// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRF-01DTG 0600Z
ColdRecon / Brief Archive / Week of June 29, 2026
Signal Brief · Archived

Week of June 29, 2026

2026-06-29 — 2026-07-05 · 10 PUBLIC EVENTS · GENERAL / NON-PERSONALIZED

In the week of June 29, 2026, ColdRecon logged 10 public endpoint-security events from open-source reporting — 6 incidents, 2 research pocs, 1 vuln disclosure, 1 vendor announcement. Vendors in the record this week: Microsoft, Arctic Wolf, ConnectWise.

The Week's Public Record

Events

2026-07-02
incident
Ransomware Groups Leverage BYOVD to Disable Endpoint SecurityBYOVD
Ransomware groups are increasingly using Bring Your Own Vulnerable Driver (BYOVD) techniques to disable endpoint security systems. Even fully patched Windows systems with all exploit mitigations enabled do not provide complete protection against this method. The Sophos Counter Threat Unit also investigated a partnership between VECT and TeamPCP combining supply chain credential theft with ransomware.
2026-07-02
incident
Arctic Wolf Impersonation on GitHub Delivers Information StealerGitHub Impersonation Information Stealer
Arctic Wolf's internal SecOps identified a GitHub page impersonating the company to target customers and prospects. The page distributed an information stealer, though the specific malware family is not named. This incident highlights the use of trusted platforms for social engineering and malware delivery.
2026-07-02
incident
ClickFix-style malware distributed through sponsored ad on XClickFix-style malware via X sponsored ad
Jamf Threat Labs discovered a ClickFix-style attack using a sponsored ad on X to distribute malware. The attack tricked users into running malicious commands, leading to endpoint compromise. This incident highlights evolving social engineering tactics that bypass traditional security controls.
2026-07-02
incident
Attackers Abuse ScreenConnect to Deploy AsyncRAT via Fake InstallersScreenConnect AsyncRAT campaign
A widespread campaign used fake software installers to deliver a legitimate ScreenConnect instance, which attackers then leveraged to deploy the AsyncRAT trojan. The attack chain abuses trusted remote administration tools to bypass endpoint defenses and gain persistent remote access.
2026-07-02
incident
Phishing Campaign Uses Fake Invoice PDF to Drop Multiple RATsFake Invoice PDF Phishing Campaign Delivering AsyncRAT, VenomRAT, XWorm
A phishing campaign distributes a fake invoice PDF that leads to the deployment of AsyncRAT, VenomRAT, and XWorm. The attack uses social engineering and malicious scripts to infect endpoints, posing a threat to endpoint security by evading detection through legitimate-looking documents.
2026-07-02
vuln disclosure
Microsoft Defender Flaw CVE-2025-24084 Exploited in Ransomware AttacksCVE-2025-24084
A vulnerability in Microsoft Defender (CVE-2025-24084) was publicly disclosed on April 2, 2025, before a patch was available. The flaw is now being linked to ransomware attacks in the wild, allowing attackers to bypass Defender protections.
2026-07-02
vendor announcement
Opera Browser Adds Built-in Protection Against ClickFix Clipboard AttacksOpera-ClickFix-Protection
Opera has introduced a new security feature in its desktop browser that detects and blocks malicious 'ClickFix' clipboard attacks. The feature monitors clipboard content for suspicious commands and warns users before they execute potentially harmful code. This addresses a growing social engineering technique where users are tricked into pasting and running malicious scripts.
2026-07-02
incident
Attackers Disable Defender, Sysmon, and WAF Before Credential Dumping with MimikatzDisable-Defender-Sysmon-WAF-Mimikatz
In a real-world incident, attackers disabled Windows Defender, Sysmon, and a web application firewall on a compromised IIS server before using Mimikatz to dump credentials. The attack highlights how adversaries systematically neutralize endpoint defenses to enable credential theft.
Microsoft · Sysinternals ↗ cybersecuritynews.com (2026-07-02)
2026-07-02
research poc
ValleyRAT Campaign Uses RC4 Encryption, Donut Shellcode, and rundll32 Injection to Evade DetectionValleyRAT
A recent ValleyRAT campaign employs RC4-encrypted payloads, Donut-generated shellcode, and in-memory execution via suspended rundll32 processes to evade endpoint security detection. The malware achieves stealth by decrypting and injecting shellcode into a legitimate Windows process, bypassing traditional signature-based and behavioral defenses.
2026-07-02
research poc
Browser-Based Ransomware Uses File System Access API to Encrypt Files Without Malware InstallationBrowser-Based Ransomware via File System Access API
A proof-of-concept demonstrates ransomware delivered entirely through a web browser using the File System Access API, requiring only user consent to access a folder. The attack avoids traditional endpoint detection by executing within the browser process without dropping binaries or using exploits. This technique highlights a gap in endpoint security tools that focus on native code execution.
Every event in this brief is a record in ColdRecon's canonical set, drawn from public open-source reporting and linked to its source. This is the general, non-personalized signal — published 7 days after the fact. The live daily brief, written for your deals, is for cleared officers.

This is last week, public. Get this morning's, written for you.

The live ColdRecon brief lands at 0600 daily — the same signal, filtered to your competitors and framed for your deals. Request clearance and tomorrow's is yours.

Request Clearance →