ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories

ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories
This week’s ThreatsDay Bulletin highlights a wave of social engineering, trojanized apps, phishing frameworks, stealer malware, botnets, and exposed systems being abused across Windows, Android, IoT, and cloud environments. From ReliaQuest and Microsoft Purview to ShinyHunters, Aeternum, ToxNetV2, and PackClient, attackers keep using trust, urgency, and weak visibility to gain access and expand control. #ReliaQuest #ShinyHunters #MicrosoftPurview #Aeternum #ToxNetV2 #PackClient

Keypoints

  • ReliaQuest stopped a social engineering attack using a lookalike domain and fake SSO page.
  • Trojanized productivity apps and fake scans were used to trick users into installing malware or removing antivirus.
  • New stealers and RATs, including Phantom Stealer, Vanta Stealer, Salat Stealer, and CNCMachineRMS, targeted credentials and remote access.
  • Botnets and loaders like Dysphoria, Aeternum, and ToxNetV2 used blockchain, AI, and decentralized C2 methods.
  • Microsoft, CISA, and researchers warned that exposed systems, SharePoint flaws, and ungoverned AI tools are widening attack opportunities.

Read More: https://thehackernews.com/2026/08/threatsday-296k-iot-botnet-100-water.html