Tortoiseshell is known to be active since at least July 2018, mainly targeting defense, aerospace, IT service providers, and military organizations in the Middle East and the U.S. Group-IB, in a new analysis published today, described the cyber espionage actor as among the most active Iranian APT groups in 2026. Flashpoint data reveals infostealers were responsible for taking 1.7 billion credentials in the first half of 2026 Grandoreiro is active after its 2024 disruption, with Mexico now accounting for 40% of detections Scroll down for all the latest threat intelligence news and articles.
A threat actor keeps spreading the WeedHack malware to Minecraft players despite its original infrastructure taken down in July A 35-year-old man operating from China ran the largest fraudulent dark web network ever dismantled and the most disturbing detail… ShinyHunters used a phone-based social engineering attack to access Google’s corporate Salesforce database. Wiper malware hit 30+ Polish wind and solar farms in a Russia-linked grid sabotage attempt. Breach reports, malware alerts, and practical defense guidance, published as the threat https://hokuen.info/silverstone-circuit-security-surveillance-tech landscape moves. The activity was concentrated on DSEwiki , a German software developer wiki that runs on the ProWiki farm at wikiservice.at and had been edited about 20 times over the previous decade.
“These clusters engage in persistent, adaptive phishing campaigns, using sophisticated social engineering tactics to compromise personal accounts across multiple platforms,” Google Threat Intelligence Group (GTIG) researchers Gabby Roncone and Wesley Shields said in a report published today. Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks within the U.S. Developers are advised to search ~/.cargo/registry/cache for the deleted crate files and to pin arrayref at 0.3.9 or earlier, after the Rust Security Response Team unyanked the maliciously-yanked versions during the response.
Sansec said all current versions are affected, including 2.4.9, and that it reproduced the full unauthenticated chain on clean Magento Open Source installations of 2.4.7, 2.4.8, and 2.4.9. “The payloads are protected with javascript-obfuscator , using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers,” Check Point Research said in a technical report published last week. The company’s own communications disagree on whether the flaw has already been exploited. N-able has released its fourth hotfix in five weeks for the N-central remote monitoring and management (RMM) platform, this time for a maximum-severity vulnerability that could allow remote code execution on the N-central server without authentication.
- The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities ( KEV ) catalog, stating they are being exploited in the wild.
- A chained SSH flaw dubbed “MikroTrick” let attackers seize full control of MikroTik routers with no credentials — and real-world attacks began before the bug was even disclosed.
- Kaspersky, which discovered the threat in June 2026, said the end goal of the malware is to serve a multi-stage downloader to enable ad fraud and creation of a proxy botnet.
- “While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn’t do harm, the threat actor’s use of npm isn’t to infect developers who install it, but to use the registry and its mirrors as a safe, validated storage for the malware,” OX Security researchers Moshe Siman Tov Bustan and Vitalii Chepurko said .
- Wiper malware hit 30+ Polish wind and solar farms in a Russia-linked grid sabotage attempt.
- Cybersecurity researchers have unpacked JSCeal , a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities.
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
According to findings from Gen Digital, WordlistLoader is being used to deliver Amatera Stealer (aka ACR Stealer or AcridRain Stealer) via ClearFake campaigns, which employ the ClickFix (aka FakeCaptcha) technique to dupe victims into running malicious commands under the pretext of completing CAPTCHA verification checks. Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that’s used to deliver next-stage payloads and likely sell access to ransomware groups. Weedhack was first documented by the cybersecurity company back in June 2026, detailing its use of SEO poisoning and YouTube to redirect traffic to the bogus domains. Notably, one of the sites has been built using Lovable , an artificial intelligence (AI)-powered website builder, highlighting how readily available tools can further lower the barrier and make it easier to launch convincing new malicious sites. However, it’s worth noting that the method is a lot less stealthy than traditional web-based DDRs, as security controls are likely to flag FTP connections …
Coupang Data Breach Traced to Ex-Employee’s Unrevoked Access Keys Exposes 33 Million Accounts
A Poland cyberattack targeting critical energy infrastructure nearly led to a blackout, prompting warnings from Digital Affairs Minister Krzysztof Gawkowski. Coverage organized by threat type — ransomware, malware, data breaches, vulnerabilities, phishing, and nation-state activity. Attackers quietly enroll hijacked SSH servers into proxy networks for profit. Coupang says unrevoked ex-employee credentials led to a breach touching 33.7 million accounts. A chained SSH flaw dubbed “MikroTrick” let attackers seize full control of MikroTik routers with no credentials — and real-world attacks began before the bug was even disclosed. Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions.
The implant is equipped to harvest Windows credentials using pixel-perfect fake lock screens, offer a reverse SOCKS5 https://exprimamedia.com/threat-intelligence-platforms-market-insights.html pivot into victim networks, execute arbitrary commands, and establish persistence on the host. Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a macOS-focused information stealer, after correlating recurring endpoint and network behaviors across changing infrastructure, tracing the malware from payload retrieval through data collection, staging, and exfiltration. The accounts “were being used to promote the International Burke Institute (IBI), a self-described ‘expert community’ based in Israel,” the company said .
JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies
Microsoft did not disclose a victim count or attribute the activity to a named threat actor in the report published Tuesday. The researchers said 1,923 cameras were configured with a persistent account during the operation and 283 were reached through the P2P path. Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and a peer-to-peer (P2P) relay technique. “What makes SilkParasite interesting is the traces of AI-assisted development running through otherwise expert code, which is a different thing from AI-generated malware,” Bitdefender Labs said in a technical report shared with The Hacker News. A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia. A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska).
This creates significant identity-related risks for companies, potentially exposing corporate email, trusted business accounts, and other sensitive data. Apple’s own guidance states that the company never asks for a password, device passcode, or 2FA code to provide support. Cybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple’s Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support and ask for their device passcode. Nimbus Manticore also has a history of orchestrating its own version of the Dream Job campaign to deliver malware under the pretext of job opportunity-themed social engine…
“We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems.” The exposure is in addition to 13,689 customers the company disclosed last month as having had their data either fully or partially exposed. The breach does not affect the security of the company’s hardware wallets. “Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions,” JetBrains said . A successful attack gives https://event-miami24.com/israeli-servicemen-will-be-banned-from-accessing.html the attacker code execution on the store’s server and installs a persistent backdoor. “Sansec is publishing early because stores are being compromised right now,” the company said. The company named the four programs ProManager , WinUpdate , SoftManager , and LockAppHost and published the findings on September 2 , along with a technical white paper .
Because the malicious code sat in the build script of the injected dependency, building a project that resolved it was sufficient to run the payload, and nothing from the crates themselves had to be called. Although the security bulletin originally marked the “Exploited” field under the Exploitability Assessment table as “Yes,” on August 21, 2026, Microsoft corrected the “Exploited” status to “No” after The Hacker News contacted the company for comment. Kaspersky, which discovered the threat in June 2026, said the end goal of the malware is to serve a multi-stage downloader to enable ad fraud and creation of a proxy botnet. Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2 4.0. Two subsequent artifacts, each detected in June and July 2026, make use of a Virtual Hard Disk (VHD) file that activates the infection chain. The activity is assessed to be the work of a China-nexus threat actor with moderate confidence.
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
“The investigation also confirmed active data exfiltration, not just beaconing,” the company said. The tech giant said it required multiple endpoint and network behaviors to align before treating a domain as connected, including process ancestry, command-line patterns, request paths, headers, and upload parameters. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities ( KEV ) catalog, stating they are being exploited in the wild. The activity, codenamed Operation CameraSwarm , was reconstructed from a 407 MB exposed working directory containing 2,616 files across 234 subdirectories, including tooling, logs, shell history, and campaign records, with the researchers saying confirmed compromises were concentrated in Ukraine and Russia. The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remote payload during compilation.