Threat Alerts
Your place for the latest CyberProof cyber threat intelligence alerts and updates
Speak with an ExpertStarland RAT Distributed via Trojanized Installers
A financially motivated actor is distributing a Python-based remote access trojan named Starland via trojanized installers bundled with legitimate apps (WebEx, Zoom, MobaXterm, DBeaver, FACEIT), enabling credential and cryptocurrency theft and persistent remote access.
The multi-stage chain frequently begins with an HTA delivered through ClickFix-style prompts that runs via mshta.exe. The HTA retrieves an NSIS trojanized installer that bundles pythonw.exe and a compiled loader disguised as LICENSE.txt; the loader XOR-decrypts and executes Starland in memory. Starland performs anti-analysis checks, establishes persistence, scheduled tasks and Startup LNKs, attempts UAC elevation, performs host and Active Directory reconnaissance, enumerates browser and desktop/extension cryptocurrency wallets, captures screenshots, and can stage shellcode or download additional payloads.
Command-and-control uses a hardcoded C2 with a blockchain-anchored fallback retrieved via a Polygon JSON-RPC call and sends execution beacons to Telegram bots. A separate PowerShell in-memory C2 implant implements encrypted beaconing, HWID binding, and a Runspace task engine to deliver further scripts. Successful compromises can yield long-lived remote access, credential and wallet theft, reconnaissance of domain environments, and follow-on payload execution while minimizing disk artifacts and complicating detection.
Critical Zoom Windows Account Takeover Vulnerability
A critical Windows vulnerability in Zoom clients can allow unauthenticated attackers to hijack user accounts over the network, creating high-impact risks to confidentiality, integrity, and availability of affected endpoints and corporate accounts.
The flaw, tracked as CVE-2026-53412(CVSS Score 9.8), stems from improper input validation in Windows Zoom Desktop/Workplace and certain VDI client builds and can be exploited via network access to perform account takeover without prior authentication. Multiple Windows branches and legacy client versions are affected.
ACR Stealer Abuses WebDAV Shares and ClickFix for Credential Theft
ACR Stealer is an information-stealing malware family that targets Windows systems to steal credentials, browser session cookies, and other sensitive data while establishing persistent remote access. Successful compromise enables account takeover, unauthorized access to enterprise applications, and provides a foothold for additional payload deployment or follow-on intrusion activity. Recent campaigns have increasingly targeted enterprise environments using ClickFix-themed social engineering and trusted Windows components to evade detection.
The attack chain begins with ClickFix lures directing victims to attacker-controlled WebDAV shares, where malicious DLLs are executed directly from the remote location through the legitimate Windows utility rundll32.exe, eliminating the need to stage a traditional executable on disk. Execution deploys Python-based loaders that retrieve additional payloads, establish encrypted command-and-control communications, and exfiltrate credentials, browser session cookies, and other collected information
LegacyHive Windows Zero-Day Local Privilege Escalation Vulnerability
LegacyHive is an unpatched Windows local privilege escalation vulnerability that abuses the User Profile Service to load attacker-controlled registry hives. Successful exploitation enables attackers with local code execution and valid user credentials to access another user’s registry hive, creating opportunities for privilege escalation, persistence, and post-compromise activity. The vulnerability affects fully patched Windows desktop and server systems, and no Microsoft security update is currently available.
Microsoft Addresses Two Exploited Zero-Days and SharePoint Flaws
Microsoft has released its July Patch Tuesday updates, addressing a record 622 vulnerabilities across Windows, Microsoft Office, Active Directory, and SharePoint Server. The release includes two zero-day vulnerabilities that are actively exploited in the wild, making this month’s updates a high priority for organizations.
The exploited vulnerabilities include CVE-2026-56164 (CVSS Score 9.8), a SharePoint Server privilege escalation vulnerability that can be exploited remotely without authentication, and CVE-2026-56155 (CVSS Score 7.8), a privilege escalation vulnerability affecting Active Directory Federation Services (AD FS). Successful exploitation could allow attackers to obtain elevated privileges and expand access within compromised environments.
Microsoft also addressed CVE-2026-55040 (CVSS Score 9.1), a SharePoint Server JWT authentication bypass vulnerability. Although not known to be exploited, it can be chained with the unpatched SharePoint remote code execution vulnerability CVE-2026-50522 (CVSS Score 9.8) to achieve unauthenticated remote code execution against vulnerable servers. Microsoft is expected to release a fix for CVE-2026-50522 in its August security updates, making the July patch an important step in disrupting the attack chain.
Critical Map-Regex Vulnerability Enables Pre-Auth RCE
A critical pre-authentication vulnerability, CVE-2026-42533(CVSS Score 9.2), impacts a widely deployed web server’s regex-based map evaluation. Exploitation can trigger a heap buffer overflow and an information leak, enabling ASLR bypass and potential remote code execution or denial-of-service.
The flaw is caused by a missing save-and-restore of PCRE capture state in the server’s two-pass script evaluation engine. When a regex capture is evaluated before a regex map variable, the shared capture array can be overwritten between the measurement and write passes. An attacker can craft requests that cause a heap buffer overflow with attacker-controlled content and length or produce an information leak that exposes heap pointers to defeat ASLR; chaining these primitives can yield reliable pre-auth remote code execution. Deployments that use map directives with regex patterns alongside capture-based sources in both HTTP and stream contexts are at risk, and patches have been released for affected builds.





