// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRF-01DTG 0600Z
ColdRecon / Brief Archive / Week of August 17, 2026
Signal Brief · Archived

Week of August 17, 2026

2026-08-17 — 2026-08-23 · 34 PUBLIC EVENTS · GENERAL / NON-PERSONALIZED

In the week of August 17, 2026, ColdRecon logged 34 public endpoint-security events from open-source reporting — 17 research pocs, 11 incidents, 4 vuln disclosures, 2 vendor announcements. Vendors in the record this week: Microsoft, Tenable, Cloudflare.

The Week's Public Record

Events

2026-08-22
incident
Gentlemen ransomware driver terminates 180 security processes before encryptionGentlemen ransomware driver
The Gentlemen ransomware operation deploys a kernel driver that terminates 180 security-related processes, including antivirus, endpoint detection, and backup agents, before encrypting files. This allows the ransomware to operate without interference from security tools.
2026-08-22
vuln disclosure
Tenable Nessus Agent Link Following VulnerabilityCVE-2026-33694
A link following vulnerability (CWE-59) in Tenable Nessus and Nessus Agent allows an attacker to exploit improper handling of symbolic links, potentially leading to unauthorized file access or modification. The vulnerability is rated High severity.
2026-08-21
research poc
Trojanized npm Packages Drop RedC2 4.0 Backdoor with AI-Assisted C2RedC2 4.0
Researchers discovered 14 malicious npm packages that install the RedC2 4.0 backdoor, a multi-OS command-and-control framework. The Windows beacon includes antivirus tampering, in-memory execution, and lateral movement capabilities. The framework is advertised as built with evasion as a core principle and uses AI-assisted C2.
2026-08-21
incident
Agent Tesla v4 delivered via emoji-obfuscated JScript in BEC campaignAgent Tesla v4 emoji-obfuscated JScript campaign
A business email compromise (BEC) campaign is distributing Agent Tesla v4, an infostealer, using JScript files heavily obfuscated with emojis. The malware steals credentials from browsers, email clients, and messaging applications. The technique evades detection by leveraging uncommon obfuscation and living-off-the-land binaries.
2026-08-21
research poc
CAV3RN espionage toolkit evolves with Google Apps Script C2 targeting Israeli organizationsCAV3RN
Kaspersky GReAT reports that the CAV3RN cyberespionage toolkit has evolved with advanced features and redesigned communication channels, actively targeting Israeli organizations. The toolkit now abuses Google Apps Script for command-and-control, enhancing stealth and persistence.
2026-08-21
research poc
Peer2Profit Turns Employee Devices Into AstroProxy Nodes That Can Expose Internal NetworksPeer2Profit-to-AstroProxy
Researchers found that the Peer2Profit proxyware application can be repurposed to enroll devices into the AstroProxy residential proxy network, potentially exposing corporate internal networks. This allows attackers to route malicious traffic through compromised employee devices, bypassing IP-based security controls.
2026-08-20
incident
UAT-10147 Uses AI-Assisted Playbooks to Compromise IIS Servers and Add Defender ExclusionsUAT-10147 AI-assisted IIS exploitation
Cisco Talos reports that Chinese-speaking cybercrime group UAT-10147 is using AI-generated playbooks and automation to compromise Windows and Linux web servers, turning them into a repeatable criminal operation. The group adds Microsoft Defender exclusions on compromised Windows IIS servers to evade detection. This highlights the use of AI in crafting attack playbooks and the specific endpoint evasion technique of modifying Defender settings.
2026-08-20
research poc
Remote Spectre Attack Leaks Cloudflare Worker JWTRemote Spectre Attack on Cloudflare Workers
Researchers demonstrated a remote Spectre attack that leaked a JWT between co-located Cloudflare Workers. Cloudflare has since mitigated the technique.
2026-08-20
research poc
Microsoft Defender BTR.sys driver abused to disable EDR/AVBTR.sys abuse
Researchers demonstrated that Microsoft Defender's legitimate Boot-Time Removal driver (BTR.sys) can be abused by an attacker with administrative privileges to perform arbitrary kernel-level file and registry operations, potentially disabling endpoint security protections. The technique leverages the driver's intended functionality to delete or tamper with files and registry keys used by security products.
2026-08-20
incident
Malicious Rust crate arrayref backdoored in supply chain attack with DPRK overlapRust supply chain attack on arrayref crate
Malicious versions of the Rust crate arrayref (and others) executed a backdoor at compile time. The campaign's infrastructure overlaps with recent DPRK supply chain attacks, including Mastra and axios. This incident highlights the risk of compromised dependencies in the software supply chain.
2026-08-20
incident
ErrTraffic Malware Campaign Uses Social Engineering and Defense EvasionErrTraffic
A malware campaign observed in late July 2026 uses compromised WordPress sites injected with obfuscated ErrTraffic JavaScript to deliver malware. The attack combines social engineering with defense evasion techniques to bypass endpoint security. The campaign highlights evolving threats against endpoint detection and response systems.
2026-08-20
research poc
Fake CAPTCHA Campaign Deploys Malware with EDR-Killer ComponentEDR-Killer via MocoMsys driver
A malware campaign uses fake CAPTCHA pages to trick users into running a malicious script. The script downloads additional components, including an EDR killer that attempts to disable endpoint security by exploiting a vulnerable signed driver. This highlights the ongoing risk of BYOVD attacks against security products.
2026-08-20
research poc
ClawHavoc: Indirect Prompt Injection Weaponizes AI Agents to Install MalwareClawHavoc
Researchers demonstrated ClawHavoc, an indirect prompt injection attack that manipulates AI agents into instructing users to install malware. The attack bypasses safe execution policies by exploiting the agent's trust in external content. This highlights the need for endpoint telemetry beyond malicious-file detection in agentic environments.
2026-08-20
research poc
Rapid7 Operation ASTERIX: AI-Driven Crypto Phishing CampaignOperation ASTERIX
Rapid7 uncovered Operation ASTERIX, a crypto phishing campaign using counterfeit wallet apps and AI-generated content to target victims. The campaign involved approximately 885,000 phone numbers and demonstrates increased precision in social engineering. This highlights the growing use of AI in crafting convincing phishing lures.
2026-08-20
research poc
AI-Agent-Driven Autonomous Crypto-Theft Campaign Exposed via Open DirectoryAI-Agent Crypto-Theft Campaign
CloudSEK discovered an exposed directory belonging to a Chinese-speaking operator who used AI coding agents, Telegram, and a self-hosted LLM proxy to run autonomous intrusions against WordPress sites, crypto/DeFi targets, and wallet-bearing phishing databases. The operator also built a blockchain-based C2 and credential-harvesting infrastructure, leading to mass wallet and credential compromise.
2026-08-20
research poc
UAT-10147 deploys SPECTRE cross-platform implant with Linux rootkit and BYOVDSPECTRE
Researchers identified a new implant named SPECTRE used by threat actor UAT-10147. SPECTRE is a cross-platform tool with Linux rootkit and BYOVD capabilities, integrating C2, process injection, credential theft, and anti-analysis. It represents an evolution in commodity intrusion tooling with kernel-level EDR bypass.
2026-08-19
incident
MaaS Campaign Combines ClickFix, ErrTraffic, and CruciferraClickFix-ErrTraffic-Cruciferra MaaS Campaign
A malware-as-a-service (MaaS) campaign combines ClickFix social engineering, ErrTraffic traffic redirection, and Cruciferra malware to deliver a loader that disables endpoint security. The operation demonstrates how separate MaaS offerings can be chained to outsource delivery, social engineering, and defense evasion.
2026-08-19
vendor announcement
Microsoft Defender Update Breaks Virus ScansMicrosoft Defender scan failure after Security Intelligence update
A Microsoft Defender Security Intelligence update released on August 18, 2026, caused Quick, Full, and Offline scans to abort. The issue affected both home users and Defender for Endpoint admins, leaving systems without reliable malware scanning until a fix was issued.
2026-08-19
incident
Check Point Research Unravels StopAndProtect Cybercrime OperationStopAndProtect
Check Point Research identified and analyzed the StopAndProtect cybercrime operation, uncovering a series of operational security failures that exposed the attackers. The investigation reveals how a single slip-up led to the unraveling of a global cybercrime empire.
2026-08-18
vuln disclosure
CoSnitch: One-Click Vulnerability in Microsoft Copilot PersonalCoSnitch
A one-click vulnerability named CoSnitch was discovered in Microsoft Copilot Personal. The flaw allows attackers to exfiltrate private data via a malicious prompt. The vulnerability highlights risks in AI assistants that can access sensitive information.
2026-08-18
incident
CISA Warns Medusa Ransomware Hackers Steal Data, Kill Security Tools, and Encrypt Entire NetworksMedusa Ransomware
CISA, FBI, and HHS issued an updated advisory on Medusa ransomware, which has impacted over 300 victims across critical infrastructure sectors. The ransomware actors use phishing and unpatched vulnerabilities for initial access, then disable security tools and exfiltrate data before encryption. The advisory provides indicators of compromise and mitigation guidance.
2026-08-18
vuln disclosure
Microsoft Copilot Vulnerability Disclosed and PatchedCVE-2026-XXXX
A vulnerability in Microsoft Copilot was disclosed on August 18, 2026, with patches released the same day. The flaw could be triggered by prompting Copilot, potentially exposing its own vulnerabilities. There is no evidence of exploitation in the wild.
2026-08-18
research poc
Microsoft uncovers MacSync Stealer infrastructure via behavioral pivotsMacSync Stealer
Microsoft researchers identified over 30 domains associated with MacSync Stealer, a macOS malware that rapidly rotates domains to evade detection. By pivoting on consistent behavioral characteristics, they exposed the broader infrastructure behind the stealer.
2026-08-18
research poc
Projextor Campaign Abuses Electron Framework to Conceal Malware ActivityProjextor
The Projextor campaign abuses Electron-based productivity applications to hide malware-like capabilities behind fully functioning document converters. The malware uses a Node.js backdoor and a Python-based RAT to execute commands and exfiltrate data. The campaign targets Windows and macOS users, leveraging the cross-platform Electron framework to evade detection.
2026-08-18
incident
Asruex Trojan Embedded in GEEKOM Mini PC Realtek Ethernet DriverAsruex Trojan in GEEKOM Mini PC Realtek Ethernet Driver
GEEKOM confirmed that a malware-flagged Realtek LAN driver package was accessible through an outdated support page for its mini PCs. The driver contained the Asruex Trojan, which can download additional malware and steal information. This supply-chain style compromise affects users who downloaded the driver from the official support page.
2026-08-18
research poc
HoneyMyte CoolClient Backdoor Uses Signed Kernel Rootkit to Hide ProcessesHoneyMyte CoolClient Backdoor
The HoneyMyte threat group has upgraded its CoolClient backdoor with a signed kernel rootkit to hide processes and evade endpoint detection. This kernel-level evasion technique allows the malware to operate stealthily on compromised systems.
2026-08-18
vendor announcement
Shadow hVNC Malware Kit Advertised for Covert Remote ControlShadow hVNC
A malware-as-a-service toolkit named Shadow hVNC is being advertised, combining browser credential theft, hidden virtual desktop control, and reverse proxying. It enables attackers to remotely control a victim's machine through a hidden desktop session, evading detection by the user. The toolkit is sold as a service, lowering the barrier for cybercriminals.
2026-08-18
research poc
TWINLOOT malware abuses Microsoft cloud services for C2TWINLOOT
Researchers disclosed TWINLOOT, a malware that uses Microsoft SharePoint, Teams, Azure, and the victim's own Edge browser to hide command-and-control traffic inside trusted Microsoft infrastructure. The technique makes detection difficult because traffic appears as legitimate Microsoft cloud activity.
2026-08-17
incident
SilverFox APT Uses Fake Claude Apps to Target Asian CompaniesSilverFox Claude Malware Campaign
The SilverFox APT group is distributing trojanized versions of Anthropic's Claude AI application to target companies in India and other Asia-Pacific countries. The malware steals sensitive data and establishes persistence, leveraging the popularity of AI tools for social engineering. This campaign highlights the risk of third-party app distribution channels.
2026-08-17
incident
44 Zero-Day Exploits in One Week Overwhelm Enterprise Defenses44 Zero-Days in One Week
In a single week, 44 zero-day vulnerabilities were exploited in the wild, including flaws in Microsoft Defender, VMware vCenter, and SAP Commerce Cloud. The surge highlights the increasing pressure on enterprise security teams to patch and respond rapidly.
2026-08-17
research poc
12 KB Windows Backdoor Hides C2 Domain in desktop.ini Whitespacedesktop.ini whitespace C2 backdoor
A 12 KB Windows backdoor disguised as Realtek software hides its command-and-control (C2) address in trailing spaces inside a fake desktop.ini file. The backdoor uses the hidden domain to fetch a PowerShell script for further malicious activity. This technique evades detection by hiding the C2 domain in an unusual location.
2026-08-17
research poc
Windows 11 security defenses bypassed via RAM chip flaw using scriptRAMBleed
Researchers demonstrated a method to bypass Windows 11's strongest security defenses by exploiting a RAM chip flaw, requiring only a script and no physical access. The technique undermines core OS security mechanisms, potentially exposing sensitive data.
2026-08-17
research poc
Mustang Panda's CoolClient Backdoor Operates at Windows Kernel LevelCoolClient
Mustang Panda, a China-linked APT, has deployed a new backdoor named CoolClient that operates at the Windows kernel level, enabling it to evade detection and maintain persistence. The backdoor is delivered via a malicious Word document and uses a kernel driver to execute malicious code with high privileges.
2026-08-17
vuln disclosure
NTFS Heap Overflow Vulnerabilities Exploited via Crafted VHD FilesCVE-2025-24993
Three NTFS heap overflow vulnerabilities (CVE-2025-24993, CVE-2025-24984, CVE-2025-24985) are exploited by mounting a crafted VHD file, leading to local privilege escalation. The article provides detection rules and forensic artifacts for defenders.
Every event in this brief is a record in ColdRecon's canonical set, drawn from public open-source reporting and linked to its source. This is the general, non-personalized signal — published 7 days after the fact. The live daily brief, written for your deals, is for cleared officers.

This is last week, public. Get this morning's, written for you.

The live ColdRecon brief lands at 0600 daily — the same signal, filtered to your competitors and framed for your deals. Request clearance and tomorrow's is yours.

Request Clearance →