Article Read Time

1. FBI Dismantles NetNut, One of the World’s Largest Residential Proxy Networks
On July 3, the FBI and private-sector partners took down NetNut, a residential proxy service built on roughly 2 million secretly hijacked home devices. The network had quietly routed criminal traffic — from credential stuffing to fraud — through ordinary people’s routers and IoT gear for years, making it a case study in how consumer devices become unwitting infrastructure for cybercrime. The takedown is one of the more consequential law enforcement actions against proxy-for-hire infrastructure this year.
Source: https://cybernews.com/
2. Critical SimpleHelp RMM Flaw (CVSS 10.0) Actively Exploited, Added to CISA’s KEV Catalog
CVE-2026-48558, a critical authentication bypass in SimpleHelp’s Remote Monitoring and Management software, lets an unauthenticated attacker forge an OIDC token and walk away with a fully authenticated “Technician” session — no credentials required. CISA added the flaw to its Known Exploited Vulnerabilities catalog on June 29 with a July 2 remediation deadline, and Arctic Wolf and Horizon3.ai have confirmed active exploitation, including deployment of the TaskWeaver loader across managed endpoints. An estimated 14,000 SimpleHelp servers are internet-facing, with roughly 1,000 directly vulnerable a reminder that RMM tools remain a prime target for supply-chain-style attacks on MSPs.
Source: https://thehackernews.com/
3. New “Avalon” Malware Framework Bundles Credential Theft, Lateral Movement, and CrownX Ransomware
Researchers uncovered a previously undocumented, modular malware framework dubbed Avalon that combines credential harvesting, lateral movement, remote access, backup/recovery disruption, and ransomware deployment (internally named CrownX) into a single toolkit. Delivery starts with a spoofed legal-document phishing lure that points to a password-protected Proton Drive archive, with the payload hidden inside an ISO to evade email-layer detection, and the framework shows signs of AI-assisted development, with specific evasion routines built against Defender, SentinelOne, CrowdStrike, and other major EDR products. It sat on VirusTotal with zero detections for months before being flagged.
Source: https://thehackernews.com/2026/07/new-avalon-malware-framework-packs.html
4. Ransomware Crews Pivot to Citrix Bleed 2, BYOVD, and Stolen Supply-Chain Credentials
The Anubis ransomware-as-a-service operation has been observed exploiting the Citrix Bleed 2 vulnerability (CVE-2025-5777) for initial access, then living off legitimate RMM tools like ScreenConnect, Zoho Assist, and UltraVNC to move laterally. Separately, researchers detailed a partnership between the VECT and TeamPCP crews that pairs supply-chain credential theft — harvested from the Trivy and LiteLLM compromises — with ransomware deployment across every downstream victim. Bring-your-own-vulnerable-driver (BYOVD) techniques continue to let attackers blind fully patched, fully mitigated endpoints in seconds.
Source: https://thehackernews.com/2026/07/ransomware-groups-turn-to-citrix-bleed.html
5. California’s Expanded Privacy Rules Take Effect, Raising the Bar on Sensitive Data
A significant amendment to California’s privacy framework became effective July 1, broadening the definition of sensitive personal information to include health data, transgender and nonbinary status, and related categories, while adding new rights to contest automated profiling decisions and banning targeted advertising to minors. Combined with new comprehensive privacy laws already in effect in Indiana, Kentucky, and Rhode Island, and a federal push toward 72-hour incident reporting and 24-hour ransomware payment disclosure, the regulatory floor for data handling continues to rise nationwide.
