July 27, 2026 Emerging Threats Weekly
This week’s briefing covers:
00:00 – Intro
00:45 [MALWARE] Cruciferra Crypter Service Gains Traction Across Email-Delivered RAT and Stealer Campaigns
Cruciferra crypter service is being used by multiple unrelated cybercriminal clusters to package and deliver commodity malware through opportunistic email campaigns. These crypter services are using to conceal malicious payloads with the intent to improve the success rate of malware delivery. Researchers said the service has been marketed since Fall 2025 and is now appearing in dozens of campaigns, indicating growing adoption rather than a single-actor operation.
03:23 [VULNERABILITY] WP2Shell WordPress Exploitation Enables Remote Takeover at Large Scale
Attackers are actively exploiting the WP2Shell vulnerability chain in WordPress Core, combining CVE-2026-60137 and CVE-2026-63030 to achieve unauthenticated remote code execution on default WordPress installations. Exploitation began widely within days of disclosure, with public proof-of-concept code accelerating scanning and compromise activity.
05:22 [NEW TECHNIQUE] HOLLOWGRAPH Uses Microsoft 365 Calendars as Covert C2
Security researchers have identified a new malware sample that's capable of silently exfiltrating data through Microsoft 365 mailbox calendar events. Dubbed HOLLOWGRAPH, the malware utilizes trusted Microsoft cloud infrastructure and the mailbox application to blend into typical enterprise network traffic, according to researchers at Group-IB.
08:31 [VULNERABILITY] ServiceNow AI Platform RCE Exploitation Observed Days After Disclosure
On July 21 that active exploitation had been observed for CVE-2026-6875, a critical vulnerability affecting the ServiceNow AI Platform. The flaw is an unauthenticated remote code execution issue caused by a sandbox escape. ServiceNow stated that security updates were applied to hosted instances, but self-hosted customers are responsible for deploying patches.
10:24 [NEW TECHNIQUE] Hidden Pull Request Comments Can Hijack Azure DevOps MCP AI Review Agents
Researchers have demonstrated a prompt-injection weakness affecting Microsoft Azure DevOps MCP workflows that allows hidden pull request content to influence AI review agents. The issue can cause agents to access private data, perform actions outside the scope of the review or interact with tools the attacker could not access directly using their own permissions.
12:51 [MALWARE] ENCFORGE JadePuffer Evolves with Purpose-Built Ransomware Targeting AI Models
Researchers have linked a new ransomware payload known as ENCFORGE to JADEPUFFER, the AI-agent-driven operator previously associated with autonomous exploitation of Langflow environments. Unlike the earlier campaign, which focused on database encryption and extortion, the latest activity introduces a purpose-built ransomware payload designed specifically to target AI and machine learning assets.
Dive deeper:
Kroll’s Monthly Threat Intelligence Spotlight Report: https://www.kroll.com/en/reports/cyber/threat-intelligence-reports/cti-spotlight-trends-report
Kroll’s Cyber Threat Intelligence: https://www.kroll.com/en/services/cyber/threat-intelligence-services
Kroll’s Q4 2024 Cyber Threat Landscape: https://www.kroll.com/en/reports/cyber/threat-intelligence-reports/q4-2024-threat-landscape-report-phishing
Kroll’s 2025 Cyber Threat Landscape Report: Cybercrime in the Crypto Era: https://www.kroll.com/Reports/Cyber/Threat-Intelligence-Reports/Threat-Landscape-Report-Lens-on-Crypto
Playlist of Kroll's Weekly Cyber Threat Intelligence Briefings: https://www.youtube.com/playlist
Kroll Cyber Blog: https://www.kroll.com/en/insights/cyber
Kroll Cyber Threat Intelligence: https://www.kroll.com/en/services/cyber/threat-intelligence-services
Kroll Threat Intelligence Reports: https://www.kroll.com/en/reports/cyber/threat-intelligence-reports
Kroll Cyber and Data Resilience: https://www.kroll.com/en/services/cyber
#krollcyber #threatintelligence #cyberthreats