Zscalerのブログ

Zscalerの最新ブログ情報を受信

CXO Insights

Zscaler CXO Monthly Roundup | June 2026

image
DEEPEN DESAI
July 22, 2026 - 9 分で読了

Introduction

The CXO Monthly Roundup provides the latest Zscaler ThreatLabz research, alongside insights into other cyber-related subjects that matter to technology executives. 

This month’s roundup covers a Zenith Live 2026 recap, the evolving Shai-Hulud campaign, SmartApeSG’s third-party widget compromise, MLTBackdoor, an AI-generated ClickFix lure delivering SmartRAT, and Edgecution. Plus updates on Python package typosquatting, World Cup ticketing typosquats, Splunk RCE (CVE-2026-20253), and another fake Android document reader spreading Anatsa.

Zenith Live 2026 Recap

I had the chance to speak with Alex Phillips CIO of NOV at Zenith Live Americas and Peter Gerdenitsch from Raiffeisen Bank International (RBI) at Zenith Live EMEA. 

Peter Gerdenitsch (left) and me at Zenith Live EMEA 2026.

Peter Gerdenitsch (left) and me at Zenith Live EMEA 2026.

Alex described NOV’s journey and how they’re now focused on Zero Trust for offices and microsegmentation to protect legacy systems through ZPA. Peter explained how RBI replaced country-by-country legacy setups with ZIA and ZPA, improving security and user access while reducing attack surface with identity-based access and segmentation.

With both, we discussed how agentic attacks require faster detection and response using better signals, automation, segmentation, and deception.

My keynote focused on a shift we’re all experiencing in security right now: AI is pushing attackers toward autonomous, multi-step operations at machine speed. That means that the traditional model where humans manually piece together alerts, evidence, and responses will not scale.

What’s top of mind for CXOs right now

  • Frontier AI models will accelerate real-world attacks. These models can chain vulnerabilities, pivot through identity, and generate working exploit paths with much higher fidelity than we’ve seen before. On our side, my team has built an AI scanning harness to test how these models perform in real security testing scenarios. This involves both real world attack and defense scenarios that help us measure what frontier AI models can actually do and what defenders should plan for.
  • AI-powered social engineering is scaling fast. ThreatLabz is seeing campaigns that combine phishing with human pressure tactics (including impersonation over collaboration tools), designed to get employees to click, run scripts, or approve “one quick step.” (A good example is the kind of playbook we saw in campaigns like Payouts King.)
  • Supply chain + insider/contractor risk remains a high-impact path. Open-source repositories, third-party access, and developer environments continue to be prime targets because a single compromise can cascade downstream. We’re still seeing open-source libraries and packages targeted in high numbers, especially through npm (for example, Shai Hulud). The “remote worker/contractor” risk pattern continues to show up as well, especially with the North Korean IT worker-style activity aimed at global organizations.

Agentic attack demo

During my keynote I walked through a realistic “agentic attacker” scenario where the attack targeted a technology company with both human and agentic employees. AI-powered attackers can automate an entire attack chain from start to finish. An “agent” can scan a company’s internet-facing systems, find weaknesses, break in by chaining those identified weaknesses, and then move quickly inside the network.

Once inside, the agentic attacker targets developer accounts and tools, steals tokens, passwords, and source code, and sends the data out in ways that can look like normal work traffic. The worst-case outcome is a supply chain attack, where the attacker slips a backdoor into the company’s software so customers get infected too.

When the attackers are targeting your environment at machine speed, you have to respond to those attacks at machine speed.

The response: Agentic SOC + closed-loop remediation

This is why we’re releasing the Agentic SecOps solution (now in limited availability with paying customers). Agentic SOC is an AI-driven security operations layer that connects telemetry across Zscaler platform and core security controls (endpoints/EDR, identity, and cloud), detects real threats, and then orchestrates automated remediation. The outcome is faster containment with fewer manual investigations, and reduced business risk, because response actions can be closed-loop across the tools already deployed in your environment.

Six takeaways for CXOs and security leadership

  1. Hide your attack surface wherever possible. What can’t be discovered is harder to exploit.
  2. Apply Zero Trust everywhere (including inside the office), not just for remote access.
  3. Minimize blast radius with segmentation and deception. Assume breach and contain fast.
  4. Treat AI assets as crown jewels and manage that risk explicitly.
  5. Use the AI-powered Exposure Management solution to find and fix vulnerabilities before attackers do, with prioritization tied to business context.
  6. Modernize SecOps for machine-speed defense with agentic workflows and continuous red teaming.

Watch my full cyber innovation keynote here: “Stopping Cyber Attacks and Modernizing Security Operations session.”

Shai-Hulud Campaign Evolution: Miasma, Hades, and AI Scanner Evasion

ThreatLabz published a blog documenting the evolution of the Shai-Hulud campaign. From the version 1 and version 2 waves to the Miasma and Hades campaigns, Shai-Hulud has evolved from a maintainer-focused npm compromise into broader software supply chain abuse spanning PyPI, CI/CD pipelines, and trusted publishing workflows.

Key developments since version 2 of Shai-Hulud: 

Shai-hulud timeline

Zscaler Zero Trust Exchange Coverage – Zscaler Internet Access (Advanced Cloud Sandbox, Advanced Threat Protection, Advanced Cloud Firewall, SSL Inspection), Deception, Zscaler Private Access (AI Segmentation), Zscaler AI Protect, Zscaler Exposure Management (Asset Exposure Management, External Attack Surface Management, Unified Vulnerability Management)

SmartApeSG Launches Widget Supply Chain Attack

ThreatLabz published a blog analyzing a software supply chain attack where the threat actor group SmartApeSG injected malicious JavaScript into the Okendo Reviews widget. Because this widget is popular and deployed across high-traffic pages, a single compromise could create downstream exposure for any system loading the script. (Before publishing our blog, ThreatLabz reached out to Okendo, which confirmed it was aware of the incident and had restored the widget to a clean state.)

The JS script behaves like a staged browser-based loader that limits runs to avoid detection by using browser state and filtered targets based on environment signals. In addition, the JS script uses obfuscation to conceal where it would fetch the next stage from. Once conditions are met, it dynamically pulls additional content into the page, giving the threat actor flexibility to change follow-on behavior over time.

At a high level, the SmartApeSG loader workflow includes the stages shown in the figure below:

SmartApeSG attack flow

Later stages are consistent with SmartApeSG activity and include ClickFix-style social engineering. From there, the infection chain can deliver additional malicious payloads and enable follow-on activity on affected systems.

Defenders should treat third-party widgets and plugins as critical components especially if they are part of your production applications: inventory them, monitor for changes, and maintain a rapid rollback capability. Back this with strong vendor incident response expectations and controls that prevent supply chain attacks.

Zscaler Zero Trust Exchange Coverage – Zscaler Internet Access (Advanced Cloud Sandbox, Advanced Threat Protection, Advanced Cloud Firewall, SSL Inspection), Deception, Zscaler Private Access (AI Segmentation)

Technical Analysis of MLTBackdoor

ThreatLabz published a blog on MLTBackdoor, a newly identified malware family likely leveraged by ransomware threat actors like Payouts King. MLTBackdoor is delivered through a multi-stage ClickFix infection chain involving a compromised automotive webpage. The malware is designed to establish a foothold, support operator issued commands, and expand functionality through a Beacon Object File (BOF) loader. 

The attack flow is shown below:

MLTBackdoor attack flow

The attack flow starts with a ClickFix lure that convinces the victim to copy, paste, and execute a command. That command creates a temporary directory, downloads a compressed archive, extracts it, and uses rundll32 to execute a dropped DLL. The DLL then decrypts an embedded encrypted payload to load MLTBackdoor, which performs a self update and uses a sideloading technique involving a legitimate signed executable to run under a trusted process context. Once active, MLTBackdoor provides built-in commands and can load BOFs to add new capabilities.

For network communication, MLTBackdoor uses a custom encrypted binary protocol over TLS that blends in with normal traffic, including consistent request formatting and masquerading artifacts. MLTBackdoor derives per session encryption keys using ECDH and protects messages with AES, and it uses a domain generation algorithm (DGA) as a fallback to maintain command and control if hardcoded domains become unreachable.

Zscaler Zero Trust Exchange Coverage – Zscaler Internet Access (Advanced Cloud Sandbox, Advanced Threat Protection, Advanced Cloud Firewall, SSL Inspection), Deception, Zscaler Private Access (AI Segmentation)

ClickFix Campaign Generated Via AI Delivers SmartRAT

ThreatLabz published a blog about a typosquatting domain hosting malicious content generated with AI-powered website creation tools. Threat actors are leveraging website builders to create convincing lures quickly and at scale, with capabilities ranging from basic credential theft to a ClickFix campaign that delivers remote access trojans (RATs).

This specific campaign impersonated a Brazilian bank and used a ClickFix lure to trick victims into running a PowerShell command that downloaded and executed a PowerShell-based RAT ThreatLabz named SmartRAT. 

The attack flow is shown below.

SmartRAT attack flow

SmartRAT supports encrypted C2, remote control, credential theft (including keylogging and bank-branded overlays), QR-code interception, and persistence via scheduled tasks and a Windows service. ThreatLabz also found a critical weakness in the malware’s web-based C2 panel. Its login could be bypassed using client-side localStorage values, indicating design often seen in AI generated infrastructure.

Zscaler Zero Trust Exchange Coverage – Zscaler Internet Access (Advanced Cloud Sandbox, Advanced Threat Protection, Advanced Cloud Firewall, SSL Inspection), Deception, Zscaler Private Access (AI Segmentation)

ThreatLabz Identifies New Attack Technique, Edgecution

ThreatLabz has published a blog analyzing Edgecution, a newly observed attack technique in which a malicious Microsoft Edge extension abuses Chrome native messaging to escape the browser sandbox and enable host-level compromise. The Edgecution attack has two key components: a Microsoft Edge browser extension and a Python script. The attack flow is shown below:

Edgecution flow

The campaign typically begins with Microsoft Teams lures impersonating IT staff and achieving remote control over the victim’s system.

From there, the threat actor uses a fake Microsoft update portal with scripts that allow them to deliver the Edgecution malware and download accompanying artifacts, including a Python script, an extension, and a native directory.

Once installed, the extension beacons to C2 and relays privileged commands via native messaging to the Python component, which performs the primary malicious actions (system discovery, command execution, file operations, process enumeration, and PowerShell execution).

Zscaler Zero Trust Exchange Coverage – Zscaler Internet Access (Advanced Cloud Sandbox, Advanced Threat Protection, Advanced Cloud Firewall, SSL Inspection), Deception, Zscaler Private Access (AI Segmentation)

Updates

Splunk RCE - CVE-2026-20253

ThreatLabz has published a blog on CVE-2026-20253, a critical unauthenticated remote code execution (RCE) vulnerability in Splunk Enterprise. On June 10, 2026, Splunk disclosed the vulnerability which had a CVSS score of 9.8. CVE-2026-20253 stemmed from missing authentication on a PostgreSQL sidecar service recovery endpoint that can be reached through the Splunk Web interface, which proxies requests to the internal PostgreSQL sidecar service without enforcing authentication. A successful attacker can create or truncate arbitrary files and ultimately achieve arbitrary code execution under the Splunk service account.

PyPI typosquatting delivers Telegram backdoor via “parsimonius”

ThreatLabz identified a malicious Python package on PyPI named “parsimonius” that impersonated the legitimate parsimonious library via typosquatting (a one-character difference) and used a newer version number to increase the odds of accidental installation. Before it was removed, the package was downloaded 2,474 times in a matter of days.

Threat actors target World Cup fans

ThreatLabz observed multiple threat actors targeting fans using fake FIFA World Cup ticket websites that mimic legitimate platforms to steal payments and payment-related information. In one example, a Spanish-language site typosquatted a well-known ticket reseller and redirected users into a QR-code-based payment flow.

Fake Android document reader (100K+ installs) drops Anatsa trojan

ThreatLabz discovered another fake document reader app on the Google Play Store with 100K+ downloads that delivers the Anatsa Android trojan.

form submtited
お読みいただきありがとうございました

このブログは役に立ちましたか?

免責事項:このブログは、Zscalerが情報提供のみを目的として作成したものであり、「現状のまま」提供されています。記載された内容の正確性、完全性、信頼性については一切保証されません。Zscalerは、ブログ内の情報の誤りや欠如、またはその情報に基づいて行われるいかなる行為に関して一切の責任を負いません。また、ブログ内でリンクされているサードパーティーのWebサイトおよびリソースは、利便性のみを目的として提供されており、その内容や運用についても一切の責任を負いません。すべての内容は予告なく変更される場合があります。このブログにアクセスすることで、これらの条件に同意し、情報の確認および使用は自己責任で行うことを理解したものとみなされます。

Zscalerの最新ブログ情報を受信

このフォームを送信することで、Zscalerのプライバシー ポリシーに同意したものとみなされます。