Threat Alerts
Your place for the latest CyberProof cyber threat intelligence alerts and updates
Speak with an ExpertCritical SD-WAN Manager Vulnerability Exploited in the Wild
A critical authentication bypass vulnerability, CVE-2026-76504 (CVSS 9.8), is being actively exploited in a widely deployed enterprise SD-WAN management platform. The flaw allows remote, unauthenticated attackers to access the SD-WAN Manager API with full administrative privileges, potentially enabling complete compromise of exposed systems. The default administrator role permits unrestricted operations on the device, increasing the risk to internet-facing deployments.
The vulnerability stems from improper URI encoding in the API’s session-handling mechanism, allowing crafted HTTP requests to bypass authentication checks for a protected endpoint. Exploitation attempts may involve URI-encoded characters in session login request paths to evade detection controls. Relevant activity can be investigated through specific application log files, although analysts should correlate multiple indicators to distinguish malicious requests from legitimate activity.
The vulnerability affects SD-WAN Manager regardless of its configuration, and no other products have been identified as affected. Security updates are available across multiple release trains, and organizations that previously installed patches for earlier vulnerabilities must apply the latest update, as those fixes do not address this flaw. Given confirmed exploitation in the wild, organizations should prioritize patching exposed instances and review relevant logs for potential unauthorized access.
TeamViewer Remote Session Access Control Bypass
TeamViewer addressed a high-severity vulnerability, CVE-2026-92370 (CVSS Score 8.8), affecting its Full Client and Host applications that could allow an authenticated remote attacker to bypass configured session permissions and potentially achieve remote code execution. The flaw stems from improper access control during remote session establishment, allowing an attacker to manipulate access control parameters and perform actions that were explicitly restricted by the targeted user.
Successful exploitation requires the attacker to establish an authenticated TeamViewer session with the target, but could allow actions beyond the permissions granted for that session, potentially resulting in code execution on the affected system.
CloudSyncD Backdoor Hides in Fake Zoom Installer to Target macOS Users
A new macOS backdoor has been discovered hidden inside a fake Zoom installer, designed to trick users into handing over their login credentials before silently deploying a second-stage payload. The malware, known as CloudSyncD, has already progressed beyond early development and has been observed operating against live command-and-control infrastructure, signaling an active and advancing threat.
The malware arrives as a disk image mimicking a legitimate Zoom installer, instructing victims to bypass macOS security protections through system settings to get around Gatekeeper. It then presents a fake authorization prompt, collecting the user’s password and validating it locally β the password is never transmitted externally, but instead buried in a decoy configuration file using hidden Unicode characters, where it is later retrieved to launch the second stage with elevated privileges.
The embedded payload supports both Apple silicon and Intel architectures, and the malware initially attempts to execute it entirely in memory to avoid leaving traces on disk. If that method fails, it falls back to writing the payload temporarily and running it using the harvested password for elevated access. Once active, the backdoor establishes a hidden working directory on the system and communicates with its operators over encrypted channels, first sending a system survey and then using the machine’s hardware identifier for ongoing check-ins. Rather than functioning as a traditional infostealer, CloudSyncD focuses on remote task execution β capable of receiving and running executable files or archives β with no built-in functionality for harvesting browser data, keychain items, or cryptocurrency wallets, suggesting its primary purpose is maintaining operator access rather than immediate data theft.
NetScaler SAML Memory Overflow Actively Exploited
Citrix disclosed a high-severity vulnerability, CVE-2026-88779 (CVSS Score 8.7), affecting NetScaler ADC and NetScaler Gateway that is being exploited in targeted attacks against unmitigated deployments. The vulnerability is caused by improper restriction of operations within a memory buffer and can be exploited under specific configuration conditions to trigger a denial-of-service (DoS), potentially leaving affected services unavailable when the condition is repeatedly triggered.
Exploitation is dependent on the NetScaler configuration and primarily affects customer-managed deployments using SAML authentication together with Gateway or AAA functionality, including appliances configured as a SAML Service Provider (SP) or SAML Identity Provider (IdP).
Phishing Campaign Abuses RMM Tools for Persistent Remote Access
A phishing campaign observed lately targeted organizations across multiple industries by distributing legitimate remote monitoring and management (RMM) software disguised as business documents, meeting invitations, software updates, and other common workplace content. Victims were redirected to attacker-controlled or legitimate cloud-hosting services and tricked into downloading a digitally signed MSP360 RMM installer presented under deceptive filenames. Once executed with elevated privileges, the software established persistent remote access to the compromised endpoint.
After establishing the initial foothold, the attackers used the MSP360 agent to execute PowerShell and silently deploy ConnectWise ScreenConnect, creating a second remote-access channel. This provided redundant persistence and enabled attackers to remotely transfer and execute additional tools. The campaign did not exploit vulnerabilities in the RMM products themselves; instead, attackers abused legitimate administrative software to blend into normal IT activity and reduce the likelihood of detection.
Post-compromise activity included credential-access operations, local information collection, deployment of additional tooling, and remote command execution. Observed phishing themes included Zoom and Google Meet installation prompts, PDF and Adobe updates, workplace meeting requests, job offers, document-signing requests, e-cards, and package-delivery notifications.
Custom GPTs Abused to Deliver RAT Malware
Threat actors are abusing a trusted AI platform’s custom chatbot feature to distribute malware by disguising malicious bots as legitimate product offerings. The campaign begins with a sponsored search result directing users to a fraudulent custom chatbot, which displays a fake service availability notice and redirects victims to a secondary domain. The site presents a fraudulent CAPTCHA that tricks users into copying and executing a malicious PowerShell command, initiating the infection chain.
The command deploys an installer that abuses a legitimate signed binary to sideload a malicious DLL, which then extracts an encrypted loader concealed within an audio file. The loader uses anti-analysis techniques, including security tool evasion, unhooking of system libraries used by antivirus software, and virtual machine checks. The final payload is a Remote Access Trojan (RAT) capable of remote desktop access, camera and microphone capture, browser interaction across 17 browser types, file system access and execution of additional payloads and scripts.
To conceal its command-and-control activity, the RAT routes DNS queries through encrypted HTTPS connections to legitimate public DNS resolvers, making the traffic harder to distinguish from normal network activity. The campaign highlights the growing abuse of trusted AI platforms and fake CAPTCHA verification pages as social engineering vectors for malware delivery, combining trusted-service impersonation, signed binary abuse, encrypted payloads and anti-analysis techniques to evade detection.




