Normal view

There are new articles available, click to refresh the page.
Today — 11 August 2026Main stream

Top US defense device maker IEH Corporation admits hackers broke into its systems

  • Attackers stole IEH employee credentials via a fake Microsoft login page
  • Inbox access exposed sensitive defense‑related communications and technical documentation
  • Malicious mailbox rules were removed as IEH contained the unauthorized access

Criminals have broken into the email inboxes of IEH Corporation, a significant supplier for the US military and companies in the commercial aerospace and space industry.

In an 8-K report filed with the US Securities and Exchange Commission (SEC), IEH said that unidentified threat actors reached out to one of its employees, pretending to be a “prospective business contact”.

The atatckers shared a link to what appeared to be a Microsoft document, prompting the victim to log in. Obviously, the login page was bogus, and the login credentials were relayed to the attackers instead.

Malicious mailbox rules

“The threat actor gained access to mailbox contents, including email messages, attachments, customer communications, purchase orders, engineering-related documentation, and potentially export-controlled technical information,” the 8-K reads.

The culprits, however, were not named and no threat actors have yet claimed responsibility for the attack.

IEH said it found no evidence that data had been exfiltrated from the compromised inbox. However, its defenders did discover and remove “malicious mailbox rules”. Usually, crooks set up such rules to automatically forward incoming emails to an inbox under their control, while deleting traces of the activity. This would allow them to continue receiving sensitive emails even after the initial compromise was remediated.

The company also said it completed a full audit of the inbox and done “corrective actions to contain any impact of the unauthorized access.”

IEH Corporation produces “specialized products used in military satellites, missiles and fighter jets,” meaning the information found in the inbox could be quite valuable, especially for nation-states such as Russia, China, North Korea, or Iran.

IEH does not publicly name its clients but it does say that its defense applications include Apache AH-64, V-280 Valor and SH-60 Seahawk programs, as well as Patriot, THAAD, AMRAAM and APKWS missile programs. It reported a revenue of almost $30 million for the 2026 fiscal year.

Via The Record

US healthcare software giant Unlimited Technology Systems admits hackers may have stolen sensitive data of 3.8 million people

  • Attackers stole extensive personal and medical data from 3.8 million individuals from Unlimited Technology Systems
  • Breach source and methods remain unknown, with no group claiming responsibility
  • Stolen data poses major fraud risks, prompting free identity monitoring from Kroll

US healthcare organization Unlimited Technology Systems has revealed it suffered a cyberattack in which it lost a treasure trove of sensitive information belonging to millions of people.

The company recently made the information public and shared details with the US Department of Health and Human Services, noting that someone broke in on October 5, 2025 and within five days exfiltrated valuable data belonging to just over 3.8 million people.

The attacker stole people’s full names, Social Security numbers (SSN), dates of birth, emails and mailing addresses, phone numbers, demographic information, scans of driver’s licenses and other government IDs, insurance cards, intake forms, health insurance policy numbers, claims and benefits information, medical record numbers, dates of service, and diagnosis data.

Supply chain woes

The company did not say who the threat actors were, or if they demanded any ransom in exchange for deleting the data.

No hackers have claimed responsibility just yet, and we also don’t know how they managed to break in, as different groups have different methods.

ShinyHunters, for example, prefer calling their victims on the phone, pretending to be IT support and convincing their victims to give them access via remote management tools. Other groups might try to exploit vulnerabilities in routers, firewalls, and other hardware.

Whoever it was, they have a valuable data set in their possession. This kind of information can be sold on the black market or used in identity theft and wire fraud. To mitigate these risks, Unlimited Technology Systems is offering free identity monitoring services to affected individuals through Kroll.

Unlimited Technology Systems is a software company that provides financial technology for healthcare organizations. It works with around 4,500 clinics and 6,500 specialty healthcare providers in the US, processing north of $70 billion in net healthcare charges every year.

According to BleepingComputer, the company processes information on behalf of its clients, which means that the victims of this attack have no direct relationship with Unlimited and have probably not even heard of it.

Samsung patches nearly 200 security issues on its phone hardware - here's what you need to know

  • Oversecured found 176 vulnerabilities across Samsung’s preinstalled mobile apps
  • Flaws enabled account takeover, code execution, and traffic hijacking via bloatware
  • Samsung patched all reported issues, affecting hundreds of millions of devices

Security researchers from Oversecured have given “bloatware” an entirely new meaning, revealing that they uncovered 176 vulnerabilities - including some rather worrying ones - in Samsung’s mobile apps.

For the last three years, the team analyzed Samsung’s preinstalled system applications and found vulnerabilities that could cause some serious harm. Some of the bugs granted camera and microphone access, while others allowed for remote Samsung Account takeover with nothing more than a single click.

Some flaws allowed for network traffic hijacking via DNS manipulation, and others granted arbitrary code execution via an image. In theory, a malicious actor could craft and send a JPEG image which, when the victim opens, copies and loads attacker-controlled native libraries from the SD card. Finally, Oversecured found path traversal vulnerabilities allowing writing arbitrary files to the file system without proper path validation.

Arbitrary code execution

The researchers disclosed their findings to Samsung which, according to their report, fixed all of the reported issues - the full list can be found on GitHub.

Most Android smartphone manufacturers preload their devices with proprietary apps - think Bixby, Samsung Free, or AR Zone. These apps - which cannot be uninstalled or removed from the devices - aren’t necessary to their operations and are often not wanted by the users in the first place.

This 'bloatware' is also one of the key selling propositions of Google Pixel devices, since these are considered “stock Android”, or bloatware-free.

Out of context, these bugs are nothing extraordinary. Single-click account takeover flaws and traffic hijacking bugs pop up every now and then and get fixed rather quickly. The context here is that these are Samsung’s proprietary apps that don’t fall under the protection of Google’s Play Protect. Users might think they’re safe because they’ve not downloaded apps from risky places, or enabled dangerous permissions, when in reality, they’re not safe at all:

“Preinstalled system applications run with extra privileges than normal apps, cannot be removed by users, and operate outside Google Play Protect,” the researchers warned. “A single vulnerability affects hundreds of millions of devices globally through one vendor's distribution channel.”

Levi's reveals security tear may have let hackers steal important corporate data

  • Attackers used social engineering to access Levi’s network and steal corporate data
  • Details on stolen information, methods, and perpetrators remain largely undisclosed
  • Voice‑phishing extortion groups are suspected, though no one has claimed responsibility

Levi Strauss has revealed it recently suffered a cyberattack and lost corporate files - however some crucial details around the incident are missing.

The company filed a new report with the US Securities and Exchange Commission (SEC), noting how hackers accessed its infrastructure through “social engineering” against three of its employees. We don’t know if that was via email, voice phishing, or some other technique.

After breaching the network, the crooks - who weren’t identified - “accessed and exfiltrated certain corporate information”. Again, we don’t know which information was accessed, or how much of it.

Was it UNC6671?

In response, Levi’s said it had “initiated response protocols, implemented containment measures, and launched an investigation” which remains ongoing. Again, we don’t know what these measures are, or how the crooks were ousted.

The company says the incident did not disrupt its business operations, or caused interruptions, in any way, and that it does not expect it to have any material impact whatsoever.

While Levi’s did not name the perpetrators, and while none have yet claimed responsibility on the dark web, some publications have hinted at UNC6671, a “financially motivated threat cluster that conducts data-theft extortion attacks through voice phishing”. The tactic seems to have been “borrowed” from ShinyHunters, arguably one of the largest data extortionists out there.

The group would call their targets on the phone (usually low-level employees with access to company SaaS solutions) and, while pretending to be from the IT department, convince the victims to either grant remote access, or to visit a malicious credential-grabbing landing page.

From there, the attackers would move in, map the infrastructure, exfiltrate valuable data, and then demand payment in cryptocurrency in exchange for deleting the data.

We have reached out to Levi’s with further questions and will update the article if we get an answer.

Via BleepingComputer

Experts warn North Korean hackers are increasingly using AI to build smarter and more devious cyberattacks

  • Kimsuky used local AI tools to evade monitoring and enhance operations
  • Researchers observed extensive AI-driven capability building across the group’s infrastructure
  • Defenders urged behavior-based detection to spot evolving AI-enabled threats

North Korean hackers have found a way to use Generative Artificial Intelligence (GenAI) to supercharge their activities without tipping off the tool’s maintainers.

When people use AI tools like ChatGPT or Claude, their activities can be (at least to some extent) tracked and curbed - with OpenAI recently identifying and terminating multiple ChatGPT accounts used in phishing and human trafficking.

That is why Kimsuky - a known state-sponsored North Korean threat actor, used Ollama, GPT4All and Msty locally, allowing them to process documents without sending any sensitive information to outside AI services.

"Consistent process of capability development"

The attacks were spotted by security researchers Genians who “conducted months of tracking and log analysis on the infrastructure utilized as C2 in this campaign,” to identify the tools they used.

Aside from the three LLMs, they also used retrieval augmented generation (RAG) tools for document search, as well as AI agent development frameworks, text-to-speech software, and an AI-assisted coding tool called Cursor.

Using AI to write malicious code is not as simple as it sounds, due to various guardrails set up by the developers. As a result, AI in crime has been mostly limited to drafting phishing emails and crafting authentic-looking but malicious landing pages. However, Kimsuky has shown that AI in cybercrime continues to evolve and is becoming an ever-greater threat.

“What was observed in the threat actor's infrastructure was not merely evidence of several documents being created with AI, but a consistent process of capability development: establishing local LLM runtime environments, configuring RAG based on documents in the actor's possession, collecting AI agent development frameworks, and acquiring libraries for integration with external commercial AI services,” Genians concluded.

As a result, defenders must move from content-based assessment to behavior-based detection, the researchers warned, saying this should serve “as the fundamental premise of security recommendations.”

“In addition to indicator of compromise (IoC)-based detection, organizations should contextually correlate the sequence of anomalous activities following LNK execution, including PowerShell execution, persistence establishment, and external communications, to assess the overall threat level.”

Before yesterdayMain stream

Why are so many AI models going 'rogue'? The experts weigh in

Over the past month, it seems like every frontier model has broken free of its constraints and launched a devastating attack against one or more other companies.

One of OpenAI’s models escaped a testing sandbox and launched a very real attack against AI and machine learning company Hugging Face. Just days later, Anthropic revealed that multiple variants of its Claude model also escaped a sandbox that wasn’t properly sealed and began attacking the enterprise infrastructure of three companies.

Now, Meta has revealed that one of its models attacked another company’s infrastructure during testing. The accident has been pinned on a misconfiguration that allowed the model to access the internet. So why have so many incidents happened in such a short space of time?

Why are models escaping their sandbox?

In the cases of Anthropic and Meta, their models were being tested by a third party company called Irregular. Anthropic’s AI model was taking part in a "Capture the Flag" exercise, where the model’s raw offensive capabilities were tested without the usual safeguards. But the sandbox was left connected to the internet. A similar error to Meta’s own accidental escape.

During the OpenAI incident, the company was testing two versions of GPT‑5.6 Sol using the ExploitGym benchmark. Unfortunately, the AI models performed better than expected - chaining multiple attack vectors, stolen credentials, and zero-day vulnerabilities.

The main reason these models are escaping their testing environments is because they are designed to do exactly that. These AI models act like a massive team of highly-trained cybersecurity experts hunting for vulnerabilities and exploits. But what would take a team of humans days or weeks to accomplish can be done in hours, or even minutes, by these AI models.

It’s no wonder thousands of employees from AI firms are calling for a pause on the development of the technology, and Congress is considering an AI kill switch.

Expert perspectives on AI escapes:

OpenAI

  • Nathaniel Jones VP, Security & AI Strategy, Darktrace:

What makes the OpenAI and Hugging Face incident important is that the models did not need malicious intent to cause harm. They were given the legitimate goal of solving a cybersecurity benchmark and found an unexpected route to the answers, escaping their test environment and compromising another organization in the process. From the models’ perspective, this appears to have been an effective solution to the task.

The AI's actions challenge the assumption that giving an agent a legitimate goal will produce legitimate behavior. As models become capable of pursuing objectives over longer periods, developers need to define not only what success looks like, but also which methods and boundaries remain unacceptable in reaching it. Those limits must also be enforced by the surrounding infrastructure, rather than relying on the model to respect them.

A single action by an agent may appear acceptable but as this incident shows, models are now capable of long, complex chains of reasoning and action that add up to a harmful outcome.

Security teams need to consider the AI systems operating in their own businesses as these capabilities rapidly evolve. Right now, many security systems focus on single actions. A single action by an agent may appear acceptable but as this incident shows, models are now capable of long, complex chains of reasoning and action that add up to a harmful outcome. Teams need a mindset shift to understanding AI agent behavior in its entirety, including the outcome it is working towards, in order to safeguard it.

Hugging Face's response also exposed a second tension. The company reportedly needed a Chinese-developed open-weight model because commercial models would not process genuine attack material. Its nationality is less important than the operational lesson that safeguards that cannot distinguish an attacker from an authorized investigator may constrain defenders more than adversaries.

OpenAI and Hugging Face deserve credit for investigating this together and discussing it publicly. Other AI developers should study it closely.

Anthropic

  • Dr. Ilia Kolochenko, founder of global cybersecurity company ImmuniWeb:

This seems to be quite an unimpressive marketing move from Anthropic in response to the OpenAI / Hugging Face drama, which attracted a lot of attention from all over the world recently.

Operationally, it appears that due to the progressive deterioration of the quality of training data, new AI models are getting dumber. Cheating and breaking the law, instead of accomplishing specific tasks, is certainly not an indicator of intelligence. Given that organizations and companies of all sizes now vigorously undertake all possible measures to protect their data from being exploited for AI training purposes, AI companies face a huge shortage of the high-quality and current data they so desperately need. Ultimately, frontier models are trained on synthetic, low-quality or even malicious and poisoned data, undermining their so-called intelligence. The situation is unlikely to improve in the near future unless AI companies agree to pay a fair price for training data, but this will force most of them out of business.

Given that organizations and companies of all sizes now vigorously undertake all possible measures to protect their data from being exploited for AI training purposes, AI companies face a huge shortage of the high-quality and current data they so desperately need.

Contemporary AI agents and LLM models tasked with security testing can – and almost certainly will – go rogue when security controls or safeguards are insufficient. Powerful LLMs are unpredictable by design and thus virtually uncontrollable by humans. Therefore, using frontier AI models for security testing might be extremely costly from the legal viewpoint. Under the existing laws on both sides of the Atlantic, if an AI agent or any AI-powered app escapes its sandbox and causes damage to a third party, the operator of the AI model will likely be liable for all the damage caused. Excuses like “AI did it” do not currently exist in the eyes of the law, leaving AI vendors on the hook. Criminal prosecution, under a narrow set of circumstances, is also not excluded.

The same is true for the end-users of AI: even if your security testing tool is powered by a third-party AI model, your company will likely be fully liable if something goes wrong. You may then file a lawsuit against the AI vendor that you used, but here your chances to succeed in a court of law are tiny due to countless contractual disclaimers and limitations of liability that will likely be enforceable against you. Therefore, if you plan to use agentic AI for security testing – think twice and talk to your lawyers. Otherwise, you may start getting summons to court on a daily basis.

Meta

  • Alex Goller, Principal Solution Architect EMEA at Illumio:

The fact we've had similar situations happen three times now across the biggest AI players is simply ridiculous. We've seen guardrails intentionally loosened to test their limits – Meta's model didn't need to be clever to breach another company's systems.

The timing of conveniently finding the exact same problem either means it's a stunt or they weren't paying enough attention during testing. Either way, both answers are worrying.

If the model has internet access, it's a bit like leaving the door open and being surprised when the cat walks out. What is concerning is that the testing infrastructure meant to prove these models are safe failed on a basic control issue.

If the model has internet access, it's a bit like leaving the door open and being surprised when the cat walks out. What is concerning is that the testing infrastructure meant to prove these models are safe failed on a basic control issue.

Fundamental cybersecurity hygiene still matters, and a frontier AI model is only as secure as the environment it's operating in.

Organisations need visibility into what AI systems can access and how they interact with the wider environment, along with controls that contain the impact when an agent behaves unexpectedly. That means keeping a close eye on egress traffic, so it’s flagged immediately when an agent tries to open unexpected outbound communication patterns that are not required to achieve its original goal. In the best case this would have been contained proactively.

We need to define exactly what an AI agent is permitted to do, rather than relying only on instructions about what it shouldn't do.

Shock horror — AI-generated security patches fall short of actually solving all the problems they were meant to fix

  • Researchers tested AI-generated patches on six CVEs with poor success rates
  • Many fixes failed, altered behavior, or introduced new vulnerabilities
  • Guidance improved outcomes, leading to FLAWED evaluation harness release

When using Generative Artificial Intelligence (GenAI) to fix vulnerabilities, security professionals are most of the time just robbing Peter to pay Paul, experts have warned.

Researchers from 1Passwords Off-by-1 Labs analyzed fixes proposed by two frontier models - ChatGPT 5.5 at “medium” effort, and Claude Opus 4.8 at “high” effort.

As an experiment, the researchers took six recently disclosed CVEs and produced 6,080 patches using two frontier, cyber-capable reasoning models. The results were underwhelming to say the least - of all the proposed patches, just a quarter (26%) fully resolved the issue.

FLAWED work?

This obviously leaves plenty to be desired, as half (49.3%) of the patches failed to fix at least one existing exploit path. A fifth (20.1%) fixed the original issue but changed application behavior, while 2.3% introduced new security issues. Funny enough, 2.2% failed to fix the vulnerability while also introducing additional exploit paths, as well.

Even among the patches that might be considered (26% of clean ones and 20.1% of those that changed app behavior), more than a third were fragile and not entirely addressing the underlying problem.

The researchers created an acronym for automated LLM patches: FLAWED (Fix-Like Artifacts With Embedded Defects), and warned against letting AI work without human oversight: "The expected value of a fully LLM-generated, non-human-reviewed patch is a net-negative by a considerable margin."

Results drastically improved when the AI was given better context, the researchers further explained. Before working on any patch, human developers are usually given initial guidance. When AI is given proper guidance, its success rate rises to 65%. Incorrect guidance, on the other hand, drops the success rate down to 15.2%. The difference between humans and AI is that humans are better at catching misleading information and poor guidance.

This doesn’t mean developers will, or should, abandon AI. Worst case scenario is that developers will spend more time reviewing AI-generated fixes which could increase cognitive load and still end up being net negative. Therefore, the researchers released a patch evaluation harness called FLAWED, which organizations can now use to determine the effectiveness of their AI-generated fixes.

Via The Register

Experts warn malicious AI skills are hitting more victims than ever — with one family amassing 1.7 million downloads

  • Attackers cloned AI skills, later adding malicious code to steal credentials
  • Zenity Labs found millions of installs and dozens of dangerous skill variants
  • Vercel and Microsoft removed malicious skills, but manual removal is still required

AI skills, instructions that teach AI agents how to do certain tasks and thus extend their capabilities, are increasingly being used in supply chain attacks, researchers have found.

Security experts at Zenity Labs uncovered a credential-stealing campaign on skills.sh, a public registry (essentially an app store) for AI agent skills. In the registry, belonging to Vercel (a cloud platform for web applications), threat actors were cloning existing skills, creating typosquatted lookalikes which, at first, did nothing malicious.

However, after a little time had past, and the skills amassed a solid download count, the attackers introduced malicious code instructing the AI agents to, among other things, exfiltrate SSH keys, cloud credentials, Git and package manager tokens, Kubernetes and Docker configurations, database credentials, infrastructure-as-code credentials, environment files and service account files. The agents were then told to package the stolen information with host metadata and send it to the attackers.

Dozens of malicious skills

While Zenity Labs could not say exactly how many people fell victim to this attack, they did stress that a single skill family amassed more than 1.7 million aggregate installs (not unique users).

And that is just one skill family, in a sea of malicious skills. The researchers also said they found “dozens” of additional skills exhibiting either malicious or dangerous behavior. Almost a third (30%) of identified dangerous skills abused Claude Code and OpenClaw to drop malware to their targets, as well. Also, Zenity found “hundreds” of reserved and empty package names that were being kept for future attacks.

These findings show how quickly cybercriminals adapt, and how creative they can get when it comes to abusing new tech. In essence, this campaign is an AI spin on a software supply-chain attack, being similar in spirit to incidents where attackers compromise an existing trusted package or repository, and later push a malicious update.

Following responsible disclosure, Vercel and Microsoft removed the identified skills, but Zenity warns that those who installed them before won’t be safe until they remove them from their systems manually.

Top US hedge funds targeted by major vishing campaign — Blackstone, KKR and CME among those under fire

  • Google’s Threat Intelligence team links BlackFile (now Redact) to phishing and extortion attacks on major hedge funds and law firms
  • Group impersonates IT staff by phone, steering victims to spoofed login pages to steal SaaS credentials and tokens, then exfiltrates sensitive data
  • Targets include Blackstone, KKR, Apollo, CME Group, and firms like Paul Hastings; Google tracked $10.7 million flowing into 18 crypto wallets between January–May 2026

Some of the biggest US hedge funds and law firms have been targeted by a highly sophisticated data breach and extortion campaign, conducted by a group of criminals previously known as BlackFile, experts have warned.

BlackFile (or Redact, as the group is now calling itself) has a relatively simple modus operandi, also used by ShinyHunters - they call their targets on the phone (usually employees with access to SaaS systems), identify as IT staff, and direct victims to convincing, lookalike login pages designed to steal their credentials and authentication tokens.

Once they gain access to victims' accounts, the attackers access enterprise SaaS environments (for example, Microsoft 365 and Okta) and use automated tools to exfiltrate sensitive data. In the last step, they notify the victims and threaten to leak the data on the dark web unless a ransom is paid.

Stealing millions

Since a part of the process is to navigate the victims to spoofed login pages, the criminals often register domain names that can easily be confused for legitimate ones.

That is also a good way to spot who the potential victims are, and according to a new report from Google’s Threat Intelligence Group (TGIT) team, these are some of the biggest names in the finance industry: Blackstone, KKR & Co, Apollo Global Management Inc, and CME Group Inc.

Apart from these names, a few law firms were also spotted, including Paul Hastings LLP and Greenberg Traurig LLP. However, none of these confirmed having been breached, and Greenberg Traurig told Reuters they were never targeted in the first place.

The group seems to be making quite the progress. In April and May, they registered a new phishing domain every 2.2 days, rising to every 1.6 days for June and July. It’s paying off, too.

In the 18 cryptocurrency wallets Google associates with the group and tracks, around $10.7 million was received between January and mid-May 2026.

This 'classic' decades-old SQL injection flaw could let hackers take over entire Windows servers, thanks to a nifty database trick

  • Huntress saw Oracle SQLi used to deploy rare khunt toolkit
  • Khunt enabled OS commands, credential theft, and registry hive exfiltration
  • Defense includes input sanitation and more

Someone managed to pair the classic SQL Injection (SQLi) attack with a nifty database trick to take over the underlying system entirely.

Security researchers Huntress, who were called in to investigate the incident, said the investigation first showed a classic, decades-old technique called an SQL injection attack: a public-facing application with an Oracle backend accepted and executed SQL commands input into a form without checking whether that input was valid or not.

This granted the attackers the ability to upload a database-resident, posts-exploitation toolkit named khunt. This technique is something of a cyber-white whale: it’s been widely discussed but rarely seen in the wild.

How to defend

“What happened next, however, raised our eyebrows,” Huntress said. “After performing SQL injection, the threat actor managed to upload a database-resident, post-exploitation toolkit named khunt. This is a technique that's previously been discussed and described over the years, including via a technique described as oraexec – however, the use of the technique in the wild has rarely been documented.”

As a toolkit, khunt granted the attackers multiple capabilities, including loading cmd.exe on the system and running arbitrary OS commands, steal usernames and passwords, listing, reading, searching, and checking file sizes (essentially looking around the compromised system), unzipping files, and more.

Of all the things they could have done, the attackers opted to run a PowerShell command and invoke the Windows Registry tool, copying the SAM, SECURITY and SYSTEM registry hives. They can later use the copies to extract and decode password hashes for local accounts on the system, the researchers explained.

To defend against such attacks, Huntress recommends making sure the forms aren’t injectable. “Practice proper input sanitization and query parameterization for any inputs,” they warned. “It's also important to ensure that users with the ability to execute queries aren't overprovisioned.”

Even if someone manages to pull off SQL injection, user accounts should not be capable of authoring Java sources or running stored procedures.

Another top router maker accused of firmware having backdoors — Chinese giant Zbtlink halts downloads to fix issue

  • VulnCheck CTO Jacob Baines reported Zbtlink routers shipped with a built‑in backdoor dubbed ENDLESSDOORS, allowing remote root commands and reverse shells
  • Zbtlink denied malicious intent, calling it an after‑sales maintenance feature, but quietly pulled vulnerable firmware and promised patches
  • Researchers warn all firmware images are hijackable; mitigation advice is to replace devices or enforce strict egress controls and treat LAN as untrusted

Chinese networking firm Zbtlink has been accused of shipping its products with a backdoor - and while the company denies the allegations, it has still apparently moved to address the issue.

CTO of cybersecurity company VulnCheck, Jacob Baines, recently published an in-depth report stating a Zbtlink device he runs “continuously attempts to reach a command-and-control server on the internet.”

“Zbtlink routers phone home, waiting for orders. Not because they were hacked. Because they were shipped that way.”

Detention and escape attempts

Baines dubbed the flaw “ENDLESSDOORS” and says it was uploaded to GitHub in early 2015 and “never touched again”. “It can send the client individual shell commands or tell the client to spawn a reverse bash shell.”

“The vocabulary of this protocol is two phrases: run this as root, and give me a root shell,” he further explained, saying that anyone along the path can hijack the client/server communication. VulnCheck researchers tried it, and apparently - succeeded.

Baines said that every firmware on the company’s download page (roughly two dozen images) is all “hijackable in the same way”, and said the company decided not to “responsibly disclose” the vulnerability since that assumes the vendor did not intend the behavior. "That assumption doesn't hold here."

In response to the allegations, Zbtlink told The Register VulnCheck mischaracterized the code.

“This feature is solely intended for after‑sales maintenance and serves no other purposes,” the company told the publication. “It is generally retained only on sample units to assist customers with software debugging and will not be included in mass‑production shipments.”

The Register didn’t see it as a credible explanation since, in the meantime, the company posted a warning on its downloads page:

“We have detected firmware security vulnerabilities affecting selected router firmware releases. As a precautionary measure, the impacted firmware versions have been temporarily taken down from download channels. Our engineering team is working intensively to develop and validate secured patched firmware.” This warning was allegedly posted sometime in the past seven days.

Baines gave a list of suggestions how to mitigate the risk but ended up saying that “for anything carrying real traffic, our advice is to replace the device, or at minimum move it behind strict egress control and treat its LAN as untrusted.”

Google Blogger locks out thousands of users after malware false positive

  • Google’s automated systems mistakenly flagged hundreds of Blogger sites as malicious
  • Company admitted a bug caused false malware labels, promising a fix
  • Users advised to request reviews, avoid migrating content

Hundreds of Blogger websites were locked down, and some apparently deleted as well, after Google’s automated security systems erroneously flagged them as malicious.

A user posted a new message on Google’s forum saying the huge number of reports regarding locked blogs are all for the same reason - Malware and Similar Malicious Content.

The nature of the lockdown “suggests misclassification by automated systems”, the post reads, adding that the team has “already been notified of this issue.”

Aware of a bug""

Those affected will see a red padlock in their dashboard and a warning saying the blog was locked:

"This blog was removed for violating Blogger's Community Guidelines. If you wish to request a review of the blog, click 'Request Review' below," the notice reads.

At press time, the forum post had more than 500 “I have the same question” votes, and more than 200 replies.

In a statement given to BleepingComputer, Google said it was aware of a bug that falsely labeled many sites as malicious, and that it was working on a fix.

"We are aware of a bug that incorrectly flagged some Blogger-hosted sites as malware for less than a day. We are working on a fix to resolve the issue as quickly as possible," the company said.

To make matters even worse, Google said that if users don’t file an appeal, that their blogs can be permanently deleted.

Users are advised not to create new blogs and migrate content, since that is in violation with Google’s TOS. They are also advised against deleting their Blogger profile or service from their Google account, since this will irrevocably delete the blogs. They can, however, back up their blogs if they are afraid of losing the content.

The full extent of the issue is unknown, but according to BleepingComputer, the number of users on the platform exceeds 200,000.

OpenAI says it stopped an Asian scam campaign hijacking ChatGPT to lure in victims

  • OpenAI disrupted a major scam campaign in Cambodia’s Poipet, banning accounts and blocking new registrations
  • Criminals used ChatGPT to run romance fraud, fake investments, bogus police scams, and even operations linked to human trafficking
  • AI was leveraged for fake personas, fraudulent messages, job lures, and worker administration; OpenAI shared findings with authorities after evidence of hundreds of victims losing thousands of dollars

OpenAI said it disrupted a major scam campaign coming out of Southeast Asia by banning accounts used by the operation and making it difficult to open new ones.

In a blog post, the ChatGPT maker said it was tipped off about the existence of the campaign by WhatsApp.

After investigating further, the company found that a group of criminals in Cambodia used its AI tool in different scam campaigns - romance fraud, fake investment scams, or bogus police investigations. It also used AI to help with day-to-day operations and, most worryingly, for things that could be related to human trafficking and forced criminality.

Detention and escape attempts

OpenAI did not say if the group had a name, just that it operated out of Poipet, “a city in Banteay Meanchey province that public reporting⁠ has repeatedly⁠ linked⁠ to online scam compounds and trafficking operations.”

The group used AI to create fake personas, to help draft fraudulent emails and chat messages, and to create posters for fake jobs which were probably used to lure people into human trafficking or forced labor.

The tool was also used for worker administration, since the operators maintained records of employee debts, salary deductions, disciplinary fines, and loan repayments. They also used the tool to translate discussions about immigration status, work permits, visa overstays, and recruitment incentives.

“Some conversations also referenced apparent detention, escape attempts, and potential criminal liability for people who had been trafficked and forced to work in scam operations,” OpenAI said. “While these conversations do not allow us to determine the circumstances of any particular individual, they are consistent with extensive public reporting⁠ describing⁠ the activities of organized crime groups in Southeast Asia.”

The company could not say how many people fell victim, or how much money this group has stolen, but said it found evidence of “hundreds” of victims losing “thousands of dollars.” These findings were shared with relevant authorities.

Via The Hacker News

Hackers use fake Adobe and Zoom updates to load malware onto victim devices — here's what to look out for

  • Securonix uncovers SMOKE#SCREEN, a campaign tricking users into installing weaponized ScreenConnect via fake Zoom/Adobe updates and business docs
  • Attackers gain persistent remote access, evolving tactics to disable protections and abuse trusted services like Dropbox/Cloudflare for delivery
  • Victims observed on Windows and macOS; businesses urged to verify updates via official sites and train staff against unexpected installs

Security experts Securonix Threat Research have uncovered a new malicious campaign that tricks users into installing legitimate remote monitoring and management (RMM) software.

Dubbed SMOKE#SCREEN, the campaign uses fake Zoom and Adobe update messages, as well as a whole swathe of fraudulent business-related documents (document review requests, system maintenance tools, invoices, and similar), to convince the victims to run malicious files.

Victims who don’t see through the ruse and run the files end up installing ConnectWise ScreenConnect, a legitimate RMM tool that many IT teams use to provide technical support to their coworkers and clients. However, it is also one of the more abused solutions in the criminal cyber-underworld, since it can often fly under the radar of security products.

Dangerous evolution

After installation, attackers can remotely access compromised devices, potentially allowing them to steal data, install additional threats, or move deeper into an organization’s network.

At first glance, SMOKE#SCREEN looks like a fairly standard “phishing - install legitimate RMM - remote access” campaign. However, what makes it unique is how it evolved over time, Securonix explained. Earlier versions focused on hiding the malicious activity, while newer versions attempted to disable security protections and avoid detection by security software. The attackers also used trusted services such as Dropbox and Cloudflare to deliver their files, making the activity harder to block.

Victims were observed on both Windows and macOS ecosystems, it was added.

“The SMOKE#SCREEN campaign demonstrates a capable, actively maintained, and rapidly adapting threat actor who has built a diversified toolkit around a single objective: gaining persistent, legitimate-looking remote access to victim systems through weaponized ScreenConnect deployments,” the researchers explained.

“The use of multiple social engineering themes, rotating payload hashes, cross-platform coverage, and a live staging server that doubles as a ScreenConnect relay indicates a well-resourced actor with deliberate operational security practices.”

To minimize the risk of compromise, businesses should disable receiving software updates delivered through emails, verify update requests through official websites, and instruct their employees to be cautious when opening attachments or installing tools they were not expecting.

Via The Hacker News

Experts flag Bank of America phishing scam that hands your device over to hackers

  • Huntress flags phishing emails spoofing Bank of America, pushing victims into different infection chains on Windows vs. macOS
  • Windows users were tricked into installing ScreenConnect RMM via fake “Account Guard,” while macOS users faced credential‑harvesting forms for identity theft
  • Emails mimicked Bank of America branding but came from unrelated domains; users advised to verify sender addresses to spot scams

Bank of America customers have been warned to take extra caution after experts warned of hackers spoofing the bank into trick you into downloading unwanted software and granting them access to your computer.

Security researchers Huntress revealed how it received a phishing email in their honeypot (an address set up primarily to catch scammers) claiming to have come from Bank of America.

Obviously, the message came from a domain completely unrelated to the company, but looked almost identical to the real thing, with the company logos, color schemes, and other details, meticulously imitated.

Just another ScreenConnect scam

In the email, the researchers were warned that their account was about to be “restricted” unless they “confirmed” certain information.

Depending on the platform from which the victim views the email, both the infection chain and the end goal are different. For Windows users, victims are invited to install “Account Guard”, which is described as a “powerful tool designed to protect your financial data, prevent unauthorized transactions, and other cyber threats”.

This is no guard - this is a Visual Basic script that leads to an installation of the ScreenConnect Remote Monitoring and Management (RMM) tool. ScreenConnect is not malicious itself - it is a legitimate tool - but it is also one of the most abused software out there, leveraged to grant attackers unabated access to victim computers without triggering any alarms.

For macOS users, on the other hand, the goal is different. Instead of trying to deploy malware, the attackers try to steal sensitive data. First, the victims are asked to log in to their banking account (twice - the first attempt is scripted to fail, in case the victim purposely submits the wrong password the first time).

Then, once they “log in”, the second web page asks the victims to “confirm” their details - full name, mailing address, government ID details, Social Security number (SSN), and the payment card details. This is more than enough information for an identity theft attack, or even wire fraud.

Huntress is now warning all Bank of America users to double-check the sender address for any email claiming to be from the bank, since that is the best way to know if the email is legitimate, or a scam.

TP-Link router owners update now — 15 flaws patched to stop hackers hijacking your devices

  • Forescout’s Vedere Labs found 15 flaws in TP‑Link Omada business networking gear, exploitable for RCE when chained with prior CVEs
  • Weak trust shortcuts in zero‑touch provisioning exposed devices to client‑side code execution, hijacking, spoofing, and encrypted comms compromise
  • TP‑Link released firmware updates; admins should patch immediately, with 1,800+ Omada controllers exposed online

TP-Link has patched more than a dozen vulnerabilities across multiple business networking products which could have been chained to achieve remote code execution (RCE).

Security researchers at Vedere Labs from Forescout found the flaws and published an in-depth report on the issues, which particularly affect TP-Link Omada, the company’s business networking platform for centrally managing enterprise and small-business network infrastructure.

It includes cloud-managed Wi-Fi access points, routers, switches, gateways, and controllers, all of which can be monitored and configured from a single interface.

Enabling "concrete attacks"

These support zero-touch provisioning (ZTP), a mechanism that allows IT managers to deploy and maintain devices without needing to configure each one manually and on site.

However, ZTP has to establish trust between a factory-fresh device, and a controller with no human involved, so TP-Link used different shortcuts: from hard-coded keys and certificates shared across multiple devices, to default credentials, and from guessable serial numbers as “identity”, to weak session-key randomness.

Now, Forescout says 15 vulnerabilities its researchers discovered all allow for different ways of exploiting these shortcuts, meaning a flaw anywhere in the onboarding chain can compromise every device that goes through it. These bugs would need to be combined with two previously disclosed command-injection flaws, though.

“The vulnerabilities fall into four impact categories: client-side code execution, information disclosure, device hijacking and spoofing, and compromise of encrypted communications,” Forescout said. “Combined with two previously disclosed CVEs (CVE-2025-7850 and CVE-2025-7851), these flaws enable concrete attacks that let attackers infiltrate networks through controllers and client devices.”

Out of the 15 discovered flaws, 11 received CVE identifiers, and the rest did not receive a tracking number.

Forescout said there are more than 1,800 Omada controllers accessible from the wider internet. If you are using any of the devices from the platform, you should head over to TP-Link’s download portal and grab the latest firmware for your device model.

Microsoft 365 users hit by phishing scheme posing as RingCentral emails

  • ZeroBEC observes Greatness PhaaS evolving to bypass MFA and phish Microsoft 365, iCloud, Yahoo, and Google Workspace accounts
  • Attackers spoofed RingCentral emails post‑ShinyHunters breach, luring victims to fake Microsoft 365 logins that capture authentication tokens
  • Greatness is sold on Telegram for $289/month, enabling access to Outlook, Teams, SharePoint, OneDrive, and more across multiple regions

Microsoft 365 users have been getting phishing emails spoofing RingCentral, designed to steal their accounts even if they were protected by multi-factor authentication (MFA), experts have warned.

Security researchers ZeroBEC claim to have observed a phishing-as-a-service (PhaaS) platform called Greatness evolve to also target MFA accounts, as well.

Greatness used to be a simple credential phishing platform. However, in recent times, it evolved to target not just Microsoft 365 accounts, but also those of iCloud, Yahoo, and Google Workspace.

Grabbing MFA-approved authentication tokens

ZeroBEC notes that RingCentral recently suffered a data breach at the hands of the infamous ShinyHunters hackers, meaning there is a good chance (although not confirmed) that the threat actors exfiltrated a list of emails belonging to RingCentral customers from that attack, and used it in this attack.

Now, RingCentral customers have been getting emails that look as if they are coming from the company itself, despite being mailed from an unknown mail server, and despite failing SPF and DMARC checks. The emails are the standard fake voicemail and performance-review notifications which, if clicked, redirect the victim to attacker-owned infrastructure spoofing the Microsoft 365 login page.

Through this malicious landing page, Greatness operators are able to capture MFA-approved authentication tokens, bypassing the login process entirely and moving straight into victim accounts.

From there, they would enumerate Outlook mailboxes, Teams conversations, and SharePoint sites. They would also access OneDrive files, contacts, calendars, and registered applications through Microsoft Graph.

The number of victims is unknown at the time, but ZeroBEC says Greatness has been active for at least four years now, targeting users in the US, UK, Australia, Canada, and South Africa.

According to BleepingComputer, the platform is being advertised for sale on Telegram channels with “thousands of subscribers”, and is currently being offered for a monthly fee of $289.

Via BleepingComputer

New ChainDrop worm poisons over 1,300 npm packages, Keyv and Cacheable among those hit

  • Aikido researchers uncovers ChainDrop, a Shai‑Hulud variant infecting 1,300+ npm packages with an infostealer
  • Attackers compromised GitHub accounts tied to popular libraries (Keyv, Cacheable, flat‑cache, file‑entry‑cache) and pushed tainted releases with 2B monthly downloads
  • Malware exfiltrates developer/cloud credentials and secrets to a public GitHub repo; admins should treat affected systems as compromised even after removal

Another Shai-Hulud variant has been discovered in the wild, infecting more than 1,300 npm packages with an infostealer.

Security researchers Aikido reported finding “at least 868 packages (across 1381 versions) that have been compromised by the worm.”

Shai-Hulud is a self-propagating supply chain malware that targets software developers by compromising open-source packages and CI/CD pipelines. It steals credentials, API keys, and access tokens and then uses those stolen secrets to publish additional malicious packages.

What to do in case of an infection

In May 2026, actors claiming to be associated with the TeamPCP group publicly released the Shai-Hulud worm's source code, saying they were “open sourcing the carnage” and inviting other threat actors to adopt and modify the code. Since then, there were multiple copycat campaigns and variants, including this one which Aikido dubbed ‘ChainDrop’.

Aikido said the attackers compromised the GitHub account of the person maintaining Keyv and Cacheable, widely used open source JavaScript libraries for caching data in Node.js applications. From there, they were able to move into other popular utilities such as flat-cache and file-entry-cache, as well as packages associated with organizations such as Deliveroo, Ornikar, OneReach, Picsart, Qlik, and ServiceTitan.

The malware was pushed directly into the projects’ main branches, and then generated additional package releases. The compromised packages have a combined 2 billion monthly downloads.

Aikido says the infostealer grabs developer and cloud credentials, encrypts them, and then sends them to a public GitHub repository called “Shai-Hulud: Here We Go Again.”

It also steals local configuration files, GitHub PATs, workflow tokens, and other ghp_, gho_, and ghs_ tokens, certain npm tokens, GitHub Actions secrets, AWS credentials, Kubernetes secrets, and more.

The researchers are saying system admins who installed a tainted package should treat their developer workstation or CI/CD runner as compromised, even if they removed the package.

Watch out — Microsoft login pages are being abused as hackers try and lure in unlucky victims, here's what to look out for

  • Phishing campaign used fake Teams notifications to route victims to a genuine Microsoft sign-in page
  • Rather than stealing passwords, attackers asked victims to approve permissions for an attacker-controlled app, gaining access to mail, files, Teams, SharePoint, OneDrive and calendars without defeating MFA
  • Check Point says the technique has been commoditized in 2026 into a rentable service; the practical defense is restricting app consent rather than relying on users to spot a fake

A phishing campaign that ran from late June into July 2026 did something that breaks most of the advice organizations have spent a decade teaching their staff: it sent victims to a real Microsoft login page.

Check Point's email research team, which disclosed the campaign, identified more than 200 phishing emails targeting users across roughly 120 organizations worldwide.

The lure was a fake Microsoft Teams notification with a genuine destination; what actually compromised accounts was not a stolen password but a permissions prompt that the victim clicked through voluntarily.

A sophisticated attack that relied on tricking users into granting permissions

Check Point noted in its brief that what actually compromised the accounts was not a stolen password but a permissions prompt that the victim clicked through voluntarily. This is a reminder of a stark change in attackers' tactics: they have stopped forging Microsoft's front door and started walking through it.

The email appeared to be a Microsoft Planner task-assignment notification. The sender name read "There's New Activity On Team," the subject line claimed that HR had sent three messages via Teams chat, and the body referenced a payroll and benefits update, along with a counter showing four overdue employee tasks.

To someone who works in security, the message had its own telltale signs of being a typical phishing attempt: every link in the email, including both call-to-action buttons, routed through the same redirect. And the visible sender address belonged to the recipient's own organization, meaning the email appeared to have been sent to the same person it came from.

The link opened a real OAuth authorization URL on login.microsoftonline.com, not a look-alike domain. Signing in displayed a permissions prompt asking the user to approve the permissions or accept them on behalf of their organization.

If they did, Microsoft redirected the browser to the redirect address specified in the original request, which in this particular campaign was an AWS API Gateway endpoint under the attackers' control. The authorization code was delivered there, and the attackers exchanged it for access. No password was stolen at any point, and there was no fake page to spot.

This is not unlike how the phishing-as-a-service Kali365 platform compromises Microsoft accounts, but instead of stealing session cookies or OAuth tokens, it opts for a more permanent illicit grant of consent.

This runs counter to the usual security training checklist, which emphasizes adhering to norms rather than going against the grain; users are told to check the URL, look for the padlock, and watch for misspelled domains. None of those measures matter because there is nothing forged to catch. The domain and certificate are Microsoft's, while the sign-in page is the one the user sees every morning, offering a false sense of security to a user not looking for this particular attack vector.

Multi-factor authentication does not help either; it protects the login sequence but not access to the user's data post-login. The attacker never needs the password or the second factor because they walk away with a token granted by the user's valid session, a technique called 'consent phishing'.

There are many ways to prevent this, but the simplest two are asking users to check every single permission/consent screen they click (the phishing attempt still requires users to allow it) and limiting access to permissions for user accounts that applications can request via Microsoft Entra at the system administrator level.

It would be prudent to do the latter at a minimum, even as Check Point notes that the campaign is no longer active because the underlying technique it used is not going anywhere.

Cybercrime is costing the world trillions every year - new report says victims lose an average of nearly $10,000 in every hit

  • New study puts average cybercrime victim losses at $9,468, making a global annual toll at just over $1.24 trillion across 130.9 million victims
  • Cybercrime is still massively underreported by both victims and authorities, so official numbers might be 'softer' than the underlying problem
  • Some of the countries published limited, if any, financial data regarding cybercrime, making losses an estimate at best

New figures have claimed cybercrime victims lose $9,468 in the average incident, showing the scale of an increasingly global problem.

The report from Comparitech claims 130.9 million people are hit each year, and that the annual global toll comes to just over $1.24 trillion.

A December 2023 study from the company put those figures at $8,069 per victim, 88.5 million people and $714 billion in total losses respectively, highlighting a growing trend that sees a mix of illegal activity moving the needle further.

A growing problem with regional caveats

The United States remains a favorite for cybercriminals, topping the charts with 6.7 million victims losing $138.9 billion, a per-victim loss amount of ~$20,731, more than twice that of the global average.

This is in stark contrast with the next four countries on the list (Spain, France, Sweden and Turkey), all of which offered an average of approximately $10,000 per victim.

Russia, coming in 6th, reports a much larger number of victims than the four countries ahead of it, but offers a much lower per-victim loss estimate of $3,659. Interestingly, the total number of cybercrimes committed in 2025 dropped to 663,000 from 775,000 in 2024, despite an ongoing conflict with Ukraine, which often sees cyberattacks at both the industrial and localized levels by both parties.

However, a weakening economic situation, as well as Russia localizing many of its communication applications and restricting banking, might also mean that Russia's figures also remain inadvertently capped by policy decisions the country has taken.

With 18.8 million victims, India has the highest number of scam victims worldwide, even though its pro-rata number is considerably lower than the mean at ~$835 per victim, which may be attributable to the country's lower GDP per capita.

Interestingly, China, with 1.2 million victims, a fraction of its neighbor, managed to lose approximately $11.5 billion, a pro-rata number of approximately $9583, in line with global estimates by Comparitech and possibly fueled by the country's heavy-handed approach to cybercriminals, which saw it apply increasing amounts of pressure on neighboring Myanmar that culminated in it convicting and executing scammers arrested across the border.

Comparitech's $1.24 trillion figure is conservative, and the study acknowledges this, noting that it covers only victim losses. It notes that experts anticipated the global cost reaching $10.5 trillion in 2025 and calls its own $1.24 trillion a drop in the ocean by comparison.

That $10.5 trillion comes from Cybersecurity Ventures' 2016 report, which estimated $3 trillion for 2015 and projected it forward at an assumed 15 percent compound annual growth rate, describing the result as the greatest transfer of economic wealth in history.

At a time when AI automation offers better security, often allowing users to screen calls or leverage security applications that adapt on a case-by-case basis, the inverse is also true with hackers and cybercriminals considerably upping their game when it comes to bypassing security altogether; Comparitech's figures provide a sobering reality: if the industry estimates it has hold and are compared to the GDP of entire countries, the firm says it would rank 20th in the world in those terms alone.

❌
❌