The Canadian Centre for Cyber Security published four security advisories on 2026-07-10 covering critical vulnerabilities in Roundcube Webmail, Broadcom/VMware Tanzu products, Microsoft Edge, and Bitwarden Server. The most urgent advisory (AL25-007 Update 1) confirms ongoing exploitation of CVE-2024-42009 and CVE-2025-49113 in Roundcube Webmail, where attackers first obtain valid credentials via CVE-2024-42009 and then leverage CVE-2025-49113 (a Post-Auth RCE via PHP Object Deserialization) to achieve remote code execution. Both CVEs are listed in CISA's KEV catalog, and a proof-of-concept exists for CVE-2025-49113.
Bitwarden
4 posts
Cyber Centre Daily Advisory Digest — 2026-07-10 (4 advisories) From Cookies to Keys: Why Hackers Don’t Need Your Passwords Anymore Cybercriminals are shifting from traditional credential theft to session hijacking using infostealer malware, allowing them to bypass multi-factor authentication (MFA). By harvesting and replaying valid session tokens using automated tools, attackers gain rapid, stealthy access to corporate environments, which is then often monetized by Initial Access Brokers.
Supply chain attacks hit Checkmarx and Bitwarden developer tools A coordinated supply chain attack compromised official distribution channels for Checkmarx KICS and the Bitwarden CLI, pushing malicious updates designed to harvest developer credentials, cloud keys, and AI assistant configurations. The payloads exfiltrated data to a shared C2 domain and exhibited advanced techniques, including weaponizing stolen GitHub tokens to inject malicious workflows and using victim repositories as dead drops.
Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign The Bitwarden CLI npm package was compromised in a supply chain attack linked to the ongoing Checkmarx campaign. The malicious payload, injected via GitHub Actions, harvests extensive cloud and developer credentials, exfiltrating them through unauthorized GitHub repositories and a dedicated C2 server while employing a Russian locale kill switch and shell profile persistence.