Interconnected digital blocks representing diverse cybersecurity vulnerabilities and attacks.

Daily Cybersecurity News - July 7, 2026

New Januscape Linux Flaw Allows VM Escape

A 16-year-old Linux kernel bug just surfaced that lets attackers break out of VMs and run code on the host.

The flaw, called Januscape, lives in how the kernel handles certain memory operations. It affects Intel and AMD systems running virtualization. Attackers inside a guest VM can escalate to host-level execution.

Impacts kernels back to 2010. Hits hypervisors on servers and developer machines using KVM or similar setups on both CPU vendors.

The researcher released a PoC that triggers a host kernel panic, while the full guest-to-host escape exploit is being withheld.

BeyondTrust warns of critical flaws in remote access software

BeyondTrust flagged two critical bugs in its Remote Support and Privileged Remote Access tools that let attackers skip authentication entirely.

The flaws sit in the authentication flow. Attackers can reach admin consoles without valid credentials on affected versions.

Remote support deployments and privileged access gateways running unpatched code are exposed. Enterprise environments that rely on these products for technician and admin sessions sit in scope.

The advisory lists specific build numbers that require immediate replacement.

Attackers Vote Themselves 20 Million BONK

Attackers used a governance vote to drain roughly $20 million worth of BONK from BonkDAO.

Holders with a large amount of BONK pushed through a malicious proposal. The move transferred coins directly into their wallets.

This is a classic governance attack on a token DAO where voting power equals control. The exploit required no code break, just enough tokens to win the poll.

BonkDAO called it out on social media after the vote passed.

Source: The Record

The Ghost in the Database Recovering Active ADFS Signing Keys via Machine DPAPI

Microsoft ADFS environments remain a high-value target for identity attackers. Researchers showed how to pull live signing keys straight from the database without touching the filesystem much.

They abused the Machine DPAPI backup mechanism that stores encrypted master keys on disk. From there, the team decrypted the actual ADFS signing material used for SAML assertions.

This revives the Golden SAML path first mapped in 2017. The technique reuses old DPAPI artifacts but targets a different storage layer than prior credential-dumping approaches.

Mandiant demonstrated the technique during a recent red team engagement in an ADFS environment with configuration drift caused by manual certificate rotation and disabled automatic certificate rollover.

RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service

RedWing is a new malware-as-a-service operation renting Android bank fraud tools on Telegram.

Buyers get ready-made packages that take over phones, steal banking logins, and capture one-time codes. Low-skill criminals can deploy it without writing code.

Nothing here is novel. The angle is pure commoditization: packaging known mobile RAT capabilities for quick rental instead of custom builds.

Zimperium researchers tracked active distribution channels running since early 2026 with dozens of rental listings.

Claude Code's Hidden Tracker Was an Experiment

Anthropic says a hidden tracking mechanism in Claude Code was just an internal test.

The mechanism used a hidden Unicode marker to signal information such as specific time zone conditions to Anthropic’s backend. Anthropic said it was an experiment aimed at detecting unauthorized resellers and model distillation. It surfaced after security researchers spotted the behavior and raised flags about data handling.

The disclosure came only after external discovery, which undercuts the "experiment" framing. Vendor-funded explanations often arrive late when something looks off.

Anthropic has not released the test scope or data retention details.

Source: Malwarebytes

Court Filing Shows Device ID Tracked Scattered Spider

FBI traced an alleged Scattered Spider member to a luxury jewelry retailer breach via a persistent Windows device ID.

Microsoft records tied the ID to the attackers' account used for ongoing access in the May 2025 incident. Prosecutors unsealed the complaint linking the identifier to the defendant.

This is evidence gathering, not infrastructure seizure. The operator's location remains unclear and no broader group takedown occurred.

Device ID persisted across account resets, giving investigators the durable link they needed.