Search/hikvision
Vendor

hikvision

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
ds-7604ni-q1/4p(c) firmware
Connections
208 relationships
Week in review: Compromised Zimbra servers, previously patched Citrix NetScaler flaw exploited
Week in review: Compromised Zimbra servers, previously patched Citrix NetScaler flaw exploited Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Unpatched Zimbra servers are falling to CVE-2026-73570 attacks At least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570, the Shadowserver Foundation shared on Monday. AI supply chain risk is showing up in developer workflows first In this Help Net Security interview, Dr. Jaushin Lee, CEO of Zentera Systems, discusses where AI supply chain risk shows up. He says most incidents still hit developer workflows and open-source package repositories, while poisoned model weights and compromised MCP servers stay mostly in research demos. Suspected Iran-linked attack knocked UK power plant offline for days News that suspected Iranian hackers caused the shutdown of a British power plant broke over the weekend, raising the question of whether UK’s power grid and, indeed, the country’s critical infrastructure can fend off destructive cyber attacks. Production data in testing is still common, and Tricentis’ CISO wants it gone In this Help Net Security interview, Erika Dean, CISO at Tricentis, talks about keeping production data out of test environments and why she thinks the alternatives are good enough now. She explains how her team caught a prompt injection gap in red-teaming and held a release for a week until it was fixed. CISA’s logging guidance works beyond government The US Cybersecurity and Infrastructure Security Agency (CISA) wants federal agencies to (re)shape their logging strategy around one question: when an attack hits, can you actually use the logs you’ve collected to catch it and reconstruct what happened afterward? AI will not fix a governance problem in your camera estate Camera systems often outlive the companies that install them. In this Help Net Security interview, Rob Janssens, EMEA Cyber Security Director at Hikvision Europe, discusses what happens when the integrator is gone, the documentation is lost, and nobody holds the admin credentials. Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004) Attackers have begun exploiting CVE-2026-60004, a critical code injection vulnerability in the Gitea Git platform, CISA confirmed on Tuesday by adding the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. What 90 days and a small budget can buy in AI agent security In this interview with Help Net Security, Prasad Tharippala, Field CISO at Versa, explains what organizations miss when they run open-weight models in house. He covers the hidden costs of GPU infrastructure, licensing review and staffing, and why hardening and incident response become the buyer’s job. Fake bank websites play dead to evade security scanners A phishing method, named Chameleon SEO Poisoning, that uses manipulated search results and cloaked fake banking websites to steal credentials while evading security scanners has been discovered by Fortra. Android car head units infected with proxy botnet malware through built-in software updaters A newly discovered Android malware, distributed through the built-in updaters in affected Android-based car head units, turns infected devices into ad-fraud tools and nodes in a proxy botnet, Kaspersky has found. PaperCut NG/MF vulnerabilities exploited in zero-day attacks PaperCut Software has identified the two vulnerabilities chained in these attacks and urged users to install a second patch. Cybersecurity job ads demanding AI skills double in a year Job postings asking for AI skills in cybersecurity have doubled in a single year in G7 countries according to new research from the Cisco-founded AI Workforce Consortium. ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack Cybersecurity company ReliaQuest has confirmed that one of its own employees fell for a social engineering attack, handing attackers a password and a brief window into the company’s identity system. Fake OpenAI Codex download tricks macOS users into installing malware A malware campaign using a sponsored search ad and a fake OpenAI Codex download page to trick macOS users into pasting a malicious command into Terminal has been uncovered by Cato Networks. Bogus recruiters go after high-value corporate credentials on mobile Scammers posing as HR staff at well-known companies are running interview scheduling scams that end with a stolen corporate password, according to Zimperium. AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes A phishing-as-a-service (PhaaS) platform called AnonyMousKIT is automating the theft of Apple ID credentials needed to remove Activation Lock from stolen iPhones, SOCRadar found. FBI takes down China-linked hacking network behind attacks on NASA, DOJ and U.S. Senate The Justice Department and FBI have seized domains tied to two hacking tools built and run by a Chinese state-sponsored group, cutting off access to malware that had been used against U.S. government agencies for years. Previously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452) CISA added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including a previously patched Citrix NetScaler ADC and Gateway flaw, tracked as CVE-2026-8452, that is being exploited in the wild. Cyberattack causes network outage at Boston Scientific, disrupts global operations Medical technology company Boston Scientific suffered a cyberattack that disrupted its IT systems and caused a network outage, affecting global operations. Manchester Airports Group breached, millions of customers’ data stolen Someone broke into the systems of Manchester Airports Group (MAG) and walked away with a “quantity” of customer data from three UK airports, the company has confirmed. North Korean remote workers are broadening their job hunt beyond IT North Korean (DPRK) remote workers are expanding their job searches beyond IT, according to Huntress. Recent investigations have identified suspected DPRK workers employed in sales and marketing and the medical profession. Two alleged TeamPCP hackers arrested over global supply chain attacks Two men from Western Australia have been charged after police allege they were part of TeamPCP, a cybercrime group that planted malicious code in open-source software, then used it to break into organizations around the world. Android 17 adds new protections against sneaky Wi-Fi tracking and web snooping Google introduced a batch of network security changes coming in Android 17, aimed at making it harder for network operators, snoops, and scammers to track what you do on your phone. The cybercrime supply chain has five stages, each with a price In this Help Net Security video, Chris Nyhuis, CEO at Vigilant, explains why the picture of a lone ransomware attacker is about 15 years out of date. Ransomware attackers are zeroing in on mid-market companies Mid-sized companies accounted for 73% of publicly disclosed ransomware and data-extortion incidents with known revenue in North America and Europe between January 2023 and June 2026, according to Black Kite. HOL Guard: Open-source antivirus for AI agents HOL Guard is a free, open-source tool that sits between an AI assistant and the computer it runs on. When the assistant tries something risky, the tool pauses it and asks you first. It installs in about a minute, runs on your own machine, and a typical check takes under 50 milliseconds. Hottest cybersecurity open-source tools of the month: August 2026 Presented here is a curated selection of noteworthy open-source cybersecurity solutions that have drawn recognition for their ability to enhance security postures across diverse settings. Product showcase: AI Paper Trail shows the privacy cost of talking to AI Proton’s AI Paper Trail is a free tool designed to make the information accumulated across AI conversations easier to see. Cybersecurity jobs available right now: August 25, 2026 We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now. New infosec products of the month: August 2026 Here’s a look at the most interesting products from the past week, featuring releases from A10 Networks, Abnormal AI, F5 Networks, Intezer, Netscout, ScienceLogic, Searchlight Cyber, SelectHub, ServiceNow, Snyk, Tanium, and Tufin.
helpnetsecurity.comAug 30, 2026extracted
AI will not fix a governance problem in your camera estate
AI will not fix a governance problem in your camera estate Camera systems often outlive the companies that install them. In this Help Net Security interview, Rob Janssens, EMEA Cyber Security Director at Hikvision Europe, discusses what happens when the integrator is gone, the documentation is lost, and nobody holds the admin credentials. He explains why products should let customers recover control on their own, and how secure-by-default settings reduce the damage of predictable installation mistakes. He also weighs source code escrow, country-of-origin rules, and what evidence vendors can and cannot offer critical infrastructure operators. Most camera estates outlive the integrator who installed them. What happens operationally in year six when the installer has folded, the commissioning documentation is gone, and nobody has the admin credentials? That situation is more common than the industry would like to admit. A camera may have a ten-year operational life, while the company that installed it may not exist in the same form five years later. People move jobs, contractors change, and documentation gets lost. From our manufacturer’s point of view, we have to accept that reality. The customer owns the system. They should not be dependent on a particular installer to keep control of it. That is why the basics matter so much. The device needs a secure activation process, proper account controls, a controlled way to recover or reset access, firmware maintenance, and enough audit information for the customer to understand what has happened to the device. We require mandatory password creation during activation, login-failure monitoring, IP filtering and controlled SSH access. Those are useful controls, but they only work properly if the device remains under the customer’s ownership and is maintained. The other change I expect to see is better asset management. Security teams are getting much better at discovering devices, checking configurations and identifying systems that have fallen outside normal management. AI will help with that, but I would not make AI the answer to a basic governance problem. The first requirement is still ownership, governance, and a documented recovery process. If an installer disappears and the customer can no longer administer its own cameras that is a lifecycle problem. Manufacturers should design products so that the customer can recover control without having to go back to the original installer. A significant share of physical security kit is specified by procurement teams buying on price, installed by electricians, and never touched again. How do you engineer for a channel that will not read your hardening guide? We have to be realistic about how these systems are installed. You cannot build a security strategy around the assumption that every installer will read a long security manual and then remember it five years later. The product therefore has to do more of the work. For example, requiring a new password when a device is activated is much better than shipping equipment with a universal default password. Services that are not needed should not simply be exposed because they happen to be available. Remote administration should be controlled, and the device should make the secure choice the easy choice. This is also where the distinction between secure-by-design and secure-by-default is important. Secure-by-design means security is considered throughout development, testing and maintenance. Secure-by-default means the customer does not have to become a security specialist just to get a reasonably safe initial configuration. Our Security Development Lifecycle covers the product from requirements and design through development, verification, release and maintenance. That is the right direction for the industry. Security cannot be something added at the end of the installation project. Of course, no manufacturer can compensate for every bad network design. If somebody puts a camera directly on the public Internet, disables controls, and never patches it, there is still a risk. However, we can make the product much more resistant to predictable mistakes. How do you handle an integrator who is knowingly deploying devices with security features disabled because a customer wants remote access to work in five minutes rather than five hours? First, I would want to understand exactly what has been disabled and why. There are legitimate operational requirements for remote access, but ‘it works’ is not the same as ‘it is secure’. If an integrator deliberately turns off a security control, the customer should know what that means. That decision should not be hidden in an installation script or made simply because it is quicker. There is also a product responsibility here. High-risk settings should not be something that can be changed accidentally. The user should be able to see that a security control has been weakened, and important changes should leave an audit trail. The better answer to the remote-access problem is normally architecture rather than disabling security. Restrict access, use appropriate secure protocols, segment the video network, and only expose the services that are actually required. Our product-security guidance, for example, recommends limiting remote access and using more secure methods such as VPNs rather than exposing systems directly to the Internet. I would not pretend that customers never make risk decisions. They do, and sometimes they have good operational reasons. Our responsibility is to make those decisions visible and to give customers a secure baseline to start from. The threat environment is changing as well. Automated scanning means that a configuration which might have remained unnoticed for months can be found very quickly. That makes ‘we have always done it this way’ a poor security argument. Several European buyers now require source code escrow, third-party binary analysis, or country-of-origin restrictions. Which of those measures do you consider security theatre, and which have improved your products? I would be careful about calling any of these measures ‘security theatre’ in isolation. They address different risks. Independent testing and vulnerability research are useful because another engineer can find something our own teams missed. Binary analysis can also be valuable, particularly when a customer wants to understand what is actually running on a device rather than relying only on documentation. Source-code escrow is different. I can understand why a customer would want it, especially for business continuity or supplier risk reasons. But having access to source code is not, by itself, evidence that a product is secure. You still need secure development processes, code review, testing, vulnerability management, control of dependencies, and a trustworthy build and update process. Country-of-origin requirements are even more complicated. Customers operating critical infrastructure have legitimate legal, geopolitical, and supply-chain concerns. Those requirements need to be addressed honestly. At the same time, nationality alone should not replace objective, technical security evaluation. The useful question is what evidence and technical controls are in place and what risks they address. From our side, the measures that have the technical value are the ones that create repeated feedback security testing, vulnerability disclosure, testing, secure development requirements, and continuous improvement. That is also why transparency matters. A customer should be able to ask how security is handled and then verify the answer where appropriate. Hikvision sits under US sanctions and continued scrutiny in several European countries. When a critical infrastructure operator asks you why they should trust your firmware, what evidence do you put on the table, and what can you not prove to them? I would start by saying that they should not trust a vendor simply because the vendor says its firmware is secure. They should ask for evidence, and we should be prepared to provide evidence that is appropriate for the product and the customer. There are several parts to that. One is the development process. Hikvision has published information about its Security Development Lifecycle and about the controls it uses during design, development, verification and maintenance. We also publish product-security information and operate a very mature certified vulnerability reporting process, certified under ISO/IEC 29147 & ISO/IEC 30011. Also, our AI is edge, this means that the AI is running directly on the camera, without requiring external connectivity. We are also among the industry pioneers to achieve ISO/IEC 42001 certification. This is the world’s first certifiable international standard dedicated to AI standards for an Artificial Intelligence Management System (AIMS), providing a structured framework for AI governance. This standard helps us to ensure that the AI systems are ethical, transparent, secure, and aligned with stakeholder expectations. Another part is the product. Customers can look at things such as authentication, password controls, secure management protocols, firmware protection, and update mechanisms. For example, Hikvision product-security documentation describes password requirements and an activation process that requires a new password. It also describes anti-downgrade protection and SSH being disabled by default unless an administrator enables it. Then there is independent validation. Customers may perform their own testing, use third-party assessments, or conduct binary and network analysis. I see that as a normal part of doing business with critical infrastructure. A serious customer should challenge its suppliers. What we cannot prove is that a particular piece of software contains no vulnerabilities. No responsible manufacturer or software vendor can make that claim. The same applies to trust. A certification or a white paper cannot manufacture trust. The better approach is to give customers enough information to assess the technology, keep improving the products, respond when vulnerabilities are reported, and accept independent scrutiny. For me, that is a more credible position than asking customers simply to take our word for it.
helpnetsecurity.comAug 27, 2026extracted
CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw
ON-PREM EPA to drop requirement for public notice of polluting datacentersState and local regulators would decide whether the public gets a say on minor-source permits SYSTEMS OpenAI's upcoming Jalapeño chip looks like it'll be an inference beast128 chips, 1.7 exaFLOPS, and 27 TB of HBM give Altman and crew a leg up over Blackwell, and maybe even Rubin SYSTEMS What Nvidia's first Groq 3 LPU benchmarks tell us about its $20B gambleGemma 4 31B performance tests offer a best-case scenario for next-gen dataflow accelerators ON-PREM US datacenters tripled their water footprint in 10 years... and those are figures from the start of the AI boom. It can only be worse now. Silo-ed reporting isn't helping ai and ML AI slop is good for business if you know what you're doingYour irresponsibility is someone else's opportunity Security Russians are posing as Signal support to launch phishing attacksPLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attackPLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructureVoting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included Security EQT buys majority share in Swiss cybersecurity biz AcronisWent at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sightOn the plus side, infosec's a good bet for a long, stable career Emperor Penguin Linus Torvalds banishes a bug – with a botThe lad himself finds and fixes a tricky one… or does he? FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash anotherWord up GNOME can look like Windows – and Flashback can do it without extensionsNew 'Simple-taskbar' is an option, but there's a simpler, stabler way A moment of silence, please, for the final release of Debian on x86-32New Debian versions hit FOSSland in the form of 13.6 and 12.15 Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websitesFlaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide Frame: A new X11 server – implemented directly in assemblyJoins yserver, Phoenix, and of course XLibre – and outlier Arcan
theregister.comAug 25, 2026extracted
Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies
Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn internet-facing devices into SOCKS proxies. "While the malware reuses the DDoS engine from the publicly leaked Mirai source code, it extends the original framework with numerous capabilities, including encrypted C2 communications, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer, and an integrated exploit arsenal targeting multiple known vulnerabilities," Fortinet FortiGuard Labs said. Evidence indicates that the botnet has been active in the wild since July 2026, exploiting known vulnerabilities in publicly-accessible devices to deliver the malware. Some of the security flaws weaponized by the botnet are below - CVE-2007-3010 - Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability CVE-2016-6277 - NETGEAR Multiple Routers Remote Code Execution Vulnerability CVE-2018-14558 - Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability CVE-2019-14931 - Mitsubishi Electric Europe B.V. ME-RTU devices and INEA ME-RTU devices remote Command Injection vulnerability CVE-2020-10987 - Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability CVE-2021-46422 - Telesquare SDT-CW3B1 Command Injection vulnerability CVE-2022-37055 - D-Link Routers Buffer Overflow Vulnerability CVE-2024-29269 - Telesquare TLR-2005KSH Command Injection Vulnerability CVE-2025-10123 - D-Link DIR-823X Command Injection Vulnerability CVE-2025-55583 - D-Link DIR-868L B1 router Command Injection Vulnerability Successful exploitation leads to the execution of a loader shell script ("wget.sh") hosted on an external server ("91.92.40[.]118"), which then retrieves the botnet binary that's compatible with the device CPU architecture. The script subsequently clears Bash history to erase traces of the attack. Upon execution, the binary checks for the presence of analysis tools, sandboxes, and virtual environments, before establishing encrypted communications with a command-and-control (C2) server on port 443. The port choice is intentional as it allows the malware to blend in with expected HTTPS traffic at the network perimeter. Once the host is registered with the C2 server, it waits for further commands to take action. It supports a number of commands that allow an operator to install persistence mechanisms, update the binary, terminate the bot, upload/download files, launch an interactive shell, intercept HTTP Basic Authorization and Cookie headers, turn the host into a proxy node, launch an SSH brute-force scanner, trigger DDoS attacks over DNS, TCP, and UDP, and fire an HTTP-based exploit dispatcher for exploiting known flaws. The CVE attack module includes the ability to launch exploits for eight security flaws impacting Hikvision (CVE-2021-36260), Atlassian Confluence (CVE-2022-26134), WSO2 (CVE-2022-29464), Zyxel (CVE-2022-30525), TP-Link (CVE-2023-1389), PHP (CVE-2024-4577), D-Link (CVE-2024-10914), Kubernetes (CVE-2025-1974). The proxy component, on the other hand, transforms an infected router, firewall, IP camera, or other edge device into a SOCKS5 proxy that the threat actor can leverage as a network relay to conduct follow-on operations and evade detection. "This capability significantly increases the value of an infected host to attackers," Fortinet said. "The victim's IP address can be used to disguise malicious traffic, bypass geographic restrictions, or provide access to internal networks through an already compromised machine." "In larger botnets, the same functionality could also be used to build a distributed proxy infrastructure, enabling anonymous traffic forwarding or monetization through residential and enterprise proxy services."
thehackernews.comAug 17, 2026extracted
New Evooo1Bot Linux botnet turns routers into traffic relay nodes
A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes. The malware's capabilities extend beyond turning devices into proxy nodes and include credential theft, SSH brute-forcing, and launching distributed denial-of-service (DDoS) attacks. Since at least July, Evooo1Bot has been targeting devices from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link across various regions by exploiting known vulnerabilities. “While the malware reuses the DDoS engine from the publicly leaked Mirai source code, it extends the original framework with numerous capabilities, including encrypted C2 communications, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer, and an integrated exploit arsenal targeting multiple known vulnerabilities,” Fortinet researchers found. Newer builds include a separate vulnerability-exploitation module targeting Hikvision cameras, Atlassian Confluence, Zyxel firewalls, TP-Link routers, D-Link NAS devices, WSO2 products, Kubernetes ingress-nginx, and vulnerable PHP-CGI installations. However, Fortinet notes that some of the embedded exploits are not correctly implemented, leading to failed exploitation. When leveraging an exploit successfully, a script downloads one of the 12 available malware builds that match the host’s CPU architecture, then clears Bash history to wipe traces of the attack. Evooo1Bot uses encrypted command-and-control (C2) communications over port 443 and performs extensive checks for debuggers, security tools, sandboxes, virtual machines, containers, and honeypots before it launches on the infected device. Persistence is established through systemd, SysV init, shell profiles, and rc.local, while a cron job attempts to re-download the payload every five minutes. An interactive shell gives operators direct control over compromised systems, while file-transfer commands support uploads and downloads. The malware also features a credential sniffer module that monitors ‘/proc/net/tcp’ and attempts to capture HTTP Basic Authentication and Cookie headers. The SOCKS5 module supports direct listening and reverse-relay modes, allowing attackers to conceal malicious traffic, circumvent geographic restrictions, or potentially access networks through compromised systems. Fortinet says proxying sessions run independently, and multiple can be opened simultaneously, allowing monetization through residential proxy services if the botnet grows large enough. The SSH scanner module uses 150 username and password combinations for enterprise-oriented accounts, and performs post-login checks to avoid honeypots. Finally, the DDoS module that was inherited by Mirai supports 16 flood methods, including UDP, DNS, SYN, ACK, GRE, fragmented TCP, and an HTTP flood with customizable requests. To defend against botnet malware, keep your IoT devices’ firmware updated, replace default admin credentials, turn off remote access panels, and replace devices when the vendor no longer provides support for them. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comAug 15, 2026extracted
New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks
A newly discovered cyber attack campaign has been observed delivering a previously undocumented malware family called SharkLoader that acts as a loader for deploying Cobalt Strike Beacon on compromised hosts. Kaspersky, which is tracking the activity under the moniker StrikeShark, said the campaign has targeted a diplomatic organization in Indonesia, government organizations in Taiwan, software development companies across multiple countries, and entities associated with other sectors located in Hong Kong, Lebanon, Syria, Colombia, North Macedonia, Nepal, and Serbia. "The observed victimology suggests a campaign with broad geographic reach and a diverse target set rather than a narrow focus on a specific industry or region," the Russian cybersecurity vendor said. The campaign does not exhibit direct links to any known threat actor or group, although the operators have utilized several open-source post-compromise tools like FScan and Pillager, which are commonly put to use by Chinese-speaking developers. It's believed that the campaign is the handiwork of a Chinese-speaking threat actor. Attack chains involve the two initial access pathways: the exploitation of known Exchange Server flaws, such as CVE-2021-26855 (aka ProxyLogon), to strike the Indonesian diplomatic entity, or through a path traversal vulnerability impacting Openfire (CVE-2023-32315) in the case of Taiwanese software development organizations, or a critical remote code execution bug in GeoServer (CVE-2024-36401) to target a Colombian organization. Other remote code execution and authentication bypass vulnerabilities weaponized by the threat actor are listed below - Apache Shiro: CVE-2016-4437 Hikvision Products: CVE-2021-36260 Microsoft SharePoint: CVE-2021-27076 Zimbra Collaboration Suite: CVE-2022-27925 Microsoft Exchange Server: CVE-2022-41082 (aka ProxyNotShell) F5 BIG-IP: CVE-2023-46747 Fortinet FortiOS: CVE-2024-21762 React Server Components: CVE-2025-55182 Fortinet FortiOS: CVE-2022-40684 Cisco IOS XE Web UI: CVE-2023-20198 It's assessed that the threat actors are likely employing publicly available proof-of-concept (PoC) exploits hosted on GitHub or other open-source platforms to gain initial access in an opportunistic manner. Upon gaining a foothold, the threat actors establish persistence by deploying web shells to trigger a DLL side-loading chain involving "SystemSettings.exe" (CVE-2021-27076) to deliver SharkLoader ("SystemSettings.dll"). A second method used by StrikeShark to distribute the loader is via custom dropper executables masquerading as legitimate software installers or applications like Google Update and Cisco AnyConnect, and executing the malware loader once the installation process completes. The method by which these droppers are delivered is currently unknown. "In addition to installer-themed lures, several SharkLoader droppers use decoy PDF documents to persuade victims to open the malicious file," Kaspersky explained. "However, not all samples employ this technique, as some droppers function solely as a delivery mechanism for SharkLoader without presenting any lure content." Once the DLL is loaded, SharkLoader implements what's called Perfect DLL Hijacking, a technique detailed by security researcher Elliot Killick in October 2023, to execute malicious code while bypassing Windows Loader Lock, a system-wide lock held by the operating system when loading and unloading DLLs. Specifically, it's engineered to decrypt and load "DscCoreR.mui," which is then used to decompress and load Cobalt Strike in a new thread created in a suspended state, along with two other components - SyncRes.dat, which installs multiple Windows API hooks by using the Microsoft Detours library to monitor exceptions generated during runtime. MinHook DLL, which installs API hooks for the VirtualAlloc and Sleep functions to copy the decompressed Cobalt Strike Beacon into the allocated memory region using VirtualAlloc. The Sleep-related hook is triggered when the Beacon calls Sleep, likely in an attempt to evade memory scanning techniques that identify executable (RWX) code regions in memory. "Finally, after the API hooks are installed and the Cobalt Strike Beacon shellcode has been written to the thread buffer, the malware calls the ResumeThread API to resume the suspended thread and begin execution of the beacon," Kaspersky explained. While SharkLoader does not come with persistence mechanisms built into it, the threat actor has been found to leverage Registry Run keys and scheduled tasks as a way to activate the launch of "SystemSettings.exe" either when a user logs in, or even if no user is logged in. The attacks also involve an extensive reconnaissance phase following initial compromise and persistence, with the threat actor engaging in Active Directory enumeration, credential theft by targeting the LSASS process and the NTDS database file, and deploying open-source scanners and information gathering tools like FScan, Searchall, and Pillager. Given the absence of active data exfiltration, it's unclear what the end goals of StrikeShark are. However, the targeting of government and software development organizations suggests a cyber espionage bent with a potential interest in hoovering political intelligence or intellectual property. "At the same time, the use of SharkLoader and Cobalt Strike, alongside the exploitation of public-facing applications and malicious installers and droppers, suggests the attacker may also be opportunistically targeting vulnerable systems," Kaspersky said. "The absence of clear evidence of data exfiltration thus far does not exclude this possibility, as Cobalt Strike’s file operation and data exfiltration modules could be employed at a later stage."
thehackernews.comJun 26, 2026extracted
Mystery hackers use novel SharkLoader dropper against governments, software devs
Mystery hackers use novel SharkLoader dropper against governments, software devs Kaspersky researchers have uncovered a previously unknown cyberattack campaign that has compromised government organizations and software development companies in multiple countries. They first stumbled onto the campaign while investigating an attack on a diplomatic organization in Indonesia. What initially looked like an isolated incident revealed a global operation they’ve dubbed StrikeShark, due to the attackers’ use of a previously unknown dropper the researchers named SharkLoader. How the attackers get in The attackers gain access either by exploiting known vulnerabilities in internet-facing applications, or by tricking users into running malware-laced files disguised as legitimate software. The list of exploited vulnerabilities is wide-ranging, spanning flaws in products from Microsoft (SharePoint, Exchange Server), Fortinet (FortiOS), Cisco (IOS XE), F5 (BIG-IP), Zimbra, Apache (Shiro), and Hikvision. Some of these date back as far as 2016. All the vulnerabilities identified have publicly available (proof-of-concept) exploit code, suggesting the attackers rely on existing offensive resources rather than developing their own. Though Kaspersky researchers were unable to pinpoint how the attackers distributed the SharkLoader dropper directly to employees at those organizations, they known the attackers have been disguising it as a Cisco AnyConnect VPN installer and a Google Update utility. Some droppers displayed convincing decoy PDF documents, including one appearing to be a technical document about liquid rocket engine design, and another one related to a biological treatment process. What happens once the attackers are inside Once SharkLoader is running, it installs a Cobalt Strike beacon, a commercial penetration-testing tool that’s used for maintaining remote access and moving through networks. The threat actor conducted extensive reconnaissance and credential theft, including dumping credentials from Windows memory and from Active Directory. Armed with those credentials, the attackers could potentially move freely through a victim’s entire network. The malware itself is designed to stay hidden: it disguises its components as ordinary Windows system files, abuses a legitimate Windows application to load itself, and goes to great lengths to disable the security logging that defenders rely on to detect intrusions. Who’s behind these attacks? The campaign has hit government organizations in Taiwan, software development companies across multiple countries, and various entities in Hong Kong, Lebanon, Syria, Colombia, North Macedonia, Nepal, Serbia, and elsewhere. Post-exploitation tools used in the campaign were developed by Chinese-speaking developers on GitHub, but that’s not a strong indicator that the attackers are also Chinese-speaking. “Targeting of government and software development organizations may indicate a cyber-espionage objective, although our confidence remains low due to the limited post-compromise activity observed, which primarily consisted of credential access, system reconnaissance, and lateral movement,” Kaspersky researchers noted. “At the same time, the use of SharkLoader and Cobalt Strike, alongside the exploitation of public-facing applications and malicious installers and droppers, suggests the attacker may also be opportunistically targeting vulnerable systems. The absence of clear evidence of data exfiltration thus far does not exclude this possibility, as Cobalt Strike’s file operation and data exfiltration modules could be employed at a later stage.” The researchers weren’t able to establich direct links to any known hacking group. Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!
helpnetsecurity.comJun 26, 2026extracted
StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader
Introduction During our research of activity affecting a diplomatic organization in Indonesia, we uncovered a previously undocumented malware family that we have named SharkLoader. What initially appeared to be an isolated case quickly expanded into a broader campaign as we identified additional SharkLoader infections across multiple countries and sectors. Our investigation revealed that SharkLoader serves as a loader designed to deploy Cobalt Strike Beacon on compromised systems. We observed the threat actor deploying SharkLoader through exploitation of internet-facing applications, including Microsoft Exchange, Microsoft SharePoint, and Openfire Server, as well as through malware-based delivery mechanisms. Beyond the diplomatic entity in Indonesia, we identified related activity targeting government organizations in Taiwan, software development companies across multiple countries, and entities in other sectors located in Hong Kong, Lebanon, Syria, Colombia, North Macedonia, Nepal, Serbia, and more. The observed victimology suggests a campaign with broad geographic reach and a diverse target set rather than a narrow focus on a specific industry or region. For now, we are tracking this activity as StrikeShark. Although the operators utilize several open-source post-compromise tools associated with Chinese-speaking developers, we have not identified direct code reuse, infrastructure overlap, or operational similarity to confidently attribute the activity to any known APT or cybercrime group. As a result, attribution remains preliminary and the campaign’s ultimate objectives are still under research. Initial infection Our analysis of SharkLoader intrusions indicates that the threat actor employs multiple methods to gain initial access to victim environments. During our investigation, we observed two primary infection vectors: the exploitation of vulnerabilities in internet-facing applications and the deployment of custom dropper samples, some of which were disguised as legitimate software. Exploitation of public-facing applications In the incident affecting an Indonesian diplomatic entity, the threat actor exploited Microsoft Exchange vulnerabilities, including CVE-2021-26855 (ProxyLogon), to gain access to the target environment. Similar activity was observed in Taiwan, where software development organizations were compromised through exploitation of Openfire (CVE-2023-32315). In a separate incident affecting a Colombian organization, the threat actor exploited a GeoServer instance vulnerable to CVE-2024-36401. Beyond these incidents, we identified additional exploitation activity targeting vulnerabilities in multiple internet-facing enterprise applications and network appliances including those listed below: Remote Code Execution (RCE) Apache Shiro: CVE-2016-4437 Hikvision Products: CVE-2021-36260 Microsoft SharePoint: CVE-2021-27076 Zimbra Collaboration Suite: CVE-2022-27925 Microsoft Exchange Server: CVE-2022-41082 F5 BIG-IP system: CVE-2023-46747 Fortinet FortiOS: CVE-2024-21762 React Server Components: CVE-2025-55182 Authentication Bypass Fortinet FortiOS: CVE-2022-40684 Cisco IOS XE Web UI: CVE-2023-20198 As of the time of writing this article, we haven’t obtained the exploits the attackers used. However, based on the vulnerabilities observed across multiple attacks, we assess with medium confidence that the threat actor primarily relies on publicly available proof-of-concept (PoC) exploits to gain initial access. All the vulnerabilities identified during our investigation have publicly available exploit code, including PoCs hosted on GitHub and other open-source platforms, suggesting the actor leverages existing offensive resources rather than develops custom exploit capabilities. The victim profile also indicates that the activity is largely opportunistic, affecting organizations across various industries, regions, and technology environments without a clear focus on a specific target set. Also, one of the IP addresses associated with the C2 domain was also observed conducting internet-wide scanning activity, potentially aimed at identifying and exploiting vulnerable internet-facing systems at scale. Following exploitation, the attacker established persistence on compromised servers through the deployment of webshells. Although we were unable to recover the webshell files, a series of commands whose execution we observed in our telemetry along with the detection records of webshells strongly indicate their use for post-exploitation activities. One of the earliest observed actions involved copying the legitimate Windows application SystemSettings.exe to a new location before executing it. This application was later abused as part of a DLL sideloading chain used to launch SharkLoader, which in this scenario was hidden in the malicious SystemSettings.dll library. We suspect that this DLL along with malicious encrypted files, which we’ll describe further, was uploaded through the webshell to the same directory as SystemSettings.exe. In another case involving the exploitation of CVE-2021-27076, the threat actor launched SystemSettings.exe triggering the subsequent SharkLoader sideloading chain from different directories on the system, which suggests renewed operational activity in the victim environment. In some of the cases, they used security product vendor names as the directory names, allegedly to appear legitimate. Dropper-based distribution In several observed cases, the threat actor distributed SharkLoader through custom dropper executables masquerading as legitimate software installers or applications such as Google Update and Cisco AnyConnect. However, the exact delivery mechanism used to distribute these droppers remains unknown. The observed dropper filenames include: GoogleUpdateStepup.exe AnyConnect-win-4.10.04071-predeploy-k9exe AutoUpdate.exe 319-pfd-8001-reva_traitement biologique_master.zip In one of the samples we analyzed, the threat actor used a legitimate Cisco AnyConnect VPN installer as a lure. The custom dropper extracted zlib-compressed data embedded within its resource section, decompressed it into an MSI package, and wrote the file to %APPDATA%\reports\AnyConnect-win-4.msi. The MSI package was a legitimate Cisco AnyConnect VPN installer, which was subsequently executed via the ShellExecuteW API, making the user believe the custom dropper was a legitimate application. While the Cisco AnyConnect installer was decompressed and executed, SharkLoader components were silently dropped into directories in %APPDATA% different from %APPDATA%\reports\ in the background, executing the malware loader once the installation process completes. In addition to installer-themed lures, several SharkLoader droppers use decoy PDF documents to persuade victims to open the malicious file. However, not all samples employ this technique, as some droppers function solely as a delivery mechanism for SharkLoader without presenting any lure content. Among the samples analyzed, most droppers write the decoy PDF to a subdirectory named aswerf within the %TEMP% directory, while others save the document directly to %TEMP%. Analysing the sample shows the PDF files are stored within the dropper’s resource section under the resource name TELEMETRY and are compressed with zlib. Upon execution, the dropper extracts and decompresses the embedded PDF, writes it to disk using the same filename as the dropper executable but with a PDF extension, and launches it via cmd.exe /c to display the decoy document to the victim. The following are examples of PDF documents extracted and displayed by the droppers during the deployment of SharkLoader. In one dropper sample, discovered on a machine located in Lebanon (MD5: 1F65544978B8EA0E745E573B8EE9684B), the dropper extracts and decompresses SystemSettings.dll from zlib-compressed data embedded within the binary and writes it to %APPDATA%\xwreg. It also extracts and decompresses DscCoreR.mui and SyncRest.dat from resources named VAULTSVCD and UMRDPRDAT, respectively, and writes them to the same directory. The dropper then copies the legitimate SystemSettings.exe application from C:\Windows\ImmersiveControlPanel to the target location to facilitate DLL sideloading. Across other SharkLoader dropper samples analyzed, the malware components were observed being written to either %APPDATA%\xwreg or %APPDATA%\xgdf. SharkLoader installation SharkLoader is composed of multiple components that work together to load and execute the final implant, a Cobalt Strike Beacon. While the majority of SharkLoader samples analyzed rely on the sideloading of SystemSettings.dll, other variants leverage alternative DLL side-loading targets, including msedge.dll, PrintDialog.dll, and miracastview.dll, each of them leveraging a corresponding legitimate application. Across the different variants examined, the encrypted modules were also observed using a variety of filenames, including: The SharkLoader execution flow is as follows: In the dropper-based infections, after deploying all required SharkLoader components, the dropper creates two scheduled tasks through the Windows Task Scheduler COM interfaces. Task names: OneDrive Standalone Update Task-S-1-5-21-4165425321-4153752593-2322023643-1000 MicrosoftUpdateTaskUserS-1-5-32-2456537112-101246289-228944324-1000 Both tasks are configured to execute the copied SystemSettings.exe from the malware’s working directory (for example, %APPDATA%\xwreg or %APPDATA%\xgdf), triggering the side-loading of the malicious SharkLoader DLL. The first scheduled task uses a time-based trigger that executes every five minutes, providing long-term persistence. The second task is configured to execute every second, likely to ensure immediate execution of SharkLoader following deployment. After a delay of approximately 1.5 seconds, the dropper removes the second scheduled task by using the Task Scheduler COM interfaces, leaving the first task in place to maintain persistence on the system. SharkLoader DLL – Main implant For the detailed analysis of the infection chain, we’ll focus on the SharkLoader components deployed by a malicious dropper named 一种异常状况的截图(包括操作系统和输入法版本).pdf.exe (MD5: 24FCEBDEECBA65004FDB0923763D74FD), which was identified in a campaign targeting a government entity in Taiwan. “PerfectDLL Hijacking” technique Once the malicious DLL is loaded, SharkLoader implements a technique commonly referred to as “Perfect DLL Hijacking” and originally described by a security researcher named Elliot Killick on his blog. The purpose of this technique is to bypass the Windows loader lock and safely create a malicious thread via the CreateThread API without risking a deadlock. According to Microsoft’s Dynamic-Link Library Best Practices, the Windows loader holds a synchronization object known as the “loader lock” while executing the DllMain function. This mechanism ensures that only one thread can perform DLL loading and initialization operations within a process at any given time. As a result, invoking APIs such as CreateThread or LoadLibrary from within DllMain can lead to deadlocks because the loader lock remains held throughout the execution of the function. To avoid this issue, SharkLoader manipulates the process’s internal loader state to release the loader lock before invoking CreateThread from the DllMain execution path. By doing so, it attempts to execute its malicious code without triggering the loader-related deadlocks that can occur when threads are created while the loader lock remains held. Based on the code, SharkLoader first resolves the addresses of several undocumented loader structures within ntdll.dll, including: LdrpLoaderLock : the critical section object used by the Windows loader to synchronize module loading and initialization operations LdrpWorkInProgress : an internal loader state variable that tracks whether module initialization is currently in progress After locating these structures, SharkLoader forcefully releases the loader lock by invoking LeaveCriticalSection on LdrpLoaderLock. It then decrements the value of LdrpWorkInProgress with InterlockedDecrement64, effectively marking the initialization process as complete. Finally, the malware signals the loader completion event via SetEvent before creating a new thread to execute its malicious functionality. As a result, these actions manipulate the loader’s internal state and cause Windows to treat the DLL initialization process as having completed successfully. This allows SharkLoader to continue execution after forcefully releasing the loader lock, despite still operating from within the DllMain execution path. Decryption and loading of >DscCoreR.mui As shown in the previous section, the loader creates a new thread after escaping the Windows loader lock. This thread subsequently spawns a second thread responsible for decrypting and reflectively loading the encrypted file, DscCoreR.mui. The routine first reads the encrypted file into memory and extracts the first 16 bytes to use as the Blowfish decryption key. It then initializes the Blowfish cipher by using custom P-array and S-box constants embedded in the loader and decrypts the file in ECB mode with the extracted key. Once decryption is complete, the resulting PE file is reflectively loaded into memory and executed without being written to disk. The decrypted DscCoreR.mui file is a packed PE file with its MZ header removed, likely as an anti-analysis measure. After decryption, SharkLoader processes the PE image by parsing its headers, allocating memory for the image, mapping its sections, applying relocations, resolving imported functions, and setting the appropriate memory protections. Once the in-memory PE loading process is complete, the main loader, SystemSettings.dll, transfers execution to the entry point of the mapped image, which contains the packer stub. The stub then unpacks the protected code, invokes the DLL’s DllMain function, and returns execution to SystemSettings.dll. Finally, SystemSettings.dll calls the exported function SetUserProcessPriorityBoost from the mapped DLL, triggering execution of the fully unpacked next-stage DLL. DscCoreR.mui and SyncRes.dat DLLs Within the decrypted and unpacked DscCoreR.mui code, the malware proceeds to load and decrypt a second encrypted file, SyncRes.dat, before reflectively loading the resulting DLL into memory. The mapped DLL installs multiple API hooks by using Microsoft Detours, which will be discussed in the next section. After mapping and loading SyncRes.dat for API hooks, the DscCoreR.mui performs installation of the Vectored Exception Handler (VEH) and then creates a thread in a suspended state that is later used to execute the Cobalt Strike Beacon shellcode. Additionally, to facilitate additional API hooks, it decompresses and loads the MinHook library and uses it to install hooks on the VirtualAlloc and Sleep APIs. The DscCoreR.mui then decompresses the Cobalt Strike Beacon shellcode into the memory region associated with the suspended thread and then the suspended thread is resumed, resulting in execution of the beacon. Decryption and loading of SyncRes.dat To decrypt SyncRes.dat, the malware extracts a 16-byte AES-128 key and a 16-byte initialization vector (IV) directly from the file itself. The first 16 bytes of the file contain the AES key, while the subsequent 16 bytes contain the IV. The remaining file content consists of AES-encrypted data, which is decrypted using the extracted key and IV. Once decrypted, the resulting data reveals a PE image with its MZ header removed, similar to DscCoreR.mui. Similar to the decrypted DscCoreR.mui module, the decrypted SyncRes.dat file is also protected by an unknown custom packer. After decryption, the loader reflectively loads the PE image before transferring execution to the module’s entry point. The entry point contains a packer stub responsible for unpacking the protected code in memory. Once the unpacking routine is complete, the malware invokes a specific exported function named StartEngineData, which serves as the primary execution routine of the third-stage DLL. Before continuing with the DscCoreR.mui analysis, we will first discuss SyncRes.dat. SyncRes.dat decrypted DLL: Multiple API hooks The decrypted and unpacked SyncRes.dat DLL is primarily responsible for installing multiple Windows API hooks by using the Microsoft Detours library. After attaching all detour hooks, it calls DetourTransactionCommitEx to apply them in one commit. The following table lists the hooked Windows APIs and their corresponding hook handler functions. Upon completing the installation of API hooks via the decrypted SyncRes.dat, the DscCoreR.mui DLL proceeds with the remaining functions, which are discussed below. VEH registration and access violation handling Following the installation of the API hooks, the malware registers a Vectored Exception Handler (VEH) to monitor exceptions generated during runtime. The handler specifically checks for access violation exceptions (0xC0000005). When such an exception occurs, it retrieves the faulting memory address from the exception record and calls VirtualProtect to restore read, write, and execute (RWX) permissions to the corresponding memory page before resuming execution. During our analysis, no access violations were observed. It is possible that this mechanism is intended to handle access violations that may occur under specific runtime conditions. Thread creation for Cobalt Strike Beacon execution The malware creates a new thread in a suspended state that is intended to execute the Cobalt Strike Beacon shellcode. The thread entry point is configured to point to a memory buffer that will later contain the beacon shellcode. At this stage, the buffer does not yet contain the actual Cobalt Strike Beacon shellcode. Instead, the thread is created in a suspended state so that the malware can prepare and inject the shellcode into the buffer before execution. Once the beacon payload has been written into the buffer, the malware resumes the suspended thread using the ResumeThread API, which triggers the execution of the Cobalt Strike beacon. MinHook DLL, API hooking, and Cobalt Strike beacon After creating the suspended thread for beacon execution, the malware decompresses a zlib-compressed MinHook PE file embedded within DscCoreR.mui. The MinHook library is used to install API hooks for the VirtualAlloc and Sleep functions. Once the MinHook DLL is decompressed and loaded into memory, the malware resolves the exported functions MH_Initialize and MH_CreateHook, which are then used to install hooks on the VirtualAlloc and Sleep APIs. After the hooks are installed, the malware invokes a function that decompresses a zlib-compressed Cobalt Strike Beacon shellcode embedded within the malware. The function first decompresses the shellcode into a temporary buffer and then allocates executable memory using VirtualAlloc with RWX permissions. The decompressed beacon is subsequently copied into the allocated memory region. Because the VirtualAlloc API has already been hooked at this stage, the hook handler captures the address and size of the allocated memory used to store the beacon shellcode. The hook records the addresses and sizes of the first three successful memory allocations and stores these values in global variables to track specific memory regions allocated during execution. These tracked regions are associated with memory buffers used by the Cobalt Strike Beacon during runtime. The second hook, on the Sleep API, is used when Cobalt Strike Beacon calls Sleep, such as during beacon sleep intervals. It temporarily modifies the memory protection of the tracked allocation regions by using VirtualProtect, changing their protection to PAGE_READWRITE (RW) before invoking the original Sleep function. After the sleep period ends, the malware restores the memory protection of those regions to PAGE_EXECUTE_READWRITE (RWX). This behavior suggests that the malware developer implemented this mechanism to evade memory scanning techniques that identify executable (RWX) code regions in memory. Finally, after the API hooks are installed and the Cobalt Strike Beacon shellcode has been written to the thread buffer, the malware calls the ResumeThread API to resume the suspended thread and begin execution of the beacon. Persistence mechanism While the analyzed SharkLoader implant does not contain a built-in persistence mechanism especially when it comes to cases when it is dropped after the exploitation of a public-facing application, our investigations revealed that the threat actor employs several techniques to maintain access to compromised systems. Registry Run key: In the incident that affected an organization in Hong Kong, the attacker manually created a registry Run key to launch SystemSettings.exe upon user logon. The following command was used: This technique allows the malware to automatically execute whenever the user logs in, ensuring persistent access. Scheduled task: In the separate compromise that affected a diplomatic government entity in Indonesia, the attacker established persistence through a scheduled task configured to execute SharkLoader daily. The task, named "\Microsoft\Windows\Edge\Edgeupdate", was configured to run C:\ADriveLogs_Logs\SystemSettings.exe by using the following command: Running the task with SYSTEM privileges ensures that SharkLoader executes even if no user is logged in. Post-compromise activity Following initial compromise and persistence, the attacker engaged in extensive reconnaissance and credential theft activities. System information enumeration: The attacker initially gathered basic system information by using the following commands: Post-exploitation tools: Our analysis revealed the use of several third-party post-exploitation tools, most of which are open-source and developed by Chinese-speaking developers. These tools included: We also detected the use of SharpGPOAbuse by the threat actor, a tool designed to modify Group Policy Objects within Active Directory environments. Active Directory enumeration: In the compromise affecting a diplomatic government entity in Indonesia, the attacker used both Cobalt Strike and a webshell to enumerate the internal Active Directory environment. They executed a series of commands to gather information about the network, users, and groups: Network information: User and group information: Specific group membership: Process enumeration: Directory listing: Credential dumping: The attacker also attempted to dump credentials from the compromised machine by targeting both the LSASS process and the NTDS database file. The following commands were observed: Dumping the LSASS process allows the attacker to extract in-memory credentials, while accessing the NTDS database enables retrieval of Active Directory account password hashes. This combination of techniques allows the attacker to obtain privileged credentials for lateral movement, privilege escalation, and deeper compromise. Victimology The victimology observed in this campaign shows a combination of strategic and opportunistic characteristics. Confirmed victims include government-related entities, such as the ministry in Taiwan and the diplomatic organization in Indonesia, as well as software development companies in Taiwan, Lebanon, and Syria. Additional affected organizations were identified in Hong Kong, Colombia, Macedonia, Nepal, and Serbia. Targeting of government and software development organizations may indicate a cyber-espionage objective, although our confidence remains low due to the limited post-compromise activity observed, which primarily consisted of credential access, system reconnaissance, and lateral movement. The compromise of government and software development organizations could indicate an interest in gathering political intelligence or intellectual property. At the same time, the use of SharkLoader and Cobalt Strike, alongside the exploitation of public-facing applications and malicious installers and droppers, suggests the attacker may also be opportunistically targeting vulnerable systems. The absence of clear evidence of data exfiltration thus far does not exclude this possibility, as Cobalt Strike’s file operation and data exfiltration modules could be employed at a later stage. Although the full scope of the campaign is not yet known, the combination of targeted and opportunistic activity suggests it should continue to be closely monitored. Attribution Our investigation reveals no code or infrastructure overlap linking SharkLoader to any existing threat actor at this time. The TTPs employed during the operation also do not align with those of known actors. However, analysis of the post-exploitation open-source tools used during the campaign revealed that several reconnaissance tools, including FScan, Searchall, and Pillager, were developed by individuals identified as Chinese speaking developers on GitHub. We assess StrikeShark to be a Chinese-speaking threat actor with low confidence. This assessment is based on limited indicators and should be considered preliminary. Further investigation is required to characterize this cluster more fully, and the possibility remains that other actors may also be utilizing these tools. Conclusion Our investigation discovered a previously undocumented intrusion cluster that we are tracking as StrikeShark. The StrikeShark campaign represents a sophisticated malware threat to entities worldwide. The use of SharkLoader to deploy Cobalt Strike, coupled with API hook installation to evade detection, demonstrates a significant level of technical expertise. The campaign’s broad targeting across sectors and geographic regions suggests a potential focus on espionage or information gathering. While the precise objectives remain under investigation, the combination of targeting government entities and software developers warrants heightened vigilance. Given that our visibility is limited to incidents observed through Kaspersky telemetry, we suspect the actual number of compromises may be significantly higher and extend beyond these victims as the threat actor actively used several exploitations of public facing application. Indicators of compromise Additional information about this activity, including indicators of compromise, is available to customers of the Kaspersky Intelligence Reporting Service. If you are interested, please contact [email protected]. C559CC68986933200FD5D9E4388E2F58 Installer B3352B42432DEDC4A519F011DC8B5D5A Dropper 24FCEBDEECBA65004FDB0923763D74FD Dropper 9C872A0D5D5A38950E8B9AC9B488BE3F SharkLoader DLL AA3086BE652C8B20B0B29B2730D57119 SharkLoader DLL A514D1BB62D7916475946FE7C07AC0AA Encrypted file 9CBD560F820C95D7C38342CD558CB5C6 Encrypted file connect-microsoft[.]com ms-record[.]com ms-record[.]top ms-tray[.]top
securelist.comJun 24, 2026extracted
China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance
Cybersecurity researchers have warned of a "resurgence and expansion" of JDY, a covert network associated with China-nexus state-sponsored threat actors. "The JDY botnet comprises over 1,500 SOHO [small office and home office] and IoT devices and operates as a centrally controlled, high-performance scanner used to discover, fingerprint, and continuously map exposed services at scale," Lumen's Black Lotus Labs said in a report shared with The Hacker News. JDY was first flagged as a cluster within another botnet codenamed KV-botnet in mid-December 2023. Primarily used for broader scanning against internet targets, the stealthy network comprising compromised SOHO routers, firewalls, and IoT devices has been put to use by Chinese hacking groups like Volt Typhoon. Following KV-botnet's takedown by the U.S. government in early 2024, the botnet operators began making behavioral changes to the network, with the second KV cluster largely going offline. It's suspected that the botnet is offered by the operators to various hacking outfits, while carrying out reconnaissance and targeting on their own. The latest findings from Black Lotus Labs show that the malware has expanded in scope to infect a broader range of devices and act as a conduit to feed "structured reconnaissance data" into a larger scanning ecosystem for follow-on target identification and exploitation. Specifically, the JDY cluster is being used to conduct targeted scanning and service fingerprinting with an aim to flag vulnerable infrastructure following public disclosures. This points to an industrialized reconnaissance effort, the results of which are leveraged by Chinese nation-state groups. This has been complemented by a growth in the botnet's size, which has surged from 650 bots at the start of January 2024 to more than 1,500 compromised devices. Most of the hacked nodes are located in the U.S. and Brazil, followed by Europe and Asia. Black Lotus Labs told The Hacker News that the cluster in Brazil is reflective of the fact that "we're seeing more and more botnets made up of Brazilian victims these days." Where previously the cluster primarily featured Cisco RV320 and RV325 routers, the present makeup of the botnet is a lot more diverse, including devices from Araknis, Mimosa Networks, Ubiquiti, Draytek, Hikvision, and Linksys. The vast majority of the victim devices are assessed to have reached end-of-life (EoL) with known vulnerabilities. Although the exact nature of the security flaws remains unclear, it's suspected to involve the following based on the specific device models that are being exploited - Cisco RV042 - Possibly vulnerable to flaws like CVE-2023-20118 DrayTek Vigor3900 Series - Possibly vulnerable to flaws like CVE-2022-32548 Araknis AN-300-RT-4L2W - Possibly vulnerable to flaws like CVE-2023-24738 Hikvision IP cameras - Possibly vulnerable to flaws like CVE-2021-36260 Linksys LRT224 - No known CVEs, but alleged zero-days have been sold on the dark web "The botnet's large number of U.S.-based SOHO/IoT devices enables the botnet operators to evade defenses and traditional IP-based controls, such as geofencing, IP reputation-based detection, and static blocklists," Black Lotus Labs said. "By distributing their scanning and reconnaissance activity across a wide range of IP addresses, the operators make it less likely that any single IP will be labeled as a scanner and blocked. Additionally, using compromised SOHO and IoT devices helps this activity blend in with legitimate user traffic." The architecture that powers the botnet is best described as layered: the operators use Tor nodes to manage infected infrastructure, including both the command-and-control (C2) and payload servers. The C2 servers direct the bots to perform targeted reconnaissance and system profiling, as opposed to indiscriminate scanning. Results of the scans are sent to central servers for ongoing intelligence gathering in an effort to further Chinese threat actors' objectives. Attack chains weaponize newly disclosed vulnerabilities in edge devices (e.g., CVE-2026-35616) to deliver a shell script dropper that checks if the malware is already active, and if not, proceeds to download the primary payload based on the detected processor architecture (e.g., mips, mips64, mipsel, or mipsel64). Once the malware is launched, it's deleted from disk. The malware that facilitates scanning and target reconnaissance is designed to fingerprint the host, receive scanning tasks from a central C2 server, carry out high-volume TCP, SSL, UDP, and ICMP-assisted probing, capture responses (TLS certificates, metadata, etc.), and report the results back to the dispatch server. The goal is to conduct infrastructure reconnaissance rather than exploitation. A noteworthy functionality of the malware is its ability to adapt its scanning methodology based on its privileges on the local system. If it can open a raw socket, an indication of root privileges, it initiates high-speed SYN scanning using custom-crafted TCP packets. If raw sockets are unavailable or if the task is a web scan, the scanning engine resorts to using standard TCP and TLS connections or employs protocols like UDP and ICMP. This activity most likely informs asset discovery, vulnerability-targeting pipelines, and downstream exploitation or attack-orchestration systems, the cybersecurity company said. "JDY demonstrates how IoT/SOHO botnets and covert networks of compromised devices are being used for rapid vulnerability exploitation," the company said. "JDY's growth and continued operation illustrate how modern reconnaissance networks persist despite takedowns and adapt as a durable capability within a broader adversary ecosystem." "JDY's evolution from a supporting component of the KV-botnet to an independent, high-performance reconnaissance capability demonstrates that disruption of individual nodes or clusters does not eliminate the underlying capability. The capability persists, adapts, and continues to provide adversaries with timely targeting data, often within hours of vulnerability disclosure." (The story was updated after publication to include additional insights from Lumen Black Lotus Labs.)
thehackernews.comJun 10, 2026extracted
China-linked JDY botnet expands targeting of U.S. military networks
The JDY botnet, a malware network previously associated with Chinese threat actors like Volt Typhoon, has significantly expanded its targeting scope and reconnaissance efforts. According to researchers at Black Lotus Labs by Lumen, who have been monitoring its activity, JDY maintains a strong focus on the United States, where many of its compromised devices are located and where it heavily targets military and associated networks. The security firm notes that JDY has grown from roughly 650 active bots in January 2024 to over 1,500 compromised SOHO and IoT devices today. While the numbers seem low, it's important to note that JDY isn't an exploitation framework or a DDoS botnet that requires large swarms to accumulate firepower, but is instead a distributed scanning and fingerprinting network that helps its operators locate targets vulnerable to newly disclosed flaws. "Analysis of this activity shows a clear focus on identifying vulnerable infrastructure shortly after public vulnerability disclosures, suggesting that reconnaissance output is rapidly operationalized by China-nexus advanced persistent threat (APT) actors," reads the Black Lotus Labs report. "This targeted focus has been observed across a range of sectors, with the U.S. military and associated entities as the most prominent." CISA has previously warned about the risk Volt Typhoon operatives pose to unprotected SOHO routers, urging network device vendors to eliminate vulnerabilities in SOHO router web management interfaces (WMIs) during the design and development phases. The JDY botnet is designed to conduct service discovery, service banner grabbing, TLS certificate collection, protocol fingerprinting, and flaw-focused reconnaissance. Among the compromised devices are those from Cisco, Araknis, Mimosa Networks, Ubiquiti, DrayTek, Hikvision, and Linksys, for MIPS, MIPS64, MIPSEL, and MIPSEL64 architectures. The threat actors are quick to target newly disclosed vulnerabilities, with Lumen researchers observing JDY scans targeting CVE-2026-35616 shortly after Fortinet publicly disclosed the FortiClient EMS flaw. The operators control the botnet through hidden Tor services, which also serve as command-and-control (C2) infrastructure. The open-source reverse-shell and host-management framework Platypus is also used in some cases. The malware registers with a central "Dispatch Service" and receives scanning assignments, which it executes, compresses the results, and sends them back to the C2. The scanning module supports the following: TCP scanning SSL/TLS scanning UDP scanning ICMP probing Banner collection TLS certificate harvesting Service fingerprinting using downloadable rule sets The botnet client repeats the same cycle until the operator specifically orders it to stop. The TCP scanning function is one of the most technically interesting, say the researchers, explaining that, when JDY has sufficient privileges, it performs much faster and stealthier raw SYN scanning. "If the malware can open a raw socket, which generally requires root or administrative privileges, it initiates high-speed SYN scanning using custom-crafted TCP packets," explains the report. "These custom packets use a fixed source port of 19000, increment the destination ports one at a time, and batch-process thousands of scan targets." As JDY botnet activity increases, organizations should ensure routers, firewalls, and IoT devices are running the latest security updates and patches to prevent them from being recruited into reconnaissance networks. Defenders should also reduce their external attack surface by disabling unnecessary internet-exposed administrative interfaces, restricting remote management access, replacing default credentials, and monitoring for unusual outbound scanning activity originating from edge devices. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJun 10, 2026extracted
Week in review: Cisco SD-WAN 0-day exploited, Patch Tuesday forecast
Week in review: Cisco SD-WAN 0-day exploited, Patch Tuesday forecast Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: OWASP Agent Memory Guard: Stop AI agents from being weaponized through their own memory Agent Memory Guard is an open-source runtime defense layer that sits between an agent and its memory store, screening every read and write through a pipeline of detectors and a YAML policy. The project is the OWASP reference implementation for ASI06, Memory Poisoning, one entry in the OWASP Top 10 for Agentic Applications. Data discovery gaps that catch enterprises off guard In this interview with Help Net Security, Avani Desai, CEO at Schellman, talks about the gap between what organizations think they know about their data and what discovery scans turn up. She shares stories of shadow data in abandoned cloud storage, post-merger surprises where duplicated datasets slowed integration, and why synthetic data is overmarketed while confidential computing stays underappreciated. Zero trust physical security needs trust decisions at the edge In this interview with Help Net Security, Chuck Davis, VP, Global Information Security at Hikvision, explains how zero trust applies to physical security systems like cameras and door controllers. He breaks down how to make trust decisions at the edge without recreating old perimeter assumptions, why these devices should be treated as IT assets, and what the Mirai botnet taught the industry. A small Slovenian team handles 6,000 cyber incidents a year Online fraud complaints, ransomware cases, and phishing tips reach Slovenia’s national cyber response center in steady volume, and a team of around a dozen analysts sorts through them. Gorazd Božič, who manages SI-CERT at the public agency ARNES, described that work in an interview conducted in person at the Span Cyber Security Arena conference. He put the original proposal for a Slovenian CERT to ARNES leadership in 1994, and the center now records about 6,000 incidents a year, up from roughly 300 ten to fifteen years earlier. Only 11% of production agents pass the AI agent security bar Enterprise teams are running AI agents that write code, drive browsers, answer customer calls, manage cloud infrastructure, and query data warehouses with standing credentials. A new independent assessment of 100 production agents finds that nearly all of them carry the conditions for a single hostile document to take them over. Spotless compliance evidence can still hide a broken control In this interview with Help Net Security, Marc Rubbinaccio, Head of Cybersecurity and Compliance at Secureframe, explains where security teams go wrong when preparing for CMMC and FedRAMP 20x. The conversation covers how organizations check the 110 requirements but miss the 320 assessment objectives beneath them, why spotless SOC 2 evidence can hide a broken control, and how continuous monitoring is changing compliance work. OAuth marketplace apps keep access after publishers vanish Installing an app from the Google Workspace Marketplace or GitHub Marketplace can grant a third party access to company email, files, calendars, code repositories, CI workflows, organization settings, and secrets. Marketplace presence gives these apps the appearance of approval. The OAuth grants behind them often reach into business systems beyond the listed function. Thieves can pull off keyless car theft in under a minute and here’s how to stop them A keyless car can be stolen in under a minute. Two people, a pair of cheap radio amplifiers, and a fob sitting on a hallway table inside the house. That is enough. No broken glass. No alarm. No sound. The vulnerability runs across the global market. Germany’s largest auto club, ADAC, runs ongoing tests of keyless models against relay attacks. AgentGG: Open-source agentic SAST scanner Static analysis tools have spent years matching source code against known-bad patterns and handing engineers long lists of candidate issues to triage by hand. AgentGG approaches the same job with AI agents that read the code, follow imports, walk the call graph, and confirm a finding before they report it. The project is an open-source agentic SAST scanner released under the Apache 2.0 license. Hackers are exploiting Palo Alto GlobalProtect VPN authentication bypass (CVE-2026-0257) Authentication bypass vulnerabilities (CVE-2026-0257) in Palo Alto Networks’ firewalls that the company disclosed on May 13 have been targeted in “limited exploit attempts”. The good news, though, is that the company hasn’t observed any indication of successful lateral movement from the devices. How NIST fumbled management of the National Vulnerability Database A US federal watchdog has outlined how the National Institute of Standards and Technology (NIST) failed to effectively manage the growing backlog of unprocessed cybersecurity vulnerabilities in the National Vulnerability Database (NVD). Windows Netlogon RCE exploited, domain controllers at risk (CVE-2026-41089) CVE-2026-41089, a critical Windows Netlogon RCE flaw that allows remote code execution, is now actively exploited in the wild, the Centre for Cybersecurity Belgium (CCB) warned last Friday. CVE-2026-41089 is a stack-based buffer overflow vulnerability in Windows Netlogon, the service and protocol that handles authentication and security within a Windows domain environment. Google fixes actively exploited Android vulnerability (CVE-2025-48595) Google has announced the June 2026 Android security updates, which fix a bucketload of vulnerabilities, including a high-severity vulnerability (CVE-2025-48595) in the Android Framework that “may be under limited, targeted exploitation.” Autonomous AI-driven worm can reason its way through corporate networks Researchers at the University of Toronto, the Vector Institute, and the University of Cambridge have built and tested a proof-of-concept AI-driven worm that does not operate on a fixed list of exploits. Instead, it analyzes each target it encounters, reasons about how to attack it, and creates a strategy on the fly, all with the help of a small, free large language model (LLM) running directly on machines it has already compromised. Cisco SD-WAN 0-day exploited, no patch available (CVE-2026-20245) A 0-day privilege escalation vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager that has yet to be patched by Cisco is being leveraged by attackers. June 2026 Patch Tuesday forecast: Where are the CVEs? Forecast from last month was only partly right. After the Anthropic Mythos announcements and the deluge of newly discovered vulnerabilities from vendors like Mozilla, Microsoft’s updates were standard fare, 65 CVEs reported in Windows 11 and 58 in Windows 10. The modern-day business can learn a lot about risk from this year’s mega events Every year brings its share of global events, but 2026 is proving to be a banner year for mega-scale entertainment. The year got off to a roaring start with the Winter Olympics, and now anticipation is building for the fast-approaching FIFA World Cup. But amid the buzz, have you ever paused to consider the staggering level of risk inherent to such large-scale events? Or how impressive it is that organizers are able to manage that risk so successfully? From critical to controlled: Cutting vulnerabilities in a live manufacturing environment A vulnerability scanner flags a critical CVSS 10 vulnerability on an industrial asset. The report lands in the boss’ inbox and now he wants to know why we’re sitting on a critical vulnerability. In a normal IT environment, you patch it then close the ticket and call it a day. If, however, you’re in OT or dealing with ICS in a live manufacturing facility, it’s rarely that simple. Why you need BAS and autonomous pentesting together A new autonomous penetration testing tool delivers impressive results at first—finding critical issues, uncovering undocumented attack paths, and exposing forgotten accounts. But by the fourth or fifth run, the discoveries dry up. The tool keeps reporting the same stale issues, and the dashboard becomes another source of noise. What seemed like continuous validation quietly turns into a repeat of the same well-worn attack paths. Governing shadow AI without killing innovation In this Help Net Security video, Alan Snyder, CEO at NowSecure, talks about governing shadow AI without stopping innovation. He frames the problem as two opposing forces. Companies need to adopt AI fast because attackers and competitors will outpace them otherwise, but they also need to do it safely. What CISOs need to do about post-quantum migration in the next 24 months In this Help Net Security video, Garfield Jones, SVP Global Strategy and Research, QuSecure, lays out what CISOs should do over the next 24 months. A recent Google paper moved the expected arrival of a cryptographically relevant quantum computer from 2035 to 2029, leaving organizations about two and a half years to prepare. AI agent governance gets harder when agents outnumber your people In this Help Net Security video, Amit Gautam, CTO at Abluva, explains the security risks that autonomous AI agents bring into enterprise environments. EU organizations buckle under rising compliance pressure Cybersecurity governance in the EU is shifting under expanding frameworks such as NIS2 and DORA, while AI raises new questions for security teams. What the future brings is hard to predict, and organizations must find a way to cope. Antonija Vojnović, Governance, Risk and Compliance Department Manager at Span, spoke with Help Net Security at the Span Cyber Security Arena conference about how these regulatory frameworks are shaping compliance priorities and day-to-day decision-making. DNS-AID lets AI agents find and verify each other through DNS AI agents run across many platforms, and each one needs a way to locate and confirm the identity of the others it works with. The Linux Foundation’s DNS-AID project gives them that capability through the Domain Name System, the same address lookup system that has directed internet traffic for decades. The project lets AI agents and Model Context Protocol (MCP) servers use DNS as a global, vendor-neutral directory for publishing, discovering, and verifying one another. Brute-force attack triggers Dashlane account lockouts Password manager Dashlane has confirmed that a brute-force attack targeting user accounts triggered temporary account suspensions and authentication issues. The company first acknowledged the incident on May 31 after users reported receiving account suspension emails and experiencing login problems. Meta tries to get ahead of scammers before the World Cup begins Football fans are counting down the days until the FIFA World Cup begins, and scammers are doing the same. Last week, the FBI warned that cybercriminals are spoofing FIFA websites to steal personal information, sell fake tickets, and promote fraudulent hospitality packages ahead of the tournament. Sensitive government personnel data posted online, Spanish police arrest suspect The Spanish National Police arrested a man in Granada for allegedly leaking personal data belonging to members of several sensitive state institutions. 64,000 accounts exposed in breach of GTA V cheat service Atlas Menu Atlas Menu, a cheat service for Grand Theft Auto V and Counter-Strike 2, has been added to the Have I Been Pwned database following a data breach that exposed tens of thousands of user records. The incident exposed approximately 64,000 accounts, including email addresses, usernames, IP addresses, support tickets, and passwords hashed with bcrypt. Anthropic expands Project Glasswing to 150 organizations in more than 15 countries Anthropic is expanding Project Glasswing, its cybersecurity initiative built around the Claude Mythos Preview model, by adding about 150 organizations following several weeks of work with its initial group of partners, security firms, open-source maintainers, and government agencies. Malware campaign targeting Minecraft users infects over 116,000 systems A Malware-as-a-Service (MaaS) operation named WeedHack is targeting Minecraft users and allows threat actors to gain remote access to victims’ screens, webcams, and files through a web-based dashboard, McAfee researchers found. Microsoft responds to security challenges facing code, AI agents, and models Microsoft has introduced a series of security tools and capabilities focused on AI-driven vulnerability discovery, AI agents, and AI models. The updates include a multi-agent vulnerability discovery system, new controls for managing and securing AI agents, data protection capabilities, and tools designed to identify potentially vulnerable or compromised AI models before deployment. AI is helping low-skill hackers pull off advanced cyberattacks Anthropic has published an analysis of cyber-related misuse of its AI systems, examining 832 accounts that were banned for malicious cyber activity between March 2025 and March 2026. The company mapped the observed behavior to the MITRE ATT&CK framework, which documents tactics and techniques used by attackers. Attackers obtained encrypted password vaults from some Dashlane user accounts Dashlane has disclosed new details about a brute-force attack that let a threat actor access some customer accounts and copy encrypted vaults. Dashlane said it found no evidence that the attackers compromised its internal systems. The company first acknowledged the incident on May 31 after users reported receiving account suspension emails and experiencing login problems. 145 AI laws passed in 2025 and privacy teams aren’t catching a break 145 AI-related laws were enacted by state legislatures in 2025, and more than 1,000 additional bills were introduced or revised, according to DataGrail’s Privacy and AI Trends Report 2026. NVIDIA goes open source with a big batch of physical AI agent tools NVIDIA just dropped a big batch of open-source “physical AI” skills and tools, and they’re designed to make a roboticist’s life a whole lot easier. The idea? Take the messy, complicated work behind robots, self-driving cars, vision AI, and industrial digital twins, and break it into bite-sized tasks that AI agents can actually run themselves. Microsoft Defender Vulnerability Management gets a smarter exposure score Microsoft Defender Vulnerability Management’s updated exposure score model adds vulnerability risk signals and asset context to help teams understand where risk is concentrated and which remediation actions are likely to have the greatest impact. The model is available in public preview. This AI model backdoor attack stays hidden until you customize the model Most teams that deploy AI start with a backbone model. They download a large pre-trained system, adapt it to a specific task, and put it into production. The download step carries a security question: the origin of the model. A research team built an attack called BadBone. It plants a backdoor inside a backbone model. Downstream tasks that adapt the model inherit the backdoor. The name points at the target. Corrupt the skeleton, and systems built on top of it carry the flaw. OpenAI brings frontier AI to existing AWS environments OpenAI frontier models and Codex are now available on AWS, giving customers access to OpenAI capabilities within AWS environments and the controls needed to move more quickly from evaluation to deployment. These capabilities are available through OpenAI models on Amazon Bedrock, a platform for building generative AI applications and agents at production scale. The platform enables teams to build AI applications using AWS-native security and governance controls. KDE Linux security audit cuts kernel modules and unused packages KDE Linux, the in-progress operating system from the KDE community, removed several kernel modules and software packages after a security audit of the components shipped with the system. The work followed the discovery of multiple security issues in the upstream Linux kernel during the prior month. Codex knowledge work expands into research, reports, and spreadsheets Office workers in the United States lose hours each week to email triage and to searching for files spread across disconnected systems. Roughly 40 percent of US labor, about 72 million people, works primarily with information such as analysis, documents, designs, and communication. Research from the McKinsey Global Institute puts the average knowledge worker at 28 percent of the workweek on email and close to 20 percent on hunts for internal information or for colleagues who can help with specific tasks. Meta adds stricter guardrails for teen feeds Meta has expanded its Teen Accounts 13+ content settings globally on Instagram, Facebook, and Messenger. The safeguards are designed to help young users see age-appropriate content by default. The company also introduced Limited Content on Instagram for parents seeking stricter restrictions. Meta plans to roll out the feature on Facebook and Messenger later this year. Known vulnerabilities behind most application security incidents Eight in ten organizations took an application security hit during the past year tied to a vulnerability their team had already cataloged, according to a survey of 902 IT and security professionals conducted by the Cloud Security Alliance. The pattern points to a structural condition across the industry, where the window between identifying a flaw and closing it in production stays open long enough for attackers to act. Agent Threat Rules: Open detection rule format for AI agent security threats AI agents run inside coding assistants, MCP servers, and multi-agent frameworks, and the access that makes them useful also opens paths to prompt injection, tool poisoning, and credential theft. Public CVE feeds carry agent-execution flaws that reach production faster than the tooling built to catch them. Agent Threat Rules, or ATR, is an open detection format aimed at this category of attack. Microsoft Scout agent opens a new category of always-on Autopilots Workplace AI assistants have mostly waited for a prompt before doing anything. A user asks, the tool answers, and the exchange ends there. Microsoft is putting a different kind of agent inside its Office applications, one designed to keep operating in the background once a person stops paying attention. The company introduced Microsoft Scout, calling it the first entry in a category it labels Autopilots. New Android feature promises to spot deepfake scam calls Android is introducing fake call detection to help protect users from impersonation scams. The feature can detect and flag suspected spoofed calls when both parties use Phone by Google on Android 12 or later. It will roll out globally this month, starting with Pixel devices. ETSI sets security requirements for AI data centers and cloud platforms ETSI has published TS 104 033, a technical specification that defines security requirements for AI computing platforms. The specification establishes a security framework for platforms used to host AI applications in data center and edge computing environments, covering security functions, platform components, interfaces, and services designed to protect AI models, datasets, training processes, and inference workloads. Product showcase: Trend Micro Mobile Security detects scams in messages, QR codes, and websites Trend Micro Mobile Security for iOS protects devices from potentially harmful websites while browsing, blocks ads and personal information trackers, helps users avoid unsafe Wi-Fi networks, and monitors data usage. The app is available for both iOS and Android devices. Most pros have seen AI hallucinations in IT operations Autonomous AI is taking action inside enterprise IT environments. Software is restarting services, isolating risky devices, and applying patches without waiting for a human to approve the step. The capability is spreading at the same time IT professionals are reporting frequent encounters with AI output errors that can carry operational impact. Let’s Encrypt works toward post-quantum certificates at web scale Let’s Encrypt plans to pursue a post-quantum-safe Web PKI through Merkle Tree Certificates (MTCs), a new approach that adds post-quantum authentication to the web without sacrificing the speed and reliability that have made TLS universal. The project is targeting late 2026 for a staging environment that issues MTCs, with a production-ready environment planned for 2027. Photos: Infosecurity Europe 2026 Infosecurity Europe 2026 is a cybersecurity event that took place from June 2 to 4 in London. Help Net Security was on-site and here’s a closer look at the conference. Attackers already know the secrets are on your developers’ machines. Do you? In a recent GitGuardian analysis, an average of 150 secrets were found on a sample of developer endpoints. Private keys accounted for 38% of unique secrets, while cloud, identity provider, and secret management credentials (AWS IAM, Hashicorp vault) added another 22%. Simplify security management with CIS SecureSuite Platform CIS SecureSuite Membership simplifies the process with tools, benefits, and resources for implementing the secure recommendations of the CIS Benchmarks. With the release of CIS SecureSuite Platform, it’s now even easier for Members to harden their systems. Cybersecurity jobs available right now: June 2, 2026 We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now. New infosec products of the week: June 5, 2026 Here’s a look at the most interesting products from the past week, featuring releases from Asimily, depthfirst, Diligent, Hyland, MazeBolt, and Noma.
helpnetsecurity.comJun 7, 2026extracted
Zero trust physical security needs trust decisions at the edge
Zero trust physical security needs trust decisions at the edge In this interview with Help Net Security, Chuck Davis, VP, Global Information Security at Hikvision, explains how zero trust applies to physical security systems like cameras and door controllers. He breaks down how to make trust decisions at the edge without recreating old perimeter assumptions, why these devices should be treated as IT assets, and what the Mirai botnet taught the industry. Davis also covers posture assessment for devices that cannot run standard agents, and how to manage device identity and revoke trust across tens of thousands of endpoints during a live incident. Zero trust orthodoxy says “never trust, always verify,” but a physical security system has a brutal constraint: a 200-millisecond door unlock decision cannot wait for a cloud-based policy engine experiencing latency. How do you architect trust decisions at the edge without quietly reintroducing the perimeter assumptions you are trying to eliminate? One of the biggest misconceptions about zero trust is the assumption that every authorization decision must travel to a centralized policy engine in real time. I hear this used regularly as a reason to carve out physical security systems from zero trust architecture entirely, as if the 200-millisecond constraint on a door controller is somehow an exemption from sound security principles. It is a design constraint, and there is a well-established architecture for meeting it without abandoning the core zero trust principle that nothing should be trusted just because of where it sits on the network. Zero trust does not require centralized decision execution. It requires centralized trust governance. Those are different things, and keeping them straight is what makes edge enforcement work. The model I prefer in this situation, is distributed trust with centralized policy. Policy creation, identity governance, and authorization logic stay centralized. Enforcement happens locally at the edge, where latency and operational continuity actually matter. The architecture that enables this separates the Policy Decision Point (PDP) from the Policy Enforcement Point (PEP). The PDP determines whether access should be granted based on identity, context, policy, and risk signals. The PEP, which lives on the edge controller or access device, executes that decision locally. The door opens in well under 200 milliseconds. The policy governing that decision was authored, validated, and pushed from a centralized system. The critical detail is that local enforcement does not mean local trust. Edge devices should operate against cryptographically signed policies with short-lived credentials and well-defined access boundaries. Policies are distributed and cached locally, but remain governed centrally, refresh on a defined cadence, and are subject to revalidation. A controller should never be trusted simply because it sits inside a particular VLAN or building network. That is the old perimeter security model in disguise, and it has a way of quietly creeping back into zero trust architectures if you are not deliberate about keeping it out. This is where organizations get into trouble operationally. You start with a well-designed architecture and a 90-second policy cache lifetime. Then a network hiccup causes a door to fail to unlock and someone submits a facilities ticket. Rather than fixing the underlying network reliability issue, the security team extends the cache lifetime to avoid receiving another complaint. Ninety seconds becomes 30 minutes, becomes four hours, becomes a 12-hour offline grace period. At that point you no longer have zero trust at the edge. You have a slowly drifting perimeter, and nobody documented it as a security decision because it happened one exception at a time. The architecture also requires a deliberate answer to the fail-safe versus fail-secure question, and the answer is not the same for every door. Emergency egress systems are often designed to prioritize availability and life safety, so they should default open under degraded network conditions. Highly restricted environments may require the opposite. Those outcomes need to be explicit architectural decisions, not accidental side effects of a dropped network connection. Ultimately, zero trust is not about routing every decision through the cloud. It is about ensuring that wherever decisions are made, they are identity-aware, constrained, continuously validated, and revocable. The 200-millisecond door controller is not an exception to that principle. It is just a particularly clear illustration of why the architecture has to be designed for the environment it operates in. A Hikvision device sits at a fascinating intersection: it is simultaneously an IoT endpoint, a data processor, and a physical actuator. When you are conducting a threat model for a customer’s environment, which of those three identities generates the most dangerous blind spots, and can you walk us through a real scenario where that blind spot was exploited? The framing of your question assumes organizations are actively managing all three of those identities and just getting one wrong. The more common challenge across the industry is that the foundational shift has not fully taken hold yet: physical security devices are still not universally treated as the IT assets they are. There is a tendency to think of physical security equipment only in terms of its physical purpose. A camera is a camera. A badge reader is a badge reader. An NVR is a recording appliance. That framing shapes everything downstream: how the devices are inventoried, how they are maintained, and how cyber risk for those systems gets assigned across the organization. The moment a physical security device connects to a network, it becomes something else entirely. It becomes an embedded compute platform running an operating system, authentication services, APIs, a web interface, a database, encryption functions, and remote management capabilities. When physical security and IT operate in separate silos, that risk often falls into the gap between them. That gap is where the blind spots live. The scenario that brought this into sharp focus for the broader security industry was the Mirai botnet in 2016. Mirai’s operators scanned the internet for IoT devices, including large numbers of IP-connected security cameras and DVRs, and compromised them at scale by logging in with factory credentials that had never been changed. No zero-day exploits. No sophisticated tradecraft. Those compromised cameras were recruited into a botnet used to launch some of the largest distributed denial-of-service attacks ever recorded, including the October 2016 attack against Dyn that took down Twitter, Reddit, Netflix, and large portions of internet infrastructure for hours. What made Mirai so damaging was not the sophistication of the attack. It was that the industry had not yet established consistent standards for how these devices should be deployed and secured. Devices were internet-exposed without firewall protection. Security hardening guidance was inconsistent or absent. Network monitoring on physical security segments was rare. Mirai exposed the gap between how these devices were being deployed and how they needed to be managed as networked IT assets. That is the blind spot. Not a sophisticated attack against a complex threat model. Internet-exposed cameras, running factory defaults, with likely nobody watching the traffic they were generating. Most of these controls are not novel. The challenge is operational discipline. Isolate physical security devices on their own network segment. Place them behind a firewall with no direct inbound access from the internet. Keep firmware current. Follow manufacturer hardening guidance. If remote access is required, use a VPN or zero trust network access solution. If an attacker cannot reach your security camera, they cannot attack it. Physical security infrastructure is enterprise IT infrastructure. The most important architectural shift is recognizing it as such and managing it accordingly. Firmware is the soft underbelly of physical security devices. What does a zero trust posture assessment look like for a camera or access reader that cannot run an EDR agent, cannot be patched during business hours, and may have a seven-year depreciation cycle baked into a facilities budget? A mature zero trust assessment for these environments starts by accepting an uncomfortable reality: many physical security devices will never achieve the same security telemetry or control depth as enterprise laptops and servers. Trying to force traditional IT security assumptions onto them leads to frustration and poor risk decisions. The goal is not perfect visibility. The goal is risk reduction through compensating controls. The concept I find most useful here is what I call the trust envelope. Rather than trying to instrument the device directly, you define and enforce a boundary of acceptable behavior around it. What should this device communicate with? Which protocols? How often? At what volume? That profile, captured through network telemetry from adjacent infrastructure, becomes your posture proxy. A camera that should only communicate with a local video management server should not be initiating outbound connections to unfamiliar infrastructure. Anything outside the envelope is worth investigating. On the device side, the assessment should focus on what you can actually validate. Secure boot and signed firmware verification provide stronger assurance that the device is running what it is supposed to be running. A software bill of materials (SBOM) gives you the component-level inventory you need to know when a vulnerability in a third-party library inside that firmware actually affects you. I would take that a step further and argue that a network bill of materials (NetBOM), a structured inventory of what devices exist, their expected communication patterns, and their approved network dependencies, is equally important. Without that foundation, you are making security assertions against an unknown baseline. Surrounding the device, least-privilege networking does the heavy lifting when endpoint controls are unavailable. Segmentation, deny-by-default firewall rules, and tightly scoped management access through dedicated out-of-band networks collectively limit what an attacker can do even if a device is fully compromised. You may not be able to see inside the box, but you can control what the box can reach and who can reach it. Lifecycle governance is where many organizations fall short. Facilities budgets assume seven to ten years of operational use. Security expectations move considerably faster. That gap widens quietly until a device that still functions perfectly well is running firmware nobody is updating anymore. At that point it stops being a technical problem and becomes a business risk decision. Replacement thresholds, vulnerability disclosure monitoring, and procurement standards tied to vendor support commitments all need to be part of the assessment framework from the start. The real maturity test is whether the organization can detect a compromise quickly, isolate the affected device cleanly, and keep it from becoming something larger. Identity for human users is hard enough. For physical security devices, you are dealing with device identity at scale, sometimes tens of thousands of endpoints in a single campus deployment. What does credential compromise look like when the “user” is a PTZ camera, and how do you revoke trust from a device that is bolted to a ceiling in a restricted zone during a live incident? Identity for human users is hard enough. Device identity at scale is a different problem entirely, and the physical security environment makes it harder in ways that do not get enough attention. A campus deployment managed with shared credentials or static API keys is not a device identity program. It is an asset list with false confidence attached to it. Shared credentials do not compromise the way a human account does. There is no failed login from an unusual location, no suspicious authentication time, no behavioral anomaly a security team can correlate against a user profile. Few environments have written detection rules for a PTZ camera behaving like an authenticated user account. What credential compromise looks like for a physical security device is more subtle. Configuration changes initiated from unexpected management sources. Outbound connections to destinations outside the device’s established communication baseline. Firmware version mismatches against what the asset inventory says should be running. Authentication attempts to the management plane from IP addresses that are not the designated controller. None of those are exotic indicators. They are just indicators that most physical security environments are not actively watching for. The scale problem compounds everything. When thousands of devices share a credential pool, a single compromise does not affect one device. It potentially affects all of them, and you may have no clean way to determine which ones were accessed or what was done. The architecture that makes this manageable is individual device certificates issued from an enterprise PKI with automated enrollment and renewal. One certificate per device. Defined lifetime. Automated renewal. A device that fails to renew, or whose certificate is explicitly revoked, loses authenticated access. Certificate support varies significantly across manufacturers, ranging from basic certificate import through a web interface all the way to full automated lifecycle management with SCEP enrollment, OCSP revocation, and API-driven certificate rotation. Those are not the same thing, and procurement teams should ask specifically which capabilities a device supports before assuming enterprise PKI integration is possible. Identity without automated rotation eventually becomes credential management debt. Certificate lifecycle automation may become an increasingly important differentiator in physical security procurement. The groundwork for revocation has to be laid before an incident, not during one. The authorization to execute isolation actions needs to be pre-granted. The network hooks need to be pre-configured. The mapping from every device to its switch port, VLAN, and management controller needs to exist in the asset inventory before something goes wrong. When that preparation is in place, quarantining a compromised device becomes a VLAN reassignment or an ACL update from the network access control platform, executed remotely in under a minute without dispatching anyone to the physical location. Where certificate-based identity is deployed, revocation can close authenticated sessions quickly, though the speed depends on whether the environment uses real-time OCSP checking or CRL-based revocation. Device identity at scale requires deliberate architecture, tested processes, and clear ownership. The time to build that foundation is before an incident makes it urgent.
helpnetsecurity.comJun 2, 2026extracted
Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flaws
Ivanti, Fortinet, n8n, SAP, and VMware have released security fixes for various vulnerabilities that could be exploited by bad actors to bypass authentication and execute arbitrary code. Topping the list is a critical flaw impacting Ivanti Xtraction (CVE-2026-8043, CVSS score: 9.6) that could be exploited to achieve information disclosure or client-side attacks. "External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a web directory, leading to information disclosure and possible client-side attacks," Ivanti said in an advisory. Fortinet published advisories for two critical shortcomings affecting FortiAuthenticator and FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS that could result in code execution - CVE-2026-44277 (CVSS score: 9.1) - An improper access control vulnerability in FortiAuthenticator that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. (Fixed in FortiAuthenticator versions 6.5.7, 6.6.9, and 8.0.3) CVE-2026-26083 (CVSS score: 9.1) - A missing authorization vulnerability in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS WEB UI that may allow an unauthenticated attacker to execute unauthorized code or commands via HTTP requests. (Fixed in FortiSandbox versions 4.4.9 and 5.0.2, FortiSandbox Cloud version 5.0.6, and FortiSandbox PaaS versions 4.4.9. and 5.0.2) SAP also shipped fixes for two critical vulnerabilities - CVE-2026-34260 (CVSS score: 9.6) - An SQL injection vulnerability in SAP S/4HANA CVE-2026-34263 (CVSS score: 9.6) - A missing authentication check in the SAP Commerce cloud configuration "The vulnerability is caused by an overly permissive security configuration with improper rule ordering, allowing an unauthenticated user to perform malicious configuration upload and code injection, resulting in arbitrary server-side code execution," Onapsis said about CVE-2026-34263. On the other hand, CVE-2026-34260 could be exploited by an attacker to inject malicious SQL statements and potentially impact the confidentiality and availability of the application. However, since the affected code only allows read access to data, the vulnerability does not compromise the integrity of the application. "It allows a low-privileged, authenticated attacker to inject malicious SQL code via user-controlled input, potentially exposing sensitive database information and crashing the application," Pathlock said. Patches have also been released by Broadcom for a high-severity flaw in VMware Fusion (CVE-2026-41702, CVSS score: 7.8) that could pave the way for local privilege escalation. The issue has been addressed in version 26H1. "VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary," Broadcom said. "A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system where Fusion is installed." Round off the list is a set of five critical vulnerabilities impacting n8n - CVE-2026-42231 (CVSS score: 9.4) - A vulnerability in the xml2js library used to parse XML request bodies in n8n's webhook handler that allows prototype pollution via a crafted XML payload, enabling an authenticated user with permission to create or modify workflows to achieve remote code execution on the n8n host. (Fixed in n8n versions 1.123.32, 2.17.4, and 2.18.1) CVE-2026-42232 (CVSS score: 9.4) - An authenticated user with permission to create or modify workflows could achieve global prototype pollution via the XML Node, leading to remote code execution when combined with other nodes exploiting the prototype pollution. (Fixed in n8n versions 1.123.32, 2.17.4, and 2.18.1) CVE-2026-44791 (CVSS score: 9.4) - A bypass for CVE-2026-42232 that could result in remote code execution on the n8n host. (Fixed in n8n versions 1.123.43, 2.20.7, and 2.22.1) CVE-2026-44789 (CVSS score: 9.4) - An authenticated user with permission to create or modify workflows could achieve global prototype pollution via an unvalidated pagination parameter in the HTTP Request node, leading to remote code execution on the n8n host. (Fixed in n8n versions 1.123.43, 2.20.7, and 2.22.1) CVE-2026-44790 (CVSS score: 9.4) - An authenticated user with permission to create or modify workflows could inject CLI flags on the Git node's Push operation, enabling an attacker to read arbitrary files from the n8n server and resulting in full compromise. (Fixed in n8n versions 1.123.43, 2.20.7, and 2.22.1) Software Patches from Other Vendors Security updates have also been released by other vendors over the past several weeks to rectify various vulnerabilities, including - ABB Adobe Amazon Web Services AMD Apple ASUS Atlassian Axis Communications AVEVA Canon Cisco CODESYS ConnectWise Dell Devolutions Drupal F5 Fortra Foxit Software Fujitsu GitLab GnuTLS Google Android and Pixel Google Chrome Google Cloud Grafana Hikvision Hitachi Energy Honeywell HP HP Enterprise (including Aruba Networking and Juniper Networks) Huawei IBM Intel Jenkins Lenovo Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Meta WhatsApp Microsoft Mitel Mitsubishi Electric MongoDB Moxa Mozilla Firefox, Firefox ESR, and Thunderbird NVIDIA OPPO Palo Alto Networks Phoenix Contact Phoenix Technologies Progress Software QNAP Qualcomm React Ricoh Samsung Schneider Electric Siemens Sophos Spring Framework Supermicro Synology Tenable TP-Link WatchGuard Zoom, and Zyxel
thehackernews.comMay 18, 2026extracted
FBI Warns of Data Security Risks From China-Made Mobile Apps
The FBI issued an alert on Tuesday warning users about the data security risks associated with foreign-developed mobile applications. The alert says many of the top-grossing and most-downloaded apps in the US are created by foreign companies, particularly those from China. The agency pointed out that apps maintaining digital infrastructure in China are subject to local laws, and the Chinese government could gain access to the data of mobile app users. The FBI’s alert does not name any specific applications, but prominent examples include TikTok and the shopping apps Shein and Temu — all widely used in the United States. The DeepSeek AI chatbot also fits the profile. US authorities have taken action against TikTok, Temu, and DeepSeek over national security or data security concerns. TikTok, which is used by more than 200 million Americans, recently finalized a deal to create a new entity that would help it avoid a ban in the United States. The FBI’s new alert warns users that the risky apps could collect their personal information, store user data in China, and some may even contain malware. “This could include malicious code and hard-to-remove malware designed to exploit known vulnerabilities in various operating systems and insert a backdoor for escalated privileges, such as enabling the download and execution of additional malicious packages designed to provide unauthorized access to users’ data,” the alert reads. The FBI has advised individuals to report suspicious activity related to foreign apps to the agency’s Internet Crime Complaint Center (IC3). This comes shortly after the FCC announced a ban on the acquisition of new consumer routers made outside the United States. Related: Cybersecurity Firms React to China’s Reported Software Ban Related: Canada Gives Hikvision the Boot on National Security Grounds Related: Google Disrupts Chinese Hackers Targeting Telecoms, Governments
securityweek.comApr 1, 2026extracted
⚡ Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple Forces U.K. Age Checks and More
Some weeks are loud. This one was quieter but not in a good way. Long-running operations are finally hitting courtrooms, old attack methods are showing up in new places, and research that stopped being theoretical right around the time defenders stopped paying attention. There's a bit of everything this week. Persistence plays, legal wins, influence ops, and at least one thing that looks boring until you see what it connects to. All of it below. Let's go. ⚡ Threat of the Week Citrix Flaw Comes Under Active Exploitation — A critical security flaw in Citrix NetScaler ADC and NetScaler Gateway (CVE-2026-3055, CVSS score: 9.3) has come under active exploitation as of March 27, 2026. The vulnerability refers to a case of insufficient input validation leading to memory overread, which an attacker could exploit to leak potentially sensitive information. Per Citrix, successful exploitation of the flaw hinges on the appliance being configured as a SAML Identity Provider (SAML IDP). Your Engineers Are Drowning in Tools — Here's the Data Chainguard surveyed 1,200 engineers and tech leaders for their 2026 Engineering Reality Report. AI is buying back time but also introducing new security concerns, while technical debt, tool sprawl, and burnout keep dragging teams down. 72% say time pressure blocks new feature work; 88% report productivity loss from too many tools. Get the Full Report ➝ 🔔 Top News FBI Confirms Hack of Director Kash Patel's Personal Email Account — The U.S. Federal Bureau of Investigation (FBI) confirmed that threat actors gained access to an email account belonging to FBI Director Kash Patel, but said no government information has been compromised. The Iran-linked hacker group Handala claimed responsibility for the hack, releasing files allegedly representing photos, emails, and classified documents taken from the FBI director's inbox. "The so-called 'impenetrable' systems of the FBI were brought to their knees within hours by our team," the hackers wrote. It's unclear when the account was hacked. The U.S. government, which recently took down multiple sites operated by Iranian state actors, said it's offering up to $10 million for information on threat groups like Parsian Afzar Rayan Borna and Handala. Parsian Afzar Rayan Borna is an IT company that's been implicated in Iran's disinformation and surveillance campaigns. The company is assessed to be linked to Banished Kitten, an Iran-nexus adversary active since at least 2008 and operates the Homeland Justice and Handala Hack personas. Red Menshen Uses Stealthy BPFDoor to Spy on Telecom Networks — A China-linked state-sponsored threat actor known as Red Menshen has deployed kernel implants and passive backdoors deep within telecommunication backbone infrastructure worldwide for long-term persistence. The implants have been fittingly described as sleeper cells that lie dormant and blend into target environments, but spring into action upon receiving a magic packet by quietly monitoring network traffic instead of opening a visible connection. Initial access is usually gained by exploiting known vulnerabilities in edge networking devices and VPN products or by leveraging compromised accounts. Once inside, the threat actor maintains long-term access by deploying tools like BPFdoor. Some BPFdoor samples mimic bare-metal infrastructure, posing as legitimate enterprise platforms to blend into operational noise. Others spoof core containerization components. By embedding the implant deep below traditional visibility layers, the goal is to significantly complicate detection efforts. Rapid7 has released a scanning script designed to detect known BPFDoor variants across Linux environments. GlassWorm Evolves to Drop Extension-Based Stealer — A new evolution of the GlassWorm campaign is delivering a multi-stage framework capable of comprehensive data theft and installing a remote access trojan (RAT), which deploys an information-stealing Google Chrome extension masquerading as an offline version of Google Docs. "It logs keystrokes, dumps cookies and session tokens, captures screenshots, and takes commands from a C2 server hidden in a Solana blockchain memo," Aikido said. GlassWorm is the moniker assigned to a persistent campaign that obtains an initial foothold through rogue packages published across npm, PyPI, GitHub, and the Open VSX marketplace. In addition, the operators are known to compromise the accounts of project maintainers to push poisoned updates. Russian Hacker Sentenced to 2 Years for TA551-Linked Ransomware Attacks — Ilya Angelov, a 40-year-old Russian national, was sentenced to two years in prison for managing a botnet that was used to launch ransomware attacks against U.S. companies. Angelov, who went by the online aliases "milan" and "okart," is said to have co-managed a Russia-based cybercriminal group known as TA551 (aka ATK236, G0127, Gold Cabin, Hive0106, Mario Kart, Monster Libra, Shathak, and UNC2420) between 2017 and 2021. The attacks leveraged spam emails to compromise systems and rope them into a botnet that other cybercriminals used to break into corporate systems and deploy ransomware. This included threat actors affiliated with BitPaymer and IcedID. FCC Bans New Foreign-Made Routers Over Security Risks — The U.S. Federal Communications Commission (FCC) said it was banning the import of new, foreign-made consumer routers, citing "unacceptable" risks to cyber and national security. To that end, all consumer-grade routers manufactured in foreign countries have been added to the Covered List, unless they have been granted a Conditional Approval by the Department of War (DoW) or the Department of Homeland Security (DHS) after determining that they do not pose any risks. The development comes as the Indian government appears to be preparing to bar Chinese CCTV product makers, such as Hikvision, Dahua, and TP-Link, from selling their cameras from April 1, 2026, to tighten oversight under the Standardisation Testing and Quality Certification (STQC) rules, the Economic Times reported. ️🔥 Trending CVEs New vulnerabilities show up every week, and the window between disclosure and exploitation keeps getting shorter. The flaws below are this week's most critical — high-severity, widely used software, or already drawing attention from the security community. Check these first, patch what applies, and don't wait on the ones marked urgent — CVE-2026-3055 (Citrix NetScaler ADC and NetScaler Gateway), CVE-2025-62843, CVE-2025-62844, CVE-2025-62845, CVE-2025-62846 (QNAP), CVE-2026-22898 (QNAP QVR Pro), CVE-2026-4673, CVE-2026-4677, CVE-2026-4674 (Google Chrome), CVE-2026-4404 (GoHarbor Harbor), CVE-2026-1995 (IDrive for Windows), CVE-2026-4681 (Windchill and FlexPLM), CVE-2025-15517, CVE-2025-15518, CVE-2025-15519, CVE-2025-15605, CVE-2025-62673 (TP-Link),CVE-2025-66176 (HikVision), CVE-2026-32647 (NGINX Open Source and NGINX Plus), CVE-2026-22765, CVE-2026-22766 (Dell Wyse Management Suite), CVE-2026-21637, CVE-2026-21710 (Node.js), CVE-2026-25185 aka LnkMeMaybe (Microsoft), CVE-2026-1519, CVE-2026-3104, CVE-2026-3119, CVE-2026-3591 (BIND 9), CVE-2026-2931 (Amelia Booking plugin), CVE-2026-33656 (EspoCRM), CVE-2026-3608 (Kea), CVE-2026-20817 (Microsoft Windows Error Reporting), CVE-2025-33244 (NVIDIA Apex), CVE-2026-32746 (Synology DiskStation Manager), and CVE-2026-3098 (Smart Slider 3 plugin). 🎥 Cybersecurity Webinars Your Identity Program Is Mature. So Why Are You Still Getting Breached? → Your identity program is mature. Yet hundreds of apps still operate outside it. New 2026 Ponemon research from 600+ security leaders shows exactly how big that gap is and what it costs. Now, AI agents are making it worse. This webinar breaks down the findings and shows you what to fix first. Everyone Agrees AI Agents Need Identity. Almost Nobody Knows How to Do It → Everyone agrees AI agents need identity. Few know how to actually do it. This session skips the theory and shows you what a real production deployment looks like, including how to give agents strong identities, see exactly what they're doing, and control how they behave. 📰 Around the Cyber World Fortinet FortiClient EMS Flaw Comes Under Attack — A recently patched security flaw affecting Fortinet FortiClient EMS has come under active exploitation in the wild as of March 24, 2026. The vulnerability in question is CVE-2026-21643 (CVSS score: 9.1), a critical SQL injection that could allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests. The issue was addressed by Fortinet last month in FortiClient EMS version 7.4.5. "Attackers can smuggle SQL statements through the 'Site'-header inside an HTTP request," Defused Cyber said. Nearly 1,000 FortiClient EMS are publicly exposed. Meta Disrupts Influence Operation Linked to Iran — Meta said it disrupted an influence operation linked to Iran that employed "sophisticated fake personas" on Instagram to build relationships with U.S. users before sending political messaging. The network used accounts posing as journalists, commentators, and ordinary people to engage users and gradually introduce political narratives. A second layer of accounts amplified posts to help spread the messaging. Armenian National Extradited to U.S. in Connection with RedLine Stealer Operations — An Armenian national has been extradited to the United States over his alleged role in the administration of the RedLine infostealer malware. Hambardzum Minasyan, per court documents, allegedly developed and managed the stealer, while unnamed conspirators maintained digital infrastructure, including the command-and-control (C2) servers and administrative panels to enable the deployment of the malware by affiliates, and collected payments from the affiliates. "They allegedly responded to questions and requests from actual and potential RedLine affiliates, conspired with each other and affiliates to steal and possess the financial information, including access devices, of victims, and laundered the proceeds of cybercrime through cryptocurrency exchanges and other means," the U.S. Justice Department said. Minasyan has also been accused of registering two virtual private servers to host portions of RedLine's infrastructure, as well as two internet domains in support of the scheme, repositories on an online file sharing site to distribute the stealer to affiliates, and registering a cryptocurrency account in November 2021 to receive payments. RedLine Stealer was disrupted in an international law enforcement operation in October 2024. Minasyan has been charged with conspiracy to commit access device fraud, conspiracy to violate the Computer Fraud and Abuse Act, and conspiracy to commit money laundering. If convicted, he faces up to 10 years in prison for access device fraud and up to 20 years in prison for the other two counts. In June 2025, the U.S. Department of State announced a $10 million reward for information on Maxim Alexandrovich Rudometov, who is believed to be the main developer and administrator of RedLine. New Android Malware "Android God Mode" Abuses Accessibility Permissions — The Indian Cybercrime Coordination Centre (I4C) has issued an advisory, alerting users of a new Android malware called Android God Mode that abuses its permissions to accessibility services to seize control of infected devices. The malware is propagated via dropper apps that masquerade as banking, public, and utility services such as SBI YONO, Jivan Parman Patra, and RTO Challan, indicating that the campaign's focus is on targeting Indian users. "By coercing users into granting elevated Android permissions, these threats achieve near-total control over the device, enabling stealthy overlay attacks and the real-time theft of sensitive financial and personal information," the I4C said. The malware is distributed in the form of links or APK files shared through WhatsApp. Once installed, it abuses Android's accessibility services to grant itself additional permissions to harvest incoming SMS messages, send messages on the victim's behalf, access contact lists, initiate fraudulent call forwarding, and take pictures using the device's camera. Android 17 Beta Gains New Security Features — To improve security against code injection attacks, Android now enforces that dynamically loaded native libraries must be read-only. If your app targets Android 17 or higher, all native files loaded using System.load() must be marked as read-only beforehand. Another new addition is the support for Post-Quantum Cryptography (PQC) through the new v3.2 APK Signature Scheme. This scheme utilizes a hybrid approach, combining a classical signature with an ML-DSA signature. China-Linked Actors Deliver Mofu Loader and KIVARS — In recent months, Chinese-affiliated espionage clusters like DRBControl have employed DLL side-loading techniques to deliver Mofu Loader – a malware previously attributed to GroundPeony – which then drops a C++ backdoor capable of executing commands issued by an attacker-controlled server. Last year, companies and organizations in Japan and Taiwan have also been targeted by variants of a backdoor called KIVARS, which is tied to a Chinese hacking group called BlackTech. Automated Traffic Outpaces Human Traffic — HUMAN Security found that automated traffic grew eight times faster than human traffic year-over-year. "In 2025, automated traffic across the internet grew 23.51% year over year, while human traffic increased 3.10% over the same period," the company said. The cybersecurity company noted that its customers experienced more than 400,000 attempted post-login account compromise attacks, more than quadruple that of 2024. U.S. Accuses China of Backing Scam Compounds — A senior U.S. official accused Beijing of implicitly backing Chinese criminal syndicates running cyber scam compounds across Southeast Asia. Speaking during a Joint Economic Committee congressional hearing about U.S. efforts to combat digital scams, Reva Price, commissioner with the U.S.-China Economic and Security Review Commission, said links have been unearthed between scam centers and the Chinese government's Belt and Road Initiative. Chinese criminal syndicates have "invested in projects linked to China's Belt and Road Initiative alongside China's state-owned enterprises," she said, adding that they "have also seen criminal leaders who appear to have gotten a pass by promoting messaging and other activities aligned with Chinese Communist Party priorities." Scam centers in Southeast Asia are often operated by Chinese crime syndicates that lure people into the region with enticing job opportunities and coerce them into participating in pig butchering or romance baiting scams by confiscating their passports and subjecting them to torture. Exploitation Against Oracle WebLogic Servers — A recently disclosed security flaw in Oracle WebLogic (CVE-2026-21962, CVSS score: 10.0) witnessed automated exploitation attempts almost immediately after public exploit code was released, demonstrating how software flaws are being rapidly weaponized by bad actors. The activity, detected by CloudSEK against its honeypots, also leveraged other WebLogic flaws (CVE-2020-14882, CVE-2020-14883, CVE-2020-2551, and CVE-2017-10271), as well as flaws impacting Hikvision and PHPUnit, indicating a spray and pray approach. "Attackers predominantly utilized rented Virtual Private Servers (VPS) from common hosting providers like DigitalOcean and HOSTGLOBAL.PLUS," the company said. "The overall activity was characterized by high-volume, automated scanning, with tools like libredtail-http and the Nmap Scripting Engine dominating the malicious traffic." Security Flaws in Cisco Catalyst 9300 Series Switches — Details have emerged about now-patched vulnerabilities in Cisco Catalyst 9300 Series switches (CVE-2026-20110, CVE-2026-20112, CVE-2026-20113, and CVE-2026-20114) that could result in privilege escalation, operational denial-of-service, stored cross-site scripting (XSS), and CRLF injection. "Collectively, these vulnerabilities introduce risks to administrative trust boundaries, service availability, session integrity, and system log reliability – affecting both operational continuity and security monitoring capabilities," OPSWAT said. "CVE-2026-20114 and CVE-2026-20110 are the most operationally impactful when chained. A low-privilege Web UI user can escalate access and invoke a maintenance-mode operation, resulting in full denial of service that may require physical intervention to restore." The issues were patched by Cisco last week. Financial Institution Targeted by BRUSHWORM and BRUSHLOGGER — A modular backdoor with USB-based spreading capabilities was used in an attack targeting an unnamed South Asian financial institution, according to findings from Elastic Security Labs. The malware, dubbed BRUSHWORM, is one of the two malware components identified in the victim's infrastructure, the other being a DLL keylogger referred to as BRUSHLOGGER. "BRUSHWORM features anti-analysis checks, AES-CBC encrypted configuration, scheduled task persistence, modular DLL payload downloading, USB worm propagation, and broad file theft targeting documents, spreadsheets, email archives, and source code," security researcher Salim Bitam said. BRUSHWORM is also responsible for running basic anti-analysis checks, maintaining persistence, command-and-control (C2) communication, and downloading additional modular payloads. BRUSHLOGGER augments the backdoor by capturing system-wide keystrokes via a simple Windows keyboard hook and logging the active window context for each keystroke session. "Neither binary employs meaningful code obfuscation, packing, or advanced anti-analysis techniques," Elastic said. "Given the absence of a kill switch, the use of free dynamic DNS servers in testing versions, and some coding mistakes, we assess with moderate confidence that the author is relatively inexperienced and may have leveraged AI code-generation tools during development without fully reviewing the output." U.K. Sanctions Xinbi — The U.K.'s Foreign, Commonwealth and Development Office (FCDO) has sanctioned Xinbi, a Chinese-language guarantee marketplace accused of enabling large-scale online fraud and human exploitation by supporting #8 Park (aka Legend Park), an industrial-scale scam compound in Cambodia notorious for large-scale pig butchering scams and forced labor of trafficked workers. The U.K. is the first country to sanction Xinbi. The move is designed to isolate Xinbi from the legitimate crypto ecosystem and disrupt its operations. Xinbi is estimated to have processed over $19.9 billion between 2021 and 2025. "The platform facilitates everything from 'Black U' money laundering and unlicensed OTC trades to the sale of compromised personal databases and scam infrastructure," Chainalysis said. "In the face of previous takedowns, Xinbi demonstrated significant resilience by rapidly migrating to the SafeW messaging app and launching its own proprietary payment app, XinbiPay. This evolution highlights the challenges around pursuing illicit services as they build custom financial rails to insulate themselves from platform-level disruptions." According to a report published by Elliptic last month, #8 Park is linked to a company named Legend Innovation, which, in turn, has ties to Prince Group, whose chairman, Chen Zhi, was arrested and extradited to China in connection with a crackdown on a large-scale fraud operation. #8 Park is also tied to HuiOne Group, with its payment business, HuiOne Pay (later rebranded as H-PAY), which operates a physical store within the compound. There has since been a sharp decline in incoming payments to merchants operating inside the compound beginning around February 9, 2026, with transactions almost entirely ceasing by February 13. What is Tsundere? — Tsundere is a botnet that enables system fingerprinting and arbitrary command execution on victim machines. It's notable for the use of a technique called EtherHiding to retrieve command-and-control (C2) servers stored in smart contracts on the Ethereum blockchain. The malware is suspected to be a Malware-as-a-Service (MaaS) offering of Russian origin, owing to logic that checks whether the infected host is located in a CIS country, including Ukraine, and terminates execution if so. Most recently, the use of the botnet has been linked to the Iranian state-sponsored actor MuddyWater. Jailbreaking, a Continued Risk to LLMs — New research from Palo Alto Networks Unit 42 has uncovered that prompt jailbreaking remains a practical risk to large language models (LLMs) and that a genetic algorithm-based fuzzing approach can be used to generate meaning-preserving prompt variants to trigger policy-violating outcomes against both closed-source and open-weight pre-trained models. "The broader implication is that guardrails should be treated as probabilistic controls that require continuous adversarial evaluation, not as definitive security boundaries," Unit 42 said. The findings reinforce that security for LLM applications cannot rely on a single layer, necessitating that organizations define and enforce application scope, use robust, multi-signal content controls, treat user input as untrusted and isolate it from privileged instructions, validate outputs against scope and policy, and monitor for misuse, and apply standard security controls, such as authentication, rate limiting, and and least privilege tool permissions. SEO Campaign Delivers AsyncRAT — Since October 2025, an unknown threat actor has been running an active SEO poisoning campaign, using impersonation sites of over 25 popular applications to direct victims to malicious installers, including VLC Media Player, OBS Studio, KMS Tools, and CrosshairX. The campaign uses ScreenConnect, a legitimate remote management tool, to establish initial access and to deliver AsyncRAT. "Most notable in this campaign is the RAT’s added cryptocurrency clipper, dynamic plugin system capable of loading arbitrary capabilities at runtime, and a geo-fencing mechanism that deliberately excludes targets across the Middle East, North Africa, and Central Asia," NCC Group said. AsyncRAT has also been delivered as part of a series of attacks on Libyan organizations between November 2025 and February 2026. The attacks targeted an oil refinery, a telecoms organization, and a state institution. "AsyncRAT is a remote access Trojan with a variety of capabilities, including keylogging, screen capture, and remote command execution capabilities, making it ideal for use in intelligence gathering and espionage attacks," Symantec and Carbon Black said. "It is also modular, meaning it can be updated and customized, which is attractive for attackers." Nigerian National Sentenced to 7 Years in Prison — A Nigerian man has been sentenced to more than seven years in a U.S. prison for his role in a scheme that broke into business email accounts and tricked victims into sending millions of dollars to fraudulent bank accounts. James Junior Aliyu, 31, received a 90-month prison sentence for conspiracy to commit wire fraud and money laundering. The court also ordered Aliyu to forfeit $1.2 million and repay nearly $2.39 million to the victims. Aliyu, who pleaded guilty in August 2025, acknowledged that he conspired with others, including Kosi Goodness Simon-Ebo, 31, and Henry Onyedikachi Echefu, 34, to deceive and defraud multiple American victims from February 2017 until at least July 2017. The business email compromise scheme targeted American businesses and individuals by compromising email accounts and sending false wiring instructions to deceive victims into sending money to bank accounts under their control. "Aliyu and his accomplices conspired to commit money laundering by disbursing the fraudulently obtained funds in the drop accounts to other accounts," the U.S. Justice Department said. "Co-conspirators moved the stolen money by initiating account transfers, withdrawing cash, and obtaining cashier’s checks. They also wrote checks to other individuals and entities to hide the true ownership and source of these assets. In total, Aliyu and his co-conspirators attempted to defraud victims of at least $10.4 million, and the victims suffered an actual loss of at least $2,389,130." Sensor Technology to Combat Deepfakes — Researchers at ETH Zürich have developed a sensor system that stamps a cryptographic signature onto images, video, and audio within a sensor chip at the exact moment they are captured, making it impossible to tamper with the data without being detected. "If the signatures are uploaded to a public ledger (e.g., a blockchain), anyone can verify the authenticity of videos and other data," ETH Zürich said. "The technology can, in principle, be integrated into any type of sensor or camera. It would then be possible to identify manipulated content on online platforms with minimal effort." Middle East Conflict Fuels Cyber Attacks — Threat actors have been capitalizing on geopolitical tensions in the Middle East region to spread Android spyware by distributing trojanized versions of Israel's Red Alert apps via SMS phishing messages. The espionage campaign has been codenamed Operation False Siren by CYFIRMA. ZIP archives containing lures related to the conflict are also being used to launch malicious payloads that lead to the deployment of PlugX and LOTUSLITE backdoors. These ZIP-based phishing campaigns have been attributed to a Chinese nation-state actor known as Mustang Panda. Elsewhere, an Iran-themed fake news blog site hosting malicious JavaScript has been found, leading to the deployment of StealC malware. Apple Tests Ways to Block Malicious Copy-Pastes in macOS — With the release of macOS 26.4 last week, Apple has introduced a new feature that warns Mac users if they paste harmful commands in the Terminal app to curb ClickFix-style attacks that have increasingly targeted macOS in recent months. "Scammers often encourage pasting text into Terminal to try and harm your Mac or compromise your privacy," the message reads. "These instructions are commonly offered via websites, chat agents, apps, files, or a phone call." The alert comes with a "Paste Anyway" for those who wish to proceed. The disclosure comes as multiple ClickFix campaigns have come to light, including using a Cloudflare-themed verification page to deliver a Python-based macOS stealer dubbed Infiniti Stealer. A similar Cloudflare verification, but for Windows, has been used to launch PowerShell commands that ultimately drop StealC, Lumma, Rhadamanthys, Vidar Stealer, and Aura Stealer malware. The ClickFix strategy has also been adopted by a traffic distribution system known as KongTuke to redirect visitors of compromised WordPress websites to phishing pages and malware payloads. According to eSentire, ClickFix lures have been used to deliver EtherRAT, a Node.js-based backdoor linked to North Korean threat actors. "EtherRAT allows threat actors to run arbitrary commands on compromised hosts, gather extensive system information, and steal assets such as cryptocurrency wallets and cloud credentials," the Canadian security company said. "Command-and-Control (C2) addresses are retrieved using 'EtherHiding,' a technique to make C2 addresses more resilient by storing and updating them in Ethereum smart contracts, allowing threat actors to rotate infrastructure at a small cost and avoid takedowns by law enforcement." Recorded Future said it has identified five distinct clusters leveraging ClickFix to facilitate initial access to Windows and macOS systems since May 2024. "This indicates that the ClickFix methodology has transitioned into a standardized, high-ROI template adopted across a fragmented ecosystem of threat actors," Insikt Group said. "While visually diverse, all analyzed clusters use a consistent execution framework that bypasses traditional browser security controls by shifting the point of exploitation to user-assisted manual commands. These campaigns target a wide variety of sectors, including accounting (QuickBooks), travel (Booking.com), and system optimization (macOS)." Apple Rolls Out Mandatory Age Verification in U.K. — In more Apple news, the tech giant has rolled out mandatory U.K. age verification with iOS 26.4, requiring users to provide a credit card or ID to confirm if they are an adult before "downloading apps, changing certain settings, or taking other actions with your Apple Account." The move comes at a time when online child safety is increasingly drawing attention from regulators, causing many digital services, including social media apps and porn sites, to roll out similar checks. Discord, which announced plans to verify the ages of all its users last month, has since paused the effort until H2 2026 after concerns were raised about how IDs and personal information would be handled. Discord has reiterated that it does not receive any identifying personal information from users who need to manually verify their age. Instead, it is partnering with third-party age verification companies, who will "handle verification and only pass back your age group." The company also said it's no longer working with age verification vendor Persona, which has attracted criticism over allegations that it shared users' data with other companies and left its frontend source code exposed to the internet. 🔧 Cybersecurity Tools OpenClaw Security Handbook → It is a detailed security guide published by ZAST AI for users of OpenClaw, a multi-channel AI gateway that connects messaging platforms, LLMs, and local system capabilities. Because that combination creates a serious attack surface, the handbook covers the real risks — prompt injection, malicious skills, exposed ports, credential theft — backed by documented incidents and CVEs, with practical configuration guidance for locking it down. VulHunt → It is an open-source framework from Binarly's research team for hunting vulnerabilities in software binaries and UEFI firmware. It uses customizable rulepacks for scanning and can connect to Binarly's Transparency Platform for large-scale triage. It also supports running as an MCP server, letting AI assistants interact with it directly. Disclaimer: For research and educational use only. Not security-audited. Review all code before use, test in isolated environments, and ensure compliance with applicable laws. Conclusion That's the week. Some of it will age well, some of it is already being quietly exploited while you're reading this sentence. The through-line, if there is one: patience. Attackers are playing long games. The detections, the arrests, the patches — they matter, but they're almost always trailing. Stay sharp, check the CVE list, and see you next Monday.
thehackernews.comMar 30, 2026extracted
TP-Link Patches High-Severity Router Vulnerabilities
TP-Link has released patches for four high-severity vulnerabilities in Archer NX router models that could be exploited to fully compromise devices. The bugs, tracked as CVE-2025-15517, CVE-2025-15518, CVE-2025-15519, and CVE-2025-15605, were resolved in fresh firmware releases for the Archer NX200, NX210, NX500, and NX600 router models. The first of the flaws, CVE-2025-15517, allows attackers to bypass authentication and perform actions such as firmware uploads or configuration operations, TP-Link notes in its advisory. CVE-2026-15518 and CVE-2026-15519 are command injection bugs that require administrative privileges for successful exploitation, while CVE-2025-15605 exists because a hardcoded cryptographic key is used for configuration file encryption and decryption, allowing attackers to tamper with these files. The fixes were rolled out one day before Cisco’s Talos researchers published details on 10 vulnerabilities affecting TP-Link’s Archer AX53 routers, including nine memory safety flaws and one misconfiguration issue that could lead to credentials leak. Successful exploitation of these security defects could allow attackers to execute arbitrary code remotely on vulnerable devices or to leak credentials via a man‑in‑the‑middle (MITM) attack. Talos reported the vulnerabilities to TP-Link in October, and the vendor rolled out fixes for its Archer AX53 v1.0 routers in early February. Now, Talos has published technical details on all 10 bugs, as well as on 19 flaws in the Canva Affinity pixel and vector art manipulation tool, and one issue in Hikvision’s face recognition terminals. Of the Affinity security defects, 18 could be exploited to leak sensitive information and one to execute arbitrary code using specially crafted EMF files. The Hikvision vulnerability could be exploited remotely via specially crafted network packets to achieve arbitrary code execution. Related: BIND Updates Patch High-Severity Vulnerabilities Related: Cisco Patches Multiple Vulnerabilities in IOS Software Related: iOS, macOS 26.4 Roll Out With Fresh Security Patches Related: TP-Link Patches Vulnerability Exposing VIGI Cameras to Remote Hacking
securityweek.comMar 27, 2026extracted
Ricatto a Esprinet, “abbiamo 1,2 TB di dati, pagateci”: cosa sappiamo
Un nuovo gruppo ransomware, identificato come ALP-001, ha rivendicato un attacco informatico ai danni di Esprinet, azienda italiana nota per la distribuzione all’ingrosso di prodotti di tecnologia. Secondo quanto riportato sul portale di leak del gruppo, raggiungibile mediante la rete Tor, gli attaccanti sostengono di aver esfiltrato circa 1,2 terabyte di dati aziendali. Esprinet riferisce di non avere subito nessun attacco né perdita di dati, ma di avere solo ricevuto una mail estorsiva. Al momento non risultano pubblicati campioni o prove dirette dell’avvenuta sottrazione dei file. Indice degli argomenti Il gruppo ALP-001 è una nuova sigla criminale emersa a marzo 2026, legata a un presunto Initial Access Broker (IAB) precedentemente attivo nel commercio di accessi a infrastrutture aziendali compromesse. Secondo le analisi circolate in ambienti di sicurezza, il gruppo avrebbe abbandonato il modello di vendita degli accessi per passare alla estorsione diretta, minacciando di pubblicare informazioni riservate se le vittime non accettano di negoziare. Le attività attribuite al gruppo indicano un uso tipico di vettori d’attacco su sistemi esposti su Internet: vulnerabilità note in dispositivi VPN, gateway Citrix e server SSH/FTP. Tra le vittime precedentemente rivendicate da ALP-001 compare anche Hikvision, azienda cinese nota nel campo della videosorveglianza. Al momento non è possibile verificare la veridicità della rivendicazione nei confronti di Esprinet né l’effettiva compromissione dei dati dichiarati. Esprinet ha fatto sapere comunque di non avere subito attacchi e che si tratta solo di un ricatto infondato. Gli esperti di sicurezza raccomandano cautela nella diffusione delle informazioni relative a tali gruppi, in attesa di eventuali conferme ufficiali o riscontri tecnici indipendenti. Articolo soggetto ad aggiornamenti man mano che emergeranno nuovi dati o dichiarazioni ufficiali da parte dell’azienda.
cybersecurity360.itMar 27, 2026extracted
FCC bans new routers made outside the USA over security risks
The Federal Communications Commission has updated its Covered List to include all consumer routers made in foreign countries, banning the sale of new models in the U.S. The Covered List, created under the Secure and Trusted Communications Networks Act of 2019, is an FCC-maintained list of communications equipment and services that the U.S. government has determined to pose an unacceptable risk to national security or the safety of Americans. The list previously included specific products and companies tied to security concerns, such as Kaspersky, Huawei, ZTE, Hikvision, and Dahua. Adding all routers manufactured abroad to the Covered List follows a National Security Determination issued on March 20 by an Executive Branch interagency body. According to the assessment, foreign-produced routers carry a supply-chain risk "that could disrupt the U.S. economy, critical infrastructure, and national defense." The agency determined that these devices could also be used "to immediately and severely disrupt U.S. critical infrastructure and directly harm U.S. persons." In support of the decision, the FCC highlights that foreign-made routers helped the Volt, Flax, and Salt Typhoon hackers carry out attacks that targeted vital U.S. infrastructure. Exemptions and alternative approval path Conditional approval has been granted to certain routers used in the U.S. Department of War (DoW) or the Department of Homeland Security (DHS) for drone systems, which have been determined not to constitute a security risk. Also, the new rules do not bar foreign consumer-grade router makers from seeking approval in the U.S., as long as they transparently disclose: Corporate and ownership structure, including any foreign government financial support and influence. Manufacturing and supply chain details, including bill of materials, country of origin for all components, IP ownership details, manufacturing and assembly locations, and origin of software/firmware. Plan to move critical components manufacturing to the United States, and provide a description of existing U.S.-based manufacturing or assembly processes. Consumer impact For regular consumers in the United States, the new rules are expected to have no immediate effect, as all existing routers will continue to be sold in the country. In what concerns Unmanned Aircraft Systems (UAS) and their critical components, the FCC noted that it will allow software and firmware updates until at least January 1, 2027. Access to new router models for U.S.-based consumers may become more difficult, and the devices may also become more expensive, as the regulatory approval process adds extra complications and costs. Given that testing, approvals, and FCC certification typically take a couple of months, even when all conditions are met. In some cases, this might lead to a delay in entering the U.S. market. Some manufacturers may also decide that the alternative certification pathway is not worth the effort - particularly due to the onshoring requirement - and exit the U.S. market, reducing model availability. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comMar 24, 2026extracted
Authorities Disrupt SocksEscort Proxy Service Powered by AVrecon Botnet
Law enforcement agencies in the United States and Europe have disrupted SocksEscort, a malicious proxy service that facilitated criminal activities. These proxy services enable users to hide their identity and bypass security systems. In the case of SocksEscort, it has been used for various types of cybercrime, including DDoS attacks, ransomware attacks, and the distribution of child abuse materials. According to Europol and the US Justice Department, SocksEscort has been powered by compromised routers and other IoT devices, with roughly 363,000 IP addresses from 163 countries linked to the cybercrime service since 2020. In February 2026, just before the takedown operation was initiated, SocksEscort was supported by approximately 8,000 hacked routers, including 2,500 in the US. Lumen Technologies, whose Black Lotus Labs assisted the disruption efforts, said “SocksEscort maintained an average size of approximately 20,000 distinct victims weekly, with communications routed through an average of 15 command-and-control nodes.” Authorities estimate that SocksEscort customers paid a total of more than $5.7 million for the proxy service, and US Justice Department data indicates many users profited substantially from it, with some defrauding victims of hundreds of thousands or even $1 million in individual schemes. Europol reported that “law enforcement agencies successfully took down and seized 34 domains as well as 23 servers located in seven countries. In addition, the United States froze a total of USD 3.5 million in cryptocurrency. The infected modems used to offer the proxy service have been disconnected from the service.” The FBI on Thursday issued an alert for the AVrecon malware that has powered the SocksEscort service. The agency said the proxy service’s operators exploited known vulnerabilities in routers and IoT devices to deploy the malware and create a botnet. “SocksEscort uses AVrecon malware to target approximately 1,200 device models manufactured by Cisco, D-Link, Hikvision, MicroTik, Netgear, TP-Link, and Zyxel,” the FBI said. “The vast majority of observed devices infected with AVrecon malware are small-office/home-office (SOHO) routers infected using critical vulnerabilities such as Remote Code Execution (RCE) and command injection.” The agency has shared information on the AVrecon malware’s distribution, execution, persistence, and communication, providing indicators of compromise (IoCs) and recommendations for securing devices. News of the SocksEscort takedown comes shortly after Europol, Microsoft, and cybersecurity companies announced a joint effort to take down the phishing-as-a-service platform Tycoon 2FA. Related: SystemBC Infects 10,000 Devices After Defying Law Enforcement Takedown Related: RaccoonO365 Phishing Service Disrupted, Leader Identified Related: 1,000+ Servers Hit in Law Enforcement Takedown of Rhadamanthys, VenomRAT, Elysium
securityweek.comMar 13, 2026extracted
US, Europol disrupt SocksEscort network that exploited thousands of residential routers
US, Europol disrupt SocksEscort network that exploited thousands of residential routers A cybercriminal platform that offered access to thousands of residential routers was disrupted by law enforcement agencies in the U.S. and Europe on Wednesday. The SocksEscort proxy network allowed cybercriminals to purchase access to routers infected with malware. Criminals could conceal their location and IP address by routing their activities through the infected routers. The Justice Department said from 2020 to 2026, SocksEscort offered access to about 369,000 different IP addresses in 163 countries but listed about 8,000 IP addresses as of February. Of those 8,000 available for sale, 2,500 were in the U.S. In total, 34 domains were seized and 23 servers were taken down by law enforcement agencies in seven countries. U.S. officials also froze access to $3.5 million worth of cryptocurrency. Alongside the operation against SocksEscort, the FBI published a flash alert about a malware strain known as AVRecon on Thursday, warning the public that it is targeted at routers and internet-of-things devices. Threat actors “have been found to compromise routers, install AVrecon Malware, and then sell access to the compromised devices as residential proxies using the SocksEscort residential proxy service.” SocksEscort uses AVrecon malware “to target approximately 1,200 device models manufactured by Cisco, D-Link, Hikvision, MicroTik, Netgear, TP-Link, and Zyxel,” the FBI said. Europol noted that when the devices were infected with the malware, owners would not know that their IP address was being abused. Catherine De Bolle, executive director of Europol, said proxy services like SocksEscort “provide criminals with the digital cover they need to launch attacks, distribute illegal content and evade detection.” “By dismantling this infrastructure, law enforcement has disrupted a service that enabled cybercrime on a global scale,” De Bolle said in a statement. U.S. officials executed seizure warrants against several U.S. domains that enabled the SocksEscort operation. Court documents tied the SocksEscort site to dozens of different cyberscams, including fraudulent unemployment insurance claims, cryptocurrency thefts and the takeover of U.S. bank accounts. The people behind SocksEscort allegedly netted more than $5.7 million from the service. Law enforcement agencies in Austria, France and the Netherlands took down SocksEscort servers and officials in Bulgaria, Germany, Hungary and Romania were involved in the investigation, which began in June 2025. The DOJ noted that private sector firms like Lumen’s Black Lotus Labs and the Shadowserver Foundation also provided assistance. Black Lotus Labs published its own advisory on AVRecon and SocksEscort, writing that over the past several years, the platform “maintained an average size of approximately 20,000 distinct victims weekly, with communications routed through an average of 15 command-and-control nodes (C2s).” In 2023, the company said AVrecon’s botnet was one of the largest it has seen targeting home office routers. An FBI official told The Register that SocksEscort had 124,000 users and that they planned to use the seized servers to target other cybercriminal activity. U.S. and European law enforcement agencies have ramped upbotnet takedowns in recent years to stymie cybercriminal and nation-state attack campaigns. Botnets like QakBot, 911 S5, IPStorm, KV, DanaBot, Anyproxy, 5socks and others have faced law enforcement scrutiny since 2021. Jonathan Greig is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
therecord.mediaMar 12, 2026extracted
CISA Adds iOS Flaws From Coruna Exploit Kit to KEV List
The US cybersecurity agency CISA on Thursday expanded the Known Exploited Vulnerabilities (KEV) list with five flaws, including three bugs targeted by the nation-state-grade Coruna iOS exploit kit. Coruna contains exploits targeting 23 vulnerabilities in iOS versions spanning four years, namely iOS 13.0 to iOS 17.2.1, but is ineffective against the latest iterations of Apple’s mobile platform. It has been used by multiple threat actors, including the customer of a spyware vendor, a Russian espionage group, and a financially motivated Chinese group. Likely built using ‘second-hand’ zero-day exploits, Coruna fingerprints devices to load the appropriate WebKit remote code execution (RCE) exploit, bypasses various platform mitigations, and injects a payload in the ‘powerd’ daemon running as root. The payload targets the victim’s financial information and can also load additional modules for exfiltrating cryptocurrency wallets and sensitive information from multiple applications. Of the 23 security defects targeted by the exploit kit, 12 have had a CVE identifier assigned. All the exploited issues, publicly disclosed or not, have been patched. Of the publicly disclosed bugs, nine were previously flagged as exploited, most of them as zero-days. These include CVE-2022-48503, CVE-2024-23222, CVE-2023-32409, CVE-2020-27932, CVE-2020-27950, CVE-2023-32434, CVE-2023-38606, CVE-2024-23225, and CVE-2024-23296. There appear to have been no public reports of the exploitation of the remaining three CVEs, namely CVE-2021-30952, CVE-2023-41974, and CVE-2023-43000, before this week’s revelations of the Coruna iOS exploit kit targeting them. Now that CISA has added all three iOS flaws to the KEV catalog, federal agencies have three weeks to identify within their environments any vulnerable devices and to patch them, as mandated by Binding Operational Directive (BOD) 22-01. On Thursday, CISA also warned that older vulnerabilities in multiple Hikvision and Rockwell products have been exploited in the wild. While BOD 22-01 only applies to federal agencies, all organizations are advised to prioritize the remediation of bugs in the KEV catalog. Related: Google: Half of 2025’s 90 Exploited Zero-Days Aimed at Enterprises Related: Android Update Patches Exploited Qualcomm Zero-Day Related: Apple Patches iOS Zero-Day Exploited in ‘Extremely Sophisticated Attack’
securityweek.comMar 6, 2026extracted
Iran-Linked MuddyWater Hackers Target U.S. Networks With New Dindoor Backdoor
New research from Broadcom's Symantec and Carbon Black Threat Hunter Team has discovered evidence of an Iranian hacking group embedding itself in several U.S. companies' networks, including banks, airports, non-profit, and the Israeli arm of a software company. The activity has been attributed to a state-sponsored hacking group called MuddyWater (aka Seedworm). It's affiliated with the Iranian Ministry of Intelligence and Security (MOIS). The campaign is assessed to have begun in early February, with recent activity detected following U.S. and Israeli military strikes on Iran. "The software company is a supplier to the defense and aerospace industries, among others, and has a presence in Israel, with the company's Israel operation seeming to be the target in this activity," the security vendor said in a report shared with The Hacker News. The attacks targeting the software company, as well as a U.S. bank and a Canadian non-profit, have been found to pave the way for a previously unknown backdoor dubbed Dindoor, which leverages the Deno JavaScript runtime for execution. Broadcom said it also identified an attempt to exfiltrate data from the software company using the Rclone utility to a Wasabi cloud storage bucket. However, it's currently not known if the effort paid off. Also found in the networks of a U.S. airport and a non-profit was a separate Python backdoor called Fakeset, which was downloaded from servers belonging to Backblaze, an American cloud storage and data backup company. The digital certificate used to sign Fakeset has also been used to sign Stagecomp and Darkcomp malware, both previously linked to MuddyWater. Brigid O Gorman, senior intelligence analyst, Symantec and Carbon Black Threat Hunter Team, said Microsoft and Kaspersky have detected samples associated with the Stagecomp and the Darkcomp malware with Muddywater-linked signatures – "Trojan:Python/MuddyWater.DB!MTB" for Microsoft and "Backdoor.Python.MuddyWater.a" for Kaspersky. "While this malware wasn't seen on the targeted networks, the use of the same certificates suggests the same actor -- namely Seedworm -- was behind the activity on the networks of the U.S. companies," Symantec and Carbon Black said. "Iranian threat actors have become increasingly proficient in recent years. Not only has their tooling and malware improved, but they've also demonstrated strong social engineering capabilities, including spear-phishing campaigns and 'honeytrap' operations used to build relationships with targets of interest to gain access to accounts or sensitive information." The findings come against the backdrop of an escalating military conflict in Iran, triggering a barrage of cyber attacks in the digital sphere. Recent research from Check Point has uncovered the pro-Palestinian hacktivist group known as Handala Hack (aka Void Manticore) routing its operations through Starlink IP ranges to probe externally facing applications for misconfigurations and weak credentials. In recent months, multiple Iran-nexus adversaries, such as Agrius (aka Agonizing Serpens, Marshtreader, and Pink Sandstorm), have also observed scanning for vulnerable Hikvision cameras and video intercom solutions using known security flaws such as CVE-2017-7921 and CVE-2023-6895. The targeting, per Check Point, has intensified in the wake of the current Middle East conflict. The exploitation attempts against IP cameras have witnessed a surge in Israel and Gulf countries, including the U.A.E., Qatar, Bahrain, and Kuwait, along with Lebanon and Cyprus. The activity has singled out cameras from Dahua and Hikvision, weaponizing the two aforementioned vulnerabilities, as well as CVE-2021-36260, CVE-2025-34067, and CVE-2021-33044. "Taken together, these findings are consistent with the assessment that Iran, as part of its doctrine, leverages camera compromise for operational support and ongoing battle damage assessment (BDA) for missile operations, potentially in some cases prior to missile launches," the company said. "As a result, tracking camera-targeting activity from specific, attributed infrastructures may serve as an early indicator of potential follow-on kinetic activity." The U.S. and Israel's war with Iran has also prompted an advisory from the Canadian Centre for Cyber Security (CCCS), which cautioned that Iran will likely use its cyber apparatus to stage retaliatory attacks against critical infrastructure and information operations to further the regime's interests. Some other key developments that have unfolded in recent days are listed below - Israeli intelligence agencies hacked into Tehran's extensive traffic camera network for years to monitor the movements of bodyguards of Ayatollah Ali Khamenei and other top Iranian officials in the lead up to the assassination of the supreme leader last week, the Financial Times reported. Iran's Islamic Revolutionary Guard Corps (IRGC) targeted Amazon's data center in Bahrain for the company's support of the "enemy's military and intelligence activities," state media Fars News Agency said on Telegram. Active wiper campaigns are said to be underway against Israeli energy, financial, government, and utilities sectors. "Iran's wiper arsenal includes 15+ families (ZeroCleare, Meteor, Dustman, DEADWOOD, Apostle, BFG Agonizer, MultiLayer, PartialWasher, and others)," Anomali said. Iranian state-sponsored APT groups like MuddyWater, Charming Kitten, OilRig, Elfin, and Fox Kitten "demonstrated clear signs of activation and rapid retooling, positioning themselves for retaliatory operations amid the escalating conflict," LevelBlue said, adding "cyber represents one of Iran's most accessible asymmetric tools for retaliation against Gulf states that condemned its attacks and support U.S. operations." According to Flashpoint, a massive #OpIsrael cyber campaign involving pro-Russian and pro-Iranian actors has targeted Israeli industrial control systems (ICS) and government portals across Kuwait, Jordan, and Bahrain. The campaign is driven by NoName057(16), Handala Hack, Fatemiyoun Electronic Team, and Cyber Islamic Resistance (aka 313 Team). Between 28 February 2026 and 2 March 2026, pro-Russia hacktivist group Z-Pentest claimed responsibility for compromising several U.S.-based entities, including ICS and SCADA systems and multiple CCTV networks. "The timing of these unverified claims, coinciding with Operation Epic Fury, suggests Z-Pentest likely began prioritizing U.S. entities as targets," Adam Meyers, head of Counter Adversary Operations at CrowdStrike, told The Hacker News. "Iran's offensive cyber capability has matured into a durable instrument of state power used to support intelligence collection, regional influence, and strategic signaling during periods of geopolitical tension," UltraViolet Cyber said. "A defining feature of Iran's current cyber doctrine is its emphasis on identity and cloud control planes as the primary attack surface." "Rather than prioritizing zero-day exploitation or highly novel malware at scale, Iranian operators tend to focus on repeatable access techniques such as credential theft, password spraying, and social engineering, followed by persistence through widely deployed enterprise services." Organizations are advised to bolster their cybersecurity posture, strengthen monitoring capabilities, limit exposure to the internet, disable remote access to operational technology (OT) systems, enforce phishing-resistant multi-factor authentication (MFA), implement network segmentation, take offline backups, and ensure that all internet-facing applications, VPN gateways, and edge devices are up-to-date "Western organizations should continue to remain on high-alert for potential cyber response as the conflict continues and activity may move beyond hacktivism and into destructive operations," Meyers said.
thehackernews.comMar 6, 2026extracted
Hikvision and Rockwell Automation CVSS 9.8 Flaws Added to CISA KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added two security flaws impacting Hikvision and Rockwell Automation products to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The critical-severity vulnerabilities are listed below - CVE-2017-7921 (CVSS score: 9.8) - An improper authentication vulnerability affecting multiple Hikvision products that could allow a malicious user to escalate privileges on the system and gain access to sensitive information. CVE-2021-22681 (CVSS score: 9.8) - An insufficiently protected credentials vulnerability affecting multiple Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, and Logix Controllers that could allow an unauthorized user with network access to the controller to bypass the verification mechanism and authenticate with it, as well as alter its configuration and/or application code. The addition of CVE-2017-7921 to the KEV catalog comes more than four months after the SANS Internet Storm Center disclosed that it had detected exploit attempts against Hikvision cameras susceptible to the flaw. However, there appears to be no public report describing attacks involving CVE-2021-22681. In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are recommended to update to the latest supported software versions by March 26, 2026, as part of Binding Operational Directive (BOD) 22-01. "These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise," CISA said. "Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice."
thehackernews.comMar 6, 2026extracted
Surge in Attacks on Surveillance Cameras Linked to Iranian Hackers
A surge in attempts to compromise internet-connected surveillance cameras across the Middle East has been identified during the ongoing regional conflict, with activity attributed to infrastructure linked to Iranian threat actors. The targeting, which began intensifying on February 28, has affected Israel, Qatar, Bahrain, Kuwait, the UAE and Cyprus, with additional focused activity observed in parts of Lebanon on March 1. The findings, released by Check Point Research (CPR), point to a coordinated campaign against devices manufactured by Hikvision and Dahua. The researchers said the pattern of activity aligns with Iran's established military doctrine of using compromised cameras to support operational planning and battle damage assessment following missile strikes. Activity Tied To Regional Escalation According to CPR, the spike in exploitation attempts coincided with key geopolitical developments. Earlier, more targeted scanning was recorded on January 14–15, around the time Iran temporarily closed its airspace amid expectations of a possible US strike. Subsequent waves of activity aligned with other high-profile events, including: January 24 – A visit to Israel by the US Central Command commander during heightened tensions Early February – Public warnings from Iranian leadership that a US strike could spark wider regional conflict The infrastructure used in the campaign combines commercial VPN exit nodes, including Mullvad, ProtonVPN, Surfshark and NordVPN, along with virtual private servers assessed to be operated by multiple Iran-linked threat actors. Specific Vulnerabilities Exploited The campaign observed by CPR focused exclusively on Hikvision and Dahua products. Researchers observed scanning for known vulnerabilities, including authentication bypass and remote code execution (RCE) flaws. Patches are available for all identified issues. Check Point examined exploitation attempts involving CVE-2021-33044 and CVE-2017-7921, traced to infrastructure attributed to Iran and active since the start of the year. The researchers noted similar tactics during the 12-day conflict between Israel and Iran in June 2025. In one widely reported incident, a street camera facing the Weizmann Institute of Science was allegedly compromised shortly before a ballistic missile struck the site. The report concluded that monitoring camera-targeting activity from known Iranian-linked infrastructure may offer early warning of potential follow-on kinetic operations. To help mitigate these risks, defenders should eliminate public exposure by removing WAN access and using a VPN, while enforcing strong credentials and keeping firmware up-to-date. Additionally, they should implement network segmentation for cameras on a dedicated VLAN and monitor for unusual login attempts and outbound connections.
infosecurity-magazine.comMar 4, 2026extracted
Interplay between Iranian Targeting of IP Cameras and Physical Warfare in the Middle East
Interplay between Iranian Targeting of IP Cameras and Physical Warfare in the Middle East March 4, 2026 Key Findings During the ongoing conflict, we identified intensified targeting of IP cameras from two manufacturers starting on February 28, originating from infrastructure we attribute to Iranian threat actors. The targeting extends across Israel, Qatar, Bahrain, Kuwait, the UAE, and Cyprus – countries that have also experienced significant missile activity linked to Iran. On March 1st, we additionally observed camera-targeting activity focused on specific areas in Lebanon. We also observed earlier, more targeted activity against cameras in Israel and Qatar on January 14–15. These dates surround with Iran’s temporary closure of its airspace, reportedly amid expectations of a potential U.S. strike. Taken together, these findings are consistent with the assessment that Iran, as part of its doctrine, leverages camera compromise for operational support and ongoing battle damage assessment (BDA) for missile operations, potentially in some cases prior to missile launches. As a result, tracking camera-targeting activity from specific, attributed infrastructures may serve as an early indicator of potential follow-on kinetic activity. Introduction As highlighted in the Cyber Security Report 2026, cyber operations have increasingly become an additional tool in interstate conflicts, used both to support military operations and to enable ongoing battle damage assessment (BDA). During the 12-day conflict between Israel and Iran in June 2025, the compromise of cameras was likely used to support BDA and/or target-correction efforts. In the current Middle East conflict, Check Point Research has observed intensified targeting of cameras beginning in the first hours of hostilities, including a sharp increase in exploitation attempts against IP cameras not only in Israel but also across Gulf countries: specifically the UAE, Qatar, Bahrain, and Kuwait, as well as similar activity in Lebanon and Cyprus. This activity originated from multiple attack infrastructures that we attribute to several Iran-nexus threat actors. Notably, we also identified earlier activity exhibiting similar patterns, dated January 14, coinciding with the peak of anti-regime protests in Iran, a period during which Iran anticipated potential action from the United States and Israel and temporarily closed its airspace. Findings Check Point Research (CPR) continuously tracks infrastructure used by Iran-nexus threat actors. Starting February 28, we observed a spike in targeting of IP cameras in several countries in the Middle East including Israel,UAE, Qatar, Bahrain, Kuwait and Lebanon, while also similar activity occurred against Cyprus. The attack infrastructure we track combines specific commercial VPN exit nodes (Mullvad, ProtonVPN, Surfshark, NordVPN) and virtual private servers (VPS), and is assessed to be employed by multiple Iran-nexus actors. Scanning activity we observed targets cameras such as Hikvision and Dahua and aligns with attempts to identify exposure to the vulnerabilities listed below. No attempts to interact with other camera vendors were observed from this infrastructure. The popular devices of Hikvision and Dahua are targeted with the following vulnerabilities: Patches are available for all of the vulnerabilities listed above. As a case study, we conducted a deep dive into two of the CVEs listed above – CVE-2021-33044 and CVE-2017-7921 – and examined exploitation attempts originating from operational infrastructure we attribute to Iran, observed since the beginning of the year. Waves of activity against Israel: The spikes in this activity are closely aligned with geopolitical events around the same time: January 14-15 – While internal anti-regime protests in Iran peaked, Iranian officials and state media portrayed the unrest as a foreign-backed plot by Iran’s adversaries, including the United States and Israel and also closed its airspace. At the same time we also observe a wave of scans of cameras in the Iraqi Kurdistan. January 24 – The U.S. Central Command (CENTCOM) commander visited Israel and met with the Israel Defense Forces’ chief of staff amid heightened tensions. Beginning of February – Iran’s leadership was increasingly worried about a possible U.S. strike; Iranian/IRGC-linked messaging warned a strike could trigger a wider regional war. Waves of activity against Qatar: Waves of activity against Bahrain: Waves of activity against Kuwait: Waves of activity against United Arab Emirates: Waves of activity against Cyprus: Waves of activity against Lebanon: We observed similar targeting patterns during the 12-day war between Israel and Iran in June 2025, likely to support battle damage assessment (BDA) and/or targeting correction. One of the best-known cases occurred when Iran struck Israel’s Weizmann Institute of Science with a ballistic missile and had reportedly taken control of a street camera facing the building just prior to the hit Recommendations for Defenders: Eliminate public exposure: remove direct WAN access to cameras/NVRs; place them behind VPN or a zero-trust access gateway; block inbound port-forwards. Patch management: keep cameras/NVR firmware and management software updated – updates from the manufacturers are available; remove/replace end-of-life devices that no longer get security fixes. Network segmentation: isolate cameras on a dedicated VLAN with no lateral access to corporate/OT networks; tightly control outbound traffic (only to required update/cloud endpoints). “The Turkish Rat” Evolved Adwind in a Massive Ongoing Phishing Campaign Check Point Research Publications August 11, 2017 “The Next WannaCry” Vulnerability is Here Check Point Research Publications March 12, 2026 “Handala Hack” – Unveiling Group’s Modus Operandi SUBSCRIBE TO CYBER INTELLIGENCE REPORTS We value your privacy! BFSI uses cookies on this site. We use cookies to enable faster and easier experience for you. By continuing to visit this website you agree to our use of cookies.
research.checkpoint.comMar 4, 2026extracted
Over 60 Software Vendors Issue Security Fixes Across OS, Cloud, and Network Platforms
It's Patch Tuesday, which means a number of software vendors have released patches for various security vulnerabilities impacting their products and services. Microsoft issued fixes for 59 flaws, including six actively exploited zero-days in various Windows components that could be abused to bypass security features, escalate privileges, and trigger a denial-of-service (DoS) condition. Elsewhere, Adobe released updates for Audition, After Effects, InDesign Desktop, Substance 3D, Bridge, Lightroom Classic, and DNG SDK. The company said it's not aware of in-the-wild exploitation of any of the shortcomings. SAP shipped fixes for two critical-severity vulnerabilities, including a code injection bug in SAP CRM and SAP S/4HANA (CVE-2026-0488, CVSS score: 9.9) that an authenticated attacker could use to run an arbitrary SQL statement and lead to a full database compromise. The second critical vulnerability is a case of a missing authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform (CVE-2026-0509, CVSS score: 9.6) that could permit an authenticated, low-privileged user to perform certain background Remote Function Calls without the required S_RFC authorization. "To patch the vulnerability, customers must implement a kernel update and set a profile parameter," Onapsis said. "Adjustments in user roles and UCON settings might be required to not interrupt business processes." Rounding off the list, Intel and Google said they teamed up to examine the security of Intel Trust Domain Extensions (TDX) 1.5, uncovering five vulnerabilities in the module (CVE-2025-32007, CVE-2025-27940, CVE-2025-30513, CVE-2025-27572, and CVE-2025-32467), and nearly three dozen weaknesses, bugs, and improvement suggestions. "Intel TDX 1.5 introduces new features and functionality that bring confidential computing significantly closer to feature parity with traditional virtualization solutions," Google said. "At the same time, these features have increased the complexity of a highly privileged software component in the TCB [Trusted Computing Base]." Software Patches from Other Vendors Security updates have also been released by other vendors in recent weeks to rectify several vulnerabilities, including — ABB Amazon Web Services AMD AMI Apple ASUS AutomationDirect AVEVA Broadcom (including VMware) Canon Check Point Cisco Citrix Commvault ConnectWise D-Link Dassault Systèmes Dell Devolutions dormakaba Drupal F5 Fortinet Foxit Software FUJIFILM Fujitsu Gigabyte GitLab Google Android and Pixel Google Chrome Google Cloud Grafana Hikvision Hitachi Energy HP HP Enterprise (including Aruba Networking and Juniper Networks) IBM Intel Ivanti Lenovo Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Mitsubishi Electric MongoDB Moxa Mozilla Firefox and Thunderbird n8n NVIDIA Phoenix Contact QNAP Qualcomm Ricoh Rockwell Automation Samsung Schneider Electric ServiceNow Siemens SolarWinds Splunk Spring Framework Supermicro Synology TP-Link WatchGuard Zoho ManageEngine Zoom, and Zyxel
thehackernews.comFeb 11, 2026extracted
⚡ Weekly Recap: Fortinet Exploits, RedLine Clipjack, NTLM Crack, Copilot Attack & More
In cybersecurity, the line between a normal update and a serious incident keeps getting thinner. Systems that once felt reliable are now under pressure from constant change. New AI tools, connected devices, and automated systems quietly create more ways in, often faster than security teams can react. This week’s stories show how easily a small mistake or hidden service can turn into a real break-in. Behind the headlines, the pattern is clear. Automation is being used against the people who built it. Attackers reuse existing systems instead of building new ones. They move faster than most organizations can patch or respond. From quiet code flaws to malware that changes while it runs, attacks are focusing less on speed and more on staying hidden and in control. If you’re protecting anything connected—developer tools, cloud systems, or internal networks—this edition shows where attacks are going next, not where they used to be. ⚡ Threat of the Week Critical Fortinet Flaw Comes Under Attack — A critical security flaw in Fortinet FortiSIEM has come under active exploitation in the wild. The vulnerability, tracked as CVE-2025-64155 (CVSS score: 9.4), allows an unauthenticated attacker to execute unauthorized code or commands via crafted TCP requests. In a technical analysis, Horizon3.ai described the issue as comprising two issues: an unauthenticated argument injection vulnerability that leads to arbitrary file write, allowing for remote code execution as the admin user, and a file overwrite privilege escalation vulnerability that leads to root access and complete compromise of the appliance. The vulnerability affects the phMonitor service, an internal FortiSIEM component that runs with elevated privileges and plays an integral role in system health and monitoring. Because the service is deeply embedded in FortiSIEM's operational workflow, successful exploitation grants attackers full control of the appliance. When Your CEO Calls, Will You Know It's Real? Today's phishing attacks involve AI voices, videos, and exec deepfakes. Adaptive Security is the first security awareness platform built to stop AI-powered social engineering. Adaptive protects your team with custom training and deepfake simulations featuring your own executives. Book a Demo ➝ 🔔 Top News VoidLink Linux Malware Enables Long-Term Access — A new cloud-native Linux malware framework named VoidLink focuses on cloud environments, providing attackers with a wide assortment of custom loaders, implants, rootkits, and plugins that are designed for additional stealth and for reconnaissance, privilege escalation, and lateral movement inside a compromised network. The feature-rich framework is engineered for long-term access, surveillance, and data collection rather than short-term disruption, allowing an operator to control agents, implants, and plugins via a web-based dashboard localized for Chinese users. Key to the malware's architecture is to "automate evasion as much as possible" by profiling a Linux environment and intelligently choosing the best strategy for operating without detection. Indeed, when signs of tampering or malware analysis are detected on an infected machine, it can delete itself and invoke anti-forensics modules designed to remove traces of its activity. It's fitted with an "unusually broad" feature set, including rootkit-style capabilities, an in-memory plug-in system for extending functionality, and the ability to adjust runtime evasion based on the security products it detects. VoidLink draws inspiration from Cobalt Strike, an adversary simulation framework that has been widely adopted and misused by attackers over the years. It's believed to be the work of Chinese developers. "Together, these plugins sit atop an already sophisticated core implementation, enriching VoidLink's capabilities beyond cloud environments to developer and administrator workstations that interface directly with those cloud environments, turning any compromised machine into a flexible launchpad for deeper access or supply-chain compromise," Check Point said. "Its design reflects a level of planning and investment typically associated with professional threat actors rather than opportunistic attackers." However, its intended use remains unclear, and no evidence of real-world infections has been observed, which supports the assumption that the modular malware was created "either as a product offering or as a framework developed for a customer." Microsoft Disrupts RedVDS Criminal Service — A cybercriminal subscription service responsible for fraud campaigns causing millions of dollars in losses has been disrupted in a coordinated action by Microsoft alongside legal partners in the U.S. and, for the first time, the U.K. The Windows makers said it seized the website and infrastructure of RedVDS, a platform that hosted cybercrime-as-a-service tools for phishing and fraud campaigns, which cost users as little as $24 a month. The subscription service is known to have cost victims in the U.S. alone over $40 million since March 2025. In total, Microsoft has identified nearly 190,000 organizations worldwide that fell victim to RedVDS-supported campaigns. In one month, the company noted approximately 2,600 RedVDS virtual machines sent an average of 1 million phishing messages to Microsoft customers daily. RedVDS provided cybercriminals with access to cheap, effective, and disposable virtual computers running unlicensed software, including Windows, allowing criminals to conduct phishing attacks and business email compromise (BEC) schemes. The service is also said to have been a player in the spread of real estate payment diversion scams, affecting more than 9,000 customers primarily in Canada and Australia. RedVDS did not own physical data centers and instead rented servers from third-party hosting providers in the U.S., Canada, the U.K., France, and the Netherlands. "Once provisioned, these cloned Windows hosts gave actors a ready‑made platform to research targets, stage phishing infrastructure, steal credentials, hijack mailboxes, and execute impersonation‑based financial fraud with minimal friction," Microsoft said. "Threat actors benefited from RedVDS’s unrestricted administrative access and negligible logging, allowing them to operate without meaningful oversight. The uniform, disposable nature of RedVDS servers allowed cybercriminals to rapidly iterate campaigns, automate delivery at scale, and move quickly from initial targeting to financial theft." Over 550 Kimwolf Botnet C2 Nodes Null-Routed — Lumen Technologies' Black Lotus Labs has blocked more than 550 command-and-control (C2) nodes linked to Aisuru and Kimwolf's servers since October 2025, as the botnets gained attention for their role in orchestrating hypervolumetric distributed denial-of-service (DDoS) attacks. Kimwolf, which is said to mainly target unsanctioned Android TV boxes, has caught on like wildfire, corralling over 2 million devices into its botnet. The disruption of RapperBot and the arrest of its alleged leader in August 2025 played a key factor in the rise of Aisuru and Kimwolf. Recent research by QiAnXin XLab and Synthient revealed how the botnet's operators have leveraged proxy services to expand its reach. In a separate report, Infoblox said nearly 25% of its cloud customers made a query to a Kimwolf domain since October 1, 2025. "The main takeaway is these residential proxies are literally everywhere," Chris Formosa, senior lead information security engineer at Lumen Technologies' Black Lotus Labs, told The Hacker News. "Like everywhere and in most organizations you can think of. Given we know the actors were exploiting it, the story is mainly a story of a lot of networks you may think are secured, but have devices running residential proxies which can provide attackers with an opportunity to get an initial foothold, bypassing a large majority of your devices you likely have in place." Reprompt Attack Targets Microsoft Copilot — Security researchers discovered a new attack named Reprompt that allowed them to exfiltrate user data from Microsoft Copilot once a victim clicks on a specifically crafted link pointing to the artificial intelligence (AI) chatbot. The attack bypasses data leak protections and allows for persistent session exfiltration even after the Copilot session was closed. The attack leverages a combination of Parameter 2 Prompt (P2P) injection (i.e., the exploitation of the "q" parameter), a double-request technique, and a chain-request technique to obtain a data exfiltration primitive. "Client-side monitoring tools won't catch these malicious prompts, because the real data leaks happen dynamically during back-and-forth communication — not from anything obvious in the prompt the user submits," Varonis said. The attack does not affect enterprise customers using Microsoft 365 Copilot. Microsoft has since addressed the issue. AWS CodeBuild Misconfiguration Creates Supply Chain Risks — A critical misconfiguration in Amazon Web Services (AWS) CodeBuild could have allowed complete takeover of the cloud service provider's own GitHub repositories, including its AWS JavaScript SDK, putting every AWS environment at risk. The vulnerability, codenamed CodeBreach, was fixed by AWS in September 2025. "By exploiting CodeBreach, attackers could have injected malicious code to launch a platform-wide compromise, potentially affecting not just the countless applications depending on the SDK, but the Console itself, threatening every AWS account," Wiz said. ️🔥 Trending CVEs Hackers act fast. They can use new bugs within hours. One missed update can cause a big breach. Here are this week’s most serious security flaws. Check them, fix what matters first, and stay protected. This week’s list includes — CVE-2025-20393 (Cisco AsyncOS Software), CVE-2026-23550 (Modular DS plugin), CVE-2026-0227 (Palo Alto Networks PAN-OS), CVE-2025-64155 (Fortinet FortiSIEM), CVE-2026-20805 (Microsoft Windows Desktop Window Manager), CVE-2025-12420 (ServiceNow), CVE-2025-55131, CVE-2025-55131, CVE-2025-59466, CVE-2025-59465 (Node.js), CVE-2025-68493 (Apache Struts 2), CVE-2026-22610 (Angular Template Compiler), CVE-2025-66176, CVE-2025-66177 (Hikvision), CVE-2026-0501, CVE-2026-0500, CVE-2026-0498, CVE-2026-0491 (SAP), CVE-2026-21859, CVE-2026-22689 (Mailpit), CVE-2026-22601, CVE-2026-22602, CVE-2026-22603, CVE-2026-22604 (OpenProject), CVE-2026-23478 (Cal.com), CVE-2025-14364 (Demo Importer Plus plugin), CVE-2025-14502 (News and Blog Designer Bundle), CVE-2025-14301 (Integration Opvius AI for WooCommerce plugin), CVE-2025-52493 (PagerDuty Runbook), CVE-2025-55315 (ASP.NET Core Kestrel server), CVE-2026-20965 (Microsoft Windows Admin Center), and CVE-2025-14894 (Livewire Filemanager). 📰 Around the Cyber World Unpatched Flaw in Livewire Filemanager — An unpatched security flaw was disclosed in Livewire Filemanager, a file manager component for Laravel-based websites that allows file uploads. The vulnerability (CVE-2025-14894, CVSS score: 7.5) can permit threat actors to upload malicious PHP files to a remote server and trigger its execution. "When a user uploads a PHP file to the application, it can be accessed and executed by visiting the web-accessible file hosting directory," the CERT Coordination Center (CERT/CC) said. "This enables an attacker to create a malicious PHP file, upload it to the application, then force the application to execute it, enabling unauthenticated arbitrary code execution on the host device." More GhostPoster Extensions Spotted — LayerX said it found a new cluster of 17 extensions related to GhostPoster impacting Google Chrome and Microsoft Edge. The new extensions, which are designed to hijack affiliate links, inject tracking code, and commit click and ad fraud, have a collective install base of over 840,000 users, and some of them date back to 2020. GhostPoster, first disclosed last month, is part of a broader campaign undertaken by a Chinese threat actor dubbed DarkSpectre. The new findings show that GhostPoster first originated on Microsoft Edge in February 2020 and then expanded to Firefox and Chrome. RedLineCyber Distributes Clipboard Hijacking Malware — A threat actor named RedLineCyber has been observed leveraging the notoriety of the well-known RedLine information stealer to distribute an executable called "Pro.exe" (or "peeek.exe"). It's a Python-based clipboard hijacking trojan that is designed for cryptocurrency theft by continuously monitoring the Windows clipboard for cryptocurrency wallet addresses and substituting them with a wallet address under their control to facilitate cryptocurrency theft. "The threat actor exploits trust relationships within Discord communities focused on gaming, gambling, and cryptocurrency streaming," CloudSEK said. "Distribution occurs through direct social engineering, where the actor cultivates relationships with potential victims, particularly cryptocurrency streamers and influencers, over extended periods before introducing the malicious payload as a 'security tool' or 'streaming utility.'" Fake Shipping Documents Deliver Remcos RAT — A new phishing campaign is using shipping-themed lures to trick recipients into opening a malicious Microsoft Word document that, in turn, triggers an exploit for a years-old security flaw in Microsoft Office (CVE-2017-11882) to distribute a new variant of Remcos RAT that's executed directly in memory, Fortinet said. Successful exploitation of the vulnerability triggers the download of a Visual Basic Script, which executes Base64-code PowerShell code to download and launch a .NET DLL loader module responsible for launching the RAT in addition to setting up persistence using scheduled tasks. An off-the-shelf malware, Remcos RAT (version 7.0.4 Pro) enables comprehensive data gathering capabilities, including system management, surveillance, networking, communication, and agent control. In another campaign detected by AhnLab, users in South Korea have been targeted by Remcos RAT malware masquerading as VeraCrypt installers or software associated with illegal gambling websites. Google Releases Rainbow Tables to Speed Up Demise of Net-NTLMv1 — Google's Mandiant threat intelligence division released a comprehensive dataset of Net-NTLMv1 rainbow tables to emphasize the need for urgently moving away from the outdated protocol. While Microsoft previously announced its plans to deprecate NTLM in favor of Kerberos, Google said it continues to identify the use of Net-NTLMv1 in active environments, leaving organizations vulnerable to trivial credential theft. "While tools to exploit this protocol have existed for years, they often required uploading sensitive data to third-party services or expensive hardware to brute-force keys," Google said. "The release of this dataset allows defenders and researchers to recover keys in under 12 hours using consumer hardware costing less than $600 USD." Former U.S. Navy Sailor Sentenced to 200 Months for Spying for China — Jinchao Wei (aka Patrick Wei), 25, a former U.S. Navy sailor, was sentenced in the U.S. to 200 months in prison for selling secrets to China by abusing his security clearance and access to sensitive national defense information about the amphibious assault ship U.S.S. Essex. Wei was convicted of espionage charges in August 2025 following his arrest in August 2023. "By sharing thousands of documents, operating manuals, and export-controlled and sensitive information with a Chinese intelligence officer, Petty Officer Wei knowingly betrayed his fellow service members and the American people," said NCIS Director Omar Lopez. Wei was recruited by a Chinese intelligence officer in February 2022 and sent photographs and videos of the Essex via an encrypted messaging application, and advised the officer of the location of various Navy ships. He also described the defensive weapons of the Essex, sent thousands of pages of technical and operational information about U.S. Navy surface warfare ships, and sold approximately 60 technical and operational manuals about U.S. Navy ships. In exchange, Wei received more than $12,000 over 18 months. Post his arrest, Wei admitted to the Federal Bureau of Investigation (FBI) that what he did amounted to espionage and that "I'm screwed." Australia Warns Domestic Firms About AI Security Risks — The Australian Signals Directorate (ASD) has warned local businesses against uploading customer data and files to AI chatbots or genAI platforms without proper anonymization. "Some artificial intelligence providers may use customer‑submitted data to train or refine their models. This can depend on the configuration settings or the type of subscription," ASD said. "As a result, information entered into these platforms could potentially be reused or disclosed in unexpected contexts later." It also warned that AI systems are susceptible to hallucinations and can be tricked by malicious cyber actors through prompt injections, which refer to malicious inputs disguised as legitimate requests designed to confuse or mislead the AI into giving sensitive, wrong, or unsafe answers. Furthermore, ASD warned of potential supply chain risks resulting from AI integration, emphasizing the need for secure deployment of AI chatbots. Jordan National Pleads Guilty to Selling Access — A Jordanian national pleaded guilty in the U.S. to charges of selling access to the networks of at least 50 companies through a cybercriminal forum. Feras Khalil Ahmad Albashiti (aka r1z, Feras Bashiti, and Firas Bashiti), 40, is facing a maximum penalty of 10 years in prison after being charged with fraud and related activity in connection with access credentials. Albashiti was arrested in July 2024. His sentencing will take place in May 2026. The FBI, which contacted the defendant in September 2026 under cover, said it was able to trace the "r1z” cybercrime forum account to Albashiti because it was registered in 2018 with the same Gmail address that was used to apply for a U.S. visa in October 2016. According to a report from SentinelOne, the "r1z" account marketed a malware dropper and bypass service called EDR Killer on underground forums. The account was previously identified as advertising access to 50 vulnerable Confluence servers acquired by exploiting the critical Confluence unauthenticated RCE vulnerability, tracked as CVE-2022-26134, and claimed to be in possession of a list of over 10,000 vulnerable Confluence servers. Other tools included illicit versions of Cobalt Strike, private exploits for local privilege escalation (LPE) vulnerabilities in different services, access to 30 SonicWall VPN and 50 Microsoft Exchange servers with a working exploit, as well as a service that acquired compromised VPN and RDP login credentials from other criminals on the XSS forum. R1z is said to have been active on XSS since 2019. Google Agrees to Pay $8.25M to Settle Children Privacy Violations — Google has agreed to pay $8.25 million to settle a class-action lawsuit that claimed the company illegally collected data from devices belonging to children under age 13, The Record reported. The case was brought more than two years ago by the parents of six minors who allegedly downloaded apps and games from the Play Store that were targeted at children, such as Fun Kid Racing, GummyBear, and Friends Speed Racing. The apps, according to the lawsuit, came with Google's AdMob software development kit that collected data from children at scale, violating the Children's Online Privacy Protection Act (COPPA). U.S. Bank Targeted by Keylogger — Sansec identified a keylogger on the employee merchandise store of a major U.S. bank. The store is used by the bank's 200,000 employees to order company-branded items. "The malware intercepts everything typed into the site's forms: login credentials, payment card numbers, personal information," the Dutch company said. "The stolen data is exfiltrated via image beacon, a common technique that bypasses many security controls." The malware has since been removed from the site. The activity is assessed to share overlaps with an October 2024 breach of the Green Bay Packers Pro Shop, citing infrastructure pattern similarities. Payroll Pirates Redirect Paychecks to Accounts Under Their Control — In a new social engineering attack targeting an unnamed organization, the threat actors behind Payroll Pirates reached out via a phone call, impersonating employees to manipulate multiple help desks and successfully perform password resets and re-enroll multi-factor authentication (MFA) devices. The threat actor has also been observed attempting to establish persistence by registering an external email address as an authentication method for a service account within the client's Azure AD environment. "Once authenticated into the payroll system, the attacker moved quickly," Palo Alto Networks Unit 42 said. "In total, they compromised multiple employee accounts, each one granting access to sensitive payroll information. The attacker then proceeded to modify direct-deposit details for multiple individuals, redirecting their paychecks into bank accounts under the attacker’s control. Because the credentials were valid and MFA appeared legitimate, the activity blended in with normal operations. The incident was discovered only when employees reported missing paychecks." New Attack Uses DLL Side-Loading to Distribute PDFSIDER Malware — An unknown threat actor is leveraging DLL side-loading to deploy PDFSIDER, a backdoor with encrypted C2 capabilities, using a legitimate executable associated with PDF24 Creator ("pdf24.exe"). The malware operates primarily in memory, minimizing disk artifacts. "PDFSIDER blends traditional cyber-espionage behaviors with modern remote-command functionality, enabling operators to gather system intelligence and remotely execute shell commands covertly," Resecurity said. "The malware uses a fake cryptbase.dll to bypass endpoint detection mechanisms. Once loaded, the malware provides attackers with an interactive, hidden command shell and can exfiltrate command output through its encrypted channel." The malware is delivered via spear-phishing emails that guide victims to a ZIP archive attached to the message. Resecurity told The Hacker News that PDFSIDER has been used in targeted attacks either via spear-phishing or a social engineering attack in which the threat actors impersonate tech support personnel to contact employees in large enterprises and government agencies and deliver the package over Microsoft Teams or Quick Assist. The cybersecurity company also said it observed an affiliate of Qilin ransomware using the malware, although it expects more groups to join the bandwagon. There is no evidence it's being advertised under a malware-as-a-service (MaaS) model. 🎥 Cybersecurity Webinars How Top MSSPs Are Using AI to Grow in 2026: Learn Their Formula — By 2026, MSSPs are under pressure to do more with less, and AI is becoming the edge that separates those who scale from those who stall. This session explores how automation reduces manual work, improves margins, and enables growth without adding headcount, with real-world insights from Cynomi founder David Primor and Secure Cyber Defense CISO Chad Robinson on turning expertise into repeatable, high-value services. Stop Guessing Your SOC Strategy: Learn What to Build, Buy, or Automate — Modern SOC teams are overloaded with tools, noise, and promises that don’t translate into results, making it hard to know what to build, buy, or automate. In this session, AirMDR CEO Kumar Saurabh and SACR CEO Francis Odum cut through the clutter with a practical, vendor-neutral look at SOC operating models, maturity, and real-world decision frameworks—leaving teams with a clear, actionable path to simplify their stack and make their SOC work more effectively. 🔧 Cybersecurity Tools AuraInspector — It is an open-source tool for auditing Salesforce Experience Cloud security. It helps find misconfigurations that could expose data or admin functions by checking accessible records, self-registration options, and hidden “home URLs.” The tool automates much of the testing, including object discovery through GraphQL methods, and works in both guest and authenticated contexts. It’s a research utility, not an official Google product, designed to make Salesforce Aura security testing faster and more reliable. Maltrail — It is an open-source tool for detecting malicious network traffic. It compares network activity against known blacklists of suspicious domains, IPs, URLs, and user agents linked to malware or attacks, and can also flag new threats using heuristics. The system uses sensors to monitor traffic and a central server to log and display events through a web interface, helping identify infected hosts or abnormal activity in real time. Disclaimer: These tools are for learning and research only. They haven’t been fully tested for security. If used the wrong way, they could cause harm. Check the code first, test only in safe places, and follow all rules and laws. Conclusion The message is clear. Today’s threats aren’t just single break-ins. They come from connected weak spots, where one exposed service or misused tool can affect an entire system. Attackers don’t see cloud platforms, AI tools, and enterprise software as separate. They see one shared space. Defenders need to think the same way, treating every part of their environment as connected and worth watching all the time, not just after something goes wrong. What happened this week isn’t unusual. It’s a warning. Every update, setting, and access rule matters, because the next attack will likely begin from something already inside. This recap shows how small gaps turned into big openings—and what’s being done to close them before the next round begins.
thehackernews.comJan 19, 2026extracted
Microsoft Fixes 114 Windows Flaws in January 2026 Patch, One Actively Exploited
Microsoft on Tuesday rolled out its first security update for 2026, addressing 114 security flaws, including one vulnerability that it said has been actively exploited in the wild. Of the 114 flaws, eight are rated Critical, and 106 are rated Important in severity. As many as 58 vulnerabilities have been classified as privilege escalation, followed by 22 information disclosure, 21 remote code execution, and five spoofing flaws. According to data collected by Fortra, the update marks the third-largest January Patch Tuesday after January 2025 and January 2022. These patches are in addition to two security flaws that Microsoft has addressed in its Edge browser since the release of the December 2025 Patch Tuesday update, including a spoofing flaw in its Android app (CVE-2025-65046, 3.1) and a case of insufficient policy enforcement in Chromium's WebView tag (CVE-2026-0628, CVSS score: 8.8). The vulnerability that has come under in-the-wild exploitation is CVE-2026-20805 (CVSS score: 5.5), an information disclosure flaw impacting Desktop Window Manager. The Microsoft Threat Intelligence Center (MTIC) and Microsoft Security Response Center (MSRC) have been credited with identifying and reporting the flaw. "Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager (DWM) allows an authorized attacker to disclose information locally," Microsoft said in an advisory. "The type of information that could be disclosed if an attacker successfully exploited this vulnerability is a section address from a remote ALPC port, which is user-mode memory." There are currently no details on how the vulnerability is being exploited, the scale of such efforts, and who may be behind the activity. "DWM is responsible for drawing everything on the display of a Windows system, which means it offers an enticing combination of privileged access and universal availability, since just about any process might need to display something," Adam Barnett, lead software engineer at Rapid7, said in a statement. "In this case, exploitation leads to improper disclosure of an ALPC port section address, which is a section of user-mode memory where Windows components coordinate various actions between themselves." Microsoft previously addressed an actively exploited zero-day flaw in DWM in May 2024 (CVE-2024-30051, CVSS score: 7.8), which was described as a privilege escalation flaw that was abused by multiple threat actors, in connection with the distribution of QakBot and other malware families. Satnam Narang, senior staff research engineer at Tenable, called DWM a "frequent flyer" on Patch Tuesday, with 20 CVEs patched in the library since 2022. Jack Bicer, director of vulnerability research at Action1, said the vulnerability can be exploited by a locally authenticated attacker to disclose information, defeat address space layout randomization (ASLR), and other defenses. "Vulnerabilities of this nature are commonly used to undermine Address Space Layout Randomization (ASLR), a core operating system security control designed to protect against buffer overflows and other memory-manipulation exploits," Kev Breen, senior director of cyber threat research at Immersive, told The Hacker News. "By revealing where code resides in memory, this vulnerability can be chained with a separate code execution flaw, transforming a complex and unreliable exploit into a practical and repeatable attack." The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has since added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, mandating Federal Civilian Executive Branch (FCEB) agencies to apply the latest fixes by February 3, 2026. Another vulnerability of note concerns a security feature bypass impacting Secure Boot Certificate Expiration (CVE-2026-21265, CVSS score: 6.4) that could allow an attacker to undermine a crucial security mechanism that ensures that firmware modules come from a trusted source and prevent malware from being run during the boot process. In November 2025, Microsoft announced that it will be expiring three Windows Secure Boot certificates issued in 2011, effective June 2026, urging customers to update to their 2023 counterparts - Microsoft Corporation KEK CA 2011 (June 2026) - Microsoft Corporation KEK 2K CA 2023 (for signing updates to DB and DBX) Microsoft Windows Production PCA 2011 (October 2026) - Windows UEFI CA 2023 (for signing the Windows boot loader) Microsoft UEFI CA 2011 (June 2026) - Microsoft UEFI CA 2023 (for signing third-party boot loaders) and Microsoft Option ROM UEFI CA 2023 (for signing third-party option ROMs) "Secure Boot certificates used by most Windows devices are set to expire starting in June 2026. This might affect the ability of certain personal and business devices to boot securely if not updated in time," Microsoft said. "To avoid disruption, we recommend reviewing the guidance and taking action to update certificates in advance." The Windows maker also pointed out that the latest update removes Agere Soft Modem drivers "agrsm64.sys" and "agrsm.sys" that were shipped natively with the operating system. The third-party drivers are susceptible to a two-year-old local privilege escalation flaw (CVE-2023-31096, CVSS score: 7.8) that could allow an attacker to gain SYSTEM permissions. In October 2025, Microsoft took steps to remove another Agere Modem driver called "ltmdm64.sys" following in-the-wild exploitation of a privilege escalation vulnerability (CVE-2025-24990, CVSS score: 7.8) that could permit an attacker to gain administrative privileges. Also high on the priority list should be CVE-2026-20876 (CVSS score: 6.7), a critical-rated privilege escalation flaw in Windows Virtualization-Based Security (VBS) Enclave, enabling an attacker to obtain Virtual Trust Level 2 (VTL2) privileges, and leverage it to subvert security controls, establish deep persistence, and evade detection. "It breaks the security boundary designed to protect Windows itself, allowing attackers to climb into one of the most trusted execution layers of the system," Mike Walters, president and co-founder of Action1, said. "Although exploitation requires high privileges, the impact is severe because it compromises virtualization-based security itself. Attackers who already have a foothold could use this flaw to defeat advanced defenses, making prompt patching essential to maintain trust in Windows security boundaries." Software Patches from Other Vendors In addition to Microsoft, security updates have also been released by other vendors since the start of the month to rectify several vulnerabilities, including — ABB Adobe Amazon Web Services AMD Arm ASUS Broadcom (including VMware) Cisco ConnectWise Dassault Systèmes D-Link Dell Devolutions Drupal Elastic F5 Fortinet Fortra Foxit Software FUJIFILM Gigabyte GitLab Google Android and Pixel Google Chrome Google Cloud Grafana Hikvision HP HP Enterprise (including Aruba Networking and Juniper Networks) IBM Imagination Technologies Lenovo Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Mitel Mitsubishi Electric MongoDB Moxa Mozilla Firefox and Firefox ESR n8n NETGEAR Node.js NVIDIA ownCloud QNAP Qualcomm Ricoh Samsung SAP Schneider Electric ServiceNow Siemens SolarWinds SonicWall Sophos Spring Framework Synology TP-Link Trend Micro, and Veeam
thehackernews.comJan 14, 2026extracted
Arizona Attorney General Sues Chinese Online Retailer Temu Over Data Theft Claims
Arizona Attorney General Kris Mayes announced Tuesday that Arizona is the latest state to sue Temu and its parent company PDD Holdings Inc. over allegations that the Chinese online retailer is stealing customers’ data. Mayes said the app deceives customers about the quality of its low-cost products and collects what she described as a shocking amount of sensitive data without the consent of users, including GPS locations and a list of other apps on users’ phones. According to the lawsuit, prosecutors are concerned about Temu being subject to laws in China that require Chinese companies to hand over data requested by the government, and that its code is designed to evade security reviews. “It can detect everywhere you go, to a doctor’s office, to a public library, to a political event, to your friends’ houses,” Mayes said during a news conference. “So the scope of this invasion of privacy is enormous, and that’s why I consider it possibly the gravest violation of the Arizona Consumer Fraud Act that we have ever seen in Arizona.” Arizona’s top prosecutor also said the state wants to protect businesses from being “ripped off” by the online retailer, alleging the company has copied the intellectual property of brands that include the Arizona Cardinals and Arizona State University. Attorneys general in Kentucky, Nebraska and Arkansas have filed similar lawsuits in recent years. There have been legislative efforts at the federal level to counter China’s influence, especially when it comes to technology and intellectual property. But Mayes suggested there should be greater intervention by the federal government to protect consumers. Mayes called the allegations against Temu more egregious than those that have been made against TikTok. Through a forensic review, investigators in Arizona found the app’s code has portions recognized by experts as malware or spyware and allows exfiltration of data from a user’s mobile device while concealing that the app is doing so. The review also found in the app “large swaths” of previously banned code from the platform’s precursor version. Mayes urged Arizonans to delete their Temu accounts, uninstall the app and scan their devices for malware. Related: TikTok Faces Fresh European Privacy Investigation Over China Data Transfers Related: Canada Gives Hikvision the Boot on National Security Grounds Related: Vodafone Germany Fined $51 Million Over Privacy, Security Failures
securityweek.comDec 3, 2025extracted
Microsoft Fixes 80 Flaws — Including SMB PrivEsc and Azure CVSS 10.0 Bugs
Microsoft on Tuesday addressed a set of 80 security flaws in its software, including one vulnerability that has been disclosed as publicly known at the time of release. Of the 80 vulnerabilities, eight are rated Critical and 72 are rated Important in severity. None of the shortcomings has been exploited in the wild as a zero-day. Like last month, 38 of the disclosed flaws are related to privilege escalation, followed by remote code execution (22), information disclosure (14), and denial-of-service (3). "For the third time this year, Microsoft patched more elevation of privilege vulnerabilities than remote code execution flaws," Satnam Narang, senior staff research engineer at Tenable, said. "Nearly 50% (47.5%) of all bugs this month are privilege escalation vulnerabilities." The patches are in addition to 12 vulnerabilities addressed in Microsoft's Chromium-based Edge browser since the release of August 2025's Patch Tuesday update, including a security bypass bug (CVE-2025-53791, CVSS score: 4.7) that has been patched in version 140.0.3485.54 of the browser. The vulnerability that has been flagged as publicly known is CVE-2025-55234 (CVSS score: 8.8), a case of privilege escalation in Windows SMB. "SMB Server might be susceptible to relay attacks depending on the configuration," Microsoft said. "An attacker who successfully exploited these vulnerabilities could perform relay attacks and make the users subject to elevation of privilege attacks." The Windows maker said the update enables support for auditing SMB client compatibility for SMB Server signing as well as SMB Server EPA, allowing customers to assess their environment and detect any potential device or software incompatibility issues before deploying appropriate hardening measures. "The key takeaway from the CVE-2025-55234 advisory, other than the explanation of the well-known attack surface around SMB authentication, is that this is one of those times where simply patching isn't enough; in fact, the patches provide administrators with more auditing options to determine whether their SMB Server is interacting with clients that won't support the recommended hardening options," Adam Barnett, lead software engineer at Rapid7, said. Mike Walters, president and co-founder of Action, said the vulnerability stems from the fact that SMB sessions can be established without properly validating the authentication context when key hardening measures, such as SMB signing and Extended Protection for Authentication, are not in place. "This gap opens the door to man-in-the-middle relay attacks, where attackers can capture and forward authentication material to gain unauthorized access," Walters added. "It can easily become part of a larger campaign, moving from phishing to SMB relay, credential theft, lateral movement, and eventually data exfiltration." The CVE with the highest CVSS score for this month, but not listed in the Release Notes, is CVE-2025-54914 (CVSS score: 10.0), a critical flaw impacting Azure Networking that could result in privilege escalation. It requires no customer action, given that it's a cloud-related vulnerability. Two other shortcomings that merit attention include a remote code execution flaw in Microsoft High Performance Compute (HPC) Pack (CVE-2025-55232, CVSS score: 9.8) and an elevation of privilege issue affecting Windows NTLM (CVE-2025-54918, CVSS score: 8.8) that could allow an attacker to gain SYSTEM privileges. "From Microsoft's limited description, it appears that if an attacker is able to send specially crafted packets over the network to the target device, they would have the ability to gain SYSTEM-level privileges on the target machine," Kev Breen, senior director of threat research at Immersive, said. "The patch notes for this vulnerability state that 'Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network,' suggesting an attacker may already need to have access to the NTLM hash or the user's credentials." Lastly, the update also remediates a security flaw (CVE-2024-21907, CVSS score: 7.5) in Newtonsoft.Json, a third-party component used in SQL Server, that could be exploited to trigger a denial-of-service condition, as well as two privilege escalation vulnerabilities in Windows BitLocker (CVE-2025-54911, CVSS score: 7.3, and CVE-2025-54912, CVSS score: 7.8). Microsoft's Hussein Alrubaye has been credited with discovering and reporting both the BitLocker flaws. The two defects add to four other vulnerabilities in the full-disk encryption feature (collectively called BitUnlocker) that were patched by Microsoft in July 2025 - CVE-2025-48003 (CVSS score: 6.8) - BitLocker Security Feature Bypass Vulnerability via WinRE Apps Scheduled Operation CVE-2025-48800 (CVSS score: 6.8) - BitLocker Security Feature Bypass Vulnerability by Targeting ReAgent.xml Parsing CVE-2025-48804 (CVSS score: 6.8) - BitLocker Security Feature Bypass Vulnerability by Targeting Boot.sdi Parsing CVE-2025-48818 (CVSS score: 6.8) - BitLocker Security Feature Bypass Vulnerability by Targeting Boot Configuration Data (BCD) Parsing Successful exploitation of any of the above four flaws could allow an attacker with physical access to the target to bypass BitLocker protections and gain access to encrypted data. "To further enhance the security of BitLocker, we recommend enabling TPM+PIN for pre-boot authentication," Security Testing and Offensive Research at Microsoft (STORM) researchers Netanel Ben Simon and Alon Leviev said in a report last month. "This significantly reduces the BitLocker attack surfaces by limiting exposure to only the TPM." "To mitigate BitLocker downgrade attacks, we advise enabling the REVISE mitigation. This mechanism enforces secure versioning across critical boot components, preventing downgrades that could reintroduce known vulnerabilities in BitLocker and Secure Boot." The disclosure comes as Purple Team detailed a new lateral movement technique dubbed BitLockMove that involves the remote manipulation of BitLocker registry keys via Windows Management Instrumentation (WMI) to hijack specific COM objects of BitLocker. BitLockMove, developed by security researcher Fabian Mosch, works by initiating a remote connection to the target host through WMI and copying a malicious DLL to the target over SMB. In the next phase, the attacker writes a new registry key that specifies the DLL path, ultimately causing BitLocker to load the copied DLL by hijacking its COM objects. "The purpose of the BitLocker COM Hijacking is to execute code under the context of the interactive user on a target host," Purple Team said. "In the event that the interactive user has excessive privileges (i.e., domain administrator), this could also lead to domain escalation." Software Patches from Other Vendors In addition to Microsoft, security updates have also been released by other vendors over the past several weeks to rectify several vulnerabilities, including — Adobe Arm Broadcom (including VMware) Cisco Commvault Dell Drupal F5 Fortra FUJIFILM Gigabyte GitLab Google Android and Pixel Google Chrome Google Cloud Google Wear OS Fortinet Hikvision Hitachi Energy HP HP Enterprise (including Aruba Networking) IBM Ivanti Jenkins Juniper Networks Lenovo Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Mitsubishi Electric Moxa Mozilla Firefox, Firefox ESR, and Thunderbird NVIDIA QNAP Qualcomm Rockwell Automation Salesforce Samsung SAP Schneider Electric Siemens Sitecore Sophos Spring Framework Supermicro Synology TP-Link, and Zoom
thehackernews.comSep 10, 2025extracted
Videosorveglianza sotto attacco: Un bug in Hikvision consente accesso admin senza login
Betti RHC, la prima graphic novel al mondo dedicata alla cybersecurity awareness, ha finalmente il suo sito ufficiale. Uno spazio tutto suo dove scoprire il progetto, sfogliare le copertine degli episodi e immergersi nel mondo di Betti: la giovane laureanda in informatica che, dopo la morte misteriosa del padre, si trasforma nell'hacker più potente del mondo. Una storia avvincente che, episodio dopo episodio, affronta una minaccia digitale diversa — dal phishing al ransomware, fino al cyberbullismo — e insegna a riconoscerla e a difendersi, senza che sembri mai una lezione. Sul sito trovate tutto ciò che rende Betti un progetto diverso dal solito: la sua filosofia, le anteprime delle tavole e il racconto di come nasce ogni volume. Perché dietro Betti RHC c'è solo lavoro umano: ogni tavola è disegnata interamente a mano dagli artisti del Gruppo Arte di Red Hot Cyber, senza alcun uso di intelligenza artificiale. E a garantire che ogni storia sia realistica e tecnicamente corretta c'è la supervisione degli hacker etici del gruppo HackerHood, che mantengono il racconto fedele al mondo reale della sicurezza informatica. C'è spazio anche per le aziende, che possono usare Betti come strumento di awareness diverso dai soliti corsi: acquistare i volumi, personalizzarli con il proprio brand o sponsorizzare nuovi episodi. E come primo regalo, l'episodio "Byte the Silence", dedicato al cyberbullismo, è scaricabile gratuitamente per uso personale. Perché la miglior difesa, in fondo, è una bella storia. 👉 Scopri tutto su https://betti.redhotcyber.com/
redhotcyber.comSep 2, 2025extracted
⚡ Weekly Recap: WhatsApp 0-Day, Docker Bug, Salesforce Breach, Fake CAPTCHAs, Spyware App & More
Cybersecurity today is less about single attacks and more about chains of small weaknesses that connect into big risks. One overlooked update, one misused account, or one hidden tool in the wrong hands can be enough to open the door. The news this week shows how attackers are mixing methods—combining stolen access, unpatched software, and clever tricks to move from small entry points to large consequences. For defenders, the lesson is clear: the real danger often comes not from one major flaw, but from how different small flaws interact together. ⚡ Threat of the Week WhatsApp Patches Actively Exploited Flaw — WhatsApp addressed a security vulnerability in its messaging apps for Apple iOS and macOS that it said may have been exploited in the wild in conjunction with a recently disclosed Apple flaw in targeted zero-day attacks. The vulnerability, CVE-2025-55177 relates to a case of insufficient authorization of linked device synchronization messages. The Meta-owned company said the issue "could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target's device." It also assessed that the shortcoming may have been chained with CVE-2025-43300, a vulnerability affecting iOS, iPadOS, and macOS, as part of a sophisticated attack against specific targeted users. WhatsApp said it sent in-app threat notifications to less than 200 users who may have been targeted as part of the spyware campaign. Level Up Your Auth for Not Only Your Users, But Also Your AI Agents Auth0 provides robust security and gives you control over the user experience, from sign-up flows to advanced authorization. Learn More ➝ 🔔 Top News U.S. Treasury Continues to Hit IT Worker Scheme with Sanctions — The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) sanctioned a fraudulent IT worker network linked to the Democratic People's Republic of Korea (DPRK). This included Vitaliy Sergeyevich Andreyev, a Russian national who facilitated payments to Chinyong Information Technology Cooperation Company (Chinyong), also known as Jinyong IT Cooperation Company, which was sanctioned by OFAC and South Korea’s Ministry of Foreign Affairs (MOFA) in May 2023. Also included in the designation were Kim Ung Sun, Shenyang Geumpungri Network Technology Co., Ltd., and Korea Sinjin Trading Corporation. These actors were designated for their involvement in schemes that funnel DPRK IT worker-derived revenue to support DPRK weapons of mass destruction and ballistic missile programs. The cryptocurrency wallet linked to Andreyev has "received over $600,000 of payments and has source exposure back to the Atomic Wallet exploit of June 2023," which was attributed to the Lazarus Group, per Elliptic. The designation builds upon other actions OFAC has taken to disrupt the DPRK's IT worker schemes. Critical Docker Flaw Patched — Users of Docker Desktop on Windows and Mac are urged to upgrade to the latest version to patch a critical vulnerability that could allow an attacker to break the container isolation layer and potentially take over the host system. The vulnerability (CVE-2025-9074) stems from the fact that Docker Desktop exposes the Docker Engine API, which can be used to control Docker containers over a TCP socket without any authentication. As a result of this flaw, an attacker who gains access to a Docker container could leverage the API to create a new Docker container and mount the operating system's file system, gaining access to sensitive information or overwriting system-critical files, resulting in arbitrary code execution. However, mounting the file system administrator works only on Windows, as attempting this process on macOS would prompt the user for permission. Also, on macOS, Docker doesn't run with administrator privileges like it does on Windows. Critical Sectors Targeted by MixShell — Cybercriminals have targeted dozens of critical U.S. manufacturers and supply-chain companies, looking to steal sensitive data and deploy ransomware. The activity, dubbed ZipLine, dates back to the beginning of May 2025. Instead of emailing a malicious link in an unsolicited email, the miscreants initiate contact through the organization's public "Contact Us" form under the guise of partnership inquiries or other business pretexts, tricking the victim into starting the conversation and allowing the attackers to bypass email filters. The attacks led to the deployment of a stealthy implant called MixShell. By using website contact forms, the attack flips the phishing playbook by getting victims to make the first email contact with the attacker rather than the other way around. Salesforce Instances Targeted via Salesloft Drift — A threat activity cluster has committed a spate of data breaches of organizations' Salesforce instances by compromising OAuth tokens associated with the Salesloft Drift third-party application. UNC6395 has been carrying out a "widespread data theft" campaign by targeting Salesforce instances beginning as early as August 8 through at least August 18. UNC6395 "systematically exported large volumes of data from numerous corporate Salesforce instances" for the purpose of harvesting sensitive credentials, such as Amazon Web Services (AWS) access keys (AKIA), passwords, and Snowflake-related access tokens. Once these credentials were exfiltrated, "the actor then searched through the data to look for secrets that could be potentially used to compromise victim environments," and then covered its tracks by deleting query jobs. Storm-0501 Linked to Cloud Extortion Attacks — Storm-0501 has sharpened its ransomware tactics by exploiting hijacked privileged accounts to move seamlessly between on-premises and cloud environments, exploiting visibility gaps to encrypt data and exfiltrate sensitive data, and carry out mass deletions of cloud resources, including backups. The threat actor checked for the presence of security software, suggesting a deliberate effort to avoid detection by targeting non-onboarded systems. The attackers also conducted reconnaissance activities to gain deep visibility into the organization’s security tooling and infrastructure. This evolution signals a technical shift and a change in impact strategy. Instead of just encrypting files and demanding ransom for decryption, Storm-0501 exfiltrates sensitive cloud data, destroys backups, and then extorts victims by threatening permanent data loss or exposure. UNC6384 Deploys PlugX via Captive Portal Hijack — Chinese state hackers have been hijacking captive portal checks to deliver malware couched as Adobe software. The activity, attributed to Mustang Panda, appears to have targeted Southeast Asian diplomats in particular, and other unidentified entities around the globe, between approximately March and July of this year. Around two dozen victims were likely compromised, although it's possible there were more. The trick to Mustang Panda's latest campaign involves hijacking captive portal checks to redirect users to a website under their control to distribute malware. It's believed that the hackers infected edge devices in the targets' networks, which they used to intercept the check made by the Google Chrome browser. Users who fell for the scheme ended up downloading an ostensibly innocuous binary that ultimately led to the deployment of PlugX. ShadowCapatcha Leverages ClickFix to Deliver Malware — A financially motivated campaign dubbed ShadowCaptcha is leveraging fake Google and Cloudflare CAPTCHA pages to trick victims into executing malicious commands using compromised WordPress sites as an infection vector. The attacks lead to the deployment of information stealers and ransomware, demonstrating a versatile monetization approach. The activity primarily focuses on three revenue streams: Data theft and subsequent sale, drop cryptocurrency miners, and infect machines with ransomware. This multi-pronged strategy ensures a sustained revenue generation mechanism, maximising their return on investment while also maintaining persistent access. 🔥 Trending CVEs Hackers act fast. They attack soon after a weakness is found. One missed update, a hidden error, or a forgotten security alert can let them in. A small problem can quickly turn into big trouble like stolen data or system crashes, before you even notice. Here are this week's serious risks. Check them, fix them fast, and stay safe before attackers do. This week's list includes — CVE-2025-55177 (WhatsApp), CVE-2025-34509, CVE-2025-34510, CVE-2025-34511 (Sitecore Experience Platform), CVE-2025-57819 (FreePBX), CVE-2025-26496 (Tableau Server), CVE-2025-54939 (LSQUIC QUIC), CVE-2025-9118 (Google Cloud Dataform API), CVE-2025-53118 (Securden Unified PAM), CVE-2025-9478 (Google Chrome), CVE-2025-50975 (IPFire 2.29), CVE-2025-23307 (NVIDIA NeMo Curator), CVE-2025-20241 (Cisco Nexus 3000 and 9000 Series switches), CVE-2025-20317 (Cisco Integrated Management Controller), CVE-2025-20294, CVE-2025-20295 (Cisco Unified Computing System Manager), CVE-2025-54370 (PhpSpreadsheet), CVE-2025-39245, CVE-2025-39246, CVE-2025-39247 (Hikvision HikCentral), CVE-2025-49146, CVE-2025-48976, CVE-2025-53506, CVE-2025-52520 (Atlassian), CVE-2025-50979 (NodeBB), and CVE-2025-8067 (Linux UDisks daemon). 📰 Around the Cyber World Microsoft RDP services Targeted by Malicious Scans — Microsoft's Remote Desktop Protocol (RDP) services have been hit with a torrent of malicious scans from tens of thousands of IP addresses in recent days, indicating a coordinated reconnaissance campaign. "The wave's aim was clear: test for timing flaws that reveal valid usernames, laying the groundwork for credential-based intrusions," GreyNoise said. The activity took place over two waves on August 21 and 24, with thousands of unique IP addresses simultaneously probing both Microsoft RD Web Access and Microsoft RDP Web Client authentication portals. Flaw in TheTruthSpy Spyware — A vulnerability in TheTruthSpy spyware app can allow bad actors to take over any account and retrieve collected victim data. The vulnerability exploits an issue with the app's password recovery process to change the password of any account. TheTruthSpy told TechCrunch it can't fix the bug because it "lost" the app's source code. Russia's Max App Logs User Activity — The Russian government's WhatsApp rival, Max, is constantly monitoring and logging all user activity. According to Corellium's technical analysis, the app doesn't use encryption and tracks user location in real-time and with high accuracy. Developed by Russian tech giant VK, the app has been made mandatory and must be installed on all mobile devices sold in Russia after September 1, 2025. The app was initially launched earlier this March. OpenSSH's PQC Play — OpenSSH said it will start showing warnings when users connect to an SSH server that does not have post-quantum cryptography protections starting with OpenSSH 10.1. "The ideal solution is to update the server to use an SSH implementation that supports at least one of these," the maintainers said. "OpenSSH versions 9.0 and greater support sntrup761x25519-sha512 and versions 9.9 and greater support mlkem768x25519-sha256. If your server is already running one of these versions, then check whether the KexAlgorithms option has disabled their use." Credential Harvesting Campaign Targets ScreenConnect Super Admin Accounts — A low-volume campaign is targeting ScreenConnect cloud administrators with fake email alerts warning about a potentially suspicious login event with the goal of stealing their credentials for potential ransomware deployment. The activity, ongoing since 2022, has been attributed by Mimecast to MCTO3030. "The campaign employs spear phishing emails delivered through Amazon Simple Email Service (SES) accounts, targeting senior IT professionals, including directors, managers, and security personnel with elevated privileges in ScreenConnect environments," the company said. "The attackers specifically seek super administrator credentials, which provide comprehensive control over remote access infrastructure across entire organizations." The attackers are using the open source Evilginx framework to provision these phishing pages and to act as a reverse proxy between the victim and the real site. The framework can capture both login credentials and session cookies. More ScreenConnect-Themed Campaigns Discovered — Another campaign has leveraged phishing emails with fake Zoom meeting invitations and Microsoft Teams calls to lead victims to malicious links that download the ScreenConnect software. "The weaponization of a legitimate IT administration tool – one designed to grant IT professionals deep system access for troubleshooting and maintenance – combined with social engineering and convincing business impersonation creates a multi-layered deception that provides attackers with the dual advantage of trust exploitation and security evasion," Abnormal AI said. The campaign has so far targeted more than 900 organizations, impacting a broad range of sectors and geographies. A separate campaign has also been observed using fake AI-themed content to lure users into executing a malicious, pre-configured ScreenConnect installer, which then acts as an entry point for the XWorm malware, per Trustwave. In a related development, attackers have been observed weaponizing Cisco's secure links ("secure-web.cisco[.]com") in credential phishing campaigns to evade link scanning and by-pass network filters. "Attackers compromise or create accounts within Cisco-protected organizations," Raven AI said. "They simply email themselves malicious links, let Cisco's system rewrite them into Safe Links, then harvest these URLs for their campaigns." A similar campaign exploiting Proofpoint links was disclosed by Cloudflare in July 2025. TRM Labs Warns of Scam Campaign Impersonating the Firm — Blockchain intelligence company said it's aware of individuals using false domains to impersonate TRM Labs and/or government agencies working in collaboration with TRM Labs. "These are not TRM Labs domains, and the actors behind these are scammers," the company said. "TRM Labs is not involved in fund recovery processes for victims and does not partner with government agencies for the purposes of fund recovery. Unfortunately, these types of scams deliberately target vulnerable people, often when they’re financially vulnerable, having potentially already lost funds to scams." The warning comes against the backdrop of an alert issued by the U.S. Federal Bureau of Investigation (FBI), urging cryptocurrency scam victims to be on the lookout for scams where fraudsters pose as lawyers representing fictitious law firms to help them assist with fund recovery, only to deceive them a second time. New Ransomware Strains Detected — A new ransomware strain going by the name of Cephalus has been spotted in the wild. In incidents observed around mid-August 2025, the group behind the locker used compromised RDP accounts for initial access and used the cloud storage service MEGA for likely data exfiltration purposes. The development comes as the Underground and NightSpire ransomware gangs have launched ransomware attacks against companies in various countries and industries, including South Korea. In another attack analyzed by eSentire, compromised third-party MSP SonicWall SSL VPN credentials served as an initial access pathway for Sinobi, a rebrand of the Lynx ransomware. "Using the compromised account, the threat actors executed commands to create a new local administrator account, set its password, and add it to the domain administrators group," eSentire said. "Both the initial compromised account and the newly created account were subsequently used for lateral movement throughout the network." Most Active Ransomware Groups — Akira, Cl0p, Qilin, Safepay, and RansomHub were the most active ransomware groups in the first half of 2025, per Flashpoint, which found that ransomware attacks increased by 179% compared to the 2024 midyear. The development comes amid notable changes in the ransomware ecosystem, where threat actors increasingly prefer extortion over encryption and have begun to incorporate LLMs in their tooling. The landscape has also continued to splinter, with new gangs and rebrands proliferating in the wake of law enforcement takedowns. MalwareBytes said it tracked 41 newcomers between July 2024 and June 2025, with more than 60 total ransomware gangs operating at once. Microsoft to Throttle Emails to Combat Spam — Microsoft said it will begin throttling emails starting October 15, 2025. The limit will be set to 100 external recipients per organization per 24-hour rolling window. From December 1, the tech giant will start rolling out the restrictions across tenants, starting with tenants with fewer than three seats and eventually reaching tenants with more than 10,001 seats by June 2026. "Despite our efforts to minimize abuse, spammers often exploit newly created tenants to send bursts of spam from '.onmicrosoft.com' addresses before we can intervene," Microsoft said. "This degrades this shared domain’s reputation, affecting all legitimate users. To ensure brand trust and email deliverability, organizations should establish and use their own custom domains for sending email." SleepWalk, a Physical Side-Channel Attack to Leak Data — A group of academics from the University of Florida has devised a new hardware side-channel attack dubbed SleepWalk that exploits context switching and CPU power consumption to leak sensitive data like cryptographic keys. "We introduce a physical power side-channel leakage source that exploits the power spike observed during a context switch, triggered by the inbuilt sleep function of the system kernel," the researchers said. "We observed that this power spike directly correlates with both the power consumption during context switching and the residual power consumption of the previously executed program. Notably, the persistence of residual power signatures from previous workloads extends the scope of this side-channel beyond extracting the data in registers during the context switch. Unlike traditional approaches that require analyzing full power traces, applying complex preprocessing, or relying on external synchronization triggers, this novel technique leverages only the amplitude of a single power spike, significantly simplifying the attack." AI Systems Vulnerable to Prompt Injection via Image Scaling Attack — In a novel form of prompt injection attacks aimed at artificial intelligence (AI) chatbots, attackers can hide malicious instructions inside large-scale images and have the prompts execute when the AI agent downscales them. The attacker's prompt is invisible to the human eye in the high-resolution image, but shows up when the image is downscaled by preprocessing algorithms. "This attack works because AI systems often scale down large images before sending them to the model: when scaled, these images can reveal prompt injections that are not visible at full resolution," Trail of Bits said. The cybersecurity company has released an open-source tool called Anamorpher to generate such crafted images. Social Media Accounts Launder News from Chinese State Media Sites — A network of 11 domains and 16 companion social media accounts across Facebook, Instagram, Mastodon, Threads, and X has been found laundering exclusively English-language articles originally published by the Chinese state media outlet CGTN. "The assets almost certainly used AI tools to translate and summarize articles from CGTN, likely in an attempt to disguise the content's origin," Graphika said. "The network assets disseminated primarily pro-China, anti-West content in English, French, Spanish, and Vietnamese." The findings came as the U.S. told Denmark to "calm down" over allegations of covert influence operations by U.S. citizens in Greenland to sow discord between Denmark and Greenland and to promote Greenland's secession from Denmark to the U.S. Analyzing Secret Families of VPN Apps — New research conducted by the Arizona State University and Citizen Lab has found that nearly two dozen VPN applications in Google Play contain security weaknesses impacting the privacy of their users, exposing transmitted data to decryption risks. Further analysis has determined that eight VPN applications from Innovative Connecting, Autumn Breeze, and Lemon Clove (Turbo VPN, Turbo VPN Lite, VPN Monster, VPN Proxy Master, VPN Proxy Master – Lite, Snap VPN, Robot VPN, and SuperNet VPN) share code, dependencies, outdated and unsafe encryption methods, and hard-coded passwords, potentially allowing attackers to decrypt the traffic of their users. Cumulatively, these apps have over 380 million downloads on Google Play. All three companies were found to have ties with Qihoo 360, a Chinese cybersecurity firm that the U.S. sanctioned in 2020. Security Risks in the eSIM Ecosystem — A new study undertaken by academics from Northeastern University has found that many providers associated with eSIMs route user data through foreign telecommunications networks, including Chinese infrastructure, regardless of user location. "Many travel eSIMs route user traffic through third-party infrastructure, often located in foreign jurisdictions," the researchers said. "This may expose user metadata and content to networks outside the user’s country, raising concerns about jurisdictional control and surveillance." What's more, the digital provisioning model creates new opportunities for phishing and spoofing. Malicious actors can distribute fake eSIM profiles via fraudulent QR codes or websites, tricking users into installing unauthorized configurations. ComfyUI Flaw Exploited to Deliver Pickai Backdoor — Threat actors have exploited vulnerabilities in an artificial intelligence (AI) platform called ComfyUI to deliver a backdoor called Pickai. "Pickai is a lightweight backdoor written in C++, designed to support remote command execution and reverse shell access," XLab said, adding that it "includes anti-debugging, process name spoofing, and multiple persistence mechanisms." Pickai samples have been observed hosted on the official site of Rubick.ai, a commercial AI-powered platform serving the e-commerce sector across the U.S., India, Singapore, and the Middle East. Early versions of the malware were uploaded to VirusTotal as far back as February 28, 2025. The activity has compromised nearly 700 infected servers worldwide, mainly in Germany, the U.S., and China. Flaw in LSQUIC QUIC Disclosed — Cybersecurity researchers have discovered a vulnerability dubbed QUIC-LEAK (CVE-2025-54939) in the LSQUIC QUIC implementation, allowing threat actors to smuggle malformed packets to exhaust memory and crash QUIC servers even before a connection handshake is established, thereby bypassing QUIC connection-level safeguards. The issue has been fixed in OpenLiteSpeed 1.8.4 and LiteSpeed Web Server 6.3.4. Fake Sites Pushing YouTube Downloads Serve Proxyware — Proxyware programs are being distributed through YouTube sites that allow users to download videos. Attackers who previously installed DigitalPulse and HoneyGain Proxywares are also installing Infatica Proxyware. Similar to coin miners, Proxyware malware profits by utilizing the system’s resources, and many systems in South Korea have recently become the targets of these attacks. U.S. Senator Castigates Federal Judiciary for Negligence — U.S. Senator Ron Wyden accused the federal judiciary of "negligence and incompetence" following a recent hack, reportedly by hackers with ties to the Russian government, that exposed confidential court documents. The breach of the judiciary’s electronic case filing system first came to light in a report by Politico three weeks ago, which went on to say that the vulnerabilities exploited in the hack were known since 2020. The New York Times, citing people familiar with the intrusion, said that Russia was "at least partly responsible" for the hack. "The federal judiciary’s current approach to information technology is a severe threat to our national security," Wyden wrote. "The courts have been entrusted with some of our nation's most confidential and sensitive information, including national security documents that could reveal sources and methods to our adversaries, and sealed criminal charging and investigative documents that could enable suspects to flee from justice or target witnesses." Law Enforcement Freezes $50M in Crypto Assets Tied to Romance Baiting Scams — Several cryptocurrency companies, including Chainalysis, OKX, Binance, and Tether, have come together to freeze nearly $50 million stolen via "romance baiting" scams in collaboration with APAC-based authorities. "Once funds were transferred, scammers then sent proceeds to a consolidation wallet which transferred $46.9 million in USDT [Tether] to a collection of three intermediary addresses," Chainalysis said. "The funds then moved to five different wallets." The funds were frozen by Tether in July 2024. South Korea Extradites Chinese National for Cyber Attacks — South Korean authorities have successfully extradited a 34-year-old Chinese national suspected of orchestrating one of the most sophisticated hacking operations targeting high-profile individuals and financial institutions. He is alleged to have stolen 38 billion won from financial accounts and virtual asset accounts. Anthropic and OpenAI Test Each Other's AI — OpenAI has called on AI firms to test their rivals' systems for safety, as the company and Anthropic conducted safety evaluations of each other's AI systems to tackle risks like prompt injection and model poisoning. The development came as Anthropic revealed that a cybercriminal abused its agentic AI coding tool to automate a large-scale data theft and extortion campaign, marking a "new evolution" in how AI is super-charging cybercrime. The chatbot then analyzed the companies' hacked financial documents to help arrive at a realistic amount of bitcoin to demand in exchange for not leaking the stolen material. It also wrote suggested extortion emails. "The operation demonstrates a concerning evolution in AI-assisted cybercrime, where AI serves as both a technical consultant and active operator, enabling attacks that would be more difficult and time-consuming for individual actors to execute manually," the the company said. Where years of specialized training once throttled the ability of bad actors to pull off attacks at scale, the new wave of AI-assisted cybercrime could further lower technical barriers, allowing even novices and unskilled operators to carry out complex activities with ease. Separately, Anthropic has announced a policy change to train its AI chatbot Claude with user data, giving existing users until September 28, 2025, to either opt in or opt out to continue using the service; it says it will enable the company to deliver "even more capable, useful AI models" and strengthen safeguards against harmful usage like scams and abuse. Plex Servers Susceptible to New Flaw — Plex has addressed a security vulnerability (CVE-2025-34158), stemming from incorrect resource transfer between spheres, affecting Plex Media Server versions 1.41.7.x to 1.42.0.x. It has been patched in versions 1.42.1.10060 or later. According to data from Censys, there are 428,083 devices exposing the Plex Media Server web interface, although not all of them are necessarily vulnerable. Fake Recipe and Guide Sites Drop Malware — Bogus sites masquerading as image, recipe, and educational guide finders have been found to harbor stealthy code to issue stealthy commands and drop malware on users' systems that can steal sensitive information. It’s assessed that these sites reach targets via malvertising campaigns. 🎥 Cybersecurity Webinars What Every AppSec Leader Must Learn About Code-to-Cloud Security - Modern AppSec is no longer just about spotting risks—it’s about learning how they emerge and spread from code to cloud. Without visibility across that journey, teams face blind spots, noise, and delayed fixes. Code-to-cloud context changes the game, giving security and engineering teams the clarity to learn faster, act sooner, and protect what matters most. Practical Steps to Keep AI Agents Safe from Cyberattacks - AI agents are rapidly reshaping business—automating decisions, streamlining operations, and unlocking new opportunities. But with innovation comes risk. Join our upcoming webinar with Auth0’s Michelle Agroskin to uncover the security challenges AI agents introduce and learn actionable strategies to protect your organization. Discover how to stay ahead of threats while confidently embracing the future of AI-driven innovation. From Fingerprints to Code Traces: How Experts Hunt Down Shadow AI - AI Agents are multiplying in your workflows, clouds, and business processes—often without approval. These “shadow agents” move faster than governance, fueled by hidden identities and one-click deployments. The result? Security teams are left chasing ghosts. Join our expert panel to uncover where shadow AI hides, who’s behind it, and how to take back control—without slowing down innovation. 🔧 Cybersecurity Tools PcapXray - Investigating packet captures can be slow and messy. PcapXray speeds up the process by turning raw PCAP files into clear, visual network diagrams. It highlights hosts, traffic flows, Tor usage, and potential malicious activity—helping investigators and analysts quickly see what’s happening inside the data without digging line by line. Kopia - It is an open-source backup and restore tool that creates encrypted snapshots of selected files and directories. Instead of imaging an entire machine, it lets you back up what matters most—whether to local storage, network drives, or cloud providers like S3, Azure, or Google Cloud. With built-in deduplication, compression, and end-to-end encryption, Kopia helps ensure backups are efficient, secure, and under your full control. Disclaimer: These newly released tools are for educational use only and haven’t been fully audited. Use at your own risk—review the code, test safely, and apply proper safeguards. 🔒 Tip of the Week How to Lock Down Your MCP Servers — AI tools like GitHub Copilot are getting smarter every day. With the Model Context Protocol (MCP), they can connect to outside tools and services—running code, pulling data, or even talking to internal systems. That’s powerful, but it’s also risky: if a bad actor sneaks in with a fake or compromised MCP server, your AI could be tricked into leaking secrets, exposing credentials, or executing harmful commands. The solution isn’t to avoid MCP. It’s to secure it properly. Here’s a practical way to do that using free tools. 1. Test Before You Trust: Before turning on any MCP server, run an audit. Tool to try: MCPSafetyScanner What it does: Scans MCP definitions, runs test attacks, and reports if something looks unsafe. 2. Wrap Servers with a Safety Net: Don’t expose servers directly. Add a guard layer. Tool to try: MCP Guardian (open-source prototype from research). What it does: Adds authentication, logs all activity, and blocks suspicious requests. 3. Stress-Test Like an Attacker: Simulate real-world threats to see how your setup holds up. Tool to try: MCPSecBench What it does: Launches different known MCP attack patterns and measures resilience. 4. Enforce Rules as Code: Add guardrails for what AI can and can’t do. Tools to try: Open Policy Agent (OPA) or Kyverno What they do: Define policies (e.g., “only read from X API, never write”) and enforce them automatically. 5. Go Zero-Trust on Access: Every connection should be verified and limited. Use OAuth 2.1 for authorization. Add mTLS (mutual TLS) so both client and server prove who they are. Send all logs to your SIEM (e.g., Elastic or Grafana Loki) for monitoring. AI + MCP is moving fast. The line between “helpful automation” and “security hole” is thin. By auditing, stress-testing, enforcing rules, and monitoring, you’re not just protecting against today’s risks—you’re preparing for tomorrow’s. Think of it like this: MCP gives your AI superpowers. Your job is to make sure those powers don’t get hijacked. Conclusion Quantum-safe encryption, AI-driven phishing, identity without passwords—these are not distant theories anymore. They are already shaping the security landscape quietly, underneath the day-to-day headlines. The closing lesson: the biggest shocks often arrive not as breaking news, but as trends that grow slowly until suddenly they cannot be ignored.
thehackernews.comSep 1, 2025extracted
Loading 4 more…