July 27, 2026 Emerging Threats Weekly

Jul 27, 2026

This week’s briefing covers:

00:00 – Intro

00:45 [MALWARE] Cruciferra Crypter Service Gains Traction Across Email-Delivered RAT and Stealer Campaigns
Cruciferra crypter service is being used by multiple unrelated cybercriminal clusters to package and deliver commodity malware through opportunistic email campaigns. These crypter services are using to conceal malicious payloads with the intent to improve the success rate of malware delivery. Researchers said the service has been marketed since Fall 2025 and is now appearing in dozens of campaigns, indicating growing adoption rather than a single-actor operation.

03:23 [VULNERABILITY] WP2Shell WordPress Exploitation Enables Remote Takeover at Large Scale
Attackers are actively exploiting the WP2Shell vulnerability chain in WordPress Core, combining CVE-2026-60137 and CVE-2026-63030 to achieve unauthenticated remote code execution on default WordPress installations. Exploitation began widely within days of disclosure, with public proof-of-concept code accelerating scanning and compromise activity.

05:22 [NEW TECHNIQUE] HOLLOWGRAPH Uses Microsoft 365 Calendars as Covert C2
Security researchers have identified a new malware sample that's capable of silently exfiltrating data through Microsoft 365 mailbox calendar events. Dubbed HOLLOWGRAPH, the malware utilizes trusted Microsoft cloud infrastructure and the mailbox application to blend into typical enterprise network traffic, according to researchers at Group-IB.

08:31 [VULNERABILITY] ServiceNow AI Platform RCE Exploitation Observed Days After Disclosure
On July 21 that active exploitation had been observed for CVE-2026-6875, a critical vulnerability affecting the ServiceNow AI Platform. The flaw is an unauthenticated remote code execution issue caused by a sandbox escape. ServiceNow stated that security updates were applied to hosted instances, but self-hosted customers are responsible for deploying patches.

10:24 [NEW TECHNIQUE] Hidden Pull Request Comments Can Hijack Azure DevOps MCP AI Review Agents
Researchers have demonstrated a prompt-injection weakness affecting Microsoft Azure DevOps MCP workflows that allows hidden pull request content to influence AI review agents. The issue can cause agents to access private data, perform actions outside the scope of the review or interact with tools the attacker could not access directly using their own permissions.

12:51 [MALWARE] ENCFORGE JadePuffer Evolves with Purpose-Built Ransomware Targeting AI Models
Researchers have linked a new ransomware payload known as ENCFORGE to JADEPUFFER, the AI-agent-driven operator previously associated with autonomous exploitation of Langflow environments. Unlike the earlier campaign, which focused on database encryption and extortion, the latest activity introduces a purpose-built ransomware payload designed specifically to target AI and machine learning assets.

Dive deeper:

Kroll’s Monthly Threat Intelligence Spotlight Report: https://www.kroll.com/en/reports/cyber/threat-intelligence-reports/cti-spotlight-trends-report

Kroll’s Cyber Threat Intelligence: https://www.kroll.com/en/services/cyber/threat-intelligence-services

Kroll’s Q4 2024 Cyber Threat Landscape: https://www.kroll.com/en/reports/cyber/threat-intelligence-reports/q4-2024-threat-landscape-report-phishing

Kroll’s 2025 Cyber Threat Landscape Report: Cybercrime in the Crypto Era: https://www.kroll.com/Reports/Cyber/Threat-Intelligence-Reports/Threat-Landscape-Report-Lens-on-Crypto

Playlist of Kroll's Weekly Cyber Threat Intelligence Briefings: https://www.youtube.com/playlist

Kroll Cyber Blog: https://www.kroll.com/en/insights/cyber

Kroll Cyber Threat Intelligence: https://www.kroll.com/en/services/cyber/threat-intelligence-services

Kroll Threat Intelligence Reports: https://www.kroll.com/en/reports/cyber/threat-intelligence-reports

Kroll Cyber and Data Resilience: https://www.kroll.com/en/services/cyber

#krollcyber #threatintelligence #cyberthreats