This bulletin covers a wide range of threats, from phishing and fake install guides to credential stuffing, DNS hijacking, and AI-assisted exploitation, all aimed at stealing access, data, or money. It also highlights major campaigns and incidents involving XWorm, GenieLocker, MacSync Stealer, CastleLoader, SpyGlace, MedusaHVNC, ShinyHunters, and Origin Energy, along with exposed flaws in My Eicher, SonicWall, and Chrome. #XWorm #GenieLocker #MacSyncStealer #CastleLoader #SpyGlace #MedusaHVNC #ShinyHunters #OriginEnergy #MyEicher #SonicWall #Chrome
Keypoints
- Phishing campaigns are delivering XWorm, SpyGlace, and MacSync Stealer through fake guides and trusted-looking services.
- Toy Ghouls used custom GenieLocker ransomware against Russian organizations through trusted partner access and lateral movement.
- CastleLoader, RenPy Loader, and other loaders are spreading crypto theft tools, browser persistence, and stealer payloads.
- AI-enabled attackers are automating exploitation across multiple CVEs using Hermes Agent and DeepSeek.
- Recent incidents include SonicWall credential stuffing, CubePilot DNS hijacking, and the exposure of 900,000 Origin Energy customer records.
Read More: https://thehackernews.com/2026/07/threatsday-ai-powered-hacking-370.html