulnerabilities across technology stacks.

Today's threat environment demands heightened vigilance across identity systems, developer supply chains, and network infrastructure. Organizations should prioritize patching Active Directory Certificate Services, implementing DNS security controls for remote access scenarios, and establishing developer security awareness programs focused on supply chain risks.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Fake Corepack Site Distributes Infostealer and Proxyware to Developers
Domain10
  • corepack[.]org
    Impersonates Corepack, distributes malware
  • nostop[.]go2cloud[.]org
    Part of malware delivery infrastructure
  • yakteam[.]xyz
    Part of malware delivery infrastructure
  • beadpie[.]xyz
    Part of malware delivery infrastructure
  • ukankingwithea[.]com
    Part of malware delivery infrastructure
  • ghabovethec[.]info
    Part of malware delivery infrastructure
  • aifpleasurebeh[.]org
    Part of malware delivery infrastructure
  • moonlighthathel[.]org
    Part of malware delivery infrastructure
  • freevpn[.]win
    Part of malware delivery infrastructure
  • openshield[.]canatrace[.]com
    Part of malware delivery infrastructure
In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws
CVE3
  • Malicious code execution in Siemens ROX II web management task scheduler
  • Arbitrary file disclosure in Siemens ROX II switches
  • Command injection privilege escalation in Siemens ROX II switches
Malware3
  • Dolphin X
    AI-powered infostealer targeting 300+ applications for credential and token theft
  • Everest
    Ransomware group demanding 10M CHF from Stadler Rail
  • Laundry Bear
    Russian state-sponsored APT exploiting Zimbra flaw for espionage