Search/acronis
Vendor

acronis

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
cyber infrastructure
Connections
98 relationships
Acronis warns of actively exploited flaw in its cPanel backup plugin
Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. cPanel & WHM and Plesk are used by web hosting companies and server administrators to manage websites and servers through graphical interfaces. Acronis’ backup add-ons connect the hosting control panel to the company's infrastructure, allowing administrators to back up and restore websites, files, databases, mailboxes, and hosting accounts from within the cPanel and Plesk interfaces. The flaw was published in a brief advisory last weekend, but the technology company issued an update today, identifying it as CVE-2026-87886 and assigning it a severity score of 7.8. A low-privileged attacker can exploit CVE-2026-87886 to increase their permission level on a vulnerable Linux server, potentially enabling them to access or modify sensitive data and disrupt the system without user interaction. Further technical details on CVE-2026-87886 have not been published, as the company wants to give system administrators time to apply the available patches before sharing more information. Acronis says it has detected exploitation of the vulnerability in the wild, "in limited, targeted attacks." “Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin for cPanel & WHM deployments,” the advisory warns. In a statement for BleepingComputer, Acronis notes that the assessment is based on a single report from a "potentially affected" customer. The CVE-2026-87886 vulnerability affects the following product versions: Acronis Backup plugin for cPanel & WHM builds earlier than 1.9.3.1021, fixed in version 1.9.3 HF3 Acronis Backup extension for Plesk builds earlier than 1.8.11.638, fixed in version 1.8.11 The company has identified no specific indicators of compromise and did not disclose when the activity occurred or what attackers achieved beyond the privilege-escalation impact described by the advisory. All affected users of Acronis backup integrations for cPanel & WHM and Plesk are recommended to apply the available updates immediately. Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat
bleepingcomputer.comSep 15, 2026extracted
Ransomware protection for MSPs: A 6-point checklist for faster recovery
Ransomware protection for MSPs should deliver six tested outcomes: reduce exposure, detect activity before encryption, provide 24/7 response, preserve isolated recovery points, recover cleanly and operate consistently across tenants. Backup alone is not enough, and neither is endpoint detection without a rehearsed recovery path. The Acronis Cyberthreats Report identified 143 MSP, IT-service provider and telecom ransomware victims in 2025, with phishing accounting for 52% of initial access cases and unpatched vulnerabilities for 27%. The checklist below turns those failure modes into controls and evidence an MSP should require before calling a service complete. The six things your service must do and what to verify A complete ransomware protection service connects prevention, detection, response and recovery. For each control, demand evidence from the exact tenant, workload, storage configuration and service tier being sold. Important: Immutable, offline and air-gapped describe different controls. Verify each one separately. How EDR, XDR, MDR and immutable backup work together EDR monitors endpoint activity and supports investigation, isolation and remediation. XDR connects endpoint signals with other attack surfaces so analysts see one incident instead of separate alerts. MDR adds people and process: a staffed service investigates and responds around the clock. Immutable backup protects recovery points from alteration or deletion; it neither detects data theft nor replaces incident response. Use them together. In the Acronis model, EDR provides endpoint detection and response, XDR extends visibility to email, identity and Microsoft 365 applications, and Acronis MDR operates on EDR or XDR. Acronis Cyber Protect Cloud supplies the backup, management and multi-tenant operating layer. Immutability is one recovery control; it is not the same as an offline or air-gapped copy. Acronis Cyber Protect Cloud with Acronis MDR brings prevention, detection, 24/7 response, backup and recovery into one multi-tenant platform. See how you can reduce operational complexity, protect recovery points and respond faster across client environments. Explore Acronis MDR The recovery runbook: Cut recovery time at every handoff Recovery time is the total of detection, triage, containment, clean-point selection, restoration and validation. An MSP reduces RTO by shortening every stage - especially the handoffs between security, backup, identity, networking and the client. Declare the incident, assign one commander and open an out-of-band channel. Identify affected tenants, identities, workloads and likely initial access. Isolate compromised endpoints and block malicious sessions, tokens and remote access. Preserve evidence before wiping systems or rotating logs away. Close the entry point by patching, disabling access and rotating credentials. Choose the latest recovery point that predates compromise and passes validation. Restore identity and infrastructure dependencies before applications and user data. Scan, test, reconnect in stages and monitor for renewed attacker activity. Acronis backup scanning and malware-free recovery capabilities can help validate candidate recovery points, while Acronis Disaster Recovery can coordinate recovery workflows where licensed. The incident team should still confirm that the selected point predates the compromise. Automation should remove repeatable waits, but an incident commander should approve high-impact actions such as mass isolation, credential resets and failover. A rehearsed path preserves the option to recover without paying, although no tool can guarantee recovery in every attack. After each drill, record achieved RPO/RTO and every delay, then revise the runbook from evidence rather than estimated restore speed. Is immutable backup enough against double-extortion ransomware? No. Immutable backup can preserve recoverability, but it cannot retract data that attackers already stole or remove breach-notification duties. A ransomware protection service must therefore look for exfiltration and identity abuse before encryption begins. Correlate endpoint, identity, email, Microsoft 365, DNS, proxy and egress telemetry. During response, isolate devices, revoke sessions and tokens, rotate credentials, block attacker destinations and preserve evidence for legal and notification decisions. Acronis EDR provides endpoint context and response, while Acronis XDR adds telemetry and response across email, identity and Microsoft 365 applications; network egress evidence may still come from firewalls, SIEM or other client controls. Test those handoffs in advance. How to evaluate an MSP ransomware platform Before buying or standardizing a platform, require a live demonstration of these seven items: Coverage for client workloads and tenant tiers. Prevention and detection before broad encryption begins. Named 24/7 response ownership, escalation paths and approval boundaries. Immutable-storage mode, retention behavior and privileged-access separation. Clean-point selection, malware scanning and isolated restoration. Measured RPO/RTO in a dependency-ordered recovery drill. Multi-tenant roles, reporting, audit evidence and RMM/PSA/API integrations. An integrated option is Acronis Cyber Protect Cloud with Acronis MDR. It brings together capabilities for the six operational jobs, subject to the selected MDR tier, licensing, deployment, storage architecture and the MSP’s incident-response responsibilities. Require a live incident-and-recovery test using the production configuration. Frequently asked questions What is the best ransomware protection for an MSP? A complete ransomware protection service should demonstrate all six outcomes across the client workloads it is contracted to protect. Acronis Cyber Protect Cloud with Acronis MDR is an integrated example. The MSP should validate the production configuration and confirm whether the selected MDR tier includes the required remediation and recovery actions. What should be included in a ransomware protection service? Include exposure reduction, EDR or XDR detection, 24/7 response, access-separated immutable recovery points, tested clean recovery and multi-tenant operations with client evidence. How can an MSP reduce ransomware recovery time? Remove handoff delays. Preassign owners, map dependencies, validate clean points, automate safe steps and rehearse restores until achieved RPO/RTO matches the service commitment. Does immutable backup stop double-extortion ransomware? No. It protects recovery data from change or deletion but cannot undo exfiltration. Detection, identity controls, egress visibility, containment and notification processes are still required. Make recovery a tested service outcome Ransomware resilience is the ability to contain attacks early, preserve a recovery path and prove critical services can return on schedule. Acronis Cyber Protect Cloud with Acronis MDR can bring detection, response, recovery and multitenant management into one MSP operating model. The MSP should validate the selected tier, storage architecture, integrations and operational responsibilities against the six tests above. See how Acronis Cyber Protect Cloud with Acronis MDR helps MSPs detect and contain ransomware, protect recovery points, and restore client operations faster. Sponsored and written by Acronis.
bleepingcomputer.comSep 2, 2026extracted
Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools
Individuals and organizations in Cambodia have emerged as the target of a new campaign that delivers an open-source remote access trojan (RAT) called Spark RAT. "The samples employ diverse lure themes, suggesting an effort to appeal to a broad range of potential victims. These include government notices, public health materials, real estate-related content, and other topics," Acronis Threat Research Unit (TRU) researchers Darrel Virtusio and Subhajeet Singha said in an analysis published Wednesday. The multi-stage attack is notable for employing the bring your own vulnerable driver (BYOVD) technique to load a legitimate-but-vulnerable driver associated with OPSWAT AppRemover ("ardrv.sys") to escalate privileges and neutralize security software. Attack chains likely make use of targeting phishing emails to distribute compressed archives containing an Inno Setup executable and trick recipients into running it using wide-ranging lures, including Cambodian government notices, public health announcements, dental examination records, real estate documents, and promotional offers. Acronis said it discovered a number of malicious artifacts between late June through early August 2026, although it's unclear if the campaign remains ongoing. The Inno Setup installer is designed to trigger a DLL side-loading chain using a signed Tencent executable, which then delivers interim payloads responsible for deploying the vulnerable "ardrv.sys" and then launching the Spark RAT payload. Spark RAT is an open-source, Go-based cross-platform RAT that enables remote control of compromised devices. The DLL loader also carries out a timing-based anti-sandbox check to detect environments that shorten or manipulate sleep delays, and proceeds to terminate execution if the elapsed time falls outside the expected range. Furthermore, it reviews running processes for those related to Huorong Internet Security ("HipsTray.exe"), a Chinese endpoint security program. If the process is present, the loader attempts to weaken the privileges of the security product. In the next stage, it decrypts shellcode concealed within a PNG file present in the archive to run a second stager, which verifies if it is running with SYSTEM privileges. "Based on these checks, the payload selects one of two execution modes," Acronis said. "If it is already running as SYSTEM, it proceeds directly to inject mode, bypassing the persistence setup and executing the next stage. Otherwise, it enters setup mode, where it establishes persistence first, then executes the next stage." The inject mode works by parsing and decrypting shellcode embedded in another PNG file from the archive, and then injecting it into "vssvc.exe" and executing it within the context of the target process. To ensure the injected payload remains running, it monitors the "vssvc.exe" instance and re-injects the shellcode if the process terminates or restarts with a new PID. In the setup mode, the malware reads and decrypts the shellcode from the same file, after which it checks for a list of hard-coded processes associated with Qihoo 360. If none of them are found, it sets up a Windows service-based persistence mechanism to launch the binary that sideloads the DLL to relaunch the entire cycle all over again. After establishing persistence on the host, it injects the shellcode into "vssvc.exe" like before. The payload performs the following sequence of actions - Attempt to patch AMSI and ETW related functionality Setup persistence using a scheduled task Install the ardrv.sys driver that's vulnerable to CVE-2026-36425 to terminate security-related processes such as Microsoft Defender, Huorong Internet Security, and Tencent PC Manager Read and decrypt another embedded payload from a third PNG file to perform user-mode termination of hard-coded security processes Simultaneously, a fourth PNG-based payload file is processed to extract and decrypt shellcode that's injected into "ctfmon.exe," ultimately leading to the execution of Spark RAT. Interestingly, the BYOVD routine references a number of other drivers, including those part of TrueSight and Zemana Anti-Malware SDK, both of which have been put to use by the Silver Fox threat actor prior to dropping Winos 4.0 (aka ValleyRAT). In addition, the targeting of Huorong security processes has been repeatedly observed in past Silver Fox-related attacks. Other Silver Fox-style indicators include targeting overlaps, the use of DLL sideloading through a signed application, multi-stage payload delivery, persistence through Windows services and scheduled tasks, and Microsoft Defender exclusions. Despite these similarities, there is not enough evidence to definitively attribute the latest activity to the threat actor. This assessment, Acronis said, is based on the absence of shared infrastructure, function-level code reuse, and matching certificates. Another crucial differentiator is the choice of the malware itself. While Silver Fox campaigns are known to leverage ValleyRAT and other custom payloads, it has not been attributed to the deployment of an open-source RAT. "This difference does not rule out a relationship, since operators can change payloads, but it removes one of the stronger links used in previous attributions," the cybersecurity company added. "The Spark RAT configuration contains a Chinese-language value, and the malware targets several security products commonly used in Chinese-speaking environments." "We therefore track the activity as an unattributed cluster with possible Chinese-language development or deployment links and operational similarities to the broader Silver Fox ecosystem. This assessment remains low confidence and may change if additional code, infrastructure, victimology, or other attributional evidence is identified."
thehackernews.comAug 27, 2026extracted
Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight
Cybersecurity companies this week shared information about new and updated banking trojans targeting users worldwide. These types of malware can enable their operators to phish credentials, steal sensitive user data, and remotely control compromised devices. Manic ThreatFabric has detailed Manic, described as an Android malware that combines banking trojan and spyware capabilities. The malware has mainly been used against Ukraine, including banks, government services, and messaging applications. However, it has also been observed targeting Russian and European financial institutions, global cryptocurrency and fintech services, and military-focused messaging apps. Distributed via malicious websites and droppers, the malware enables attackers to log keystrokes, display phishing screens, and remotely control the compromised phone for banking and cryptocurrency fraud. In addition, Manic includes spyware capabilities such as notification monitoring, location tracking, file harvesting, and remote device surveillance. “A particularly distinctive capability is its offline mesh relay, which allows collected data to move through nearby infected devices over Wi-Fi Direct or Bluetooth when direct C2 access is unavailable,” ThreatFabric noted. Grandoreiro The Acronis Threat Research Unit warned that the Grandoreiro banking trojan remains active, continuing to focus on users in Latin America. Grandoreiro was also seen targeting Europe last year, and it continues to target Europe alongside North America. However, a recent campaign monitored by Acronis saw the bulk of attacks aimed at Mexico. The Windows malware, of Brazilian origin, has been around for a decade, and it has continued to improve despite law enforcement’s attempts to disrupt it. Recent samples abuse the legitimate Duplicate Files Finder (DFF) application to execute malicious code through DLL sideloading. This allows the malware to blend with regular software activity and avoid detection. “The initial sample incorporates extensive anti-analysis functionality, including sandbox detection, virtual machine artifact checks, process blacklisting and environment profiling designed to evade automated analysis systems,” Acronis explained. “These checks are performed before any attempt to contact the command-and-control (C2) infrastructure, suggesting that avoiding analysis is a high priority for the operators.” ToxicPanda 2.0 Mobile security firm Zimperium has issued a warning over an updated variant of ToxicPanda, which is known to mainly target Europe. The Android banking trojan’s latest version introduces significant changes, including support for 167 remote commands and a target list of nearly 350 financial applications; previous versions targeted only 16 apps. ToxicPanda 2.0 is designed to target financial institutions across 16 countries, including Pakistan, South Africa, Mexico, Nigeria, India, Indonesia, and Panama. “The malware also introduces an automated click-based mechanism to abuse Android Wireless Debugging (ADB), enabling privilege escalation and shell-level access on compromised devices,” Zimperium explained. It added, “The updated campaign also reveals a shift in distribution methods, with ToxicPanda 2.0 samples being delivered through Amazon AWS-hosted buckets, indicating the attackers are leveraging cloud infrastructure for malware delivery.” Related: Rust Supply Chain Attack Linked to North Korean Hackers Related: AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions
securityweek.comAug 22, 2026extracted
ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit, and More
A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do. Signed drivers get turned against defenses. Legitimate apps help malware blend in. A weak header check opens a path to code execution. Elsewhere, exposed systems, old bugs, odd hiding tricks, and AI-assisted exploit research keep lowering the effort needed to cause damage. Nothing here needs much decoration. The small gaps are doing enough work already. The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out. Signed driver abuseIn new research, Check Point has reverse engineered Microsoft Defender's Defender Boot-Time Removal driver ("BTR.sys") and demonstrated that it's possible to repurpose the signed remediation driver as a universal kernel operation engine to bypass endpoint security solutions by exploiting a "golden window" between system start and user mode initialization without having to rely on the bring your own vulnerable driver (BYOVD) method. "Because BTR.sys is a legitimate Microsoft-signed component, signature-based blocking is ineffective," security researcher Jiří Vinopal said. "Furthermore, a well-crafted weaponization tool (like BTR_CLI) intentionally mimics the operational footprint of the legitimate Windows Defender remediation process." $10 million rewardThe U.S. Department of Justice (DoJ) has charged 17 members of the Mabna Institute, an Iran-based company that, since at least 2013, has conducted a coordinated campaign of cyber intrusions into computer systems for 144 U.S.-based universities, 178 foreign universities, at least 42 U.S.-based private sector companies, at least 11 foreign private sector companies, at least five U.S. federal and state government agencies, and at least two non-governmental organizations (NGOs). The Mabna Institute has been accused of stealing more than 31 TB of academic data and intellectual property from these universities, as well as the email accounts of employees at the private sector companies, government agencies, and NGOs. In all, the Mabna Institute targeted more than 100,000 accounts of professors around the world, successfully compromising approximately 8,000 of them. The defendants carried out these intrusions on behalf of Iran's Islamic Revolutionary Guard Corps (IRGC). The Mabna Institute was founded by Gholamreza Rafatnejad and Ehsan Mohammadi around 2013. "The campaign started in approximately 2013, continued through at least December 2017, and broadly targeted all types of academic data and intellectual property from the systems of compromised universities," the DoJ said. "In addition to stealing academic data and login credentials for the benefit of the Government of Iran, the defendants also sold the stolen data through two websites, Megapaper.ir (Megapaper) and Gigapaper.ir (Gigapaper)." The U.S. Department of State is offering a $10 million reward for information about five of the defendants, or associated individuals or entities. "Mabna represents the privatization of state espionage: a contractor selling stolen research to whoever's paying, with the IRGC as an anchor client rather than a sole owner," Shmuel Gihon, Security Research Team Lead of Exposure Management at Check Point, told The Hacker News. "That's the trend to watch: capable, deniable, commercially-run crews doing state-level work at industrial scale, with universities as the perfect target. They offer enormous IP value, thin identity controls, and an open-access culture that phishing exploits directly. We've seen this blurring of cyber-criminal and state-sponsored activity before, but historically it's been more associated with Russian-speaking crews. What this case shows is that Iran and the IRGC are increasingly playing the same game." DLL sideloading campaignA new Grandoreiro malware campaign has been found abusing the legitimate Duplicate Files Finder (DFF) application to run malicious code via DLL sideloading. According to telemetry data from Acronis, Grandoreiro activity remains concentrated in Latin America, with Mexico, Spain, Peru, and Argentina accounting for the lion's share of infections. "The initial sample incorporates extensive anti-analysis functionality, including sandbox detection, virtual machine artifact checks, process blacklisting and environment profiling designed to evade automated analysis systems," Acronis said. "These checks are performed before any attempt to contact the command-and-control (C2) infrastructure, suggesting that avoiding analysis is a high priority for the operators." ClickFix meets BYOVDErrTraffic-generated ClickFix campaigns have been observed attempting to deliver Cruciferra, which, in turn, employs a legitimate but vulnerable driver ("DCRCVDrv.sys") as part of a BYOVD attack to escalate privileges and terminate security processes. ErrTraffic, sold by a threat actor named LenAI, is a malware-as-a-service (MaaS) framework and a traffic distribution system (TDS) that's designed to distribute multiple threats through compromised WordPress websites, ClickFix social engineering, and EtherHiding. In recent months, ErrTraffic has been used to deliver Remus Stealer, Vidar Stealer, Okobot, LegionLoader, OnionDrop-related payloads, and BabaDedaLoader, per WatchGuard. "Victims land on compromised WordPress sites injected with an obfuscated ErrTraffic-generated JavaScript loader," eSentire said. "The loader resolves its C2 domain by querying a Polygon smart contract, then sends a request to the C2 to retrieve the next stage to serve a ClickFix lure." The end goal of the attack is to launch Remus Stealer via process hollowing. Private AI processingOpenAI has announced a privacy-centric safety approach to monitoring model misuse. The company said it's previewing a new service to select customers that it calls Private Safety Processing, which keeps tabs on potential abuse without retaining customer data. "For ZDR deployments, customer content remains on infrastructure the customer controls," OpenAI said. "We are also developing an option in which content is stored on OpenAI infrastructure, encrypted with keys controlled by the customer. In both cases, automated systems can identify potential misuse and return limited safety signals without exposing the underlying prompts or responses to OpenAI personnel." The system clearly takes aim at rival Anthropic, which has a 30-day retention policy for business customers who want to use its Mythos-class models. In a related development, Google has showcased Homomorphic Encryption Intermediate Representation (HEIR), which enables cryptographically secure private AI inference on encrypted inputs. "HEIR (Homomorphic Encryption Intermediate Representation) is an open-source compiler toolchain and development platform for homomorphic encryption," Google said. "In particular, HEIR can convert pre-trained AI models that operate on unencrypted data to operate on encrypted inputs." Guardrail-free AIA new AI-powered service called Kriminal AI offers paying customers a way to get answers about everything, without any of the filters or guardrails that are typically implemented by AI platforms. "Kriminal.AI gives you raw, uncut intelligence — the questions other AIs refuse to touch," the website claims. The service claims to have more than 2,300 users. Kriminal AI follows WormGPT, FraudGPT, and Xanthorox into a market that has expanded quickly to attract users who may be frustrated by safety, security, and ethical safeguards embedded into widely used models. Subscriptions for Kriminal AI start at $12.99/month and go all the way to $99.00/month. The most concerning aspect is that the service is not lurking in the dark web. It's accessible on the clearnet, and comes with a tagline: "No filters. No guardrails. No "I can't help with that." Kriminal.AI gives you raw, uncut intelligence — the questions other AIs refuse to touch." According to ThreatDown, the service appears to make use of Grok for primary inference; Google Cloud and Cloudflare for hosting; Anthropic's Claude for a long-context model layer; Llama routed through OpenRouter for certain specialized tasks; Tavily for live search; NowPayments for cryptocurrency checkout (no KYC included, apparently); and Cloudflare/Let's Encrypt for DNS and TLS. ATT consent changesApple has agreed to make changes to its App Tracking Transparency (ATT) feature in Germany, after the Federal Cartel Office, or FCO, found the feature gave its own apps more favorable consent prompts than those of third-party developers. Apple has four months to implement the changes after. According to a statement issued by Apple, the changes will apply in almost all European Union countries. "The differences between the consent request used for Apple’s own offerings and the consent request predefined by Apple for third-party apps exceeded what could be justified based on differences in types of data processing," FCO said. "The wording, design and selection options of the request used for Apple’s own offerings had the potential to encourage users to give their consent, whereas they had the potential to discourage consent for third-party apps. In addition, third-party apps in some cases had to request consent several times even when users had already given data protection law-compliant consent." Apple was fined €98.6 million (then $116 million) in December 2025 by Italy's antitrust authority after finding that ATT restricted App Store competition. Refrigeration controllers exposedClaroty's Team82 has discovered 23 vulnerabilities in Copeland XWEB Pro controllers, including those that can be chained to bypass security mechanisms and achieve root-level remote code execution. A compromised controller could be used to remotely manipulate refrigeration equipment, including cooling fans and compressors, and conceal the resulting temperature increase while silently allowing the food to spoil. Multiple vulnerabilities have also been disclosed in Danfoss AK-SM 800A refrigeration controllers, including a "hidden 'code-of-the-day' authentication mechanism that could be abused to bypass normal authentication, a command-injection vulnerability leading to remote code execution." A second flaw allowed authenticated users to inject arbitrary Nginx configuration directives, which could be abused to manipulate web traffic and trigger a denial-of-service condition. All the identified vulnerabilities have been fixed by the respective vendors. C2 hidden in whitespaceA hand-written Windows backdoor has been found to store its C2 domain as the number of trailing spaces in a fake desktop.ini file. The 12 KB backdoor was discovered by Gen Digital on a single corporate workstation while hunting for unusual WMI persistence. "The malware was small, had a limited command set and disguised itself as legitimate Realtek software," Gen said. "Its most unusual feature was its configuration: the address of its command-and-control server was not stored as readable text or encrypted data, but encoded in the number of spaces on each line of a Windows 'desktop.ini' file. To a user, and to many automated inspection systems, the file would appear almost empty. To the malware, those spaces spelled out its server address." There is no evidence connecting the backdoor to a known threat actor. The absence of related samples indicates that it may have been a deliberately targeted operation. Maximum-severity RCEA maximum-severity security flaw in Gogs (CVE-2026-52813, CVSS score: 10.0) could be exploited to achieve remote code execution through Git hooks. "Organization names containing path traversal sequences (../) are accepted by Gogs, and repositories under them are written to paths following these path traversals," according to a June 2026 advisory. "This allows storing/retrieving data for repositories at arbitrary locations on the filesystem. By creating a nested structure of Git repositories, one can overwrite the other's hooks configuration to result in Remote Code Execution (RCE)." The issue was addressed in version 0.14.3, alongside patches for CVE-2026-52810 (a logic bug to write on read-only repositories) and GHSA-6vxv-wg6j-5qwp (an XSS flaw in the outdated version of "jsvine/notebookjs" used to render Jupyter notebook files). Aikido Security has been credited with discovering and reporting the flaws. Memory leak via PostScriptDetails have emerged about a now-patched out-of-bounds read flaw in Apple macOS Spotlight (CVE-2026-43774, CVSS score: 5.5) that could be exploited by a malicious app to access sensitive user data. The vulnerability was patched by the iPhone maker in late July 2026. "The vulnerability is in the Spotlight PostScript plugin," Iru researcher Csaba Fitzl said, adding an attacker can use a specially crafted .ps file to trigger the vulnerability. It requires three conditions to be met: (1) The file is at least 4000 bytes, (2) A DSC comment keyword (e.g., %%Creator:) appears somewhere in the first 4000 bytes, and (3) The bytes following the keyword, up to byte 4000, contain no control characters. Unauthenticated CI/CD takeoverA critical security flaw has been disclosed in @circleci/mcp-server-circleci that could result in remote code execution by means of a specially crafted request. "With one well-placed request, an attacker achieves an unauthenticated RCE in your CI/CD pipeline, taking full control of your build secrets and cloud identities," Remedio said. The attack takes advantage of the fact that the Host and Origin headers associated with an HTTP request used to block browser-based attacks can be set by a network-adjacent threat actor. "Send a simple HTTP request that says Host: localhost in the HTTP header with no Origin, and you get right through," Remedio said. "Once in, you can freely communicate with connected tools. Call the "run pipeline" tool, hand it the pipeline configuration you wrote, and add a step to run your commands. CircleCI executes it using the organization's token." The vulnerability has been fixed in version 0.19.2 of the npm package. Workflow-to-RCE chainA critical vulnerability in n8n, an open-source workflow automation platform, can allow an authenticated user with permission to create or modify workflows to exploit a prototype pollution vulnerability in the XML and the GSuiteAdmin nodes and achieve remote code execution on the n8n instance. The issue (CVE-2026-33696, CVSS score: 9.4) has been fixed in versions 2.14.1, 2.13.3, and 1.123.27. Security researcher Simon Koeck, who discovered the Flaw, said the prototype pollution alone is serious enough to crash the entire n8n instance, but can be chained to obtain full code execution and allows the attacker's command to be run as the n8n process user. Cable cut stopped intrusionIn late 2024, reports emerged of a Salt Typhoon campaign that targeted T-Mobile and other major U.S. telecommunications companies as part of a cyber espionage effort to gain access to valuable customer data. Although the activity was caught before the Chinese cyber spies could siphon any data from T-Mobile's networks, the company has now revealed to Bloomberg that its staff spent months looking for suspected intruders without much success, only to eventually trace unusual behavior on one of its systems coming from a Chicago router belonging to a different telecom company. Jeff Simon, T-Mobile's chief information officer, said he and three others drove to the data center that housed the compromised device and "pulled out a pair of scissors" to cut the cable. AI exploitation gainsChinese AI startup Z.ai has released GLM-5.3, a new AI model that it said is better suited for complex coding and long-horizon tasks. "GLM-5.3 is state of the art on CyberGym for vulnerability discovery, and its gains are largest further up the exploitation chain, where it more than doubles GLM-5.2 on exploitation benchmarks," it said. "GLM-5.3 did not simply become better at identifying isolated flaws: it began to reason across multiple stages of exploitation, forming coherent plans for complete exploitation chains," Z.ai said it has been working with several security teams in China to run its open-source models against real-world codebases, identifying 2,436 vulnerabilities across 269 projects, including 1,097 medium-to-high severity issues. "The findings span system kernels, operating systems, browser engines, open-source infrastructure, web applications, and network protocols," it said. "Many had remained unnoticed for years or even decades, with the oldest dating back roughly 40 years." Despite these advances, benchmarks show that GLM-5.3 lags behind Anthropic Mythos 5 in converting discovered flaws into working attacks. The useful part of weeks like this is that the attacks rarely begin with magic. They begin with trust, exposure, weak assumptions, and things nobody thought worth abusing. That leaves plenty to fix. Tighten what gets trusted, question the defaults, and keep looking at the boring edges. Attackers clearly are.
thehackernews.comAug 20, 2026extracted
41 deceptive download sites show a real link, then send you somewhere else
We identified a network of 41 websites impersonating popular games and Windows software, all designed to push visitors towards the same Download Studio installer. The sites advertise everything from Counter-Strike, Half-Life, Fallout, Roblox, PUBG, and The Witcher to VLC, 7-Zip, Paint.NET, VMware, Total Commander, and Foxit PDF. They go to surprising lengths to look convincing, using accurate product information, genuine developer resources, and even real download links. But the link you see isn’t the link you follow. One site promises Counter-Strike. Hover over its download button and the browser displays a genuine Steam Store address. Click the button, however, and Steam never opens. The link looks safe when you hover, but the click says otherwise. One of the oldest web-safety tips is to hover over a link before clicking it and inspect the destination shown by your browser. We even recommend doing this when checking emails for phishing links and scams. But it isn’t foolproof. This campaign shows how a site can display a legitimate destination when you hover over a link, then send you somewhere completely different when you click it. On the Counter-Strike page, the download button contains a legitimate Steam Store URL. That is the address the browser displays when you hover over it. But JavaScript on the page handles the click separately. Instead of following the Steam link, the script cancels the expected navigation and sends the visitor through an affiliate redirect. The legitimate Steam URL provides reassurance, but isn’t the actual destination. The page goes further by linking to genuine Steam resources in its footer and presenting itself as a straightforward source of technical information. That veneer disappears the moment the download button is pressed. 41 sites, one destination The Counter-Strike site isn’t an isolated example. Across the 41 sites we identified, the branding and advertised downloads change, but visitors are ultimately pushed towards the same software: Download Studio. One site, GTA 6 PLAY, claims to offer a PC download of Grand Theft Auto VI. It provides installation instructions, system requirements, and everything else you might expect from a real game-download page. There is one rather significant problem: There is no announced PC version to download. Rockstar currently lists Grand Theft Auto VI for PlayStation 5 and Xbox Series X|S, with a release date of November 19, 2026. It has not announced a PC release. After visitors follow the download process, they’re shown instructions telling them to install Download Studio. Here’s an example of that screen from the Counter-Strike site: In other words, the advertised software is the lure. Installing Download Studio is the destination. The software lures are even more convincing The same technique appears on pages advertising ordinary Windows applications. A fake VLC Media Player page, for example, places a genuine VideoLAN download address inside its download button. It also identifies VideoLAN’s servers as the source of the file. At the time of our research, VLC 3.0.23 was VideoLAN’s current release. So the information shown to the visitor can be completely accurate. The link can be real. The version can be real. The developer can be correctly identified. Then the click handler overrides all of it. Instead of allowing the browser to retrieve VLC from VideoLAN, the page sends the visitor toward Download Studio. Even the signature advice can mislead you The VLC lure also recommends checking the installer’s digital signature before running it. A digital signature allows Windows to verify who signed a piece of software and whether the signed file has been changed since it was signed. To check one, right-click the downloaded file, select Properties, then open the Digital Signatures tab. You can select the signature and click Details to see whether Windows considers it valid and who signed it. Normally, that’s a useful check. But the Download Studio installer passes it. The sample we examined is validly signed by Grand Media, TOV. So you could follow the page’s advice, see that Windows considers the signature valid, and still have downloaded something completely different from what you intended. That’s because a valid signature tells you who signed a file and whether the signed content has been altered. It doesn’t tell you that you’ve downloaded the program you intended to. Microsoft’s own Authenticode documentation makes the same distinction. Code signing provides information about the publisher and integrity of a file. It does not guarantee that signed software is trustworthy. The lures include everyday software This campaign isn’t limited to people looking for unreleased games. VLC, 7-Zip, Paint.NET, and AIMP are legitimate applications people routinely download. Someone searching for one of them is doing nothing unusual. Other lures target security, backup, and recovery products, including Avast, Acronis, and Recuva. Someone looking for everyday software, or even software to protect or recover their computer, can be pushed into installing a program they never asked for. What the sites actually deliver The sample delivered during our research is a roughly 73 MB Windows installer for Download Studio. It is signed by Grand Media, TOV, and the signature validates successfully. Our analysis found Download Studio installing and launching its own interface and torrent components. The program registers torrent and magnet associations, and its installer includes an option to make Download Studio the default torrent client. The installation also enables its automatic updater. Importantly, our analysis did not establish that Download Studio itself is malware. What this campaign clearly demonstrates is that people looking for one piece of software are being deceptively funneled into installing another. The redirect includes affiliate tracking, suggesting there may be a commercial incentive. Download Studio has relevant history There is another reason Download Studio’s automatic updater caught our attention. In 2020, researchers at Avast found that Download Studio’s automatic updates had been used to silently distribute FakeMBAM, a backdoor disguised as a Malwarebytes installer. Avast monitored Download Studio’s updates and observed the fake Malwarebytes installers being delivered and executed in the same way as legitimate updates, silently in the background and without users knowingly initiating the installation. The backdoor could download additional malware, and the persistent payloads Avast observed were cryptocurrency miners. When the researchers contacted Download Studio’s developers, they said they had detected a security incident involving their continuous-integration server, investigated it, and added additional security measures. Avast said the developers did not answer follow-up questions about how many users were affected or whether they had been notified. The research also named Grand Media, TOV among the companies associated with the applications involved. The Download Studio installer we examined in this campaign is also signed by Grand Media, TOV. There is no evidence that the Download Studio installer in this campaign is malicious or that the same attack is happening again. But its automatic-update mechanism has previously been abused to distribute malware, making the fact that the current installer enables automatic updates relevant. Check what you actually downloaded There is another simple check that exposes the bait-and-switch used by these sites. Right-click the downloaded executable, select  Properties , and open the Details tab. For the sample we examined,  File description  and  Product name  identify Download Studio,  Original filename  is  DS-Setup.exe , and the copyright information names Grand Media. If you clicked a button labelled “Download VLC” and those fields say “Download Studio,” you have an immediate and obvious mismatch. The Details tab isn’t proof that a file is safe, however. The software publisher controls that information, so a malicious program could use convincing product names and descriptions. Instead, look at the whole download: Did it come from the developer or a trusted store? Is it signed by the publisher you expected? And does the file identify itself as the program you meant to download? How to protect yourself There are a few simple ways to avoid getting caught by this kind of download bait-and-switch: Get software directly from the developer’s website or a trusted app store. For games, use a legitimate store such as Steam or the publisher’s own store. Don’t rely on hovering over a link alone. As this campaign shows, a page can display a legitimate destination and then send you somewhere else when you click. A valid digital signature doesn’t mean you got the right program. Check  Properties > Details  and confirm the product name matches what you wanted. If a download page says you need to install a separate download manager first, close it. If a game hasn’t been released for your platform, a site claiming to offer an official download cannot have it. If Download Studio is already installed and you didn’t choose it, remove it through  Settings > Apps  and run a  full virus scan . Malwarebytes Browser Guard  blocks pages like these before they load, which stops the problem before you’ve downloaded anything. Indicators of Compromise (IOCs) File hashes (SHA-256)   9a3f6e69c12cb814c45862219ecb17e9ab7744877c9da1c49f3ea046437f8fca  ( DS-Setup.exe ) Network indicators   r.byteengineering[.]net   apis.downloadstud[.]io downloadstudio[.]net dstudio[.]app   getdownloadstudio[.]net   4kvideodownloader[.]ru acronisportal[.]ru cristalixmine[.]ru , crystaldisk24[.]ru csgodownload[.]ru cupheadplay[.]ru fallout24[.]ru farcryplay[.]ru faststoneportal[.]ru formatf[.]ru foxitpdf[.]ru get7zip[.]ru getaf[.]ru getaimp[.]ru getavast[.]ru getbandicam[.]ru getbluestacks[.]ru getmovavi[.]ru getrecuva[.]ru getultraiso[.]ru getvmware[.]ru getvuescan[.]ru gogetter24[.]ru gta6-play[.]ru halflife-play[.]ru memuemulator[.]ru paintdotnet[.]ru pdfxchange[.]ru poppyplaytimeplay[.]ru pubgplay[.]ru rdrplay[.]ru regorganize[.]ru roblox-play[.]ru rust-play[.]ru   tcommander[.]ru tf2play[.]ru   thewitcherplay[.]ru uninstalltooll[.]ru   vlcmp[.]ru   windowsmp[.]ru yandereplay[.]ru Stop threats before they can do any harm. Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →
malwarebytes.comAug 19, 2026extracted
Grandoreiro Resurfaces in Mexico With New DLL Sideloading Campaign
Grandoreiro has resurfaced in a campaign targeting Latin American users, with Mexico accounting for 40% of observed detections and attackers using DLL sideloading to execute the banking trojan through legitimate software. The Brazilian-origin malware remains active despite a major law-enforcement operation in January 2024 that disrupted parts of its infrastructure. Acronis’ Threat Research Unit (TRU) observed the renewed campaign in May 2026, while telemetry from the last 30 days of June showed Mexico as the largest source of detected samples. The findings add to previous Grandoreiro campaigns targeting Mexico and the malware's earlier expansion into Spain. Grandoreiro Abuses Legitimate Software The latest campaign abused the legitimate Duplicate Files Finder application as part of a DLL sideloading chain. Attackers renamed the application and placed a malicious mingwm10.dll alongside legitimate dependencies, causing the trusted executable to load the malicious library. The initial loader also used extensive anti-analysis checks. It looked for virtualization and sandbox artifacts, security and analysis tools, system characteristics and specific user and machine configurations before attempting to contact its command-and-control (C2) infrastructure. It also checked the victim's public IP address and geolocation, while traffic from several countries was blacklisted. Acronis said the malware's initial delivery vector could not be confirmed, although an invoice-like ZIP filename and Grandoreiro's historical distribution patterns led them to assess with moderate confidence that spam had been involved. The malware used encrypted strings to complicate analysis and contacted its C2 infrastructure only after completing its environmental checks. The C2 server was offline during the researchers' analysis, but static examination indicated that the loader would attempt to retrieve a second-stage payload after establishing communication. Mexico accounted for 40% of detections in the analyzed telemetry, followed by Spain at 17%, Peru at 13% and Argentina at 10%. Activity remained concentrated in Latin America, with smaller detection clusters in Europe and North America. Acronis said overall Grandoreiro activity remained below its previous peak but continued to evolve, indicating that the 2024 disruption had not eliminated the malware operation.
infosecurity-magazine.comAug 19, 2026extracted
Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants
Overview of the attack In July 2026, Kaspersky experts detected a new attack by the Head Mare group. Previously, we classified them as hacktivists, but now we define them as an APT group due to the sophistication of their TTPs and the absence of destructive activity (encryption, wiping) in the targeted infrastructures. In this latest campaign, the attackers exploited a chain of vulnerabilities in the TrueConf video conferencing server and replaced the original TrueConf client installers with infected versions that installed the PhantomCore malware on the system. An investigation of the compromised server revealed that the attackers used a combination of two new vulnerabilities (assigned the internal identifiers KLCERT-26-057 and KLCERT-26-058), allowing them to execute arbitrary code with the highest privileges. The attack occurs in several stages: The attackers connect to the TrueConf server without prior authorization via port 4307/TCP, which, according to the product documentation, is open by default. The attack targets TrueConf servers running versions 5.3.X through 5.3.9, 5.4.X through 5.4.9, and 5.5.X through 5.5.5. Once connected, attackers call a server function to transmit a malicious script and execute it on the server. The vulnerability that allows this stage of the attack to be carried out has been assigned the internal identifier KLCERT-26-057. The received script runs on the TrueConf server in an isolated environment. By default, operating system functions are not accessible in this environment, which should limit the capabilities of the executed code. To escape the isolated environment, attackers exploit a second vulnerability, assigned the internal identifier KLCERT-26-058. Exploiting this vulnerability allows them to bypass the restrictions of the isolated environment and proceed to execute commands in the context of the operating system. Once the environment’s restrictions are bypassed, attackers gain the ability to execute arbitrary code on the server with the privileges of the NT AUTHORITY\SYSTEM account. Once they have gained elevated privileges, attackers replace the file …\public\js\locale.php with a web shell, which can be used for subsequent remote control of the compromised server. This web shell was used for the following activities: collecting data on the IT infrastructure; gaining privileged access to the TrueConf database; replacing the original TrueConf Client distribution with an infected version containing the PhantomCore backdoor. The vulnerabilities exploited by the attackers were patched by the vendor in the latest TrueConf Server updates (versions 5.3.9, 5.4.9, and 5.5.5). These updates were released on June 18, 2026. The PhantomCore backdoor was successfully detected by Kaspersky solutions. To automatically launch the malware after the system boots, a registry key is created: HKEY_CURRENT_USER\Software\Classes\CLSID\{0340F119-A598-4ed9-B0AC-6F6A12D3E755}\InprocServer32, with the value set to the path to the malicious program’s file. Using a web shell, in addition to PhantomCore, the attackers load a backdoor that we have named PhantomGraph, consisting of two modules: SysExcSvc.dll is responsible for receiving commands from the attackers and transmitting the results of their execution. The attackers used an account on Microsoft OneDrive cloud storage as their command-and-control (C2) server. SysReadSvc.dll reads the command transmitted by the first module, executes it, and saves the execution result. To establish persistence on the system, the attackers execute a Base64-encoded PowerShell command that installs SysExcSvc.dll and SysReadSvc.dll as Windows services. We believe the attackers deliberately split this malicious command into two components to make it harder to detect using EDR tools. Additionally, the program’s code partially matches that of PhantomCore, indicating that it belongs to Head Mare’s arsenal. We also managed to identify the commands executed by the attackers when connecting to the backdoor. The SysReadSvc module executes commands using a BATCH file. Example of execution: Commands detected: Memory dump of the lsass.exe process: Reconnaissance of the user and system names: Launching an SSH reverse tunnel: In addition, we discovered several commands that did not work due to the attackers’ typos and encoding issues. We are observing several active Head Mare campaigns targeting Russian organizations across various industries: instrument manufacturing, electronics, transportation, energy, IT, and software development. The attackers distribute their backdoors using various methods, including phishing, exploiting public web servers, or through a subcontractor. We recommend that all organizations using TrueConf software install the latest server version (versions 5.3.9, 5.4.9, and 5.5.5) in accordance with the vendor’s recommendations. We also recommend verifying that the client distributions downloaded from the TrueConf server used by your organization have a valid TrueConf digital signature and have not been tampered with. The malicious distributions we detected did not have a valid digital signature. You can also verify authenticity on the vendor’s website. Important: Even if your organization does not use a TrueConf server, your employees may connect to compromised TrueConf servers belonging to business partners to participate in online meetings and download infected installation packages. The attack mechanism and the vulnerabilities exploited are described in more detail on the Kaspersky ICS CERT website. Detection by Kaspersky solutions Kaspersky security solutions successfully detect malicious activity associated with the attacks described above. The malware used in this attack is detected by our solutions with the following detection names: Backdoor.PHP.WebShell.abi, Backdoor.Win64.PhantomCore.dt, Trojan.Win64.Agent.smgvnc, Trojan.Win64.Agent.smgvnb, HEUR:Backdoor.Win64.PhantomCore.gen, HEUR:Backdoor.Linux.Agent.fb, HEUR:Backdoor.Linux.PhantomHook.a, HEUR:Backdoor.Linux.PhantomReact.a, Trojan.Win64.PhantomGraph.gen UDS:Backdoor.Win64.PhantomCore.a Let’s take a closer look using Kaspersky Endpoint Detection and Response Expert (KEDR Expert) as an example. Specifically, activity involving the replacement of the legitimate file …\public\js\locale.php with a web shell, as well as the deletion of entries from TrueConf event logs, is detected by the rule unusual_php_file_creation_from_trueconf_process. Downloading a file containing the PhantomCore backdoor via the replaced legitimate file …\public\js\locale.php is detected by KEDR Expert with the rule unusual_file_creation_from_trueconf. Activity related to the installation of an infected TrueConf client installer containing the PhantomCore backdoor is detected by KEDR Expert using the unsigned_trueconf_installer rule. The Kaspersky Managed Detection and Response service detects the described attack by monitoring the following actions: Creation of suspicious files by TrueConf Server processes. Execution of a TrueConf Client installer file that lacks a software developer’s signature. Suspicious process chains associated with TrueConf Client executables and TrueConf Client update executables. Registration of suspicious libraries in the HKEY_CURRENT_USER\Software\Classes\CLSID\ registry key. Actions related to retrieving information about the lsass.exe process. Memory dump creation for the lsass.exe process using thecomsvcs.dll library. Accessing the memory of the lsass.exe process. Creating tunnels using the ssh process. To protect companies using our Kaspersky SIEM system, a general set of rules is available in the product repository that allows detection of the following techniques: Creation of suspicious files in the C:\Windows\System32\inetsrv\* directory: R405_07_File write to IIS native modules folder or OWA via WriteData. Creating a memory dump of the lsass.exe process using thecomsvcs.dll library: R233_04_Process memory dump via comsvcs.dll. Accessing the memory of the lsass.exe process: R262_Suspicious access to the LSASS process. We also recommend paying attention to the following events when developing your own detection rules or conducting threat hunting: Registration of suspicious libraries in the registry key \Software\Classes\CLSID\{0340F119-A598-4ed9-B0AC-6F6A12D3E755}\InprocServer32: Creating the SysExcSvc andSysReadSvc services to run executables from temporary directories in the background via cmd: Creation of suspicious processes originating from the TrueConf update process (trueconf_windows_update.exe) For the detection rules to work correctly, ensure that events from Windows systems are received in full, including Security events 4688, 4663, 4657, and 4697 and Sysmon events 1, 7, 11, and 13. Indicators of compromise File hashes (MD5) Web shell 4d27b4eb1c5dbb3d8160f29b8119523e locale.php Infected installer 748c9f8cb1065000616204935f96207f trueconf_windows_update.exe PhantomCore DLL c5a460e4e68a088f6e51b2c6474642ec 129462164a7d52e9ea8560b60f0412c5 doc.txt ec0bf4a2186a88874e9f26f07cfeb532 usocacheddata.txt b348642146ea34771e5785c5857950f5 c915cb6c2aeb863ee8479238e1644217 doc.txt 0e79996d9483d1e44fea32b0a48c2c19 doc.txt 2bb75c20e778eb5c416965bd4d4259b1 trueconf_windows_client_x64_[redacted].exe b3a6fee3307f1c26841fd5c603e2b013 usocacheddata.txt 8fcc3e4ccbf1725d9989fb464abf3561 usocacheddata.txt PhantomGraph 489f43be558b2679284ceabed7adc4f3 sysexcsvc.dll dd1fd2b459b97b7d59375cb8383cd19a sysreadsvc.dll 0e4541c3153ec5ed01497f19cf4f63d0 sysexcsvc.dll 12d4e8f5295f2ef7e0f9bfc0f4830939 sysexcsvc.dll 7f267006cac10f341c356b62fe493527 sysexcsvc.dll ee2861d5965e8730708cd1da8a93fa4c sysexcsvc.dll Backdoor (ELF) c3a2abe8756910f42582b04a44ea3514 43f435c3c437bc879a2d7d4634f43494 Rootkit aee9642b45b099cb7f3053b9b680b425 IP 81.177.32[.]12 194.87.239[.]71 ssh 194.87.93[.]153 ssh 38.244.205[.]244 31.59.102[.]61 Domains Windows service names SysExcSvc SysReadSvc File paths C:\Windows\System32\inetsrv\SysExcSvc.dll C:\Windows\System32\inetsrv\SysReadSvc.dll C:\Windows\System32\inetsrv\graphi-refresh.dat C:\Windows\System32\inetsrv\share\input_*.txt C:\Windows\System32\inetsrv\share\output_*.txt %TEMP%\cmd_cmd_*.bat %LOCALAPPDATA%\TrueConf\Client\api-ms-win-crt-time-l1-1-0-2.dll /etc/systemd/system/omicluster.service /etc/systemd/system/schedul2-bin.service /opt/acronis/bin/schedul2-bin /omi/bin/omicluster /usr/lib64/libzvbi-tchain.so.2 /var/tmp/cx2 Registry keys HKEY_CURRENT_USER\Software\Classes\CLSID\{0340F119-A598-4ed9-B0AC-6F6A12D3E755}\InprocServer32 Kaspersky detection names Backdoor.PHP.WebShell.abi Backdoor.Win64.PhantomCore.dt Trojan.Win64.Agent.smgvnc Trojan.Win64.Agent.smgvnb HEUR:Backdoor.Win64.PhantomCore.gen HEUR:Backdoor.Linux.Agent.fb HEUR:Backdoor.Linux.PhantomHook.a HEUR:Backdoor.Linux.PhantomReact.a Trojan.Win64.PhantomGraph.gen UDS:Backdoor.Win64.PhantomCore.a YARA rules
securelist.comAug 11, 2026extracted
Backup su larga scala: dagli indicatori di stato “verde” alla reale capacità di ripristino
Si considera spesso il backup come un controllo secondario fino a quando non diventa l’ultima risorsa disponibile. In caso di attacco ransomware, interruzioni operative o cancellazioni accidentali, ciò che conta davvero è disporre di backup recenti e utilizzabili. L’analisi della telemetria globale di Acronis Cyber Protect relativa agli ultimi mesi del 2025 evidenzia come l’aver completato correttamente un backup non garantisce automaticamente la reale capacità di recovery. Indice degli argomenti Da un lato, i job possono terminare oltre la finestra pianificata, riducendo l’efficacia dell’RPO, aumentando anche la pressione sugli ambienti di produzione; dall’altro, gerarchie negli ambienti MSP aumentano significativamente la complessità e il rischio di errore. Nella settimana peggiore del periodo analizzato,l’1% dei backup più lenti ha richiesto fino a 185 minuti, mentre il5% dei backup più complessi ha impiegato tempi da 26,5 a 30,5 volte superiori rispetto a un tipico backup. Inoltre, al dodicesimo livello delle directory, il tasso di errore sale al 39,78%, rispetto al 9,5% registrato al livello precedente. Per assicurare una reale prontezza al ripristino, le organizzazioni dovrebbero definire obiettivi misurabili, progettare pianificazioni che tengano conto dei casi più critici e ridurre la complessità operativa, rafforzando monitoraggio, governance e capacità di risposta. Tre fattori hanno ampliato il divario tra lo stato percepito dei backup e l’effettiva prontezza al ripristino. Gli autori degli attacchi ransomware spesso tentano di eliminare o crittografare i backup accessibili per impedirne il ripristino. La Cyber sercurity and Infrastructure Security Agency (CISA) statunitense raccomanda di conservare backup offline e crittografati e di testare regolarmente la disponibilità e l’integrità dei backup in scenari di ripristino di emergenza. Anche lelinee guida di Microsoft sottolineano che gli attacchi ransomware prendono di mira i dati, i backup e la documentazione necessaria per il ripristino, fornendo indicazioni su come proteggere e verificare i backup. Le piccole e medie imprese (PMI) e le aziende di medie dimensioni ricorrono sempre più spesso al backup come servizio gestito. Il modello multitenancy migliora l’efficienza operativa, ma aggiunge complessità strutturale in termini di autorizzazione, isolamento, ereditarietà e osservabilità. L’Azure Architecture Center e le linee guida AWS sul SaaS multitenant descrivono questi compromessi. I sistemi su larga scala sono influenzati dal comportamento delle cosiddette ‘code’ (tail): eventi rari e lenti possono modificare i risultati complessivi. Jeffrey Dean e Luiz André Barroso hanno spiegato come episodi temporanei di elevata latenza influenzino le prestazioni su larga scala. Le operazioni di backup mostrano dinamiche simili: anche se la maggior parte dei processi è veloce, in un parco sistemi di grandi dimensioni alcuni saranno inevitabilmente lenti ogni notte. Questa si verifica quando i team danno per scontato che la pianificazione all’interno di una cornice temporale implichi il completamento entro tale periodo. Un processo può comunque essere contrassegnato come riuscito anche se termina dopo l’inizio della giornata lavorativa. Ciò crea un rischio nascosto: contese a livello di produzione e un punto di protezione più datato del previsto. Questa descrive un aumento non lineare dei tassi di errore man mano che le gerarchie degli utenti diventano sempre più numerose. La complessità della gerarchia è un indicatore della complessità amministrativa: un numero maggiore di livelli di controllo comporta un numero maggiore di confini RBAC (Role-Based Access Contro) e una maggiore complessità nell’instradamento degli alert e nella gestione delle eccezioni. Le gerarchie molto strutturate possono aumentare il rischio di errore perché rendono più complessa la gestione operativa. Con l’ingresso di nuovi client e configurazioni non standard, le eccezioni alle policy tendono ad accumularsi, creando possibili disallineamenti tra pianificazioni, credenziali e regole di conservazione. Inoltre, gli alert possono essere inviati ai team che non dispongono delle autorizzazioni necessarie per intervenire rapidamente, con il rischio di prolungare i tempi di risoluzione e far ripetere gli stessi problemi. La crescente eterogeneità degli ambienti, delle reti e delle destinazioni di backup rende più difficile standardizzare le configurazioni, mentre pianificazioni simili tra diversi sub-tenant possono generare picchi di carico e accentuare ritardi e sovrapposizioni. Per l’utente finale, questo rende fondamentali report specifici sul proprio ambiente, indicatori come il completamento entro la finestra prevista, l’età effettiva dell’ultimo punto di ripristino e i risultati dei test di restore. Sono inoltre necessari SLA di escalation chiari, responsabilità definite, policy standardizzate con eccezioni documentate e verifiche periodiche delle impostazioni ereditate, oltre a una pianificazione della capacità che consideri i picchi di utilizzo e i comportamenti più critici. I due fenomeni si rafforzano a vicenda: i backup con tempi di esecuzione più lunghi superano la finestra prevista, mentre le gerarchie amministrative complesse rendono più difficile individuare e risolvere rapidamente i problemi. Il risultato può essere un sistema apparentemente stabile, con dashboard prevalentemente positive, che però accumula nel tempo un rischio crescente per la capacità di ripristino. Le pianificazioni vengono spesso definite sulla base dei tempi di esecuzione tipici, ma una parte dei job richiede tempi più lunghi e termina in ritardo pur risultando tecnicamente riuscita. I ritardi possono sovrapporsi ai cicli successivi o alle attività dell’inizio della giornata, aumentando il carico e generando un effetto a catena che rende più probabili ulteriori rallentamenti. Di conseguenza, l’ultimo punto di ripristino realmente disponibile può essere più vecchio di quanto previsto, anche se il backup risulta completato con successo. Le gerarchie profonde aggravano il problema perché policy, eccezioni, alert e responsabilità sono distribuiti su più livelli. Questo può rallentare la remediation, rendere meno chiara la responsabilità degli interventi e far sì che errori intermittenti si ripetano senza essere risolti in modo tempestivo. In caso di ransomware, outage o modifiche errate, l’effetto combinato diventa evidente: i recovery point sono meno recenti del previsto, i restore richiedono più tempo e quelli che sembravano piccoli problemi operativi notturni possono trasformarsi in un impatto concreto sul business. Le raccomandazioni si rivolgono sia alle aziende che gestiscono direttamente i backup sia a quelle che si affidano a un provider. Il primo passo è definire risultati di recovery chiari e misurabili per ciascuna tipologia di carico di lavoro, stabilendo entro quale orario il backup debba essere completato per risultare realmente utile al business. Un job concluso oltre tale soglia dovrebbe essere considerato un problema operativo, anche se tecnicamente riuscito. È quindi importante monitorare il completamento entro la finestra prevista, i tempi dei job più lenti, l’età effettiva dell’ultimo punto di ripristino disponibile e l’esito dei test di restore. Le pianificazioni e la capacità devono essere progettate considerando i picchi e i casi più critici, non solo le prestazioni medie. Scaglionare gli avvii, separare i workload più pesanti e prevedere risorse adeguate per notti caratterizzate da aggiornamenti, grandi variazioni di dati o attività di fine mese riduce il rischio di code e rallentamenti a catena. Nei servizi gestiti, la governance deve essere parte integrante dell’offerta: report dettagliati sul singolo ambiente, SLA di escalation concreti, responsabilità chiare e verifiche periodiche delle policy aiutano ad intercettare eccezioni, configurazioni incoerenti e problemi derivanti da gerarchie complesse. È inoltre utile introdurre controlli immediati al termine della finestra di backup, affinché si analizzino anche i job completati in ritardo. Un sistema di alert differenziato per criticità e una breve revisione quotidiana delle anomalie notturne consentono di individuare i problemi prima che si accumulino. capacità di ripristino Occorre verificare la capacità di ripristino in modo continuativo. I test di restore dovrebbero essere eseguiti con regolarità su workload critici, registrando non solo l’esito ma anche i tempi di recupero e la correttezza dei dati ripristinati. Documentazione, credenziali e procedure operative devono restare aggiornate e disponibili anche in condizioni di degrado. Quando appropriato, è infine consigliabile mantenere copie di backup offline o logicamente isolate e testarne periodicamente l’effettiva recuperabilità. Alcuni dati di telemetria analizzati confermano che il backup deve essere considerato un sistema operativo continuo e non una semplice attività notturna. Pianificare i processi sulla base dei tempi medi può infatti sottostimare il reale fabbisogno operativo, poiché una parte dei job richiede tempi molto più lunghi e può terminare oltre le tempistiche utili per il business. Inoltre, la gestione dei backup su larga scala introduce rischi di complessità non lineari: gerarchie molto profonde aumentano sensibilmente la probabilità di errore, anche se questa complessità resta spesso invisibile al cliente finale. Di conseguenza, un servizio può apparire regolare dall’esterno, mentre le condizioni interne riducono progressivamente l’effettiva capacità di recovery.
cybersecurity360.itJul 24, 2026extracted
ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories
Most of this week's trouble came dressed as something useful. A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders to an AI agent. Other threats hid in open systems, weak code, and normal network traffic. The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out. The danger was easy to miss because it looked ordinary. Here is the full list: Support uploads face cutoffGitHub has announced an upcoming security change that may affect GitHub Enterprise Server (GHES) support bundle uploads. "Beginning August 18, 2026, GitHub will start rejecting command-line support bundle uploads from older GHES appliances that have not been updated with the required security patches," GitHub said. "To avoid any disruption when submitting support bundles with ghe-support-bundle, ghe-cluster-support-bundle, or ghe-support-upload commands, please update your GHES instance to the latest patch release available for your current version line." At minimum, the required patch versions are: 3.21.3, 3.20.5, 3.19.9, 3.18.12, and 3.17.18. Npm install triggers stealerAn npm package named @copilot-mcp/apex has been found to act as a postinstall dropper that installs a macOS infostealer on any machine that runs npm install or npx @copilot-mcp/apex. The same payload is said to have been distributed via another dropper named @apexfdn/apex. "On macOS, the dropper's second stage decrypts and runs an AppleScript payload through osascript," SefeDep said. "The decrypted payload is a 707-line AMOS-family stealer: it phishes the login password through a fake system prompt, then harvests browser credentials, 20+ crypto wallets, SSH keys, AWS and Kubernetes credentials, the login Keychain, Telegram, and shell history into /tmp/osalogging.zip and uploads it over chunked HTTPS PUT to attacker infrastructure." The malware also sets up a LaunchAgent that polls the attacker's command-and-control server every 60 seconds to ensure that the infection outlives the initial exfiltration. Fake extension opens backdoorA Microsoft Visual Studio Code (VS Code) marketplace extension called "Markdown All Pro" ("markdown.markdown-all-pro") has been found to impersonate the legitimate "Markdown All in One" extension with over 14 million downloads. Installing the rogue extension allows the machine's details to be shipped to the attacker and opens a channel through which the operator can send any additional commands without having to touch the extension again. "On install, these beacon the machine's username and hostname to a hardcoded IP over cleartext HTTP and fetch a remote file to disk, with no user interaction required," Manifold Security said. "This one is small, but it deliberately misrepresents itself as a trusted tool, and the remote fetch it performs is a live delivery channel whose payload the operator can change at any time." After the extension was removed by Microsoft, it reappeared under an identical name ("MarkdownLinks.markdown-links-pro"). The second extension has since been taken down as well. Old releases locked downThe Python Package Index (PyPI) has made a new security change that rejects new files being uploaded to releases that are older than 14 days. "This restriction was put in place to prevent old and long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects were compromised," PyPI said. "As far as we are aware, this has not yet been abused, but there is no technical reason beyond that attackers weren't aware it was possible." Phishing delivers banking malwareA new malware campaign is targeting Portuguese users through phishing emails impersonating financial and administrative communications to deliver the Lampion banking malware. First publicly documented in December 2019, the Brazilian banking malware family is derived from the ChePro lineage, and has consistently targeted Portugal and other Portuguese-speaking users. "Initial payloads are delivered through ZIP archives containing heavily obfuscated HTML files designed to evade static detection and analysis," Acronis said. "The HTML stage retrieves and executes additional scripts from attacker-controlled infrastructure, leading to the deployment of a multistage VBS infection chain. Each stage employs extensive obfuscation techniques, including junk code, encrypted strings and dynamically generated scripts, significantly inflating file sizes while concealing core functionality. The infection chain is deliberately fragmented across multiple independent execution stages, complicating behavioral analysis and reducing the visibility of malicious activity." Call endings trigger adsDoubleVerify has uncovered a growing wave of "AfterCall" apps that trick users into granting special permissions, which then display intrusive ads immediately after Android users end a phone call. The ad fraud scheme is assessed to be responsible for hundreds of millions of ad impressions. "The fraud works by tricking users into granting overlay permissions, allowing malicious apps to display ads outside their normal context," DoubleVerify said. "The apps also use evasion techniques that make them difficult for users to identify and uninstall." Fake Claude app drops RATHuntress disclosed that between July 21 and July 22, 2026, at least 29 organizations fell victim to a malvertising campaign that redirected them to a malicious Claude Artifact publicly hosted on the legitimate Claude.ai domain. "The malicious Claude Artifact redirected users to an attacker-controlled domain, where they downloaded what looks like a legitimate Claude desktop app (ClaudeDesktop.exe)," Huntress said. "In reality, the executable led to the download of SectopRAT. The attackers used an array of anti-analysis techniques, including packaging the malware with VMProtect to make it difficult to reverse engineer and checking the graphics hardware on systems before deciding whether to actually execute the malicious payload as a way to suss out VMs." The public Claude Artifact has been removed as of July 22, 2026. The campaign has been codenamed FakeAgent. Image hides agent instructionsA new attack technique called GhostCommit employs a pull request that can steal a repository's secrets by hiding the malicious instruction inside a PNG image that's processed by an LLM reviewer. "The text rendered in that image names .env, tells the agent to read it byte-by-byte, to encode each byte as its ASCII codepoint, and ends with a self-check that must pass before commit: the decoded numbers have to equal the real .env," the University of Missouri-Kansas City's ASSET Research Group said. "The image is the only place in the entire pull request where any of this appears. Unfortunately, for a text-based reviewer, an image is a binary blob, so there is nothing to read." Once the change is committed and merged, the payload just sits in the repository, dormant, until the trap springs itself when a victim prompts the coding agent in an unrelated session. "The developer asks the coding agent for something ordinary, say a token-tracking module," the researchers said. "The agent reads the merged AGENTS.md at startup, follows the pointer to build-spec.png, reads the procedure rendered inside, opens .env, and writes the requested module with a provenance constant near the top." Iran-linked actors target PLCsThe U.S. government has issued an update to an advisory published in April 2026 to warn organizations of ongoing Iranian-affiliated cyber activity targeting internet-connected operational technology (OT) devices. "The update provides new guidance to detect malicious changes in reusable code modules used within Rockwell Automation PLC programs and adds more recommended mitigations," the Cybersecurity and Infrastructure Security Agency (CISA) said. "It also expands the manufacturer scope to include observed targeting of Schneider Electric, Siemens, and possible other PLC manufacturers. The additional manufacturers being targeted emphasize the importance for OT owners and operators to restrict direct internet access and ensure secure PLC deployment." The authoring agencies said the Iranian-affiliated activity has disrupted PLCs across several U.S. critical infrastructure sectors by attempting to download malicious project files and manipulate data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays. Targets include Water and Wastewater Systems, Energy, and Government Services and Facilities. The federal advisory does not mention any specific hacking groups. Fake alert app enables surveillanceDream has disclosed details of an Android app that masquerades as a Bahraini Civil Defense "BH Alert" siren app but embeds a malware called OctagonPanel to hoover sensitive data from a compromised device. "It is distributed through a network of look-alike domains that clone the Google Play Store and official Bahraini government sites, complete with fake install animations and ad-tracking pixels, and it deploys a four-stage surveillance platform capable of harvesting lockscreen credentials, SMS and one-time codes, contacts, and screenshots, running banking-app overlays, and taking full remote control of the device," Dream said. "It relies on social engineering and the abuse of legitimate Android permissions, delivered under a public-safety brand at a moment when users are primed to install it." Earlier this March, the cybersecurity vendor highlighted another phishing campaign that distributed a trojanized version of the Israeli "Red Alert" app to silently collect valuable data. Fake apps deliver surveillance RATAn Iran-nexus threat actor tracked as TAG-182 has been observed disseminating MarkiRAT malware in support of Iranian government surveillance operations. "It is highly likely that TAG-182 is targeting Iranians living inside and outside the country using different lures, including free download tools and fake VPN applications," Recorded Future said. "The group's operations are highly likely active across social media platforms like Instagram." The malware is distributed through fake Android applications masquerading as legitimate services such as VPNs and media tools to collect intelligence from Iranian targets. "The MarkiRAT sample identified during this research shares notable tradecraft overlaps with historical variants, including the use of the Background Intelligent Transfer Service (BITS), suggesting a credible relationship between TAG-182 and activity previously attributed to Ferocious Kitten," the cybersecurity company added. AI-built apps expose critical flawsAn analysis of 28 vibe-coded apps has uncovered 434 unique and validated vulnerabilities. "The most common bug in AI-generated code overall is missing rate-limiting and DoS controls (such as unbounded pagination, no rate limits, or synchronous blocking work)," Xint said. "When we narrow our focus to the most critical bugs, a different picture emerges. Secret exposures made up the largest share of the most critical bugs in AI-generated code. These are hard-coded or default secrets that allow an attacker to forge sessions or tokens. Authorization and IDOR bugs - a type of flaw where a user gets access to data beyond their permissions - were more common in larger apps." AI guardrails become attack toolsAn enterprising Russian-speaking threat actor known as Trim has "spent the better part of 2026 systematically dismantling the guardrails on publicly available frontier AI models and rebuilding them as offensive tools," Cato Networks said. "What started in March as a knowledge-sharing post on a Russian cybercrime forum detailing how to break Claude Opus into writing malware, had evolved by June into a fully productized, commercially marketed AI-powered penetration testing platform." Trim has also outlined six techniques for jailbreaking Claude Opus: Context Warming, which involves opening with innocent professional queries before slipping in a malicious request; Black Box Principle, which strips the model of the ability to reason by instructing it via system prompt to analyze only code structure; Ghost Reset, which involves gaslighting the model mid-session by deleting an ongoing chat, reopening it, telling Claude that the internet dropped, and feeding it a softened version of the refused request; Model Cascading, which falls back to alternative AI models if one refuses to comply; Local Uncensored Models, which uses self-hosted or locally run AI models with few or no safety guardrails when commercial models block requests; and Gray-Market API Access, which obtains low-cost API keys from underground resellers to access commercial AI models. The findings once again demonstrate that frontier AI safety controls can be bypassed by a determined and technically literate adversary, and how quickly threat actors can capitalize on generative AI. DNS traffic conceals TrickBot C2A new version of the TrickBot malware has been observed using DNS tunneling to communicate with its command-and-control (C2) servers. "To protect itself from static analysis, TrickBot employs several obfuscation techniques," Fortinet said. "This TrickBot maintains persistence on the victim's computer by leveraging the Windows Task Scheduler. TrickBot wraps its command-and-control request packets in encrypted DNS query packets." While normal DNS response packets typically contain the IP addresses associated with the queried domain, TrickBot uses it to hide the malicious data within the IP addresses of these responses. This, in turn, allows the malware to fetch commands to be executed on the machine or download and run additional modules. AI models pinpoint vulnerable codeCisco has unveiled Antares, which it frames as a "family of security small language models (SLMs) purpose-built for one of the hardest, most time-consuming and expensive problems in security: pinpointing where known vulnerabilities exist within a codebase." The network equipment company further noted that "Antares follows an iterative search pattern that resembles how a human investigator works through a repository. Each model starts from a vulnerability description, searches for relevant code patterns, reads candidate files, incorporates new evidence, changes direction when a path is unhelpful, and narrows toward the files most likely to matter. The goal is not to replace expert judgment, but rather to help make the first stages of source-code vulnerability triage faster, more repeatable, and easier to review." The common thread was not advanced hacking. It was borrowed trust. Each threat used something people already accept: an install, a permission, a familiar name, or a normal system feature. That changes the job. The question is no longer only "Is this safe?" It is also "What can this do if it is not?" The smaller the action looks, the tighter its limits should be.
thehackernews.comJul 23, 2026extracted
How enterprise GenAI can amplify ransomware risk — and how to contain it
Generative AI is rapidly becoming part of everyday business operations. Employees use AI assistants to summarize documents, search enterprise knowledge, draft content and automate routine tasks. Organizations are also beginning to deploy AI agents that interact with business applications and execute workflows with minimal human intervention. These technologies promise significant productivity gains, but they also introduce new security considerations. As AI gains access to the same identities, business data and systems that cybercriminals already target, it can increase the speed and scale of ransomware attacks if not properly governed. AI does not create an entirely new ransomware threat. Instead, it amplifies techniques attackers already use, particularly during reconnaissance, credential abuse and data theft. Understanding where AI changes the attack surface is becoming an important part of enterprise cyber resilience. Two AI threat models organizations should understand Discussions about AI and ransomware often combine two different threat models: Attackers using AI to improve their own operations. Criminal groups increasingly rely on AI to generate phishing emails, write malicious code, automate reconnaissance, analyze stolen information and streamline extortion. AI allows attackers to work faster and operate at greater scale without fundamentally changing how ransomware campaigns unfold. Organizations deploying enterprise AI. AI assistants and agents are increasingly connected to document repositories, collaboration platforms, SaaS applications and internal knowledge bases. If attackers compromise the identities or permissions associated with these systems, AI can accelerate their ability to locate sensitive information, navigate connected systems and abuse legitimate access. These two trends are occurring simultaneously. As attackers become more efficient through AI, organizations must ensure their own AI deployments do not unintentionally expand the attack surface. Where enterprise AI creates new exposure Not every AI application presents the same level of risk. AI assistants primarily retrieve information or generate content in response to prompts. AI agents go further by interacting with business applications, invoking APIs and performing actions on a user's behalf. The greater an application's autonomy and permissions, the greater the potential impact if its associated identity is compromised. The real issue is delegated authority. Modern ransomware campaigns typically begin with vulnerability exploitation, credential compromise or abuse of trusted third-party access. Attackers then perform discovery, escalate privileges, identify valuable data and exfiltrate information before deciding whether to encrypt systems, extort victims or both. Microsoft reports analyzing approximately 38 million identity risk detections every day, underscoring how central identity attacks have become. The Cloud Security Alliance has also documented large-scale OAuth device-code phishing campaigns targeting Microsoft 365 users. AI-enabled applications introduce new security challenges, from prompt injection and unauthorized data access to AI-assisted reconnaissance. Acronis GenAI Protection helps identify shadow AI usage, monitor prompts and AI interactions, detect policy violations, and provide visibility into AI-related risks alongside endpoint, identity, SaaS, and backup telemetry. Strengthen detection, response, and recovery with a unified cyber resilience platform. Learn more about Acronis GenAI Protection How identity compromise turns AI into an attack accelerator These attacks matter for enterprise AI because AI assistants and agents inherit the identities and delegated permissions under which they operate. When attackers compromise those identities, they may also gain access to the AI services, enterprise data and connected applications available through the same permissions. An AI assistant connected to enterprise knowledge can dramatically reduce the effort required to locate sensitive information. Rather than manually searching hundreds of folders, an attacker with legitimate credentials could ask an AI assistant to identify backup documentation, administrative procedures, customer information or financial records. Similarly, if an AI agent has permission to send emails, export files or invoke connected business tools, attackers who compromise its identity could potentially abuse those capabilities to accelerate data theft or unauthorized actions. The underlying risk is excessive access rather than AI itself. Prompt injection is an AI-specific application-layer vulnerability, but it is only one part of the wider risk created by excessive permissions, insecure integrations and insufficient oversight. Malicious instructions embedded in documents, emails or web content may influence AI behavior when retrieved by enterprise applications. The impact depends largely on the permissions granted to the AI system, which is why security guidance from organizations such as OWASP emphasizes layered controls, least privilege and human approval for high-risk actions instead of relying solely on prompt filtering. AI is already making cybercrime more efficient Evidence shows AI is making existing cybercrime faster rather than fundamentally changing how attacks work. The Acronis Cyberthreats Report H2 2025 documents several examples of AI supporting different stages of cyber operations: The GTG-2002 threat group used AI to generate and debug scripts, assist credential harvesting, analyze stolen information and personalize extortion communications, allowing relatively small attack teams to scale their operations. The GLOBAL GROUP ransomware operation introduced an AI chatbot to automate ransom negotiations after compromise. While the chatbot did not change the ransomware infection chain, it enabled operators to manage more victims simultaneously while reserving human negotiators for complex cases. Anthropic researchers have documented a Chinese state-sponsored group using agentic AI to execute much of a cyberespionage campaign, including reconnaissance, vulnerability research, credential harvesting and data collection. Meanwhile, ransomware-as-a-service operators increasingly advertise AI-assisted automation for defense evasion and operational efficiency. Those advertisements signal how ransomware operators are positioning AI and where they expect it to deliver efficiency gains, although individual capability claims may not be independently verified. Taken together, these examples show AI functioning primarily as an operational force multiplier rather than creating entirely new attack techniques. Six controls that reduce AI-enabled ransomware exposure Organizations do not need to replace their existing security strategy for enterprise AI. However, they do need to extend it with AI-specific governance, access controls and monitoring. Acronis security experts advise that organizations should extend existing governance, identity and data protection practices to cover AI applications and workflows by: Maintaining an inventory of approved and unauthorized AI applications, models and integrations. Every AI workflow should have a defined owner, business purpose and appropriate risk classification. Granting least-privilege access to users, AI applications, service accounts and APIs. Regularly review delegated permissions, revoke unused credentials and limit AI access to only the systems and information required for each task. Applying controls to AI-related traffic and data movement. Use secure web gateway, CASB and DLP capabilities to discover AI services, restrict access to unauthorized tools and prevent sensitive information from being uploaded or transferred. Monitoring and auditing AI activity. Correlate AI application usage, identity events, data access, exports and agent actions with endpoint, SaaS and cloud telemetry in SIEM or XDR systems. Maintain audit trails showing which user or service account initiated an action, what resources were accessed and whether approval was required. Preparing for containment and recovery. Security teams should be able to revoke compromised tokens, disable affected integrations and suspend AI workflows when malicious activity is detected. Immutable backups and tested recovery procedures remain essential for restoring operations after destructive attacks, although they cannot reverse data theft or eliminate extortion risk. Implementing human or policy-based authorization for high-risk actions, such as bulk exports, administrative changes, external communications and code execution. OWASP explicitly recommends least privilege and human approval for privileged operations. Extending cyber resilience to enterprise AI Enterprise AI will continue expanding because the business benefits are clear. The challenge is ensuring that productivity gains do not come at the expense of security. The most effective approach is to incorporate AI into existing identity, data protection and incident response strategies rather than treating it as a separate security domain. Organizations should evaluate AI security controls based on how well they integrate with existing governance and security operations while providing visibility into AI usage, permissions and policy violations. For managed service providers (MSPs) and enterprise security teams, there is an opportunity to extend cyber resilience strategies to include AI governance. Acronis GenAI Protection, built natively into the Acronis platform, helps organizations discover shadow AI usage, inspect prompts for sensitive data, enforce usage policies and review GenAI activity within the same platform used for other cyber protection services. This enables organizations to strengthen GenAI governance and make interactions with AI tools safer without introducing another standalone management console. As enterprise AI adoption accelerates, organizations that combine strong governance with established cybersecurity practices will be better positioned to reduce ransomware risk while realizing AI's productivity benefits. Try Acronis GenAI Protection now and see how generative AI can help protect your network. Author: Santiago Pontiroli Bio: Santiago Pontiroli is the Threat Intelligence Research Lead at the Acronis Threat Research Unit (TRU), where he leads global investigations into advanced threat actors, cybercrime ecosystems, and emerging attack techniques. He specializes in analyzing nation-state actors, criminal organizations, and financially motivated threat groups, focusing on malware analysis, reverse engineering, and developing advanced detection capabilities. With over 15 years of experience in cybersecurity, he has presented original research at leading international conferences including Virus Bulletin, CARO, MITRE ATT&CK, BlueHat, AVAR, Nuit du Hack, and ekoParty, among others. Sponsored and written by Acronis.
bleepingcomputer.comJul 22, 2026extracted
QRコード攻撃はなぜメールセキュリティを無力化できるのか? その理由を解説
���[���Z�L�����e�B���i�����Ă��邩��Ƃ����āA���S�Ƃ͌���Ȃ��BQR�R�[�h�����p�����t�B�b�V���O�U���́A�]���̃��[���Q�[�g�E�F�C���O��Ƃ��Ă����������@�����蔲����\��������Ƃ����B�ǂ��������������B ���̋L���͉������ł��B����o�^�i�����j����ƑS�Ă������������܂��B �@Acronis��2026�N4��17���i���n���ԁj�AQR�R�[�h�����p�����t�B�b�V���O�U�����A�]���^�̃��[���Z�L�����e�B���i���O��Ƃ��Ă������������̌��E��˂��Ă���Ɖ�������B �@�U���҂͈���URL��QR�R�[�h�摜�ɖ��ߍ��݁A�d�q���[���{����Y�t�t�@�C���Ƃ��đ��M����B��M�҂��X�}�[�g�t�H���œǂݎ��ƁA�F�؏��𓐂ދU��Web�T�C�g��s���v���O�����̔z�z��ɗU�������B��Ƃ��Ǘ�����PC�ł͂Ȃ��A�����X�}�[�g�t�H���ɍU���o�H���ڂ�_���A�]���̃����N�^�t�B�b�V���O�Ƃ͈قȂ�������Ƃ����B �@�]���^�̃Z�L���A���[���Q�[�g�E�F�C�́A���[���w�b�_��{���AHTML�A�{������URL����͂��邱�Ƃ�O��ɐv����Ă���B����A����URL��QR�R�[�h�摜�ɖ��ߍ��܂�Ă���ꍇ�A�{�����ɉ�͑ΏۂƂȂ镶�����݂��Ȃ����߁A�摜�t�@�C���Ƃ��Ă��̂܂ܒʉ߂��Ă��܂��\��������B �@Acronis�́A���̖��͐ݒ�~�X��V�O�l����s���ł͂Ȃ��A�]���̃��[���h�䂪������\���I�Ȑ��Ǝw�E�����B �@QR�R�[�h��K�ɔ��肷��ɂ́A�摜����QR�R�[�h�����o�E����������ŁA���o����URL�̕]����J�ڐ�y�[�W�̓��I��͂܂Ŏ��s����K�v������BURL�̃u���b�N���X�g��s���e�[�V��������ł́A�摜���ɉB���ꂽ�U�����\���Ɍ������Ȃ��Ƃ����B �@QR�R�[�h�����p�����t�B�b�V���O�͑����X���ɂ���BAnti-Phishing Working Group�́A2025�N�Ɍ����ĉ摜�����p�����t�B�b�V���O�U������400�����������ƕ����BKeepnet Labs��Supercode�́A�t�B�b�V���O�S�̖̂�12���ʼn摜�𗘗p������@���m�F���ꂽ�Ƃ��Ă���B�܂��AZenSec��2025�N�ɓY�t�t�@�C���������170�����̈���QR�R�[�h�����o���A�uMicrosoft Digital Defense Report�v�͋���@�ւ�_����QR�R�[�h�t���t�B�b�V���O���[����1��������1��5000�������ƕ����B �@���p�҂̍s�����U�����㉟�����Ă���BKnowBe4��NordVPN�̒����ł́A73���̗��p�҂������N����m�F������QR�R�[�h��ǂݎ��Ɖ����B���H�X�̃��j���[�⒓�ԏ�̐��Z�A�C�x���g��t�Ȃǂ�QR�R�[�h�̗��p�����퉻�������ƂŁA���p�҂̌x���S������A���̏K�����d�q���[���U���ɂ����p����Ă����Acronis�͕��͂��Ă���B �@QR�R�[�h�U���̂�����̓����́A�U���o�H����ƊǗ��[�����玄���X�}�[�g�t�H���Ɉڂ�_���B�]�ƈ����Ζ��pPC�Ń��[�����J���A�\�����ꂽQR�R�[�h�������X�}�[�g�t�H���œǂݎ��ƁA���̌�̒ʐM�͊�Ƃ̒[���ی��Web�v���L�V�ADNS�t�B���^�����O�A�f�[�^�R�����h�~�iDLP�j�Ȃǂ̊Ď��ΏۊO�Ői�s����B�U��Web�T�C�g�ɔF�؏�����͂���A�U���҂͊�ƃA�J�E���g�ɃA�N�Z�X���邽�߂̎��i�����擾�ł���B �@�U���҂̎�@�����x�����Ă���B��ƃ��S��g�ݍ���QR�R�[�h��A����z�F��ς���QR�R�[�h�̑��A�uASCII�v������uUnicode�v�����𗘗p����QR�R�[�h�A�u���E�U�����ňꎞ�I�ɐ��������uBlob URI�v�A�A�v���������N�A�摜�����Ė��ߍ��ގ�@�A�umultipart MIME�v�\���̈��p�A�Z�kURL��N���E�h�T�[�r�X���o�R�������_�C���N�g�ȂǁA���l�ȉ����@���m�F����Ă���B�����́A�l�̖ڂɂ��m�F���ʓI�ȉ摜��͂�������邱�Ƃ�ړI�Ƃ��Ă���B �@Acronis�́A���������U���ɂ����IT�Ǘ��҂�MSP�i�}�l�[�W�h�T�[�r�X�v���o�C�_�[�j�ł́A�s�R���[���̒��������̑�����F�؏��R�����ւ̑Ή��A�����̌��m�w�W�ւ̉ߐM�A�č����̐������S�Ȃǂ��ۑ�ɂȂ�Ǝw�E����B�摜�^��QR�R�[�h�U������M���֓͂��ꍇ�A���m�����Ⴂ�Ƃ��������A�����������m�ΏۂƂ��ĔF������Ă��Ȃ����Ђ��c���Ă���\��������Ƃ����B �@Acronis�́AQR�R�[�h�����p�����t�B�b�V���O�͒P�Ȃ�V���ȍU����@�ł͂Ȃ��A�������͂�O��Ƃ��Ă����]���̃��[���h��̌��E������ɂ�����̂��ƈʒu�t����B����́A�摜����QR�R�[�h����͂��A�������URL��J�ڐ�܂Ŏ�M�O�ɕ]������d�g�݂�g�ݍ��ނ����łȂ��A�]���^���[���Q�[�g�E�F�C�̐v�v�z���̂��̂����������Ƃ����߂���Ƃ��Ă���B Copyright © ITmedia, Inc. All Rights Reserved.
atmarkit.itmedia.co.jpJul 7, 2026extracted
Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks
The China-aligned espionage group Mustang Panda is running two campaigns against the Indian government and hydropower targets, deploying new malware and turning a legitimate cloud service into its command channel. Acronis Threat Research Unit found active compromises inside Indian government networks, including machines used by senior administrative staff, and worked with CERT-In on notification and cleanup. The malware abuses Zoho WorkDrive, a cloud storage platform common in India's government sector, to pass commands and exfiltrate data. That is the whole idea: the traffic looks like ordinary cloud activity, so it hides inside the network it is stealing from. Acronis names three new tools. SHARDLOADER is a loader that runs by sideloading a malicious DLL through a legitimately signed binary, a Solid PDF Creator executable in one campaign, and a Citrix Receiver binary in the other. It deploys one of two implants. MINIRECON is a reworked variant of the Toneshell backdoor documented by IBM X-Force, now beaconing over a WebSocket connection on HTTPS. ZOHOMURK is the novel piece: it carries hardcoded Zoho OAuth credentials and uses them to run an attacker-controlled WorkDrive account as a dead drop, reading commands from an inbox folder and writing stolen output to an outbox. Both campaigns arrive as ZIP archives with the malicious DLL marked hidden. Acronis believes they were delivered by spear-phishing. The lures fit the targets: one themed around a hydropower cooperation proposal, the other around a memorandum of understanding between Indian and Taiwanese institutions. Per Acronis, the goal is intelligence on India's hydropower plans and its defense ties with Taiwan. Acronis attributes the activity to Mustang Panda with high confidence. The report includes the reused Solid PDF Creator sideloading chain, code overlap with Toneshell, command servers sitting in the same network block as infrastructure IBM X-Force tied to the group, and a recurring typo, RunOnece, carried across multiple implants. Operational security was thin. Hardcoded tokens, plaintext identifiers, and reused infrastructure all helped analysts pin it down. Active beaconing ran from June 12 to June 22, 2026. This continues a steady push against Indian targets. In April, Acronis tied the group's LOTUSLITE backdoor to attacks on India's banking sector and South Korean policy circles, also staged through a legitimate cloud service. The broader China-linked interest in India's power sector goes back further: the 2021 RedEcho campaign targeted the country's electricity grid with ShadowPad. There is no patch to apply. The defense is catching the delivery and the cloud abuse. Acronis published indicators and hunting tips, including the persistence Run keys, a scheduled task named SolidPDFPcl2Bmp, the C2 domain couldinstallup[.]com, and the Zoho user agents that turn up on non-browser processes. Government and energy organizations, especially those tied to cross-border deals likely to interest Beijing, should watch for geopolitical lures and sideloading from signed binaries. And flag any endpoint process calling cloud APIs that it has no reason to touch.
thehackernews.comJun 29, 2026extracted
INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023
Cybersecurity researchers have charted the evolution of INC from an nascent ransomware-as-a-service (RaaS) operation to one of the most prolific cybercrime groups in 2026, claiming no less than 830 victims since August 2023. "The disruption of LockBit and the shutdown of BlackCat created opportunities for INC to expand as affiliates migrated to alternative ransomware operations," Acronis researcher Darrel Virtusio said. "United States organizations account for more than 65% of listed victims, with legal services, manufacturing, construction, technology and health care among the most targeted sectors." INC's Windows and Linux/ESXi encryptors have also been rewritten in Rust to facilitate easier cross-platform development and better resist reverse engineering efforts. Attacks deploying the ransomware are characterized by the use of an updated credential dumper capable of targeting newer Veeam backup deployments that use the salted DPAPI credential encryption. What's more, the sale of INC's Windows and Linux variants on the cybercrime underground in May 2024 has led to the emergence of related ransomware families such as Lynx and Sinobi with "significant code overlap," even as the brand has continued to evolve. "INC ransomware affiliates utilize a diverse range of tools and techniques in targeting victims," Acronis said. "In their latest campaigns, they continue to target unpatched edge devices for initial access, dump credentials from Veeam backup servers, and use a mix of LOLBins and commercial RMM tools to move through victim networks." The overall attack chain adopted by the double extortion crew is as follows - Obtain initial access via a wide range of methods, including spear-phishing, account credentials purchased from IABs, and the exploitation of vulnerabilities in public-facing applications such as Citrix Netscaler (CVE-2023-3519 and CVE-2025-5777), Fortinet EMS (CVE-2023-48788), and SimpleHelp (CVE-2024-57727). Extract sensitive credentials from the compromised environment. Use living-off-the-land binaries (LOLBins), such as remote desktop protocol (RDP) and PsExec, for lateral movement. Employ the bring your own vulnerable drive (BYOVD) technique using filwfp.sys, filnk.sys, fildds.sys to impair system defenses. Drop Cobalt Strike, AnyDesk, ScreenConnect, and TeamViewer for command-and-control. Exfiltrate data of interest using Rclone after staging them as password-protected archives. Run the encryptor and speed up the process using techniques like multithreading and partial encryption. The payload features a command-line interface that gives the operator more control during hands-on deployments. When it's executed with the "--esxi" argument, it attempts to shut down virtual machines. The findings show that ransomware groups can find success and scale up by following widely known techniques without having to lean on advanced tradecraft or bespoke tooling, effectively producing a steady stream of victims spanning various geographies and sectors. Data compiled by ZeroFox shows that INC ransomware emerged as the fourth most prominent ransomware group in Q1 2026 after Qilin (338), Akira (197), and The Gentlemen (192), accounting for over 120 incidents during the time period. "INC continues to strengthen its ransomware operation through Rust-based payload rewrites and continuous toolkit enhancement, while carefully targeting industries such as health care, legal services, professional services, manufacturing, and construction where operational downtime creates strong financial pressure to pay," Acronis said. "This threat is further amplified because these sectors depend heavily on uninterrupted operations and supply chains, increasing the risk of collateral exposure across vendor networks and downstream partners when breaches occur."
thehackernews.comJun 18, 2026extracted
5 reasons Microsoft 365 backup isn’t enough for business data protection
Written by Andy Kerr, Senior Manager, Solutions Marketing at Acronis. Many organizations assume Microsoft 365 automatically provides built-in protection for their business data. It doesn’t, and Microsoft doesn’t claim that it does. Microsoft 365 operates under a shared responsibility model: Microsoft ensures service availability and infrastructure security, but data protection, including backup and recovery, remains the customer’s responsibility. That gap becomes critical in real-world scenarios involving ransomware, accidental deletion, insider threats or compliance failures. A third-party solution is essential for data protection. Organizations need dedicated backup, security and recovery capabilities to effectively safeguard Microsoft 365 data. Need some evidence? Here are five key reasons why Microsoft 365 backup alone isn’t enough for business data protection. 1. Microsoft 365 does not protect against ransomware and malicious data loss By design, Microsoft 365 does not fully protect against ransomware and malicious data loss, particularly when encrypted or deleted files are synced across accounts. While versioning and recycle bins provide limited recovery, they are not designed to ensure clean, reliable restoration after sophisticated attacks. To address this gap, organizations need solutions that provide immutable storage, AI-based ransomware detection and clean recovery points to ensure safe data restoration. Ransomware attacks increasingly target cloud environments, not just endpoints. When files in OneDrive or SharePoint are encrypted, those changes are often synchronized instantly across users and devices. Native version history may help in simple cases, but attackers frequently corrupt multiple versions, or attacks remain undetected long enough to render recovery points unusable. Additionally, Microsoft’s tools are not about to effectively identify ransomware. They do not know which versions of files are safe and which are compromised. That creates uncertainty during recovery and can significantly delay restoration. A third-party cybersecurity solution can address that issue by combining backup with active protection. Features such as immutable storage in Acronis Cyber Platform, for instance, prevent attackers from tampering with backup data while AI-based detection identifies suspicious encryption patterns. As a result, organizations can roll back to clean, verified recovery points without having to make dangerous guesses as to which data is safe. Protect Microsoft 365 with Acronis, combining secure backups, AI-powered ransomware detection, rapid recovery, and long-term data retention in one platform. Recover clean data with confidence, simplify management, and strengthen protection across Microsoft 365, endpoints, and workloads from a single console. Learn how Acronis helps secure Microsoft 365 data 2. Native Microsoft 365 retention policies are not enough for compliance Microsoft 365 retention policies are not sufficient for many compliance requirements, especially for organizations that need long-term flexible data retention. Retention settings are often limited in granularity and may not meet industry-specific or legal data preservation standards, A third-party solution can provide customizable, compliance-ready backup capabilities. Compliance requirements vary widely across industries. Healthcare, finance and legal sectors often require years or even decades of data retention along with strict auditability. Microsoft’s retention policies are primarily designed for basic governance, not comprehensive backup. Limitations include rigid retention structures, lack of independent storage and challenges in demonstrating compliance during audits. Retention policies also do not equal backups since they are not designed for full data restoration scenarios. Organizations need a third-party option that provides independent long-term storage with flexible retention policies that can be tailored to regulatory requirements. That way, organizations can maintain complete control over their data lifecycle, while ensuring compliance and without sacrificing recoverability. 3. Granular recovery in Microsoft 365 is limited and inefficient Microsoft 365 is not designed to natively enable efficient andgranular data recovery. As a result, quickly restoring specific files, emails or user data is difficult. Recovery processes can be time-consuming and often lack precision, which increases downtime and operational overhead. A third-party offering such as Acronis Cyber Platform addresses that challenge by enabling fast granular recovery across Exchange, SharePoint, Teams and OneDrive from a centralized platform. In practice, organizations rarely need to restore entire environments. They need specific emails, folders or user accounts. Microsoft’s native tools often require complex workflows or full-site restores to retrieve small pieces of data. That inefficiency leads to longer recovery times and increased IT workload, particularly in large environments with multiple users and services. A third party solution can simplify this process with centralized management and highly granular recovery options. IT teams can quickly locate and restore individual items, whether it is a single email, a Teams conversation or a SharePoint document, without disrupting the broader environment. 4. Phishing and insider threats expose data beyond Microsoft safeguards With Microsoft 365, Microsoft does not intend or claim to fully protect against data loss caused by phishing attacks or insider threats. Even when threats are detected, organizations may still need to manually recover compromised or deleted data, which can delay response times. The right third-party solution, such as Acronis Cyber Platform, combines backup and cybersecurity capabilities so organizations can recover clean data quickly after incidents involving compromised accounts or malicious actions. Phishing remains one of the most common entry points for attackers. Once an account is compromised, attackers can delete files, exfiltrate data or manipulate content, all within legitimate user sessions. Similarly, insider threats, whether malicious or accidental, can result in significant data loss. Microsoft 365 performs some limited threat prevention, but recovery after an incident is often manual and fragmented. A third-party platform that combines cybersecurity with backup enables organizations not only to detect threats but also to recover quickly from their impact. Clean data restoration becomes part of the incident response process. 5. Microsoft 365 backup is not designed for cost-efficient scaling Microsoft 365 backup is not designed to be cost-efficient at scale, particularly for growing organizations or managed service providers (MSPs) managing multiple tenants. Native options can become expensive and lack the flexibility needed to manage storage and retention efficiently across environments. A third party such as Acronis Cyber Platform for MSPs offers a scalable per-seat pricing model with predictable costs, making it easier for businesses and MSPs to manage Microsoft 365 backup at scale. As organizations grow, so does their data footprint. Managing backups across multiple users, departments or tenants can quickly become complex and costly with native tools. Microsoft’s pricing and storage structures are not optimized for large-scale backup strategies, especially for managed service providers who need multi-tenant visibility and control. A third party can address that issue with a scalable architecture and predictable pricing. A per-seat model simplifies cost management while centralized administration enables efficient backup across multiple environments. You are responsible for your Microsoft 365 data Microsoft 365 is a powerful productivity platform, but it is not designed or intended to be a complete data protection solution. The limitations of native Microsoft 365 data protection are significant. Organizations need secure and flexible third-party backup solutions to ensure their data remains protected and recoverable under any circumstances. Solutions like Acronis Cyber Platform provide that missing layer in Microsoft 365 data security and protection, combining backup, cybersecurity and recovery into a single platform designed for a threat landscape that continues to prove a dangerous challenge to organizations. About the writer Andy Kerr is a cyber resilience and data protection expert with more than a decade of experience helping businesses navigate the evolving world of cybersecurity, backup, and disaster recovery. As Senior Manager, Solutions Marketing at Acronis, he works closely with MSPs and IT leaders across Europe to turn complex cyber protection challenges into practical, business-focused strategies. Known for making technical topics accessible and engaging, Andy regularly speaks on cyber resilience, SaaS protection, ransomware defence, and the future of managed services. Sponsored and written by Acronis.
bleepingcomputer.comJun 18, 2026extracted
⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More
Stuff broke again. Not in a movie way. An old tool was left exposed. An abandoned package was abused. A deprecated feature was still running in prod. This week is the same lesson in a new form: phishing kits are easier to rent, AI names are useful bait, old login paths still fail, and forgotten software keeps becoming someone else's entry point. Scroll through the full Monday Cybersecurity Recap below for the news, tools, webinars, and fixes worth your time this week. ⚡ Threat of the Week Google Patches Actively Exploited Chrome 0-Day - Google released security updates to address 74 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-11645 (CVSS score: 8.8), has been described as an out-of-bounds memory access in V8, Chrome's JavaScript and WebAssembly engine. Google acknowledged that an "exploit for CVE-2026-11645 exists in the wild," but stopped short of sharing additional specifics to ensure that a majority of the users are updated with a fix and to prevent further exploitation. Google has addressed a total of five actively exploited Chrome zero-days since the start of the year. This includes CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, and CVE-2026-5281. How Drata Tackles Shadow AI and SaaS Sprawl With a Lean Team Learn how the role of IT has changed in modern orgs, the operational realities of shadow IT and identity sprawl, and how Drata uses Nudge Security to gain visibility and control of AI use, SaaS sprawl, and identity risks. 🎥 June 16th, 2026 at 1pm CT Register Now ➝ 🔔 Top News ShinyHunters Gang Exploits Oracle PeopleSoft Zero-Day - The ShinyHunters (aka UNC6240) extortion crew exploited an unpatched flaw in Oracle PeopleSoft (CVE-2026-35273, CVSS score: 9.8) to break into enterprise networks. The vulnerability relates to a missing authentication for a critical function that could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools. According to Google Mandiant, the exploitation activity was observed between May 27 and June 9, 2026. Following a successful compromise, the attackers have been observed conducting targeted internal reconnaissance using MeshCentral, lateral movement, and data exfiltration. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, giving Federal Civilian Executive Branch (FCEB) agencies until June 15, 2026, to apply the fixes. The campaign has mainly targeted the higher education sector; 68% of the more than 100 notified organizations were universities and colleges. "The observed exploitation targeted PeopleSoft's Environment Management Hub (PSEMHUB) endpoints, and data stolen during the campaign was published on the ShinyHunters Data Leak Site (DLS) on June 9, 2026," Rapid7 said. 100s of Arch Linux Packages Compromised to Push Rootkit and Stealer - Unknown threat actors have managed to compromise hundreds of legitimate-but-abandoned packages in the Arch User Repository (AUR) and modify them with preinstall scripts that download and execute a malicious npm package called atomic-lockfile. The campaign has been codenamed Atomic Arch by Sonatype. "Analysis of atomic-lockfile, the malicious dependency, found a bundled Linux payload with functionality tied to credential harvesting, stealth, anti-debugging, and potential data exfiltration," the company said. Although the initial number of affected packages was 400, it has since risen to over 1,500. As of June 12, 2026, Arch Linux developers have deleted all the malicious commits they are aware of. Outside PhaaS Enterprise Taken Down - The U.S. Federal Bureau of Investigation said it took down a number of domains linked to Outsider, a Chinese phishing-as-a-service (PhaaS) software kit behind an estimated 3,870,000 stolen credit cards and a corresponding estimated $1.9 billion in losses since July 2023. In tandem, Google said it pursuing legal action against the operators, who weaponized Gemini to "help generate fraudulent phishing pages and deploy massive SMS phishing ('smishing') attacks, often through text messages impersonating legitimate brands, alerting recipients of 'brokerage account issues' or insisting they are eligible for 'rewards through their mobile phone carrier." According to a complaint filed by Google, the group "built, maintains, and uses a turn-key, online software suite that enables criminals, regardless of technical skill, to publish fraudulent websites designed to rob victims and enrich themselves." The toolkit costs $88 per week or $200 per month, offering access to more than 290 pre-built templates that mimic legitimate websites. The goal is to steal passwords and corresponding multi-factor authentication codes, as well as financial information in real-time. "Part of the Outsider software's appeal is the ease with which someone with limited technical expertise -like many members of the Enterprise - can purchase the software, execute various phishing attacks, and, upon purchase, meet other members of the Enterprise who are proficient in other areas," the tech giant added. Critical Check Point VPN Flaw Exploited in Limited Attacks - Check Point warned of active exploitation of a critical vulnerability CVE-2026-50751 (CVSS score: 9.3) impacting Remote Access VPN and Mobile Access deployments that are configured to use the deprecated IKEv1 key exchange protocol. The security flaw is a case of a logic flow weakness in certificate validation that allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password. The Israeli cybersecurity company said it first observed indications of suspicious activity on June 4, 2026, with the earliest observed exploitation dating back to May 7, 2026. Exploitation efforts are said to have ramped up starting this month. The exploitation activity, Check Point added, has been limited to a "few dozen targeted organizations globally." In one case, the post-exploitation phase has been associated with a Qilin ransomware affiliate. The Gentlemen Ransomware Claims 478 Victims - A new analysis of The Gentlemen operation revealed that the financially motivated threat group initially operated as an affiliate responsible for conducting double extortion attacks, while leveraging resources from various ransomware-as-a-service (RaaS) schemes like LockBit (aka Tenacious Mantis), Qilin (aka Pestilent Mantis), and Medusa (aka Venomous Mantis). The group, which it tracks as Phantom Mantis, is led by a Russian-speaking cybercriminal it calls LARVA-368, who goes by the online aliases hastalamuerte, ArmCorp, zeta88, nobody0, and santamuerte. The Gentlemen is known to be active since March 2025, claiming a total of 478 victims to date. Microsoft, which is tracking the cluster under the moniker Storm-2697, said the operation "initially started as a closed ransomware group then began offering its RaaS to affiliates in September 2025." 🔥 Trending CVEs Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild. Check the list, patch what you have, and hit the ones marked urgent first - CVE-2026-11645 (Google Chrome), CVE-2026-50751 (Check Point Remote Access VPN and Mobile Access), CVE-2026-35273 (Oracle PeopleSoft), CVE-2026-5027 (Langflow), CVE-2026-44963 (Veeam Backup & Replication), CVE-2026-23111 (Linux kernel), CVE-2026-45447 (OpenSSL), CVE-2026-44748, CVE-2026-27671 (SAP NetWeaver AS ABAP and ABAP Platform), CVE-2026-22732 (SAP Commerce Cloud and SAP Data Hub), CVE-2026-40128 (SAP NetWeaver Application Server Java Web Container), CVE-2026-10520 (Ivanti Sentry), CVE-2026-28252, CVE-2026-28253, CVE-2026-28254, CVE-2026-28255, CVE-2026-28256 (Trane Tracer SC+ HVAC controller), CVE-2025-46412, CVE-2025-41426 (Vertiv Liebert IS-UNITY-DP network cards), CVE-2026-0274 (Palo Alto Networks Cortex XSOAR and Cortex XSIAM), CVE-2026-20253 (Splunk Enterprise), CVE-2026-9648 (Haskell TLS software stack), from CVE-2026-12007 through CVE-2026-12011 (Google Chrome), CVE-2026-45034 (PhpSpreadsheet), PTT-2026-004, PTT-2026-005, an authentication bypass vulnerability (phpBB), and a maximum-severity code injection vulnerability in Wazuh (no CVE). 🎥 Expert Webinars Find Out What Your Automated Pentest Is Missing Before Attackers Do → Automated pentesting is useful. It is also easy to overread. A tool that proves an exploit path worked does not prove your SIEM saw it, your EDR reacted, or your team could respond before damage spread. This webinar cuts through that gap: what automated pentesting actually validates, why repeat runs start returning fewer useful findings, and how BAS helps show which controls failed, not just which vulnerabilities exist. Stop AI-Speed Attacks Before Your Legacy Controls Catch Up → AI has changed the pace of cyberattacks. Lures get sharper, campaigns adapt faster, and attackers can test what works before defenders finish investigating. This webinar breaks down how AI-powered threats like Mythos get in, move, and scale, then shows how to fight back with tighter access, reduced attack surface, blocked lateral movement, and in-line controls that stop risky behavior before it becomes an incident. Stop Employees From Leaking Source Code, Contracts, and PII Into AI Tools → Employees are already pasting company data into AI tools. Source code, contracts, customer records, and internal notes can leave the business through one prompt. This webinar shows how to move from after-the-fact detection to real-time prevention, with browser-level controls that stop risky AI use at the point where data is about to leak. 📰 Around the Cyber World Campaigns Use AI Brands as Lures - Microsoft warned of campaigns capitalizing on the global interest around artificial intelligence (AI) as a social engineering lure in campaigns. "These campaigns, which don't represent compromise of services, span phishing, malvertising, and search engine optimization (SEO)-driven attacks that ultimately lead to credential theft, financial fraud, or malware infection," the company said. Some of the campaigns include a ChatGPT-themed lure that leads to a phishing kit collecting credit card data, a Claude-themed phishing campaign collecting credentials and access tokens, an "Awesome AI Windows Plugin" malvertising campaign deploying Vidar Stealer, and Fake DeepSeek V4 installers on GitHub delivering Vidar Stealer. The tech giant said it "observed the initial access broker Storm-3075 employing AI-themed malvertising to deliver payloads, including malware signed by the malware-signing-as-a-service (MSaaS) offering attributed to the financially motivated threat actor Fox Tempest, on behalf of multiple downstream actors." macOS Users Targeted by Fake Installers - Deceptive installers for popular software are being used to push information stealers to macOS users. "The infection chain almost always starts inside a web browser," Huntress said. "Threat actors lean heavily on search engine optimization (SEO) poisoning to hijack search results, or they seed compromised links across torrent networks and cracked software forums. A user drops their guard, clicks the malicious link, and downloads what they assume is an authentic installer." The DMG files, once executed, aim to bypass Apple Gatekeeper protections to realize their goals. In 2024, more than 65% of newly reported macOS malware was classified as infostealers. History of Chinese-Language Guarantee Marketplaces - Flare has shed light on the "guarantee model" that powers various illicit online Telegram marketplaces like HuiOne Guarantee and Tudou Guarantee. "These marketplaces are third-party escrow services for illicit transactions," security researcher Chris d'Eon explained. "The marketplace operator stands between buyer and seller, holds the buyer's funds in escrow, releases them to the seller only when the buyer confirms delivery, and adjudicates disputes when something goes wrong. In return, the operator collects deposits from vendors who want to advertise under its brand, fees on transactions, and revenue from paid promotional slots." The model, which has its roots in legitimate Chinese consumer-internet trust architecture launched by Alipay in 2003, facilitates the sale of money laundering services, stolen data, fraud kits, fake identity documents, recruitment for scam compounds, retail fraud, deepfake services, and the physical infrastructure that drives human trafficking and forced-labour compounds. Law enforcement crackdown has led to "fragmentation but not elimination" of the criminal enterprise. More than 30 successor marketplaces have emerged following the takedown of HuiOne and Xinbi, almost all of them managing their operations via Telegram owing to its reach, bot infrastructure, and improved resilience despite the platform's efforts to crack down on such activities. These include Tiancheng, Dabai, Ouyi, Yinuo, Jin Bo, Haihua, Timi, and Lao Niu. UniFi OS Flaws Exploited - The UniFi OS Server remote code execution chain, comprising CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, is now being actively exploited, according to Defused Cyber, following a report from Bishop Fox about how the three flaws could be combined to achieve unauthenticated code execution as root. The attacks culminated in the deployment of commodity malware. Khmer Shadow Targets Cambodian Government Entities - A targeted cyber espionage campaign against Cambodian government entities has leveraged a meeting-themed SFX archive to sideload a custom C++ loader dubbed NIGHTFORGE, which then decrypts and executes a Havoc Demon payload in memory. "NIGHTFORGE has demonstrated a moderate level of sophistication, combining advanced defense-evasion techniques such as NTDLL unhooking and Hell's Gate syscall resolution, a method that enables direct system calls and helps evade user-mode monitoring, with operational shortcomings that suggest the tool is still under active development," Acronis said. The activity has been attributed to any known threat group, but it's "likely aligned with regional intelligence collection interests in Southeast Asia." How Attackers Could Exploit Cloud Logging Services - Palo Alto Networks Unit 42 has warned that threat actors could exploit cloud logging services, which are crucial for security monitoring, to "create weak spots, evade detection, and in certain scenarios, establish continuous visibility within a target's environment." Attackers could tamper with resources within the cloud logging service (e.g., disabling, altering, or deleting logs, or even impairing logging) to hide their presence or attempt to route logs to their own accounts, establishing continuous visibility over the victim's environment, performing continuous discovery, and passively monitoring all activity. Operation TaxShadow Delivers Multi-Stage Malware Framework - An Indian tax-themed phishing campaign has been observed delivering a sophisticated multi-stage malware framework through a mix of social engineering, phishing infrastructure, and memory-resident malware execution techniques. "The campaign begins with a fraudulent tax notification email impersonating an official Indian tax authority, leveraging government branding, urgency-based messaging, and compliance-related threats to manipulate victims into interacting with a malicious phishing website," CYFIRMA said. "Victims are subsequently instructed to download a malicious ZIP archive containing three staged payload components: कर विवरण.exe, SbieDll.dll, and SbieDll.bin, which collectively establish the complete infection lifecycle." The attack makes use of a highly modular malware architecture, coupled with advanced defense-evasion and anti-analysis techniques, to launch a payload in memory. The malware also establishes persistent WebSocket-based communications. MagicAd Displays Background Ads on Android Devices - A new Android trojan called MagicAd has been found to bypass operating system restrictions to display background ads. "One of these methods is universal, while the others are designed for devices from specific manufacturers," Russian cybersecurity company Doctor Web said. "These include exploiting third-party software and using the system media player." The malware is distributed via apps on GetApps, the official app catalog for Xiaomi devices. It has been discovered in more than 50 games and apps. The campaign is assessed to have commenced in 2025, with the threat actors behind it also leveraging the Samsung Galaxy Store as a distribution mechanism. Currently, none of the apps are available for download. Residential Proxies in the Wild - Residential proxies are designed to relay internet traffic through devices that belong to regular consumers, such as home routers, mobile devices, IoT devices, and devices with applications embedded with proxyware. One way this is achieved is that application developers themselves can embed software development kits (SDKs) provided by the residential proxy networks into their products as a way to monetize their software, allowing them to receive a small amount of money on each installation. In an analysis published last week, Infoblox said monthly queries to residential proxy domains steadily grew from nearly 400 billion to over 500 billion between January 2025 and April 2026 across its customer base, an increase of about 25%. "There are likely several explanations for this: certainly, the rise in AI-related training, which often requires scraping websites, is a major driver of residential proxy demand," it said. "Residential proxies bypass many anti-scraping measures, as the traffic appears to be coming from the devices of real people." Some of the most commonly observed proxy services queried include Bright Data, Hola VPN, Oxylabs Proxy, Honeygain, and Grass. The DNS threat intelligence firm said many residential proxy services operate in a grey space. SHEET#CREEP Drops C# Remote Access Trojan - An ongoing cyber espionage campaign dubbed SHEET#CREEP has leveraged a diplomatic-themed ISO phishing lure to distribute a C# remote access trojan (RAT). The activity was previously flagged by Zscaler and Bitdefender, attributing it to a threat actor known as Transparent Tribe. "The RAT abuses the Google Sheets API as its command-and-control (C2) channel, authenticating via an embedded GCP service account private key and using individual spreadsheet tabs per victim for bidirectional communication," Securonix researchers Shikha Sangwan, Akshay Gaikwad, and Aaron Beardslee said. "The LNK triggers a C# dropper that extracts a bait PDF, drops the RAT payload into the Windows Vault directory, and establishes persistence through a scheduled task, before melting (self-deleting) to remove forensic traces." The cybersecurity company said it identified 91 active victim tabs in the C2 spreadsheet, including a high-confidence target located in Pakistan. Malware Distributed via npm and PyPI Packages - A cryptocurrency-focused software supply chain campaign has used malicious npm packages to facilitate credential harvesting, wallet theft, remote payload delivery, and blockchain-based command-and-control. "Technical analysis uncovered capabilities including cryptocurrency wallet interception, private key and mnemonic phrase theft, SSH credential harvesting, environment variable collection, sensitive file discovery, remote activation mechanisms, blockchain-based infrastructure retrieval, and multi-stage malware deployment," CYFIRMA said. A second campaign, codenamed Solana FakeFix, has targeted Solana developers with 20 bogus npm and PyPI packages to steal wallet keys, cloud credentials, source-control tokens, SSH keys, and environment secrets, while a third campaign, CMS Windows Loader, has used five npm packages to load remote executables and JavaScript code dynamically. In a related development, two versions of the dbmux npm package (2.2.5 and 1.0.5) were flagged for containing malware. "Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer," according to a GitHub advisory. "The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it." Ransomware Attack Uses Easyupload.io for Data Exfiltration - In one ransomware attack investigated by Huntress, a threat actor accessed the victim's hypervisor and created a new virtual machine (VM) as a staging location from which they launched the Akira ransomware. The threat actor rapidly progressed through the attack, disabling Microsoft Defender and installing WinRAR, an archival tool typically used by threat actors for staging data. "The threat actor used the Microsoft Edge browser to access Bing, and search for the term 'eayupload' before settling on Easyupload.io, a website that provides access to file uploads via drag-and-drop," the cybersecurity company said. "Shortly after accessing the LimeWire website, presumably to exfiltrate staged archives, the threat actor launched the akira.exe file encryptor against several mounted shares." 🔧 Cybersecurity Tools SpooNMAP → It is a Python tool that wraps Nmap and Masscan to make port scanning easier and faster. It guides users through scan options, supports small, medium, large, full, and custom scans, can grab service banners with Nmap, and lets users scan target IPs or CIDR ranges from a file. CVE MCP Server → It connects Claude to 27 security intelligence tools across 21 data sources, helping analysts look up CVEs, check EPSS and CISA KEV status, find PoCs, scan dependencies, review IP reputation, and generate risk reports from one place. Disclaimer: This is strictly for research and learning. It hasn't been through a formal security audit, so don't just blindly drop it into production. Read the code, break it in a sandbox first, and make sure whatever you're doing stays on the right side of the law. Conclusion This week's lesson is simple: attackers do not need magic. They need old code, busy teams, weak defaults, and one forgotten box nobody wants to claim. That is the uncomfortable part. The next big incident may already be sitting in your stack, quietly working as designed.
thehackernews.comJun 15, 2026extracted
サッカーW杯、偽ライブ配信サイトに注意 生成AIで詐欺が巧妙化 Acronisが警告
サッカーW杯、偽ライブ配信サイトに注意 生成AIで詐欺が巧妙化 Acronisが警告 6月11日に開幕する「FIFAワールドカップ2026」に便乗し、サイバー攻撃が増加する可能性があると、スイスのセキュリティ企業Acronis(アクロニス)が注意喚起している。 生成AI技術の発展により、偽のチケット販売サイトや偽のライブ配信サイトなどの手口は巧妙化しており、十分な注意が必要だ。 現地観戦者が警戒すべき手口は、空港やホテル、スタジアムなどに設置される不正なWi-Fiネットワーク、偽サイトに誘導する「クィッシング」と呼ばれるQRコード詐欺、DDoS攻撃やブランドなりすましによるデジタル決済への攻撃など。 生成AI技術の普及により、正規サイトと見分けがつかない偽サイトを容易に作れるようになったため、攻撃者がユーザーに個人情報やクレジットカード情報を入力させた上で、スタジアムの入場ゲートで使えない偽のQRコードチケットを送りつける手口も横行しているという。 オンライン視聴では、無料や割引をうたう偽のストリーミングサイトでログイン情報・決済情報を盗む手口や、非公式アプリを通じてマルウェアやスパイウェアをインストールさせる手口が確認されている。 過去の情報漏えいで盗まれた認証情報を使い、正規のストリーミングサービスのアカウントを乗っ取る「クレデンシャルスタッフィング攻撃」にも注意が必要だ。 Acronisは対策として、認証情報や決済情報を入力する前にURLを確認すること、機密性の高い情報を扱う際は公共Wi-Fiの利用を避けること、多要素認証を有効にすることなどを推奨している。 Copyright © ITmedia, Inc. All Rights Reserved.
itmedia.co.jpJun 11, 2026extracted
VMware離れの次を狙う? アクロニスが“HCI参戦”で描く新勢力図
�o�b�N�A�b�v�x���_�[�̃C���[�W�������A�N���j�X���A���ɑ_���̂́gVMware��h�̎M�������BHCI�Q���̗��ɂ́A�N���E�h�ڍs�ɗh��钆���E������Ǝs��ƁA��������AI�E�Z�L�����e�B���v������B����ɓ��Ђ�MDR��AI�������ASCS�]�����x�Ή��܂œ��ݍ������Ƃ��Ă���B ���̋L���͉������ł��B����o�^�i�����j����ƑS�Ă������������܂��B �@�A�N���j�X�E�W���p���i�ȉ��A�A�N���j�X�j��2026�N5��20���ɐ헪���\����J�Â����B����܂Ń��[�U�[��Ƃ��x������p�[�g�i�[��T�[�r�X�v���o�C�_�[�����̐��i����Ă������Ђ����A����A�T�[�r�X�v���o�C�_�[�����̃n�C�p�[�R���o�[�W�h�C���t���X�g���N����iHCI�j�A�uAcronis Cyber Frame�v�\�����B�o�b�N�A�b�v����^�p�Ǘ��̎������A�Z�L�����e�B�ɃJ�o�[�̈���g�債�Ă������Ђ��A�����HCI�\�����[�V��������邱�ƂɂȂ�B �@���Ђ̐��N�Y���i��\������В��j�́A�u�o�b�N�A�b�v��Z�L�����e�B�A�����[�g�}�l�W�����g�́A���ꎩ�̂��ړI�ł͂���܂���B�ꌾ�Ō����A�A�N���j�X��IT�ی�Ɋւ��̈���L���J�o�[���Ă����܂��v�Əq�ׁAIT�ی�A�Ђ��Ă͂���IT�𗘗p���Ă����Ƃ��̂��̂̕ی��ڎw���A�i������ƈӋC���݂��q�ׂ��B �@�V���Ƀ����[�X����Acronis Cyber Frame�́AIaaS�iInfrastructure as a Service�j��Ղ���������HCI�����A���ꂾ���ł͂Ȃ��Ƃ����B��莁�́u�o�b�N�A�b�v�ƃ��X�g�A�A�f�B�U�X�^���J�o���[�A���������ꂽ�^�p�Ǘ��A�T�C�o�[�Z�L�����e�B�����S�ɓ������ꂽIaaS�ł��v�Ǝ咣����B �@Acronis Cyber Frame�ɂ́A�A�N���j�X���g���A������2�J�����܂ߑS���E��50�J���ȏ�ɓW�J���Ă���f�[�^�Z���^�[�Ƀz�X�e�B���O���AIaaS����Œ����uAcronis Cyber Frame Cloud�v�ƁA�z�X�e�B���O���Ǝ҂�T�[�r�X�v���o�C�_�[�Ƃ��������Ђ̃p�[�g�i�[���T�[�r�X���e�≿�i���R���g���[�������œƎ��̃z�X�e�B���O�T�[�r�X��W�J�ł���uAcronis Cyber Frame Local�v��2��ނ�����B��҂́A�p�[�g�i�[�����ꂼ��W�J���Ă��鎩�Ђ̃T�[�r�X�Ɠ������ꂽIaaS�Ƃ��Ē��邱�Ƃ��\���B �@�ł͂Ȃ����Ђ����������\�����[�V���������̂��낤���B�傫�ȗ��R��VMware�̊�Ɣ����ɔ����s��̕ω����āAIaaS��ՂƂȂ蓾��\�t�g�E�F�A�̑�փ\�����[�V���������߂��Ă��邱�Ƃ��B���̑��A�f�[�^�匠��@�K���Ή��Ƃ������v���ɂ�郍�[�J���\���ւ̃j�[�Y�̍��܂������Ƃ����B �@�����A���������̒��A�p�[�g�i�[�e�Ђ����O�Ńf�[�^�Z���^�[�Ȃǂ̃C���t�����\�z���A�ڋq�̊����z�X�e�B���O����̂̓n�[�h���������B���Ƃ����āA����܂Ńz�X�e�B���O����v���C�x�[�g�N���E�h���ʼnғ����Ă����V�X�e�����n�C�p�[�X�P�[���[�e�Ђ̃p�u���b�N�N���E�h�Ɉڍs����̂�����ŁA���ɒ����E������Ƃ����߂�@�\����������Ȃ��\���������ɁA�p�[�g�i�[�e�ЂɂƂ��Ă̓r�W�l�X�̂��܂݂����Ȃ���BAcronis Cyber Frame�͂����ɑ�ֈĂ������̂��B �@��莁�́u�o�b�N�A�b�v��G���h�|�C���g�Ǘ��������I�[���C�������^�\�����[�V�����wAcronis Cyber Protect Cloud�x������܂Œ��Ă�����Ղ����A���N�̌o���ƋZ�p�́A�p�[�g�i�[�����{���g�ݍ��킹�邱�ƂŁA�p�[�g�i�[�t�@�[�X�g�ŁA�p�[�g�i�[���g�̃r�W�l�X�Ɋ�^����ƍl���Ă��܂��v�Əq�ׂ��B �@�܂��AAcronis�̃��b�N�E�w�u���[���i�V�j�A�f�B���N�^�[�j�́AAcronis Cyber Frame�ł̓}����e�i���g��������A�f�[�^�ی��Ǘ��A�������Ƃ������K�v�ȃc�[�����܂܂�Ă��邱�Ƃɂ��G��A�Ǝ��̃T�[�r�X��A�v���P�[�V������g�ݍ��킹��Ȃǂ��āu�p�[�g�i�[�e�Ђ����ꂼ��̏����̌���IaaS��W�J���A�ڋq�ɃA�E�g�J����ł��܂��v�Ɛ��������B �@��������ł́A�f�[�^�ی�@�\�̌p���I�ȋ�����i�߂�ƂƂ��ɁA������A�ی�@�\���K�ɓ��삵�Ȃ������ꍇ�ɋ��K�I�ɕ⏞����uCyber Warranty�v�v���O�����ȂǁA����̃��[�h�}�b�v���Љ�ꂽ�B �@���Ɏ��Ԃ������ďЉ�ꂽ�̂��A�N���j�X�̃Z�L�����e�B�헪���B �@���Ђ͈ȑO����Acronis Cyber Protect Cloud��ʂ��āA�o�b�N�A�b�v��f�B�U�X�^���J�o���[�i�ЊQ�����j�A�����[�g�^�p�Ǘ���j�^�����O�ɉ����A�T�C�o�[�Z�L�����e�B�֘A�̋@�\����Ă����B���̃v���b�g�t�H�[���́A���E�I�ȃZ�L�����e�B��̎w�j�ł���č������W���Z�p�������iNIST�j�́u�T�C�o�[�Z�L�����e�B�t���[�����[�N�v�iNIST CSF�j�̍l�����Ɋ�Â������̂��Ɛ�莁�͐��������B �@�uAcronis Cyber Protect Cloud�́A�P��̐��i�A�P��̊Ǘ��R���\�[����NIST CSF�ŋ��߂��镝�L���@�\����A�V���v���Ɍ����悭�Ǘ��ł���悤�ɂ��Ă��܂��v�i��莁�j �@����A���̒��ł̓T�v���C��F�[���Z�L�����e�B���X�N�����܂��Ă���B���������w�i����o�ώY�ƏȂ́ANIST CSF�Ȃǂ̃t���[�����[�N�����~���ɂ��āu�T�v���C��F�[�������Ɍ������Z�L�����e�B���]�����x�v�iSCS�]�����x�j�̔N�x���̎��{��ڎw���Ă���B �@���������g�����h���Љ����Ő�莁�́AAcronis Cyber Protect Cloud�����A�u500�Ђ���p�[�g�i�[�ƂƂ��ɁA�w���{�S�̂̃Z�L�����e�B���x�����グ����x�Ƃ���SCS�]�����x�̖ړI�B���Ɍ����ϋɓI�ɎQ�����A���y�A���i���Ă����܂��v�ƌ�����B �@����Acronis Cyber Protect Cloud�̃R���v���C�A���X�x���@�\�uAcronis Compliance Orchestrator�v�ł́A�e���v���[�g���g���āANIST CSF�̑��A�uCIS Controls�v�ȂǕ����̃Z�L�����e�B�K�C�h���C�����Q�Ƃ��Ȃ���A�K�v�ȗv������������Ă��邩�ǂ�������F�b�N���A�K�ȏC�������s����d�g�݂����B�ƊE�K�C�h���C�������łȂ��A���Ԋ�Ƃ�����T�C�o�[�ی��ɂ��Ă��A�ی��������������邩�ǂ������m�F�ł���e���v���[�g������Ă���BSCS�]�����x�Ɍ������Z�L�����e�B�̃x�[�X���C�����m�ۂ����������E������ƂɂƂ��Ă͂��ꂵ���@�\���낤�B �@�w�u���[���͂���ɁA����̃Z�L�����e�B�֘A�̃��[�h�}�b�v�ɂ��Ă��Љ���B �@1�ڂ̓G���h�|�C���g�Z�L�����e�B�̋������B�uEndpoint Security Posture Management�v�@�\��AI�����p�����C���V�f���g�̎����g���A�[�W�A�}�l�[�W�h�Z�L�����e�B�T�[�r�X�v���o�C�_�[�ɂ�鋺�Ѓn���e�B���O�Ȃǂ��\�肳��Ă���B �@2�ڂ́A�A�N���j�X���g�ɂ��}�l�[�W�h�T�[�r�X�iMDR�j�̒��B���̃T�[�r�X���̂�2026�N�����ɔ��\���ꂽ���̂����A�߂������ɋ@�\������ɋ������A�_�[�NWeb�ɃA�C�f���e�B�e�B�[��R�������Ă��Ȃ����ǂ���������@�\��[���Z�L�����e�B�ɑ���MDR�@�\�̊g���ɉ����A�p�[�g�i�[�E�T�[�r�X�v���o�C�_�[�����łȂ��A�G���h���[�U�[�ɒ���MDR�@�\����邱�Ƃ��v�悵�Ă���B �@MDR�͌����_�ŁA���Ђ̋��ЃC���e���W�F���X����uThreat Research Unit�v�iTRU�j��������\�肾���AAcronis Cyber Frame�Ɠ��l�ɍ���́A�����̃p�[�g�i�[�o�R�ł̒��i�߂�Ƃ����B����ɂ��A�e�}�l�[�W�h�Z�L�����e�B�T�[�r�X�v���o�C�_�[�iMSSP�j�͎��Ђ̃T�[�r�X�Ƒg�ݍ��킹����ŁA�A�N���j�X��MDR��ł���悤�ɂȂ�B �@�uMDR�́A�A�N���j�X���ŃC���t�����z�X�e�B���O������AMSSP�̃p�[�g�i�[�����O�̃f�[�^�Z���^�[�Œ�����ł��܂��B�I�[�v���ȃG�R�V�X�e���Ɋ�Â��A�p�[�g�i�[�����ꂼ��A�N���j�X�̃\�����[�V�����Ƒ��Ђ̃A�v���P�[�V������g�ݍ��킹�鐢�E�ς��������܂��v�i�w�u���[���j �@���̑��A�A�b�v�f�[�g�Ƃ��Ă͑��֕��͌^��ITDR�iIdentity Threat Detection and Response�j�̒��\�肵�Ă���B�uSaaS��t�@�C�A�E�H�[���AVPN�A���̑����܂��܂ȃV�X�e�����烍�O����荞�݁A���֕��͂������邱�Ƃɂ���āA���܂��܂ȋ��Ђ̌��m�ɂȂ��Ă��������ƍl���Ă��܂��v�i�w�u���[���j �@�Z�L�����e�B�ƕ���ő傫�����Ԃ��������̂��AAI�̊��p�ɂ��Ă��B �@Acronis Cyber Protect�ł͂���܂ł��A�Í������ꂽ�f�[�^���L���b�V�����烊�A���^�C���ɕ���������APC��T�[�o�̌��S�������j�^�����O������Ƃ��������܂��܂Ȍ��ML�i�@�B�w�K�j���܂߂�AI�����p���Ă����B�u����25��ނ�AI�V�i���I���lj�����Ă���A������lj�����\��ł��v�i��莁�j �@�����w�u���[���ɂ��ƁA�����AI���p�̑��i�K���Ƃ����B���̃X�e�b�v�́A����AI���K�͌��ꃂ�f���iLLM�j�����p�����₢���킹�Ή��̌��������B�A�N���j�X�́AIT�T�|�[�g�T�[�r�X������ƌ�����AI�����p�����@�\����Ă���B�u�p�b��K�p�O�ɏ\���Ɍ����A�G���[���N����Ȃ����Ƃ��m�F������œK�p����Ƃ������v���Z�X���ALLM�ɂ���ĊȒP�ɂł���悤�ɂȂ�܂����v�i�w�u���[���j �@�����đ�O�i�K�ł́AAI�������̈ӎv������x������u�n�C�p�[�������v�Ƃł��Ăׂ�i�K���B����Ɍ����ăA�N���j�X�ł́A�}�l�[�W�h�T�[�r�X�v���o�C�_�[�iMSP�j��AI�����p���ăw���v�f�X�N���[�N�t���[������������uCyber Studio�v����Ă���B �@��̓I�ɂ�2026�N��3�l�����ɁA�ی��Ǘ��A�������@�\���l�C�e�B�u�ɓ��������uAcronis Cyber Console�v�������[�X���AAI�����p�����v���A�N�e�B�u��UX�����\�肾�B���̓����R���\�[���ɂ́A�T�[�r�X�f�X�N��p�[�g�i�[�|�[�^�������������v�悾�Ƃ����B �@���̑��A�����[�g�Ď��E�Ǘ����x������uAcronis RMM�v�ł��AAI�X�R�A�����O�ɂ����S�ȃp�b�`�K�p���͂��߁A�i�K�I�ɂ��܂��܂�AI�e�N�m���W�[���ς݂��B���コ��ɁA�\�t�g�E�F�A���p�b�P�[�W�����Ď����I�ɁA���Z�L���A�Ƀf�v���C����uAI Deploy Pilot�v��A�����[�g�T�|�[�g�̍ۂɊ֘A����AI�ɂ�郌�R�����f�[�V�����Ȃǂ��ꌳ�I�ɕ\������uAI�x���ɂ�郊���[�g�A�N�Z�X�v�Ȃǂ𓋍ڂ�����j���B �@����́A�A�N���j�X���e�v���b�g�t�H�[����ʂ��Ē~�ς��Ă�����ʂ̏���AI�ʼn�͂��A�����̃A�N�V�����ɂȂ���u�C���T�C�g�v�ɗ��Ƃ����ށuAcronis Cyber Intelligence�v�̒��\�肵�Ă���B �@�uAcronis Cyber Intelligence�����p���邱�ƂŁA�T�[�r�X�v���o�C�_�[�͂��ǂ��ӎv����������A��葽���̃T�[�r�X����A�Ђ��Ă͌ڋq�ɂ��ǂ����ʂ�͂�����ł��傤�v�i�w�u���[���j �@���̂悤�ɃA�N���j�X�ł́A������ϓ_��AI���p�𐄂��i�߂���j���B�����A���Ղ�AI���p�͊��G�ɂ��A�V���h�[IT�̗�����AI��������R�����A�v�����v�g�C���W�F�N�V�����Ƃ��������X�N�������N�������˂Ȃ��B���Ƃ�����AI�̊��p���ɂ��ẮA����A���Y���̌���▣�͂���T�[�r�X�̎����͌����߂Ȃ��B �@�����ŃA�N���j�X�ł͕��s���āA����AI�̗��p���������A�|���V�[�Ɋ�Â��ė��p���R���g���[�����A�������[���ɔ����ċ@������͂����悤�ȏꍇ�ɂ͌��m�E�u���b�N����uAcronis GenAI Protection�v�����邱�ƂŁA�o�����X�����Ȃ���AAI�������炷�����b�g������ł���悤�x������Ƃ����B Copyright © ITmedia, Inc. All Rights Reserved.
atmarkit.itmedia.co.jpMay 31, 2026extracted
Tracking TamperedChef Clusters via Certificate and Code Reuse
This article documents novel activity clusters that have significant overlap with the publicly described threat known as TamperedChef (aka EvilAI). TamperedChef-style malware is trojanized productivity software, such as PDF editors or calendars, that deliver malicious payloads. These campaigns typically employ malicious ads that direct users to sites hosting the applications. While this style of malware shares many similarities in technical operation, installation lures and distribution methods, we do not attribute it to a single author or group. TamperedChef-style malware samples share characteristics with potentially unwanted programs (PUPs) and adware. These include robust mechanisms to remain persistent, and end-user licensing agreements (EULAs) that attempt to legally cover the software's questionable actions. However, TamperedChef-style malware is far more stealthy than PUPs or adware, remaining dormant for weeks to months before activating. This includes continuous command and control (C2) methods enabling adversaries to retrieve additional payloads, such as information stealers, proxy tooling or remote access Trojans (RATs). We have been tracking several campaigns of TamperedChef-style activity starting in 2024, with three distinct clusters: CL-CRI-1089, CL-UNK-1090 and CL-UNK-1110. Between the three clusters of activity, we have identified over 4,000 samples across 100 unique variants. Palo Alto Networks customers are better protected from TamperedChef activity discussed in this article through the following products and services: If you think you might have been compromised or have an urgent matter, contact the Unit 42 Incident Response team. Since early 2024, we have observed a sharp increase in information stealer-style incidents originating from software mimicking legitimate productivity tools (e.g., PDF editors, ZIP file extractors, GIF image makers). Upon deeper inspection, these applications generally contain code that enables the delivery of arbitrary binaries. These features are typically used to deploy stealer malware. In 2025, our telemetry revealed over 100 unique variants of malware masquerading as productivity software. They all contained a malicious component, such as basic RAT capabilities, or delivering adware and infostealers. Due to their legitimate functionality and tendency to remain dormant for long periods of time, these applications often go unnoticed by the victim. They are also commonly downplayed or miscategorized by defenders and security researchers as potentially unwanted programs (PUPs). Because these applications can execute arbitrary code on victims' machines, either directly or indirectly through module loads, these threats are more significant than mere background annoyances or adware. We have been able to track over 4,000 file hashes and 81 unique code signing organisations through several methods, including: Reviewing code-signing certificates of the binaries Analyzing code reuse among the binaries Open-source intelligence (OSINT) on corporate structures for organizations distributing the binaries Leveraging ad transparency platforms to hunt for advertising overlaps that can identify additional organizations distributing the binaries We have identified TamperedChef-style malware campaigns starting in 2023. These malicious productivity application campaigns include AppSuite PDF, Calendaromatic, JustAskJacky and CrystalPDF. The actors behind these campaigns take steps not commonly observed with other adware groups to remain undetected. In some cases, these attackers appear to diversify their revenue streams through more aggressive and malicious activities. This diversification includes deploying infostealers, establishing residential proxies and exhibiting behavior that resembles access brokers. These applications avoid many of the common indicators that users are trained to associate with downloading malicious software, such as: Distributing via well-built, legitimate-looking websites - Without ads (as shown in Figure 1) - Appearing modern and credible - Containing common elements like descriptions, legal terms and contact pages Leveraging unique and contextually relevant domains for each campaign One-click download buttons distributed by large content distribution networks (CDNs) to minimize friction Providing promised functionality with minimal bloat, meaning victims are not likely to suspect anything is amiss Attackers also employ several tricks to avoid detection. These tricks include: Using code signing to increase the apparent legitimacy of the binaries Rebuilding binaries with only minor changes on a frequent basis to minimize the effectiveness of static or hash-based detection - The exact frequency varies, but is typically between one week and one month per rebuild Remaining dormant for periods of weeks to months before retrieving or running malicious components This combination of technical and social masquerading enables these applications to remain undiscovered, unreported and free to operate without resistance for months — if not years — at a time. Adware is a class of software designed to increase the number of ads a user observes. The more ads they observe, the more money for the distributor. This is typically done with some form of browser manipulation or additional free tooling bundled alongside downloads. Adware sits in a middle zone between malware and legitimate software, often employing malware-like tactics to maintain persistence or display more ads to users. The distinction between malware and adware can be so fine that they are indistinguishable from each other when statically analyzed, only becoming clear after misuse occurs. Adware and malware are also often interlinked, with many seemingly legitimate adware developers overstepping into malware territory, either naively or intentionally. Modern adware also walks the line between legal and illegal behavior. EULAs are ways that the groups behind adware and TamperedChef-style malware attempt to protect themselves legally. Examples of this are found on websites distributing TamperedChef-style software, such as one from hxxps[:]//www.crystalpdf[.]com/conditions: “The Additional Services offer users enhanced, tailored features. Be aware that using these services may modify your browser’s new tab settings or installed features, possibly altering your browser configuration.” However, TamperedChef-style programs execute commands remotely, exfiltrate users' credentials and deploy malware without consent. These actions firmly place them in the malware category. The name TamperedChef was initially given to a cluster of activity that included several malicious recipe applications, PDF editors, manuals and search assistant applications. It started to see widespread installation in June 2025, with some evidence suggesting these applications have been in the wild since February 2025. As reporting on malicious productivity apps within the cybersecurity community grew, TamperedChef became a broad, informal term for several productivity software campaigns. These campaigns are likely not all operated by the same group. The confusion in previous reporting is understandable, as many of the actors are leveraging extremely similar tactics, techniques and procedures (TTPs) and lures. The differences only become apparent when observing the infrastructure, code quality and organizations tied to the code signing. It is important to understand these differences to separate the attackers' motivations, capability and risks. We identified and tracked three major clusters of activity that share many of the same operational traits, but we believe these represent three distinct groups. We track the three main activity clusters as CL-CRI-1089, CL-UNK-1090 and CL-UNK-1110. The CL-UNK-1110 cluster is most commonly associated with the TamperedChef alias and includes campaigns distributing applications such as: JustAskJacky GoCookMate RocketPDFPro ManualReaderPro Acronis has researched and reported on this cluster in detail. While this cluster remains active and significant, the primary focus of our analysis will be on the two other clusters, CL-CRI-1089 and CL-UNK-1090. The CL-CRI-1089 cluster has been identified as active since early 2023. It includes several high-profile campaigns distributing applications such as: Calendaromatic DocuFlex AppSuite PDF These campaigns leverage a diverse set of deployment methods and show the most change when it comes to the malware’s techniques and tactics. This group leveraged infrastructure and code-signing certificates related to Ukrainian, Malaysian and British entities, which has remained consistent over the last two years of operation. CL-UNK-1090 is unique in its clear evidence of vertical integration between marketing and malware creation. Similar to other clusters, the group behind this cluster distributes its malware via malicious advertisements (aka malvertisements). A review of public records on corporate structures shows that, unlike the other groups, CL-UNK-1090 operators own both the code-signing companies and the ad agencies distributing the malware. This cluster used primarily Israeli infrastructure and code signing entities. It is responsible for several recent campaigns, including: CrystalPDF Easy2Convert PDF-Ezy We have observed approximately 12,000 unique instances of this fake productivity software across our customer base. Our analysis shows that this threat is global with no significant geographic or sector targeting within the Managed Threat Hunting customer base. The data highlights that while Israel and the U.S. see slightly higher targeting than other countries, TamperedChef-style malware is seen globally in non-negligible volumes. This is consistent across all three clusters, indicating that they all appear to operate globally. Understanding the capability of these threats is crucial to detection, response and disruption. Fortunately, the malware operators have made several design decisions that we can leverage to identify and link large portions of their operations. One unique attribute of the TamperedChef-style malware is that almost all the first-stage binaries are signed with legitimate code-signing certificates. Attackers used code-signing to add stealth to these payloads. However, a lack of proper certificate hygiene allowed us to follow these samples further than any one campaign. We initially identified code signing reuse with the Calendaromatic campaign. This campaign involved a simple Neutralinojs framework-based calendar app, contained in a 7z self-extracting archive (SFX). The calendar app would operate as expected, but it also contained a relatively basic RAT that enabled attackers to collect and install a second-stage payload. This campaign gained some attention due to its novel use of homoglyphs to obfuscate the incoming command strings. The 7zSFX when extracted contains both a calendaromatic-win_x64.exe binary that is essentially just a wrapper for the real bulk of the code, a heavily obfuscated Neutralinojs resource file named resources.neu. Public reporting highlighted that the 7zSFX file was signed by CROWN SKY LLC. Digging further through malware repositories, we identified four total files with the same core behavior of a 7zSFX file containing a calendaromatic-win_x64.exe binary and a resources.neu file. The resources.neu file varied across the samples. However, all appeared to contain similar functionality with differing C2 locations. Of these four samples identified, we identified two unique signers. Samples one and two were signed by CROWN SKY LLC and sample three was signed by MARKET FUSION INNOVATIONS LLC. The final sample was found to not be signed and may not have been deployed widely. Code-signing certificates are considered private material and not commonly shared between entities. A single code base signed by two uniquely authored certificates generally indicates that a single entity or actor is in possession of both code-signing certificates. This can occur for several reasons, including certificate theft, a single entity with ownership of two or more organisations (e.g., shell corporations) or organisations providing code signing as a service. Reviewing sample repositories for evidence of this new signer, we found two additional campaigns that we identified as related to the Calendaromatic operators: PDFPrime and ManualzPDF. Both PDFPrime and ManualzPDF campaigns share striking similarities and likely share a codebase. Similarities between the samples include: The same C2 domain structures Shared code signing dates Shared embedded PDF editors However, these samples are very distinct from the Calendaromatic campaign, sharing no code. This highlights attackers’ preference to abandon codebases upon discovery rather than iterate and evolve. Figure 2 below shows a simplified view of these certificate chains. The PDFPrime and ManualzPDF campaigns have several distinct variants, all with different code signers. Due to the high degree of code overlap, we clustered 34 samples to the PDFPrime/ManualzPDF codebase. We call these samples PixelCheck due to the C2 domains leveraging the format of pixel.toolname[.]com. They represent some of the earliest evidence of the Calendaromatic operator’s activity originating in late 2023. Pivoting through sample repositories to identify other examples of the PixelCheck variant, seven additional signers were identified in the code of related malware: ADVANTAGE WEB MARKETING LLC Europae-Solutio Ltd SP Development and Solution Limited BUZZ BOOST ADVERTISERS LLC ADSMARKETO LLC LLC MATCH-TWO-USERS Monetize forward LLC Tracking these samples via code signing overlaps involves: Identifying the code signers Mapping their certificate chains Pivoting to similar samples Repeating the steps with newly identified signers This iterative approach uncovered an extensive network of seemingly disparate samples, all linked to a single group through certificate ownership. While effective, this discovery method relies on lax operational security. True certificate isolation would prevent expanded identification and limit certificate burning. Reusing code signing across variants also does not appear to be a cost-saving measure, as multiple campaigns often use unique signers rather than reusing a small set of certificates. If cost minimization was the primary goal, we would not see these cases of individual certificate use. Certificate reuse most commonly appears to be a result of poor testing practice, where attackers use previous certificates on early samples of a new campaign before they can procure a dedicated certificate. At the current cost of code-signing certificates, burning more than two certificates per campaign carries heavy financial costs. As a result of this research, we attributed a total of 34 unique code-signing certificates related to the Calendaromatic campaign to the CL-CRI-1089 cluster. Based on the current cost of code-signing certificates, this inefficient approach likely cost the operators over $10,000 in certificate expenses alone. This further highlights the scale of this operation, where this sum is likely considered a reasonable operational cost. Much of the TamperedChef-style malware distribution is via ads, and as such it is subject to ad transparency. Ad transparency is a byproduct of regulation requiring players in the distribution of advertising to provide insights into ad content and owners. Many of the major platforms in the space have their own version of an ad transparency tool or dataset, and investigators can use these to map and track malvertising campaigns. In most cases, ad transparency platforms enable searching either by the advertiser or the site being advertised. While the definition of an advertiser can be complicated, for the most part, the advertiser is the entity that sold or is selling an ad within the platform. This means there is no guarantee that the malware operator and the ad seller are the same or related entities. However, it implies that the malware operator has interacted with the advertiser in some capacity (e.g., exchanging funds or ad details). Advertisers using these advertising marketplaces are held to certain standards by the platforms and must abide by the terms of service, which distribution of malware would typically breach. TamperedChef-style campaigns are different from many other malvertising campaigns, as the malware creators and advertisers are generally vertically integrated. This vertical integration means advertisers also create the malware and, on occasion, sign the code. This direct link between code signers and advertisers implies a strong relationship between malware operators and distributors. This link can provide a starting point to map the wider network distributing this malware. This is particularly evident with activity in CL-UNK-1090 being run by attackers that are clearly well versed in using ad marketplaces to distribute their malware. For CL-UNK-1090, we identified more than 20,000 unique ads deployed over several years via ad transparency platforms. This volume of ads is unlikely to originate from an individual. The OneZip campaign belonging to the CL-UNK-1090 cluster provides a real-world illustration of how tracking these clusters through advertising commonality and agencies works. OneZip is a malicious compression tool with binaries signed by TAU CENTAURI LTD observed in the wild in early 2025. OneZip was distributed via the site onezipapp[.]com (Figure 3 shows the landing page). By leveraging ad transparency platforms, we find that a single advertiser (CANDY TECH LTD) creates and distributes ads for onezipapp[.]com. Based on information from these platforms, CANDY TECH LTD has distributed approximately 4,000 ads that appear related to malicious productivity applications starting in June 2024. Figure 4 below shows an example of the ads distributed. While not the most innovative, attackers have taken care with these ads to consider language, format, logo and branding. This indicates an actor well-versed in the AdTech space. Between June 2024 and December 2024, ad transparency platforms report that CANDY TECH LTD pushed ads for JustConvertFiles, a similar TamperedChef-style campaign. JustConvertFiles is a malicious file conversion tool similar in operation to all other TamperedChef-style samples. JustConvertFiles binaries are signed by B.L.A ASPIRE LTD and PASTEL CONCEPTION LTD, and entities with these names are both observed reusing certificates. These entities appear to be responsible for several other campaigns, including: PDFPilot SwiftNav ShinyPDF FileEase Based on advertising transparency data, we have not observed CANDY TECH LTD representing any campaigns other than TamperedChef-style malware. CANDY TECH LTD is also observed in the malware creation stages, too. Several TamperedChef-style binaries are signed by CANDY TECH LTD or have other links to an entity with this name. These include: ZipMakerPro GifsMakerPro ScreensRecorder RapiDoc (contained a copyright stub with CANDY TECH LTD, but not signed) We then performed the following activities to substantially flesh out CL-UNK-1090 and CL-CRI-1089, and to identify additional campaigns: Leveraging known TamperedChef download URLs Identifying the advertiser Pivoting around the public information on these advertisers These advertising pivots are not without limitations, and many malvertising actors do not have the expertise to set up the AdTech infrastructure, instead relying on established entities for distribution. This makes any sensible linking through public sources much more difficult, as most of the time, the malware advertising only accounts for a small percentage of the advertisers' overall ad presence. In these cases, other methods are likely to be more effective. However, when possible, investigating the distributor can provide more information. The TamperedChef-style malware footprint is large and well-organised, with hundreds of campaigns and large sums of money invested. All TamperedChef certificates are validated by an organization, which means certificate authorities require a corporate entity to fulfill OV/EV requirements to be granted certificates. Certificate issuers impose these validation requirements to aid in maintaining the reputation of signed code. There is a cost, of both money and time, for adversaries to establish a corporation for the sole purpose of signing code. Corporate structures tend to leave traces, particularly in countries where data is publicly available. This opens new avenues for discovery. OSINT sources such as private and government-run corporate search engines can be used to gain rapid insights into corporate entities. Our primary focus areas when tracking code-signing entities were: Co-location, especially in residential dwellings Companies with a handful of employees and minimal presence, especially when owned by much larger corporations, can indicate possible shell corporations Shared ownership structures, particularly when shared ownership is by an individual and not a corporate entity History of company renames (especially renames that are potentially aligned with malware campaigns) With the CL-UNK-1090 cluster, we can use CANDY TECH LTD as an example again. Ad transparency data indicates that CANDY TECH LTD is registered in Israel. Leveraging Israeli company search engines, we found CANDY TECH LTD with a listed phone number, website, address and ownership structure. Figure 5 below shows the webpage for CANDY TECH LTD. From public records, Zizik with me is the director of CANDY TECH LTD and Fairark Systems Ltd. consists of option holders for the company. Zizik with me and Fairark Systems Ltd. are listed as having sole ownership stakes in several companies in Israel, such as: AMARYLLIS SIGNAL LTD TAU CENTAURI LTD RED ROOT LTD BITTERN SKY LTD TOGO NETWORKS LTD The list of companies that we mined from the Zizik with me and Fairark Systems Ltd. ownership structures — as well as some minor variations and co-location checks — match the names of companies that signed significant volumes of TamperedChef-style code. With high confidence, we believe these ownership structures link all cases to a single group. Additionally, many of these companies have undergone several name changes in the past three years. Many of the old names match names that were used to sign TamperedChef-style malware. Fairark Systems Ltd. is the registered name of FireArc, an Israeli advertising company. It states it creates games, connected TV applications, eCommerce solutions and, notably, utility applications. Figure 6 shows this statement on its website. Additionally, the RapiDoc campaign created by CANDY TECH LTD has a program database (PDB) (D:\!Work\Clients\ \Projects\RapiDoc\SrcForTests\RapiDoc\x64\Release\RapiDoc\RapiDoc.pdb). This could have been left by mistake in the RapiDoc binaries installed during execution. PDBs are created during the build process for binaries and contain useful symbol and debug information. Binaries that are productionized tend to remove the PDB, as it can provide reverse engineers a head start when analyzing a binary, which is not desirable for either legitimate software or malware. PDBs, where applicable, were for the most part removed from other TamperedChef-style samples, indicating that this was likely an error. The SHA256 hashes for the binaries containing the PDB are: 248de1470771904462c91f146074e49b3d7416844ec143ade53f4ac0487fdb44 2231bfa7c7bd4a8ff12568074f83de8e4ec95c226230cccc6616a1a4416de268 Leveraging several linking methods, we broadly identified significant portions of these activity clusters’ operations, mapping several networks of TamperedChef-style malware. While this may not represent their entire infrastructure, it highlights the pervasive nature of this threat. We supply all identified samples, domains, signers and any other relevant details in the Indicators of Compromise section. Using Calendaromatic as a starting point, we mapped out the CL-CRI-1089 cluster to include 34 unique code-signing entities. Our primary method of identification was code and certificate reuse. We observed some evidence of shared corporate addresses with code signers. However, generally, each entity was separately created and operated. The CL-CRI-1089 cluster included malvertisements generated through self-created and likely dedicated companies. This cluster did not appear to cross-contaminate advertising entities with code-signing entities. This cluster primarily leveraged companies based out of Ukraine, Malaysia, Singapore, the U.S. and the UK to perform operations. In cases where the owner's place of birth was recorded by the UK government, all owners were of Ukrainian origin. We identified over 3,300 samples related to CL-CRI-1089 across Palo Alto Networks and public sample databases, with the vast majority related to productivity software. We mapped out CL-UNK-1090 primarily through a combination of real-world incidents, OSINT on the FireArc corporate structures and advertising network links. Certificate and code reuse were present but formed less of a basis for discovery. We found CL-UNK-1090 used 39 Israeli corporations for certificate generation. This cluster included changed organization names to mine these structures for multiple certificates, so the real number of organizations is likely less than 39. We identified approximately 750 samples related to CL-UNK-1090, all with productivity application themes. The scale of TamperedChef-style malware is immense. We found evidence of the two tracked clusters (CL-CRI-1089 and CL-UNK-1090) across more than 50% of Managed Threat Hunting customers. If this number is an accurate representation of the wider community, it shows an operation on a scale rarely observed. The distribution and scale of these campaigns come with high monetary and labor costs. TamperedChef-style actors are likely to have bought much of their success. They have positioned themselves less as malware experts than as advertising and logistics specialists. Code signing as a practice provides authenticity and integrity validation to binaries, but it can be misused by malicious actors. Purchasing code-signing certificates offers a marginal increase in binary trustworthiness. However, they come with strict identity validation and cost, which can deter many malware developers. These requirements did not impede any of the TamperedChef actors, and one of their key strengths comes from a deep understanding of the business side of advertising. The development of several shell companies appeared minimally impactful and provided a reusable pool of code-signing certificates. In the case of CL-UNK-1090, it appeared that renaming existing companies was enough to be granted new, valid certificates, further lowering the barrier for entry. In recent months, we’ve identified a trend of these clusters moving away from code signing. This shift could be occurring because these binaries are becoming better understood and researched. The damage done by identifying an entire campaign through tracking code signers may now outweigh the benefits gained through signing binaries. The rate and scale at which the TamperedChef-style actors deploy new campaigns is incredibly fast. Attackers run tens of campaigns simultaneously, with new ones being developed constantly. The CL-CRI-1089 cluster, in particular, demonstrates a high degree of variation. Each campaign features an entirely new set of TTPs, delivery methods, languages, functionality and C2 structures. This suggests a new codebase for each campaign, and potentially even different developers. The code quality also shows a lack of mature development practices and teams likely inexperienced with malware development. This does somewhat work in favor of TamperedChef binaries, as upon first glance, the C2 methods are not always obvious. In the case of CL-CRI-1089, the codebases are highly variant. However, they share common certificates, demonstrating limited code reuse between campaigns. This may indicate they were created by several development teams or that generative AI was at least partially responsible for the set of campaigns. Distribution infrastructure setup appears to be largely driven using generative AI. This is particularly evident with the distribution websites where the content of pages for different campaigns appears visually similar. However, they have distinct Document Object Model (DOM) structures. This is indicative of a non-deterministic development practice, which is characteristic of content generated by large language models (LLMs). TamperedChef-style samples for all clusters are distributed primarily through malvertisements, sponsored results and search engine marketing techniques. Our telemetry for real-world infection chains commonly shows victims browsing terms like “free calendar prints” or “document formatting” before being served the malvertisements. TamperedChef-style malware establishes a distribution-first approach. Getting installed by the masses is far more important to the operators than managing persistent and reliable C2. While none of the identified TamperedChef malware samples are technically complex, they vary significantly between campaigns. All samples tend to share a common set of TTPs and second-stage payloads, which only serves to further highlight the motivations and risks these TamperedChef-style malware samples pose. These universal TTPs include: Leveraging code signing for the first-stage payloads Implementing a robust persistence mechanism, almost always through scheduled tasks or registry Run keys Initial information gathering and exfiltration typically occurring on install - This usually involves simple data collection, like system version, hostname and active browsers. - However, we have seen more targeted information gathered, including patch levels, user details, domain information, geolocation and screen size. Employing a delayed activation technique to evade detection - Initially, the samples mimic legitimate applications, remaining dormant for days or even weeks. - Upon activation, they trigger the next stage, which typically involves downloading and executing an additional payload delivered via an upstream API. Obfuscating the malicious components - This is the clearest evidence to suggest that these binaries are not just simple adware. - Most of the campaigns we observed used some form of obfuscation or defense evasion techniques for their loader or stealer components. - While obfuscation is used for intellectual property (IP) protection, in this case, the routines were primarily for de-obfuscating incoming payloads within the loader components. - Since no other parts of the binaries were obfuscated, IP protection was likely not the main reason for these methods. TamperedChef-style malware, when activated, can deliver arbitrary payloads, but in practice sticks to two primary categories: adware and browser hijackers or RATs and stealer malware. Which payload it delivers depends on the campaign specifics. TamperedChef rarely deploys both simultaneously. The primary objective of the majority of the TamperedChef-style binaries is to distribute ads or gain some form of control over the user’s browser. This has been achieved via either: Installing a new adversary-controlled default search engine in the user’s primary browser Installing an entirely new adversary-controlled browser (e.g., OneBrowser) Both these methods enable adversaries to control the content searched, ads displayed to victims and, in the case of the browser installation, full control over user cookies and credentials. While adware can be disruptive and undesirable, it does not generally pose a major organizational risk. TamperedChef-style binaries, on the other hand, display a level of stealth, defense evasion and persistence that is unusual and excessive for adware. This likely further indicates that the true threat of the TamperedChef-style malware goes beyond adware and into more insidious use cases. This is backed by real-world cases where attackers have consistently deployed active C2 and stealer-style malware as second stages targeting victims’ browser credentials or for information gathering. These second-stage stealers range in capability, targets and formats but are almost always deployed after a dormancy period of weeks. Evidence of more exotic payloads has been observed too, but far less frequently and not en masse. An example of this was the AppSuite campaign that saw the sporadic installation of proxy-style malware. Distilling the Motivations Our analysis shows that CL-CRI-1089 activity focuses on criminal-style activity targeting credentials, deploying adware and in some cases proxy-style payloads. Based on sample and corporate analysis, the operators of CL-CRI-1089 are globally distributed but centrally operated. In contrast, the motivations behind CL-UNK-1090 activity are far less clear. This activity appears to be solely managed by a much smaller group of entities related, at least in part, to a seemingly successful advertising agency. These samples are all designed to look like adware. However, the samples do not operate like adware, housing RATs with .NET loader-style capabilities that legitimate adware or productivity software do not require. In real world cases, we have not observed the same volume of malicious second stage deployments from samples tracked as CL-UNK-1090 as we have with the CL-CRI-1089 samples. However, second stages deployed by CL-UNK-1090 are more stealthy, existing primarily in memory and include RAT deployments, browser hijackers and adware. Some key preventive steps to combat this threat are: Education: Ensure users are aware of this style of threat and know that even legitimate looking software can carry risks Endpoint/extended detection and response (EDR/XDR): Ensure updated EDRs/XDRs are in place on all hosts within an environment Enterprise browsers: Enterprise browsers can help protect against this threat and ensure that in the event of compromise, saved credentials remain secure Device hardening: Consider hardening user endpoints to prevent the installation of software from untrusted sources Due to the prevalence of these threats, continuous active monitoring and hunting can have a very high return on investments however due to the varied nature of these threats hunting queries vary in effectiveness. If these threats are identified, our general remediation advice is to: Remove and/or quarantine all files associated with the malicious software - These are generally located in the installation folder Ensure that persistence mechanisms such as the created scheduled tasks are removed to prevent reinfection - Consider running a full malware scan of the host as it may identify any second-stage components Consider revoking active tokens for the impacted users and resetting their credentials - It is likely that any browser-based credentials are potentially compromised Review access logs to ensure that the impacted users' credentials are not actively being misused TamperedChef-style campaigns are likely to continue to misuse advertising pipelines to deliver malware, developing and adapting new lures and evasion methods. The prevalence of the CL-CRI-1089, CL-UNK-1090 and CL-UNK-1100 clusters will likely serve as a blueprint for future malvertising campaigns. New trends, such as moving away from using code signing, will require new tracking methods to be developed to remain ahead of these actors' operations. Palo Alto Networks customers are better protected from the threats discussed above through the following products: Cortex XDR and XSIAM help to prevent the threats described in this blog, by employing the Malware Prevention Engine. This approach combines several layers of protection, including Advanced WildFire, Behavioral Threat Protection and the Local Analysis module, designed to prevent both known and unknown malware from causing harm to endpoints. Prisma Browser helps to prevent access to known malicious campaigns using Advanced URL Filtering, Advanced Web Protection (Live Page Scanning) which runs AI models within the browser to detect and block attack patterns, file download scanning and protection on the default search engine. If you think you may have been compromised or have an urgent matter, get in touch with the Unit 42 Incident Response team or call: North America: Toll Free: +1 (866) 486-4842 (866.4.UNIT42) UK: +44.20.3743.3660 Europe and Middle East: +31.20.299.3130 Asia: +65.6983.8730 Japan: +81.50.1790.0200 Australia: +61.2.4062.7950 India: 000 800 050 45107 Palo Alto Networks has shared these findings with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the Cyber Threat Alliance. Table 1 lists the signers’ organization noted in code-signing certificates used in the TamperedChef-Style malware samples we found in our research. Table 1. Signers of code-signing certificates from the TamperedChef-style malware samples. Cooking up trouble: How TamperedChef uses signed apps to deliver stealthy payloads – Acronis When the Dash Hits the Fan: Artificial Intelligence Exposes the Homoglyph Hustle – GuidePoint Security EvilAI Operators Use AI-Generated Code and Fake Apps for Far-Reaching Attacks – TrendMicro Malicious Appsuite PDF Editor Spreads Tamperedchef Malware – Truesec The history of AppSuite: the certs of the BaoLoader developer – Expel
unit42.paloaltonetworks.comMay 20, 2026extracted
Le nuove infrastrutture per l’AI partono da un approccio “security first”
Per sfruttare al massimo le opportunità dell’AI, bisogna partire dalla sicurezza. Se l’evoluzione dell’intelligenza artificiale ha già chiarito che l’uso dell’agentic AI ha già abbandonato la fase di sperimentazione per diventare un fenomeno estremamente concreto, la vera sfida che si pone adesso è quella della governance. Una partita che si giocherà su più livelli. L’implementazione dell’AI non sta portando solo a un radicale cambiamento dei modelli di business delle aziende, ma richiede anche una profonda revisione delle infrastrutture digitali su cui poggiano i servizi. È questo lo scenario emerso nel corso di un incontro con la stampa nel quale Acronis ha illustrato l’ennesima evoluzione della sua strategia, rivolgendosi principalmente ai Managed Service Provider. Per comprendere il quadro i cui si inserisce questa scelta è fondamentale partire… dalla fine. Indice degli argomenti L’evento di presentazione della società svizzera si è concluso con un intervento di Ray Kurzweil, autore della teoria sulla singolarità tecnologica. Kurzweil è stato uno dei primi studiosi a teorizzare l’avvento dell’intelligenza artificiale generale (AGI), cioè di quell’AI in grado di raggiungere (o addirittura superare) gli esseri umani. Nel suo video-messaggio ha ricordato come, in tempi non sospetti, avesse fissato una data per questo obiettivo: il 2029. Una previsione basata su considerazioni estremamente pragmatiche. “All’inizio degli anni ’80, mentre lavoravo con Stevie Wonder all’invenzione del primo sintetizzatore capace di riprodurre il suono di un pianoforte a coda, mi resi conto che anche la migliore invenzione fallisce se non viene sviluppata e lanciata nel momento giusto. Così iniziai a monitorare la potenza di calcolo per capire quando introdurre le mie invenzioni.” ha spiegato. “Fu allora che scoprii che il calcolo computazionale – e in realtà tutta la tecnologia, anche se lo si vede soprattutto nel computing – stava avanzando in modo esponenziale”. Un fenomeno che Kurzweil considera guidato da diversi fattori. Se l’evoluzione dell’hardware negli ultimi anni ha subito un rallentamento rispetto a quanto previsto dalla legge di Moore (il raddoppio del numero di transistor integrabili in un chip ogni 18-24 mesi – ndr), lo sviluppo di software più efficienti ha contribuito in maniera decisiva alla crescita della capacità computazionale. “Gli algoritmi che alimentano i grandi modelli linguistici stanno raddoppiando la loro efficienza circa ogni otto mesi”, ha sottolineato. Se per Kurzweil la vera e propria “singolarità” è rappresentata dall’espansione delle capacità umane attraverso l’uso delle nanotecnologie e non si verificherà prima del 2045, nel prossimo futuro l’evoluzione dell’AI manterrà un andamento esponenziale. In questo nuovo contesto, Kurzweil considera la sicurezza come una priorità. “La particolarità dell’IA è che rappresenta sia il problema sia la soluzione” ha spiegato. “Le stesse capacità che possono essere utilizzate per creare minacce sono gli strumenti esatti che possiamo usare per contrastarle e costruire difese più resilienti”. Nella sua visione, vedremo i conflitti informatici svolgersi sempre più tra macchine piuttosto che tra esseri umani. Qualcosa a cui, in una certa misura stiamo già assistendo. La crescita nell’uso di agenti AI, però, porterà a un salto di qualità anche in questo settore. “Dobbiamo accettare che gli esseri umani biologici siano la parte più lenta della rete. Poiché un’AI malevola può lanciare attacchi in millisecondi, non possiamo fare affidamento sugli esseri umani per individuare le minacce in tempo” ha proseguito. “Abbiamo bisogno che le nostre AI difensive agiscano come uno scudo, fermando immediatamente l’agente dannoso prima ancora che un essere umano debba prendere una decisione”. In questa logica, è evidente come il controllo dell’AI diventi uno dei temi fondamentali nello sviluppo delle infrastrutture informatiche. Nella lettura di Acronis, questo obiettivo è raggiungibile solo attraverso la predisposizione di un ambiente che permetta di avere visibilità, controllo e sicurezza. Il livello a cui intervenire è quello alto, rivolgendosi direttamente ai Managed Service Provider per offrire loro una serie di prodotti che consentano di centralizzare la gestione di tutti i servizi (con grande enfasi sull’AI) in un’ottica di semplificazione e messa in sicurezza dei sistemi. La famiglia “Cyber” si compone di diversi strumenti, integrati all’interno di quello che l’azienda svizzera ha battezzato come Cyber Frame. “Si tratta di una piattaforma Infrastructure as a Service (IaaS) che mette a disposizione degli MSP una iperconvergenza che mette al centro la security” conferma Desin Cassinerio, Senior Director and General Manager of South Europe & CEE di Acronis. “Il framework che mettiamo a disposizione permette di integrare tutte le tecnologie legate alla sicurezza informatica in maniera nativa, partendo dal supporto multi-tenant”. La mossa di Acronis si colloca in una fase in cui il mercato dell’iperconvergenza e della virtualizzazione sta vivendo una fase di assestamento che si muove su due binari. Da una parte lo scossone legato alla vicenda del cambio delle politiche commerciali di VMware, che hanno portato molte aziende del mondo MSP a valutare alternative allo storico ecosistema di virtualizzazione. Sotto un’altra prospettiva, la creazione di un framework con le caratteristiche di Cyber Frame conferma la necessità di evolvere verso le principali richieste delle aziende: gestione dell’AI e garanzie sulla sicurezza informatica. “Stiamo attraversando un momento trasformativo estremamente importante” sottolinea Cassinerio. “Il nostro obiettivo è quello di offrire una soluzione che garantisca un elevato livello di sicurezza e la massima semplicità nella gestione di tutti i servizi” conclude.
cybersecurity360.itMay 18, 2026extracted
Why ransomware attacks succeed even when backups exist
Written by Subramani Raom Senior Manager, Cybersecurity Solutions Strategy at Acronis Your backup plan probably won’t survive a ransomware attack. Why? Because backups fail during ransomware attacks when attackers deliberately target and destroy backup systems before launching encryption. In modern attacks, backup infrastructure is often exposed, accessible and unprotected, making recovery impossible. What should serve as a recovery mechanism becomes a single point of failure instead. Platforms like Acronis Cyber Platform address this problem by combining backup with security controls such as immutability, access protection and threat detection. For years, backups have been positioned as the ultimate fallback in cybersecurity strategy, the guarantee that even if systems are compromised, recovery is still possible. But there is a new, uncomfortable reality: Backups often fail during ransomware attacks not because they don’t exist but because they are exposed, accessible and unprotected. It’s no secret that the pace and severity of ransomware attacks are continually accelerating. The number of attacks rose 50% last year, according to the Acronis Cyberthreats Report H2 2025. It’s time for IT and security professionals to rethink long-standing assumptions about backup and recovery. How attackers systematically break backup strategies Most ransomware attacks follow a predictable sequence: Initial access → credential theft → lateral movement → backup discovery → backup destruction → ransomware deployment To stop this chain, organizations need controls at each stage. For example, Acronis integrates endpoint protection, credential monitoring and backup protection in one platform to detect threats before backups are compromised. Backup systems are rarely isolated. Once attackers gain administrative credentials, they can: Enumerate backup servers and storage repositories. Access backup consoles via stolen credentials. Delete or encrypt backup files and snapshots. Disable backup agents and scheduled jobs. Modify retention policies to remove recovery points. Common techniques include: Deleting Volume Shadow Copies (VSS) on Windows systems. Using legitimate admin tools (living-off-the-land techniques). Targeting hypervisor snapshots in virtual environments. Exploiting API access to cloud backup storage. By the time ransomware is executed, it’s too late. Recovery paths are already gone. Secure your business with integrated backup, rapid disaster recovery, and AI‑powered endpoint security and management. Stop threats sooner, recover faster, and simplify daily IT work—all from a single Acronis platform built to reduce complexity and downtime. Strengthen IT Resilience with Acronis The most common backup failures in ransomware incidents Across incident response investigations, several recurring weaknesses explain why backup and recovery ransomware strategies fail. No isolation between production and backup Backup systems often sit in the same domain, use the same credentials and are reachable from compromised hosts. This eliminates any meaningful separation between production and backup systems. Weak access controls Shared admin credentials, lack of multifactor authentication (MFA) and overprivileged service accounts give attackers easy entry into backup infrastructure. No immutability If backups can be modified or deleted, attackers will remove them. Traditional backups without immutability offer little resistance. Untested recovery processes Organizations frequently discover during an incident that backups are incomplete, corrupted or too slow to restore at scale. Siloed security and backup tools Backup systems often operate independently of security monitoring, so attacks on backup infrastructure go undetected. Why immutability is critical for ransomware protection If backups can be modified or deleted, attackers will remove them. This is why traditional backups fail. Immutable backups prevent any changes or deletion for a defined period, ensuring a clean recovery point always exists. Acronis Cyber Platform provides immutable storage with enforced retention policies and protection against credential misuse. Key characteristics of immutable backup include: Write-once, read-many (WORM) storage. Time-based retention locks. Protection against API and credential misuse. Enforcement at the storage layer not just software. Even if attackers gain full administrative access, immutable backups remain intact. This ensures that a clean recovery point always exists, which is essential for business continuity. However, immutability alone is not enough. It must be combined with access control, monitoring and recovery validation. 5 ways to protect backups from ransomware For managed service providers (MSPs) and enterprise IT teams managing multiple environments, securing backups requires consistency and standardization. Key practices include: 1. Enforce identity separation: Use dedicated credentials and MFA 2. Isolate backup environments: Segment networks and limit access 3. Use immutable backups: Prevent deletion or modification 4. Monitor backup activity: Detect abnormal behavior early 5. Test recovery regularly: Ensure backups can be restored Platforms like Acronis integrate all these capabilities into a single solution, reducing complexity and improving resilience. What to do if backups are already compromised When backups are impacted during a ransomware attack, recovery becomes significantly more complex. Options to rectify the situation include: Identifying older untouched backup copies if they exist. Leveraging off-site or cloud-based immutable storage. Rebuilding systems from clean baselines. Using forensic analysis to determine the last known good state. This highlights a critical point: Recovery is not just about having backups but about having trustworthy backups. Building a ransomware-resilient backup strategy The Acronis research is clear: to protect backups from ransomware, organizations need to move beyond traditional backup thinking and adopt a resilience-first approach. MSPs and organizations looking to ensure backups are protected from ransomware attacks should invest in protection solutions like those in the Acronis Cyber Platform, which include: Integrating security and backup Backup systems should not operate in isolation. Detection, protection and recovery must work together. Automating protection and recovery Manual processes fail under pressure. Automated backup validation and recovery orchestration reduce risk. Ensuring end-to-end visibility Security teams need visibility into backup status, anomalies and potential compromise indicators. Designing for attack scenarios Assume attackers will reach backup systems and design controls accordingly. The shift toward integrated cyber protection One of the biggest gaps in traditional architectures is fragmentation. Separate tools for endpoint protection, backup and monitoring create blind spots that attackers exploit. A more effective approach is consolidating these capabilities into a unified platform that can: Detect threats before backup compromise occurs. Protect backup infrastructure with the same rigor as production systems. Ensure recovery points remain intact and verified. Provide centralized visibility across environments. Solutions like the Acronis Cyber Platform are designed around this integrated model, combining backup, cybersecurity and recovery management into a single operational framework. That model reduces complexity while improving resilience. Backups fail because they are exposed Backups still play a critical role in ransomware defense but only if they are designed to withstand active attacks. The key takeaway is simple: Backups fail not because they are missing but because they are exposed. To ensure recovery in modern threat environments, organizations must rethink backup architecture with security at its core, embracing immutability, isolation, monitoring and integration. After all, your backup is only as strong as its ability to survive the attack. Author: Subramani Rao Subramani Rao is Senior Manager, Cybersecurity Solutions Strategy at Acronis, where he focuses on solution strategy, positioning, and go-to-market initiatives across operational technology, business continuity, and cyber protection. He has more than 15 years of cybersecurity experience across security strategy, risk, compliance, cloud, and resilience, and has helped organizations align security outcomes with broader business priorities. He holds an Executive MBA from London Business School, an MSc in Computer Security, and is CISSP certified. Sponsored and written by Acronis.
bleepingcomputer.comMay 6, 2026extracted
⚡ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & More
This week, the shadows moved faster than the patches. While most teams were still triaging last month’s alerts, attackers had already turned control panels into kill switches, kernels into open doors, and open-source pipelines into silent delivery systems. The game has shifted from breach to occupation. They’re living inside SaaS sessions, pushing code with trusted commits, and scaling operations like legitimate businesses — except their product is chaos. And the underground is getting uncomfortably professional. Here’s the full weekly cybersecurity recap: ⚡ Threat of the Week cPanel Flaw Comes Under Attack—A critical flaw in cPanel and WebHost Manager (WHM) has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-41940, could result in an authentication bypass and allow remote attackers to gain elevated control of the control panel. In some cases, the attacks have led to a complete wipe of entire websites and backups. Other attacks have deployed Mirai botnet variants and a ransomware strain called Sorry. Is Your Security Program Built on Compliance Theater or Measurable Maturity? If you can't measure your program's maturity, you can't improve it or defend its budget. The SANS Security Awareness & Culture Maturity Model™️ maps 5 stages of security culture development with concrete indicators, behavioral targets, and alignment to business risk priorities. Download Now — Free ➝ 🔔 Top News Cybercrime Groups Use Vishing for Data Theft and Extortion—Two cybercrime groups tracked as Cordial Spider and Snarky Spider are carrying out "rapid, high-impact attacks" operating almost within the confines of SaaS environments, while leaving minimal traces of their actions. The groups employ voice calls, text messages, and emails, directing targeted employees to phishing pages masquerading as their employer's legitimate single sign-on (SSO) page to capture credentials and provide attackers an entry point into systems, which they exploit for deeper access to victims' SaaS environments. The attacks also use the initial access hooks to remove and set up multi-factor authentication devices under their control and delete emails that would otherwise alert organizations of potential malicious activity. According to CrowdStrike, "These actors use vishing to bypass MFA and move laterally across entire SaaS ecosystems with a single authenticated session, masking their tracks through residential proxy networks to blend in as legitimate home user traffic. This is part of a larger trend of English-speaking ransomware crews that share similar playbooks but are branching off into their own distinct groups." Copy Fail Linux Flaw Exploited—The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-31431, a vulnerability impacting various Linux distributions, to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. It's described as a logic bug in the Linux kernel's authentication cryptographic template that allows an attacker to reliably trigger privilege escalation trivially by means of a 732-byte Python-based exploit. According to Theori and Xint, CVE-2026-31431 was the result of a series of unremarkable updates to the Linux kernel over the years, particularly one update from 2017 that was meant to speed up data encryption. As a result, all major Linux distributions from 2017 are impacted. What complicates matters is that Copy Fail works 100% of the time, unlike most local privilege escalation (LPE) bugs that tend to be probabilistic in nature. More worryingly, it leaves no traces on disk as exploitation occurs in memory and enables container escape from any pod in a Kubernetes cluster. TeamPCP's Supply Chain Attack Spree Continues—TeamPCP's extensive supply chain campaign continued last week, as the cybercriminal group compromised several packages across the npm, PyPI, and Packagist ecosystems in a "Mini Shai-Hulud" attack. TeamPCP has in recent months compromised the packages of several open source software projects, including Trivy, a security scanner maintained by Aqua Security, and KICS, a Checkmarx-developed tool for static code analysis. Amit Genkin, threat researcher at Upwind, said the latest string of attacks represents a shift, where they are not only more frequent but harder to detect because they weaponize legitimate CI/CD pipelines to push out poisoned versions under real identities, allowing the activity to blend in with normal development workflows. "Campaigns like Shai-Hulud take that further by using each compromised pipeline to spread to the next, turning credential theft into a scaling problem across environments," Genkin said. "For teams, the immediate priority is to check for the affected version and rotate any credentials tied to pipelines that may have run it, especially GitHub and cloud tokens. Longer term, this is a signal to reduce how broadly pipeline credentials are scoped and to add visibility into what's actually happening during installs and builds – because if you're relying on traditional scanning or known indicators, this type of activity is easy to miss." New Python Backdoor Enables Comprehensive Data Theft—A newly identified stealthy Python-based backdoor framework dubbed DEEP#DOOR provides attackers with persistent remote command execution and surveillance capabilities on Windows computers. Once active, the backdoor enables shell command execution, file manipulation, system and network reconnaissance, and surveillance operations such as keylogging, clipboard monitoring, screenshot capture, microphone and webcam access, and credentials and SSH key harvesting. Additionally, the malware can shift from data gathering to disruption and system manipulation, as it can overwrite the Master Boot Record, force system crashes, exhaust system resources by spawning numerous processes, and disable Microsoft Defender services. GitHub Flaw Leads to Remote Code Execution—Cybersecurity researchers from Wiz disclosed details of a critical security vulnerability impacting GitHub.com and GitHub Enterprise Server (CVE-2026-3854, CVSS score: 8.7) that could allow an authenticated user to obtain remote code execution with a single "git push" command. The vulnerability was severe enough that Microsoft rolled out a patch within six days of responsible disclosure. On GitHub.com, it allowed remote code execution on shared storage nodes, and on GitHub Enterprise Server, it granted full server compromise, enabling unauthorized access to all hosted repositories and internal secrets. "Exploitation could expose the codebases of nearly all of the world's biggest enterprises, making this one of the most severe SaaS vulnerabilities ever found," a Wiz spokesperson told The Hacker News. VECT 2.0 Ransomware's Flawed Encryption Makes Data Recovery Impossible—VECT 2.0 ransomware has been found to wipe large files instead of merely encrypting them, making recovery impossible, even for the attackers. VECT 2.0 is a ransomware-as-a-service (RaaS) program that first appeared in December 2025. The group quickly grabbed headlines after it announced on BreachForums that it was partnering with TeamPCP, the threat group behind several supply chain attacks, such as Trivy, Checkmarx KICS, LiteLLM, and Telnyx, in March and April 2026. VECT also announced a partnership with BreachForums itself, promising that every registered forum user will become an affiliate and be granted use of the ransomware, negotiation platform, and leak site for operations. Beazley Security, in an analysis of the ransomware, said the VECT 2.0 RaaS panel covers the "full operational lifecycle an affiliate needs from payload generation through to payout." 🔥 Trending CVEs Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild. Check the list, patch what you have, and hit the ones marked urgent first — CVE-2026-41940 (cPanel and WebHost Manager), CVE-2026-31431 aka Copy Fail (Linux Kernel), CVE-2026-42208 (LiteLLM), CVE-2026-3854 (GitHub.com and GitHub Enterprise Server), CVE-2026-32202 (Microsoft Windows Shell), CVE-2026-26268 (Cursor), CVE-2026-35414 (OpenSSH), CVE-2026-6770 (Mozilla Firefox and Tor Browser), CVE-2026-42167 (ProFTPD), CVE-2026-24908, CVE-2026-23627, CVE-2026-24487 (OpenEMR), CVE-2026-6807 (GRASSMARLIN), CVE-2026-7363, CVE-2026-7361, CVE-2026-7344, CVE-2026-7343 (Google Chrome), CVE-2026-7322, CVE-2026-7323, CVE-2026-7324 (Mozilla Firefox), CVE-2026-6100 (CPython), CVE-2026-0204 (SonicWall), CVE-2026-35414 (OpenSSH), CVE-2026-42511 (FreeBSD), CVE-2026-40684, CVE-2026-40685, CVE-2026-40686, CVE-2026-40687 (Exim), CVE-2026-5402, CVE-2026-5403, CVE-2026-5405, CVE-2026-5656 (Wireshark), CVE-2026-42520, CVE-2026-42523, CVE-2026-42524 (Jenkins), CVE-2026-3008 (Notepad++), and CVE-2025-41658, CVE-2025-41659, CVE-2025-41660 (CODESYS). 🎥 Cybersecurity Webinars Learn to Spot Attack Paths Your AppSec Tools Completely Miss → Modern attackers chain tiny flaws across code, pipelines, and cloud into major breaches — while your AppSec tools stay blind. Join this free webinar with Wiz and The Hacker News to uncover the top real-world attack paths and learn exactly how to spot, map, and stop them fast. Practical insights to prioritize real risks and strengthen your entire software lifecycle. How to Match AI Attack Speed with Autonomous Exposure Validation → Struggling with AI attacks moving faster than your team can respond? Join this free webinar from Picus Security & The Hacker News to discover Autonomous Exposure Validation – how to automatically find real risks, test attack paths, and fix them in minutes, not weeks. Practical, no-fluff insights to stay ahead without burnout. Grab your spot now. Learn Latest AI Threats + Practical Ways to Kill Initial Access → Modern attackers are slipping past traditional defenses with AI-powered phishing, encrypted malware, and stealthy “Patient Zero” tactics. Want to stay ahead? Join this free webinar with Zscaler and The Hacker News to uncover the latest threat trends and practical Zero Trust strategies that actually stop initial compromise — before it becomes a full-blown breach. No fluff, just real insights to protect your organization. 📰 Around the Cyber World OpenAI Debuts Advanced Account Security —OpenAI launched Advanced Account Security, a set of opt-in protections for ChatGPT users "designed for people at increased risk of digital attacks, as well as for those who want the strongest account protections available." As part of the new program, the new controls strengthen sign-in protections, tighten account recovery, reduce exposure from compromised sessions, and give users more visibility into account activity. OpenAI has also partnered with Yubico to link two physical security keys, YubiKey C Nano and YubiKey C NFC, to ChatGPT accounts. That said, users can use any other FIDO-compliant security key, or use software-based passkeys for phishing-resistant authentication. Over 8.8K Ransomware Attacks in 2025 —Fortinet said it recorded 7,831 confirmed ransomware victims globally in 2025, skyrocketing from approximately 1,600 identified victims in 2024. "Availability of crime service kits like WormGPT, FraudGPT, and BruteForceAI contributed to this 389% increase year-over-year (YoY)," Fortinet said. "The top three targeted sectors include manufacturing (1,284), business services (824), and retail (682). Geographic concentration includes the U.S. (3,381), Canada (374), and Germany (291)." KidsProtect Android Surveillance Tool Marketed on the Web —A new Android surveillance tool called KidsProtect is being openly advertised on the clear web that gives an operator near-total secret control of a victim’s phone. "It can't be removed without the attacker's permission," Certo said. "From a web-based dashboard, an operator can secretly record calls, stream live audio from the device’s microphone, track GPS location in real time, read SMS messages and notifications from apps including WhatsApp and Viber, log keystrokes, access contacts and photos, and remotely trigger the front and rear cameras." Assessed to be the work of a Greek-speaking developer, it's available on a subscription basis starting from $60, allowing anyone to buy it, rebrand it, and start selling it as their own. New KYCShadow Android Malware Detected —An Android malware masquerading as a bank KYC verification application is being distributed via WhatsApp and primarily targeting users in India. "The application operates as a multi-stage dropper that installs a secondary payload and establishes persistent command-and-control (C2) communication," CYFIRMA said. "It combines native code obfuscation, Firebase-based remote execution, VPN-based traffic manipulation, and WebView-based phishing to systematically harvest sensitive user data." Phishing Campaign Targets Pakistan Orgs —A highly targeted spear-phishing campaign targeting the Punjab Safe Cities Authority and PPIC3 in Pakistan has been found to use legitimate-sounding government infrastructure projects as lures to deliver malware. "The email carried two malicious attachments: a Word document with a VBA macro dropper and a PDF with a fake Adobe Reader lure, both delivering payloads from a BunnyCDN-hosted malicious infrastructure," Joe Security said. "The attack chain establishes persistent remote access by abusing Microsoft's legitimate VS Code tunnel service, with exfiltration notifications sent via a Discord webhook — a sophisticated technique designed to evade network-level detection." Calendly-Themed Phishing Attacks on the Rise —Multiple threat clusters are leveraging Calendly-themed phishing to fingerprint site visitors and steal credentials and other data. "Behind the shared Calendly branding sits a diverse set of phishing kits, including API-driven frameworks, real-time Socket.IO applications, fake CAPTCHA chains, and Telegram-based exfiltration," urlscan said. Fraud Campaigns GovTrapand FEMITBOT Exposed —Threat actors have been observed deploying sophisticated tactics, including fake government portals, SMS phishing, and lookalike domains, to drive financial fraud and credential harvesting as part of an effort called GovTrap. The government impersonation scam mimics official portals with high accuracy, with links to the fake sites distributed via SMS or email. The end goal is to trick users into entering their personal and financial information, or make non-existent payments that are transferred through money mule accounts. The collected payment card details are abused to facilitate fraudulent transactions. Another threat cluster has leveraged FEMITBOT, a malicious infrastructure that abuses Telegram Mini Apps to scale global fraud campaigns and Android malware delivery. "By leveraging Telegram's native features, threat actors create highly convincing fake platforms across crypto, financial services, AI, and streaming sectors," CTM360 said. "Built on a modular, template-driven architecture, FEMITBOT enables rapid deployment, brand impersonation, and campaign optimization using real-time tracking and analytics." New PowerShell Desktop Stealer Spotted —A Pastebin-hosted PowerShell script disguised as "Windows Telemetry Update" comes with capabilities to steal Telegram Desktop session data via Telegram bot API exfiltration. "The script collects host metadata, including username, hostname, and public IP via api.ipify[.]org, then checks for Telegram Desktop and Telegram Desktop Beta tdata directories," Flare said. "If found, it terminates the Telegram process to release file locks, archives session material into 'TEMP\diag.zip,' and uploads the archive to the attacker-controlled operator chat via the Telegram Bot API sendDocument endpoint." Surge in Teams Phishing in 2026 —eSentire said it has observed an increase in Microsoft Teams-based phishing since early 2026, in which threat actors impersonate IT support and help desk personnel to trick users into granting remote access to their devices. "These phishing attacks have often been linked to email bombing, followed by threat actors reaching out to users under the guise of providing assistance to resolve an issue," eSentire said. "The objective of the attack is to trick the user into granting remote access to their device, and once obtained, threat actors will attempt to exfiltrate data and execute additional payloads to establish persistence or deploy ransomware." New KarstoRAT Malware Enables Data Theft —First spotted in early 2026, KarstoRAT is capable of system reconnaissance, audio and webcam monitoring, screenshot capture, key logging, and token theft. It also enables threat actors to download and run additional payloads, which could point to it being used for post-compromise control on infected machines. "KarstoRAT uses a command-and-control (C2) server that has a diverse set of open ports and services, indicating that it has a multi-purpose infrastructure created for C2 communication and payload distribution," LevelBlue said. "Threat actors use a fake Blox Fruits (a popular Roblox game) virtual marketplace as a lure to trick players into downloading malware that will install KarstoRAT into their machines." ClickUp Discloses Email Address Exposure —ClickUp said its client-side feature flag configuration exposed personally identifiable information. This included 893 customer email addresses that were embedded in feature flag targeting rules, along with one flag that improperly referenced a customer’s API token. "The exposure was limited to 893 customer email addresses used in feature flag targeting rules to control which users see specific features during rollouts," it said. "If your email address was among those included in a feature flag configuration, you have been directly contacted." The incident did not expose any other data. Finnish Authorities Arrest Alleged Scattered Spider Member —Finnish authorities arrested 19-year-old Peter Stokes (aka Bouquet), a dual U.S.-Estonian citizen, as he tried to board a flight to Japan. U.S. prosecutors have charged him as a key member of the notorious Scattered Spider hacking group, and he faces multiple counts of wire fraud, conspiracy, and computer intrusion. New Attacks Linked to Versatile Werewolf —The threat actor known as Versatile Werewolf (aka HeartlessSoul) has been linked to campaigns targeting Russian state structures and aviation companies via phishing emails with malicious archive attachments and malvertising campaigns to deliver a JavaScript trojan. The end goal is to obtain confidential data, particularly geospatial information. Alternatively, the threat actor is known to distribute malicious code using the legitimate SourceForge platform through a project called GearUP. Versatile Werewolf is believed to be active since at least September 2025. Some of the attachments have exploded ZDI-CAN-25373 to trigger the infection chain. The malvertising campaign uses fake domains ("battleflight[.]pro") to deliver bogus installers for aviation-related software to launch the same trojan. "The initial infection involves executing PowerShell commands or scripts designed to download a JavaScript loader from C2 servers," Kaspersky said. "This loader, in turn, loads and executes the main JS-RAT and its modules in memory, among which we found tools for data collection and exfiltration, keyloggers, screen capture tools, UAC bypass tools, and other payloads." The company noted that the domain "battleflight[.]pro" resolves to an IP address that also hosts fake domains linked to the GOFFEE APT. "Both groups actively use PowerShell payloads to deliver and execute malicious modules," it added. "GOFFEE also targets the public sector, which suggests the possibility of joint or coordinated campaigns." Cisco Unveils Model Provenance Kit —Cisco unveiled a new open-source tool, named Model Provenance Kit, to help organizations address potential issues associated with the use of third-party AI models. "Much like a DNA test reveals biological origins, the Model Provenance Kit examines both metadata and the actual learned parameters of a model (like a unique genome that comprises a model), to assess whether models share a common origin and identify signs of modification," Cisco said. "This, combined with a constitution that defines provenance linkages, is an important step toward providing evidence-based assurance that the AI you deploy is what it says it is." Abuse of Hugging Face and ClawHub for Malware Delivery —Threat actors are abusing legitimate AI platforms like Hugging Face and ClawHub for malware delivery, once again demonstrating how trust in AI ecosystems are being exploited. Acronis said it identified more than 575 malicious skills across 13 developer accounts that target both Windows and macOS systems with trojans, cryptocurrency miners, and AMOS stealer, a macOS-focused infostealer. "On Hugging Face, attackers leverage repositories to host payloads and act as staging infrastructure within multistep infection chains, distributing malware disguised as legitimate applications," Acronis said. European Authorities Bust Cryptocurrency Fraud Ring —Albanian and Austrian authorities dismantled a cryptocurrency investment fraud ring that caused estimated losses of more than €50 million ($58.5 million) to victims worldwide. The operation, which took place over two years, resulted in the arrest of ten individuals, the search of multiple premises, and the seizure of 891,735 in cash, 443 computers, 238 mobile phones, six laptops, and multiple storage devices. "The criminal network, allegedly operating several call centres in Tirana, Albania, is believed to have caused significant financial damage, totalling at least €50 million," Europol said. "The call centres were professionally set up and organized, resembling legitimate business structures featuring a clear division of roles and hierarchical management." The criminal network is estimated to have involved up to 450 employees across various departments. The scheme involved luring victims to seemingly legitimate online investment platforms through deceptive advertisements on social media or web searches, and coaxing them into making investments under the promise of huge returns. Victims were then assigned retention agents, who masqueraded as investment advisors and used remote access software to gain full control of their devices. "The fraudsters feigned professional expertise and employed psychological pressure to persuade victims to make additional investments, falsely claiming they would be profitable," Europol said. "In truth, the funds were never invested but were instead channelled into an intricate international money-laundering scheme, ultimately disappearing into the hands of the criminal organisation." In some cases, the fraudsters reached out to the victims again and offered help with recovering their stolen funds, only to demand a €500 entry fee and defraud them a second time. Flaws in EnOcean's SmartServer —Two security flaws have been disclosed in EnOcean's SmartServer IoT platform that affect version 4.60.009 and prior. According to Claroty: "CVE-2026-20761 allows remote attackers to send malicious, crafted LON IP-852 messages that result in arbitrary command execution on devices. CVE-2026-22885 allows remote attackers to send malicious, crafted IP-852 messages that bypass ASLR memory protections and leak memory." Successful exploitation of the flaws results in attackers obtaining control over building management and building automation systems running affected versions of this platform and legacy i.LON devices. Patches have been released for both vulnerabilities. Google Announces Android Credential Manager Update —Google has announced a new update to Android's Credential Manager that allows apps to automatically verify a user's personal Gmail address without requiring one-time passwords (OTPs) or email verification links. "Google now issues a cryptographically verified email credential directly to Android devices," the company said. "For users, this completely removes the need to manually verify their email through external channels. For developers, the API securely delivers these verified user claims for any scenario, whether you are building an account creation flow, a recovery process, or a high-risk step-up authentication." Nearly 8.8K Secrets Leaked Online —According to Truffle Security, 8,792 verified, unique secrets have been leaked online through web-based development environments. The tokens were found across 22 million public projects hosted on Cloud Development Environments (CDEs) such as CodePen, CodeSandbox, JSFiddle, and StackBlitz. Is There More to the Xygeni Compromise? —Multiple connections have been found between the compromise of the Xygeni vulnerability scanner on GitHub and a proxy botnet of hacked ASUS and TP-Link routers. Some of the TP-Link consumer routers have been compromised with Microsocks to unroll them to a residential proxy network. "These routers were also running a custom command-and-control beacon that was named ShadowLink," Ctrl-Alt-Intel said. "When we analysed the ShadowLink protocol, we found it was identical, down to a shared authentication secret, to the backdoor planted in the Xygeni GitHub Action used for that supply chain attack." Brazilian Anti-DDoS Firm Behind DDoS Attacks on ISPs —Huge Networks, a Brazilian tech company that specializes in protecting networks from distributed denial-of-service (DDoS) attacks, has been enabling a botnet responsible for massive DDoS attacks against other internet service providers (ISPs) in the country, according to KrebsOnSecurity. The company has since said the malicious activity resulted from an intrusion first detected in January 2026 and claimed it was likely the work of a competitor. Canonical Target of Sustained DDoS Attack —Canonical disclosed its web infrastructure came under a "sustained, cross-border attack," knocking Ubuntu servers offline for several hours. A pro-Iranian hacktivist group known as the Islamic Cyber Resistance in Iraq, aka 313 Team, claimed responsibility for the attack on Telegram. The websites have since become operational. Last month, the group also disrupted access to the decentralized social media platform Bluesky. New Phishing Kit Bluekit Detailed —A new phishing kit named Bluekit is offering more than 40 templates targeting popular services and includes basic artificial intelligence (AI)-powered features for generating campaign drafts. Available templates can be used to target email accounts (Outlook, Hotmail, Gmail, Yahoo, ProtonMail), cloud and enterprise services (iCloud and Zoho), developer platforms (GitHub), and cryptocurrency services (Ledger). What makes the kit stand out is the presence of an AI Assistant panel that supports multiple models, including Llama, GPT-4.1, Claude, Gemini, and DeepSeek, to help criminals draft phishing emails. It also has support for two-factor authentication, geolocation emulation, antibot cloaking, notifications, spoofing capabilities, voice cloning, and a mail sender. The development once again reinforces the broader trend of crimeware services integrating AI to streamline and scale their operations. Bluekit is the second kit to integrate AI features in as many months. In April 2026, Abnormal Security shed light on a cybercrime platform called ATHR that uses AI vishing agents, credential harvesting panels, and built-in phishing mailers to execute and scale telephone-oriented attack delivery (TOAD) attacks. North Korea Calls U.S. Cyber Threat Claims a Fabrication — North Korea's foreign ministry rejected U.S. accusations that the country poses a cyber threat, stating the U.S. was spreading false information about a non-existent cyber threat from North Korea for political purposes, per Reuters. The ministry said it "would actively take all necessary measures for defending the interests of the state and protecting the rights and interests of its citizens in cyberspace." 🔧 Cybersecurity Tools Model Provenance Kit → It is a free open-source Python tool from Cisco AI Defense that helps identify if a machine learning model is based on a known base model (like Llama, Mistral, GPT, etc.). It analyzes architecture, tokenizer, and weights to quickly compare two models or check against a database of ~150 popular base models. AutoFyn → It is an open-source tool from SignalPilot Labs that runs Claude AI in self-improving loops to optimize measurable goals. Give it a GitHub repo, a clear task (like security hardening, bug fixing, or performance optimization), and a time budget — it works in sandboxed rounds, tracks progress with real evaluations, learns from failures, and delivers improved code via PRs. Disclaimer: This is strictly for research and learning. It hasn't been through a formal security audit, so don't just blindly drop it into production. Read the code, break it in a sandbox first, and make sure whatever you’re doing stays on the right side of the law. Conclusion Stay sharp out there. The pace of attacks is accelerating, and the margin for delay is shrinking. Patch what you can today, verify your supply chains, tighten SaaS access, and treat every “routine” login or pipeline run as potentially hostile. Small habits now will save major headaches later. Until next Monday. Keep your defenses tight and your eyes open. The threats won’t wait — neither should we. See you in the next recap.
thehackernews.comMay 4, 2026extracted
Microsoft confirms April Windows updates cause backup failures
Microsoft has confirmed that the April 2026 security updates are causing failures in third-party backup applications using the psmounterex.sys driver. As BleepinComputer reported last week, this issue affects software using VSS (Volume Shadow Copy Service) snapshots and causes failures due to a VSS service timeout. Software impacted by this includes, but is not limited to, products from Macrium (Reflect), Acronis (Cyber Protect Cloud), UrBackup Server, and NinjaOne Backup running on Windows 11, Windows Server, and Windows 10 devices. A Macrium spokesperson told BleepingComputer after the article was published that "the update causes issues in legacy versions of Reflect (which are no longer sold or supported); our latest version, Reflect X, isn't experiencing this issue." Microsoft has now updated its support documents to confirm that the April updates include a security hardening change that adds psmounterex.sys to the company's vulnerable driver blocklist to defend users against attacks targeting a high-severity buffer overflow vulnerability (CVE-2023-43896) that allows attackers to escalate privileges or execute arbitrary code. Microsoft also advised those affected by this issue to update to a newer version of their app that uses newer drivers, which include the required protections. On impacted systems, where the vulnerable drive is blocked by Windows Code Integrity enforcement, IT admins and users may observe the following behavior: Backup applications that rely on the kernel driver psmounterex.sys might fail to mount backup image files as virtual drives. Attempting to browse or restore from a backup image might result in errors or timeouts. Failures might be followed by error messages, such as "The backup has failed because Microsoft VSS has timed out during the snapshot creation" or VSS_E_BAD_STATE. Event Viewer might show Code Integrity errors indicating that psmounterex.sys was blocked from loading. Backup creation (full image backups) may still succeed, but image-mount operations will fail. "In the April 2026 Windows security update, we added known vulnerable kernel driver psmounterex.sys to the Vulnerable Driver Blocklist. Backup applications that rely on this driver may experience failures when attempting to mount or manage disk images," Microsoft told BleepingComputer. "We do not recommend uninstalling or pausing this update. Customers with an impacted driver should install the latest application versions and validate against the driver blocklist to remain protected." To check whether the Microsoft Vulnerable Driver Blocklist blocks a driver, affected customers can look for 'Event ID 3077' with Policy ID {D2BDA982-CCF6-4344-AC5B-0B44427B6816} in the Code Integrity Operational log, which indicates that the psmounterex driver was blocked in enforcement mode. To do that, right-click Start, select Event Viewer, go to 'Applications and Services Logs\Microsoft\Windows\CodeIntegrity\Operational' in the left pane, and look for Event ID 3077 in the middle pane. Earlier this month, Microsoft warned that some Windows Server 2025 devices may also boot into BitLocker recovery mode, prompting users to enter the BitLocker key after installing the KB5082063 update. Microsoft also released out-of-band (OOB) updates to fix issues affecting Windows Server systems that caused update installation failures and restart loops after installing the April 2026 security updates. Update May 30, 03:28 EDT: Added Macrium statement. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comMay 4, 2026extracted
Hugging Face, ClawHub Abused for Malware Distribution
Threat actors are using trojanized shared files to distribute malware via AI distribution platforms such as Hugging Face and ClawHub, Acronis reports. The attacks do not compromise AI agents, but rely on social engineering to trick users into downloading files containing malicious code designed to execute commands, fetch payloads, and install hidden dependencies. The same as other AI distribution platforms, both Hugging Face and ClawHub allow developers to easily share code, and threat actors are abusing users’ trust in them for nefarious purposes. “A key aspect of this activity is the abuse of trust between users, AI agents and external resources. Through techniques such as indirect prompt injection, attackers embed hidden instructions that can be executed by AI systems without user awareness,” Acronis explains. On ClawHub, the company identified close to 600 malicious skills across 13 developer accounts designed to distribute trojans, cryptominers, and information stealers targeting both Windows and macOS systems. Two of the identified developer accounts contained most of the malicious skills: hightower6eu had 334, and sakaen736jih had 199, Acronis says. In the OpenClaw ecosystem, skills are community-built extensions that allow users to expand their agents’ capabilities. This modular architecture also means that the AI can execute external code with high privileges. By injecting indirect prompts into resources that the AI reads, the attackers instruct the agents to download and execute code on users’ machines, leading to malware infections. One of the identified payloads targeting macOS users is the infamous Atomic macOS Stealer (AMOS) Stealer. “It appears that threat actors distributing payloads through traditional vectors such as malvertisement are increasingly shifting toward poisoning trusted distribution channels. In particular, AI-related platform ecosystems such as ClawHub are being abused to deliver payloads while leveraging user trust in legitimate-looking AI tooling,” Acronis says. Across two distribution campaigns abusing Hugging Face, the attackers created repositories hosting malicious files and designed to stage multi-step infection chains leading to infostealers, trojans, malware loaders, and other types of malware targeting Windows, Linux, and Android. According to Acronis, other campaigns may also abuse the platform for similar purposes, as threat actors take advantage of Hugging Face’s increased popularity and rapid expansion. “Accurately measuring the full extent is difficult because of the platform’s scale and the dynamic nature of hosted content. The true scale of this activity is likely higher but requires further and deeper investigation,” Acronis notes. Related: Chinese Cybersecurity Firm’s AI Hacking Claims Draw Comparisons to Claude Mythos Related: Why Agentic AI Systems Need Better Governance – Lessons from OpenClaw Related: Hugging Face Abused to Deploy Android RAT Related: Dozens of Open VSX Extension Clones Linked to GlassWorm Malware
securityweek.comMay 1, 2026extracted
April KB5083769 Windows 11 update causes backup software failures
The April 2026 KB5083769 security update breaks third-party backup applications from multiple vendors on systems running Windows 11 24H2 and 25H2. According to user reports, first spotted by Microsoft MVP Susan Bradley, this issue affects software using VSS (Volume Shadow Copy Service) snapshots and causes failures due to a VSS service timeout. Microsoft VSS was introduced in Windows Server 2003 and helps ensure that the operating system, backup software, and business apps (such as SQL Server and Exchange) work together more effectively. VSS is also used by Windows features and applications like Windows Server Backup, System Center Data Protection Manager, and System Restore. The list of software impacted by this known issue includes, but is not limited to, products from Acronis (Cyber Protect Cloud), Macrium (Reflect), NinjaOne Backup, and UrBackup Server. Acronis has also published a support document confirming that the issue affects Windows 11 Pro and Home editions, causing backup operations to fail with the error "The backup has failed because Microsoft VSS has timed out during the snapshot creation" after installing the KB5083769 update. "This update may introduce system-wide issues that affect Microsoft VSS (Volume Shadow Copy Service) operations, leading to backup failures," Acronis says. "In some cases, the affected machine may also lose connectivity with the cloud console and appear offline." As a temporary workaround, affected users are advised to uninstall the problematic "Security update for Microsoft Windows (KB5083769)" from Settings > Windows Update > Update history > Related settings > Uninstall updates, then pause Windows updates and reboot the system. BleepingComputer reached out to Microsoft for more information, but a response was not immediately available. Earlier this month, Microsoft also released out-of-band (OOB) updates to fix issues affecting Windows Server systems that caused them to enter restart loops and trigger update installation failures after installing the April 2026 security updates. Microsoft also warned that some Windows Server 2025 devices will boot into BitLocker recovery and ask for a BitLocker key after installing the KB5082063 update. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comApr 30, 2026extracted
Brazilian LofyGang Resurfaces After Three Years With Minecraft LofyStealer Campaign
A cybercrime group of Brazilian origin has resurfaced after more than three years to orchestrate a campaign that targets Minecraft players with a new stealer called LofyStealer (aka GrabBot). "The malware disguises itself as a Minecraft hack called 'Slinky,'" Brazil-based cybersecurity company ZenoX said in a technical report. "It uses the official game icon to induce voluntary execution, exploiting the trust of young users in the gaming scene." The activity has been attributed with high confidence to a threat actor known as LofyGang, which was observed leveraging typosquatted packages on the npm registry to push stealer malware in 2022, specifically with an intent to siphon credit card data and user accounts associated with Discord Nitro, gaming, and streaming services. The group, believed to be active since late 2021, advertises their tools and services on platforms like GitHub and YouTube, while also contributing to an underground hacking community under the alias DyPolarLofy to leak thousands of Disney+ and Minecraft accounts. "Minecraft has been a LofyGang target since 2022," Acassio Silva, co-founder and head of threat intelligence at ZenoX, told The Hacker News. "They leaked thousands of Minecraft accounts under the DyPolarLofy alias on Cracked.io. The current campaign goes after Minecraft players directly through a fake 'Slinky' hack." The attack begins with a Minecraft hack that, when launched, triggers the execution of a JavaScript loader that's ultimately responsible for the deployment of LofyStealer ("chromelevator.exe") on compromised hosts and execute it directly in memory with an aim to harvest a wide range of sensitive data spanning multiple web browsers, including Google Chrome, Chrome Beta, Microsoft Edge, Brave, Opera, Opera GX, Mozilla Firefox, and Avast Browser. The captured data, which includes cookies, passwords, tokens, cards, and International Bank Account Numbers (IBANs), is exfiltrated to a command-and-control (C2) server located at 24.152.36[.]241. "Historically, the group's primary vector was the JavaScript supply chain: NPM package typosquatting, starjacking (fraudulent references to legitimate GitHub repositories to inflate credibility), and payloads embedded in sub-dependencies to evade detection," ZenoX said. "The focus was on Discord token theft, Discord client modification for credit card interception, and exfiltration via webhooks abusing legitimate services (Discord, Repl.it, Glitch, GitHub, and Heroku) as C2." The latest development marks a departure from previously observed tradecraft and a shift towards a malware-as-a-service (MaaS) model with free and premium tiers, along with a bespoke builder called Slinky Cracked that's used as a delivery vehicle for the stealer malware. The disclosure comes as threat actors are increasingly abusing the ubiquity and trust associated with GitHub to host bogus repositories that act as lures for malware families like SmartLoader, StealC Stealer, and Vidar Stealer. Unsuspecting users are directed to these repositories through techniques like SEO poisoning. In some cases, attackers have been found to spread Vidar 2.0 through Reddit posts advertising fake Counter-Strike 2 game cheats, redirecting victims to a malicious website that delivers a ZIP archive containing the malware. "This infostealer campaign highlights an ongoing security challenge where widely trusted platforms are abused to distribute malicious payloads," Acronis said in an analysis published last month. "By taking advantage of social trust and common download channels, threat actors are often able to bypass traditional security solutions." The findings add to a growing list of campaigns that have leveraged GitHub in recent months - Targeting developers directly inside GitHub, using fake Microsoft Visual Studio Code (VS Code) security alerts posted through Discussions to trick users into installing malware by clicking on a link. "Because GitHub Discussions trigger email notifications for participants and watchers, these posts are also delivered directly to developers' inboxes," Socket said. "This extends the reach of the campaign beyond GitHub itself and makes the alerts appear more legitimate." Targeting Argentina's judicial systems using spear‑phishing emails to distribute a compressed ZIP archive that uses an intermediate batch script to retrieve a remote access trojan (RAT) hosted on GitHub. Creating GitHub accounts and OAuth applications, followed by opening an issue that mentions a target developer, triggering an email notification that, in turn, tricks them into authorizing the OAuth app, effectively allowing the attacker to obtain their access tokens. The issues aim to induce a false sense of urgency, warning users of unusual access attempts. Using fraudulent GitHub repositories to distribute malicious batch script installers masquerading as legitimate IT and security software, leading to the deployment of the TookPS downloader, which then initiates a multi-stage infection chain to establish persistent remote access using SSH reverse tunnels and RATs like MineBridge RAT (aka TeviRAT). The activity has been attributed to Rift Brigantine (aka FIN11, Graceful Spider, and TA505). Using counterfeit GitHub repositories posing as AI tools, game cheats, Roblox scripts, phone number location trackers, and VPN crackers to distribute LuaJIT payloads that function as a generic trojan as part of a campaign dubbed TroyDen's Lure Factory. "The breadth of the lure factory – gaming cheats, developer tools, phone trackers, Roblox scripts, VPN crackers – suggests an actor optimizing for volume across audiences rather than precision targeting," Netskope said. "Defenders should treat any GitHub-hosted download that pairs a renamed interpreter with an opaque data file as a high-priority triage candidate, regardless of how legitimate the surrounding repository looks."
thehackernews.comApr 28, 2026extracted
Mustang Panda’s New LOTUSLITE Variant Targets India Banks, South Korea Policy Circles
Cybersecurity researchers have discovered a new variant of a known malware called LOTUSLITE that's distributed via a theme related to India's banking sector. "The backdoor communicates with a dynamic DNS-based command-and-control server over HTTPS and supports remote shell access, file operations, and session management, indicating a continued espionage-focused capability set rather than financially motivated objectives," Acronis researchers Subhajeet Singha and Santiago Pontiroli said in an analysis. The use of LOTUSLITE was previously observed in spear-phishing attacks targeting U.S. government and policy entities using decoys associated with the geopolitical developments between the U.S. and Venezuela. The activity was attributed with medium confidence to a Chinese nation-state group tracked as Mustang Panda. The latest activity flagged by Acronis involves deploying an evolved version of LOTUSLITE that demonstrates "incremental improvements" over its predecessor, indicating that the malware is being actively maintained and refined by its operators. The deviation from the prior attack wave relates to a geographic pivot that focuses mainly on the banking sector of India, while keeping the rest of the operational playbook mostly intact. The starting point of the attack is a Compiled HTML (CHM) file embedding the malicious payloads – a legitimate executable and a rogue DLL – along with an HTML page that contains a pop-up which prompts the user to click "Yes." This step is designed to silently retrieve and execute a JavaScript malware from a remote server ("cosmosmusic[.]com"), whose primary responsibility is to extract and run the malware contained inside the CHM file using DLL side-loading. The DLL ("dnx.onecore.dll") is an updated version of LOTUSLITE that communicates with the domain "editor.gleeze[.]com" to receive commands and exfiltrate data of interest. Further analysis of the campaign has uncovered similar artifacts designed to target South Korean entities, specifically individuals within the policy and diplomatic community. "We believe that the group had been targeting certain entities belonging to the South Korean and U.S. diplomatic and policy communities, specifically those involved in Korean peninsula affairs, North Korea policy discussions and Indo-Pacific security dialogues," Acronis said. "What stands out is the broadening of the group's targeting, from U.S. government entities with geopolitical lures, to India's banking sector through implants embedded with HDFC Bank references and pop-ups masquerading as legitimate banking software, and now to South Korean and U.S. policy circles through the impersonation of a prominent figure in Korean peninsula diplomacy, delivered via spoofed Gmail accounts and Google Drive staging."
thehackernews.comApr 22, 2026extracted
ThreatsDay Bulletin: Defender 0-Day, SonicWall Brute-Force, 17-Year-Old Excel RCE and 15 More Stories
You know that feeling when you open your feed on a Thursday morning and it's just... a lot? Yeah. This week delivered. We've got hackers getting creative in ways that are almost impressive if you ignore the whole "crime" part, ancient vulnerabilities somehow still ruining people's days, and enough supply chain drama to fill a season of television nobody asked for. Not all bad though. Some threat actors got exposed with receipts, a few platforms finally tightened things up, and there's research in here that's genuinely worth your time. Grab your coffee and keep scrolling. Targeted wallet breachCryptocurrency wallet service Zerion has disclosed that one of its team member's devices was compromised, resulting in the theft of approximately $100K in stolen funds from internal company hot wallets. The company noted that user funds, Zerion apps, or infrastructure were not impacted by the breach. The team member is said to have been the target of an artificial intelligence (AI)-enabled social engineering attack carried by a North Korean threat actor tracked as UNC1069. The hacking group was recently attributed to the poisoning of the popular Axios npm package. "This allowed the attacker to gain access to some of the team members' logged-in sessions and credentials as well as private keys to company hot wallets used for testing and internal purposes," Zerion said. "This was not an opportunistic attack. The actor is clearly sophisticated and well-resourced. They planned the attack thoroughly." Anonymous age checksThe European Union has announced that it will soon roll out a new online age verification app to allow users to prove their age when accessing online platforms. Users can set it up by downloading the app on their Android or iOS device using a passport or ID card. The Commission has emphasized that the app will respect users' privacy. "Users will prove their age without revealing any other personal information," President of the European Commission, Ursula von der Leyen, said. "Put simply, it is completely anonymous: users cannot be tracked. Third, the app works on any device – phone, tablet, computer, you name it. And, finally, it is fully open source – everyone can check the code." The development comes as countries around the world are undertaking various stages of regulatory action to keep cyberspace a safer place for children and minors and protect them from serious harm. New Defender zero-dayA researcher using the alias "Chaotic Eclipse" released a zero-day exploit called BlueHammer earlier this month following Microsoft's handling of the vulnerability disclosure process. Although the issue appears to have been fixed as of this month's Patch Tuesday release (CVE-2026-33825), the researcher has since disclosed a new unpatched Microsoft Defender privilege escalation vulnerability. The exploit has been codenamed RedSun. "This works 100% reliably to go from unprivileged user to SYSTEM against Windows 11 and Windows Server with April 2026 updates, as well as Windows 10, as long as you have Windows Defender enabled," security researcher Will Dormann said. A third exploit released by "Chaotic Eclipse," referred to as UnDefend, also targets Defender and triggers a denial-of-service (DoS) condition. "This tool, while stupid, is quite dangerous [be]cause if paired with BlueHammer, your machine is basically a hole, anyone can run anything with administrator privileges andwindows defender can't really do much about it," the researcher said. "Considering that's the whole purpose of an antivirus, you're better off removing it LOL." Legacy Excel RCE activeThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added an old remote code execution vulnerability impacting Microsoft Office to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to remediate the shortcoming by April 28, 2026. The vulnerability in question is CVE-2009-0238, which has a CVSS score of 8.8. "Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object," CISA said. sudo now requires passwordRaspberry Pi has released version 6.2 of its Raspberry Pi OS, which introduces one significant change: it disables passwordless sudo by default. As a result, users who run a sudo command for administrator-level access will be prompted to enter the current user's password. The change affects only new installations; existing setups are untouched. "Given the ever-increasing threat of cybercrime, we continually review the security of Raspberry Pi OS to ensure it is sufficiently robust to withstand potential attacks," Raspberry Pi said. "This is always a tricky balance, as anything that makes the operating system more secure will invariably inconvenience legitimate users to some extent, so we try to keep such changes to a minimum. This particular security update is one that many users may not even notice, but it will affect some." Stealth C2 frameworks uncoveredA previously undocumented command-and-control (C2) framework dubbed ObsidianStrike has been deployed on infrastructure belonging to a Brazilian law firm. "Only two instances of ObsidianStrike exist on the entire internet," Breakglass Intelligence said. "The framework has zero presence on GitHub, zero samples on VirusTotal or MalwareBazaar, and near-zero vendor detection. This is a fully private, Portuguese-language C2 built for targeted Windows operations, hidden behind a victim organization's domain." Also discovered by the security vendor is ArchangelC2, a C2 panel behind an industrial-scale ScreenConnect remote-access fraud campaign that has been operational since November 2024. Fake app drains $9.5MA fake Ledger app managed to slip onto the Apple App Store, draining $9.5 million in cryptocurrency from more than 50 victims between April 7 and April 13, 2026. The app, named Ledger Live, was released by a developer, "SAS Software Company," and published under "Leva Heal Limited." Users who downloaded the fraudulent app were tricked into entering their seed phrases, giving attackers full access to their wallets and allowing them to send digital assets to external addresses under their control. While Apple has since removed the macOS app from the store, questions remain as to how it managed to pass the company's review process. In more Apple-related news, the company has also removed a data harvesting app called Freecash from its App Store after it was deceptively advertised as a way to "make money just by scrolling TikTok," while collecting sensitive information from users. This included details about a user's race, religion, sex life, sexual orientation, health, and other biometrics. Once installed, however, instead of the promised functionality, users were routed to a roster of mobile games where they are offered cash rewards for completing time-limited in-game challenges. The app continues to be available on the Google Play Store. Localized ransomware campaignCybercriminals are using a new ransomware strain called JanaWare to target people in Turkey, according to Acronis. The attack leverages phishing emails containing a Google Drive link that paves the way for the download and subsequent execution of a malicious JAR file via javaw.exe. The payload is a customized Adwind (aka AlienSpy, jRAT, or Sockrat) variant with polymorphic characteristics that's used to deliver the ransomware module. The malware implements geofencing and environment filtering to ensure that the compromised systems match the Turkish language and region. While none of these tricks are particularly novel or advanced, they continue to work against unprotected small targets. It's unclear how many people or businesses might have fallen prey to the scheme. The low-stakes, localized approach has allowed the campaign to persist since at least 2020 without any major disruption. "Victimology appears to primarily include home users and small to medium-sized businesses. Initial access is assessed to occur via phishing emails delivering malicious Java archives," the company said. "Ransom demands observed in analyzed samples range from $200–$400, consistent with a low-value, high-volume monetization approach." Crackdown on navigation abuseGoogle said it's introducing a new spam policy for "back button hijacking," which occurs when a site interferes with a user's browser navigation and prevents them from using their back button to immediately get back to the page they came from. Instead, the hijack could redirect users to sketchy sites or other pages they have never visited before. "Back button hijacking interferes with the browser's functionality, breaks the expected user journey, and results in user frustration," Google said. "Pages that are engaging in back button hijacking may be subject to manual spam actions or automated demotions, which can impact the site's performance in Google Search results. To give site owners time to make any needed changes, we're publishing this policy two months in advance of enforcement on June 15, 2026." Stealth cloud credential theftThe China-linked hacking group known as APT41 has been attributed to an undetectable, purpose-built ELF backdoor targeting Linux cloud workloads across Amazon Web Services (AWS), Google Cloud, Microsoft Azure, and Alibaba Cloud environments. "The implant uses SMTP port 25 as a covert command-and-control channel, harvests cloud provider credentials and metadata, and phones home to three Alibaba-themed typosquat domains hosted on Alibaba Cloud infrastructure in Singapore," Breakglass Intelligence said. "A selective C2 handshake validation mechanism renders the server invisible to conventional scanning tools like Shodan and Censys." RDP phishing hardeningStarting with the April 2026 security update (CVE-2026-26151), Microsoft has introduced new Windows protections to defend against phishing attacks that abuse Remote Desktop connection (RDP) files, adding security warnings and turning off redirections by default. "Malicious actors misuse this capability by sending RDP files through phishing emails," Microsoft said. "When a victim opens the file, their device silently connects to a server controlled by the attacker and shares local resources, giving the attacker access to files, credentials, and more." Russian hacking groups like APT29 have weaponized RDP configuration files to target Ukrainian government agencies, enterprises, and military entities in the past. Plugin supply chain breachUnknown threat actors have staged a supply chain attack on a WordPress plug-in maker called Essential Plugin (formerly WP Online Support) after acquiring it in early 2025 from the original developers in a six-figure deal to plant a backdoor in August and subsequently weaponize it early this month to distribute malicious payloads to any website with the plug-ins installed. WordPress has since permanently closed all the plugins. "The plugin's wpos-analytics module had phoned home to analytics.essentialplugin.com, downloaded a backdoor file called wp-comments-posts.php (designed to look like the core file wp-comments-post.php), and used it to inject a massive block of PHP into wp-config.php," Anchor Hosting said. "The injected code was sophisticated. It fetched spam links, redirects, and fake pages from a command-and-control server. It only showed the spam to Googlebot, making it invisible to site owners." In addition, it resolved the command-and-control (C2) domain through an Ethereum smart contract to make it resilient to takedown efforts. Prior to their removal, the plugins collectively had more than 180,000 installs. "This is a classical case of supply chain compromise that happened because the original vendor sold their plugins to a third-party, which turned out to be a malicious threat actor," Patchstack said. Sanctioned crypto market persistsTelegram has continued to host Xinbi Guarantee, an illicit marketplace that has processed over $21 billion in total transaction volume, despite sanctions issued by the U.K. last month. The development has raised questions about the platform's willingness to police its own ecosystem and suspend bad actors. The Chinese-language bazaar is known to offer money laundering solutions to cryptocurrency scammers, harassment services, and products like electrified batons and tasers that cater to investment scams operating out of Southeast Asia. "Xinbi is still going strong," Elliptic's cofounder and chief scientist, Tom Robinson, told WIRED. "They're on track to become the largest market of this kind that has ever existed." Malvertising leads to ransomwareOrange Cyberdefense has revealed that threat actors used malvertising in three separate incidents observed between early February and early April 2026 to deliver the SmokedHam (aka Parcel RAT, SharpRhino, and WorkersDevBackdoor) backdoor by masquerading it as installers for RVTools or Remote Desktop Manager (RDM). The malware is assessed to be a modified version of the open-source trojan known as ThunderShell. In at least one case, the attack led to the deployment of Qilin ransomware, but not before dropping employee monitoring and remote desktop solutions like Controlio, TeraMind, and Zoho Assist for persistent access, exfiltrating KeePass password databases, and conducting discovery and lateral movement. The adoption of legitimate dual-use tools is a concerning trend as it allows attackers to blend their actions into legitimate activity and reduce the risk of detection. The activity has been attributed with medium confidence to UNC2465, an affiliate of DarkSide, LockBit, and Hunters International. It also overlaps with a campaign detailed by Synacktiv and Field Effect in early 2025. APT lineage link uncoveredNew research has discovered that the threat actor known as Water Hydra (aka DarkCasino) is still active in 2026, with new evidence uncovering a previously unreported connection between evilgrou-tech, a commodity operator, and the hacking group. "The handle 'evilgrou' is assessed with moderate confidence to be a deliberate reference to EvilNum (Evil + [num -> grou]p), the predecessor APT group from which WaterHydra/DarkCasino splintered in late 2022," Breakglass Intelligence said. The strongest attribution indicator is a shared developer workspace path embedded in binaries associated with EvilNum and Water Hydra: "C:\Users\Administrator\Desktop\vaeeva\shellrundll.tlb." These two artifacts are separated by two years, one in July 2022 and the other in January 2024. Scientific software RCE riskCybersecurity researchers have disclosed security flaws in HDF5 software, a file format to manage, process, and store heterogeneous data, that could be exploited to compromise a vulnerable system. "The discovered vulnerabilities, based on a stack buffer overflow, could allow threat actors to overwrite memory and compromise target systems for stealing highly classified research data, industrial espionage, or a foothold into the internal network," ThreatLeap's co-founder, Leon Juranic, said. "In practice, this means the vulnerability could be exploited by a single specially crafted malicious input file and, as a result, an entire system could get compromised." The issues were addressed in October 2025 following responsible disclosure. Brute-force surge on edge devicesSecurity researchers have detected a "sharp rise" in brute-force attempts to hijack SonicWall and FortiGate devices between January and March 2026, with the vast majority (88%) appearing to originate from the Middle East. Most attempts were unsuccessful, either blocked outright by security tools or directed at invalid usernames. "Attackers are aggressively scanning and testing perimeter devices for weak or exposed credentials," Barracuda Networks said. "Even when attacks fail, persistent probing raises the risk that a single weak password or misconfiguration could lead to compromise." Fraud network evades sanctionsTriad Nexus, a sprawling cybercrime ecosystem acting as the backbone of scams, money laundering, and illicit gambling operations since at least 2020, has been observed using geographic fencing and laundering its infrastructure through "clean" front companies to acquire accounts at major enterprise cloud providers (Amazon, Cloudflare, Google, and Microsoft) in an attempt to distance itself from Funnull, a Philippines-based company that was sanctioned by the U.S. last year. Simultaneously, the group has expanded into the Spanish, Vietnamese, and Indonesian markets using localized templates to target these regions. Besides engaging in fraud, the group specializes in high-fidelity brand impersonation, weaponizing the digital identities of Global 2000 companies to dupe victims. "The network has industrialized brand theft on a global scale; its catalog includes 'pixel-perfect' clones of everything from high-end luxury goods to public services," Silent Push said. "Despite federal sanctions in 2025, the group has reinstated its global fraud engine, shifting its focus toward emerging markets while maintaining a persistent threat to Western enterprise assets." Triad Nexus is estimated to be responsible for over $200 million in reported losses, primarily fueled by pig butchering and virtual currency scams. That's a wrap for this week. If anything here made you pause, good. Go check your patches, side-eye your dependencies, and maybe don't trust that app just because it's sitting in an official store. The basics still matter more than most people want to admit. We'll be back next Thursday with whatever fresh chaos the internet cooks up. Until then, stay sharp and keep your logs close. See you on the other side.
thehackernews.comApr 16, 2026extracted
New ‘JanaWare’ ransomware targeting Turkish citizens as cybercriminal ecosystem fragments
New ‘JanaWare’ ransomware targeting Turkish citizens as cybercriminal ecosystem fragments Cybercriminals are using a new ransomware strain called JanaWare to target people in Turkey, according to a new report from cybersecurity firm Acronis. The researchers said the ransomware operation has been ongoing since 2020 and is associated with a strain of malware that enforces execution constraints based on system locale and external IP geolocation — restricting its activity to systems only in Turkey. The ransom demands are very low, hovering around $200 to $400, and Acronis said the hackers are likely opting for a low-value, high-volume approach. “Despite evidence suggesting the campaign has been active for several years, its regional focus and relatively small-scale operations likely helped it remain largely unnoticed,” the researchers said. “This case demonstrates how targeted, localized ransomware campaigns can quietly persist in the threat landscape.” Acronis said the ransomware was typically used against home users and small to medium-sized businesses, with most becoming infected through phishing emails that delivered malicious Java archives. The attacks begin with a malware strain called Adwind that contains several features that “hinder detection and analysis, including heavy obfuscation,” Acronis said. The ransom notes are written in Turkish and victims are urged to contact the hackers through qTox — a free decentralized chat platform that operates over the Tox peer-to-peer network. Several analyzed incidents began with an email read through Microsoft Outlook. A Google Drive link in the email triggered the launch of a process that led to the download of a malicious file. Acronis shared one victim report found on a popular public forum confirming that their device files were encrypted by JanaWare after opening an email in Outlook. The malware checks the victim’s system location, language and country settings — requiring it to match the Turkish language and location. It will proceed only if the system is in Turkey. Acronis noted that the focus on Turkey also limits the ability of international security researchers to examine the malware and ransomware. They suggested the specific targeting of Turkish residents “suggests the malware is not opportunistic but instead part of a targeted campaign with a defined geographic scope, using location checks both to evade detection and to ensure it operates only in intended environments.” The ransom note — which is written in Turkish — is embedded directly within the malware, according to Acronis, providing another example proving the campaign is targeted specifically at Turkish residents. The Acronis report comes amid warnings from cybersecurity researchers and law enforcement agencies that the ransomware ecosystem is fragmenting following multiple high-profile disruptions of larger ransomware gangs. Last week, the FBI said it identified 63 new ransomware variants that caused more than $32 million in losses last year. A ransomware report published on April 8 by TRM Labs backed that assessment, finding that while ransomware-linked volume on the blockchain fell from $1.9 billion in 2024 to $1.3 billion in 2025, 93 new ransomware variants emerged last year. That represents a 94% increase compared to 2024. But TRM Labs found that ransomware activity was expanding beyond Russia and other regions that do not have extradition treaties with the U.S. "What we saw in 2025 is a ransomware ecosystem that is more fragmented than ever — but that fragmentation is also creating real vulnerabilities," said Ari Redbord, global head of policy at TRM Labs. "The old playbook of brand-level takedowns is less effective against 161 variants — but for the first time, we're seeing operators in reachable jurisdictions, weaker service layers exposed, and a laundering infrastructure that is far more traceable than actors assume." Redbord added that the intelligence gained from past leaks and seizures has given law enforcement an opportunity to disrupt ransomware gangs “at a scale we haven't seen before.” "The question for 2026 is whether that window gets used,” Redbord said. Jonathan Greig is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
therecord.mediaApr 14, 2026extracted
Acronis MDR by TRU brings 24/7 managed detection and response to MSPs
Acronis MDR by TRU brings 24/7 managed detection and response to MSPs Acronis has announced the launch of Acronis MDR by Acronis TRU, a globally available 24/7/365 managed detection and response (MDR) service. Built specifically for managed service providers (MSPs) of all sizes, the service provides threat detection, incident response, and cyber resilience powered by the Acronis Threat Research Unit (TRU). With this offering, MSPs can expand their security capabilities and deliver scalable protection without the complexity or cost of operating an in-house security operations center. As cyber threats grow in sophistication and frequency, many MSPs struggle to deliver advanced security services due to the cost, expertise, and infrastructure required. Acronis MDR by Acronis TRU addresses this challenge by delivering continuous monitoring, rapid threat containment, and expert incident response powered by the Acronis Threat Research Unit, helping MSPs strengthen client security while reducing operational overhead. Unlike MDR services that rely on multiple tools for detection, remediation, and recovery, Acronis MDR by Acronis TRU provides an integrated, globally available solution optimised for MSPs of all sizes. The service combines endpoint detection and response with integrated proactive protection via patch management and built-in business continuity capabilities, enabling faster incident response, streamlined management, and improved cyber resilience. “Acronis MDR by Acronis TRU was built to make advanced detection and response accessible globally to MSPs of any size,” said Gaidar Magdanurov, President at Acronis. “Unlike traditional MDR services, Acronis MDR combines proactive protection, integrated business continuity, and Acronis’ expertise so MSPs have the ability to deliver secure, high-quality MDR to their clients while minimising complexity and costs.” MDR purpose-built for MSPs Acronis MDR by Acronis TRU enables MSPs to expand their service portfolio with a scalable, cost-efficient solution that integrates detection, response, and recovery in a single platform for end-to-end cyber resilience and business continuity. Key benefits include: 24/7 monitoring and rapid response – Continuous endpoint monitoring, threat triage, and rapid isolation by Acronis’ Threat Research Unit (TRU). Critical incidents are remediated in as little as 15 minutes. Integrated proactive protection and business continuity – Built-in patch management and attack rollback capabilities enable seamless protection and recovery. Highly accessible for MSPs – Flexible pricing and simplified onboarding make MDR easy to adopt and scale. “If you want to build a strong security operation, you need 24/7 coverage and deep expertise. That’s not something a mid-sized MSP can easily do in-house, but with Acronis MDR, we get that level of protection for our customers,” said Robert Nieuwenhuijse, CEO at SIX ICT. “We were really impressed by the technical knowledge of the MDR team—the way they investigate incidents, how thoroughly they work and how they communicate. It shows the seniority of the experts protecting our systems.” Broader MDR ecosystem As part of the broader Acronis MDR portfolio, the service can also be delivered through trusted MSSP partners. These options help MSPs worldwide scale MDR delivery while ensuring integration, compliance, and high-quality service. With Acronis MDR by Acronis TRU as the primary offering, and additional options through strategic MSSP partners, Acronis enables MSPs across the globe to provide compliant, localised, and secure MDR services.
helpnetsecurity.comApr 7, 2026extracted
Vidar Stealer 2.0 Exploits GitHub, Reddit to Deliver Malware via Fake Game Cheats
Hundreds of GitHub repositories seemingly offering “free game cheats” deliver malware, including the Vidar infostealer, Acronis Threat Research Unit (TRU) has found. While the identified malicious repositories already target “virtually every major online game title,” the security researchers estimate the true number “could be in the thousands”, they warned in a report published on March 17. They also found Reddit posts mentioning and promoting a game cheat for Counter-Strike 2 leading to a fake website that encourages the user to download and install Vidar 2.0. The campaigns delivering the infostealer start, like most typical cheat campaigns, in Discord chat rooms or Reddit communities dedicated to cheating in specific online games, said Acronis TRU. “In their simplest form, campaigns take the shape of an offer for a ‘free’ cheating tool,” the researchers wrote. The targeted users become “the perfect victims” as they are willingly looking for software that operates outside legitimate channels. Therefore, they expect the software to behave in ways that might trigger security warnings and they have strong incentive not to report any suspicious activity to authorities. Moreover, the researchers noted that cheats typically require deep system access, making it easier for malicious actors to lure users into installing malware that bypasses traditional defenses. GitHub Repository Distribution Chain Several fake GitHub repositories identified by the researchers distribute the Vidar 2.0 infostealer variant masking as game cheats or hardware ID ban bypass software. In this campaign, it lures the victim to download the software named TempSpoofer.exe, Monotone.exe or CFXBypass.exe. These first-stage payloads, disguised as game cheats, are PowerShell scripts compiled into .NET executables using PS2EXE, allowing them to bypass basic script-based detections while appearing as legitimate applications. The PowerShell loader then executes a multi-stage infection process: Defender evasion: adds an exclusion to Windows Defender for an attacker-controlled directory, preventing scanning of subsequent malicious payloads Command-and-control (C2) communication: retrieves a secondary payload URL from a hard-coded Pastebin link, which points to a GitHub-hosted executable Payload delivery: creates a hidden directory in %AppData%, adds it to Defender’s exclusion list, and downloads background.exe (a Themida-packed Vidar Stealer 2.0). Execution and privilege escalation: verifies the file’s integrity (MZ header check), hides it from the user, and attempts to elevate privileges via runas Persistence: establishes a scheduled task (SystemBackgroundUpdate) to run at logon with elevated privileges The Vidar Stealer 2.0 payload then: Creates a directory in %ProgramData% to store stolen data Exfiltrates data to C2 servers masked via Telegram and Steam dead-drop resolvers (e.g., hxxps://telegram[.]me/bul33bt, hxxps://steamcommunity[.]com/profiles/76561198765046918) Reddit Distribution Chain In another campaign, attackers spread Vidar 2.0 through Reddit posts advertizing fake Counter-Strike 2 game cheats, redirecting victims to a malicious website that delivers EzFrags_Private.zip. The archive contains a self-extracting (SFX) executable with an invalid digital signature, raising suspicion. Upon execution, the loader extracts an embedded cabinet archive and runs a command to process Perfume.mdb, a script obfuscated with randomized variable names to hinder analysis. The script then creates a directory (123043) and assembles Typically.com, a compiled AutoIt interpreter, by stitching together file fragments. It then builds the Vidar 2.0 payload from multiple .mdb files and executes it via AutoIt. The final payload connects to the same C2 infrastructure seen in prior campaigns, suggesting the same threat actor or group is behind both operations. Vidar 2.0: A Stealthier, More Powerful Infostealer The real novelty in the campaigns detected by Acronis TRU is the delivery of Vidar 2.0. Vidar is an infostealer capable of extracting browser credentials, cookies and autofill data, as well as Azure tokens, cryptocurrency wallets, FTP/SSH credentials, Telegram, Discord and local files. According to the researchers, Vidar 2.0 represents a significant technical evolution from the first version of the infostealer, with enhanced capabilities including: Polymorphic builds and multithreaded execution that improve speed and evade static detection Advanced obfuscation, debugger detection, timing checks and virtual machine detection that hinder analysis C2 infrastructure hidden via Telegram bots and Steam profiles as dead drop resolvers “Taken together, these capabilities make Vidar 2.0 a powerful and stealthy threat, often completing its mission before victims are aware anything is wrong, and well before stolen data can be recovered or invalidated,” the researchers highlighted. The latest version of the Vidar Sealer has risen in adoption after law enforcement actions against two of the most prominent infostealers, Lumma and Rhadamanthys. “This demonstrates how enforcement action reshapes the threat landscape: criminal demand simply migrates, and defenders must remain vigilant and informed,” the researchers concluded.
infosecurity-magazine.comMar 18, 2026extracted
From VMware to what’s next: Protecting data during hypervisor migration
Broadcom’s acquisition of VMware in 2023 set off a wave of migrations that shows no signs of subsiding. But moving from VMware to another hypervisor may introduce significant technical and operational risks. IT teams must prepare for challenges that are not always apparent at the start of a migration. Price hikes, licensing changes and shifts in customer support have driven VMware customers to look for alternatives. Recent operational problems haven’t helped. Last year, VMware Workstation auto-updates failed due to a Broadcom URL redirect. In 2026, the migration continues. Gartner research VP Julia Palmer recently predicted that VMware would lose 35% of its workloads by 2028. Many of those workloads will shift to platforms such as Microsoft Hyper‑V, Azure Stack HCI, Nutanix AHV, Proxmox VE or KVM. Unfortunately, the journey comes with challenges. Switching hypervisors is a high-stakes infrastructure change. IT professionals need to focus on completing a successful migration with their data intact and available. Why hypervisor migration is technically risky It sounds simple: Export data, convert it to a new format and then import it into a new hypervisor. But that process is far riskier than it sounds. That’s because hypervisors don’t interoperate. Multiple technical variables increase the risk of failed or unstable migrations. Hypervisors differ in disk formats, hardware abstractions, driver stacks and networking models. Virtual hardware versions, storage controllers, chipset emulation and network virtualization layers don’t always translate cleanly. Snapshots and templates behave differently. Even subtle configuration differences can create instability that only surfaces once workloads are under real production pressure. Migrating from VMware can increase cost, risk and operational drag, while limiting strategic options. Acronis Cyber Protect gives IT leaders control with a flexible, AI‑powered cyber protection platform that cuts migration time by up to 60% and keeps the business secure and responsive throughout change. See how Acronis delivers control Backup is essential to a successful hypervisor migration The most important prerequisite for any platform migration is not a conversion tool. It is verified, restorable backup. Organizations need to protect workloads with full-image, application-consistent backups that IT pros can restore not only to the same hypervisor but to dissimilar hardware or an entirely different virtualization platform. IT teams need to perform recovery drills before they start migration, not just after cutover. A platform-agnostic backup architecture provides a necessary safety net. It enables restoration from the source environment to the destination environment, and it allows rapid reversion to the original platform if compatibility or performance issues arise. The bottom line is that data remains safe and accessible. Any-to-any hypervisor recovery — restoration from physical, virtual or cloud environments to any other destination — reduces migration risk and has the added advantage of reducing long-term vendor lock-in. How to avoid three risks most teams underestimate during migration Even the most carefully planned and executed migrations can fail for predictable reasons. 1. Teams often underestimate planned downtime Too many teams plan for an ideal level of downtime as opposed to a worst-case scenario. Unfortunately, migrations frequently stretch beyond maintenance windows. If a window closes when systems are not stable, organizations can suffer missed transactions, stalled operations, SLA violations and reputational damage. That’s why migration planning must include a formal business continuity strategy, Ask in advance: How long can each workload realistically be offline? What happens if rollback is required? Who makes the go or no-go decision? What is the communication plan if restoration time exceeds expectations? Backup and recovery are critical. The ability to quickly restore workloads to their original platform can mean the difference between a short delay and a multi-day outage. 2. Backup and recovery gaps can plague transitions Migration creates a dangerous gray zone for backup and disaster recovery, with environments are often split between old and new platforms. That is when recoverability must be strongest. The time it takes to restore backups from either environment is critical. Common gaps appear when: Backup chains are broken during VM exports. Incremental backup jobs may fail after platform conversion. Application-consistent snapshots are not validated on the new hypervisor. DR replication targets are not synchronized during phased cutovers. Backup and recovery must function continuously throughout the migration. IT teams need to maintain parallel protection during overlap periods so that workloads are recoverable from both the legacy and target platforms until the transition is finished. 3. An expanding attack surface means backup images need protection Migration also expands your attack surface. With two hypervisor stacks running, complexity spikes. Backup repositories, an image-level backups in particular, can become high-value targets. If attackers compromise them during migration, your rollback and recovery options disappear. Immutability is essential during this phase. IT teams need to protect backup images against modification or deletion, even by privileged accounts. They need to tighten role-based access controls and limit administrative access. Equally important is adherence to the 3-2-1 principle: At least three copies of data, on two different media types, with one copy stored off-site or offline. During migration, that third copy becomes critical insurance. If both production and primary backup infrastructure are affected, an isolated copy preserves your recovery path. The value of a natively integrated platform Maintaining parallel protection is essential because it lowers operational risk. However, it also increases management complexity. Two hypervisor stacks, multiple storage systems and parallel protection policies must coexist without creating gaps. A unified cyber protection platform can simplify this process for IT teams. A unified cyber protection platform can reduce complexity by delivering consistent backup, recovery and security controls across physical servers, hypervisors and cloud workloads through a single point of control. Natively integrated protection and migration capabilities in Acronis Cyber Protect can reduce transition timelines while maintaining rollback readiness and continuous synchronization. Migration as a resilience opportunity The shift away from VMware has made one concept clear: Migration planning is a long-term competency, not a one-time project. Teams that succeed treat hypervisor transitions as resilience exercises. They validate backups in advance, ensure cross-platform recovery capability, maintain rollback paths, harden backup storage against ransomware and verify data integrity after cutover. With these safeguards in place, migration becomes more predictable and significantly more likely to succeed. VMware migrations don’t have to be slow, risky or disruptive. With Acronis Cyber Protect, IT teams gain a flexible, responsive platform that accelerates migration while delivering AI‑powered security, backup and recovery in one natively integrated solution. If you’re planning a move away from VMware, see how Acronis helps organizations migrate faster and stay protected at every step. Sponsored and written by Acronis.
bleepingcomputer.comMar 13, 2026extracted
⚡ Weekly Recap: Qualcomm 0-Day, iOS Exploit Chains, AirSnitch Attack & Vibe-Coded Malware
Another week in cybersecurity. Another week of "you've got to be kidding me." Attackers were busy. Defenders were busy. And somewhere in the middle, a whole lot of people had a very bad Monday morning. That's kind of just how it goes now. The good news? There were some actual wins this week. Real ones. The kind where the good guys showed up, did the work, and made a dent. It doesn't always happen, so when it does, it's worth noting. The bad news? For every win, there's a fresh headache waiting right behind it. New tricks, old tricks dressed up in new clothes, and a few things that'll make you want to go touch grass and never log back in. But you will. We all do. So here's everything that mattered this week — the wins, the warnings, and the stuff you really shouldn't ignore. ⚡ Threat of the Week Tycoon 2FA and LeakBase Operations Dismantled — The infrastructure hosting the Tycoon2FA service, which Europol said was among the largest adversary-in-the-middle (AitM) phishing operations worldwide, has been dismantled by a coalition of security companies and law enforcement agencies. "Taking down infrastructure associated with Tycoon 2FA and identifying the individual allegedly responsible for creating this prolific hacking tool will have a significant impact on overall MFA credential phishing, and hopefully strike a blow to the world's most prolific AitM phishing-as-a-service," Proofpoint said in a statement shared with The Hacker News. Phishing kits and PhaaS platforms have become an Achilles' heel in recent years, streamlining and democratizing phishing attacks for less technically savvy hackers by providing them with a suite of tools to create convincing emails and phishing pages that unsuspecting victims will engage with. For a relatively modest fee, aspiring cybercriminals can subscribe to these services and carry out phishing attacks at scale. In a similar development, authorities also took down LeakBase, one of the world's largest online forums for cybercriminals to buy and sell stolen data and cybercrime tools. While the disruption is a positive development, it's known that such takedowns typically create only short-term disruptions, as the ecosystem adapts by migrating to other forums or more resilient distribution channels, like Telegram. Shadow AI Is EVERYWHERE. Here's How You Can Find and Secure It Shadow AI is quietly accessing sensitive data across your SaaS environment. Learn how to close AI blind spots and get ahead of data exposure risks with this new guide. Get Answers Now ➝ 🔔 Top News Anthropic Finds 22 Firefox Vulnerabilities in Firefox — Anthropic said it discovered 22 new security vulnerabilities in the Firefox web browser using its Claude Opus 4.6 large language model (LLM)as part of a security partnership with Mozilla. Of these, 14 have been classified as high, seven have been classified as moderate, and one has been rated low in severity. The issues were addressed in Firefox 148, released late last month. The vulnerabilities were identified over a two-week period in January 2026. The company noted that the cost of identifying vulnerabilities is cheaper than creating an exploit for them, and the model is better at finding issues than at exploiting them. Qualcomm Flaw Exploited in the Wild — A high-severity security flaw impacting Qualcomm chips used in Android devices has been exploited in the wild. The vulnerability in question is CVE-2026-21385 (CVSS score: 7.8), a buffer over-read in the Graphics component that could result in memory corruption and arbitrary code execution. There are currently no details on how the vulnerability is being exploited in the wild. However, Google acknowledged in its monthly Android security bulletin that "there are indications that CVE-2026-21385 may be under limited, targeted exploitation." Coruna iOS Exploit Kit Uses 23 Exploits Against Older iOS Devices — Google disclosed details of a new and powerful exploit kit dubbed Coruna (aka CryptoWaters) targeting Apple iPhone models running iOS versions between 13.0 and 17.2.1. The exploit kit featured five full iOS exploit chains and a total of 23 exploits, the company said. What makes it different is that it started with a commercial surveillance vendor in February 2025, got picked up by what seems like a Russian espionage group targeting Ukrainians in July 2025, and ended up in the hands of financially motivated attackers in China going after crypto wallets by the end of the year. Coruna began its life as a surveillance exploit kit, but by the time it reached the Chinese cybercrime gang, it was heavily focused on financial theft. It's not known how the exploit kit got passed between multiple threat actors of varied motivations. This has raised the possibility of a secondhand market where it's resold to other threat actors, who end up repurposing them for their own objectives. Transparent Tribe Unleases Vibeware Against Indian Entities — In a new attack campaign detected by Bitdefender, the Pakistan-aligned threat actor known as Transparent Tribe has leveraged artificial intelligence (AI)-powered coding tools to vibe-code malware and use them to target the Indian government and its embassies in multiple foreign countries. These tools are written in niche programming languages like Nim, Zig, and Crystal so as to evade detection. "Rather than a breakthrough in technical sophistication, we are seeing a transition toward AI-assisted malware industrialization that allows the actor to flood target environments with disposable, polyglot binaries," the company said. Iranian Hackers Target U.S. Entities Amid Conflict — The Iranian hacking group tracked as MuddyWater (aka Seedworm) targeted several U.S. companies, including banks, airports, non-profit, and the Israeli arm of a software company, as part of a campaign that began in early February 2026, and continued after the joint U.S.-Israel military strikes on Iran towards the end of the month. The development comes against the backdrop of hacktivist-fueled cyber attacks, with wiper campaigns targeting Israeli energy, financial, government, and utilities sectors. "The trajectory is clear: what began as nation-state-level ICS capability in 2012 [with Shamoon wiper] has become, by 2026, something any motivated actor can attempt with free tools and an internet connection," CloudSEK said in a report last week. "The technical barrier has collapsed. The threat pool has expanded. And the US attack surface has never been larger." Another targeted campaign has distributed a trojanized version of the Red Alert rocket warning Android app to Israeli users via SMS messages impersonating official Home Front Command communications. Once installed, the malware monitors and abuses the granted permissions to collect sensitive data, including SMS messages, contacts, location data, device accounts, and installed applications. The campaign is believed to be the work of a Hamas-affiliated actor known as Arid Viper. There are currently no details available on the scope of the campaign and whether any of the infections were successful. Acronis said it highlights how trusted emergency services can be weaponized during periods of geopolitical tension using social engineering. ️🔥 Trending CVEs New vulnerabilities show up every week, and the window between disclosure and exploitation keeps getting shorter. The flaws below are this week's most critical — high-severity, widely used software, or already drawing attention from the security community. Check these first, patch what applies, and don't wait on the ones marked urgent — CVE-2026-2796 (Mozilla Firefox), CVE-2026-21385 (Qualcomm), CVE-2026-2256 (MS-Agent), CVE-2026-26198 (Ormar), CVE-2026-27966 (langflow), CVE-2025–64712 (Unstructured.io), CVE-2026-24009 (Docling), CVE-2026-23600 (HPE AutoPass License Server), CVE-2026-27636, CVE-2026-28289 (aka Mail2Shell) (FreeScout), CVE-2025-67736 (FreePBX), CVE-2025-34288 (Nagios XI), CVE-2025-14500 (IceWarp), CVE-2026-20079 (Cisco Secure Firewall Management Center), CVE-2025-13476 (Viber app for Android), CVE-2026-3336, CVE-2026-3337, CVE-2026-3338 (Amazon AWS-LC), CVE-2026-25611 (MongoDB), CVE-2026-3536, CVE-2026-3537, CVE-2026-3538 (Google Chrome), CVE-2026-27970 (Angular), CVE-2026-29058 (AVideo) a privilege escalation flaw in IPVanish VPN for macOS (no CVE), and and a remote code execution vulnerability in Ghost CMS (no CVE). 🎥 Cybersecurity Webinars Automating Real-World Security Testing to Prove What Actually Works → Running a security test once a year and hoping for the best? That's not a strategy anymore. This webinar shows you how to continuously test your defenses using real attack techniques — so you actually know what holds up and what quietly breaks when no one's looking. When AI Agents Become Your New Attack Surface → AI tools aren't just answering questions anymore — they're browsing the web, hitting APIs, and touching your internal systems. That changes everything about how you think about risk. This webinar breaks down what that means for security, and what you actually need to do before something goes wrong. 📰 Around the Cyber World New AirSnitch Attack Shows Wi-Fi Client Isolation May Not Be Enough — A group of academics has developed a new attack called AirSnitch that breaks the encryption that separates Wi-Fi clients. Xin'an Zhou, the lead author of the research paper, told Ars Technica that AirSnitch bypasses worldwide Wi-Fi encryption and that it "might have the potential to enable advanced cyber attacks." The attack, at its core, leverages three weaknesses in client isolation implementations: (1) It abuses the group key(s) that are shared between all clients in the same Wi-Fi network, (2) It bypasses client isolation by tricking the gateway into forwarding packets to the victim at the IP layer by taking advantage of the fact that many networks only enforce client isolation at the MAC/Ethernet layer, and (3) It allows an adversary to manipulate internal switches and bridges to forward the victim's uplink and downlink traffic to the adversary. As a result, they enable the attacker to restore AitM capabilities even if client isolation protections exist. "We found that Wi-Fi client isolation can often be bypassed," Mathy Vanhoef said. "This allows an attacker who can connect to a network, either as a malicious insider or by connecting to a co-located open network, to attack others." Google Tracked 90 Exploited 0-Days in 2025 — Google said it tracked 90 zero-day vulnerabilities exploited in-the-wild in 2025, up from 78 in 2024 and down from 100 in 2023. "Both the raw number (43) and proportion (48%) of vulnerabilities impacting enterprise technologies reached all-time highs, accounting for almost 50% of total zero-days exploited in 2025," the company said. Of these, vulnerabilities in security and networking appliances made up about half (21) of the enterprise-related zero-days in 2025. Mobile zero-days rebounded from nine in 2024 to 15 in 2025, with commercial surveillance vendors (15, plus likely another three) leading the charge in exploiting zero-day vulnerabilities than state-sponsored cyber espionage groups (12) for the first time. The names of the commercial spyware companies were not disclosed. Microsoft had the largest number of actively exploited flaws at 25, followed by Google (11), Apple (8), Cisco (4), Fortinet (4), Ivanti (3), and Broadcom VMware (3). Memory safety issues accounted for 35% of all exploited zero-day vulnerabilities last year. Financially motivated threat groups, including ransomware gangs, also targeted enterprise technologies and accounted for nine zero-days in 2025, double the five attributed to them in 2024. Velvet Tempest Deploys ClickFix Attack — Velvet Tempest (aka DEV-0504) has been observed using a ClickFix lure, followed by hands-on-keyboard activity consistent with Termite ransomware tradecraft. According to a report by Deception.Pro, the attack used the social engineering technique to drop payloads like DonutLoader and CastleRAT. "Follow-on activity included Active Directory reconnaissance (domain trusts, server discovery, user listing) and attempted browser credential harvesting via a PowerShell script downloaded from 143.198.160[.]37," it said. "Telemetry and infrastructure in this chain align with a modern initial-access playbook: rapid staging, heavy use of living-off-the-land binaries (LOLBins), and long-lived command-and-control (C2) traffic that blends into normal browser noise." No ransomware was deployed in the attack that took place between February 3 and 16, 2026. Ghanaian National Pleads Guilty to Role in $100M Romance Scam — A Ghanaian national pleaded guilty to his role in a massive fraud ring that stole over $100 million from victims across the U.S. through business email compromise attacks and romance scams. 40-year-old Derrick Van Yeboah pleaded guilty to conspiracy to commit wire fraud and agreed to pay more than $10 million in restitution. "Van Yeboah personally perpetrated many of the romance scams by impersonating fake romantic partners in communications with victims," the U.S. Justice Department said. "Many of the conspiracy’s victims were vulnerable older men and women who were tricked into believing that they were in online romantic relationships with persons who were, in fact, fake identities assumed by members of the conspiracy." The conspirators, part of a criminal organization primarily based in Ghana, also committed business email compromises to deceive businesses into wiring funds to the enterprise. In total, the scheme stole and laundered more than $100 million from dozens of victims. After stealing the money, the fraud proceeds were laundered to West Africa. The defendant is scheduled to be sentenced in June 2026. Taiwan Indicts 62 People for Cyber Scams — Prosecutors in Taipei indicted 62 people and 13 companies for their involvement in cyber scam operations organized throughout Asia by the Prince Group. Chen Zhi, the founder of the Prince Group, was indicted by U.S. prosecutors last year on money laundering charges. Taipei prosecutors said those associated with Prince Group laundered at least $339 million into Taiwan and used the stolen funds to buy 24 properties, 35 vehicles, and other assets amounting to approximately $1.7 million. In all, authorities seized about $174 million in cash and assets. Prince Group "effectively controlled 250 offshore companies in 18 countries, holding 453 domestic and international financial accounts. By creating fictitious transaction contracts between these offshore companies, the group laundered money through foreign exchange channels," they added. Ransomware Actors Use AzCopy — Ransomware operators are ditching the usual tools like Rclone for Microsoft's own AzCopy, turning a trusted Azure utility into a stealthy data exfiltration mechanism and blending into normal activity. "The adoption of AzCopy and other familiar tools by attackers represents a similar logic to living-off-the-land in the final and most critical phase of an operation: exfiltrating data out of an organization," Varonis said. "Spinning up an Azure storage account takes minutes and requires only a credit card or compromised credentials. The attacker gains the benefits of Microsoft's global infrastructure while security teams struggle to distinguish between malicious uploads and legitimate traffic." Threat Actors Exploit Critical Flaw in WPEverest Plugin — Threat actors are exploiting a critical security flaw in WPEverest's User Registration & Membership plugin (CVE-2026-1492, CVSS score: 9.8) to create rogue administrator accounts. The vulnerability affects all versions of User Registration & Membership through 5.1.2. The issue has been addressed in version 5.1.3. Wordfence said the plugin is susceptible to improper privilege management, which enables the creation of bogus admin accounts. "This is due to the plugin accepting a user-supplied role during membership registration without properly enforcing a server-side allowlist," it said. "This makes it possible for unauthenticated attackers to create administrator accounts by supplying a role value during membership registration." MuddyWater Evolves Its Tactics — The Iranian hacking group known as MuddyWater has been observed leveraging Shodan and Nuclei to identify potential vulnerable targets, as well as using subfinder and ffuf to perform enumeration of target web applications. The findings come from an analysis of the threat actor's VPS server hosted in the Netherlands. MuddyWater is also said to be attempting to scan and/or exploit recently disclosed CVEs related to BeyondTrust (CVE-2026-1731), Ivanti (CVE-2026-1281), n8n (CVE-2025-68613), React (CVE-2025-55182), SmarterMail (CVE-2025-52691), Laravel Livewire (CVE-2025-54068), N-Central (CVE-2025-9316), Citrix NetScaler (CVE-2025-5777), Langflow (CVE-2025-34291), and Fortinet (CVE-2024-55591, CVE-2024-23113, CVE-2022-42475), along with SQL injection vulnerabilities in BaSalam and an unspecified Postgres development platform for initial access. One of the custom tools identified in the server is KeyC2, a command-and-control (C2) framework that allows operators to remotely control compromised Windows machines over a custom binary protocol on port 1269 from a Python script. Two C2 tools used by the adversary are PersianC2, which relies on standard HTTP polling to receive commands and files via JSON API endpoints, and ArenaC2, a Python-based program that operates over HTTP POST requests. Also detected is a PowerShell loader that leads to the execution of obfuscated Node.js payloads that appear similar to Tsundere Botnet. The infrastructure is assessed to have been used to target entities in Israel, Egypt, Jordan, the U.A.E., and the U.S. Some aspects of the activity overlap with Operation Olalampo. 2,622 Valid Certificates Exposed — A new study undertaken by Google and GitGuardian found over a million unique private keys leaked across GitHub and Docker Hub, out of which 40,000 were mapped to 140,000 real TLS certificates. "As of September 2025, 2,600 of these certificates were valid, with more than 900 actively protecting Fortune 500 companies, healthcare providers, and government agencies," GitGuardian said. "Our disclosure campaign achieved 97% remediation, but at the cost of 4,300 emails sent, 1,706 entities contacted, 9 bug bounty submissions, countless follow-ups, and days of meticulous attribution work employing multiple OSINT techniques. The high success rate masks the extraordinary effort required to protect organizations that fail to protect themselves." Context7 MCP Server Suffers from ContextCrush — A critical security flaw in Upstash's Context7 MCP Server, a widely used tool for delivering documentation to AI coding assistants, has been discovered. Dubbed ContextCrush, the vulnerability could allow attackers to inject malicious instructions into AI development tools through a trusted documentation channel. Noma Security, which disclosed details of the flaw, said it's rooted within the platform's "Custom Rules" feature, which allows library maintainers to provide AI-specific instructions to help assistants better interpret documentation. "Context7 operates both as the registry, where anyone can publish and manage library documentation, and as the trusted delivery mechanism that pushes content directly into the AI agent's context," security researcher Eli Ainhorn said. "The attacker never needs to reach the victim's machine. Instead, the attacker can plant malicious custom rules in Context7's registry, and Context7’s infrastructure delivers them through the MCP server to the AI agent running in the developer's IDE. As agents are execution machines and run whatever is loaded into their context, all the victim’s agent does is execute the attacker's instructions on the victim’s machine, using its own tool access (Bash, file read/write, network). In this scenario, the agent has no way to distinguish between legitimate documentation and attacker-controlled content because they arrive through the same trusted channel and from the same trusted source." German Court Sentences Key Person Behind Call Center Scam — A German court has sentenced a suspected central figure in the so-called Milton Group call-center fraud network to seven-and-a-half years in prison. Although the court did not publicly name the defendant, court records reviewed by the Organized Crime and Corruption Reporting Project (OCCRP) indicate the person convicted was Mikheil Biniashvili, a citizen of Georgia and Israel. In addition to the prison sentence, the court ordered the confiscation of €2.4 million ($2.8 million) linked to the operation. Between 2017 and 2019, the defendant ran a call-center operation in Albania that used trained agents to persuade victims to invest in fraudulent online trading schemes. The scheme caused losses of about €8 million ($9.4 million) to victims, mostly in German-speaking countries. The operation employed up to 600 people at its peak. Call-center agents allegedly posed as investment advisers, building trust with targets before persuading them to deposit funds into fake trading platforms controlled by the network by promising large investment returns. Biniashvili was arrested in Armenia in 2023 and extradited to Germany in 2024. Multiple Flaws in Avira Internet Security — Three vulnerabilities have been disclosed in Avira Internet Security that could allow for arbitrary file deletion (CVE-2026-27748) in the Software Updater component, an insecure deserialization (CVE-2026-27749) in System Speedup, and an arbitrary folder deletion over TOCTOU (CVE-2026-27748) in the Optimizer. "The file delete primitive is useful on its own," Quarkslab said. "The other two both result in Local Privilege Escalation to SYSTEM." Russian Ransomware Operator Pleads Guilty in U.S. — Evgenii Ptitsyn, a 43-year-old Russian national, has pleaded guilty in a U.S. court to running the Phobos ransomware outfit that targeted more than 1,000 victims globally and extorted ransom payments worth over $39 million. Ptitsyn was extradited from South Korea in November 2024. "Beginning in at least November 2020, Ptitsyn and others conspired to engage in an international computer hacking and extortion scheme that victimized public and private entities through the deployment of Phobos ransomware," the Justice Department said. "As part of the scheme, Ptitsyn and his co-conspirators developed and offered access to Phobos ransomware to other criminals or 'affiliates' to encrypt victims' data and extort ransom payments from victims. The administrators operated a darknet website to coordinate the sale and distribution of Phobos ransomware to co-conspirators and used online monikers to advertise their services on criminal forums and messaging platforms." Ptitsyn faces a maximum penalty of 20 years in prison for wire fraud charges. Fake Google Security Check Leads to RAT — A bogus website resembling the Google Account security page is being used to deliver a Progressive Web App (PWA) capable of harvesting one-time passcodes and cryptocurrency wallet addresses, and proxying attacker traffic through victims' browsers. "Disguised as a routine security checkup, it walks victims through a four-step flow that grants the attacker push notification access, the device's contact list, real-time GPS location, and clipboard contents – all without installing a traditional app," Malwarebytes said. "For victims who follow every prompt, the site also delivers an Android companion package introducing a native implant that includes a custom keyboard (enabling keystroke capture), accessibility-based screen reading capabilities, and permissions consistent with call log access and microphone recording." Phishing Campaign Abuses Google Infrastructure — A new email phishing campaign is leveraging legitimate Google infrastructure to bypass standard security filters. The activity uses Google Cloud Storage (GCS) to host initial phishing URLs that, when clicked, redirect unsuspecting users to a malicious site designed to capture their financial information or deploy malware. "By hosting the initial link on Google's servers, the attackers ensure the email passes authentication checks like SPF and DKIM," security researcher Anurag Gawande said. Client-Side Injection Conducts Ad Fraud — A new malicious client-side injection originating from a malicious browser extension impersonating Microsoft Clarity has been found to overwrite referral tokens to redirect affiliate revenue to unknown threat actors. "A browser extension is injecting obfuscated JavaScript from msclairty[.]com, a typosquatted domain impersonating Microsoft Clarity," c/side's Simon Wijckmans said. "The domain is not serving analytics. It is delivering an obfuscated JavaScript payload that performs affiliate cookie stuffing, tracking cookie deletion, and Fetch API hijacking inside the visitor's browser. This prevents a competing tracking service from recording the real traffic source. The attacker does not just want credit for the visit. They actively block other trackers from capturing any attribution data that would conflict with their fraudulent cookie." The script has affected sites across multiple unrelated sectors, including transportation, SaaS platforms, sports management, and government payment portals. Impacted visitors primarily span Chrome versions 132, 138, and 145, and originate from U.S.-based IP addresses on the East and West coasts. Illinois Man Charged with Hacking Snapchat Accounts to Steal Nudes — U.S. prosecutors have charged a 26-year-old Illinois man, Kyle Svara, with conducting a phishing operation that made it possible to break into the Snapchat accounts of approximately 570 women to steal private photos and sell them online. "From at least May 2020 to February 2021, Svara used social engineering and other resources to collect his targets' emails, phone numbers, and/or Snapchat usernames," the Justice Department said. "He then used those means of identification to access his targets' Snapchat accounts, which prompted Snap Inc. to send account security codes to those women. Using anonymized phone numbers, Svara posed as a representative of Snap Inc. and sent more than 4,500 text messages to hundreds of women, requesting those Snapchat access codes." Svara is alleged to have accessed the Snapchat accounts of at least 59 women without permission to download their nude or semi-nude images and sell them on internet forums. Meta Sued Over AI Smart Glasses' Privacy Concerns — Meta is facing a new class action lawsuit over its AI-powered Ray-Ban Meta glasses, following a report from Swedish newspapers Svenska Dagbladet and Goteborgs-Posten that employees at Kenya-based subcontractor Sama are reviewing intimate, personal footage filmed from customers' glasses. Meta said subcontracted workers might sometimes review content captured by its AI smart glasses for the purpose of improving the "experience," as stated in its Privacy Policy. It also claimed that data is filtered to protect people's privacy. But the investigation found that this step did not always consistently work. "Unless users choose to share media they've captured with Meta or others, that media stays on the user's device," Meta told BBC News. "When people share content with Meta AI, we sometimes use contractors to review this data for the purpose of improving people's experience, as many other companies do." Total Ransomware Payments Stagnated in 2025 — The total ransomware payments in 2025 stagnated, even if the number of attacks increased. According to blockchain analysis firm Chainalysis, total on-chain ransomware payments fell by approximately 8% to $820 million in 2025, even as claimed attacks rose 50%. "While aggregate revenue stagnated, the median ransom payment grew 368% year-over-year to nearly $60,000," the company said. "The 2025 total is likely to approach or exceed $900 million as we attribute more events and payments, just as our 2024 total grew from our initial $813 million estimate this time last year." The decline in payment rates from 63% in 2024 to just 29% last year indicates that fewer victims are yielding to attackers' ransom demands, it added. The development comes amid increased fragmentation of the ransomware ecosystem and threat actors shifting towards more stealthy methods, such as defense evasion and persistence techniques, to prioritize data theft and prolonged, low-noise access. Mobile Blockchain Wallet Found Vulnerable to Severe Flaws — An unnamed mobile blockchain wallet app for Android has been found susceptible to two independent severe vulnerabilities, allowing untrusted deep links to trigger sensitive wallet flows and trick users into approving phishing-driven transactions, as well as retain cryptographic private keys from the device despite deleting an account. This meant that an attacker with later device access could re-import the account using its public address and regain full signing authority without re-entering the keys. According to LucidBit Labs, the vulnerabilities have been patched by the developer. "The main strength of crypto wallets lies in their cryptographic foundations," security researcher Assaf Morag said. "However, when these wallets are implemented as user-facing applications, the overall orchestration of the system becomes just as critical as the cryptography itself. As the saying goes, a system’s security posture is defined by its weakest link. In this case, the two vulnerabilities demonstrate how flaws at the application layer can undermine the entire security model, despite the strength of the underlying cryptography." Kubernetes RCE Via Nodes/Proxy GET Permission — New research has identified an authorization bypass in Kubernetes Role-based access control (RBAC) that allows a service account with nodes/proxy GET permissions to execute commands in any Pod in the cluster. The issue exploits a bug in how Kubernetes API servers handle WebSocket connections. "Nodes/proxy GET allows command execution when using a connection protocol such as WebSockets," security researcher Graham Helton said. "This is due to the Kubelet making authorization decisions based on the initial WebSocket handshake's request without verifying CREATE permissions are present for the Kubelet's /exec endpoint, requiring different permissions depending solely on the connection protocol. The result is anyone with access to a service account assigned nodes/proxy GET that can reach a Node's Kubelet on port 10250 can send information to the /exec endpoint, executing commands in any Pod, including privileged system Pods, potentially leading to a full cluster compromise." The Kubernetes project has declined to address the issue, stating its intended behavior. However, it's expected to release Fine-Grained Kubelet API Authorization (KEP-2862) next month to address the attack. "A targeted patch would require coordinated changes across multiple components with special-case logic," Edera said. "This is the kind of complexity that could lead to future vulnerabilities. Once KEP-2862 reaches GA and sees adoption, nodes/proxy can be deprecated for monitoring use cases." Other Key Stories on the Radar — The Israeli government is working on the country's first cybersecurity law, the U.S. National Security Agency (NSA) published Zero Trust Implementation Guidelines (ZIGs) to help organizations safeguard sensitive data, systems, and services against sophisticated cyber threats, Google Project Zero found multiple vulnerabilities that could be used to bypass a new Windows 11 feature called Administrator Protection and obtain admin privileges, threat actors are continuing to abuse Microsoft Teams functionality by leveraging guest invitations and phishing-themed team names to impersonate billing and subscription notifications, and a loader named PhantomVAI has been used in the wild over the past year to deploy other payloads, such as Remcos RAT, XWorm, AsyncRAT, DarkCloud, and SmokeLoader. 🔧 Cybersecurity Tools DetectFlow → It is an open-source detection pipeline from SOC Prime that matches streaming log events against Sigma rules in real time — before they ever reach your SIEM. Instead of relying on your SIEM to do the heavy lifting, it tags and enriches events in-flight using Apache Kafka and Flink, then passes the results downstream to wherever you need them. Built on 11 years of detection intelligence, it's designed for teams who want faster detection, more rule coverage, and less dependency on SIEM-imposed limits. ADTrapper → It is an open-source platform that analyzes Windows Active Directory authentication logs and flags threats using 54+ built-in detection rules — covering everything from brute force to AD CS attacks. It runs in Docker, deploys with one command, and supports SharpHound data for deeper AD analysis. Disclaimer: For research and educational use only. Not security-audited. Review all code before use, test in isolated environments, and ensure compliance with applicable laws. Conclusion That's your week. A lot happened. Some of it was bad, some of it was worse, and a little bit of it was actually good. The scoreboard is messy, like it always is. Same time next week — and if history is any guide, we'll have plenty more to talk about. Stay patched, stay skeptical, and maybe don't click that link.
thehackernews.comMar 9, 2026extracted
Week in review: Firmware-level Android backdoor found on tablets, Dell zero-day exploited since 2024
Week in review: Firmware-level Android backdoor found on tablets, Dell zero-day exploited since 2024 Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Security at AI speed: The new CISO reality The CISO role has changed significantly over the past decade, but according to John White, EMEA Field CISO, Torq, the most disruptive shift is accountability driven by agentic AI. In this Help Net Security interview, White explains how security leaders must design and govern hybrid workforces where humans and AI agents operate side by side, making decisions and acting at scale. He notes that automation is moving beyond simple task execution into real-time insight and response. REMnux v8 brings AI integration to the Linux malware analysis toolkit REMnux, a specialized Linux distribution for malware analysis, has released version 8 with a rebuilt platform based on Ubuntu 24.04 and a new capability aimed at connecting AI agents directly to its toolset. Your encrypted data is already being stolen Quantum computing is often treated as a distant, theoretical cybersecurity issue. According to Ronit Ghose, Global Head, Future of Finance of Citi Institute, that mindset is already putting financial institutions at risk. The biggest misconception, he says, is that quantum threats begin on a single future Q-day, when quantum machines suddenly crack encryption. In reality, adversaries can harvest encrypted data today and decrypt it later, creating long-term exposure for banks handling sensitive identity and transaction data. SecureClaw: Dual stack open-source security plugin and skill for OpenClaw SecureClaw is an open-source project that adds security auditing and rule-based controls to OpenClaw agent environments. The tool is published by Adversa AI and is designed to work with OpenClaw and related agents such as Moltbot and Clawdbot. Everyone uses open source, but patching still moves too slowly Enterprise security teams rely on open source across infrastructure, development pipelines, and production applications, even when they do not track it as a separate category of technology. Open source has become a default building block in many environments, and the operational risks now look like standard enterprise security problems: patch delays, version sprawl, and aging platforms that stay online longer than planned. The defense industrial base is a prime target for cyber disruption Cyber threats against the defense industrial base (DIB) are intensifying, with adversaries shifting from traditional espionage toward operations designed to disrupt production capacity and compromise supply chains. In this Help Net Security interview, Luke McNamara, Deputy Chief Analyst, Google Threat Intelligence Group, explains how attackers target the broader defense ecosystem and why identity has become the new security boundary. One stolen credential is all it takes to compromise everything Attackers often gain access through routine workflows like email logins, browser sessions, and SaaS integrations. A single stolen credential can give them a quick path to move across systems when access permissions are broad and visibility is fragmented. That pattern appears across more than 750 incident response engagements covered in Unit 42’s Global Incident Response Report 2026. The CISO view of fraud risk across the retail payment ecosystem In this Help Net Security interview, Paul Suarez, VP and CISO at Casey’s, explains how his team manages patching and upgrades for fuel payment systems with long hardware lifecycles. He also discusses risks tied to QR code payments and outlines why loyalty abuse can be hard to spot. Suarez shares how Casey’s monitors payment systems across stores, corporate networks, and third-party processors. Google patches Chrome vulnerability with in-the-wild exploit (CVE-2026-2441) Google released a security update for Chrome to address a high-severity zero‑day vulnerability (CVE-2026-2441) on Friday. CVE-2026-2441 is a use-after-free bug in the CSS processing component of Google Chrome, which allows a remote attacker “to execute arbitrary code inside a sandbox via a crafted HTML page.” OpenClaw creator Peter Steinberger joins OpenAI Peter Steinberger, the Austrian software developer who vibe coded the popular OpenClaw autonomous AI agent, has joined OpenAI. The reason why Steinberger chose OpenAI to achieve this goal is, professedly, his lack of interest in building a company and his wish to “change the world” – and do it quickly. Firmware-level Android backdoor found on tablets from multiple manufacturers A new Android backdoor embedded directly in device firmware can quietly take control of apps and harvest data, Kaspersky researchers found. The malware, named Keenadu, was discovered during an investigation into earlier Android threats and appears to have been inserted during the firmware build process, not after devices reached users.  Design weaknesses in major password managers enable vault attacks, researchers say Can cloud-based password managers that claim “zero-knowledge encryption” keep users’ passwords safe even if their encrypted-vault servers are compromised? Researchers at ETH Zurich and Università della Svizzera italiana set out to answer that question, and the answer is (unfortunately) no. Notepad++ secures update channel in wake of supply chain compromise Notepad++, the popular text and source code editor for Windows whose update mechanism was hijacked last year, has been updated to prevent similar attacks in the future. The hijacking of the update mechanism was confirmed earlier this month by Notepad++ maintainer Don Ho. Scammers exploit trust in Atlassian Jira to target organizations Threat actors have leveraged legitimate email notification feature of Atlassian Jira to deliver localized scam emails at scale. From late December 2025 through late January 2026, victims were targeted with spam emails from legitimate-looking Atlassian Jira Cloud addresses. China-linked hackers exploited Dell zero-day since 2024 (CVE-2026-22769) A suspected China-linked cyberespionage group has been covertly exploiting a critical zero-day flaw (CVE-2026-22769) in Dell’s RecoverPoint for Virtual Machines software since at least mid-2024, according to new research from Google’s threat intelligence team and Mandiant. The attackers deployed stealthy backdoors (BRICKSTORM and GRIMBOLT), a webshell (SLAYSTYLE) and maintained long-term access inside targeted networks. Bug in widely used VoIP phones allows stealthy network footholds, call interception (CVE-2026-2329) A critical security vulnerability (CVE-2026-2329) in Grandstream VoIP phones could let hackers remotely take full control of the devices and even intercept calls, Rapid7 researchers discovered. Data on 1.2 million French bank accounts accessed in registry breach In late January 2026, a malicious intruder accessed France’s national bank account registry, FICOBA, enabling them to view information tied to 1.2 million accounts, the Ministry of the Economy and Finance disclosed on Wednesday. TV5 Monde reported that the perpetrator (or perpetrators) obtained login credentials belonging to a civil cervant authorized to use the database and then used those credentials to explore its contents. Microsoft reveals critical Windows Admin Center vulnerability (CVE-2026-26119) Microsoft has disclosed a privilege-escalation vulnerability in Windows Admin Center (WAC), a browser-based platform widely used by IT administrators and infrastructure teams to manage Windows clients, servers, clusters, Hyper-V hosts and virtual machines, as well as Active Directory-joined systems. Criminals create business website to sell RAT disguised as RMM tool A RAT masquerading as legitimate remote monitoring and management (RMM) software is being sold to cybercriminals as a service, Proofpoint researchers recently discovered. The fake RMM tool, called TrustConnect, was being marketed via an LLM-created website parked on trustconnectsoftware[.]com, supposedly belonging to “TrustConnect Software PTY LTD”. LockBit 5.0 ransomware expands its reach across Windows, Linux, and ESXi The Acronis Threat Research Unit (TRU) has identified a new and significantly enhanced version of the LockBit ransomware, LockBit 5.0, currently being deployed in active campaigns. The latest variant demonstrates expanded cross-platform capabilities, enabling attackers to target Windows, Linux, and VMware ESXi systems within a single coordinated attack. Don’t panic over CISA’s KEV list, use it smarter In this Help Net Security video, Tod Beardsley, VP of Security Research at runZero, explains what CISA’s Known Exploited Vulnerabilities (KEV) Catalog is and how security teams should use it. He shares his perspective as a former section chief for KEV at CISA and breaks down common misunderstandings about what the list represents. Cybersecurity in cross-border logistics operations In this Help Net Security video, Dieter Van Putte, CTO at Landmark Global, discusses how cybersecurity has become a core part of global supply chain operations. He explains that logistics is now also about data moving between carriers, customs authorities, warehouses, brokers, and customers. That constant flow increases risk and expands the attack surface. In GitHub’s advisory pipeline, some advisories move faster than others GitHub Security Advisories are used to distribute vulnerability information in open-source projects and security tools. A new study finds that only a portion of those advisories ever pass through GitHub’s formal review process. Android 17 beta brings privacy, security, and performance changes Google has released the first beta of Android 17, giving developers an early view of changes to core app behavior, platform tooling, performance, media handling, and connectivity. The company plans to move quickly from this beta toward the Platform Stability milestone, targeted for March, where final APIs and behavior definitions for apps will be delivered. UK sets course for stricter AI chatbot regulation The UK government has announced immediate action to force AI chatbot providers to comply with laws requiring online platforms to protect children from illegal and harmful content. Providers that fail to meet these duties will face legal consequences. Microsoft equips CISOs and AI risk leaders with a new security tool Microsoft released Security Dashboard for AI in public preview for enterprise environments. The dashboard aggregates posture and real-time risk signals from Microsoft Defender, Microsoft Entra, and Microsoft Purview into a single view within security tools. Phobos ransomware affiliate arrested in Poland Officers from Poland’s Central Bureau for Combating Cybercrime (CBZC) detained a 47-year-old man suspected of creating, acquiring, and sharing computer programs used to unlawfully obtain information stored in computer systems. He faces a potential prison sentence of up to five years. Pressure builds on Grok AI, Ireland launches investigation The Irish Data Protection Commission (DPC) opened an investigation into X over concerns that its Grok AI chatbot was used to generate sexualized deepfakes. The investigation focuses on the apparent creation and publication of potentially harmful, non-consensual intimate or sexualised images on X using generative AI tools linked to the platform’s Grok LLM. Claude Sonnet 4.6 launches with improved coding and expanded developer tools Anthropic released Claude Sonnet 4.6, marking its second major AI launch in less than two weeks. According to Anthropic, Sonnet 4.6 delivers improved coding skills to more users. Tasks that once required an Opus-class model, including economically valuable office work, are handled by Sonnet 4.6. The model also brings improvements in computer use capabilities compared to earlier Sonnet versions. Attackers keep finding the same gaps in security programs Attackers keep getting in, often through the same predictable weak spots: identity systems, third-party access, and poorly secured perimeter devices. A new threat report from Barracuda based on Managed XDR telemetry from 2025 shows that many successful incidents still start with basic access and configuration failures, not advanced malware. Microsoft signals breakthrough in data storage that can last for generations Microsoft announced progress on Project Silica, its research initiative focused on developing durable, long-term quartz glass-based data storage technology. Rising global data volumes increase the need for storage that can last for generations. Researchers believe this technology could preserve information for up to 10,000 years. UK sounds alarm on rising cyber risks to businesses The UK government launched a national campaign urging businesses to strengthen basic cyber defenses. The initiative follows new figures highlighting the scale of the threat. Serious cyber incidents cost businesses an average of £195,000, with about half of small firms experiencing one in the past 12 months, officials say. Open-source benchmark EVMbench tests how well AI agents handle smart contract exploits EVMbench is a new open-source benchmark designed to test AI agents on practical smart contract security tasks. The benchmark was developed by OpenAI and Paradigm, and it focuses on real-world vulnerability patterns drawn from audited codebases and contest reports. Adidas investigates alleged data breach affecting 815,000 records Adidas confirmed it is investigating a possible data breach involving one of its third-party customer service providers. The company stated that there is no indication its IT infrastructure, e-commerce platforms, or consumer data were impacted by the incident. Poland restricts Chinese-made cars at protected military sites Poland’s military leadership has decided that cars manufactured in the People’s Republic of China will no longer cross the gates of sensitive military bases. The decision follows a risk analysis focused on the growing integration of digital systems in cars and the potential for uncontrolled acquisition and use of data by those systems. 651 arrested, $4.3 million recovered in African cybercrime sweep Operation Red Card 2.0, supported by INTERPOL and involving law enforcement agencies from 16 African countries, led to 651 arrests and the recovery of more than $4.3 million from online scams. Running from 8 December 2025 to 30 January 2026, the operation targeted networks behind high-yield investment fraud, mobile money scams and fraudulent loan applications that caused more than $45 million in losses. Man gets five years for aiding North Korean IT employment scam Ukrainian national Oleksandr Didenko, 29, was sentenced in U.S. District Court to 5 years in prison for an identity theft scheme that enabled North Korean workers to secure fraudulent employment. Ex-Google engineers charged with orchestrating high-tech secrets extraction A federal grand jury has indicted three Silicon Valley engineers on charges in a scheme to steal trade secrets from Google and other leading technology companies. MOS: Open-source modular OS for servers and homelabs A growing number of homelab builders and small server operators are testing an open source operating system that combines basic server management, storage control, and container services under a web interface. MOS is a free modular OS built on a Devuan base that provides a web UI and API for system monitoring, storage pooling, container orchestration, and virtualization. Apple privacy labels often don’t match what Chinese smart home apps do Smart home devices in many homes collect audio, video, and location data. The apps that control those devices often focus on the account owner, even when the technology also captures guests, neighbors, and other people who never agreed to be monitored. New research examined whether Chinese smart home apps provide privacy protections for these bystanders. Vim 9.2 adds scripting updates, diff improvements, and experimental Wayland support Vim 9.2 adds a range of incremental changes focused on scripting, usability, and cross-platform support. The update includes improvements to completion behavior, expanded Vim9 language features, and new options for diff mode. ChatGPT gets new security feature to fight prompt injection attacks OpenAI has introduced Lockdown Mode and Elevated Risk labels in ChatGPT to help users and organizations reduce the risk of prompt injection attacks and other advanced security threats, particularly when using features that interact with external systems. OT teams are losing the time advantage against industrial threat actors In many industrial environments, internet-facing gateways, remote access appliances, and boundary systems sit close enough to production networks that attackers can move from IT intrusion to operational disruption with limited resistance. Dragos’ 2026 OT/ICS Year in Review describes a threat landscape where adversaries are spending more time learning how physical processes work and less time treating OT access as a passive foothold. AWS coding agents gain new plugin support across development tools AI coding assistants have become a routine part of many development workflows, helping engineers write, test, and deploy code from IDEs or command line interfaces. One recent change in this ecosystem makes it possible for those agents to interact with AWS in a broader set of ways by adding a library of plugins that give agents specific AWS knowledge and actions. Microsoft Defender update lets SOC teams manage, vet response tools Microsoft introduced library management in Microsoft Defender to help security analysts working with live response manage scripts and tools they use to triage, investigate and remediate threats. The library management interface allows analysts to organize their investigation tools and manage everything without waiting for an active session. Consumers feel less judged by AI debt collectors Debt collection agencies are starting to use automated voice systems and AI-driven messaging to handle consumer calls. These systems help scale outreach, reduce call center staffing demands, and offer 24/7 service. A new study covering 11 European countries found that this shift changes how consumers emotionally experience debt collection, especially around stigma and empathy. Men sentenced to 8 years in $1.3 million computer intrusion and tax fraud scheme Matthew A. Akande, a Nigerian national, was sentenced by a U.S. District Court to eight years in prison, followed by three years of supervised release, for his role in a scheme to break into Massachusetts tax preparation firms’ computer networks and file fraudulent tax returns. The operation generated over $1.3 million in fraudulent tax refunds. Public mobile networks are being weaponized for combat drone operations On June 1, 2025, Ukraine launched drone strikes on five Russian airfields, damaging or destroying aircraft. More than 100 explosive drones used mobile networks to transmit data, receive instructions, and send images. Enea researchers analyzed the growing use of mobile-connected drones in conflict and the implications for national infrastructure. PromptSpy: First Android malware to use generative AI in its execution flow ESET researchers have discovered PromptSpy, the first known Android malware to abuse generative AI as part of its execution flow in order to achieve persistence. This marks the first time generative AI has been deployed in this way. Uptime Kuma: Open-source monitoring tool Service availability monitoring remains a daily operational requirement across IT teams, SaaS providers, and internal infrastructure groups. Many environments rely on automated checks and alerting to track outages, latency issues, and service degradation across web applications and network endpoints. Uptime Kuma is an open-source uptime monitoring project that supports this type of operational monitoring through a self-hosted deployment model. Quantum security is turning into a supply chain problem Supplier onboarding, invoice processing, and procurement platforms run on encrypted data flows that were built for long-term trust. In many organizations, that trust still depends on cryptographic standards like RSA and elliptic curve cryptography (ECC), even as security teams begin planning for a post-quantum world. A recent apexanalytix research report argues that supply chain leaders are already operating inside a quantum risk window, even though large-scale quantum computing remains years away. LINK“>Google cleans house, bans 80,000 developer accounts from the Play Store Google prevented more than 1.75 million policy-violating apps from being published on Google Play and banned over 80,000 developer accounts that attempted to publish harmful apps in 2025. Developer verification, mandatory pre-review checks, and testing requirements in the Google Play ecosystem have reduced entry points for bad actors. LLMs change their answers based on who’s asking AI chatbots may deliver unequal answers depending on who is asking the question. A new study from the MIT Center for Constructive Communication finds that LLMs provide less accurate information, increase refusal rates, and sometimes adopt a different tone when users appear less educated, less fluent in English, or from particular countries. Applying green energy tax policies to improve cybersecurity For years, governments have focused only on the stick of compliance when they could leverage the carrot of tax incentives. Theoretically, compliance fines and penalties should act as a deterrent that improves accountability and reduces data breaches. However, many vendors often assume compliance risk rather than securing data effectively. The era of the Digital Parasite: Why stealth has replaced ransomware For years, ransomware encryption signaled a breach. When systems locked up, defenders knew an attack had occurred. Data from Picus Security’s Red Report 2026 shows attackers shifting their strategy from disruption to persistence. Cybersecurity jobs available right now: February 17, 2026 We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now. New infosec products of the week: February 20, 2026 Here’s a look at the most interesting products from the past week, featuring releases from Compliance Scorecard, Impart Security, Redpanda, and Virtana.
helpnetsecurity.comFeb 22, 2026extracted
ThreatsDay Bulletin: OpenSSL RCE, Foxit 0-Days, Copilot Leak, AI Password Flaws & 20+ Stories
The cyber threat space doesn’t pause, and this week makes that clear. New risks, new tactics, and new security gaps are showing up across platforms, tools, and industries — often all at the same time. Some developments are headline-level. Others sit in the background but carry long-term impact. Together, they shape how defenders need to think about exposure, response, and preparedness right now. This edition of ThreatsDay Bulletin brings those signals into one place. Scan through the roundup for quick, clear updates on what’s unfolding across the cybersecurity and hacking landscape. Privacy model hardeningGoogle announced the first beta version of Android 17, with two privacy and security enhancements: the deprecation of Cleartext Traffic Attribute and support for HPKE Hybrid Cryptography to enable secure communication using a combination of public key and symmetric encryption (AEAD). "If your app targets (Android 17) or higher and relies on usesCleartextTraffic='true' without a corresponding Network Security Configuration, it will default to disallowing cleartext traffic," Google said. "You are encouraged to migrate to Network Security Configuration files for granular control." RaaS expands cross-platform reachA new analysis of the LockBit 5.0 ransomware has revealed that the Windows version packs in various defense evasion and anti-analysis techniques, including packing, DLL unhooking, process hollowing, patching Event Tracing for Windows (ETW) functions, and log clearing. "What's notable among the multiple systems support is its proclaimed capability to 'work on all versions of Proxmox,'" Acronis said. "Proxmox is an open-source virtualization platform and is being adopted by enterprises as an alternative to commercial hypervisors, which makes it another prime target of ransomware attacks." The latest version also introduces dedicated builds tailored for enterprise environments, highlighting the continued evolution of ransomware-as-a-service (RaaS) operations. Mac users lured via nested obfuscationCybersecurity researchers have detailed a new evolution of the ClickFix social engineering tactic targeting macOS users. "Dubbed Matryoshka due to its nested obfuscation layers, this variant uses a fake installation/fix flow to trick victims into executing a malicious Terminal command," Intego said. "While the ClickFix tactic is not new, this campaign introduces stronger evasion techniques — including an in-memory, compressed wrapper and API-gated network communications — designed to hinder static analysis and automated sandboxes." The campaign primarily targets users attempting to visit software review sites, leveraging typosquatting in the URL name to redirect them to fake sites and activate the infection chain. Loader pipeline drives rapid domain takeoverAnother new ClickFix campaign detected in February 2026 has been observed delivering a malware-as-a-service (MaaS) loader known as Matanbuchus 3.0. Huntress, which dissected the attack chain, said the ultimate objective of the intrusion was to deploy ransomware or exfiltrate data based on the fact that the threat actor rapidly progressed from initial access to lateral movement to domain controllers via PsExec, rogue account creation, and Microsoft Defender exclusion staging. The attack also led to the deployment of a custom implant dubbed AstarionRAT that supports 24 commands to facilitate credential theft, SOCKS5 proxy, port scanning, reflective code loading, and shell execution. According to data from the cybersecurity company, ClickFix fueled 53% of all malware loader activity in 2025. Typosquat chain targets macOS credentialsIn yet another ClickFix campaign, threat actors are relying on the "reliable trick" to host malicious instructions on fake websites disguised as Homebrew ("homabrews[.]org") to trick users into pasting them on the Terminal app under the pretext of installing the macOS package manager. In the attack chain documented by Hunt.io, the commands in the typosquatted Homebrew domain are used to deliver a credential-harvesting loader and a second-stage macOS infostealer dubbed Cuckoo Stealer. "The injected installer looped on password prompts using 'dscl . -authonly,' ensuring the attacker obtained working credentials before deploying the second stage," Hunt.io said. "Cuckoo Stealer is a full-featured macOS infostealer and RAT: It establishes LaunchAgent persistence, removes quarantine attributes, and maintains encrypted HTTPS command-and-control communications. It collects browser credentials, session tokens, macOS Keychain data, Apple Notes, messaging sessions, VPN and FTP configurations, and over 20 cryptocurrency wallet applications." The use of "dscl . -authonly" has been previously observed in attacks deploying Atomic Stealer. Phobos affiliate detained in EuropeAuthorities from Poland's Central Bureau for Combating Cybercrime (CBZC) have detained a 47-year-old man over suspected ties to the Phobos ransomware group. He faces a potential prison sentence of up to five years. The CBZC said the "47-year-old used encrypted messaging to contact the Phobos criminal group, known for conducting ransomware attacks," adding the suspect's devices contained logins, passwords, credit card numbers, and server IP addresses that could have been used to launch "various attacks, including ransomware." The arrest is part of Europol's Operation Aether, which targets the 8Base ransomware group, believed to be linked to Phobos. It has been almost exactly a year since international law enforcement dismantled the 8Base crew. More than 1,000 organizations around the world have been targeted in Phobos ransomware attacks, and the cybercriminals are believed to have obtained over $16 million in ransom payments. Industrial ransomware surge acceleratesThere has been a sharp rise in the number of ransomware groups targeting industrial organizations as cybercriminals continue to exploit vulnerabilities in operational technology (OT) and industrial control systems (ICS), Dragos warned. A total of 119 ransomware groups targeting industrial organizations were tracked during 2025, a 49% increase from the 80 tracked in 2024. 2025 saw 3,300 industrial organizations around the world hit by ransomware, compared with 1693 in 2024. The most targeted sector was manufacturing, followed by transportation. In addition, a hacking group tracked as Pyroxene has been observed conducting "supply chain-leveraged attacks targeting defense, critical infrastructure, and industrial sectors, with operations expanding from the Middle East into North America and Western Europe." It often leverages initial access provided by PARISITE, to enable movement from IT into OT networks. Pyroxene overlaps with activity attributed to Imperial Kitten (aka APT35), a threat actor affiliated with the cyber arm of the Islamic Revolutionary Guard Corps (IRGC). Copilot bypassed DLP safeguardsMicrosoft confirmed a bug (CW1226324) that let Microsoft 365 Copilot summarize confidential emails from Sent Items and Drafts folders since January 21, 2026, without users' permission, bypassing data loss prevention (DLP) policies put in place to safeguard sensitive data. A fix was deployed by the company on February 3, 2026. However, the company did not disclose how many users or organizations were affected. "Users' email messages with a confidential label applied are being incorrectly processed by Microsoft 365 Copilot chat," Microsoft said. "The Microsoft 365 Copilot 'work tab' Chat is summarizing email messages even though these email messages have a sensitivity label applied, and a DLP policy is configured. A code issue is allowing items in the sent items and draft folders to be picked up by Copilot even though confidential labels are set in place." (Update: As of February 19, 2026, Microsoft said the root cause of this issue has been addressed for most customers, and that it's now "completing a longer-term, comprehensive sync to apply this fix retroactively to previously affected messages within the Sent and Draft folders to fully remediate the impact.") Jira trials weaponized for spamThreat actors are abusing the trust and reputation associated with Atlassian Jira Cloud and its connected email system to run automated spam campaigns and bypass traditional email security. To accomplish this, the operators created Atlassian Cloud trial accounts using randomized naming conventions, allowing them to generate disposable Jira Cloud instances at scale. "Emails were tailored to target specific language groups, targeting English, French, German, Italian, Portuguese, and Russian speakers — including highly skilled Russian professionals living abroad," Trend Micro said. "These campaigns not only distributed generic spam, but also specifically targeted sectors such as government and corporate entities." The attacks, active from late December 2025 through late January 2026, primarily targeted organizations using Atlassian Jira. The goal was to get recipients to open the emails and click on malicious links, which would initiate a redirect chain powered by the Keitaro Traffic Distribution System (TDS) and then finally lead them to pages peddling investment scams and online casino landing sites, suggesting that financial gain was likely the main objective. GitLab SSRF now federally mandated patchThe U.S. Cybersecurity and Infrastructure Security Agency (CISA), on February 18, 2026, added CVE-2021-22175 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patch by March 11, 2026. "GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the internal network for webhooks are enabled," CISA said. In March 2025, GreyNoise revealed that a cluster of about 400 IP addresses was actively exploiting multiple SSRF vulnerabilities, including CVE-2021-22175, to target susceptible instances in the U.S., Germany, Singapore, India, Lithuania, and Japan. Telegram bots fuel Fortune 500 phishingAn elusive, financially motivated threat actor dubbed GS7 has been targeting Fortune 500 companies in a new phishing campaign that leverages trusted company branding with lookalike websites aimed at harvesting credentials via Telegram bots. The campaign, codenamed Operation DoppelBrand, targets top financial institutions, including Wells Fargo, USAA, Navy Federal Credit Union, Fidelity Investments, and Citibank, as well as technology, healthcare, and telecommunications firms worldwide. Victims are lured through phishing emails and redirected to counterfeit pages where credentials are harvested and transmitted to Telegram bots controlled by the attacker. According to SOCRadar, the group itself, however, has a history stretching back to 2022. The threat actor is said to have registered more than 150 malicious domains in recent months using registrars such as NameCheap and OwnRegistrar, and routing traffic through Cloudflare to evade detection. GS7's end goals include not only harvesting credentials, but also downloading remote management and monitoring (RMM) tools like LogMeIn Resolve on victim systems to enable remote access or the deployment of malware. This has raised the possibility that the group may even act as an initial access broker (IAB), selling the access to ransomware groups or other affiliates. Remcos shifts to live C2 surveillancePhishing emails disguised as invoices, job offers, or government notices are being used to distribute a new variant of Remcos RAT to facilitate comprehensive surveillance and control over infected systems. "The latest Remcos variant has been observed exhibiting a significant change in behaviour compared to previous versions," Point Wild said. "Instead of stealing and storing data locally on the infected system, this variant establishes direct online command-and-control (C2) communication, enabling real-time access and control. In particular, it leverages the webcam to capture live video streams, allowing attackers to monitor targets remotely. This shift from local data exfiltration to live, online surveillance represents an evolution in Remcos’ capabilities, increasing the risk of immediate espionage and persistent monitoring." China-made vehicles restricted on basesPoland's Ministry of Defence has banned Chinese cars, and other motor vehicles equipped with technology to record position, images, or sound, from entering protected military facilities due to national security concerns and to "limit the risk of access to sensitive data." The ban also extends to connecting work phones to infotainment systems in motor vehicles produced in China. The ban isn't permanent: the Defence Ministry has called for the development of a vetting process to allow carmakers to undergo a security assessment that, if passed, can allow their vehicles to enter protected facilities. "Modern vehicles equipped with advanced communication systems and sensors can collect and transmit data, so their presence in protected zones requires appropriate safety regulations," the Polish Army said. The measures introduced are preventive and comply with the practices of NATO countries and other allies to ensure the highest standards of defense infrastructure protection. They are part of a wider process of adapting security procedures to the changing technological environment and current requirements for the protection of critical infrastructure." DKIM replay fuels invoice scamsBad actors are abusing legitimate invoices and dispute notifications from trusted vendors, such as PayPal, Apple, DocuSign, and Dropbox Sign (formerly HelloSign), to bypass email security controls. "These platforms often allow users to enter a 'seller name' or add a custom note when creating an invoice or notification," Casey-owned INKY said. "Attackers abuse this functionality by inserting scam instructions and a phone number into those user-controlled fields. They then send the resulting invoice or dispute notice to an email address they control, ensuring the malicious content is embedded in a legitimate, vendor-generated message." Because these emails originate from a legitimate company, they bypass checks like Domain-based Message Authentication, Reporting and Conformance (DMARC). As soon as the legitimate email is received, the attacker proceeds to forward it to the intended targets, allowing the "authentic looking" message to land in the victims' inboxes. The attack is known as a DKIM replay attack. RMM abuse surges 277%A new report from Huntress has revealed that the abuse of Remote Monitoring and Management (RMM) software surged 277% year-over-year, accounting for 24% of all observed incidents. Threat actors have begun to increasingly favor these tools because they are ubiquitous in enterprise environments, and the trusted nature of the RMM software allows malicious activity to blend in with legitimate usage, making detection harder for defenders. They also offer increased stealth, persistence, and operational efficiency. "As cybercriminals built entire playbooks around these legitimate, trusted tools to drop malware, steal credentials, and execute commands, the use of traditional hacking tools plummeted by 53%, while remote access trojans and malicious scripts dropped by 20% and 11.7%, respectively," the company said. Texas targets China-linked tech firmsTexas Attorney General Ken Paxton has sued TP-Link for "deceptively marketing its networking devices and allowing the Chinese Communist Party ('CCP') to access American consumers' devices in their homes." Paxton's lawsuit alleges that TP Link's products have been used by Chinese hacking groups to launch cyber attacks against the U.S. and that the company is subject to Chinese data laws, which it said require firms operating in the country to support its intelligence services by "divulging Americans' data." TP-Link told The Record that these allegations are "without merit" and that neither the Chinese government nor the Chinese Communist Party (CCP) exercises control over the company, its products, or user data. It also added that all U.S. user data is stored on domestic Amazon Web Services (AWS) servers. In a second lawsuit, Paxton also accused Anzu Robotics of misleading Texas consumers about the "origin, data practices, and security risks of its drones." Paxton's office described the company's products as "21st century Trojan horse linked to the CCP." MetaMask backdoor expands DPRK campaignThe North Korea-linked campaign known as Contagious Interview is designed to target IT professionals working in cryptocurrency, Web3, and artificial intelligence sectors to steal sensitive data and financial information using malware such as BeaverTail and InvisibleFerret. However, recent iterations of the campaign have expanded their data theft capabilities by tampering with the MetaMask wallet extension (if it's installed) through a lightweight JavaScript backdoor that shares the same functionality as InvisibleFerret, according to security researcher Seongsu Park. "Through the backdoor, attackers instruct the infected system to download and install a fake version of the popular MetaMask cryptocurrency wallet extension, complete with a dynamically generated configuration file that makes it appear legitimate," Park said. "Once installed, the compromised MetaMask extension silently captures the victim's wallet unlock password and transmits it to the attackers’ command-and-control server, giving them complete access to cryptocurrency funds." Booking.com kits hit hotels, guestsBridewell has warned of a resurgence in malicious activity targeting the hotel and retail sector. "The primary motivation driving this incident is financial fraud, targeting two victims: hotel businesses and hotel customers, in sequential order," security researcher Joshua Penny said. "The threat actor(s) utilize impersonation of the Booking.com platform through two distinct phishing kits dedicated to harvesting credentials and banking information from each victim, respectively." It's worth noting that the activity shares overlap with a prior activity wave disclosed by Sekoia in November 2025, although the use of a dedicated phishing kit is a new approach by either the same or new operators. EPMM exploits enable persistent accessThe recently disclosed security flaws in Ivanti Endpoint Manager Mobile (EPMM) have been exploited by bad actors to establish a reverse shell, deliver JSP web shells, conduct reconnaissance, and download malware, including Nezha, cryptocurrency miners, and backdoors for remote access. The two critical vulnerabilities, CVE-2026-1281 and CVE-2026-1340, allow unauthenticated attackers to remotely execute arbitrary code on target servers, granting them full control over mobile device management (MDM) infrastructure without requiring user interaction or credentials. According to Palo Alto Networks Unit 42, the campaign has affected state and local government, healthcare, manufacturing, professional and legal services, and high technology sectors in the U.S., Germany, Australia, and Canada. "Threat actors are accelerating operations, moving from initial reconnaissance to deploying dormant backdoors designed to maintain long-term access even after organizations apply patches," the cybersecurity company said. In a related development, Germany's Federal Office for Information Security (BSI) has reported evidence of exploitation since the summer of 2025 and has urged organizations to audit their systems for indicators of compromise (IoCs) as far back as July 2025. AI passwords lack true randomnessNew research by Irregular has found that passwords generated directly by a large language model (LLM) may appear strong but are fundamentally insecure, as "LLMs are designed to predict tokens – the opposite of securely and uniformly sampling random characters." The artificial intelligence (AI) security company said it detected LLM-generated passwords in the real world as part of code development tasks instead of leaning on traditional secure password generation methods. "People and coding agents should not rely on LLMs to generate passwords," the company said. "LLMs are optimized to produce predictable, plausible outputs, which is incompatible with secure password generation. AI coding agents should be directed to use secure password generation methods instead of relying on LLM-output passwords. Developers using AI coding assistants should review generated code for hardcoded credentials and ensure agents use cryptographically secure methods or established password managers." PDF engine flaws enable account takeoverCybersecurity researchers have discovered more than a dozen vulnerabilities (CVE-2025-70401, CVE-2025-70402, and CVE-2025-66500) in popular PDF platforms from Foxit and Apryse, potentially allowing attackers to exploit them for account takeover, session hijacking, data exfiltration, and arbitrary JavaScript execution. "Rather than isolated bugs, the issues cluster around recurring architectural failures in how PDF platforms handle untrusted input across layers," Novee Security researchers Lidor Ben Shitrit, Elad Meged, and Avishai Fradlis said. "Several vulnerabilities were exploitable with a single request and affected trusted domains commonly embedded inside enterprise applications." The issues have been addressed by both Apryse and Foxit through product updates. Training labs expose cloud backdoorsA "widespread" security issue has been discovered where security vendors inadvertently expose deliberately vulnerable training applications, such as OWASP Juice Shop, DVWA, bWAPP, and Hackazon, to the public internet. This can open organizations to severe security risks when they are executed from a privileged cloud account. "Primarily deployed for internal testing, product demonstrations, and security training, these applications were frequently left accessible in their default or misconfigured states," Pentera Labs said. "These critical flaws not only allowed attackers full control over the compromised compute engine but also provided pathways for lateral movement into sensitive internal systems. Violations of the principle of least privilege and inadequate sandboxing measures further facilitated privilege escalation, endangering critical infrastructure and sensitive organizational data." Further analysis has determined that threat actors are exploiting this blind spot to plant web shells, cryptocurrency miners, and persistence mechanisms on compromised systems. Evasion loader refines C2 stealthThe malware loader known as Oyster (aka Broomstick or CleanUpLoader) has continued to evolve into early 2026, fine-tuning its C2 infrastructure and obfuscation methods, per findings from Sekoia. The malware is distributed mainly through fake websites that distribute installers for legitimate software like Microsoft Teams, with the core payload often deployed as a DLL for persistent execution. "The initial stage leverages excessive legitimate API call hammering and simple anti-debugging traps to thwart static analysis," the company said. "The core payload is delivered in a highly obfuscated manner. The final stage implements a robust C2 communication protocol that features a dual-layer server infrastructure and highly-customized data encoding." Stealer taunts researchers in codeNoodlophile is the name given to an information-stealing malware that has been distributed via fake AI tools promoted on Facebook. Assessed to be the work of a threat actor based in Vietnam, it was first documented by Morphisec in May 2025. Since then, there have been other reports detailing various campaigns, such as UNC6229 and PXA Stealer, orchestrated by Vietnamese cybercriminals. Morphisec's latest analysis of Noodlophile has revealed that the threat actor "padded the malware with millions of repeats of a colorful Vietnamese phrase translating to 'f*** you, Morphisec,'" suggesting that the operators were not thrilled about getting exposed. "Not just to vent frustration over disrupted campaigns, but also to bloat the file and crash AI-based analysis tools that are based on the Python disassemble library – dis.dis(obj)," security researcher Michael Gorelik said. Crypto library RCE risk patchedThe OpenSSL project has patched a stack buffer overflow flaw that can lead to remote code execution attacks under certain conditions. The vulnerability, tracked as CVE-2025-15467, resides in how the library processes Cryptographic Message Syntax data. Threat actors can use CMS packets with maliciously crafted AEAD parameters to crash OpenSSL and run malicious code. CVE-2025-15467 is one of 12 issues that were disclosed by AISLE late last month. Another high-severity vulnerability is CVE-2025-11187, which could trigger a stack-based buffer overflow due to a missing validation. Machine accounts expand delegation riskNew research from Silverfort has cleared a "common assumption" that Kerberos delegation -- which allows a service to request resources or perform actions on behalf of a user -- applies not just to human users, but also to machine accounts as well. In other words, a computer account can be delegated on behalf of highly privileged machine identities such as domain controllers. "That means a service trusted for delegation can act not just on behalf of other users, but also on behalf of machine accounts, the most critical non-human identities (NHIs) in any domain," Silverfort researcher Dor Segal said. "The risk is obvious. If an adversary can leverage delegation, it can act on behalf of sensitive machine accounts, which in many environments hold privileges equivalent to Domain Administrator." To counter the risk, it's advised to run "Set-ADAccountControl -Identity “HOST01$” -AccountNotDelegated $true" for each sensitive machine account. Security news rarely breaks in isolation. One incident leads to another, new research builds on older findings, and attacker playbooks keep adjusting along the way. The result is a constant stream of signals that are easy to miss without a structured view. This roundup pulls those signals together into a single, readable snapshot. Go through the full list to get quick clarity on the developments shaping defender priorities and risk conversations right now.
thehackernews.comFeb 19, 2026extracted
CRESCENTHARVEST Campaign Targets Iran Protest Supporters With RAT Malware
Cybersecurity researchers have disclosed details of a new campaign dubbed CRESCENTHARVEST, likely targeting supporters of Iran's ongoing protests to conduct information theft and long-term espionage. The Acronis Threat Research Unit (TRU) said it observed the activity after January 9, with the attacks designed to deliver a malicious payload that serves as a remote access trojan (RAT) and information stealer to execute commands, log keystrokes, and exfiltrate sensitive data. It's currently not known if any of the attacks were successful. "The campaign exploits recent geopolitical developments to lure victims into opening malicious .LNK files disguised as protest-related images or videos," researchers Subhajeet Singha, Eliad Kimhy, and Darrel Virtusio said in a report published this week. "These files are bundled with authentic media and a Farsi-language report providing updates from 'the rebellious cities of Iran.' This pro- protest framing appears to be intended to increase credibility and to attract Farsi-speaking Iranians seeking protest-related information." CRESCENTHARVEST, although unattributed, is believed to be the work of an Iran-aligned threat group. The discovery makes it the second such campaign identified as going after specific individuals in the aftermath of the nationwide protests in Iran that began towards the end of 2025. Last month, French cybersecurity company HarfangLab detailed a threat cluster dubbed RedKitten that targeted non-governmental organizations and individuals involved in documenting recent human rights abuses in Iran with an aim to infect them with a custom backdoor known as SloppyMIO. According to Acronis, the exact initial access vector used to distribute the malware is not known. However, it's suspected that the threat actors are relying on spear-phishing or "protracted social engineering efforts" in which the operators build rapport with the victims over time before sending the malicious payloads. It's worth noting that Iranian hacking groups like Charming Kitten and Tortoiseshell have a storied history of engaging in sophisticated social-engineered attacks that involve approaching prospective targets under fake personas and cultivating a relationship with them, in some cases even stretching for years, before weaponizing the trust to infect them with malware. "The use of Farsi language content for social engineering and the distributed files depicting the protests in heroic terms suggest an intent to attract Farsi-speaking individuals of Iranian origin, who are in support of the ongoing protests," the Swiss-based security company noted. The starting point of the attack chain is a malicious RAR archive that claims to contain information related to the Iranian protests, including various images and videos, along with two Windows shortcut (LNK) files that masquerade as an image or a video file by using the double extension trick (*.jpg.lnk or *.mp4.lnk). The deceptive file, once launched, contains PowerShell code to retrieve another ZIP archive, while simultaneously opening a harmless image or video, tricking the victim into thinking that they have interacted with a benign file. Present within the ZIP archive is a legitimate Google-signed binary ("software_reporter_tool.exe") shipped as part of Chrome's cleanup utility and several DLL files, including two rogue libraries that are sideloaded by the executable to realize the threat actor's objectives - urtcbased140d_d.dll, a C++ implant that extracts and decrypts Chrome's app-bound encryption keys through COM interfaces. It shares overlaps with an open-source project known as ChromElevator. version.dll (aka CRESCENTHARVEST), a remote access tool that lists installed antivirus products and security tools, enumerates local user accounts on the device, loads DLLs, harvests system metadata, browser credentials, Telegram desktop account data, and keystrokes. CRESCENTHARVEST employs Windows Win HTTP APIs to communicate with its command-and-control (C2) server ("servicelog-information[.]com"), allowing it to blend in with regular traffic. Some of the supported commands are listed below - Anti, to run anti-analysis checks His, to steal browser history Dir, to list directories Cwd, to get the current working directory Cd, to change directory GetUser, to get user information ps, to run PowerShell commands (not working) KeyLog, to activate keylogger Tel_s, to steal Telegram session data Cook, to steal browser cookies Info, to steal system information F_log, to steal browser credentials Upload, to upload files shell, to run shell commands "The CRESCENTHARVEST campaign represents the latest chapter in a decade-long pattern of suspected nation-state cyber espionage operations targeting journalists, activists, researchers, and diaspora communities globally," Acronis said. "Much of what we observed in CRESCENTHARVEST reflects well-established tradecraft: LNK-based initial access, DLL side-loading through signed binaries, credential harvesting and social engineering aligned to current events." The disclosure comes days after The New York Times revealed that Iran's government likely tracked protesters' locations through their phones to warn them over a text message that their "presence at illegal gatherings" had been recorded and that they were under "intelligence monitoring." The move, it said, was an attempt to crack down dissent. According to a report published by Iran-focused digital rights group Holistic Resilience last week, some people who posted on social media about the protests and other political topics have had their SIM cards suspended. "The Islamic Republic is building a distinct model of digital control and surveillance, one that is not based on permanent isolation but on conditional and interruptible connectivity," RaazNet said. "The central pillar of this model is the National Information Network (NIN). Unlike traditional physical infrastructure, such as roads or factories, the NIN is not a static state project. Like other digital systems, it evolves continuously alongside advances in communications technologies, undergoes regular versioning, and is expanded in response to changing technical and political requirements." The move is part of a broader effort that combines information gleaned from e-government databases, surveillance cameras, as well as malware deployed via social engineering to establish remote access and monitor its citizens' movements online in a sustained manner. One such tool is a lightweight modular trojan called 2Ac2 RAT that's designed for victim device control and data collection.
thehackernews.comFeb 19, 2026extracted
Hackers target supporters of Iran protests in new espionage campaign
Hackers target supporters of Iran protests in new espionage campaign Hackers believed to be aligned with Tehran are targeting supporters of Iran’s anti-government protests in a new cyberespionage campaign, researchers have found. The campaign, discovered by Swiss cybersecurity firm Acronis, began in early January, shortly after mass nationwide demonstrations erupted across Iran calling for an end to the Islamic Republic system. Researchers said the attackers likely took advantage of a spike in demand for information after authorities imposed sweeping internet blackouts across the country to limit coverage of the unrest. The threat actor distributed malicious files bundled with authentic protest footage and a Farsi-language report described as providing updates from “the rebellious cities of Iran.” Two files in the archive, disguised as a video and an image, delivered a previously undocumented malware strain that researchers dubbed CRESCENTHARVEST. The malware functions as both a remote access trojan and an information stealer. It is capable of executing commands, logging keystrokes and extracting sensitive data, including saved credentials, browsing history, cookies and Telegram account information. It can also detect installed antivirus software, allowing it to adjust its behavior — becoming more aggressive on poorly protected systems or minimizing activity to avoid detection. While the group behind the campaign has not been identified, Acronis said the attackers’ code, infrastructure and methods suggest links to an Iranian-aligned threat actor. “Amid ongoing political turmoil, this campaign appears specifically crafted to target Farsi-speaking Iranians sympathetic to the protests, though activists, journalists, and others seeking reliable information from within Iran may also be at risk,” researchers said. Given the ongoing internet blackout in Iran, the campaign is more likely aimed at Iranians abroad or their supporters rather than domestic targets, they added. The initial infection method remains unclear, though researchers assess that the campaign likely began with spear-phishing or prolonged social engineering efforts designed to build trust before delivering the malicious files. Daryna Antoniuk is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.
therecord.mediaFeb 17, 2026extracted
LockBit 5.0 ransomware expands its reach across Windows, Linux, and ESXi
LockBit 5.0 ransomware expands its reach across Windows, Linux, and ESXi The Acronis Threat Research Unit (TRU) has identified a new and significantly enhanced version of the LockBit ransomware, LockBit 5.0, currently being deployed in active campaigns. The latest variant demonstrates expanded cross-platform capabilities, enabling attackers to target Windows, Linux, and VMware ESXi systems within a single coordinated attack. According to analysis, LockBit 5.0 introduces dedicated builds tailored for enterprise environments, reflecting the continued evolution of ransomware-as-a-service (RaaS) operations. By supporting multiple operating systems and virtualization platforms, the threat actors are positioning themselves to compromise endpoints, servers, and hypervisors, simultaneously increasing the potential scale and severity of attacks. The Windows variant incorporates advanced defense-evasion techniques, including obfuscation and anti-analysis mechanisms designed to bypass detection tools and disrupt monitoring systems. Meanwhile, the Linux and ESXi versions are engineered to target critical infrastructure and virtual machines, allowing attackers to encrypt multiple workloads at once and cause widespread operational disruption. Researchers observed that LockBit 5.0 continues to rely on strong encryption routines and appends encrypted files with randomized extensions, making recovery without secure backups significantly more challenging. The ESXi-focused functionality is particularly concerning, as compromising a single hypervisor host can impact numerous virtual machines simultaneously. The emergence of LockBit 5.0 underscores the resilience and adaptability of ransomware groups, even as global law enforcement continues sustained efforts to disrupt and dismantle their infrastructure. The release of this upgraded version also signals a continued shift toward enterprise-grade targets, with virtualization platforms and critical backend systems increasingly in the crosshairs. Acronis TRU advises organizations to adopt a layered security strategy, including comprehensive endpoint and server protection, network segmentation, strong access controls such as multi-factor authentication, and regularly tested offline backups. As ransomware operators continue to expand their technical sophistication and platform reach, cross-environment visibility and proactive cyber resilience measures are becoming increasingly critical for enterprise defense.
helpnetsecurity.comFeb 16, 2026extracted
Loading 40 more…