Italy Targeted by Multiple Adversaries, Developments in the APT Landscape, Vulnerabilities Exploited ITW
Italy: multiple Malicious Activities Observed
Several malicious activities targeting Italy have been identified. A smishing campaign was detected leveraging the theme of a purported failed delivery in the name of Bartolini (now known as BRT) to trick victims into providing personal data and payment card information. In addition, a phishing operation was identified exploiting the name and logo of the Italian Public Digital Identity System (SPID) to persuade victims to contact fraudsters by phone (vishing). Furthermore, a phishing campaign impersonating the Italian Ministry of Health was tracked and blocked. Its objective was to exfiltrate users’ personal and financial data by reusing a technique already observed in previous similar operations. Finally, a phishing activity exploiting the name of the Italian National Social Security Institute (INPS) was observed with the aim of stealing personal and financial information, using a modus operandi previously seen in campaigns impersonating other public institutions (the Ministry of Health and SEND). Turning to the ransomware landscape, the Qilin Team claimed on its leak site to have compromised Retelit S.p.A., a group operating in the telecommunications and information and communications technology (ICT) sector; the LockBit Team claimed SIRSA S.p.A., a company active in plastics manufacturing; Payouts King claimed Casta Diva Group S.p.A. – Società Benefit, a multinational company listed on Euronext Growth Milan operating in the integrated communications, audiovisual production, and event management sectors (this corresponds to the previously unspecified victim claimed in early July); and the DragonForce Team claimed SITAV S.p.A. (Società Italiana Treni Alta Velocità), a company specializing in the manufacturing, modernization, and maintenance of electric locomotives, passenger coaches, and trains.
APT: north korean, russian, chinese, and indian operations tracked
On July 13, 2026, security researchers identified a spear-phishing campaign dubbed Operation Capsule Vault, orchestrated by the North Korean threat actor ScarCruft to distribute a variant of RokRAT. The campaign derives its name from the container-like structure of the PIF file, which conceals both the legitimate document and the malicious payload, extracting them sequentially during execution. Shifting focus to Russia, the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), and the Federal Bureau of Investigation (FBI), together with 15 other agencies from Australia, the United Kingdom, Canada, New Zealand, Estonia, Finland, France, and Italy, published a joint advisory updating information on the activities of the state-sponsored Energetic Bear group, linked to the Russian Federal Security Service’s (FSB) 16th Center. The advisory describes campaigns targeting vulnerable or insecurely configured network devices, expands a previous 2025 FBI advisory, and provides additional details on observed techniques and recommended mitigation measures. It highlights the abuse of the Simple Network Management Protocol (SNMP) as one of the primary techniques observed, as well as the misuse of Cisco Smart Install and the exploitation of known vulnerabilities affecting Cisco devices. Also concerning Russia, the French authorities attributed a series of cyber espionage operations targeting strategic national interests to the state-sponsored Turla Group, likewise linked to the FSB’s 16th Center, and more specifically to Unit 61240. At the same time, the Centre de Coordination des Crises Cyber (C4) published a joint report detailing activities observed in France since 2010. Finally, the European Union issued an official statement in which, together with its Member States, it condemned Russia’s malicious cyber activities conducted through a complex cyber ecosystem involving both state and non-state actors, including intelligence services, cybercriminal groups, hacktivists, and private companies. The statement publicly identified the FSB’s 16th Center as the entity responsible for overseeing several cyber groups, including Turla Group. It also emphasized cooperation with the United Kingdom and strengthened coordination with international partners, including NATO, while reaffirming the importance of adherence to the United Nations framework for responsible state behavior in cyberspace. Turning to South Asia, between February 2024 and April 2026, suspected China- and India-aligned threat actors conducted independent yet converging espionage campaigns against Pakistani law enforcement organizations. The convergence on the same systems highlights the high intelligence value of the internal security information held by Pakistani law enforcement agencies. For the suspected Chinese groups, such data appears relevant to safeguarding Chinese citizens in Pakistan, given the country’s significant Chinese presence, largely associated with the China–Pakistan Economic Corridor (CPEC), a flagship project of the Belt and Road Initiative. For the suspected Indian actors, the information appears strategically relevant in the context of regional rivalry and the situation in Balochistan, amid longstanding mutual accusations between India and Pakistan of supporting armed groups operating in each other’s areas of strategic interest. On the Chinese front, four years after its initial discovery and public disclosure in 2022, the Daxin backdoor—attributed to a Beijing-linked cyber espionage group—was identified in May 2026 running on a compromised host belonging to the Taiwan-based subsidiary of a multinational high-tech manufacturing company, alongside a previously undocumented backdoor named Stupig. Both malware samples carry compilation timestamps dating back to early 2013; however, the compromised host only began transmitting telemetry data in May 2026. Although no direct code-level relationship was identified between the two malware families, several indicators suggest they were developed by the same threat actor. On July 7, 2026, Taiwanese authorities charged two executives of a local company, Li Hualun and Chen Mengsen, with assisting threat actors linked to the Chinese government in conducting a cyber espionage campaign targeting politicians, academics, journalists, and civil society organizations. The investigation, launched in April 2025 by the Taipei City Investigation Office, led to searches of the company’s premises and other locations during two separate investigative operations conducted in 2026. This week, authorities formally indicted the two executives for alleged violations of Taiwan’s Personal Data Protection Act and other criminal offenses.
Vulnerabilities: multiple flaws exploited ITW and the new LegacyHive 0-Day discovered
Following evidence of active exploitation, CISA added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: CVE-2008-4128 affecting Cisco IOS; CVE-2023-4346 affecting the KNX Association’s KNX Protocol Connection Authorization Option 1; CVE-2026-46817 affecting Oracle E-Business Suite; CVE-2026-48939 affecting iCagenda; and CVE-2026-56291 affecting Balbooa Forms. Specifically, CVE-2026-48939 and CVE-2026-56291, both classified as Unrestricted Upload of File with Dangerous Type vulnerabilities with a CVSS score of 10.0, were exploited as zero-days in-the-wild (ITW) attacks targeting Joomla websites. The former was leveraged in automated campaigns, while the latter was already under active exploitation at the time of its identification. CISA’s KEV Catalog was also updated to include two SonicWall zero-day vulnerabilities that had been exploited ITW and subsequently patched: CVE-2026-15409 (CVSS 10.0), a Server-Side Request Forgery (SSRF) vulnerability, and CVE-2026-15410 (CVSS 7.2), a Code Injection vulnerability. SonicWall’s PSIRT reported investigating multiple incidents indicating active exploitation of both flaws. As customary, Microsoft released its July Patch Tuesday, which this month addressed 622 vulnerabilities. Of these, two were confirmed as actively exploited: CVE-2026-56155 (CVSS 7.8), an Insufficient Granularity of Access Control vulnerability, and CVE-2026-56164 (CVSS 5.3), a Missing Authentication for Critical Function vulnerability. On July 14, 2026, CISA added both vulnerabilities to its KEV Catalog, requiring U.S. Federal Civilian Executive Branch (FCEB) agencies to remediate CVE-2026-56155 by July 28, 2026, and CVE-2026-56164 by July 17, 2026. Only a few hours after the release of Patch Tuesday, the security researcher known as Nightmare Eclipse published a Proof-of-Concept (PoC) exploit for a new Windows zero-day vulnerability affecting Microsoft’s User Profile Service (profsvc), dubbed LegacyHive. At the time of writing, no CVE identifier has been assigned, and Microsoft has not yet released a security patch. LegacyHive provides a useful post-compromise primitive by allowing access to configuration settings and data stored within the registry hives of other users. In particular, it can facilitate credential theft and persistence operations, although it does not constitute a standalone compromise vector capable of fully breaching a system. Finally, the Australian Cyber Security Centre (ACSC) published an advisory warning of an ongoing large-scale exploitation campaign targeting multiple vulnerabilities affecting content management systems (CMS) worldwide. According to the advisory, numerous small and medium-sized enterprises (SMEs) have already been impacted.
Weekly Threats Report is Telsy’s weekly update featuring the main developments on cyber attacks and threat actors worldwide, produced by our Threat Intelligence & Response team.
The team is composed of analysts and security researchers with technical and investigative skills and internationally recognized experience.
Through continuous monitoring of cyber threats and geopolitical events, it produces and provides organizations with useful information to anticipate attacks and understand their scope, with the support of a trusted partner in the event of a cyber incident.
Learn more about our Cyber Threat Intelligence solution.
