Zero-Day abuses to Active Malware - A week of Real-World exploitation
Executive Summary
Zero-Day abuses to Active Malware - A week of Real-World exploitation
Executive Summary
This week’s threat landscape was marked by a sharp escalation in confirmed, real-world exploitation, as defenders faced both newly weaponized zero-days and the resurfacing of long-standing flaws across enterprise, infrastructure, and open-source ecosystems. The CISA Known Exploited Vulnerabilities (KEV) catalog grew by seven additions, including two flaws in SmarterTools SmarterMail, and single entries affecting Microsoft, Broadcom, Fortinet, GNU InetUtils, and an eight-year-old Linux kernel vulnerability, highlighting the persistent risk posed by unpatched environments. In parallel, the Google Threat Intelligence Group reported active malware campaigns exploiting the critical WinRAR vulnerability CVE-2025-8088 to establish initial access and deliver diverse payloads, while Trend Micro highlighted China-aligned APT activity leveraging the PeckBirdy JScript-based C2 framework including campaigns such as SHADOW-VOID-044, which abused CVE-2020-16040 alongside modular backdoors maintain persistent access across targeted environments.
1. Trending / Critical Vulnerabilities
This week’s threat landscape reflected a broad surge in actively exploited vulnerabilities spanning enterprise software, infrastructure platforms, open-source services, and endpoint environments, as the CISA KEV catalog expanded across both newly weaponized and long-standing flaws. A zero-day security feature bypass in Microsoft Office - CVE-2026-21509 was confirmed as actively exploited, allowing attackers to evade OLE mitigations via crafted documents, while SmarterTools SmarterMail saw continued abuse of both an authentication bypass - CVE-2026-23760 that enabled administrator password resets and SYSTEM-level command execution, and an unrestricted file upload flaw - CVE-2025-52691 that allowed unauthenticated web shell placement and remote code execution. On the infrastructure front, Fortinet’s FortiAnalyzer, FortiManager, FortiOS, and FortiProxy - CVE-2026-24858 were targeted through a FortiCloud SSO authentication bypass exploited as a zero-day, and Broadcom VMware vCenter Server - CVE-2024-37079 resurfaced in the KEV catalog following confirmed in-the-wild abuse of a DCE/RPC out-of-bounds write vulnerability that could lead to remote root compromise. The week also highlighted risks in legacy and open-source environments, with an argument injection flaw in GNU InetUtils telnetd - CVE-2026-24061 enabling remote root login via crafted USER variables, and the long-standing Linux kernel integer overflow “Mutagen Astronomy” - CVE-2018-14634 re-emphasized as a persistent privilege escalation risk across unpatched systems. Together, these developments reinforced the shrinking gap between disclosure and exploitation and the growing importance of KEV-driven prioritization across both modern and legacy technology stacks.
2. Exploit Activity and Mass Scanning Observed on Cytellite Sensors
Cytellite telemetry recorded heightened scanning and active exploitation across internet-facing enterprise and infrastructure platforms, with attackers focusing on a cluster of critical and high-risk vulnerabilities impacting network management, application servers, and embedded devices. Confirmed in-the-wild exploitation included CVE-2025-4632 - Samsung MagicINFO, CVE-2025-31324 - SAP NetWeaver, CVE-2025-22457 - Ivanti Connect Secure, Policy Secure, and ZTA Gateways, CVE-2024-4577 -PHP CGI, CVE-2024-3721 - TBK DVR devices, CVE-2024-3400 -Palo Alto Networks PAN-OS, CVE-2024-47176 - OpenPrinting CUPS, CVE-2024-29973 - Zyxel NAS devices, and CVE-2024-29269 - Telesquare TLR-2005KSH -several of which were already listed in the CISA KEV catalog. Additional attacker interest was observed in CVE-2025-26399 - SolarWinds Web Help Desk, signaling continued probing of enterprise service management platforms and the potential for rapid weaponization of yet-to-be-exploited flaws.
3. Vulnerabilities Abused by Malware
This week’s threat activity was marked by widespread exploitation of the WinRAR vulnerability CVE-2025-8088, with both state-linked and financially motivated actors using the flaw to gain initial access and deliver malware. Russia-nexus groups UNC4895 and APT44 targeted Ukrainian military and government entities, while TEMP. Armageddon sustained campaigns using RAR and HTA-based loaders. The Turla (SUMMIT) group deployed the STOCKSTAY malware suite, and a PRC-linked actor leveraged the vulnerability to deliver POISONIVY. The Google Threat Intelligence Group highlighted “zeroplayer” as an upstream supplier fueling the underground market for WinRAR exploits, amplifying the scale of ongoing campaigns. In parallel, Trend Micro reported China-aligned APT campaigns leveraging the PeckBirdy JScript-based C2 framework, including SHADOW-VOID-044, which abused CVE-2020-16040 alongside modular backdoors and Cobalt Strike to maintain persistent access across targeted environments.
4. Open-Source Software (OSS) vulnerabilities observed this week
This week’s open-source threat activity highlighted a cluster of high-impact vulnerabilities across major package ecosystems, underscoring risk in widely used developer and runtime components. Notable issues included a Denial-of-Service flaw in Protocol Buffers - CVE-2026-0994 on PyPI, a Sandbox Escape vulnerability in SandboxJS - CVE-2026-23830 on npm, and Deserialization of Untrusted Data weaknesses in Apache Karaf Decanter -CVE-2026-24656 on Maven and PHPUnit - CVE-2026-24765 on Packagist. The week also saw attention on a Resource Exhaustion vulnerability in the Go standard library net/url - CVE-2025-61726, reinforcing how core language libraries and popular package managers remain attractive targets for exploitation and supply chain risk.
5. Pre-NVDs vulnerabilities observed this week
This week’s early disclosures spotlighted pre-publication vulnerabilities across cloud, industrial, and web ecosystems, highlighting risks surfacing before formal NVD indexing. Observed issues included an Improper Certificate Validation flaw in Fog-kubevirt-CVE-2026–1530, a Remote SQL Execution vulnerability impacting Johnson Controls platforms-CVE-2026-21654, an Authenticated Arbitrary File Upload weakness in the Restaurt WordPress theme -CVE-2026–22327, and a Local Privilege Escalation via Command Injection in Jetico BestCrypt-CVE-2025-9546. Together, these findings reinforced the importance of monitoring pre-NVD sources and applying mitigations early to reduce exposure across both IT and OT environments.
Conclusion
This week’s developments reinforced how both new and long-standing vulnerabilities are being rapidly weaponized across enterprise, infrastructure, and open-source ecosystems. The convergence of active KEV additions, malware-driven exploitation, and Pre-NVD exposure highlights the shrinking window between disclosure and real-world impact. LOVI empowers security teams to stay ahead of this curve, delivering real-time vulnerability intelligence, exploitation tracking, and prioritized risk insights to turn early warning into decisive action.
For more details, check out the full report.
Explore our Annual Vulnerability Intelligence Report 2025 for deeper insights - Read here: https://www.loginsoft.com/reports/annually/vulnerability-intelligence-report-2025
메타데이터
- post_id
- 62743885acb4
- slug
- zero-day-abuses-to-active-malware-a-week-of-real-world-exploitation-62743885acb4
- url
- https://medium.com/@Loginsoft/zero-day-abuses-to-active-malware-a-week-of-real-world-exploitation-62743885acb4
- canonical_url
- https://medium.com/@Loginsoft/zero-day-abuses-to-active-malware-a-week-of-real-world-exploitation-62743885acb4
- author_url
- https://medium.com/@Loginsoft
- status
- ok
- fetched_at
- 2026-07-15 18:16:01