Threat Briefing: July 17, 2026

Threat Briefing Cybersecurity

July 17, 2026

Threat Intel Update

Threat Intel Update

This week’s threats point to more stealth, scale, and automation. Attackers spoofed OAuth client IDs to validate stolen Microsoft Entra ID credentials without tripping sign-in logs, and slipped credential-stealing malware into trusted npm packages via a compromised GitHub Actions workflow.

Initial access is also getting more industrialized as residential proxy botnets, malware like the ClickLock macOS infostealer, and evasive cross-platform delivery are driving credential theft at scale. Microsoft also disclosed GigaWiper, a Windows backdoor combining surveillance with destructive wiping and encryption. Together, these show espionage, cybercrime, and disruptive attacks increasingly converging.

Cybersecurity News

  • OAuth Spoofing Lets Attackers Silently Validate Stolen Microsoft Entra Credentials – Proofpoint found two campaigns using fake-but-valid OAuth client IDs to test stolen credentials against Microsoft Entra ID without triggering sign-in logs or Conditional Access alerts. Over 3 million accounts across thousands of tenants were targeted, and other identity providers may share the same gap. The Hacker News
  • Compromised GitHub Workflow Spreads Malware Through Popular npm Packages – Attackers exploited a misconfigured GitHub Actions workflow to push five malicious AsyncAPI npm package versions, downloaded 2.25M+ times weekly, before removal about four hours later. The packages carried legitimate-looking provenance data and steal credentials, tokens, and crypto wallets; systems that installed them may still be infected. BleepingComputer
  • “Lurking Lizard” Builds Massive Proxy Botnet via Fake Software Installers – Infoblox identified a botnet built from trojanized 7-Zip, WhatsApp, and VPN installers spread across 230+ fake domains since 2022. Infected devices are resold as proxy access, causing victims’ IPs to get flagged for others’ malicious traffic. The campaign spans Windows, macOS, and Android. The Hacker News
  • New Malware “ClickLock” Forces Password Entry by Crashing Mac Apps Repeatedly – Group-IB found ClickLock, a macOS infostealer hitting 100+ victims in 33 countries since May 2026. It kills system processes every 210ms for up to 83 hours until victims type their password, then steals Keychain data, browser credentials, and crypto wallets, evading antivirus entirely. The Hacker News
  • Microsoft Discloses “GigaWiper,” a Windows Backdoor With Destructive Wiping Capabilities – Microsoft disclosed GigaWiper, a backdoor combining remote access and surveillance with disk-wiping and unrecoverable encryption. Its 20 commands let operators manipulate processes, clear logs, and exfiltrate data, enabling long dwell-then-destroy attacks on Windows systems. Hack Read

Sign Up

To receive Threat Briefings by email.

Sign Up Now

Share

About the Author
CampusGuard Logo

CampusGuard Threat Intel Team