Threat Research | Weekly Recap [23 Aug 2026]

Threat Research | Weekly Recap [23 Aug 2026]

Cybersecurity Threat Research ‘Weekly’ Recap. This week covered government/health phishing schemes for refund and reimbursement theft, plus Microsoft 365 session hijacking via AiTM tooling and broader crypto fraud using fake AML checkers, wallet apps, and stealer pipelines. Across malware delivery, supply chain, and cloud/identity abuse, researchers tracked campaigns involving ToxicPanda 2.0, ClearFake-to-Amatera chains, StopAndProtect WordPress intrusions, and covert infrastructure using BOFScale and Cloudflare Workers, alongside defensive guidance and emerging AI security benchmarking (EchoBench, AVDH).
#Mirage2FA #OperationASTERIX #ToxicPanda #ClearFake #Amatera #StopAndProtect #BRIDGEHEAD #BOFScale #CloudflareWorkers #EchoBench #BTRsys #Cruciferra

Phishing, Fraud & Account Theft

Malware Delivery, Loaders & Banking Trojans

Supply Chain & Developer Ecosystem Attacks

Cloud, Identity & Covert Infrastructure

Windows, Kernel & Defender Abuse

AI Security, Agentic Research & Benchmarking

Policy, Risk & Infrastructure Defense

Threat Research | Weekly Recap – hendryadrian.com