~/greenteam/nerd

Weekly review

Week of July 6-12, 2026

A historically record-breaking week in vulnerability volume — July 2026 Patch Tuesday alone addressed 622 CVEs — coincided with the Pentagon's suspension of CMMC Phase 2 third-party assessment requirements, reshaping both the technical and compliance landscapes simultaneously. Ransomware actors escalated EDR-evasion tactics with Microsoft-signed malicious kernel drivers, while multiple unpatched or newly disclosed flaws across SharePoint, KVM hypervisors, SonicWall, FortiSandbox, WordPress, and Adobe ColdFusion kept patch queues overflowing.

What you might have missed

Stories not surfaced in this week's daily digests.

cybersec Dark Reading / Symantec Threat Hunter Team

GodDamn Ransomware Uses Microsoft-Signed PoisonX Kernel Driver to Blind EDR Before Encryption

Symantec disclosed on July 9 that the Hyadina ransomware group deployed a newly rebranded locker called GodDamn against U.S. organizations, using a Microsoft Hardware Compatibility Publisher-signed kernel driver called PoisonX to forcibly terminate endpoint security processes at the kernel level before encrypting at least 10 hosts. Unlike typical BYOVD attacks that abuse an existing vulnerable driver, PoisonX appears to be a purpose-built malicious driver that its author succeeded in getting legitimately signed by Microsoft. The campaign used AnyDesk, PsExec, Mimikatz, and 13 NirSoft credential-harvesting tools alongside the driver, following a deliberate multi-week intrusion pattern.

Why it matters: PoisonX is a purposely malicious driver that cleared Microsoft's signing process, meaning Microsoft's Vulnerable Driver Blocklist will not block it until manually updated — organizations cannot rely on default HVCI/blocklist settings and must verify HVCI is active and monitor kernel driver load events independently of their EDR agent.

infrastructure BleepingComputer

Januscape (CVE-2026-53359): 16-Year-Old Linux KVM Flaw Enables Guest-to-Host VM Escape on Intel and AMD

Security researcher Hyunwoo Kim disclosed CVE-2026-53359, dubbed Januscape, a use-after-free vulnerability in the Linux KVM shadow MMU code present since kernel 2.6.36 (August 2010) that allows a guest VM with root access to corrupt host kernel memory, panic the host, or — via an unreleased exploit — execute code as root on the host and take over all co-tenant VMs. The flaw is the first known KVM guest-to-host exploit triggerable on both Intel and AMD x86 architectures, and a public proof-of-concept that reliably crashes the host is already available. The mainline kernel patch (commit 81ccda30b4e8) landed June 19; stable kernel releases shipped July 4, but downstream distribution backports vary and many enterprise KVM hosts remain unpatched.

Why it matters: Any x86 KVM host running nested virtualization is vulnerable to a single rented cloud instance crashing the entire physical host or, with the withheld full exploit, achieving root code execution across all co-tenant VMs — a critical priority for organizations running on-premises KVM clusters or multi-tenant private clouds.

cybersec BleepingComputer / CISA

Adobe ColdFusion CVE-2026-48282 (CVSS 10.0) Exploited Within Hours of Disclosure; CISA Issued 3-Day Patch Deadline

CISA added CVE-2026-48282, a maximum-severity path traversal vulnerability in Adobe ColdFusion, to the Known Exploited Vulnerabilities catalog on July 7 after honeypot sensors detected active exploitation attempts within minutes of a public watchTowr technical analysis. The flaw affects ColdFusion 2025 Update 9 and earlier and 2023 Update 20 and earlier, allows unauthenticated remote code execution by uploading a malicious file to an internet-facing server where RDS is enabled, and carries no authentication requirement. Federal civilian agencies were required to patch by July 10 under BOD 26-04, and Adobe recommends updating to ColdFusion 2025 Update 10 or 2023 Update 21 immediately.

Why it matters: ColdFusion is a recurring high-value target for attackers due to its deep integration with enterprise backend systems, and the three-day federal remediation deadline — the shortest possible under BOD 26-04 — combined with exploitation starting within two hours of disclosure means any unpatched internet-facing ColdFusion instance should be treated as likely already compromised.

cybersec Kaspersky Securelist

GoSerpent: Five-Year APAC Government Espionage Campaign Targeting Police Biometric Databases and Diplomatic Networks Disclosed

Kaspersky GReAT disclosed on July 17 that a sophisticated Go-based backdoor campaign called GoSerpent has been silently operating against Southeast Asian government and diplomatic entities since at least 2021, harvesting police complaint management systems, biometric databases, criminal case files, and diplomatic records. The attackers used an extreme patience model — deploying credential-dumping tools first, waiting weeks for ThumbcacheService to silently accumulate files, then returning in May 2026 with Stowaway RAT and the TmcLoader/TmcPayload exfiltration chain that transferred stolen data through internal network shares using previously stolen credentials, making traffic appear as authorized employee access. Kaspersky found overlaps with the TetrisPhantom threat actor but definitive attribution remains uncertain.

Why it matters: The campaign's core technique — using stolen internal credentials to exfiltrate via authenticated network share traffic — evades standard network monitoring that treats internal authenticated traffic as benign, making it a directly applicable detection gap for any organization relying primarily on perimeter or external-traffic anomaly alerting.

cmmc Government Contracts Law / McCarter & English

DoD CMMC Reform RFI Closes August 14 — Industry Has Six Weeks to Shape Post-Suspension Framework

Alongside the July 13 CMMC Phase 2 suspension, the DoD published a formal Request for Information seeking direct feedback from Defense Industrial Base companies on seven specific questions covering compliance cost drivers, administrative burdens, security controls that provide meaningful cyber uplift, commercial cybersecurity tool alternatives, and policy reforms actionable within 60 days. The RFI responses feed directly into the CMMC Reform Task Force, which must deliver recommendations within 60 days and could recommend outcomes ranging from minor tweaks to termination of the current program. Responses are due by 12:00 PM ET on August 14, 2026, and must be submitted electronically — legal analysts note the RFI window is the rare moment when contractor cost data can directly move policy.

Why it matters: The August 14 RFI deadline is the single most actionable item of the entire CMMC suspension week — defense contractors and their IT service providers who fail to submit input risk having the reformed framework shaped entirely by larger primes, while smaller voices that the suspension was ostensibly designed to protect go unrepresented.

Themes this week

Patterns observed across coverage.

Trusted Infrastructure as the New Attack Surface

This week repeatedly demonstrated that attackers are compromising components previously placed in a trusted-by-design category: a Microsoft-signed kernel driver (PoisonX/GodDamn), the UEFI shim trust database (11 revoked but still-trusted bootloaders), the KVM hypervisor isolation layer (Januscape), UEFI Secure Boot (forgotten shim bootloaders), and the OpenSSL TLS stack (HollowByte). The pattern — original design components, long-term stability, high privilege — has emerged as a distinct risk category that sits outside standard CVE-driven patch management workflows.

ClickFix as the Dominant Social Engineering Delivery Rail

At least three separate malware families covered this week — ACR Stealer, TELEPUZ, and multiple phishing chains — all use ClickFix, the technique of tricking users into pasting malicious commands into the Windows Run dialog. The proliferation of independent threat actors converging on the same delivery mechanism suggests ClickFix has crossed from novel technique to commoditized delivery rail, warranting dedicated user awareness training and Run dialog restriction policies rather than per-campaign response.

CMMC at an Existential Inflection Point

The week's CMMC storyline moved from initial suspension shock (July 14) to the first Reform Task Force meeting (July 16) to listening session planning (July 17-19), revealing a program whose Phase 2 and beyond are fully frozen, whose assessor ecosystem (roughly 100 C3PAOs vs. 100,000+ contractors needing assessment) was structurally unworkable, and whose legal status remains ambiguous since no DFARS rule was amended. The August 14 RFI deadline and the task force's 60-day clock mean the program's future architecture will be largely determined by September 2026.

AI as Both Attack Accelerant and Vulnerability Multiplier

Multiple stories this week converged on AI's dual role: Microsoft attributed the record 622-CVE Patch Tuesday volume partly to AI-assisted vulnerability research; the AI-generated PowerShell AD enumeration script documented in the wild lowers the skill floor for internal reconnaissance; the NadMesh botnet actively scans and harvests credentials from exposed AI services; and the Gold Eagle White House initiative attempts to centralize AI-driven vulnerability discovery at the federal level. AI is simultaneously expanding the vulnerability surface, compressing attacker dwell times, and beginning to shape government vulnerability coordination policy.

Suggested new sources

Worth considering for your feed list. Review and add manually.

tl;dr sec (Clint Gibler)

Curated security research, offensive/defensive tooling, AppSec, and cloud security — weekly newsletter format with deep research links

The existing digest feeds cover breaking news well but lack deep research curation; tl;dr sec systematically surfaces practitioner-grade security research, conference talks, and tool releases — including supply chain, cloud, and identity content — that rarely makes it into news-oriented RSS feeds, and would have flagged the Januscape, PoisonX BYOVD, and OAuth spoofing research early.

RSS: https://rss.beehiiv.com/feeds/xgT9DKBpgmfHWjcbpfN7ek.xml

Risky Business News (Patrick Gray)

Concise daily cybersecurity news briefings with editorial context on threat intelligence, geopolitics, and enterprise security strategy

Risky Business News provides tightly edited daily news briefs with stronger geopolitical and nation-state context than the current digest sources, which would complement BleepingComputer's technical depth — the Russia-GRU router advisory, EU-UK sanctions coordination, and DigiCert/GoldenEyeDog attribution threads all received sharper strategic framing in Risky Biz coverage.

RSS: https://risky.biz/feeds/risky-biz-news.xml

DefenseScoop

DoD technology policy, defense IT acquisition, CMMC, and federal cybersecurity — written specifically for the defense technology community

The existing CMMC coverage relies on Federal News Network, which covers all of federal IT broadly; DefenseScoop is dedicated to the defense technology and acquisition beat and broke several CMMC suspension details — including the assessor math quote and the Cyber AB not being notified before the announcement — that did not appear in the digest's FNN coverage.

RSS: https://defensescoop.com/feed/

Past reviews