We are pleased to announce that our latest Trellix Endpoint Detection and Response with Forensics (EDRF) Cloud threat detection update for July 2026 is now available.
This cumulative report summarizes the detection content released throughout June 2026, adding 61 new detections to your defense stack.
Key threat coverage
-
State-sponsored APTs and espionage: Expanded coverage for Iranian APT42 targeting the nuclear sector via evolved TAMECAT backdoors, alongside dedicated detections for Russian Gamaredon’s GammaPhish and GammaWorm unified malware taxonomy.
-
Supply chain and evasion techniques: Added detection against fake Claude AI sites using DLL side-loading (PlugX), phishing abusing Google Cloud Run subdomains, and script-based vjw0rm chains masquerading as system binaries (lsass.exe, csrss.exe).
- Zero-day and vulnerability defenses: Deployed proactive detections for critical exploits, including GreenPlasma SYSTEM privilege escalation via ctfmon.exe (CVE-2026-45586), YellowKey BitLocker pre-boot bypasses (CVE-2026-45585), and active Phantom RPC framework exploitation.
These updates are fully compatible with all EDR and EDRF client versions. There is no action required.
For more details and a complete list of the changes, see the release details in the Knowledge article Trellix EDRF Cloud Threat Detection Updates – July 2026.
For more details and a complete list of the changes, see the release details in the Knowledge article Trellix EDRF Cloud Threat Detection Updates – July 2026.