π Security Pulse Β· 2026-07-23 16:00 UTC
β‘ TL;DR
New highly sophisticated malware identified with significant reverse engineering challenges signals rising threat complexity π΄π΄. Iranian-affiliated actors aggressively targeting critical infrastructure PLCs escalate risk in national security π΄. Overall threat level elevated.
π CYBER THREATS
- Oracle Fusion Middleware Java security is under assault with a cluster of 15+ vulnerabilities (CVE-2026-60366 through CVE-2026-60455, plus others) exposing centralized thirdparty jar components, risking enterprise middleware platforms worldwide π‘π‘ [7-17].
- Check Point products reveal multiple vulnerabilities enabling authentication bypass and privilege escalation including CVE-2026-16232 and CVE-2026-62144/45, facilitating remote attacker control over security management systems π‘π‘ [39-41].
- Telerik UI for AJAX contains XML external entity and file read/write flaws (CVE-2026-14865, CVE-2026-14932) threatening web app integrity and data confidentiality π‘ [37-38].
- New mega malware of exceptional complexity found in the wild, with serious reverse engineering hurdles, linked to a South American threat actor and propagated through deceptive campaigns via Telegram and fake Korean fitness sites π π π [3-5, 31, 34].
- Multiple Joomla CMS core vulnerabilities (CVE-2026-64791 through CVE-2026-64798 series) permit unauthorized backend access, CSRF attacks, and unsafe content injection, heightening risk of content manipulation and data leaks π‘π‘ [18-22, 28-30].
- DNS infrastructure faces several resource exhaustion and query manipulation exploits in BIND resolver (CVE-2026-10723, CVE-2026-10822, CVE-2026-11605 to CVE-2026-11721), threatening domain resolution stability and integrity π‘ [43-48].
- An out-of-bounds read vulnerability discovered in libheif image format decoder (CVE-2026-48029) risks remote code execution via malicious HEIF/AVIF files constantly used in digital media π‘ [1].
π‘οΈ NATIONAL SECURITY
- Iranian-affiliated threat actors actively target internet-connected PLCs from Rockwell Automation, Schneider Electric, and Siemens across critical infrastructure sectors, creating serious operational disruption and espionage risks π₯π₯π₯ [2].
- Multiple data breaches reported at Origin Energy, at least the fourth this year, showcasing ongoing risks to energy sector confidentiality and operational safety π [3][4].
β οΈ RISK FLAGS
β οΈ The deployment of rare, ultra-sophisticated malware with unknown full capabilities indicates imminent higher impact cyberattacks possibly aimed at critical infrastructure or high-value targets π΄π΄π΄ [5].
β οΈ Active exploitation potential flagged for multiple middleware and security platform vulnerabilities (Oracle Fusion Middleware and Check Point vulnerability chains) with remote exploitation avenues π π [7-17, 39-41].
β οΈ Iranian state-affiliated cyber actors targeting US/EU critical infrastructure PLCs via known vendor devices could prelude kinetic attacks or sabotage events, demanding urgent defensive posture upgrades π΄π΄π΄ [2].
π§ THREAT MOOD
Elevated β While many vulnerabilities remain being disclosed and patched, the rise of complex malware variants and targeted PLC attacks on critical infrastructure increase risk across sectors. Vigilant monitoring and prompt patching is essential π .
π Sources
- CVE-2026-48029 libheif is a HEIF and AVIF file format decoder β¦ β @CVEnew
- π¨ Iranian-affiliated threat actors are targeting internet-conβ¦ β @CISAgov
- Yeah, I can see why this message wasnβt received well by @origβ¦ β @troyhunt
- Here we go again, first disclosure email from @originenergy. Tβ¦ β @troyhunt
- A colleague of mine notified me of actual super rare mega fuckβ¦ β @vxunderground
Educational & informational only β not financial advice. Markets carry risk; do your own research.
Serial 20260723-16-v18 Β· 2026-07-23 16:00 UTC Β· pulse.uzylab.com