- credential-stuffing attackAttack vector used to compromise 23andMe customer accounts in October 2023
ThreatNoir Weekend Brief — July 25
Morning Review in IT Security — July 25, 2026
July 25, 2026 brings critical security developments across multiple threat vectors, from credential-stuffing breaches affecting genetic data to advanced Active Directory exploitation techniques and the continued proliferation of botnet infrastructure. Today's landscape underscores the evolving sophistication of threat actors and the persistent challenges organizations face in securing identity systems and developer ecosystems.
Spanish DPA Fines 23andMe €2.4M for Credential-Stuffing Breach
Spain's data protection authority has issued a significant enforcement action against genetic testing company 23andMe following a credential-stuffing attack that exposed the genetic data of Spanish users. Source: AEPD (Spain) - PS-00140-2025. The fine reflects regulatory scrutiny of companies handling sensitive personal information and their responsibility to implement adequate protections against account takeover attacks. This enforcement action demonstrates the intersection of privacy compliance and cybersecurity, where breaches of genetic information trigger both regulatory penalties and reputational consequences.
Certighost Exploit Enables Domain Controller Impersonation
Researchers H0j3n and Aniq Fakhrul have released a working exploit demonstrating how low-privileged Active Directory users can obtain a certificate for a Domain Controller and authenticate as that machine, a vulnerability designated CVE-2026-54121. Source: Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller. The flaw, codenamed Certighost, leverages Active Directory Certificate Services to grant attackers directory replication rights, allowing them to retrieve the krbtgt secret through DCSync operations. This represents a critical escalation path from standard user access to domain-wide compromise and demands immediate patching across enterprise environments.
Botnets Rebound Despite Takedown Operations
Despite repeated law enforcement and industry disruption efforts, botnet infrastructure continues to expand at an alarming rate, with approximately one in four compromised IP addresses located in the United States. Source: Despite multiple takedowns, botnets continue to grow. According to Lumen's Black Lotus Labs, botnets such as IPIDEA have rebounded quickly and now exceed their pre-disruption footprints. The persistence of these networks reflects the economic incentives driving their operation and the challenge of achieving lasting disruption against distributed infrastructure.
Hermes AI Agent Automates Attack on Thai Finance Ministry
A threat actor deployed the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activities during an alleged breach of Thailand's Ministry of Finance. Source: Hermes AI agent used to automate attack on Thai Finance Ministry. This incident marks an escalation in how threat actors are leveraging AI-driven tools to expand attack scope and reduce manual operational overhead. The use of automation in post-exploitation phases highlights the risks posed by unpatched infrastructure and the growing sophistication of nation-state threat actors.
Hotel Wi-Fi DNS Hijacking Targets Microsoft 365 Credentials
Threat actors are compromising DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fraudulent Microsoft 365 login pages, harvesting credentials from unsuspecting travelers. Source: Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts. Malicious domains including m365-owa[.]com, ms365-device[.]com, ms365-live[.]com, and owa-ms365[.]com have been identified as part of this campaign. This attack vector exploits the trust users place in hotel networks and the ubiquity of cloud-based productivity tools, making it particularly effective against business travelers.
BlueNoroff Phishing Kit Targets Cryptocurrency Wallets
North Korean threat actors operating the ClickFix-style campaigns have established an active phishing kit impersonating Zoom and Microsoft Teams to conduct social engineering attacks designed to deliver malware. Source: BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery. The group has operationalized trust abuse by combining compromised industry contacts with social engineering tactics, specifically profiling cryptocurrency wallet targets before malware delivery. This campaign demonstrates the continued focus of state-sponsored actors on financial assets and their willingness to invest in sophisticated social engineering infrastructure.
Fake Corepack Site Distributes Infostealer and Proxyware to Developers
A malicious website impersonating Corepack, the Node.js package manager tool, is distributing infostealer malware and proxyware to developers searching for legitimate downloads. Source: Fake Corepack Site Distributes Infostealer and Proxyware to Developers. The fake domain corepack[.]org has been active since early 2026 and recently began serving executable downloads that install OpenShield, a tool that steals browser profiles, SSH keys, and enrolls systems in bandwidth-sharing proxy networks. The attack exploits the transition of Corepack from bundled Node.js distribution to standalone npm package installation, targeting developers who search for installation guidance. Multiple delivery paths on the site distribute both infostealers and adware, indicating a multi-channel monetization strategy. Developers are advised to install Corepack only from the official npm registry using npm install -g corepack and to treat any .exe downloads from unfamiliar domains as suspicious.
Emerging Threats: AI Malware, ICS Vulnerabilities, and Linux Kernel Flaws
Recent security research has identified several noteworthy threats including Dolphin X, an AI-powered malware variant, vulnerabilities in Siemens ROX II industrial switches, a Russian Zimbra webmail espionage campaign, and over 400 Linux kernel vulnerabilities. Source: In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws. These developments span industrial control systems, endpoint security, and core operating system infrastructure, reflecting the breadth of the threat landscape and the ongoing discovery of critical vulnerabilities across technology stacks.
Today's threat environment demands heightened vigilance across identity systems, developer supply chains, and network infrastructure. Organizations should prioritize patching Active Directory Certificate Services, implementing DNS security controls for remote access scenarios, and establishing developer security awareness programs focused on supply chain risks.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Improper authorization vulnerability in Active Directory Certificate Services (AD CS).
118.107.222.232Attacker-controlled infrastructure in Malaysia202.181.27.115Attacker-controlled infrastructure in Hong Kong
ms365-live[.]comFake Microsoft 365 login portal domainowa-ms365[.]comFake Microsoft 365 login portal domainm365-owa[.]comFake Microsoft 365 login portal domainms365-device[.]comFake Microsoft 365 login portal domain
- ClickFixName of the malware campaign/payload used by BlueNoroff.
- ClickFake InterviewName of a related North Korea-aligned threat cluster.
corepack[.]orgImpersonates Corepack, distributes malwarenostop[.]go2cloud[.]orgPart of malware delivery infrastructureyakteam[.]xyzPart of malware delivery infrastructurebeadpie[.]xyzPart of malware delivery infrastructureukankingwithea[.]comPart of malware delivery infrastructureghabovethec[.]infoPart of malware delivery infrastructureaifpleasurebeh[.]orgPart of malware delivery infrastructuremoonlighthathel[.]orgPart of malware delivery infrastructurefreevpn[.]winPart of malware delivery infrastructureopenshield[.]canatrace[.]comPart of malware delivery infrastructure
- Malicious code execution in Siemens ROX II web management task scheduler
- Arbitrary file disclosure in Siemens ROX II switches
- Command injection privilege escalation in Siemens ROX II switches
- Dolphin XAI-powered infostealer targeting 300+ applications for credential and token theft
- EverestRansomware group demanding 10M CHF from Stadler Rail
- Laundry BearRussian state-sponsored APT exploiting Zimbra flaw for espionage