
Resurgence of AutoIT Malware, Apple Security Updates, and Critical Nginx Exploit Highlight Cybersecurity Threats
On July 29, 2026, the SANS Internet Storm Center reported a resurgence of AutoIT-based malware distributed via fake bank emails containing RAR attachments. The attack employs multi-layered PowerShell obfuscation, ultimately injecting shellcode into charmap.exe, a legitimate Windows utility, to evade detection. Apple released security updates for iOS, macOS, iPadOS, tvOS, watchOS, and other platforms (versions 26.6 and macOS 14/15), patching nearly 200 vulnerabilities—none actively exploited—though descriptions were minimal. Confiant detailed Sour Trade, a malvertising campaign targeting crypto traders, which generates unique malware per victim using pseudo-random byte streams assembled in the browser to bypass network and endpoint detection. Researchers also demonstrated a reliable proof-of-concept exploit for a patched Nginx heap-based buffer overflow (CVE likely disclosed mid-July 2026), bypassing ASLR to achieve remote code execution on hardened servers. The Nginx exploit underscores the urgency of patching despite initial assumptions about exploitability.