Daily Drop (1333)
07-12-26
Sunday, July 12, 2026 // Buy Bob a Coffee // Ghostwire
China Recovers Long March 10B Booster in First Net-Based Orbital Rocket Catch
NOTE:
China's first orbital booster recovery lands as more than a domestic milestone; it recalibrates the international launch competition. With this catch, China joins SpaceX and Blue Origin as the only entities to recover an orbital-class booster — ending a decade in which reusability was an exclusively American capability. That symbolism matters. Reusable launch has been the single largest driver of the cost and cadence gap between US and non-US space access, and its demonstration by a state-owned Chinese enterprise signals that the moat is eroding.
Bottom Line Up Front (BLUF): China successfully launched and recovered the first stage of its new Long March 10B rocket on July 10, 2026, using a sea-based net and cable system. The mission marked China’s first controlled recovery of an orbital-class booster and the first known use of a net-based capture method for an orbital launch vehicle. Chinese officials plan to refly the recovered stage before the end of 2026.
Analyst Comments: The Long March 10B launched from the Wenchang Commercial Space Launch Site at 04:15 UTC on July 10. Roughly 10 minutes later, the first stage descended toward an offshore platform in the South China Sea, where tensioned cables captured hooks mounted on the booster and left the vehicle suspended above the deck. The approximately 63.6-meter rocket uses seven kerosene-fueled YF-100K engines in its first stage and a methane-fueled YF-219 engine in its upper stage. It is designed to carry about 16 metric tons to low-Earth orbit, slightly less than SpaceX’s Falcon 9. The flight also deployed the CX-26 experimental satellite.
READ THE STORY: arsTechnia
Russian-Linked Hackers Allegedly Hijack IP Cameras to Monitor NATO Supply Routes Into Ukraine
Bottom Line Up Front (BLUF): Dutch intelligence reportedly identified a Kremlin-linked operation that compromised internet-connected residential and commercial cameras across NATO member states and Ukraine. The attackers allegedly targeted devices overlooking strategic transport corridors, allowing them to monitor military shipments to Ukraine in near real time.
Analyst Comments: The exposure reflects a familiar Internet of Things problem: inexpensive cameras are widely deployed, rarely updated, and often protected by default or reused credentials. Many are also connected directly to the internet through vendor cloud services or insecure remote-access configurations. A compromised camera may appear insignificant on its own, but hundreds of cameras positioned along the same logistics network can create a persistent surveillance capability.
READ THE STORY: Telegram
South Korean Military Faced Nearly 19,000 Cyberattack Attempts in 2025 as Talent Retention Worsened
Bottom Line Up Front (BLUF): South Korea’s military recorded 18,951 cyberattack attempts in 2025, a five-year high and a 31 percent increase from roughly 14,400 incidents in 2024. Nearly all reported activity targeted military websites, while malicious email campaigns also continued to rise. At the same time, the armed forces are struggling to retain and recruit trained cyber officers, creating a widening gap between operational demand and defensive capacity.
Analyst Comments: The attack count is notable, but volume alone does not reveal how many attempts were sophisticated, successful, or linked to North Korea. The more important signal is the combination of sustained targeting and declining defender retention. South Korea can absorb routine scanning and low-grade intrusion attempts, but persistent state-backed operators benefit when experienced military personnel leave faster than replacements can be trained.
READ THE STORY: The Korean Herald
Italy Alleges Russian Espionage Network Targeted Air-Defense Systems Supplied to Ukraine
Bottom Line Up Front (BLUF): Italian authorities reportedly uncovered a Russian intelligence network seeking classified information on air-defense systems, missiles, and other military technologies connected to Ukraine. Investigators allege that Russian military attaché Mikhail Astakov directed former Italian intelligence officer Gavino Piras, who used cash to recruit sources inside Italy’s armed forces. Italy subsequently expelled two Russian military attachés, including Astakov.
Analyst Comments: The reported collection priorities align with Russia’s immediate operational needs: identifying the capabilities, vulnerabilities, deployment patterns, and future development paths of Western systems supporting Ukraine. Information on SAMP/T, CAMM-ER, Storm Shadow, and emerging Leonardo platforms could support countermeasure development, targeting decisions, electronic-warfare planning, and strategic procurement assessments.
READ THE STORY: Telegram
China- and India-Aligned Threat Actors Target Pakistani Police Systems in Sustained Espionage Campaigns
Bottom Line Up Front (BLUF): SentinelOne researchers identified sustained cyberespionage activity targeting Pakistani law enforcement organizations between February 2024 and April 2026. The campaigns compromised network appliances, email infrastructure, and web applications containing criminal, biometric, personnel, hotel, tenant, and national identity data. At least four intrusion clusters deployed PlugX, ShadowPad, Cobalt Strike, and Remcos RAT, with activity assessed as linked to China- and India-aligned operators.
Analyst Comments: Pakistani law enforcement networks are high-value intelligence targets because they reveal the government’s internal security picture: active investigations, personnel records, biometric data, border-control activity, and assessments of domestic threats. The simultaneous presence of suspected Chinese and Indian operators is not surprising. Both have distinct geopolitical interests in Pakistan, and both benefit from access to the same sensitive institutions.
READ THE STORY: THN
Google Pays $250,000 for KVM Escape Vulnerability Affecting Cloud Hosts
Bottom Line Up Front (BLUF): A security researcher received a $250,000 reward through Google’s kvmCTF program after disclosing a KVM virtual machine escape vulnerability tracked as CVE-2026-53359 and dubbed “Januscape.” The flaw reportedly allows an attacker with code execution inside a guest virtual machine to break isolation and execute arbitrary commands on the underlying Linux host, creating serious risk for cloud, VPS, and multi-tenant environments.
Analyst Comments: A working KVM escape is one of the highest-impact vulnerability classes in cloud security because it undermines the isolation boundary between tenants and the hypervisor. An attacker could rent a low-cost virtual machine, exploit the flaw from inside the guest, and gain control of the physical host. From there, the attacker could potentially access neighboring workloads, steal customer data, compromise management systems, or use the host as a pivot into the wider provider environment. The $250,000 payout reflects the severity of the outcome rather than the size of the code defect. Google’s kvmCTF assigns its highest reward to a complete guest-to-host escape because this type of bug threatens the trust model underpinning public cloud infrastructure. The source states that researchers disclosed the issue responsibly, waited for Linux kernel fixes, and released only limited proof-of-concept material rather than a complete weaponized escape chain. Even so, providers should assume exploit development will continue and prioritize patching and rebooting affected hosts.
READ THE STORY: t00ls (CN)
OpenAI Safety Chief Departs as Company Integrates Safety More Deeply Into Model Research
Bottom Line Up Front (BLUF): OpenAI’s head of safety systems, Johannes Heidecke, is leaving the company as it reorganizes its safety and research functions. According to WIRED, OpenAI’s safety teams will report to Mia Glaese, whose role is expanding to vice president of research and safety, while Saachi Jain will serve as interim head of safety systems.
Analyst Comments: The departure matters less as an isolated personnel change than as part of a broader shift in how OpenAI structures safety oversight. Integrating safety teams directly with frontier-model research could give evaluators earlier access to model development and greater influence over launch decisions. It could also reduce organizational independence if the same leadership chain is responsible for both capability development and safety approval.
READ THE STORY: Wired
Ghost GitHub Accounts Map Organizations in Coordinated Reconnaissance Campaigns
Bottom Line Up Front (BLUF): Datadog identified multiple campaigns using more than 50 dormant GitHub accounts to systematically enumerate organizations, repositories, users, and access relationships through GitHub’s API. Most activity focused on publicly available data and blended with legitimate traffic, but some operations escalated to cloning repositories and accessing private commit paths with exposed user tokens.
Analyst Comments: This is reconnaissance, but it should not be dismissed as harmless scraping. Public GitHub data can reveal an organization’s development structure, active projects, employee relationships, technology stack, and likely high-value repositories. That information can support targeted phishing, credential theft, dependency attacks, and follow-on intrusion planning. The use of accounts created years earlier is a deliberate trust-evasion tactic. Dormant identities are less likely to trigger scrutiny than newly registered accounts, and API calls to public resources return normal HTTP 200 responses instead of authentication failures. That leaves defenders with weak signals unless they are monitoring user agents, request patterns, account age, and changes from normal organizational activity.
READ THE STORY: Security week
Apple Sues OpenAI Over Alleged Theft of Hardware Trade Secrets
Bottom Line Up Front (BLUF): Apple has filed a federal lawsuit accusing OpenAI, its hardware chief Tang Tan, and other defendants of misappropriating confidential hardware designs, prototype information, supplier details, and internal security procedures. Apple alleges that OpenAI encouraged departing employees to bring proprietary materials into its hardware program and coached recruits on how to avoid Apple’s security controls. OpenAI denies having any interest in competitors’ trade secrets.
Analyst Comments: This is a major insider-risk and intellectual-property dispute, not just a talent-poaching case. Apple’s allegations describe a deliberate collection process involving former employees, unreleased components, supplier intelligence, internal presentations, and guidance on evading exit procedures. If substantiated, the case could expose serious weaknesses in how sensitive hardware organizations manage departing personnel, supplier access, and post-employment monitoring. The broader issue is that elite technical hiring increasingly overlaps with trade-secret exposure. Companies building new AI hardware are recruiting from the same small pool of engineers, designers, and suppliers that support established consumer-device manufacturers. That creates a persistent risk that institutional knowledge, prototype details, and manufacturing methods move with employees faster than legal and security controls can respond.
READ THE STORY: Wired
GigaWiper Combines Espionage, Ransomware, and Disk Destruction in a Modular Go Backdoor
Bottom Line Up Front (BLUF): Microsoft has detailed GigaWiper, a Go-based backdoor that combines remote-access functionality with multiple destructive capabilities, including disk wiping, unrecoverable file encryption, and commands that can erase Windows installations. Observed since October 2025, the malware gives operators the flexibility to conduct surveillance, steal data, deploy additional tools, or trigger system-wide destruction on demand.
Analyst Comments: GigaWiper is significant because destruction is not its only purpose. Traditional wipers are often built for a single terminal action: destroy data and render systems unusable. GigaWiper instead provides persistent remote control before the operator decides whether to spy, extort, disrupt, or erase. That flexibility increases the incident-response risk. By the time defenders observe disk wiping, encryption, or forced crashes, the attacker may already have spent weeks collecting data, mapping the environment, and preparing follow-on actions. Recovery planning must therefore account for both destructive impact and prior data compromise.
READ THE STORY: t00ls (CN)
CISA Adds Critical Joomla Extension Flaws to KEV Catalog After Active Exploitation
Bottom Line Up Front (BLUF): CISA added two arbitrary file-upload vulnerabilities affecting the iCagenda and Balbooa Forms Joomla extensions to its Known Exploited Vulnerabilities catalog. Both flaws can enable attackers to upload executable files and achieve remote code execution. U.S. federal civilian agencies must remediate the vulnerabilities by July 13, 2026.
Analyst Comments: CVE-2026-48939 carries a CVSS score of 10.0 and can allow PHP code execution through iCagenda’s attachment functionality. CVE-2026-56291 affects Balbooa Forms and reportedly permits unauthenticated upload of executable files, leading to full remote code execution. Once attackers gain code execution, they can deploy web shells, steal credentials, alter site content, or use the server as infrastructure for follow-on attacks. Organizations running Joomla should treat exposure of either extension as an incident-response priority, not a routine patching task.
READ THE STORY: Security Affairs
Windows Trojan Infects Visual Studio Projects to Spread Through Developer Builds
Bottom Line Up Front (BLUF): Doctor Web researchers identified a multi-stage Windows malware operation that infects C++ and C# development projects to propagate through software builds. The malware adds malicious pre-build instructions to Visual Studio project files, allowing it to execute whenever affected code is compiled. Its capabilities include credential theft, remote access, clipboard hijacking, cryptocurrency mining, persistence, and infection of additional source code and executables.
Analyst Comments: By modifying .vcxproj, .csproj, and related development files, the malware turns trusted developer workflows into a supply-chain distribution mechanism. A compromised workstation can poison internal applications, public repositories, build artifacts, and downstream systems without requiring the attacker to breach each target directly. The use of project-level pre-build events is particularly dangerous because the malicious execution can appear to be part of the normal compilation process. Developers who clone and build an infected repository may trigger the payload before security teams recognize that the source tree itself has been altered.
READ THE STORY: GBhackers
Compromised Jscrambler npm Releases Deploy Cross-Platform Infostealer Against Developer Systems
Bottom Line Up Front (BLUF): Attackers used a compromised npm publishing credential to distribute a Rust-based infostealer through five malicious versions of the jscrambler package: 8.14.0, 8.16.0, 8.17.0, 8.18.0, and 8.20.0. The malware targeted Windows, macOS, and Linux systems, stealing cloud credentials, developer tokens, browser data, password-manager sessions, cryptocurrency wallets, and credentials stored by AI coding tools. Jscrambler and Socket recommend upgrading to version 8.22.0 and treating any system that executed an affected release as compromised.
Analyst Comments: This incident is a direct supply-chain attack on developer workstations and CI infrastructure—the exact environments most likely to hold high-value secrets. The early malicious releases relied on preinstall hooks, but versions 8.18.0 and 8.20.0 reportedly moved the dropper into the package’s main code and command-line interface. That change matters because disabling npm lifecycle scripts or using npm install --ignore-scripts would not prevent execution when the package was imported or run. Defenders should not treat an upgrade as sufficient remediation. Any host that installed or executed an affected version should undergo incident response, credential rotation, persistence checks, and network review. The Linux payload’s apparent eBPF capability also warrants deeper forensic analysis because it may provide functionality beyond conventional userspace credential theft.
READ THE STORY: THN
Ghostcommit Attack Hides Prompt-Injection Payloads in Images to Compromise AI Coding Agents
Bottom Line Up Front (BLUF): ASSET Research Group disclosed “Ghostcommit,” a software supply-chain technique that hides malicious prompt-injection instructions inside PNG images committed to a repository. Text-only code reviewers may ignore the image, allowing the payload to survive review and later manipulate an AI coding agent into reading sensitive files such as .env and encoding their contents into source code.
Analyst Comments: Ghostcommit exposes a control gap in AI-assisted development: security depends as much on the agent harness, repository instructions, and file-processing pipeline as it does on the underlying model. The attack does not need to exploit a conventional software vulnerability. It abuses trusted project context—such as AGENTS.md files—and an agent’s ability to interpret images and access local secrets.
READ THE STORY: CSN
Study Finds Widespread Privacy and Security Failures in Free Android VPN Apps
Bottom Line Up Front (BLUF): Researchers testing 281 popular free Android VPN applications found that many failed to provide the privacy and security users expect from a VPN. Twenty-nine apps leaked traffic outside the encrypted tunnel, 61 transmitted data in plaintext, and five downloaded configuration files without encryption—creating a path for attackers on the same network to redirect users through malicious VPN servers. Apps with at least one identified issue accounted for more than 2.4 billion installations.
Analyst Comments: These findings reinforce a basic reality: a VPN does not eliminate trust—it transfers trust from the internet service provider to the VPN operator. When the application leaks DNS traffic, uses obsolete cryptography, transmits configuration files over HTTP, or embeds advertising trackers, the product can create more risk than it removes.
READ THE STORY: Segu Info
Linux Kernel ptrace Flaw Enables Local Privilege Escalation on Vulnerable Systems
Bottom Line Up Front (BLUF): CVE-2026-46333 is a Linux kernel privilege-management flaw involving __ptrace_may_access() and process teardown behavior. According to a Codeby.net technical analysis, an unprivileged local user may be able to exploit a race condition to access privileged file descriptors, potentially exposing /etc/shadow, SSH host keys, or authenticated D-Bus connections. Public proof-of-concept code is reportedly available, increasing the urgency for organizations running affected kernels.
Analyst Comments: This is a post-compromise escalation issue, not a remote entry point. An attacker first needs local code execution or valid low-privilege access through another vector, such as a vulnerable web application, stolen SSH credentials, or a compromised CI runner. Once inside, however, a reliable kernel-level privilege-escalation primitive can turn a limited foothold into full host compromise.
READ THE STORY: Codeby
Items of interest
From Prompt Engineering to Intent Engineering: AI Workflows Shift From Instructions to Outcomes
Bottom Line Up Front (BLUF): Daniel Miessler argues that users should stop prescribing step-by-step methods to advanced AI systems and instead define the outcome they want. He calls this shift “Intent Engineering”—a prompting approach that gives capable models room to determine the best way to complete a task rather than constraining them with increasingly outdated human workflows.
Analyst Comments: The argument tracks with Sutton’s Bitter Lesson: as general-purpose AI systems improve, handcrafted rules and elaborate prompting frameworks are likely to become less useful—and may actively degrade performance. Detailed instructions still matter when a task has hard constraints, compliance requirements, or a specific operating procedure. But for open-ended analysis, research, coding, and content generation, excessive scaffolding can narrow the model’s reasoning and lock it into a weaker approach. Organizations should review existing prompt libraries and separate genuine requirements from legacy instructions that merely describe how a human would perform the task.
READ THE STORY: Dan Miessler
Prompt Engineering Full Course (Video)
FROM THE MEDIA: Tech with Tim explains what it is, why it's important, how to do it faster. The top techniques and methods and advanced strategies to get the most out of loops.
You SUCK at Prompting AI (Here's the secret) (Video)
FROM THE MEDIA: You’re probably using AI wrong. Don’t worry, it’s not your fault. Most people suck at prompting, but today I’m showing you real prompting techniques I learned from top Coursera prompting courses, official docs from Anthropic/Google/OpenAI, and advice from some of the best prompt engineers in the world.
The selected stories cover a broad range of cyber threats and are intended to help readers frame key publicly discussed threats and improve overall situational awareness. InfoDom Securities does not endorse any third-party claims made in its original material or related links on its sites; the opinions expressed by third parties are theirs alone. For further questions, don’t hesitate to get in touch with InfoDom Securities at dominanceinformation@gmail.com.


