From BleepingComputer · 40 stories
ReliaQuest employee targeted in social engineering attack by ShinyHunters
Cybersecurity firm ReliaQuest confirmed that an employee was targeted in a social engineering attack by the ShinyHunters group, which attempted to gain access to internal systems. Although one employee entered credentials on a fake SSO page, device-trust controls prevented the attackers from accessing applications or customer data. This incident highlights the ongoing threat of social engineering and the importance of multi-layered security controls.
ToxicPanda 2.0 Android Malware Expands Global Banking and Cryptocurrency Targeting
The Android banking malware ToxicPanda has been updated to version 2.0, significantly expanding its targeting scope to over 140 banking and cryptocurrency applications globally, up from 16. This new version includes 167 remote commands, improved credential harvesting, and new methods for privilege escalation and evading battery optimization policies, posing an increased threat to Android users.
Ransom Busters Affiliate Claims Hacking Ransomware Servers, Demands Payment from Victims
A ransomware affiliate named Ransom Busters is emailing victims, claiming to have hacked ransomware group servers and offering to delete stolen data for $20,000 to $60,000. This activity is unusual as it involves a third party proactively contacting victims with an offer to recover data and delete backups held by ransomware groups. The practice raises legal concerns under the U.S. Computer Fraud Abuse Act.
Microsoft tests faster File Explorer and customizable context menu in Windows 11 preview
Microsoft is testing a faster File Explorer and a redesigned, customizable context menu in Windows 11 preview builds. These updates aim to improve performance, reliability, and user experience by reducing clutter and offering more control over menu options.
New Android Malware WindRelay and SpyNote Steal Credit Card Data and Facilitate Loan Fraud
A new Android NFC relay malware, WindRelay, is being used with the SpyNote remote administration tool (RAT) to steal credit card data and take out loans in victims' names. This combination allows attackers to gain remote access to devices and relay live NFC transactions, enabling real-time financial fraud.
Seven Arrested in €30M Commerzbank Fraud Exploiting Service Provider Flaw
Seven individuals have been arrested in Brazil and Europe in connection with a €30 million bank fraud that impacted Commerzbank customers in November 2023. The fraud exploited a vulnerability in a service provider's system, leading to unauthorized withdrawals, though Commerzbank states customers suffered no financial losses.
RingCentral Data Breach Impacts 1.6 Million Accounts After Social Engineering Attack
RingCentral experienced a data breach in July, affecting 1.6 million individuals, following a "sophisticated social engineering campaign." The ShinyHunters extortion group claimed responsibility and leaked data after RingCentral did not meet their demands, leading to the information being added to HaveIBeenPwned.
Trezor Customers Affected by Data Breach at Shipping Partner ShipMonk
Hardware wallet manufacturer Trezor disclosed a data breach impacting nearly 14,000 customers after its shipping provider, ShipMonk, experienced unauthorized access to its systems. The incident exposed customer order data, including names, addresses, emails, and phone numbers, for orders placed between May 10 and August 8, 2026. Trezor's own systems were not compromised, but the breach raises concerns about potential phishing attempts targeting affected users.
AI Watermark Removal Tools Emerge, Efficacy Unverified Against Text Watermarks
A market for tools claiming to remove AI watermarks has appeared following Anthropic's announcement of invisible watermarks in Claude's output. However, the efficacy of these tools against text watermarks cannot be verified because Anthropic has not released details on its watermarking method or a corresponding detector. This development highlights the ongoing challenge of verifying AI-generated content and the rapid response from developers to new AI features.
Hundreds of Fake Chrome VPN Extensions Route User Traffic Through Proxies
Security researchers identified 737 Chrome VPN extensions that routed user browser traffic through a single SOCKS5 proxy infrastructure. These extensions, downloaded nearly 75,000 times and primarily targeting Russian-speaking users, impersonated legitimate VPN brands, allowing an adversary-in-the-middle to observe browsing activity and data.
Researchers demonstrate 'Plug And Pwn' attack for Windows SYSTEM access via USB auto-install
Security researchers Alejandro Hernando and Borja Martinez have unveiled "Plug And Pwn" attacks that exploit the Windows Plug and Play (PnP) feature to achieve SYSTEM-level code execution. This method abuses the automatic installation of vendor software for emulated USB devices, allowing an unprivileged user to gain high-level access on Windows 11 machines. The attack can be triggered physically or remotely under specific conditions.
Cloudflare Reports 519% Surge in 1 Tbps DDoS Attacks in Q2 2026
Cloudflare's H1 2026 DDoS Threat Report indicates a 519% quarter-over-quarter increase in network-layer DDoS attacks exceeding 1 Tbps between Q1 and Q2 2026. The report, based on data from Cloudflare's network, highlights a shift in attack vectors, with DNS-based attacks becoming the primary method, and notes the influence of geopolitical events on the threat landscape.
BdThemes WordPress Plugins Removed After Supply Chain Attack Creates Rogue Admins
A supply chain attack on BdThemes, a WordPress plugin vendor, led to the compromise of their infrastructure and the modification of a remote JSON feed. This allowed attackers to create rogue administrator accounts on WordPress sites using affected plugins, prompting WordPress.org to remove all BdThemes products, impacting over 350,000 active installations.
UK Man Sentenced for Blackmail and Sextortion of 117 Victims as Part of 'The Com'
Justin Swaddle, a 20-year-old from Leeds, was sentenced to two years in prison for blackmail and sextortion offenses against 117 victims aged 13 to 17. Operating under aliases like 'Epstein' and 'Moscow' on platforms including Snapchat, Telegram, and Discord, Swaddle was a member of 'The Com,' an online collective whose members coerce victims into self-harm and sexual activity for peer status.
North Carolina Ports Hit by Cyberattack, Forcing Manual Operations
North Carolina Ports experienced a cyberattack that disrupted IT systems and forced a shift to manual operations across its three locations: Wilmington, Morehead City, and Charlotte. The incident, detected on August 4, led to system-wide outages and delays, though operations are gradually returning to normal with manual processing still in effect. This event highlights the ongoing vulnerability of critical infrastructure to cyber threats.
77 Malicious "Evil Twin" Extensions Removed from Open VSX Marketplace
Manifold Security discovered 77 malicious "evil twin" extensions on the Open VSX marketplace between July 26 and August 1, 2026. These extensions mimicked legitimate developer tools and exfiltrated system and development environment information, leading to their removal from Open VSX on August 3, 2026.
Greatness PhaaS Adds Device Code Phishing, Targets Microsoft 365 Accounts
The Greatness phishing-as-a-service (PhaaS) toolkit now supports device code phishing, exploiting the OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and compromise user accounts. This update allows attackers to steal MFA-approved authentication tokens and maintain access to compromised accounts, posing a greater threat to online security. The platform is sold for $289 per month and targets platforms including Microsoft 365, iCloud, Yahoo, and Google Workspace.
Amgen Discloses Data Breach Affecting Patient Health and Proprietary Information
Biotechnology company Amgen reported a data breach where threat actors stole corporate data and patient information from third-party cloud systems. The unauthorized activity was detected in July 2026, leading to an ongoing investigation into the scope of the exfiltrated data, which includes proprietary information and protected health information.
ShinyHunters Leaks Brinks Home Data After Breach Affecting 4.9 Million Records
Brinks Home, a residential security company, experienced a data breach identified on July 20, with the ShinyHunters extortion group claiming responsibility. ShinyHunters has leaked over 41 gigabytes of data, including 4.9 million Salesforce records with personally identifiable information (PII), after Brinks Home did not pay a ransom. The breach did not affect alarm monitoring or system functionality.
Arch Linux Disables AUR Package Adoption and Pushes Due to Malware Influx
Arch Linux has disabled package adoption and pushes in its Arch User Repository (AUR) following an increase in malicious package adoptions and commits. This measure was taken to prevent the spread of malware, including remote-access trojans (RATs) and info-stealers, which attempt to upload user data and spread laterally across systems. The disablement is temporary while the Arch Linux DevOps team addresses the security situation.
Coordinated Cyberattack Impacts Over 30 Minnesota Water Systems
A coordinated cyberattack targeted the operational technology of more than 30 community water systems in Minnesota on July 26 and 27. The attack caused outages and communication failures, with Braham's water plant going offline and other cities like Plymouth, South St. Paul, and Maple Plain experiencing affected automated controls or cellular communication issues. The incident prompted a statewide cybersecurity response involving Minnesota IT Services (MNIT).
CISA and ACSC Release Guidance for Isolating Critical Infrastructure OT Systems During Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Australian Cyber Security Centre (ACSC) have issued joint guidance, "CI Fortify – Advice for isolating vital systems," for critical infrastructure organizations. This guidance advises preparing to isolate operational technology (OT) systems from less trusted networks to maintain essential services during cyberattacks or other disruptions, addressing threats from state-sponsored actors.
Dysphoria IoT Botnet Uses Blockchain for C2 After JackSkid Disruption
The Dysphoria IoT botnet has adopted blockchain-based name services and infected-device relays for command-and-control (C2) following a March law enforcement operation against its predecessor, JackSkid. Researchers from CNCERT and Qi'anxin's XLab estimate the botnet to have over 200,000 bots, using them for distributed denial of service (DDoS) attacks and traffic relay operations. This architectural change makes the botnet more resilient to disruption by obscuring the location of its controllers.
Dolphin X Malware Uses AI Profiling to Rank High-Value Targets
A new remote access trojan named Dolphin X incorporates an "AI Profiler" feature to score and rank infected users, helping cybercriminals prioritize victims. This development allows attackers to automate the identification of high-value targets from a large pool of compromised accounts, potentially increasing the efficiency of cyberattacks.
Chick-fil-A reports data breach from credential stuffing attacks
Chick-fil-A has alerted customers about a data breach caused by credential stuffing attacks affecting accounts. The breach may involve sensitive information like names, email addresses, and partial credit card numbers.
Upbound Group discloses $13M fraud in Acima leases following data breach
Upbound Group reported a cybersecurity incident where threat actors stole non-sensitive customer information and documents, leading to $13 million in fraudulent Acima lease-to-own agreements. The stolen data was used to obtain goods, resulting in financial losses for the company when fraudsters failed to make payments. Upbound has implemented enhanced security measures and notified federal law enforcement.
Swiss rail manufacturer Stadler rejects $12.3M ransom demand after cyberattack
Swiss rail vehicle manufacturer Stadler Rail rejected a $12.3 million ransom demand from the Everest ransomware gang following a data breach on a platform shared with a supplier. The company reported no impact on its IT systems or production operations, and stated only non-security-relevant technical information was stolen, demonstrating a firm stance against cyber extortion.
South Korea's diplomat training system breached by hackers for 9 months
Hackers compromised South Korea's diplomatic academy's e-learning platform for nine months, exposing employee data. This breach raises serious cybersecurity concerns, especially given the country's past experiences with North Korean cyberattacks.
Authorities Shut Down Kratos Phishing-as-a-Service Platform, Arrest Developer
German and U.S. authorities dismantled the Kratos phishing-as-a-service platform, used for Microsoft 365 phishing campaigns, and arrested its developer in Indonesia. The platform had 1,800 users running 15,000 campaigns monthly, significantly affecting global cybersecurity due to its ability to bypass multifactor authentication.
23andMe Settles $18 Million Data Breach Case Across 42 States
23andMe will pay $18 million to settle claims from 42 states over a data breach affecting 6.9 million users, including genetic data. The settlement requires enhanced cybersecurity measures and accountability going forward. This settlement follows issues of inadequate data protection and significant delays in breach notifications.
Qilin Ransomware Gang Exploits Patched PAN-OS VPN Vulnerability
The Qilin ransomware gang is exploiting a critical flaw (CVE-2026-0257) in Palo Alto Networks' PAN-OS GlobalProtect to gain unauthorized access and deploy ransomware. Despite the vulnerability being patched on May 13, 2026, attacks have led to network breaches and data encryption. The U.S. CISA has urged federal agencies to secure their GlobalProtect instances immediately.
Estée Lauder Data Breach Exposes Sensitive Details Through Oracle E-Business Vulnerability
Estée Lauder disclosed a significant data breach resulting from the exploitation of a zero-day vulnerability in Oracle E-Business Suite. The attack occurred in August 2025 and was revealed in June 2026, impacting personal data including Social Security numbers, financial, and health information of employees. The breach was connected to the Cl0p cybercrime group and affected multiple companies.
7-Zip Version 26.02 Fixes High-Severity RCE Flaw in XZ Archive Processing
7-Zip released version 26.02 to address a remote code execution (RCE) vulnerability linked to XZ-compressed data. Discovered by Lunbun researcher Landon Peng, the flaw could be exploited if a user opened a specially crafted archive. This highlights the need for manual updates due to 7-Zip's lack of an automatic update feature, emphasizing user awareness and action.
OkoBot Malware Targets Cryptocurrency Wallets via Seed Phrase Phishing
OkoBot, a malware framework active since April 2025, targets cryptocurrency wallet users by injecting phishing pages into legitimate wallet apps like Ledger and Trezor. Kaspersky reports hundreds of victims globally, particularly in Brazil, Vietnam, Canada, Mexico, and Türkiye. The malware delivers over 20 payloads to steal credentials and sensitive data, posing a significant threat.
Dutch Police Uncover Global Crypto Scam, Arrest Alleged Leader
Dutch police dismantled a large-scale international crypto scam, arresting the alleged mastermind and several associates. The scheme, operating through 20 call centers, swindled tens of thousands, making over €100 million monthly. The main suspect is a 46-year-old Israeli-Polish known in the cyberworld, caught in Poland and extradited to the Netherlands.
Lidl Data Breach Affects Customers in Germany, Belgium, and Netherlands
Lidl, a European supermarket chain, suffered a data breach affecting online customers in Germany, Belgium, and the Netherlands. Attackers accessed customer data stored by a third-party service provider. Although no payment information was compromised, affected customers have been advised to be cautious of potential phishing scams.
Forg365 Phishing-as-a-Service Targets Microsoft 365 with Sophisticated Methods
Forg365, a new phishing-as-a-service platform, targets Microsoft 365 accounts with advanced techniques such as adversary-in-the-middle attacks, AI-generated lures, and device code phishing. This operation is notable for its complexity and capability to execute persistent access while leveraging legitimate email services for delivery.
Six Vulnerabilities Found in U-Boot Bootloader Threaten Device Security at Boot
Six vulnerabilities in the U-Boot bootloader, used in devices from routers to servers, have been identified. These flaws enable attackers to execute arbitrary code or crash devices during boot, compromising security before the operating system verifies software. This poses significant risks due to U-Boot's widespread deployment in various embedded systems.
Armenian Man Pleads Guilty to Involvement in Ryuk Ransomware Attacks
Karen Serobovich Vardanyan, a 34-year-old Armenian national, pleaded guilty in the US to charges related to deploying Ryuk ransomware. Extradited from Ukraine, Vardanyan facilitated attacks from November 2019 to April 2020, securing approximately $15 million in ransoms. His case underscores ongoing cybersecurity threats impacting various sectors.
Injective SDK npm Package Compromised to Steal Cryptocurrency Keys
A version of the Injective SDK npm package was compromised, leading to the theft of cryptocurrency wallet private keys via a malicious version. Hackers accessed Injective Labs' GitHub to publish the harmful package, affecting developers in the decentralized finance space.