
Daily Cybersecurity News - July 6, 2026
Max Severity Adobe ColdFusion Flaw Now Exploited
Attackers are actively exploiting a critical Adobe ColdFusion bug that lets them take over servers without credentials.
CVE-2026-48282 carries CVSS 9.8 and is actively exploited. The flaw allows unauthenticated remote code execution through a single crafted request.
ColdFusion 2023 and 2025 installations exposed to the internet are affected. Self-hosted and on-prem deployments face the highest risk.
KEVIntel flagged the flaw days after disclosure.
Linux Bad Epoll PoC Released
A new local root exploit for Linux is now public after a researcher published working code for the Bad Epoll flaw.
CVE-2026-46242 is a race condition use-after-free in the epoll subsystem. An unprivileged process can leak kernel memory and hijack control flow through a ROP chain to gain root. CVSS 7.8, with public PoC available.
Affects Linux kernels 6.4 and newer on desktops, servers, and confirmed on Pixel 10 Android devices running 6.6.
PoC succeeds roughly 99 percent of the time on tested systems after widening the narrow timing window.
When Checking the URL Isn't Enough: Device Code Phishing via Microsoft
Attackers are tricking users into completing authentication on a real Microsoft page. The lure arrives in email and directs victims to paste a code into login.microsoftonline.com.
They first request a device code from the Microsoft endpoint, then host a page that shows the code and redirects the user to the official verification page. Once the victim completes MFA there, the attacker polls the token endpoint and receives access and refresh tokens.
The trick reuses a legitimate OAuth flow built for IoT devices. It bypasses domain checks because the final login happens on Microsoft's own site. Campaigns have adapted quickly, shifting from PDF attachments to open redirects on sites like cacoo.com.
The observed activity ran from early April through mid-May 2026 before expanding to targets in Brazil.
Armored Likho Hits Power Grid Targets
Armored Likho is a newly named group hitting government agencies and electric power operators in Russia, Brazil, and Kazakhstan.
Spear-phishing delivers LNK files or archives that fetch payloads from GitHub. They drop the Python BusySnake Stealer for credential theft and now embed reverse SSH tunneling via Go2Tunnel integration.
The group mixes financial theft against individuals with espionage against organizations. It shows possible overlap with the Eagle Werewolf cluster active since 2023.
They shifted tunneling from a standalone tool into the stealer itself for tighter persistence on the same hosts.
North Korean Hackers Target Open Source Developers
North Korean hackers are poisoning open source packages to hit developers building real software.
The PolinRider campaign published over 100 malicious packages across npm, Packagist, Go modules, and Chrome extensions. Attackers compromise maintainer accounts, inject obfuscated JavaScript loaders, and deliver DEV#POPPER RAT plus OmniStealer straight into dev environments.
The play reuses the same Contagious Interview playbook but scales it across four ecosystems at once with hidden loaders in legitimate-looking releases. Overlap with prior Famous Chollima activity is clear from shared tooling and targeting patterns.
Campaign remains active with new packages still appearing as of early July 2026.
Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments
Malicious sites are injecting prompts into web content to hijack autonomous AI agents and trigger crypto transfers.
Attackers embed hidden instructions that instruct the agent to visit a wallet site and approve payments. The technique targets agents browsing freely without human oversight.
This approach reuses classic prompt injection but applies it against agentic workflows instead of chatbots. Researchers saw two separate campaigns using the same pattern.
Researchers tested the attacks against 26 LLMs using a custom autonomous agent and successfully triggered payments from four models.
NetNut botnet takes a hit
FBI and Google knocked down the NetNut residential proxy network, cutting access to roughly 2 million hijacked consumer devices that criminals rented as exit nodes.
They disabled Google accounts tied to command and control, pushed Play Protect detections for the malware SDKs, and seized hundreds of domains including netnut[.]com. The network had served 316 threat clusters in a single recent week.
Infrastructure suffered real degradation, with millions of devices removed from the pool, though the operators linked to a publicly traded Israeli firm remain untouched.
Same infrastructure previously reappeared under new brands after earlier proxy takedowns.