ThreatBrief AI

Daily Cyber Digest: July 7, 2026

Critical remote-access auth bypasses, a 16-year Linux KVM VM-escape flaw, Cisco ISE RCE, Chrome and Teams threats lead the day.

+ +

Published

July 07, 2026

Item Count

6 items

TLP Protocol

TLP:clear

Briefing Items

01

Rank #1 · vulnerability · critical · high confidence

BleepingComputer

BeyondTrust patches critical auth-bypass flaws in remote access software

BeyondTrust urged customers to patch two critical authentication-bypass vulnerabilities in Remote Support and Privileged Remote Access that could let attackers bypass authentication.

Remote-access and privileged-access tooling is a prime initial-access target; auth bypasses can lead directly to full compromise of managed estates.

02

#2 · malware · high

BleepingComputer

Fake Microsoft Teams IT-support calls deliver EtherRAT malware

Attackers impersonate corporate IT support over Microsoft Teams voice calls to trick employees into installing EtherRAT, gaining initial network access.

Living-off-trust social-engineering via legitimate collaboration tools bypasses perimeter controls and is hard to detect with signature tooling.

03

#3 · vulnerability · high

Cisco PSIRT

Cisco ISE Remote Code Execution and information disclosure flaws

Multiple vulnerabilities in Cisco ISE and ISE-PIC could allow a remote attacker to achieve RCE or information disclosure; no workarounds are available.

ISE sits at the core of network identity and access control; remote code execution there risks broad lateral-movement potential.

04

#4 · vulnerability · high

SecurityWeek

Linux KVM 'Januscape' VM-escape flaw (CVE-2026-53359)

A 16-year-old KVM shadow-MMU defect (CVE-2026-53359, dubbed Januscape) can let a guest escape the VM and run code on Intel and AMD hosts; patched in mainline on June 19.

VM escape breaks tenant isolation in cloud and multi-tenant environments, threatening confidentiality and integrity of host systems.

05

#5 · advisory · medium

Canadian Centre for Cyber Security

Google Chrome security advisory AV26-669

On July 7 Google published a Chrome advisory; the Canadian Cyber Centre urges users to update Chrome for Desktop prior to 150.0.7871.100/101.

Browser patches close routinely exploited attack surface; timely updates reduce drive-by and in-the-wild exploit risk.

06

#6 · tooling · medium

Trend Micro

Trend Micro DPI rules: Splunk auth bypass and Crawl4AI RCE

Trend Micro released DPI rules covering Splunk Enterprise auth bypass (CVE-2026-20253) and Crawl4AI hooks code execution (CVE-2026-26216).

Network-level detection coverage for high-impact auth-bypass and AI-tooling RCE gives defenders a faster signal on exploitation attempts.

Executive snapshot

July 7, 2026 was dominated by authentication-bypass and remote-code-execution disclosures across privileged-access, network-identity, and virtualization stacks. BeyondTrust shipped fixes for two critical auth-bypass flaws in remote-access products, while Cisco remediated RCE and information-disclosure issues in ISE with no available workaround. A 16-year-old Linux KVM defect (Januscape) resurfaced as a VM-escape risk on Intel and AMD hosts. On the threat-actor side, a Microsoft Teams social-engineering campaign pushed EtherRAT for initial access. Government and vendor advisories rounded out the day with a Chrome update (AV26-669) and new Trend Micro detection rules for Splunk and Crawl4AI flaws.

Notable items

The day’s pattern is authentication and isolation failure: two of the highest-severity items (BeyondTrust, Januscape) erode the trust boundaries defenders rely on for privileged access and VM separation. Cisco ISE RCE compounds this by threatening the identity-control plane itself. The EtherRAT-over-Teams campaign shows attackers leaning on legitimate collaboration tooling and human trust rather than exploits. The Chrome and Trend Micro items are the more routine but still operationally important patch-and-detect signals that should feed standard update and detection pipelines.

Watchlist

  • Prioritize BeyondTrust Remote Support/PRA and Cisco ISE patching; both are internet- and identity-adjacent and lack workarounds (Cisco).
  • Hunt for Teams-based social-engineering and EtherRAT indicators; brief help desks on verifying unsolicited IT-support calls.
  • Inventory Linux KVM hosts and apply kernel fixes for CVE-2026-53359; treat multi-tenant VMs as higher risk until patched.
  • Roll out Chrome 150.0.7871.100+ and deploy Trend Micro DPI rules for CVE-2026-20253 and CVE-2026-26216.
  • Watch for follow-on proof-of-concept or in-the-wild exploitation of the auth-bypass and VM-escape flaws.