Visualização de leitura

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 113

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape

Malware Newsletter

Hackers Steal Claude Login Sessions With Infostealer Malware to Hijack Accounts

Fire Ant Evolves: From Hypervisors to Trusted Infrastructure      

Gryxa: The AI-Built Toolkit That Watches How You Remove It

ValleyRAT masquerading as adware  

13 Malicious Packagist Themes Deliver iOS Spyware That Steals Crypto Wallet Seeds  

Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set

Uncovering StreamRat: From Meta Ads to Full Device Takeover  

Counterfeit installers to system compromise: Tracking a deceptive software download campaign

Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon September 2, 2026

Mini Shai-Hulud’s Latest Wave: 280 New Places It Hunts for Your Secrets  

Pegasus Spyware Infection of Serbian Pro-Democracy Student Activist 

Chinese-Speaking Operator Uses AI Agents to Target Government and Education Systems Across Asia

DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

Anatomy of BraZetsu: How Cybercriminals Fuel the Underground Ecosystem

Peer Pressure: Inside the Sality Botnet Disruption Operation

Graph-Based Learning for Android Authorship Attribution: A Comparative Analysis of GNN Models

Stability and Hopf Criteria in a Malware Dissemination Model for Wireless Sensor Networks with Distributed Recovery Delays

PhantomCall: Evading ML Malware Detectors via Function Call Graph Perturbation

REPLICANT: Learning Policies for Evading and Hardening Malware Detectors

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

Security Affairs newsletter Round 593 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including international press.

PaperCut Flaws Exploited in Attacks on U.S. and European Schools
Broadcom Patches Critical VMware Workstation and Fusion VM-Escape Vulnerabilities
U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog
Crooks Behind Manchester Airports Group Hack Leaked Data of 8.8 Million People
PostgreSQL Hit by 12-Year-Old Vulnerability Allowing Server Takeover
Chinese Hackers Use AI Agents in Multi-Country Cyber Campaign
Google fixes the sixth actively exploited Chrome zero-day of 2026
Dark Web Service Nexus Sells 153M+ Driver’s Licenses
2,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber Operators
OpenAI Astra Brings Autonomous Zero-Day Exploitation to AI
SonicWall Patches Two New Actively Exploited Zero-Days in SMA 1000 VPNs
$536 and 8 Hours: AI Learns to Attack a Different PLC
Iran-linked APT Mirage Kitten Uses Fake Job Tests to Spread Malware
Hackers Target Langflow in CVE-2026-0768 Attacks
Attackers Access Aesto Health AWS Infrastructure, Exposing 9.5 Million Records
Chaotic Eclipse Releases GenDigital Avast Antivirus ZeroDay PrettyPrague
Five Venezuelan Nationals Plead Guilty in Kansas ATM Jackpotting Attempt
North Korea-linked IT Workers Are Getting Hired Inside Western Companies
Chaotic Eclipse Releases Kaspersky Zero-Day HardBreacher
U.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog
ValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool
China-linked Fire Ant Hides Inside Trusted Infrastructure
Infostealers Are Hijacking Claude Sessions and Draining Subscriptions
Critical GiveWP Flaw Lets Attackers Run Commands on WordPress Servers
Extortion Group FulcrumSec Claims 86GB Manchester Airports Group Data Theft
Hackers Are Probing PaperCut Servers, and 47% Still Have No Patch

International Press – Newsletter

Cybercrime

FulcrumSec claims Manchester Airports hack, theft of 86 GB of data

Aurora ransomware targets ESXi, abuses Cursor Agent for exploitation  

FBI investigation leads to five Venezuelan nationals pleading guilty to attempting to jackpot Kansas ATMs  

FBI Probes Service Selling 153M+ Drivers Licenses

Two Nigerian Nationals Extradited from Nigeria to the United States to Face Sextortion Charges in North Carolina and Mississippi  

The Town 2025 ticketing data sold as a Ticketmaster breach 

Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon September 2, 2026  

Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal   

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

ASCII smuggling crosses over from AI prompt injection to phishing evasion

Malware

Hackers Steal Claude Login Sessions With Infostealer Malware to Hijack Accounts

Gryxa: The AI-Built Toolkit That Watches How You Remove It

ValleyRAT masquerading as adware  

13 Malicious Packagist Themes Deliver iOS Spyware That Steals Crypto Wallet Seeds  

Mini Shai-Hulud’s Latest Wave: 280 New Places It Hunts for Your Secrets  

Hacking

Eclypsium flags 1,051 CVEs in infrastructure advisories 

Unauthenticated PHP Object Injection to Remote Code Execution on GiveWP  

Kaspersky zero-day exploit HardBreacher 

PrettyPrague: GenDigital Avast Antivirus ZeroDay Elevation of Privileges Vulnerability  

Same Target, Different Playbooks: Two Attackers, Two Different Paths to Pwning the AI Stack 

Can AI Create PLC Attacks? Yes, But It’s Not That Easy Yet  

Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in Crowdstrike Falcon 

Cloud Sync Root RegistrationShieldBreak: Hunting Windows Defender Remediation Abuse and Cloud Files Hijacking  

Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day

When Sorting Leads To Confusion  

Intelligence and Information Warfare  

Pegasus Spyware Infection of Serbian Pro-Democracy Student Activist

Fire Ant Evolves: From Hypervisors to Trusted Infrastructure

Insights into Suspected DPRK Workers: Red Flags to Look Out For   

Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set  

Leaked Russian Cyber-Operations Training Materials  

Threat Intelligence Report: University Leak Exposes Russia’s Military Cyber Training Pipeline  

Chinese-Speaking Operator Uses AI Agents to Target Government and Education Systems Across Asia

How the Russians Got Inside My Phone

DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors    

Cybersecurity

Judge says Pentagon’s measures against Anthropic were ‘illegal and baseless’  

How AI could make it harder for governments to use hacking tools  

Own a gun? Go to church? Do yoga? AI can find out in seconds        

Path to Astra: critical capabilities and frontier safeguards  

PostGREShell: The database powering much of the internet had an open door for 12 years 

Fighting AI with AI: The US’s New Cyber Rules of Engagement 

ATM Flaws Reveal Key Weaknesses in the Software Supply Chain 

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 112

Security Affairs newsletter Round 592 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including international press.

Hack One Robot, Reach the Next: Unitree G1 Security Flaws
Rhysida Ransomware Group Targets Berlin Government Ahead of Vote
Philippine Nuclear and Naval Targets Hit by Suspected Chinese Operator
Love Electric Breach: 877,000 Driver Records Offered for $600
Trump Targets Foreign Technology in New U.S. Power Grid Security Order
U.S. CISA adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog
Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations
PaperCut Zero-Day Under Active Attack: Emergency Patch Released
U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog
Cyberattack on UK Airport Operator MAG Exposes Data of 8.7 Million Customers Across Three Airports
Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback
Australian Police Charge Two Over TeamPCP Credential Theft
Meta to Pay Up to $18B Over Teen Social Media Use
CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do
OpenAI banned Russian ChatGPT accounts backing covert influence operation
CISA Red Team Fully Compromised Two Critical Infrastructure Orgs
FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure
U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog
88 ID Verification Breaches Show the Cost of Collecting Identity Data
WhatsApp Adds Stronger Security as Passkeys Hit 1 Billion
Operation Jackal: 58 Arrests Expose the Money Laundering Machine Behind Global Scams
Norway ’s Digital Government Infrastructure Hit by a new DDoS Attack
When the Algorithm Fires You: Uber Faces €825M Fine
Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as Vulnerable
U.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalog
Fake Minecraft Sites Are Still Spreading WeedHack After C2 Takedown
Cybercriminals Turn GTA VI Leaks Into Malware Bait
Slovakia Warns of Cyber Risks in Road Speed Cameras
TikTok Settles U.S. Child Privacy Case for $400 Million
iAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset
UK Power Plant Disabled for Four Days by Iran-Linked Hackers, Concurrent with US Water Attacks
Zero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context Injection

International Press – Newsletter

Cybercrime

iAuthFlow v2 Enrolls Google Passkeys That Survive Password Resets     

Fake GTA VI ISO circulates on the internet a few days after leak, internet sleuths claim 113GB download is padded malware        

Taiwan charges 9 over illegal AI server exports to China, including Nvidia and Super Micro staff  

Indian man who fled US arrested on charges he helped scammers siphon $7.5 million from the elderly

58 arrests in global effort to dismantle West African organized crime groups

Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain       

RTM Locker interview: a ransomware actor on the RaaS market 

Two WA men charged following AFP-FBI-WAPF disruption of alleged global cybercrime syndicate  

Love Electric driver data for sale: NI, licence numbers 

Ransomware group says it stole Berlin data, offers it for auction  

Malware 

FTP Banners: The New Dead Drop Resolver Delivering Novel RATs

The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution     

19 Chrome and Edge Extensions Deliver a Wallet Drainer and Credential-Stealing Payloads  

SLEEPWALKER: A Passive Backdoor With Its Own Command Language  

Hacking

One slug, seven editions: the miniOrange SAML SSO bug that let anyone log in as your WordPress admin  

A Tale of Two SOCs: Insights From Two Red Team Assessments  

Three UK airports hit by cyber-attack with data of 8.7m customers accessed   

New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access

PaperCut Releases Emergency Patch for Exploited Zero-Day

Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator Using Known Vulnerabilities   

The Hugging Face incident and the road ahead

Power Leak: Amazon Kiro IDE Prompt Injection Enables Data Exfiltration      

Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users’ Reservations in Tests

UniBLEed: Unauthenticated Root RCE on Any Unitree G1 Humanoid Robot Within Bluetooth Range  

PaperCut Actively Exploited: A Pre-Auth RCE Chain  

Intelligence and Information Warfare  

Iranian hackers shut down UK power plant  

Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor    

Digdir stabilizes solutions after cyberattack  

Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical Infrastructure

The infrastructure quartermaster: inside a China-nexus state enablement model     

Disrupting a new covert influence campaign from Russia 

Tortoiseshell: New Toolset and Operational Infrastructure Exposed

Treasury Launches Unprecedented Campaign Against Iranian Regime on Economic D-Day

Dark Caracal Reloaded: New Malware, Same Hunting Grounds  

Cambodia-focused cluster uses multistage infection chain with localized lures

BlueDelta Targets Defense and Diplomacy with HOOKEDGE

Cybersecurity

Warning about the risks of road meters  

One billion people are now protected with passkeys on WhatsApp, plus more account security features

An ID Check Breach Timeline: 2011–2026 

Internet Exposure Reduction Guidance 

Meta agrees to pay $18 billion to settle US lawsuits over children’s social media addiction  

DECLARING A NATIONAL EMERGENCY TO SECURE THE UNITED STATES BULK-POWER SYSTEM  

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 111

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape

Malware Newsletter

Akira Hits Safe Mode: Ransomware Rebooting Around EDR 

Multi-Functional Linux Botnet “Evooo1Bot”     

StubMaker RubyGems Campaign Delivers a Windows Infostealer  

Hunting MacSync Stealer infrastructure through behavioral pivots 

Manic: Blend between Banking Malware & Spyware  

Clop Returns with Custom Implant in Mass-Extortion Campaign

The ToxicPanda Never Sleeps: ToxicPanda 2.0 Prepares its Next Strike on Mobile

Striking gold: Inside the GoldDigger Android malware     

SilkParasite: Tracking a China-Nexus APT Across Central Asia

Prompting the Payload: How an npm Supply Chain Attack Delivers the RedC2 AI-Powered Linux Implant  

The invisible passenger in your car

Malware Crypting Services and the Threat Actors Who Sell Them 

Grandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaign  

Survival of~the~Stealthiest: Evolving Low-Entropy Ransomware via~Genetic Algorithms

Malformer: A Multi-Modal Malware Detector Using Transformers

XAI-Guided Graph-Based Feature Engineering and Heterogeneous Ensemble Learning for Android Malware Detection

An Explainable Deep Learning Pipeline for Malware Family Classification: GAF Image Encoding and API-Grounded LLM Interpretation

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

Security Affairs newsletter Round 591 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including international press.

ToxicPanda 2.0 Gets a Major Upgrade, Expanding Attacks Across 16 Countries
Malware Hijacks Android Car Head Units
Critical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command Execution
U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog
Your Shredded Visa Card May Still Work at the Checkout
Six Maximum-Severity Flaws Found in Cisco Products
Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics
GitLab Warns of Active Exploitation of Critical GraphQL Flaw
Poland’s CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite Flaw
U.S. CISA adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog
Cl0p Targets 40+ Organizations Through PTC Windchill Flaw
Manic: The Android Malware That Exfiltrates Data Even When the Phone Is Offline
NSA, CISA, FBI, DOE, and EPA Warn of Active AI-Assisted Attacks on Siemens S7 PLCs
U.S. CISA adds an MLflow flaw to its Known Exploited Vulnerabilities catalog
US Indicts 17 Iranians Over Years-Long Cyber Espionage Campaign
StopAndProtect Turns 2,000 Hacked WordPress Sites Into a Criminal Network
Inside Operation CameraSwarm: How One Actor Took Over 14,000 Dahua Cameras
Microsoft Tracks MacSync Stealer by Its Behavior, Not Its Domains
50,000 Stripe Secrets Leaked in Public Code
U.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog
Hackers Expose Data of 1.2 Million Heights Finance Customers
Project noRecognition: Teaching AI to Fool Surveillance Cameras
GitLab Patches Critical Unauthenticated GraphQL Vulnerability
U.S. CISA adds a Ray-Project Ray flaw to its Known Exploited Vulnerabilities catalog
New Mirai-Based Evooo1Bot Botnet Targets Linux Devices
SafePal Says 39,798 Customers Hit by Data Breach
LiteLLM Supply-Chain Attack – Technology, Banking and Healthcare the Most Affected
Invisible AI Prompts Trigger Court Sanctions
McDonald’s Employee Data Appears in Leak, Seller Claims 1.7M Records Stolen
Akira Ransomware Uses Safe Mode to Bypass EDR
DDoS Attacks Cause Major Threema Outages
Mustang Panda Upgrades CoolClient With a Kernel Rootkit
Sophisticated Cyberattack Exposes Data of 678,000 French Taxpayers
APT36 Suspected in PATCHCORD Espionage Campaign Using Google Sheets C2

International Press – Newsletter

Cybercrime

McDonald’s employee data listed for sale in wider Entra campaign      

$7 Million in Expired Domains Fuel a Streaming Empire with a Malware Secret 

Live Stripe keys for 659 merchants, published for free  

Clop Returns with Custom Implant in Mass-Extortion Campaign  
Justice Department Secures $400M Settlement with TikTok and ByteDance to Resolve Children’s Privacy Litigation       

Malware

Akira Hits Safe Mode: Ransomware Rebooting Around EDR 

Hunting MacSync Stealer infrastructure through behavioral pivots 

Manic: Blend between Banking Malware & Spyware  

The ToxicPanda Never Sleeps: ToxicPanda 2.0 Prepares its Next Strike on Mobile

The invisible passenger in your car

Grandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaign  

Hacking

Large-scale DDoS attacks disrupted Threema secure messaging service

The LiteLLM Supply-Chain Attack — TeamPCP “SANDCLOCK” CI/CD Credential-Harvesting Campaign via a Backdoored Trivy GitHub Action  

Actively exploited vulnerability in Zimbra Collaboration Suite

AI-assisted tool helped secure satellite communication system after 2022 Russian hacking

Expired credit cards revived by researchers to make unauthorized payments     

CDN Tsunami: Exploiting HTTP/3-HTTP/1.1 Conversion for DoS Attacks

When the NASA Ground Station Has No Lock on the Door: Unauthenticated Command Execution in AIT-GUI (GHSA-p9r8-2q67-fp86)      

Zero-click Grok data theft: Cryptographic Context Injection attack leaks chat histories  

Intelligence and Information Warfare  

Operation CameraSwarm:  Over 14,000 Dahua cameras compromised across Ukraine and Russia 

17 Iranians Charged with Conducting Massive Cyber Theft Campaign on Behalf of the Islamic Revolutionary Guard Corps and Other Iranian Entities  

Defending Against an Active Threat to Siemens S7 Series PLCs  

Rust Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns  

Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia  

SilkParasite: Tracking a China-Nexus APT Across Central Asia

Revealed: Cyber spies used malware from GitHub to hack EncroChat cryptophone network    

Cybersecurity

France probes unprecedented cyberattack after tax data of 678,000 users stolen 

Person Hides Prompt Injection in Legal Filing Telling AI to Side With Them  

SafePal Unauthorized Access To A Subset Of Customer Order Information 

This ‘adversarial’ pattern can prevent surveillance cameras from detecting you 

France’s cybersecurity problem demands strong political will  

The Powerful Chinese AI Model Experts Warned About—and Waited for—Is Here 

OpenAI president says companies should do 10 things ASAP to defend against AI cyber threats 

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 110

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape

Malware Newsletter

Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM

ShieldBreak – August 2026 disclosure  

Kimwolf v7: An Evolution of the Kimwolf Botnet 

CISA, FBI and Partners Warn Organizations of Gunra Ransomware Actors Targeting Multiple Critical Infrastructure Sectors 

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

AmnesiaStealer: a multi-stage Rust-based macOS infostealer that hijacks Chromium browsers  

Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme  

PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure

737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection  

Concept Drift Detection and Adaptive Retraining of Malware Classification Models

A Comparison of Malware Image Transformations Using Grad-CAM and Hybrid Learning Models

C-GUARD: Context-Adaptive Conformal Gating for Improving Robustness Against Evasive Windows PE Malware

An Explainable Deep Learning Pipeline for Malware Family Classification: GAF Image Encoding and API-Grounded LLM Interpretation

APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

Security Affairs newsletter Round 590 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including international press.

Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware
SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild
macOS Screen Sharing Flaw Exploited to Deploy Monero Miners
GeoServer Zero-Day Is Already Being Probed. That’s the Problem
Apple warned hundreds of users of mercenary spyware attacks
AmnesiaStealer Gives Attackers Live Control of Victims’ macOS Browsers
Chess.com Leak Exposes 7.3 Million Users – Evidence Points to Scraping
US Authorizes Private Cyber Firms to Hack Transnational Criminal Networks
Adobe Commerce CVE-2026-71362 Comes Under Attack Shortly After Public Disclosure
U.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog
SharePoint CVE-2026-55040 Comes Under Attack Following Public Exploit
Storm-1175 Replaces Medusa With New StormEncryptor Ransomware
North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job
CEVA Logistics Cyberattack Disrupts European Warehouses and Shipments
China-Linked Hackers Use AI Agents in Autonomous Attack on Taiwan
Kimwolf v7 Hides DDoS Traffic Behind Chrome Fingerprints and Ethereum
ShieldBreak: New Windows Zero-Day Bypasses Microsoft’s RoguePlanet Patch
Microsoft Patch Tuesday for August 2026 Fixed a Zero-Day and Wormable RCE
Zoom Patches “Zoomsday” Zero-Click Flaw Enabling Remote Code Execution
ExfilSquad Targets New Victims, Shares Data via Torrents
Iran-Linked Hackers Target More US Water Infrastructure in New Jersey and Alabama
The inconvenient truth about AI pentesting: someone has to check all the work
Cisco Warns of Seven ClamAV Flaws, Two With Public PoCs
Gym Booking Task Turns Into Real-World AI Cyberattack
U.S. Defense Manufacturer IEH Hit by Phishing Attack, Exposing Potentially Export-Controlled Data
Webmail CSS Attacks Expose a New Risk for AI-Powered Email Tools

International Press – Newsletter

Cybercrime

ExfilSquad Targets New Victims, Shares Data via Torrents  

Israeli population registry for sale, but the data is old  

Before Fraud Transacts  

ExfilSquad Targets New Victims, Shares Data via Torrents

Fake CAPTCHA, Real Business: Traffic Distribution for Hire  

7.3M chess.com records leaked, and the data is real

Drop Something? Don’t Worry, Someone Caught it      

Malware

ShieldBreak – August 2026 disclosure  

Kimwolf v7: An Evolution of the Kimwolf Botnet 

AmnesiaStealer: a multi-stage Rust-based macOS infostealer that hijacks Chromium browsers  

Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme  

737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection  

Hacking

Chinese Model Kimi K3 Breaks UK AI Safety Institute Benchmark Evaluations  

AI assistant hacks gym website in first known Australian autonomous cyber attack  

Zoomsday

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

Hackers exploit macOS Screen Sharing flaw to deploy Monero miner

It’s a pre-auth, stupid!  

A root remote command execution on macOS with M5 in 2026?

Intelligence and Information Warfare  

Follow-Up Analysis of the 29 December 2025 Energy Sector Incident    

New Jersey, Alabama Join States Targeted in Water Cyberattacks 

Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM  

China-linked hackers hit Taiwan in unprecedented ‘autonomous’ AI cyber attack  

State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit  

Social engineering performed by UAC-0145: compromising in the employment process 

Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side  

PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure 

APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit

North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring

How Tehran’s Use of Cyber Operations in the U.S.-Iran Conflict Has Evolved  

Cybersecurity

How a small Israeli startup was linked to rogue AI hacks at OpenAI, Anthropic and Meta

Responding to the next frontier of critical cyber capabilities      

Facebook is paying controversial creators to produce rage-bait content  

Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC  

The August 2026 Security Update Review 

Cyberattack on logistics giant CEVA delivers customer data into the wrong hands

About Apple threat notifications and protecting against mercenary spyware

If Apple sends you a push notification alerting you to a spyware attack, take it seriously 

AI isn’t changing how companies work. It’s changing what a company is 

Swarms of OpenAI systems set up their own chatrooms to discuss and carry out hacks, company reveals 

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

Security Affairs newsletter Round 589 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including international press.

Palo Alto Networks Faces China Cybersecurity Review Amid Rising Tech Tensions
Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data
U.S. CISA adds a Progress LoadMaster flaw to its Known Exploited Vulnerabilities catalog
Unlimited Technology Systems Data Breach Exposes Data of 3.8 Million Healthcare Patients
WordPress XSS2Shell Flaw Turns Simple Login Bug Into Full Server Takeover
Hackers Impersonate IT Support to Breach Leading Financial Companies
Meta Ordered to Pay $567 Million Over Child Safety Failures in New Mexico Case
Researchers Discover Hidden Backdoor in 20 Router Models Allowing Remote Root Access
AI Deepfakes Used to Impersonate OnlyFans Creators in New Scam
Exposed SISVISA Database Leaks 102,000 Brazilian Health Surveillance Records
Ransom Cartel Leader Sentenced to 16 Years in U.S.
Meta AI Model Hacked a Company During Testing, Marking Third AI Lab Incident
U.S. CISA adds a JetBrains TeamCity flaw to its Known Exploited Vulnerabilities catalog
Snowflake Hacker Pleads Guilty After Breaching 165 Companies and Stealing Billions of Records
AI Deception Emerges in Cyber Tests as Agents Target Real People and Systems
Brown Health Medical Group-MA Data Breach Exposes Information of 311,000 Individuals
U.S. CISA adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalog
OVSwrap: 13-Year-Old Linux Kernel Flaw Lets Local Users Become Root
SMOKE#SCREEN Campaign Abuses ScreenConnect to Give Attackers Remote Control Access
SharePoint Flaws Used to Hack Switzerland’s Federal IT Agency
INC Ransomware is Calling Victims – Pressure Tactics Post SonicWall Zero-Day Exploit
CVE-2026-58048: cPanel Bug Enables Full Database Administrator Access
U.S. CISA adds a N-able N-central flaw to its Known Exploited Vulnerabilities catalog
31,000 Records Compromised in Breach of Liechtenstein Companies and Foundations Register
AI Runs the Hack: Chinese Actor Automates Cyberattacks With DeepSeek
River Bank obtained assurances from the attackers that the stolen data in the June attack was deleted
PNLD Confirms Data Breach Affecting UK Police and Justice Staff
Alleged Żabka Breach Exposes Jira Data, Source Code, and API Keys
Ruby on Rails Patches Critical Active Storage Vulnerability Affecting Image Processing
CareCloud Breach Exposes Medical and Financial Data of 345,000
CISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota Attacks

International Press – Newsletter

Cybercrime

CareCloud begins to notify hundreds of thousands after hackers stole medical records  

Żabka alleged data leak: 541k Jira tickets, 89 repos  

ExfilSquad Targets Misconfigured Microsoft Power Pages Portals  

Cyberattack hits Liechtenstein’s register of people behind companies and foundations  

Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions   

Major hedge funds targeted in wave of attempted cyberattacks

Belarusian leader of international ransomware scheme known as “Ransom Cartel” sentenced to 16 years in prison  

Scammers target OnlyFans users with deepfakes

UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments  

Malware

Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums   

DOUBLECUP, a ClickFix Loader Delivering CountLoader and DeviceManager RATs  

Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages

Wallet-depleting macOS malware wants your crypto     

Hacking

Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks

Rapid Response: Critical N-able N-central Vulnerability and Active Exploitation 

Swiss federal IT office hit by cyberattack  

OVSwrap: another Linux local root vulnerability 

Incident Report: unsanctioned agent behaviour during cyber testing  

Meta says its AI model hacked into another company during testing  

Natjack A NEW ATTACK CLASS AGAINST NETWORK INFRASTRUCTURE DEVICES  

XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638)  

Black Hat USA 2026: The ‘Breaking’ News: The OpenAI–Hugging Face Incident  

Hackers Stalked Me by Hijacking a Smartwatch for Kids  

Security update available for Metabase – Please upgrade now 

CSS:the bomb inside your inbox  

Intelligence and Information Warfare  

DarkSword’s Panel Sprawl: How One Body Hash Unravels a Six-Panel, Two-Codebase Operator Cluster

China launches mysterious probe into security of Palo Alto Networks’ products

The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict  

Republic of Georgia alleges foreign disinfo campaign sought to scare off Russian tourists

Cybersecurity

EU in talks with OpenAI, Anthropic after rogue AI agent hacks  

Commission publishes new guidance to support timely Cyber Resilience Act implementation  

Western government leaders call for a focus on infrastructure resilience, not AI hype

Brazil Health Surveillance Database Exposed 79GB of Sensitive Records     

Chinese router vendor denies its firmware contains backdoors – but pauses downloads to fix security issues anyway

ENDLESSDOORS Is Phoning Home. Pick Up  

Meta fined $567m in largest child safety ruling against social media giant 

Hackers targeted US private equity, other firms including Blackstone, CME, data shows  

Military device manufacturer discloses cyber incident to SEC 

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 108

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape

Malware Newsletter

TAG-195 Upgrades MaaS Ecosystem with Modular Tools 

Inside a DPRK BlueNoroff ClickFix Kit

SourTrade: Browser-Assembled Malware Delivered Through Malvertising  

MedusaHVNC: A Hidden Desktop That Steals Live Windows Sessions  

Unpacking “Cruciferra”: An Analysis of a Sophisticated Crypter Service  

Dysphoria: A Rising Star in Botnets – Evolution and In-Depth Technical Analysis  

Adform compromised to serve crypto stealer via supply chain attack  

Cato CTRL™ Threat Research: SilverFox Evolves: Abuse of New Drivers and Trusted Software Hijacking Enable Remote Access with ValleyRAT in Japan

Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon  

ClickFix, EtherHiding & a DPRK Wallet Trail

(Joint Cybersecurity Advisory) Warning Against Hacking Attacks on Korean Citizens and Businesses by State-Backed Hacking Organizations  

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft  

OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia 

Nested Trust: HollowFrame’s Layered Loader and Matryoshka Backdoors

Guarding Organizations Against Malware Risk: A Novel Graph-Based Malware Detection Method

EXE-Bench: Ranking the Tradeoffs of AI-based Windows Malware Detectors for Real-World Usability

Symmetric Dual-Domain Prototype Adaptation for Few-Shot Image-Based Malware Classification

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 107

Security Affairs newsletter Round 587 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.

Iran-Linked Actors Breach Are Targeting US Water and Energy Control Systems
Australian energy provider Origin Energy disclosed a data breach impacting customer data
Google Fined €890M Under EU Digital Markets Act Over Search and Play Store Practices
Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged
UAC-0099 Is Now Hiding Malware Inside a Fake Notepad++ Plugin to Target Ukrainian Organizations
The AI Trust Paradox: Businesses Are Racing Ahead, but Consumers Are Hesitating
US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra Servers
U.S. CISA adds Microsoft SharePoint and Check Point SmartConsole flaws to its Known Exploited Vulnerabilities catalog
Chaos ransomware deploys browser-based msaRAT to evade network detection
Google Released Gemini 3.5 Flash Cyber AI, a Specialized AI Model for Vulnerability Hunting
Check Point patches actively exploited SmartConsole authentication bypass flaw
CVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protections
Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft
U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities catalog
OpenAI AI models exploited zero-days to reach Hugging Face in benchmark test
Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522
Zimbra 10.1.20 patches multiple security issues, including a critical command injection bug
Qilin Ransomware Affiliates Abuse CVE-2026-0257 to Gain Unauthorized VPN Access
Attackers Exploit Critical ServiceNow RCE Flaw CVE-2026-6875
Dutch Intelligence Warns Russia Uses Hacked IP Cameras for Military Espionage
Critical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now!
CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server Takeovers
AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign
Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances
Attackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits

International Press – Newsletter

Cybercrime

Cookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware  

A blow against one of the world’s most dangerous phishing groups  

The Perfect Heist: NuGet Typosquat Targets Betting Platform to Rig Results

Swiss train maker tells ransomware crooks to get off at the next stop

Europol-led action against nihilistic violent extremist network “The Com”  

Illinois Man Sentenced to Over Six Years in Prison for Identity Theft and Wire Fraud  

Origin Energy investigates alleged cyber attack after hacker claims to have stolen data of two million customers in ransom bid 

Malware

SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor  

HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels  

AgentBaiting: How 800+ Fake AI Skills and MCP Servers Delivered Malware  

Chaos ransomware’s msaRAT: Living off the browser to build a covert C2 channel  

Dolphin X Stealer Targets 300+ Apps and Profiles Users with AI  

Hacking

Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation

Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)      

World’s Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent

5-Year-Old Pre-Auth nginx RCE Across 13 Call Sites: Two-Pass Capture Clobbering CVE-2026-42533  

Smashing the ServiceNow Sandbox – Pre Authentication RCE  

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

OpenAI and Hugging Face partner to address security incident during model evaluation  

The Vulnerability That Turned Adobe’s 300M-Install Extension Into a Full WhatsApp Takeover 

CVE-2026-8933: Local Privilege Escalation in Set-Capabilities snap-confine

Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access

American Hackers-for-Hire Proposal Sparks Heavy Criticism  

Intelligence and Information Warfare  

Brochure Cybersecurity advisory Russian state actors are compromising IP cameras  

UAC-0145 Primary Compromise Vectors as of July 2026  

Inside Russia’s Camera-Hacking Espionage Campaign 

Blog JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake 

CISA, NSA, FBI and Partners Warn Zimbra Collaboration Suite Users of Ongoing Russian State-Supported Malicious Threat Activity  

UAC-0099: LUNCHPOKE, BURNYBEAR, updated to MATCHBOIL.V2 and using Notepad++ 8.8.3

Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days from TA458

Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged  

Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure 

Cybersecurity

Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities

Identity Attacks Overtake Exploits as Top Ransomware Cause  

LG to Ban Residential Proxies from Smart TV Apps  

Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains

Introducing Gemini 3.6 Flash, 3.5 Flash-Lite, and 3.5 Flash Cyber  

Google hit with $1 billion EU fine, in ‘constructive’ talks to avoid more penalties  

Is Patching Dead? Vulnerability Management in the Post-Mythos Era

How AI guardrails are impeding the work of offensive cybersecurity researchers  

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

Security Affairs newsletter Round 586 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.

OpenSSL Fixes HollowByte Memory Exhaustion Bug
Daxin: 13-Year-Old China-Linked Malware Found Still Active on Manufacturer’s Network
U.S. CISA adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog
Ernst & Young (EY) Investigates Data Breach Involving Third-Party Support Tickets
A cyberattack hit Nichirei, one of Japan’s largest food companies
New Russian Campaign Uses Fake Webex and Zoom Installers to Deploy Starland RAT
U.S. CISA adds KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws to its Known Exploited Vulnerabilities catalog
Two Scattered Spider Members Sentenced to Prison Over £29 Million TfL Cyberattack
TuxBot v3: The IoT Botnet Built With AI – Bugs, Disclaimers and All
Claude Code and DeepSeek Powered Chinese Cyber Espionage Campaign
Zoom Fixes CVE-2026-53412, a Critical Account Takeover Bug
US and allied Governments’ Recommendations: Securing Network Devices Against Russian APT Groups
Chaotic Eclipse Unveils LegacyHive Exploit Affecting Fully Patched Windows Systems
AsyncAPI npm Supply Chain Attack: Malware Injected Into Packages With 2 Million Weekly Downloads
U.S. CISA adds SonicWall and Microsoft flaws to its Known Exploited Vulnerabilities catalog
SonicWall warns of active exploitation of two SMA 1000 zero-days
Patch Tuesday security updates for July 2026, the largest update ever. 621 CVEs in one month
U.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware Losses
Attacker Used AI to Build Custom PowerShell Recon Malware
Malware Hits Japan’s Largest Taxi Company Nihon Kotsu, Services Temporarily Suspended
CrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper
Lidl Notified Online Shop Customers in Germany, Belgium, and the Netherlands of a Data Breach
U.S. CISA adds a Cisco IOS flaw to its Known Exploited Vulnerabilities catalog
EU Targets FSB-Linked Hackers in New Sanctions Over Cyber Sabotage
Dutch Nationals Suspected in Odido Hack That Exposed Six Million Customers
Australia Alerts Organizations to Ongoing CMS Exploitation Attacks
Ryuk Ransomware Member Pleads Guilty Over Attacks on U.S. Organizations
Progress Told ShareFile Customers to Pull the Plug on Their Servers. Here’s What We Know.

International Press – Newsletter

Cybercrime

Armenian National Extradited to the United States Pleads Guilty to Ransomware Extortion Conspiracy  

Investigation into Odido hack points to possible involvement of the Dutch  

German firm files for insolvency, blames cybercrims who shut down production for 6 weeks

Japan’s largest taxi operator shuts systems after cyberattack

Inside Forg365: A Telegram-Distributed Sneaky 2FA-Style PhaaS Targeting Microsoft 365 

Two sentenced for hacking Transport for London in UK’s biggest ever cyber crime case  

Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man

Malware

CrashStealer: C++ macOS infostealer posing as crash reporter

Lucide Proxy: Turning Student Web Proxies into DDoS Bots      

AsyncAPI npm organization compromised, 2M weekly downloads affected  

TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains  

NadMesh Botnet Analysis: A Product-Grade Threat for the AI Service Era  

Hacking

Large-scale exploitation campaign targeting website content management systems (CMS)  

Analyzing AI-Augmented Network Enumeration  

LegacyHive public disclosure 

Claude for-Chrome Extension-Bypass

Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8n  

wp2shell: Pre Authentication RCE in WordPress Core  

OpenSSL HollowByte: A DoS Hiding in 11 Bytes  

wp2shell: Pre Authentication RCE in WordPress Core  

Intelligence and Information Warfare  

EU targets Russian intelligence officers accused of running a yearslong cyberspying campaign  

NSA revives ‘Tailored Access Operations’ name for elite hacking unit  

UK and EU strike Russian cyber networks with new sanctions  

Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting

NATO logistics, Ukrainian troops are top subjects of Russian camera hacks, advisory says  

Suspected Chinese Operators Use Claude Code and DeepSeek to Target Government and Financial Systems Across Four Countries  

Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor

New North Korean campaign uses fake coding interviews to steal developer credentials

Cybersecurity

xAI Grok CLI Uploads Full Repos and Secrets, Opt-Out Ignored  

Satya Nadella’s ‘Reverse Information Paradox’ post draws reactions from AI leaders

BabeLLM: A unified taxonomy for NLP-based LLM cybersecurity applications  

Treasury Sanctions Malware and Infrastructure Providers Supporting Ransomware Attacks Against Americans 

The July 2026 Security Update Review  

A Puerto Rico Government Agency Exposed 1 Million Social Security Numbers 

AI Data Centers Are Being Built Faster Than They Can Be Secured

Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei  

Ernst & Young discloses data breach after support system hack  

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

Security Affairs newsletter Round 585 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.

U.S. CISA adds iCagenda and Balbooa Forms flaws to its Known Exploited Vulnerabilities catalog
Critical U-Boot Bugs Undermine Secure Boot on Millions of Devices
Update Now: Critical Zimbra Classic Web Client Flaw Could Expose Mailboxes
Ransomware Never Stopped: Over 9,000 Confirmed Attacks Since 2018
222 GitHub Repositories Linked to Fake Go Package Malware Operation
Former Ransomware Negotiator Sentenced to 70 Months in Prison for Secretly Helping BlackCat Gang
GigaWiper Merges Three Malware Families Into One Destructive Backdoor
INTERPOL Operation First Light Nets 5,811 Arrests and Seizes $293 Million
GodDamn Ransomware Uses PoisonX to Blind Security Software
AssuranceAmerica Breach Exposes 7 Million Driver’s Licenses After Employee Account Hack
Microsoft fixed Defender flaw RoguePlanet (CVE-2026-50656)
Fake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes
Ubiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege Escalation
A Hacker Claims 35 GB of Accenture Source Code. The Company discloses the data breach
Telegram-Hosted RedWing Malware Lets Anyone Rent Android Spyware Tools
U.S. CISA adds Adobe ColdFusion, Joomlack Page Builder, Langflow, and JoomShaper SP Page Builder flaws to its Known Exploited Vulnerabilities catalog
CISA Deploys Anthropic’s Mythos AI to Hunt Vulnerabilities in U.S. Government Code
Critical Gitea Docker Bug Under Active Exploitation Exposes Repositories and Secrets
Spanish Police Arrest Man Linked to CARR, Z-Pentest, and NoName057(16)
Hidden Tenda Router Backdoor Grants Admin Access, No Patch Available
AI-Generated Malware Powers New Armored Likho APT Campaign
Januscape: 16-Year-Old Linux KVM Bug Enables Cloud VM Escape Attacks
Adobe ColdFusion flaw CVE-2026-48282 now exploited in the wild
Hidden Web Prompts Trick AI Agents Into Sending Money
Seven Bugs in FatFs Put IoT and Embedded Devices at Risk
Bad Epoll Flaw Gives Attackers Root Access on Linux and Android
Medtronic Notifies 3.8 Million After ShinyHunters Data Breach

International Press – Newsletter

Cybercrime

The National Police have arrested a suspected collaborator of the pro-Russian hacktivist groups CyberArmy of Russia Reborn (CARR) and Z-Pentest  

Accenture confirms breach after hacker offers stolen data for sale  

Over 5,800 arrests, USD 293 million intercepted in global fraud bust  

Florida Ransomware Negotiator Who Extorted and Attacked Multiple U.S. Victims Sentenced to Prison 

Felons, Fraudsters Flog Offensive Cybersecurity Startup 

Malware

Novel Java-Based QuimaRAT Targets Windows, macOS, and Linux  

Vibe Coded Extortion: Avalon’s Path from Legal Lure to CrownX Ransom Capabilities

GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses

GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware

Malicious Go Module Exposes GitHub Malware Lure Network Spanning 222 Repositories  

Hacking

Bad Epoll: The bug missed by Mythos  

Seven FatFs bugs, one very large blast radius  

Indirect Prompt Injection in Web Content Targets AI Agents  

TrojPix: Electromagnetic Covert Channels via Imperceptible Pixel Modulation  

Januscape: Guest-to-Host Escape in KVM/x86  

Critical Gitea Flaw Under Active Exploitation, Researchers Warn

Understanding Langflow CVE-2026-55255, and why higher CVSS vulnerabilities aren’t always the most exploited     

New Ghost Phishing Wave Is Breaking Traditional Email Security

Intelligence and Information Warfare  

Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign

Cavern Manticore: Exposing Iran-Linked Modular C2 Framework

Hacktivists call out Trump by hacking and defacing US Army websites 

What Happens if China Hacks the US Water Supply? I Went to a Secret War Game to Find Out  

CIA Officers Can Sense the Threat Within 

Canadian spy agency says it hacked drug traffickers, extremists, and a ransomware gang last year  

One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement

Cybersecurity

Tenda firmware (multiple versions) contains hidden authentication backdoor 

US cyber agency is using Anthropic’s Mythos to audit government code, sources say

Showdown in Strasbourg: The unexpected return of Chat Control 1.0 

Another massive data breach exposed millions of driver’s license numbers 

Reframing smart glasses as ‘pervert glasses’  

EU takes member states to court over unimplemented cybersecurity law 

npm install-time security and GAT bypass2fa deprecation 

Unfit to Boot: Breaking U-Boot’s FIT Signature Verification  

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

Security Affairs newsletter Round 584 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.

U.S. Government Agency Paid $1M to Data Extortion Group Kairos
FBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials
Pegasus Used Against MEP Investigating Pegasus, Citizen Lab Finds
JADEPUFFER: First End-to-End AI-Driven Ransomware Operation
The Anatomy of a Shadow AI Supply-Chain Breach: Lessons from the 2026 Vercel Incident
Law enforcememt operation disrupted Malicious Residential Proxy Networks NetNut
Government and Healthcare Are the Weakest Links in Global Email Security
Europe Confirms Record €4.1B Penalty Against Google for Android Practices
U.S. CISA adds a Microsoft SharePoint Server flaw to its Known Exploited Vulnerabilities catalog
430,000 FortiGate Devices Exposed in FortiBleed Ransomware Link
Adobe fixed multiple maximum-severity flaws in ColdFusion and Campaign Classic
Alleged Scattered Spider Hacker Extradited to U.S. to Face Cybercrime Charges
Oracle E-Business Suite Flaw Under Active Attack, 950 Systems Exposed
Azure CLI Targeted in LSHIY Password Spray Campaign Across 64 Orgs
CISA Warns BlueHammer Flaw Is Now Exploited in Ransomware Attacks
RustDuck: The Botnet That’s Still Small but Engineering Like It Plans to Grow
GuardFall Flaw Hits 10 of 11 Popular Open-Source AI Agents
XSS.is, The Forum That Ran the Ransomware Supply Chain Is Down. The Market Isn’t
U.S. CISA adds SimpleHelp flaw to its Known Exploited Vulnerabilities catalog
Hackers Steal Data of 4.38 Million Aflac Japan Customers
Apple Fixes WebKit Flaws in iOS and macOS, With Help From AI Tools
Attackers actively exploit the Oracle E-Business Suite flaw CVE-2026-46817
WhatsApp Usernames Are Coming. You Can Reserve Yours Right Now
U.S. Targets Russian Cyber Spies With $10M Bounty Over Messaging App Attacks
StegoAd: How 119 Fake Browser Extensions Stole Credentials and Ran Ad Fraud for Two Years
SSU and FBI Uncover Russian Cyber Espionage Operation Against Officials and Military Personnel
KDDI Data Breach Impacts up to 14.2 Million Email Accounts at Six ISPs

International Press – Newsletter

Cybercrime

Blackfield ransomware asks Nidec Corporation for $2 million ransom

XSS forum: from DaMaGeLaB to the 2025 takedown   

No (Bad) CAP: Inside an Ongoing LSHIY Password Spray Attack 

Alleged Member of Criminal Cyber Hacking Group “Scattered Spider” Arrested in Finland and Extradited to the United States 

SOCRadar Links FortiBleed Campaign to INC and Lynx Ransomware Operations

FBI Seizes NetNut Proxy Platform, Popa Botnet 

From CitrixBleed 2 to Cloudflared: The Tools and Techniques Behind Anubis Ransomware Attacks       

Cyber Criminal Group TeamPCP  

Malware

Hijacked npm Packages Use Novel VSCode Autorun and Blockchain Dead Drops to Deploy a Credential/Crypto Stealer  

Inside StegoAd: How a Threat Actor Evolved to Fuel Silent Ad Fraud and Credential Theft at Scale 

A Djinn in the Machine: TaskWeaver’s Node.js Intrusion Chain  

Chromium extension uses AI‑related branding to redirect browser search  

Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique      

Hacking

Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild

CVE-2026-48558: SimpleHelp Authentication Bypass Indicators of Compromise   

GuardFall: a universal shell injection vulnerability in open-source AI agents  

Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector

Hidden LLM Backdoors Could Detonate At Massive Scale 

Intelligence and Information Warfare  

Ukraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging Credentials

UNC5792 – Reward

Mustang Panda targets India’s government and energy sectors with ZOHOMURK and MINIRECON

PolinRider: North Korea-Linked Supply Chain Campaign Expands Across Open Source Ecosystems

Espionage Against the European Parliament         

Lazarus-Linked npm Malware Masquerades as Rollup Polyfills

Cybersecurity

It’s time to reserve your WhatsApp username

Massive breach spills credentials for thousands of sensitive networks  

Over 900 Oracle E-Business instances exposed to ongoing attacks 

Google Android: the Court of Justice upholds Google’s fine of around €4.1 billion 

Which industry & country has the worst email security? An analysis of 5,800+ domains for SPF, DMARC, DKIM & MTA-STS protocols

China Has Matched Anthropic in Cybersecurity, Resetting AI Race      

Google’s Continued Disruption of Malicious Residential Proxy Networks 

Claude Fable 5 isn’t permanently leaving subscriptions, Anthropic says

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 103

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape

Malware Newsletter

More Than 4,000 Legacy Routers Compromised by AryStinger, Turned into Global Attack Proxies for Hackers  

A VBScript campaign distributed through WhatsApp deploying RMM software 

Lost in relocation: analysis of a new loader distributing CASTLESTEALER  

PSA: Supply Chain Compromise Targets ShapedPlugin, Backdoored Pro Plugins Distributed via Official Channels

From PostCSS Masquerading to Windows RAT  

Prinz Eugen ransomware: a deep dive into a new Go-based encryptor

From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet      

Backdoor.Mistic: New Backdoor May be Linked to Ransomware Access Broker  

ESET takes part in Operation Endgame to disrupt Amadey and Stealc 

StealC you later: Proofpoint and IBM X-Force support Operation Endgame disruptions 

Backdoor.Mistic: New Backdoor May be Linked to Ransomware Access Broker 

macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox 

Miasma Mini Shai-Hulud Hits LeoPlatform npm Packages and GitHub Actions, Expands to the Go Ecosystem  

CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure  

DroidBreaker: Practical and Functional Problem-Space Attacks on Machine-Learning Android Malware Detectors

Burnyard: Future of Malware Analysis

Consistent and Compatible Modelling of Cyber Intrusions and Incident Response Demonstrated in the Context of Malware Attacks on Critical Infrastructure

An Explainable Hybrid Pipeline for Malware Classification: Benchmark Construction, Feature Reduction, and Security-Oriented Evaluation

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

Security Affairs newsletter Round 583 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.

New FBI Alert: Russian Intelligence Uses Signal Recovery Keys to Access Messages
Hospitality Sector Hit by Phishing Campaign Using Fake Guest Complaint Emails
DirtyClone: Fourth Linux Kernel Flaw in Six Weeks Escalates to Root
Chinese APT CL-STA-1062 Expands Attacks on Southeast Asian Critical Infrastructure With Custom Malware
Activist Phone Hacked With Cellebrite After Russia Contract Cancellation
U.S. CISA adds Cisco and PTC Windchill and FlexPLM flaws to its Known Exploited Vulnerabilities catalog
Third-Party Breach at Polymarket Leads to $2.94M Crypto Theft
macOS.Gaslight: North Korea-Linked Malware That Tries to Gaslight the Analyst
Tata Electronics Confirms Data Breach After 630GB Leak Claim Targets Apple and Tesla
Curl Fixes a 25-Year-Old Bug in Its Largest CVE Release Yet
Inside Mistic, the New Stealth Backdoor in Ransomware Intrusions
Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited Months Before Disclosure
Nathan Austad Pleads Guilty in DraftKings Hacking Scheme, Gets 18 Months
Europol Disrupts StealC and Amadey Malware Infrastructure in Operation Endgame
Why Frontier AI makes prioritization the most important part of your CTEM program
U.S. CISA adds Ubiquiti UniFi OS and Lantronix EDS5000 plugin flaws to its Known Exploited Vulnerabilities catalog
FortiBleed: The Broker Who Turned 73,000 Firewalls Into a Product Catalog
One Railway Radio Outage Stopped Trains Across Germany and Nobody Knew Why
Samsung KNOX Kernel UAF Exposes Millions of Galaxy Devices
Cisco Unified CM Flaw CVE-2026-20230 Actively Exploited in the Wild
DifyTap: Four Bugs Put over 1 million AI Apps at Risk
Xsolis Data Breach Impacts 1.4 Million People
ShapedPlugin Supply Chain Attack Backdoors Pro Plugin Updates
Squidbleed: 29-Year-Old Squid Bug Leaks User Credentials
4,300+ Outdated Routers Hijacked in Stealthy Spy Infrastructure by AryStinger malware
usbliter8 Brings Unpatchable BootROM Exploit to Apple A12 and A13 Devices

International Press – Newsletter

Cybercrime

The Broker Behind FortiBleed: Anatomy of a Russian-Speaking Access Operation  

Security News This Week: Hackers Claim to Leak Stolen Madison Square Garden Data 

Scaling cybercrime disruption through innovation and AI

Global cyber strike disrupts SocGholish, Amadey, and StealC malware networks

Third Defendant Sentenced To Prison For Hacking Fantasy Sports And Betting Website    

ACE, UEFA, UC3 and Mexican Authorities Disrupt Major PirloTV-Linked Sports Piracy Ring Serving Latin America

India’s Tata Electronics hit by cyber breach claiming to expose Apple, Tesla trade secrets     

Polymarket to Refund Users After Hackers Steal $3M in Frontend Attack      

Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access  

Malware

More Than 4,000 Legacy Routers Compromised by AryStinger, Turned into Global Attack Proxies for Hackers  

A VBScript campaign distributed through WhatsApp deploying RMM software 

Prinz Eugen ransomware: a deep dive into a new Go-based encryptor

Backdoor.Mistic: New Backdoor May be Linked to Ransomware Access Broker  

Miasma Mini Shai-Hulud Hits LeoPlatform npm Packages and GitHub Actions, Expands to the Go Ecosystem  

Hacking

Introducing usbliter8 

Squidbleed (CVE-2026-47729) Heartbleed’s ancient cousin, hiding in Squid since 1997  

PSA: Supply Chain Compromise Targets ShapedPlugin, Backdoored Pro Plugins Distributed via Official Channels  

DifyTap: Zafran discovers how attackers can silently wiretap AI data across tenants on a platform powering 1M+ apps  

When Defenses Become Attack Surface: CVE-2026-20971, a Samsung Kernel UAF  

Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager   

AISLE Discovers 6 New CVEs in curl, Including the Oldest Issue Ever Reported 

A new unpatchable flaw in Apple chips opens the door to an iPhone jailbreak  

Elite network says it was hacked after members’ personal data was left exposed  

New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries

Dissecting and Exploiting Linux LPE Variant: DirtyClone (CVE-2026-43503)  

Intelligence and Information Warfare  

Claude Fable 5 Resurfaces in Android App as NSA Breach Testimony Reshapes Ban  

From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet

Five Eyes cyber security agencies statement The AI shift in cyber risk: why leaders must act now   

Weaponized AI: Inside The Criminal Ecosystem Fueling The Fifth Wave of Cybercrime  

macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox  

Russia Breaks Into Human Rights Activist’s Phone With Cellebrite 

CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure

Russian Intelligence Services Continue to Target Commercial Messaging Applications  

Cybersecurity

Deutsche Bahn halts trains nationwide amid IT meltdown

How to Disappear From the Internet in 7 Days 

The quantum threat: Navigating cryptographic risks in a new computing era

Dozens of America’s largest companies have no simple way to report security flaws      

Xsolis Data Breach Affects 1.4 Million Individuals  

‘Wake-up call’: Europe reacts to Anthropic halting access to its Fable 5 and Mythos 5 AI models  

Meta Pauses Employee-Tracking Program Following Internal Data Leak 

State of SDLC Security 2026 

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 102

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape

Malware Newsletter

OptinMonster supply chain attack hits 1.2 million sites  

Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research   

Rokarolla : Android Banker with Complete Device Takeover Capabilities  

FishMonger’s arsenal upgraded: SprySOCKS for Windows

Analysis of APT37 NarwhalRAT Leveraging MS-Themed Phishing and Dead-drop C2

The macOS Tahoe artifact that tracks every menu selection a user makes  

easy-day-js: Supply Chain Campaign Targets Mastra npm Packages

WordPress PBN Plugin Drops Dual Webshells via Database Injection     

Hidden in Teams: DragonForce Attackers Weaponize Microsoft Teams Relays to Stay Hidden

Italian Invoice-Themed Phishing Campaign Delivers UpCrypter and NeptuneRAT

Multiple JetBrains IDE plugins caught stealing AI keys

Dozens of malicious wallpapers found on Steam Workshop: gamers’ accounts at risk  

Crypto Clipper uses Tor and worm-like propagation for persistence and control      

Sayonara, SocGholish: Operation Endgame Disrupts Major Cybercrime Operation  

Killing me gently: Inside Gentlemen’s EDR killer framework 

Cognitive Network Intrusion Detection Systems: Anomaly and Malware Detection for Zero-Day Attack Resilience

Multi-View Decompilation for LLM-Based Malware Classification

Anywhere, Any-Stymie: Remote Activation of Trojan Malware on LiDAR with Modulated Signals

Scalable Malware Family Classification Using Quantum Kernel Based Machine Learning

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

❌