DomainFork
Markets
MarketsCompaniesCryptoCommoditiesIslamic Finance
Money
Personal FinanceProperty
World
MalaysiaASEANAsiaWorld
Business
TechnologyStartupsOpinion
Intelligence
AI EdgeOSINT Desk
Media
VideoAudioLifestyle
Breaking
Public finance is feminist terrainChaos ransomware's msaRAT: Living off the browser to build a covert C2 channelLe photographe de l’AFP Luis Acosta récompensé par le prix Simon BolivarWAN-Ifra 2016 : tour du monde de l’actualité en imagestest title18 May 2026 – Job Advert for temporary field worker LFS 202627 April 2026 – DEPS issued 20 compounds for offences under the Price Control ActA heartfelt farewell to our dear Óscarเตือนภัย! กลุ่มแรนซัมแวร์ Qilin ใช้ช่องโหว่ Palo Alto VPN เจาะเครือข่ายองค์กรเพื่อขโมยข้อมูลพบมัลแวร์ msaRAT ใช้ Chrome และ Edge เป็นช่องทางติดต่อ C2 หลบเลี่ยงการตรวจจับ#WinningWednesdays: Stories of Biodiversity Champions across ASEANDon’t swing at everythingBeating Plastic Pollution in Three StepsJuly 2026How Indigenous-owned firms finance their operationsThe Star ESG Award – Gold Winner in the Human Rights and Labour Standards category (Large Companies Tier)SD Guthrie and Sime Darby Property Advance Strategic Industrial Corridor into Next PhaseEmail threat landscape: Q2 2026 trends and insightsReal world incident response: Microsoft and AXA XL strengthen cyber resilienceKhazanah Nasional welcomes Public Accounts Committee recommendations on MAHBPublic finance is feminist terrainChaos ransomware's msaRAT: Living off the browser to build a covert C2 channelLe photographe de l’AFP Luis Acosta récompensé par le prix Simon BolivarWAN-Ifra 2016 : tour du monde de l’actualité en imagestest title18 May 2026 – Job Advert for temporary field worker LFS 202627 April 2026 – DEPS issued 20 compounds for offences under the Price Control ActA heartfelt farewell to our dear Óscarเตือนภัย! กลุ่มแรนซัมแวร์ Qilin ใช้ช่องโหว่ Palo Alto VPN เจาะเครือข่ายองค์กรเพื่อขโมยข้อมูลพบมัลแวร์ msaRAT ใช้ Chrome และ Edge เป็นช่องทางติดต่อ C2 หลบเลี่ยงการตรวจจับ#WinningWednesdays: Stories of Biodiversity Champions across ASEANDon’t swing at everythingBeating Plastic Pollution in Three StepsJuly 2026How Indigenous-owned firms finance their operationsThe Star ESG Award – Gold Winner in the Human Rights and Labour Standards category (Large Companies Tier)SD Guthrie and Sime Darby Property Advance Strategic Industrial Corridor into Next PhaseEmail threat landscape: Q2 2026 trends and insightsReal world incident response: Microsoft and AXA XL strengthen cyber resilienceKhazanah Nasional welcomes Public Accounts Committee recommendations on MAHB
Home/OSINT
Economy

Don’t swing at everything

Thorsten explores Q2 2026 stats, the artificial buffer zone of 2026, and why smart, prioritized patching is more critical than ever.

Source: Cisco Talos Intelligence · July 25, 2026 at 11:33 PM · AI-assisted report

KUALA LUMPUR, 26 JULY 2026 —

Listen to this article

DomainFork Audio · read aloud

Headline: Don’t swing at everything Lead: Thorsten explores Q2 2026 stats, the artificial buffer zone of 2026, and why smart, prioritized patching is more critical than ever. Body: Welcome to this week’s edition of the Threat Source newsletter. Lately I've found myself thinking a lot about the Australian TV series Mr. Inbetween (IMDb 8.7/10) — not because I'm a hitman for hire, but because I literally feel in-between. Specifically, in-between what I'd call the "pre-Mythos" and “post-Mythos” eras. We've crossed a capability threshold, and it's not just one model family driving that — Codex 5.3 and GPT-5.5 deliver comparable or better performance , and Tulongfeng or GLM-5.2 (an incredibly powerful open-weight model, MIT-licensed) show the frontier isn't limited to closed models anymore. On the other side of that line, real-world impact hasn't caught up yet and we're living in an artificial buffer zone. For me, defining the “pre-” and “post-” status comes down to the gap between "vulnerability discovery" and "vulnerability publication." Last week’s Patch Tuesday gave a signal of change, as Joe pointed out , so maybe the buffer zone has come to an end. As in past years, we're seeing a steeper curve than the year before — a solid 49% YoY growth, though still not the hockey-stick moment I keep waiting for. By the end of June we were tracking close to 200 CVEs per day. Using the keyword methodology described here , I found 452 AI-related CVEs this calendar year. If "openclaw" is added to the keyword list, that number jumps by another 536 — a reminder that these counts are sensitive to keyword drift. Given how much the keyword list keeps changing, I'm reconsidering whether to keep publishing this particular metric going forward. KEVs, by contrast, "only" grew 13% — a small April spike aside, it's fairly flat relative to total CVE growth. Networking-gear-related CVEs continued their climb, now accounting for 24% of KEV-related vulnerabilities (up from 20% in Q1) — consistent with the trend I flagged last quarters. As in previous quarters, CVEs from 2024 or earlier still make up about 24% of everything we're tracking. More strikingly, even though the standard enterprise patch cycle is described to run 30–90 days, 181 days into 2026, 46% of today's actively-exploited (KEV) CVEs still trace back to 2025 or earlier. Old vulnerabilities don't retire, new ones keep arriving, and machine-speed vulnerability discovery is going to keep outpacing human-speed patching. Which brings me back — once again — to EPSS as a tool for prioritizing patching against this dataset. If you patched purely by CVSS 9+, you'd be urgently chasing ~3,700 CVEs — but 95% of those sit below 5% EPSS, meaning the real-world odds of exploitation are tiny. Of the 32 CVSS 9+ CVEs with EPSS ≥ 50%, 25 are already on CISA's KEV list. The remaining seven outliers are still high-probability by EPSS but haven't made KEV yet — worth watching. Ray Shoesmith (Mr. Inbetween) once told his therapist, "You know, if I hit somebody, I generally got a pretty good reason." Same principle applies to patching. Don't swing at everything — swing at what you have good reason to believe is coming for you. Cisco Talos has discovered "msaRAT," a new Rust-based remote access trojan (RAT) deployed by the Chaos ransomware group. Built on the Tokio asynchronous runtime, it establishes a covert command-and-control (C2) channel by hijacking Chrome or Edge browsers via the Chrome DevTools Protocol (CDP). The infection starts with a deceptive MSI file masquerading as a Windows update that loads the payload directly into memory, paving the way for ransomware deployment. This RAT is a master of evasion, living off the browser to build its C2 infrastructure without ever directly touching the network. By routing traffic through legitimate browser processes and trusted services, msaRAT easily bypasses traditional network-based detections. Additionally, its use of the Tokio runtime enables highly efficient, parallel execution of malicious tasks, accelerating the attacker's ability to establish persistence and deploy double-extortion ransomware. Defenders should monitor for unusual curl commands, especially those downloading MSI files to the ProgramData directory or sending plain HTTP traffic over port 443. Scrutinize unexpected MSI files impersonating Windows updates and watch for unauthorized Chrome or Edge manipulation. Finally, implement behavioral monitoring to catch Chrome DevTools Protocol abuse and unauthorized WebRTC connections. Read the full blog for complete coverage and indicators of compromise (IOCs). Introducing Antares: Highly efficient open weight AI models for vulnerability localization This week, Cisco introduced Antares, a family of security small language models (SLMs) purpose-built for pinpointing where known vulnerabilities exist within a codebase. ( Cisco ) Hacker wipes European country’s entire land registry database, paralyzing real-estate market A hacker wiped Romania’s entire land registry database after an unsuccessful extortion attempt. The attack halted all property transactions, preventing notaries from authenticating sales or registering mortgages nationwide. ( Cybernews ) "WP2Shell” opens millions of WordPress sites to remote takeover Barely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet. ( DarkReading ) Progress tells ShareFile customers to shut down Storage Zone Controllers over security threat Only the Storage Zone Controller is affected, not standard cloud-only ShareFile accounts. The controller is a server that a company runs itself, so files can stay on its own storage while it still uses ShareFile's cloud to share and manage them. ( The Hacker News ) Microsoft SharePoint under attack via new exploit Researchers warned that patching is not enough to address the deserialization flaw and that security teams “should rotate credentials on any assets that may have been exposed.” ( Cybersecurity Dive ) [Video] Where protection starts: Cisco Talos Intelligence Integrations Every day, defenders make high-consequence decisions with incomplete information. Learn how Cisco Talos Intelligence Integrations help reduce uncertainty by turning the latest threat intelligence into proactive protections across Cisco technologies. The Hunter's Paradox: Is it time to embrace automated threat hunting? Humans can no longer keep up with the… (AI-assisted rewrite, based on the original source)

Related: Microsoft

Malaysia Impact

Global development — watch for knock-on effects on oil prices, the ringgit, and KLCI risk sentiment.

Suggested Reads

Public finance is feminist terrainChaos ransomware's msaRAT: Living off the browser to build a covert C2 channelLe photographe de l’AFP Luis Acosta récompensé par le prix Simon BolivarWAN-Ifra 2016 : tour du monde de l’actualité en images

Analyst Consensus — This Week

Neutral6.3/10AI sentiment across 124 stories · not investment advice

The Daily Brief · Free

Five market signals.
Five minutes. Every morning.

AI-curated intelligence on Malaysia, ASEAN, and global markets — before the opening bell.

  • ✓ KLCI, ringgit & sector movers
  • ✓ The AI Edge sentiment read
  • ✓ No spam — one email, weekday mornings

Free daily market briefing. No spam, unsubscribe anytime.

DomainFork

Malaysian financial intelligence — AI-assisted coverage of finance, economics, technology, and open-source data across Malaysia, ASEAN, and the world.

Sections

  • Malaysia
  • ASEAN
  • Asia
  • World
  • Tech
  • Markets

Intelligence

  • AI Daily Briefing
  • OSINT Desk
  • Video
  • Audio

Company

  • About Us
  • Editorial Standards
  • Advertise
  • Contact the Desk

Disclaimer: DomainFork provides financial, economic, technology, and OSINT information for general education and research. AI summaries, sentiment scores, and market data are not investment advice. Consult a licensed professional before making financial decisions.

© 2026 DomainFork. All rights reserved.

Powered by: Codint Technology : codint.io