Normal view

There are new articles available, click to refresh the page.
Today — 11 August 2026Main stream

Top US defense device maker IEH Corporation admits hackers broke into its systems

  • Attackers stole IEH employee credentials via a fake Microsoft login page
  • Inbox access exposed sensitive defense‑related communications and technical documentation
  • Malicious mailbox rules were removed as IEH contained the unauthorized access

Criminals have broken into the email inboxes of IEH Corporation, a significant supplier for the US military and companies in the commercial aerospace and space industry.

In an 8-K report filed with the US Securities and Exchange Commission (SEC), IEH said that unidentified threat actors reached out to one of its employees, pretending to be a “prospective business contact”.

The atatckers shared a link to what appeared to be a Microsoft document, prompting the victim to log in. Obviously, the login page was bogus, and the login credentials were relayed to the attackers instead.

Malicious mailbox rules

“The threat actor gained access to mailbox contents, including email messages, attachments, customer communications, purchase orders, engineering-related documentation, and potentially export-controlled technical information,” the 8-K reads.

The culprits, however, were not named and no threat actors have yet claimed responsibility for the attack.

IEH said it found no evidence that data had been exfiltrated from the compromised inbox. However, its defenders did discover and remove “malicious mailbox rules”. Usually, crooks set up such rules to automatically forward incoming emails to an inbox under their control, while deleting traces of the activity. This would allow them to continue receiving sensitive emails even after the initial compromise was remediated.

The company also said it completed a full audit of the inbox and done “corrective actions to contain any impact of the unauthorized access.”

IEH Corporation produces “specialized products used in military satellites, missiles and fighter jets,” meaning the information found in the inbox could be quite valuable, especially for nation-states such as Russia, China, North Korea, or Iran.

IEH does not publicly name its clients but it does say that its defense applications include Apache AH-64, V-280 Valor and SH-60 Seahawk programs, as well as Patriot, THAAD, AMRAAM and APKWS missile programs. It reported a revenue of almost $30 million for the 2026 fiscal year.

Via The Record

US healthcare software giant Unlimited Technology Systems admits hackers may have stolen sensitive data of 3.8 million people

  • Attackers stole extensive personal and medical data from 3.8 million individuals from Unlimited Technology Systems
  • Breach source and methods remain unknown, with no group claiming responsibility
  • Stolen data poses major fraud risks, prompting free identity monitoring from Kroll

US healthcare organization Unlimited Technology Systems has revealed it suffered a cyberattack in which it lost a treasure trove of sensitive information belonging to millions of people.

The company recently made the information public and shared details with the US Department of Health and Human Services, noting that someone broke in on October 5, 2025 and within five days exfiltrated valuable data belonging to just over 3.8 million people.

The attacker stole people’s full names, Social Security numbers (SSN), dates of birth, emails and mailing addresses, phone numbers, demographic information, scans of driver’s licenses and other government IDs, insurance cards, intake forms, health insurance policy numbers, claims and benefits information, medical record numbers, dates of service, and diagnosis data.

Supply chain woes

The company did not say who the threat actors were, or if they demanded any ransom in exchange for deleting the data.

No hackers have claimed responsibility just yet, and we also don’t know how they managed to break in, as different groups have different methods.

ShinyHunters, for example, prefer calling their victims on the phone, pretending to be IT support and convincing their victims to give them access via remote management tools. Other groups might try to exploit vulnerabilities in routers, firewalls, and other hardware.

Whoever it was, they have a valuable data set in their possession. This kind of information can be sold on the black market or used in identity theft and wire fraud. To mitigate these risks, Unlimited Technology Systems is offering free identity monitoring services to affected individuals through Kroll.

Unlimited Technology Systems is a software company that provides financial technology for healthcare organizations. It works with around 4,500 clinics and 6,500 specialty healthcare providers in the US, processing north of $70 billion in net healthcare charges every year.

According to BleepingComputer, the company processes information on behalf of its clients, which means that the victims of this attack have no direct relationship with Unlimited and have probably not even heard of it.

Samsung patches nearly 200 security issues on its phone hardware - here's what you need to know

  • Oversecured found 176 vulnerabilities across Samsung’s preinstalled mobile apps
  • Flaws enabled account takeover, code execution, and traffic hijacking via bloatware
  • Samsung patched all reported issues, affecting hundreds of millions of devices

Security researchers from Oversecured have given “bloatware” an entirely new meaning, revealing that they uncovered 176 vulnerabilities - including some rather worrying ones - in Samsung’s mobile apps.

For the last three years, the team analyzed Samsung’s preinstalled system applications and found vulnerabilities that could cause some serious harm. Some of the bugs granted camera and microphone access, while others allowed for remote Samsung Account takeover with nothing more than a single click.

Some flaws allowed for network traffic hijacking via DNS manipulation, and others granted arbitrary code execution via an image. In theory, a malicious actor could craft and send a JPEG image which, when the victim opens, copies and loads attacker-controlled native libraries from the SD card. Finally, Oversecured found path traversal vulnerabilities allowing writing arbitrary files to the file system without proper path validation.

Arbitrary code execution

The researchers disclosed their findings to Samsung which, according to their report, fixed all of the reported issues - the full list can be found on GitHub.

Most Android smartphone manufacturers preload their devices with proprietary apps - think Bixby, Samsung Free, or AR Zone. These apps - which cannot be uninstalled or removed from the devices - aren’t necessary to their operations and are often not wanted by the users in the first place.

This 'bloatware' is also one of the key selling propositions of Google Pixel devices, since these are considered “stock Android”, or bloatware-free.

Out of context, these bugs are nothing extraordinary. Single-click account takeover flaws and traffic hijacking bugs pop up every now and then and get fixed rather quickly. The context here is that these are Samsung’s proprietary apps that don’t fall under the protection of Google’s Play Protect. Users might think they’re safe because they’ve not downloaded apps from risky places, or enabled dangerous permissions, when in reality, they’re not safe at all:

“Preinstalled system applications run with extra privileges than normal apps, cannot be removed by users, and operate outside Google Play Protect,” the researchers warned. “A single vulnerability affects hundreds of millions of devices globally through one vendor's distribution channel.”

Levi's reveals security tear may have let hackers steal important corporate data

  • Attackers used social engineering to access Levi’s network and steal corporate data
  • Details on stolen information, methods, and perpetrators remain largely undisclosed
  • Voice‑phishing extortion groups are suspected, though no one has claimed responsibility

Levi Strauss has revealed it recently suffered a cyberattack and lost corporate files - however some crucial details around the incident are missing.

The company filed a new report with the US Securities and Exchange Commission (SEC), noting how hackers accessed its infrastructure through “social engineering” against three of its employees. We don’t know if that was via email, voice phishing, or some other technique.

After breaching the network, the crooks - who weren’t identified - “accessed and exfiltrated certain corporate information”. Again, we don’t know which information was accessed, or how much of it.

Was it UNC6671?

In response, Levi’s said it had “initiated response protocols, implemented containment measures, and launched an investigation” which remains ongoing. Again, we don’t know what these measures are, or how the crooks were ousted.

The company says the incident did not disrupt its business operations, or caused interruptions, in any way, and that it does not expect it to have any material impact whatsoever.

While Levi’s did not name the perpetrators, and while none have yet claimed responsibility on the dark web, some publications have hinted at UNC6671, a “financially motivated threat cluster that conducts data-theft extortion attacks through voice phishing”. The tactic seems to have been “borrowed” from ShinyHunters, arguably one of the largest data extortionists out there.

The group would call their targets on the phone (usually low-level employees with access to company SaaS solutions) and, while pretending to be from the IT department, convince the victims to either grant remote access, or to visit a malicious credential-grabbing landing page.

From there, the attackers would move in, map the infrastructure, exfiltrate valuable data, and then demand payment in cryptocurrency in exchange for deleting the data.

We have reached out to Levi’s with further questions and will update the article if we get an answer.

Via BleepingComputer

Experts warn North Korean hackers are increasingly using AI to build smarter and more devious cyberattacks

  • Kimsuky used local AI tools to evade monitoring and enhance operations
  • Researchers observed extensive AI-driven capability building across the group’s infrastructure
  • Defenders urged behavior-based detection to spot evolving AI-enabled threats

North Korean hackers have found a way to use Generative Artificial Intelligence (GenAI) to supercharge their activities without tipping off the tool’s maintainers.

When people use AI tools like ChatGPT or Claude, their activities can be (at least to some extent) tracked and curbed - with OpenAI recently identifying and terminating multiple ChatGPT accounts used in phishing and human trafficking.

That is why Kimsuky - a known state-sponsored North Korean threat actor, used Ollama, GPT4All and Msty locally, allowing them to process documents without sending any sensitive information to outside AI services.

"Consistent process of capability development"

The attacks were spotted by security researchers Genians who “conducted months of tracking and log analysis on the infrastructure utilized as C2 in this campaign,” to identify the tools they used.

Aside from the three LLMs, they also used retrieval augmented generation (RAG) tools for document search, as well as AI agent development frameworks, text-to-speech software, and an AI-assisted coding tool called Cursor.

Using AI to write malicious code is not as simple as it sounds, due to various guardrails set up by the developers. As a result, AI in crime has been mostly limited to drafting phishing emails and crafting authentic-looking but malicious landing pages. However, Kimsuky has shown that AI in cybercrime continues to evolve and is becoming an ever-greater threat.

“What was observed in the threat actor's infrastructure was not merely evidence of several documents being created with AI, but a consistent process of capability development: establishing local LLM runtime environments, configuring RAG based on documents in the actor's possession, collecting AI agent development frameworks, and acquiring libraries for integration with external commercial AI services,” Genians concluded.

As a result, defenders must move from content-based assessment to behavior-based detection, the researchers warned, saying this should serve “as the fundamental premise of security recommendations.”

“In addition to indicator of compromise (IoC)-based detection, organizations should contextually correlate the sequence of anomalous activities following LNK execution, including PowerShell execution, persistence establishment, and external communications, to assess the overall threat level.”

Before yesterdayMain stream

Why are so many AI models going 'rogue'? The experts weigh in

Over the past month, it seems like every frontier model has broken free of its constraints and launched a devastating attack against one or more other companies.

One of OpenAI’s models escaped a testing sandbox and launched a very real attack against AI and machine learning company Hugging Face. Just days later, Anthropic revealed that multiple variants of its Claude model also escaped a sandbox that wasn’t properly sealed and began attacking the enterprise infrastructure of three companies.

Now, Meta has revealed that one of its models attacked another company’s infrastructure during testing. The accident has been pinned on a misconfiguration that allowed the model to access the internet. So why have so many incidents happened in such a short space of time?

Why are models escaping their sandbox?

In the cases of Anthropic and Meta, their models were being tested by a third party company called Irregular. Anthropic’s AI model was taking part in a "Capture the Flag" exercise, where the model’s raw offensive capabilities were tested without the usual safeguards. But the sandbox was left connected to the internet. A similar error to Meta’s own accidental escape.

During the OpenAI incident, the company was testing two versions of GPT‑5.6 Sol using the ExploitGym benchmark. Unfortunately, the AI models performed better than expected - chaining multiple attack vectors, stolen credentials, and zero-day vulnerabilities.

The main reason these models are escaping their testing environments is because they are designed to do exactly that. These AI models act like a massive team of highly-trained cybersecurity experts hunting for vulnerabilities and exploits. But what would take a team of humans days or weeks to accomplish can be done in hours, or even minutes, by these AI models.

It’s no wonder thousands of employees from AI firms are calling for a pause on the development of the technology, and Congress is considering an AI kill switch.

Expert perspectives on AI escapes:

OpenAI

  • Nathaniel Jones VP, Security & AI Strategy, Darktrace:

What makes the OpenAI and Hugging Face incident important is that the models did not need malicious intent to cause harm. They were given the legitimate goal of solving a cybersecurity benchmark and found an unexpected route to the answers, escaping their test environment and compromising another organization in the process. From the models’ perspective, this appears to have been an effective solution to the task.

The AI's actions challenge the assumption that giving an agent a legitimate goal will produce legitimate behavior. As models become capable of pursuing objectives over longer periods, developers need to define not only what success looks like, but also which methods and boundaries remain unacceptable in reaching it. Those limits must also be enforced by the surrounding infrastructure, rather than relying on the model to respect them.

A single action by an agent may appear acceptable but as this incident shows, models are now capable of long, complex chains of reasoning and action that add up to a harmful outcome.

Security teams need to consider the AI systems operating in their own businesses as these capabilities rapidly evolve. Right now, many security systems focus on single actions. A single action by an agent may appear acceptable but as this incident shows, models are now capable of long, complex chains of reasoning and action that add up to a harmful outcome. Teams need a mindset shift to understanding AI agent behavior in its entirety, including the outcome it is working towards, in order to safeguard it.

Hugging Face's response also exposed a second tension. The company reportedly needed a Chinese-developed open-weight model because commercial models would not process genuine attack material. Its nationality is less important than the operational lesson that safeguards that cannot distinguish an attacker from an authorized investigator may constrain defenders more than adversaries.

OpenAI and Hugging Face deserve credit for investigating this together and discussing it publicly. Other AI developers should study it closely.

Anthropic

  • Dr. Ilia Kolochenko, founder of global cybersecurity company ImmuniWeb:

This seems to be quite an unimpressive marketing move from Anthropic in response to the OpenAI / Hugging Face drama, which attracted a lot of attention from all over the world recently.

Operationally, it appears that due to the progressive deterioration of the quality of training data, new AI models are getting dumber. Cheating and breaking the law, instead of accomplishing specific tasks, is certainly not an indicator of intelligence. Given that organizations and companies of all sizes now vigorously undertake all possible measures to protect their data from being exploited for AI training purposes, AI companies face a huge shortage of the high-quality and current data they so desperately need. Ultimately, frontier models are trained on synthetic, low-quality or even malicious and poisoned data, undermining their so-called intelligence. The situation is unlikely to improve in the near future unless AI companies agree to pay a fair price for training data, but this will force most of them out of business.

Given that organizations and companies of all sizes now vigorously undertake all possible measures to protect their data from being exploited for AI training purposes, AI companies face a huge shortage of the high-quality and current data they so desperately need.

Contemporary AI agents and LLM models tasked with security testing can – and almost certainly will – go rogue when security controls or safeguards are insufficient. Powerful LLMs are unpredictable by design and thus virtually uncontrollable by humans. Therefore, using frontier AI models for security testing might be extremely costly from the legal viewpoint. Under the existing laws on both sides of the Atlantic, if an AI agent or any AI-powered app escapes its sandbox and causes damage to a third party, the operator of the AI model will likely be liable for all the damage caused. Excuses like “AI did it” do not currently exist in the eyes of the law, leaving AI vendors on the hook. Criminal prosecution, under a narrow set of circumstances, is also not excluded.

The same is true for the end-users of AI: even if your security testing tool is powered by a third-party AI model, your company will likely be fully liable if something goes wrong. You may then file a lawsuit against the AI vendor that you used, but here your chances to succeed in a court of law are tiny due to countless contractual disclaimers and limitations of liability that will likely be enforceable against you. Therefore, if you plan to use agentic AI for security testing – think twice and talk to your lawyers. Otherwise, you may start getting summons to court on a daily basis.

Meta

  • Alex Goller, Principal Solution Architect EMEA at Illumio:

The fact we've had similar situations happen three times now across the biggest AI players is simply ridiculous. We've seen guardrails intentionally loosened to test their limits – Meta's model didn't need to be clever to breach another company's systems.

The timing of conveniently finding the exact same problem either means it's a stunt or they weren't paying enough attention during testing. Either way, both answers are worrying.

If the model has internet access, it's a bit like leaving the door open and being surprised when the cat walks out. What is concerning is that the testing infrastructure meant to prove these models are safe failed on a basic control issue.

If the model has internet access, it's a bit like leaving the door open and being surprised when the cat walks out. What is concerning is that the testing infrastructure meant to prove these models are safe failed on a basic control issue.

Fundamental cybersecurity hygiene still matters, and a frontier AI model is only as secure as the environment it's operating in.

Organisations need visibility into what AI systems can access and how they interact with the wider environment, along with controls that contain the impact when an agent behaves unexpectedly. That means keeping a close eye on egress traffic, so it’s flagged immediately when an agent tries to open unexpected outbound communication patterns that are not required to achieve its original goal. In the best case this would have been contained proactively.

We need to define exactly what an AI agent is permitted to do, rather than relying only on instructions about what it shouldn't do.

WhatsApp scam costs Hong Kong man $1.27 million after criminals used AI voice notes to impersonate his father — experts say secret codewords are the best way to stay safe

  • Scammers stole $1.27m from a Hong Kong man after tricking him with AI
  • The scheme impersonated his father using AI deepfake tech
  • Experts say using a secret codeword can thwart the fraudsters

A Hong Kong man was recently conned out of HK$10 million ($1.27 million) by scammers who used artificial intelligence (AI) on WhatsApp to impersonate his father and request the payments, highlighting the dangers of trusting increasingly realistic AI tools. Yet experts say there’s a simple trick that can save you from suffering a similar fate.

According to the Hong Kong police’s Cyberdefender platform (via the South China Morning Post), the fraudsters sent a WhatsApp voice message to the victim saying they urgently needed a transfer of HK$1 million ($127,000).

This was convincing to the target, the SCMP reported, because the “voice and manner of speech [of the message] matched his father’s.” The victim was repeatedly exploited this way until he had transferred the entirety of his savings.

Warning people against falling for AI trickery, the Hong Kong police force said: “Do not blindly trust voice messages. Even if the voice sounds similar, it does not necessarily mean it is accurate.”

If you’re unsure whether the message is genuine, put the phone down and call your friend or family member back so that you know with certainty who you are speaking to. The police also recommended enabling two-factor authentication on your devices and reviewing the list of devices connected to your accounts. If you see any suspicious devices, remove them immediately.

How to beat the fraudsters

The WhatsApp icon on an iPhone's display.

(Image credit: Brett Jordan / Unsplash)

Deepfake scams like this are so effective because they appear to come from a familiar, trustworthy source — even when they’re anything but. Yet experts have just published a proven way that you can beat the swindlers and keep everyone safe.

As reported by the BBC, setting a secret codeword to be used in emergencies can help you tell if the person on the call is actually a loved one or merely an AI impersonating them. As the BBC put it, “Deepfake scams might use your voice, but they don’t know what’s in your head.”

One tactic used by scammers is to use urgency in order to create panic and prevent you from thinking straight. That’s why it’s important to take a moment to think to ensure you remember to use the codeword and verify the caller’s identity.

When it comes to picking a codeword, “Pick something that’s easy to remember and hard to guess,” the BBC recommended. “Inside jokes are a safe bet.”

As Philadelphia lawyer and anti-scam activist Gary Schildhorn put it, there are three red flags to look out for: time pressure, a request for hard-to-trace funds (like cash, cryptocurrency or gift cards), and control over who you can speak to on the call. Experience any of those and you might be speaking to a malicious con artist.

Bear all that in mind and you stand a much better chance of protecting yourself from fraudsters. The next time you get an unusual message or call seemingly from a loved one, take a minute to breathe and remember your codeword.

Shock horror — AI-generated security patches fall short of actually solving all the problems they were meant to fix

  • Researchers tested AI-generated patches on six CVEs with poor success rates
  • Many fixes failed, altered behavior, or introduced new vulnerabilities
  • Guidance improved outcomes, leading to FLAWED evaluation harness release

When using Generative Artificial Intelligence (GenAI) to fix vulnerabilities, security professionals are most of the time just robbing Peter to pay Paul, experts have warned.

Researchers from 1Passwords Off-by-1 Labs analyzed fixes proposed by two frontier models - ChatGPT 5.5 at “medium” effort, and Claude Opus 4.8 at “high” effort.

As an experiment, the researchers took six recently disclosed CVEs and produced 6,080 patches using two frontier, cyber-capable reasoning models. The results were underwhelming to say the least - of all the proposed patches, just a quarter (26%) fully resolved the issue.

FLAWED work?

This obviously leaves plenty to be desired, as half (49.3%) of the patches failed to fix at least one existing exploit path. A fifth (20.1%) fixed the original issue but changed application behavior, while 2.3% introduced new security issues. Funny enough, 2.2% failed to fix the vulnerability while also introducing additional exploit paths, as well.

Even among the patches that might be considered (26% of clean ones and 20.1% of those that changed app behavior), more than a third were fragile and not entirely addressing the underlying problem.

The researchers created an acronym for automated LLM patches: FLAWED (Fix-Like Artifacts With Embedded Defects), and warned against letting AI work without human oversight: "The expected value of a fully LLM-generated, non-human-reviewed patch is a net-negative by a considerable margin."

Results drastically improved when the AI was given better context, the researchers further explained. Before working on any patch, human developers are usually given initial guidance. When AI is given proper guidance, its success rate rises to 65%. Incorrect guidance, on the other hand, drops the success rate down to 15.2%. The difference between humans and AI is that humans are better at catching misleading information and poor guidance.

This doesn’t mean developers will, or should, abandon AI. Worst case scenario is that developers will spend more time reviewing AI-generated fixes which could increase cognitive load and still end up being net negative. Therefore, the researchers released a patch evaluation harness called FLAWED, which organizations can now use to determine the effectiveness of their AI-generated fixes.

Via The Register

Experts warn malicious AI skills are hitting more victims than ever — with one family amassing 1.7 million downloads

  • Attackers cloned AI skills, later adding malicious code to steal credentials
  • Zenity Labs found millions of installs and dozens of dangerous skill variants
  • Vercel and Microsoft removed malicious skills, but manual removal is still required

AI skills, instructions that teach AI agents how to do certain tasks and thus extend their capabilities, are increasingly being used in supply chain attacks, researchers have found.

Security experts at Zenity Labs uncovered a credential-stealing campaign on skills.sh, a public registry (essentially an app store) for AI agent skills. In the registry, belonging to Vercel (a cloud platform for web applications), threat actors were cloning existing skills, creating typosquatted lookalikes which, at first, did nothing malicious.

However, after a little time had past, and the skills amassed a solid download count, the attackers introduced malicious code instructing the AI agents to, among other things, exfiltrate SSH keys, cloud credentials, Git and package manager tokens, Kubernetes and Docker configurations, database credentials, infrastructure-as-code credentials, environment files and service account files. The agents were then told to package the stolen information with host metadata and send it to the attackers.

Dozens of malicious skills

While Zenity Labs could not say exactly how many people fell victim to this attack, they did stress that a single skill family amassed more than 1.7 million aggregate installs (not unique users).

And that is just one skill family, in a sea of malicious skills. The researchers also said they found “dozens” of additional skills exhibiting either malicious or dangerous behavior. Almost a third (30%) of identified dangerous skills abused Claude Code and OpenClaw to drop malware to their targets, as well. Also, Zenity found “hundreds” of reserved and empty package names that were being kept for future attacks.

These findings show how quickly cybercriminals adapt, and how creative they can get when it comes to abusing new tech. In essence, this campaign is an AI spin on a software supply-chain attack, being similar in spirit to incidents where attackers compromise an existing trusted package or repository, and later push a malicious update.

Following responsible disclosure, Vercel and Microsoft removed the identified skills, but Zenity warns that those who installed them before won’t be safe until they remove them from their systems manually.

Top US hedge funds targeted by major vishing campaign — Blackstone, KKR and CME among those under fire

  • Google’s Threat Intelligence team links BlackFile (now Redact) to phishing and extortion attacks on major hedge funds and law firms
  • Group impersonates IT staff by phone, steering victims to spoofed login pages to steal SaaS credentials and tokens, then exfiltrates sensitive data
  • Targets include Blackstone, KKR, Apollo, CME Group, and firms like Paul Hastings; Google tracked $10.7 million flowing into 18 crypto wallets between January–May 2026

Some of the biggest US hedge funds and law firms have been targeted by a highly sophisticated data breach and extortion campaign, conducted by a group of criminals previously known as BlackFile, experts have warned.

BlackFile (or Redact, as the group is now calling itself) has a relatively simple modus operandi, also used by ShinyHunters - they call their targets on the phone (usually employees with access to SaaS systems), identify as IT staff, and direct victims to convincing, lookalike login pages designed to steal their credentials and authentication tokens.

Once they gain access to victims' accounts, the attackers access enterprise SaaS environments (for example, Microsoft 365 and Okta) and use automated tools to exfiltrate sensitive data. In the last step, they notify the victims and threaten to leak the data on the dark web unless a ransom is paid.

Stealing millions

Since a part of the process is to navigate the victims to spoofed login pages, the criminals often register domain names that can easily be confused for legitimate ones.

That is also a good way to spot who the potential victims are, and according to a new report from Google’s Threat Intelligence Group (TGIT) team, these are some of the biggest names in the finance industry: Blackstone, KKR & Co, Apollo Global Management Inc, and CME Group Inc.

Apart from these names, a few law firms were also spotted, including Paul Hastings LLP and Greenberg Traurig LLP. However, none of these confirmed having been breached, and Greenberg Traurig told Reuters they were never targeted in the first place.

The group seems to be making quite the progress. In April and May, they registered a new phishing domain every 2.2 days, rising to every 1.6 days for June and July. It’s paying off, too.

In the 18 cryptocurrency wallets Google associates with the group and tracks, around $10.7 million was received between January and mid-May 2026.

This 'classic' decades-old SQL injection flaw could let hackers take over entire Windows servers, thanks to a nifty database trick

  • Huntress saw Oracle SQLi used to deploy rare khunt toolkit
  • Khunt enabled OS commands, credential theft, and registry hive exfiltration
  • Defense includes input sanitation and more

Someone managed to pair the classic SQL Injection (SQLi) attack with a nifty database trick to take over the underlying system entirely.

Security researchers Huntress, who were called in to investigate the incident, said the investigation first showed a classic, decades-old technique called an SQL injection attack: a public-facing application with an Oracle backend accepted and executed SQL commands input into a form without checking whether that input was valid or not.

This granted the attackers the ability to upload a database-resident, posts-exploitation toolkit named khunt. This technique is something of a cyber-white whale: it’s been widely discussed but rarely seen in the wild.

How to defend

“What happened next, however, raised our eyebrows,” Huntress said. “After performing SQL injection, the threat actor managed to upload a database-resident, post-exploitation toolkit named khunt. This is a technique that's previously been discussed and described over the years, including via a technique described as oraexec – however, the use of the technique in the wild has rarely been documented.”

As a toolkit, khunt granted the attackers multiple capabilities, including loading cmd.exe on the system and running arbitrary OS commands, steal usernames and passwords, listing, reading, searching, and checking file sizes (essentially looking around the compromised system), unzipping files, and more.

Of all the things they could have done, the attackers opted to run a PowerShell command and invoke the Windows Registry tool, copying the SAM, SECURITY and SYSTEM registry hives. They can later use the copies to extract and decode password hashes for local accounts on the system, the researchers explained.

To defend against such attacks, Huntress recommends making sure the forms aren’t injectable. “Practice proper input sanitization and query parameterization for any inputs,” they warned. “It's also important to ensure that users with the ability to execute queries aren't overprovisioned.”

Even if someone manages to pull off SQL injection, user accounts should not be capable of authoring Java sources or running stored procedures.

Another top router maker accused of firmware having backdoors — Chinese giant Zbtlink halts downloads to fix issue

  • VulnCheck CTO Jacob Baines reported Zbtlink routers shipped with a built‑in backdoor dubbed ENDLESSDOORS, allowing remote root commands and reverse shells
  • Zbtlink denied malicious intent, calling it an after‑sales maintenance feature, but quietly pulled vulnerable firmware and promised patches
  • Researchers warn all firmware images are hijackable; mitigation advice is to replace devices or enforce strict egress controls and treat LAN as untrusted

Chinese networking firm Zbtlink has been accused of shipping its products with a backdoor - and while the company denies the allegations, it has still apparently moved to address the issue.

CTO of cybersecurity company VulnCheck, Jacob Baines, recently published an in-depth report stating a Zbtlink device he runs “continuously attempts to reach a command-and-control server on the internet.”

“Zbtlink routers phone home, waiting for orders. Not because they were hacked. Because they were shipped that way.”

Detention and escape attempts

Baines dubbed the flaw “ENDLESSDOORS” and says it was uploaded to GitHub in early 2015 and “never touched again”. “It can send the client individual shell commands or tell the client to spawn a reverse bash shell.”

“The vocabulary of this protocol is two phrases: run this as root, and give me a root shell,” he further explained, saying that anyone along the path can hijack the client/server communication. VulnCheck researchers tried it, and apparently - succeeded.

Baines said that every firmware on the company’s download page (roughly two dozen images) is all “hijackable in the same way”, and said the company decided not to “responsibly disclose” the vulnerability since that assumes the vendor did not intend the behavior. "That assumption doesn't hold here."

In response to the allegations, Zbtlink told The Register VulnCheck mischaracterized the code.

“This feature is solely intended for after‑sales maintenance and serves no other purposes,” the company told the publication. “It is generally retained only on sample units to assist customers with software debugging and will not be included in mass‑production shipments.”

The Register didn’t see it as a credible explanation since, in the meantime, the company posted a warning on its downloads page:

“We have detected firmware security vulnerabilities affecting selected router firmware releases. As a precautionary measure, the impacted firmware versions have been temporarily taken down from download channels. Our engineering team is working intensively to develop and validate secured patched firmware.” This warning was allegedly posted sometime in the past seven days.

Baines gave a list of suggestions how to mitigate the risk but ended up saying that “for anything carrying real traffic, our advice is to replace the device, or at minimum move it behind strict egress control and treat its LAN as untrusted.”

Google Blogger locks out thousands of users after malware false positive

  • Google’s automated systems mistakenly flagged hundreds of Blogger sites as malicious
  • Company admitted a bug caused false malware labels, promising a fix
  • Users advised to request reviews, avoid migrating content

Hundreds of Blogger websites were locked down, and some apparently deleted as well, after Google’s automated security systems erroneously flagged them as malicious.

A user posted a new message on Google’s forum saying the huge number of reports regarding locked blogs are all for the same reason - Malware and Similar Malicious Content.

The nature of the lockdown “suggests misclassification by automated systems”, the post reads, adding that the team has “already been notified of this issue.”

Aware of a bug""

Those affected will see a red padlock in their dashboard and a warning saying the blog was locked:

"This blog was removed for violating Blogger's Community Guidelines. If you wish to request a review of the blog, click 'Request Review' below," the notice reads.

At press time, the forum post had more than 500 “I have the same question” votes, and more than 200 replies.

In a statement given to BleepingComputer, Google said it was aware of a bug that falsely labeled many sites as malicious, and that it was working on a fix.

"We are aware of a bug that incorrectly flagged some Blogger-hosted sites as malware for less than a day. We are working on a fix to resolve the issue as quickly as possible," the company said.

To make matters even worse, Google said that if users don’t file an appeal, that their blogs can be permanently deleted.

Users are advised not to create new blogs and migrate content, since that is in violation with Google’s TOS. They are also advised against deleting their Blogger profile or service from their Google account, since this will irrevocably delete the blogs. They can, however, back up their blogs if they are afraid of losing the content.

The full extent of the issue is unknown, but according to BleepingComputer, the number of users on the platform exceeds 200,000.

OpenAI says it stopped an Asian scam campaign hijacking ChatGPT to lure in victims

  • OpenAI disrupted a major scam campaign in Cambodia’s Poipet, banning accounts and blocking new registrations
  • Criminals used ChatGPT to run romance fraud, fake investments, bogus police scams, and even operations linked to human trafficking
  • AI was leveraged for fake personas, fraudulent messages, job lures, and worker administration; OpenAI shared findings with authorities after evidence of hundreds of victims losing thousands of dollars

OpenAI said it disrupted a major scam campaign coming out of Southeast Asia by banning accounts used by the operation and making it difficult to open new ones.

In a blog post, the ChatGPT maker said it was tipped off about the existence of the campaign by WhatsApp.

After investigating further, the company found that a group of criminals in Cambodia used its AI tool in different scam campaigns - romance fraud, fake investment scams, or bogus police investigations. It also used AI to help with day-to-day operations and, most worryingly, for things that could be related to human trafficking and forced criminality.

Detention and escape attempts

OpenAI did not say if the group had a name, just that it operated out of Poipet, “a city in Banteay Meanchey province that public reporting⁠ has repeatedly⁠ linked⁠ to online scam compounds and trafficking operations.”

The group used AI to create fake personas, to help draft fraudulent emails and chat messages, and to create posters for fake jobs which were probably used to lure people into human trafficking or forced labor.

The tool was also used for worker administration, since the operators maintained records of employee debts, salary deductions, disciplinary fines, and loan repayments. They also used the tool to translate discussions about immigration status, work permits, visa overstays, and recruitment incentives.

“Some conversations also referenced apparent detention, escape attempts, and potential criminal liability for people who had been trafficked and forced to work in scam operations,” OpenAI said. “While these conversations do not allow us to determine the circumstances of any particular individual, they are consistent with extensive public reporting⁠ describing⁠ the activities of organized crime groups in Southeast Asia.”

The company could not say how many people fell victim, or how much money this group has stolen, but said it found evidence of “hundreds” of victims losing “thousands of dollars.” These findings were shared with relevant authorities.

Via The Hacker News

FBI agent accused of stealing $1 million in crypto — and he even consulted ChatGPT on how to leave the country

  • A former FBI counterintelligence supervisor is accused of memorizing seed phrases from bureau systems
  • The agent moved roughly $1 million out of wallets tied to a foreign adversary without having to resort to any sort of hacking
  • Investigators recovered ChatGPT conversations in which he asked how to invest the money and how to gain EU residency, and the chatbot's replies recited his age, wife, child, and property plans back to him

Patrick Steven Yaroch, a supervisory special agent in the FBI's Counterintelligence and Espionage Division, has been arrested and charged with interstate transportation and receipt of stolen goods.

An affidavit filed in the Eastern District of Virginia, claims Yaroch took roughly a million dollars in cryptocurrency from wallets he encountered while investigating a foreign adversary and then used ChatGPT to determine what to do with it.

The theft, as described, required no technical sophistication whatsoever: Yaroch held a Top Secret clearance with SCI access and had spent 2017 to 2025 on a national security squad at the FBI's Boston division working against a single adversarial nation, which NBC News reports was Russia.

An atypical heist with the alleged mastermind acting out of "frustration"

Patrick Steven Yaroch encountered the cryptocurrency wallets tied to his work in November 2024. He had researched how wallets work, created one of his own, searched the FBI's holdings for the relevant account information, and memorized the recovery seed phrases.

He then made roughly 10-12 transfers to his own wallet. No encryption was broken, and no protocol was exploited because none was in place for a man with his security clearance; he simply read a phrase off an internal system and remembered it.

The incident is particularly interesting because he self-reported, effectively turning himself in to his colleagues: on July 28 2026, he contacted a Justice Department employee he had worked with in Boston over Signal, asking to meet. They met at FBI headquarters the next day, where Yaroch reportedly began breaking down almost immediately, and the conversation moved to the other man's office.

He said the situation was "eating him up inside" and that he wanted to give all the money back. He filed an online self-report to the FBI's Security Division and told headquarters personnel he had screwed up. When agents arrived at his Ashburn home that evening, he told them, unprompted and in blunter terms, that he had messed up.

His defense, as per the affidavit, however, is slightly different from what one would expect: His stated motive was not greed. He told his colleagues he had grown frustrated that the FBI could not or would not act against those accounts, described himself as "spinning out of control" at the time, and said he decided to take matters into his own hands.

Despite this, he seemingly had a change of heart after cooperating earlier, asking for a paper containing his wallet seed phrases, which he had volunteered to agents, while declining to continue the interview without a lawyer while asking for time over the next two days.

This culminated in agents obtaining warrants, executing them on July 31 with SWAT securing the house, and recovering an iPhone, a Trezor hardware wallet, the handwritten seed phrases, a Portuguese power of attorney dated June 15, and three passports, one of them diplomatic.

Man annoyed at laptop

(Image credit: Marjan Apostolovic / Shutterstock)

Ironically, the most potentially damning evidence of his intentions comes from his conversations with AI, still on his phone and directly linked to him.

His conversations with ChatGPT convey a very different thought process: On May 28, he asked how to invest or spend a million dollars to maximize profit and return. On June 4, he asked what someone with about a million dollars should do to leave the United States and become a resident or citizen of an EU country. On June 17 he asked whether an American connecting through Turkey needs a visa. On June 26 he asked for help drafting an email to an executive about a job opening and life in Greece.

There is more evidence that he might already have acted based on the answers he received: prosecutors have found a power of attorney authorizing two Portuguese lawyers to register him with the country's tax authority and obtain a Portuguese tax identification number, and unreported foreign travel to Germany in May, Portugal later that month, and Grenada in early July, all in breach of bureau reporting rules.

His current investments seem to be equally erratically reasoned: On July 23, five days before he first confessed, Yaroch moved roughly $1.02 million into Suilend, a lending protocol on the Sui blockchain, reaching it through the Slush wallet app, which he then deleted. He parked the funds there to earn interest. When asked why he chose that service, he said he liked its logo, a water droplet.

When agents looked, the position was worth $933,756, roughly 8% below its level a week earlier. His Kraken account held another $188,570, including about $5,000 in a token called Squid and $1.67 in Bitcoin. Agents ultimately swept $925,426 into government wallets, leaving about $165,582 behind because it was dollars and could not be moved to a crypto wallet.

Yaroch is charged under sections 2314 and 2315 of the federal criminal code, the general provisions on transporting and receiving stolen goods. He is not charged with espionage, with computer fraud, or with theft of government property.

The wallets were not the government's, and that might change how they are treated legally, even as it raises important questions about the security protocols at federal agencies regarding cryptocurrencies, since they both monitor and have seized increasingly large amounts of them over the past few years.

In Yaroch's case, if the allegations hold, government protocols failed to identify the theft for nearly eighteen months before the person responsible reported himself, making the case for a potential review by federal agencies about how they handle such matters.

Hackers use fake Adobe and Zoom updates to load malware onto victim devices — here's what to look out for

  • Securonix uncovers SMOKE#SCREEN, a campaign tricking users into installing weaponized ScreenConnect via fake Zoom/Adobe updates and business docs
  • Attackers gain persistent remote access, evolving tactics to disable protections and abuse trusted services like Dropbox/Cloudflare for delivery
  • Victims observed on Windows and macOS; businesses urged to verify updates via official sites and train staff against unexpected installs

Security experts Securonix Threat Research have uncovered a new malicious campaign that tricks users into installing legitimate remote monitoring and management (RMM) software.

Dubbed SMOKE#SCREEN, the campaign uses fake Zoom and Adobe update messages, as well as a whole swathe of fraudulent business-related documents (document review requests, system maintenance tools, invoices, and similar), to convince the victims to run malicious files.

Victims who don’t see through the ruse and run the files end up installing ConnectWise ScreenConnect, a legitimate RMM tool that many IT teams use to provide technical support to their coworkers and clients. However, it is also one of the more abused solutions in the criminal cyber-underworld, since it can often fly under the radar of security products.

Dangerous evolution

After installation, attackers can remotely access compromised devices, potentially allowing them to steal data, install additional threats, or move deeper into an organization’s network.

At first glance, SMOKE#SCREEN looks like a fairly standard “phishing - install legitimate RMM - remote access” campaign. However, what makes it unique is how it evolved over time, Securonix explained. Earlier versions focused on hiding the malicious activity, while newer versions attempted to disable security protections and avoid detection by security software. The attackers also used trusted services such as Dropbox and Cloudflare to deliver their files, making the activity harder to block.

Victims were observed on both Windows and macOS ecosystems, it was added.

“The SMOKE#SCREEN campaign demonstrates a capable, actively maintained, and rapidly adapting threat actor who has built a diversified toolkit around a single objective: gaining persistent, legitimate-looking remote access to victim systems through weaponized ScreenConnect deployments,” the researchers explained.

“The use of multiple social engineering themes, rotating payload hashes, cross-platform coverage, and a live staging server that doubles as a ScreenConnect relay indicates a well-resourced actor with deliberate operational security practices.”

To minimize the risk of compromise, businesses should disable receiving software updates delivered through emails, verify update requests through official websites, and instruct their employees to be cautious when opening attachments or installing tools they were not expecting.

Via The Hacker News

Experts flag Bank of America phishing scam that hands your device over to hackers

  • Huntress flags phishing emails spoofing Bank of America, pushing victims into different infection chains on Windows vs. macOS
  • Windows users were tricked into installing ScreenConnect RMM via fake “Account Guard,” while macOS users faced credential‑harvesting forms for identity theft
  • Emails mimicked Bank of America branding but came from unrelated domains; users advised to verify sender addresses to spot scams

Bank of America customers have been warned to take extra caution after experts warned of hackers spoofing the bank into trick you into downloading unwanted software and granting them access to your computer.

Security researchers Huntress revealed how it received a phishing email in their honeypot (an address set up primarily to catch scammers) claiming to have come from Bank of America.

Obviously, the message came from a domain completely unrelated to the company, but looked almost identical to the real thing, with the company logos, color schemes, and other details, meticulously imitated.

Just another ScreenConnect scam

In the email, the researchers were warned that their account was about to be “restricted” unless they “confirmed” certain information.

Depending on the platform from which the victim views the email, both the infection chain and the end goal are different. For Windows users, victims are invited to install “Account Guard”, which is described as a “powerful tool designed to protect your financial data, prevent unauthorized transactions, and other cyber threats”.

This is no guard - this is a Visual Basic script that leads to an installation of the ScreenConnect Remote Monitoring and Management (RMM) tool. ScreenConnect is not malicious itself - it is a legitimate tool - but it is also one of the most abused software out there, leveraged to grant attackers unabated access to victim computers without triggering any alarms.

For macOS users, on the other hand, the goal is different. Instead of trying to deploy malware, the attackers try to steal sensitive data. First, the victims are asked to log in to their banking account (twice - the first attempt is scripted to fail, in case the victim purposely submits the wrong password the first time).

Then, once they “log in”, the second web page asks the victims to “confirm” their details - full name, mailing address, government ID details, Social Security number (SSN), and the payment card details. This is more than enough information for an identity theft attack, or even wire fraud.

Huntress is now warning all Bank of America users to double-check the sender address for any email claiming to be from the bank, since that is the best way to know if the email is legitimate, or a scam.

TP-Link router owners update now — 15 flaws patched to stop hackers hijacking your devices

  • Forescout’s Vedere Labs found 15 flaws in TP‑Link Omada business networking gear, exploitable for RCE when chained with prior CVEs
  • Weak trust shortcuts in zero‑touch provisioning exposed devices to client‑side code execution, hijacking, spoofing, and encrypted comms compromise
  • TP‑Link released firmware updates; admins should patch immediately, with 1,800+ Omada controllers exposed online

TP-Link has patched more than a dozen vulnerabilities across multiple business networking products which could have been chained to achieve remote code execution (RCE).

Security researchers at Vedere Labs from Forescout found the flaws and published an in-depth report on the issues, which particularly affect TP-Link Omada, the company’s business networking platform for centrally managing enterprise and small-business network infrastructure.

It includes cloud-managed Wi-Fi access points, routers, switches, gateways, and controllers, all of which can be monitored and configured from a single interface.

Enabling "concrete attacks"

These support zero-touch provisioning (ZTP), a mechanism that allows IT managers to deploy and maintain devices without needing to configure each one manually and on site.

However, ZTP has to establish trust between a factory-fresh device, and a controller with no human involved, so TP-Link used different shortcuts: from hard-coded keys and certificates shared across multiple devices, to default credentials, and from guessable serial numbers as “identity”, to weak session-key randomness.

Now, Forescout says 15 vulnerabilities its researchers discovered all allow for different ways of exploiting these shortcuts, meaning a flaw anywhere in the onboarding chain can compromise every device that goes through it. These bugs would need to be combined with two previously disclosed command-injection flaws, though.

“The vulnerabilities fall into four impact categories: client-side code execution, information disclosure, device hijacking and spoofing, and compromise of encrypted communications,” Forescout said. “Combined with two previously disclosed CVEs (CVE-2025-7850 and CVE-2025-7851), these flaws enable concrete attacks that let attackers infiltrate networks through controllers and client devices.”

Out of the 15 discovered flaws, 11 received CVE identifiers, and the rest did not receive a tracking number.

Forescout said there are more than 1,800 Omada controllers accessible from the wider internet. If you are using any of the devices from the platform, you should head over to TP-Link’s download portal and grab the latest firmware for your device model.

Microsoft 365 users hit by phishing scheme posing as RingCentral emails

  • ZeroBEC observes Greatness PhaaS evolving to bypass MFA and phish Microsoft 365, iCloud, Yahoo, and Google Workspace accounts
  • Attackers spoofed RingCentral emails post‑ShinyHunters breach, luring victims to fake Microsoft 365 logins that capture authentication tokens
  • Greatness is sold on Telegram for $289/month, enabling access to Outlook, Teams, SharePoint, OneDrive, and more across multiple regions

Microsoft 365 users have been getting phishing emails spoofing RingCentral, designed to steal their accounts even if they were protected by multi-factor authentication (MFA), experts have warned.

Security researchers ZeroBEC claim to have observed a phishing-as-a-service (PhaaS) platform called Greatness evolve to also target MFA accounts, as well.

Greatness used to be a simple credential phishing platform. However, in recent times, it evolved to target not just Microsoft 365 accounts, but also those of iCloud, Yahoo, and Google Workspace.

Grabbing MFA-approved authentication tokens

ZeroBEC notes that RingCentral recently suffered a data breach at the hands of the infamous ShinyHunters hackers, meaning there is a good chance (although not confirmed) that the threat actors exfiltrated a list of emails belonging to RingCentral customers from that attack, and used it in this attack.

Now, RingCentral customers have been getting emails that look as if they are coming from the company itself, despite being mailed from an unknown mail server, and despite failing SPF and DMARC checks. The emails are the standard fake voicemail and performance-review notifications which, if clicked, redirect the victim to attacker-owned infrastructure spoofing the Microsoft 365 login page.

Through this malicious landing page, Greatness operators are able to capture MFA-approved authentication tokens, bypassing the login process entirely and moving straight into victim accounts.

From there, they would enumerate Outlook mailboxes, Teams conversations, and SharePoint sites. They would also access OneDrive files, contacts, calendars, and registered applications through Microsoft Graph.

The number of victims is unknown at the time, but ZeroBEC says Greatness has been active for at least four years now, targeting users in the US, UK, Australia, Canada, and South Africa.

According to BleepingComputer, the platform is being advertised for sale on Telegram channels with “thousands of subscribers”, and is currently being offered for a monthly fee of $289.

Via BleepingComputer

New ChainDrop worm poisons over 1,300 npm packages, Keyv and Cacheable among those hit

  • Aikido researchers uncovers ChainDrop, a Shai‑Hulud variant infecting 1,300+ npm packages with an infostealer
  • Attackers compromised GitHub accounts tied to popular libraries (Keyv, Cacheable, flat‑cache, file‑entry‑cache) and pushed tainted releases with 2B monthly downloads
  • Malware exfiltrates developer/cloud credentials and secrets to a public GitHub repo; admins should treat affected systems as compromised even after removal

Another Shai-Hulud variant has been discovered in the wild, infecting more than 1,300 npm packages with an infostealer.

Security researchers Aikido reported finding “at least 868 packages (across 1381 versions) that have been compromised by the worm.”

Shai-Hulud is a self-propagating supply chain malware that targets software developers by compromising open-source packages and CI/CD pipelines. It steals credentials, API keys, and access tokens and then uses those stolen secrets to publish additional malicious packages.

What to do in case of an infection

In May 2026, actors claiming to be associated with the TeamPCP group publicly released the Shai-Hulud worm's source code, saying they were “open sourcing the carnage” and inviting other threat actors to adopt and modify the code. Since then, there were multiple copycat campaigns and variants, including this one which Aikido dubbed ‘ChainDrop’.

Aikido said the attackers compromised the GitHub account of the person maintaining Keyv and Cacheable, widely used open source JavaScript libraries for caching data in Node.js applications. From there, they were able to move into other popular utilities such as flat-cache and file-entry-cache, as well as packages associated with organizations such as Deliveroo, Ornikar, OneReach, Picsart, Qlik, and ServiceTitan.

The malware was pushed directly into the projects’ main branches, and then generated additional package releases. The compromised packages have a combined 2 billion monthly downloads.

Aikido says the infostealer grabs developer and cloud credentials, encrypts them, and then sends them to a public GitHub repository called “Shai-Hulud: Here We Go Again.”

It also steals local configuration files, GitHub PATs, workflow tokens, and other ghp_, gho_, and ghs_ tokens, certain npm tokens, GitHub Actions secrets, AWS credentials, Kubernetes secrets, and more.

The researchers are saying system admins who installed a tainted package should treat their developer workstation or CI/CD runner as compromised, even if they removed the package.

❌
❌