From The Hacker News · 40 stories
DevMan RaaS Operates Centralized Portal for Payload Builds and Victim Management
The DevMan ransomware-as-a-service (RaaS) scheme utilizes a dedicated web portal for affiliates to build payloads, manage victims, and handle payouts. This centralized platform, tracked by PRODAFT as Funky Mantis, integrates various functions from build generation to victim chat and financial management, indicating a structured and sophisticated operation.
Bing Image Flaws Allowed Remote Code Execution on Microsoft Servers via Crafted SVGs
Security researchers at XBOW discovered two critical vulnerabilities in Bing's image processing service that allowed remote code execution as SYSTEM on Microsoft's production servers. Microsoft has since patched these server-side flaws, identified as CVE-2026-32194 and CVE-2026-32191, before public disclosure, requiring no user action.
Golden Chickens Malware-as-a-Service Introduces Four New Malware Families
The Golden Chickens malware-as-a-service (MaaS) ecosystem has released four new malware families: TinyEgg, ChonkyChicken, a modular ChonkyChicken variant, and ChromEggscalator. This development indicates an architectural shift towards modular, operator-driven tooling for defense evasion, impacting organizations targeted by financially motivated threat actors.
NodeBB Patches Eight AI-Found Security Flaws Exposing Admin Access and Private Chats
NodeBB has released version 4.14.2 to patch eight security flaws, rated high severity by Aikido Security, that could expose admin access and private user data. These vulnerabilities, discovered by AI pentest agents, affect all NodeBB versions prior to 4.14.0 and could allow unauthorized access to administrative functions, private messages, and the injection of malicious code.
Redis Patches Zero-Day Vulnerabilities Allowing Remote Code Execution
Redis released seven security updates on July 23 to address authenticated remote code execution (RCE) vulnerabilities in multiple Redis versions. These vulnerabilities, which require the RESTORE command, could allow attackers to execute arbitrary code on affected systems. Users are advised to upgrade to the patched versions or revoke RESTORE permissions from untrusted accounts.
New Threats Include macOS Infostealer via npm Package and Malicious VS Code Extension
A new macOS infostealer is being distributed through an npm package, and a malicious Visual Studio Code extension impersonates a popular tool to exfiltrate data and open backdoors. These incidents highlight ongoing supply chain and marketplace security risks for developers.
China-Nexus JadeProx Group Uses New TriBack Loader in Attacks on Government and Healthcare
Group-IB uncovered a China-nexus operation, JadeProx, that used a new Windows loader called TriBack Loader to target government, healthcare, and education organizations in Asia and Latin America. The discovery was made through an exposed Alibaba Cloud server, revealing active intrusions and spear-phishing campaigns. This new loader employs DLL sideloading and various evasion techniques, posing a threat to targeted sectors.
Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers
A large-scale campaign is using compromised GitHub repositories to create distributed attack infrastructure, targeting cPanel and WebHost Manager (WHM) instances. Malicious GitHub Actions workflows in compromised developer accounts are exploiting CVE-2026-41940 to gain elevated control and harvest credentials from vulnerable servers.
Ubuntu snap-confine Flaw Allows Local Root Privilege Escalation on Desktop Installs
A local privilege escalation vulnerability (CVE-2026-8933) in snap-confine allows unprivileged users to gain root access on default Ubuntu Desktop installations. This flaw, caused by a race condition during sandbox initialization, enables attackers to take full control of affected systems.
Armenia Detains Wrong Aleksandr Ermakov on US Extradition Request
Armenia has detained a Russian tourist, Aleksandr Ermakov, based on a US warrant for a REvil hacker with the same name. His lawyers argue he is not the individual sought by US authorities, highlighting potential issues in extradition processes and international law enforcement collaboration.
n8n Token Exchange Vulnerability Allows Unauthorized User Logins
n8n's workflow automation platform experienced a security flaw allowing attackers to log in as users from different issuers. The bug allowed valid tokens from one issuer to erroneously authenticate users from another, impacting Enterprise deployments that trust multiple external token issuers.
TuxBot v3 Evolution IoT Botnet Shows Signs of LLM Development
Cybersecurity researchers revealed the TuxBot v3 Evolution IoT botnet framework, which incorporates elements generated with a large language model (LLM). Functional issues were noted alongside its sophisticated features, highlighting potential risks in IoT security as AI tools assist in malware development.
Webinar Addresses Security Risks in AI-Era Ad Tech
A new on-demand webinar highlights the Approval Gap in ad tech, emphasizing the security risks posed by unmonitored third-party scripts. It features insights from Reflectiz and Taboola, discussing how to vet vendors effectively to protect customer data.
Progress Urges ShareFile Customers to Shut Down Storage Zone Controllers Due to Threat
Progress has advised ShareFile customers to disable Storage Zone Controllers due to a credible security threat. Although access to affected accounts has been temporarily disabled, the nature of the threat remains unclear, with no evidence of unauthorized access reported.
AI-Generated PowerShell Script Used in Active Directory Attack
Researchers identified a cyber attack employing a PowerShell script likely generated by AI for Active Directory enumeration. The script executed a sophisticated attack chain, highlighting a trend of using AI-assisted tools in cyber intrusions.
Lumen Technologies Expands Asset Inventory from 17,000 to 1.1 Million
Lumen Technologies utilized the Axonius asset intelligence platform to consolidate data from over 40 systems, uncovering 1.1 million devices, significantly increasing its asset visibility. This comprehensive view enhances Lumen's ability to manage vulnerabilities and streamline incident response procedures.
npm 12 Disables Install Scripts by Default to Enhance Security
npm version 12 disables install scripts by default and introduces changes to access tokens to mitigate supply chain risks. These modifications require explicit user approval for install scripts and restrict operations for granular access tokens, aiming to enhance security for developers.
AI Coding Agents Trigger Security Alarms for Normal Operations
Sophos detected that AI coding agents like Claude Code and Codex are triggering endpoint security alarms by performing activities that mimic cyberattacks. This is significant as it highlights the challenges of distinguishing legitimate developer tools from potential threats in security systems.
Recent Security Threats Highlight Weaknesses in AI and Email Systems
This week's security updates reveal new phishing campaigns, vulnerabilities in AI sandboxing, and flaws in Apple's email privacy service. These issues indicate pervasive weaknesses in various systems and could lead to increased risk for small businesses and users of affected services.
Threat Actors Use SEO-Poisoned Sites to Deploy AsyncRAT via ScreenConnect
Cybercriminals are using the ScreenConnect remote access tool to deploy AsyncRAT through compromised installer archives on spoofed websites. The campaign targets multiple languages and has resulted in a significant security risk as it enables attackers to maintain control over compromised devices and steal sensitive data.
Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures
The Ousaban banking trojan is targeting Windows users in Spain and Portugal through phishing PDFs designed to look like corrupted files. This malware can capture sensitive information during online banking sessions, posing a significant threat to users' accounts.
2026 Cybersecurity Assessment Reveals Awareness vs. Resilience Gap
The 2026 Bitdefender Cybersecurity Assessment reveals significant discrepancies between organizations' awareness of cyber risks and their actual resilience capabilities. While there is broad acknowledgment of AI’s role in cybersecurity, many teams struggle to effectively reduce their attack surfaces and maintain visibility into AI usage, highlighting a critical sector challenge.
Microsoft Accelerates Post-Quantum Cryptography Roadmap to 2029
Microsoft is fast-tracking its quantum-safe security roadmap, aiming for post-quantum cryptography by 2029 in response to advances in quantum computing. This update could significantly impact encryption standards and security protocols across the tech industry.
AI-Generated Domains Used in Phishing Attacks via Phantom Squatting
Attackers are purchasing domains created by AI models before anyone else, leveraging misplaced trust from users. This tactic, termed 'phantom squatting' by Palo Alto Networks' Unit 42, poses significant risks as AI-generated links can mislead users into visiting malicious sites.
Microsoft Identifies Risks from Poisoned MCP Tool Descriptions for AI Agents
Microsoft research reveals that poisoned tool descriptions can enable attackers to coerce AI agents into leaking sensitive data without triggering alarms. This issue arises particularly as companies empower AI agents for more complex tasks, highlighting vulnerabilities in the Model Context Protocol (MCP).
RustDuck Botnet Targets Routers and Servers with Two-Stage Malware
The RustDuck botnet is hijacking devices like routers and cameras to execute DDoS attacks. Its significance lies in its rapid evolution and the transition from C to Rust, making analysis more difficult.
Silent Swap Crypto Clipper Targets Users via Fake Google Notes Extension
Cybersecurity researchers identified the Silent Swap crypto clipper campaign, which uses a fake 'Google Notes' extension to steal cryptocurrency. The campaign replaces wallet addresses during transactions, leading to irreversible financial losses for victims.
Study Reveals 282 iOS AI Apps Expose API Keys and Access Tokens
A study found that 282 of 444 tested iOS AI chatbot apps leaked API keys through network traffic, enabling unauthorized access. This exposes developers to financial risks and highlights security vulnerabilities amidst the growing reliance on AI applications.
Cyber Risks Identified Ahead of FIFA World Cup 2026
A recent report reveals significant cyber threats targeting the FIFA World Cup 2026, including email spoofing risks and a surge in fake sportsbook apps. With many partners lacking sufficient protections, this exposes critical vulnerabilities within the event's supply chain, posing a major risk to financial transactions.
Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer
An exploit of the critical authentication bypass vulnerability CVE-2026-48558 in SimpleHelp has allowed attackers to deploy TaskWeaver and Djinn Stealer malware. This intrusion showcases the importance of securing remote monitoring software, as compromised systems can lead to severe data theft.
Malicious Chrome Extension Logged User Searches Under Perplexity Name
Microsoft discovered a malicious Chrome extension pretending to be Perplexity that intercepted user searches and address bar input. This extension logged every search query and typed character before redirecting users to legitimate search engines, posing a significant data privacy risk.
Apple Releases Security Updates for 30+ iOS, macOS, Safari Vulnerabilities
Apple released security updates for iOS, macOS, and Safari fixing over 30 vulnerabilities, including four WebKit flaws uncovered using AI tools. This marks a proactive approach from Apple in response to potential AI-enhanced exploitation techniques.
Over 236,000 DCloud Sites Linked to Cryptocurrency Scams and Phishing
Infoblox reports that over 236,000 websites employing DCloud Uni-App templates are involved in scams. These include cryptocurrency exchanges, phishing networks, and wallet drainers, raising significant security concerns.
Urgency Grows for Quantum-Resistant Cryptography Amid Quantum Threats
Organizations must adapt to post-quantum cryptography as public-key systems will be vulnerable to quantum computers. With cryptographically relevant quantum computers potentially available within 15 years, industries face pressures to upgrade security protocols before major deadlines set by agencies like the NSA and NIST.
Gamaredon Intensifies Cyber Attacks on Ukraine with New Malware Techniques
Gamaredon, a Russian APT group, has expanded its cyber attacks against Ukraine with new malware and tactics throughout 2025. The group has conducted 35 spear-phishing campaigns aimed at Ukrainian governmental and military institutions, focusing on exfiltrating sensitive data that could serve Russian interests in the ongoing conflict.
Ukraine and FBI Uncover Russian Intelligence Messaging Credential Theft Campaign
The Security Service of Ukraine, in collaboration with the FBI, revealed a Russian intelligence operation targeting messaging accounts of officials and civilians. The attackers used fake support messages to coax victims into revealing sensitive credentials.
New SharkLoader Malware Used to Deploy Cobalt Strike in Global Cyberattacks
Kaspersky reports a new malware called SharkLoader is being used to deploy Cobalt Strike in cyber attack campaigns. Targeting various sectors in multiple countries, the campaign reveals a significant and global threat landscape potentially linked to a Chinese-speaking threat actor.
Chinese APT CL-STA-1062 Uses TinyRCT Backdoor in Southeast Asia Cyber Campaign
A Chinese-speaking APT known as CL-STA-1062 has been linked to a new backdoor, TinyRCT, targeting government and critical infrastructure in Southeast Asia. This development highlights a sustained threat environment for state entities in the region.
Amazon Q Developer Flaw Allows Code Execution via Malicious Repos
A high-severity flaw in Amazon Q Developer permitted malicious repositories to execute code and steal developer credentials. The issue stemmed from the way Amazon's AI coding assistant handled Model Context Protocol servers, which has now been patched by Amazon.
Microsoft Alerts on Phishing Campaign Targeting Hotels with Node.js Implant
Microsoft identified a phishing campaign targeting hotels across Europe and Asia that leverages ZIP files containing a Node.js implant. The campaign uses specialized email tactics to bypass security measures and exploit hotel operational themes, highlighting a significant security concern in the hospitality sector.