Daily Recap, phishing and account abuse dominated the news, with ConsentFix v3 abusing OAuth to hijack Azure tokens, Bluekit offering AI-assisted phishing templates, AccountDumpling compromising roughly 30,000 Facebook accounts via Google AppSheet, and Cordial Spider and Snarky Spider using vishing and SSO abuse to extort users inside Google Workspace, HubSpot, SharePoint, and Salesforce. Nation-state activity followed with a China-linked SHADOW-EARTH-053 cluster targeting Asian governments, a Poland NATO state, journalists, and activists using Exchange/IIS exploits and ShadowPad, plus GLITTER CARP and SEQUIN CARP phishing aimed at journalists and activists; the report also covers urgent cPanel patching, revised bug bounties, guidance on secure deployment of agentic AI, and notable breaches at Trellix and Instructure, as well as the ANTS data breach case. #ConsentFix #Azure #Bluekit #AccountDumpling #Facebook #Meta #AppSheet #CordialSpider #SnarkySpider #SHADOW_EARTH_053 #ShadowPad #GLITTERCARP #SEQUINCARP #cPanel #Trellix #Instructure #ANTS #ALPHV #BlackCat #ScatteredSpider #GUARDAct #WindowsRun
Phishing & Account Abuse
- ConsentFix v3 uses automated OAuth abuse, Cloudflare Pages phishing, and Pipedream to steal Microsoft tokens and hijack Azure accounts – ConsentFix v3
- Bluekit is an AI-assisted phishing kit with 40+ templates, anti-bot cloaking, voice cloning, and Telegram exfiltration, though it is still in development – Bluekit Kit
- A Vietnamese-linked AccountDumpling campaign abused Google AppSheet to phish Meta Support logins, impacting roughly 30,000 Facebook accounts and stealing 2FA codes and ID photos – AppSheet Fraud
- Cordial Spider and Snarky Spider used vishing and SSO abuse to rapidly extort victims inside SaaS platforms like Google Workspace, HubSpot, SharePoint, and Salesforce – SaaS Extortion
Nation-State & Espionage
- A China-linked cluster tracked as SHADOW-EARTH-053 targeted Asian governments, a Poland NATO state, journalists, and activists with Exchange/IIS exploits, ShadowPad, and web shells – Shadow Earth
- Citizen Lab also tied separate phishing activity to GLITTER CARP and SEQUIN CARP, aimed at journalists and activists – CARP Phishing
Vulnerabilities & Patching
- CISA ordered federal agencies to patch a cPanel vulnerability by Sunday, underscoring the risk of delayed remediation – cPanel Fix
- Google revamped Chrome and Android bug bounties, lowering many Chrome payouts while raising select Android rewards amid a surge in AI-assisted vulnerability discovery – Bug Bounties
- Five national cybersecurity agencies issued guidance for securely deploying agentic AI, stressing zero trust, least privilege, encryption, human approval, and defenses against prompt injection – AI Agents
Breach & Incident Response
- Trellix confirmed unauthorized access to part of its source code repository but said there is no evidence the code was released or exploited – Trellix Breach
- Instructure disclosed a cyber incident and said it is investigating the impact on its systems and data – Instructure Incident
- France detained a 15-year-old over the ANTS data breach after a forum post claimed access to up to 18 million records, with 11.7 million accounts later confirmed impacted – ANTS Breach
Ransomware & Justice
- Two incident responders received 4-year prison sentences for secretly running ALPHV/BlackCat ransomware attacks that generated a $1.2 million extortion and exposed sensitive patient data – BlackCat Case
- A wider roundup highlighted arrests, sanctions, major data exposures, and critical vulnerabilities, including the arrest of a Scattered Spider suspect and North Korean social engineering against crypto firms – Threat Roundup
Policy & Product Updates
- The U.S. Senate Judiciary advanced the GUARD Act, which would restrict minors from AI companions and require chatbots to disclose they are not human – GUARD Act
- Microsoft is testing a modernized Windows Run dialog in Windows 11 with Fluent Design, dark mode, and faster performance than the legacy version – Windows Run