The Lyceum: Cyber Intelligence Daily — Jul 07, 2026
Photo: lyceumnews.com
Tuesday, July 7, 2026
Morning Command Brief
- Patch ColdFusion now: CVE-2026-48282 grants unauthenticated RCE and was exploited within two hours of disclosure — treat it as KEV-equivalent and update to 2025 Update 10 or 2023 Update 21 immediately.
- Audit your KVM hosts: the 16-year-old "Januscape" flaw (CVE-2026-53359) has a public crash PoC and a withheld full host-escape, putting multi-tenant Linux clouds at cross-tenant risk.
- Assume NetScaler tokens are stolen: CitrixBleed (CVE-2026-8451) has two confirmed threat actors exploiting it since June 30 but still isn't on CISA KEV — patch and rotate sessions without waiting for a listing.
What Changed Overnight
"Januscape" KVM Guest-to-Host Flaw Goes Public
Researcher Hyunwoo Kim disclosed CVE-2026-53359, a use-after-free in Linux KVM's shadow MMU that sat unnoticed for ~16 years. Exploitation needs root inside a guest plus nested virtualization exposed by the host; the public PoC crashes the entire host (taking down every co-tenant), while a separate unreleased exploit reportedly achieves full host code execution. Anyone running or renting x86 KVM infrastructure is exposed. Fixed kernels shipped July 4 — confirm your build includes commit 81ccda30b4e8 via changelog, or disable nested virtualization (kvm_intel.nested=0 / kvm_amd.nested=0); watch provider bulletins for emergency maintenance.
ColdFusion CVE-2026-48282 Exploited in Two Hours
CVE-2026-48282 hits ColdFusion 2025.9, 2023.20 and earlier with unauthenticated RCE; KEVIntel reported exploitation under two hours after disclosure, first probe from an India-geolocated IP (per Security Affairs). This follows Adobe's July 1 disclosure of nine ColdFusion/Campaign Classic flaws, seven at CVSS 10.0, prompting a shift to twice-monthly bulletins from July 14. Shadowserver tracks nearly 800 exposed instances. Update to 2025 Update 10 or 2023 Update 21 now — Adobe's 72-hour clock started days ago.
CitrixBleed: Second Actor Confirmed, Still Off KEV
Attackers began exploiting CVE-2026-8451 in NetScaler ADC/Gateway under 24 hours after Citrix's June 30 disclosure and watchTowr's writeup (per SecurityWeek). Lupovis observed a second actor probing from a Koapu Cloud HK IP, both delivering full payloads on a 200 OK. The unauthenticated pre-auth memory overread in the SAML XML parser affects ADC/Gateway 14.1 before 14.1-72.61 and 13.1 before 13.1-63.18. Despite active exploitation, it remains absent from CISA KEV — echoing prior CitrixBleed breaches at Boeing, ICBC, and DP World. Patch now and inspect NSC_TASS cookie values for binary content indicating a successful overread.
Fake Teams IT Calls Deliver Blockchain-Powered EtherRAT
Unit 42 detailed a campaign chaining a phishing email, a Teams voice call impersonating a "System Administrator" from an external tenant (flagged "External unfamiliar"), legitimate RMM tools, and a Node.js loader. EtherRAT uses EtherHiding to pull its C2 address from an Ethereum smart contract, letting operators reroute infected machines without redeploying malware. An open directory held installer versions v1–v9, signaling active development. The fix is policy: restrict external Teams calling to approved domains and train staff that IT never cold-calls from external accounts. Watch for RMM installs your helpdesk didn't initiate.
Coverage Notes
- Coverage note: Microsoft Office CVE-2026-21509 Zero-Day: Emergency Patch Released to Counter Active Exploita... — This is a required major-headline item for reader awareness; monitor vendor guidance, exploitation reports, and any emergency patch timeline. Key terms: zero-day, Microsoft Office, CVE-2026-21509, active exploitation, emergency patch. Source: Rescana.
Watch Next
- If the withheld Januscape full-escape exploit leaks or is independently reproduced, it means multi-tenant KVM clouds face genuine tenant-to-tenant data exposure — watch AWS, Google Cloud, and major VPS providers for unscheduled maintenance windows.
- If CVE-2026-8451 still isn't on CISA KEV by week's end despite two confirmed actors, it means KEV has a structural lag as a patch-prioritization trigger and KEV-driven shops must stop relying on it alone.
- If the Instructure Canvas "deal" collapses after the July 8 publication deadline, it means ~275 million student records become a live phishing resource against .edu addresses within the week.