Threat Actors & CampaignsEmerging1 src
Mustang Panda 추정 일본 외무성,방위성 노린것으로 추정 되는 악성코드-新段階に入った日印の戦略的関係.pdf.lnk
오늘은 Mustang Panda 추정 일본 외무성, 방위성 노린 것으로 추정되는 악성코드-新段階に入った日印の戦略的関係. pdf. lnk에 대해서 글을 적어보겠습니다. 일단 Mustang Panda라고 추정되는 이유는 중국은 일본-인도 간의 밀착 및 Quad..
Mustang Panda 추정 일본 외무성,방위성 노린것으로 추정 되는 악성코드-新段階に入った日印の戦略的関係. pdf. lnk
1 p
Breaches & RansomwareEmerging1 src
KR: 3Pro TV Data Breach Exposes 460,000 Records, Including 2,979 Bank Accounts
Park Hyo-jung reports: More than 460,000 pieces of personal data, including bank account and credit card information, were exposed in a breach at South Korean financial media outlet 3Pro TV. E-Broadcasting, the company that operates 3Pro TV, posted a notice on the outlet’s website saying it had confirmed that “an external actor illegally accessed the…
Source
https://databreaches.net/2026/08/09/kr-3pro-tv-data-breach-exposes-460000-records-including-2979-bank-accounts/1post-1participantReadfulltopic
Breaches & RansomwareEmerging1 src
Ransomware gangs skip the CEO, head straight for the 40-something IT manager
Carly Page reports: Turns out the fastest way to get a company to consider paying a ransom isn’t calling the CEO – it’s targeting the 46-year-old IT manager. That’s according to Zscaler, whose ThreatLabz researchers tracked 351 victims across 334 organizations caught up in a single ransomware campaign over the course of a month. The data…
Source
https://databreaches.net/2026/08/09/ransomware-gangs-skip-the-ceo-head-straight-for-the-40-something-it-manager/1post-1participantReadfulltopic
Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM
◈ Key Findings
• Observed indications that the Kimsuky group built and operated local LLM environments using Ollama, GPT4All, and Msty.
• Assessed to be in the phase of accumulating technologies and capabilities to integrate AI across its overall attack operations.
• Identified indicators exhibiting North Korea-linked characteristics, such as "Arirang", "싸이트", "가입리력", and "로출되였는지".
• Continued targeted attacks against foreign diplomatic missions, as well as the military, security, and virtual asset sectors.
• Abused Git-based repositories as C2 infrastructure and distribution channels for encrypted AsyncRAT payloads.
• Highlighted the need to strengthen behavior-based EDR detection and threat hunting against the abuse of LNK files, PowerShell, and GitHub.
Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM
Breaches & RansomwareEmerging1 src
Security Affairs newsletter Round 589 by Pierluigi Paganini – INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.
Enjoy a new round of the weekly SecurityAffairs newsletter, including international press.
Palo Alto Networks Faces China Cybersecurity Review Amid Rising Tech Tensions Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data U. S. CISA adds a Progress LoadMaster flaw to its Known Exploited Vulnerabilities catalog Unlimited Technology Systems Data Breach Exposes Data of 3.
Vulnerabilities & PatchesEmerging1 src
Voting machine researchers say federal work abruptly ended after Trump ally pushed back on their findings
LAS VEGAS — After spending roughly six weeks analyzing Dominion voting systems used in Puerto Rico’s 2024 elections, Mojave Research came back to the Trump administration with findings that startled its researchers.
The systems contained at least a dozen high- or critical-severity software vulnerabilities. Passwords were reused, firewalls were disabled and basic cryptographic protections were poorly implemented. And in Puerto Rico, active cellular hardware modems opened additional pathways into underlying software that was thought to be isolated.
But the small cybersecurity firm found no evidence that any of those weaknesses had actually been exploited, or that votes had been changed. The company still wanted more time to be certain.
Federal officials initially seemed willing to give them considerably more of it.
Vulnerabilities & PatchesEmerging1 src
Meeting Bank of Italy AI Guidance in the Post-Mythos Era with Picus
Key Takeaways
• The Bank of Italy warns that advanced AI models find and exploit software vulnerabilities in very little time.
• Attackers no longer need the skill or time once required, shrinking exploitation windows from months to hours.
• Bank of Italy guidance spans governance, cyber hygiene, exposure management, patching, monitoring, resilience testing, and third-party risk.
• Severity alone does not predict breaches, so validation evidence should drive patch, mitigate, monitor, or accept decisions.
• Picus Swarm connects BAS, Autonomous Pentesting, Exposure Validation, threat intelligence, and response in one governed workflow.
The Bank of Italy has warned financial institutions that advanced AI models can find software vulnerabilities and generate ways to exploit them in very little time. Attackers no longer need the same level of skill or time they once did [1].
Threat Actors & CampaignsEmerging1 src
2026-08-09: Traffic Analysis Exercise - First to Last
Malware-Traffic-Analysis.net - 2026-08-09 - Traffic analysis exercise: First to Last
Vulnerabilities & PatchesEmerging1 src
Palo Alto Networks Faces China Cybersecurity Review Amid Rising Tech Tensions
China opened a cybersecurity review of Palo Alto Networks, citing national security concerns but giving no details about the reasons behind the probe.
China’s Cyberspace Administration (CAC) announced that it’s launching a cybersecurity review of products Palo Alto Networks sells in the country. The announcement itself runs to a few sentences of formal Chinese, citing national security law and cybersecurity law as the basis for the review, and offers essentially nothing beyond that.
Threat Actors & CampaignsEmerging1 src
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems.
"These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but all of them deliver a powerful RAT and infostealer payload," OpenSourceMalware researcher Paul
Threat Actors & CampaignsEmerging1 src
ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials.
The macOS-focused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that's compatible with the computer's CPU architecture.
"
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
A recent wave of cyber attacks targeting financial services, private equity, and professional services has been attributed to a data extortion group known as UNC6671.
"UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via
Breaches & RansomwareEmerging1 src
Apple battles it out again with the UK over encrypted iCloud access
The UK Home Office has once again demanded Apple allows it access to encrypted iCloud data.
The Guardian reports that the Home Office issued a Technical Capability Notice to Apple, this time targeting only British users. A Technical Capability Notice is a formal government order that compels tech and telecommunications companies to build or maintain specific technical functions—such as intercepting data or removing encryption protections—so law enforcement can access communications.
In the last round of this ongoing battle , the UK secretly ordered Apple to provide blanket access to protected iCloud backups around the world. Advanced Data Protection (ADP) is Apple’s opt‑in end‑to‑end encryption for iCloud backups, which even Apple itself cannot read.
Travelers targeted when logging into hotel Wi-Fi networks
Microsoft has warned that hotel, conference, and other hospitality Wi-Fi networks are being actively abused by a Russian group to target travelers worldwide. The campaign, dubbed “CaptiveCrunch” turns a routine Wi-Fi login moment into an opportunity to compromise corporate accounts and devices.
From the user’s perspective, nothing looks out of the ordinary: they connect to hotel Wi-Fi, get the usual captive portal prompt, and perhaps see a familiar‑looking message about needing to update something before they can browse. However, behind the scenes, the allegedly state-linked group position themselves in the network path and manipulate DNS (Domain Name System) and HTTP traffic from captive‑portal Wi-Fi.
Threat Actors & CampaignsEmerging1 src
Cloud and SaaS Environments Now Top Targets for Attackers
Cloud and SaaS are now the preferred operating environments for threat actors, amid a continued shift to identity attacks
Who’s legally to blame for Anthropic and OpenAI’s autonomous AI hacks? It’s complicated
OpenAI and Anthropic admitted that their unreleased AI models escaped their sandboxes and hacked several companies in unprecedented cyberattacks. Who is legally to blame? Should prosecutors charge the two AI frontier labs? Can victims sue them? We spoke to lawyers who specialize in computer hacking laws to find out.
Threat Actors & CampaignsEmerging1 src
China-Linked Threat Actors Weaponize New Vulnerabilities in Under a Day
Chinese actors exploited the critical React2Shell exploit inside a day, while 88% of exploited vulnerabilities in H1 2026 were compromised within 48 hours of disclosure
Threat Actors & CampaignsEmerging1 src
HollowFrame Loader Uses Fake Python DLL to Evade Defender
New HollowFrame loader hid Go code in a fake Python DLL after pre-staging Defender exclusions
Threat Actors & CampaignsEmerging1 src
Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan
Two npm beta releases in the @joyfill namespace contain an import-time JavaScript implant that resolves encrypted code through Tron, Aptos, and BNB Smart Chain transactions. Static analysis shows that its primary branch reaches a 77 KB Node. js remote-access trojan. A parallel branch launches a detached Node. js process, requests a separate boot payload from 23[. ]27[. ]13[.
]43/$/boot , sends the marker header Sec-V: A9-0135-3 , decrypts the response, and evaluates it.
Joyfill provides software development kits for embedding forms, documents, and PDFs into web and mobile applications. @joyfill/components supplies the React UI components used to build, render, and edit these experiences, while @joyfill/layouts manages their page and field layouts.
Each package receives approximately 16,000 weekly downloads on npm.
Breaches & RansomwareEmerging1 src
The Next Evolution of MDR: Preemptive Defense and Agentic Investigation
For years, security operations followed a familiar sequence: detect suspicious activity, investigate what happened, and respond before it caused significant harm. That model developed in a threat landscape where defenders had considerably more time to establish the facts and decide what to do next.
In 2019, the average data breach took 206 days to identify and another 73 days to contain, creating a total breach lifecycle of 279 days .
As the time between initial access and attacker movement continues to contract, security teams are being asked to operate within a much narrower window. AI is accelerating reconnaissance, vulnerability discovery, and campaign execution, while defenders are responsible for growing volumes of data across cloud, identity, endpoint, SaaS, and AI environments, often without equivalent growth in analyst capacity.
Vulnerabilities & PatchesEmerging1 src
Modern Attack Vectors | Recorded Future
Key Takeaways
• Modern threat actors have shifted from brute-forcing firewalls to compromising digital identities via stolen session cookies and credential stuffing to bypass MFA entirely
• Adversaries increasingly target unpatched edge infrastructure like VPNs for zero-day access while exploiting open-source repositories to launch upstream supply chain attacks
• Traditional internal security telemetry may miss critical pre-attack signals, making real-time, outside-in threat intelligence essential to neutralizing modern vectors before a breach occurs
For today’s Chief Information Security Officers (CISOs) and security team leaders, defending your business can feel like trying to hold back the ocean.
Threat Actors & CampaignsEmerging1 src
Tracking Advanced Persistent Threat Groups | Recorded Future
Key takeaways
• Advanced Persistent Threats (APTs) are sophisticated, long-term cyber campaigns conducted by well-funded human adversaries (often nation-states) who target specific organizations for espionage, data theft, or critical infrastructure disruption.
• Traditional security tools often fail because APT groups bypass signature-based defenses by using customized malware and Living-off-the-Land (LotL) tactics that mimic legitimate user activity inside the network.
• Effective advanced persistent threat detection requires minimizing breakout time, the window between initial access and lateral movement, by identifying threats before they establish deep persistence.
• To defeat modern APTs, organizations must move from reactive internal monitoring to proactive threat intelligence, tracking adversary infrastructure on the open, deep, and dark web before an attack is launched.
Threat Actors & CampaignsEmerging1 src
AI Has Enhanced Iran’s Asymmetric Playbook During the 2026 Conflict
Executive Summary
Between January and June 2026, Tehran survived unprecedented military, economic, and political pressure by relying on its longstanding hybrid warfare model: blending asymmetric military operations, cyber operations, information warfare, proxy attacks, and coercive state control.
Artificial intelligence (AI) enhanced these capabilities, acting as a force multiplier and almost certainly increasing the speed, scale, and effectiveness of Iranian operations. Ultimately, Iran demonstrated that its strategic resilience does not depend on possessing the most advanced AI capabilities; rather, the source of Iranian power remains the asymmetric playbook itself.
During these crises, Iran compensated for conventional military and economic disadvantages through scalable, low-cost, and deniable asymmetric capabilities.
Policy & RegulationEmerging1 src
The FBI Warned About Fake Permit Fees. The Harder Question Is Where the Money Goes. | Recorded Future
A fast-growing scam impersonates city and county planning departments, sending property owners real-looking invoices for fake permit fees and pressuring them to wire payment on a deadline. Because the victim authorizes the transfer, payments commonly clear the behavioral checks built to catch fraud, making beneficiary accounts one of the most reliable signals to track this campaign.
Research from CYBERA, the partner behind Recorded Future® Money Mule Intelligence, maps a single active ring down to the verified accounts it used, and shows why direct, fraudster engagement and account-level intelligence catches what scoring misses.
The FBI sounded the alarm. Issuers still can't see it
On March 9, 2026, the FBI's Internet Crime Complaint Center issued a public alert about criminals impersonating city and county officials to collect fraudulent planning and zoning permit fees.
Breaches & RansomwareEmerging1 src
Moody Bible Institute - 2,303,416 breached accounts
In June 2026, Moody Bible Institute was targeted by a ShinyHunters "pay or leak" extortion campaign . Over 2. 3M unique email addresses and other personal data were later published publicly, including names, physical addresses, phone numbers, dates of birth and other information relating to donors, supporters, students and alumni.
In their disclosure notice , Moody advised that they had "engaged both internal and external cybersecurity experts to thoroughly investigate the matter".
Threat Actors & CampaignsEmerging1 src
Guide to Cloud Application Security: Must-Knows and No-No’s | Huntress
Cloud application security keeps threat actors away from your data. We share practical ways to protect your apps and why it matters for your team today.
Breaches & RansomwareEmerging1 src
Sysco - 2,691,852 breached accounts
In June 2026, the food distribution company Sysco was targeted by a ShinyHunters "pay or leak" extortion campaign . Data was subsequently published containing 2. 7M unique email addresses belonging to staff and customers. The data also contained largely corporate contact information including names, phone numbers, physical addresses, internal job titles, and customer feedback.
Breaches & RansomwareEmerging1 src
American Tower - 216,601 breached accounts
In June 2026, telecommunications tower infrastructure company American Tower was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data allegedly taken from the company containing more than 200k unique email addresses belonging to employees, contractors, customers, and leads. Exposed data also included names, addresses, and phone numbers.
Breaches & RansomwareEmerging1 src
Madison Square Garden Sports - 9,796,738 breached accounts
In June 2026, the sports and entertainment company Madison Square Garden Sports was the target of a ShinyHunters "pay or leak" extortion campaign . The group later published the alleged data, which included almost 10M unique email addresses spanning staff and customers, along with extensive personal, employment and customer relationship information.
Breaches & RansomwareEmerging1 src
JCPenney - 368,418 breached accounts
In June 2026, retailer JCPenney and associated brands were targeted in a ShinyHunters "pay or leak" extortion campaign . Data allegedly obtained from JCPenney through the exploitation of a critical zero-day vulnerability in Oracle PeopleSoft was later published publicly. The exposed records indicated they primarily related to internal HR systems and impacted current and former employees.
The data included 368k corporate and personal email addresses, names, dates of birth, Social Security numbers, phone numbers and
[tl;dr sec] #332 - I've Joined OpenAI, fwd:cloudsec, AWS Well Architected Supply Chain Security
Hey there,
I hope you’ve been doing well!
🤔 New Job, Who Dis?
TL;DR : I’ve joined OpenAI to lead their Cyber efforts.
I’m joined by Mike Aiello , an awesome security executive and human. Mike was previously CTO at Secureworks, led product for Google Cloud Security from 0 → $B’s in revenue, and CISO at Goldman Sachs.
I was going to write a post describing all the details about joining, my thought process, etc. but it turns out there’s a lot to do at OpenAI and I’ve gotten very busy 😅 The post is started but not finished, will share when I can.
So here’s the short version.
Why
Threat Actors & CampaignsEmerging1 src
SilabRAT, What’s Your Power?
SilabRAT (aka SnappyClient) is an advanced Remote Access Trojan (RAT) sold as a Malware-as-a-Service (MaaS) on Darkweb forums. Developed by the threat actor "o1oo1," SilabRAT is heavily focused on financial gain through credential theft. It offers stability and is capable of bypassing existing security measures.
[tl;dr sec] #330 - AWS Pathfinding Labs, Running Codex Safely at OpenAI, Glasswing Updates
Hey there,
I hope you’ve been doing well!
⛰️ Ain’t No Mountain High Enough
To keep me from sending to you bae.
Literally as I was starting to write this intro, my home Internet went out. After a moment I realized I had gotten a text a few days ago- scheduled maintenance with my Internet provider 😅
So now I’m finishing this issue via hot spotting with my phone.
I’ve wondered sometimes what I’d do if there was some sort of force majeure world or personal event that put my ability to finish the newsletter in jeopardy.
We cut to- *Movie trailer voice* In a world, where there’s too much security news…
Vulnerabilities & PatchesEmerging1 src
CVE-2025-68613: Zerobot botnet exploits critical vulnerability impacting n8n AI orchestration platform
Zerobot, a Mirai-based botnet known for targeting Internet of Things (IoT) devices, has leveraged a critical vulnerability tracked as CVE-2025-68613 to compromise instances of the n8n workflow automation platform.
Threat Actors & CampaignsEmerging1 src
Handala Threat Group
An Iranian aligned threat group conducting destructive and espionage focused cyber operations against organizations in Israel and Western countries.
What's on your clipboard?
One of the fascinating aspects of Windows systems, from a DF/IR perspective, for me has been the clipboard. Notice I said, "one of", rather than "the"... that's because there are a lot of fascinating aspects of Windows systems when it comes to DF/IR work. I include the clipboard in this mostly because there is various malware... infostealers, etc...
that will dump the contents of the clipboard as part of their functionality. Also, there's malware that will place a malicious bitcoin wallet address on the clipboard, in hopes that the user simply pastes that address when they're enabling a transaction. I mention malware that modifies the clipboard in this 2008 blog post .
I'll admit that early on in my DF/IR career, this isn't something that I thought about collecting as part of an IR engagement.
Questions I've Been Asked
Sometimes I'll get questions via different routes... webinars or podcasts, via social media, DM, or even email. Getting questions is good, because it keeps me aware that I'm in somewhat of a bubble, given the work I do and the environment in which I do it. Given the nature of "social" media (hint: it's rarely "social"), it's tough to draw a bead on where you are at any given moment, so questions can be invaluable.
Here's an interesting question I got from Brian Carrier during a webinar he invited me to...
If you have the entire Registry and limited time, what do you do?
The Cyber Triage LinkedIn post has 9 pages, and as you can see from the first one, my answer to the above question is:
I cheat.
For me, it's pretty simple. Beginning with the second slide from that LinkedIn post, I explain what I mean by " I cheat ".
Grab Bag
This started out as a bit of an end-of-the-year grab bag of posts, but I don't like simply linking to things, dropping links with no explanation as to why; instead, I'd rather share the why behind what I found interesting about the post or article.
And don't worry... I know after 2025, there are folks out there expecting a flaming bag full of dog poop dropped off on their doorstep, but rest assured... this isn't that.
Anyway, as I was working on this post, it just sort of rolled into 2026, so I'll start off my first post of the year with a grab bag of things I found interesting right there at the end of 2025.
What's in your Registry? CloudSEK recently shared this write-up on Silver Fox; what I found most interesting was from "Stage 4 - Valley RAT", "Stage 2".
Selling Surveillance as Convenience
Selling Surveillance as Convenience
Illustration: Em / Privacy Guides
• Photo: Zeki Okur / Unsplash
Increasingly, surveillance is being normalized and integrated in our lives. Under the guise of convenience, applications and features are sold to us as being the new better way to do things. While some might be useful, this convenience is a Trojan horse . The cost of it is the continuous degradation of our privacy rights, with all that that entails.
As appalling as it is, the truth is the vast majority of software companies do not consider privacy rights and data minimization practices strongly enough, if at all. Most fail to implement the principles of Privacy by Design that should guide development from the start.
Whether this comes from ignorance, incompetence, greed, or malicious intent can be debated.