Developers in the Crosshairs: Fake AI Tools Deliver Infostealer

Netskope Threat Labs reported a NodeJS-based MaaS infostealer campaign delivered through ClickFix and trojanized GitHub repositories that impersonated AI and developer resources. The operation used a multi-stage SmartLoader chain with EtherHiding on the Polygon blockchain to resolve C2 at runtime and targeted developers across North America, Asia, and Southern Europe. #NetskopeThreatLabs #SmartLoader #EtherHiding #Polygon #ClickFix #Claude #ComfyUI #GitHub

Read More
Targeted Attack on Government Entities in the Middle East | Part 2

Zscaler details BINDCLOAK, a new 64-bit modular Windows backdoor that appears to be a variant of OctLurk and was delivered through MIXEDKEY in a multi-stage attack against government entities in the Middle East. The report also links the campaign to shared C2 infrastructure, reflective DLL loading, token abuse, and encrypted TLS-over-TCP communications used by the same threat actor behind OctLurk. #BINDCLOAK #OctLurk #MIXEDKEY #TELESHIM #cert.hypersnet.com #about.blsouqs.com #ftabnews.com

Read More
Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums

Bitdefender researchers uncovered a Java-based malware campaign that impersonates an “undetected” Xeno Roblox script executor and spreads through gaming forums and Discord communities. The payload steals browser cookies, Discord, Roblox and Minecraft accounts, crypto-wallet and payment data, while also enabling keylogging, webcam access, desktop streaming, file manipulation, PowerShell execution, and remote…

Read More
Access For Sale: Inside a Russian-Speaking Access Broker’s Dual Operation

An exposed server tied to a Russia-nexus operator exposed months of activity showing high-volume initial access brokerage, broad exploitation of appliances, credential theft, and full Active Directory compromise across many sectors worldwide. The same operator later used Sliver C2 for targeted collection against Ukrainian defence and aerospace organisations, including theft from Git repositories and imagery from thousands of exposed IP cameras, with the activity aligning to AIVD/MIVD warnings about Russian camera surveillance. #Sliver #AIVD #MIVD #Fortinet #F5 #Citrix #SonicWall #SAP #HikVision #Neo-reGeorg

Read More
Octagon: Technical Analysis of a Fake Bahrain Civil Defense Application

Octagon is a multi-stage Android threat that impersonated the BH Alert emergency app to target users in Bahrain and deploy dynamically loaded DEX/JAR payloads. It abuses VPN, Accessibility, and AccountManager/Sync Adapter features to persist, capture credentials, intercept data, and communicate with a C2 server at 209[.]99[.]184[.]50:4444. #BHAlert #Octagon #com.kisa.octagonpanel #com.kit.kitty #ZfChs.dex #ZGdSEl.jar #alertbh.info

Read More
Alert Zero: AI-driven alert triage and attack investigation for the agentic SOC

Elastic Security 9.5 introduces Alert Zero tools that help SOC teams reduce alert fatigue by automating triage, correlating related alerts, and embedding investigations into existing workflows while keeping analysts in control. The update centers on Security alert analysis, Attack Discovery, and Elastic Workflows, with support for custom models, inspectable agent reasoning, and approved detection-gap remediation. #ElasticSecurity #AttackDiscovery #ElasticWorkflows #ESQL #VirusTotal

Read More
The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version

XCSSET v40 is a heavily updated macOS malware family that uses memory-resident execution, polymorphism, and supply-chain infection through poisoned Xcode projects to target developers. It also adds browser hijacking, Telegram trojanizing, defense evasion, and a rotating C2 infrastructure across domains, IPs, and endpoints. #XCSSET #Xcode #GoogleChrome #Telegram #Apple…

Read More
Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise

Google Threat Intelligence Group (GTIG) reports a sharp rise in open source software supply chain compromise in 2025 and early 2026, including major campaigns tied to UNC6780, MIDNIGHT NEPTUNE, and UNC4899. The article also outlines detailed mitigation guidance for protecting ecosystems such as PyPI, npm, Docker Hub, GitHub Actions, and developer pipelines from package poisoning, credential theft, and workflow abuse. #UNC6780 #MIDNIGHTNEPTUNE #UNC4899 #axios #PyPI #npm #DockerHub #GitHubActions

Read More
Network Anomaly Detection in KATA

The article explains how Kaspersky Anti Targeted Attack (KATA) uses Network Anomaly Detection to identify Kerberoasting and DNS tunneling by spotting deviations from normal Kerberos and DNS behavior rather than relying on signatures. It also shows how prebuilt NAD rules, variables, and SQL-based logic help reduce false positives and surface actionable alerts for attacks that blend into legitimate network traffic. #KATA #Kerberoasting #DNStunneling #Kerberos #DNS

Read More
A DNS Investigation of LenAI’s ErrTraffic ClickFix Distribution Network

Sekoia researchers analyzed a new ErrTraffic ClickFix campaign that targeted WordPress servers, used fake AI tool lures, and hid C&C infrastructure in blockchain-based networks. Their DNS and WHOIS investigation uncovered 71 domains, multiple malicious IPs, typosquatting clusters, and possible links to the LenAI MaaS operator and the Aeternum botnet. #ErrTraffic #ClickFix #LenAI #Aeternum

Read More
Phishing Scam Targeting Drivers: Il Portale dell’Automobilista Ranked Among Google’s Top Results

CERT-AGID identified a phishing campaign that impersonates “Il Portale dell’Automobilista” through the typosquatted domain illportaledelautomobilista[.]org, which appears prominently in Google search results. The fake site steals personal and driver-license data such as codice fiscale, numero patente, and expiration date, while CERT-AGID has requested takedown actions and alerted Google and the Ministry of Infrastructure and Transport. #CERTAGID #IlPortaledellAutomobilista #MinisterodelleInfrastruttureeDeiTrasporti #illportaledelautomobilistaorg

Read More
Two ways to scale your scripts

The article explains that operational scripts on customer endpoints should be governed like production software, whether they are cloned, hand-written, or AI-generated. It highlights two scaling models—template reuse and AI-assisted authoring—showing that Acronis built-in scripts are heavily cloned while AI-generated scripts are increasingly common in some markets, requiring different governance controls for each. #Acronis #NISTSP800-53 #CISControlsv8 #OWASP #ENISA

Read More
OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia

The article describes OctLurk, SilkLurk, and LurkProxy, three closely related implants used since January 2025 against government and other organizations across Central Asia and the Syrian Arab Republic, with victim-specific loaders and heavy obfuscation. The same campaign also included credential theft, keylogging, browser password theft, network scanning, remote access, and the later deployment of PlugX, while infrastructure overlap and shared artifacts suggest a Chinese-speaking threat actor. #OctLurk #SilkLurk #LurkProxy #PlugX

Read More
Not Every Fox is Silver: Inside an AtlasRAT loader chain

AtlasRAT is a modular Windows RAT delivered through a four-stage in-memory loader chain, beginning with a Delphi executable disguised as AGE Flash Player and ending in TLS-based, ChaCha20-encrypted command-and-control with plugin execution, offline keylogging, and DLL injection into WeChat processes. Analysis suggests a builder-based malware framework with multiple versions and branches,…

Read More