OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack

Socket researchers found that @7nohe/openapi-react-query-codegen was compromised with ten malicious npm versions published through an abused comment-triggered GitHub Actions workflow, and the latest tag still resolved to a poisoned release at the time of reporting. The payload installs a large obfuscated loader that steals cloud, registry, GitHub Actions, and AI-related secrets while showing self-propagation behavior consistent with Mini Shai-Hulud. #MiniShaiHulud #openapi-react-query-codegen #GitHubActions #npm #SocketThreatResearchTeam

Read More
A DNS Infrastructure Analysis of a Microsoft 365 Device Code Phishing Campaign

ReversingLabs documented a Microsoft 365 device code phishing campaign that abused the legitimate OAuth 2.0 Device Authorization Grant flow to trick victims into authorizing attacker-controlled devices instead of entering passwords on a fake login page. The investigation uncovered 290 IoCs across domains, subdomains, IPs, and email-connected infrastructure, with evidence pointing to a coordinated operation involving typosquatting, brand impersonation, and disposable redirector hosts. #Microsoft365 #OAuth20DeviceAuthorizationGrant #ReversingLabs

Read More

A malicious LNK sample appears to target a Russian-speaking victim, using a decoy CommuniGate Pro implementation questionnaire aimed at Delovye Linii. The infection chain downloads a tar archive, launches a second LNK, and sideloads calibre-launcher.dll to contact www.ncloudtechlab[.]online and retrieve additional payloads. #CommuniGatePro #DelovyeLinii #ncloudtechlabonline #calibrelauncherDLL

Read More
Still Circling: Inside the Operator Behind Blind Eagle’s GitHub Loader

The investigation traced a GitHub staging account to an email address that also appeared in a stealer log, confirming the operator’s workstation was compromised and exposing its files, browser history, and build artifacts. Those artifacts revealed a broader Blind Eagle-style operation involving RATs, phishing templates, bulk email tooling, crypters, and infrastructure across GitHub, DuckDNS, Bitbucket, AWS S3, and related services. #BlindEagle #AsyncRAT #DcRat #Remcos #XWorm #GitHub #DuckDNS #Bitbucket #AWS_S3

Read More
Gryxa: The AI-Built Toolkit That Watches How You Remove It

ReliaQuest reports Gryxa, a new toolkit used by a financially motivated threat actor to maintain access across 324 listed hosts, and assesses that much of it was built with a commercial AI coding agent. The toolkit uses RMM abuse, layered persistence, credential theft, and response-aware countermeasures, while collecting Windows logs and host artifacts after defenders try to remove it. #Gryxa #ReliaQuest #Chromium #MicrosoftDefender #Telegram

Read More
19 Chrome and Edge Extensions Deliver a Wallet Drainer and Credential-Stealing Payloads

Socket uncovered 19 malicious Chrome and Edge extensions tied to the “Superior” campaign, which uses an extendable malware framework to steal wallet secrets, drain crypto, and harvest credentials through WebSocket-based C2, CSP stripping, and XSS-style injection. The campaign weaponized both threat-actor-created and legitimately purchased extensions, including “Enable Right Click & Copy — Smart Unlock + OCR,” and has expanded across multiple domains, payloads, and browser ecosystems. #Superior #EnableRightClickCopy #PreppHint #ChromeWebStore #MicrosoftEdge

Read More
Threat Intelligence Report: University Leak Exposes Russia’s Military Cyber Training Pipeline

Leaked records indicate that Bauman Moscow State Technical University’s Department No. 4 served as a long-term training pipeline for GRU cyber and intelligence personnel, with students funneled into specialties tied to special intelligence, operational cyber effects, and information-technology protection. The material also links graduates and supervisors to GRU units 26165, 74455, and 29155, and includes evidence of malware analysis, phishing, intrusion reconstruction, and other cyberwarfare instruction. #GRU #APT28 #Sandworm #MilitaryUnit26165 #MilitaryUnit74455 #DepartmentNo4

Read More
Caught in 4K: The Aurora Files

An exposed directory exposed months of activity by a Russian-speaking Aurora ransomware affiliate who compromised more than twenty organisations across nine countries between April and July 2026 and then deployed Aurora encryptors written in Zig. CloudSEK and TRM Labs traced a ransom negotiation and multiple victim payments through shared laundering infrastructure, tying the operator directly to Aurora rather than a broker and linking four victims to Aurora’s public leak site. #Aurora #TRMLabs #CloudSEK #Zig

Read More
BlueDelta Targets Defense and Diplomacy with HOOKEDGE

Insikt Group identified BlueDelta initial access campaigns from late September 2025 to early April 2026 that targeted government and diplomatic organizations in Romania, Spain, and Türkiye using macro-enabled Word documents to deliver the HOOKEDGE backdoor. HOOKEDGE relies on webhook[.]site, Microsoft Edge, scheduled tasks, and staged batch-script execution, and the activity overlaps heavily with the earlier HEADLACE malware and the BlueDelta cluster associated with APT28, Fancy Bear, and Forest Blizzard. #BlueDelta #HOOKEDGE #HEADLACE #APT28 #FancyBear #ForestBlizzard #webhooksite

Read More
Inhospitable: Tracking Russian Cyber Espionage Infrastructure

Google Threat Intelligence Group research on Russian-aligned espionage clusters showed how infrastructure, registration data, CSS, favicon, and DNS pivots can reveal additional related domains used for phishing and decoy sites. The article highlights UNC6293, UNC7005, and UNC5976, along with lookalike domains and proxy infrastructure tied to OAuth phishing, device code phishing, and deceptive redirects. #UNC6293 #UNC7005 #UNC5976 #foreignrelationsus #stateaffairsus #verifydrivecom

Read More
Why Trust is the New Attack Surface: Mid-Year Threat Update 2026

Darktrace says the first half of 2026 was defined by attackers abusing trusted identities, SaaS, cloud entitlements, AI systems, and supply-chain relationships rather than relying on traditional exploitation, with one React2Shell honeypot compromised in under two hours. Campaigns involving StealC, AMOS, Phexia, Axios, Trivy, Hola VPN, BeyondTrust, and JadePuffer showed how quickly trust-based tradecraft, AI-generated malware, and supply-chain abuse are reshaping intrusion paths. #React2Shell #Darktrace #StealC #AMOS #Phexia #Axios #Trivy #HolaVPN #BeyondTrust #JadePuffer

Read More
Testing a Prompt injection Attack Against an Enterprise AI Agent

Darktrace detected and quarantined a prompt injection email before a Gemini AI agent in Google Cloud could process it, showing that natural-language attacks can bypass traditional signature-based defenses. The article also highlights EchoLeak (CVE-2025-32711) and GTG-1002 as examples of how AI-driven threats and social engineering are making behavioral detection essential for securing enterprise AI systems. #EchoLeak #CVE-2025-32711 #Gemini #GoogleCloud #Darktrace #GTG-1002

Read More
Cambodia-focused cluster uses multistage infection chain with localized lures

Acronis TRU uncovered a Cambodia-focused campaign that uses phishing-style archives, DLL sideloading, PNG-embedded payloads, BYOVD, and process injection to deploy SparkRAT while impairing multiple security products. The activity shows similarities to SilverFox tradecraft but lacks enough evidence for direct attribution, so it is tracked as an unattributed cluster with possible Chinese-language development or deployment links. #SparkRAT #SilverFox #CVE-2026-36425 #ardrv.sys #OPSWATAppRemover #HuorongInternetSecurity #TencentPCManager

Read More
THE TRUST CASCADE

CYFIRMA’s report shows how identity compromise, delegated SaaS access, agentic infrastructure, and data-theft objectives can combine into composable attack surfaces across cases like Vercel/Context.ai, Salesloft/Drift, Taiwan, and EchoLeak. It emphasizes that the Policy/Authorization Control Plane and non-human identity governance are high-leverage defenses, while standards such as AIMS and Cross App Access are emerging to close the gap. #Vercel #Contextai #Salesloft #Drift #EchoLeak #AIMS #CrossAppAccess

Read More