Threat Intelligence Latest News, Reports & Analysis


threat intelligence news

Cybersecurity researchers have unpacked JSCeal , a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities. N-able’s incident notice says the flaw has been exploited in the wild; its release notes say that is unconfirmed. A TantoSec proof-of-concept turns an AES-CBC “padding oracle” in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. Attacker tools and infrastructure are now changing at machine speed. Weak IAM controls and missing logging are near-universal, affecting between 80% and 98% of accounts regardless of provider.

A threat actor keeps spreading the WeedHack malware to Minecraft players despite its original infrastructure taken down in July A 35-year-old man operating from China ran the largest fraudulent dark web network ever dismantled and the most disturbing detail… ShinyHunters used a phone-based social engineering attack to access Google’s corporate Salesforce database. Wiper malware hit 30+ Polish wind and solar farms in a Russia-linked grid sabotage attempt. Breach reports, malware alerts, and practical defense guidance, published as the threat landscape moves. http://articlesss.com/cisco-data-center-security-measures-taking-the-next-step-in-data-specific-safety/ The activity was concentrated on DSEwiki , a German software developer wiki that runs on the ProWiki farm at wikiservice.at and had been edited about 20 times over the previous decade.

According to findings from Gen Digital, WordlistLoader is being used to deliver Amatera Stealer (aka ACR Stealer or AcridRain Stealer) via ClearFake campaigns, which employ the ClickFix (aka FakeCaptcha) technique to dupe victims into running malicious commands under the pretext of completing CAPTCHA verification checks. Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that’s used to deliver next-stage payloads and likely sell access to ransomware groups. Weedhack was first documented by the cybersecurity company back in June 2026, detailing its use of SEO poisoning and YouTube to redirect traffic to the bogus domains. Notably, one of the sites has been built using Lovable , an artificial intelligence (AI)-powered website builder, highlighting how readily available tools can further lower the barrier and make it easier to launch convincing new malicious sites. However, it’s worth noting that the method is a lot less stealthy than traditional web-based DDRs, as security controls are likely to flag FTP connections …

threat intelligence news

Tortoiseshell Expands Malware Toolset With New Backdoor, SSH Tunnel

“The investigation also confirmed active data exfiltration, not just beaconing,” the company said. The tech giant said it required multiple endpoint and network behaviors to align before treating a domain as connected, including process ancestry, command-line patterns, request paths, headers, and upload parameters. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities ( KEV ) catalog, stating they are being exploited in the wild. The activity, codenamed Operation CameraSwarm , was reconstructed from a 407 MB exposed working directory containing 2,616 files across 234 subdirectories, including tooling, logs, shell history, and campaign records, with the researchers saying confirmed compromises were concentrated in Ukraine and Russia. The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remote payload during compilation.

A Poland cyberattack targeting critical energy infrastructure nearly led to a blackout, prompting warnings from Digital Affairs Minister Krzysztof Gawkowski. Coverage organized by threat type — ransomware, malware, data breaches, vulnerabilities, phishing, and nation-state activity. Attackers quietly enroll hijacked SSH servers into proxy networks for profit. Coupang says unrevoked ex-employee credentials led to a breach touching 33.7 million accounts. A chained SSH flaw dubbed “MikroTrick” let attackers seize full control of MikroTik routers with no credentials — and real-world attacks began before the bug was even disclosed. Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions.

threat intelligence news

threat intelligence news

Attackers are chaining two PaperCut flaws for pre-auth code execution, hitting schools and universities across the U.S. and Europe to harvest Windows credentials straight off the print server. “A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host,” Broadcom said in an alert. JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store’s server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5 . Security firm TantoSec has published a working exploit chain targeting vulnerabilities in Telerik UI for ASP.NET AJAX that can allow an unauthenticated attacker to execute remote code on the server hosting a vulnerable application.

  • Weak IAM controls and missing logging are near-universal, affecting between 80% and 98% of accounts regardless of provider.
  • Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management gave outsiders useful clues before login.
  • The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remote payload during compilation.
  • The implant is equipped to harvest Windows credentials using pixel-perfect fake lock screens, offer a reverse SOCKS5 pivot into victim networks, execute arbitrary commands, and establish persistence on the host.
  • “These clusters engage in persistent, adaptive phishing campaigns, using sophisticated social engineering tactics to compromise personal accounts across multiple platforms,” Google Threat Intelligence Group (GTIG) researchers Gabby Roncone and Wesley Shields said in a report published today.
  • “Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions,” JetBrains said .

Mathspace Breach Impacts More Than 1 Million Users in Australia, NZ

“We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems.” The exposure is in addition to 13,689 customers the company disclosed last month as having had their data either fully or partially exposed. The breach does not affect the security of the company’s hardware wallets. “Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions,” JetBrains said . A successful attack gives the attacker code execution on the store’s server and installs a persistent backdoor. “Sansec is publishing early because stores are being compromised right now,” the company said. The company named the four programs ProManager , WinUpdate , SoftManager , and LockAppHost and published the findings on September 2 , along with a technical white paper .

threat intelligence news

However, once the ScreenConnect instances were installed, the cybersecurity company said it observed the clients repeatedly spawning “wscript.exe” to execute VBScripts named 1.vbs, 2.vbs, 3.vbs, and 4.vbs. Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems. Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management gave outsiders useful clues before login. Securities and Exchange Commission on September 2, 2026, the California-based company said it settled the suit related to historical data practices before 2020, when it was managed by Kunlun.

Sansec said all current versions are affected, including 2.4.9, and that it reproduced the full unauthenticated chain on clean Magento Open Source installations of 2.4.7, 2.4.8, and 2.4.9. “The payloads are protected with javascript-obfuscator , using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers,” Check Point Research said in a technical report published last week. The company’s own communications disagree on whether the flaw has already been exploited. N-able has released its fourth hotfix in five weeks for the N-central remote monitoring and management (RMM) platform, this time for a maximum-severity vulnerability that could allow remote code execution on the N-central server without authentication.

“These clusters engage in persistent, adaptive phishing campaigns, using sophisticated social engineering tactics to compromise personal accounts across multiple platforms,” Google Threat Intelligence Group (GTIG) researchers Gabby Roncone and Wesley Shields said in a report published today. Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks within the U.S. Developers are advised to search ~/.cargo/registry/cache for the deleted crate files and to pin arrayref https://www.internetling.com/computer-security-tips-that-work.html at 0.3.9 or earlier, after the Rust Security Response Team unyanked the maliciously-yanked versions during the response.