~/greenteam/nerd

Saturday, July 18, 2026

Daily digest

Two high-severity vulnerabilities affecting widely deployed infrastructure — the OpenSSL HollowByte DoS flaw and the Windows LegacyHive local privilege escalation zero-day — demand immediate attention today. Both have public proof-of-concept code available.

cybersec BleepingComputer

New Windows LegacyHive Zero-Day Gives Attackers Admin Privileges

A researcher published a working exploit called LegacyHive that allows local privilege escalation to administrator on fully patched Windows systems. No patch is currently available. The exploit is publicly accessible, lowering the bar for threat actors significantly.

Why it matters: Your Intune-managed Windows 11 fleet is directly exposed — any standard user account that gets compromised (phishing, stealer malware) can now trivially escalate to admin on the endpoint. Monitor for exploit usage and consider tightening endpoint detection rules in Defender for Endpoint immediately while awaiting a Microsoft patch.

cybersec The Hacker News

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests

A denial-of-service vulnerability in OpenSSL, named HollowByte and reported by Okta's Red Team, allows an unauthenticated attacker to permanently consume up to 131 KB of server memory per 11-byte TLS request on glibc-based systems, with memory not recovered until the process restarts. OpenSSL silently shipped a fix in June with no CVE, advisory, or changelog entry flagging the security nature of the change. A full technical writeup and proof-of-concept are now public.

Why it matters: OpenSSL underpins TLS across your Nutanix AHV nodes, AWS GovCloud endpoints, Ansible control plane, and any Linux-based services — all are potentially vulnerable if not on the June or later OpenSSL release. The silent fix means automated patch-gap detection won't catch this without a version audit; run one now and document remediation for NIST 800-171 SI.3 compliance records.

cybersec Dark Reading

Inc Ransomware Exploits SonicWall SMA Zero-Days

The Inc ransomware group is actively chaining two zero-day vulnerabilities in SonicWall Secure Mobile Access appliances to achieve root-level code execution. The flaws are being exploited in the wild, and CISA has issued a patch order.

Why it matters: If SonicWall SMA appliances are part of your remote-access or VPN boundary, this is an active ransomware entry point with root-level impact — patch or isolate immediately. CISA's KEV listing creates a mandatory remediation timeline under federal directives applicable to your environment.

cybersec The Hacker News

ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files

The ACR Stealer infostealer, active since 2024, is being delivered via ClickFix social-engineering lures that trick users into pasting malicious commands into the Windows Run dialog. Once executed, it exfiltrates saved browser credentials, live session tokens, PDFs, Microsoft 365 documents, and files from synced OneDrive and SharePoint folders. Microsoft's Defender Experts team documented the delivery chains this week.

Why it matters: This directly targets M365 files and OneDrive/SharePoint-synced content — exactly the CUI-bearing documents in your GCC High environment. ClickFix attacks bypass most email security controls because the malicious action happens on the endpoint; reinforce user awareness training and consider blocking or monitoring Run dialog execution via Intune or Defender Attack Surface Reduction rules.

cybersec The Hacker News

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

Two WordPress core vulnerabilities, now assigned CVE IDs and collectively dubbed wp2shell, allow an unauthenticated attacker to achieve remote code execution on any WordPress 6.9 or 7.0 installation — no plugins required. A persistent object cache condition has been identified as a complicating factor, and a working proof-of-concept exploit is publicly available.

Why it matters: If any internet-facing WordPress instance runs on your infrastructure or in AWS GovCloud, treat this as a critical priority — a bare default install is fully exploitable with public PoC code in the wild. Patch to the latest WordPress release immediately and audit for signs of compromise.

cybersec The Hacker News

NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

A Go-based botnet named NadMesh, observed in early July, uses Shodan to continuously scan for exposed AI services including Ollama, ComfyUI, Open WebUI, Langflow, n8n, and Gradio. The botnet harvests AWS API keys and Kubernetes tokens from these services; the operator's own dashboard reportedly claims over 3,800 unique AWS keys collected.

Why it matters: If your self-hosted AI stack (Ollama, Open WebUI, or similar) has any internet-accessible interface — even temporarily — NadMesh will find it and attempt to extract AWS GovCloud credentials or Kubernetes tokens. Verify all AI service endpoints are bound to localhost or internal networks only, and audit AWS IAM credential exposure in your GovCloud environment.

cybersec The Register

Attackers Target Critical FortiSandbox Flaws as CISA Issues Patch Order

Command injection vulnerabilities in Fortinet's FortiSandbox have been added to CISA's Known Exploited Vulnerabilities catalog after researchers observed active exploitation attempts. CISA has issued a directive requiring federal agencies to patch within mandated timelines.

Why it matters: CISA KEV listings carry mandatory patching obligations for federal contractors and agencies operating under BOD 22-01 requirements; verify whether FortiSandbox is in your environment and apply patches before the deadline to remain compliant.

cmmc Federal News Network

DoD Plans CMMC Listening Sessions as Questions Swirl Around Review

DoD CIO Kirsten Davies confirmed that the ongoing CMMC program review — now in its first formal meeting stage — could result in outcomes ranging from a complete overhaul to minor adjustments. The Department plans to hold listening sessions to gather industry input as part of the review process.

Why it matters: Any structural changes to CMMC Level 2 requirements could alter your assessment scope, evidence requirements, or timeline — participate in listening sessions if accessible, and avoid locking in long-term compliance architecture decisions until the review's direction becomes clearer.

cybersec The Hacker News

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT

Checkmarx identified seven malicious npm packages impersonating Vite frontend tooling as part of a supply chain campaign called ViteVenom. The packages use a four-tier blockchain-based command-and-control infrastructure spanning the Tron network to deliver a remote access trojan, making C2 traffic extremely difficult to block via traditional domain or IP filtering.

Why it matters: If any developer or automation pipeline in your environment uses npm (including Ansible roles with Node.js dependencies or CI/CD tooling), these packages could be pulled transitively. Audit npm lockfiles for Vite-adjacent packages and ensure software composition analysis is part of your pipeline — a CMMC-relevant supply chain risk under NIST 800-171 SR controls.

cybersec The Hacker News

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft

Expel has attributed the April 2026 DigiCert breach to CylindricalCanine, a subgroup of the Chinese cybercrime cluster GoldenEyeDog (also known as APT-Q-27 and Dragon Breath). The attackers stole code-signing certificates during the intrusion, raising concerns about the potential downstream use of legitimately signed malicious software.

Why it matters: Stolen DigiCert code-signing certificates can be used to bypass application allowlisting and endpoint security controls that trust Microsoft-ecosystem certificate chains — a meaningful risk to your Intune-managed fleet. Monitor for indicators of compromise associated with CylindricalCanine and watch for DigiCert revocation notices affecting certificates in your trust store.

cybersec BleepingComputer

Ernst & Young Discloses Data Breach After Support System Hack

Ernst & Young is notifying customers that attackers compromised a third-party IT support ticketing system used by EY personnel, resulting in a data breach. The scope of exposed data is still being determined.

Why it matters: If EY is your CMMC third-party assessor organization (C3PAO), external auditor, or managed service provider, this breach may have exposed data or credentials shared during assessments or engagements — contact your EY representative to determine whether your organization's data was in scope.

infrastructure The Register

Microsoft Gives Admins Exchange Online Breathing Room on PowerShell Credential Retirement

Microsoft has pushed back the retirement of the PowerShell `-Credential` parameter for Exchange Online from its original deadline to the end of 2026. Admins who rely on basic-auth-style credential passing in Exchange Online PowerShell scripts have additional time to migrate to certificate-based or OAuth authentication methods.

Why it matters: Any Ansible playbooks or PowerShell automation scripts managing Exchange Online in your GCC High tenant that still use `-Credential` authentication need to be migrated before end of 2026 — plan the refactor now rather than scrambling at deadline, and ensure the replacement auth method meets NIST 800-171 IA controls.