Daily Recap, a cybersecurity news digest, covers malware campaigns like AVrecon and CrystalX, phishing services like EvilTokens and PXA Stealer, and notable incidents such as Hasbro and Drift, plus Go RAT and WhatsApp-based spyware trends. It also notes ongoing vulnerability patches (CVE-2026-20160, CVE-2026-20093, CVE-2026-5281, CVE-2025-53521, CVE-2026-25075, CVE-2026-3502) and law enforcement actions (Uranium Charges) across vendors like Cisco, Google, F5, StrongSwan, and companies including Nissan and Linx Security.
#AVrecon #SocksEscort #CrystalX #CrystalRAT #DeepLoad #NoVoice #EvilTokens #PXAstealer #AGEWHEEZE #WhatsAppFakeApp #WhatsAppVBS #CERTUA #DarkSword #Hasbro #Drift #Nissan #LinxSecurity #Depthfirst #Uranium #TornadoCash #Cisco #Google #F5 #StrongSwan #TrueConf
#AVrecon #SocksEscort #CrystalX #CrystalRAT #DeepLoad #NoVoice #EvilTokens #PXAstealer #AGEWHEEZE #WhatsAppFakeApp #WhatsAppVBS #CERTUA #DarkSword #Hasbro #Drift #Nissan #LinxSecurity #Depthfirst #Uranium #TornadoCash #Cisco #Google #F5 #StrongSwan #TrueConf
Malware & Botnets
- AVrecon router malware converts exposed home/SOHO devices into proxy nodes used for fraud and sold via the SocksEscort service (â 369,000 devices) â AVrecon Alert
- CrystalX (aka CrystalRAT) is a Goâbased malwareâasâaâservice offering RAT, stealers, keylogging, VNC and prankware via encrypted payloads and WebSocket C2 â CrystalX Malware
- DeepLoad was observed in ClickFix campaigns delivering a persistent PowerShell loader that injects evasive DLLs and intercepts browser activity for live crypto theft â DeepLoad Drop
- NoVoice Android apps on Google Play reached at least 2.3 million installs, using steganography and exploits to gain root and steal WhatsApp keys/backups â NoVoice Android
Phishing & Account Takeover
- EvilTokens is a phishingâasâaâservice that automates Microsoft deviceâcode token theft to hijack accounts for BEC and persistent access â EvilTokens Kit
- PXA Stealer (Vietnamâlinked) used spoofed LinkedIn recruiter lures, Google Forms and DLL sideloading to steal credentials and crypto data from professionals worldwide â PXA Stealer
- Campaigns impersonating authorities delivered the Go RAT AGEWHEEZE via passwordâprotected ZIPs to ~1 million emails targeting state, medical, education and finance sectors â CERTâUA Lure
- WhatsApp-based attacks included a fake iPhone client distributing spyware and VBSâbased chains that use UAC bypass and cloud payload hosting to gain persistent elevated access â WhatsApp Fake App, WhatsApp VBS
Vulnerabilities & Patches
- Multiple vendors released fixes or warnings for active and highârisk flawsâCisco patched critical bugs including CVE-2026-20160 and CVE-2026-20093; Google patched 21 Chrome flaws including an actively exploited issue (CVE-2026-5281); Shadowserver found > 14,000 exposed F5 BIGâIP APM instances vulnerable to the reclassified CVE-2025-53521; strongSwan patched a 15âyear integer underflow (CVE-2026-25075); and attackers exploited a TrueConf update zeroâday (CVE-2026-3502) prompting vendor patches and rebuild guidance â Cisco Patches, Chrome Update, F5 Exposure, strongSwan Flaw, TrueConf ZeroâDay
Mobile & Apps
- The FBI warned that many foreignâdeveloped mobile appsâparticularly from Chinaâcan collect extensive device and location data, be subject to foreign laws, and may contain hidden malware, urging limited permissions and IC3 reporting â FBI Mobile Warning, FBI Mobile Warning
- Apple expanded availability of iOS 18.7.7 fixes to more devices to block the actively exploited DarkSword exploit kit used to deploy infostealers/backdoors â iOS DarkSword
Incidents & Breaches
- Hasbro detected unauthorized network access, took systems offline and engaged external responders while business continuity plans remain active and delays are possible â Hasbro Breach
- Crypto platform Drift suspended services after an active attack that firms estimate stole roughly $130Mâ$285M in repeated conversions while teams and exchanges scrambled to contain losses â Drift Heist
- Nissan says claimed theft stemmed from a thirdâparty vendor and found no evidence Nissan systems or customer data were compromised after a hacking group posted alleged files â Nissan Claim
Threat Reports & Strategy
- Blackpoint Cyberâs 2026 report finds modern intrusions increasingly rely on legitimate credentials, administrative tools and social engineering (SSL VPN abuse, RMM misuse, ClickFix), urging stricter remoteâaccess controls â Routine Access Report
- Opinion/analysis argues shifting from blunt blocking to sessionâlevel governance (prompt DLP, extension riskâscoring, agentless controls) to avoid a âworkaround economyâ that fuels invisible data exfiltration â Block the Prompt
Funding & Business
- Linx Security raised $50 million in a Series B to expand its AIânative identity security and Autopilot remediation platform (total funding $83M) â Linx Security
- Depthfirst secured $80 million in Series B (total $120M) and launched openâsource model Dfsâmini1 for security tasks across domains â Depthfirst Raise
Law Enforcement & Legal
- U.S. authorities charged Jonathan Spalletta for exploiting Uranium Finance in 2021, seizing roughly $31 million and alleging laundering via Tornado Cash amid fraud and moneyâlaundering counts â Uranium Charges