Daily Recap, CISA ordered U.S. agencies to patch an actively exploited LiteSpeed cPanel plugin zero-day within 4 days, while Microsoft released a fix for a SharePoint RCE flaw and KnowledgeDeliver was exploited as a zero-day to deploy web shells. The FBI warned that Silent Ransom is using in-person tactics like operatives inserting USB drives to steal data, and Glassworm’s botnet was disrupted after a takedown of its C2 infrastructure. #LiteSpeed #cPanel #SharePoint #KnowledgeDeliver #SilentRansom #FBI #ShinyHunters #Charter #MuddyWater #DLLsideloading #LA_Metro #Iran #GRU #Russian #Glassworm #C2 #USBdrives
Zero-Days & Patching
- CISA ordered U.S. agencies to patch an actively exploited LiteSpeed cPanel plugin zero-day within 4 days, while Microsoft also shipped a fix for a SharePoint RCE flaw across server versions. – cPanel Fix, LiteSpeed Fix, SharePoint RCE
- KnowledgeDeliver was exploited as a zero-day to deploy web shells, underscoring continued post-compromise abuse of enterprise software. – KnowledgeDeliver
Ransomware & Extortion
- The FBI warned that the Silent Ransom gang is using in-person data theft tactics, including operatives who insert USB drives to steal information. – Silent Ransom, USB Tactics
- Charter confirmed a data breach after extortion pressure from ShinyHunters, adding to the group’s string of high-profile coercion campaigns. – Charter Breach
State-Backed Threats
- MuddyWater used DLL side-loading in an espionage campaign targeting 9 countries, while the LA Metro cyberattack was tied to Iranian state-sponsored hackers. – MuddyWater, LA Metro
- Dutch authorities arrested suspects accused of providing infrastructure for Russian cyber operations, and the Kremlin named a cyber executive with alleged GRU ties to a Security Council role. – Dutch Arrests, Kremlin Pick
Law Enforcement & Theft
- Romanian hacker Marcel was sentenced in the U.S. for selling access to a state network, highlighting the criminal market for stolen footholds. – Romanian Hacker
- Lithuania is investigating the theft of 600,000 state registry records by a foreign actor, pointing to large-scale public-sector data exposure. – Lithuania Records
- Dutch police arrested a suspect linked to the Ajax football club hack, continuing enforcement actions around recent intrusions. – Ajax Hack
Botnets & Malware
- The Glassworm botnet was disrupted after a takedown of its resilient C2 infrastructure, weakening its ability to recover. – Glassworm Botnet
Vulnerability Research & Defense
- Apple open-sourced quantum-resistant encryption code, while RevEng.AI raised $15 million to find flaws and backdoors in software binaries. – Apple Quantum, RevEng.AI
- Anthropic said its Mythos system found more than 10,000 software flaws in its first month, signaling rapid growth in AI-assisted vulnerability discovery. – Mythos Flaws
- SecurityWeek will host an AI Risk Summit on August 11-12 at the Ritz-Carlton, Half Moon Bay, as organizations assess emerging AI threats. – AI Summit
- White House unveiled new federal cybersecurity logging guidance, aiming to improve visibility and incident response across agencies. – Logging Rules
- Windows 11 update KB5089573 was released with performance improvements, continuing Microsoft’s routine platform maintenance. – Win11 Update