Daily Drop (1331)
07-07-26
Tuesday, July 07, 2026 // Buy Bob a Coffee // Ghostwire
BeyondTrust Patches Critical Pre-Auth Bypass Flaws in Remote Support and Privileged Remote Access
Bottom Line Up Front (BLUF): BeyondTrust released patches for four vulnerabilities affecting Remote Support and Privileged Remote Access, including two critical pre-authentication access-control bypass flaws rated CVSS 9.2. Successful exploitation could allow unauthenticated attackers to gain unauthorized access to vulnerable appliances, including accounts with elevated privileges, under specific authentication configurations. Organizations running RS or PRA 25.3.2 or earlier should upgrade to 25.3.3 or later immediately.
Analyst Comments: Remote support and privileged access appliances are not “just another patch.” They sit directly in the administrative control path, which makes pre-auth flaws especially dangerous. If attackers can bypass authentication on these systems, they may inherit the same reach defenders gave the tool for legitimate administration. BeyondTrust says it is not aware of exploitation in the wild, but that should not slow anyone down. RS and PRA have already been targeted in prior campaigns, including exploitation of CVE-2024-12356 and CVE-2026-1731 to deploy web shells and backdoors. That history matters. Attackers know these products are high-value, and critical pre-authentication bugs in remote access infrastructure tend to move from advisory to exploitation quickly.
READ THE STORY: THN
Multiple High-Severity Citrix NetScaler Vulnerabilities: Patch Internet-Facing ADC and Gateway Appliances Immediately
Bottom Line Up Front (BLUF): The Centre for Cybersecurity Belgium is warning organizations to urgently patch six high-severity vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway. The flaws include memory overread, memory overflow, arbitrary file read, and denial-of-service issues, with several exploitable remotely without authentication. NetScaler Gateway sits directly in the authentication and remote access path for many organizations, making exposed appliances high-value targets.
Analyst Comments: These appliances often front VPN, ICA Proxy, AAA, SAML, load balancing, and remote access workflows—meaning compromise or disruption can quickly become an enterprise-wide problem. CVE-2026-8451 is especially concerning because it involves unauthenticated memory overread when NetScaler is configured as a SAML IDP, putting it in the same uncomfortable neighborhood as prior “CitrixBleed”-style risk. CCB does not state that exploitation is confirmed in the wild, but public technical analysis is already available, so exposure windows matter.
READ THE STORY: CCB
Tenda Router Firmware Contains Hidden Admin Backdoor: CERT/CC Warns of Full Device Takeover Risk
Bottom Line Up Front (BLUF): CERT/CC is warning that several Tenda router firmware versions contain an undocumented administrative backdoor tracked as CVE-2026-11405. The flaw allows attackers to bypass normal password verification and gain full admin access to the device web management interface without valid credentials. The issue remains unpatched as of the report, so affected users should disable remote management and reduce exposure immediately.
Analyst Comments: The Hacker News reported that CERT/CC disclosed CVE-2026-11405, an undocumented authentication backdoor affecting multiple Tenda firmware versions. The backdoor exists inside the login() function of the /bin/httpd web server binary. The normal login flow first performs MD5-based password verification, but if authentication fails, the firmware checks an alternate value stored as sys.rzadmin.password. If the supplied password matches that hidden configuration value, the device grants administrator-level access with role=2 and creates a valid elevated session. CERT/CC noted that the associated rzadmin username is not actually validated, meaning any username can succeed when paired with the backdoor password. The mechanism is not documented and is not visible through the administrative interface.
READ THE STORY: THN
AI-Driven CNAPP Platforms in 2026: Cloud Security Tools Still Fail Without Real Detection Workflows
Bottom Line Up Front (BLUF): A Codeby analysis compares five major CNAPP platforms—Wiz, CrowdStrike Falcon Cloud Security, Microsoft Defender for Cloud, Orca Security, and Prisma Cloud—against real-world cloud detection needs. The key finding is blunt: high compliance scores and clean CSPM dashboards do not equal attack-path coverage. Modern cloud intrusions increasingly rely on valid credentials, identity chaining, misconfigured roles, and overlooked storage access, so SOC teams need platforms that correlate posture, identity, runtime telemetry, and SIEM alerts—not just isolated findings.
Analyst Comments: The strongest point in the article is the gap between configuration visibility and exploitability. A CSPM tool can tell you an S3 bucket, IAM policy, or workload is misconfigured. That does not mean it can explain whether an attacker can move from a compromised service account into production, reach sensitive data, disable logging, and exfiltrate storage contents. That attack-path context is where CNAPP platforms are supposed to earn their keep. The trade-off remains familiar. Wiz is strong for fast deployment and graph-based attack-path analysis, but it does not provide inline runtime blocking. CrowdStrike has stronger runtime visibility through its agent model, but deployment and cost are real constraints. Defender for Cloud makes the most sense in Azure-heavy environments, while AWS and GCP coverage requires more work. Orca reduces operational overhead through agentless scanning, but snapshot-based detection is not the same as real-time protection. Prisma Cloud is powerful in mature DevSecOps environments, but the learning curve and operational load are higher.
READ THE STORY: Codeby(RU)
Rare Werewolf Phishing Campaign Uses Fake Contract Thread to Deploy Hidden AnyDesk and Steal Credentials
Bottom Line Up Front (BLUF): Angara MTDR reported a new phishing campaign attributed to Rare Werewolf, also tracked as Rezet or Librarian Ghouls. The campaign uses convincing business-email lures and password-protected archives to deliver a malicious executable disguised as a contract document. Once opened, the payload installs AnyDesk in hidden mode, configures unattended access, extracts saved browser and email credentials, exfiltrates results over attacker-controlled SMTP infrastructure, weakens Windows defenses, and removes many local artifacts.
Analyst Comments: This is not exotic malware, but it is practical, quiet, and effective. Rare Werewolf is leaning on a familiar playbook: business-context phishing, encrypted archives to dodge scanners, legitimate remote access tooling, and credential theft utilities that defenders have seen for years. The social engineering is the real delivery mechanism here. The email mimics normal corporate contract review traffic, uses “Fwd” and “Re” prefixes, references specific contract language, provides an archive password, and even includes a fake security-mail-gateway notice to lower suspicion.
READ THE STORY: habr(RU)
JADEPUFFER Shows Agentic Ransomware Has Arrived: AI-Driven Attack Chain Runs from Exploitation to Destruction
Bottom Line Up Front (BLUF): The Centre for Cybersecurity Belgium is warning organizations to urgently patch six high-severity vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway. The flaws include memory overread, memory overflow, arbitrary file read, and denial-of-service issues, with several exploitable remotely without authentication. NetScaler Gateway sits directly in the authentication and remote access path for many organizations, making exposed appliances high-value targets.
Analyst Comments: Security researchers report that JADEPUFFER represents the first fully documented case of “agentic ransomware,” where an LLM-driven AI Agent executed the attack chain end to end without direct human keyboard control. The operation reportedly abused a patched Langflow vulnerability, harvested credentials, moved through MinIO, MySQL, and Nacos infrastructure, encrypted 1,342 configuration records, and then shifted into destructive database deletion. The real issue is not novel malware—it is the automation of known weaknesses at machine speed.
READ THE STORY: Anquanke (CN)
Oracle PeopleSoft Zero-Day Campaign Hits Nissan: Employee HR and Payroll Data May Be Exposed
Bottom Line Up Front (BLUF): Nissan says a cyberattack tied to Oracle PeopleSoft zero-day CVE-2026-35273 may have exposed personal data belonging to current and former employees in the United States, Brazil, Mexico, and Canada. The potentially affected data includes contact details, bank account information, tax records, government-issued ID numbers, and dependent or beneficiary information. Oracle reportedly warned Nissan that attackers targeted PeopleSoft systems as part of a broader campaign affecting more than 100 organizations.
Analyst Comments: PeopleSoft is exactly the kind of enterprise system attackers love: old, business-critical, full of sensitive HR and payroll data, and often treated as “back office” infrastructure until something breaks. That makes this incident more than a Nissan problem. If the reporting is accurate, CVE-2026-35273 gave attackers a clean path into high-value employee data across multiple organizations.
READ THE STORY: t00ls (CN)
Items of interest
Flock “Vehicle Fingerprint” Expands Surveillance Beyond License Plate Reads
Bottom Line Up Front (BLUF): Bruce Schneier highlights a 2024 Flock presentation showing that the company’s cameras can help law enforcement identify vehicles even without full license plate data. Flock’s “Vehicle Fingerprint” capability reportedly lets officers search for decals, bumper stickers, racks, temporary tags, unique state tags, and vehicles believed to be traveling together.
Analyst Comments: The issue is not just whether police can read plates; it is whether they can build persistent movement profiles from visual features that people do not think of as identifiers. A car with a distinctive bumper sticker, roof rack, dent pattern, temporary tag, or state-specific marker can become trackable even when the plate is missing, obscured, or unknown. Schneier’s comparison to cellphone location correlation is the right frame: once a system can identify objects that repeatedly appear near each other, it can infer relationships, routines, and associations. That is useful for investigations, but it also creates obvious privacy and abuse risks when deployed at scale.
READ THE STORY: Schneier
Flock Cameras: What Your City Isn’t Telling You (Video)
FROM THE MEDIA: Flock Safety's license plate reader network has spread to over 5,000 cities, tracking vehicles with no warrant required. Federal criminal defense attorney Ron Chapman examines the Flock camera surveillance system, the Fourth Amendment questions surrounding it, and the wave of cities now ripping these cameras out.
FLOCK CAMERAS! Everything you NEED TO KNOW (Video)
FROM THE MEDIA: Flock Safety cameras are not just license plate readers. According to Bruce Schneier’s summary of a 2024 company presentation, Flock can also identify vehicles using decals, bumper stickers, racks, temporary tags, unique state tags, and other visual characteristics when full plate data is unavailable. The company calls this a “Vehicle Fingerprint,” giving law enforcement another way to search, track, and correlate vehicles across locations.
The selected stories cover a broad range of cyber threats and are intended to help readers frame key publicly discussed threats and improve overall situational awareness. InfoDom Securities does not endorse any third-party claims made in its original material or related links on its sites; the opinions expressed by third parties are theirs alone. For further questions, don’t hesitate to get in touch with InfoDom Securities at dominanceinformation@gmail.com.


