TABLE OF CONTENT
This week’s intelligence highlights an intense wave of perimeter exploitation and novel endpoint evasion techniques. Threat actors are weaponizing unpatched edge devices, bypassing WAFs to compromise enterprise HR platforms, leveraging native Windows pipes to bypass EDR memory hooks, and exploiting deep CPU microarchitecture flaws to leak kernel secrets.
SISA Weekly Threat Watch – our weekly feature brings to you a quick snapshot of all the major security vulnerabilities that posed a threat to organizations worldwide. These recurring actionable threat advisories will also provide information and recommendations that will help security teams take appropriate actions to defend against the latest and critical threats.
1. Zero-Days & Critical Edge Perimeter Exploitation
Edge network appliances and perimeter firewalls are under active, critical bombardment from unauthenticated threat actors executing remote code and deploying advanced RATs.
- Citrix NetScaler 0-Days & PAN GlobalProtect Exploitation — Two unpatched RCE zero-days (CVE-2026-88771, CVE-2026-88772) in Citrix NetScaler ADC/Gateway are being actively exploited in the wild alongside Palo Alto GlobalProtect authentication bypasses. Attackers are routing compromised access into "Operation Master," a multi-tiered monetization pipeline utilizing AdaptixC2, DNS tunneling, and serverless PIX payment proxies for automated invoice fraud.
- Fortinet FortiMail Zero-Day (CVE-2026-104286) — Actively exploited in the wild, this CVSS 9.8 flaw combines path traversal and NULL byte injection in the FortiMail Web UI (
/ibe). Unauthenticated attackers can bypass directory restrictions to write arbitrary files, resulting in full system compromise and the creation of rogue archive accounts for data exfiltration. - Cisco SD-WAN & Zimbra RCE Exploitation — An unauthenticated authentication bypass (CVE-2026-76504, CVSS 9.8) in Cisco Catalyst SD-WAN Manager is under active exploitation via URI-encoded requests. Concurrently, attackers are exploiting a Zimbra SNMP notification path (CVE-2026-73570) via SMTP to execute arbitrary code, deploy JSP webshells, and hijack
sudoprivileges.
2. EDR Evasion & Stealth Execution Techniques
Adversaries are actively bypassing and inverting endpoint security controls using novel injection methods, code-bound decryption, and legitimate application abuse.
- InjectSetConsole (Console Named-Pipe Injection) — A novel remote process injection technique completely bypasses EDR hooks on
WriteProcessMemoryandVirtualAllocEx. The injector streams encoded shellcode through the standard input (hStdInput) named pipe of an interactive console process (likenetsh.exe), changes memory protection to executable viaVirtualProtectEx, and hijacks the thread context. - NeedyMantis & 2CLoader Frameworks — The China-aligned
NeedyMantisframework uses custom archives and WebSockets C2 for deep post-compromise persistence. Meanwhile, the2CLoaderdropper relies on "code-bound decryption"—using its own raw opcodes to derive decryption keys—and employs Hell's Gate indirect syscalls and trampoline hooks to evade EDRs and deliver stealers like Vidar. - Advanced Side-Loading (SectopRAT, OpenSUpdater, SilverFox) — Threat actors are shifting to fileless execution and open-source tampering.
SectopRATexecutes shellcode via Windows callback APIs (EnumSystemCodePagesW) hidden in audio software.OpenSUpdatermodifies recompiled 7-Zip SFX stubs and bloats certificates to evade static analysis.SilverFoxutilizes signed KuGou executables to sideload malicious DLLs delivered via WhatsApp lures.
3. Enterprise App Exploitation & Cloud Espionage
Vulnerabilities deep within enterprise platforms and collaboration servers are providing attackers with silent pathways to full domain control and ransomware deployment.
- UNC6240 Oracle PeopleSoft Exploitation — The ShinyHunters-linked UNC6240 group is bypassing perimeter WAFs by URL-encoding HTTP request paths (
/%50SEMHUB/) to exploit a critical Java deserialization flaw (CVE-2026-35273) in PeopleSoft. The attackers drop dual obfuscated JSP web shells to deploy theSIDEEYEC++ backdoor and MeshAgent RMM. - Warlock Ransomware & UAT-11587 Espionage — The China-nexus Warlock group exploits Microsoft SharePoint to steal ASP.NET machine keys, achieving RCE and utilizing BYOVD tactics before distributing ransomware domain-wide via SYSVOL replication. Concurrently, the UAT-11587 campaign uses the
AntinoRust backdoor to route all C2 traffic exclusively through Microsoft Graph API, utilizing Outlook and OneDrive as network-invisible dead drops. - BotHelper & AgtaBackup RATs —
BotHelperdecrypts its payload in memory using a position-dependent XOR routine, patches AMSI, and streams live desktop video via HTTP.AgtaBackupuses fake Microsoft Store pages to deploy legitimately signed RMM installers (ScreenConnect/LogMeIn) to gainSYSTEMprivileges, dropping a RAT disguised asCredential Guard.exeand tampering with Service SDDLs to hide from local administrators.
4. OS, Kernel & CPU Microarchitecture Flaws
Deep architectural vulnerabilities in modern CPUs and operating systems are exposing core infrastructure to privilege escalation and side-channel memory leaks.
- Branch Target Reuse (BTR) CPU Flaw — A novel Spectre-v2 variant targeting JIT compilers across Intel, AMD, and Arm CPUs. By abusing stale Branch Target Buffer (BTB) entries during JIT cache re-allocations, local attackers achieve "speculative execute-after-free" primitives, leaking sensitive kernel memory (like root password hashes) at 8 bytes/second.
- Multi-Platform Criticals (TeamViewer, WatchGuard, macOS, Linux) — TeamViewer disclosed a CVSS 8.8 access-control bypass (CVE-2026-92370) allowing remote session hijacking. WatchGuard APs face CVSS 9.3 unauthenticated API command injection. Apple addressed an out-of-bounds write in macOS CoreGraphics, and the Linux kernel patched a critical out-of-bounds write (CVE-2026-72018) in the SMC-D/DIBS loopback module enabling local privilege escalation to root.
- Debian Linux Kernel Security Rollup — Debian 13 ("Trixie") received a massive security rollup (DSA-6528-1) addressing 1,313 historical and current CVEs within the 6.12 kernel tree, mitigating extensive LPE and DoS vectors.
Proactive Steps for the Week
- Isolate NetScaler & Patch Edge Devices: Immediately evaluate taking unpatched Citrix NetScaler appliances offline or isolating them until emergency zero-day patches are available. Apply updates for FortiMail (disabling IBE as a workaround), Cisco SD-WAN Manager, and Zimbra mail servers. Upgrade WatchGuard AP firmware to 3.4.8.
- Harden WAFs & Web Servers: Configure WAFs, reverse proxies, and load balancers to perform full URL decoding and path normalization before evaluating access control rules to block encoded bypass attempts like
/%50SEMHUB/against Oracle PeopleSoft. - Monitor Process Injection & EDR Evasion: Deploy EDR behavioral detections hunting for non-standard applications spawning interactive console processes (
netsh.exe,nslookup.exe) with redirected standard input handles (STARTF_USESTDHANDLES) to catch theInjectSetConsoletechnique. Enforce WDAC/AppLocker to restrict execution from user-writable directories. - Restrict RMM Tools & Service SDDLs: Maintain a strict inventory of authorized RMM software. Implement application control to block unauthorized instances of ConnectWise, LogMeIn, and MeshAgent. Monitor endpoint telemetry for non-standard SDDL modifications applied to Windows services.
- Deploy OS & Kernel Mitigations: Upgrade host Linux kernels to incorporate IBPB flushing during BPF JIT allocations to mitigate the BTR CPU flaw, and apply Debian's DSA-6528-1 rollup. Apply patches for macOS Tahoe 26.7.1 / Sequoia 15.8.1, and update TeamViewer to 15.82+.
