CyberNews: 24/07/2026 Edition

Published by Dunateo on 2026-07-24

Today’s roundup

  • Clop ransomware targets Windchill, FlexPLM in data theft attacks
  • New Dolphin X malware uses AI to rank high-value targets
  • Australian energy provider Origin says data breach exposes client data
  • Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry
  • Golden Chickens Resurfaces With Four New Malware Families and Modular Implants
  • NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats
  • Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say
  • Hotel Wi-Fi Routers Compromised to Steal Corporate Login Credentials From Visitors
  • UAC-0099 Is Now Hiding Malware Inside a Fake Notepad++ Plugin to Target Ukrainian Organizations
  • U.S. CISA adds Microsoft SharePoint and Check Point SmartConsole flaws to its Known Exploited Vulnerabilities catalog
  • Summary

    The Clop ransomware group is now targeting internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. This marks an expansion of their tactics to include industrial product lifecycle management software.

    A novel remote access trojan (RAT) named Dolphin X has emerged, featuring an AI-powered profiling capability. This allows cybercriminals to score and rank infected users to identify high-value targets for prioritized exploitation.

    Australian energy provider Origin Energy has confirmed a data breach where an unauthorized party accessed and leaked customer data online. The incident exposed sensitive personally identifiable information (PII) of its clients.

    An attacker reportedly deployed a Hermes AI assistant on a rented server, disabling its permission-asking feature for risky commands, and directed it at Thailand's Ministry of Finance network. The AI agent autonomously conducted post-exploitation activities, including hunting for root access and searching file systems.

    The Golden Chickens malware-as-a-service (MaaS) ecosystem has reappeared with four new malware families: TinyEgg, ChonkyChicken, a modularized ChonkyChicken variant, and a modified web browser credential stealer. This indicates continued development despite previous public disclosures.

    NodeBB, a forum software, has patched eight high-severity security flaws, including those exposing administrative access and private chats. These vulnerabilities were discovered by Aikido Security's AI pentest agents during a six-hour source code review, affecting all versions prior to 4.14.0.

    Redis released seven security updates on July 23 after Kimi K3 AI agents reportedly discovered multiple authenticated Remote Code Execution (RCE) zero-days and developed Proof-of-Concept exploits for Redis versions 6.2.22, 7.4.9, 8.6.4, and 8.8.0. The underlying memory flaws could lead to remote code execution.

    Widespread DNS poisoning attacks have been identified targeting the hospitality sector, compromising hotel Wi-Fi routers. Researchers at ReliaQuest warn this cyber espionage campaign aims to steal corporate login credentials from visiting professionals.

    The Russia-aligned threat actor UAC-0099 is distributing malware via a fake Notepad++ plugin in a new phishing campaign targeting Ukrainian organizations. The attack chain leverages a VBScript to install a trojanized Notepad++ bundle containing LUNCHPOKE, BURNYBEAR, and MATCHBOIL.V2, with BURNYBEAR exhibiting anti-analysis behavior.

    The U.S. CISA has added a critical Check Point SmartConsole Improper Authentication Vulnerability (CVE-2026-16232, CVSS 9.3) to its Known Exploited Vulnerabilities catalog. The flaw allows unauthenticated remote attackers to obtain an application login token and gain full administrative access, with CISA ordering federal agencies to patch by July 25, 2026.

    Want to dig deeper?

    Vulnerabilities

    CVE-2026-16232 Critical