Team Cymru validated active Cluster A phishing infrastructure linked to Push Security’s research on ShinyHunters and BlackFile, confirming Mevspace-hosted domains, a Doko-branded artifact, and recurring victim-themed naming patterns. The analysis surfaced more than 40 additional domains and highlighted how phishing panels are built from hosted infrastructure, certificates, exposed services, and reusable…
Category: Threat Research
Elastic Security Labs identified a Shai-Hulud campaign that compromised the keyv maintainer and spread a self-propagating CHAINDROP worm through trojanized npm packages, affecting hundreds of packages and exposing a massive developer ecosystem. The operation steals credentials, uses smart-contract-based C2 resolution and GitHub-backed fallback exfiltration, and targets AI, cloud, GitHub, SSH, Kubernetes, and npm secrets. #ShaiHulud #CHAINDROP #keyv #Claude #OpenAI #Anthropic #npm-cache.com #awqhnjewqjkl.icu
AhnLab SEcurity intelligence Center linked Larva-26005 to Xctdoor campaigns in Korea, including 2026 attacks disguised as Veraport and SoftCamp installers and LNK-based phishing cases that delivered XcLoader and Xctdoor. The report also connects these operations to earlier CRAT activity, Hansom ransomware, Ngrok, and Lazarus-related tradecraft, while listing related IOCs such as…
Unit 42 reports a surge in AI token jacking, where attackers steal legitimate API keys to rack up massive usage charges through transfer stations and gray-market proxy services. The article explains how stolen tokens, compromised developer accounts, and supply-chain infections like Shai-Hulud and Miasma fuel the abuse, while recommending spending limits,…
CERT-AGID identified and disrupted a fraudulent website impersonating ARERA to trick users into revealing personal and financial data through a fake refund tied to the social water bonus. The site used typosquatting and a staged flow that led victims from a phone-number check to a bogus credit card verification page. #ARERA #CERT-AGID #bonussocialeidrico
Sysdig Secure AI uses agentic cloud security to continuously triage vulnerability backlogs, trace 2,731 SLA-breaching findings in a Node.js base image to one fix, and route the remediation through human approval into Jira ticket DEJI-342. The same capability also runs headless in Claude via the Sysdig MCP server, using runtime data to prioritize issues by exploitability, KEV status, and reachability. #SysdigSecureAI #Jira #Claude #SysdigMCPServer #DEJI342
A single PDF factory has produced more than 12,700 structurally similar FakeCaptcha documents on Webflow’s CDN, where they appear in Google search as ordinary “upgrade guides” and feed a traffic-distribution system. The campaign routes qualified visitors to malware, scam, or reseller infrastructure while using rotated lure domains, ww80/wwNN routers, and a custom Elixir/Phoenix gate to keep the operation active. #FakeCaptcha #Webflow #GoogleGemini #Claude #LegionLoader #berapt-medii #yfdpco
A threat actor compromised hundreds of npm packages on August 4, 2026 and used them to distribute a self-propagating backdoor that spreads in ways similar to the Shai-Hulud npm worm. The campaign affected popular packages such as Keyv, Cacheable, and Ecto, and used multiple propagation, exfiltration, and credential-theft paths across npm, GitHub, cloud, and CI environments. #Keyv #Cacheable #Ecto #ShaiHulud
CERT-AGID identified a phishing campaign that abuses the names and visuals of Polizia di Stato and pagoPA to trick victims into paying a fake traffic fine. The fraudulent flow collects vehicle plate data, tax code, email address, and payment card details, while domains containing “poliziadistato” were used to host the fake pages. #PoliziaDiStato #pagoPA #CERTAGID
July featured major security developments including the first agentic ransomware operation attributed to JADEPUFFER, a new US vulnerability coordination body called GOLD EAGLE, and an AI-assisted breach at Hugging Face involving OpenAI agents. The month also saw Azure tenant takeover abuse, ENCFORGE ransomware targeting AI/ML assets, and several high-profile breaches affecting FastJson, Abbott Laboratories, Accenture, and Fairlife. #JADEPUFFER #GOLDEAGLE #HuggingFace #OpenAI #ENCFORGE #FastJson #AbbottLaboratories #Accenture #Fairlife
Elastic built an AI-assisted bug bounty triage system to handle a surge of AI-generated HackerOne reports, using multi-stage analysis, adversarial review, and sandboxed reproduction on ephemeral Google Cloud VMs. The system agrees with human security engineers 85% of the time and uses Elastic-specific triage rules to distinguish real issues from features or out-of-scope reports while keeping a human in the final decision loop. #HackerOne #Elastic #Claude #ElasticWorkflows #GoogleCloudPlatform #Elasticsearch #Kibana
Socket is tracking an active supply chain compromise in the keyv and cacheable npm ecosystems, where trojanized packages used a malicious preinstall hook to download Bun, steal cloud and CI credentials, and republish infected packages through stolen npm tokens. The campaign affected tens of millions of weekly downloads and also planted persistence in developer and AI coding environments via .claude and .vscode hooks. #keyv #cacheable #Jaredwray #Bun #npm #GitHubActions #HashiCorpVault
July 2026 attacks showed how trusted business workflows, legitimate platforms, and built-in tools were abused to drive account takeover, data theft, fraud, and persistent access across the US, Europe, and Brazil. ANY.RUN highlighted campaigns involving Kratos, PhantomEnigma, Kali365, Banana RAT, DARTHVADER Stealer, OVERLORD RAT, DestinyStealer, and fake Zoom event lures that…
Unit 42 found that nearly half of malware samples with command-and-control activity make direct-to-IP connections, bypassing DNS and exposing a major visibility gap in traditional defenses. The report highlights ZT-IP detections for Phorpiex, SectopRAT, Mozi, and Boatnet activity, plus an obfuscated GET exfiltration campaign and hard-coded IP-based infrastructure. #Phorpiex #SectopRAT #Mozi…
Aqua detected a multistage fileless XMRig cryptojacking campaign targeting containerized Node.js applications built with Next.js, exposing malicious activity across in-memory execution, container drift, persistence, and outbound mining communication. The campaign used tactics like memfd-based loading, cron and rc.d persistence, SSH key backdoors, and anti-removal defenses, while Aqua runtime enforcement could block the attack before unauthorized code ran or mining traffic left the workload. #XMRig #Nextjs #Aqua #memfd #Nodejs