Chaos ransomware’s msaRAT: Living off the browser to build a covert C2 channel

Cisco Talos discovered msaRAT, a new Rust-based remote access trojan used by the Chaos ransomware group, which hides its command-and-control traffic by abusing Chrome DevTools Protocol and WebRTC through a browser process. The malware uses Cloudflare Workers for signaling and Twilio TURN for relayed communications, making its network activity difficult to trace and blending it into normal browser traffic. #msaRAT #Chaos #CloudflareWorkers #TwilioTURN #ChromeDevToolsProtocol

Read More
Cl0p Exploitation of PTC Windchill & FlexPLM (CVE-2026-12569)

This advisory describes an active Cl0p ransomware affiliate campaign targeting internet-exposed PTC Windchill and FlexPLM systems by chaining a FlexPLM WSDL information disclosure flaw with a Windchill login servlet vulnerability to gain unauthenticated remote code execution. It also details post-exploitation webshell deployment, data theft, and extortion emails sent to affected organizations across Manufacturing, Automotive, Aerospace, and Retail/Apparel sectors. #Cl0p #PTCWindchill #FlexPLM #CVE-2026-12569

Read More
RevolutionParts Database Allegedly Leaked, 5.1 Million Customer Records Posted for Free

Get Nice Holdings, a Hong Kong-listed financial services company, was hit by a cyberattack on July 19 that temporarily disrupted electronic trading systems and share withdrawal services. The securities unit resumed operations the same day, while the futures unit remained offline as the company investigated the incident with a cybersecurity firm and notified Hong Kong authorities. #GetNiceHoldings #HongKong

Read More
RevolutionParts Database Allegedly Leaked, 5.1 Million Customer Records Posted for Free

A threat actor using the alias xpl0itrs claims RapidFort was breached in a CanisterWorm campaign linked to TeamPCP, with 569GB of data from 48 S3 buckets reportedly offered for sale. The alleged haul includes cloud credentials, kubeconfigs, private keys, and customer deployment materials, but the claim remains unverified. #RapidFort #CanisterWorm #TeamPCP…

Read More
Stadler gibt Entwarnung nach Cyberangriff

Cybercriminals gained access in mid-July 2026 through compromised credentials to a data exchange platform used by one of Stadler’s suppliers, exposing technical information from the supplier rather than Stadler’s own systems. Stadler says no internal IT systems were compromised, no personal data was affected, and production and train operations continue without disruption, while the Everest Group claims the attack and demands 10 million Swiss francs. #Stadler #EverestGroup #Thurgau

Read More
Cookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware – Arctic Wolf

Arctic Wolf Labs found multiple June 2026 intrusions in which attackers used CVE-2026-0257 against Palo Alto Networks firewall appliances to gain VPN access and quickly deploy Qilin ransomware across victim networks. The activity showed shared operational patterns, including PsExec lateral movement, credential theft, log clearing, and in some cases data exfiltration for double-extortion, suggesting overlapping Qilin affiliates or shared exploitation infrastructure. #CVE-2026-0257 #PaloAltoNetworks #Qilin #GlobalProtect #PsExec

Read More
RevolutionParts Database Allegedly Leaked, 5.1 Million Customer Records Posted for Free

A claimed breach of Georgia’s judiciary alleges that the High Council of Justice and related court systems were compromised, with about 5TB of judicial data reportedly offered for sale. If true, the exposed material could reveal sensitive court records, personal data, and technical details that may help attackers target Georgian judicial…

Read More
RevolutionParts Database Allegedly Leaked, 5.1 Million Customer Records Posted for Free

A breach is alleged against Bogotá’s Secretaría Distrital de Movilidad, with 5.6GB of traffic agent and citation-related data reportedly listed for sale at $500. The data package is said to include citations, agent rosters, medical records, and multiple file types, and is attributed to PescobarLegado / NyxarGroup. #SecretaríaDistritaldeMovilidad #Bogotá #PescobarLegado #NyxarGroup…

Read More