Threat Alerts
Your place for the latest CyberProof cyber threat intelligence alerts and updates
Speak with an ExpertACR Stealer Campaign Uses WebDAV and rundll32
A surge in ACR Stealer attacks targeted enterprise customers from April through June. The campaign uses social-engineering lures to distribute malicious DLLs via WebDAV shares and leverages legitimate Windows utilities for execution, risking credential and web session cookie theft and remote control.
Campaign operators use ClickFix-themed lures to coerce victims into accessing files hosted on WebDAV; malicious DLLs are executed via rundll32.exe directly from those shares, avoiding obvious EXE artifacts. Techniques in the chain include obfuscated payloads, ingress of secondary tools, timestomping of artifacts, and establishment of encrypted channels for command-and-control and data exfiltration.
The typical chain begins with social engineering and file retrieval over WebDAV, proceeds to DLL-based execution through a trusted system binary, and culminates in credential and session cookie theft followed by encrypted C2. Indicators of compromise include unusual rundll32 activity, anomalous WebDAV access patterns, and atypical outbound encrypted connections.
LegacyHive Windows Zero-Day Local Privilege Escalation Vulnerability
LegacyHive is an unpatched Windows local privilege escalation vulnerability that abuses the User Profile Service to load attacker-controlled registry hives. Successful exploitation enables attackers with local code execution and valid user credentials to access another user’s registry hive, creating opportunities for privilege escalation, persistence, and post-compromise activity. The vulnerability affects fully patched Windows desktop and server systems, and no Microsoft security update is currently available.
Microsoft Addresses Two Exploited Zero-Days and SharePoint Flaws
Microsoft has released its July Patch Tuesday updates, addressing a record 622 vulnerabilities across Windows, Microsoft Office, Active Directory, and SharePoint Server. The release includes two zero-day vulnerabilities that are actively exploited in the wild, making this month’s updates a high priority for organizations.
The exploited vulnerabilities include CVE-2026-56164 (CVSS Score 9.8), a SharePoint Server privilege escalation vulnerability that can be exploited remotely without authentication, and CVE-2026-56155 (CVSS Score 7.8), a privilege escalation vulnerability affecting Active Directory Federation Services (AD FS). Successful exploitation could allow attackers to obtain elevated privileges and expand access within compromised environments.
Microsoft also addressed CVE-2026-55040 (CVSS Score 9.1), a SharePoint Server JWT authentication bypass vulnerability. Although not known to be exploited, it can be chained with the unpatched SharePoint remote code execution vulnerability CVE-2026-50522 (CVSS Score 9.8) to achieve unauthenticated remote code execution against vulnerable servers. Microsoft is expected to release a fix for CVE-2026-50522 in its August security updates, making the July patch an important step in disrupting the attack chain.
Critical Map-Regex Vulnerability Enables Pre-Auth RCE
A critical pre-authentication vulnerability, CVE-2026-42533(CVSS Score 9.2), impacts a widely deployed web server’s regex-based map evaluation. Exploitation can trigger a heap buffer overflow and an information leak, enabling ASLR bypass and potential remote code execution or denial-of-service.
The flaw is caused by a missing save-and-restore of PCRE capture state in the server’s two-pass script evaluation engine. When a regex capture is evaluated before a regex map variable, the shared capture array can be overwritten between the measurement and write passes. An attacker can craft requests that cause a heap buffer overflow with attacker-controlled content and length or produce an information leak that exposes heap pointers to defeat ASLR; chaining these primitives can yield reliable pre-auth remote code execution. Deployments that use map directives with regex patterns alongside capture-based sources in both HTTP and stream contexts are at risk, and patches have been released for affected builds.
ClickFix Campaign Abuses AI Platforms to Target macOS Users
A recent malvertising campaign abused trusted AI platforms to target macOS users through the ClickFix social engineering technique, tricking victims into executing malicious Terminal commands. The campaign leveraged paid search advertisements that redirected users searching for a popular AI assistant to shared AI chat links containing fraudulent ClickFix instructions, adding a layer of legitimacy to the attack. Researchers attribute the activity to Russian-speaking threat actors who used the technique to steal sensitive information from compromised systems.
Once the victim executed the obfuscated command, a multi-stage infection chain delivered additional payloads, concealed execution, established persistence by modifying shell configuration files and collected sensitive data from the system. The malware targeted browser credentials, macOS Keychain data, shell history, cloud access credentials, messaging application files and desktop wallet applications, while also displaying a fake system prompt to capture the user’s macOS password. The stolen information was exfiltrated over HTTP in multiple chunks to attacker-controlled infrastructure. The campaign demonstrates how threat actors are increasingly abusing trusted AI services and social engineering techniques to evade detection and compromise users.
Fortinet Releases Security Updates Addressing Seven Vulnerabilities
Fortinet has released security updates addressing seven vulnerabilities affecting FortiSandbox, FortiOS, FortiProxy, and FortiPAM. The most severe vulnerability, CVE-2026-59835 (CVSS 7.7), affects FortiSandbox and could allow an unauthenticated attacker to access the VNC server of virtual machines under analysis, potentially exposing sensitive files and malware samples.
The advisory also addresses several additional high- and medium-severity vulnerabilities, including CVE-2026-59837 (CVSS 7.2), a stack-based buffer overflow that could lead to arbitrary code execution, CVE-2026-59839 (CVSS 6.7), a path traversal vulnerability that may enable unauthorized file access, and CVE-2026-23573 (CVSS 6.1), a stored cross-site scripting (XSS) vulnerability.
Three lower-severity issues were also patched: CVE-2026-59836 (CVSS 4.3), CVE-2026-59838 (CVSS 3.7), and CVE-2026-59840 (CVSS 3.1), which could result in HTTP response splitting, information disclosure, or other security impacts depending on the affected product and deployment.





