Daily Recap, Two key themes dominated today: attackers are targeting AI and software supply chains, including Ghostcommit’s prompt-injection images and a GitHub compromise at Injective Labs that pushed wallet-key-stealing npm packages. Critical patching also remains urgent, with vulnerabilities in Zimbra, ShareFile, U-Boot, and Gitea along with broader pressure on healthcare, privacy, and enforcement efforts.
Category: Daily Recap
Daily Recap, Threat activity highlighted targeting of a Pakistani police force by China- and India-linked hackers, new Helix SharePoint-related vishing theft tactics, and GigaWiper’s Windows backdoor that blends disk wiping, fake ransomware, and spyware. Patch and response updates included Zimbra’s critical XSS fix, Palo Alto Networks’ 13 vulnerability updates, Microsoft’s additional Windows security expectations plus OWA Light retirement, and npm supply-chain hardening via Injective SDK and npm 12’s install-script changes, while BlackCat and DigitalMint cases progressed through sentencing. #China #India #Pakistani #Helix #SharePoint #Okta #Microsoft365 #Forg365 #GigaWiper #GitHub #InjectiveSDK #Zimbra #XSS #PaloAltoNetworks #Microsoft #OWALight #ExchangeServer #npm12 #BlackCat #DigitalMint #INTERPOL #NSA #TailoredAccessOperations
Daily Recap, Data breaches impacted AssuranceAmerica (6.9 million drivers), KDDI (12 million users), Mount Royal University, and Accenture after claims of stolen source code. AI security updates covered HalluSquatting, and new exploit and patch activity included Google’s GhostLock payout, Microsoft Defender fixes for RoguePlanet, plus Chrome 150, Ubiquiti UniFi, and Roundcube-targeted spying.
#AssuranceAmerica #KDDI #MountRoyalUniversity #Accenture #HalluSquatting #GhostLock #RoguePlanet #UniFi #UniFi #Roundcube #Intellexa #Predator #Leash #Entra #Microsoft365 #NPM #PyPI #Paysafe #Skrill
Daily Recap, this cybersecurity update highlights ongoing exploitation and misuses across AI and cloud services, including conversation hijacking risks tied to Dialogflow, alongside federal patch pressure for Adobe ColdFusion, Langflow, and Joomla flaws in the KEV catalog. It also covers breach and fraud activity from KDDI’s 12M+ email exposure and Accenture’s confirmed incident, plus threats ranging from LONGLEASH malware to RedWing Android MaaS and device-code flow abuse via DEBULL.
#Dialogflow #RogueAgent #AdobeColdFusion #Langflow #Joomla #KEV #KDDI #Accenture #LONGLEASH #RedWing #Tenda #DEBULL
Daily Recap, Linux and virtualization issues topped the roundup, including a Januscape-disclosed Linux kernel vulnerability that enables VM escape on Intel/AMD systems affecting KVM guest-to-host isolation, alongside rapid probing of a Gitea Docker flaw (CVE-2026-20896) shortly after disclosure. State-sponsored and criminal activity also featured prominently, with Iran-linked actors using a modular Cavern C2 framework, Chinese espionage groups leveraging Roundcube exploit chains and Armored Likho continuing targeting of government and electric power, while BeyondTrust patched critical authentication-bypass issues and CERT/CC warned of a hidden Tenda admin backdoor—plus phishing delivery of EtherRAT and Blogspot-hosted Veil#Drop staging. #Januscape #KVM #Gitea #CVE-2026-20896 #Cavern #Iran #Israeli #Roundcube #Armored Likho #BeyondTrust #PRA #Tenda #EtherRAT #VeilDrop #Blogspot #HiAnime #BONK
Daily Recap, Agentic ransomware techniques were documented for the first time as Sysdig tracked JADEPUFFER, while prompt injection attacks demonstrated how AI agents can be manipulated into making crypto payments. North Korean actors continued supply-chain pressure by targeting open source developers, and researchers also flagged trojanized PoC repos and malicious PyPI packages. #JADEPUFFER #Sysdig #NorthKorea #PoC #PyPI
Cybersecurity Threat Research ‘Weekly’ Recap. This week’s coverage highlights ongoing supply-chain and browser-extension abuse, including trojanized Proof-of-Concept repos and PyPI packages, “free VPN” clipboard-stealing extensions, and phishing efforts enabled by LLM-generated phantom domains and messaging lures. Researchers also tracked new and evolving infostealers/RATs (BusySnake, MarkiRAT, Glitch SPY, EKZ Stealer, Umbrij), BYOVD-driven defense-killing intrusion chains, and AI-driven attack techniques such as indirect prompt injection, JADEPUFFER agentic ransomware, and browser-only ransomware methods. #ChocoPoC #ChocoPoCs #ChocoPoC #BusySnakeStealer #ArmoredLikho #MarkiRAT #AsyncRAT #Remcos #TA416 #EKZStealer #CVE-2026-35616 #ToddyCat #Umbrij #JADEPUFFER #Langflow #MySQL #Nacos #Gentlemen #RaaS #BYOVD #StratusRedTeam #MustangPanda
Daily Recap, ransomware and extortion developments highlighted JadePuffer using an AI agent to automate attacks, alongside reports that a U.S. government entity paid $1 million to the Kairos group in a data-theft extortion case. The news also covered supply-chain and targeted intrusion campaigns, including PolinRider’s 108 malicious packages and browser extensions, North Korea–linked npm lures delivering BeaverTail, OtterCookie, and ContagiousInterview, and Pegasus spyware found on a European Parliament member’s phone.
Daily Recap, Agentic AI was reported to drive a ransomware attack via Langflow, while Cursor AI IDE flaws could allow OS-level remote code execution affecting developers. Ransomware groups are also leveraging Citrix Bleed 2, BYOVD, and stolen supply-chain credentials, as CISA warns that a Microsoft SharePoint RCE bug is actively exploited in the wild.
#Langflow #AgenticAI #Cursor #CitrixBleed2 #BYOVD #SharePoint #RCE #Pegasus #ScatteredSpider #Medtronic #NetNut #ConsentFix #ClickFix #M365 #UKNationalCyberActionPlan
Daily Recap, cybersecurity coverage highlighted rapid exploitation of widely used software flaws, including Cisco Unified CM attacks, a CitrixBleed issue exploited immediately after disclosure, a SharePoint RCE added to CISA KEV, active targeting of Oracle E-Business instances, and an unpatched Argo CD repo-server flaw that could enable takeover of Kubernetes clusters. The same roundup also covered the FortiBleed credential-theft campaign tied to INC and Lynx ransomware, ChocoPoC RAT attempts to compromise vulnerability researchers, 81 million login attempts against Microsoft 365, and ShinyHunters’ data breach impacting Medtronic customers. #UnifiedCM #CitrixBleed #SharePointRCE #CISAKEV #OracleEBS #ArgoCD #Kubernetes #FortiBleed #INC #Lynx #ChocoPoC #ChocoPoCRAT #ClickFix #Microsoft365 #ShinyHunters #Medtronic #BioShocking #Claude #Teams #Copilot #ScatteredSpider #Kubota #HSIN #DHS
Daily Recap, Citrix patched multiple NetScaler issues, including a new HTTP/2 Bomb and bugs tied to CitrixBleed, while Progress Kemp LoadMaster faced active exploitation attempts for a pre-auth RCE flaw. Across AI and threats, Microsoft warned that poisoned MCP tool descriptions can lure AI agents into leaking data, and security researchers reported Azure CLI password-spraying against at least 78 Microsoft accounts, with additional supply-chain abuse via malicious PyPI packages targeting Telegram bot servers.
#Citrix #NetScaler #HTTP2Bomb #CitrixBleed #ProgressKemp #LoadMaster #PreAuthRCE #Mythos #Fable #MythosFable #MCP #BioShocking #Monero #Langflow #AzureCLI #PasswordSpray #RustDuck #PyPI #Telegram #CISA #CIA #RussellVought #Ratcliffe
Daily Recap, BlueHammer and SimpleHelp weaknesses continue to be exploited, with CISA noting BlueHammer has entered ransomware-gang playbooks, while Oracle PeopleSoft issues have also driven data theft and malware activity tied to ShinyHunters. Meanwhile, Blackfield ransomware demanded $2 million from Nidec Corporation, Aflac Japan disclosed a breach impacting 4.38 million people, and Mustang Panda used Zoho WorkDrive as a command channel against Indian government targets. #BlueHammer #SimpleHelp #OracleEBS #PeopleSoft #CISA #Blackfield #Nidec #AflacJapan #ShinyHunters #NAIC #MustangPanda #ZohoWorkDrive #Signal #WhatsApp
Daily Recap, OpenAI and Anthropic are limiting access to new AI models during a cybersecurity review, while OpenAI also introduced GPT-5.6 Sol as its most advanced cybersecurity-focused AI and Straiker raised $64 million to expand its AI security platform for enterprise workloads. DirtyClone is highlighted for a Linux kernel issue that can enable root access, Microsoft removed 119 Edge extensions that hid malware in images and fonts, and a breach exposed up to 14.2 million email logins across six ISPs—along with U.S. bounties tied to Russian state hackers and updated post-quantum cryptography readiness demands for CISOs. #OpenAI #Anthropic #GPT-5.6 Sol #Straiker #DirtyClone #Microsoft #Edge #Russian #post-quantum #CISO #DirtyCloneLinux #6 ISPs
Cybersecurity Threat Research ‘Weekly’ Recap. This week’s coverage spans supply-chain and DevOps attacks, credential-harvesting phishing, and exploitation of widely used software to steal tokens, deploy backdoors, or monetize access. It also highlights nation-state and fraud ecosystems, alongside Windows and macOS tradecraft that focus on evasion, persistence, and stealthy command-and-control.
Daily Recap, AI-native security, agentic workflows, and AI-abusing malware were front and center, including Nebulock’s $25 million raise for contextual AI security, the expanding MCP spec bringing new enterprise risks, and a new macOS malware strain that plants fake errors to throw off AI analysis. Other key stories covered Robinhood speeding up access approvals, Poland’s SIM-swapping gang bust tied to millions in crypto theft, and Microsoft extending free Windows 10 ESU support to October 2027.
#Nebulock #MCP #macOS #Robinhood #Philip Martin #Uber #Akrites #Poland #SIMSwapping #Bluekit #Cellebrite #FCC #CISA #Windows10ESU #Chrome #Shop #PirloTV #TataElectronics #Snyk