CISA’s July 23 industrial-control advisories put patching pressure on operators of Weintek, Rockwell Automation, Johnson Controls and MZ Automation products,…
CISA Flags ICS Flaws as Ransomware Adapts (7.23)
Overview
- CISA published a broad set of industrial-control advisories affecting Weintek, Rockwell Automation, Johnson Controls and MZ Automation products, with impacts ranging from credential exposure to remote code execution.
- Cisco Talos reported that Chaos ransomware used msaRAT to route command-and-control traffic through headless Chrome or Edge instead of making its own outbound connection.
- Group-IB tied a China-nexus cluster called JadeProx to government, healthcare and education targeting across Asia and Latin America using a new Windows loader.
- Accomplish AI reported a Claude Cowork sandbox escape that could let an AI agent running inside a Linux VM read or write files elsewhere on a Mac.
Details
CISA Advisories Put ICS Operators on a Patch Clock
CISA’s July 23 industrial-control advisories covered several operational-technology products used in manufacturing, building systems and utility environments. The advisory set included Weintek cMT3092X, Rockwell Automation ThinManager, Johnson Controls C-CURE 9000 and Victor, MZ Automation libIEC61850, MZ Automation lib60870, Panduit IntraVUE and Johnson Controls XAAP Android.
The most severe operational risk came from products where exploitation could cross from application compromise into control-system impact. CISA said Johnson Controls C-CURE 9000 and Victor application server flaws could allow an attacker with network access to achieve remote code execution(RCE). The MZ Automation libIEC61850 advisory said an unauthenticated network-adjacent attacker could crash critical IEC 61850 services or execute arbitrary code.
CISA also identified narrower but still material issues. Weintek cMT3092X firmware before 20210218 and EasyWeb before v2.1.20 are affected by flaws that could let a non-privileged user escalate privileges or view other users’ credentials. Rockwell Automation ThinManager versions in the affected ranges could let an authenticated attacker write arbitrary files to restricted directories outside the application’s intended path.
Key takeaway: The CISA batch is a patch-management story more than a single emergency. Remote code execution and network-adjacent protocol-library flaws should move to the front of the queue.
Chaos Ransomware Uses Browsers to Hide msaRAT Traffic
The Hacker News reported on Cisco Talos research describing msaRAT, a Rust implant used in activity tied to Chaos ransomware. Cisco Talos found the implant on a compromised Windows machine before the encryptor appeared, making it part of the pre-ransomware stage rather than only the final payload.
The notable behavior was how the implant handled command-and-control traffic. The report said msaRAT did not open its own outbound connection. Instead, it communicated locally with 127.0.0.1 while starting Chrome or Edge in headless mode and driving the browser to handle external traffic.
That approach complicates detection because browser traffic often blends into ordinary endpoint behavior. A security team looking only for a suspicious standalone process making outbound connections could miss the more important relationship between the implant, localhost traffic and headless browser activity.
Key takeaway: Chaos activity shows why ransomware detection cannot stop at the encryptor. Headless browser use, localhost traffic and unusual process ancestry are now part of the signal.
JadeProx Campaign Exposes New TriBack Loader Targeting Public Sectors
The Hacker News reported that Group-IB linked an exposed Alibaba Cloud server to a China-nexus operation it tracks as JadeProx. The activity targeted government, healthcare and education organizations across Asia and Latin America, according to the report.
Group-IB identified a previously undocumented Windows loader called TriBack Loader in the campaign. A loader is malware used to prepare or deliver later-stage tooling, so its presence usually points to an intrusion chain rather than a one-step compromise.
The infrastructure timeline gives defenders a useful anchor. Group-IB found the server in mid-April 2026 in Alibaba Cloud’s Singapore region, and the report said the server was offline by the time of publication. That means the public exposure is useful for analysis, but defenders should expect infrastructure to move.
Key takeaway: JadeProx is a reminder that loader changes can be as important as the final payload. Public-sector defenders should treat new staging malware as an early warning signal.
Claude Cowork Sandbox Escape Raises Mac File-Access Risk
The Hacker News reported that Accomplish AI found a sandbox escape vulnerability in Anthropic’s Claude Cowork. The flaw involved an AI agent running inside a Linux virtual machine on macOS and could allow file access outside that intended boundary.
According to the report, the issue could make it possible to read or write files anywhere on the Mac. Accomplish AI said about 500,000 macOS users were running the affected environment, based on the excerpt collected for this briefing.
The risk is different from a conventional browser or office-document flaw. Agent tools are designed to take actions, inspect files and automate workflows. When their isolation boundary fails, the impact can include files the user did not intend to expose to the agent.
Key takeaway: The Claude Cowork report turns agent isolation into a practical endpoint-security issue. Local AI tools need the same containment scrutiny as remote-access and automation software.
Morning Breaking Updates
- feeds.feedburner.com: Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes - A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client. The payload goes after the last 90 days of
- feeds.feedburner.com: ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories - Most of this week's trouble came dressed as something useful. A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders
- microsoft.com: Email threat landscape: Q2 2026 trends and insights - In this article Tycoon2FA Q2 disruption impact QR code phishing attacks CAPTCHA-gated phishing tactics Malicious payloads Business email compromise Microsoft Teams threats Notable
At a glance
| Fact | Publisher | Source |
|---|---|---|
| Weintek cMT3092X firmware before 20210218 and EasyWeb before v2.1.20 are affected. | CISA | cisa.gov |
| ThinManager flaws could let an authenticated attacker write files outside intended directories. | CISA | cisa.gov |
| Johnson Controls C-CURE 9000 and Victor flaws could allow remote code execution. | CISA | cisa.gov |
| libIEC61850 flaws could let a network-adjacent attacker crash services or run code. | CISA | cisa.gov |
| Cisco Talos reported Chaos ransomware using msaRAT with headless Chrome or Edge. | The Hacker News | thehackernews.com |
| Group-IB linked JadeProx activity to a new Windows loader called TriBack Loader. | The Hacker News | thehackernews.com |
| Accomplish AI reported a Claude Cowork sandbox escape affecting macOS users. | The Hacker News | thehackernews.com |
FAQ
Sources
- Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files - feeds.feedburner.com
- Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge - feeds.feedburner.com
- China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks - feeds.feedburner.com
- Weintek cMT3092X - cisa.gov
- Rockwell Automation ThinManager - cisa.gov
- Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite - cisa.gov
- Johnson Controls XAAP Android - cisa.gov
- MZ Automation libIEC61850 - cisa.gov
- MZ Automation lib60870 - cisa.gov
- Johnson Controls C-CURE 9000 and Victor application server - cisa.gov
- Panduit IntraVUE - cisa.gov
- How Synthetic Identity Fraud is Coming for Machine Identities - feeds.feedburner.com
- National Vulnerability Database - NIST
- Microsoft Security Response Center - Microsoft
- Google Online Security Blog - Google
- Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes - feeds.feedburner.com
- ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories - feeds.feedburner.com
- Email threat landscape: Q2 2026 trends and insights - microsoft.com
Last updated: 2026-07-24T11:22:55.607Z
댓글
댓글 쓰기