Daily Recap, UK cyber officials report they are handling four major incidents per week amid rising nation-state activity from Russia, Iran and China, while the EU imposes sanctions on Russian propaganda networks and Ukraine exposes a bot farm supplying thousands of fake Telegram accounts to Russian spies. Ransomware cases surface in legal actions around BlackCat/ALPHV and insider-leakage details, while GoGra Linux backdoor abusing Microsoft Graph API and an npm supply-chain attack on Namastex Labs highlight evolving threats, alongside the Vercel breach via Context.ai.
#BlackCat #GoGra
#BlackCat #GoGra
State & Geopolitics
- UK cyber officials say they are handling four major incidents a week amid a surge in nation-state activity from Russia, Iran and China – UK Incidents, UK Threats
- The EU imposed new sanctions on two Russian propaganda networks, while Ukraine said it busted a bot farm supplying thousands of fake Telegram accounts to Russian spies – EU Sanctions, Ukraine Bot Farm
- China-linked Mustang Panda shifted to targeting Indian banks with spear-phishing and LotusLite, showing espionage groups are broadening into financial-sector collection – Mustang Panda
- French government agencies confirmed a breach as data was offered for sale online, adding to a week of public-sector incident disclosures – French Breach
Ransomware & Crime
- Former ransomware negotiators including Angelo Martino pleaded guilty to helping BlackCat/ALPHV extort victims, exposing how insiders leaked negotiation details and contributed to roughly $75.3 million in extorted payments – Martino Guilty, BlackCat Scheme, Scattered Spider, Ransomware Insider, BlackCat Plea
- Scattered Spider figure Tyler Robert Buchanan admitted to phishing and SIM-swap attacks that stole more than $8 million in cryptocurrency and thousands of credentials – Buchanan Plea
- The Gentlemen ransomware operation used SystemBC infrastructure tied to more than 1,570 compromised corporate networks, while lawmakers continue debating harsher responses to hospital ransomware attacks – SystemBC C2, Hospital Ransomware
Microsoft & Enterprise Security
- Microsoft issued emergency patches for CVE-2026-40372, a critical ASP.NET Core flaw that could let attackers gain SYSTEM privileges, and warned customers to rotate DataProtection keys – ASP.NET Fix, Emergency Patch
- Microsoft SharePoint admins are still exposed to active spoofing attacks via CVE-2026-32201, with more than 1,300 servers vulnerable and fewer than 200 reportedly patched – SharePoint Spoofing
- Microsoft also traced Universal Print failures to a Graph API code change, while rolling out Teams efficiency features and expanded OneDrive AI/compliance updates – Universal Print, Teams Update, OneDrive Update
- A new GoGra Linux backdoor used Microsoft Graph API and hardcoded Azure AD credentials for covert command-and-control, highlighting abuse of cloud identity services – GoGra Backdoor
Supply Chain & Vulnerabilities
- A malicious npm supply-chain attack compromised Namastex Labs packages, stole auth tokens and secrets, and tried to self-propagate across ecosystems including PyPI – npm Attack
- Oracle shipped 481 patches in its April 2026 CPU, covering about 450 CVEs with more than 300 remotely exploitable bugs across major product families – Oracle CPU
- CISA added multiple actively exploited flaws to its KEV catalog, including Cisco Catalyst SD-WAN Manager bugs such as CVE-2026-20133, along with issues in PaperCut NG/MF, JetBrains TeamCity, Quest KACE and Zimbra – CISA KEV, SD-WAN Flaw
- More than 20,000 Lantronix and Silex serial-to-IP converters are exposed by 22 BRIDGE:BREAK flaws, widening attack surface for industrial and remote-access environments – Bridge Flaws
- VirtualBox 7.2.8 landed with crash fixes, graphics, clipboard and UEFI repairs, plus support for newer Linux kernels – VirtualBox 7.2.8
Cloud, AI & Platform Abuse
- Vercel said it was breached through a compromised third-party AI tool, Context.ai, leading to access of an employee Google Workspace account and prompting customer credential resets – Vercel Breach
- Google Antigravity was patched for a sandbox-escape flaw, while criminals also used a fake site to distribute a trojanized installer that stole browser data and wallets – Antigravity Attack
- OpenAI is testing Chronicle for Codex, a screen-memory feature that raises privacy and prompt-injection concerns because it stores recent screen captures locally – Chronicle
- Tencent launched QClaw, an AI agent app for Windows and macOS, as the enterprise AI assistant race continues – QClaw AI
Threats, Botnets & DDoS
- Mastodon suffered a major DDoS attack that hit Mastodon.social shortly after a similar disruption to Bluesky, underscoring ongoing pressure on decentralized platforms – Mastodon DDoS
- ProxySmart-powered SIM farms were found across 17 countries and 94 locations, using mobile proxies, IP rotation and fingerprint spoofing for likely fraud and account abuse – SIM Farm
- Ofcom opened probes into Telegram and teen chat sites over alleged child safety and grooming failures under the UK Online Safety Act – Telegram Probe
Malware & Mobile/Endpoint Intrusions
- Lotus, a previously undocumented data wiper, was used against Venezuelan energy and utility firms to disable defenses and make systems unrecoverable – Lotus Wiper
- Cisco Talos reported that phishing reclaimed the top initial-access spot, while attackers also abused the AI builder Softr, exposed GitHub tokens, and weak MFA and logging to reach cloud environments – Talos Phishing