// Ransomware
Ransomware, Rogue Agents, and Rootless Exploits: Your July 26 Threat Briefing
By NeoShield AI Threat Desk · Published 2026-07-26 · 5 min read
#ransomware#Cl0p#PTC Windchill#FlexPLM#Active Directory#Certighost#BlueNoroff#DevMan RaaS
From Cl0p targeting industrial PLM platforms to a public Active Directory domain-takeover exploit, today's threat landscape demands immediate action across patching, identity hardening, and AI governance. Here is what your team needs to know right now.
Cl0p Pivots to Industrial PLM Platforms
The Cl0p ransomware ecosystem, tracked under aliases including Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest, has shifted targeting toward internet-exposed deployments of PTC Windchill and FlexPLM. These are product lifecycle management platforms used heavily in manufacturing, aerospace, and defense supply chains. Attackers are reportedly chaining a pre-authentication information disclosure flaw with a remote code execution vulnerability, meaning no credentials are required to gain a foothold. Organizations running either platform with any internet-facing exposure should treat this as an active emergency. Pull your external attack surface inventory today, confirm whether these services are reachable from the public internet, and apply vendor patches immediately. If patching cannot happen within hours, place an emergency WAF rule or network ACL in front of the service and alert your incident response team. Given Cl0p's history of mass exploitation and data theft before encryption, assume that any exposed instance may already be compromised and initiate a forensic review of recent access logs.
Certighost: A Public Exploit for Full Domain Takeover
Perhaps the most structurally dangerous item today is Certighost, a publicly available exploit that allows any low-privileged Active Directory user to obtain a Domain Controller certificate and then authenticate as that DC. From there, a DCSync attack extracts the krbtgt hash, which is effectively the master key to your entire Kerberos environment. This is a misconfiguration-class vulnerability in Active Directory Certificate Services, and the fact that working exploit code is publicly circulating means your window to remediate before opportunistic attackers weaponize it is extremely narrow. Run the Microsoft PKI health checker or a tool like Certify or PSPKIAudit against your CA infrastructure to identify misconfigured certificate templates, particularly those with the ENROLLEE_SUPPLIES_SUBJECT flag enabled or overly permissive enrollment rights. Revoke any suspicious certificates already issued. Enable CA audit logging if it is not already active and alert on any certificate requests from non-privileged accounts targeting DC authentication OIDs.
DevMan RaaS and the Industrialization of Ransomware
The DevMan RaaS portal, tracked as Funky Mantis, represents the continued professionalization of the ransomware-as-a-service economy. With centralized payload builds, victim management dashboards, and automated affiliate payouts, this operation lowers the barrier to entry for less-skilled threat actors while increasing the operational tempo of attacks. Defenders should not treat this as a single-actor threat but as a scalable platform that could be pointed at any sector. Ensure your endpoint detection and response tooling has current behavioral signatures for ransomware staging activity, including volume shadow copy deletion, rapid file enumeration, and lateral movement via legitimate admin tools. Segment your backup infrastructure so it is not reachable from general workstations or servers.
BlueNoroff Zoom Phishing Targets Crypto Holders
North Korean APT group BlueNoroff is running a phishing kit that impersonates Zoom and Microsoft Teams through typosquatted domains, using ClickFix-style social engineering to trick cryptocurrency wallet holders into executing malware. The campaign reportedly leverages compromised industry contacts to add legitimacy. Train users to verify meeting links through calendar invites or direct messages rather than clicking links in unsolicited emails. Implement DNS filtering to block newly registered domains and enforce browser isolation for high-risk users such as finance and executive staff.
ChatGPT AgentForger: AI Governance Is Now a Security Control
The now-patched AgentForger vulnerability in OpenAI ChatGPT Workspace Agents allowed a single phishing link to silently deploy rogue AI agents with organizational permissions. OpenAI patched this on June 8, but organizations that have not audited their AI agent inventory since then should do so immediately. Review which agents are authorized in your workspace, who approved them, and what data scopes they hold. Establish a formal approval workflow for any new AI agent deployment and log agent creation events as a monitored security signal.
SourTrade Malvertising Assembles Malware in the Browser
The SourTrade malvertising campaign is delivering a Windows executable by having the victim's browser assemble it in pieces, using a legitimate Bun runtime as a carrier to evade file-based detection. This technique bypasses many traditional AV signatures because no single complete malicious file is ever written to disk in a recognizable form. Enforce application allowlisting to prevent unexpected runtimes from executing, and ensure your EDR is configured for behavioral detection rather than relying solely on file hash matching.
Defensive Priorities for July 26
- Immediately audit and restrict internet exposure of PTC Windchill and FlexPLM; apply available patches as emergency priority
- Audit Active Directory Certificate Services for misconfigured templates and remediate Certighost-class misconfigurations before end of business
- Review ChatGPT Workspace Agent inventory and enforce an approval workflow for AI agent deployment
- Validate EDR behavioral detection coverage for ransomware staging, browser-assembled payloads, and DCSync activity
- Brief high-risk users on Zoom and Teams phishing impersonation and enforce DNS filtering for typosquatted domains
- Confirm backup infrastructure is isolated from general network segments and test restoration procedures
This briefing is informational and does not replace official vendor advisories, patches, or guidance from your organization's incident response team.
Related articles
Ransomware, Rogue Agents, and Rootless Certs: The Threat Landscape for July 26, 2026
From Cl0p affiliates hammering industrial PLM platforms to a publicly available Active Directory exploit that hands attackers…
RansomwareAI Agents, SVG Exploits, and Supply-Chain Ransomware: July 25 Threat Briefing
Today's threat landscape features autonomous AI-driven attacks, a critical server-side RCE via crafted SVGs in Bing's image…
Lazarus GroupLazarus Zero-Day, Patch Tuesday Avalanche, and Portal Data Theft: August 13 Threat Briefing
A North Korean zero-day targeting defense firms headlines a massive Microsoft Patch Tuesday while CISA flags three actively…
NeoShield Security publishes defensive cybersecurity guides for developers, small teams, SOC learners, and MSPs. AI-assisted content is reviewed for safety, defensive purpose, and practical security value.