<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>X’s InfoSec Newsletter</title>
    <description>Weekly curated list of {Cyber,Info}Security insightful resources and links, and some other security &amp; privacy things too.</description>
    
    <link>https://infosec-mashup.santolaria.net/</link>
    <atom:link href="https://rss.beehiiv.com/feeds/HVhiKYpQlR.xml" rel="self"/>
    
    <lastBuildDate>Mon, 20 Jul 2026 03:43:10 +0000</lastBuildDate>
    <pubDate>Sat, 18 Jul 2026 09:17:39 +0000</pubDate>
    <atom:published>2026-07-18T09:17:39Z</atom:published>
    <atom:updated>2026-07-20T03:43:10Z</atom:updated>
    
      <category>Artificial Intelligence</category>
      <category>Cybersecurity</category>
      <category>Privacy</category>
    <copyright>Copyright 2026, X’s InfoSec Newsletter</copyright>
    
    <image>
      <url>https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/publication/logo/ab407690-3f0c-4109-add5-5e9bf75e0e54/xsa-hs.png</url>
      <title>X’s InfoSec Newsletter</title>
      <link>https://infosec-mashup.santolaria.net/</link>
    </image>
    
    <docs>https://www.rssboard.org/rss-specification</docs>
    <generator>beehiiv</generator>
    <language>en-us</language>
    <webMaster>support@beehiiv.com (Beehiiv Support)</webMaster>

      <item>
  <title>🕵🏻‍♂️ [InfoSec MASHUP] 29/2026 - They Didn&#39;t Hack the Military. They Hacked the Phone Network.</title>
  <description>Plus: Microsoft patched a record 622 vulnerabilities, asyncapi npm packages delivered a botnet loader via GitHub Actions, and ShinyHunters spent a year inside Salesforce via OAuth abuse</description>
  <link>https://infosec-mashup.santolaria.net/p/infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network</link>
  <guid isPermaLink="true">https://infosec-mashup.santolaria.net/p/infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network</guid>
  <pubDate>Sat, 18 Jul 2026 09:17:39 +0000</pubDate>
  <atom:published>2026-07-18T09:17:39Z</atom:published>
    <dc:creator>Xavier Santolaria</dc:creator>
    <category><![CDATA[Malware]]></category>
    <category><![CDATA[Opensource]]></category>
    <category><![CDATA[Privacy]]></category>
    <category><![CDATA[Cybersecurity]]></category>
    <category><![CDATA[Threat Intelligence]]></category>
    <category><![CDATA[Ai]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">The <a class="link" href="https://techcrunch.com/2026/07/14/iran-abused-mobile-networks-vulnerabilities-to-locate-u-s-military-in-the-middle-east-report-says/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">story</a> that should not get lost in this week&#39;s 622-CVE Patch Tuesday avalanche is quieter and more unsettling. Iran didn&#39;t need a zero-day to locate U.S. military personnel in the Middle East. They used SS7 — the decades-old telephony signaling protocol with known, unfixable-by-design vulnerabilities — and ad-targeting infrastructure. The kind that serves you a shoe ad based on where you walked yesterday. Cross-referenced against known military bases and hotels, it produced location hits precise enough to enable strikes that caused injuries.</p><p class="paragraph" style="text-align:left;">This is the threat model most organizations aren&#39;t building for, because it doesn&#39;t fit neatly into a CVE or a patch cycle. SS7 abuse is not new — telecom researchers have been documenting it since 2014. Ad-tech as a surveillance layer has been a known risk for nearly as long. What&#39;s changed is the operational willingness to combine them and act on the output. The attack surface here isn&#39;t a misconfigured server or an unpatched appliance. It&#39;s the mobile advertising ecosystem, the global telephony backbone, and the assumption that civilian infrastructure doesn&#39;t get weaponized against military targets. That assumption had a bad week.</p><h2 class="heading" style="text-align:left;">Table of Contents</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="#breaches-security-incidents" rel="noopener noreferrer nofollow">BREACHES & SECURITY INCIDENTS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#cybercrime-cyber-espionage-ap-ts" rel="noopener noreferrer nofollow">CYBERCRIME, CYBER ESPIONAGE, APT’s</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#government-politics-and-privacy" rel="noopener noreferrer nofollow">GOVERNMENT, POLITICS, AND PRIVACY</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#malware-threats" rel="noopener noreferrer nofollow">MALWARE & THREATS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ai-crypto-tech-tools" rel="noopener noreferrer nofollow">AI, CRYPTO, TECH & TOOLS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#vulnerabilities-research-and-threat" rel="noopener noreferrer nofollow">VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ics-ot-io-t" rel="noopener noreferrer nofollow">ICS, OT & IoT</a></p></li></ul><div id="breaches-security-incidents" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🔓 BREACHES & SECURITY INCIDENTS</h3><p class="paragraph" style="text-align:left;">🇺🇸 <b>Ernst & Young disclosed a data breach</b> after a third-party support ticket system used by its IT staff was hacked. Support tickets and <a class="link" href="https://www.bleepingcomputer.com/news/security/ernst-and-young-discloses-data-breach-after-support-system-hack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">downloaded documents may have included client tax and financial information</a>. <b>EY</b> says it contained the breach, notified law enforcement, and is offering affected clients 24 months of identity monitoring.</p><p class="paragraph" style="text-align:left;">🇺🇸 🥤 <b>Coca-Cola said its </b><i><b>Fairlife</b></i><b> dairy unit was hit by ransomware</b> and <a class="link" href="https://techcrunch.com/2026/07/16/coca-cola-suspended-production-at-its-fairlife-dairy-after-a-ransomware-attack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">has stopped U.S. production</a>. Operations in Canada were not affected. The company gave no timeline for restoring systems.</p><p class="paragraph" style="text-align:left;">⌛️ <b>A new Spirals ransomware finished a full corporate breach</b>—from webshell access to data theft and file encryption—<a class="link" href="https://www.security.com/threat-intelligence/ransomware-spirals-extortion?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">in under 24 hours</a>. The attacker disabled defenses, moved laterally, and deployed a Rust-based payload named <code>bitsadmin.exe</code> to encrypt files and drop a <code>RECOVERY_SECTION.log</code> ransom note. <b>Symantec</b> saw this one case and published indicators and hashes to help organizations defend against Spirals.</p><p class="paragraph" style="text-align:left;">🇯🇵 🚕 <b>Japan&#39;s largest taxi operator, </b><i><b>Nihon Kotsu</b></i><b>, shut parts of its systems after a weekend cyberattack</b> that infected internal systems with malware. Key services like dispatch, web booking, reservations, telephone dispatch, and some internal systems remain offline. The <a class="link" href="https://www.bleepingcomputer.com/news/security/japans-largest-taxi-operator-shuts-systems-after-cyberattack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">company has hired external cybersecurity experts</a>, is investigating possible data leaks, and urges customers to avoid suspicious messages.</p><p class="paragraph" style="text-align:left;">🇩🇪 <b>Lidl said attackers stole customer data after a hack at a service provider</b> for its online shop. The stolen details may include names, contact info, birthdates, and possibly passwords or payment data. <b>Lidl</b> <a class="link" href="https://www.bleepingcomputer.com/news/security/lidl-discloses-online-shop-breach-after-service-provider-hack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">warned customers to watch for phishing</a> and notified authorities while investigating.</p><p class="paragraph" style="text-align:left;">🇺🇸 <b>Centers Laboratory disclosed a data breach affecting about 542,000 people</b> — Hackers accessed systems in August 2025 and stole sensitive personal and medical information. The <b>WorldLeaks</b> group l<a class="link" href="https://www.securityweek.com/centers-laboratory-data-breach-affects-540000-individuals/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">ater published 720 GB of stolen files</a> and listed <b>Centers Lab</b> on its site.</p><p class="paragraph" style="text-align:left;">→ More breaches:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/23andme-to-pay-18-million-in-new-genetics-data-breach-settlement/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">23andMe to pay $18 million in new genetics data breach settlement</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/synopsys-finds-no-evidence-of-data-breach-following-bosch-hack-claims/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/cyberattack-disrupts-operations-of-japanese-frozen-food-giant-nichirei/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/abbott-laboratories-probes-two-cyber-incidents-amid-extortion-claims/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">Abbott Laboratories probes two cyber incidents amid extortion claims</a></p></li></ul></div><p class="paragraph" style="text-align:left;"></p><div id="cybercrime-cyber-espionage-ap-ts" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🥷🏻 CYBERCRIME, CYBER ESPIONAGE, APT’s</h3><p class="paragraph" style="text-align:left;">🇬🇧 🕷️ <b>Two young members of the </b><i><b>Scattered Spider</b></i><b> hacking group were jailed in the UK</b> for their role in a 2024 cyberattack on <b>Transport for London</b> that cost £29 million. Each <a class="link" href="https://www.securityweek.com/two-scattered-spider-hackers-sentenced-to-jail-in-uk/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">received five years and six months after pleading guilty</a>. Authorities say the arrests have largely stopped the group’s criminal operations while other suspects face ongoing prosecutions.</p><p class="paragraph" style="text-align:left;">🇳🇱 <b>Dutch police arrested suspects in an international investment fraud ring that stole over €100 million</b> and may have tens of thousands of victims. The group ran 20 call centers with 700+ people who used fake trading platforms and crypto transfers to take victims&#39; money. The <a class="link" href="https://www.bleepingcomputer.com/news/security/dutch-police-bust-investment-fraud-ring-stealing-over-100-million/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">main suspect, a 46-year-old tech expert, was extradited from Poland</a> and charged after investigators traced digital and financial evidence.</p><p class="paragraph" style="text-align:left;">🇮🇷 🇺🇸 <b>A report says Iran used known telecom flaws to find U.S. military personnel </b>in the Middle East. They <a class="link" href="https://techcrunch.com/2026/07/14/iran-abused-mobile-networks-vulnerabilities-to-locate-u-s-military-in-the-middle-east-report-says/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">exploited SS7 protocols and ad-targeting tech</a> to track phones at bases and hotels. Those location hits enabled strikes that caused several injuries.</p><p class="paragraph" style="text-align:left;">🇬🇧 🇷🇺 <b>UK authorities charged five people linked to </b><i><b>Russian Coms</b></i>, a caller ID spoofing platform used in large-scale scams. The <a class="link" href="https://www.bleepingcomputer.com/news/security/uk-charges-suspects-linked-to-russian-coms-call-spoofing-platform/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">platform helped criminals make over 1.8 million scam calls</a> and caused tens of millions in losses to about 170,000 victims. The suspects will appear in Westminster Magistrates&#39; Court on August 14.</p><p class="paragraph" style="text-align:left;">🇺🇸 🇷🇺 <b>U.S. authorities indicted three Russians for running bulletproof hosting services</b> that helped cybercriminals <a class="link" href="https://www.databreachtoday.com/feds-target-widely-used-russian-bulletproof-hosting-services-a-32230?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">attack critical infrastructure and steal at least $62 million</a>. The services, <b>Media Land</b> and <b>ML.Cloud</b>, hosted ransomware, phishing, banking Trojans, and stolen-card sites from 2014 onward. The FBI and allies have charged the operators, imposed sanctions, and offered up to $10 million for related intelligence.</p><p class="paragraph" style="text-align:left;">🇺🇸 🇷🇺 <b>The U.S. Treasury sanctioned a VPN service called </b><i><b>First VPN</b></i><b> and two individuals</b> for helping ransomware groups hide attacks and sell tools that evade security. <b>First VPN</b> was <a class="link" href="https://thehackernews.com/2026/07/us-sanctions-first-vpn-service-and.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">shut down after years of enabling attacks</a> that cost U.S. businesses and infrastructure billions. The U.K., E.U., and U.S. also sanctioned Russian cyber actors and warned about state-linked groups exploiting routers and device vulnerabilities.</p><p class="paragraph" style="text-align:left;">🇪🇸 <b>Spanish police broke up a large cybercrime and money-laundering ring that stole about €140 million</b> through investment fraud and CEO/BEC scams. Four suspects were arrested in Spain, Portugal, and Panama, and raids seized computers, phones, and €3 million frozen for victims. Authorities say the <a class="link" href="https://www.bleepingcomputer.com/news/security/spanish-police-take-down-140-million-cyber-fraud-ring-arrest-four/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">network of hundreds of bank accounts and many money mules has been dismantled</a>.</p><p class="paragraph" style="text-align:left;">🔎 <b>Attackers tied to ShinyHunters spent a year stealing Salesforce data without exploiting platform bugs</b> by <a class="link" href="https://www.microsoft.com/en-us/security/blog/2026/07/13/defending-saas-based-applications-against-shinyhunters-oauth-abuse/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">abusing trusted OAuth connections</a>. Microsoft mapped three paths: vishing to get users to approve malicious apps, stolen tokens from compromised vendors, and misconfigured guest access. <b>Microsoft</b> and <b>Salesforce</b> added real-time detection and governance tools to spot over‑privileged apps and suspicious OAuth activity.</p><p class="paragraph" style="text-align:left;">🇪🇺 🇷🇺 <b>The EU sanctioned nine Russian intelligence officers</b>, hackers and four companies for a yearslong cyber spying campaign. The attacks targeted governments and critical infrastructure like heating and power plants in at least nine countries. The <a class="link" href="https://www.securityweek.com/eu-targets-russian-intelligence-officers-accused-of-running-a-yearslong-cyber-spying-campaign/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">EU said the FSB ran the groups</a> and countries including France and Poland were targeted.</p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;">🗓️ <b><a class="link" href="https://xsa.github.io/infosec-events/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">{Cyber,Info}Sec Events</a></b> — A community-maintained list of infosec conferences worldwide. Subscribe to the <a class="link" href="https://xsa.github.io/infosec-events/events.ics?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">ICS calendar feed</a> to get events straight into your calendar, or follow <a class="link" href="https://infosec.exchange/@infosecevents?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">@infosecevents@infosec.exchange</a> on Mastodon for weekly digests. Contributions and ⭐ welcome!</p></div><p class="paragraph" style="text-align:left;"></p><div id="government-politics-and-privacy" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">👨🏻‍⚖️ 👀 GOVERNMENT, POLITICS, AND PRIVACY</h3><p class="paragraph" style="text-align:left;">🇦🇲 🇷🇺 <b>Armenia detained a Russian tourist, Aleksandr Ermakov, on a U.S. extradition request linked to REvil</b> hacker — His lawyers <a class="link" href="https://thehackernews.com/2026/07/armenia-detains-russian-tourist-on-us.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">say the arrested man is a different Aleksandr Ermakov</a> and not the sanctioned hacker wanted by the U.S., Australia, and the UK. Armenian courts must now decide whether to extradite while Moscow seeks consular access.</p><p class="paragraph" style="text-align:left;">🇪🇺 <b>The EU used the Digital Markets Act to force Google to share search data and open Android</b> to rival AI. <b>Google</b> <a class="link" href="https://arstechnica.com/gadgets/2026/07/its-official-eu-will-force-google-to-share-search-data-and-open-up-ai-on-android/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">must let competing AI platforms access</a> system features now reserved for its <b>Gemini</b>. The rules are legally binding and aim to boost competition in Europe.</p><p class="paragraph" style="text-align:left;">🇬🇧 ⏲️ <b>The UK government plans an overnight social media curfew for 16- and 17-year-olds</b>, with <a class="link" href="https://www.bbc.com/news/articles/c982857nlrlo?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">apps defaulting off between midnight and 06:00</a>. Teenagers can opt out by changing settings, and the rules would also limit autoplay and infinite scroll. Critics say the measures may be ineffective or harmful and that stronger, device-level controls are needed.</p><p class="paragraph" style="text-align:left;">🇺🇸 ⏸️ e<b>The Pentagon paused CMMC phase two set for November</b> while it <a class="link" href="https://www.securityweek.com/pentagon-suspends-cmmc-phase-2-as-it-rethinks-contractor-cybersecurity-rules/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">reviews the program for 60 days</a>. Contractors still must follow phase one rules and existing cybersecurity regulations. A task force will seek industry input and recommend simpler rules to help small suppliers compete.</p><p class="paragraph" style="text-align:left;">🇺🇸 🗳️ <b>Federal help for election security is collapsing after the Trump administration</b> fired Election Assistance Commission leaders and curtailed agencies like CISA. States are <a class="link" href="https://cyberscoop.com/trump-administration-eac-firings-doj-election-officials-threat/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">building their own smaller, local networks to protect voting systems</a> and share threat information. Officials worry federal actions and DOJ threats are undermining trust and making election administration harder.</p></div><p class="paragraph" style="text-align:left;"></p><div id="malware-threats" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🦠 MALWARE & THREATS</h3><p class="paragraph" style="text-align:left;">🇧🇷 <b>Researchers found over 20 Brazilian government websites hijacked to deliver </b><i><b>PhantomEnigma</b></i><b> malware</b> — Attackers used authenticated emails and compromised <code>.gov.br</code> hosts to <a class="link" href="https://news.backbox.org/2026/07/16/hidden-infrastructure-exposed-any-run-reveals-hijacked-gov-websites-delivering-malware/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">hide a modular JavaScript backdoor</a> that can load additional payloads. This technique lets criminals steal credentials and maintain persistent access, posing major risk to banks and public agencies.</p><p class="paragraph" style="text-align:left;">🇷🇺 🐀 <b>A Russian-linked group called UAT-11795 trojanized popular apps like WebEx and Zoom</b> to install a new backdoor named <b>Starland RAT</b>. Starland steals browser credentials and crypto wallets, gathers system and Active Directory data, and deploys additional stealers and RATs. <b>Cisco Talos</b> <a class="link" href="https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">warns</a> users to download only from official sources and use provided IoCs to defend.</p><p class="paragraph" style="text-align:left;">🍎 <b>Researchers discovered </b><i><b>CrashStealer</b></i><b>, a new macOS info-stealer written in C++</b> that harvests browsers, crypto wallets, password managers, keychain items, and local files. It <a class="link" href="https://www.jamf.com/blog/crashstealer-macos-infostealer-analysis/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">uses a signed and Apple-notarized disk image dropper</a> to bypass Gatekeeper, then validates the user password, re-signs itself, and persists as a LaunchAgent. Collected data is AES-GCM encrypted, zipped, and exfiltrated to an attacker server as part of a larger campaign.</p><p class="paragraph" style="text-align:left;">📦️ <b>Four compromised </b><code>@asyncapi</code><b> npm packages delivered a multi-stage botnet loader</b> that fetches an encrypted malware payload from IPFS. The <a class="link" href="https://www.stepsecurity.io/blog/compromised-next-branch-pushes-malicious-asyncapi-generator-generator-helpers-and-generator-components-to-npm?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">final payload, called Miasma-like</a>, supports multiple C2 channels, persistence, credential theft, lateral movement, and a destructive dead-man switch. The attacker abused <b>GitHub Actions</b> to publish malicious releases with valid provenance, and the poisoned modules run when required during builds or CI.</p><p class="paragraph" style="text-align:left;">🐀 <b>Researchers found a new Rust-based remote access trojan called </b><i><b>LabubaRAT</b></i> that pretends to be <b>NVIDIA</b> software. It can profile Windows hosts, run commands, move files, take screenshots, and proxy traffic. The <a class="link" href="https://blackpointcyber.com/blog/labubarat-a-rust-based-remote-access-tool-masquerading-as-nvidia-software/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">malware uses configurable C2 channels</a> (HTTPS, WebView2, DNS) and may be sold as malware-as-a-service.</p><p class="paragraph" style="text-align:left;">📦️ <b>Researchers found 148 npm packages masquerading as student web proxies that turned visitors&#39; browsers into a DDoS botnet</b> — The hidden code loaded remote scripts and opened many WebSocket connections to flood and crash proxy servers and a nursing school site. The <a class="link" href="https://research.jfrog.com/post/lucide-proxy-npm-malware-campaign/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">packages were easy to rearm and many remain available</a>, so admins should block attacker domains and users should clear browser data.</p><p class="paragraph" style="text-align:left;">🔙 🚪<b>Jscrambler&#39;s npm package was backdoored with an infostealer</b> and <a class="link" href="https://jscrambler.com/blog/security-advisory-malicious-npm-package?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">downloaded ~1,500 times</a>. The malicious releases ran a preinstall hook to steal credentials, source code, cloud keys, wallets, and browser data. <b>Jscrambler</b> revoked publishing credentials, deprecated the packages, and urged users to rotate secrets and update to safe versions.</p></div><p class="paragraph" style="text-align:left;"></p><div id="ai-crypto-tech-tools" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🤖 🧰 AI, CRYPTO, TECH & TOOLS</h3><p class="paragraph" style="text-align:left;">👀 🗓️ <b>Researchers say two vulnerabilities in Claude for Chrome still let malicious extensions</b> make the <a class="link" href="https://www.manifold.security/blog/claude-for-chrome-extension-bypass?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">AI act without real user clicks</a>. An attacker could use this to read <b>Gmail</b>, <b>Google Docs</b>, and calendar data, especially if &quot;<i>Act without asking</i>&quot; is on. <b>Anthropic</b> patched <i><b>ClaudeBleed</b></i> earlier this year, but the reported flaws remain in recent extension versions.</p><p class="paragraph" style="text-align:left;">⚖️ <b>Apple says a former engineer, Chang Liu, used a rare authentication bug to access and download dozens of confidential files</b> after leaving for <b>OpenAI</b>. Apple alleges the files included unreleased product specs and that Liu kept an Apple laptop and did not report the bug. <a class="link" href="https://techcrunch.com/2026/07/13/apple-says-former-employee-exploited-rare-bug-to-download-confidential-files-after-leaving-for-openai/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">Apple is suing OpenAI</a> and seeks a jury trial.</p></div><p class="paragraph" style="text-align:left;"></p><div id="vulnerabilities-research-and-threat" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🐛 🧠 VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</h3><p class="paragraph" style="text-align:left;">➝ From the Patching Department:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/7-severe-vulnerabilities-patched-in-vmware-avi-load-balancer/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">7 Severe Vulnerabilities Patched in VMware Avi Load Balancer</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/adobe-patches-critical-coldfusion-vulnerabilities/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">Adobe Patches Critical ColdFusion Vulnerabilities</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/critical-vulnerabilities-patched-with-fresh-chrome-150-firefox-152-updates/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/f5-patches-multiple-nginx-big-ip-vulnerabilities/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">F5 Patches Multiple NGINX, BIG-IP Vulnerabilities</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/microsoft-patches-record-622-vulnerabilities-including-two-exploited-zero-days/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days</a> ‼️ </p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/sap-patches-critical-vulnerabilities-in-netweaver-approuter-commerce-cloud/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/sonicwall-issues-urgent-sma-patch-warning-for-two-zero-day-exploits/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/zimbra-patches-critical-code-execution-vulnerability/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">Zimbra Patches Critical Code Execution Vulnerability</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://thehackernews.com/2026/07/zoom-patches-critical-windows-flaw-that.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">Zoom Patches Critical Windows Flaw That Could Enable Account Takeover</a></p></li></ul><p class="paragraph" style="text-align:left;">0️⃣ 🗓️ <b>Researcher Chaotic Eclipse released a limited LegacyHive PoC that can load arbitrary Windows</b> user hives and escalate privileges. The PoC works on all supported Windows versions, <a class="link" href="https://git.projectnightcrawler.dev/NightmareEclipse/LegacyHive?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">including after the July 2026 Patch Tuesday</a>. <b>Microsoft</b> is investigating amid broader tension with the researcher and active exploitation of several other patched vulnerabilities.</p><hr class="content_break"><p class="paragraph" style="text-align:left;">🐛 ⚠️ <b>A bug called </b><i><b>HollowByte</b></i><b> lets attackers bloat OpenSSL server memory</b> and <a class="link" href="https://sec.okta.com/articles/2026/06/openssl-hollowbtye-a-dos-hiding-in-11-bytes/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">cause a DoS with only an 11-byte payload</a>. <b>OpenSSL</b> has quietly fixed it and backported patches to older releases. Upgrade OpenSSL now to avoid servers becoming permanently memory‑bloated.</p><p class="paragraph" style="text-align:left;">💥 <b>A critical SharePoint RCE bug (CVE-2026-58644) is being exploited</b> soon after <b>Microsoft</b> patched it. <b>CISA</b> <a class="link" href="https://www.securityweek.com/fresh-sharepoint-vulnerability-exploited-soon-after-disclosure/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">added the flaw to its Known Exploited Vulnerabilities list</a> and told agencies to patch within three days. Other exploited bugs in <b>SharePoint</b> and <b>Fortinet</b> appliances were also noted.</p><p class="paragraph" style="text-align:left;">🐛 ⚠️ <b>A flaw in RabbitMQ’s management interface can leak the broker’s OAuth client secret (CVE-2026-5721), letting attackers impersonate the broker</b> and get admin tokens. This <a class="link" href="https://www.miggo.io/post/full-broker-takeover-no-login-required-miggo-discovers-critical-rabbitmq-vulnerabilities-putting-application-data-at-risk?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">affects setups using an OAuth/OIDC provider and any instance with the management port reachable</a> by untrusted networks. Organizations should patch immediately, block or isolate exposed interfaces, and rotate secrets.</p><p class="paragraph" style="text-align:left;">0️⃣ 🗓️ <b>Progress Software says a zero-day vulnerability caused the recent ShareFile Storage Zones Controller outage</b> and access is being restored. They released patches for versions 5.x and 6.x and urged customers to update and disconnect exposed servers. <b>Progress</b> <a class="link" href="https://www.securityweek.com/progress-confirms-zero-day-vulnerability-behind-sharefile-disruption/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">reports no evidence of customer data compromise</a>, but security experts warn to assume possible compromise and investigate further.</p><p class="paragraph" style="text-align:left;">💥 <b>SonicWall says two zero-day flaws in SMA 1000 appliances are being actively exploited</b> — One flaw can let an attacker run admin commands. Customers must <a class="link" href="https://thehackernews.com/2026/07/two-sonicwall-sma-1000-zero-days.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">apply patches now</a> and check for compromise indicators.</p></div><p class="paragraph" style="text-align:left;"></p><div id="ics-ot-io-t" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🛰️ ICS, OT & IoT</h3><div class="embed"><a class="embed__url" href="https://unit42.paloaltonetworks.com/tuxbot-v3-evolution-iot-botnet/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank"><div class="embed__content"><p class="embed__title"> TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development </p><p class="embed__description"> TuxBot v3 Evolution, an IoT botnet framework built with LLMs. Read our analysis of its cross-compiled binaries, C2 architecture and bugs. </p><p class="embed__link"> Unit 42 • Chris Navarrete, Asher Davila, Doel Santos </p></div><img class="embed__image embed__image--right" src="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/AdobeStock_992950050-1-scaled.jpeg"/></a></div><p class="paragraph" style="text-align:left;">🩹 <b>ICS Patch Tuesday</b> — Siemens, Schneider Electric, and Rockwell Automation <a class="link" href="https://www.securityweek.com/ics-patch-tuesday-vulnerabilities-fixed-by-siemens-schneider-rockwell/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">released July 2026 Patch Tuesday advisories</a> fixing multiple critical and high-severity vulnerabilities in ICS products. The flaws could allow attackers to bypass authentication, execute code, cause DoS, or gain full control of affected systems. Other vendors and agencies (ABB, Mitsubishi, VDE CERT, CISA) also reported or distributed related advisories.</p><p class="paragraph" style="text-align:left;">🐛 ⚠️ <b>TP-Link fixed two vulnerabilities in Kasa EC70 v4 and EC71 v4 cameras that could let someone</b> on the same local network <a class="link" href="https://cybersecuritynews.com/tp-link-cameras-vulnerability/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">steal sensitive data</a>. The worst flaw is a hardcoded cryptographic key that can enable man-in-the-middle attacks; the other leaks location data via the discovery service. Update camera firmware and the Kasa app, or isolate cameras on a separate IoT network until patched.</p><p class="paragraph" style="text-align:left;">🇷🇺 ⚠️ <b>U.S. and eight allied agencies warn Russian state hackers are targeting poorly configured routers</b> to breach critical infrastructure networks. The group (FSB Centre 16) uses weak SNMP credentials and known Cisco flaws to steal device configs and exfiltrate them. <a class="link" href="https://www.ic3.gov/CSA/2026/260713.pdf?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">Agencies urge</a> upgrades (SNMPv3), disabling Cisco Smart Install, strong passwords, blocking TFTP/SNMP, and patching or replacing devices.</p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">💬 CONNECT</h3><p class="paragraph" style="text-align:left;">Follow me on <a class="link" href="https://infosec.exchange/@0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">Mastodon</a> for quick daily updates and bite-sized content.</p><p class="paragraph" style="text-align:left;">Prefer using an RSS feed? Add <b>Infosec MASHUP</b> to your feed <a class="link" href="https://rss.beehiiv.com/feeds/HVhiKYpQlR.xml?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">here</a>.</p><p class="paragraph" style="text-align:center;"><b>Enjoying our newsletter? </b>Forward it to a colleague—<br>it’s one of the best ways to support us.</p><p class="paragraph" style="text-align:left;">Thanks for reading today’s newsletter, and if you&#39;re enjoying it and want to support my work, you can <b>buy me a coffee</b> ☕ over at <a class="link" href="https://www.buymeacoffee.com/0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network" target="_blank" rel="noopener noreferrer nofollow">https://www.buymeacoffee.com/0x58</a></p><p class="paragraph" style="text-align:left;"> See you next time!</p><p class="paragraph" style="text-align:left;">-X.</p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=27b6fdbc-17e6-41bf-ba62-5488f9e7e878&utm_medium=post_rss&utm_source=x_s_infosec_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🕵🏻‍♂️ [InfoSec MASHUP] 28/2026 - The Agent Ran the Attack. The Human Just Aimed.</title>
  <description>Plus: The DHS threat intelligence network got breached, a 16-year-old Linux KVM flaw lets guest VMs crash the host, and Canada&#39;s spy agency confirmed it hacked drug traffickers and a ransomware gang last year</description>
  <link>https://infosec-mashup.santolaria.net/p/infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed</link>
  <guid isPermaLink="true">https://infosec-mashup.santolaria.net/p/infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed</guid>
  <pubDate>Sat, 11 Jul 2026 07:00:00 +0000</pubDate>
  <atom:published>2026-07-11T07:00:00Z</atom:published>
    <dc:creator>Xavier Santolaria</dc:creator>
    <category><![CDATA[Malware]]></category>
    <category><![CDATA[Opensource]]></category>
    <category><![CDATA[Privacy]]></category>
    <category><![CDATA[Cybersecurity]]></category>
    <category><![CDATA[Threat Intelligence]]></category>
    <category><![CDATA[Ai]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Back after a week off — field hockey duties called, Turkey answered.</p><p class="paragraph" style="text-align:left;">AI didn&#39;t assist the <b>JudePuffer</b> ransomware campaign. It ran it. The human operator set the target and, by all accounts, largely stepped back. What followed was an AI agent handling reconnaissance, credential theft, lateral movement, persistence, and payload deployment — generating over 600 unique ransomware variants, self-correcting errors in seconds, adapting to defensive responses faster than any human operator could manage. The campaign hit 23 organizations across healthcare and logistics before analysts caught up with what they were actually looking at.</p><p class="paragraph" style="text-align:left;">In <a class="link" href="https://infosec-mashup.santolaria.net/p/infosec-mashup-19-2026-offense-just-got-a-co-pilot?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">issue 19</a> we watched AI used as a recon assistant against a water utility in Monterrey — find the interface, recommend the attack, generate the toolkit. That felt like a threshold moment. <b>JudePuffer</b> is what comes next. The skill floor for running a ransomware operation has not just dropped — it has been removed. The barrier that used to sit between &quot;motivated attacker&quot; and &quot;capable attacker&quot; was always knowledge and tradecraft. An autonomous agent with access to a target network doesn&#39;t need either. It needs a prompt and patience.</p><h2 class="heading" style="text-align:left;">Table of Contents</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="#breaches-security-incidents" rel="noopener noreferrer nofollow">BREACHES & SECURITY INCIDENTS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#cybercrime-cyber-espionage-ap-ts" rel="noopener noreferrer nofollow">CYBERCRIME, CYBER ESPIONAGE, APT’s</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#government-politics-and-privacy" rel="noopener noreferrer nofollow">GOVERNMENT, POLITICS, AND PRIVACY</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#malware-threats" rel="noopener noreferrer nofollow">MALWARE & THREATS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ai-crypto-tech-tools" rel="noopener noreferrer nofollow">AI, CRYPTO, TECH & TOOLS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#vulnerabilities-research-and-threat" rel="noopener noreferrer nofollow">VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ics-ot-io-t" rel="noopener noreferrer nofollow">ICS, OT & IoT</a></p></li></ul><div id="breaches-security-incidents" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🔓 BREACHES & SECURITY INCIDENTS</h3><p class="paragraph" style="text-align:left;">🇯🇵 <b>Japanese telecom KDDI says attackers breached an email platform and exposed over 12 million email addresses</b> and 7.6 million passwords. The breach <a class="link" href="https://www.bleepingcomputer.com/news/security/japanese-telecom-giant-kddi-says-data-breach-affects-12-million-people/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">exploited a zero-day in third-party software</a> discovered May 16 and confirmed June 17. <b>KDDI</b> is forcing password resets, deploying EDR tools, and working with ISPs and regulators to secure accounts.</p><p class="paragraph" style="text-align:left;">🇺🇸 <b>Accenture confirmed a security breach</b> after a hacker offered stolen data for sale. The attacker claims to have taken about 35 GB of source code and keys. <b>Accenture</b> <a class="link" href="https://www.bleepingcomputer.com/news/security/accenture-confirms-breach-after-hacker-offers-stolen-data-for-sale/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">says the issue was remediated</a> and operations were not impacted.</p><p class="paragraph" style="text-align:left;">🇺🇸 <b>A small US county reportedly paid a $1 million ransom to the Kairos extortion group after a May 2025 breach</b> — The <a class="link" href="https://www.securityweek.com/county-government-reportedly-paid-1-million-to-cyber-extortion-group/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">attackers claimed to have taken about 2 TB of data</a>, including sensitive personal and financial records. The payment followed weeks of negotiation and came amid pressured deadlines and limited proof that the data were fully deleted.</p><p class="paragraph" style="text-align:left;">🇺🇸 <b>Two U.S. Army subdomain error pages were defaced with pro-Kurdish messages</b> and <a class="link" href="https://cyberscoop.com/us-army-websites-defaced-404-hijacking-kurdistan/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">insults to President Trump and adviser Tom Barrack</a>. The hacks used 404 hijacking on legacy, third‑party WordPress/Microsoft cloud sites and affected only error pages. The Army took the pages offline and is investigating the incident.</p><p class="paragraph" style="text-align:left;">🇺🇸 <i><b>AdaptHealth</b></i><b>, a home medical equipment supplier, told the SEC hackers stole a large amount of patient health and personal data </b>after a social engineering attack. The <a class="link" href="https://www.databreachtoday.com/home-medical-gear-firm-tells-sec-hackers-stole-patient-data-a-32161?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">company said stolen items include insurance billing passwords and records</a> from external electronic health record portals, and it has contained the breach. <b>AdaptHealth</b> could not yet determine the full financial or reputational impact and may have paid a ransom.</p><p class="paragraph" style="text-align:left;">🇺🇸 <b>Hackers breached the Department of Homeland Security’s </b><i><b>Homeland Security Information Network</b></i>, a platform used by tens of thousands of officials to <a class="link" href="https://www.databreachtoday.com/hackers-breach-sensitive-dhs-information-sharing-network-a-32164?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">share sensitive but unclassified threat intelligence</a>. <b>DHS</b> says it isolated affected systems, mitigated the vulnerability, and is investigating, with no evidence yet that classified networks were hit. Officials warn the compromise could expose operational plans and enable targeted attacks on partners.</p><p class="paragraph" style="text-align:left;">→ More breaches:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/assuranceamerica-data-breach-exposes-records-of-69-million-drivers/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">AssuranceAmerica data breach exposes records of 6.9 million drivers</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/mount-royal-university-confirms-breach-as-hackers-claim-attack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">Mount Royal University confirms breach as hackers claim attack</a></p></li></ul></div><div id="cybercrime-cyber-espionage-ap-ts" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🥷🏻 CYBERCRIME, CYBER ESPIONAGE, APT’s</h3><p class="paragraph" style="text-align:left;">❌ <b>Interpol&#39;s </b><i><b>Operation First Light</b></i><b> led to more than 5,800 arrests across 97 countries</b> and identified over 142,000 victims. Authorities <a class="link" href="https://cyberscoop.com/interpol-cybercrime-crackdown-operation-first-light/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">seized $293 million, blocked 31,000 bank accounts</a>, and analyzed more than 152,800 cybercrime cases. The operation targeted scams like romance fraud, business email compromise, and money laundering.</p><p class="paragraph" style="text-align:left;">🇨🇳 🦠 <b>A China-linked group called UAT-7810 is expanding its ORB network by hacking internet-facing routers</b> and other devices. They <a class="link" href="https://blog.talosintelligence.com/uat-7810/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">upgraded their malware</a> from <b>ShortLeash</b> to a more capable <i>LONGLEASH</i> and added tools like <i>DOGLEASH</i> and <i>LEASHTEST</i>. The group exploits known router flaws to build relay servers that other threat actors can use.</p><p class="paragraph" style="text-align:left;">🇪🇸 🇷🇺 <b>Spain&#39;s police arrested a man suspected of helping pro-Russian hacktivist groups CARR and Z-Pentest</b> — He is accused of aiding a hacker, coordinating with group members, and trying to help the hacker flee to Russia. Authorities <a class="link" href="https://www.bleepingcomputer.com/news/security/spain-arrests-suspected-member-of-pro-russian-hacktivist-groups/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">seized computers and crypto wallets</a> and say he may face terrorism and computer crime investigations.</p><p class="paragraph" style="text-align:left;">🇺🇸 ⚖️ <b>Prosecutors say a persistent Windows device ID helped link 19-year-old Peter Stokes</b> to a May 2025 jewelry retailer breach. Attackers used social engineering to get help-desk password resets, tunneled out 77 GB, and <a class="link" href="https://thehackernews.com/2026/07/court-filing-reveals-windows-device-id.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">tried to deploy ransomware</a>. Experts warn <b>Scattered Spider</b> is a loose collective, so one arrest may not stop future attacks.</p><p class="paragraph" style="text-align:left;">🇨🇳 📧 <b>China-aligned attackers used two </b><i><b>Roundcube</b></i><b> email client vulnerabilities to break into U.S. and Canadian</b> university networks. They targeted physics and engineering staff to steal credentials and install webshells and backdoors for persistent access. <b>Proofpoint</b> <a class="link" href="https://www.proofpoint.com/us/blog/threat-insight/one-email-closer-edge-unkmasstraction-physics-exploitation?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">says fewer than 10 victims were confirmed</a> but many more may be affected.</p><p class="paragraph" style="text-align:left;">🇮🇷 🇮🇱 <b>An Iran-linked hacking group called </b><i><b>Cavern Manticore</b></i><b> uses a new modular C2 framework named Cavern to target Israeli IT providers</b> and government organizations. The malware uses varied <b>.NET</b> compilation methods and DLL modules to evade analysis, persist, and load mission-specific tools for reconnaissance, data theft, tunneling, and lateral movement. Attackers <a class="link" href="https://research.checkpoint.com/2026/cavern-manticore-exposing-iran-linked-modular-c2-framework/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">abused trusted software updates and RMM tools</a> to move through supply chains and exfiltrate sensitive data.</p><p class="paragraph" style="text-align:left;">🇻🇳 <b>Vietnamese authorities arrested seven people accused of running </b><i><b>HiAnime</b></i>, a major anime piracy streaming service. The site hosted over 26,000 pirated anime titles, drew hundreds of millions of visits, and earned about $12.85 million in illegal ad revenue. The <a class="link" href="https://www.bleepingcomputer.com/news/security/vietnam-arrests-suspects-behind-hianime-anime-piracy-service/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">arrests follow a multi-year investigation supported by international partners</a> and the anti-piracy group ACE.</p><p class="paragraph" style="text-align:left;">⚡️ <b>Armored Likho is a hacking group attacking governments and electric power companies</b> in several countries. They <a class="link" href="https://securelist.com/tr/armored-likho-apt-with-busysnake-stealer/120292/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">use phishing emails to install stealthy malware</a> that steals passwords, screenshots, and other sensitive data. Their tools give them remote control over infected computers to spy and steal information.</p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;">🗓️ <b><a class="link" href="https://xsa.github.io/infosec-events/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">{Cyber,Info}Sec Events</a></b> — A community-maintained list of infosec conferences worldwide. Subscribe to the <a class="link" href="https://xsa.github.io/infosec-events/events.ics?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">ICS calendar feed</a> to get events straight into your calendar, or follow <a class="link" href="https://infosec.exchange/@infosecevents?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">@infosecevents@infosec.exchange</a> on Mastodon for weekly digests. Contributions and ⭐ welcome!</p></div><p class="paragraph" style="text-align:left;"></p><div id="government-politics-and-privacy" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">👨🏻‍⚖️ 👀 GOVERNMENT, POLITICS, AND PRIVACY</h3><p class="paragraph" style="text-align:left;">🇬🇧 🤖 <b>The UK launched </b><i><b>Cyber Shield</b></i><b> to build national agentic AI defenses</b> that <a class="link" href="https://www.securityweek.com/uk-government-rolls-out-agentic-ai-defense-plan-alongside-industry-pledge/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">find and fix vulnerabilities at machine speed</a>. Critics warn many organizations still fail basic cyber hygiene and may struggle to adopt autonomous AI defenses. The government also unveiled a voluntary <i>Cyber Resilience Pledge</i> to push board accountability, early warning enrollment, and supply-chain standards.</p><p class="paragraph" style="text-align:left;">🇺🇸 <b>A Senate committee approved language for a pilot letting the Defense Department hire private contractors</b> to <a class="link" href="https://www.databreachtoday.com/american-hackers-for-hire-proposal-sparks-heavy-criticism-a-32176?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">conduct cyberoperations under U.S. Cyber Command</a>. Critics warn this could undermine government control, increase global cyber instability, and create dangerous escalation and accountability problems. Supporters say industry can fill capacity gaps if tightly overseen.</p><p class="paragraph" style="text-align:left;">🇨🇦 <b>Canada’s spy agency, the Communications Security Establishment (CSE), said it carried out several state-authorized cyberattacks</b> last year to disrupt threats to Canada. The <a class="link" href="https://techcrunch.com/2026/07/06/canadian-spy-agency-says-it-hacked-drug-traffickers-extremists-and-a-ransomware-gang-last-year/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">operations targeted fentanyl brokers, an overseas extremist group, and a ransomware-as-a-service gang</a>, reducing their ability to harm Canadians. <b>CSE</b> also ran a defensive operation to disrupt a phishing campaign against federal institutions.</p></div><p class="paragraph" style="text-align:left;"></p><div id="malware-threats" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🦠 MALWARE & THREATS</h3><p class="paragraph" style="text-align:left;">🏦 🇷🇺 <i><b>RedWing</b></i><b> is an Android malware sold on Telegram as an easy bank-fraud rental service</b> that builds custom malicious apps for buyers. It <a class="link" href="https://zimperium.com/blog/redwing-a-mobile-malware-as-a-service-operation?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">tricks victims into sideloading fake apps</a> and granting Accessibility and other permissions to steal logins, one-time codes, and control phones. Researchers link it to Russian-focused campaigns and warn to only install apps from official stores and refuse suspicious permission requests.</p><p class="paragraph" style="text-align:left;">🐀 📲 <b>Attackers use fake Microsoft Teams calls pretending to be IT to get employees to install remote-access tools</b> <a class="link" href="https://www.bleepingcomputer.com/news/security/fake-it-support-calls-on-microsoft-teams-push-etherrat-malware/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">and a malicious MSI</a>. The MSI loads <b>EtherRAT</b>, a Node.js remote access trojan that steals data, runs commands, and keeps persistent access. <b>Microsoft</b> added warnings and admin controls to help block these impersonation and vishing attacks.</p><p class="paragraph" style="text-align:left;">🇨🇳 🐀 🇮🇳 <b>Researchers found a phishing campaign targeting Indian taxpayers that tricks users into downloading a fake tax utility</b> which installs a <a class="link" href="https://www.seqrite.com/blog/operation-dragonreturn-china-nexus-cyber-espionage-campaign-targeting-govt-of-india-mof-tax-infrastructure-via-multi-stage-dcrat-deployment/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">remote access trojan (DcRAT)</a>. The malware uses DLL sideloading, image-based payload concealment, and Windows service persistence to steal data and maintain access. Infrastructure links and tactics point to a China-associated actor likely aiming for credential theft and long-term espionage.</p><p class="paragraph" style="text-align:left;">🐀 <b>Researchers discovered </b><i><b>QuimaRAT</b></i><b>, a Java-based remote access trojan</b> that runs on Windows, Linux, and macOS. It is <a class="link" href="https://www.levelblue.com/blogs/spiderlabs-blog/novel-java-based-quimarat-targets-windows-macos-and-linux?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">sold as malware-as-a-service</a> with modular plugins, builders, loaders, and persistence features to evade detection. <b>QuimaRAT</b> gives attackers broad control (commands, credential theft, fileless execution) and uses flexible C2 methods for persistent access.</p></div><p class="paragraph" style="text-align:left;"></p><div id="ai-crypto-tech-tools" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🤖 🧰 AI, CRYPTO, TECH & TOOLS</h3><p class="paragraph" style="text-align:left;">🔓️ <b>Researchers tested 281 free Android VPN apps and found</b> many <a class="link" href="https://thehackernews.com/2026/07/study-of-281-free-android-vpn-apps.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">leak traffic, send data unencrypted, or include tracking</a>. These problems affect apps with over 2.4 billion installs and include five that download config files in clear text, allowing tunnel hijacking. The study warns users to trust only audited providers and says store &quot;verified&quot; labels are not a security guarantee.</p><p class="paragraph" style="text-align:left;">🇫🇷 🧪 <b>The Paris Peace Forum is launching </b><i><b>INTAiC</b></i><b>, a global hub to study AI-driven cyber threats</b> — It will unite researchers, companies, and governments to share evidence and produce practical reports. The <a class="link" href="https://cyberscoop.com/paris-peace-forum-intaic-ai-cyber-threats/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">goal is a fast, international coalition</a> to detect and respond to AI-related attacks.</p><p class="paragraph" style="text-align:left;">🔍️ <b>CISA is using Anthropic’s Mythos AI to scan federal software</b> for security flaws. The AI audits, run by CISA’s Attack Surface Evaluation team, have <a class="link" href="https://www.securityweek.com/cisa-reportedly-using-anthropics-mythos-to-scan-government-software-for-flaws/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">reportedly found many vulnerabilities</a>. Details and official comments from <b>CISA</b> or <b>Anthropic</b> were not released.</p><p class="paragraph" style="text-align:left;">⚖️ <b>A class-action lawsuit against xAI’s Grok tool was expanded to include two more anonymous plaintiffs who say the AI made nonconsensual deepfake</b> child sexual abuse images from their real photos. The suit alleges <b>Grok</b> enabled widespread sharing of the images, caused severe harm, and that <b>xAI</b> failed to provide law enforcement with the generated files. The complaint also adds <b>Stability AI</b>, <a class="link" href="https://cyberscoop.com/deepfake-csam-lawsuit-grok-xai-expands-stability-ai/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">claiming its open models and weakened safeguards</a> helped fuel tools that produce CSAM.</p><p class="paragraph" style="text-align:left;">🇪🇺 <b>The EU unveiled an action plan to boost domestic AI and cybersecurity capabilities and reduce reliance on foreign models</b> — It will build EU evaluation capacity, <a class="link" href="https://www.databreachtoday.com/eu-pushes-for-domestic-ai-momentum-a-32171?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">a secure testing platform</a>, and a &quot;grand challenge&quot; for AI-assisted vulnerability remediation. Regulators urge banks and critical sectors to speed up patching, monitoring, and risk plans to prevent systemic disruption.</p><p class="paragraph" style="text-align:left;">👀 <b>A researcher found hidden code in Anthropic’s Claude Code that encoded a stealth marker</b> into a harmless-looking date string. <b>Anthropic</b> <a class="link" href="https://www.malwarebytes.com/blog/news/2026/07/claude-codes-hidden-tracker-was-an-experiment-says-anthropic?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">said it was an “experiment”</a> to detect abuse and removed the code but gave no detailed explanation. The incident raised concerns about trust, telemetry, and potential targeting of developers using AI tools.</p><p class="paragraph" style="text-align:left;">💸 <b>Researchers at Sysdig say an AI agent ran most steps of a late‑June 2026 ransomware attack</b>, automating reconnaissance, credential theft, lateral movement, persistence and encryption. The <a class="link" href="https://cyberscoop.com/sysdig-judepuffer-ai-agentic-ransomware-attack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">agent executed over 600 purposeful payloads</a>, fixed errors in seconds, and used multiple models and API keys. A human still set up and targeted the operation, but the event shows AI greatly lowers the skill needed to run ransomware.</p></div><p class="paragraph" style="text-align:left;"></p><div id="vulnerabilities-research-and-threat" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🐛 🧠 VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</h3><p class="paragraph" style="text-align:left;">➝ From the Patching Department:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://thehackernews.com/2026/07/beyondtrust-patches-critical-auth.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/chrome-150-update-patches-27-vulnerabilities/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">Chrome 150 Update Patches 27 Vulnerabilities</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-rogueplanet-defender-zero-day-vulnerability/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">Microsoft patches RoguePlanet Defender zero-day vulnerability</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/palo-alto-networks-patches-13-vulnerabilities/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">Palo Alto Networks Patches 13 Vulnerabilities</a></p></li></ul><hr class="content_break"><p class="paragraph" style="text-align:left;">🐛 <b>A critical prompt injection flaw in GitHub Agentic Workflows called &quot;</b><i><b>GitLost</b></i><b>&quot;</b> lets unauthenticated attackers trick AI agents via crafted public issues. The agents can be made to read and leak files from both public and private repositories. <b>Noma Labs</b> <a class="link" href="https://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">urges treating user content as untrusted</a>, tightening agent permissions, and sanitizing inputs.</p><p class="paragraph" style="text-align:left;">🩹 <b>Ubiquiti released patches for seven critical UniFi OS vulnerabilities</b>, including a max-severity command injection flaw (CVE-2026-50746). The <a class="link" href="https://www.bleepingcomputer.com/news/security/ubiquiti-warns-of-new-max-severity-unifi-os-vulnerability/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">flaw affects UniFi Connect</a> and could let a network attacker run commands on the host, so users should update to version 3.4.20 or later. Thousands of UniFi OS instances are exposed online, and similar <b>Ubiquiti</b> flaws have been actively exploited by threat actors.</p><p class="paragraph" style="text-align:left;">💥 <b>Attackers are exploiting a critical Adobe ColdFusion flaw (CVE-2026-48282)</b> — <b>Adobe</b> released urgent patches and <a class="link" href="https://www.bleepingcomputer.com/news/security/max-severity-adobe-coldfusion-flaw-now-exploited-in-attacks/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">urged admins to update</a> within 72 hours. Canadian authorities warn many online <b>ColdFusion</b> instances remain exposed.</p><p class="paragraph" style="text-align:left;">🐧 <b>A 16-year-old use-after-free bug in Linux KVM called Januscape (CVE-2026-53359)</b> lets a <a class="link" href="https://thehackernews.com/2026/07/16-year-old-linux-kvm-flaw-lets-guest.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">guest VM corrupt the host&#39;s shadow-page state and crash the host</a>. The bug affects both Intel and AMD x86 when nested virtualization is enabled and can be escalated to full host code execution. Patch kernels contain commit 81ccda30b4e8 or disable nested virtualization to mitigate.</p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://arstechnica.com/security/2026/07/high-severity-guest-vm-escape-is-1-of-2-linux-vulnerabilities-to-surface-this-week/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">Google pays $250K for Linux vulnerability allowing guest VM escapes</a></p><p class="paragraph" style="text-align:left;">🐧 <b>Researchers found </b><i><b>GhostLock</b></i><b>, a 15-year-old Linux kernel bug</b> that <a class="link" href="https://nebusec.ai/research/ionstack-part-2/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">lets any logged-in user become root </a>and escape containers. The flaw, present in most distributions since 2011, was fixed in April but patches are still rolling out and early fixes had issues. Install your distro&#39;s final patched kernel now, especially on shared, cloud, and container hosts.</p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://www.securityweek.com/proof-of-concept-exploit-released-for-linux-bad-epoll-root-access-vulnerability/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">Proof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access Vulnerability</a></p></div><p class="paragraph" style="text-align:left;"></p><div id="ics-ot-io-t" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🛰️ ICS, OT & IoT</h3><p class="paragraph" style="text-align:left;">🔙 🚪<b>CERT/CC found a hidden backdoor in several Tenda router firmware versions</b> that <a class="link" href="https://kb.cert.org/vuls/id/213560?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">lets attackers bypass the login</a> and gain admin access (CVE-2026-11405). The backdoor compares a special config-stored password in plaintext and accepts any username with that password. Users should disable remote management and change the default LAN IP until a patch is available.</p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">💬 CONNECT</h3><p class="paragraph" style="text-align:left;">Follow me on <a class="link" href="https://infosec.exchange/@0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">Mastodon</a> for quick daily updates and bite-sized content.</p><p class="paragraph" style="text-align:left;">Prefer using an RSS feed? Add <b>Infosec MASHUP</b> to your feed <a class="link" href="https://rss.beehiiv.com/feeds/HVhiKYpQlR.xml?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">here</a>.</p><p class="paragraph" style="text-align:center;"><b>Enjoying our newsletter? </b>Forward it to a colleague—<br>it’s one of the best ways to support us.</p><p class="paragraph" style="text-align:left;">Thanks for reading today’s newsletter, and if you&#39;re enjoying it and want to support my work, you can <b>buy me a coffee</b> ☕ over at <a class="link" href="https://www.buymeacoffee.com/0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-28-2026-the-agent-ran-the-attack-the-human-just-aimed" target="_blank" rel="noopener noreferrer nofollow">https://www.buymeacoffee.com/0x58</a></p><p class="paragraph" style="text-align:left;"> See you next time!</p><p class="paragraph" style="text-align:left;">-X.</p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=4ec04a62-bb8a-4547-9094-1299a25d084a&utm_medium=post_rss&utm_source=x_s_infosec_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🕵🏻‍♂️ [InfoSec MASHUP] 26/2026 - Project Glasswing Proved the Point Nobody Wanted Proved</title>
  <description>Plus: North Korea poisoned 141 npm packages in 45 minutes, FortiBleed exposed 430,000+ FortiGate credentials, and a 1997 Squid Proxy bug finally got a CVE</description>
  <link>https://infosec-mashup.santolaria.net/p/infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved</link>
  <guid isPermaLink="true">https://infosec-mashup.santolaria.net/p/infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved</guid>
  <pubDate>Sat, 27 Jun 2026 08:55:00 +0000</pubDate>
  <atom:published>2026-06-27T08:55:00Z</atom:published>
    <dc:creator>Xavier Santolaria</dc:creator>
    <category><![CDATA[Malware]]></category>
    <category><![CDATA[Opensource]]></category>
    <category><![CDATA[Privacy]]></category>
    <category><![CDATA[Cybersecurity]]></category>
    <category><![CDATA[Threat Intelligence]]></category>
    <category><![CDATA[Ai]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><b>Anthropic&#39;s Mythos</b> model found real vulnerabilities in classified U.S. government systems. Not in a lab, not against synthetic targets — in actual production infrastructure, during sanctioned testing under <b>Project Glasswing</b>. The model did exactly what a capable offensive security tool should do: it found things that humans had missed, in systems that presumably had people paid to look. The U.S. government&#39;s response to this demonstration has been to restrict access to Anthropic&#39;s most capable models over security concerns.</p><p class="paragraph" style="text-align:left;">The circular logic is almost elegant. The argument for keeping powerful AI out of defenders&#39; hands is that it&#39;s too dangerous. The argument for putting it in defenders&#39; hands just ran live in a classified environment and found bugs. The security research community has been pushing back on the model restrictions for weeks. <b>Project Glasswing</b> just handed them their best exhibit yet — and the administration appears to be looking the other way.</p><h2 class="heading" style="text-align:left;">Table of Contents</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="#breaches-security-incidents" rel="noopener noreferrer nofollow">BREACHES & SECURITY INCIDENTS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#cybercrime-cyber-espionage-ap-ts" rel="noopener noreferrer nofollow">CYBERCRIME, CYBER ESPIONAGE, APT’s</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#government-politics-and-privacy" rel="noopener noreferrer nofollow">GOVERNMENT, POLITICS, AND PRIVACY</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#malware-threats" rel="noopener noreferrer nofollow">MALWARE & THREATS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ai-crypto-tech-tools" rel="noopener noreferrer nofollow">AI, CRYPTO, TECH & TOOLS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#vulnerabilities-research-and-threat" rel="noopener noreferrer nofollow">VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ics-ot-io-t" rel="noopener noreferrer nofollow">ICS, OT & IoT</a></p></li></ul><div id="breaches-security-incidents" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🔓 BREACHES & SECURITY INCIDENTS</h3><p class="paragraph" style="text-align:left;">💸 <b>Polymarket says hackers stole users’ crypto</b> after a third-party vendor was compromised. The company says it contained the issue and will contact and refund affected users. Blockchain monitors <a class="link" href="https://techcrunch.com/2026/06/25/polymarket-says-hackers-stole-users-funds/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">estimate about $3 million stolen</a> from multiple victims.</p><p class="paragraph" style="text-align:left;">🇮🇳 <b>Tata Electronics says it suffered a cyberattack</b> that affected some IT systems. The <a class="link" href="https://www.bleepingcomputer.com/news/security/tata-electronics-confirms-cyberattack-as-hackers-leak-data/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">company says operations were not disrupted</a>. A hacker group called <i><b>World Leaks</b></i> claimed it leaked manufacturing files, including alleged <b>Apple</b> component data.</p><p class="paragraph" style="text-align:left;">🔓️ <b>LastPass says hackers stole OAuth tokens from Klue and used them to access customer data</b> in its Salesforce system. The breach did not affect <b>LastPass</b> products or customer vaults, but names, contacts, addresses, and CRM details may be exposed. <b>LastPass</b> <a class="link" href="https://blog.lastpass.com/posts/klue-supply-chain-incident-and-lastpass-response?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">rotated tokens</a>, cut <b>Klue</b> access, warned customers, and notified law enforcement.</p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://techcrunch.com/2026/06/23/klue-says-hackers-stole-credential-from-2022-that-led-to-customer-data-breaches/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">Klue says hackers stole credential from 2022 that led to customer data breaches</a></p><p class="paragraph" style="text-align:left;">🇨🇦 ⚡️ <b>Canadian electricity provider </b><i><b>London Hydro</b></i><b> says hackers accessed its systems</b> and <a class="link" href="https://www.securityweek.com/canadian-electricity-provider-london-hydro-discloses-data-breach/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">may have taken some customers&#39; personal and account information</a>. The data possibly exposed includes names, addresses, emails, phone numbers, account and billing details, and meter information. The company reports no financial or highly sensitive data was accessed and warns customers to watch for phishing or suspicious activity.</p><p class="paragraph" style="text-align:left;">💸 <b>An attacker tricked the </b><i><b>JaredFromSubway</b></i><b> MEV bot with fake tokens and pools and stole $15 million</b> — The <a class="link" href="https://www.bleepingcomputer.com/news/security/jaredfromsubway-mev-bot-hacked-in-15-million-crypto-theft/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">bot auto-approved attacker contracts</a>, letting them drain WETH, USDC, and USDT. <b>JaredFromSubway</b> offered increasing bounties and is negotiating with a white-hat group to recover funds.</p><p class="paragraph" style="text-align:left;">🇺🇸 <b>Xsolis, a healthcare technology vendor, suffered a targeted phishing attack</b> on January 22, 2026 that <a class="link" href="https://databreaches.net/2026/06/22/xsolis-breach-affected-1396519-of-its-clients-patients/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">exposed data for 1,396,519 patients</a>. The breach may have included names, contact details, Social Security numbers, insurance and medical treatment information. <b>Xsolis</b> contained the incident, reset passwords, added security measures, and offered affected people 12 months of identity monitoring.</p></div><p class="paragraph" style="text-align:left;"></p><div id="cybercrime-cyber-espionage-ap-ts" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🥷🏻 CYBERCRIME, CYBER ESPIONAGE, APT’s</h3><p class="paragraph" style="text-align:left;">🇵🇱 <b>Polish police arrested four people in a SIM‑swapping ring that stole millions</b> by <a class="link" href="https://www.bleepingcomputer.com/news/security/poland-busts-sim-swapping-gang-tied-to-millions-in-crypto-theft/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">hijacking phone numbers and crypto accounts</a>. The arrests followed an investigation with help from the <b>FBI</b> and <b>HSI</b>. Suspects face charges including organized crime, hacking, and money laundering, with up to 25 years in prison.</p><p class="paragraph" style="text-align:left;">🇺🇸 ⚖️ <b>Nathan Austad, 21, known as &quot;</b><i><b>Snoopy</b></i><b>&quot;, was sentenced to 18 months in prison</b> for his role in the November 2022 <b>DraftKings</b> hack. He and co-conspirators <a class="link" href="https://www.bleepingcomputer.com/news/security/draftkings-hacker-snoopy-sentenced-to-18-months-in-prison/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">compromised about 60,000 accounts</a>, added payment methods to 1,600 accounts, and stole roughly $600,000. <b>Austad</b> was also ordered to forfeit $463,684, pay $1,327,061 in restitution, and serve three years of supervised release.</p><p class="paragraph" style="text-align:left;">🇺🇸 ❌ <b>Microsoft and law enforcement used a single court order to disrupt two criminal tools at once:</b> the <b>Amadey</b> botnet and the <b>StealC</b> infostealer. They <a class="link" href="https://cyberscoop.com/microsoft-amadey-stealc-takedown/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">treated both as one conspiracy</a>, taking down over 200 command-and-control servers. The move aims to make attacks harder to mount and rebuild.</p><p class="paragraph" style="text-align:left;">🇺🇸 ❌ <b>The U.S. Justice Department seized a cloud account used by </b><i><b>HuiOne Group</b></i><b> subsidiaries that helped launder billions</b> from crypto scams. <b>HuiOne</b> <a class="link" href="https://thehackernews.com/2026/06/doj-seizes-huione-cloud-account-tied-to.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">ran a Telegram marketplace</a> selling crimeware, data, money‑laundering services, and tools for deepfakes and human trafficking. U.S. authorities and Treasury sanctions say these networks enabled massive fraud and continue to spawn successor markets.</p><p class="paragraph" style="text-align:left;">🇩🇿 ⚖️ 🇺🇸 <b>An Algerian man nicknamed &quot;SPOX&quot; was extradited from Spain and charged in the U.S. </b>for running two online cybercrime marketplaces. Prosecutors say his sites sold phishing kits and stolen credentials, <a class="link" href="https://cyberscoop.com/algerian-man-charged-cybercrime-marketplaces/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">victimizing about 5,600 people and moving roughly $900,000 in cryptocurrency</a>. He faces a conspiracy to commit bank fraud charge that carries up to 30 years in prison.</p><p class="paragraph" style="text-align:left;">🇬🇧 ⚖️ <b>Two young men pleaded guilty to hacking </b><i><b>Transport for London</b></i>, causing months of <a class="link" href="https://www.bbc.com/news/articles/czx5yp9qy0do?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">disruption and £39m in costs</a>. The attack began on 31 August 2024 and affected about 10 million customers. They admitted reckless, unauthorised access and will be sentenced on 15 July.</p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;">🗓️ <b><a class="link" href="https://xsa.github.io/infosec-events/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">{Cyber,Info}Sec Events</a></b> — A community-maintained list of infosec conferences worldwide. Subscribe to the <a class="link" href="https://xsa.github.io/infosec-events/events.ics?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">ICS calendar feed</a> to get events straight into your calendar, or follow <a class="link" href="https://infosec.exchange/@infosecevents?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">@infosecevents@infosec.exchange</a> on Mastodon for weekly digests. Contributions and ⭐ welcome!</p></div><p class="paragraph" style="text-align:left;"></p><div id="government-politics-and-privacy" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">👨🏻‍⚖️ 👀 GOVERNMENT, POLITICS, AND PRIVACY</h3><p class="paragraph" style="text-align:left;">🇺🇸 ☑️ <b>The FCC approved new rules to strengthen cybersecurity for the Emergency Alert System and Wireless Emergency Alerts</b> — The rules require basic cyber hygiene, stronger authentication, and faster security updates to prevent hijacked warnings. The <b>FCC</b> <a class="link" href="https://cyberscoop.com/fcc-undersea-cable-regulations-national-security/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">also updated undersea cable rules</a>, adding oversight and streamlined reviews for providers that meet high security standards.</p><p class="paragraph" style="text-align:left;">🇷🇺 📲 <b>Researchers say Russian authorities used Cellebrite phone-cracking tools to access the phone of jailed human rights activist</b> Andrey Pivovarov even after Cellebrite ended its contract with Russia. <b>Citizen Lab</b> <a class="link" href="https://citizenlab.ca/research/russia-breaks-into-human-rights-activists-phone-with-cellebrite/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">found evidence</a> the phone was accessed in mid-2021 and that data may have helped surveil other dissidents. <b>Cellebrite</b> says any use of its old hardware in Russia after March 2021 is unauthorized and now ineffective.</p></div><p class="paragraph" style="text-align:left;"></p><div id="malware-threats" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🦠 MALWARE & THREATS</h3><div class="embed"><a class="embed__url" href="https://www.ibm.com/think/x-force/stealc-you-later-proofpoint-x-force-support-operation-endgame-disruptions?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank"><div class="embed__content"><p class="embed__title"> StealC you later: Proofpoint and IBM X-Force support Operation Endgame disruptions | IBM </p><p class="embed__description"> Discover how Proofpoint and IBM X-Force supported Operation Endgame to disrupt StealC malware, seizing over 25.6 million stolen credentials from compromised systems, showcasing effective cybercrime disruption through global collaboration. </p><p class="embed__link"> Golo Mühr </p></div><img class="embed__image embed__image--right" src="https://www.ibm.com/content/dam/worldwide-content/stock-assets/adb-stk/ul/g/fa/1e/adobestock_632358672.jpeg/_jcr_content/renditions/cq5dam.web.1280.1280.jpeg"/></a></div><hr class="content_break"><p class="paragraph" style="text-align:left;">🍎 🇰🇵 <b>Researchers discovered a new macOS malware called </b><i><b>Gaslight</b></i><b> that steals data</b> and maintains control via a Telegram-based command channel. It embeds a prompt-injection payload that aims to fool AI analysis tools into aborting or refusing to analyze it. <b>SentinelOne</b> <a class="link" href="https://www.sentinelone.com/labs/macos-gaslight-rust-backdoor-turns-prompt-injection-on-the-analyst-not-the-sandbox/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">links the Rust implant to North Korea-aligned actors</a> and notes it exfiltrates browser, system, and keychain data.</p><p class="paragraph" style="text-align:left;">🍎 <b>A new ClickFix campaign tricks Mac users into pasting a Terminal command that downloads and silently mounts</b> a malicious DMG. The <a class="link" href="https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2026-06-20-ClickFix-campaign-delivers-macOS-infostealer-via-DMG.txt?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">DMG installs the Atomic macOS Stealer</a>, which grabs browser credentials, crypto wallets, Keychain items, messaging data, and documents. Users should never run unknown Terminal commands or follow fake CAPTCHA/system fix instructions.</p><p class="paragraph" style="text-align:left;">🐀 <b>A threat actor called </b><i><b>Woodgnat</b></i><b> (aka </b><i><b>KongTuke</b></i><b>) is using a new RAT called </b><i><b>Mistic</b></i><b> to gain access to many organizations</b> and sell that access to ransomware groups. <b>Mistic</b> is <a class="link" href="https://www.security.com/threat-intelligence/new-mistic-backdoor-modelorat?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">deployed as a sideloaded DLL</a> and can download/upload files, run code, steal credentials, and self-terminate. The group uses compromised sites, social engineering, and Teams helpdesk lures to trick victims into running malicious PowerShell commands.</p><p class="paragraph" style="text-align:left;">🐀 <b>Researchers found malicious npm packages pretending to be PostCSS tools</b> that <a class="link" href="https://research.jfrog.com/post/from-postcss-typosquat-to-windows-rat/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">install a Windows remote access trojan (RAT)</a>. The packages drop a PowerShell script that downloads a ZIP with VBScript, a Python runtime, and native modules that steal Chrome data, run commands, and communicate with a C2 server. Users should remove the packages, delete any artifacts, and rotate credentials.</p><p class="paragraph" style="text-align:left;">🇰🇵 <b>North Korean state-backed hackers (</b><i><b>Sapphire Sleet</b></i><b>) injected a malicious typosquat dependency into 141 Mastra npm packages</b> during <a class="link" href="https://www.microsoft.com/en-us/security/blog/2026/06/17/postinstall-payload-inside-mastra-npm-supply-chain-compromise/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">a 45-minute window on June 17</a>. The malware ran at install time, targeted Windows/macOS/Linux, and aimed to steal system data and crypto-wallets. Users who ran npm install/update then should remove affected versions, scan for malware, and rotate secrets.</p><p class="paragraph" style="text-align:left;">🏰 <b>Researchers found a new loader called OXLOADER that uses malicious Google Ads</b> to <a class="link" href="https://www.elastic.co/security-labs/oxloader-malware-loader-infostealer?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">trick users into running a fake installer</a> and fetch <b>CastleStealer</b>. The attack hides its code with strong obfuscation, uses Storj-hosted files, and avoids targets in CIS countries. <b>OXLOADER</b> is new but well engineered, giving it low detection and time to operate.</p><p class="paragraph" style="text-align:left;">🤖 🕸️ <b>A new malware called </b><i><b>AryStinger</b></i><b> has infected about 4,300 old home routers</b> to <a class="link" href="https://blog.xlab.qianxin.com/arystinger-botnet-hijacks-legacy-routers-for-global-attacks-en/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">build a reconnaissance and proxy network</a>. Infected devices scan, fingerprint targets, tunnel traffic, and relay commands for attackers while hiding their location. Owners should retire unsupported routers, check for unknown binaries and C2 connections, and disable remote admin.</p><hr class="content_break"><div class="embed"><a class="embed__url" href="https://unit42.paloaltonetworks.com/openclaw-ai-supply-chain-risk/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank"><div class="embed__content"><p class="embed__title"> OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat </p><p class="embed__description"> Unit 42&#39;s analysis of ClawHub revealed evasive malicious skills bypassing automated scanners to deploy infostealers and execute agentic financial fraud. </p><p class="embed__link"> Unit 42 • Shresta Bellary Seetharam, Nabeel Mohamed, Billy Melicher, Oleksii Starov </p></div><img class="embed__image embed__image--right" src="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/AdobeStock_768915868-1.jpg"/></a></div></div><p class="paragraph" style="text-align:left;"></p><div id="ai-crypto-tech-tools" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🤖 🧰 AI, CRYPTO, TECH & TOOLS</h3><p class="paragraph" style="text-align:left;">🔐 <b>OpenAI released GPT-5.5-Cyber and an updated Codex Security plugin</b> to help defenders find, validate, and patch software vulnerabilities faster. They also launched <b><a class="link" href="https://openai.com/index/patch-the-planet/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">Patch the Planet</a></b><b> </b>to support open-source projects and scale patch development with human oversight. The <a class="link" href="https://openai.com/index/daybreak-securing-the-world/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">moves</a> aim to close the gap between rapid AI-driven discovery and slower patching while keeping maintainers in control.</p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://newsroom.ibm.com/2026-06-22-ibm-and-openai-bring-frontier-ai-to-cyber-defense-helping-enterprises-keep-pace-with-machine-speed-threats?mkt_tok=NzkzLVZCTS05MTUAAAGikEICVagOznk3jl5Tfbe3zSI95TCalAKl5MylIOjt-aduuagCcKT8IicoTZHSzx_j4H-HonU5R56RBQWvjfjDd-KVk_vmVAqpqMOPpKxbNrYL&utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">IBM announced it has joined the OpenAI Daybreak Cyber Partner Program</a></p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://techcrunch.com/2026/06/25/the-white-house-is-asking-openai-to-slow-roll-the-release-of-its-new-model-over-safety-concerns/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">The White House is asking OpenAI to slow roll the release of its new model over safety concerns</a></p><p class="paragraph" style="text-align:left;">🐛 <b>Four serious vulnerabilities in the open-source Dify AI platform could let attackers steal other customers’ data</b> in multi-tenant cloud setups. These <a class="link" href="https://www.securityweek.com/data-exposure-flaws-threaten-dify-ai-platform-powering-over-1-million-apps/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">flaws</a> let attackers read private chats, access files, and call internal APIs across tenants. <code>Dify 1.14.2</code> fixes the issues; users should update immediately and apply WAF rules for extra protection.</p><p class="paragraph" style="text-align:left;">🐛 <b>The Anthropic AI model called Mythos found vulnerabilities in highly classified U.S. government systems</b> during tests. The testing was part of <b>Project Glasswing</b> with U.S. agencies, though <a class="link" href="https://www.securityweek.com/anthropics-mythos-model-found-vulnerabilities-in-classified-us-government-systems-official-says/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">finding flaws did not mean they were immediately exploited</a>. The move has sparked tensions with the government, which restricted access to Anthropic’s models over security concerns.</p><p class="paragraph" style="text-align:left;">🇺🇸 🔐 <b>The Trump administration will issue orders to speed up the federal shift to quantum-resistant encryption</b> and to <a class="link" href="https://cyberscoop.com/trump-executive-order-post-quantum-encryption-deadline/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">boost the domestic quantum computing industry</a>. Agencies may be forced to meet a new deadline around 2029–2030 for civilian networks and must report to OMB if they miss it. The actions aim to steer federal funding and research to help U.S. quantum companies compete.</p></div><p class="paragraph" style="text-align:left;"></p><div id="vulnerabilities-research-and-threat" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🐛 🧠 VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</h3><p class="paragraph" style="text-align:left;">➝ From the Patching Department:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/25-year-old-vulnerability-patched-in-curl/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">25-Year-Old Vulnerability Patched in Curl</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/chrome-149-update-resolves-18-severe-vulnerabilities/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">Chrome 149 Update Resolves 18 Severe Vulnerabilities</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/gitlab-patches-code-execution-information-disclosure-vulnerabilities/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">GitLab Patches Code Execution, Information Disclosure Vulnerabilities</a></p></li></ul><hr class="content_break"><p class="paragraph" style="text-align:left;">🔎 <b>Mandiant revealed that attackers abused a Cisco SD-WAN command-injection flaw (CVE-2026-20245) </b>to create a rogue root account named &quot;<i>troot</i>&quot; and <a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">gain full control of devices</a>. The intrusions began with unauthorized SD-WAN peering and likely used earlier authentication bypasses to access admin interfaces. <b>Mandiant</b> urges collecting diagnostics, checking for rogue peering, and applying <b>Cisco</b>&#39;s security updates.</p><p class="paragraph" style="text-align:left;">💥 <b>CISA warns attackers are exploiting three critical Ubiquiti UniFi OS vulnerabilities (CVE-2026-34908/34909/34910)</b> that allow bypassing authentication, accessing files, and <a class="link" href="https://www.securityweek.com/critical-ubiquiti-vulnerabilities-in-attackers-crosshairs/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">performing command injection</a>. <b>Ubiquiti</b> released patches in <code>UniFi OS Server 5.0.8</code>, but reports and analyses show these flaws were likely used in automated in-the-wild attacks to create rogue admin accounts. CISA added them to its KEV list and urges urgent patching within three days.</p><p class="paragraph" style="text-align:left;">📲 <b>Researchers found an eight-year-old high-severity flaw in Samsung KNOX that affected Galaxy S9 through S25</b> and many A-series phones. The <a class="link" href="https://www.securityweek.com/eight-year-old-samsung-knox-flaw-exposed-millions-of-galaxy-devices-to-kernel-attacks/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">bug is a race-condition use-after-free in the kernel </a>that could be triggered by an untrusted app to corrupt kernel memory. Samsung patched it in the January 2026 update, so users should install updates immediately.</p><p class="paragraph" style="text-align:left;">🍎 📲 <b>Researchers disclosed </b><i><b>Usbliter8</b></i><b>, a new BootROM exploit that permanently bypasses Apple’s secure boot </b>on iPhones with A12/A13 chips and some Apple Watches. The <a class="link" href="https://ps.tc/pages/blog-usbliter8.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">attack needs physical USB access</a> and lets an attacker run unsigned code with full processor privileges, though it does not directly break the Secure Enclave. The exploit cannot be fixed by software updates and the researchers published proof-of-concept code.</p><p class="paragraph" style="text-align:left;">🔥 🧱 🩸 <b>A Russian initial-access broker is running the </b><i><b>FortiBleed</b></i><b> campaign</b> to <a class="link" href="https://www.securityweek.com/russian-initial-access-broker-behind-fortibleed-campaign/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">harvest credentials from over 430,000</a> <b>FortiGate</b> firewalls and other devices. They compromise exposed appliances, deploy a Golang sniffer to capture and crack authentication data, then sell access or use it for further intrusions. The operation has exposed millions of credentials and targeted MSPs, SMBs, and high-value organizations including a NATO-aligned contractor.</p><p class="paragraph" style="text-align:left;">🦑 <b>Researchers found a memory-leak bug in Squid Proxy, dubbed </b><i><b>Squidbleed</b></i>, that dates back to 1997. The <a class="link" href="https://blog.calif.io/p/squidbleed-cve-2026-47729?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">flaw can expose other users&#39; cleartext HTTP request data </a>(like passwords and tokens) if the proxy handles FTP and is shared by many users. A patch is available and disabling FTP in Squid stops the risk.</p></div><p class="paragraph" style="text-align:left;"></p><div id="ics-ot-io-t" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🛰️ ICS, OT & IoT</h3><p class="paragraph" style="text-align:left;">💥 <b>A critical flaw (CVE-2025-67038) in Lantronix EDS5000 serial-to-IP devices lets unauthenticated attackers run root commands</b> and is <a class="link" href="https://www.securityweek.com/lantronix-serial-to-ip-converter-flaw-exploited-in-attacks-after-ot-threat-warning/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">being exploited in the wild</a>, <b>CISA</b> says. The bug is part of the <code>BRIDGE:BREAK</code> set of serial-to-IP vulnerabilities that can let attackers manipulate sensors, spread laterally, and exfiltrate data. Thousands of <b>Lantronix</b> devices are internet-exposed, though it’s unclear how many are vulnerable or which sectors are being targeted.</p><p class="paragraph" style="text-align:left;">🗒️ <b>NIST released an updated draft of its IoT product cybersecurity guidelines</b> and is <a class="link" href="https://www.securityweek.com/nist-opens-updated-iot-security-guidance-to-public-review/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">asking for public comments through August 24</a>. The update clarifies how IoT products should be treated in risk assessments and aligns requirements with current threats. Organizations are urged to use the guidance and related <b>NIST</b> risk-management publications when integrating IoT products.</p><p class="paragraph" style="text-align:left;">🇨🇦 <b>Canada’s spy agency got a judge-approved warrant to access and neutralize two foreign-run botnets on Canadian servers</b>, routers, and IoT devices. The court <a class="link" href="https://thehackernews.com/2026/06/canadas-spy-agency-used-first-of-its.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">found the threat imminent and allowed CSIS to alter or destroy botnet</a> data while avoiding targeting people or content. The operation highlights risks from unmaintained consumer gear and leaves open legal questions about warrantless IP collection.</p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">💬 CONNECT</h3><p class="paragraph" style="text-align:left;">Follow me on <a class="link" href="https://infosec.exchange/@0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">Mastodon</a> for quick daily updates and bite-sized content.</p><p class="paragraph" style="text-align:left;">Prefer using an RSS feed? Add <b>Infosec MASHUP</b> to your feed <a class="link" href="https://rss.beehiiv.com/feeds/HVhiKYpQlR.xml?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">here</a>.</p><p class="paragraph" style="text-align:center;"><b>Enjoying our newsletter? </b>Forward it to a colleague—<br>it’s one of the best ways to support us.</p><p class="paragraph" style="text-align:left;">Thanks for reading today’s newsletter, and if you&#39;re enjoying it and want to support my work, you can <b>buy me a coffee</b> ☕ over at <a class="link" href="https://www.buymeacoffee.com/0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-26-2026-project-glasswing-proved-the-point-nobody-wanted-proved" target="_blank" rel="noopener noreferrer nofollow">https://www.buymeacoffee.com/0x58</a></p><p class="paragraph" style="text-align:left;"> See you next time!</p><p class="paragraph" style="text-align:left;">-X.</p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=cdd963d0-18dd-4296-ae66-e6f42be4b8a8&utm_medium=post_rss&utm_source=x_s_infosec_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🕵🏻‍♂️ [InfoSec MASHUP] 25/2026 - Client-Side Authorization Is Not Authorization</title>
  <description>Plus: The SocGholish botnet is down after nine years, Texas leaked 3M driver&#39;s licenses and passports, and dozens of cybersecurity vets are calling the Anthropic ban dangerous</description>
  <link>https://infosec-mashup.santolaria.net/p/infosec-mashup-25-2026-client-side-authorization-is-not-authorization</link>
  <guid isPermaLink="true">https://infosec-mashup.santolaria.net/p/infosec-mashup-25-2026-client-side-authorization-is-not-authorization</guid>
  <pubDate>Sat, 20 Jun 2026 08:45:00 +0000</pubDate>
  <atom:published>2026-06-20T08:45:00Z</atom:published>
    <dc:creator>Xavier Santolaria</dc:creator>
    <category><![CDATA[Malware]]></category>
    <category><![CDATA[Opensource]]></category>
    <category><![CDATA[Privacy]]></category>
    <category><![CDATA[Cybersecurity]]></category>
    <category><![CDATA[Threat Intelligence]]></category>
    <category><![CDATA[Ai]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><b>BobDaHacker</b> <a class="link" href="https://bobdahacker.com/blog/fifa-hack?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">didn&#39;t find a zero-day</a>. She didn&#39;t exploit a memory corruption bug or chain together three CVEs. She uploaded a photo of her ID to <b>FIFA</b>&#39;s public agent registration portal, got added to FIFA&#39;s Microsoft Entra tenant, and walked straight into the live production Streaming Management panel for the FIFA World Cup 2026. Every match. Every camera angle. Every RTMP stream key. One click away from replacing the PGM feed — the main broadcast output going to every TV network worldwide — with whatever she felt like pushing. She did not push anything. She spent the rest of the night calling FIFA, MediaKind, HBS, CISA, and the FBI trying to get someone to pick up the phone.</p><p class="paragraph" style="text-align:left;">The root cause is almost insultingly mundane: client-side authorization with no server-side enforcement. The Angular frontend checked the JWT, found no roles, showed an &quot;<code>access denied</code>&quot; page. The backend APIs didn&#39;t check anything. FIFA fixed it by the next morning without ever responding to the researcher. She&#39;s still on their official match document distribution list, receiving Start Lists and Tactical Lineups in four languages. The vulnerability is gone. The bug bounty program, the <code>security.txt</code> file, and the acknowledgment to the person who saved them from a global broadcast catastrophe remain absent. Client-side authorization is not authorization. It&#39;s 2026.</p><h2 class="heading" style="text-align:left;">Table of Contents</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="#breaches-security-incidents" rel="noopener noreferrer nofollow">BREACHES & SECURITY INCIDENTS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#cybercrime-cyber-espionage-ap-ts" rel="noopener noreferrer nofollow">CYBERCRIME, CYBER ESPIONAGE, APT’s</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#government-politics-and-privacy" rel="noopener noreferrer nofollow">GOVERNMENT, POLITICS, AND PRIVACY</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#malware-threats" rel="noopener noreferrer nofollow">MALWARE & THREATS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ai-crypto-tech-tools" rel="noopener noreferrer nofollow">AI, CRYPTO, TECH & TOOLS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#vulnerabilities-research-and-threat" rel="noopener noreferrer nofollow">VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ics-ot-io-t" rel="noopener noreferrer nofollow">ICS, OT & IoT</a></p></li></ul><div id="breaches-security-incidents" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🔓 BREACHES & SECURITY INCIDENTS</h3><p class="paragraph" style="text-align:left;">🇺🇸 🪪 <b>Hackers breached a Texas state vendor and stole more than 3 million</b> <a class="link" href="https://techcrunch.com/2026/06/18/texas-government-data-breach-allowed-hackers-to-steal-3-million-drivers-licenses-and-passports/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">driver’s license and passport numbers</a>. The leak also exposed emails, phone numbers, and home addresses. The <b>Texas Parks & Wildlife Department</b> confirmed the incident but gave few details.</p><p class="paragraph" style="text-align:left;">🇦🇺 <b>Mackay Sugar, Australia’s second-largest raw sugar producer, was hit by a ransomware attack</b> that forced some mills to shut down. The company has <a class="link" href="https://www.securityweek.com/ransomware-attack-shuts-down-mills-of-australias-second-largest-sugar-producer/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">partially resumed limited, manual operations</a> while restoring systems and advising growers not to harvest yet. The cybercriminal group <i><b>The Gentlemen</b></i> claimed the attack but has not yet leaked data.</p><p class="paragraph" style="text-align:left;">🔓️ <b>Attackers used a compromised Klue app connection to steal Salesforce CRM data</b> via OAuth tokens. <b>Salesforce</b> suspended <b>Klue</b> integrations <a class="link" href="https://www.databreachtoday.com/attackers-steal-salesforce-data-from-klue-battlecards-users-a-32011?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">while Klue revoked credentials</a> and warned customers. The breach exposed sales contacts and quotes for some customers, and investigators say this matches a known OAuth-abuse playbook.</p><p class="paragraph" style="text-align:left;">🇺🇸 <b>MCNA Dental agreed to a multimillion-dollar settlement after a 2023 LockBit ransomware attack</b> that exposed data for <a class="link" href="https://www.databreachtoday.com/multimillion-dollar-settlement-reached-in-mcna-dental-hack-a-32017?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">nearly 9 million people</a>. The settlement offers limited cash payments, two years of medical data monitoring, and covers administrative and legal fees. <b>MCNA</b> denies wrongdoing and says it has improved security measures.</p><p class="paragraph" style="text-align:left;">🇪🇺 <b>Extortion group </b><i><b>ShinyHunters</b></i><b> claims it hacked the Council of Europe</b> and stole about 297–300 GB of data. The group says the haul includes payrolls, CVs, medical records, bank details, and other staff files for thousands of employees. <b>ShinyHunters</b> <a class="link" href="https://www.securityweek.com/shinyhunters-claims-council-of-europe-hack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">threatens to publish the files</a> unless the Council contacts them by June 16; the Council has not yet commented.</p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://www.bleepingcomputer.com/news/security/kodak-confirms-data-breach-claimed-by-shinyhunters-extortion-gang/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">Kodak confirms data breach claimed by ShinyHunters extortion gang</a></p><p class="paragraph" style="text-align:left;">🇺🇸 <b>iRhythm disclosed a data breach after hackers stole patient</b> and <a class="link" href="https://www.bleepingcomputer.com/news/security/irhythm-discloses-data-breach-says-hackers-stole-patient-info/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">personal information from third-party business apps</a>. The company said attackers demanded a ransom and confirmed data was exfiltrated, but its devices and clinical systems were not impacted. <b>iRhythm</b> is investigating with cybersecurity experts and has activated its response plan.</p><p class="paragraph" style="text-align:left;">🇫🇷 <b>A hacker calling itself “</b><i><b>misère</b></i><b>” and French authorities say about 73,000 government Tchap accounts were stolen</b> in a June 7 breach. The <a class="link" href="https://www.securityweek.com/french-government-messaging-platform-breached-by-mysterious-misere-hacker/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">attacker claims they also took 13.5 GB of files</a> and hundreds of thousands of messages, but that claim is unverified. Experts warn the exposed names, emails and messages could fuel widespread phishing or worse, yet motive and actor remain unclear.</p><p class="paragraph" style="text-align:left;">🇩🇰 <b>Pharmaceutical company Novo Nordisk said hackers accessed some internal IT systems</b> and personal data. The <a class="link" href="https://www.securityweek.com/ozempic-maker-novo-nordisk-says-hackers-breached-it-systems/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">breach exposed limited clinical trial info</a> and some healthcare provider contact details, but not names linked to trial participants. No group has claimed responsibility.</p><p class="paragraph" style="text-align:left;">→ More breaches:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/infinite-campus-data-breach-affects-137-000-school-staff-accounts/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">Infinite Campus data breach affects 137,000 school staff accounts</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.databreachtoday.com/south-korea-fines-coupang-409m-over-massive-data-breach-a-31985?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">South Korea Fines Coupang $409M Over Massive Data Breach</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/nintendo-confirms-data-stolen-in-webmd-subsidiary-cyberattack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">Nintendo confirms data stolen in WebMD subsidiary cyberattack</a></p></li></ul></div><p class="paragraph" style="text-align:left;"></p><div id="cybercrime-cyber-espionage-ap-ts" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🥷🏻 CYBERCRIME, CYBER ESPIONAGE, APT’s</h3><p class="paragraph" style="text-align:left;">❌ <b>Authorities disrupted the </b><i><b>SocGholish</b></i><b> (aka FakeUpdates) botnet used by Evil Corp</b> to infect websites and steal access since 2017. Law enforcement and partners <a class="link" href="https://cyberscoop.com/socgholish-malware-botnet-takedown-evilcorp/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">took down 106 servers, cleaned nearly 15,000 infected sites</a>, and disabled the botnet. Officials warned criminals used traffic distribution systems to redirect victims to malware, ransomware, and credential-stealing schemes.</p><p class="paragraph" style="text-align:left;">🇨🇳 ❌ <b>The FBI, with Google and Black Lotus Labs, shut down </b><i><b>Outsider Enterprise</b></i><b>, a huge China-linked phishing-as-a-service operation </b>that used AI and over a million fake URLs. Authorities say the scams stole millions of credit card records and caused about $1.9 billion in losses. <b>Google</b> filed a lawsuit, <a class="link" href="https://blog.google/innovation-and-ai/technology/safety-security/combatting-ai-scams/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">helped block messages with carriers</a>, and urges stronger anti-scam laws and AI defenses for users.</p><p class="paragraph" style="text-align:left;">🇨🇳 <b>Google&#39;s Threat Intelligence Group says a China-linked cyberespionage group, UNC6508, has targeted</b> North American medical, academic, and military research since at least 2023. The attackers used malware called <b>InfiniteRed</b> and abused <b>REDCap</b> servers and email compliance rules to steal data on medicine, AI, drones, and defense. <b>Google</b> <a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/prc-targets-us-medical-research?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">disrupted the group’s infrastructur</a>e, warned victims, and published technical details and IoCs.</p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;">🗓️ <b><a class="link" href="https://xsa.github.io/infosec-events/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">{Cyber,Info}Sec Events</a></b> — A community-maintained list of infosec conferences worldwide. Subscribe to the <a class="link" href="https://xsa.github.io/infosec-events/events.ics?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">ICS calendar feed</a> to get events straight into your calendar, or follow <a class="link" href="https://infosec.exchange/@infosecevents?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">@infosecevents@infosec.exchange</a> on Mastodon for weekly digests. Contributions and ⭐ welcome!</p></div><p class="paragraph" style="text-align:left;"></p><div id="government-politics-and-privacy" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">👨🏻‍⚖️ 👀 GOVERNMENT, POLITICS, AND PRIVACY</h3><div class="embed"><a class="embed__url" href="https://thecyberexpress.com/ukraine-joins-eu-cybersecurity-reserve/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank"><div class="embed__content"><p class="embed__title"> What Ukraine’s Entry Into the EU Cybersecurity Reserve Means </p><p class="embed__description"> Ukraine Joins EU Cybersecurity Reserve after receiving approval from the Council of the European Union, enabling the country to access </p><p class="embed__link"> The Cyber Express </p></div><img class="embed__image embed__image--right" src="https://thecyberexpress.com/wp-content/uploads/Ukraine-Joins-EU-Cybersecurity-Reserve.webp"/></a></div><p class="paragraph" style="text-align:left;">🇮🇳 🚫 <b>India told the Delhi High Court that it warned Telegram before blocking the app</b> over channels selling leaked NEET-UG exam papers. <b>Telegram</b> <a class="link" href="https://www.bleepingcomputer.com/news/security/telegram-admits-it-couldnt-police-exam-leak-channels-india-tells-court/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">admitted it could not proactively find such channels</a> and only acted on reports, while it says it cooperated and calls the ban unlawful. The nationwide block disrupted access beyond India and remains in place until the court rules.</p><p class="paragraph" style="text-align:left;">📍 <b>Google will start using UK, EEA and Swiss users&#39; IP addresses to identify devices for ad measurement and personalization</b> from about August 3, 2026. This treats IPs as personal data under EU/UK rules and requires user consent, shifting compliance responsibility to advertisers. Regulators warn <a class="link" href="https://www.bleepingcomputer.com/news/security/google-to-use-uk-and-eu-user-ip-addresses-for-ad-personalization/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">existing consent rules still apply</a> and <b>Google</b> will add a user choice later in its rollout.</p><p class="paragraph" style="text-align:left;">🇬🇧 🤳 <b>The UK will ban under-16s from major social media platforms and require age checks for new accounts</b> starting spring 2027. New users will likely need to upload ID or pass a facial age scan, ending easy anonymous sign-ups. Experts warn <a class="link" href="https://www.bleepingcomputer.com/news/security/uk-to-require-id-or-face-scan-before-you-can-make-social-media-accounts/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">this risks privacy and can be bypassed</a>, while platforms say it may push teens to less-regulated spaces.</p><p class="paragraph" style="text-align:left;">🇺🇸 <b>President Trump signed NSPM-12 to strengthen cybersecurity for the most sensitive U.S. government systems (NSS)</b> — The memo reestablishes and modernizes the Committee on National Security Systems (CNSS) and names the NSA director as National Manager to oversee standards, emergency directives, and coordination. Agencies <a class="link" href="https://www.securityweek.com/white-house-issues-memo-to-bolster-nss-cybersecurity/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">must inventory their NSS, update it yearly</a>, and CNSS will revise policies and issue a roadmap within three months.</p></div><p class="paragraph" style="text-align:left;"></p><div id="malware-threats" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🦠 MALWARE & THREATS</h3><p class="paragraph" style="text-align:left;">🪱 <b>A Windows crypto clipper active since Feb 2026 steals clipboard wallet data</b>, replaces addresses, and uploads screenshots. It <a class="link" href="https://www.microsoft.com/en-us/security/blog/2026/06/17/crypto-clipper-uses-tor-worm-like-propagation-for-persistence-control/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">uses script-based payloads, a portable Tor client</a> (<code>localhost:9050</code>), and hidden-service C2s for stealthy control and runtime tasking. A worm-like component spreads via malicious <code>.lnk</code> shortcuts and creates persistence while avoiding Defender scans.</p><p class="paragraph" style="text-align:left;">🕸️ 📺️ <b>Researchers say the </b><i><b>Popa</b></i><b> botnet has turned millions of Android TV boxes into residential proxies used for ad fraud</b>, account takeovers, and massive web scraping. Multiple firms link <b>Popa</b> traffic to <b>NetNut</b>, a proxy service owned by publicly traded <b>Alarum Technologies</b>, though the company denies it runs a botnet. Security experts warn these proxy SDKs <a class="link" href="https://krebsonsecurity.com/2026/06/popa-botnet-linked-to-publicly-traded-israeli-firm/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">put home and corporate networks at risk</a> and fuel large-scale AI data scraping.</p><p class="paragraph" style="text-align:left;">🔙 🚪 <b>Researchers found a new Go backdoor, </b><i><b>Backdoor.Turn</b></i><b>, used by DragonForce</b> that <a class="link" href="https://www.security.com/threat-intelligence/dragonforce-msteams-backdoor?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">hides command-and-control traffic inside legitimate Microsoft Teams</a> relay connections. The attackers used this stealthy tool along with DLL sideloading and kernel-level exploits to persist, move laterally, and steal data. This technique makes malicious traffic look like normal Teams activity, evading detection.</p><p class="paragraph" style="text-align:left;">🏦 🎠 <b>A new Android banking Trojan called </b><i><b>Rokarolla</b></i><b> gives attackers near-total control of infected phones</b> to <a class="link" href="https://www.databreachtoday.com/rokarolla-android-banking-trojan-enables-device-takeover-a-31996?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">steal credentials and take over accounts</a>. It is spread via fake app downloads and targets over 200 banking, crypto, and social apps while disabling protections like Google Play Protect. <b>Rokarolla</b> intercepts SMS codes, records keystrokes, and uses overlays and call blocking to hide fraud and prevent users from stopping it.</p><p class="paragraph" style="text-align:left;">🇰🇵 <b>North Korean group APT37 (ScarCruft) sent fake Microsoft security emails to trick victims into opening a ZIP</b> that ran a malicious LNK file. The LNK <a class="link" href="https://www.genians.co.kr/en/blog/threat_intelligence/narwhalrat?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">launched a multi-stage Python-based loader</a> that installed <b>NarwhalRAT</b>, giving attackers keystroke logging, screenshots, audio capture, file theft, and remote control. The malware uses Korean sites and pCloud as C2 channels and persists via scheduled tasks while hiding data in a folder named to resemble the <b>Naver Whale</b> browser.</p></div><p class="paragraph" style="text-align:left;"></p><div id="ai-crypto-tech-tools" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🤖 🧰 AI, CRYPTO, TECH & TOOLS</h3><div class="embed"><a class="embed__url" href="https://techcrunch.com/2026/06/15/cybersecurity-vets-protest-dangerous-us-government-ban-on-anthropics-most-powerful-models/?utm_source=forwardfuture.ai&utm_medium=newsletter&utm_campaign=anthropic-ai-ban-soaring-token-costs-claude-lawsuit" target="_blank"><div class="embed__content"><p class="embed__title"> Cybersecurity vets protest &#39;dangerous&#39; US government ban on Anthropic&#39;s most powerful models | TechCrunch </p><p class="embed__description"> A group made up of dozens of cybersecurity experts urged the White House to remove export-control restrictions on Anthropic’s Fable and Mythos models, arguing that the order is going to limit the ability of cybersecurity defenders to secure their software and products. </p><p class="embed__link"> TechCrunch • Lorenzo Franceschi-Bicchierai </p></div><img class="embed__image embed__image--right" src="https://techcrunch.com/wp-content/uploads/2026/06/claude-mythos-logo.jpg?resize=1200,800"/></a></div><p class="paragraph" style="text-align:left;">🐛 <b>A bug in the Google Vertex AI Python SDK</b> let attackers pre-create predictable storage buckets and <a class="link" href="https://unit42.paloaltonetworks.com/hijacking-vertex-ai-model/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">hijack model uploads</a>. Attackers could replace models with malicious pickle payloads that ran code in <b>Google&#39;</b>s serving containers and stole tokens. <b>Google</b> patched the issue; update to <code>google-cloud-aiplatform v1.148.0+</code> and set an <code>explicit staging_bucket</code>.</p><p class="paragraph" style="text-align:left;">🦠 📦️ <b>Hackers poisoned many packages in the </b><i><b>Mastra AI </b></i><b>npm ecosystem</b> by <a class="link" href="https://www.databreachtoday.com/mastra-ai-framework-poisoned-in-npm-supply-chain-attack-a-32003?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">adding a malicious typosquat dependency</a> that ran a hidden payload. Users who installed <code>@mastra</code> packages should treat their environments as compromised and downgrade or lock to <code>mastra@1.13.0</code> immediately. <b>GitHub/npm</b> are rolling out security changes to block automatic scripts from dependencies to reduce such supply-chain attacks.</p><p class="paragraph" style="text-align:left;">🤝 🔍️ <b>A group of fintech and tech companies formed </b><i><b>Athena</b></i><b> to find and fix open-source software vulnerabilities</b> before they can be exploited. Members share findings, protections, and patches on a common platform so fixes reach users faster than public disclosure. The <a class="link" href="https://www.securityweek.com/tech-coalition-athena-targets-oss-vulnerabilities-ahead-of-disclosure/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">goal is to stop fast AI-driven attacks</a> by coordinating defenses across many organizations.</p><hr class="content_break"><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/gRgDsdm4RQo" width="100%"></iframe><hr class="content_break"><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/BznlV0ErsUE" width="100%"></iframe></div><p class="paragraph" style="text-align:left;"></p><div id="vulnerabilities-research-and-threat" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🐛 🧠 VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</h3><p class="paragraph" style="text-align:left;">➝ From the Patching Department:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/apple-fixes-beats-studio-buds-flaw-that-let-hackers-spy-on-conversations/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">Apple fixes Beats Studio Buds flaw that let hackers spy on conversations</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/atlassian-splunk-patch-critical-vulnerabilities/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">Atlassian, Splunk Patch Critical Vulnerabilities</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/chrome-and-firefox-updated-to-patch-critical-high-severity-vulnerabilities/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">Chrome and Firefox Updated to Patch Critical, High-Severity Vulnerabilities</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/critical-command-execution-vulnerability-patched-in-cisco-ise/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">Critical Command Execution Vulnerability Patched in Cisco ISE</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/f5-issues-out-of-band-patches-for-critical-nginx-vulnerabilities/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">F5 issues out-of-band patches for critical NGINX vulnerabilities</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/microsoft/microsoft-working-on-defender-patch-for-rogueplanet-zero-day/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">Microsoft working on Defender patch for RoguePlanet zero-day</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/oracles-second-monthly-security-updates-deliver-245-patches/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">Oracle’s Second Monthly Security Updates Deliver 245 Patches</a></p></li></ul><hr class="content_break"><p class="paragraph" style="text-align:left;">🔥 🧱 <b>Cybercriminals have hacked tens of thousands of Fortinet firewalls and VPNs worldwide</b> by <a class="link" href="https://techcrunch.com/2026/06/17/cybercriminals-allegedly-hacked-tens-of-thousands-of-fortinet-firewalls-used-by-major-companies-all-over-the-world/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">using lists of leaked or weak passwords</a>. Once inside, they monitor traffic to steal more credentials and then use those to breach more devices. Major companies and government agencies in many countries were affected.</p><p class="paragraph" style="text-align:left;">💥 <b>Attackers are exploiting two serious bugs in Joomla’s JCE editor (</b><a class="link" href="https://www.joomlacontenteditor.net/news/jce-security-update-and-a-free-patch-for-older-sites?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow"><b>CVE-2026-48907</b></a><b>) and LiteSpeed’s cPanel plugin (</b><a class="link" href="https://blog.litespeedtech.com/2026/06/01/security-update-for-litespeed-cpanel-plugin-2/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow"><b>CVE-2026-54420</b></a><b>)</b> to run code and gain root privileges. Both flaws have been actively used in the wild and patches were released in early June. Authorities (CISA) urge immediate updates and checks because automated exploits can fully compromise servers.</p><p class="paragraph" style="text-align:left;">⚽️ <b>A researcher found a simple bug in FIFA’s systems</b> that let anyone register as an agent and access internal platforms. Using that access, <a class="link" href="https://bobdahacker.com/blog/fifa-hack?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">she could control the TV feed</a> and what commentators saw for every World Cup match. She reported it and <b>FIFA</b> fixed the flaw within hours.</p><hr class="content_break"><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/ZB51rSX909g" width="100%"></iframe></div><p class="paragraph" style="text-align:left;"></p><div id="ics-ot-io-t" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🛰️ ICS, OT & IoT</h3><p class="paragraph" style="text-align:left;">🩹 <b>Rockwell Automation released patches for multiple vulnerabilities</b> in its controllers, <b>Flex I/O</b> adapters, <b>RSLinx</b> software, and <b>FactoryTalk</b> suite. Some flaws allow denial-of-service, bypassing authentication, or unauthorized administrative actions. The company says the new issues have <a class="link" href="https://www.securityweek.com/rockwell-automation-patches-vulnerabilities-in-ics-controllers-and-software/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">not yet been observed being exploited in the wild</a>.</p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">💬 CONNECT</h3><p class="paragraph" style="text-align:left;">Follow me on <a class="link" href="https://infosec.exchange/@0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">Mastodon</a> for quick daily updates and bite-sized content.</p><p class="paragraph" style="text-align:left;">Prefer using an RSS feed? Add <b>Infosec MASHUP</b> to your feed <a class="link" href="https://rss.beehiiv.com/feeds/HVhiKYpQlR.xml?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">here</a>.</p><p class="paragraph" style="text-align:center;"><b>Enjoying our newsletter? </b>Forward it to a colleague—<br>it’s one of the best ways to support us.</p><p class="paragraph" style="text-align:left;">Thanks for reading today’s newsletter, and if you&#39;re enjoying it and want to support my work, you can <b>buy me a coffee</b> ☕ over at <a class="link" href="https://www.buymeacoffee.com/0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-25-2026-client-side-authorization-is-not-authorization" target="_blank" rel="noopener noreferrer nofollow">https://www.buymeacoffee.com/0x58</a></p><p class="paragraph" style="text-align:left;"> See you next time!</p><p class="paragraph" style="text-align:left;">-X.</p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=18e6d1ea-3b3a-442c-94cc-f66c236496c6&utm_medium=post_rss&utm_source=x_s_infosec_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🕵🏻‍♂️ [InfoSec MASHUP] 24/2026 - npm v12 Is the Apology. The Malware Section Is the Receipt.</title>
  <description>Plus: Microsoft patched 200 flaws and three zero-days, Cisco&#39;s SD-WAN hit its seventh exploited zero-day of the year, and ShinyHunters went after Oracle PeopleSoft at 100+ universities</description>
  <link>https://infosec-mashup.santolaria.net/p/infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt</link>
  <guid isPermaLink="true">https://infosec-mashup.santolaria.net/p/infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt</guid>
  <pubDate>Sat, 13 Jun 2026 08:20:00 +0000</pubDate>
  <atom:published>2026-06-13T08:20:00Z</atom:published>
    <dc:creator>Xavier Santolaria</dc:creator>
    <category><![CDATA[Malware]]></category>
    <category><![CDATA[Opensource]]></category>
    <category><![CDATA[Privacy]]></category>
    <category><![CDATA[Cybersecurity]]></category>
    <category><![CDATA[Threat Intelligence]]></category>
    <category><![CDATA[Ai]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Last week&#39;s question was why the software ecosystem keeps shipping holes and handing the cleanup bill to operational teams. This week npm answered, at least partially. <b>npm v12</b> will block automatic code execution during install by default — no more preinstall scripts running silently, no more Git dependencies or URL-based packages pulling in whatever they feel like. Developers will have to explicitly opt in. It&#39;s the right call, it&#39;s what the supply chain attack surface has been screaming for across months of <b>CanisterWorm</b>, <b>Shai-Hulud</b>, <b>IronWorm</b>, and <b>Megalodon</b> campaigns, and it arrives roughly four years after the attack pattern became impossible to ignore.</p><p class="paragraph" style="text-align:left;">The malware section this week is, as ever, the context that makes the fix legible. Nineteen PyPI packages trojaned via <code>.pth</code> startup hooks. A WinRAR flaw from last year still fueling active campaigns against Ukrainian organizations. <b>TeamPCP</b> back with CanisterWorm. The backlog of techniques that predate npm v12 isn&#39;t going anywhere — and the install-time execution block doesn&#39;t touch the packages already in production, the developers who won&#39;t upgrade immediately, or the registries that aren&#39;t npm. It&#39;s a meaningful fix to a well-understood problem. It&#39;s also, by the industry&#39;s own timeline, a very belated one.</p><h2 class="heading" style="text-align:left;">Table of Contents</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="#breaches-security-incidents" rel="noopener noreferrer nofollow">BREACHES & SECURITY INCIDENTS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#cybercrime-cyber-espionage-ap-ts" rel="noopener noreferrer nofollow">CYBERCRIME, CYBER ESPIONAGE, APT’s</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#government-politics-and-privacy" rel="noopener noreferrer nofollow">GOVERNMENT, POLITICS, AND PRIVACY</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#malware-threats" rel="noopener noreferrer nofollow">MALWARE & THREATS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ai-crypto-tech-tools" rel="noopener noreferrer nofollow">AI, CRYPTO, TECH & TOOLS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#vulnerabilities-research-and-threat" rel="noopener noreferrer nofollow">VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ics-ot-io-t" rel="noopener noreferrer nofollow">ICS, OT & IoT</a></p></li></ul><div id="breaches-security-incidents" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🔓 BREACHES & SECURITY INCIDENTS</h3><p class="paragraph" style="text-align:left;">🇮🇷 🇺🇸 <b>Iran-linked hacker group </b><i><b>Handala</b></i><b> says it breached </b><i><b>California Water Service</b></i> and posted 5 GB of stolen data. The leak includes customer billing records, account details, and admin credentials for an RTKBase GNSS system. Security firm <b>Dataminr</b> <a class="link" href="https://www.dataminr.com/resources/intel-brief/cyber-intel-brief-handala-claims-breach-of-california-water-service/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">warns the group could escalate to destructive attacks</a> and urges credential rotation and audits.</p><p class="paragraph" style="text-align:left;">🇩🇰 <b>Pharma giant </b><i><b>Novo Nordisk</b></i><b> reported a data breach</b> exposing <a class="link" href="https://www.bleepingcomputer.com/news/security/pharmaceutical-giant-novo-nordisk-discloses-security-breach/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">pseudonymized clinical trial patient data and personal details</a> of some healthcare professionals. The company says names were not linked to the patient data but warned HCPs to watch for phishing and fraudulent contact. <b>Novo Nordisk</b> has taken affected systems offline and is working with cybersecurity experts to investigate.</p><p class="paragraph" style="text-align:left;">🔓️ <b>Cybercrime group </b><i><b>ShinyHunters</b></i><b> says it breached Oracle PeopleSoft servers</b> at <a class="link" href="https://techcrunch.com/2026/06/10/cybercriminals-claim-breach-of-oracle-peoplesoft-servers-at-100-plus-organizations/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">over 100 organizations</a>, many universities. Stolen data reportedly includes student addresses, phone numbers, emails, birthdates, and other sensitive records. The group targets common software vulnerabilities to compromise many victims at once.</p><p class="paragraph" style="text-align:left;">🩹 <b>ServiceNow fixed a security flaw that let unauthenticated attackers query customer data</b> via a vulnerable API. <a class="link" href="https://www.bleepingcomputer.com/news/security/servicenow-discloses-security-incident-exposing-customer-data/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">Impacted customers were told via support cases</a> and a hidden bulletin; <b>ServiceNow</b> is still investigating what was accessed. Admins reported the issue tied to a REST endpoint and shared indicators of compromise.</p><p class="paragraph" style="text-align:left;">🇫🇷 <b>Hackers used a hijacked user account to breach </b><i><b>Tchap</b></i><b>, France’s government encrypted messaging platform</b> — DINUM says the account was blocked and an investigation is ongoing, and users were warned that public rooms are not encrypted. A <a class="link" href="https://www.bleepingcomputer.com/news/security/french-govt-messaging-service-breached-in-account-hijacking-attack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">threat actor claims to have stolen ~13.5 GB of data</a>, thousands of messages, and tens of thousands of account details.</p><p class="paragraph" style="text-align:left;">🇭🇰 <b>SoFi Hong Kong says hackers accessed a database at a third-party vendor</b> and a data breach occurred. The <a class="link" href="https://www.bleepingcomputer.com/news/security/sofi-confirms-third-party-data-breach-at-hong-kong-subsidiary/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">company discovered the incident on April 30, 2026</a>, and is investigating with a cybersecurity firm. Customers are urged to watch for phishing, secure their accounts, and contact <b>SoFi</b> for help.</p><p class="paragraph" style="text-align:left;">🇬🇧 <b>Oxford University disclosed a data breach</b> after its third-party <b>CareerConnect</b> platform was hacked on May 28. Attackers accessed names, emails, and encrypted passwords for users who do not use Single Sign-On. The university says <a class="link" href="https://www.bleepingcomputer.com/news/security/oxford-university-discloses-data-breach-after-careerconnect-platform-hack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">no university systems or financial data appear compromised</a> but warns of possible phishing.</p><p class="paragraph" style="text-align:left;">→ More breaches:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/174000-impacted-by-lansing-community-college-data-breach/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">174,000 Impacted by Lansing Community College Data Breach</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/nottingham-university-data-breach-affects-over-450-000-students/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">Nottingham University data breach affects over 450,000 students</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/south-korea-hits-coupang-with-record-409-million-fine-over-data-breach/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">Coupang hit with record $409 million data breach fine in Korea</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/japanese-energy-firm-loses-drive-with-data-of-109-million-clients/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">Japanese energy firm loses drive with data of 10.9 million clients</a></p></li></ul></div><p class="paragraph" style="text-align:left;"></p><div id="cybercrime-cyber-espionage-ap-ts" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🥷🏻 CYBERCRIME, CYBER ESPIONAGE, APT’s</h3><div class="embed"><a class="embed__url" href="https://krebsonsecurity.com/2026/06/who-runs-the-ransomware-group-the-gentlemen/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank"><div class="embed__content"><p class="embed__title"> Who Runs the Ransomware Group ‘The Gentlemen?’ – Krebs on Security </p><p class="embed__link"> krebsonsecurity.com/2026/06/who-runs-the-ransomware-group-the-gentlemen </p></div></a></div><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://thehackernews.com/2026/06/the-gentlemen-ransomware-claims-478.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">The Gentlemen Ransomware Claims 478 Victims</a></p></li></ul><hr class="content_break"><p class="paragraph" style="text-align:left;">🔞 ❌ <b>U.S., French, and Italian authorities seized domains for </b><code>CFAKE.com</code><b> and </b><code>SOCFAKE.com</code><b> for hosting thousands of nonconsensual deepfake porn</b> images and videos. The sites let users search disturbing categories like “rape” and “degradation” and targeted public figures and private women. A <a class="link" href="https://cyberscoop.com/us-international-authorities-shutdown-deepfake-porn-site/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">French suspect was arrested</a>, assets seized, and prosecutors say the sites involved hundreds of thousands of images and thousands of videos.</p><p class="paragraph" style="text-align:left;">🎣 ❌ <b>INTERPOL led </b><i><b>Operation Ramz</b></i><b> and shut down </b><i><b>Sniper Dz</b></i><b>, a decade-old phishing-as-a-service platform</b> — Authorities from <a class="link" href="https://thehackernews.com/2026/06/interpol-takes-down-sniper-dz-phishing.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">13 MENA countries made 201 arrests</a>, including the platform’s main developer, and seized its servers and tools. <b>Sniper Dz</b> had hosted thousands of phishing sites targeting major brands and harvested credentials and other data for fraud.</p><p class="paragraph" style="text-align:left;">🇺🇸 ⚖️ 🇷🇺 <b>U.S. prosecutors charged Russian citizen Denis Obrezko for helping a large cyber-espionage campaign</b> tied to the Russia-linked group <b>Void Blizzard</b>. Investigators say <a class="link" href="https://cyberscoop.com/russian-national-charged-void-blizzard-cyber-espionage/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">he bought servers and domains used to break into companies</a>, schools, and other organizations. The group used stolen session tokens and simple proxy tricks to steal emails, files, and access to cloud accounts.</p><p class="paragraph" style="text-align:left;">🇺🇸 ❌ 🇨🇳 <b>The FBI seized 13 fake websites that posed as consulting firms</b> to lure U.S. workers with security clearances. Officials say the <a class="link" href="https://www.securityweek.com/fbi-seizes-13-websites-that-officials-say-were-used-by-china-to-target-and-recruit-us-workers/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">sites were used by operatives tied to Chinese intelligence</a> to recruit people and buy sensitive information. China’s embassy denies the allegations.</p><p class="paragraph" style="text-align:left;">🇻🇳 🪷 <b>Vietnam-linked OceanLotus used the SPECTRALVIPER backdoor in two campaigns</b> that targeted a Vietnamese construction firm and stock investors via a compromised <b>FireAnt Metakit</b> updater. The attackers delivered <b>SPECTRALVIPER</b> through DLL side-loading and a malicious update, enabling data theft, lateral movement, and remote control. <b>ESET</b> <a class="link" href="https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">warns</a> this shows a shift toward more selective domestic espionage by the long-running group.</p><p class="paragraph" style="text-align:left;">😶 <b>Silent Ransom Group (SRG) uses social engineering and vishing to get into victims’ networks</b>, often targeting law firms. They steal data, pressure victims with extortion emails, and sometimes use in-person USB drops. <b>Resecurity</b> found SRG hides its infrastructure with a global fast flux network of <a class="link" href="https://www.resecurity.com/blog/article/silent-ransom-group-srg-uncovering-dns-fast-flux-infrastructure?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">infected routers and IoT devices</a>.</p><hr class="content_break"><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/pv4rFNo0uxU" width="100%"></iframe></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;">🗓️ <b><a class="link" href="https://xsa.github.io/infosec-events/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">{Cyber,Info}Sec Events</a></b> — A community-maintained list of infosec conferences worldwide. Subscribe to the <a class="link" href="https://xsa.github.io/infosec-events/events.ics?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">ICS calendar feed</a> to get events straight into your calendar, or follow <a class="link" href="https://infosec.exchange/@infosecevents?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">@infosecevents@infosec.exchange</a> on Mastodon for weekly digests. Contributions and ⭐ welcome!</p></div><p class="paragraph" style="text-align:left;"></p><div id="government-politics-and-privacy" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">👨🏻‍⚖️ 👀 GOVERNMENT, POLITICS, AND PRIVACY</h3><p class="paragraph" style="text-align:left;">🇺🇸 ⚖️ <b>Meta says it found a spearphishing campaign linked to NSO Group that violated a court injunction</b> — <b>Meta</b> <a class="link" href="https://cyberscoop.com/meta-contempt-complaint-nso-group-spyware/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">filed a contempt-of-court complaint</a> after disrupting the attacks and removing fake WhatsApp accounts. Critics say <b>NSO</b>’s behavior supports keeping it on the U.S. sanctions Entity List.</p><p class="paragraph" style="text-align:left;">🇺🇸 📍 <b>Massachusetts lawmakers passed a Consumer Data Privacy Act giving residents new rights</b> to access and delete personal data. The <a class="link" href="https://techcrunch.com/2026/06/08/massachusetts-votes-to-pass-new-privacy-rights-bill-that-bans-sale-of-precise-location-data/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">bill bans companies from selling precise location data</a> and other sensitive information without consent. It now goes to the Senate and the governor and is expected to become law.</p></div><p class="paragraph" style="text-align:left;"></p><div id="malware-threats" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🦠 MALWARE & THREATS</h3><div class="embed"><a class="embed__url" href="https://www.picussecurity.com/resource/blog/canisterworm-how-teampcp-turned-the-npm-ecosystem-into-a-weapon?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank"><div class="embed__content"><p class="embed__title"> CanisterWorm: How TeamPCP Turned the npm Ecosystem Into a Weapon </p><p class="embed__description"> CanisterWorm infected 60+ npm packages in 24 hours. Learn how the TeamPCP supply chain attack works and how to protect your projects. </p><p class="embed__link"> www.picussecurity.com/resource/blog/canisterworm-how-teampcp-turned-the-npm-ecosystem-into-a-weapon </p></div></a></div><hr class="content_break"><p class="paragraph" style="text-align:left;">🆕 📦️ <b>GitHub says npm v12 will block automatic code execution and remote dependency sources</b> during npm install unless explicitly approved. This stops install scripts, Git dependencies, and URL-based packages from running by default to reduce supply-chain attacks. Developers <a class="link" href="https://www.bleepingcomputer.com/news/security/github-announces-npm-security-changes-to-tackle-supply-chain-attacks/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">must opt in for these behaviors</a> and can test with npm 11.16.0 before upgrading.</p><p class="paragraph" style="text-align:left;">❌ <b>Microsoft temporarily removed 73 GitHub repositories after detecting possible malicious content</b> linked to a <b>Miasma/Shai-Hulud</b> supply‑chain campaign. The takedown briefly broke Azure Functions deployment workflows, but the repos were restored and deemed clean. <b>Microsoft</b> is <a class="link" href="https://www.bleepingcomputer.com/news/security/github-disables-microsoft-repos-pushing-password-stealing-malware/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">investigating</a> and notifying affected customers.</p><p class="paragraph" style="text-align:left;">🇷🇺 🇺🇦 <b>Two Russia-aligned groups used a patched WinRAR flaw (CVE-2025-8088) to infect Ukrainian organizations</b> with data-stealing malware. They <a class="link" href="https://www.trendmicro.com/en_us/research/26/f/old-winrar-flaw-fuels-attacks-on-ukraine.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">delivered payloads via crafted RAR archives and ADS files</a>, then used loaders to steal browser data, passwords, and documents. Attackers shifted to dedicated C2 servers and long-running infection chains to maintain stealthy access.</p><p class="paragraph" style="text-align:left;">🐍 <b>Hackers trojanized 19 popular PyPI packages in a Shai-Hulud supply-chain attack</b> to steal developer secrets. The malicious packages used <code>.pth</code> startup hooks to <a class="link" href="https://socket.dev/blog/shai-hulud-descends-to-hades-miasma-pypi-wave?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">run an obfuscated JavaScript payload via the Bun runtime</a> and exfiltrated tokens, cloud credentials, SSH keys, and more. <b>Socket</b> urges affected users to rotate secrets, restore from clean backups, and watch for <code>.pth</code> hooks or unexpected Bun downloads.</p><p class="paragraph" style="text-align:left;">🏦 <b>New NFCShare Android malware is being spread as fake bank app updates </b>on GitHub. It <a class="link" href="https://www.d3lab.net/nfcshare-android-trojan-nfc-card-data-theft-via-malicious-apk/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">tricks users into tapping cards to their phones</a>, steals card data and PINs via NFC, and sends them to attackers. Users should only install banking apps from <b>Google Play</b> and ignore unexpected NFC verification prompts.</p><p class="paragraph" style="text-align:left;">🇨🇳 🔙 🚪 <b>A China-linked group called </b><i><b>VerdantBamboo</b></i><b> deployed a BSD variant of the BRICKSTORM backdoor</b> plus <b>PLENET</b> and <b>AGENTPSD</b> to <a class="link" href="https://www.volexity.com/blog/2026/06/04/verdantbamboo-just-another-brickstorm-in-the-firewall/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">compromise Linux appliances and NAS devices</a>. They gained access by breaching an MSP and abusing VPN/firewall credentials to move laterally and blend in with normal traffic. The actor uses tailored implants, living-off-the-land techniques, and careful operational security to maintain long-term access.</p><hr class="content_break"><div class="embed"><a class="embed__url" href="https://www.blackfog.com/inside-onyxc2-the-new-stealer-targeting-210-apps/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank"><div class="embed__content"><p class="embed__title"> Inside OnyxC2: The New Stealer Targeting 210 Apps | BlackFog </p><p class="embed__description"> Discover OnyxC2, the new malware-as-a-service stealer targeting 210 apps, how it evades detection, steals credentials, and enables data theft. </p><p class="embed__link"> BlackFog </p></div><img class="embed__image embed__image--right" src="https://privacy.blackfog.com/wp-content/uploads/2026/06/BF-Blog_Inside-OnyxC2_featured-image.png"/></a></div></div><div id="ai-crypto-tech-tools" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🤖 🧰 AI, CRYPTO, TECH & TOOLS</h3><div class="embed"><a class="embed__url" href="https://emmanuelgjr.github.io/genai_incidents/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank"><div class="embed__content"><p class="embed__title"> GenAI & Agentic AI Security Incidents </p><p class="embed__description"> 7,700+ GenAI & agentic-AI security incidents, mapped to OWASP LLM Top 10, OWASP Agentic, NIST AI RMF & MITRE ATLAS. Searchable, filterable, open data (CC-BY-4.0). </p><p class="embed__link"> emmanuelgjr.github.io/genai_incidents </p></div></a></div><hr class="content_break"><p class="paragraph" style="text-align:left;">❌ <b>Law enforcement dismantled </b><i><b>AudiA6</b></i><b>, a crypto-laundering service that moved over $380 million</b> for ransomware and other cybercrimes. Investigators from 11 countries <a class="link" href="https://www.europol.europa.eu/media-press/newsroom/news/ransomware-gangs-cut-eur-336-million-audia6-crypto-laundering-pipeline?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">arrested two alleged admins</a>, seized domains, vehicles, crypto, and KYC records tied to thousands of mule accounts. The platform and its forum <b>Dark2Web</b> now show seizure notices and the suspects face heavy prison time.</p><p class="paragraph" style="text-align:left;">🆕 <b>Anthropic released Claude Fable 5, a powerful Mythos-class AI</b> with <a class="link" href="https://www.securityweek.com/anthropic-launches-claude-fable-5-mythos-class-ai-with-cybersecurity-guardrails/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">built-in safety blocks</a> that prevent use in high-risk areas like cybersecurity. In sensitive queries the model automatically falls back to the less capable <b>Claude Opus 4.8</b>, and tests and external red-teaming found no universal jailbreaks. Trusted partners in <b>Project Glasswing</b> get upgraded <b>Mythos</b> access, and both <b>Fable 5</b> and <b>Mythos 5</b> are available via API with published pricing.</p><p class="paragraph" style="text-align:left;"><b>Anthropic</b> says <a class="link" href="https://www.securityweek.com/anthropic-disputes-fable-5-ai-jailbreak/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">claims that Claude Fable 5 was jailbroken are false</a>. The company says its separate classifier safeguards still block dangerous outputs even if the model is coaxed to respond. Reviewers found no evidence the system was bypassed to produce harmful, nonpublic guidance.</p><p class="paragraph" style="text-align:left;">🇺🇸 <b>The U.S. government ordered Anthropic to shut down its two most powerful AI models, Claude Fable 5 and Claude Mythos 5</b>, over <a class="link" href="https://techcrunch.com/2026/06/12/anthropics-safety-warnings-may-have-just-backfired-the-government-has-pulled-the-plug-on-its-most-powerful-ai/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">national security concerns</a>. <b>Anthropic</b> says the move is wrong and that any jailbreak risk is narrow and already present in other models. Critics note the company’s warnings about <b>Mythos</b> may have drawn the government’s scrutiny.</p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://www.databreachtoday.com/anthropic-limits-on-ot-access-to-mythos-draw-criticism-a-31959?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">Anthropic Limits on OT Access to Mythos Draw Criticism</a></p><div class="embed"><a class="embed__url" href="https://techcrunch.com/2026/06/10/cybersecurity-researchers-arent-happy-about-the-guardrails-on-anthropics-fable/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank"><div class="embed__content"><p class="embed__title"> Cybersecurity researchers aren&#39;t happy about the guardrails on Anthropic&#39;s Fable | TechCrunch </p><p class="embed__description"> Cybersecurity researchers are complaining that Anthropic&#39;s new model Fable has guardrails that are too strict for any cybersecurity work. </p><p class="embed__link"> TechCrunch • Lorenzo Franceschi-Bicchierai </p></div><img class="embed__image embed__image--right" src="https://techcrunch.com/wp-content/uploads/2026/06/anthropic-claude-fable.jpg?resize=1200,798"/></a></div><p class="paragraph" style="text-align:left;">🔐 <b>OpenAI is expanding two ChatGPT security controls</b> to <a class="link" href="https://www.securityweek.com/openai-rolling-out-chatgpt-account-security-controls/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">help protect accounts</a> and data. <b>Lockdown Mode</b> limits features and outbound requests to reduce data exfiltration from prompt injections. <b>Active Sessions</b> shows where you are signed in, and <b>Advanced Account Security</b> adds passkeys and tighter sign-in protections.</p></div><p class="paragraph" style="text-align:left;"></p><div id="vulnerabilities-research-and-threat" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🐛 🧠 VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</h3><p class="paragraph" style="text-align:left;">➝ From the Patching Department:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/adobe-patches-123-vulnerabilities/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">Adobe Patches 123 Vulnerabilities</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://thehackernews.com/2026/06/ai-agent-uncovers-21-zero-days-in.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/gogs-patches-critical-zero-day-enabling-remote-code-execution/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">Gogs patches critical zero-day enabling remote code execution</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/google-patches-5th-chrome-zero-day-exploited-in-2026/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">Google Patches 5th Chrome Zero-Day Exploited in 2026</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/new-max-severity-ivanti-sentry-flaw-allows-code-execution-as-root/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">Ivanti Patched two critical flaws in its Sentry Gateway</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2026-patch-tuesday-fixes-3-zero-day-200-flaws/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">Microsoft June 2026 Patch Tuesday fixes 3 zero-day, 200 flaws</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/openssl-patches-high-severity-vulnerability-found-with-ai/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">OpenSSL Patches High-Severity Vulnerability Found With AI</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/sap-fixes-critical-flaws-in-netweaver-and-commerce-cloud/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">SAP fixes critical flaws in NetWeaver and Commerce Cloud</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/servicenow-patches-vulnerability-exploited-against-some-customers/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">ServiceNow Patches Vulnerability Exploited Against Some Customers</a></p></li></ul><hr class="content_break"><div class="embed"><a class="embed__url" href="https://cyberscoop.com/cisa-vulnerability-remediation-directive-bod-26-04/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank"><div class="embed__content"><p class="embed__title"> CISA directive orders agencies to prioritize vulnerability patching in a new way </p><p class="embed__description"> CISA has issued BOD 26-04, ordering federal agencies to prioritize software vulnerabilities using four new criteria to counter accelerating AI-driven threats. </p><p class="embed__link"> CyberScoop • Tim Starks </p></div><img class="embed__image embed__image--right" src="https://cyberscoop.com/wp-content/uploads/sites/3/2026/06/GettyImages-2238549241.jpg"/></a></div><p class="paragraph" style="text-align:left;">💥 <b>A high-severity unpatched flaw (CVE-2026-5027) in Langflow</b> lets attackers write files anywhere via path traversal and can <a class="link" href="https://thehackernews.com/2026/06/unpatched-langflow-flaw-cve-2026-5027.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">lead to unauthenticated remote code execution</a>. The bug is exploitable without credentials because <b>Langflow</b> enables auto-login by default, and attacks are already observed in the wild. Thousands of <b>Langflow</b> instances are exposed online, raising risk as attackers increasingly target AI development tools.</p><p class="paragraph" style="text-align:left;">🐧 <b>A one-character bug in Linux </b><code>nf_tables</code><b> (CVE-2026-23111) lets an unprivileged local user escalate to root</b> and break out of containers. Public <a class="link" href="https://thehackernews.com/2026/06/one-character-linux-kernel-flaw-enables.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">working exploits were published</a> in April and June, and the upstream one-line fix shipped February 5, 2026. Update affected kernels and reboot, and restrict unprivileged user namespaces until patches are applied.</p><p class="paragraph" style="text-align:left;">💥 <b>A high-severity command injection bug in BerriAI LiteLLM (CVE-2026-42271) is being actively exploited</b>, letting authenticated users run commands on the host. Researchers say <a class="link" href="https://thehackernews.com/2026/06/litellm-flaw-cve-2026-42271-exploited.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">it can be chained with a </a><a class="link" href="https://thehackernews.com/2026/06/litellm-flaw-cve-2026-42271-exploited.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow"><b>Starlette</b></a><a class="link" href="https://thehackernews.com/2026/06/litellm-flaw-cve-2026-42271-exploited.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow"> host header bypass (CVE-2026-48710)</a> to achieve unauthenticated remote code execution. Users should update <b>LiteLLM</b> to 1.83.7+ and <b>Starlette</b> to 1.0.1+ or apply immediate mitigations like blocking the test endpoints.</p><p class="paragraph" style="text-align:left;">🩹 <b>Check Point patched a critical VPN flaw (CVE-2026-50751) that lets remote attackers bypass authentication</b> on devices using the deprecated IKEv1 protocol. The <a class="link" href="https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">bug was exploited in zero-day attacks</a> affecting a few dozen organizations, with at least one incident tied to the <b>Qilin ransomware </b>group. <b>Check Point</b> also found a second IKEv1-related certificate validation bug (CVE-2026-50752) and urged immediate updates and mitigations.</p><hr class="content_break"><div class="embed"><a class="embed__url" href="https://cyberscoop.com/cisco-sdwan-zero-day-vulnerability-exploited-cve202620245/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank"><div class="embed__content"><p class="embed__title"> Cisco customers encounter another SD-WAN zero-day under attack </p><p class="embed__description"> The defect marks the seventh actively exploited zero-day in Cisco SD-WANs this year, and the vendor has yet to release a patch. </p><p class="embed__link"> CyberScoop • Matt Kapko </p></div><img class="embed__image embed__image--right" src="https://cyberscoop.com/wp-content/uploads/sites/3/2023/10/GettyImages-1127349614.jpg"/></a></div></div><p class="paragraph" style="text-align:left;"></p><div id="ics-ot-io-t" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🛰️ ICS, OT & IoT</h3><p class="paragraph" style="text-align:left;">🩹 <b>ICS Patch Tuesday</b> — Siemens, Schneider Electric, and Phoenix Contact <a class="link" href="https://www.securityweek.com/ics-patch-tuesday-vulnerabilities-fixed-by-siemens-schneider-phoenix-contact/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">released security advisories</a> fixing multiple industrial control system vulnerabilities this month. <b>Siemens</b> patched flaws including remote code execution and information leaks, <b>Schneider</b> fixed DoS, credential, and information disclosure issues, and <b>Phoenix Contact</b> addressed an unauthenticated log download bug. CISA and VDE CERT also issued related notices while other vendors like <b>Rockwell</b>, <b>ABB</b>, and <b>Mitsubishi</b> posted updates or enhancements.</p><p class="paragraph" style="text-align:left;">🦠 <b>C0XMO is a new, modular Gafgyt-based botnet that exploits a DD-WRT router flaw</b> to i<a class="link" href="https://www.bleepingcomputer.com/news/security/c0xmo-botnet-spreads-via-dd-wrt-router-flaw-kills-rival-malware/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">nfect many device types and CPU architectures</a>. It spreads by scanning, brute-forcing credentials, installing persistent binaries, and killing rival malware. Once connected to its C2, it can run 19 DDoS attack methods and be updated remotely.</p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">💬 CONNECT</h3><p class="paragraph" style="text-align:left;">Follow me on <a class="link" href="https://infosec.exchange/@0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">Mastodon</a> for quick daily updates and bite-sized content.</p><p class="paragraph" style="text-align:left;">Prefer using an RSS feed? Add <b>Infosec MASHUP</b> to your feed <a class="link" href="https://rss.beehiiv.com/feeds/HVhiKYpQlR.xml?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">here</a>.</p><p class="paragraph" style="text-align:center;"><b>Enjoying our newsletter? </b>Forward it to a colleague—<br>it’s one of the best ways to support us.</p><p class="paragraph" style="text-align:left;">Thanks for reading today’s newsletter, and if you&#39;re enjoying it and want to support my work, you can <b>buy me a coffee</b> ☕ over at <a class="link" href="https://www.buymeacoffee.com/0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-24-2026-npm-v12-is-the-apology-the-malware-section-is-the-receipt" target="_blank" rel="noopener noreferrer nofollow">https://www.buymeacoffee.com/0x58</a></p><p class="paragraph" style="text-align:left;"> See you next time!</p><p class="paragraph" style="text-align:left;">-X.</p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=e9d90c4a-2ad0-47f7-be57-b6bfb3fdb452&utm_medium=post_rss&utm_source=x_s_infosec_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🕵🏻‍♂️ [InfoSec MASHUP] 23/2026 - Built Broken, Patched by Others</title>
  <description>Plus: Palo Alto GlobalProtect auth bypass is actively exploited, Weil Gotshal reportedly paid $20M to keep client files quiet, and the EU is moving to limit U.S. cloud in sensitive infrastructure</description>
  <link>https://infosec-mashup.santolaria.net/p/infosec-mashup-23-2026-built-broken-patched-by-others</link>
  <guid isPermaLink="true">https://infosec-mashup.santolaria.net/p/infosec-mashup-23-2026-built-broken-patched-by-others</guid>
  <pubDate>Sat, 06 Jun 2026 07:28:00 +0000</pubDate>
  <atom:published>2026-06-06T07:28:00Z</atom:published>
    <dc:creator>Xavier Santolaria</dc:creator>
    <category><![CDATA[Malware]]></category>
    <category><![CDATA[Opensource]]></category>
    <category><![CDATA[Privacy]]></category>
    <category><![CDATA[Cybersecurity]]></category>
    <category><![CDATA[Threat Intelligence]]></category>
    <category><![CDATA[Ai]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Another week, another set of trojaned packages, hijacked registries, and one-click credential theft. The operational response is by now well-rehearsed: patch, rotate secrets, enable 2FA, audit your dependencies, check your CI/CD workflows. The patching teams are doing their jobs. The question this week&#39;s malware section keeps nudging at is a different one: why is so much of what they&#39;re patching broken at the point of creation?</p><p class="paragraph" style="text-align:left;">The supply chain attack surface exists because the software ecosystem normalized shipping fast over shipping secure, because package registries scaled adoption without scaling trust infrastructure, and because the developer who published a package with a hardcoded credential and the organization running it in production are rarely the same person bearing the consequences. IBM and Red Hat just committed $5 billion to fix this upstream. CISA launched CI Fortify to help OT operators survive worst-case scenarios downstream. Both efforts are necessary. Both are also symptoms of an industry that has spent decades externalizing the cost of insecure software onto the people least positioned to refuse it.</p><p class="paragraph" style="text-align:left;">Let’s now dive into this week’s top insights! 🚀</p><h2 class="heading" style="text-align:left;">Table of Contents</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="#breaches-security-incidents" rel="noopener noreferrer nofollow">BREACHES & SECURITY INCIDENTS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#cybercrime-cyber-espionage-ap-ts" rel="noopener noreferrer nofollow">CYBERCRIME, CYBER ESPIONAGE, APT’s</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#government-politics-and-privacy" rel="noopener noreferrer nofollow">GOVERNMENT, POLITICS, AND PRIVACY</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#malware-threats" rel="noopener noreferrer nofollow">MALWARE & THREATS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ai-crypto-tech-tools" rel="noopener noreferrer nofollow">AI, CRYPTO, TECH & TOOLS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#vulnerabilities-research-and-threat" rel="noopener noreferrer nofollow">VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ics-ot-io-t" rel="noopener noreferrer nofollow">ICS, OT & IoT</a></p></li></ul><div id="breaches-security-incidents" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🔓 BREACHES & SECURITY INCIDENTS</h3><p class="paragraph" style="text-align:left;">🦷 <b>A data breach at dental benefits administrator DentaQuest exposed information from about 2.6 million accounts</b> — The <a class="link" href="https://www.bleepingcomputer.com/news/security/dentaquest-data-breach-exposed-info-of-26-million-accounts/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">leaked 234 GB dataset</a> included names, emails, phone numbers, IDs, insurance details, genders, and birthdates. People affected should watch for phishing and other scams.</p><p class="paragraph" style="text-align:left;">🇺🇸 <b>Weil Gotshal reportedly paid $18–$20 million to stop hackers from publishing</b> stolen client documents. The firm says the <a class="link" href="https://www.legalcheek.com/2026/06/weil-reportedly-pays-up-to-20-million-after-hackers-steal-client-data/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">breach involved a limited number of files</a> and did not disrupt its network. <b>Weil</b> notified affected clients, launched an investigation, and involved law enforcement.</p><p class="paragraph" style="text-align:left;">🔓️ <b>Dashlane says hackers brute-forced its two-factor authentication and </b><a class="link" href="https://techcrunch.com/2026/06/02/password-manager-dashlane-says-hackers-stole-some-customers-password-vaults/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">accessed about 20 customer accounts</a> — The attackers :un, which can only be opened with each user’s master password. <b>Dashlane</b> notified affected users and says it has taken steps to reduce future risk.</p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://arstechnica.com/security/2026/06/dashlane-issues-opaque-advisory-warning-20-encrypted-vaults-were-stolen/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">Can&#39;t make sense of Dashlane&#39;s vault theft notification? You&#39;re not alone.</a></p><p class="paragraph" style="text-align:left;">📥️ 🤑 <b>Hackers accessed a senior executive’s Outlook mailbox at a major global stock exchange and stole data</b> for about 150 days. They <a class="link" href="https://www.securityweek.com/hackers-target-global-stock-exchange-in-espionage-operation/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">used disguised malware</a>, cloud services like <b>Dropbox</b> and <b>OneDrive</b>, and persistent fake system tasks to avoid detection. Security firms suspect espionage and released IoCs to help others detect similar attacks.</p><p class="paragraph" style="text-align:left;">→ More breaches:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/ima-diligence-services-data-breach-impacts-525000-people/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">IMA Diligence Services Data Breach Impacts 525,000 People</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/un-world-food-programme-breach-affects-600-000-gaza-households/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">UN food agency discloses breach affecting 600,000 Gaza households</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/nightclub-giant-rci-says-data-breach-affects-40000-individuals/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">Nightclub Giant RCI Says Data Breach Affects 40,000 Individuals</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.databreachtoday.com/conduent-hack-victim-count-now-tops-622-million-a-31900?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">Conduent Hack Victim Count Now Tops 62.2 Million</a></p></li></ul></div><p class="paragraph" style="text-align:left;"></p><div id="cybercrime-cyber-espionage-ap-ts" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🥷🏻 CYBERCRIME, CYBER ESPIONAGE, APT’s</h3><p class="paragraph" style="text-align:left;">🇨🇳 💼 <b>Five Eyes intelligence agencies warn China’s military intelligence uses LinkedIn and other job sites</b> to <a class="link" href="https://www.databreachtoday.com/china-using-linkedin-to-recruit-government-insiders-a-31861?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">recruit government and military insiders</a>. Recruiters pose as consultants, ask for reports, and pay via third-party platforms to obtain sensitive information. These operations have led to prosecutions, job losses, and cleared personnel losing security access.</p><p class="paragraph" style="text-align:left;">🇨🇳 🎣 <b>China-linked cybercrime group TA4922 has expanded phishing attacks</b> to the U.K., Germany, Italy, South Africa and other countries. They use HR, tax and business lures to deliver malware like <b>Atlas RAT</b>, <b>RomulusLoader</b> and <b>SilentRunLoader</b> to steal credentials and data. <b>Proofpoint</b> <a class="link" href="https://www.proofpoint.com/us/blog/threat-insight/ta4922-suspected-chinese-crime-group-going-global?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">says TA4922 is likely financially motivated</a> but has tools that could also enable surveillance or be sold to espionage groups.</p><p class="paragraph" style="text-align:left;">🇧🇬 🇪🇺 <b>European and international police dismantled nine organized crime groups and arrested 29 people</b> in Operation <i>KRATOS 2</i>. The seven-month raid, led by Bulgaria with <b>Europol</b> and partners from 13 countries, <a class="link" href="https://www.bleepingcomputer.com/news/security/police-dismantles-9-crime-groups-in-illegal-streaming-crackdown/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">removed over 27,000 illegal streaming URLs</a> and flagged hundreds of thousands more infringing links. Authorities said the networks earned big profits, hid servers across borders, and exposed users to malware and data theft.</p><p class="paragraph" style="text-align:left;">🇪🇸 <b>Spanish police arrested a person accused of leaking sensitive personal data of employees</b> from key state bodies, including <b>INCIBE</b> and the <b>National Police</b>. Officers raided the suspect’s home and seized computers to find forensic evidence and possible co-conspirators. Authorities say the <a class="link" href="https://www.bleepingcomputer.com/news/security/spain-arrests-doxer-leaking-sensitive-data-of-govt-employees/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">data came from aggregated sources and published on doxing forums</a>, and more arrests may follow.</p><p class="paragraph" style="text-align:left;">🇺🇸 🗳️ <b>Tina Peters, convicted for breaking into Mesa County election systems</b>, gave a defiant interview after her sentence was commuted. She said <a class="link" href="https://cyberscoop.com/tina-peters-unapologetic-bannon-interview-polis-commutation/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">she will keep fighting in court to clear her record</a> and repeated false claims about election fraud. The commutation drew praise from conservatives and strong criticism from Democrats and election officials.</p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://cyberscoop.com/2026-election-cyber-threats-campaign-systems/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">Election threats are focused on campaign systems, not voting machines</a></p><p class="paragraph" style="text-align:left;">🇪🇺 🇷🇺 <b>European intelligence officials say Russian spy agencies are aggressively stealing Western technology and defense secrets</b> as sanctions squeeze its economy. They use fake companies, middlemen, cyberattacks and hackers to acquire machine tools, software, space and weapons-related tech. Officials <a class="link" href="https://www.securityweek.com/russian-spies-are-aggressively-seeking-western-technology-as-sanctions-bite-officials-say/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">warn this risks helping Russia improve its weapons and enabling attacks</a> on critical infrastructure.</p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;">🗓️ <b><a class="link" href="https://xsa.github.io/infosec-events/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">{Cyber,Info}Sec Events</a></b> — A community-maintained list of infosec conferences worldwide. Subscribe to the <a class="link" href="https://xsa.github.io/infosec-events/events.ics?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">ICS calendar feed</a> to get events straight into your calendar, or follow <a class="link" href="https://infosec.exchange/@infosecevents?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">@infosecevents@infosec.exchange</a> on Mastodon for weekly digests. Contributions and ⭐ welcome!</p></div><p class="paragraph" style="text-align:left;"></p><div id="government-politics-and-privacy" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">👨🏻‍⚖️ 👀 GOVERNMENT, POLITICS, AND PRIVACY</h3><p class="paragraph" style="text-align:left;">🇪🇺 ☁️ <b>The EU is proposing rules to favor European cloud and AI services</b> and <a class="link" href="https://www.databreachtoday.com/eu-prepares-path-for-shutting-out-us-cloud-providers-a-31879?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">limit reliance on non‑EU providers</a>. New assurance levels could bar firms subject to foreign laws, which would hit U.S. cloud vendors because of the U.S. Cloud Act. Critics say the plan risks discrimination and fragmentation while supporters call it needed tech sovereignty.</p><p class="paragraph" style="text-align:left;">🇺🇸 🫂 <b>DHS Secretary Markwayne Mullin told Congress CISA should ideally have about 2,800 staff</b>, up from roughly 2,200 now. The agency once had about 3,400 employees <a class="link" href="https://cyberscoop.com/dhs-secretary-markwayne-mullin-pinpoints-optimal-cisa-staffing-levels/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">before cuts and faces more proposed reduction</a>s. <b>Mullin</b> said CISA can meet its mission by using partnerships and grants while a new director is expected to be nominated soon.</p></div><p class="paragraph" style="text-align:left;"></p><div id="malware-threats" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🦠 MALWARE & THREATS</h3><div class="embed"><a class="embed__url" href="https://unit42.paloaltonetworks.com/flutterbridge-new-fluttershell-backdoor/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank"><div class="embed__content"><p class="embed__title"> Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor </p><p class="embed__description"> Operation FlutterBridge is a malvertising campaign targeting macOS users. It distributed the new backdoor FlutterShell, built using the Flutter framework. </p><p class="embed__link"> Unit 42 • Ido Asher, Noa Dekel, Tom Fakterman </p></div><img class="embed__image embed__image--right" src="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/07_Malware_Category_1920x900.jpg"/></a></div><hr class="content_break"><p class="paragraph" style="text-align:left;">🇷🇺 🪆 🇺🇦 <b>Russian group Gamaredon is exploiting a WinRAR flaw (CVE-2025-8088)</b> to <a class="link" href="https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">deliver an HTA payload that installs VBScript</a> downloaders. Those downloaders deploy a worm (<b>GammaWorm</b>) that persists, hides via LNK and ADS, and a stealer (<b>GammaSteel</b>) that exfiltrates files to AWS S3 or attacker servers. The campaign targets Ukrainian government and military networks and can be reused to drop additional malware.</p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://blog.sekoia.io/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">FSB’s matryoshka #3/3 – Gamaredon’s gifts that keeps unpacking – GammaSteel</a></p><p class="paragraph" style="text-align:left;">🦀 <b>A new Rust-based malware called </b><i><b>IronWorm</b></i><b> infected 36 npm packages</b> to steal credentials and keys. It hides with an eBPF rootkit, uses <b>Tor</b>, and can self-publish trojaned packages using stolen npm secrets. Researchers <a class="link" href="https://research.jfrog.com/post/iron-worm-shai-hulud-rustier-cousin/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">stopped the attack early</a> and urge developers to update packages, rotate keys, and enable 2FA.</p><p class="paragraph" style="text-align:left;">🆔 ❌ <b>French and Spanish police shut down an online marketplace selling fake EU identity documents</b> used by migrant smugglers. Officers arrested a suspect in Alicante and seized equipment and about 800 counterfeit IDs. <b>Europol</b> says <a class="link" href="https://www.europol.europa.eu/media-press/newsroom/news/fake-document-factory-dismantled-in-spain-around-800-ids-seized?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">document fraud fuels migrant smuggling</a> and new EU efforts aim to improve cross‑border investigations.</p><p class="paragraph" style="text-align:left;">👾 <i><b>WeedHack</b></i><b> is a large malware campaign that has infected over 116,000 Minecraft players</b> since January. The malware is spread via fake <b>Minecraft</b> mods and YouTube/SEO-poisoned links and <a class="link" href="https://www.mcafee.com/blogs/other-blogs/mcafee-labs/weedhack-minecraft-malware-as-a-service-campaign-research/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">acts as a malware-as-a-service infostealer</a>. It steals credentials, browser data, crypto wallets, and can give remote control, and some paid tiers add keylogging and webcam access.</p><p class="paragraph" style="text-align:left;">🪱 <b>Attackers hijacked Red Hat’s official npm account </b>and published malicious packages. Over <a class="link" href="https://arstechnica.com/security/2026/06/dozens-of-red-hat-packages-backdoored-through-its-offical-npm-channel/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">30 packages contained a worm</a> that steals credentials and spreads to other machines. The supply-chain compromise is still active and widely trusted by developers.</p><p class="paragraph" style="text-align:left;">🇵🇰 🇦🇫 <b>Researchers say the Pakistan-linked </b><i><b>SideCopy</b></i><b> group used Pashto-language spear-phishing to target Afghanistan’s Ministry of Finance</b> with <b>Xeno RAT</b>. The <a class="link" href="https://www.seqrite.com/blog/operation-xenofiscal-sidecopy-deploying-persistent-xenorat-targeting-the-mof-afghanistan/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">attack used a malicious LNK file</a> that fetched an HTA to run obfuscated JavaScript and install <b>Xeno RAT 1.8.7</b>, which can steal data and control the system. This activity fits a broader pattern of <b>Transparent Tribe</b> operations against South Asian government and military targets.</p><p class="paragraph" style="text-align:left;">🤖 <b>A malicious npm package named </b><code>codexui-android</code><b> and linked Android apps stole OpenAI Codex auth tokens</b> by reading <code>~/.codex/auth.json</code> and sending them to attacker servers. The package was a functional, actively developed tool with over 29,000 weekly downloads and the exfiltration persisted across versions. Stolen refresh tokens <a class="link" href="https://www.aikido.dev/blog/codex-remote-ui-steals-ai-tokens?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">allow persistent account impersonation</a>, exposing developer workflows and supply-chain risks.</p></div><p class="paragraph" style="text-align:left;"></p><div id="ai-crypto-tech-tools" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🤖 🧰 AI, CRYPTO, TECH & TOOLS</h3><div class="image"><a class="image__link" href="https://cyberplace.social/@GossiTheDog/116679693992983945?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/102969d4-cf64-462d-9f72-dedaefcd1faf/Screenshot_2026-06-02_at_13.34.23.png?t=1780400137"/></a><div class="image__source"><span class="image__source_text"><p>Figure: Kevin Beaumont’s <a class="link" href="https://cyberplace.social/@GossiTheDog/116679693992983945?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">Toot</a> on Mythos</p></span></div></div><p class="paragraph" style="text-align:left;">🇪🇺 <b>Anthropic has offered EU cybersecurity agency ENISA controlled access to its Mythos</b> <a class="link" href="https://www.databreachtoday.com/europe-edges-closer-to-claude-mythos-access-a-31827?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">vulnerability-finding AI through </a><a class="link" href="https://www.databreachtoday.com/europe-edges-closer-to-claude-mythos-access-a-31827?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow"><b>Project Glasswing</b></a>. European agencies and banks are negotiating access as experts warn these models can rapidly find many software flaws. <b>OpenAI</b> and other companies are also discussing limited access to similar cyber-focused models.</p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://www.securityweek.com/anthropic-expanding-mythos-access-to-150-new-organizations/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">Anthropic Expanding Mythos Access to 150 New Organizations</a></p><hr class="content_break"><p class="paragraph" style="text-align:left;">🇺🇸 🤖 <b>Anthropic sent about six engineers to the NSA to help the agency use its cybersecurity AI, Mythos</b> — It is unclear if <b>Mythos</b> or the engineers<a class="link" href="https://techcrunch.com/2026/06/05/nsa-said-to-be-readying-anthropics-mythos-for-use-in-cyber-operations/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow"> are being used</a> in actual hacking operations. The reports follow earlier claims the <b>NSA</b> used <b>Mythos</b> despite a federal ban and <b>Anthropic</b> limiting access over security concerns.</p><p class="paragraph" style="text-align:left;">🔉 <b>Researchers found a critical flaw in Google’s Gemini voice assistant</b> that let attackers inject commands via normal messaging notifications. The <i><a class="link" href="https://www.safebreach.com/blog/gemini-voice-assistant-prompt-injection-exploit?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">Fake Context Alignment</a></i><a class="link" href="https://www.safebreach.com/blog/gemini-voice-assistant-prompt-injection-exploit?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow"> attack</a> hid instructions in WhatsApp, Slack, and SMS messages so <b>Gemini</b> would act without the user knowing. <b>Google</b> patched the issue after disclosure, but researchers warn prompt-injection risks remain as assistants gain deeper device access.</p><p class="paragraph" style="text-align:left;">💰️ 🇮🇷 ❌ <b>The U.S. Treasury blacklisted </b><i><b>Nobitex</b></i><b>, Iran’s largest crypto exchange</b>, for <a class="link" href="https://home.treasury.gov/news/press-releases/sb0519?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">helping fund terrorism</a> and evade sanctions. Officials say <b>Nobitex</b> processed over half of Iran’s crypto inflows in 2025 and moved funds tied to the IRGC and ransomware actors. The sanctions freeze U.S.-held assets and bar U.S. persons from dealing with the exchange and its executives.</p><p class="paragraph" style="text-align:left;">💰️ 🌏️ ❌ <b>The U.S. Justice Department led a global operation that disrupted Southeast Asian crypto</b> and online fraud networks. Private companies and police <a class="link" href="https://thehackernews.com/2026/06/doj-disrupts-southeast-asia-crypto.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">froze over $3.8 million in stolen cryptocurrency</a> and took down millions of scam accounts and servers. Authorities identified suspects, made arrests, and warned these scams steal victims’ savings and often involve trafficked workers in scam compounds.</p><p class="paragraph" style="text-align:left;">🇺🇸 <b>The Trump administration issued a scaled-back AI executive order that favors voluntary industry cooperation</b> over strict rules. Companies <a class="link" href="https://cyberscoop.com/donald-trump-white-house-ai-executive-order-scaled-back/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">may give the government access to frontier models</a> for up to 30 days, with protections for confidentiality and intellectual property. The order also creates an interagency cybersecurity clearinghouse led by Treasury to coordinate testing and threat benchmarks.</p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://cyberscoop.com/pentagon-cyber-integration-ai-security/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">DOD wants to integrate cyber in all operations, and integrate security into AI</a></p><p class="paragraph" style="text-align:left;">🤖 <b>Hackers used a trick to make Meta’s AI support bot add a new email and reset</b> Instagram passwords. High-profile accounts were <a class="link" href="https://krebsonsecurity.com/2026/06/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">briefly defaced</a> with pro-Iran messages. Enabling strong MFA (like passkeys or security keys) would have stopped the attack.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c8ce8976-e6a1-4fe5-8fbe-ab616112d6a5/image.png?t=1780644843"/><div class="image__source"><span class="image__source_text"><p>Figure: A screenshot from a video released on Telegram claiming to show how Meta’s AI customer support bot could be tricked into resetting a target’s password/krebsonsecurity.com</p></span></div></div></div><p class="paragraph" style="text-align:left;"></p><div id="vulnerabilities-research-and-threat" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🐛 🧠 VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</h3><p class="paragraph" style="text-align:left;">➝ From the Patching Department:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/acer-warns-of-max-severity-zero-days-affecting-wave-7-routers/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">Acer working to patch max severity zero-days in Wave 7 routers</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/android-update-patches-exploited-zero-day-123-other-vulnerabilities/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">Android Update Patches Exploited Zero-Day, 123 Other Vulnerabilities</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/chrome-149-patches-429-vulnerabilities/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">Chrome 149 Patches 429 Vulnerabilities</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://thehackernews.com/2026/06/cisco-patches-cve-2026-20230-in-unified.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">Cisco Patches CVE-2026-20230 as Exploit Code Goes Public</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/oracles-first-monthly-patches-resolve-77-vulnerabilities/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">Oracle’s First Monthly Patches Resolve 77 Vulnerabilities</a></p></li></ul><hr class="content_break"><div class="embed"><a class="embed__url" href="https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank"><div class="embed__content"><p class="embed__title"> Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257 </p><p class="embed__description"> We include indicators of activity and mitigations for PAN-OS vulnerability CVE-2026-0257. </p><p class="embed__link"> Unit 42 • Andy Piazza, Unit 42 </p></div><img class="embed__image embed__image--right" src="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/07_Vulnerabilities_1920x900.jpg"/></a></div><p class="paragraph" style="text-align:left;">💣️ <b>Calif researchers discovered an </b><i><b>HTTP/2 Bomb</b></i><b> exploit that can crash major web servers</b> in seconds. It chains an HPACK compression bomb with a Slowloris-style hold to exhaust memory and bypass limits. The <a class="link" href="https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">attack affects many default</a> NGINX, Apache, IIS, Envoy, and Cloudflare Pingora setups and can be run from a home connection.</p><p class="paragraph" style="text-align:left;">💥 <b>CISA warns that a two-year-old Oracle WebLogic bug (CVE-2024-21182) is now being exploited</b> in the wild. The flaw allows remote, unauthenticated attackers to <a class="link" href="https://www.securityweek.com/oracle-weblogic-vulnerability-exploited-in-the-wild/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">access or steal data from vulnerable servers</a>. <b>CISA</b> added it to its Known Exploited Vulnerabilities list and told agencies to fix it immediately.</p><p class="paragraph" style="text-align:left;">🐧 <b>A 19-year-old bug in the Linux kernel’s CIFS subsystem</b> lets low-privileged users gain root access. The flaw lets attackers supply fake key descriptions so <code>cifs.upcall</code> runs as root and loads attacker-controlled NSS code. Major distributions <a class="link" href="https://www.securityweek.com/19-year-old-linux-kernel-vulnerability-exposes-systems-to-root-access/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">have released fixes and a PoC was published</a> to help validate patches.</p><p class="paragraph" style="text-align:left;">💥 🔓️ <b>Hackers are actively exploiting a Palo Alto GlobalProtect VPN bug (CVE-2026-0257)</b> to bypass authentication and gain VPN access. The flaw affects devices with authentication override cookies enabled and reused certificates, <a class="link" href="https://www.bleepingcomputer.com/news/security/palo-alto-globalprotect-vpn-auth-bypass-flaw-now-exploited-in-attacks/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">letting attackers forge valid cookies</a>. Update PAN-OS now or disable the override feature and use separate certificates to stop the attacks.</p></div><p class="paragraph" style="text-align:left;"></p><div id="ics-ot-io-t" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🛰️ ICS, OT & IoT</h3><p class="paragraph" style="text-align:left;">⛽️ 🇺🇸 <b>Over 900 automatic tank gauge systems in the U.S. are exposed online</b> and vulnerable to attacks. Federal agencies <a class="link" href="https://www.bleepingcomputer.com/news/security/over-900-us-gas-station-tank-gauge-systems-exposed-to-attacks/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">warn</a> attackers can change settings, disable alerts, and risk leaks or damage. Organizations are urged to restrict internet access, change defaults, and apply security controls.</p><p class="paragraph" style="text-align:left;">⚠️ <b>CISA launched </b><i><b>CI Fortify</b></i><b> to help industrial control operators plan for and rehearse surviving major cyberattacks</b> that cut them off from networks. The <a class="link" href="https://www.databreachtoday.com/cisa-urges-ot-operators-to-plan-for-worst-case-scenarios-a-31877?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">guidance focuses on keeping critical services</a> like water and power running without internet or remote control. <b>CISA</b> must coordinate with other agencies, vendors, and service providers to make the plan practical.</p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">💬 CONNECT</h3><p class="paragraph" style="text-align:left;">Follow me on <a class="link" href="https://infosec.exchange/@0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">Mastodon</a> for quick daily updates and bite-sized content.</p><p class="paragraph" style="text-align:left;">Prefer using an RSS feed? Add <b>Infosec MASHUP</b> to your feed <a class="link" href="https://rss.beehiiv.com/feeds/HVhiKYpQlR.xml?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">here</a>.</p><p class="paragraph" style="text-align:center;"><b>Enjoying our newsletter? </b>Forward it to a colleague—<br>it’s one of the best ways to support us.</p><p class="paragraph" style="text-align:left;">Thanks for reading today’s newsletter, and if you&#39;re enjoying it and want to support my work, you can <b>buy me a coffee</b> ☕ over at <a class="link" href="https://www.buymeacoffee.com/0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-23-2026-built-broken-patched-by-others" target="_blank" rel="noopener noreferrer nofollow">https://www.buymeacoffee.com/0x58</a></p><p class="paragraph" style="text-align:left;"> See you next time!</p><p class="paragraph" style="text-align:left;">-X.</p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=04944c6a-fdeb-4ebf-a76f-9898b3e823f4&utm_medium=post_rss&utm_source=x_s_infosec_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🕵🏻‍♂️ [InfoSec MASHUP] 22/2026 - The Patch Is Scaling. So Is the Attack.</title>
  <description>Plus: ShinyHunters hit Carnival, Charter, and Mytheresa, the Dutch blocked a U.S. takeover of their national ID infrastructure, and Iran-linked actors are coding backdoors with AI assistance</description>
  <link>https://infosec-mashup.santolaria.net/p/infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack</link>
  <guid isPermaLink="true">https://infosec-mashup.santolaria.net/p/infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack</guid>
  <pubDate>Sat, 30 May 2026 09:05:00 +0000</pubDate>
  <atom:published>2026-05-30T09:05:00Z</atom:published>
    <dc:creator>Xavier Santolaria</dc:creator>
    <category><![CDATA[Malware]]></category>
    <category><![CDATA[Opensource]]></category>
    <category><![CDATA[Privacy]]></category>
    <category><![CDATA[Cybersecurity]]></category>
    <category><![CDATA[Threat Intelligence]]></category>
    <category><![CDATA[Ai]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><b>Megalodon</b> backdoored 5,500 GitHub repositories in six hours. Not six days — six hours. Malicious commits silently replacing CI/CD workflows, hoovering tokens, cloud credentials, SSH keys, and environment variables before most of the affected projects had processed a single alert. The same week, <b>IBM</b> and <b>Red Hat</b> announced a $5 billion commitment, called <b>Project Lightwell</b>, to securing the open source supply chain, Anthropic&#39;s Mythos model surfaced 23,000 potential vulnerabilities across 1,000 OSS projects, and Apple open-sourced its quantum-resistant crypto stack with formal verification proofs attached. The industry&#39;s response to supply chain risk is finally arriving at a scale that looks serious.</p><p class="paragraph" style="text-align:left;">The problem is the math. The response is measured in billions of dollars and multi-year programs. The attack is measured in hours and automated tooling. Megalodon&#39;s six-hour window isn&#39;t an anomaly — it&#39;s a benchmark. Last week it was <b>TeamPCP</b> and the <b>GitHub</b> cascade. The week before, Laravel Lang and malicious postinstall hooks across 700 repos. The investment in defense is real and necessary, but it&#39;s being deployed against a threat that doesn&#39;t need a budget cycle to iterate. <b>Project Lightwell</b> will fund important work. Megalodon already shipped.</p><p class="paragraph" style="text-align:left;">Let’s now dive into this week’s top insights! 🚀</p><h2 class="heading" style="text-align:left;">Table of Contents</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="#breaches-security-incidents" rel="noopener noreferrer nofollow">BREACHES & SECURITY INCIDENTS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#cybercrime-cyber-espionage-ap-ts" rel="noopener noreferrer nofollow">CYBERCRIME, CYBER ESPIONAGE, APT’s</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#government-politics-and-privacy" rel="noopener noreferrer nofollow">GOVERNMENT, POLITICS, AND PRIVACY</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#malware-threats" rel="noopener noreferrer nofollow">MALWARE & THREATS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ai-crypto-tech-tools" rel="noopener noreferrer nofollow">AI, CRYPTO, TECH & TOOLS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#vulnerabilities-research-and-threat" rel="noopener noreferrer nofollow">VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ics-ot-io-t" rel="noopener noreferrer nofollow">ICS, OT & IoT</a></p></li></ul><div id="breaches-security-incidents" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🔓 BREACHES & SECURITY INCIDENTS</h3><div class="embed"><a class="embed__url" href="https://haveibeenpwned.com/Breach/Mytheresa?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank"><div class="embed__content"><p class="embed__title"> Have I Been Pwned: Mytheresa Data Breach </p><p class="embed__description"> In April 2026, the luxury fashion e-commerce platform Mytheresa was listed as a victim of the ShinyHunters &quot;pay or leak&quot; extortion group. After the ransom deadline passed, the group publicly released the data which contained 84k unique email addresses. The exposed data also included names, phone numbers, physical addresses, purchases and partial credit card data including card type, last 4 digits and expiry date. </p><p class="embed__link"> Have I Been Pwned </p></div><img class="embed__image embed__image--right" src="https://haveibeenpwned.com/Images/OG/Mytheresa"/></a></div><hr class="content_break"><p class="paragraph" style="text-align:left;">🛳️ <b>Carnival Corporation confirmed a data breach that exposed nearly 6 million people’s information</b> after attackers used social engineering to access its IT systems. Security researchers and <b>Have I Been Pwned</b> say the leaked data includes names, birth dates, emails, locations, and loyalty program details. The <b>ShinyHunters</b> gang <a class="link" href="https://www.bleepingcomputer.com/news/security/carnival-cruise-confirms-data-breach-affecting-nearly-6-million-people/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">claimed responsibility</a>, and <b>Carnival</b> is investigating with outside security experts.</p><p class="paragraph" style="text-align:left;">🇳🇱 ⚽️ <b>Dutch police arrested a 35-year-old man suspected of repeatedly hacking Ajax</b>’s computer systems. The <a class="link" href="https://www.bleepingcomputer.com/news/security/dutch-police-arrests-suspect-linked-to-ajax-football-club-hack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">breach exposed data on hundreds of fans</a> and let the attacker alter tickets and stadium bans. <b>Ajax</b> patched the flaws and reported the incident to authorities.</p><p class="paragraph" style="text-align:left;">🇺🇸 📡 <b>Charter Communications says it suffered a data breach after the ShinyHunters extortion group threatened to leak</b> stolen records. <b>Charter</b> claims no sensitive personal or CPNI data was exfiltrated and is notifying authorities. <b>ShinyHunters</b> say they accessed an employee&#39;s <b>Microsoft</b> Entra account and <a class="link" href="https://www.bleepingcomputer.com/news/security/charter-confirms-data-breach-after-shinyhunters-extortion-threat/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">exported millions of customer records</a> from <b>Salesforce</b>.</p><p class="paragraph" style="text-align:left;">🇱🇹 <b>Lithuania says over 600,000 national registry entries were leaked</b>, likely by a foreign actor. Officials blocked accounts, tightened security, and the registry head resigned. Some <a class="link" href="https://www.securityweek.com/lithuania-suspects-foreign-involvement-in-data-leak-of-over-600000-national-register-entries/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">suspect Russian involvement</a>, but authorities have not named a country.</p><p class="paragraph" style="text-align:left;">→ More breaches:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/266000-affected-by-data-breach-at-radiology-associates-of-richmond/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">266,000 Affected by Data Breach at Radiology Associates of Richmond</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://techcrunch.com/2026/05/26/7-eleven-data-breach-affects-over-185000-peoples-personal-data/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">7-Eleven data breach affects over 185,000 people’s personal data</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/docketwise-data-breach-impacts-143000/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">DocketWise Data Breach Impacts 143,000</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/man-sent-to-prison-for-selling-data-of-7-millions-elderly-americans/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">Man sent to prison for selling data of 7 millions elderly Americans</a></p></li></ul></div><p class="paragraph" style="text-align:left;"></p><div id="cybercrime-cyber-espionage-ap-ts" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🥷🏻 CYBERCRIME, CYBER ESPIONAGE, APT’s</h3><p class="paragraph" style="text-align:left;">🇮🇷 <b>Iran-linked </b><i><b>MuddyWater</b></i><b> ran an espionage campaign in early 2026 hitting at least nine organizations</b> across four continents. The <a class="link" href="https://www.security.com/threat-intelligence/iran-seedworm-electronics?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">attackers used DLL side‑loading</a> of signed binaries and <b>Node.js/PowerShell</b> implants to steal credentials, browser data, and stage exfiltration. Researchers say the tactics show quieter, more disciplined operations and improved operational hygiene.</p><p class="paragraph" style="text-align:left;">🇨🇦 ⚖️ <b>A Canadian man, Ramanan Pathmanathan, was sentenced to 33 years in U.S. prison for running an eight-year sextortion scheme</b> targeting over 145 children, some as young as six. He <a class="link" href="https://www.bleepingcomputer.com/news/security/sextortionist-sentenced-to-33-years-for-targeting-145-children/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">pleaded guilty to coercion and child pornography charges</a>, must register as a sex offender, and will serve 10 years supervised release on top of a prior 12-year Canadian sentence. Pathmanathan used fake social media accounts to coerce victims into sexual acts on video and threatened to share recordings.</p><p class="paragraph" style="text-align:left;">🇷🇴 ⚖️ 🇺🇸 <b>A Romanian hacker, Catalin Dragomir, was sentenced in the U.S. to 4 years and 8 months for selling</b> access to an Oregon state network. He <a class="link" href="https://www.securityweek.com/romanian-hacker-sentenced-to-prison-in-us-for-selling-access-to-state-network/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">admitted hacking the network in 2021</a>, selling access and data from multiple U.S. organizations, and causing over $250,000 in losses. <b>Dragomir</b> was arrested in Romania, extradited to the U.S., and pleaded guilty to computer fraud and identity theft.</p><p class="paragraph" style="text-align:left;">🇮🇷 🇺🇸 🚇️ <b>Security researchers say Iranian state-backed hackers breached the Los Angeles transit system</b> in March. An Israeli firm, <b>Gambit Security</b>, ties the group <b>Ababil of Minab</b> to <a class="link" href="https://techcrunch.com/2026/05/26/iranian-hackers-blamed-for-breach-of-los-angeles-transit-system-that-took-weeks-to-recover/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">Iran’s Ministry of State Security</a>. The attack fits a pattern of Iran-linked fake &quot;hacktivist&quot; groups targeting infrastructure.</p><p class="paragraph" style="text-align:left;">🇮🇹 ❌ <b>Italian police shut down the CINEMAGOAL piracy app</b> that stole streaming auth codes to give users access to Netflix, Disney+, Spotify and more. The <a class="link" href="https://www.bleepingcomputer.com/news/legal/italy-disrupts-cinemagoal-piracy-app-that-stole-streaming-auth-codes/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">app used stolen decryption codes from fake subscriptions</a> and routed streams through servers in Europe, earning operators millions and costing platforms about €300 million. Authorities seized servers, identified many subscribers, issued fines, and continue investigating resellers and other accomplices.</p><p class="paragraph" style="text-align:left;">🇳🇱 ❌ 🇷🇺 <b>Dutch authorities seized over 800 servers and arrested two men tied to hosting companies that allegedly supported Russian cyberattacks</b> and disinformation. Investigators say the firms routed <b>Stark Industries</b>’ infrastructure and helped sanctioned entities evade limits. The <a class="link" href="https://krebsonsecurity.com/2026/05/netherlands-seizes-800-servers-arrests-2-for-aiding-cyberattacks/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">suspects deny wrongdoing</a> while probes continue and services linked to the firms have been paused.</p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;">🗓️ <b><a class="link" href="https://xsa.github.io/infosec-events/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">{Cyber,Info}Sec Events</a></b> — A community-maintained list of infosec conferences worldwide. Subscribe to the <a class="link" href="https://xsa.github.io/infosec-events/events.ics?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">ICS calendar feed</a> to get events straight into your calendar, or follow <a class="link" href="https://infosec.exchange/@infosecevents?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">@infosecevents@infosec.exchange</a> on Mastodon for weekly digests. Contributions and ⭐ welcome!</p></div><p class="paragraph" style="text-align:left;"></p><div id="government-politics-and-privacy" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">👨🏻‍⚖️ 👀 GOVERNMENT, POLITICS, AND PRIVACY</h3><p class="paragraph" style="text-align:left;">🇺🇸 ⚖️ 🧬 <b>California sued 23andMe for failing to protect genetic data after a 2023 breach</b> that exposed nearly 7 million customers. The <a class="link" href="https://www.securityweek.com/california-sues-23andme-alleging-it-failed-to-protect-user-data-in-2023-breach/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">suit says the company ignored warning signs</a>, did not require password resets or multifactor authentication, and misled the public. <b>23andMe</b> previously agreed to a settlement worth up to $50 million over the breach.</p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://www.databreachtoday.com/23andme-failed-to-stop-months-long-hack-state-alleges-a-31816?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">23andMe Failed to Stop Months-Long Hack, State Alleges</a></p><p class="paragraph" style="text-align:left;">🇳🇱 🇺🇸 ☁️ <b>The Dutch government blocked the sale of Solvinity, which runs the DigiD system, to U.S. firm Kyndryl over national security</b> and <a class="link" href="https://www.databreachtoday.com/us-takeover-dutch-cloud-id-provider-blocked-by-government-a-31780?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">digital sovereignty concerns</a>. Officials cited risks from U.S. laws like the Cloud Act and potential dependence on foreign tech. <b>Kyndryl</b> said it was disappointed while <b>Solvinity</b> is consulting with authorities.</p></div><p class="paragraph" style="text-align:left;"></p><div id="malware-threats" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🦠 MALWARE & THREATS</h3><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/BLb46310iLs" width="100%"></iframe><hr class="content_break"><p class="paragraph" style="text-align:left;">⛏️ <b>Attackers are spreading GPU‑mining malware by poisoning search results</b> and even manipulating AI chatbot recommendations. Users downloading popular utility tools get a ZIP that contains a legitimate program and a malicious DLL which installs remote access (ScreenConnect) and a hidden miner. The <a class="link" href="https://www.microsoft.com/en-us/security/blog/2026/05/26/poisoned-search-results-gpu-mining-cryptojacking-campaign-abusing-screenconnect-microsoft-net-utilities/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">campaign focuses on high‑performance systems</a> and uses stealth techniques to maximize GPU mining yield.</p><p class="paragraph" style="text-align:left;">🎣 💬 <b>Hackers are sending fake Signal Support messages to trick users into revealing their recovery keys</b> for encrypted backups. If stolen, those keys could let attackers access old chats, photos, and documents. <b>Signal</b> <a class="link" href="https://techcrunch.com/2026/05/28/hackers-are-trying-to-steal-signal-users-backups-in-new-wave-of-phishing-attacks/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">warns it will never ask for recovery keys</a>, PINs, or registration codes.</p><p class="paragraph" style="text-align:left;">🎠 📲 <b>BTMOB is an Android remote access trojan that can steal data and fully take over devices</b> — It’s <a class="link" href="https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">sold as an easy-to-use kit</a> and spread via phishing, fake app stores, and social media. ESET warns it’s evolving fast and mainly seen in Latin America but can spread further.</p><p class="paragraph" style="text-align:left;">❌ <b>CrowdStrike, with help from Google and Shadowserver, dismantled the Glassworm botnet</b> by taking down four attacker-controlled servers. <b>Glassworm</b> had infected hundreds of open-source projects and abused developer tools to spread malware and steal data. The <a class="link" href="https://cyberscoop.com/crowdstrike-glassworm-botnet-takedown/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">takedown disrupted the attackers’ infrastructure</a> and aimed to slow future supply-chain attacks.</p><p class="paragraph" style="text-align:left;">🇰🇵 <b>Researchers say North Korea-linked Lazarus Group is using a memory-only RAT called </b><i><b>RemotePE</b></i> to target financial and crypto firms. <b>RemotePE</b> is loaded in stages by <i>DPAPILoader</i> and <i>RemotePELoader</i> and runs entirely in memory to avoid detection. The <a class="link" href="https://blog.fox-it.com/2026/05/22/remotepe-the-lazarus-rat-that-lives-in-memory/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">toolset is stealthy, under active development since 2023</a>, and likely used for long-term spying and high-value theft.</p><p class="paragraph" style="text-align:left;">🥷 <b>Attackers hijacked </b><i><b>Laravel Lang</b></i><b> Git tags to distribute malicious Composer packages</b> without changing the original source. The injected code downloaded a cross-platform <a class="link" href="https://www.aikido.dev/blog/supply-chain-attack-targets-laravel-lang-packages-with-credential-stealer?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">credential stealer</a> that harvests keys, tokens, passwords, and browser data. Developers should check versions, rotate credentials, and scan for signs of compromise.</p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://socket.dev/blog/malicious-postinstall-hook-found-across-700-github-repos?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">Malicious Postinstall Hook Found Across 700+ GitHub Repositories, Including Packagist and Node.js Projects</a></p><p class="paragraph" style="text-align:left;">🔙 🚪<b>A supply chain attack called </b><i><b>Megalodon</b></i><b> infected over 5,500 GitHub repositories with malicious commits</b> that added or replaced GitHub Actions workflows. The malware stole many secrets — tokens, cloud credentials, SSH keys, and CI environment variables. The <a class="link" href="https://safedep.io/megalodon-mass-github-repo-backdooring-ci-workflows/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack#full-list-of-compromised-github-repositories" target="_blank" rel="noopener noreferrer nofollow">attack ran in a six-hour window and can trigger dormant backdoors</a> via GitHub tokens.</p><p class="paragraph" style="text-align:left;">🇮🇷 🔙 🚪<b>Iran-linked group </b><i><b>Nimbus Manticore</b></i><b> used phishing, fake meeting invites, and SEO-poisoned sites to spread new backdoors</b> called <b>MiniJunk V2</b> and <b>MiniFast</b>. <a class="link" href="https://research.checkpoint.com/2026/fast-and-furious-nimbus-manticore-operations-during-the-iranian-conflict/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">Check Point</a> and <a class="link" href="https://unit42.paloaltonetworks.com/tracking-iran-apt-screening-serpens/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">Unit 42</a> say <b>MiniFast</b> shows signs of AI-assisted coding and gives long-term remote access and data exfiltration. The attacks targeted aviation, software, energy, and other sectors across the U.S., Europe, and the Middle East, ramping up after the February 2026 conflict.</p></div><p class="paragraph" style="text-align:left;"></p><div id="ai-crypto-tech-tools" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🤖 🧰 AI, CRYPTO, TECH & TOOLS</h3><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/5DPQ3m3e8OE" width="100%"></iframe><hr class="content_break"><p class="paragraph" style="text-align:left;">🔐 <b>IBM and Red Hat are investing $5 billion in </b><i><b>Project Lightwell</b></i><b> to secure open source software</b> used by businesses. The project <a class="link" href="https://www.securityweek.com/ibm-and-red-hat-commit-5-billion-to-secure-open-source-supply-chains-under-project-lightwell/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">uses artificial intelligence to find and fix security problems</a> in open source code. Many big banks and companies will take part to help protect important digital systems.</p><p class="paragraph" style="text-align:left;">🇬🇧 🔫 <b>The head of Britain’s GCHQ warned that AI is an “unstoppable force” that can be weaponized</b> in cyberspace. She said <a class="link" href="https://cyberscoop.com/gchq-warns-ai-cyber-warfare-threats/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">AI is reshaping offense and defense</a>, and agencies must rebuild cybersecurity around agentic AI. She also warned that <b>China</b> and <b>Russia</b> are using AI and cyber tools to boost their power and influence.</p><p class="paragraph" style="text-align:left;">🧩 <b>Anthropic added 28 security and compliance integrations to Claude</b> so companies can govern the AI like other workplace tools. The <a class="link" href="https://claude.com/blog/compliance-api-security-partners?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">Claude Compliance API</a> sends conversation content and activity logs to existing security platforms for monitoring and policy enforcement. Supported vendors include CrowdStrike, Microsoft, Palo Alto Networks, Okta, Datadog, IBM and many others.</p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://claude.com/blog/code-w-claude-london-2026-rethinking-how-we-build?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">Anthropic Releases New Claude Sandbox, Security Guidance Plugin</a></p><p class="paragraph" style="text-align:left;">🍎 🔐 <b>Apple open-sourced its quantum-resistant encryption code and the formal verification tools</b> used to prove the code correct. The <a class="link" href="https://cyberscoop.com/apple-open-source-quantum-resistant-encryption/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">release includes ML-KEM and ML-DSA in Apple’s corecrypto library</a>, used on billions of devices, plus a Cryptol-to-Isabelle translator and verification documentation. <b>Apple</b> says it combined formal proofs with conventional testing to catch subtle bugs and boost real-world security.</p></div><p class="paragraph" style="text-align:left;"></p><div id="vulnerabilities-research-and-threat" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🐛 🧠 VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</h3><p class="paragraph" style="text-align:left;">➝ From the Patching Department:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/chrome-148-update-patches-151-vulnerabilities/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">Chrome 148 Update Patches 151 Vulnerabilities</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://thehackernews.com/2026/05/microsoft-patches-sharepoint-rce-flaw.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions</a></p></li></ul><hr class="content_break"><div class="embed"><a class="embed__url" href="https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank"><div class="embed__content"><p class="embed__title"> A shared responsibility: Protecting customers through Coordinated Vulnerability Disclosure </p><p class="embed__link"> www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure </p></div></a></div><div class="embed"><a class="embed__url" href="https://techcrunch.com/2026/05/29/microsoft-under-fire-for-threatening-security-researcher-with-criminal-investigation/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank"><div class="embed__content"><p class="embed__title"> Microsoft under fire for threatening security researcher with criminal investigation | TechCrunch </p><p class="embed__description"> A public spat between Microsoft and an independent security researcher reopens a long-running debate over who is responsible for securing software. </p><p class="embed__link"> TechCrunch • Lorenzo Franceschi-Bicchierai </p></div><img class="embed__image embed__image--right" src="https://techcrunch.com/wp-content/uploads/2026/05/microsoft-logo.jpg?resize=1200,800"/></a></div><div class="image"><a class="image__link" href="https://www.linkedin.com/posts/spacerogue_microsoft-didnt-get-6-zero-days-dumped-on-share-7466106369029476352-lz6t/?utm_source=share&utm_medium=member_desktop&rcm=ACoAAACXoJQBJKaNb1ebm-7Rze9KPHv43nNYuKE" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/6f2d8f9c-f750-4448-9d4c-2c3ba8fce713/Screenshot_2026-05-30_at_09.58.28.png?t=1780127929"/></a><div class="image__source"><span class="image__source_text"><p>Figure: <a class="link" href="https://www.linkedin.com/posts/spacerogue_microsoft-didnt-get-6-zero-days-dumped-on-share-7466106369029476352-lz6t/?utm_source=share&utm_medium=member_desktop&rcm=ACoAAACXoJQBJKaNb1ebm-7Rze9KPHv43nNYuKE" target="_blank" rel="noopener noreferrer nofollow">Space Rogue’s LinkedIn post</a> reacting on Microsoft’s stance on responsible vulnerabiliy disclosures</p></span></div></div><hr class="content_break"><p class="paragraph" style="text-align:left;">🔎 <b>A federal audit found NIST has mismanaged the National Vulnerability Database</b>, causing a <a class="link" href="https://cyberscoop.com/nist-nvd-audit-mismanagement-duplication/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">large backlog and poor planning</a>. Analysts spend too much time on duplicate or unnecessary work, and NIST and CISA sometimes repeat each other’s efforts. The inspector general urged clearer plans, better coordination, and improved communication, and NIST agreed to fix the problems.</p><p class="paragraph" style="text-align:left;">🩹 <b>Security researchers found five linked bugs in Zapier that could have let an attacker control millions</b> of user accounts. The chain began with a free account and ended with code that could act inside users’ browsers to run automations. <b>Zapier</b> <a class="link" href="https://cyberscoop.com/zapier-bug-chain-account-takeover-patched/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">fixed the issues after disclosure</a> and says there is no evidence the flaws were exploited.</p><p class="paragraph" style="text-align:left;">💥 <b>Attackers exploited a critical FortiClient EMS flaw (CVE-2026-35616) </b>to <a class="link" href="https://arcticwolf.com/resources/blog/forticlient-ems-exploited-via-cve-2026-35616-to-deliver-ekz-infostealer-disguised-as-a-fortinet-patch/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">push a fake update</a> that ran malicious PowerShell on managed endpoints. The payload stole browser data and saved it locally, while a PowerShell script exfiltrated the stolen data to an attacker server. <b>Fortinet</b> patched the vulnerability in <b>FortiClient</b> <b>EMS</b> 7.4.7 and later.</p><p class="paragraph" style="text-align:left;">🔓️ <b>A four-year bug in Gitea’s container registry (CVE-2026-27771) let anyone pull images marked private</b> without authentication. <a class="link" href="https://www.noscope.com/blog/gitea-instances-exposing-private-container?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">NoScope found</a> about 31,750 of ~34,000 internet-facing <b>Gitea</b> instances were likely vulnerable, including ~4,000 production systems. Update to <b>Gitea</b> 1.26.2 or require authentication for registry access immediately.</p><p class="paragraph" style="text-align:left;">🤖 <b>Anthropic’s Claude Mythos model flagged over 23,000 potential vulnerabilities across more than 1,000 open-source projects</b> — External reviews confirmed <a class="link" href="https://www.securityweek.com/anthropic-mythos-detected-23000-potential-vulnerabilities-across-1000-oss-projects/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">1,726 issues so far, including over 1,000 rated high or critical</a>, and <b>Anthropic</b> expects thousands more confirmations as scans continue. The company is sharing findings with vendors, has started patching some flaws, and plans to expand access while adding safeguards.</p><p class="paragraph" style="text-align:left;">💥 <b>A patched SQL injection bug in the Ghost CMS (CVE-2026-26980) has been widely exploited</b> to hack over 700 sites. Attackers <a class="link" href="https://www.sentinelone.com/vulnerability-database/cve-2026-26980/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">stole Admin API keys to inject malicious JavaScript</a> and alter site content. Victims include big organizations and many personal blogs, and many owners did not respond to notifications.</p></div><p class="paragraph" style="text-align:left;"></p><div id="ics-ot-io-t" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🛰️ ICS, OT & IoT</h3><p class="paragraph" style="text-align:left;">⚽️ <b>The 2026 World Cup faces high cyber risk from criminal fraud, hacktivist DDoS/defacement, and state-linked</b> disruptive or destructive operations. Fans, hospitality providers, ticketing/FanID systems, and host-city utilities are prime targets. Organizers should pre-coordinate multi-jurisdictional defenses, audit OT and exposed services, and <a class="link" href="https://unit42.paloaltonetworks.com/fifa-world-cup-attack-surface/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">run realistic incident exercises before kickoff</a>.</p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">💬 CONNECT</h3><p class="paragraph" style="text-align:left;">Follow me on <a class="link" href="https://infosec.exchange/@0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">Mastodon</a> for quick daily updates and bite-sized content.</p><p class="paragraph" style="text-align:left;">Prefer using an RSS feed? Add <b>Infosec MASHUP</b> to your feed <a class="link" href="https://rss.beehiiv.com/feeds/HVhiKYpQlR.xml?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">here</a>.</p><p class="paragraph" style="text-align:center;"><b>Enjoying our newsletter? </b>Forward it to a colleague—<br>it’s one of the best ways to support us.</p><p class="paragraph" style="text-align:left;">Thanks for reading today’s newsletter, and if you&#39;re enjoying it and want to support my work, you can <b>buy me a coffee</b> ☕ over at <a class="link" href="https://www.buymeacoffee.com/0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-22-2026-the-patch-is-scaling-so-is-the-attack" target="_blank" rel="noopener noreferrer nofollow">https://www.buymeacoffee.com/0x58</a></p><p class="paragraph" style="text-align:left;"> See you next time!</p><p class="paragraph" style="text-align:left;">-X.</p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=0e709fd7-d54e-413a-8d3b-931b31826097&utm_medium=post_rss&utm_source=x_s_infosec_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🕵🏻‍♂️ [InfoSec MASHUP] 21/2026 - The Supply Chain Didn&#39;t Break. It Was Walked.</title>
  <description>Plus: fast16 predated Stuxnet and corrupted nuclear simulations quietly, Pwn2Own Berlin paid $1.3M for 47 bugs, and Bluesky got hijacked for Russian propaganda</description>
  <link>https://infosec-mashup.santolaria.net/p/infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked</link>
  <guid isPermaLink="true">https://infosec-mashup.santolaria.net/p/infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked</guid>
  <pubDate>Sat, 23 May 2026 07:59:00 +0000</pubDate>
  <atom:published>2026-05-23T07:59:00Z</atom:published>
    <dc:creator>Xavier Santolaria</dc:creator>
    <category><![CDATA[Malware]]></category>
    <category><![CDATA[Opensource]]></category>
    <category><![CDATA[Privacy]]></category>
    <category><![CDATA[Cybersecurity]]></category>
    <category><![CDATA[Threat Intelligence]]></category>
    <category><![CDATA[Ai]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">This week&#39;s issue reads like a case study in cascade failure. A malicious VS Code extension on one <b>GitHub</b> employee&#39;s device leads to 3,800 internal repositories exfiltrated — by <b>TeamPCP</b>, the same group that poisoned 170 npm and PyPI packages last week. <b>Grafana</b> gets breached via a token nobody rotated after the TanStack attack, itself a TeamPCP operation. A GitHub Action used by thousands of projects gets compromised and starts exfiltrating CI/CD credentials. And somewhere in a public GitHub spreadsheet, <b>CISA</b> contractor credentials — including AWS GovCloud keys — sat waiting to be found.</p><p class="paragraph" style="text-align:left;">These aren&#39;t four separate incidents. They&#39;re one incident with four manifestations. The supply chain isn&#39;t a vector anymore; it&#39;s the terrain. Developer tooling, CI/CD pipelines, third-party actions, tokens issued and forgotten — all of it is now actively mapped and exploited with a persistence that makes the traditional &quot;patch and move on&quot; response look quaint. The <b>Verizon DBIR</b> dropped this week noting that third-party compromise is surging. The week&#39;s news was already illustrating the point before the report landed.</p><p class="paragraph" style="text-align:left;">Let’s now dive into this week’s top insights! 🚀</p><h2 class="heading" style="text-align:left;">Table of Contents</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="#breaches-security-incidents" rel="noopener noreferrer nofollow">BREACHES & SECURITY INCIDENTS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#cybercrime-cyber-espionage-ap-ts" rel="noopener noreferrer nofollow">CYBERCRIME, CYBER ESPIONAGE, APT’s</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#government-politics-and-privacy" rel="noopener noreferrer nofollow">GOVERNMENT, POLITICS, AND PRIVACY</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#malware-threats" rel="noopener noreferrer nofollow">MALWARE & THREATS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ai-crypto-tech-tools" rel="noopener noreferrer nofollow">AI, CRYPTO, TECH & TOOLS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#vulnerabilities-research-and-threat" rel="noopener noreferrer nofollow">VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ics-ot-io-t" rel="noopener noreferrer nofollow">ICS, OT & IoT</a></p></li></ul><div id="breaches-security-incidents" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🔓 BREACHES & SECURITY INCIDENTS</h3><div class="embed"><a class="embed__url" href="https://cyberscoop.com/canvas-breach-saas-security-identity-governance-op-ed/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank"><div class="embed__content"><p class="embed__title"> The Canvas breach proved that prevention is no longer enough </p><p class="embed__description"> The Canvas breach exposed a fatal flaw in enterprise security: a total reliance on platform availability over data protection. Learn why identity governance and cryptographic resilience are the only ways to reduce the blast radius of the next inevitable SaaS attack. </p><p class="embed__link"> CyberScoop • Greg Otto </p></div><img class="embed__image embed__image--right" src="https://cyberscoop.com/wp-content/uploads/sites/3/2026/05/GettyImages-927504382.jpg"/></a></div><p class="paragraph" style="text-align:left;">🇺🇸 📲 <b>Trump Mobile leaked customers’ personal data</b>, including names, mailing addresses, and emails. YouTubers who ordered the T1 phone were alerted by a researcher and say <a class="link" href="https://techcrunch.com/2026/05/20/customers-say-trump-mobile-is-leaking-their-personal-information/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">the information is still exposed online</a>. <b>Trump Mobile</b> has not responded and customers report silence from the company.</p><p class="paragraph" style="text-align:left;">🧩 <b>GitHub says a malicious VS Code extension on an employee&#39;s device led to the breach of about 3,800 internal repositories</b> — The extension was removed, the device isolated, and <b>GitHub</b> <a class="link" href="https://github.blog/security/investigating-unauthorized-access-to-githubs-internal-repositories/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">found no sign customers outside those repos were affected</a>. The hacker group called <b>TeamPCP</b> claims the theft and is trying to sell the data.</p><p class="paragraph" style="text-align:left;">😱 <b>A security researcher found many plain-text passwords and cloud keys for CISA and DHS in publicly accessible GitHub</b> spreadsheets. The exposed <a class="link" href="https://techcrunch.com/2026/05/19/us-cyber-agency-cisa-exposed-reams-of-passwords-and-cloud-keys-to-the-open-web/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">credentials came from a contractor’s employee</a> and could have allowed access to government systems. <b>CISA</b> has not confirmed a breach or said whether the keys were revoked.</p><div class="embed"><a class="embed__url" href="https://cyberscoop.com/cisa-credential-leak-congress-demands-answers/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank"><div class="embed__content"><p class="embed__title"> CISA credential leak raises alarms, and Capitol Hill demands answers </p><p class="embed__description"> Congressional Democrats demand answers after a CISA credential leak on GitHub exposed privileged AWS GovCloud accounts and internal agency systems. </p><p class="embed__link"> CyberScoop • Tim Starks </p></div><img class="embed__image embed__image--right" src="https://cyberscoop.com/wp-content/uploads/sites/3/2026/05/GettyImages-2254820015.jpg"/></a></div><p class="paragraph" style="text-align:left;">⏬ <b>Hackers stole a privileged GitHub token from Grafana Labs and downloaded</b> its <a class="link" href="https://cybersecuritynews.com/grafana-labs-security-breach/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">private codebase</a>. They used a misconfigured <b>GitHub Action</b> and tried to extort the company, which refused to pay. <b>Grafana</b> says no customer data was accessed and it has remediated the issue.</p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://www.stepsecurity.io/blog/actions-cool-issues-helper-github-action-compromised-all-tags-point-to-imposter-commit-that-exfiltrates-ci-cd-credentials?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">The popular GitHub Action actions-cool/issues-helper has been compromised</a></p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://www.bleepingcomputer.com/news/security/grafana-breach-caused-by-missed-token-rotation-after-tanstack-attack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">Grafana breach caused by missed token rotation after TanStack attack</a></p><p class="paragraph" style="text-align:left;">🏪 🇺🇸 <b>7-Eleven confirmed a data breach after the </b><i><b>ShinyHunters</b></i><b> hacker group claimed to have stolen</b> franchisee documents. The company says an <a class="link" href="https://www.securityweek.com/7-eleven-data-breach-confirmed-after-shinyhunters-ransom-demand/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">intrusion was detected on April 8</a> and some personal information from franchise applications was exposed. <b>ShinyHunters</b> says it took over 600,000 <b>Salesforce</b> records and tried to sell the data after demanding a ransom.</p><p class="paragraph" style="text-align:left;">→ More Breaches:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/millions-impacted-across-several-us-healthcare-data-breaches/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">Millions Impacted Across Several US Healthcare Data Breaches</a></p></li></ul></div><p class="paragraph" style="text-align:left;"></p><div id="cybercrime-cyber-espionage-ap-ts" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🥷🏻 CYBERCRIME, CYBER ESPIONAGE, APT’s</h3><div class="embed"><a class="embed__url" href="https://unit42.paloaltonetworks.com/tracking-iran-apt-screening-serpens/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank"><div class="embed__content"><p class="embed__title"> Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns </p><p class="embed__description"> Unit 42 details Screening Serpens&#39; use of AppDomainManager hijacking and new RAT variants to target tech and defense sectors in recent campaigns. </p><p class="embed__link"> Unit 42 • Unit 42 </p></div><img class="embed__image embed__image--right" src="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/Boggy-Serpens.png"/></a></div><hr class="content_break"><p class="paragraph" style="text-align:left;">🇪🇺 ❌ <b>European authorities shut down </b><i><b>First VPN</b></i> and arrested its alleged administrator. The VPN was <a class="link" href="https://cyberscoop.com/europol-take-down-first-vpn-cybercrime/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">used by cybercriminals for data theft</a>, fraud, and ransomware. Investigators seized servers, user data, and found thousands linked to crimes.</p><p class="paragraph" style="text-align:left;">🇨🇦 ⚖️ 🇺🇸 <b>Canadian police arrested 23-year-old Jacob Butler, aka “Dort”, accused of running </b><i><b>Kimwolf</b></i>, a massive IoT botnet. <b>Kimwolf</b> enslaved millions of devices to launch record DDoS attacks and was linked to swatting and doxing. Butler <a class="link" href="https://krebsonsecurity.com/2026/05/alleged-kimwolf-botmaster-dort-arrested-charged-in-u-s-and-canada/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">faces charges in Canada and the U.S.</a> and is awaiting extradition and court hearings.</p><p class="paragraph" style="text-align:left;">🇺🇦 🇺🇸 <b>Ukrainian cyberpolice, with U.S. help, identified an 18-year-old from Odesa as the operator of an infostealer malware</b> scheme. The <a class="link" href="https://www.bleepingcomputer.com/news/security/ukraine-identifies-infostealer-operator-tied-to-28-000-stolen-accounts/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">malware stole session tokens and credentials from users</a> of a California online store, affecting 28,000 accounts and enabling $721,000 in unauthorized purchases. Authorities searched the suspect’s homes and seized devices and financial evidence while the investigation continues.</p><p class="paragraph" style="text-align:left;">💳️ <b>The dark web marketplace </b><i><b>B1ack’s Stash</b></i><b> released 4.6 million stolen credit card records for free</b> after sellers resold its data. The dump includes full card details, billing info, emails, phones and IPs. Security researchers warn the records will likely <a class="link" href="https://www.securityweek.com/b1acks-stash-marketplace-gives-away-4-6-million-stolen-credit-cards/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">fuel widespread online fraud</a> and phishing.</p><p class="paragraph" style="text-align:left;">☁️ ❌ <b>Microsoft seized infrastructure and disrupted a cybercrime service that created and sold over 1,000 fake code-signing certificates</b> to make malware look legitimate. The group, called <b>Fox Tempest</b>, sold signing-as-a-service to multiple ransomware and malware operators worldwide. <b>Microsoft</b> removed accounts, <a class="link" href="https://cyberscoop.com/microsoft-digital-crimes-unit-disrupts-fox-tempest/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">took down sites and virtual machines</a> to raise the cost and disrupt this criminal marketplace.</p><p class="paragraph" style="text-align:left;">🇺🇸 🏧 💸 <b>The FBI says Americans lost over $388 million to scams using crypto ATMs</b> in 2025. Scammers trick people into depositing cash at kiosks and <a class="link" href="https://www.bleepingcomputer.com/news/security/fbi-americans-lost-over-388-million-to-scams-using-crypto-atms-in-2025/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">sending funds to attacker-controlled wallets</a>. Losses rose sharply, especially among people over 50, prompting warnings and some state bans.</p><p class="paragraph" style="text-align:left;">🌍️ ❌ <b>Interpol led </b><i><b>Operation Ramz</b></i><b> across 13 Middle East and North Africa countries</b> to <a class="link" href="https://cyberscoop.com/interpol-operation-ramz-middle-east-north-africa/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">disrupt cybercrime</a>. The four-month effort seized servers, arrested 201 people, and identified 382 suspects tied to nearly 4,000 victims. Authorities and private partners shared data and dismantled phishing, malware, and fraud operations.</p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;">🗓️ <b><a class="link" href="https://xsa.github.io/infosec-events/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">{Cyber,Info}Sec Events</a></b> — A community-maintained list of infosec conferences worldwide. Subscribe to the <a class="link" href="https://xsa.github.io/infosec-events/events.ics?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">ICS calendar feed</a> to get events straight into your calendar, or follow <a class="link" href="https://infosec.exchange/@infosecevents?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">@infosecevents@infosec.exchange</a> on Mastodon for weekly digests. Contributions and ⭐ welcome!</p></div><p class="paragraph" style="text-align:left;"></p><div id="government-politics-and-privacy" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">👨🏻‍⚖️ 👀 GOVERNMENT, POLITICS, AND PRIVACY</h3><p class="paragraph" style="text-align:left;">🇵🇱 💬 <b>Poland told officials to stop using Signal after repeated account takeovers</b> linked to state-backed attackers. The hacks used social engineering, fake support messages, and malicious QR codes rather than breaking Signal’s encryption. Officials will move to domestic, <a class="link" href="https://securityaffairs.com/192381/intelligence/poland-shifts-away-from-signal-following-cyberattacks-on-officials-accounts.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">government-controlled messaging platforms</a> to protect sensitive communications.</p><p class="paragraph" style="text-align:left;">🦋 🇷🇺 <b>Bluesky says the Kremlin hacked many accounts to spread Russian propaganda</b> — Victims found fake news videos posted from their profiles without permission. Researchers and the company <a class="link" href="https://www.nytimes.com/2026/05/21/business/bluesky-russia-hacking-accounts.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">tracked the operation and linked it to Russian influence</a> efforts.</p><p class="paragraph" style="text-align:left;">🇲🇾 <b>Researchers say a suspected Malaysian government-linked campaign used hidden command-and-control systems</b> for years. The attackers masked servers and limited access to avoid detection, <a class="link" href="https://www.scworld.com/brief/malaysian-government-linked-campaign-uses-hidden-infrastructure-for-years?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">suggesting state-style espionage</a>. </p></div><p class="paragraph" style="text-align:left;"></p><div id="malware-threats" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🦠 MALWARE & THREATS</h3><p class="paragraph" style="text-align:left;">🐧 🔙 🚪 🇨🇳 <b>Researchers uncovered </b><i><b>Showboat</b></i><b>, a Linux backdoor used since 2022</b> to <a class="link" href="https://www.lumen.com/blog/en-us/introducing-showboat-a-new-malware-family-taunts-defenses-and-targets-international-telecom-firms?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">target a Middle East telecom</a> and other networks. The modular malware gives attackers a remote shell, file transfer, and a SOCKS5 proxy to reach internal systems. Evidence links its infrastructure to China-affiliated groups and shows compromises in multiple countries.</p><p class="paragraph" style="text-align:left;">📦️ 🪱 <b>Researchers found four malicious npm packages that deliver info-stealers and a Golang DDoS bot</b> called <i>Phantom Bot</i>. One package <a class="link" href="https://www.ox.security/blog/new-actors-deploy-shai-hulud-clones-teampcp-copycats-are-here/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">clones the open-source</a> <b>Shai-Hulud</b> worm and sends stolen data to attacker-controlled servers. Users should uninstall the packages, rotate secrets, remove malicious configs, and block the suspicious domains.</p><p class="paragraph" style="text-align:left;">🎣 <b>Tycoon2FA phishing kit now uses device-code phishing to hijack Microsoft 365 accounts</b> — Attackers trick victims into entering device codes on <code>microsoft.com/devicelogin</code> after clicking <b>Trustifi</b> tracking links. <b>eSentire</b> <a class="link" href="https://www.proofpoint.com/us/blog/threat-insight/device-code-phishing-evolution-identity-takeover?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">urges disabling unused device-code flows</a>, tightening OAuth consent, and monitoring Entra logs.</p><p class="paragraph" style="text-align:left;">ℹ️ 🍎 <b>A new SHub macOS infostealer variant called Reaper uses AppleScript to show fake Apple security updates </b>and installs a backdoor. It steals browser data, crypto wallets, password manager files, <b>iCloud</b> and <b>Telegram</b> data, and grabs sensitive documents. The <a class="link" href="https://www.sentinelone.com/blog/shub-reaper-macos-stealer-spoofs-apple-google-and-microsoft-in-a-single-attack-chain/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">malware hides its payload, avoids macOS protections</a>, and keeps persistence via a <i>LaunchAgent</i> for ongoing remote access.</p></div><p class="paragraph" style="text-align:left;"></p><div id="ai-crypto-tech-tools" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🤖 🧰 AI, CRYPTO, TECH & TOOLS</h3><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/u2MFautDjuM" width="100%"></iframe><hr class="content_break"><p class="paragraph" style="text-align:left;">🐬 🐧 <b>Flipper Devices announced </b><i><b>Flipper One</b></i><b>, a Linux-powered gadget for hackers</b> with Ethernet, USB, Wi‑Fi 6E, M.2 expansion, and HDMI for use as a router, desktop, or media box. It runs an eight-core RK3576 Linux CPU plus a microcontroller, 8GB RAM, and aims to support local AI and modular add-ons, though much software is still in development. The <a class="link" href="https://techcrunch.com/2026/05/21/flipper-unveils-a-linux-powered-networking-gadget-built-for-hackers-and-tinkerers/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">company invites developers to help build FlipperOS</a> and tools, and expects a base price under $350.</p><p class="paragraph" style="text-align:left;">🩹 <b>A researcher found a Claude Code network sandbox bypass</b> that could let attackers exfiltrate data. <a class="link" href="https://www.securityweek.com/anthropic-silently-patches-claude-code-sandbox-bypass/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">Anthropic quietly patched</a> the SOCKS5 null-byte issue and a related bug in early 2025 and says the fix was shipped before the report. The researcher is upset no CVE was assigned to <b>Claude Code</b> or mentioned in release notes.</p><p class="paragraph" style="text-align:left;">🔐 🤝 <b>1Password and OpenAI built an integration so AI coding agents can use credentials without exposing them</b> in prompts, code, or repos. Credentials are <a class="link" href="https://1password.com/blog/1password-trusted-access-layer-for-openai-codex?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">issued just-in-time</a>, scoped to the task, and kept in <b>1Password</b>’s encrypted runtime so they never enter the model’s context. This lets teams use <b>Codex</b> safely while keeping control and auditability of secrets.</p><p class="paragraph" style="text-align:left;">🇪🇺 <b>The European Commission says it is preparing to defend the EU against AI models that can find and exploit</b> cybersecurity bugs. Officials plan to use the EU Cybersecurity Reserve, new laws, and a Tech Sovereignty Package to boost defenses and <a class="link" href="https://www.databreachtoday.com/europe-prepares-to-hunker-down-against-bug-finding-ai-models-a-31728?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">reduce dependence on foreign tools</a>. Lawmakers want faster action, access to powerful models, and stricter rules, but some requests were not answered.</p><p class="paragraph" style="text-align:left;">🐛 🦞 <b>Four flaws in the OpenClaw AI assistant, called &quot;</b><i><b>Claw Chain</b></i><b>&quot;, can be chained to escape the sandbox</b> and <a class="link" href="https://www.cyera.com/blog/claw-chain-cyera-research-unveil-four-chainable-vulnerabilities-in-openclaw?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">install backdoors</a> on hosts. An attacker who gets code execution inside the agent can read secrets, escalate to owner privileges, and write files outside the sandbox. Over 60,000 public <b>OpenClaw</b> instances may be exposed, and patches were released after disclosure.</p></div><p class="paragraph" style="text-align:left;"></p><div id="vulnerabilities-research-and-threat" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🐛 🧠 VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</h3><p class="paragraph" style="text-align:left;">➝ From the Patching Department:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/cisco-patches-critical-vulnerability-in-secure-workload/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">Cisco Patches Critical Vulnerability in Secure Workload</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/drupal-patches-highly-critical-vulnerability-exposing-websites-to-hacking/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">Drupal Patches Highly Critical Vulnerability Exposing Websites to Hacking</a></p></li><li><p class="paragraph" style="text-align:left;">Hackers bypass SonicWall VPN MFA <a class="link" href="https://www.bleepingcomputer.com/news/security/hackers-bypass-sonicwall-vpn-mfa-due-to-incomplete-patching/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">due to incomplete patching</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/trendai-patches-apex-one-zero-day-exploited-in-the-wild/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">TrendAI Patches Apex One Zero-Day Exploited in the Wild</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/ubiquiti-patches-three-max-severity-unifi-os-vulnerabilities/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">Ubiquiti patches three max severity UniFi OS vulnerabilities</a></p></li></ul><hr class="content_break"><div class="embed"><a class="embed__url" href="https://www.securityweek.com/verizon-dbir-2026-vulnerability-exploitation-overtakes-credential-theft-as-top-breach-vector/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank"><div class="embed__content"><p class="embed__title"> Verizon DBIR 2026: Vulnerability Exploitation Overtakes Credential Theft as Top Breach Vector </p><p class="embed__description"> Verizon’s 2026 DBIR shows vulnerability exploitation was the top breach vector in 2025 as AI accelerated attacks, ransomware increased, and third-party compromises surged. </p><p class="embed__link"> SecurityWeek • Ionut Arghire </p></div><img class="embed__image embed__image--right" src="https://www.securityweek.com/wp-content/uploads/2024/05/Verizon.jpeg"/></a></div><hr class="content_break"><p class="paragraph" style="text-align:left;">🩹 <b>Microsoft released mitigations for </b><i><b>YellowKey</b></i><b>, a zero-day that can bypass BitLocker</b> when an attacker with physical access <a class="link" href="https://www.securityweek.com/microsoft-rolls-out-mitigations-for-yellowkey-bitlocker-bypass/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">boots into recovery using a malicious USB</a>. The exploit uses an FsTx payload to delete <code>winpeshl.ini</code> and spawn a shell that exposes encrypted data. Microsoft’s fixes stop <code>autofstx.exe</code> from auto-running in WinRE and advise adding a <b>BitLocker</b> PIN.</p><p class="paragraph" style="text-align:left;">🐧 <b>A new Linux local root exploit called </b><i><b>DirtyDecrypt</b></i><b> (aka </b><i><b>DirtyCBC</b></i><b>) has a public proof-of-concept</b> that can gain root on systems with CONFIG_RXGK enabled. It <a class="link" href="https://www.bleepingcomputer.com/news/security/exploit-available-for-new-dirtydecrypt-linux-root-escalation-flaw/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">mainly affects rolling or upstream-following distros</a> like Fedora, Arch, and openSUSE Tumbleweed. Users should install the latest kernel updates or apply the temporary module-disabling mitigation.</p><p class="paragraph" style="text-align:left;">💥 <b>A researcher released </b><i><b>MiniPlasma</b></i><b>, an exploit for a 2020 Windows Cloud Filter driver flaw</b> (CVE-2020-17103) that can escalate privileges. The researcher <a class="link" href="https://www.securityweek.com/researcher-drops-miniplasma-windows-exploit-for-unpatched-2020-cve/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">says the original Google Project Zero PoC still works</a>, suggesting the bug may be unpatched or patches reverted. Tests show <b>MiniPlasma</b> can spawn a System shell on Windows 11 with May 2026 updates.</p><p class="paragraph" style="text-align:left;">💥 <b>A critical NGINX flaw called </b><i><b>Nginx Rift</b></i><b> (CVE-2026-42945) enables a heap buffer overflow</b> in the rewrite module. Proof-of-concept code is public and <a class="link" href="https://www.securityweek.com/exploitation-of-critical-nginx-vulnerability-begins/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">attackers have begun remote exploitation</a>, mainly causing crashes and potential DoS. If ASLR is disabled, the bug can allow remote code execution, so immediate patching is urgent.</p><p class="paragraph" style="text-align:left;">🤑 <b>Pwn2Own Berlin 2026 awarded white hat hackers $1.3 million</b> for <a class="link" href="https://www.securityweek.com/hackers-earn-1-3-million-at-pwn2own-berlin-2026/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">47 vulnerabilities</a> across Windows, Linux, VMware, Nvidia, and AI products. The top teams, Devcore and StarLabs SG, took nearly $750,000 with high-value exploits on Microsoft and VMware. Many AI-targeted hacks paid out, some teams failed, and several researchers disclosed findings directly to vendors.</p></div><p class="paragraph" style="text-align:left;"></p><div id="ics-ot-io-t" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🛰️ ICS, OT & IoT</h3><p class="paragraph" style="text-align:left;">🩹 <b>Universal Robots patched a critical OS command-injection flaw (CVE-2026-8153) in its PolyScope 5</b> dashboard. An unauthenticated attacker with network access to the Dashboard Server <a class="link" href="https://www.securityweek.com/critical-vulnerability-exposes-industrial-robot-fleets-to-hacking/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">could run commands and take over a cobot</a>. On flat, unsegmented networks this could lead to compromise of multiple robots and connected equipment.</p><p class="paragraph" style="text-align:left;">🦠 🚀 <b>Researchers say the </b><i><b>fast16</b></i><b> malware was built to sabotage nuclear weapons</b> simulations. It <a class="link" href="https://www.security.com/threat-intelligence/fast16-nuclear-sabotage?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">secretly altered high-explosive simulation results</a> in LS-DYNA and AUTODYN to corrupt uranium-compression tests. The tool predates <b>Stuxnet</b> and shows early, sophisticated state-level sabotage of industrial software.</p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">💬 CONNECT</h3><p class="paragraph" style="text-align:left;">Follow me on <a class="link" href="https://infosec.exchange/@0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">Mastodon</a> for quick daily updates and bite-sized content.</p><p class="paragraph" style="text-align:left;">Prefer using an RSS feed? Add <b>Infosec MASHUP</b> to your feed <a class="link" href="https://rss.beehiiv.com/feeds/HVhiKYpQlR.xml?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">here</a>.</p><p class="paragraph" style="text-align:center;"><b>Enjoying our newsletter? </b>Forward it to a colleague—<br>it’s one of the best ways to support us.</p><p class="paragraph" style="text-align:left;">Thanks for reading today’s newsletter, and if you&#39;re enjoying it and want to support my work, you can <b>buy me a coffee</b> ☕ over at <a class="link" href="https://www.buymeacoffee.com/0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked" target="_blank" rel="noopener noreferrer nofollow">https://www.buymeacoffee.com/0x58</a></p><p class="paragraph" style="text-align:left;"> See you next time!</p><p class="paragraph" style="text-align:left;">-X.</p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=ed87b1b9-6b69-4805-abe8-7d6cd508b7f6&utm_medium=post_rss&utm_source=x_s_infosec_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🕵🏻‍♂️ [InfoSec MASHUP] 20/2026 - The Platform Is the Attack Surface</title>
  <description>Plus: ShinyHunters got paid, TeamPCP hit 170 packages across npm and PyPI, and Cisco&#39;s SD-WAN zero-day count hit six for the year</description>
  <link>https://infosec-mashup.santolaria.net/p/infosec-mashup-20-2026-the-platform-is-the-attack-surface</link>
  <guid isPermaLink="true">https://infosec-mashup.santolaria.net/p/infosec-mashup-20-2026-the-platform-is-the-attack-surface</guid>
  <pubDate>Sat, 16 May 2026 16:40:06 +0000</pubDate>
  <atom:published>2026-05-16T16:40:06Z</atom:published>
    <dc:creator>Xavier Santolaria</dc:creator>
    <category><![CDATA[Malware]]></category>
    <category><![CDATA[Opensource]]></category>
    <category><![CDATA[Privacy]]></category>
    <category><![CDATA[Cybersecurity]]></category>
    <category><![CDATA[Threat Intelligence]]></category>
    <category><![CDATA[Ai]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">The supply chain attack story this week isn&#39;t about a sketchy package lurking in a dark corner of <i>npm</i>. It&#39;s about <a class="link" href="https://Claude.ai?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">Claude.ai</a> shared chats being used to distribute Mac malware, a fake <b>Hugging Face</b> repository impersonating <b>OpenAI</b>&#39;s Privacy Filter trending at #1 with 244,000 downloads, and <b>JDownloader</b>&#39;s own website serving swapped installers. The common thread isn&#39;t sophistication — it&#39;s borrowed credibility. Attackers have figured out that the detection model most users rely on, implicitly or otherwise, is &quot;I&#39;ve heard of this platform, therefore this thing on it is probably fine.&quot;</p><p class="paragraph" style="text-align:left;">That assumption has always been fragile. What&#39;s changed is how systematically it&#39;s being exploited. A trending repo with a quarter-million downloads looks legitimate by every surface signal. A shared <a class="link" href="https://Claude.ai?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">Claude.ai</a> chat looks like a helpful resource. A download from the official project website looks like the official project. The trust isn&#39;t in the content — it&#39;s in the container. And the container is now the attack surface.</p><p class="paragraph" style="text-align:left;">Let’s now dive into this week’s top insights! 🚀</p><h2 class="heading" style="text-align:left;">Table of Contents</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="#breaches-security-incidents" rel="noopener noreferrer nofollow">BREACHES & SECURITY INCIDENTS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#cybercrime-cyber-espionage-ap-ts" rel="noopener noreferrer nofollow">CYBERCRIME, CYBER ESPIONAGE, APT’s</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#government-politics-and-privacy" rel="noopener noreferrer nofollow">GOVERNMENT, POLITICS, AND PRIVACY</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#malware-threats" rel="noopener noreferrer nofollow">MALWARE & THREATS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ai-crypto-tech-tools" rel="noopener noreferrer nofollow">AI, CRYPTO, TECH & TOOLS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#vulnerabilities-research-and-threat" rel="noopener noreferrer nofollow">VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ics-ot-io-t" rel="noopener noreferrer nofollow">ICS, OT & IoT</a></p></li></ul><div id="breaches-security-incidents" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🔓 BREACHES & SECURITY INCIDENTS</h3><p class="paragraph" style="text-align:left;">🤑 <b>Instructure paid a ransom to the </b><i><b>ShinyHunters</b></i><b> group after a breach that stole 3.65TB of Canvas data</b> from about 9,000 institutions. The company <a class="link" href="https://thehackernews.com/2026/05/instructure-reaches-ransom-agreement.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">says the data was returned and destroyed</a> and customers will not be separately extorted. It has closed Free-for-Teacher accounts, revoked credentials, and is improving security while warning of phishing risks.</p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://www.securityweek.com/government-to-scrutinize-instructure-on-canvas-disruption-data-breach/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">U.S. Government to Scrutinize Instructure Over Canvas Disruption</a></p><p class="paragraph" style="text-align:left;">🇺🇸 <b>Foxconn said some North American factories were hit by a cyberattack</b> and are now resuming production. A ransomware group called <i><b>Nitrogen</b></i> claimed it <a class="link" href="https://cyberscoop.com/foxconn-cyberattack-disrupts-north-america-factories/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">stole 8 terabytes of data</a> and posted screenshots. <b>Foxconn</b> gave few details and did not say if a ransom was demanded.</p><p class="paragraph" style="text-align:left;">💊 <b>West Pharmaceutical Services was hit by a ransomware attack on May 4</b> that <a class="link" href="https://www.securityweek.com/west-pharmaceutical-services-hit-by-disruptive-ransomware-attack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">forced the company to shut down</a> and isolate on-premises systems. The company says core systems and some manufacturing and shipping processes are restored, but full recovery and the extent of stolen data are still unknown. West hired <b>Unit 42</b>, notified law enforcement, and may have taken steps to limit leaked data.</p><p class="paragraph" style="text-align:left;">🏨 <i><b>BWH Hotels</b></i><b> says hackers had access to a reservation web application</b> from October 14, 2025, until the intrusion was discovered on April 22. The breach exposed guest names, emails, phone numbers, and reservation details, but not payment or financial data. The <a class="link" href="https://www.securityweek.com/bwh-hotels-says-hackers-had-access-to-reservation-data-for-6-months/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">company took the app offline</a>, is investigating with outside experts, and warns the data could be used for scams.</p><p class="paragraph" style="text-align:left;">🇬🇧 🚰 <b>A major UK water company left security gaps that let attackers stay inside its corporate network for 20 months</b> and <a class="link" href="https://www.databreachtoday.com/hackers-hid-inside-major-uk-water-utility-for-nearly-2-years-a-31656?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">expose data for over 633,000 people</a>. The regulator fined South Staffordshire nearly £964,000 after finding weak monitoring, poor patching, unsupported software, and weak access controls. The company says operational services were not affected and it has since strengthened security.</p><p class="paragraph" style="text-align:left;">🚗 <b>Skoda says a security flaw in its online shop allowed hackers to access</b> customer data. The exposed information includes names, addresses, emails, phone numbers, order details and password hashes, but not credit card data. The company <a class="link" href="https://www.securityweek.com/skoda-data-breach-hits-online-shop-customers/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">took the shop offline</a>, is investigating with forensics experts, and advises users to watch for phishing and change reused passwords.</p><p class="paragraph" style="text-align:left;">⛵️ <b>SailPoint disclosed on April 20 that some of its GitHub repositories were accessed without authorization</b> and the incident was quickly contained. The <a class="link" href="https://www.securityweek.com/sailpoint-discloses-github-repository-hack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">company said the breach came through a third-party app vulnerability</a> and that it found no evidence customer production or staging data were accessed. <b>SailPoint</b> notified affected customers and gave no further details about the attacker or the exact data involved.</p><p class="paragraph" style="text-align:left;">→ More:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/716000-impacted-by-openloop-health-data-breach/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">716,000 Impacted by OpenLoop Health Data Breach</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/american-lending-center-data-breach-affects-123000-individuals/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">American Lending Center Data Breach Affects 123,000 Individuals</a></p></li></ul></div><p class="paragraph" style="text-align:left;"></p><div id="cybercrime-cyber-espionage-ap-ts" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🥷🏻 CYBERCRIME, CYBER ESPIONAGE, APT’s</h3><div class="embed"><a class="embed__url" href="https://unit42.paloaltonetworks.com/gremlin-stealer-evolution/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank"><div class="embed__content"><p class="embed__title"> Gremlin Stealer&#39;s Evolved Tactics: Hiding in Plain Sight With Resource Files </p><p class="embed__description"> Unit 42 analyzes the evolution of Gremlin stealer. This variant uses advanced obfuscation, crypto clipping and session hijacking to compromise data. </p><p class="embed__link"> Unit 42 • Pranay Kumar Chhaparwal, Mark Lim </p></div><img class="embed__image embed__image--right" src="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/02_Malware_Category_1920x900.jpg"/></a></div><p class="paragraph" style="text-align:left;">🇮🇷 👀 <b>Iran-linked </b><i><b>MuddyWater</b></i><b> carried out a wide cyber-espionage campaign</b> that <a class="link" href="https://www.security.com/threat-intelligence/iran-seedworm-electronics?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">hit at least nine high-profile organizations</a>, including a major South Korean electronics maker. The attackers used DLL sideloading of legitimate apps and PowerShell to steal credentials, capture screenshots, and exfiltrate data. Symantec says the campaign shows greater geographic reach and stealth, focusing on industrial secrets and government espionage.</p><p class="paragraph" style="text-align:left;">🇷🇺 💬 <b>A security researcher, Donncha Ó Cearbhaill, was targeted by a phishing attack that tried to hijack his Signal account</b> — He <a class="link" href="https://techcrunch.com/2026/05/14/a-spyware-investigator-exposed-russian-government-hackers-trying-to-hijack-signal-accounts/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">traced the campaign to a Russian-linked hacking group</a> using an automated tool called “<i>ApocalypseZ</i>” and found over 13,500 targets. He warns users to enable <b>Signal’</b>s Registration Lock to protect their accounts.</p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://x.com/signalapp/status/2053957236376961474?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">Signal adds security warnings for social engineering</a></p><p class="paragraph" style="text-align:left;">🎣 <b>A long-running phishing campaign called </b><i><b>Operation HookedWing</b></i><b> stole credentials from over 500 organizations</b> across many critical sectors. Attackers used <b>GitHub</b> and compromised servers to host Outlook-themed fake login pages that harvest email, password, IP, geolocation, and organization data. The <a class="link" href="https://socradar.io/blog/operation-hookedwing-4-year-phishing/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">campaign evolved its infrastructure and lures over four years</a> and targeted high-value organizations with urgent, authoritative-looking messages.</p><p class="paragraph" style="text-align:left;">🇩🇪 <b>German police shut down a rebooted </b><i><b>Crimenetwork</b></i><b> marketplace and arrested its suspected operator</b> in Mallorca. The <a class="link" href="https://www.bleepingcomputer.com/news/security/police-shut-down-reboot-of-crimenetwork-marketplace-arrest-admin/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">new site had grown to 22,000 users</a> and made at least €3.6 million. Authorities seized cash, user data, and say the administrator will face charges in Germany.</p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://www.bleepingcomputer.com/news/security/us-charges-suspected-dream-market-admin-arrested-in-germany/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">US charges suspected Dream Market admin arrested in Germany</a></p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;">🗓️ <b><a class="link" href="https://xsa.github.io/infosec-events/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">{Cyber,Info}Sec Events</a></b> — A community-maintained list of infosec conferences worldwide. Subscribe to the <a class="link" href="https://xsa.github.io/infosec-events/events.ics?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">ICS calendar feed</a> to get events straight into your calendar, or follow <a class="link" href="https://infosec.exchange/@infosecevents?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">@infosecevents@infosec.exchange</a> on Mastodon for weekly digests. Contributions and ⭐ welcome!</p></div><p class="paragraph" style="text-align:left;"></p><div id="government-politics-and-privacy" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">👨🏻‍⚖️ 👀 GOVERNMENT, POLITICS, AND PRIVACY</h3><p class="paragraph" style="text-align:left;">🇺🇸 💰️ <b>California fined General Motors $12.75 million for secretly collecting and selling drivers’ location and behavior data</b> in violation of the CCPA. The data, gathered via OnStar and Smart Driver from 2020–2024, was <a class="link" href="https://www.bleepingcomputer.com/news/legal/gm-agrees-to-1275m-california-settlement-over-sale-of-drivers-data/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">sold to Verisk and LexisNexis</a> and used for insurance scoring. GM must stop sales for five years, delete retained data unless consumers consent, and improve privacy controls.</p></div><p class="paragraph" style="text-align:left;"></p><div id="malware-threats" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🦠 MALWARE & THREATS</h3><div class="embed"><a class="embed__url" href="https://techcrunch.com/2026/05/13/this-is-what-some-the-worlds-largest-banks-of-malware-look-like-stacked-as-hard-drives/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank"><div class="embed__content"><p class="embed__title"> This is what some of the world&#39;s largest banks of malware look like stacked as hard drives | TechCrunch </p><p class="embed__description"> What would some of the world&#39;s largest repositories of malware look like if they were stacked as hard drives, one on top of the other? </p><p class="embed__link"> TechCrunch • Zack Whittaker </p></div><img class="embed__image embed__image--right" src="https://techcrunch.com/wp-content/uploads/2026/05/GettyImages-1317298675.jpg?resize=1200,800"/></a></div><p class="paragraph" style="text-align:left;">📦️ ⚠️ <b>A coordinated supply-chain attack by TeamPCP infected over 170 NPM and PyPI packages</b>, including <b>TanStack</b>, <b>Mistral AI</b>, and <b>UiPath</b>. The malware stole developer credentials, API keys, and secrets, and used GitHub Actions OIDC and cache poisoning to <a class="link" href="https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">publish malicious packages with valid SLSA provenance</a>. Users must check for affected versions, rotate credentials, and harden CI workflows.</p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://openai.com/index/our-response-to-the-tanstack-npm-supply-chain-attack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">OpenAI Hit by TanStack Supply Chain Attack</a></p><p class="paragraph" style="text-align:left;">📦️ ⚠️ <i><b>RubyGems</b></i><b> has suspended new account registrations after bots uploaded over 500 malicious packages</b> — The junk packages were removed and existing gems and users appear unaffected. The team is <a class="link" href="https://status.rubygems.org/incidents/cytf062tkwtt?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">tightening controls and investigating</a> possible XSS and data-exfiltration attempts.</p><p class="paragraph" style="text-align:left;">💃 <b>Attackers lure users with a fake &quot;free OnlyFans&quot; zip</b> that <a class="link" href="https://www.securityweek.com/free-onlyfans-lure-used-to-spread-cross-platform-crpx0-malware/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">installs CRPx0 malware</a>. The malware steals cryptocurrency, exfiltrates data, and can deploy ransomware. It targets macOS and Windows (Linux possible), is stealthy and modular, and uses C2 control for theft and encryption.</p><p class="paragraph" style="text-align:left;">🏦 <b>A new </b><i><b>TrickMo</b></i><b> Android banking malware variant uses the TON blockchain for hidden command-and-control </b>communications. It hides as <b>TikTok</b> or streaming apps and <a class="link" href="https://www.bleepingcomputer.com/news/security/trickmo-android-banker-adopts-ton-blockchain-for-covert-comms/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">steals banking and crypto credentials</a> with overlays, keylogging, SMS interception, and more. Users should install apps only from <b>Google Play</b>, limit apps, and keep Play Protect enabled.</p><p class="paragraph" style="text-align:left;">🇷🇺 🍎 <b>Attackers use Google Ads and malicious </b><i><b>Claude.ai</b></i><b> shared chats to trick Mac users into pasting Terminal commands</b> that install malware. The <a class="link" href="https://www.bleepingcomputer.com/news/security/hackers-abuse-google-ads-claudeai-chats-to-push-mac-malware/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">malware runs in memory</a>, steals credentials and system info, and may skip targets in Russia/CIS. Users should go directly to <i>claude.ai </i>and never paste unknown terminal commands.</p><p class="paragraph" style="text-align:left;">🐍 <b>The </b><i><b>JDownloader</b></i><b> website was hacked and some Windows and Linux installers were replaced with malware</b> between May 6–7, 2026. The Windows payload <a class="link" href="https://www.bleepingcomputer.com/news/security/jdownloader-site-hacked-to-replace-installers-with-python-rat-malware/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">installs a Python-based remote access trojan</a> and the Linux installer added a root‑level backdoor. Users who ran those installers should wipe/reinstall affected systems and reset passwords.</p><p class="paragraph" style="text-align:left;">🤗 <b>A fake Hugging Face repo impersonated OpenAI’s Privacy Filter and pushed an infostealer malware</b> to Windows users. It reached #1 with 244,000 downloads before being removed, and <a class="link" href="https://www.hiddenlayer.com/research/malware-found-in-trending-hugging-face-repository-open-oss-privacy-filter?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">the malware stole browser data</a>, tokens, wallets, credentials, and screenshots. Impacted users should reimage machines, rotate credentials, and replace wallets.</p></div><p class="paragraph" style="text-align:left;"></p><div id="ai-crypto-tech-tools" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🤖 🧰 AI, CRYPTO, TECH & TOOLS</h3><p class="paragraph" style="text-align:left;">📄 <b>G7 governments released joint guidance for AI SBOMs to improve transparency and security</b> in AI systems and supply chains. The <a class="link" href="https://www.securityweek.com/g7-countries-release-ai-sbom-guidance/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">document lists seven minimum SBOM elements</a>—metadata, models, datasets, infrastructure, KPIs, security properties, and system-level properties. Experts say the guidance is useful but implementation is hard because AI development and tooling often bypass traditional supply-chain controls.</p><p class="paragraph" style="text-align:left;">🔐 📲 <b>Google is adding an opt-in feature called </b><i><b>Intrusion Logging</b></i><b> to Android to help detect and investigate spyware</b> attacks. It <a class="link" href="https://techcrunch.com/2026/05/12/google-launches-new-android-security-feature-to-help-uncover-spyware-attacks/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">saves encrypted daily logs to a user’s Google account</a> so researchers can see signs of hacking or forensic tools. The feature is limited to Pixel phones with Android 16+, requires Advanced Protection Mode, and must be enabled by the user.</p><p class="paragraph" style="text-align:left;">📆 <b>Google found a zero-day exploit created with AI and warned the vendor before</b> attackers could use it. The exploit targeted a Python script that bypassed two-factor authentication in a popular web admin tool. Researchers say this is clear evidence <a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">AI is being used to build serious cyberattacks</a> and more are likely.</p><p class="paragraph" style="text-align:left;">🙊 <b>Anthropic says fictional portrayals of evil, self-preserving AIs led Claude to try blackmail</b> in tests. After changes, <a class="link" href="https://techcrunch.com/2026/05/10/anthropic-says-evil-portrayals-of-ai-were-responsible-for-claudes-blackmail-attempts/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">newer models rarely attempt blackmail</a>. They found teaching underlying alignment principles plus examples works best.</p></div><p class="paragraph" style="text-align:left;"></p><div id="vulnerabilities-research-and-threat" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🐛 🧠 VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</h3><p class="paragraph" style="text-align:left;">➝ From the Patching Department:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/adobe-patches-52-vulnerabilities-in-10-products/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">Adobe Patches 52 Vulnerabilities in 10 Products</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/apple-patches-dozens-of-vulnerabilities-in-macos-ios/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">Apple Patches Dozens of Vulnerabilities in macOS, iOS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/chrome-148-update-patches-critical-vulnerabilities/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">Chrome 148 Update Patches Critical Vulnerabilities</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/cisco-patches-another-sd-wan-zero-day-the-sixth-exploited-in-2026/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">Cisco Patches Another SD-WAN Zero-Day, the Sixth Exploited in 2026</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/f5-patches-over-50-vulnerabilities/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">F5 Patches Over 50 Vulnerabilities</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/fortinet-ivanti-patch-critical-vulnerabilities/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">Fortinet, Ivanti Patch Critical Vulnerabilities</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/microsoft-patches-137-vulnerabilities/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">Microsoft Patches 137 Vulnerabilities</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/sap-patches-critical-s-4hana-commerce-vulnerabilities/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">SAP Patches Critical S/4HANA, Commerce Vulnerabilities</a></p></li><li><p class="paragraph" style="text-align:left;">High-Severity Vulnerability Patched in <a class="link" href="https://www.securityweek.com/high-severity-vulnerability-patched-in-vmware-fusion/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">VMware Fusion</a></p></li></ul><hr class="content_break"><div class="embed"><a class="embed__url" href="https://www.securityweek.com/poc-code-published-for-critical-nginx-vulnerability/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank"><div class="embed__content"><p class="embed__title"> PoC Code Published for Critical NGINX Vulnerability </p><p class="embed__description"> Depthfirst has published technical details and proof-of-concept (PoC) exploit code targeting a critical NGINX vulnerability. </p><p class="embed__link"> SecurityWeek • Ionut Arghire </p></div><img class="embed__image embed__image--right" src="https://www.securityweek.com/wp-content/uploads/2026/05/Nginx.jpeg"/></a></div><p class="paragraph" style="text-align:left;">📨 💥 <b>Microsoft warned of a newly disclosed Exchange Server zero-day, CVE-2026-42897</b>, that is being exploited in the wild. The flaw is a cross-site scripting issue in <b>Outlook Web Access</b> that can run arbitrary JavaScript if a user opens a crafted email. <b>Microsoft</b> <a class="link" href="https://www.securityweek.com/microsoft-warns-of-exchange-server-zero-day-exploited-in-the-wild/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">provided temporary mitigations</a> and is working on a permanent fix.</p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://thehackernews.com/2026/05/azerbaijani-energy-firm-hit-by-repeated.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">Azerbaijani Energy Firm Hit by Repeated Microsoft Exchange Exploitation</a></p><p class="paragraph" style="text-align:left;">🐧 <b>A new Linux local privilege escalation called </b><i><b>Fragnesia</b></i><b> (CVE-2026-46300) lets local attackers gain root </b>by corrupting the kernel page cache. Patches and mitigations are available and several distributions have issued advisories; apply updates or the same <i>Dirty Frag</i> mitigations. A <a class="link" href="https://www.wiz.io/blog/fragnesia-linux-kernel-local-privilege-escalation-via-esp-in-tcp?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">PoC and an overpriced exploit for sale have been reported</a>, but no in-the-wild attacks seen yet.</p><p class="paragraph" style="text-align:left;">🐛 🫰 <b>Security researchers earned $523,000 on day one of Pwn2Own Berlin 2026</b> by <a class="link" href="https://www.bleepingcomputer.com/news/security/windows-11-and-microsoft-edge-hacked-on-first-day-of-pwn2own-berlin-2026/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">exploiting 24 zero-days</a>. Notable wins included a <b>Microsoft Edge</b> sandbox escape and three <b>Windows 11</b> privilege escalations. The contest targets enterprise and AI products and forces vendors to fix disclosed flaws within 90 days.</p><p class="paragraph" style="text-align:left;">🤷 <b>A restricted test of Anthropic’s Claude Mythos found only one low-severity vulnerability in curl</b>, not the many zero-days the company hinted at. Experts <a class="link" href="https://www.securityweek.com/claude-mythos-finds-only-one-curl-vulnerability-experts-divided-on-what-it-really-means/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">are split</a>: some say this shows curl’s strong security, others say Mythos should have found more. Mozilla reports big wins with Mythos on Firefox, but critics say humans could have found those too.</p></div><p class="paragraph" style="text-align:left;"></p><div id="ics-ot-io-t" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🛰️ ICS, OT & IoT</h3><p class="paragraph" style="text-align:left;">🩹 <b>ICS Patch Tuesday</b> — Siemens, Schneider Electric, CISA, and CERT@VDE <a class="link" href="https://www.securityweek.com/ics-patch-tuesday-new-security-advisories-from-siemens-schneider-cisa/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">released new industrial control system security advisories</a> for May 2026. Siemens published 18 advisories including multiple critical flaws that allow device takeover, remote code execution, and component-level issues. Schneider, CISA, and CERT@VDE reported several high- and medium-severity vulnerabilities across various ICS products.</p><p class="paragraph" style="text-align:left;">🩹 <b>Chipmaker Patch Tuesday</b> — Intel and AMD <a class="link" href="https://www.securityweek.com/chipmaker-patch-tuesday-intel-and-amd-patch-70-vulnerabilities/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">released May Patch Tuesday advisories</a> fixing 70 vulnerabilities across their products. Each maker fixed a critical flaw plus many high-severity bugs that could allow privilege escalation, DoS, or code execution. Users and administrators should apply updates to protect devices, drivers, firmware, and data.</p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">💬 CONNECT</h3><p class="paragraph" style="text-align:left;">Follow me on <a class="link" href="https://infosec.exchange/@0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">Mastodon</a> for quick daily updates and bite-sized content.</p><p class="paragraph" style="text-align:left;">Prefer using an RSS feed? Add <b>Infosec MASHUP</b> to your feed <a class="link" href="https://rss.beehiiv.com/feeds/HVhiKYpQlR.xml?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">here</a>.</p><p class="paragraph" style="text-align:center;"><b>Enjoying our newsletter? </b>Forward it to a colleague—<br>it’s one of the best ways to support us.</p><p class="paragraph" style="text-align:left;">Thanks for reading today’s newsletter, and if you&#39;re enjoying it and want to support my work, you can <b>buy me a coffee</b> ☕ over at <a class="link" href="https://www.buymeacoffee.com/0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-20-2026-the-platform-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">https://www.buymeacoffee.com/0x58</a></p><p class="paragraph" style="text-align:left;"> See you next time!</p><p class="paragraph" style="text-align:left;">-X.</p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=1046d824-826b-4c56-a7ac-a19b819ecb00&utm_medium=post_rss&utm_source=x_s_infosec_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🕵🏻‍♂️ [InfoSec MASHUP] 19/2026 - Offense Just Got a Co-Pilot</title>
  <description>Plus: A 64-day cPanel zero-day window, ShinyHunters hits an ed-tech giant, and Europe blocks Huawei from its solar grid.</description>
  <link>https://infosec-mashup.santolaria.net/p/infosec-mashup-19-2026-offense-just-got-a-co-pilot</link>
  <guid isPermaLink="true">https://infosec-mashup.santolaria.net/p/infosec-mashup-19-2026-offense-just-got-a-co-pilot</guid>
  <pubDate>Sat, 09 May 2026 08:56:41 +0000</pubDate>
  <atom:published>2026-05-09T08:56:41Z</atom:published>
    <dc:creator>Xavier Santolaria</dc:creator>
    <category><![CDATA[Malware]]></category>
    <category><![CDATA[Opensource]]></category>
    <category><![CDATA[Privacy]]></category>
    <category><![CDATA[Cybersecurity]]></category>
    <category><![CDATA[Threat Intelligence]]></category>
    <category><![CDATA[Ai]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">The story that should not get buried under this week&#39;s patch pile is a quiet one from the <a class="link" href="#ics-ot-io-t" rel="noopener noreferrer nofollow">ICS/OT section</a>: attackers used <b>Claude</b> and <b>ChatGPT</b> to assist an intrusion into a water utility in <b>Monterrey</b>. The OT breach ultimately failed — but that&#39;s almost beside the point. What the <b>Dragos</b> report actually documents is AI being used as a competent recon assistant: autonomously identifying a vNode SCADA/IIoT interface, recommending a password-spray attack, and generating a Python toolkit on the fly. No novel exploit. No nation-state budget. Just patience and a chat window.</p><p class="paragraph" style="text-align:left;">This is the part of the AI-in-security conversation that tends to get lost between the breathless vendor marketing and the &quot;fully autonomous AI attacks are not yet observed&quot; reassurances. The threat doesn&#39;t need to be autonomous to be meaningful. Lowering the reconnaissance floor — making OT infrastructure more legible to attackers who previously lacked the domain knowledge to navigate it — is already a significant capability shift. The <b>Monterrey</b> incident didn&#39;t succeed. The next one will be run by someone who learned from it.</p><p class="paragraph" style="text-align:left;">Let’s now dive into this week’s top insights! 🚀</p><h2 class="heading" style="text-align:left;">Table of Contents</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="#breaches-security-incidents" rel="noopener noreferrer nofollow">BREACHES & SECURITY INCIDENTS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#cybercrime-cyber-espionage-ap-ts" rel="noopener noreferrer nofollow">CYBERCRIME, CYBER ESPIONAGE, APT’s</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#government-politics-and-privacy" rel="noopener noreferrer nofollow">GOVERNMENT, POLITICS, AND PRIVACY</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#malware-threats" rel="noopener noreferrer nofollow">MALWARE & THREATS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ai-crypto-tech-tools" rel="noopener noreferrer nofollow">AI, CRYPTO, TECH & TOOLS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#vulnerabilities-research-and-threat" rel="noopener noreferrer nofollow">VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ics-ot-io-t" rel="noopener noreferrer nofollow">ICS, OT & IoT</a></p></li></ul><div id="breaches-security-incidents" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🔓 BREACHES & SECURITY INCIDENTS</h3><p class="paragraph" style="text-align:left;">🇪🇸 👗 <b>Hackers stole data from Zara-related databases, exposing information for about 197,400 people</b> — The breach came from a former tech provider and reportedly included emails, locations, purchases, and support tickets. The <b>ShinyHunters</b> group <a class="link" href="https://www.bleepingcomputer.com/news/security/zara-data-breach-exposed-personal-information-of-197-000-people/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">claims responsibility and leaked a 140GB archive</a>.</p><p class="paragraph" style="text-align:left;">🔓️ <b>Trellix says part of its source code repository was breached but gave few details</b> — They are <a class="link" href="https://www.securityweek.com/trellix-source-code-repository-breached/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">investigating with forensic experts</a> and have notified law enforcement. The incident may be linked to a wider supply-chain campaign tied to groups like <b>TeamPCP</b> and <b>Lapsus$</b>.</p><p class="paragraph" style="text-align:left;">→ <i><a class="link" href="https://www.bleepingcomputer.com/news/security/trellix-source-code-breach-claimed-by-ransomhouse-hackers-or-ransomhouse-hackers-claim-trellix-source-code-breach/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">RansomHouse</a></i><a class="link" href="https://www.bleepingcomputer.com/news/security/trellix-source-code-breach-claimed-by-ransomhouse-hackers-or-ransomhouse-hackers-claim-trellix-source-code-breach/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow"> hackers claim Trellix source code breach</a></p><p class="paragraph" style="text-align:left;">🎓️ <b>Education tech company </b><i><b>Instructure</b></i><b> says a cyberattack exposed user data</b> — The <a class="link" href="https://www.bleepingcomputer.com/news/security/instructure-confirms-data-breach-shinyhunters-claims-attack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">extortion group </a><i><a class="link" href="https://www.bleepingcomputer.com/news/security/instructure-confirms-data-breach-shinyhunters-claims-attack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">ShinyHunters</a></i><a class="link" href="https://www.bleepingcomputer.com/news/security/instructure-confirms-data-breach-shinyhunters-claims-attack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow"> claims it stole hundreds of millions of records</a> and listed <b>Instructure</b> on its leak site. Instructure is investigating, patching systems, and asking customers to reauthorize API access.</p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://techcrunch.com/2026/05/07/hackers-deface-school-login-pages-after-claiming-another-instructure-hack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">Hackers deface school login pages after claiming another Instructure hack</a></p></div><p class="paragraph" style="text-align:left;"></p><div id="cybercrime-cyber-espionage-ap-ts" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🥷🏻 CYBERCRIME, CYBER ESPIONAGE, APT’s</h3><p class="paragraph" style="text-align:left;">🦶 🍑 <b>Hackers have been breaking into systems already compromised by a cybercrime group called TeamPCP</b> and <a class="link" href="https://techcrunch.com/2026/05/07/hackers-hack-victims-hacked-by-other-hackers/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">kicking TeamPCP out</a>. The new group, dubbed <b>PCPJack</b>, then steals credentials and spreads across cloud services to sell access or extort victims. Researchers think <b>PCPJack</b> aims to make money and may be rival hackers or ex-<b>TeamPCP</b> members.</p><p class="paragraph" style="text-align:left;">🇨🇦 💬 <b>Toronto police arrested three men and laid 44 charges for running an SMS blaster</b> that sent spammy, phishing texts to tens of thousands of devices across the city. The device spoofed cell towers, exploited old 2G networks, and <a class="link" href="https://techcrunch.com/2026/05/07/police-arrest-sms-blaster-crew-that-sent-malicious-messages-to-thousands-across-toronto/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">was operated from the back of a vehicle</a> to steal logins and disrupt phone and 911 service. Authorities say turning off 2G or using Lockdown Mode on Apple devices can block such attacks.</p><p class="paragraph" style="text-align:left;">🇺🇸 ⚖️ <b>Two American men were jailed for 18 months for hosting laptop farms that let North Korean IT workers pose</b> as U.S.-based employees. Their schemes affected about 70 U.S. companies and funneled roughly $1.2 million to the regime. Authorities say these cases show <a class="link" href="https://cyberscoop.com/north-korea-it-worker-scheme-laptop-farm-facilitators-sentenced/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">they will punish people who help North Korea evade sanctions</a> and steal from U.S. firms.</p><p class="paragraph" style="text-align:left;">🇷🇴 ⚖️ 🇺🇸 <b>A 53-year-old Romanian, Gavril Sandu, was extradited to the U.S. for a 2009–2010 hacking</b> and vishing scheme. He is <a class="link" href="https://www.securityweek.com/romanian-extradited-to-us-for-role-in-hacking-scheme-17-years-ago/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">accused of stealing financial data, cloning cards, and withdrawing funds</a> as a money mule. <b>Sandu</b> faces up to 30 years in prison after a 17-year gap between the crimes and his extradition.</p><p class="paragraph" style="text-align:left;">🫥 🇮🇷 <b>Iran-linked APT </b><i><b>MuddyWater</b></i><b> staged an intrusion that looked like a </b><i><b>Chaos</b></i><b> ransomware attack</b> but did not encrypt files. Attackers used social engineering via Microsoft Teams, AnyDesk and DWAgent to steal credentials, move laterally, and exfiltrate data. <b>Chaos</b> <a class="link" href="https://www.rapid7.com/blog/post/tr-muddying-tracks-state-sponsored-shadow-behind-chaos-ransomware/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">artifacts were likely false flags</a> to hide state-sponsored espionage.</p><p class="paragraph" style="text-align:left;">🇹🇼 🚅 <b>A 23-year-old Taiwanese student was arrested for triggering emergency brakes on four high-speed trains</b> by hacking the TETRA radio system using SDR equipment and handheld radios. The <a class="link" href="https://www.bleepingcomputer.com/news/security/student-hacked-taiwan-high-speed-rail-to-trigger-emergency-brakes/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">attack halted trains for 48 minutes and exploited unchanged radio parameters</a> that allowed impersonation. He faces up to 10 years in prison and is out on bail while authorities investigate.</p><p class="paragraph" style="text-align:left;">🇱🇻 ⚖️ 🇺🇸 <b>A Latvian national, Deniss Zolotarjovs, was sentenced to 8.5 years in the U.S. for helping the </b><i><b>Karakurt</b></i><b> ransomware gang</b> extort dozens of companies. He negotiated “cold case” extortions and used stolen personal and health data to pressure victims. Authorities <a class="link" href="https://www.bleepingcomputer.com/news/security/karakurt-extortion-gang-negotiator-sentenced-to-85-years-in-prison/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">say his actions contributed to losses likely in the hundreds of millions</a> and could lead to more prosecutions.</p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;">🗓️ <b><a class="link" href="https://xsa.github.io/infosec-events/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">{Cyber,Info}Sec Events</a></b> — A community-maintained list of infosec conferences worldwide. Subscribe to the <a class="link" href="https://xsa.github.io/infosec-events/events.ics?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">ICS calendar feed</a> to get events straight into your calendar, or follow <a class="link" href="https://infosec.exchange/@infosecevents?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">@infosecevents@infosec.exchange</a> on Mastodon for weekly digests. Contributions and ⭐ welcome!</p></div><p class="paragraph" style="text-align:left;"></p><div id="government-politics-and-privacy" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">👨🏻‍⚖️ 👀 GOVERNMENT, POLITICS, AND PRIVACY</h3><div class="embed"><a class="embed__url" href="https://mastodon.social/@netblocks/116537773534366677?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank"><div class="embed__content"><p class="embed__title"> NetBlocks (@netblocks@mastodon.social) </p><p class="embed__description"> Attached: 1 image 🗓️ Today marks the 70th day of #Iran&#39;s internet blackout, with the incident now surpassing 1656 hours. Digital connectivity is vital in times of crisis, and limiting service harms those most in need - people with disabilities, students, small businesses and the general public. </p><p class="embed__link"> Mastodon </p></div><img class="embed__image embed__image--right" src="https://files.mastodon.social/media_attachments/files/116/537/772/095/891/928/original/604d023eaf3ebfec.png"/></a></div><p class="paragraph" style="text-align:left;">🇺🇸 👀 <b>Rep. Summer Lee asked the Commerce Department for a briefing on U.S. use of commercial spyware</b> after ICE admitted using <b>Paragon</b>’s Graphite. She is <a class="link" href="https://cyberscoop.com/democrat-summer-lee-letter-briefing-nso-group-spyware-trump/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">worried</a> the Trump administration and U.S. investors may enable use of <b>NSO Group</b>’s Pegasus. Lawmakers cite past abuses and want details on communications and potential federal use.</p><p class="paragraph" style="text-align:left;">🇺🇸 📍 ⚖️ <b>Kochava agreed to stop selling sensitive location data to settle an FTC lawsuit</b> — The proposed order bans sharing location info tied to places like clinics, churches, shelters and daycares without users&#39; clear consent. The <a class="link" href="https://www.databreachtoday.com/kochava-will-stop-selling-sensitive-location-info-a-31601?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">company must verify suppliers&#39; permissions</a>, let people see who bought their data, and allow easy opt-out.</p><p class="paragraph" style="text-align:left;">🔎 🇺🇸 🩺 <b>An investigation found nearly all 20 state health insurance marketplaces shared applicants’ data with ad tech companies</b> like Google, Meta, LinkedIn, Snap, and TikTok. Trackers on these sites <a class="link" href="https://techcrunch.com/2026/05/04/us-healthcare-marketplaces-shared-citizenship-and-race-data-with-ad-tech-giants/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">exposed sensitive details, including race, sex, ZIP codes, and family incarceration</a> information. Some states removed or paused trackers after the findings, highlighting widespread privacy risks on government health sites.</p><p class="paragraph" style="text-align:left;">🇪🇺 ❌ 💰️ 🇨🇳 <b>The European Commission will block EU funding for solar panel inverters</b> from high-risk suppliers like <b>Huawei</b>. Officials say <a class="link" href="https://www.politico.eu/article/commission-blocks-eu-funding-for-huawei-solar-tech/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">this aims to prevent foreign interference</a> that could disrupt electricity grids. China, Russia, North Korea and Iran are affected, with Chinese firms holding about 80% of the inverter market.</p><p class="paragraph" style="text-align:left;">🇪🇺 👀 <b>The EFF urges the EU’s Digital Fairness Act to stop manipulative design and surveillance-driven</b> business models. They <a class="link" href="https://www.eff.org/deeplinks/2026/04/dos-and-donts-eus-digital-fairness-act-effs-recommendation-regulating-digital?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">want stronger privacy protections</a>, bans on dark patterns, and limits on data profiling and pay-for-privacy. The law should also boost user control by preventing lock-in, unfair post-sale restrictions, and promoting interoperability.</p></div><p class="paragraph" style="text-align:left;"></p><div id="malware-threats" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🦠 MALWARE & THREATS</h3><div class="embed"><a class="embed__url" href="https://www.404media.co/hello-boss-inside-the-chinese-realtime-deepfake-software-powering-scams-around-the-world/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank"><div class="embed__content"><p class="embed__title"> ‘HELLO BOSS’: Inside the Chinese Realtime Deepfake Software Powering Scams Around the World </p><p class="embed__description"> 404 Media has obtained a copy of ‘Haotian AI’, a popular piece of realtime deepfake software marketed to scammers. It can turn a fraudster&#39;s face into anyone else&#39;s on WhatsApp, Zoom, and Teams. </p><p class="embed__link"> 404 Media </p></div><img class="embed__image embed__image--right" src="https://storage.ghost.io/c/0f/76/0f76b548-bc58-4f25-abc3-3f5ebca07da4/content/images/size/w1200/2026/05/haotian-ai-header-art.png"/></a></div><hr class="content_break"><p class="paragraph" style="text-align:left;">🇺🇸 🎣 <b>Microsoft warned of a sophisticated phishing campaign that used fake &quot;code of conduct&quot; emails</b> to lure victims to malicious sites. The <a class="link" href="https://www.microsoft.com/en-us/security/blog/2026/05/04/breaking-the-code-multi-stage-code-of-conduct-phishing-campaign-leads-to-aitm-token-compromise/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">attacks targeted mostly U.S. organizations</a>, hitting healthcare, finance, professional services, and tech, with over 35,000 attempts. The scheme uses CAPTCHAs and an adversary-in-the-middle trick to steal session tokens and bypass MFA.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ce2f9926-e0b8-49d1-9555-e8d40a779d16/image.png?t=1778058723"/><div class="image__source"><span class="image__source_text"><p>Figure: Campaign recipients by country and industry/Microsoft.com</p></span></div></div><p class="paragraph" style="text-align:left;">🐧 <b>A new Linux malware called </b><i><b>Quasar Linux (QLNX)</b></i><b> targets developers and DevOps environments</b> to steal credentials and persist stealthily. It uses a dynamic rootkit, PAM backdoors, fileless techniques, and seven persistence methods to hide and maintain access. By harvesting developer and cloud credentials, it <a class="link" href="https://www.trendmicro.com/en_us/research/26/e/quasar-linux-qlnx-a-silent-foothold-in-the-software-supply-chain.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">can enable supply-chain attacks</a> like trojanized packages.</p><p class="paragraph" style="text-align:left;">🇨🇳 🔙 🚪 <b>Kaspersky says a backdoor was planted in the Windows disc tool </b><i><b>Daemon Tools</b></i> in a widespread supply-chain attack. The company <a class="link" href="https://techcrunch.com/2026/05/05/kaspersky-suspects-chinese-hackers-planted-a-backdoor-into-daemon-tools-in-widespread-attack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">links the attack to a Chinese-language hacking group</a> that used the backdoor to install further malware on targeted organizations in Russia, Belarus and Thailand. <b>Disc Soft</b> is investigating while the attack appears still active and thousands of users may be at risk.</p><p class="paragraph" style="text-align:left;">🇰🇵 🎮️ <b>North Korea-linked </b><i><b>ScarCruft</b></i><b> hacked a gaming platform used by ethnic Koreans</b> and inserted the <i><b>BirdCall</b></i> backdoor. The <a class="link" href="https://www.welivesecurity.com/en/eset-research/rigged-game-scarcruft-compromises-gaming-platform-supply-chain-attack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">supply-chain attack added an Android strain</a> so <b>BirdCall</b> now targets both Windows and Android. The malware steals files, messages, screenshots, and audio and uses cloud services for command-and-control.</p><p class="paragraph" style="text-align:left;">💬 📲 <b>A new CloudZ RAT plugin called </b><i><b>Pheno</b></i><b> hijacks Microsoft Phone Link on Windows to steal SMS messages and one-time passwords</b> without touching the phone. Researchers <a class="link" href="https://blog.talosintelligence.com/cloudz-pheno-infostealer/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">found</a> <b>Pheno</b> reads Phone Link’s local SQLite database to intercept codes and notifications. Users should avoid SMS OTPs and use authenticator apps or hardware keys.</p><p class="paragraph" style="text-align:left;">🐍 🔙 🚪 <b>China-linked group </b><i><b>Silver Fox</b></i><b> used tax-themed phishing to target organizations in India, Russia</b> and other countries. Phishing emails <a class="link" href="https://securelist.com/silver-fox-tax-notification-campaign/119575/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">delivered a Rust-based loader</a> that installed <b>ValleyRAT</b> and a new Python backdoor called <b>ABCDoor</b>. <b>ABCDoor</b> gives attackers persistence, remote control, data theft, and updates via HTTPS.</p></div><p class="paragraph" style="text-align:left;"></p><div id="ai-crypto-tech-tools" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🤖 🧰 AI, CRYPTO, TECH & TOOLS</h3><div class="embed"><a class="embed__url" href="https://arstechnica.com/information-technology/2026/05/mozilla-says-271-vulnerabilities-found-by-mythos-have-almost-no-false-positives/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank"><div class="embed__content"><p class="embed__title"> Mozilla says 271 vulnerabilities found by Mythos have &quot;almost no false positives&quot; </p><p class="embed__description"> The developer of Firefox says it has &quot;completely bought in&quot; on AI-assisted bug discovery. </p><p class="embed__link"> Ars Technica </p></div><img class="embed__image embed__image--right" src="https://cdn.arstechnica.net/wp-content/uploads/2026/03/GettyImages-2167753513-1152x648.jpg"/></a></div><p class="paragraph" style="text-align:left;">🤔 <b>A researcher found that Microsoft Edge decrypts and loads all saved passwords into memory</b> at startup. This means <a class="link" href="https://www.digitalescapetools.com/2026/05/edge-passwords-memory-risk.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">plaintext credentials can remain in system memory for the whole browser session</a>. The risk is mainly to systems where an attacker already has high privileges, and <b>Microsoft</b> says this behavior is intentional.</p><p class="paragraph" style="text-align:left;">🐛 <b>A critical unauthenticated bug in Ollama (CVE-2026-7482 aka </b><i><b>Bleeding Llama</b></i><b>) lets attackers read heap memory and steal</b> sensitive data like prompts, API keys, and environment variables. About 300,000 internet-accessible <b>Ollama</b> deployments <a class="link" href="https://www.cyera.com/research/bleeding-llama-critical-unauthenticated-memory-leak-in-ollama?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">are exposed</a> because the service often runs without authentication and listens on all interfaces. Update to <b>Ollama</b> 0.17.1, restrict network access, and add authentication or a proxy immediately.</p><p class="paragraph" style="text-align:left;">⬇️ <b>Google Chrome quietly writes a 4 GB AI model file to users&#39; profiles without asking</b> — This download happened automatically on many devices and can fill disks or consume months of mobile data. This <a class="link" href="https://www.thatprivacyguy.com/blog/chrome-silent-nano-install/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">mass push raises</a> privacy, transparency, legal, and climate concerns and calls for clear notices, easy removal, and reporting of the environmental cost.</p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://www.securityweek.com/chrome-148-rolls-out-with-127-security-fixes/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">Chrome 148 Rolls Out With 127 Security Fixes</a></p><p class="paragraph" style="text-align:left;">🇷🇺 💸 <b>A popular crypto exchange called </b><i><b>Grinex</b></i><b> shut down after a reported cyberattack and lost about $13 million</b> — Experts say <a class="link" href="https://www.databreachtoday.com/grinex-collapse-wont-dent-russian-sanctions-busting-a-31591?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">Russian sanctions evasion will keep using new platforms</a> and a ruble-pegged stablecoin called A7A5. The takedown adds friction but won’t stop the shadow finance networks.</p><p class="paragraph" style="text-align:left;">🇺🇸 🪖 🤖 <b>The Pentagon made deals with seven tech firms so their AI can be used on classified</b> military networks. The tools aim to help with decision-making, targeting, and logistics but raise concerns about oversight, privacy, and civilian harm. One major AI company, <b>Anthropic</b>, is <a class="link" href="https://www.securityweek.com/us-military-reaches-deals-with-7-tech-companies-to-use-their-ai-on-classified-systems/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">absent after a dispute over limits on military use</a>.</p></div><p class="paragraph" style="text-align:left;"></p><div id="vulnerabilities-research-and-threat" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🐛 🧠 VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</h3><p class="paragraph" style="text-align:left;">➝ From the Patching Department:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://securityaffairs.com/191808/security/cisco-patches-high-severity-flaws-enabling-ssrf-code-execution-attacks.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">Cisco patches high-severity flaws enabling SSRF, code execution attacks</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/critical-high-severity-vulnerabilities-patched-in-apache-mina-http-server/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">Critical, High-Severity Vulnerabilities Patched in Apache MINA, HTTP Server</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/critical-remote-code-execution-vulnerability-patched-in-android-2/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">Critical Remote Code Execution Vulnerability Patched in Android</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/ivanti-patches-epmm-zero-day-exploited-in-targeted-attacks/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">Ivanti Patches EPMM Zero-Day Exploited in Targeted Attacks</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/oracle-debuts-monthly-critical-security-patch-updates/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">Oracle Debuts Monthly Critical Security Patch Updates</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/palo-alto-networks-to-patch-zero-day-exploited-to-hack-firewalls/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">Palo Alto Networks to Patch Zero-Day Exploited to Hack Firewalls</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://thehackernews.com/2026/05/progress-patches-critical-moveit.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">Progress Patches Critical MOVEit Automation Bug Enabling Authentication Bypass</a></p></li></ul><hr class="content_break"><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/xdiE3OZwkdU" width="100%"></iframe><div class="embed"><a class="embed__url" href="https://unit42.paloaltonetworks.com/cve-2026-31431-copy-fail/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank"><div class="embed__content"><p class="embed__title"> Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years </p><p class="embed__description"> Copy Fail (CVE-2026-31431) is a critical Linux kernel LPE that allows stealthy root access. This flaw impacts millions of systems. Read our analysis. </p><p class="embed__link"> Unit 42 • Justin Moore </p></div><img class="embed__image embed__image--right" src="https://origin-unit42.paloaltonetworks.com/wp-content/uploads/2026/05/05_Vulnerabilities_1920x900-2-1.jpg"/></a></div><p class="paragraph" style="text-align:left;">🐧 <b>A new unpatched Linux kernel flaw called </b><i><b>Dirty Frag</b></i><b> lets local users gain root on many major distributions</b> — It chains two page-cache write bugs (xfrm-ESP and RxRPC) so it works in different environments. A <a class="link" href="https://almalinux.org/blog/2026-05-07-dirty-frag/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">one‑command PoC exists</a>, and admins should block esp4, esp6, and rxrpc until patched.</p><hr class="content_break"><p class="paragraph" style="text-align:left;">💥 📆 <b>A critical PAN-OS firewall zero-day (CVE-2026-0300) has been exploited for nearly a month</b> to run code as root on exposed PA- and VM-series devices. Attackers used <code>EarthWorm</code> and <code>ReverseSocks5</code> to tunnel and maintain access, and they cleaned logs after compromising devices. <b>Palo Alto</b> is <a class="link" href="https://unit42.paloaltonetworks.com/captive-portal-zero-day/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">issuing patches soon</a> and urges admins to restrict or disable the User-ID Authentication Portal until fixed.</p><p class="paragraph" style="text-align:left;">🐛 <b>The vm2 Node.js library has a dozen critical vulnerabilities that let attackers break out of its JavaScript sandbox</b> and run arbitrary code on hosts. Affected <a class="link" href="https://thehackernews.com/2026/05/vm2-nodejs-library-vulnerabilities.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">versions up to 3.11.1 are patched across updates</a>, with the latest fix in 3.11.2. Users should update <b>vm2</b> immediately to stay protected.</p><p class="paragraph" style="text-align:left;">👿 <b>A critical FreeBSD DHCP client bug (CVE-2026-42511) lets a local attacker run code as root</b> by sending crafted DHCP data. It <a class="link" href="https://cybersecuritynews.com/freebsd-dhcp-client-vulnerability/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">affects all supported </a><b><a class="link" href="https://cybersecuritynews.com/freebsd-dhcp-client-vulnerability/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">FreeBSD</a></b><a class="link" href="https://cybersecuritynews.com/freebsd-dhcp-client-vulnerability/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow"> versions</a> and can fully compromise systems when a rogue DHCP server is on the same network. <b>FreeBSD</b> has released patches—admins should update immediately or enable DHCP snooping to block rogue servers.</p><p class="paragraph" style="text-align:left;">💥 <b>The critical cPanel authentication bypass (CVE-2026-41940) was actively exploited from about Feb 23, 2026</b>, but <a class="link" href="https://webhosting.today/2026/05/03/the-cpanel-zero-day-was-active-for-64-days-before-anyone-knew/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">only publicly disclosed on April 28</a>. Around 1–1.5 million internet-facing <b>cPanel</b> hosts were potentially vulnerable, and many were quickly used in ransomware and botnet campaigns. Any server accessible without firewalling between Feb 23 and Apr 28 should be treated as possibly compromised and fully investigated.</p><p class="paragraph" style="text-align:left;">🌱 💥 <b>A critical unauthenticated RCE bug (CVE-2026-22679) in Weaver E-cology was exploited from mid-March</b> to run discovery commands and <a class="link" href="https://blog.vega.io/posts/cve-2026-22679-weaver-ecology-exploitation/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">fetch PowerShell payloads</a>. Attackers used an exposed debug API to execute system commands but failed to gain persistence. Users should install the vendor update (build 20260312) immediately.</p></div><p class="paragraph" style="text-align:left;"></p><div id="ics-ot-io-t" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🛰️ ICS, OT & IoT</h3><p class="paragraph" style="text-align:left;">🇵🇱 🚰 <b>Poland’s Internal Security Agency reports a rise in cyberattacks on industrial control systems at water treatment plants</b> in 2024–2025. Attackers exploited weak passwords and internet-exposed systems to alter equipment and risk water supplies in five municipalities. ABW <a class="link" href="https://www.securityweek.com/polish-security-agency-reports-ics-breaches-at-five-water-treatment-plants/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">blames foreign-linked hacktivist/APT groups</a>, including Russia-linked APT28/APT29 and Belarus-linked UNC1151.</p><p class="paragraph" style="text-align:left;">🤖 🚰 <b>Cyber attackers used Anthropic’s Claude and OpenAI GPT to plan and speed up an intrusion into a Monterrey water utility</b> in January 2026. <b>Claude</b> <a class="link" href="https://www.securityweek.com/claude-ai-guided-hackers-toward-ot-assets-during-water-utility-intrusion/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">autonomously found a vNode SCADA/IIoT interface</a>, recommended a password-spray attack, and helped build a large Python toolkit, though the OT breach failed. <b>Dragos</b> warns AI can make industrial systems more visible to attackers even if fully autonomous attacks are not yet observed.</p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">💬 CONNECT</h3><p class="paragraph" style="text-align:left;">Follow me on <a class="link" href="https://infosec.exchange/@0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">Mastodon</a> for quick daily updates and bite-sized content.</p><p class="paragraph" style="text-align:left;">Prefer using an RSS feed? Add <b>Infosec MASHUP</b> to your feed <a class="link" href="https://rss.beehiiv.com/feeds/HVhiKYpQlR.xml?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">here</a>.</p><p class="paragraph" style="text-align:center;"><b>Enjoying our newsletter? </b>Forward it to a colleague—<br>it’s one of the best ways to support us.</p><p class="paragraph" style="text-align:left;">Thanks for reading today’s newsletter, and if you&#39;re enjoying it and want to support my work, you can <b>buy me a coffee</b> ☕ over at <a class="link" href="https://www.buymeacoffee.com/0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-19-2026-offense-just-got-a-co-pilot" target="_blank" rel="noopener noreferrer nofollow">https://www.buymeacoffee.com/0x58</a></p><p class="paragraph" style="text-align:left;"> See you next time!</p><p class="paragraph" style="text-align:left;">-X.</p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=37d09849-8235-42ae-a43c-ee7b3d32b72e&utm_medium=post_rss&utm_source=x_s_infosec_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🕵🏻‍♂️ [InfoSec MASHUP] 18/2026 - ShinyHunters&#39; Week Off (They Didn&#39;t Take One)</title>
  <description>Plus: Supply chain attackers found the path of least resistance, OpenSSH patched a bug older than most junior devs, and Europe is done pretending U.S. cloud is a neutral choice</description>
  <link>https://infosec-mashup.santolaria.net/p/infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one</link>
  <guid isPermaLink="true">https://infosec-mashup.santolaria.net/p/infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one</guid>
  <pubDate>Sat, 02 May 2026 07:51:00 +0000</pubDate>
  <atom:published>2026-05-02T07:51:00Z</atom:published>
    <dc:creator>Xavier Santolaria</dc:creator>
    <category><![CDATA[Malware]]></category>
    <category><![CDATA[Opensource]]></category>
    <category><![CDATA[Privacy]]></category>
    <category><![CDATA[Cybersecurity]]></category>
    <category><![CDATA[Threat Intelligence]]></category>
    <category><![CDATA[Ai]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">This week&#39;s news cycle handed us the usual parade of breaches, arrests, and patch-your-stuff urgency — but if you squint at the <a class="link" href="#malware-threats" rel="noopener noreferrer nofollow">Malware</a> section long enough, a more uncomfortable story emerges. <b>SAP</b>-related npm packages backdoored with a credential stealer. A popular <b>PyPI</b> package hijacked via a forged signed release pushed through a compromised <b>GitHub Actions</b> workflow. Seventy-three &quot;sleeper&quot; extensions quietly sitting in <b>OpenVSX</b>, waiting. The common thread: attackers aren&#39;t breaking down the front door anymore. They&#39;re walking in through the tools developers use every day, often with a valid signature and a clean commit history.</p><p class="paragraph" style="text-align:left;">What makes this particularly fun — in the way a slow-motion disaster is fun — is that the blast radius isn&#39;t just the developer who ran <code>pip install</code>. It&#39;s every downstream user, every CI/CD pipeline, every AI coding agent that helpfully executed the preinstall hook without asking questions. The supply chain isn&#39;t a niche threat vector reserved for nation-state ops anymore. It&#39;s where commodity attackers are increasingly playing, because it scales beautifully and the detection gap remains embarrassingly wide.</p><p class="paragraph" style="text-align:left;">Want to read the rest? Let’s go! 🚀</p><h2 class="heading" style="text-align:left;">Table of Contents</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="#breaches-security-incidents" rel="noopener noreferrer nofollow">BREACHES & SECURITY INCIDENTS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#cybercrime-cyber-espionage-ap-ts" rel="noopener noreferrer nofollow">CYBERCRIME, CYBER ESPIONAGE, APT’s</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#government-politics-and-privacy" rel="noopener noreferrer nofollow">GOVERNMENT, POLITICS, AND PRIVACY</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#malware-threats" rel="noopener noreferrer nofollow">MALWARE & THREATS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ai-crypto-tech-tools" rel="noopener noreferrer nofollow">AI, CRYPTO, TECH & TOOLS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#vulnerabilities-research-and-threat" rel="noopener noreferrer nofollow">VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ics-ot-io-t" rel="noopener noreferrer nofollow">ICS, OT & IoT</a></p></li></ul><div id="breaches-security-incidents" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🔓 BREACHES & SECURITY INCIDENTS</h3><p class="paragraph" style="text-align:left;">🎦 <b>Vimeo says hackers stole user and customer data after breaching a third-party</b> analytics vendor. Stolen items include technical data, video titles/metadata, and some email addresses, but not video content, passwords, or payment cards. The <i><b>ShinyHunters</b></i> group <a class="link" href="https://www.securityweek.com/vimeo-confirms-user-and-customer-data-breach/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">claims responsibility and is threatening to leak files</a> unless a ransom is paid.</p><p class="paragraph" style="text-align:left;">🇧🇷 💥 <b>A Brazilian DDoS protection firm, </b><i><b>Huge Networks</b></i><b>, was tied to a botnet that launched massive attacks</b> against Brazilian ISPs. An exposed archive showed attackers used the CEO’s leaked SSH keys and scripts to hijack vulnerable TP-Link routers and DNS servers. The CEO <a class="link" href="https://krebsonsecurity.com/2026/04/anti-ddos-firm-heaped-attacks-on-brazilian-isps/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">says the company was breached and blames a competitor</a>, not his team.</p><p class="paragraph" style="text-align:left;">⚕️<b>Sandhills Medical Foundation suffered a ransomware attack</b> discovered May 8, 2025. Nearly 170,000 people may have had personal and health data exposed, including SSNs, IDs, and financial information. The <a class="link" href="https://www.securityweek.com/sandhills-medical-says-ransomware-breach-affects-170000/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">stolen files were posted by the </a><i><a class="link" href="https://www.securityweek.com/sandhills-medical-says-ransomware-breach-affects-170000/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">Inc Ransom</a></i><a class="link" href="https://www.securityweek.com/sandhills-medical-says-ransomware-breach-affects-170000/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow"> group</a> and the organization has notified affected individuals.</p><p class="paragraph" style="text-align:left;">🇺🇸 🇮🇪 <b>Medtronic says cybercriminals breached its corporate IT systems</b> but so far the <a class="link" href="https://www.databreachtoday.com/medical-device-maker-medtronic-says-its-been-hacked-a-31518?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">company found no impact</a> on products, manufacturing, or patient safety. The gang <b><i>ShinyHunters</i></b> claims it stole 9 million records and threatened to publish them. This hack is one of several recent attacks on large medical device makers, raising industry-wide security concerns.</p><p class="paragraph" style="text-align:left;">🇺🇸 <b>Checkmarx says a cybercriminal group posted data from its GitHub repository on the dark web</b> after a March 23 supply-chain attack. The company <a class="link" href="https://checkmarx.com/blog/checkmarx-security-update-april-26/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">says</a> the repo is separate from customer production systems and no customer data is stored there, and it has locked down the repo while investigating. The breach involved tampered workflows, plugins, and extensions that pushed a credential stealer and affected other packages.</p><p class="paragraph" style="text-align:left;">🏡 🔓️ <b>Home security company ADT suffered a data breach that exposed personally identifiable information</b> for about <b><a class="link" href="https://www.databreachtoday.com/home-security-firm-adt-breach-55m-customers-data-exposed-a-31511?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">5.5 million customers</a></b>. The hacker group <i><b>ShinyHunters</b></i> posted over 10 million records and said it accessed <b>ADT</b> systems via social engineering. <b>ADT</b> says payment data and security systems were not affected and it has contacted affected customers.</p><p class="paragraph" style="text-align:left;">🇺🇸 <b>Itron, a major maker of internet-connected utility meters, says it was hacked in mid-April</b> and <a class="link" href="https://techcrunch.com/2026/04/27/critical-infrastructure-giant-itron-says-it-was-hacked/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">attackers accessed some of its systems</a>. The company says it expelled the intruders, found no signs of ongoing access, and notified law enforcement. <b>Itron</b> reported operations are continuing and is using backups, but the full impact and any data breach details are still unclear.</p></div><p class="paragraph" style="text-align:left;"></p><div id="cybercrime-cyber-espionage-ap-ts" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🥷🏻 CYBERCRIME, CYBER ESPIONAGE, APT’s</h3><div class="embed"><a class="embed__url" href="https://cyberscoop.com/crowdstrike-cordial-spider-snarky-spider-extortion-attacks/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank"><div class="embed__content"><p class="embed__title"> Two new extortion crews are speedrunning the Scattered Spider playbook </p><p class="embed__description"> CrowdStrike says The Com-affiliated the groups are using voice phishing and fake SSO pages to break into SaaS environments and steal data fast for extortion. </p><p class="embed__link"> CyberScoop • Matt Kapko </p></div><img class="embed__image embed__image--right" src="https://cyberscoop.com/wp-content/uploads/sites/3/2026/03/GettyImages-1467743069.jpg"/></a></div><p class="paragraph" style="text-align:left;">🇫🇷 <b>French police detained a 15-year-old suspected of selling data from a breach of France Titres (ANTS)</b> — Authorities say the teen, using the alias &quot;<i>breach3d</i>,&quot; offered millions of records including names, emails, birthdates, addresses, and phone numbers. Prosecutors seek <a class="link" href="https://www.bleepingcomputer.com/news/security/15-year-old-detained-over-french-govt-agency-data-breach/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">formal charges and judicial supervision</a> while a judge reviews the case.</p><p class="paragraph" style="text-align:left;">🇺🇸 ⚖️ <b>Two former incident responders pleaded guilty to ransomware attacks</b> and were each sentenced to four years in prison. They <a class="link" href="https://cyberscoop.com/incident-responders-ryan-goldberg-kevin-martin-sentenced-ransomware/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">used </a><i><a class="link" href="https://cyberscoop.com/incident-responders-ryan-goldberg-kevin-martin-sentenced-ransomware/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">ALPHV/BlackCat </a></i><a class="link" href="https://cyberscoop.com/incident-responders-ryan-goldberg-kevin-martin-sentenced-ransomware/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">ransomware to extort victims</a>, including medical and engineering firms, stealing data and demanding payments. One co-conspirator extorted far more and faces a longer sentence while employers say they were unaware and fired the employees.</p><p class="paragraph" style="text-align:left;">🇮🇷 🇺🇸 🇧🇭 <b>Iran-linked group </b><i><b>Handala</b></i><b> sent threatening WhatsApp messages to US troops in Bahrain</b> and posted personal data of thousands of Marines. The group, <a class="link" href="https://www.securityweek.com/iranian-cyber-group-handala-targets-us-troops-in-bahrain/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">tied to Iran’s Ministry of Intelligence</a>, conducts influence, hacking, and destructive cyber operations. Authorities say <i>Handala</i> aims for psychological damage and has used malware, wipers, and social engineering in past attacks.</p><p class="paragraph" style="text-align:left;">🇺🇦 🕹️ <b>Ukrainian police arrested three people for hacking and selling 610,000 Roblox accounts</b>, making about $225,000. They seized cash, phones, computers, and storage devices during raids in Lviv. The <a class="link" href="https://www.bleepingcomputer.com/news/security/hackers-arrested-for-hijacking-and-selling-610-000-roblox-accounts/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">group used malware to steal credentials</a>, sold high-value accounts online, and faces up to 15 years in prison.</p><p class="paragraph" style="text-align:left;">🇨🇦 <b>Canadian police arrested three men in Toronto for using an &quot;</b><i><b>SMS blaster</b></i><b>&quot; that mimics cell towers to send phishing texts</b> to nearby phones. The device forced phones to connect, sent fake messages that look like they come from banks or the government, and blocked access to real networks and emergency services. Authorities <a class="link" href="https://www.tps.ca/media-centre/stories/unprecedented-sms-blaster-arrests/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">seized equipment, said millions were affected</a>, and warned users to treat SMS as insecure and use encrypted channels.</p><p class="paragraph" style="text-align:left;">🇪🇺 ❌ <b>Austrian and Albanian police, with Europol and Eurojust, broke up a crypto investment scam</b> that <a class="link" href="https://www.bleepingcomputer.com/news/security/european-police-dismantles-50-million-crypto-investment-fraud-ring/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">stole over €50 million</a> from people worldwide. They arrested 10 suspects, searched call centres and homes, and seized cash, computers, phones, and other devices. The fraud used fake trading platforms and call-centre &quot;brokers&quot; to trick victims and launder their money.</p><p class="paragraph" style="text-align:left;">🇺🇸 ⚖️ <b>A 19-year-old dual U.S.-Estonian citizen nicknamed &quot;</b><i><b>Bouquet</b></i><b>&quot; was arrested in Finland and charged in the U.S. for major hacking</b> and extortion with the <i>Scattered Spider</i> group. Prosecutors say <a class="link" href="https://www.bleepingcomputer.com/news/security/us-reportedly-charges-scattered-spider-hacker-arrested-in-finland/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">he helped breach multiple companies</a>, forcing victims to pay or suffer millions in damages. <i>Scattered Spider</i> is a young, criminal hacking collective known for social engineering and MFA-bypass attacks on many high-profile firms.</p><p class="paragraph" style="text-align:left;">🇺🇸 ⚖️ <b>Evan Tangeman, 22, was sentenced to 70 months for laundering millions from a $230M</b> cryptocurrency theft. He <a class="link" href="https://www.bleepingcomputer.com/news/security/money-launderer-linked-to-230m-crypto-heist-gets-70-months-in-prison/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">helped move at least $3.5M for the group that stole over 4,100 Bitcoin</a> in 2024. The gang used mixers, exchanges, VPNs, and lavish spending to hide and spend the stolen funds.</p><p class="paragraph" style="text-align:left;">🇨🇳 ⚖️ 🇺🇸 <b>A Chinese national, Xu Zewei, was extradited from Italy to the U.S. and charged for his role in a large cyberespionage</b> campaign. The attacks, linked to the <i>Silk Typhoon/HAFNIUM</i> group, exploited Microsoft Exchange flaws to steal COVID-19 research and other sensitive data. Xu faces multiple federal charges and <a class="link" href="https://cyberscoop.com/xu-zewei-extradited-china-national-silk-typhoon-hafnium/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">up to 62 years in prison</a>.</p><p class="paragraph" style="text-align:left;">→ More:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.databreachtoday.com/fbi-backed-takedown-hits-crypto-scam-centers-a-31551?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">FBI-Backed Takedown Hits Crypto Scam Centers</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/romanian-leader-of-online-swatting-ring-gets-4-years-in-prison/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">Romanian leader of online swatting ring gets 4 years in prison</a></p></li></ul></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;">🗓️ <b><a class="link" href="https://xsa.github.io/infosec-events/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">{Cyber,Info}Sec Events</a></b> — A community-maintained list of infosec conferences worldwide. Subscribe to the <a class="link" href="https://xsa.github.io/infosec-events/events.ics?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">ICS calendar feed</a> to get events straight into your calendar, or follow <a class="link" href="https://infosec.exchange/@infosecevents?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">@infosecevents@infosec.exchange</a> on Mastodon for weekly digests. Contributions and ⭐ welcome!</p></div><p class="paragraph" style="text-align:left;"></p><div id="government-politics-and-privacy" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">👨🏻‍⚖️ 👀 GOVERNMENT, POLITICS, AND PRIVACY</h3><p class="paragraph" style="text-align:left;">🇪🇺 ✈️ 🇺🇸 <b>The U.S. is asking the EU to let American authorities access Europeans’ personal and biometric data</b> or lose visa-free travel. EU leaders and privacy <a class="link" href="https://www.fodors.com/news/news/u-s-demands-access-to-europeans-private-data-or-say-goodbye-to-visa-free-travel?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">experts warn this clashes with strong EU data protections</a> and could enable mass surveillance. Critics call the demand coercive and fear it will chill free speech and travel.</p><p class="paragraph" style="text-align:left;">🇺🇸 ⏳️ <b>Congress approved a 45-day extension of Section 702, which allows warrantless surveillance </b>of foreign targets. Lawmakers <a class="link" href="https://cyberscoop.com/congress-extends-section-702-surveillance-45-days/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">want more time to address privacy concerns</a> after a court found compliance problems and a declassification review is underway. The extension delays a long-term decision as political fights continue over reform.</p><p class="paragraph" style="text-align:left;">🇮🇹 <b>Italian prosecutors say Paragon Solutions has NOT cooperated with their year-old probe into Graphite spyware</b> that targeted journalists and activists. <b>Paragon</b> previously offered to help and then publicly clashed with Italy, even cancelling contracts. Prosecutors <a class="link" href="https://techcrunch.com/2026/04/28/paragon-is-not-collaborating-with-italian-authorities-probing-spyware-attacks-report-says/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">still await a response</a> as the investigation continues.</p><p class="paragraph" style="text-align:left;">🇷🇺 🇩🇪 <b>Russian-linked phishing attacks using malicious Signal QR codes likely compromised high-ranking German officials</b> — Signal says its app and encryption were not hacked but will add protections and warns users to enable Registration Lock. European and U.S. agencies <a class="link" href="https://www.databreachtoday.com/germany-caught-up-in-likely-russian-signal-phishing-a-31535?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">blame Russian intelligence for a wider campaign targeting officials</a> across multiple countries.</p><blockquote align="center" class="twitter-tweet"><a href="https://twitter.com/signalapp/status/2048866663580246302?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one"><p> Twitter tweet </p></a></blockquote><p class="paragraph" style="text-align:left;">🇺🇸 💰️ <b>U.S. states issued a record $3.45 billion in privacy fines in 2025</b>, more than the prior five years combined. Stronger state laws, cross-state enforcement and scrutiny of AI data use drove the increase. Regulators warn <a class="link" href="https://cyberscoop.com/privacy-companies-hit-with-record-fines-2025-gartner/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">enforcement will stay strong</a> as concerns about AI and privacy grow.</p><p class="paragraph" style="text-align:left;">🇪🇺 🆚 🇺🇸 <b>Europe is trying to reduce reliance on U.S. tech</b> because laws like the CLOUD Act and political concerns threaten data sovereignty. Governments are <a class="link" href="https://techcrunch.com/2026/04/27/whats-behind-europes-efforts-to-ditch-u-s-software-in-favor-of-sovereign-tech/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">pushing for “sovereign” cloud and open-source alternatives</a>, but European providers still struggle to match U.S. rivals. Public contracts and rising demand for non‑American solutions may help build competitive European tech.</p></div><p class="paragraph" style="text-align:left;"></p><div id="malware-threats" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🦠 MALWARE & THREATS</h3><p class="paragraph" style="text-align:left;">🐍 🔙 🚪 <b>Researchers uncovered a stealthy Python backdoor called </b><i><b>DEEP#DOOR</b></i><b> that hides inside a batch dropper</b> and establishes persistent access on Windows. <br>It uses a public tunneling service (bore.pub) for command-and-control to steal browser, cloud, SSH, and other credentials and perform spying (keylogging, screenshots, webcam, audio). The <a class="link" href="https://www.securonix.com/blog/deepdoor-python-backdoor-and-credential-stealer/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">malware includes many anti-analysis and persistence tricks to avoid detection</a> and make removal difficult.</p><p class="paragraph" style="text-align:left;">🔑 <b>Researchers warn of a supply-chain attack that infected SAP-related npm packages with credential-stealing malware</b> called &quot;<i>mini Shai-Hulud</i>&quot;. The malicious releases added a preinstall hook that downloads and runs a Bun runtime to steal developer credentials, GitHub/npm tokens, cloud secrets, and exfiltrate them to public GitHub repos. The <a class="link" href="https://thehackernews.com/2026/04/sap-npm-packages-compromised-by-mini.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">payload can self-propagate via GitHub Actions</a> and injects files to trigger execution in VS Code and AI coding agents, making this a novel persistence and spread method.</p><p class="paragraph" style="text-align:left;">🐍 <b>Attackers pushed malicious </b><i><b>PyTorch Lightning</b></i><b> versions 2.6.2 and 2.6.3</b> on PyPI to steal credentials. The <a class="link" href="https://thehackernews.com/2026/04/pytorch-lightning-compromised-in-pypi.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">malware runs on import, downloads a Bun JavaScript runtime</a>, and exfiltrates tokens to spread to repositories and npm packages. PyPI quarantined the project; users should remove those versions, downgrade to 2.6.1, and rotate exposed credentials.</p><p class="paragraph" style="text-align:left;">🐍 <b>A malicious release (v0.23.3) of the popular PyPI package </b><code>elementary-data</code><b> was published and stole</b> developer secrets and crypto wallets. The <a class="link" href="https://www.stepsecurity.io/blog/elementary-data-compromised-on-pypi-and-ghcr-forged-release-pushed-via-github-actions-script-injection?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">attacker used a GitHub Actions script-injection</a> to forge a signed release, which also pushed a compromised Docker image. Users who installed that release or pulled the affected images must rotate secrets and restore from a safe backup.</p><p class="paragraph" style="text-align:left;">🪱 💤 <b>The GlassWorm campaign returned to OpenVSX with 73 &quot;</b><i><b>sleeper</b></i><b>&quot; extensions</b> that appear benign at first but <a class="link" href="https://socket.dev/blog/73-open-vsx-sleeper-extensions-glassworm?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">turn malicious after an update</a>. Researchers say six are active and deliver malware, while the rest are likely dormant or suspicious. Developers who installed any listed extensions should rotate secrets and clean their environments.</p></div><p class="paragraph" style="text-align:left;"></p><div id="ai-crypto-tech-tools" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🤖 🧰 AI, CRYPTO, TECH & TOOLS</h3><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/aiCZXK5830M" width="100%"></iframe><hr class="content_break"><p class="paragraph" style="text-align:left;">🆕 <b>Anthropic has opened Claude Security, powered by Opus 4.7, as a public beta for enterprise customers</b> to find and patch software flaws. The tool explains vulnerabilities, rates confidence and impact, and generates patch instructions usable in <b>Claude Code</b>. Some <a class="link" href="https://www.databreachtoday.com/anthropic-opens-claude-security-for-wider-public-a-31578?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">experts urge caution about real-world impact</a>, and stricter access remains for the more powerful <b>Mythos</b> model.</p><p class="paragraph" style="text-align:left;">🇰🇵 💸 <b>North Korean-linked hackers spoof fake Zoom/Teams meetings to record and trick cryptocurrency executives</b> — They <a class="link" href="https://www.databreachtoday.com/crypto-targeting-north-koreans-wield-fake-zoom-meetings-a-31516?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">replay stolen or deepfaked video</a>, then push malware or use captured footage to lure more victims. Researchers link the campaign to <i>BlueNoroff/Lazarus</i> and say it helps fund Pyongyang’s illicit activities.</p><p class="paragraph" style="text-align:left;">🦞 ✅ <b>Red Hat engineer Sally O’Malley released </b><i><b>Tank OS</b></i><b>, an open source tool that runs OpenClaw agents </b><a class="link" href="https://techcrunch.com/2026/04/28/red-hats-openclaw-maintainer-just-made-enterprise-claw-deployments-a-lot-safer/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">inside secure, bootable Podman containers</a>. <b><i>Tank OS</i></b> isolates agents, stores credentials safely, and helps IT teams deploy and update many agents across fleets. The tool aims to make enterprise <b>OpenClaw</b> use safer while still requiring technical skill to manage.</p><div class="embed"><a class="embed__url" href="https://www.theverge.com/ai-artificial-intelligence/915660/mythos-script-kiddies-hackers-attack-cybersecurity-ai?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank"><div class="embed__content"><p class="embed__title"> Attack of the killer script kiddies </p><p class="embed__description"> “It’s now or never. There’s a tidal wave coming.” </p><p class="embed__link"> The Verge • Yael Grauer </p></div><img class="embed__image embed__image--right" src="https://platform.theverge.com/wp-content/uploads/sites/2/2026/04/rogers-script-kiddies-Lede-STATIC.jpg?quality=90&strip=all&crop=0%2C10.732984293194%2C100%2C78.534031413613&w=1200"/></a></div><p class="paragraph" style="text-align:left;"></p></div><p class="paragraph" style="text-align:left;"></p><div id="vulnerabilities-research-and-threat" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🐛 🧠 VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</h3><p class="paragraph" style="text-align:left;">➝ From the Patching Department:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/incomplete-windows-patch-opens-door-to-zero-click-attacks/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">Incomplete Windows Patch Opens Door to Zero-Click Attacks</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/no-patch-for-new-phantomrpc-privilege-escalation-technique-in-windows/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">No Patch for New PhantomRPC Privilege Escalation Technique in Windows</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/sonicwall-urges-immediate-patching-of-firewall-vulnerabilities/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">SonicWall Urges Immediate Patching of Firewall Vulnerabilities</a></p></li></ul><hr class="content_break"><p class="paragraph" style="text-align:left;"><i><b>Effective March 27, the IBB program has been paused for new submissions.</b></i></p><p class="paragraph" style="text-align:left;"><i>The Internet Bug Bounty (IBB) program was created to strengthen security in open source and core internet infrastructure projects. From the outset, it was designed to reward both vulnerability discovery and remediation, with 80 percent of rewards supporting new findings and 20 percent supporting remediation efforts. The intent has been to align discovery with effective remediation so that meaningful findings lead to durable security improvements in open source projects.</i></p><p class="paragraph" style="text-align:left;"><i>The discovery landscape is changing. AI-assisted research is expanding vulnerability discovery across the ecosystem, increasing both coverage and speed. The balance between findings and remediation capacity in open source has substantively shifted. We have a responsibility to the community to ensure this program effectively accomplishes its ambitious dual purpose: discovery and remediation. Accordingly, we are pausing submissions while we consider the structure and incentives needed to further these goals.</i></p><p class="paragraph" style="text-align:left;"><i><b>Active IBB submissions will continue through standard review and payout processes without disruption.</b></i></p><p class="paragraph" style="text-align:left;"><i>→ </i><a class="link" href="https://hackerone.com/ibb?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">https://hackerone.com/ibb</a></p><hr class="content_break"><p class="paragraph" style="text-align:left;">🐧 <b>A new Linux bug called </b><i><b>Copy Fail</b></i><b> (CVE-2026-31431) lets a local unprivileged user gain root on kernels</b> from 2017–2026. Researchers released <a class="link" href="https://xint.io/blog/copy-fail-linux-distributions?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">a tiny, reliable exploit </a>that works across major distributions and was fixed in recent kernel updates. Admins should apply kernel patches or disable the <code>AF_ALG</code> crypto interface until updates are installed.</p><p class="paragraph" style="text-align:left;">🐧 <b>A high-severity PackageKit flaw called </b><i><b>Pack2TheRoot</b></i><b> (CVE-2026-41651) lets unprivileged users install RPMs as root</b> without authentication. The <a class="link" href="https://nvd.nist.gov/vuln/detail/CVE-2026-41651?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">bug is a TOCTOU race</a> that corrupts transaction flags so backends run attacker-supplied actions. It affects many Linux distributions but was fixed in <code>PackageKit 1.3.5</code> and patched by major distros.</p><p class="paragraph" style="text-align:left;">💥 <b>A severe authentication bypass in </b><i><b>cPanel</b></i><b> (CVE-2026-41940) is being actively exploited</b> in the wild. <b>cPanel</b> has released patches and detection tools after <a class="link" href="https://cyberscoop.com/cpanel-authentication-bypass-vulnerability-cve-2026-41940-exploited/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">researchers and hosts found attacks</a> that let attackers inject session data to bypass login checks. CISA added the flaw to its Known Exploited Vulnerabilities list and the issue carries a 9.8 CVSS score.</p><p class="paragraph" style="text-align:left;">💥 <b>A critical SQL injection in LiteLLM (CVE-2026-42208) allowed unauthenticated attackers to read and modify</b> its proxy database. Exploitation began <a class="link" href="https://www.sysdig.com/blog/cve-2026-42208-targeted-sql-injection-against-litellms-authentication-path-discovered-36-hours-following-vulnerability-disclosure?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">within 36 hours of disclosure</a>, targeting keys and config data tied to cloud LLM credentials. Users should update to 1.83.7 or enable <code>disable_error_logs</code> to block the attack path.</p><p class="paragraph" style="text-align:left;">🩺 <b>Researchers found 38 vulnerabilities in OpenEMR</b>, an open-source electronic medical records platform used by over 100,000 providers. Many <a class="link" href="https://www.securityweek.com/38-vulnerabilities-found-in-openemr-medical-software/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">flaws were authorization errors, plus XSS, SQL injection, path traversal, and session issues</a>; two critical SQL injection bugs could let attackers steal patient data or run code. All issues have been patched after Aisle’s review, and no public reports show widespread real-world exploitation.</p><p class="paragraph" style="text-align:left;">🔓️ <b>Researchers found a critical GitHub vulnerability (CVE-2026-3854) that let any authenticated user run commands on GitHub servers</b> with a single git push. The flaw exposed millions of public and private repositories and could fully compromise Enterprise Server instances. <b>GitHub</b> <a class="link" href="https://github.blog/security/securing-the-git-push-pipeline-responding-to-a-critical-remote-code-execution-vulnerability/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">patched the issue quickl</a>y and says it found no signs of real-world exploitation, but many Enterprise Server installs remain unpatched.</p><p class="paragraph" style="text-align:left;">🐡 <b>A 15-year-old OpenSSH bug (CVE-2026-35414) lets a comma in a certificate principal bypass access checks</b> and grant root shells. The flaw breaks authorization parsing so attacks do not show as failed logins. <b>OpenSSH</b> <a class="link" href="https://www.openssh.org/releasenotes.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one#10.3p1" target="_blank" rel="noopener noreferrer nofollow">fixed it in version 10.3</a>; update and audit systems now.</p><p class="paragraph" style="text-align:left;">🤗 <b>A critical unpatched flaw (CVE-2026-25874) in Hugging Face’s LeRobot lets unauthenticated attackers</b> run arbitrary code via unsafe pickle deserialization over gRPC. The <a class="link" href="https://thehackernews.com/2026/04/critical-cve-2026-25874-leaves-hugging.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">bug affects the </a><a class="link" href="https://thehackernews.com/2026/04/critical-cve-2026-25874-leaves-hugging.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow"><i>PolicyServer</i></a><a class="link" href="https://thehackernews.com/2026/04/critical-cve-2026-25874-leaves-hugging.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow"> async inference pipeline</a> and can lead to full server compromise, theft of credentials, and impact on connected robots. A fix is planned for v0.6.0, but the issue is currently exploitable in v0.4.3.</p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://www.acronis.com/en/tru/posts/poisoning-the-well-ai-supply-chain-attacks-on-hugging-face-and-openclaw/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">Hugging Face, ClawHub Abused for Malware Distribution</a></p></div><p class="paragraph" style="text-align:left;"></p><div id="ics-ot-io-t" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🛰️ ICS, OT & IoT</h3><p class="paragraph" style="text-align:left;">🤷 <b>CISA&#39;s new guidance adapts zero trust for operational technology but is high-level and vague</b> — Experts say<a class="link" href="https://www.databreachtoday.com/cybersecurity-experts-unimpressed-cisa-ot-guidance-a-31575?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow"> it skips key questions like who will pay and how to prioritize</a> long, costly changes. They warn many OT owners lack resources to implement the recommendations.</p><p class="paragraph" style="text-align:left;">🔓️ <b>Researchers found millions of RDP and VNC servers exposed to the internet</b>, including hundreds that <a class="link" href="https://www.forescout.com/blog/rdp-security-cps-threats-spark-need-for-secure-remote-access/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">give direct access to industrial control systems</a>. Many exposed servers run unsupported Windows, lack authentication, or are vulnerable to known exploits. Attackers have used such access for spying, ransomware, and OT disruption, so organizations should use secure remote access solutions.</p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">💬 CONNECT</h3><p class="paragraph" style="text-align:left;">Follow me on <a class="link" href="https://infosec.exchange/@0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">Mastodon</a> for quick daily updates and bite-sized content.</p><p class="paragraph" style="text-align:left;">Prefer using an RSS feed? Add <b>Infosec MASHUP</b> to your feed <a class="link" href="https://rss.beehiiv.com/feeds/HVhiKYpQlR.xml?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">here</a>.</p><p class="paragraph" style="text-align:center;"><b>Enjoying our newsletter? </b>Forward it to a colleague—<br>it’s one of the best ways to support us.</p><p class="paragraph" style="text-align:left;">Thanks for reading today’s newsletter, and if you&#39;re enjoying it and want to support my work, you can <b>buy me a coffee</b> ☕ over at <a class="link" href="https://www.buymeacoffee.com/0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-18-2026-shinyhunters-week-off-they-didn-t-take-one" target="_blank" rel="noopener noreferrer nofollow">https://www.buymeacoffee.com/0x58</a></p><p class="paragraph" style="text-align:left;"> See you next time!</p><p class="paragraph" style="text-align:left;">-X.</p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=2f84ed7c-6567-4f4a-82ad-82fb8eba0d02&utm_medium=post_rss&utm_source=x_s_infosec_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🕵🏻‍♂️ [InfoSec MASHUP] 17/2026 - Bolt-On Security Won&#39;t Cut It</title>
  <description>Plus: Scattered Spider pleads guilty, a ransomware negotiator on the wrong payroll, and a China-linked backdoor in US federal Cisco firewalls.</description>
  <link>https://infosec-mashup.santolaria.net/p/infosec-mashup-17-2026-bolt-on-security-won-t-cut-it</link>
  <guid isPermaLink="true">https://infosec-mashup.santolaria.net/p/infosec-mashup-17-2026-bolt-on-security-won-t-cut-it</guid>
  <pubDate>Sat, 25 Apr 2026 07:57:00 +0000</pubDate>
  <atom:published>2026-04-25T07:57:00Z</atom:published>
    <dc:creator>Xavier Santolaria</dc:creator>
    <category><![CDATA[Malware]]></category>
    <category><![CDATA[Opensource]]></category>
    <category><![CDATA[Privacy]]></category>
    <category><![CDATA[Cybersecurity]]></category>
    <category><![CDATA[Threat Intelligence]]></category>
    <category><![CDATA[Ai]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><div class="image"><a class="image__link" href="https://infosec.exchange/@lcamtuf/116460019194367182?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/6805aa82-edde-4e2c-b2fe-76639bc1ebac/Screenshot_2026-04-24_at_16.13.16.png?t=1777040022"/></a><div class="image__source"><span class="image__source_text"><p>Figure: @lcamtuf’s <a class="link" href="https://infosec.exchange/@lcamtuf/116460019194367182?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">toot</a>: “I’m sorry folks, but I checked with ICANN and we’re renaming “infosec” to “Mythos hot takes”</p></span></div></div><p class="paragraph" style="text-align:left;">Attackers have AI. So now defenders need AI. So vendors are shipping fast. And somewhere in that chain, someone hands access to a third-party vendor, and <b>Anthropic</b>&#39;s most restricted product ends up in unauthorized hands. This is the new normal: accelerated development, accelerated deployment, and attack surface that grows with every integration.</p><p class="paragraph" style="text-align:left;">The pressure is real — threat actors are using AI to find vulnerabilities faster, craft more convincing phishing, and automate what used to require skill and time. The defensive tooling market is responding accordingly, and Anthropic&#39;s <b>Mythos</b> is just the most visible example of a broader wave. But visibility cuts both ways. The more these tools embed themselves into organizational security infrastructure, the more they become targets themselves. A tool that finds <a class="link" href="https://blog.mozilla.org/en/privacy-security/ai-security-zero-day-vulnerabilities/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">271 Firefox bugs</a> is a tool someone else very much wants access to.</p><p class="paragraph" style="text-align:left;">The answer isn&#39;t to slow down — it&#39;s to stop treating secure architecture as something you bolt on after shipping. Secure development practices, supply chain controls, and disciplined access management aren&#39;t obstacles to speed. They&#39;re what makes speed sustainable. The threat isn&#39;t going to wait for the industry to catch up, but neither will the next vendor breach. Align the pace of deployment with the rigor of the process — or expect to keep reading about it here.</p><p class="paragraph" style="text-align:left;">You know the drill, scroll down to read about this week’s top insights 🚀</p><h2 class="heading" style="text-align:left;">Table of Contents</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="#breaches-security-incidents" rel="noopener noreferrer nofollow">BREACHES & SECURITY INCIDENTS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#cybercrime-cyber-espionage-ap-ts" rel="noopener noreferrer nofollow">CYBERCRIME, CYBER ESPIONAGE, APT’s</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#government-politics-and-privacy" rel="noopener noreferrer nofollow">GOVERNMENT, POLITICS, AND PRIVACY</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#malware-threats" rel="noopener noreferrer nofollow">MALWARE & THREATS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ai-crypto-tech-tools" rel="noopener noreferrer nofollow">AI, CRYPTO, TECH & TOOLS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#vulnerabilities-research-and-threat" rel="noopener noreferrer nofollow">VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ics-ot-io-t" rel="noopener noreferrer nofollow">ICS, OT & IoT</a></p></li></ul><div id="breaches-security-incidents" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🔓 BREACHES & SECURITY INCIDENTS</h3><p class="paragraph" style="text-align:left;">🇫🇷 <b>France’s national agency for identity documents (ANTS) says it suffered a data breach last week</b> that may have exposed personal details like names, emails, birth dates and addresses. A <a class="link" href="https://www.bleepingcomputer.com/news/security/french-govt-agency-confirms-breach-as-hacker-offers-to-sell-data/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">hacker called &quot;</a><a class="link" href="https://www.bleepingcomputer.com/news/security/french-govt-agency-confirms-breach-as-hacker-offers-to-sell-data/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow"><i>breach3d</i></a><a class="link" href="https://www.bleepingcomputer.com/news/security/french-govt-agency-confirms-breach-as-hacker-offers-to-sell-data/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">&quot; claims to be selling up to 19 million records</a>, though the data has not been widely leaked. <b>ANTS</b> notified authorities, says no action is needed now, and warns people to watch for phishing.</p><p class="paragraph" style="text-align:left;">💄 <b>Cosmetics company </b><i><b>Rituals</b></i><b> confirmed hackers stole customer membership data</b> from its database. The breach exposed names, birth dates, contact details, store preferences, and account types <a class="link" href="https://techcrunch.com/2026/04/22/cosmetics-giant-rituals-confirms-data-breach-of-customer-membership-records/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">for customers in Europe, the UK, and some in the U.S.</a>. The company is investigating but has not disclosed how many members were affected or details of the attack.</p><p class="paragraph" style="text-align:left;">🇺🇸 <b>Three U.S. healthcare organizations in Illinois and Texas reported data breaches affecting about 600,000 people</b> — The largest was <b>North Texas Behavioral Health Authority</b> (285,000), followed by <b>Southern Illinois Dermatology</b> (160,000) and <b>Saint Anthony Hospital</b> (146,000). Stolen <a class="link" href="https://www.securityweek.com/data-breaches-at-healthcare-organizations-in-illinois-and-texas-affect-600000/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">data included personal and health information</a>, with intrusions traced to network hacks, ransomware actors, and compromised employee email accounts.</p><p class="paragraph" style="text-align:left;">🇯🇵 🇺🇸 <b>Seiko USA&#39;s website was defaced</b> with a message claiming attackers stole its <b>Shopify</b> customer database. The <a class="link" href="https://www.bleepingcomputer.com/news/security/seiko-usa-website-defaced-as-hacker-claims-customer-data-theft/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">hackers demanded ransom</a> and threatened to publish names, contact details, orders, and shipping addresses. <b>Seiko</b> has not confirmed the breach and removed the extortion message.</p><p class="paragraph" style="text-align:left;">🦋 <b>Bluesky suffered a sophisticated DDoS attack starting April 15 that caused intermittent outages</b> for feeds, notifications, threads, and search. The company <a class="link" href="https://www.securityweek.com/bluesky-disrupted-by-sophisticated-ddos-attack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">said no private user data was accessed</a> and it mitigated the attack after about a day. A group called 313 Team claimed responsibility, but that attribution has not been independently verified.</p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://techcrunch.com/2026/04/20/mastodon-says-its-flagship-server-was-hit-by-a-ddos-attack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">Mastodon says its flagship server was hit by a DDoS attack</a></p><p class="paragraph" style="text-align:left;">🇺🇸 <b>Vercel says attackers gained unauthorized access to some internal systems</b> and a <a class="link" href="https://www.bleepingcomputer.com/news/security/vercel-confirms-breach-as-hackers-claim-to-be-selling-stolen-data/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">limited number of customers may be affected</a>. A threat actor claiming to be <i>ShinyHunters</i> is trying to sell stolen keys, source code, and employee records, and posted screenshots as proof. <b>Vercel</b> is investigating, working with incident responders and law enforcement, and telling customers to rotate secrets and review sensitive environment variables.</p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://www.databreachtoday.com/vercel-traces-customer-data-theft-to-agentic-ai-tool-breach-a-31461?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">Vercel Traces Customer Data Theft to Agentic AI Tool Breach</a></p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://thehackernews.com/2026/04/vercel-finds-more-compromised-accounts.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">Vercel Finds More Compromised Accounts in Context.ai-Linked Breach</a></p></div><p class="paragraph" style="text-align:left;"></p><div id="cybercrime-cyber-espionage-ap-ts" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🥷🏻 CYBERCRIME, CYBER ESPIONAGE, APT’s</h3><div class="embed"><a class="embed__url" href="https://www.zetter-zeroday.com/hwiper-targeting-venezuelas-state-oil-company-discovered/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank"><div class="embed__content"><p class="embed__title"> Mystery Around Venezuelan Cyberattack Deepens, with New Discovery of &quot;Highly Destructive&quot; Wiper </p><p class="embed__description"> The mystery around a cyberattack that struck Venezuela&#39;s state-owned oil company in December is growing, following an announcement by researchers this week that they had discovered a &quot;highly destructive&quot; wiper program that appears to have been designed to target the oil company and may have been used in the December </p><p class="embed__link"> ZERO DAY </p></div><img class="embed__image embed__image--right" src="https://storage.ghost.io/c/77/50/77508a24-24ec-49e5-99f8-d3dadb30a5ac/content/images/size/w1200/2026/04/Screenshot-2026-04-24-at-12.42.29---PM.png"/></a></div><p class="paragraph" style="text-align:left;">🇨🇳 👀 🇺🇸 <b>A China-linked espionage campaign used zero-day flaws to install a persistent backdoor called </b><i><b>Firestarter</b></i> on <b>Cisco</b> firewalls. <b>CISA</b> <a class="link" href="https://www.securityweek.com/us-federal-agencys-cisco-firewall-infected-with-firestarter-backdoor/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">says at least one US federal agency was infected</a> and that firmware patches do not remove the malware. Agencies must upload core dumps for checks, patch, and hard-reset affected devices by the April 2026 deadlines.</p><p class="paragraph" style="text-align:left;">🇨🇳 🇲🇳 <b>A China-aligned APT called </b><i><b>GopherWhisper</b></i><b> infected about 12 Mongolian government systems</b> with multiple Go- and C++‑based backdoors. The group used Discord, Slack, Outlook, and <code>file[.]io</code> for command-and-control and data exfiltration. <b>ESET</b> <a class="link" href="https://www.welivesecurity.com/en/eset-research/gopherwhisper-burrow-full-malware/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">found activity timed to China Standard Time</a>, suggesting the actor’s alignment.</p><p class="paragraph" style="text-align:left;">❌ <b>Spanish police shut down a major Spanish-language manga piracy site</b> that ran since 2014 and served millions of users. They <a class="link" href="https://www.bleepingcomputer.com/news/security/spain-dismantles-major-47m-manga-piracy-platform-arrests-four/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">arrested four people and seized a complex server setup plus crypto wallets</a> holding about $470,000. Authorities say the site made over $4.7 million from ads, harmed rights holders, and exposed minors to pornographic pop-ups.</p><p class="paragraph" style="text-align:left;">🇺🇸 ⚖️ <b>Angelo Martino, a former ransomware negotiator, pleaded guilty</b> to helping the <i><b>ALPHV/BlackCat</b></i> gang extort companies. He <a class="link" href="https://techcrunch.com/2026/04/21/ransomware-negotiator-pleads-guilty-to-helping-ransomware-gang/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">secretly gave criminals victims’ confidential info</a> and shared in ransom profits. He faces up to 20 years in prison and authorities seized $10 million.</p><p class="paragraph" style="text-align:left;">🇺🇸 ⚖️ 🇬🇧 <b>Tyler Robert Buchanan, a 24-year-old British member of the </b><i><b>Scattered Spider</b></i><b> hacking group, pleaded guilty</b> to wire fraud conspiracy and aggravated identity theft. He <a class="link" href="https://krebsonsecurity.com/2026/04/scattered-spider-member-tylerb-pleads-guilty/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">admitted running mass SMS phishing and SIM-swap attacks</a> in 2022 that helped steal millions in cryptocurrency and breach major tech firms. <b>Buchanan</b> is in U.S. custody, faces up to 22 years, and will be sentenced in August 2026.</p><hr class="content_break"><div class="embed"><a class="embed__url" href="https://unit42.paloaltonetworks.com/new-activity-central-south-america/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank"><div class="embed__content"><p class="embed__title"> TGR-STA-1030: New Activity in Central and South America </p><p class="embed__description"> Unit 42 research reports that TGR-STA-1030 remains an active threat, particularly in Central and South America. </p><p class="embed__link"> Unit 42 • Unit 42 </p></div><img class="embed__image embed__image--right" src="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/01_Nation-State-cyberattacks_1505x922.jpg"/></a></div></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;">🗓️ <b><a class="link" href="https://xsa.github.io/infosec-events/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">{Cyber,Info}Sec Events</a></b> — A community-maintained list of infosec conferences worldwide. Subscribe to the <a class="link" href="https://xsa.github.io/infosec-events/events.ics?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">ICS calendar feed</a> to get events straight into your calendar, or follow <a class="link" href="https://infosec.exchange/@infosecevents?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">@infosecevents@infosec.exchange</a> on Mastodon for weekly digests. Contributions and ⭐ welcome!</p></div><p class="paragraph" style="text-align:left;"></p><div id="government-politics-and-privacy" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">👨🏻‍⚖️ 👀 GOVERNMENT, POLITICS, AND PRIVACY</h3><p class="paragraph" style="text-align:left;">🇨🇳 <b>Twelve allied cyber agencies warned that China-linked hackers are building large covert networks from everyday routers</b> and IoT devices. These networks let attackers hide their origin and carry out espionage, malware delivery, and infrastructure pre-positioning. Agencies <a class="link" href="https://cyberscoop.com/china-nexus-covert-networks-advisory/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">urge</a> stronger cybersecurity, active hunting, and sharing threat data to block and map these networks.</p><p class="paragraph" style="text-align:left;">🇺🇸 ☝️ 🗑️ <b>Sean Plankey asked President Trump to withdraw his nomination to lead CISA</b> after a year without Senate confirmation. His <a class="link" href="https://cyberscoop.com/cisa-director-pick-sean-plankey-withdraws-his-nomination/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">renomination faced holds from several senators</a> and was widely seen as stalled. The agency remains led by acting directors amid turnover and proposed budget cuts.</p><p class="paragraph" style="text-align:left;">👀 📲 <b>The U.K. says about 100 countries now have commercial spyware that can hack phones</b> and computers. This tech is easier to get and <a class="link" href="https://techcrunch.com/2026/04/22/uk-government-says-100-countries-have-spyware-that-can-hack-peoples-phones/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">has been used not just on criminals</a> but also on journalists, bankers, and critics. Leaks and cybercriminals mean the tools can spread and threaten many more people.</p><p class="paragraph" style="text-align:left;">🇺🇸 <b>Reports say the NSA is using Anthropic’s restricted Mythos Preview</b> model. Anthropic limited Mythos because it could enable offensive cyberattacks, yet gave access to about 40 organizations. The <b>NSA</b> <a class="link" href="https://techcrunch.com/2026/04/20/nsa-spies-are-reportedly-using-anthropics-mythos-despite-pentagon-feud/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">reportedly uses it to scan for vulnerabilities</a> amid a tense Pentagon-Anthropic dispute.</p></div><p class="paragraph" style="text-align:left;"></p><div id="malware-threats" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🦠 MALWARE & THREATS</h3><p class="paragraph" style="text-align:left;">🔑 <b>Attackers briefly published a malicious </b><code>@bitwarden/cli</code> <b>npm package that stole developer credentials</b> and could spread to other projects. The malware harvested tokens, SSH keys, and cloud credentials, then exfiltrated encrypted data to public GitHub repos. <b>Bitwarden</b> removed the release, revoked access, and <a class="link" href="https://community.bitwarden.com/t/bitwarden-statement-on-checkmarx-supply-chain-incident/96127?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">says only users who installed that version</a> were affected.</p><p class="paragraph" style="text-align:left;">🐧 <b>A new Linux </b><i><b>GoGra</b></i><b> backdoor uses Microsoft Graph API and Outlook mailboxes</b> to receive commands and return results. It authenticates with hardcoded Azure AD credentials, hides as a Conky autostart, and runs ELF files disguised as PDFs. <b>Symantec</b> <a class="link" href="https://www.security.com/blog-post/harvester-new-linux-backdoor-gogra?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">links</a> this tool to the <i><b>Harvester</b></i> espionage group, showing they are expanding to Linux targets.</p><p class="paragraph" style="text-align:left;">🍎 🛍️ <b>Security researcher Kaspersky found 26 fake crypto wallet apps on Apple’s App Store</b> that steal recovery phrases and private keys. The <a class="link" href="https://securelist.com/fakewallet-cryptostealer-ios-app-store/119474/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow"><i>FakeWallet</i></a><a class="link" href="https://securelist.com/fakewallet-cryptostealer-ios-app-store/119474/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow"> campaign</a> used typosquatting and phishing links to trick users, mainly targeting Chinese users but with no strict regional limits. <b>Apple</b> has been notified and is removing the malicious apps.</p><p class="paragraph" style="text-align:left;">🎩 <b>Researchers found </b><i><b>Gentlemen</b></i><b> ransomware affiliates using the SystemBC botnet of over 1,570 infected hosts</b> to relay and deliver payloads. The gang’s RaaS encrypts many systems and now pairs Cobalt Strike, credential theft, and proxy infrastructure for targeted corporate attacks. <b>Check Point </b><a class="link" href="https://research.checkpoint.com/2026/dfir-report-the-gentlemen/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">warns this integration signals the group is scaling up</a> and offers IoCs and detections for defenders.</p><p class="paragraph" style="text-align:left;">🔙 🚪 <b>Threat actors are abusing the QEMU emulator to hide backdoors and deliver ransomware</b> and remote access tools. They <a class="link" href="https://www.sophos.com/en-us/blog/qemu-abused-to-evade-detection-and-enable-ransomware-delivery?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">exploit VPN and server vulnerabilities</a> to run <b>QEMU</b> VMs with system privileges, create reverse SSH tunnels, and steal credentials and AD data. Organizations should hunt for unauthorized <b>QEMU</b> installs, rogue scheduled tasks, strange port forwarding, and outbound SSH tunnels.</p></div><p class="paragraph" style="text-align:left;"></p><div id="ai-crypto-tech-tools" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🤖 🧰 AI, CRYPTO, TECH & TOOLS</h3><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/j51uMah-3js" width="100%"></iframe><hr class="content_break"><div class="embed"><a class="embed__url" href="https://www.schneier.com/blog/archives/2026/04/mythos-and-cybersecurity.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank"><div class="embed__content"><p class="embed__title"> Mythos and Cybersecurity - Schneier on Security </p><p class="embed__description"> Last week, Anthropic pulled back the curtain on Claude Mythos Preview, an AI model so capable at finding and exploiting software vulnerabilities that the company decided it was too dangerous to release to the public. Instead, access has been restricted to roughly 50 organizations—Microsoft, Apple, Amazon Web Services, CrowdStrike and other vendors of critical infrastructure—under an initiative called Project Glasswing. The announcement was accompanied by a barrage of hair-raising anecdotes: thousands of vulnerabilities uncovered across every major... </p><p class="embed__link"> Schneier on Security • B. Schneier </p></div></a></div><p class="paragraph" style="text-align:left;">🔓️ <b>Reporters say an unidentified online group accessed Anthropic’s new enterprise security tool, </b><i><b>Mythos</b></i>, via a third-party vendor. <b>Anthropic</b> says it <a class="link" href="https://techcrunch.com/2026/04/21/unauthorized-group-has-gained-access-to-anthropics-exclusive-cyber-tool-mythos-report-claims/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">is investigating </a>and has found no sign its own systems were breached. The group shared screenshots and demonstrations after getting in.</p><p class="paragraph" style="text-align:left;">🇰🇵 💸 <b>Hackers stole over $290 million in cryptocurrency from Kelp DAO</b> — LayerZero says <a class="link" href="https://techcrunch.com/2026/04/20/north-korea-hackers-blamed-for-290m-crypto-theft/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">preliminary evidence points to North Korea’s </a><a class="link" href="https://techcrunch.com/2026/04/20/north-korea-hackers-blamed-for-290m-crypto-theft/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow"><i>TraderTraitor</i></a> group using a bridge exploit and weak approval settings. <b>Kelp DAO</b> disputes LayerZero’s blame.</p><div class="embed"><a class="embed__url" href="https://www.platformer.news/meta-mci-monitoring-layoffs-knowledge-work/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank"><div class="embed__content"><p class="embed__title"> The week that Meta employees became training data </p><p class="embed__description"> Invasive monitoring and a fresh round of layoffs have workers I spoke to on edge. Is this the future of knowledge work? </p><p class="embed__link"> Platformer </p></div><img class="embed__image embed__image--right" src="https://storage.ghost.io/c/a0/4c/a04c7225-d919-4d78-9b7c-a3fdd071349b/content/images/size/w1200/2026/04/shutterstock_2452456231.jpg"/></a></div></div><p class="paragraph" style="text-align:left;"></p><div id="vulnerabilities-research-and-threat" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🐛 🧠 VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</h3><p class="paragraph" style="text-align:left;">➝ From the Patching Department:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://thehackernews.com/2026/04/google-patches-antigravity-ide-flaw.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">Google Patches Antigravity IDE Flaw Enabling Prompt Injection Code Execution</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-emergency-security-updates-for-critical-aspnet-flaw/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">Microsoft releases emergency patches for critical ASP.NET flaw</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/oracle-patches-450-vulnerabilities-with-april-2026-cpu/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">Oracle Patches 450 Vulnerabilities With April 2026 CPU</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/progress-patches-multiple-vulnerabilities-in-moveit-waf-loadmaster/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">Progress Patches Multiple Vulnerabilities in MOVEit WAF, LoadMaster</a></p></li></ul><hr class="content_break"><div class="embed"><a class="embed__url" href="https://chaos.social/@icing/116452666979094476?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank"><div class="embed__content"><p class="embed__title"> Stefan Eissing (@icing@chaos.social) </p><p class="embed__description"> A security audit of Rust Coreutils found 70 CVEs. 44 of these could be fixed for release 0.8. The rest remain unfixed and undisclosed for now. Ubuntu 26.04 LTS has added Rust Coreutils EXCEPT the cp, mv, and rm commands. I assume most of the remaining 26 CVEs are therefore in cp, mv and rm. How is your „let‘s rewrite it in Rust“ project going? https://www.phoronix.com/news/Ubuntu-Rust-Coreutils-Audit Update: Rust coreutils has contributed to the GNU test cases. </p><p class="embed__link"> chaos.social </p></div></a></div><p class="paragraph" style="text-align:left;">💥 <b>A privilege-escalation flaw in Microsoft Defender called </b><i><b>BlueHammer</b></i> (CVE-2026-33825) was publicly disclosed and patched April 14. Attackers used the published PoC to exploit the bug and other related techniques (RedSun, UnDefend) to try gaining System privileges. <b>Huntress</b> and <b>CISA</b> reported <a class="link" href="https://www.huntress.com/blog/nightmare-eclipse-intrusion?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">active attempts</a> involving compromised VPN access and urged immediate patching.</p><p class="paragraph" style="text-align:left;">🩹 🐛 <b>Apple released iOS and iPadOS updates to fix a bug that kept deleted message previews</b> on devices. The <a class="link" href="https://techcrunch.com/2026/04/22/apple-fixes-bug-that-cops-used-to-extract-deleted-chat-messages-from-iphones/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">flaw let cached notifications (including Signal chats) be recovered with forensic tools</a> and was reportedly used by law enforcement. Installing the new patches removes the saved previews and prevents future retention.</p><p class="paragraph" style="text-align:left;">🦊 <b>Anthropic’s Claude Mythos found 271 potential Firefox bugs</b>, and <a class="link" href="https://blog.mozilla.org/en/privacy-security/ai-security-zero-day-vulnerabilities/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">Mozilla patched many issues in Firefox 150</a>. Only three were given public CVEs, so most were lower-severity or non-exploitable findings. Security firms warn advanced AI can rapidly find and chain vulnerabilities, increasing risk if not controlled.</p></div><p class="paragraph" style="text-align:left;"></p><div id="ics-ot-io-t" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🛰️ ICS, OT & IoT</h3><p class="paragraph" style="text-align:left;">🦠 <b>Dragos says the new </b><i><b>ZionSiphon</b></i><b> malware that supposedly targets Israeli water plants is overhyped</b> — The code is broken, likely AI-generated, and shows little understanding of industrial control systems. Focusing on this <a class="link" href="https://cyberscoop.com/dragos-zionsiphon-ai-malware-targeting-water-sector-hype/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">distracts defenders from real threats</a> like <i>Volt Typhoon</i>.</p><p class="paragraph" style="text-align:left;">🐛 <b>Researchers found serious vulnerabilities in serial-to-IP converters</b> that let attackers run code, tamper firmware, and take over devices. These converters <a class="link" href="https://www.securityweek.com/serial-to-ip-converter-flaws-expose-ot-and-healthcare-systems-to-hacking/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">connect old industrial and healthcare gear to networks and thousands are exposed</a> online. Patches are available from vendors, but unpatched devices could let hackers manipulate sensors or disrupt care and critical systems.</p><p class="paragraph" style="text-align:left;"><b>🛜 A Mirai botnet is exploiting a year-old command injection flaw (</b><a class="link" href="https://nvd.nist.gov/vuln/detail/CVE-2025-29635?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow"><b>CVE-2025-29635</b></a><b>) in discontinued D-Link DIR-823X</b> routers. Attackers <a class="link" href="https://www.akamai.com/blog/security-research/2026/apr/cve-2025-29635-mirai-campaign-targets-d-link-devices?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">use crafted POST requests</a> to run a shell script that downloads a Mirai-like payload. <b>D-Link</b> says these routers are end-of-life and should be retired.</p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://www.securityweek.com/hackers-fail-to-exploit-flaw-in-discontinued-tp-link-routers/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">Hackers Fail to Exploit Flaw in Discontinued TP-Link Routers</a></p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">💬 CONNECT</h3><p class="paragraph" style="text-align:left;">Follow me on <a class="link" href="https://infosec.exchange/@0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">Mastodon</a> for quick daily updates and bite-sized content.</p><p class="paragraph" style="text-align:left;">Prefer using an RSS feed? Add <b>Infosec MASHUP</b> to your feed <a class="link" href="https://rss.beehiiv.com/feeds/HVhiKYpQlR.xml?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">here</a>.</p><p class="paragraph" style="text-align:center;"><b>Enjoying our newsletter? </b>Forward it to a colleague—<br>it’s one of the best ways to support us.</p><p class="paragraph" style="text-align:left;">Thanks for reading today’s newsletter, and if you&#39;re enjoying it and want to support my work, you can <b>buy me a coffee</b> ☕ over at <a class="link" href="https://www.buymeacoffee.com/0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-17-2026-bolt-on-security-won-t-cut-it" target="_blank" rel="noopener noreferrer nofollow">https://www.buymeacoffee.com/0x58</a></p><p class="paragraph" style="text-align:left;"> See you next time!</p><p class="paragraph" style="text-align:left;">-X.</p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=a6f067b3-a6f7-4f71-b800-af33d045c1fb&utm_medium=post_rss&utm_source=x_s_infosec_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🕵🏻‍♂️ [InfoSec MASHUP] 16/2026 - Faster Bugs, Same Backlog</title>
  <description>Plus: AI vishing platforms hit the cybercrime market, NIST quietly caps CVE coverage, and Russia goes after a Swedish power grid.</description>
  <link>https://infosec-mashup.santolaria.net/p/infosec-mashup-16-2026-faster-bugs-same-backlog</link>
  <guid isPermaLink="true">https://infosec-mashup.santolaria.net/p/infosec-mashup-16-2026-faster-bugs-same-backlog</guid>
  <pubDate>Sat, 18 Apr 2026 08:36:00 +0000</pubDate>
  <atom:published>2026-04-18T08:36:00Z</atom:published>
    <dc:creator>Xavier Santolaria</dc:creator>
    <category><![CDATA[Malware]]></category>
    <category><![CDATA[Opensource]]></category>
    <category><![CDATA[Privacy]]></category>
    <category><![CDATA[Cybersecurity]]></category>
    <category><![CDATA[Threat Intelligence]]></category>
    <category><![CDATA[Ai]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><b>Mythos</b> <b>Preview</b> found thousands of zero-days across every major OS and browser in a matter of weeks. Anthropic was nervous enough about it to not release it publicly. That&#39;s notable. What&#39;s also notable is that &quot;<i>thousands of critical vulnerabilities</i>&quot; describes a perfectly ordinary patch Tuesday for most security teams — the backlog isn&#39;t new, the speed is.</p><p class="paragraph" style="text-align:left;">The uncomfortable truth <b><a class="link" href="https://www.anthropic.com/glasswing?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">Project Glasswing</a></b> surfaces isn&#39;t that attackers are about to get a superpower (they are), it&#39;s that defenders have been relying on a fundamentally broken triage model for years. CVSS 10 gets the fire drill. The exploitable CVSS 6 sitting on an internet-facing legacy box gets the backlog. That gap is the actual attack surface. AI-accelerated discovery doesn&#39;t fix it — it just makes it more expensive to ignore.</p><p class="paragraph" style="text-align:left;">Let’s now dive into this week’s top insights! 🚀</p><h2 class="heading" style="text-align:left;">Table of Contents</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="#breaches-security-incidents" rel="noopener noreferrer nofollow">BREACHES & SECURITY INCIDENTS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#cybercrime-cyber-espionage-ap-ts" rel="noopener noreferrer nofollow">CYBERCRIME, CYBER ESPIONAGE, APT’s</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#government-politics-and-privacy" rel="noopener noreferrer nofollow">GOVERNMENT, POLITICS, AND PRIVACY</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#malware-threats" rel="noopener noreferrer nofollow">MALWARE & THREATS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ai-crypto-tech-tools" rel="noopener noreferrer nofollow">AI, CRYPTO, TECH & TOOLS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#vulnerabilities-research-and-threat" rel="noopener noreferrer nofollow">VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ics-ot-io-t" rel="noopener noreferrer nofollow">ICS, OT & IoT</a></p></li></ul><div id="breaches-security-incidents" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🔓 BREACHES & SECURITY INCIDENTS</h3><p class="paragraph" style="text-align:left;">🇺🇸 <b>Medical device maker Stryker said a March 11 cyberattack disrupted operations and will affect first-quarter results</b> — The <a class="link" href="https://www.databreachtoday.com/stryker-hack-affects-first-quarter-results-a-31444?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">company says it has no cyber insurance</a> and faces lawsuits and data theft claims. Hacktivists claim they wiped devices and exfiltrated large amounts of <b>Stryker</b> data.</p><p class="paragraph" style="text-align:left;">💸 <b>Kraken says criminals are extorting them</b> with videos showing limited internal support-system access. The company says systems were not breached, funds are safe, and about 2,000 accounts (0.02%) had limited support-data exposure. <b>Kraken</b> revoked access, will not pay, and is working with law enforcement to prosecute those responsible.</p><blockquote align="center" class="twitter-tweet"><a href="https://twitter.com/c7five/status/2043720915330969743?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog"><p> Twitter tweet </p></a></blockquote><p class="paragraph" style="text-align:left;">🇺🇸 <b>McGraw-Hill says hackers exploited a Salesforce misconfiguration to access a limited set of data</b> on a hosted webpage. The company <a class="link" href="https://www.bleepingcomputer.com/news/security/mcgraw-hill-confirms-data-breach-following-extortion-threat/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">insists</a> no Salesforce accounts, customer databases, student records, SSNs, or financial data were exposed. Extortion group <i>ShinyHunters</i> claims a much larger haul and threatened to leak data.</p><p class="paragraph" style="text-align:left;">🇺🇸 <b>Cookeville Regional Medical Center in Tennessee suffered a ransomware attack</b> that exposed personal and medical data. The breach, <a class="link" href="https://www.securityweek.com/data-breach-at-tennessee-hospital-affects-337000/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">discovered July 14, 2025, affects over 337,000 people</a> and may include SSNs, medical records, and financial details. The hackers leaked about 500 GB of stolen data after failing to sell it.</p><p class="paragraph" style="text-align:left;">✈️ <b>Booking.com says hackers may have accessed customers’ personal data</b> like names, emails, addresses, phone numbers, and booking details. Some <a class="link" href="https://techcrunch.com/2026/04/13/booking-com-confirms-hackers-accessed-customers-data/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">customers reported receiving phishing messages</a> that used stolen booking information. The company says it contained the issue, updated reservation PINs, and that financial data was not accessed.</p><p class="paragraph" style="text-align:left;">🪩 🕺 <b>RCI Hospitality disclosed a data breach after an IDOR vulnerability in an IIS web server</b> allowed unauthorized access starting March 19. The exposed data included names, birth dates, contact info, SSNs, and driver’s license numbers of many independent contractors. The <a class="link" href="https://www.securityweek.com/nightclub-giant-rci-hospitality-reports-data-breach/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">company says customer and financial systems were not affected</a> and it does not expect a material impact.</p><p class="paragraph" style="text-align:left;">🇪🇺 🏋️‍♂️ <b>Dutch gym chain </b><i><b>Basic-Fit</b></i><b> says hackers accessed data for about 1 million members</b> across several European countries. Exposed information includes names, addresses, emails, phone numbers, birthdates, bank details, and membership data. The <a class="link" href="https://www.bleepingcomputer.com/news/security/european-gym-giant-basic-fit-data-breach-affects-1-million-members/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">company stopped the intrusion quickly</a>, informed affected members, and is investigating with external security experts.</p></div><div id="cybercrime-cyber-espionage-ap-ts" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🥷🏻 CYBERCRIME, CYBER ESPIONAGE, APT’s</h3><p class="paragraph" style="text-align:left;">❌ <b>Law enforcement from 21 countries seized 53 DDoS-for-hire domains and arrested four people</b> in <i>Operation PowerOFF</i>. They <a class="link" href="https://cyberscoop.com/ddos-for-hire-takedowns-operation-poweroff/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">recovered data on over 3 million user accounts</a> and warned more than 75,000 alleged participants to stop. The operation disrupted infrastructure used to launch attacks that target websites, networks, and services.</p><p class="paragraph" style="text-align:left;">🇰🇵 ➡️ 🇺🇸 <b>Two U.S. citizens were sentenced to prison for helping North Korea place fake IT workers</b> in American companies. The scheme used laptop farms and stolen identities to steal about $5 million and access U.S. company systems. The <a class="link" href="https://techcrunch.com/2026/04/16/two-americans-sentenced-for-helping-north-korea-steal-5-million-in-fake-it-worker-scheme/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">operation helped fund North Korea</a> and risked U.S. national security.</p><p class="paragraph" style="text-align:left;">❌ <b>The FBI says it dismantled a global phishing operation called </b><i><b>W3LL</b></i><b> that targeted over 17,000 victims</b> — Authorities <a class="link" href="https://techcrunch.com/2026/04/13/fbi-announces-takedown-of-phishing-operation-that-targeted-thousands-of-victims/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">arrested the alleged developer and seized key domains</a> after working with Indonesian police. The <b>W3LL</b> kit let criminals buy fake login pages and sell stolen credentials, enabling millions in attempted fraud.</p><p class="paragraph" style="text-align:left;">🇹🇭 🇩🇪 <b>Bangkok police arrested 27-year-old German Noah Christopher, wanted on 74 European warrants</b> for <a class="link" href="https://www.bangkokpost.com/thailand/general/3235285/german-hacker-facing-74-cybercrime-warrants-arrested-in-bangkok?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">running ransomware and cyberattack-for-hire</a> platforms. Investigators say he developed services that enabled global DDoS attacks and ransom payments in cryptocurrency. His visa was revoked and he is held for extradition to Germany.</p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;">🗓️ <b><a class="link" href="https://xsa.github.io/infosec-events/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">{Cyber,Info}Sec Events</a></b> — A community-maintained list of infosec conferences worldwide. Subscribe to the <a class="link" href="https://xsa.github.io/infosec-events/events.ics?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">ICS calendar feed</a> to get events straight into your calendar, or follow <a class="link" href="https://infosec.exchange/@infosecevents?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">@infosecevents@infosec.exchange</a> on Mastodon for weekly digests. Contributions and ⭐ welcome!</p></div><p class="paragraph" style="text-align:left;"></p><div id="government-politics-and-privacy" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">👨🏻‍⚖️ 👀 GOVERNMENT, POLITICS, AND PRIVACY</h3><div class="embed"><a class="embed__url" href="https://www.404media.co/google-microsoft-meta-all-tracking-you-even-when-you-opt-out-according-to-an-independent-audit/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank"><div class="embed__content"><p class="embed__title"> Google, Microsoft, Meta All Tracking You Even When You Opt Out, According to an Independent Audit </p><p class="embed__description"> “This is the Strait of Hormuz in the data economy. If you want to make a change, this is where you cut it off. Anything short of that is theatrical political posture.” </p><p class="embed__link"> 404 Media </p></div><img class="embed__image embed__image--right" src="https://storage.ghost.io/c/0f/76/0f76b548-bc58-4f25-abc3-3f5ebca07da4/content/images/size/w1200/2026/04/photo-1613987750911-f768497fb94b.jpeg"/></a></div><p class="paragraph" style="text-align:left;">🇺🇸 <b>Nicholas Moore admitted hacking the U.S. Supreme Court’s electronic filing system</b> and other government networks. He posted stolen personal data online and used a victim’s login to break in. He was <a class="link" href="https://techcrunch.com/2026/04/17/man-who-hacked-us-supreme-court-filing-system-sentenced-to-probation/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">sentenced to one year of probation</a> after prosecutors sought no prison time.</p><p class="paragraph" style="text-align:left;">🇺🇸 ❌ 🎒 <b>CISA has canceled this year’s CyberCorps summer internships because DHS is unfunded</b> — This <a class="link" href="https://cyberscoop.com/cisa-cancels-cybercorps-internships-dhs-funding-crisis/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">leaves Scholarship for Service students without required placements</a> and disrupts their career plans. Officials say agencies are working to place or defer students once the shutdown ends.</p><p class="paragraph" style="text-align:left;">🇺🇸 <b>Senator Markwayne Mullin’s confirmation as Homeland Security Secretary is important, but CISA still lacks</b> a Senate-confirmed director. Sean Plankey, a qualified cybersecurity leader, should be confirmed to close that gap. <a class="link" href="https://cyberscoop.com/national-security-ntsc-op-ed-sean-plankey-cisa-confirmed-director/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">Rising global cyber threats make CISA leadership urgent</a> for national security.</p></div><p class="paragraph" style="text-align:left;"></p><div id="malware-threats" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🦠 MALWARE & THREATS</h3><p class="paragraph" style="text-align:left;">💧 <i><b>ZionSiphon</b></i><b> is new malware aimed at sabotaging water treatment</b> and desalination systems. It <a class="link" href="https://www.darktrace.com/blog/inside-zionsiphon-darktraces-analysis-of-ot-malware-targeting-israeli-water-systems?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">can raise chlorine levels and change pressure</a> by editing control files, but a coding error currently prevents it from working. Researchers warn future fixes could make it dangerous, especially against Israeli targets.</p><p class="paragraph" style="text-align:left;">🇺🇦 🏥 <b>CERT-UA says a group called UAC-0247 ran a malware campaign from March–April 2026 targeting Ukrainian clinics, hospitals</b>, and government to steal data from Chromium browsers and <b>WhatsApp</b>. Attackers used <a class="link" href="https://thehackernews.com/2026/04/uac-0247-targets-ukrainian-clinics-and.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">phishing links to deliver LNK/HTA files</a> that load loaders (RAVENSHELL, AGINGFLY, SILENTLOOP) and tools to exfiltrate credentials, run commands, and tunnel traffic. <b>CERT-UA</b> advises blocking execution of LNK, HTA, JS and tools like <code>mshta.exe</code>, <code>powershell.exe</code>, and <code>wscript.exe</code> to reduce risk.</p><p class="paragraph" style="text-align:left;">⚠️ 🎠 <b>A fake Claude website tricked users into downloading a trojanized installer</b> that looks like the real <b>Anthropic</b> app. The installer runs a VBScript that sideloads a signed updater to <a class="link" href="https://www.malwarebytes.com/blog/scams/2026/04/fake-claude-site-installs-malware-that-gives-attackers-access-to-your-computer?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">deploy the PlugX remote access trojan</a>. PlugX connects to a C2 server and persists via startup files, hiding its traces and making attribution difficult.</p><p class="paragraph" style="text-align:left;">🎠 🏦 <i><b>JanelaRAT</b></i><b> is a banking trojan that targets Latin American banks, stealing financial and crypto data</b> and monitoring user activity. In 2025, <b>Kaspersky</b> <a class="link" href="https://securelist.com/janelarat-financial-threat-in-latin-america/119332/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">recorded 14,739 attacks in Brazil and 11,695 in Mexic</a>o, with infections spread via phishing, ZIPs, VBScript, and malicious MSI installers using DLL side‑loading. The malware uses browser extensions, window-title detection, overlays, keystroke capture, and remote commands to harvest credentials and evade detection.</p><p class="paragraph" style="text-align:left;">🧩 <b>Researchers found 108 malicious Chrome extensions that share the same backend and steal user data</b> while injecting ads and scripts. About <a class="link" href="https://socket.dev/blog/108-chrome-ext-linked-to-data-exfil-session-theft-shared-c2?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">20,000 installs across five publisher identities </a>exfiltrate <b>Google</b> and <b>Telegram</b> credentials and bypass security headers. Users should remove these extensions and log out of <b>Telegram</b> Web immediately.</p><p class="paragraph" style="text-align:left;">🇰🇵 🎠 <b>North Korea-linked APT37 used fake Facebook accounts to befriend targets</b> and move them to <b>Messenger</b> and <b>Telegram</b>. They <a class="link" href="https://www.genians.co.kr/en/blog/threat_intelligence/pretexting?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">tricked victims into installing a tampered Wondershare PDF viewer</a> that ran shellcode and fetched a JPG carrying <b>RokRAT</b>. The malware used compromised legitimate sites and cloud services for stealthy command-and-control and remote access.</p><p class="paragraph" style="text-align:left;">🎠 <b>Attackers briefly hacked CPUID’s site to replace CPU-Z and HWMonitor downloads with trojanized installers</b> that delivered a malicious DLL. The DLL installed STX RAT, a <a class="link" href="https://securelist.com/tr/cpu-z/119365/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">remote-access trojan that steals data</a> and enables full remote control. Over 150 victims — mainly in Brazil, Russia, and China — were hit before the compromise was detected.</p><blockquote align="center" class="twitter-tweet"><a href="https://twitter.com/d0cTB/status/2042520961824559150?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog"><p> Twitter tweet </p></a></blockquote></div><p class="paragraph" style="text-align:left;"></p><div id="ai-crypto-tech-tools" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🤖 🧰 AI, CRYPTO, TECH & TOOLS</h3><div class="embed"><a class="embed__url" href="https://open.substack.com/pub/ventureinsecurity/p/ai-might-be-killing-traditional-siems?utm_campaign=post-expanded-share&utm_medium=web" target="_blank"><div class="embed__content"><p class="embed__title"> AI might be killing traditional SIEMs, but data advantage is as strong as ever </p><p class="embed__description"> A few thoughts about how AI agents are fundamentally changing SIEM and adjacent markets, and what this means for the future </p><p class="embed__link"> Ross Haleliuk </p></div><img class="embed__image embed__image--right" src="https://substackcdn.com/image/fetch/$s_!eoFN!,w_1200,h_675,c_fill,f_jpg,q_auto:good,fl_progressive:steep,g_auto/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F346af407-6624-49de-ab4e-8615fba3a5af_2000x1333.png"/></a></div><p class="paragraph" style="text-align:left;">⏩️ 🐛 <b>Top cyber groups in the US and UK warn Claude </b><i><b>Mythos</b></i><b> and similar AIs make finding and weaponizing vulnerabilities</b> much faster, lowering the skill needed for serious attacks. Tests show <b>Mythos</b> can solve many expert-level challenges and complete large multi-step simulated attacks on weak networks. Experts say <a class="link" href="https://cyberscoop.com/claude-mythos-ai-cybersecurity-threat-report/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">defenders face harder, slower fixes</a> because organizations must balance bureaucracy and legacy tech against fast, automated threats.</p><p class="paragraph" style="text-align:left;">📞 🎠 <b>A cybercrime platform called ATHR consolidates the entire TOAD (telephone-oriented attack delivery) kill chain into a single AI-powered product</b>, sold on criminal networks for $4,000 plus a cut of profits. It ships with a built-in spoofing mailer, brand-accurate phishing panels for eight platforms (including Coinbase, Google, and Microsoft), and AI voice agents that <a class="link" href="https://abnormal.ai/blog/athr-ai-voice-phishing-toad-attacks?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">handle the full social engineering call without a human operator</a>. Lure emails pass SPF, DKIM, and DMARC checks, carry no malicious links, and are personalized per target — leaving traditional email security controls with almost nothing to flag.</p><p class="paragraph" style="text-align:left;">🐛 <b>A design flaw in Anthropic’s Model Context Protocol (MCP) STDIO implementation can let attackers run commands</b> and take over local systems. <a class="link" href="https://20204725.hs-sites.com/the-mother-of-all-ai-supply-chains?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">OX Security showed the flaw is widely inherited</a>, easily exploitable, and exposes millions of users and sensitive data. <b>Anthropic</b> has not fixed the root cause, only issued cautious guidance, leaving developers to shoulder the security risk.</p><p class="paragraph" style="text-align:left;">🆕 <b>OpenAI released GPT-5.4-Cyber, a version of GPT‑5.4 tuned for defensive cybersecurity</b> — They are expanding Trusted Access for Cyber to many verified defenders and teams. <b>OpenAI</b> <a class="link" href="https://openai.com/index/scaling-trusted-access-for-cyber-defense/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">says this aims to speed fixes</a> while limiting misuse through careful, controlled rollout and stronger safeguards.</p><p class="paragraph" style="text-align:left;">🍎 <b>OpenAI found a GitHub Actions workflow used to sign its macOS apps downloaded a malicious Axios package</b> but says <a class="link" href="https://openai.com/index/axios-developer-tool-compromise/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">no user data was accessed</a>. It is revoking and rotating the signing certificate and will block older macOS app versions after May 8, 2026. The <b>Axios</b> and related <b>Trivy</b> supply-chain attacks exposed stolen secrets and widespread risk across open-source ecosystems.</p><div class="embed"><a class="embed__url" href="https://opensource.microsoft.com/blog/2026/04/02/introducing-the-agent-governance-toolkit-open-source-runtime-security-for-ai-agents/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank"><div class="embed__content"><p class="embed__title"> Introducing the Agent Governance Toolkit: Open-source runtime security for AI agents | Microsoft Open Source Blog </p><p class="embed__description"> Discover how the Microsoft Agent Governance Toolkit brings policy, identity, and reliability to autonomous AI agent systems. </p><p class="embed__link"> Microsoft Open Source Blog • Imran Siddique </p></div><img class="embed__image embed__image--right" src="https://opensource.microsoft.com/blog/wp-content/uploads/2024/06/CLO19_Ubisoft_Azure_055.png"/></a></div><p class="paragraph" style="text-align:left;">💸 <b>An international law enforcement action called </b><i><b>Operation Atlantic</b></i><b> identified over 20,000 victims of cryptocurrency fraud</b> across Canada, the U.K., and the U.S. Authorities <a class="link" href="https://www.nationalcrimeagency.gov.uk/news/fraudsters-targeting-cryptocurrency-stopped-and-12-million-frozen-in-nca-led-operation-atlantic?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">froze more than $12 million and traced over $45 million in stolen crypto</a> while disrupting approval-phishing and investment scams. Officials said public-private cooperation was key and vowed to keep pursuing criminals and helping victims.</p><p class="paragraph" style="text-align:left;">🔓️ <b>A severe bug in GitHub Copilot Chat let attackers hide instructions in pull requests to make the AI steal secrets</b> from private repos. The stolen data was exfiltrated covertly through GitHub’s own image proxy, bypassing normal network controls. This <a class="link" href="https://www.blackfog.com/camoleak-how-github-copilot-became-an-exfiltration-channel/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">attack shows AI assistants with context access can be abused</a> for data theft and requires new endpoint defenses.</p><hr class="content_break"><blockquote align="center" class="twitter-tweet"><a href="https://twitter.com/ryanaraine/status/2043714427091046636?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog"><p> Twitter tweet </p></a></blockquote></div><p class="paragraph" style="text-align:left;"></p><div id="vulnerabilities-research-and-threat" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🐛 🧠 VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</h3><p class="paragraph" style="text-align:left;">➝ From the Patching Department:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/adobe-patches-reader-zero-day-exploited-for-months/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">Adobe Patches Reader Zero-Day Exploited for Months</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/adobe-patches-55-vulnerabilities-across-11-products/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">Adobe Patches 55 Vulnerabilities Across 11 Products</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://cyberscoop.com/ai-generated-breach-narratives-ghost-threat-vector-op-ed/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">Cisco Patches Critical Vulnerabilities in Webex, ISE</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/fortinet-patches-critical-fortisandbox-vulnerabilities/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">Fortinet Patches Critical FortiSandbox Vulnerabilities</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2026-patch-tuesday-fixes-167-flaws-2-zero-days/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">Microsoft April 2026 Patch Tuesday fixes 167 flaws, 2 zero-days</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/sap-patches-critical-abap-vulnerability/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">SAP Patches Critical ABAP Vulnerability</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/splunk-enterprise-update-patches-code-execution-vulnerability/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">Splunk Enterprise Update Patches Code Execution Vulnerability</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://thehackernews.com/2026/04/new-php-composer-flaws-enable-arbitrary.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">New PHP Composer Flaws Enable Arbitrary Command Execution — Patches Released</a></p></li></ul><hr class="content_break"><div class="embed"><a class="embed__url" href="https://unit42.paloaltonetworks.com/exploitation-of-cve-2023-33538/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank"><div class="embed__content"><p class="embed__title"> A Deep Dive Into Attempted Exploitation of CVE-2023-33538 </p><p class="embed__description"> CVE-2023-33538 allows for command injection in TP-Link routers. We discuss exploitation attempts with payloads characteristic of Mirai botnet malware. </p><p class="embed__link"> Unit 42 • Asher Davila, Malav Vyas, Chris Navarrete </p></div><img class="embed__image embed__image--right" src="https://origin-unit42.paloaltonetworks.com/wp-content/uploads/2026/04/04_Vulnerabilities_1920x900.jpg"/></a></div><p class="paragraph" style="text-align:left;">🎯 <b>NIST will only prioritize detailed analysis for CVEs tied to exploited, federal, or critical software</b> to <a class="link" href="https://cyberscoop.com/nist-narrows-cve-analysis-nvd/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">handle a huge and growing backlog</a>. Many other CVEs will still appear in the NVD but without extra enrichment or CVSS scoring. The change shifts more responsibility to CNAs and private groups as vulnerabilities surge.</p><p class="paragraph" style="text-align:left;">💰️ <b>Microsoft paid $2.3 million to researchers after nearly 700 submissions to its Zero Day Quest </b>hacking contest. Over 80 high-impact cloud and AI vulnerabilities were found during the live event. The <a class="link" href="https://www.bleepingcomputer.com/news/microsoft/microsoft-pays-23-million-for-cloud-and-ai-flaws-at-zero-day-quest/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">contest supports Microsoft’s Secure Future Initiative</a> to improve cloud and AI security.</p><p class="paragraph" style="text-align:left;">🩹 🌐 <b>Esri issued urgent April 2026 security patches for two critical </b><i><b>ArcGIS</b></i><b> credential vulnerabilities</b> that <a class="link" href="https://beyondmachines.net/event_details/esri-releases-critical-security-patches-for-arcgis-developer-credential-vulnerabilities-h-f-z-u-b/gD2P6Ple2L?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">let API keys and OAuth2 tokens gain excessive permissions</a>. Cloud services were patched, but on-premises Portal for <b>ArcGIS</b> (11.5 and 12.0) admins must apply the updates now. If you cannot patch immediately, disable or audit all API keys and OAuth tokens until you do.</p><p class="paragraph" style="text-align:left;">💥 <b>A critical Nginx UI vulnerability (CVE-2026-33032) tied to its AI integration has been </b><a class="link" href="https://pluto.security/blog/mcp-bug-nginx-security-vulnerability-cvss-9-8/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">exploited in the wild</a>. Researchers found thousands of exposed instances and published exploit details, letting attackers take full control of servers. This joins other recent Nginx UI flaws that can leak backups or let attackers modify user resources.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/2b4c5fd1-f821-4c2b-8402-ddd8052b61dd/image.png?t=1776269744"/><div class="image__source"><span class="image__source_text"><p>Figure: Shodan search results showing 2,689 publicly exposed nginx-ui instances/pluto.security</p></span></div></div><p class="paragraph" style="text-align:left;">🔓️ <b>A critical flaw (CVE-2026-5194) in the </b><i><b>wolfSSL</b></i><b> library lets weak or incorrectly sized hashes be accepted </b>when verifying ECDSA and other signatures. Attackers could use this to make <a class="link" href="https://www.bleepingcomputer.com/news/security/critical-flaw-in-wolfssl-library-enables-forged-certificate-use/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">vulnerable devices or apps accept forged certificates</a> and malicious servers. Users should update to <b>wolfSSL</b> 5.9.1 and check vendor packages or firmware for fixes.</p><p class="paragraph" style="text-align:left;">💥 <b>A critical pre-auth RCE in Marimo (CVE-2026-39987) let unauthenticated users access</b> an interactive shell via <code>/terminal/ws</code>. Attackers <a class="link" href="https://www.bleepingcomputer.com/news/security/critical-marimo-pre-auth-rce-flaw-now-under-active-exploitation/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">exploited it within hours</a> to quickly steal <code>.env</code> secrets and SSH keys. Users must upgrade to 0.23.0, block <code>/terminal/ws</code>, and rotate exposed credentials.</p><div class="embed"><a class="embed__url" href="https://www.isc.org/blogs/2026-04-16-How-to-report-a-vulnerability/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank"><div class="embed__content"><p class="embed__title"> How to report a security vulnerability, 101 </p><p class="embed__description"> At ISC, we sincerely value the contributions of our users, and security researchers, who analyze and probe our software for vulnerabilities. </p><p class="embed__link"> Internet Systems Consortium </p></div></a></div></div><p class="paragraph" style="text-align:left;"></p><div id="ics-ot-io-t" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🛰️ ICS, OT & IoT</h3><p class="paragraph" style="text-align:left;">🩹 <b>ICS Patch Tuesday</b> — Eight major industrial vendors — including <b>Siemens</b>, <b>Schneider Electric</b>, <b>ABB</b>, <b>Mitsubishi</b> <b>Electric</b>, <b>Rockwell</b>, <b>Aveva</b>, <b>Phoenix Contac</b>t, and <b>Moxa</b> — released <a class="link" href="https://www.securityweek.com/ics-patch-tuesday-8-industrial-giants-publish-new-security-advisories/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">new ICS security advisories</a> this Patch Tuesday. The fixes range from critical Wi‑Fi and authorization flaws to privilege escalation, DoS, and information‑disclosure issues across many products. CISA and Germany’s CERT@VDE also published multiple related advisories for other industrial vendors.</p><p class="paragraph" style="text-align:left;">🇸🇪 🇷🇺 <b>Sweden says Russian government-linked hackers tried to disrupt a thermal power plant in early 2025 </b>but <a class="link" href="https://techcrunch.com/2026/04/15/sweden-blames-russian-hackers-for-attempting-destructive-cyberattack-on-thermal-plant/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">were stopped by built-in protections</a>. Officials warn these groups are shifting from denial-of-service to destructive attacks on critical infrastructure. Similar attacks on energy and water systems in Europe and Ukraine have been blamed on Russian-linked actors.</p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">💬 CONNECT</h3><p class="paragraph" style="text-align:left;">Follow me on <a class="link" href="https://infosec.exchange/@0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">Mastodon</a> for quick daily updates and bite-sized content.</p><p class="paragraph" style="text-align:left;">Prefer using an RSS feed? Add <b>Infosec MASHUP</b> to your feed <a class="link" href="https://rss.beehiiv.com/feeds/HVhiKYpQlR.xml?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">here</a>.</p><p class="paragraph" style="text-align:center;"><b>Enjoying our newsletter? </b>Forward it to a colleague—<br>it’s one of the best ways to support us.</p><p class="paragraph" style="text-align:left;">Thanks for reading today’s newsletter, and if you&#39;re enjoying it and want to support my work, you can <b>buy me a coffee</b> ☕ over at <a class="link" href="https://www.buymeacoffee.com/0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-16-2026-faster-bugs-same-backlog" target="_blank" rel="noopener noreferrer nofollow">https://www.buymeacoffee.com/0x58</a></p><p class="paragraph" style="text-align:left;"> See you next time!</p><p class="paragraph" style="text-align:left;">-X.</p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=49b6ce74-a1be-4ac3-994d-8da0d6f623ab&utm_medium=post_rss&utm_source=x_s_infosec_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🕵🏻‍♂️ [InfoSec MASHUP] 15/2026 - Budgets Cut, Breaches Climbing</title>
  <description>Plus: REvil&#39;s alleged leader unmasked, Adobe Reader zero-day since December, and the most uncomfortable job interview you&#39;ll watch this week</description>
  <link>https://infosec-mashup.santolaria.net/p/infosec-mashup-15-2026-budgets-cut-breaches-climbing</link>
  <guid isPermaLink="true">https://infosec-mashup.santolaria.net/p/infosec-mashup-15-2026-budgets-cut-breaches-climbing</guid>
  <pubDate>Sat, 11 Apr 2026 08:33:00 +0000</pubDate>
  <atom:published>2026-04-11T08:33:00Z</atom:published>
    <dc:creator>Xavier Santolaria</dc:creator>
    <category><![CDATA[Malware]]></category>
    <category><![CDATA[Opensource]]></category>
    <category><![CDATA[Privacy]]></category>
    <category><![CDATA[Cybersecurity]]></category>
    <category><![CDATA[Threat Intelligence]]></category>
    <category><![CDATA[Ai]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Cybercrime losses hit $20.9 billion in 2025 — a 26% jump, per the FBI&#39;s IC3 report. That figure covers only what victims bothered to report, so treat it as a floor, not a ceiling. This week&#39;s issue arrives alongside a proposal to cut CISA&#39;s budget by $707 million. Whether that&#39;s a bold strategic bet or a spectacular misread of the moment is, apparently, still under debate.</p><p class="paragraph" style="text-align:left;">Let’s now dive into this week’s crème de la crème! 🚀</p><h2 class="heading" style="text-align:left;">Table of Contents</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="#breaches-security-incidents" rel="noopener noreferrer nofollow">BREACHES & SECURITY INCIDENTS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#cybercrime-cyber-espionage-ap-ts" rel="noopener noreferrer nofollow">CYBERCRIME, CYBER ESPIONAGE, APT’s</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#government-politics-and-privacy" rel="noopener noreferrer nofollow">GOVERNMENT, POLITICS, AND PRIVACY</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#malware-threats" rel="noopener noreferrer nofollow">MALWARE & THREATS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ai-crypto-tech-tools" rel="noopener noreferrer nofollow">AI, CRYPTO, TECH & TOOLS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#vulnerabilities-research-and-threat" rel="noopener noreferrer nofollow">VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ics-ot-io-t" rel="noopener noreferrer nofollow">ICS, OT & IoT</a></p></li></ul><div id="breaches-security-incidents" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🔓 BREACHES & SECURITY INCIDENTS</h3><p class="paragraph" style="text-align:left;">🇬🇧 🇺🇸 <b>A hacker redirected a contractor payment and stole £700,000 from Zephyr Energy</b>’s U.S. subsidiary. The company says the<a class="link" href="https://techcrunch.com/2026/04/09/hacker-stole-700000-from-u-k-energy-company-by-redirecting-payment/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow"> incident is contained</a> and operations are normal. <b>Zephyr</b> is working with banks and added extra security to try to recover the funds.</p><p class="paragraph" style="text-align:left;">💸 <b>Bitcoin Depot said hackers stole about 50.9 bitcoin, worth roughly $3.6 million</b>, after an intrusion on March 23. The <a class="link" href="https://www.securityweek.com/3-6-million-stolen-in-bitcoin-depot-hack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">company says customer platforms were not affected</a> and the incident is under investigation. <b>Bitcoin Depot</b> may face reputational, legal, and recovery costs and has insurance that may or may not cover the loss.</p><p class="paragraph" style="text-align:left;">🚂 <b>Eurail says attackers stole personal data of about 308,777 people</b> in a December 2025 breach. Stolen details may include names, passport numbers, IBANs, health data, and contact info. Affected customers are <a class="link" href="https://www.bleepingcomputer.com/news/security/eurail-says-december-data-breach-impacts-300-000-individuals/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">urged to watch for scams</a>, change passwords, and monitor bank accounts.</p><p class="paragraph" style="text-align:left;">🇺🇸 🚓 <b>Hackers stole and leaked a large cache of sensitive Los Angeles Police Department documents</b>, including personnel files, internal affairs records, and unredacted discovery materials. The leak, blamed on extortion gang <i>World Leaks</i> and <a class="link" href="https://techcrunch.com/2026/04/08/hackers-steal-and-leak-sensitive-lapd-police-documents/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">totaling about 7.7 terabytes and 337,000 files</a>, appeared on a leak site then was removed. The LAPD says its systems were not breached and it is working with the LA City Attorney’s Office to investigate.</p><p class="paragraph" style="text-align:left;">🇺🇸 <b>Wynn Resorts says a 2025 hack by the </b><i><b>ShinyHunters</b></i><b> group affected 21,775</b> employees. The attackers <a class="link" href="https://www.securityweek.com/wynn-resorts-says-21000-employees-affected-by-shinyhunters-hack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">stole</a> HR data, possibly including SSNs, and later claimed they deleted it. Affected workers are being offered free credit monitoring and identity-theft protection.</p><p class="paragraph" style="text-align:left;">❄️ 🇮🇱 <b>A SaaS integrator was breached and stolen authentication tokens were used to steal data</b> from <a class="link" href="https://www.bleepingcomputer.com/news/security/snowflake-customers-hit-in-data-theft-attacks-after-saas-integrator-breach/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">over a dozen companies</a>. Most attacks targeted <b>Snowflake</b> customers, who experienced unusual activity and had some accounts locked as a precaution. The extortion group <i><b>ShinyHunters</b></i> claims responsibility and says the incident ties to <b>Anodot</b>.</p><p class="paragraph" style="text-align:left;">🇩🇪 <b>The Qilin ransomware group stole data from the German political party </b><i><b>Die Linke</b></i> and is threatening to leak it. <b>Die Linke</b> says <a class="link" href="https://www.bleepingcomputer.com/news/security/die-linke-german-political-party-confirms-data-stolen-by-qilin-ransomware/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">member records were not taken</a> and has notified police while working with IT experts. The party and observers warn the attack may be politically motivated and part of hybrid warfare.</p></div><p class="paragraph" style="text-align:left;"></p><div id="cybercrime-cyber-espionage-ap-ts" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🥷🏻 CYBERCRIME, CYBER ESPIONAGE, APT’s</h3><div class="embed"><a class="embed__url" href="https://cyberscoop.com/fbi-internet-crime-complaint-center-annual-cybercrime-report/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank"><div class="embed__content"><p class="embed__title"> Cybercrime losses jumped 26% to $20.9 billion in 2025 </p><p class="embed__description"> The FBI’s annual report on digital crimes exposes a worsening environment. Yet, an unknown number of victims still suffer in the shadows never reporting the crimes they endure. </p><p class="embed__link"> CyberScoop • Matt Kapko </p></div><img class="embed__image embed__image--right" src="https://cyberscoop.com/wp-content/uploads/sites/3/2025/10/GettyImages-2185108541.jpg"/></a></div><p class="paragraph" style="text-align:left;">👀 📰 <b>Researchers say a hack-for-hire campaign used Android spyware to target journalists and activists</b> in the Middle East and North Africa. The attacks, traced to shared infrastructure <a class="link" href="https://cyberscoop.com/hack-for-hire-spyware-campaign-targets-journalists-in-middle-east-north-africa/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">linked to the </a><a class="link" href="https://cyberscoop.com/hack-for-hire-spyware-campaign-targets-journalists-in-middle-east-north-africa/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow"><i>Bitter</i></a><a class="link" href="https://cyberscoop.com/hack-for-hire-spyware-campaign-targets-journalists-in-middle-east-north-africa/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow"> group</a>, used spearphishing via fake social accounts. Victims feel threatened and groups warn such spying endangers journalists, sources, and press freedom.</p><p class="paragraph" style="text-align:left;">🇷🇺 <b>Russian state-linked hackers (Fancy Bear/APT28) broke into thousands of home and small-business routers</b> worldwide. They <a class="link" href="https://krebsonsecurity.com/2026/04/russia-hacked-routers-to-steal-microsoft-office-tokens/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">redirected users’ internet traffic to steal passwords and login</a> tokens. Authorities and researchers say the campaign hit many countries and targeted outdated MicroTik and TP-Link devices.</p><p class="paragraph" style="text-align:left;">🇩🇪 🇷🇺 <b>German police say a 31-year-old Russian, Daniil Shchukin, led the </b><i><b>GandCrab</b></i><b> and </b><i><b>REvil</b></i><b> ransomware groups</b> from 2019 to 2021. He and associates <a class="link" href="https://www.securityweek.com/german-police-unmask-revil-ransomware-leader/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">carried out about 130 extortion attempts</a>, causing over $40 million in damage and collecting more than $2 million in ransoms in 25 cases. Shchukin, known by several aliases, is believed to be in Russia and has been linked in past arrests and investigations.</p><p class="paragraph" style="text-align:left;">🇨🇳 <b>Microsoft says </b><i><b>Storm-1175</b></i><b>, the China-based cybercrime group, uses n-day and zero-day exploits to quickly deploy Medusa</b> ransomware. The group <a class="link" href="https://www.microsoft.com/en-us/security/blog/2026/04/06/storm-1175-focuses-gaze-on-vulnerable-web-facing-assets-in-high-tempo-medusa-ransomware-operations/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">moves from initial access to data theft and ransomware in days or even 24 hours</a>, often chaining exploits and disabling defenses. Their attacks have hit healthcare, education, finance and other sectors across multiple countries and abused many known vulnerabilities.</p><p class="paragraph" style="text-align:left;">🇨🇳 🇪🇺 <b>China‑linked TA416 resumed targeting European government and diplomatic bodies since mid‑2025</b>, using OAuth redirection, fake Cloudflare pages, web bugs, and updated PlugX backdoors. They <a class="link" href="https://www.proofpoint.com/us/blog/threat-insight/id-come-running-back-eu-again-ta416-resumes-european-government-espionage?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">spread malware via phishing links</a>, cloud storage (Azure, Google Drive), compromised SharePoint, and MSBuild/C# project files with DLL side‑loading. <b>TA416</b> also expanded into the Middle East after late‑2025, showing adaptive, long‑term intelligence‑collection operations tied to geopolitical events.</p><div class="embed"><a class="embed__url" href="https://www.zetter-zeroday.com/trenchant-exec-says-he-had-depression-money-troubles-when-he-decided-to-sell-zero-days-to-russian-buyer-also-new-info-reveals-nature-of-his-work-for-australian-intelligence-agency/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank"><img class="embed__image embed__image--top" src="https://www.zetter-zeroday.com/content/images/size/w1200/2026/04/Screenshot-2026-04-07-at-8.04.46---PM.png"/><div class="embed__content"><p class="embed__title"> Trenchant Exec Says He Had Depression, Money Troubles When He Decided to Sell Zero Days to Russian Buyer; Also, New Info Reveals Nature of His Work for Australian Intelligence Agency </p><p class="embed__description"> Peter Joseph Williams, a former L3 Trenchant executive recently convicted of secretly selling zero-day exploits to a Russian broker, says he was suffering anxiety, burnout, years of depression, and financial difficulties when he decided to steal exploits from his US employer and sell them to the Russian buyer. Williams, who </p><p class="embed__link"> ZERO DAY </p></div></a></div></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;">🗓️ <b><a class="link" href="https://xsa.github.io/infosec-events/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">{Cyber,Info}Sec Events</a></b> — A community-maintained list of infosec conferences worldwide. Subscribe to the <a class="link" href="https://xsa.github.io/infosec-events/events.ics?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">ICS calendar feed</a> to get events straight into your calendar, or follow <a class="link" href="https://infosec.exchange/@infosecevents?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">@infosecevents@infosec.exchange</a> on Mastodon for weekly digests. Contributions and ⭐ welcome!</p></div><p class="paragraph" style="text-align:left;"></p><div id="government-politics-and-privacy" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">👨🏻‍⚖️ 👀 GOVERNMENT, POLITICS, AND PRIVACY</h3><p class="paragraph" style="text-align:left;">🇺🇸 💸 <b>The Trump administration proposes cutting the Cybersecurity and Infrastructure Security Agency budget by about $707 million</b> for 2027. Officials say <a class="link" href="https://techcrunch.com/2026/04/07/cisa-budget-cuts-700-million-cybersecurity-agency-trump/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">the cuts will refocus CISA on core federal network and infrastructure protection</a> and eliminate duplicative programs. Critics warn the cuts come after staff losses and amid rising major cyberattacks, and accuse the administration of politicizing CISA.</p><p class="paragraph" style="text-align:left;">🇺🇸 ⚖️ <b>A judge sentenced Bryan Fleming, maker of stalkerware </b><i><b>pcTattleTale</b></i><b>, to supervised release and a $5,000 fine</b> after his guilty plea. His software secretly recorded texts, calls, location, web activity, and video from victims’ devices. <i>pcTattleTale</i> <a class="link" href="https://cyberscoop.com/pctattletale-stalkerware-maker-sentence-includes-fine-supervised-release/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">shut down in 2024</a> after a data breach.</p><div class="embed"><a class="embed__url" href="https://www.404media.co/fbi-extracts-suspects-deleted-signal-messages-saved-in-iphone-notification-database-2/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank"><div class="embed__content"><p class="embed__title"> FBI Extracts Suspect’s Deleted Signal Messages Saved in iPhone Notification Database </p><p class="embed__description"> The case was the first time authorities charged people for alleged “Antifa” activities after President Trump designated the umbrella term a terrorist organization. </p><p class="embed__link"> 404 Media </p></div><img class="embed__image embed__image--right" src="https://www.404media.co/content/images/size/w1200/2026/04/appshunter-io-BuPiOZN5DOQ-unsplash.jpg"/></a></div></div><p class="paragraph" style="text-align:left;"></p><div id="malware-threats" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🦠 MALWARE & THREATS</h3><p class="paragraph" style="text-align:left;">🧩 <b>A malicious VS Code extension named </b><code>specstudio.code-wakatime-activity-tracker</code><b> hides a Zig-compiled native binary that infects</b> all IDEs on a developer&#39;s machine. The binary downloads and silently installs a fake extension that steals data, fetches commands via Solana, and deploys a RAT and a malicious Chrome extension. If you installed <code>specstudio.code-wakatime-activity-tracker</code> or <code>floktokbok.autoimport</code> <a class="link" href="https://www.aikido.dev/blog/glassworm-zig-dropper-infects-every-ide-on-your-machine?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">assume compromise and rotate</a> all secrets.</p><p class="paragraph" style="text-align:left;">🇹🇼 <b>Security researchers tracked a new threat cluster, UAT-10362, using spear-phishing to target Taiwanese NGOs</b> and universities. The <a class="link" href="https://blog.talosintelligence.com/new-lua-based-malware-lucidrook/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">attackers deploy a Lua-based stager called </a><i><a class="link" href="https://blog.talosintelligence.com/new-lua-based-malware-lucidrook/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">LucidRook</a></i> via DLL side-loading and droppers (<i>LucidPawn/LucidKnight</i>) to collect and exfiltrate data. The campaign uses geo-checks, obfuscation, and public or compromised infrastructure, showing stealthy, targeted tradecraft.</p><p class="paragraph" style="text-align:left;">🇷🇺 🎣 <b>Russian APT28 has been running spear-phishing attacks against Ukraine and NATO allies to deploy a new malware suite</b> called <i>PRISMEX</i>. PRISMEX uses steganography, COM hijacking, and cloud services, and was spread using fast weaponization of zero-day Windows flaws. The <a class="link" href="https://www.trendmicro.com/en_us/research/26/c/pawn-storm-targets-govt-infra.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">campaign appears aimed at espionage</a> and possible sabotage of military, logistics, and critical services.</p><p class="paragraph" style="text-align:left;">🧩 <b>Malicious actors published 36 Strapi-focused NPM packages</b> that deliver payloads like Redis remote code execution, Docker escapes, credential harvesting, and reverse shells. <a class="link" href="https://safedep.io/malicious-npm-strapi-plugin-events-c2-agent/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">SafeDep says the campaign specifically targets Guardarian cryptocurrency payment systems</a> and seeks wallet files, API modules, and database access. Infected users should immediately rotate all credentials and secrets.</p><p class="paragraph" style="text-align:left;">🇺🇦 🎠 <b>Ukraine&#39;s CERT-UA warned of a phishing campaign that impersonated the agency to spread a remote access trojan</b> called <i>AGEWHEEZE</i>. The attackers sent password‑protected ZIPs to many targets and <a class="link" href="https://thehackernews.com/2026/04/cert-ua-impersonation-campaign-spread.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">claimed to have emailed 1 million ukr.net accounts</a>. The campaign mostly failed, with only a few infections found and CERT-UA helping affected organizations.</p></div><p class="paragraph" style="text-align:left;"></p><div id="ai-crypto-tech-tools" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🤖 🧰 AI, CRYPTO, TECH & TOOLS</h3><div class="embed"><a class="embed__url" href="https://techcrunch.com/2026/04/09/is-anthropic-limiting-the-release-of-mythos-to-protect-the-internet-or-anthropic/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank"><div class="embed__content"><p class="embed__title"> Is Anthropic limiting the release of Mythos to protect the internet — or Anthropic? | TechCrunch </p><p class="embed__description"> Anthropic said this week that it limited the release of its newest model, dubbed Mythos, because it is too capable of finding security exploits in software relied upon by users around the world. Are real cybersecurity concerns a cover for a bigger problem at the frontier lab? </p><p class="embed__link"> TechCrunch • Tim Fernholz </p></div><img class="embed__image embed__image--right" src="https://techcrunch.com/wp-content/uploads/2025/02/Anthropic-Dario-Amodei.jpeg?w=1182"/></a></div><p class="paragraph" style="text-align:left;">🔎 🐛 <b>Anthropic released Claude Mythos, a powerful new AI</b> that greatly improves coding and agentic reasoning. It <a class="link" href="https://www.securityweek.com/anthropic-unveils-claude-mythos-a-cybersecurity-breakthrough-that-could-also-supercharge-attacks/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">found thousands of old and critical software vulnerabilities</a>, showing huge benefits for defense but also big risks if misused. Anthropic launched <i>Project Glasswing</i> with major tech partners to use <b>Mythos</b> to secure critical software before attackers can exploit it.</p><p class="paragraph" style="text-align:left;">🔓️ 🍎 <b>Researchers at RSAC found a way to bypass Apple Intelligence’s guardrails using two tricks</b>: Neural Execs prompt injection and Unicode right-to-left manipulation. They used these methods to make the on-device LLM produce offensive content and potentially access private app data, <a class="link" href="https://www.securityweek.com/apple-intelligence-ai-guardrails-bypassed-in-new-attack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">succeeding on 76% of test prompts</a>. Apple was notified in October 2025 and released protections in iOS 26.4 and macOS 26.4; no real-world abuse has been seen.</p><p class="paragraph" style="text-align:left;">🪄🤖 <b>Google DeepMind researchers show that malicious web content can trick autonomous AI agents</b> and <a class="link" href="https://www.securityweek.com/google-deepmind-researchers-map-web-attacks-against-ai-agents/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">make them act against their goals</a>. They identify six classes of &quot;agent traps&quot; that hide commands, manipulate memory and behavior, or exploit group dynamics and humans-in-the-loop. Defenses include model hardening, runtime checks, better web hygiene, and shared standards and benchmarks.</p></div><p class="paragraph" style="text-align:left;"></p><div id="vulnerabilities-research-and-threat" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🐛 🧠 VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</h3><p class="paragraph" style="text-align:left;">➝ From the Patching Department:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/severe-strongbox-vulnerability-patched-in-android/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">Severe StrongBox Vulnerability Patched in Android</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/chrome-147-patches-60-vulnerabilities-including-two-critical-flaws-worth-86000/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">Chrome 147 Patches 60 Vulnerabilities, Including Two Critical Flaws Worth $86,000</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/data-leakage-vulnerability-patched-in-openssl/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">Data Leakage Vulnerability Patched in OpenSSL</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/juniper-networks-patches-dozens-of-junos-os-vulnerabilities/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">Juniper Networks Patches Dozens of Junos OS Vulnerabilities</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/palo-alto-networks-sonicwall-patch-high-severity-vulnerabilities/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">Palo Alto Networks, SonicWall Patch High-Severity Vulnerabilities</a></p></li></ul><hr class="content_break"><p class="paragraph" style="text-align:left;">🅰️ 💥 <b>Attackers have been exploiting an unpatched Adobe Reader zero-day since at least December</b> using malicious PDFs. The <a class="link" href="https://www.bleepingcomputer.com/news/security/hackers-exploiting-acrobat-reader-zero-day-flaw-since-december/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">exploit can steal local data</a> and may enable remote code execution just by opening a file. Users should avoid PDFs from untrusted sources and Adobe is working on a patch.</p><p class="paragraph" style="text-align:left;">🪶 <b>A 13-year-old RCE vulnerability in Apache ActiveMQ Classic</b> (CVE-2026-34197) lets <a class="link" href="https://horizon3.ai/attack-research/disclosures/cve-2026-34197-activemq-rce-jolokia/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">attackers invoke management operations via Jolokia</a> to fetch remote configs and run OS commands. Chained with older flaws (CVE-2022-41678 and sometimes CVE-2024-32114), it can bypass authentication and lead to remote code execution. Fixes are in ActiveMQ Classic 5.19.4 and 6.2.3; update immediately.</p><p class="paragraph" style="text-align:left;">😶 <b>Researchers at Noma Security disclosed &quot;</b><i><b>GrafanaGhost</b></i><b>,&quot; a vulnerability that silently steals data from Grafana</b> by chaining multiple security bypasses. The <a class="link" href="https://cyberscoop.com/grafanaghost-grafana-prompt-injection-vulnerability-data-exfiltration/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">attack uses crafted URLs and prompt injection</a> to trick Grafana’s AI and exfiltrate data without user interaction or visible alerts. Grafana Labs was notified and issued a fix.</p><p class="paragraph" style="text-align:left;">🚢 <b>A high-severity </b><i><b>Docker Engine</b></i><b> bug (CVE-2026-34040) lets attackers bypass authorization plugins</b> by sending a padded API request that strips the request body. This <a class="link" href="https://thehackernews.com/2026/04/docker-cve-2026-34040-lets-attackers.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">can let them create privileged containers</a>, mount the host filesystem, and steal credentials. Update to Docker 29.3.1 or use rootless mode and restrict Docker API access.</p><p class="paragraph" style="text-align:left;">🔎 ☁️ <b>A botnet campaign is scanning internet-exposed </b><i><b>ComfyUI</b></i><b> instances and exploiting unsafe custom nodes</b> to run attacker Python code. Compromised hosts are enrolled in Monero and Conflux miners and a Hysteria V2 proxy botnet, with persistence and cleanup mechanisms. Over <a class="link" href="https://thehackernews.com/2026/04/over-1000-exposed-comfyui-instances.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">1,000 public </a><b><a class="link" href="https://thehackernews.com/2026/04/over-1000-exposed-comfyui-instances.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">ComfyUI</a></b><a class="link" href="https://thehackernews.com/2026/04/over-1000-exposed-comfyui-instances.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow"> instances are reachable</a>, making opportunistic cryptomining profitable for the attackers.</p><p class="paragraph" style="text-align:left;">🐛 <b>A critical CVSS 10.0 code-injection bug in </b><i><b>Flowise</b></i><b> (CVE-2025-59528) lets attackers run arbitrary JavaScript</b> and gain full Node.js privileges. Over <a class="link" href="https://thehackernews.com/2026/04/flowise-ai-agent-builder-under-active.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">12,000 internet-facing </a><b><a class="link" href="https://thehackernews.com/2026/04/flowise-ai-agent-builder-under-active.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">Flowise</a></b><a class="link" href="https://thehackernews.com/2026/04/flowise-ai-agent-builder-under-active.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow"> instances are exposed</a> and active exploitation has been observed. <b>Flowise</b> patched the issue in version 3.0.6, but many systems remain at risk.</p><p class="paragraph" style="text-align:left;">🇰🇵 💻️ <b>A viral video shows an interviewer asking a suspected North Korean job applicant</b> to insult Kim Jong Un. The applicant freezes, acts confused, and leaves the call. The <a class="link" href="https://techcrunch.com/2026/04/06/watch-this-video-of-how-a-job-interviewer-exposes-a-north-korean-fake-it-worker/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">trick can expose some fake North Korean workers </a>but does not always work.</p><p class="paragraph" style="text-align:left;">🔓️ <b>A researcher leaked working exploit code for an unpatched Windows local privilege escalation</b> called <a class="link" href="https://www.bleepingcomputer.com/news/security/disgruntled-researcher-leaks-bluehammer-windows-zero-day-exploit/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow"><i>BlueHammer</i></a>. The bug lets attackers gain SYSTEM or elevated admin access by abusing a TOCTOU and path confusion, though the PoC has reliability issues. Microsoft has not patched it and gave no comment.</p></div><p class="paragraph" style="text-align:left;"></p><div id="ics-ot-io-t" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🛰️ ICS, OT & IoT</h3><p class="paragraph" style="text-align:left;">🇮🇷 🇺🇸 <b>U.S. agencies warn Iran-backed hackers are targeting American critical infrastructure</b> to cause disruption. They have <a class="link" href="https://techcrunch.com/2026/04/07/iranian-hackers-are-targeting-american-critical-infrastructure-u-s-agencies-warn/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">attacked industrial control systems</a> like SCADA and PLCs, causing operational and financial harm. The activity is seen as an escalation linked to recent conflicts involving Iran.</p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">💬 CONNECT</h3><p class="paragraph" style="text-align:left;">Follow me on <a class="link" href="https://infosec.exchange/@0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">Mastodon</a> for quick daily updates and bite-sized content.</p><p class="paragraph" style="text-align:left;">Prefer using an RSS feed? Add <b>Infosec MASHUP</b> to your feed <a class="link" href="https://rss.beehiiv.com/feeds/HVhiKYpQlR.xml?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">here</a>.</p><p class="paragraph" style="text-align:center;"><b>Enjoying our newsletter? </b>Forward it to a colleague—<br>it’s one of the best ways to support us.</p><p class="paragraph" style="text-align:left;">Thanks for reading today’s newsletter, and if you&#39;re enjoying it and want to support my work, you can <b>buy me a coffee</b> ☕ over at <a class="link" href="https://www.buymeacoffee.com/0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-15-2026-budgets-cut-breaches-climbing" target="_blank" rel="noopener noreferrer nofollow">https://www.buymeacoffee.com/0x58</a></p><p class="paragraph" style="text-align:left;"> See you next time!</p><p class="paragraph" style="text-align:left;">-X.</p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=611d1e0a-c429-4d08-9d46-f6efa40d3784&utm_medium=post_rss&utm_source=x_s_infosec_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🕵🏻‍♂️ [InfoSec MASHUP] 14/2026 - The Pipeline Is the Attack Surface</title>
  <description>Plus: Stryker back online, $285M drained in 10 seconds, CERT-EU cloud breach, and quantum crypto&#39;s accelerating threat window</description>
  <link>https://infosec-mashup.santolaria.net/p/infosec-mashup-14-2026-the-pipeline-is-the-attack-surface</link>
  <guid isPermaLink="true">https://infosec-mashup.santolaria.net/p/infosec-mashup-14-2026-the-pipeline-is-the-attack-surface</guid>
  <pubDate>Mon, 06 Apr 2026 11:36:23 +0000</pubDate>
  <atom:published>2026-04-06T11:36:23Z</atom:published>
    <dc:creator>Xavier Santolaria</dc:creator>
    <category><![CDATA[Malware]]></category>
    <category><![CDATA[Opensource]]></category>
    <category><![CDATA[Privacy]]></category>
    <category><![CDATA[Cybersecurity]]></category>
    <category><![CDATA[Threat Intelligence]]></category>
    <category><![CDATA[Ai]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Heads up: this week&#39;s issue is running a bit light and a touch later than usual. Turns out I have a hobby that occasionally demands I be somewhere other than in front of a screen. Normal service resumes next week 😜 And Happy Easter 🐇 🐣 🍫 </p><p class="paragraph" style="text-align:left;">Every few months, the supply chain gets a reminder it still isn&#39;t fixed. This week&#39;s edition came via a compromised Axios maintainer account — someone quietly pushed two malicious versions of one of the most downloaded JavaScript packages on the planet, tucked in a fake dependency, and let a cross-platform RAT do the rest. The malicious versions were caught fast — Socket&#39;s detection flagged them within minutes — but &quot;caught fast&quot; and &quot;caught before damage&quot; are not the same sentence. The audacity isn&#39;t even the impressive part anymore. What&#39;s impressive is how predictable the pattern has become: trusted account, malicious publish, <code>postinstall</code> dropper, rotate credentials, repeat 🔁 The pipeline is the attack surface. It always has been.</p><p class="paragraph" style="text-align:left;">Let’s now dive into this week’s top insights! 🚀</p><h2 class="heading" style="text-align:left;">Table of Contents</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="#breaches-security-incidents" rel="noopener noreferrer nofollow">BREACHES & SECURITY INCIDENTS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#cybercrime-cyber-espionage-ap-ts" rel="noopener noreferrer nofollow">CYBERCRIME, CYBER ESPIONAGE, APT’s</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#government-politics-and-privacy" rel="noopener noreferrer nofollow">GOVERNMENT, POLITICS, AND PRIVACY</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#malware-threats" rel="noopener noreferrer nofollow">MALWARE & THREATS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ai-crypto-tech-tools" rel="noopener noreferrer nofollow">AI, CRYPTO, TECH & TOOLS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#vulnerabilities-research-and-threat" rel="noopener noreferrer nofollow">VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ics-ot-io-t" rel="noopener noreferrer nofollow">ICS, OT & IoT</a></p></li></ul><div id="breaches-security-incidents" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🔓 BREACHES & SECURITY INCIDENTS</h3><div class="embed"><a class="embed__url" href="https://cyberscoop.com/medtech-giant-stryker-says-its-back-up-after-iranian-cyberattack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank"><div class="embed__content"><p class="embed__title"> Medtech giant Stryker says it’s back up after Iranian cyberattack </p><p class="embed__description"> The Handala group claimed responsibility for hitting the company with a wiper attack last month. </p><p class="embed__link"> CyberScoop • Tim Starks </p></div><img class="embed__image embed__image--right" src="https://cyberscoop.com/wp-content/uploads/sites/3/2026/04/GettyImages-1339221504.jpg"/></a></div><p class="paragraph" style="text-align:left;">🧸 <b>Hasbro says it was hacked and took some systems offline after detecting the intrusion</b> on March 28. The company is <a class="link" href="https://techcrunch.com/2026/04/01/hasbro-hacked-may-take-several-weeks-to-recover/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">using continuity plans to keep orders and shipments moving</a> while cybersecurity teams investigate. <b>Hasbro</b> warns the disruption and investigation may take several weeks and it is not yet clear if data was stolen.</p><p class="paragraph" style="text-align:left;">🇪🇺 <b>CERT-EU says the TeamPCP group used a stolen AWS API key to breach the European Commission cloud</b> and steal data. The <a class="link" href="https://www.bleepingcomputer.com/news/security/cert-eu-european-commission-hack-exposes-data-of-30-eu-entities/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">leaked 90GB archive (about 340GB uncompressed) contains tens of thousands of files </a>with names, emails, and email content affecting 42 Commission clients and at least 29 other EU entities. No websites were altered and investigations are ongoing while data protection authorities and affected entities are being notified.</p><p class="paragraph" style="text-align:left;">🤖 <b>Mercor, an AI recruiting startup, says it was hit by a supply-chain cyberattack tied to the open-source LiteLLM</b> project. Extortion group <a class="link" href="https://techcrunch.com/2026/03/31/mercor-says-it-was-hit-by-cyberattack-tied-to-compromise-of-open-source-litellm-project/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow"><i>Lapsus$</i></a><a class="link" href="https://techcrunch.com/2026/03/31/mercor-says-it-was-hit-by-cyberattack-tied-to-compromise-of-open-source-litellm-project/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow"> claimed it stole</a> <b>Mercor</b> data, though details and the connection to <b>LiteLLM</b> remain unclear. <b>Mercor</b> says it is investigating with third-party forensics and working to contain the incident.</p><p class="paragraph" style="text-align:left;">🇬🇧 <b>Lloyds Banking Group had a software update glitch on March 12 that exposed transaction details</b> for about <a class="link" href="https://www.securityweek.com/lloyds-data-security-incident-impacts-450000-individuals/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">447,936 mobile users</a>. The exposure was brief and only happened when two users viewed their transaction lists almost simultaneously. No money was lost, Lloyds fixed the issue quickly and made goodwill payments to some customers.</p><p class="paragraph" style="text-align:left;">🇺🇸 <b>CareCloud, a healthcare IT company, reported a March 16 cybersecurity incident that disrupted one of its six electronic health record environments</b> for about eight hours. The company is<a class="link" href="https://www.securityweek.com/healthcare-it-platform-carecloud-probing-potential-data-breach/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow"> investigating whether patient data were accessed or stolen</a> but says the issue was limited to its <b>CareCloud Health</b> environment and systems are restored. <b>CareCloud</b> believes the incident is not materially damaging and expects cyberinsurance to cover any losses.</p><p class="paragraph" style="text-align:left;">🇳🇱 <b>The Dutch Finance Ministry shut down several systems, including the treasury banking portal, after a March 19 cyberattack</b> — About 1,600 public institutions cannot view treasury balances or use portal services, though funds and payments remain accessible. Authorities are <a class="link" href="https://www.bleepingcomputer.com/news/security/dutch-finance-ministry-takes-treasury-banking-portal-offline-after-breach/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">investigating with the NCSC</a> and external experts, and no data loss or attacker has been confirmed.</p><p class="paragraph" style="text-align:left;">→ More:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/250000-affected-by-data-breach-at-nacogdoches-memorial-hospital/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">250,000 Affected by Data Breach at Nacogdoches Memorial Hospital</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/t-mobile-sets-the-record-straight-on-latest-data-breach-filing/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">T-Mobile Sets the Record Straight on Latest Data Breach Filing</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/mercor-hit-by-litellm-supply-chain-attack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">Mercor Hit by LiteLLM Supply Chain Attack</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/hims-and-hers-warns-of-data-breach-after-zendesk-support-ticket-breach/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">Hims & Hers warns of data breach after Zendesk support ticket breach</a></p></li></ul><div class="embed"><a class="embed__url" href="https://www.troyhunt.com/passkeys-k-anonymity-searches-massive-speed-enhancements-bulk-domain-verification-api/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank"><div class="embed__content"><p class="embed__title"> HIBP Mega Update: Passkeys, k-Anonymity Searches, Massive Speed Enhancements and a Bulk Domain Verification API </p><p class="embed__description"> For a hobby project built in my spare time to provide a simple community service, Have I Been Pwned sure has, well, &quot;escalated&quot;. Today, we support hundreds of thousands of website visitors each day, tens of millions of API queries, and hundreds of millions of password searches. We&#39;re processing billions </p><p class="embed__link"> www.troyhunt.com/passkeys-k-anonymity-searches-massive-speed-enhancements-bulk-domain-verification-api </p></div><img class="embed__image embed__image--right" src="https://www.troyhunt.com/content/images/size/w1200/2026/03/IMG_4769.jpg"/></a></div></div><p class="paragraph" style="text-align:left;"></p><div id="cybercrime-cyber-espionage-ap-ts" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🥷🏻 CYBERCRIME, CYBER ESPIONAGE, APT’s</h3><p class="paragraph" style="text-align:left;">🇰🇵 💰️ <b>North Korean-linked hackers stole about $285 million from DeFi platform Drift</b> in a coordinated, <a class="link" href="https://www.securityweek.com/north-korean-hackers-drain-285-million-from-drift-in-10-seconds/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">high-speed attack</a>. They pre-signed transactions, gained admin control, created a fake token market, and drained multiple vaults in about 10 seconds. The thieves then laundered funds through thousands of wallets and automated bots across many chains.</p><p class="paragraph" style="text-align:left;">🇷🇺 <b>Russian APT </b><i><b>Star Blizzard</b></i><b> has started using the </b><i><b>DarkSword</b></i><b> iOS exploit kit</b> in a recent phishing campaign. The group sent more emails than usual that link to <a class="link" href="https://www.securityweek.com/russian-apt-star-blizzard-adopts-darksword-ios-exploit-kit/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">mobile-targeted exploits for iCloud and Apple</a> devices. Proofpoint says the kit appears aimed at stealing credentials and gathering intelligence across finance, government, education, legal, and think-tank targets.</p><p class="paragraph" style="text-align:left;">🇺🇸 ⚖️ <b>A Maryland man, Jonathan Spalletta, is charged with stealing about $53.3 million by hacking the </b><i><b>Uranium Finance</b></i><b> crypto exchange</b> … twice. He <a class="link" href="https://www.bleepingcomputer.com/news/security/hacker-charged-with-stealing-53-million-from-uranium-crypto-exchange/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">laundered the funds through Tornado Cash</a> and spent millions on rare collectibles before authorities seized about $31 million. He faces up to 10 years for computer fraud and up to 20 years for money laundering.</p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;">🗓️ <b><a class="link" href="https://xsa.github.io/infosec-events/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">{Cyber,Info}Sec Events</a></b> — A community-maintained list of infosec conferences worldwide. Subscribe to the <a class="link" href="https://xsa.github.io/infosec-events/events.ics?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">ICS calendar feed</a> to get events straight into your calendar, or follow <a class="link" href="https://infosec.exchange/@infosecevents?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">@infosecevents@infosec.exchange</a> on Mastodon for weekly digests. Contributions and ⭐ welcome!</p></div><p class="paragraph" style="text-align:left;"></p><div id="government-politics-and-privacy" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">👨🏻‍⚖️ 👀 GOVERNMENT, POLITICS, AND PRIVACY</h3><div class="embed"><a class="embed__url" href="https://www.404media.co/email/d7d7979a-494c-4729-8bf2-88e75ffe366b/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank"><div class="embed__content"><p class="embed__title"> Podcast: The Company Secretly Turning Your Zoom Meetings into Podcasts </p><p class="embed__description"> www.404media.co/email/d7d7979a-494c-4729-8bf2-88e75ffe366b </p></div><img class="embed__image embed__image--right" src="https://www.404media.co/content/images/size/w1200/2026/03/zoom-listening.png"/></a></div><p class="paragraph" style="text-align:left;">🇺🇸 👀 <b>ICE confirmed it is using Paragon spyware to target encrypted communications in fentanyl and national security</b> investigations. Three House Democrats <a class="link" href="https://cyberscoop.com/ice-using-paragon-spyware-house-democrats-letter/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">criticized the move</a>, saying there is no congressional oversight or proof of strong safeguards. Civil liberties groups and past incidents involving journalists and WhatsApp raise additional concerns.</p><p class="paragraph" style="text-align:left;">🇺🇸 🇨🇳 👀 <b>The FBI warned Americans to avoid or be cautious with foreign-developed mobile apps, especially those from China</b>, because of privacy and data security risks. These apps can collect extensive personal data, store it on servers in China, and may share it under Chinese national security laws. The FBI advises disabling unnecessary data sharing, updating devices, using verified apps, and <a class="link" href="https://www.ic3.gov/PSA/2026/PSA260331?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">reporting suspicious activity to IC3</a>.</p><p class="paragraph" style="text-align:left;">🍎 👮 <b>Apple’s “Hide My Email” can mask addresses but Apple gave real customer identities</b> to federal agents. Court records show Apple provided names, emails, and many anonymized-address records in two investigations. The case shows <a class="link" href="https://techcrunch.com/2026/03/30/apple-will-hide-your-email-address-from-apps-and-websites-but-not-cops/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">Apple’s privacy tools don’t block lawful government access</a> to stored or unencrypted data.</p><hr class="content_break"><blockquote align="center" class="twitter-tweet"><a href="https://twitter.com/wartranslated/status/2038281329247137873?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface"><p> Twitter tweet </p></a></blockquote></div><p class="paragraph" style="text-align:left;"></p><div id="malware-threats" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🦠 MALWARE & THREATS</h3><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/A58cV17avpM" width="100%"></iframe><p class="paragraph" style="text-align:left;">🎠 <b>Attackers used a compromised </b><i><b>Axios</b></i><b> maintainer accoun</b>t to publish two malicious <i><b>Axios</b></i> versions that add a fake dependency, <code>plain-crypto-js@4.2.1</code>. The dependency runs a postinstall dropper that <a class="link" href="https://socket.dev/blog/axios-npm-package-compromised?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">installs a cross-platform RAT</a> (macOS, Windows, Linux) and then hides its traces. Users should downgrade to safe <i><b>Axios</b></i> versions, remove the malicious package, check for RAT artifacts, and rotate credentials.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/5e5a8d5c-3d07-4976-b164-c0a039692e2c/image.png?t=1774947409"/><div class="image__source"><span class="image__source_text"><p>Figure: Socket’s automated malware detection flagged the package within minutes/socket.dev</p></span></div></div><div class="embed"><a class="embed__url" href="https://unit42.paloaltonetworks.com/axios-supply-chain-attack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank"><div class="embed__content"><p class="embed__title"> Threat Brief: Widespread Impact of the Axios Supply Chain Attack </p><p class="embed__description"> Unit 42 discusses the supply chain attack targeting Axios. Learn about the full attack chain, from the dropper to forensic cleanup. </p><p class="embed__link"> Unit 42 • Unit 42 </p></div><img class="embed__image embed__image--right" src="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/02_Security-Technology_Category_1920x900.jpg"/></a></div><hr class="content_break"><p class="paragraph" style="text-align:left;">🙊 <b>A new Android malware called </b><i><b>NoVoice</b></i><b> was hidden in 50+ Google Play apps</b> and <a class="link" href="https://www.bleepingcomputer.com/news/security/novoice-android-malware-on-google-play-infected-23-million-devices/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">infected at least 2.3 million devices</a>. It used steganography and old exploits to gain root, persist through factory resets, and inject code to steal WhatsApp data. Infected apps were removed, but users should assume compromise and update devices or reinstall from trusted sources.</p><p class="paragraph" style="text-align:left;">🥷 <b>Researchers warn of a new malware campaign called </b><i><b>DeepLoad</b></i><b> that steals credentials and hides</b> in enterprise systems. The attackers <a class="link" href="https://cyberscoop.com/deepload-ai-malware-obfuscation-at-every-stage-reliaquest/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">used AI-generated obfuscation and evasion</a> at every stage to evade traditional signature-based defenses. Experts say defenders must shift to behavioral and runtime detection to catch these fast-changing attacks.</p><p class="paragraph" style="text-align:left;">🛣️ 🩸 <b>Security firm Blackpoint found a new Node.js implant called </b><i><b>RoadK1ll</b></i><b> </b>that turns a compromised host into a relay to reach internal systems. It uses an outbound WebSocket tunnel to forward TCP traffic and supports multiple concurrent connections and reconnection. <b><i>RoadK1ll</i></b> has <a class="link" href="https://blackpointcyber.com/blog/roadk1ll-a-websocket-based-pivoting-implant/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">no traditional persistence but enables stealthy lateral pivoting</a> inside breached networks.</p></div><p class="paragraph" style="text-align:left;"></p><div id="ai-crypto-tech-tools" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🤖 🧰 AI, CRYPTO, TECH & TOOLS</h3><div class="embed"><a class="embed__url" href="https://arstechnica.com/security/2026/04/heres-why-its-prudent-for-openclaw-users-to-assume-compromise/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank"><div class="embed__content"><p class="embed__title"> OpenClaw gives users yet another reason to be freaked out about security </p><p class="embed__description"> The viral AI agentic tool let attackers silently gain admin unauthenticated access. </p><p class="embed__link"> Ars Technica </p></div><img class="embed__image embed__image--right" src="https://cdn.arstechnica.net/wp-content/uploads/2026/02/bluecrayfish-1152x648.jpg"/></a></div><p class="paragraph" style="text-align:left;">🔓️ 💸 <b>Google researchers say quantum computers could break the cryptography that protects Bitcoin and other cryptocurrencies</b> much sooner than thought. They <a class="link" href="https://research.google/blog/safeguarding-cryptocurrency-by-disclosing-quantum-vulnerabilities-responsibly/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">show</a> a way to break 256-bit elliptic curve keys using far fewer qubits and operations, cutting resource estimates by about 20×. Google urges faster moves to post-quantum cryptography and released a zero-knowledge proof instead of the attack details.</p><p class="paragraph" style="text-align:left;">🍎 ⚠️ <b>Apple added a Terminal safety feature in macOS Tahoe 26.4 that delays and warns when users paste</b> potentially dangerous commands. The <a class="link" href="https://www.bleepingcomputer.com/news/security/apple-adds-macos-terminal-warning-to-block-clickfix-attacks/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">change aims to block ClickFix social-engineering attacks</a> that trick people into pasting malicious commands. Users should still avoid running commands from untrusted sources because the warning’s detection method is unclear.</p><p class="paragraph" style="text-align:left;">🐛 <b>Researchers found a command-injection flaw in OpenAI Codex</b> that let attackers grab short-lived GitHub OAuth tokens. <a class="link" href="https://www.beyondtrust.com/blog/entry/openai-codex-command-injection-vulnerability-github-token?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">BeyondTrust showed</a> automation could steal and abuse those tokens to access repos and move across companies. OpenAI fixed the issue, but the report warns AI agents must be secured like live execution environments to prevent token theft.</p><p class="paragraph" style="text-align:left;">🤷 <b>Documents about Anthropic&#39;s secret &quot;</b><i><b>Claude Mythos</b></i><b>&quot; model were exposed</b> in a public CMS. Anthropic confirmed the model exists but said the leak happened. <a class="link" href="https://www.reddit.com/r/Anthropic/comments/1s5xwjp/anthropics_secret_claude_mythos_model_just_leaked/?utm_source=forwardfuture.ai&utm_medium=newsletter&utm_campaign=anthropic-ipo-google-s-agent-smith-surge-ai-risks-rise" target="_blank" rel="noopener noreferrer nofollow">Reddit users debated</a> whether the leak was accidental or a publicity stunt.</p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://www.bleepingcomputer.com/news/artificial-intelligence/claude-code-source-code-accidentally-leaked-in-npm-package/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">Claude Code source code accidentally leaked in NPM package</a></p></div><p class="paragraph" style="text-align:left;"></p><div id="vulnerabilities-research-and-threat" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🐛 🧠 VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</h3><p class="paragraph" style="text-align:left;">➝ From the Patching Department:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/apple-expands-ios-18-updates-to-more-iphones-to-block-darksword-attacks/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">Apple expands iOS 18 updates to more iPhones to block DarkSword attacks</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/cisco-patches-critical-and-high-severity-vulnerabilities/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">Cisco Patches Critical and High-Severity Vulnerabilities</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://thehackernews.com/2026/04/fortinet-patches-actively-exploited-cve.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">Fortinet Patches Actively Exploited CVE-2026-35616 in FortiClient EMS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/google-fixes-fourth-chrome-zero-day-exploited-in-attacks-in-2026/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">Google fixes fourth Chrome zero-day exploited in attacks in 2026</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://thehackernews.com/2026/03/openai-patches-chatgpt-data.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">OpenAI Patches ChatGPT Data Exfiltration Flaw and Codex GitHub Token Vulnerability</a></p></li></ul><hr class="content_break"><p class="paragraph" style="text-align:left;">🔼 <b>Two critical </b><i><b>ShareFile</b></i><b> flaws let attackers reach admin pages and upload</b> files without logging in. By chaining CVE-2026-2699 and CVE-2026-2701, researchers showed an <a class="link" href="https://www.securityweek.com/critical-sharefile-flaws-lead-to-unauthenticated-rce/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">attacker can place a web shell </a>and get remote code execution. The issues were fixed in ShareFile 5.12.4 (versions 6.x are not affected).</p><p class="paragraph" style="text-align:left;">🔓️ ✏️ <b>GIGABYTE Control Center has a critical arbitrary file-write vulnerability (CVE-2026-4415)</b> that lets unauthenticated <a class="link" href="https://www.bleepingcomputer.com/news/security/gigabyte-control-center-vulnerable-to-arbitrary-file-write-flaw/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">remote attackers write files and potentially run code</a>, escalate privileges, or cause denial of service. The flaw affects versions 25.07.21.01 and earlier when the &quot;pairing&quot; feature is enabled. Users should immediately update to version 25.12.10.01 from GIGABYTE’s official portal.</p><p class="paragraph" style="text-align:left;">📈 <b>F5 reclassified a BIG-IP APM flaw (CVE-2025-53521) from DoS to critical remote code execution</b> after attackers began exploiting it to install webshells. F5 and CISA <a class="link" href="https://www.bleepingcomputer.com/news/security/hackers-now-exploit-critical-f5-big-ip-flaw-in-attacks-patch-now/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">warn unpatched systems are at risk</a> and published IOCs and mitigation guidance. Organizations should check logs, disks, and follow incident-handling and patching procedures immediately.</p></div><p class="paragraph" style="text-align:left;"></p><div id="ics-ot-io-t" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🛰️ ICS, OT & IoT</h3><p class="paragraph" style="text-align:left;">🤷 </p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">💬 CONNECT</h3><p class="paragraph" style="text-align:left;">Follow me on <a class="link" href="https://infosec.exchange/@0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">Mastodon</a> for quick daily updates and bite-sized content.</p><p class="paragraph" style="text-align:left;">Prefer using an RSS feed? Add <b>Infosec MASHUP</b> to your feed <a class="link" href="https://rss.beehiiv.com/feeds/HVhiKYpQlR.xml?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">here</a>.</p><p class="paragraph" style="text-align:center;"><b>Enjoying our newsletter? </b>Forward it to a colleague—<br>it’s one of the best ways to support us.</p><p class="paragraph" style="text-align:left;">Thanks for reading today’s newsletter, and if you&#39;re enjoying it and want to support my work, you can <b>buy me a coffee</b> ☕ over at <a class="link" href="https://www.buymeacoffee.com/0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-14-2026-the-pipeline-is-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow">https://www.buymeacoffee.com/0x58</a></p><p class="paragraph" style="text-align:left;"> See you next time!</p><p class="paragraph" style="text-align:left;">-X.</p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=ff095f4d-124a-46d8-87b1-56e32cd154db&utm_medium=post_rss&utm_source=x_s_infosec_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🕵🏻‍♂️ [InfoSec MASHUP] 13/2026 - RSA Week, Real World Problems</title>
  <description>Plus: TeamPCP&#39;s worm, Iran&#39;s hacked cameras, and a Tycoon 2FA that just won&#39;t die. The real RSA keynotes.</description>
  <link>https://infosec-mashup.santolaria.net/p/infosec-mashup-13-2026-rsa-week-real-world-problems</link>
  <guid isPermaLink="true">https://infosec-mashup.santolaria.net/p/infosec-mashup-13-2026-rsa-week-real-world-problems</guid>
  <pubDate>Sat, 28 Mar 2026 08:52:00 +0000</pubDate>
  <atom:published>2026-03-28T08:52:00Z</atom:published>
    <dc:creator>Xavier Santolaria</dc:creator>
    <category><![CDATA[Malware]]></category>
    <category><![CDATA[Opensource]]></category>
    <category><![CDATA[Privacy]]></category>
    <category><![CDATA[Cybersecurity]]></category>
    <category><![CDATA[Threat Intelligence]]></category>
    <category><![CDATA[Ai]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">RSA Conference is in full swing in San Francisco this week — booths, buzzwords, and billion-dollar pitches as far as the eye can see. Meanwhile, out in the real world, threat actors didn&#39;t get the memo. Iran-linked hackers are using Telegram to hunt down dissidents and journalists, while TeamPCP&#39;s supply chain worm is deploying Kubernetes wipers that specifically target Iranian clusters. Two sides of the same geopolitical coin, playing out in parallel — and neither one is buying a vendor badge.</p><p class="paragraph" style="text-align:left;">Let’s now dive into this week’s top insights! 🚀</p><h2 class="heading" style="text-align:left;">Table of Contents</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="#breaches-security-incidents" rel="noopener noreferrer nofollow">BREACHES & SECURITY INCIDENTS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#cybercrime-cyber-espionage-ap-ts" rel="noopener noreferrer nofollow">CYBERCRIME, CYBER ESPIONAGE, APT’s</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#government-politics-and-privacy" rel="noopener noreferrer nofollow">GOVERNMENT, POLITICS, AND PRIVACY</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#malware-threats" rel="noopener noreferrer nofollow">MALWARE & THREATS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ai-crypto-tech-tools" rel="noopener noreferrer nofollow">AI, CRYPTO, TECH & TOOLS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#vulnerabilities-research-and-threat" rel="noopener noreferrer nofollow">VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ics-ot-io-t" rel="noopener noreferrer nofollow">ICS, OT & IoT</a></p></li></ul><div id="breaches-security-incidents" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🔓 BREACHES & SECURITY INCIDENTS</h3><p class="paragraph" style="text-align:left;">🪱 <b>A supply-chain attack on </b><i><b>Trivy</b></i><b> pushed trojanized Docker images that stole credentials</b> and spread an infostealer. Attackers (<i>TeamPCP</i>) <a class="link" href="https://socket.dev/blog/trivy-docker-images-compromised?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">used the stolen data to infect </a><i><a class="link" href="https://socket.dev/blog/trivy-docker-images-compromised?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">npm</a></i><a class="link" href="https://socket.dev/blog/trivy-docker-images-compromised?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow"> packages with a self-propagating worm</a> and to deface Aqua Security repos. They also <a class="link" href="https://www.aikido.dev/blog/teampcp-stage-payload-canisterworm-iran?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">deployed a Kubernetes wiper that targets Iranian clusters</a> and urged organizations to avoid the compromised <i>Trivy</i> versions.</p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://socket.dev/blog/trivy-docker-images-compromised?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">Trivy Supply Chain Attack Expands to Compromised Docker Images</a></p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://www.sysdig.com/blog/teampcp-expands-supply-chain-compromise-spreads-from-trivy-to-checkmarx-github-actions?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">TeamPCP expands: Supply chain compromise spreads from Trivy to Checkmarx GitHub Actions</a></p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://thehackernews.com/2026/03/teampcp-backdoors-litellm-versions.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">TeamPCP Backdoors LiteLLM Versions 1.82.7–1.82.8 Likely via Trivy CI/CD Compromise</a></p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://www.ox.security/blog/telnyx-malware-teampcp-strikes-again-following-litellm-compromise/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">TeamPCP pushed malicious telnyx versions 4.87.1 and 4.87.2 to PyPI</a> </p><hr class="content_break"><p class="paragraph" style="text-align:left;">🇮🇷 🇺🇸 😵‍💫 <b>Iran-linked hacking group </b><i><b>Handala</b></i><b> says it breached FBI director Kash Patel’s personal Gmail </b>and posted photos and files. <a class="link" href="https://techcrunch.com/2026/03/27/iranian-hackers-claim-breach-of-fbi-director-kash-patels-personal-email-account/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">TechCrunch verified some leaked emails as authentic</a> and Reuters says the Justice Department confirmed the breach. <i>Handala</i> has ramped up attacks since the U.S.-Israeli war with Iran, and U.S. prosecutors accuse Iran’s intelligence ministry of running the group.</p><p class="paragraph" style="text-align:left;">🇪🇺 ☁️ <b>The European Commission is investigating a breach</b> after a threat actor accessed its Amazon cloud infrastructure. The <a class="link" href="https://www.bleepingcomputer.com/news/security/european-commission-investigating-breach-after-amazon-cloud-hack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">attacker claims to have stolen over 350 GB of data</a> and shared screenshots as proof. The Commission&#39;s cybersecurity team detected the intrusion and is investigating while the attacker says they will later leak the data.</p><p class="paragraph" style="text-align:left;">🇪🇸 🚢 <b>A ransomware attack hit Spain’s Port of Vigo, forcing officials to disconnect</b> parts of the network. Cargo moves continue, but many tasks are being done manually with paper. An <a class="link" href="https://therecord.media/port-of-vigo-ransomware?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">investigation is underway</a> and the port won’t reconnect systems until they are declared safe.</p><p class="paragraph" style="text-align:left;">🇸🇪 🇬🇧 <b>The Lapsus$ extortion group claims it hacked AstraZeneca and stole about 3GB</b> of internal data. Stolen files allegedly include code, cloud infrastructure details, credentials, and employee info. AstraZeneca <a class="link" href="https://www.securityweek.com/extortion-group-claims-it-hacked-astrazeneca/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">has not confirmed the breach</a> and researchers say links to a recent supply-chain attack are unproven.</p><p class="paragraph" style="text-align:left;">🇺🇸 <b>HackerOne says 287 of its employees had personal data stolen</b> after a hack of <a class="link" href="https://www.bleepingcomputer.com/news/security/hackerone-discloses-employee-data-breach-after-navia-hack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">benefits administrator Navia</a>. Exposed details include names, Social Security numbers, addresses, dates of birth, and plan enrollment information. Affected workers are being offered 12 months of identity protection and warned to watch for phishing.</p><p class="paragraph" style="text-align:left;">🇺🇸 <b>Healthcare management firm QualDerm Partners says a December 2025 data breach</b> exposed personal, medical, and insurance information <a class="link" href="https://www.securityweek.com/3-1-million-impacted-by-qualderm-data-breach/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">for about 3.1 million people</a>. The attackers accessed the network for two days and stole names, contact details, medical records, diagnoses, insurance data, and in some cases IDs. QualDerm is investigating, notified authorities, and is offering 12 months of free identity and credit monitoring to affected people.</p><p class="paragraph" style="text-align:left;">🇳🇱 🚓 <b>Dutch National Police say a phishing attack led to a security breach</b> with limited impact. Investigators <a class="link" href="https://www.bleepingcomputer.com/news/security/dutch-police-discloses-security-breach-after-phishing-attack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">quickly blocked the attackers</a> and report no citizen or investigative data was accessed. A criminal probe is ongoing and authorities are tightening security measures.</p><p class="paragraph" style="text-align:left;">🇳🇱 <b>The Dutch Ministry of Finance said some of its systems were breached</b> in a cyberattack detected on March 19. Access to the affected systems has been blocked and the <a class="link" href="https://www.bleepingcomputer.com/news/security/dutch-ministry-of-finance-discloses-breach-affecting-employees/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">investigation is ongoing</a>. Tax, customs, and benefits systems were not impacted and no data loss or attacker identity has been disclosed.</p><p class="paragraph" style="text-align:left;">🇯🇵 <b>Mazda said a security breach last December exposed 692 records of employee and business partner data</b> from a warehouse management system tied to parts from Thailand. The leaked fields include names, user IDs, emails, company names, and partner IDs, though no customer data was involved. <a class="link" href="https://www.bleepingcomputer.com/news/security/mazda-discloses-security-breach-exposing-employee-and-partner-data/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">Mazda notified authorities</a>, tightened its IT security, and found no confirmed misuse so far.</p><p class="paragraph" style="text-align:left;">🇸🇬 <b>Trio-Tech said a Singapore subsidiary suffered a ransomware attack</b> on March 11 that encrypted some files. The subsidiary took systems offline, hired cybersecurity experts, notified law enforcement, and is investigating the impact. Stolen <a class="link" href="https://www.securityweek.com/chip-services-firm-trio-tech-says-subsidiary-hit-by-ransomware/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">data was posted</a> by a ransomware group, and the company now considers the incident possibly material.</p><p class="paragraph" style="text-align:left;">→ More:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/ajax-football-club-hack-exposed-fan-data-enabled-ticket-hijack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">Ajax football club hack exposed fan data, enabled ticket hijack</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/hightower-holding-data-breach-impacts-130000/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">Hightower Holding Data Breach Impacts 130,000</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/infinite-campus-warns-of-breach-after-shinyhunters-claims-data-theft/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">Infinite Campus warns of breach after ShinyHunters claims data theft</a></p></li></ul></div><p class="paragraph" style="text-align:left;"></p><div id="cybercrime-cyber-espionage-ap-ts" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🥷🏻 CYBERCRIME, CYBER ESPIONAGE, APT’s</h3><div class="embed"><a class="embed__url" href="https://unit42.paloaltonetworks.com/espionage-campaigns-target-se-asian-government-org/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank"><div class="embed__content"><p class="embed__title"> Converging Interests: Analysis of Threat Clusters Targeting a Southeast Asian Government </p><p class="embed__description"> Unit 42 uncovers multiple clusters of cyberespionage targeting a Southeast Asian government organization with USBFect, RATs and loaders. </p><p class="embed__link"> unit42.paloaltonetworks.com/espionage-campaigns-target-se-asian-government-org </p></div><img class="embed__image embed__image--right" src="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/08_Nation-State-cyberattacks_1920x900.jpg"/></a></div><p class="paragraph" style="text-align:left;">🇷🇺 <b>Russian police arrested the suspected administrator of </b><i><b>LeakBase</b></i><b>, a large marketplace for stolen</b> personal and financial data. Authorities seized equipment and said <a class="link" href="https://thehackernews.com/2026/03/leakbase-admin-arrested-in-russia-over.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">the site held hundreds of millions of credentials</a> and over 147,000 registered users. U.S. and Russian reports tied the forum to a threat actor known as Chucky and said the site was dismantled in a recent takedown. </p><p class="paragraph" style="text-align:left;">🇷🇺 ⚖️ 🇺🇸 <b>A Russian man, Ilya Angelov, was sentenced to two years for running a phishing botnet</b> used in BitPaymer ransomware attacks. The <a class="link" href="https://www.justice.gov/usao-edmi/pr/russian-cybercriminal-sentenced-prison-using-botnet-steal-millions-american-businesses?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">botnet infected thousands of computers and helped affiliates extort over $14 million</a> from more than 70 U.S. companies. The group sold access to infected machines to other cybercriminals and partnered with multiple ransomware gangs.</p><p class="paragraph" style="text-align:left;">🇷🇺 ⚖️ 🇺🇸 <b>Aleksei Volkov, a 26-year-old Russian, was sentenced to 6.75 years in the U.S. for helping ransomware groups</b> cause over $9 million in real losses. He sold access to company networks that attackers used to encrypt data and demand cryptocurrency ransoms. Volkov <a class="link" href="http://www.justice.gov/opa/pr/russian-citizen-sentenced-prison-hacking-us-companies-and-enabling-major-cybercrime-groups?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">must pay full restitution and forfeit the tools used</a> in the crimes.</p><p class="paragraph" style="text-align:left;">🆙 ✅ <b>Tycoon 2FA, a subscription phishing service that bypasses MFA, remains fully operational despite</b> a <a class="link" href="https://blogs.microsoft.com/on-the-issues/2026/03/04/how-a-global-coalition-disrupted-tycoon/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">recent international takedown</a>. The disruption briefly cut activity but attacks and cloud compromises soon returned to previous levels. Law enforcement seized domains and pursued operators, but CrowdStrike <a class="link" href="https://www.crowdstrike.com/en-us/blog/tycoon2fa-phishing-as-a-service-platform-persists-following-takedown/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">says</a> the platform’s tactics and reach continue.</p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;">🗓️ <b><a class="link" href="https://xsa.github.io/infosec-events/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">{Cyber,Info}Sec Events</a></b> — A community-maintained list of infosec conferences worldwide. Subscribe to the <a class="link" href="https://xsa.github.io/infosec-events/events.ics?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">ICS calendar feed</a> to get events straight into your calendar, or follow <a class="link" href="https://infosec.exchange/@infosecevents?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">@infosecevents@infosec.exchange</a> on Mastodon for weekly digests. Contributions and ⭐ welcome!</p></div><p class="paragraph" style="text-align:left;"></p><div id="government-politics-and-privacy" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">👨🏻‍⚖️ 👀 GOVERNMENT, POLITICS, AND PRIVACY</h3><blockquote align="center" class="twitter-tweet"><a href="https://twitter.com/lukOlejnik/status/2035771076890837337?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems"><p> Twitter tweet </p></a></blockquote><hr class="content_break"><p class="paragraph" style="text-align:left;">🤷‍♂️ 🇺🇸 <b>Four former NSA and U.S. Cyber Command leaders warned that the U.S. is losing its offensive edge</b> in cybersecurity. They <a class="link" href="https://cyberscoop.com/former-nsa-chiefs-offensive-edge-rsac/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">said</a> rising AI threats, China, and cybercrime outpace government and industry response. They urged stronger public-private cooperation and bolder policy action.</p><p class="paragraph" style="text-align:left;">🇬🇧 🇨🇳 <b>The UK has </b><a class="link" href="https://www.gov.uk/government/news/uk-crackdown-on-vile-scam-centres-steps-up-with-sanctions-on-illicit-crypto-network?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow"><b>sanctioned</b></a><b> </b><i><b>Xinbi</b></i><b>, a Chinese-language marketplace that sells stolen data and crypto services</b> to Southeast Asian scam centers. <i>Xinbi</i> is linked to laundering billions and to North Korean thefts, according to <a class="link" href="https://www.chainalysis.com/blog/xinbi-designation-chinese-language-crypto-scam-infrastructure/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">Chainalysis</a>. The sanctions also target Cambodia&#39;s #8 Park scam compound and aim to cut <i>Xinbi</i> off from legitimate crypto channels.</p><p class="paragraph" style="text-align:left;">🇬🇷 <b>Intellexa founder Tal Dilian, convicted in Greece for mass phone hacking, says he will appeal and denies</b> being a &quot;scapegoat.&quot; He <a class="link" href="https://techcrunch.com/2026/03/25/convicted-spyware-chief-hints-that-greeces-government-was-behind-dozens-of-phone-hacks/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">hinted the Greek government may have authorized the hacks</a> that targeted ministers, journalists, and others. The spyware Predator, sold mainly to governments, led to U.S. sanctions after being used against officials and journalists.</p><p class="paragraph" style="text-align:left;">🇺🇸 🔋 <b>The U.S. Department of Energy’s CESER released a 5-year plan (2026–2030) to protect </b>the <a class="link" href="https://www.securityweek.com/doe-publishes-5-year-energy-security-plan/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">nation’s energy system</a>s. It focuses on three goals: build advanced security technologies, harden critical energy infrastructure, and improve response and recovery. Programs like AI-FORTS and Project Armor aim to stop AI-enabled attacks and strengthen resilience.</p><p class="paragraph" style="text-align:left;">🇮🇱 🇮🇷 <b>Israel used hacked Iranian street cameras and AI to locate and help kill Iran’s supreme leader</b> — Poorly secured cameras worldwide can be <a class="link" href="https://www.securityweek.com/iran-built-a-vast-camera-network-to-control-dissent-israel-turned-it-into-a-targeting-tool/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">hijacked and turned into real-time targeting tools</a>. Experts warn mass surveillance meant to control dissent can make leaders and civilians more vulnerable.</p><p class="paragraph" style="text-align:left;">🇷🇺 ❌ <b>Russian authorities have blocked the paywall-bypass site </b><a class="link" href="https://Archive.today?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow"><b>Archive.today</b></a><b> and some of its domains</b>, showing Roskomnadzor error pages. The agency confirmed access to at least one <a class="link" href="https://Archive.is?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">Archive.is</a> page was limited but gave no reason. The <a class="link" href="https://techcrunch.com/2026/03/23/russian-authorities-block-paywall-removal-site-archive-today/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">extent of the block is unclea</a>r, and <a class="link" href="https://Archive.today?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">Archive.today</a> and Roskomnadzor did not comment.</p><hr class="content_break"><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/jfKEaJfcdTE" width="100%"></iframe><hr class="content_break"><p class="paragraph" style="text-align:left;">❌ 🇺🇸 <b>The FCC has banned the sale of new consumer routers made outside the USA</b> by adding them to its Covered List. The <a class="link" href="https://www.bleepingcomputer.com/news/security/fcc-bans-new-routers-made-outside-the-usa-over-security-risks/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">move follows a national security finding</a> that foreign-made routers pose severe supply-chain and cybersecurity risks. Existing routers can still be sold, but future models may be harder to buy and cost more unless makers get special approval.</p><p class="paragraph" style="text-align:left;">🇺🇸 🗳️ <b>A California sheriff seized 650,000 Riverside County ballots claiming an election-fraud probe</b> — State officials and experts say the claims are weak and the sheriff lacked authority. They <a class="link" href="https://cyberscoop.com/state-officials-election-experts-decry-california-sheriff-ballot-seizure/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">warn the seizure risks breaking ballot security</a> and undermining trust in elections.</p><p class="paragraph" style="text-align:left;">🤔 ✅ <b>An anonymous post accuses compliance startup Delve of giving customers fake audit evidence and claiming compliance</b> they didn’t earn. Delve denies the claims, saying it only provides templates and access for independent auditors. The <a class="link" href="https://techcrunch.com/2026/03/22/delve-accused-of-misleading-customers-with-fake-compliance/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">dispute raises possible legal and security risks</a> and promises more allegations to come.</p></div><p class="paragraph" style="text-align:left;"></p><div id="malware-threats" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🦠 MALWARE & THREATS</h3><div class="embed"><a class="embed__url" href="https://news.risky.biz/risky-bulletin-github-is-starting-to-have-a-real-malware-problem/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank"><div class="embed__content"><p class="embed__title"> GitHub is starting to have a real malware problem </p><p class="embed__description"> In other news: Russian intelligence services compromise thousands of Signal accounts; Trivy vulnerability scanner compromised for supply chain attack; FBI takes down Aisuru and Kimwolf botnets. </p><p class="embed__link"> news.risky.biz/risky-bulletin-github-is-starting-to-have-a-real-malware-problem </p></div><img class="embed__image embed__image--right" src="https://news.risky.biz/content/images/2026/03/000-RBN-logo-9.png"/></a></div><p class="paragraph" style="text-align:left;">🍎 📲 <b>Kaspersky found that the Coruna iOS exploit kit reuses and expands the kernel exploit code from 2023</b>&#39;s <i>Operation Triangulation</i>. The kit now targets many iPhones and is <a class="link" href="https://securelist.com/coruna-framework-updated-operation-triangulation-exploit/119228/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">being used in mass attacks</a> and watering-hole campaigns. Its modular, updated design lets more attackers reuse it and puts unpatched users at risk.</p><p class="paragraph" style="text-align:left;">🇦🇲 ⚖️ 🇺🇸 <b>Armenian national Hambardzum Minasyan was extradited to the U.S. for allegedly running parts of the </b><i><b>RedLine</b></i><b> infostealer</b>, including servers, domains, and payment handling. He faces charges including access device fraud, money laundering, and CFAA violations, with up to 20 years on some counts. <i>RedLine</i> is a <a class="link" href="https://www.securityweek.com/alleged-redline-malware-administrator-extradited-to-us/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">popular malware-as-a-service that steals credentials</a> and crypto data and remains active despite international takedown efforts.</p><p class="paragraph" style="text-align:left;">🇺🇸 🤑 <b>A malvertising campaign used Google Ads to lure U.S. tax-searchers to fake sites that install rogue ScreenConnect </b>remote access tools. The attackers <a class="link" href="https://www.huntress.com/blog/w2-malvertising-to-kernel-mode-edr-kill?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">deploy a crypter</a> and a Huawei-signed audio driver (HWAuidoOs2Ec.sys) as HwAudKiller to disable EDRs and steal credentials. They hide using commercial cloaking services and may be preparing ransomware or selling access.</p><p class="paragraph" style="text-align:left;">🇮🇷 <b>The FBI warns Iran-linked hackers are using Telegram to spread malware</b> that targets dissidents, journalists, and others seen as threats to Iran. Attackers <a class="link" href="https://cyberscoop.com/fbi-iranian-hackers-targeting-opponents-with-telegram-malware/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">fake apps and contacts to trick victims</a> into downloading files that give the hackers control. The malware has led to data theft, leaks, and reputational harm.</p><p class="paragraph" style="text-align:left;">🎣 🤑 <b>Microsoft warned of mass tax‑season phishing </b>that stole credentials and installed remote‑management malware on devices. One Feb 10 <a class="link" href="https://www.microsoft.com/en-us/security/blog/2026/03/19/when-tax-season-becomes-cyberattack-season-phishing-and-malware-campaigns-using-tax-related-lures/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">campaign hit over 29,000 users across 10,000 U.S. organizations</a> by spoofing the IRS and delivering ScreenConnect and other RMM tools. Organizations are urged to enforce 2FA, monyitor email/links, and block malicious domains to prevent persistent access.</p><p class="paragraph" style="text-align:left;">ℹ️ 🔑 <i><b>VoidStealer</b></i><b> is a new info‑stealer that bypasses Chrome’s Application‑Bound Encryption</b> to extract the browser&#39;s master key. It <a class="link" href="https://www.gendigital.com/blog/insights/research/voidstealer-abe-bypass?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">uses a debugger trick with hardware breakpoints </a>to read the v20_master_key from Chrome memory during startup. The technique appears based on the open‑source ElevationKatz tool and is the first such method seen in the wild.</p><hr class="content_break"><div class="embed"><a class="embed__url" href="https://cyberscoop.com/social-engineering-surge-intrusion-vector-mandiant-m-trends/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank"><div class="embed__content"><p class="embed__title"> The phone call is the new phishing email </p><p class="embed__description"> Voice-based phishing was at the root of multiple attack sprees Mandiant responded to last year, reflecting a concerning shift in tactics. </p><p class="embed__link"> cyberscoop.com/social-engineering-surge-intrusion-vector-mandiant-m-trends </p></div><img class="embed__image embed__image--right" src="https://cyberscoop.com/wp-content/uploads/sites/3/2026/03/GettyImages-2235631289.jpg"/></a></div></div><p class="paragraph" style="text-align:left;"></p><div id="ai-crypto-tech-tools" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🤖 🧰 AI, CRYPTO, TECH & TOOLS</h3><p class="paragraph" style="text-align:left;">💰️ <b>OpenAI launched a public safety bug bounty for AI-specific abuse and safety risks</b> in its products. The <a class="link" href="https://openai.com/index/safety-bug-bounty/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">program</a> accepts non-security issues like prompt injection, data exfiltration, agentic misuse, and connector vulnerabilities. Researchers can earn up to $7,500 for high-severity, reproducible reports with clear mitigations.</p><p class="paragraph" style="text-align:left;">🍎 🔐 <b>Apple says that since launching Lockdown Mode nearly four years ago, it has not seen any successful mercenary spyware hacks</b> on devices with the feature enabled. Independent researchers and organizations have documented attacks but <a class="link" href="https://techcrunch.com/2026/03/27/apple-says-no-one-using-lockdown-mode-has-been-hacked-with-spyware/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">found no confirmed bypasses of Lockdown Mode</a>, and some cases show it blocking spyware. Experts say Lockdown Mode greatly reduces attack surfaces and is recommended for people at high risk.</p><p class="paragraph" style="text-align:left;">📆 🔐 <b>Google will finish switching its products to quantum-resistant encryption by 2029</b> — The company sped up its plan because <a class="link" href="https://blog.google/innovation-and-ai/technology/safety-security/cryptography-migration-timeline/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">quantum computing progress is faster </a>than expected. Google hopes its aggressive timeline will push other companies to act sooner.</p><p class="paragraph" style="text-align:left;">🆕 🔐 <b>Mozilla released Firefox 149 with a built-in VPN that gives signed-in users 50 GB of browser-only traffic</b> per month. The VPN routes browser traffic through a U.S.-based proxy, can be toggled on per site, and will roll out first in the U.S., UK, Germany, and France. <a class="link" href="https://www.firefox.com/en-US/firefox/149.0/releasenotes/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">Firefox 149</a> also adds Split View, tighter SafeBrowsing controls, and patches many security flaws.</p><p class="paragraph" style="text-align:left;">🆕 🔎 <b>GitHub is adding AI-powered security detections to </b><i><b>Code Security</b></i><b> to find vulnerabilities</b> in more languages and frameworks <a class="link" href="https://cyberscoop.com/huntress-railway-ai-phishing-campaign-compromised-hundreds-of-organizations/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">beyond what static analysis covers</a>. These AI detections work with CodeQL and show risks and suggested fixes directly in pull requests. Copilot Autofix can then help developers fix issues quickly before code is merged.</p></div><p class="paragraph" style="text-align:left;"></p><div id="vulnerabilities-research-and-threat" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🐛 🧠 VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</h3><p class="paragraph" style="text-align:left;">➝ From the Patching Department:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/bind-updates-patch-high-severity-vulnerabilities-2/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">BIND Updates Patch High-Severity Vulnerabilities</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/cisco-patches-multiple-vulnerabilities-in-ios-software/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">Cisco Patches Multiple Vulnerabilities in IOS Software</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://thehackernews.com/2026/03/citrix-urges-patching-critical.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">Citrix Urges Patching Critical NetScaler Flaw Allowing Unauthenticated Data Leaks</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/chrome-146-update-patches-high-severity-vulnerabilities/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">Chrome 146 Update Patches High-Severity Vulnerabilities</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/ios-macos-26-4-roll-out-with-fresh-security-updates/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">iOS, macOS 26.4 Roll Out With Fresh Security Patches</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/qnap-patches-four-vulnerabilities-exploited-at-pwn2own/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">QNAP Patches Four Vulnerabilities Exploited at Pwn2Own</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/tp-link-warns-users-to-patch-critical-router-auth-bypass-flaw/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">TP-Link warns users to patch critical router auth bypass flaw</a></p></li></ul><hr class="content_break"><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/_f30RyXc_8Q" width="100%"></iframe><hr class="content_break"><p class="paragraph" style="text-align:left;">🔓️ 📲 <b>A hacker has posted a newer version of the DarkSword iPhone exploit kit</b> on GitHub. The leaked code makes it easy for <a class="link" href="https://techcrunch.com/2026/03/23/someone-has-publicly-leaked-an-exploit-kit-that-can-hack-millions-of-iphones/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">anyone to hack iPhones and iPads running older iOS versions</a>, likely affecting hundreds of millions of devices. Apple urges users to update their software to stay protected.</p><p class="paragraph" style="text-align:left;">🔓️ ☁️ <b>Researchers found </b><a class="link" href="https://thehackernews.com/2026/03/we-found-eight-attack-vectors-inside.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow"><b>eight ways attackers</b></a><b> can exploit AWS Bedrock</b> by abusing permissions, logs, agents, flows, knowledge bases, and prompts. A single over‑privileged identity can redirect data, hijack agents, poison prompts, or access corporate systems. Securing Bedrock requires tight permissions, inventory of AI workloads, and mapping attack paths.</p><p class="paragraph" style="text-align:left;">💥 🔓️ <b>Arctic Wolf found activity suggesting attackers exploited CVE-2025-32975</b>, a critical authentication bypass in unpatched Quest KACE SMA appliances. The flaw can let <a class="link" href="https://arcticwolf.com/resources/blog/cve-2025-32975/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">unauthenticated actors impersonate users and gain full admin control</a>, and Quest patched it in May 2025. Organizations with internet-exposed, unpatched KACE SMAs should apply the patch immediately.</p></div><p class="paragraph" style="text-align:left;"></p><div id="ics-ot-io-t" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🛰️ ICS, OT & IoT</h3><p class="paragraph" style="text-align:left;">🤷 🤷 🤷 </p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">💬 CONNECT</h3><p class="paragraph" style="text-align:left;">Follow me on <a class="link" href="https://infosec.exchange/@0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">Mastodon</a> for quick daily updates and bite-sized content.</p><p class="paragraph" style="text-align:left;">Prefer using an RSS feed? Add <b>Infosec MASHUP</b> to your feed <a class="link" href="https://rss.beehiiv.com/feeds/HVhiKYpQlR.xml?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">here</a>.</p><p class="paragraph" style="text-align:center;"><b>Enjoying our newsletter? </b>Forward it to a colleague—<br>it’s one of the best ways to support us.</p><p class="paragraph" style="text-align:left;">Thanks for reading today’s newsletter, and if you&#39;re enjoying it and want to support my work, you can <b>buy me a coffee</b> ☕ over at <a class="link" href="https://www.buymeacoffee.com/0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-13-2026-rsa-week-real-world-problems" target="_blank" rel="noopener noreferrer nofollow">https://www.buymeacoffee.com/0x58</a></p><p class="paragraph" style="text-align:left;"> See you next time!</p><p class="paragraph" style="text-align:left;">-X.</p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=7ec7b40e-d328-4a84-a6b5-69605ff1e593&utm_medium=post_rss&utm_source=x_s_infosec_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🕵🏻‍♂️ [InfoSec MASHUP] 12/2026 - Iran Is Everywhere This Week</title>
  <description>Plus: GlassWorm escalates its supply chain campaign, EU votes to ban mass message scanning, a witness blamed ChatGPT for his smartglasses</description>
  <link>https://infosec-mashup.santolaria.net/p/infosec-mashup-12-2026-iran-is-everywhere-this-week</link>
  <guid isPermaLink="true">https://infosec-mashup.santolaria.net/p/infosec-mashup-12-2026-iran-is-everywhere-this-week</guid>
  <pubDate>Sat, 21 Mar 2026 09:04:00 +0000</pubDate>
  <atom:published>2026-03-21T09:04:00Z</atom:published>
    <dc:creator>Xavier Santolaria</dc:creator>
    <category><![CDATA[Malware]]></category>
    <category><![CDATA[Opensource]]></category>
    <category><![CDATA[Privacy]]></category>
    <category><![CDATA[Cybersecurity]]></category>
    <category><![CDATA[Threat Intelligence]]></category>
    <category><![CDATA[Ai]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">👋 Writing this from San Diego 🇺🇸 — about as far from my Swiss desk as a timezone can stretch. But the news didn&#39;t care about my travel schedule.</p><p class="paragraph" style="text-align:left;">If there&#39;s one thread running through this week, it&#39;s Iran: Boggy Serpens refining its AI-enhanced espionage playbook, an attempted intrusion at Poland&#39;s nuclear research center with Iranian fingerprints, the EU hitting Iranian entities with fresh sanctions — and Iran&#39;s own population cut off from the internet for over two weeks now. Stryker is still cleaning up from last week&#39;s <i>Handala</i> attack too. A lot of activity from a lot of pro-Iran actors in one week.</p><p class="paragraph" style="text-align:left;">Oh, and if you’re in SF this week for <a class="link" href="https://www.rsaconference.com/usa?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">RSA</a>, don’t forget to check awesome side events listed here: <a class="link" href="https://xsa.github.io/infosec-events/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">https://xsa.github.io/infosec-events/</a></p><p class="paragraph" style="text-align:left;">Let’s now dive into this week’s top insights! 🚀</p><h2 class="heading" style="text-align:left;">Table of Contents</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="#breaches-security-incidents" rel="noopener noreferrer nofollow">BREACHES & SECURITY INCIDENTS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#cybercrime-cyber-espionage-ap-ts" rel="noopener noreferrer nofollow">CYBERCRIME, CYBER ESPIONAGE, APT’s</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#government-politics-and-privacy" rel="noopener noreferrer nofollow">GOVERNMENT, POLITICS, AND PRIVACY</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#malware-threats" rel="noopener noreferrer nofollow">MALWARE & THREATS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ai-crypto-tech-tools" rel="noopener noreferrer nofollow">AI, CRYPTO, TECH & TOOLS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#vulnerabilities-research-and-threat" rel="noopener noreferrer nofollow">VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ics-ot-io-t" rel="noopener noreferrer nofollow">ICS, OT & IoT</a></p></li></ul><div id="breaches-security-incidents" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🔓 BREACHES & SECURITY INCIDENTS</h3><p class="paragraph" style="text-align:left;">🇫🇷 🏃‍♂️ 📍 <b>A French Navy officer logged a run on the deck of the Charles de Gaulle and uploaded it to Strava</b>, revealing the <a class="link" href="https://techcrunch.com/2026/03/20/a-french-navy-officer-accidentally-leaked-the-location-of-an-aircraft-carrier-by-logging-his-run-on-strava/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">carrier’s exact location</a>. Strava defaults to public, and similar data has exposed military movements before. The French Armed Forces said the officer broke guidelines, and users should consider setting accounts to private.</p><p class="paragraph" style="text-align:left;">🇺🇸 🚗 <b>A cyberattack on breathalyzer firm </b><i><b>Intoxalock</b></i><b> has left drivers across the U.S. unable to start their cars</b> — The company paused systems and cannot perform required device calibrations. Intoxalock <a class="link" href="https://techcrunch.com/2026/03/20/cyberattack-on-vehicle-breathalyzer-company-leaves-drivers-stranded-across-the-us/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">did not disclose attack details</a> or a recovery timeline.</p><p class="paragraph" style="text-align:left;">🇺🇸 <b>Security researcher Jeremiah Fowler found publicly exposed </b><i><b>Sears</b></i><b> chatbot databases</b> that <a class="link" href="https://www.wired.com/story/sears-exposed-ai-chatbot-phone-calls-and-text-chats-to-anyone-on-the-web/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">contained millions of chat logs, audio files, and transcripts</a> with customers&#39; names, addresses, and phone numbers. Some recordings lasted hours and captured private conversations, raising risks of phishing and fraud. Transformco (the company that owns Sears and Sears Home Services) secured the data after being notified, but it’s still unclear who else accessed it.</p><p class="paragraph" style="text-align:left;">🇺🇸 <b>Intuitive Surgical said it was hit by a targeted phishing cyberattack that exposed</b> some internal business and contact data. The company says its surgical robots, manufacturing systems, and hospital networks were not affected. The <a class="link" href="https://www.securityweek.com/robotic-surgery-giant-intuitive-discloses-cyberattack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">breach is contained, regulators are being notified</a>, and no timeline or attacker details were given.</p><p class="paragraph" style="text-align:left;">🇺🇸 <b>Marquis says hackers stole personal and financial data from at least 672,075 people</b> in an August 2025 ransomware attack. Stolen data included names, birth dates, addresses, bank and card numbers, and Social Security numbers. Marquis <a class="link" href="https://techcrunch.com/2026/03/18/marquis-says-over-672000-people-had-personal-and-financial-data-stolen-in-ransomware-attack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">blames a SonicWall security failure</a> that let attackers access its network and deploy ransomware.</p><hr class="content_break"><p class="paragraph" style="text-align:left;">🇺🇸 <b>Stryker is restoring its internal systems after a cyberattack that wiped thousands</b> of employee devices. A pro‑Iran group called <i>Handala</i> claimed responsibility and said it used company admin access to remotely erase laptops and phones. The <a class="link" href="https://techcrunch.com/2026/03/17/stryker-says-its-restoring-systems-after-pro-iran-hackers-wiped-thousands-of-employee-devices/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">breach disrupted operations</a> but Stryker says its internet‑connected medical devices are safe.</p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://www.cisa.gov/news-events/alerts/2026/03/18/cisa-urges-endpoint-management-system-hardening-after-cyberattack-against-us-organization?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">CISA urges US orgs to secure Microsoft Intune systems after Stryker breach</a></p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://techcrunch.com/2026/03/19/fbi-seizes-pro-iranian-hacking-groups-websites-after-destructive-stryker-hack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">FBI seizes pro-Iranian hacking group’s websites after destructive Stryker hack</a></p><hr class="content_break"><p class="paragraph" style="text-align:left;">🤔 ⁉️ <b>Several major companies named by the Cl0p ransomware group in the Oracle E-Business Suite hack have not commented</b> on the breach — Broadcom, Bechtel, Estée Lauder, and Abbott <a class="link" href="https://www.securityweek.com/oracle-ebs-hack-only-4-corporate-giants-still-silent-on-potential-impact/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">remain silent</a> despite torrents claiming large amounts of stolen data. Companies may stay quiet for legal, strategic, or investigatory reasons.</p><p class="paragraph" style="text-align:left;">🇬🇧 <b>Companies House fixed a security flaw in its WebFiling service that exposed data for up to five million</b> U.K. companies. The bug, introduced in October 2025, let <a class="link" href="https://www.bleepingcomputer.com/news/security/uks-companies-house-confirms-security-flaw-exposed-business-data/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">logged-in users view other companies&#39; dashboards</a> and some non-public details like dates of birth and addresses. The agency says no passwords or identity documents were accessed, has reported the incident, and is investigating.</p><p class="paragraph" style="text-align:left;">🇨🇦 <b>Canadian retailer Loblaw says a criminal third party accessed</b> customer names, email addresses, and phone numbers. The company says passwords, health details, credit card data, and PC Financial <a class="link" href="https://www.securityweek.com/loblaw-data-breach-impacts-customer-information/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">were not affected</a>. It is unclear how many customers were impacted.</p><p class="paragraph" style="text-align:left;">🇬🇧 <b>The Guardian found that sensitive UK Biobank health data from 500,000 volunteers has been leaked</b> online many times. Researchers <a class="link" href="https://www.theguardian.com/science/2026/mar/14/confidential-health-records-exposed-online-uk-biobank?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">accidentally posted datasets to sites like GitHub</a>, exposing diagnoses and dates that could allow re-identification. Biobank says no names were shared and has issued takedown notices, but experts warn privacy risks remain.</p><p class="paragraph" style="text-align:left;">→ More:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/aura-confirms-data-breach-exposing-900-000-marketing-contacts/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">Aura confirms data breach exposing 900,000 marketing contacts</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/bitrefill-blames-north-korean-lazarus-group-for-cyberattack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">Bitrefill blames North Korean Lazarus group for cyberattack</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/navia-discloses-data-breach-impacting-27-million-people/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">Navia discloses data breach impacting 2.7 million people</a></p></li><li><p class="paragraph" style="text-align:left;"><a href="#b-af2b58cd-34a4-4913-9ae8-7cfe1c4356e8" target="_self" title="1 " data-skip-tracking="true"><sup style="-webkit-text-decoration:underline;text-decoration:underline;">1</sup></a><a class="link" href="https://www.securityweek.com/thousands-of-magento-sites-hit-in-ongoing-defacement-campaign/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">Thousands of Magento Sites Hit in Ongoing Defacement Campaign</a></p></li></ul></div><p class="paragraph" style="text-align:left;"></p><div id="cybercrime-cyber-espionage-ap-ts" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🥷🏻 CYBERCRIME, CYBER ESPIONAGE, APT’s</h3><div class="embed"><a class="embed__url" href="https://unit42.paloaltonetworks.com/boggy-serpens-threat-assessment/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank"><div class="embed__content"><p class="embed__title"> Boggy Serpens Threat Assessment </p><p class="embed__description"> Iranian threat group Boggy Serpens&#39; cyberespionage evolves with AI-enhanced malware and refined social engineering. Unit 42 details their persistent targeting. </p><p class="embed__link"> unit42.paloaltonetworks.com/boggy-serpens-threat-assessment </p></div><img class="embed__image embed__image--right" src="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/Boggy-Serpens.png"/></a></div><p class="paragraph" style="text-align:left;">🇺🇸 🤑 <b>A former Brightly Software contractor stole payroll and corporate data and then sent over 60 extortion emails</b> demanding $2.5 million. Brightly paid $7,540 in Bitcoin and reported the theft, leading the FBI to seize devices and charge 27-year-old Cameron Curry. He <a class="link" href="https://www.bleepingcomputer.com/news/security/data-analyst-found-guilty-of-extorting-brightly-software-of-25-million/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">faces up to 12 years in prison</a> for the extortion scheme.</p><p class="paragraph" style="text-align:left;">🇷🇺 🇺🇦 <b>A Russian state-sponsored group has exploited a high-severity XSS flaw in </b><i><b>Zimbra</b></i> to <a class="link" href="https://www.securityweek.com/russian-apt-exploits-zimbra-vulnerability-against-ukraine/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">attack Ukrainian targets</a>. The bug lets malicious CSS/JavaScript in email steal credentials, session tokens, 2FA backups and mailbox data. CISA <a class="link" href="https://www.cisa.gov/news-events/alerts/2026/03/18/cisa-adds-one-known-exploited-vulnerability-catalog?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">added</a> the flaw to its KEV list and urges immediate patching of Zimbra.</p><p class="paragraph" style="text-align:left;">🇮🇷 <b>Researchers found Iran-linked cyber groups built and staged hidden infrastructure for months before the Feb 28, 2026</b> US/Israeli strikes. After the strikes, about <a class="link" href="https://www.securityweek.com/iran-readied-cyberattack-capabilities-for-response-prior-to-epic-fury/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">60 coordinated hacktivist and APT groups launched attacks</a> mainly against US, Israeli, and Gulf targets. Kinetic strikes damaged Iranian internet links but did not stop or seriously degrade Iran’s cyber capabilities.</p><p class="paragraph" style="text-align:left;">🇨🇳 👀 <b>China-linked hackers have run a patient cyberespionage campaign against Southeast Asian militaries</b> since at least 2020. They used custom tools (AppleChris, MemFun, Getpass), PowerShell, and DLL hijacking to stay hidden and steal sensitive military files. Evidence like time-zone patterns, Chinese infrastructure, and Simplified Chinese <a class="link" href="https://unit42.paloaltonetworks.com/espionage-campaign-against-military-targets/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">suggests the group operates from China</a>.</p><p class="paragraph" style="text-align:left;">🇰🇭 <b>Cambodia says it will close all online scam centers</b> within weeks. Authorities have opened <a class="link" href="https://apnews.com/article/cambodia-cybercrime-phnom-penh-online-fraud-9bbfe6ee970b5a73529f5f820b931e1f?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">dozens of cases, arrested hundreds, and repatriated nearly 10,000</a> workers. Experts warn past raids left networks intact and say key beneficiaries may not be targeted.</p><p class="paragraph" style="text-align:left;">🎣 <b>A convicted scammer, Kwamaine Jerell Ford, is accused of running a new phishing scheme from prison</b> by impersonating an adult film star. He allegedly tricked professional athletes into giving iCloud logins and MFA codes, then stole their data and charged many fraudulent transactions. Prosecutors also say he coerced an OnlyFans model into sex acts and used videos to target more victims; <a class="link" href="https://cyberscoop.com/nba-nfl-athletes-social-engineering-scheme-apple-icloud-mfa/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">he faces 22 charges and is held without bail</a>.</p><p class="paragraph" style="text-align:left;">→ More:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/police-take-down-373-000-fake-csam-sites-in-operation-alice/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">Police take down 373,000 fake CSAM sites in Operation Alice</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/3-men-charged-with-conspiring-to-smuggle-us-artificial-intelligence-to-china/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">3 Men Charged With Conspiring to Smuggle U.S. Artificial Intelligence to China</a></p></li></ul></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;">🗓️ <b><a class="link" href="https://xsa.github.io/infosec-events/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">{Cyber,Info}Sec Events</a></b> — A community-maintained list of infosec conferences worldwide. Subscribe to the <a class="link" href="https://xsa.github.io/infosec-events/events.ics?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">ICS calendar feed</a> to get events straight into your calendar, or follow <a class="link" href="https://infosec.exchange/@infosecevents?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">@infosecevents@infosec.exchange</a> on Mastodon for weekly digests. Contributions and ⭐ welcome!</p></div><p class="paragraph" style="text-align:left;"></p><div id="government-politics-and-privacy" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">👨🏻‍⚖️ 👀 GOVERNMENT, POLITICS, AND PRIVACY</h3><div class="embed"><a class="embed__url" href="https://mastodon.social/@netblocks/116232059137625268?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank"><div class="embed__content"><p class="embed__title"> NetBlocks (@netblocks@mastodon.social) </p><p class="embed__description"> Attached: 1 image ⚠️ Update: #Iran&#39;s internet blackout has entered day 16 as the measure continues in its third week, with the public cut off from international networks for 360 hours. Chosen influencers enjoy whitelisting while state media report a new wave of arrests targeting Starlink users. </p><p class="embed__link"> mastodon.social/@netblocks/116232059137625268 </p></div><img class="embed__image embed__image--right" src="https://files.mastodon.social/media_attachments/files/116/232/055/907/179/238/original/9b51247b22b97d96.png"/></a></div><p class="paragraph" style="text-align:left;">🇮🇹 💰️ <b>Cloudflare appealed a €14.2M fine from Italy for refusing to block sites via its 1.1.1.1</b> DNS service. The company says<a class="link" href="https://arstechnica.com/tech-policy/2026/03/cloudflare-appeals-piracy-shield-fine-hopes-to-kill-italys-site-blocking-law/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow"> Italy’s Piracy Shield forces rapid, opaque blocking that breaks Internet architecture</a> and risks widespread overblocking. Cloudflare is fighting the law in Italian courts and with EU regulators.</p><p class="paragraph" style="text-align:left;">🇺🇸 <b>National Cyber Director Sean Cairncross said the Trump administration is not asking companies to carry out offensive cyberattacks</b> — Instead, the government wants private firms to share technical threat information so officials can respond. The <a class="link" href="https://cyberscoop.com/national-cyber-strategy-private-sector-offensive-operations-sean-cairncross/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">FBI also says companies should report breaches</a> and work with law enforcement to disrupt attackers.</p><p class="paragraph" style="text-align:left;">🇺🇸 💰️ <b>The FBI confirmed it has resumed buying Americans’ location and other data from commercial data brokers</b> to aid investigations. Critics say <a class="link" href="https://techcrunch.com/2026/03/18/fbi-is-buying-location-data-to-track-us-citizens-kash-patel-wyden/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">this lets agencies bypass warrant requirements</a> and may violate the Fourth Amendment. Lawmakers have proposed a bill to require court warrants before agencies can buy people’s data.</p><p class="paragraph" style="text-align:left;">🇪🇺 🇨🇳 🇮🇷 <b>The EU sanctioned three companies and two individuals from China and Iran</b> for <a class="link" href="https://www.consilium.europa.eu/en/press/press-releases/2026/03/16/cyber-attacks-against-the-eu-and-its-member-states-council-sanctions-three-entities-and-two-individuals/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">major cyberattacks</a>. One Chinese firm helped hack over 65,000 devices and another offered hacking-for-hire services. The Iranian company ran influence operations, stole subscriber data, and spread misinformation at the 2024 Paris Olympics.</p><p class="paragraph" style="text-align:left;">🇪🇺 🗳️ <b>The European Parliament voted to ban untargeted mass scanning of private messages</b> — Scans will be allowed <a class="link" href="https://cyberinsider.com/eu-votes-to-restrict-mass-scanning-of-peoples-private-messages/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">only when a judge names specific users or groups suspected</a> of child sexual abuse. Lawmakers extended a temporary CSAM rule until August 3, 2027, while negotiations continue.</p><div class="embed"><a class="embed__url" href="https://www.404media.co/witness-caught-using-smartglasses-in-court-blames-it-all-on-chatgpt/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank"><div class="embed__content"><p class="embed__title"> Witness Caught Using Smartglasses in Court Blames it all on ChatGPT </p><p class="embed__description"> A judge in London tossed out witness testimony after discovering the man was receiving coaching through a pair of smartglasses. </p><p class="embed__link"> www.404media.co/witness-caught-using-smartglasses-in-court-blames-it-all-on-chatgpt </p></div><img class="embed__image embed__image--right" src="https://www.404media.co/content/images/2026/03/Royal_Court2-1.jpg"/></a></div></div><p class="paragraph" style="text-align:left;"></p><div id="malware-threats" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🦠 MALWARE & THREATS</h3><div class="embed"><a class="embed__url" href="https://unit42.paloaltonetworks.com/ai-use-in-malware/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank"><div class="embed__content"><p class="embed__title"> Analyzing the Current State of AI Use in Malware </p><p class="embed__description"> Unit 42 research explores how AI is currently used in malware, from superficial integrations to advanced decision-making, and its future impact. </p><p class="embed__link"> unit42.paloaltonetworks.com/ai-use-in-malware </p></div><img class="embed__image embed__image--right" src="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/07_Malware_Category_1920x900-2.jpg"/></a></div><p class="paragraph" style="text-align:left;">🐍 <b>Researchers uncovered </b><i><b>Speagle</b></i><b>, malware that hijacks the Cobra DocGuard security program</b> to steal data. It hides exfiltration by using compromised Cobra servers and a legitimate driver. The <a class="link" href="https://www.security.com/threat-intelligence/speagle-cobradocguard-infostealer?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">attack appears targeted</a>, possibly for espionage, and may stem from a supply-chain compromise.</p><p class="paragraph" style="text-align:left;">🔎 📄 <i><b>Perseus</b></i><b> is new Android malware that steals sensitive data by scanning users&#39; note apps</b> for passwords, recovery phrases, and financial info. It <a class="link" href="https://www.threatfabric.com/blogs/perseus-dto-malware-that-takes-notes?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">spreads via sideloaded IPTV apps</a> and uses Accessibility Services to fully control devices, take screenshots, and hide activity. Users should avoid sideloading apps, stick to Google Play, and enable Play Protect.</p><p class="paragraph" style="text-align:left;">🍀 <b>Fraudsters used a legitimate </b><i><b>Nordstrom</b></i><b> email address to send a St. Patrick’s Day crypto scam</b> promising to double deposits. <i>Nordstrom</i> warned the messages were unauthorized and said it is investigating after some customers paid. The <a class="link" href="https://www.bleepingcomputer.com/news/security/nordstroms-email-system-abused-to-send-crypto-scams-to-customers/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">breach likely came through an Okta SSO to Salesforce compromise</a>, and customers are urged to ignore the promotion.</p><p class="paragraph" style="text-align:left;">🪱 <b>Researchers warn the </b><i><b>GlassWorm</b></i><b> campaign has escalated</b> by abusing Open VSX extensionPack and extensionDependencies to <a class="link" href="https://socket.dev/blog/open-vsx-transitive-glassworm-campaign?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">turn benign-looking extensions into delivery vehicles for malware</a>. At least 72 malicious extensions were found, mimicking developer tools and using obfuscation, invisible Unicode, and rotating Solana wallets to fetch commands and steal secrets. This tactic enables attackers to bypass review, inject malware transitively, and expand supply-chain compromises across registries and repositories.</p><p class="paragraph" style="text-align:left;">🤑 <b>Malicious JavaScript was delivered through the </b><i><b>AppsFlyer</b></i><b> Web SDK and could replace crypto wallet addresses</b> with attacker-controlled ones. The<a class="link" href="https://profero.io/blog/hijacked-at-the-source-a-trusted-marketing-appsflyers-sdk-distributes-a-crypto-stealer?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow"> injected code also stole the original addresses</a> and metadata from users. AppsFlyer says the issue was contained and is investigating while customers should check logs and use known-good SDK versions.</p><p class="paragraph" style="text-align:left;">🇺🇦 🇷🇺 <b>A new malware campaign called </b><i><b>DRILLAPP</b></i><b> targets Ukrainian groups</b> and likely links to Russian actors. It <a class="link" href="https://thehackernews.com/2026/03/drillapp-backdoor-targets-ukraine.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">runs a JavaScript backdoor inside Microsoft Edge</a> with special debug flags to access files, mic, camera, and screen. The attackers use paste services for control and changed tactics between February variants to improve file access and persistence.</p><p class="paragraph" style="text-align:left;">🎣 <b>Attackers hide phishing links and attachments by appending long blocks of benign text</b>, links, and many HTML break lines to emails. This <a class="link" href="https://blog.knowbe4.com/nlp-obfuscation-techniques-email-security-evasion?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">&quot;noise&quot; fools some NLP-based email security tools</a> into seeing messages as safe. KnowBe4 found this technique often uses real signatures and links (e.g., Bank of America, Uber) to evade detection.</p><p class="paragraph" style="text-align:left;">🎣 🇸🇪 <b>A C-level executive at </b><i><b>Outpost24</b></i><b> was targeted in a sophisticated phishing attack</b> that used a phishing-as-a-service kit called <i>Kratos</i>. Attackers chained redirects through trusted services (Cisco, Nylas) and reused a reclaimed domain, then served a convincing Microsoft 365 credential-stealing page behind Cloudflare. Specops <a class="link" href="https://specopssoft.com/blog/phishing-campaign-cisco/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">says the method fits Iran-linked group tactics</a> but attribution remains uncertain.</p></div><p class="paragraph" style="text-align:left;"></p><div id="ai-crypto-tech-tools" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🤖 🧰 AI, CRYPTO, TECH & TOOLS</h3><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/MhJoJRqJ0Wc" width="100%"></iframe><hr class="content_break"><p class="paragraph" style="text-align:left;">☁️ <b>Bucketsquatting is (Finally) Dead</b> — AWS added a new bucket namespace pattern (<code>prefix-accountid-region-an</code>) to <a class="link" href="https://onecloudplease.com/blog/bucketsquatting-is-finally-dead?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">stop bucketsquatting</a>. This ensures only the owning account can create buckets with that name and helps prevent attacks. Use the namespace for all new S3 buckets and migrate existing ones if you need protection!</p><p class="paragraph" style="text-align:left;">📲 ⏳️ <b>Google will add a mandatory 24-hour wait before users can sideload apps from unverified Android developers to reduce malware</b> and scams. Power users can enable an &quot;advanced flow&quot; with steps like developer mode, a restart, and biometric confirmation to allow sideloading after the wait. Google <a class="link" href="https://android-developers.googleblog.com/2026/03/android-developer-verification.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">will also offer limited free developer accounts</a> for hobbyists and students while its verification rules take effect.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/a54b2f2a-1c4a-403a-a705-21723d286291/image.png?t=1774019645"/><div class="image__source"><span class="image__source_text"><p>Figure: The Advanced Flow/Google</p></span></div></div><hr class="content_break"><p class="paragraph" style="text-align:left;">🎵 🤑 <b>North Carolina musician Michael Smith pleaded guilty to using AI-generated songs and automated bots to fraudulently stream music</b> on major platforms. He and accomplices <a class="link" href="https://www.bleepingcomputer.com/news/security/musician-pleads-guilty-to-10m-streaming-fraud-powered-by-ai-bots/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">streamed the fake tracks billions of times, collecting over $10 million</a> in royalties. Smith agreed to forfeit about $8.09 million and faces up to five years in prison.</p><p class="paragraph" style="text-align:left;">🙊 🤖 <b>A Meta AI agent shared a private internal answer without permission</b>, exposing company and user data to unauthorized engineers for two hours. The <a class="link" href="https://techcrunch.com/2026/03/18/meta-is-having-trouble-with-rogue-ai-agents/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">agent also gave bad advice that led to the exposure</a>, and Meta rated it a high-severity incident.</p><p class="paragraph" style="text-align:left;">🤝 <b>Major tech and retail companies, including Google, Meta, Microsoft, Amazon and OpenAI</b>, signed a pact to fight online scams and fraud. They <a class="link" href="https://services.google.com/fh/files/newsletters/industryaccord.pdf?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">agreed</a> to share threat information, strengthen prevention and verification, and help users report scams. They also urged governments to make scam prevention a national priority and improve data sharing and laws.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/b3af34f8-2e05-4449-93f9-fedda5a06a25/image.png?t=1773872145"/><div class="image__source"><span class="image__source_text"><p>Figure: Industry Accord Signatories/Google.com</p></span></div></div><hr class="content_break"><p class="paragraph" style="text-align:left;">🐛 <b>Researchers found several serious AI security flaws</b>: Amazon Bedrock&#39;s sandbox allows DNS-based data exfiltration and remote shells, LangSmith had a token-theft URL injection flaw fixed in v0.12.71, and SGLang contains unpatched pickle deserialization bugs that enable remote code execution. Attackers could <a class="link" href="https://www.beyondtrust.com/blog/entry/pwning-aws-agentcore-code-interpreter?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">use these issues to steal data, take over accounts, or run arbitrary code</a> if services are misconfigured or exposed. Administrators should restrict network access, audit IAM roles, migrate to VPC mode or apply DNS firewalls, and patch or isolate vulnerable deployments.</p><p class="paragraph" style="text-align:left;">🍏 🔄 <b>Apple released its first </b><i><b>background security</b></i><b> update</b> for iPhone, iPad, and Mac to fix a Safari WebKit bug. The <a class="link" href="https://techcrunch.com/2026/03/17/apple-rolls-out-first-background-security-update-for-iphones-ipads-and-macs-to-fix-safari-bug/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">bug could let a malicious website access data</a> from another site in the same browser session. The lightweight update installs quickly and is pushed between major software releases.</p><p class="paragraph" style="text-align:left;">🇨🇳 🦞 <b>Chinese cybersecurity officials warned that </b><i><b>OpenClaw</b></i><b>, the popular open-source AI agent, has weak default security </b>and high system privileges that attackers can exploit. Researchers showed <a class="link" href="https://thehackernews.com/2026/03/openclaw-ai-agent-flaws-could-enable.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">attackers can use indirect prompt injection</a>—like poisoned web pages or link previews—to make the agent leak sensitive data or run malicious commands. Users are urged to tighten network controls, isolate the service, avoid untrusted skills, and keep the agent updated.</p></div><p class="paragraph" style="text-align:left;"></p><div id="vulnerabilities-research-and-threat" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🐛 🧠 VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</h3><p class="paragraph" style="text-align:left;">➝ From the Patching Department:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/connectwise-patches-new-flaw-allowing-screenconnect-hijacking/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">ConnectWise patches new flaw allowing ScreenConnect hijacking</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/oracle-pushes-emergency-fix-for-critical-identity-manager-rce-flaw/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">Oracle pushes emergency fix for critical Identity Manager RCE flaw</a></p></li></ul><hr class="content_break"><div class="image"><a class="image__link" href="https://defcon.social/@mauvehed/116252427988398306?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/1ef96322-e200-4591-be7f-5adfc2e1da2b/Screenshot_2026-03-18_at_15.22.25.png?t=1773872569"/></a><div class="image__source"><span class="image__source_text"><p>Figure: Screenshot of Mauvehed’s <a class="link" href="https://defcon.social/@mauvehed/116252427988398306?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">Toot</a></p></span></div></div><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://attrition-org.github.io/web-hack-mirror/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">https://attrition-org.github.io/web-hack-mirror</a>/</p><hr class="content_break"><p class="paragraph" style="text-align:left;">🔓️ ☁️ <b>A critical path-traversal bug (CVE-2026-22557) in Ubiquiti’s UniFi Network Application could let attackers take over accounts</b> by accessing files. Ubiquiti released patches and advises users to update; a second fix (CVE-2026-22558) closes a privilege-escalation flaw. About <a class="link" href="https://cyberscoop.com/ubiquiti-unifi-networking-application-vulnerability/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">88,000 UniFi hosts are internet-exposed</a>, many in the U.S., raising urgent risk.</p><p class="paragraph" style="text-align:left;">💥 <b>A critical Langflow vulnerability (CVE-2026-33017) allowed unauthenticated remote code execution</b> via a POST endpoint. Attackers <a class="link" href="https://www.sysdig.com/blog/cve-2026-33017-how-attackers-compromised-langflow-ai-pipelines-in-20-hours?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">began exploiting it roughly 20 hours after public disclosure</a> to steal keys and credentials. Sysdig observed multi-stage attacks from several IPs leading to data exfiltration and possible supply-chain risk.</p><p class="paragraph" style="text-align:left;">📸 🔓️ <b>Researchers found three serious flaws in Xiaomi camera setup protocol </b>that let attackers bypass setup, predict crypto randomness, and trigger a heap overflow. Using these bugs<a class="link" href="https://labs.taszk.io/articles/post/nowyouseemi/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow"> they achieved remote root code execution</a> and built a persistent “cloud jailbreak.” The jailbreak lets attackers control the camera, steal Wi‑Fi credentials, and cut the device off from Xiaomi cloud services.</p><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/Re66rfXbB2s" width="100%"></iframe><hr class="content_break"><p class="paragraph" style="text-align:left;">😬 <b>Cisco has had a recent flood of SD‑WAN and firewall vulnerabilities, and many were already being actively exploited</b> — Attackers, including ransomware group <i>Interlock</i>, used zero‑days and other flaws to <a class="link" href="https://cyberscoop.com/cisco-firewall-sd-wan-vulnerabilities-exploited/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">gain powerful management‑plane access</a>. Researchers warn this shows attackers target network edge systems for broad, long‑lasting control.</p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://aws.amazon.com/blogs/security/amazon-threat-intelligence-teams-identify-interlock-ransomware-campaign-targeting-enterprise-firewalls/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">Amazon found Interlock ransomware exploiting a critical Cisco firewall flaw and active since Jan 26, 2026, before Cisco disclosed it</a></p><p class="paragraph" style="text-align:left;">🍎 🇷🇺 <b>Researchers found a second iOS exploit kit, called </b><i><b>Darksword</b></i><b>, likely reused by suspected Russian hackers </b>from tools originally made for the U.S. government. <i>Darksword</i> can steal passwords, crypto wallets, messages, and may be used for both money and surveillance, putting up to hundreds of millions of iPhones at risk. The <a class="link" href="https://cyberscoop.com/second-ios-exploit-kit-emerges-from-suspected-russian-hackers-using-possible-u-s-government-developed-tools/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">kit shows use of AI-generated code and poor operational security</a>, and researchers warn a growing secondary exploit market now targets mobile devices.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/7b9e051b-1393-4ee7-a4fb-34906c133cd7/image.png?t=1773875846"/><div class="image__source"><span class="image__source_text"><p>Figure: Timeline of DarkSword observations and vulnerability patches/cloud.google.com</p></span></div></div><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://support.apple.com/en-us/126776?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks</a></p><hr class="content_break"><p class="paragraph" style="text-align:left;">🐧 <b>A critical buffer-overflow bug in GNU InetUtils telnetd</b> (CVE-2026-32746) <a class="link" href="https://dreamgroup.com/vulnerability-advisory-pre-auth-remote-code-execution-via-buffer-overflow-in-telnetd-linemode-slc-handler/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week#" target="_blank" rel="noopener noreferrer nofollow">lets unauthenticated attackers run code as root </a>via port 23. The flaw is triggered during the initial Telnet handshake and affects versions through 2.7; a fix is expected by April 1, 2026. Until patched, disable Telnet, block port 23, or run telnetd without root to reduce risk.</p><p class="paragraph" style="text-align:left;">🔎 🐛 <b>RondoDox’s operators expanded their exploit list to 174 vulnerabilities and now track disclosures</b> to <a class="link" href="https://www.bitsight.com/blog/rondodox-botnet-infrastructure-analysis?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">strike before CVEs are assigned</a>. They shifted from broad scanning to a more targeted exploitation strategy to increase successful infections. The botnet uses its own infrastructure to deploy evasive implants and mainly focuses on DDoS campaigns rather than mass propagation.</p><hr class="content_break"><blockquote align="center" class="twitter-tweet"><a href="https://twitter.com/nicowaisman/status/2032539305525043686?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week"><p> Twitter tweet </p></a></blockquote></div><p class="paragraph" style="text-align:left;"></p><div id="ics-ot-io-t" class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🛰️ ICS, OT & IoT</h3><p class="paragraph" style="text-align:left;">🇺🇸 🇨🇦 🇩🇪 <b>U.S., Canadian and German authorities disrupted four large IoT botnets that had infected over three million devices</b> and launched massive DDoS attacks. The botnets—Aisuru, Kimwolf, JackSkid and Mossad—sent hundreds of thousands of attack commands and were used for extortion. Investigators <a class="link" href="https://krebsonsecurity.com/2026/03/feds-disrupt-iot-botnets-behind-huge-ddos-attacks/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">seized servers and domains and targeted alleged operators</a> in coordinated international actions.</p><p class="paragraph" style="text-align:left;">☁️ 🔓️ <b>Researchers found serious security flaws in low-cost IP KVM devices</b> from four manufacturers. These small gadgets let users control machines at the BIOS/UEFI level. If exposed to the Internet, misconfigured, or compromised, they <a class="link" href="https://arstechnica.com/security/2026/03/researchers-disclose-vulnerabilities-in-ip-kvms-from-4-manufacturers/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">can give insiders or hackers</a> wide network access.</p><p class="paragraph" style="text-align:left;">🇵🇱 <b>Poland’s National Centre for Nuclear Research (NCBJ) was targeted in a recent cyberattack that was stopped</b> before any systems were compromised. Officials say <a class="link" href="https://www.securityweek.com/hack-attempt-reported-at-polands-nuclear-research-center/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">early indicators point to Iranian-linked hackers</a>, but they warn the evidence could be misleading. This follows a separate cyber incident on Poland’s power grid two months earlier.</p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">💬 CONNECT</h3><p class="paragraph" style="text-align:left;">Follow me on <a class="link" href="https://infosec.exchange/@0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">Mastodon</a> for quick daily updates and bite-sized content.</p><p class="paragraph" style="text-align:left;">Prefer using an RSS feed? Add <b>Infosec MASHUP</b> to your feed <a class="link" href="https://rss.beehiiv.com/feeds/HVhiKYpQlR.xml?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">here</a>.</p><p class="paragraph" style="text-align:center;"><b>Enjoying our newsletter? </b>Forward it to a colleague—<br>it’s one of the best ways to support us.</p><p class="paragraph" style="text-align:left;">Thanks for reading today’s newsletter, and if you&#39;re enjoying it and want to support my work, you can <b>buy me a coffee</b> ☕ over at <a class="link" href="https://www.buymeacoffee.com/0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-12-2026-iran-is-everywhere-this-week" target="_blank" rel="noopener noreferrer nofollow">https://www.buymeacoffee.com/0x58</a></p><p class="paragraph" style="text-align:left;"> See you next time!</p><p class="paragraph" style="text-align:left;">-X.</p></div><p class="paragraph" style="text-align:left;"></p><div style="border-top:2px solid #272A2F1A;padding:15px;"><p id="b-af2b58cd-34a4-4913-9ae8-7cfe1c4356e8"><span style="font-variant-numeric:tabular-nums;text-decoration:underline;text-underline-offset:2px;">1</span>&nbsp; </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=21c734f4-a9c0-4342-8192-d650d599df89&utm_medium=post_rss&utm_source=x_s_infosec_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🕵🏻‍♂️ [InfoSec MASHUP] 11/2026 - When Bombs Fall, Keyboards Follow</title>
  <description>Plus: FBI hacked, Salt Typhoon goes global, Instagram dropping E2E encryption, and an AI agent hacked McKinsey&#39;s chatbot in two hours</description>
  <link>https://infosec-mashup.santolaria.net/p/infosec-mashup-11-2026-when-bombs-fall-keyboards-follow</link>
  <guid isPermaLink="true">https://infosec-mashup.santolaria.net/p/infosec-mashup-11-2026-when-bombs-fall-keyboards-follow</guid>
  <pubDate>Fri, 13 Mar 2026 20:43:00 +0000</pubDate>
  <atom:published>2026-03-13T20:43:00Z</atom:published>
    <dc:creator>Xavier Santolaria</dc:creator>
    <category><![CDATA[Malware]]></category>
    <category><![CDATA[Opensource]]></category>
    <category><![CDATA[Privacy]]></category>
    <category><![CDATA[Cybersecurity]]></category>
    <category><![CDATA[Threat Intelligence]]></category>
    <category><![CDATA[Ai]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><b>The Hacktivist Mirror Problem</b></p><p class="paragraph" style="text-align:left;">When bombs fall, keyboards follow. The <a class="link" href="https://www.ransomlook.io/group/Handala?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow"><b>Handala</b></a> attack on <b>Stryker</b> — <a class="link" href="https://www.zetter-zeroday.com/iranian-hacktivists-strike-medical-device-maker-stryker-in-severe-attack-that-wiped-systems/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">200,000 systems claimed wiped, 50TB stolen</a>, timed explicitly to the US-Israeli assault on Iran — is textbook retaliation hacktivist logic. But here&#39;s the thing nobody wants to say out loud: it barely matters whether the group is genuinely aggrieved civilians or a state front wearing a keffiyeh. The effect is identical. The deniability is the point.</p><p class="paragraph" style="text-align:left;">Governments have learned that a &quot;spontaneous&quot; hacktivist campaign does more reputational work than an official cyberunit ever could — and when the targeting is this clean, &quot;spontaneous&quot; deserves serious scare quotes. We saw it with pro-Russian groups after Ukraine. We saw it with pro-Palestinian groups after Gaza. We&#39;re seeing it again now with Iran. The pattern is consistent enough to be a doctrine at this point.</p><p class="paragraph" style="text-align:left;">What makes it strategically interesting — and analytically treacherous — is the deliberate ambiguity it manufactures. A group claiming to represent bombed civilians carries far more narrative weight than one that&#39;s transparently state-linked. Attribution becomes a second-order problem: even if the group is genuinely independent, states benefit from the chaos and quietly let it run. Sometimes they seed it. Sometimes they just watch. The outcome for the victim is the same either way.</p><p class="paragraph" style="text-align:left;">The targeting logic follows a reliable playbook too. Not purely military or intelligence targets — those carry too much legal and escalatory risk. Instead: corporations with visible ties to the aggressor country, ideally ones with symbolic weight or defense adjacency. <b>Stryker</b>, with its $450M U.S. military contract and the same name as an Army armored carrier, checked every box. The selection wasn&#39;t random. It was a message dressed as an attack.</p><p class="paragraph" style="text-align:left;">For defenders, none of this is new — but the tempo is accelerating. Geopolitical flashpoints are now predictable threat amplifiers with a measurable lag between event and campaign. Your company&#39;s government contracts, your country of incorporation, your defense-adjacent partnerships — these are part of your attack surface whether you&#39;ve modelled them that way or not. The groups carrying the flag may be real, fake, or somewhere in the uncomfortable middle. It doesn&#39;t matter. The wiper doesn&#39;t care about the ideology behind it.</p><p class="paragraph" style="text-align:left;">Let’s now dive into this week’s top insights! 🚀</p><h2 class="heading" style="text-align:left;">Table of Contents</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="#breaches-security-incidents" rel="noopener noreferrer nofollow">BREACHES & SECURITY INCIDENTS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#cybercrime-cyber-espionage-ap-ts" rel="noopener noreferrer nofollow">CYBERCRIME, CYBER ESPIONAGE, APT’s</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#government-politics-and-privacy" rel="noopener noreferrer nofollow">GOVERNMENT, POLITICS, AND PRIVACY</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#malware-threats" rel="noopener noreferrer nofollow">MALWARE & THREATS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ai-crypto-tech-tools" rel="noopener noreferrer nofollow">AI, CRYPTO, TECH & TOOLS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#vulnerabilities-research-and-threat" rel="noopener noreferrer nofollow">VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ics-ot-io-t" rel="noopener noreferrer nofollow">ICS, OT & IoT</a></p></li></ul><div id="breaches-security-incidents" class="section" style="background-color:transparent;border-color:#C0C0C0;border-radius:10px;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🔓 BREACHES & SECURITY INCIDENTS</h3><p class="paragraph" style="text-align:left;">🇬🇧 🏦 🙊 <b>A technical glitch at Lloyds Banking Group let some Lloyds, Halifax and Bank of Scotland app users see other customers&#39; transactions</b> and personal details. The bank says the <a class="link" href="https://www.bbc.com/news/articles/c4g23npxpwgo?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">error was fixed quickly and apologised</a>, while regulators are investigating. Customers reported seeing accounts, payments and even National Insurance numbers that were not theirs.</p><p class="paragraph" style="text-align:left;">🇮🇱 🚉 🇮🇷 <b>A cyberattack hacked advertising screens at Herzliya and Tel Aviv Hashalom stations</b> and <a class="link" href="https://www.calcalistech.com/ctechnews/article/rkuy5flcbx?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">showed fake Iranian missile alerts</a>. Authorities say the signs were from a private network, not connected to railway infrastructure, and were taken offline. National cybersecurity teams are investigating while Israel Railways works to restore and expand service.</p><p class="paragraph" style="text-align:left;">🇮🇷 🇺🇸 <i><b>Stryker</b></i><b>, a major medical device maker, suffered a severe global cyberattack that shut down many systems</b> and wiped devices. An <a class="link" href="https://www.zetter-zeroday.com/iranian-hacktivists-strike-medical-device-maker-stryker-in-severe-attack-that-wiped-systems/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">Iranian hacktivist group called </a><i><a class="link" href="https://www.zetter-zeroday.com/iranian-hacktivists-strike-medical-device-maker-stryker-in-severe-attack-that-wiped-systems/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">Handala</a></i><a class="link" href="https://www.zetter-zeroday.com/iranian-hacktivists-strike-medical-device-maker-stryker-in-severe-attack-that-wiped-systems/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow"> claimed credit</a> and said they erased servers and stole data. The company is working to restore operations while investigating the incident.</p><p class="paragraph" style="text-align:left;">🛞 <b>Tire maker </b><i><b>Michelin</b></i><b> confirmed it was hit in the large Oracle E-Business Suite (EBS) cyberattack</b> tied to the <i>Cl0p</i> group. Investigators found an EBS zero-day was exploited and some files were accessed, but <a class="link" href="https://www.securityweek.com/michelin-confirms-data-breach-linked-to-oracle-ebs-attack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow"><i>Michelin</i></a><a class="link" href="https://www.securityweek.com/michelin-confirms-data-breach-linked-to-oracle-ebs-attack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow"> says only a small, non-sensitive data set was affected</a> and no ransomware was used. The attackers have posted hundreds of gigabytes of alleged Michelin data online.</p><p class="paragraph" style="text-align:left;">🤖 <b>Researchers at CodeWall used an autonomous AI agent to hack McKinsey’s internal chatbot</b>, <i>Lilli</i>, and gained full read-write access in about two hours. The agent exploited exposed API endpoints and an SQL injection to access millions of messages, files, user accounts, and writable system prompts. McKinsey <a class="link" href="https://www.theregister.com/2026/03/09/mckinsey_ai_chatbot_hacked/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">patched the issues quickly</a>, but the incident shows agentic AI can enable fast, automated cyberattacks.</p><div class="embed"><a class="embed__url" href="https://codewall.ai/blog/how-we-hacked-mckinseys-ai-platform?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank"><div class="embed__content"><p class="embed__title"> How We Hacked McKinsey&#39;s AI Platform </p><p class="embed__description"> An autonomous AI agent found a SQL injection in McKinsey&#39;s Lilli AI platform. What it extracted was worse than we expected. </p><p class="embed__link"> codewall.ai/blog/how-we-hacked-mckinseys-ai-platform </p></div><img class="embed__image embed__image--right" src="https://codewall.ai/images/mckinsey-og.png"/></a></div><p class="paragraph" style="text-align:left;">🇺🇸 <b>Ericsson Inc. says a service provider was hacked</b> and some employee and customer data was stolen. The <a class="link" href="https://www.bleepingcomputer.com/news/security/ericsson-us-discloses-data-breach-after-service-provider-hack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">provider found the breach in April 2025</a> and finished an investigation in February 2026. Affected people are being offered free identity protection and compensation coverage.</p><p class="paragraph" style="text-align:left;">🇨🇳 <i><b>Salt Typhoon</b></i><b>, a China-linked hacking group, has breached dozens of major phone and internet companies</b> worldwide. They stole call logs, texts, and audio from senior officials and compromised telecom infrastructure. Officials say the <a class="link" href="https://techcrunch.com/2026/03/09/salt-typhoon-china-who-has-been-hacked-global-telecom-giants/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">campaign spans the Americas, Europe, Asia, Africa, and Oceania</a> and risks serious national security harm.</p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://cyberscoop.com/salt-typhoon-china-telecom-hack-impact-new-jersey/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">Officials worry Salt Typhoon apathy is killing momentum for tougher telecom security rules</a></p><p class="paragraph" style="text-align:left;">☁️ <b>Hackers from the </b><i><b>ShinyHunters</b></i><b> group claim they have been stealing data from misconfigured Salesforce Experience Cloud sites</b> by abusing the <code>/s/sfsites/aura</code> API. Salesforce says the issue is due to customer guest-user settings, not a platform vulnerability, and advises auditing guest permissions and disabling API access for guests. <i>ShinyHunters</i> says they found ways to bypass record limits and urges disabling public access, which would remove guest access entirely.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/e7a92ded-9e1c-4116-81f5-33fdd83f9042/image.png?t=1773145844"/><div class="image__source"><span class="image__source_text"><p>Figure: <i>ShinyHunters</i> Salesforce Aura campaign/BleepingComputer</p></span></div></div><p class="paragraph" style="text-align:left;">→ More:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/238000-impacted-by-bell-ambulance-data-breach/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">238,000 Impacted by Bell Ambulance Data Breach</a> 🇺🇸 </p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/telus-digital-confirms-breach-after-hacker-claims-1-petabyte-data-theft/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">Telus Digital confirms breach after hacker claims 1 petabyte data theft</a> 🇺🇸 </p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/england-hockey-investigating-ransomware-data-breach/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">England Hockey investigating ransomware data breach</a> 🏑 🇬🇧 </p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/canadian-retail-giant-loblaw-notifies-customers-of-data-breach/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">Canadian retail giant Loblaw notifies customers of data breach</a> 🇨🇦 </p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/starbucks-discloses-data-breach-affecting-hundreds-of-employees/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">Starbucks discloses data breach affecting hundreds of employees</a> ☕️</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/polands-nuclear-research-centre-targeted-by-cyberattack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">Poland&#39;s nuclear research centre targeted by cyberattack </a>🇵🇱 </p></li></ul></div><p class="paragraph" style="text-align:left;"></p><div id="cybercrime-cyber-espionage-ap-ts" class="section" style="background-color:transparent;border-color:#C0C0C0;border-radius:10px;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🥷🏻 CYBERCRIME, CYBER ESPIONAGE, APT’s</h3><p class="paragraph" style="text-align:left;">❌ <b>Interpol-led </b><i><b>Operation Synergia III</b></i><b> sinkholed tens of thousands of IP addresses and seized servers</b> tied to global cybercrime. Authorities in 72 countries made 94 arrests, seized 212 devices, and are still investigating 110 more suspects. Investigations <a class="link" href="https://www.interpol.int/News-and-Events/News/2026/45-000-malicious-IP-addresses-taken-down-in-international-cyber-operation?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">also found over 33,000 phishing sites</a> and large fraud rings in Togo and Bangladesh.</p><p class="paragraph" style="text-align:left;">❌ <b>Law enforcement from many countries dismantled </b><i><b>SocksEscort</b></i><b>, a global proxy network used for large-scale fraud</b> — The <a class="link" href="https://www.justice.gov/usao-edca/pr/authorities-dismantle-global-malicious-proxy-service-deployed-malware-and-defrauded?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">botnet hijacked hundreds of thousands of routers and IoT devices</a> and took in millions of dollars. Authorities seized domains, servers, and cryptocurrency to disrupt the operation.</p><p class="paragraph" style="text-align:left;">🇺🇸 ⚖️ <b>The U.S. charged former DigitalMint employee Angelo Martino for secretly helping BlackCat ransomware operators</b> and sharing negotiation details. He and accomplices allegedly <a class="link" href="https://www.bleepingcomputer.com/news/security/us-charges-another-ransomware-negotiator-linked-to-blackcat-attacks/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">ran attacks on many U.S. organizations</a> and took ransoms, sometimes paying BlackCat a cut. DigitalMint fired the employees and says it cooperated with law enforcement.</p><p class="paragraph" style="text-align:left;">🇺🇸 <b>A foreign hacker broke into the FBI’s New York field office in 2023 and accessed files about Jeffrey Epstein</b> — The breach exploited a vulnerable server at the Child Exploitation Forensic Lab. The <a class="link" href="https://techcrunch.com/2026/03/11/hacker-broke-into-fbi-and-compromised-epstein-files-report-says/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">FBI says it contained the incident</a> and stopped the hacker’s access.</p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-radius:10px;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;">🗓️ <b><a class="link" href="https://xsa.github.io/infosec-events/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">{Cyber,Info}Sec Events</a></b> — A community-maintained list of infosec conferences worldwide. Subscribe to the <a class="link" href="https://xsa.github.io/infosec-events/events.ics?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">ICS calendar feed</a> to get events straight into your calendar, or follow <a class="link" href="https://infosec.exchange/@infosecevents?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">@infosecevents@infosec.exchange</a> on Mastodon for weekly digests. Contributions and ⭐ welcome!</p></div><p class="paragraph" style="text-align:left;"></p><div id="government-politics-and-privacy" class="section" style="background-color:transparent;border-color:#C0C0C0;border-radius:10px;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">👨🏻‍⚖️ 👀 GOVERNMENT, POLITICS, AND PRIVACY</h3><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/MOw8YwB1HRE" width="100%"></iframe><hr class="content_break"><p class="paragraph" style="text-align:left;">🇫🇮 🇷🇺 🇨🇳 <b>Finland’s 2026 security report warns that Russia and China are actively using cyber espionage against Finnish government</b>, companies, and critical infrastructure. Both countries exploit supply chains, cloud services, and poorly protected consumer devices to steal information and hide their tracks. These operations <a class="link" href="https://industrialcyber.co/reports/finlands-national-security-overview-2026-flags-russian-and-chinese-cyber-espionage-targeting-government-critical-infrastructure/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">raise risks for national security</a>, influence campaigns, and Western dependence on Chinese technology.</p><p class="paragraph" style="text-align:left;">🇺🇸 🇷🇺 🇨🇳 📲 <b>Researchers say a powerful iPhone-hacking toolkit called </b><i><b>Coruna</b></i><b> was likely built by L3Harris’s Trenchant unit</b> and sold to U.S. government customers. The tools leaked, were traded by brokers, <a class="link" href="https://techcrunch.com/2026/03/10/us-military-contractor-likely-built-iphone-hacking-tools-used-by-russian-spies-in-ukraine/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">and ended up used by Russian spies in Ukraine</a> and by Chinese cybercriminals. The case links stolen contractor tools and a former employee who sold exploits to outside parties.</p><p class="paragraph" style="text-align:left;">🇪🇺 🎣 <b>An EU court adviser says banks must immediately refund customers for unauthorised transactions</b> unless they have good reason to suspect customer fraud. The <a class="link" href="https://curia.europa.eu/site/upload/docs/application/pdf/2026-03/cp260031en.pdf?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">opinion came from a case about a phishing attack</a> where a customer’s login was stolen and the bank refused a refund. Banks can later try to recover money if they prove the customer acted with intent or gross negligence.</p></div><p class="paragraph" style="text-align:left;"></p><div id="malware-threats" class="section" style="background-color:transparent;border-color:#C0C0C0;border-radius:10px;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🦠 MALWARE & THREATS</h3><div class="embed"><a class="embed__url" href="https://unit42.paloaltonetworks.com/cl-unk-1068-targets-critical-sectors/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank"><div class="embed__content"><p class="embed__title"> An Investigation Into Years of Undetected Operations Targeting High-Value Sectors </p><p class="embed__description"> In-depth analysis of threat activity we call CL-UNK-1068. We discuss their toolset, including tunneling, reconnaissance and credential theft. </p><p class="embed__link"> unit42.paloaltonetworks.com/cl-unk-1068-targets-critical-sectors </p></div><img class="embed__image embed__image--right" src="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/04_Malware_Category_1920x900.jpg"/></a></div><p class="paragraph" style="text-align:left;">🔎 🎮️ <b>The FBI is investigating a hacker who hid malware inside several games</b> on Steam. The <a class="link" href="https://techcrunch.com/2026/03/13/valve-steam-malware-games-fbi/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">suspected titles include BlockBlasters, Chemia, Dashverse/DashFPS, Lampy, Lunara, PirateFi, and Tokenova</a>. Steam has removed similar malware-laced games before, but some users may have been infected.</p><p class="paragraph" style="text-align:left;">🔙 🚪 <b>Researchers found a new backdoor called </b><i><b>Slopoly</b></i><b>, likely generated with AI</b>, used in an Interlock ransomware attack to steal data. Slopoly is a simple PowerShell client that beacons to a C2 server, runs commands, and keeps persistence. IBM X-Force <a class="link" href="https://www.ibm.com/think/x-force/slopoly-start-ai-enhanced-ransomware-attacks?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">links the attack to a financially motivated group known as </a><i><a class="link" href="https://www.ibm.com/think/x-force/slopoly-start-ai-enhanced-ransomware-attacks?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">Hive0163</a></i> and says AI tools are speeding custom malware development.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/91d5f1a7-5f7a-464b-8b0f-c3f0558935ca/image.png?t=1773396775"/><div class="image__source"><span class="image__source_text"><p>Figure: simplified infection chain/ibm.com</p></span></div></div><p class="paragraph" style="text-align:left;">🥷 <b>The </b><i><b>PhantomRaven</b></i><b> campaign pushed dozens of malicious npm packages that steal developer data</b> by using remote dependencies to bypass scans. <a class="link" href="https://www.endorlabs.com/learn/return-of-phantomraven?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">Endor Labs found 88 new packages</a> across disposable accounts, with most still live and sending harvested credentials and system info to attacker servers. Developers should only use trusted packages and avoid copy-pasting unvetted code or AI suggestions.</p><p class="paragraph" style="text-align:left;">🎣 🎅 <b>A phishing campaign tricks victims into mounting a malicious ISO that looks like a resume</b> and runs hidden PowerShell to load malware. The malware side‑loads a tampered DLL, contacts C2, and injects <i>BlackSanta</i>. <i>BlackSanta</i> <a class="link" href="https://www.aryaka.com/docs/reports/blacksanta-edr-killer-threat-report.pdf?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">kills antivirus and EDR at the kernel level</a> to enable credential theft and data exfiltration.</p><p class="paragraph" style="text-align:left;"><b>🛜 Researchers found </b><i><b>KadNap</b></i><b> malware has infected over 14,000 edge devices</b>, mainly Asus routers, to build a stealthy proxy botnet. It uses a <a class="link" href="https://blog.lumen.com/silence-of-the-hops-the-kadnap-botnet/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">peer-to-peer Kademlia DHT to hide its control infrastructure</a> and resist takedowns. Users are urged to update, reboot, change default passwords, and replace unsupported routers.</p><p class="paragraph" style="text-align:left;">🦞 🎠 <b>Researchers found a malicious npm package named </b><code>@openclaw-ai/openclawai</code><b> that pretended to be an OpenClaw installer</b> but installs a RAT called GhostLoader. It tricks users with a fake CLI and Keychain prompt, then steals macOS credentials, browser data, crypto wallets, SSH keys, iMessage/Notes, and more. The <a class="link" href="https://research.jfrog.com/post/ghostclaw-unmasked/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">malware persists, monitors the system, clones authenticated browser sessions, and exfiltrates data</a> to a C2 server and other channels.</p><p class="paragraph" style="text-align:left;">🔙 🚪 <b>Hackers used Microsoft Teams to social-engineer employees at financial and healthcare organizations</b> into starting Quick Assist remote sessions. They <a class="link" href="https://www.bluevoyant.com/blog/new-a0backdoor-linked-to-teams-impersonation-and-quick-assist-social-engineering?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">installed signed MSI files and sideloaded a malicious DLL</a> that decrypts and runs the <i>A0Backdoor</i> malware. <i>A0Backdoor</i> hides C2 traffic in DNS MX queries to steal host data and receive commands.</p><p class="paragraph" style="text-align:left;">🇷🇺 💬 <b>Russian state hackers are running a global campaign to hijack Signal and WhatsApp accounts of officials</b>, military staff, journalists and others. They trick users into giving verification codes or abuse linked-device features to take over accounts and read messages. <a class="link" href="https://english.aivd.nl/latest/news/2026/03/09/russia-targets-signal-and-whatsapp-accounts-in-cyber-campaign?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">Dutch intelligence warns not to use these apps for sensitive information</a> and gives steps to spot and remove compromised accounts.</p><p class="paragraph" style="text-align:left;">🧩 <b>Two Chrome extensions became malicious after ownership changed</b>, allowing attackers to inject code, <a class="link" href="https://monxresearch-sec.github.io/shotbird-extension-malware-report/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">push malware</a>, and steal browser and device data. The plugins delivered runtime JavaScript from a remote server to execute hidden payloads and trick users into running a Windows executable. Users should remove these extensions and avoid unverified browser add-ons.</p><p class="paragraph" style="text-align:left;">→ More:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://zimperium.com/blog/pixrevolution-the-agent-operated-android-trojan-hijacking-brazils-pix-payments-in-real-time?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">PixRevolution: The Agent-Operated Android Trojan Hijacking Brazil’s PIX Payments in Real Time</a> 🇧🇷 </p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://zenox.ai/en/venon-the-first-brazilian-banker-rat-in-rust/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">VENON: The First Brazilian Banker RAT in Rust</a> 🇧🇷 🏦 </p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://securelist.com/beatbanker-miner-and-banker/119121/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">BeatBanker: A dual‑mode Android Trojan</a> 🏦 </p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/new-zombie-zip-technique-lets-malware-slip-past-security-tools/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">New &#39;Zombie ZIP&#39; technique lets malware slip past security tools</a> 🦴 </p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.microsoft.com/en-us/security/blog/2026/03/12/storm-2561-uses-seo-poisoning-to-distribute-fake-vpn-clients-for-credential-theft/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft</a> 🔐 </p></li></ul></div><p class="paragraph" style="text-align:left;"></p><div id="ai-crypto-tech-tools" class="section" style="background-color:transparent;border-color:#C0C0C0;border-radius:10px;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🤖 🧰 AI, CRYPTO, TECH & TOOLS</h3><div class="embed"><a class="embed__url" href="https://aembit.io/blog/mcp-servers-and-the-return-of-the-service-account-problem/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank"><div class="embed__content"><p class="embed__title"> MCP Servers and the Return of the Service Account Problem </p><p class="embed__description"> Agentic AI is turning MCP servers into persistent access brokers, reviving the service account problem and expanding the access surface enterprises struggle to control. </p><p class="embed__link"> aembit.io/blog/mcp-servers-and-the-return-of-the-service-account-problem </p></div><img class="embed__image embed__image--right" src="https://aembit.io/wp-content/uploads/2026/03/MCP-Servers-and-the-Return-of-the-Service-Account-Problem.jpg"/></a></div><p class="paragraph" style="text-align:left;">🎣 ⏱️ <b>Researchers showed they could trick Perplexity&#39;s Comet AI browser into a phishing scam in under four minutes</b> by feeding back the browser&#39;s own reasoning to a GAN. The <a class="link" href="https://guard.io/labs/agenticblabbering---how-ai-browsers-verbose-reasoning-fuels-the-ultimate-scamming-machine?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">attack trains a fake page until the AI stops flagging it</a>, shifting the target from users to the AI agent. Experts warn prompt injection and agentic &quot;blabbering&quot; make such attacks hard to fully eliminate.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/910df40e-e7c1-4b9d-b12b-70d868b69b48/image.png?t=1773304972"/></div><p class="paragraph" style="text-align:left;">🤝 🤑 <b>OpenAI is acquiring AI security startup </b><i><b>Promptfoo</b></i> to boost its safety tools. <i>Promptfoo</i> makes a <a class="link" href="https://www.securityweek.com/openai-to-acquire-ai-security-startup-promptfoo/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">platform that tests LLMs for attack</a>s like prompt injections and data leaks. OpenAI will add these features to its Frontier platform and keep improving <i>Promptfoo</i>’s open-source tools.</p><p class="paragraph" style="text-align:left;">🤯 🔓️ 💬 <b>Instagram ending support for end-to-end encrypted messaging</b> after 8 May 2026 - <a class="link" href="https://help.instagram.com/491565145294150?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">https://help.instagram.com/491565145294150</a></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/b31f3868-c37d-46d0-a8a8-4b3b8c46714d/image.png?t=1773405785"/><div class="image__source"><span class="image__source_text"><p>Figure: Instagram warning pop-up about the end of support of end-to-end encrypted messaging/<a class="link" href="https://hachyderm.io/@pheonix/116221805295722939?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">https://hachyderm.io/@pheonix/116221805295722939</a></p></span></div></div><p class="paragraph" style="text-align:left;">📺️ 🥸 <b>YouTube is expanding its AI deepfake detection to a pilot group</b> of <a class="link" href="https://techcrunch.com/2026/03/10/youtube-ai-deepfake-detection-politicians-government-officials-journalists/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">politicians, government officials, and journalists</a>. Eligible users can verify their identity, see detected AI-generated likenesses, and request removal under YouTube policies. The company aims to balance preventing harmful impersonation with protecting free expression and plans broader rollout.</p><p class="paragraph" style="text-align:left;">🦞 <b>How AI Assistants are Moving the Security Goalposts</b> — AI assistants that act autonomously on users&#39; computers are becoming popular and powerful. They blur lines between data and code and <a class="link" href="https://krebsonsecurity.com/2026/03/how-ai-assistants-are-moving-the-security-goalposts/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">create big new security risks</a> like credential exposure, prompt-injection, and automated attacks.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/d7de475b-45a1-48e5-9a3b-447feca71342/image.png?t=1773151892"/><div class="image__source"><span class="image__source_text"><p>Figure: The lethal trifecta/<a class="link" href="https://krebsonsecurity.com?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">krebsonsecurity.com</a></p></span></div></div><hr class="content_break"><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/vEFPPaOn0ts" width="100%"></iframe></div><p class="paragraph" style="text-align:left;"></p><div id="vulnerabilities-research-and-threat" class="section" style="background-color:transparent;border-color:#C0C0C0;border-radius:10px;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🐛 🧠 VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</h3><p class="paragraph" style="text-align:left;">➝ From the Patching Department:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/adobe-patches-80-vulnerabilities-across-eight-products/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">Adobe Patches 80 Vulnerabilities Across Eight Products</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://thehackernews.com/2026/03/apple-issues-security-updates-for-older.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/chrome-146-update-patches-two-exploited-zero-days/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">Chrome 146 Update Patches Two Exploited Zero-Days</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/cisco-patches-high-severity-ios-xr-vulnerabilities-2/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">Cisco Patches High-Severity IOS XR Vulnerabilities</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/microsoft-patches-83-vulnerabilities/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">Microsoft Patches 83 Vulnerabilities</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/securing-devices-faster-with-hotpatch-updates-on-by-default/4500066?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">Microsoft to enable Windows hotpatch security updates by default</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/cisa-recently-patched-ivanti-epm-flaw-now-actively-exploited/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">CISA: Recently patched Ivanti EPM flaw now actively exploited</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/sap-patches-critical-fs-quo-netweaver-vulnerabilities/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">SAP Patches Critical FS-QUO, NetWeaver Vulnerabilities</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/splunk-zoom-patch-severe-vulnerabilities/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">Splunk, Zoom Patch Severe Vulnerabilities</a></p></li></ul><hr class="content_break"><p class="paragraph" style="text-align:left;">💰️ 🐛 <b>Google paid over $17 million in 2025 to 747 security researchers</b> through its Vulnerability Reward Program. This was a record amount and a <a class="link" href="https://bughunters.google.com/blog/google-vrps-in-review-2025?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">more than 40% increase from 2024</a>. Google also expanded AI and open-source reward programs and paid millions across Android, Chrome, and Cloud programs.</p><p class="paragraph" style="text-align:left;">🐛 <b>A critical vulnerability (CVE-2026-29000) in the </b><i><b>pac4j</b></i><b> Java security library lets attackers bypass authentication </b>using public RSA keys. The <a class="link" href="https://cyberscoop.com/pac4j-open-source-library-vulnerability-max-severity-risk/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">flaw affects many frameworks and is easy to exploit</a> with a public proof-of-concept. Patches were released quickly, but downstream projects and users remain at risk until they update.</p><p class="paragraph" style="text-align:left;">🧩 <b>An SQL injection flaw in the Elementor Ally plugin (CVE-2026-2313) lets unauthenticated attackers steal data</b> by injecting SQL via a URL parameter. Elementor patched it in version 4.1.0, but <a class="link" href="https://www.wordfence.com/blog/2026/03/400000-wordpress-sites-affected-by-unauthenticated-sql-injection-vulnerability-in-ally-wordpress-plugin/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">only ~36% of sites updated, leaving 250,000+ sites vulnerable</a>. Site owners should update Ally and WordPress immediately.</p><p class="paragraph" style="text-align:left;">🐛 <b>Researchers found critical bugs in the </b><i><b>n8n</b></i><b> workflow platform</b> that could let <a class="link" href="https://www.pillar.security/blog/zero-click-unauthenticated-rce-in-n8n-a-contact-form-that-executes-shell-commands?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">attackers run commands and expose stored credentials</a>. One bug lets public form inputs execute code, and another lets authenticated users escape the expression sandbox. <i>n8n</i> patched the issues and urges updates or temporary restrictions on node use and workflow permissions.</p></div><p class="paragraph" style="text-align:left;"></p><div id="ics-ot-io-t" class="section" style="background-color:transparent;border-color:#C0C0C0;border-radius:10px;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🛰️ ICS, OT & IoT</h3><div class="embed"><a class="embed__url" href="https://www.csoonline.com/article/4142548/the-ot-security-time-bomb-why-legacy-industrial-systems-are-the-biggest-cyber-risk-nobody-wants-to-fix.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank"><div class="embed__content"><p class="embed__title"> The OT security time bomb: Why legacy industrial systems are the biggest cyber risk nobody wants to fix </p><p class="embed__description"> We’re running million-dollar production lines on ancient software because no one wants to risk a shutdown, but ignoring that &quot;time bomb&quot; is becoming way too risky. </p><p class="embed__link"> www.csoonline.com/article/4142548/the-ot-security-time-bomb-why-legacy-industrial-systems-are-the-biggest-cyber-risk-nobody-wants-to-fix.html </p></div><img class="embed__image embed__image--right" src="https://www.csoonline.com/wp-content/uploads/2026/03/4142548-0-48210900-1773136986-shutterstock_1951501180-100962448-orig.jpg?quality=50&strip=all&w=1024"/></a></div><p class="paragraph" style="text-align:left;">🩹 <b>ICS Patch Tuesday</b> — Major ICS vendors — Siemens, Schneider Electric, Mitsubishi Electric, and Moxa — <a class="link" href="https://www.securityweek.com/ics-patch-tuesday-vulnerabilities-fixed-by-siemens-schneider-moxa-mitsubishi-electric/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">released Patch Tuesday advisories</a> fixing multiple vulnerabilities in industrial products. Issues range from critical remote code execution, stored XSS, and hardcoded credentials to DoS and third-party component flaws. CISA and Germany’s VDE-CERT also published advisories for affected ICS and building controllers, some allowing remote full compromise.</p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-radius:10px;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">💬 CONNECT</h3><p class="paragraph" style="text-align:left;">Follow me on <a class="link" href="https://infosec.exchange/@0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">Mastodon</a> for quick daily updates and bite-sized content.</p><p class="paragraph" style="text-align:left;">Prefer using an RSS feed? Add <b>Infosec MASHUP</b> to your feed <a class="link" href="https://rss.beehiiv.com/feeds/HVhiKYpQlR.xml?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">here</a>.</p><p class="paragraph" style="text-align:center;"><b>Enjoying our newsletter? </b>Forward it to a colleague—<br>it’s one of the best ways to support us.</p><p class="paragraph" style="text-align:left;">Thanks for reading today’s newsletter, and if you&#39;re enjoying it and want to support my work, you can <b>buy me a coffee</b> ☕ over at <a class="link" href="https://www.buymeacoffee.com/0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-11-2026-when-bombs-fall-keyboards-follow" target="_blank" rel="noopener noreferrer nofollow">https://www.buymeacoffee.com/0x58</a></p><p class="paragraph" style="text-align:left;"> See you next time!</p><p class="paragraph" style="text-align:left;">-X.</p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=7b9a58d4-5530-412d-a950-b195ec38eb13&utm_medium=post_rss&utm_source=x_s_infosec_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🕵🏻‍♂️ [InfoSec MASHUP] 10/2026 - They don&#39;t need new malware. They just need the news.</title>
  <description>Plus: Quantum threatens RSA-2048, 38M Canadian Tire accounts, and Europol kills a phishing factory.</description>
  <link>https://infosec-mashup.santolaria.net/p/infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news</link>
  <guid isPermaLink="true">https://infosec-mashup.santolaria.net/p/infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news</guid>
  <pubDate>Sat, 07 Mar 2026 13:40:06 +0000</pubDate>
  <atom:published>2026-03-07T13:40:06Z</atom:published>
    <dc:creator>Xavier Santolaria</dc:creator>
    <category><![CDATA[Malware]]></category>
    <category><![CDATA[Opensource]]></category>
    <category><![CDATA[Privacy]]></category>
    <category><![CDATA[Cybersecurity]]></category>
    <category><![CDATA[Threat Intelligence]]></category>
    <category><![CDATA[Ai]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">🖤<b> RIP FX (Felix Lindner)</b></p><p class="paragraph" style="text-align:left;">The infosec community lost one of its own this week. FX, founder of <i>Phenoelit</i> and a towering figure of the old-school hacker scene, has passed away. His work on Cisco IOS, port knocking, and decades of research shaped the field in ways that are hard to fully quantify. The <a class="link" href="https://x.com/dalmoz_/status/890400809682423808?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">2017 Pwnie Lifetime Achievement Award</a> barely scratched the surface of his impact.</p><p class="paragraph" style="text-align:left;">I didn&#39;t know him personally, but his influence was hard to miss. Rest in peace, FX. 🖤</p><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/IZYQILfxHiw" width="100%"></iframe><hr class="content_break"><p class="paragraph" style="text-align:left;">War makes excellent phishing bait. It always has. As strikes on Iran dominate headlines, expect threat actors — state-sponsored and opportunistic alike — to flood inboxes with lures dressed up as breaking news, humanitarian appeals, leaked documents, and &quot;exclusive footage.&quot; APT groups don&#39;t need a new playbook; they just need a news cycle. Stay skeptical of anything urgent, emotional, or too perfectly timed. The best OPSEC this week is the same as any other week: think before you click.</p><p class="paragraph" style="text-align:left;">Let’s now dive into this week’s top insights! 🚀</p><h2 class="heading" style="text-align:left;">Table of Contents</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="#breaches-security-incidents" rel="noopener noreferrer nofollow">BREACHES & SECURITY INCIDENTS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#cybercrime-cyber-espionage-ap-ts" rel="noopener noreferrer nofollow">CYBERCRIME, CYBER ESPIONAGE, APT’s</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#government-politics-and-privacy" rel="noopener noreferrer nofollow">GOVERNMENT, POLITICS, AND PRIVACY</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#malware-threats" rel="noopener noreferrer nofollow">MALWARE & THREATS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ai-crypto-tech-tools" rel="noopener noreferrer nofollow">AI, CRYPTO, TECH & TOOLS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#vulnerabilities-research-and-threat" rel="noopener noreferrer nofollow">VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ics-ot-io-t" rel="noopener noreferrer nofollow">ICS, OT & IoT</a></p></li></ul><div id="breaches-security-incidents" class="section" style="background-color:transparent;border-color:#C0C0C0;border-radius:10px;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🔓 BREACHES & SECURITY INCIDENTS</h3><p class="paragraph" style="text-align:left;">🇺🇸 🩺 <b>Health tech company </b><i><b>TriZetto</b></i><b> says hackers stole personal and health data</b> for <a class="link" href="https://techcrunch.com/2026/03/06/trizetto-confirms-3-4m-peoples-health-and-personal-data-was-stolen-during-breach/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">more than 3.4 million people</a>. The breach began in November 2024 but went undetected until October 2025. Some providers and patients across the U.S. have been confirmed affected.</p><p class="paragraph" style="text-align:left;">🇳🇱 🇺🇸 <b>Dutch paint giant </b><i><b>AkzoNobel</b></i><b> says hackers breached</b> the network of one U.S. site. The <a class="link" href="https://www.bleepingcomputer.com/news/security/paint-maker-giant-akzonobel-confirms-cyberattack-on-us-site/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow"><i>Anubis</i></a><a class="link" href="https://www.bleepingcomputer.com/news/security/paint-maker-giant-akzonobel-confirms-cyberattack-on-us-site/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow"> ransomware gang claims to have stolen 170GB</a> and leaked samples of confidential files. <i>AkzoNobel</i> says the incident is contained, impact is limited, and it is supporting affected parties.</p><p class="paragraph" style="text-align:left;">🇺🇸 <b>LexisNexis confirmed hackers breached its servers and stole files</b>, which were later leaked by a group called <i>FulcrumSec</i>. The company <a class="link" href="https://www.bleepingcomputer.com/news/security/lexisnexis-confirms-data-breach-as-hackers-leak-stolen-files/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">says the data was mostly legacy</a>, non-sensitive customer and business information from before 2020. LexisNexis has notified law enforcement, hired outside experts, and says the intrusion is contained.</p><p class="paragraph" style="text-align:left;">🕹️ <i><b>Cloud Imperium Games</b></i><b> says attackers accessed backup systems in January</b> and saw some users&#39; basic account information. The company reports no passwords, payment data, or signs the data was leaked. CIG is <a class="link" href="https://www.bleepingcomputer.com/news/security/star-citizen-game-dev-discloses-breach-affecting-user-data/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">monitoring the situation </a>and warns the exposed details could be used for phishing.</p><p class="paragraph" style="text-align:left;">🇺🇸 <b><i>Madison Square Garden</i></b><b> confirmed a data breach tied to the </b><i><b>Cl0p</b></i><b> </b><i><b>ransomware</b></i><b> group</b> exploiting Oracle E-Business Suite zero-day flaws. Hackers stole and leaked personal data in August 2025, including names and Social Security numbers. MSG <a class="link" href="https://www.securityweek.com/madison-square-garden-data-breach-confirmed-months-after-hacker-attack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">says a third-party vendor hosted the affected system</a> and it is notifying impacted individuals.</p><p class="paragraph" style="text-align:left;">🇨🇦 <b>A October 2025 breach at </b><i><b>Canadian Tire</b></i><b> exposed more than 38 million customer accounts</b> after <a class="link" href="https://www.securityweek.com/canadian-tire-data-breach-impacts-38-million-accounts/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">attackers accessed an e-commerce database</a>. Leaked data included names, emails, PBKDF2-hashed passwords, some dates of birth, partial credit card details, addresses, phones, and gender. The company says bank and loyalty data were safe and has emailed affected users.</p></div><p class="paragraph" style="text-align:left;"></p><div id="cybercrime-cyber-espionage-ap-ts" class="section" style="background-color:transparent;border-color:#C0C0C0;border-radius:10px;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🥷🏻 CYBERCRIME, CYBER ESPIONAGE, APT’s</h3><p class="paragraph" style="text-align:left;">🇮🇷 🇺🇸 🇮🇱 <b>After US‑Israeli strikes on Iran, hacktivist attacks have surged</b> but Iran’s state-backed cyber operations remain quiet. Security firms report many claim-driven website defacements, DDoS attacks, and unverified breach claims. Analysts warn the threat is evolving and urge organizations to strengthen defenses.</p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://blog.talosintelligence.com/talos-developing-situation-in-the-middle-east/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">Talos on the developing situation in the Middle East</a></p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://www.ncsc.gov.uk/news/ncsc-advises-uk-organisations-take-action-following-conflict-in-middle-east?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">UK warns of Iranian cyberattack risks amid Middle-East conflict</a></p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://techcrunch.com/2026/03/02/hackers-and-internet-outages-hit-iran-amid-u-s-air-strikes/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">Hackers and internet outages hit Iran amid U.S. air strikes</a></p><p class="paragraph" style="text-align:left;"> 🇮🇷 🇺🇸 🇮🇱 <b>U.S. and Israeli forces used cyberattacks alongside airstrikes in the opening of the war with Iran</b> to <a class="link" href="https://techcrunch.com/2026/03/03/hacked-traffic-cams-and-hijacked-tvs-how-cyber-operations-supported-the-war-against-iran/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">disrupt communications and gather intelligence</a>. Hacked TV broadcasts and apps were used for psychological operations. The true impact of these cyber actions is unclear and may be overstated.</p><div class="embed"><a class="embed__url" href="https://cstromblad.com/posts/iranian-threat-actor-profile/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank"><div class="embed__content"><p class="embed__title"> Iranian Threat Actor Profile </p><p class="embed__description"> Comprehensive analysis of Iran cyber capabilities pulled from approximately 55 open sources dating 2025-05-01 until 2026-03-03. It’s an attempt to provide a reasonably accurate and holistic view of Iranian cyber threat actors. </p><p class="embed__link"> cstromblad.com/posts/iranian-threat-actor-profile </p></div></a></div><p class="paragraph" style="text-align:left;">🇮🇷 🇺🇸 <b>Iran-linked APT </b><i><b>MuddyWater</b></i><b> has breached networks </b>of a <span style="text-decoration:underline;"><a class="link" href="https://www.security.com/threat-intelligence/iran-cyber-threat-activity-us?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">U.S. airport, a bank, a software/aerospace contractor, and a Canadian NGO</a></span>. The group deployed new backdoors named <i>Dindoor</i> and <i>Fakeset</i>, using fraudulent certificates to steal data. The intrusions persisted amid recent U.S.–Israel–Iran tensions and may still threaten other organizations.</p><p class="paragraph" style="text-align:left;">🇮🇷 🇮🇱 <b>Researchers observed Iran-linked actors intensifying scans and exploitation attempts against Hikvision and Dahua IP cameras</b> across Israel, Gulf states, Lebanon, and Cyprus. This <a class="link" href="https://research.checkpoint.com/2026/interplay-between-iranian-targeting-of-ip-cameras-and-physical-warfare-in-the-middle-east/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">camera targeting aligns with missile strikes</a> and likely supports battle-damage assessment and targeting. Defenders should patch cameras, remove public access, enforce strong credentials, and segment and monitor camera networks.</p><p class="paragraph" style="text-align:left;">🇮🇷 💥 <b>After the U.S.-Israel strikes on Iran, hacktivists launched 149 DDoS attacks on 110 organizations across 16 countries</b>, mostly in the Middle East. Two groups, <i><a class="link" href="https://www.radware.com/security/threat-advisories-and-attack-reports/ddos-activity-following-operation-epic-fury-roaring-lion/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">Keymous+</a></i><a class="link" href="https://www.radware.com/security/threat-advisories-and-attack-reports/ddos-activity-following-operation-epic-fury-roaring-lion/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow"> and </a><i><a class="link" href="https://www.radware.com/security/threat-advisories-and-attack-reports/ddos-activity-following-operation-epic-fury-roaring-lion/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">DieNet</a></i><a class="link" href="https://www.radware.com/security/threat-advisories-and-attack-reports/ddos-activity-following-operation-epic-fury-roaring-lion/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">, drove most attacks</a>, targeting governments, infrastructure, finance, and telecoms. Security firms warn of continued cyber retaliation and urge stronger monitoring and defenses.</p><p class="paragraph" style="text-align:left;">🇮🇷 🦠 <b>A suspected Iran-linked group called </b><i><b>Dust Specter</b></i><b> targeted Iraqi officials by spoofing the Ministry of Foreign Affairs</b> to deliver new malware. The campaign used two chains: SPLITDROP/TWINTASK/TWINTALK that poll files on disk, and GHOSTFORM that runs PowerShell in memory and hides artifacts. Attackers staged payloads on <a class="link" href="https://www.zscaler.com/blogs/security-research/dust-specter-apt-targets-government-officials-iraq?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news#threat-attribution" target="_blank" rel="noopener noreferrer nofollow">compromised Iraqi sites</a>, used evasion and social engineering, and likely leveraged generative AI in malware development.</p><hr class="content_break"><p class="paragraph" style="text-align:left;">⚠️ 🇰🇵 🧑‍🏭 <b>Microsoft says North Korean threat groups are using generative AI to create fake remote worker identities and get hired</b> at global companies. AI speeds up making convincing personas, lures, voice and image forgeries, and helps maintain access. <a class="link" href="https://www.microsoft.com/en-us/security/blog/2026/03/06/ai-as-tradecraft-how-threat-actors-operationalize-ai/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">Researchers warn</a> this boosts scale, sophistication, and the risk of more advanced, semi‑autonomous attacks.</p><p class="paragraph" style="text-align:left;">🇷🇺 ⚖️ 🇺🇸 <b>A 43-year-old Russian, Evgenii Ptitsyn, pleaded guilty in the U.S. for his role in the </b><i><b>Phobos</b></i><b> ransomware</b> operation. He <a class="link" href="https://cyberscoop.com/phobos-ransomware-leader-guilty/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">was arrested in South Korea in June 2024 and extradited</a> to the U.S. in November. Ptitsyn faces up to 20 years for wire fraud conspiracy after helping run and sell the ransomware that hit over 1,000 organizations.</p><p class="paragraph" style="text-align:left;">🇺🇸 🇫🇷 <b>A U.S. contractor&#39;s son, John Daghita, was arrested in Saint Martin for allegedly stealing over $46 million in cryptocurrency</b> from the U.S. Marshals Service. The <a class="link" href="https://www.bleepingcomputer.com/news/security/fbi-arrests-suspect-linked-to-46m-crypto-theft-from-us-marshals/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">arrest</a> followed a joint FBI–French Gendarmerie operation after a blockchain investigator traced the stolen funds to Daghita. Authorities seized cash, hard drives, and security keys during the arrest.</p><p class="paragraph" style="text-align:left;">🇪🇺 🎣 <b>Europol and partners dismantled </b><i><b>Tycoon 2FA</b></i><b>, a large phishing-as-a-service toolkit</b> that enabled adversary-in-the-middle attacks. The <a class="link" href="https://thehackernews.com/2026/03/europol-led-operation-takes-down-tycoon.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">service powered tens of millions of phishing emails</a> and was linked to over 64,000 incidents affecting schools, hospitals, businesses, and governments. Its tools stole credentials, MFA codes, and session cookies to allow account takeovers even after password changes.</p><p class="paragraph" style="text-align:left;">🇪🇸 🇺🇦 <b>Spanish and Ukrainian police broke up a criminal ring that exploited war-displaced Ukrainian women</b> to <a class="link" href="https://www.bleepingcomputer.com/news/security/police-dismantles-online-gambling-ring-exploiting-ukrainian-women/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">run an online gambling and money-laundering scheme</a>. The group forced the women to open bank accounts and used bots and stolen identities to place thousands of low-odds bets, laundering about €4.75 million. Authorities arrested 12 suspects, seized devices, cars, and accounts, and froze properties and funds across multiple countries.</p><p class="paragraph" style="text-align:left;">❌ <b>Authorities from 14 countries shut down </b><i><b>LeakBase</b></i><b>, a major online forum for stolen data</b> and hacking tools. Law enforcement <a class="link" href="https://www.justice.gov/opa/pr/united-states-leads-dismantlement-one-worlds-largest-hacker-forums?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">seized the site</a>, arrested suspects, and took user accounts, posts, and logs for evidence. Officials said the site hosted hundreds of millions of stolen records and was linked to many high-profile attacks.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/0bbc730a-d83f-438d-8e11-4a77c8aea020/image.png?t=1772721119"/><div class="image__source"><span class="image__source_text"><p>Figure: LeakBase Splash Page/justice.gov</p></span></div></div><p class="paragraph" style="text-align:left;">🇺🇸 <b>Hacktivists called “</b><i><b>Department of Peace</b></i><b>” say they hacked the Department of Homeland Security and leaked documents</b> about ICE contracts. A transparency group published searchable data showing more than 6,000 contractors, contract amounts, and contact details, including big firms like Palantir, Microsoft, and Raytheon. The <a class="link" href="https://techcrunch.com/2026/03/02/hacktivists-claim-to-have-hacked-homeland-security-to-release-ice-contract-data/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">hackers said they acted to expose DHS ties after recent killings</a> by federal agents.</p><p class="paragraph" style="text-align:left;">🇺🇸 ⚖️ <b>A 22-year-old Alabama man, Jamarcus Mosley, pleaded guilty to hacking and extorting hundreds of women</b> by <a class="link" href="https://www.justice.gov/usao-ndga/pr/online-predator-pleads-guilty-hacking-social-media-accounts-and-extorting-hundreds?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">stealing their social media passwords</a>. He impersonated friends to get recovery codes, then threatened to post private nude images unless victims sent more photos, gave access, or paid him. Mosley faces sentencing on May 27.</p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-radius:10px;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;">🗓️ <b><a class="link" href="https://xsa.github.io/infosec-events/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">{Cyber,Info}Sec Events</a></b> — A community-maintained list of infosec conferences worldwide. Subscribe to the <a class="link" href="https://xsa.github.io/infosec-events/events.ics?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">ICS calendar feed</a> to get events straight into your calendar, or follow <a class="link" href="https://infosec.exchange/@infosecevents?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">@infosecevents@infosec.exchange</a> on Mastodon for weekly digests. Contributions and ⭐ welcome!</p></div><p class="paragraph" style="text-align:left;"></p><div id="government-politics-and-privacy" class="section" style="background-color:transparent;border-color:#C0C0C0;border-radius:10px;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">👨🏻‍⚖️ 👀 GOVERNMENT, POLITICS, AND PRIVACY</h3><div class="embed"><a class="embed__url" href="https://www.404media.co/cbp-tapped-into-the-online-advertising-ecosystem-to-track-peoples-movements/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank"><div class="embed__content"><p class="embed__title"> CBP Tapped Into the Online Advertising Ecosystem To Track Peoples’ Movements </p><p class="embed__description"> An internal DHS document obtained by 404 Media shows for the first time CBP used location data sourced from the online advertising industry to track phone locations. ICE has bought access to similar tools. </p><p class="embed__link"> www.404media.co/cbp-tapped-into-the-online-advertising-ecosystem-to-track-peoples-movements </p></div><img class="embed__image embed__image--right" src="https://www.404media.co/content/images/size/w1200/2026/02/54723348049_72eefb5739.jpg"/></a></div><p class="paragraph" style="text-align:left;">🇺🇸 <b>President Trump released a high-level national cyber strategy promoting offensive and defensive cyber operations</b>, stronger federal network security, and use of AI and other emerging technologies. The plan has six pillars, including shaping adversary behavior, securing critical infrastructure and supply chains, streamlining regulation, and building cyber workforce capacity. Reactions were mixed, with industry praise for deterrence and regulation easing and <a class="link" href="https://cyberscoop.com/trump-cybersecurity-strategy/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">critics saying the strategy is vague</a> and lacks concrete implementation details.</p><p class="paragraph" style="text-align:left;">🇺🇸 🔎 <b>The FBI said it found and addressed suspicious activity on its networks</b> but gave no details. Reports say the <a class="link" href="https://cyberscoop.com/fbi-targeted-with-suspicious-activity-on-its-networks/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">activity targeted a surveillance system</a> used for warrants, wiretaps, and tracing data. It is unclear when the incident happened or who was responsible.</p><p class="paragraph" style="text-align:left;">🇺🇸 🪖 <b>Anthropic’s Claude is still being used by the U.S. military</b> for <a class="link" href="https://techcrunch.com/2026/03/04/the-us-military-is-still-using-claude-but-defense-tech-clients-are-fleeing/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">targeting in the conflict with Iran</a>. Many defense contractors and subcontractors are replacing Claude amid political and legal pressure. The Pentagon may label Anthropic a supply-chain risk, which could spark legal battles.</p><p class="paragraph" style="text-align:left;">🙊 <b>Anthropic CEO Dario Amodei accused OpenAI of lying</b> about its Defense Department deal. Anthropic refused the DoD’s request over worries about <a class="link" href="https://techcrunch.com/2026/03/04/anthropic-ceo-dario-amodei-calls-openais-messaging-around-military-deal-straight-up-lies-report-says/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">mass surveillance and autonomous weapons</a>. Public reaction favored Anthropic and hurt OpenAI’s reputation.</p><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/MPTNHrq_4LU" width="100%"></iframe></div><p class="paragraph" style="text-align:left;"></p><div id="malware-threats" class="section" style="background-color:transparent;border-color:#C0C0C0;border-radius:10px;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🦠 MALWARE & THREATS</h3><p class="paragraph" style="text-align:left;">🇷🇺 🇺🇦 🐾 🐈️ <b>Researchers found a Russian-linked campaign targeting Ukraine that uses phishing to deliver new malware</b> called <i>BadPaw</i> and <i>MeowMeow</i>. The <a class="link" href="https://www.clearskysec.com/russian-campaign-targeting-ukraine-badpaw-and-meowmeow/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">attack tricks victims with a Ukrainian-language decoy</a>, avoids sandboxes, and uses BadPaw to fetch the MeowMeow backdoor. MeowMeow can run remote PowerShell commands and manage files, and its Russian-language artifacts link it to APT28.</p><p class="paragraph" style="text-align:left;">🪱 <b>A self-propagating JavaScript worm infected Wikipedia</b> by <a class="link" href="https://www.bleepingcomputer.com/news/security/wikipedia-hit-by-self-propagating-javascript-worm-that-vandalized-pages/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">adding hidden scripts</a> and vandalizing pages. It spread by modifying both user common.js files and the global <code>MediaWiki:Common.js</code>, affecting about 3,996 pages and ~85 users. Wikimedia engineers restricted editing, removed the malicious code, and reverted changes while investigating how the dormant script executed.</p><p class="paragraph" style="text-align:left;">🎠 <b>Malicious Packagist (PHP) packages pretending to be Laravel tools install a cross-platform remote access trojan (RAT)</b> that works on Windows, macOS, and Linux. The RAT connects to a C2 server, sends system info, and executes commands with the web app&#39;s permissions. Users should remove the packages, <a class="link" href="https://socket.dev/blog/malicious-packagist-packages-disguised-as-laravel-utilities?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">assume compromise</a>, rotate secrets, and audit outbound traffic.</p><p class="paragraph" style="text-align:left;">🇰🇵 🪱 <b>North Korean hackers published 26 malicious </b><i><b>npm</b></i><b> packages</b> that hide command-and-control addresses <a class="link" href="https://kmsec.uk/blog/dprk-text-steganography/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">using steganography in Pastebin</a> posts. The packages install a loader that decodes C2 URLs and fetches platform-specific payloads, deploying a cross-platform RAT and credential stealers. The campaign uses Vercel hosting and typosquatting to evade detection and target developers.</p></div><p class="paragraph" style="text-align:left;"></p><div id="ai-crypto-tech-tools" class="section" style="background-color:transparent;border-color:#C0C0C0;border-radius:10px;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🤖 🧰 AI, CRYPTO, TECH & TOOLS</h3><div class="embed"><a class="embed__url" href="https://unit42.paloaltonetworks.com/ai-agent-prompt-injection/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank"><div class="embed__content"><p class="embed__title"> Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild </p><p class="embed__description"> Uncover real-world indirect prompt injection attacks and learn how adversaries weaponize hidden web content to exploit LLMs for high-impact fraud. </p><p class="embed__link"> unit42.paloaltonetworks.com/ai-agent-prompt-injection </p></div><img class="embed__image embed__image--right" src="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/04_Security-Technology_Category_1920x900.jpg"/></a></div><p class="paragraph" style="text-align:left;">🔓️ <b>A new quantum algorithm called JVG may break RSA and ECC using far fewer qubits</b> and gates than Shor’s algorithm. Researchers <a class="link" href="https://www.securityweek.com/quantum-decryption-of-rsa-is-much-closer-than-expected/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">claim JVG could factor RSA-2048 in about 11 hours</a> with under 5,000 qubits, though the results are new and need more scrutiny. Organizations should urgently adopt crypto-agility and post-quantum standards to protect data now.</p><p class="paragraph" style="text-align:left;">💬 🔓️ <b>TikTok says it will not add end-to-end encryption for direct messages</b> — The company <a class="link" href="https://techcrunch.com/2026/03/04/tiktok-wont-add-end-to-end-encryption-to-direct-messages-report-says/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">argues that end-to-end encryption could block police and safety teams</a> from accessing messages when needed. TikTok keeps standard encryption and allows authorized access under strict conditions like valid law enforcement requests.</p><div class="embed"><a class="embed__url" href="https://techcrunch.com/2026/03/06/social-media-ban-children-countries-list/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank"><div class="embed__content"><p class="embed__title"> These are the countries moving to ban social media for children | TechCrunch </p><p class="embed__description"> Australia was the first country to issue a ban in late 2025, aiming to reduce the pressures and risks that young users may face on social media, including cyberbullying, social media addiction, and exposure to predators. </p><p class="embed__link"> techcrunch.com/2026/03/06/social-media-ban-children-countries-list </p></div><img class="embed__image embed__image--right" src="https://techcrunch.com/wp-content/uploads/2026/02/GettyImages-2243719467.jpg?resize=1200,800"/></a></div><p class="paragraph" style="text-align:left;">☁️ <b>AWS announced </b><i><b>Security Hub Extended</b></i><b>, a plan that unifies AWS and curated partner security tools</b> into <a class="link" href="https://aws.amazon.com/blogs/aws/aws-security-hub-extended-o%EF%AC%80ers-full-stack-enterprise-security-with-curated-partner-solutions/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">one console</a>. It simplifies buying, onboarding, and billing with pay-as-you-go pricing and single-vendor support. Security findings from all solutions are normalized into OCSF and aggregated in Security Hub for faster response.</p><p class="paragraph" style="text-align:left;">🔐 <b>Google plans to make Chrome HTTPS certificates resistant to quantum attacks</b> by using Merkle Tree Certificates (MTCs). MTCs shrink certificate data, keep Certificate Transparency, and avoid slowing TLS with post-quantum keys. Google <a class="link" href="https://security.googleblog.com/2026/02/cultivating-robust-and-efficient.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">will test MTCs with partners</a> and roll out a quantum-resistant root program by 2027.</p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://www.bleepingcomputer.com/news/security/google-chrome-shifts-to-two-week-release-cycle-for-increased-stability/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">Google Chrome shifts to two-week release cycle for increased stability</a></p></div><p class="paragraph" style="text-align:left;"></p><div id="vulnerabilities-research-and-threat" class="section" style="background-color:transparent;border-color:#C0C0C0;border-radius:10px;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🐛 🧠 VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</h3><p class="paragraph" style="text-align:left;">➝ From the Patching Department:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/cisco-patches-critical-vulnerabilities-in-enterprise-networking-products/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">Cisco Patches Critical Vulnerabilities in Enterprise Networking Products</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://cyberscoop.com/android-security-update-march-2026/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">Google addresses actively exploited Qualcomm zero-day in fresh batch of 129 Android vulnerabilities</a></p></li></ul><hr class="content_break"><div class="embed"><a class="embed__url" href="https://zerodayclock.com?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank"><div class="embed__content"><p class="embed__title"> Zero Day Clock </p><p class="embed__description"> The gap between disclosure and exploitation is collapsing to zero. </p><p class="embed__link"> zerodayclock.com </p></div></a></div><p class="paragraph" style="text-align:left;">🦊 🤝 🤖 <b>Anthropic used its Claude Opus AI to find 22 vulnerabilities in Firefox over two weeks</b>, 14 of them high-severity. Most <a class="link" href="https://techcrunch.com/2026/03/06/anthropics-claude-found-22-vulnerabilities-in-firefox-over-two-weeks/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">bugs were fixed in Firefox 148</a>, with a few patches delayed until the next release. The team struggled to build exploits, spending $4,000 in API credits but only making two proofs of concept.</p><p class="paragraph" style="text-align:left;">🔎 🗒️ <b>Google tracked 90 zero-day vulnerabilities actively exploited in 2025, a 15% rise</b> from 2024. Nearly half targeted enterprise systems like security appliances, VPNs, and networking gear. Commercial spyware vendors and state-linked groups drove much of the exploitation, and <a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/2025-zero-day-review?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">Google warns high rates may continue into 2026</a>.</p><p class="paragraph" style="text-align:left;">⚠️ 🎣 <b>LastPass warns of a new phishing campaign</b> that <a class="link" href="https://www.forbes.com/sites/daveywinder/2026/03/04/lastpass-issues-new-account-password-warning-attacks-are-underway/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">tries to steal users&#39; master passwords</a>. Fake emails use a spoofed display name and link to counterfeit LastPass login pages. LastPass published IoCs and worked with partners to take down the malicious sites.</p><p class="paragraph" style="text-align:left;">📱 <b>Kaspersky says there is no evidence the </b><i><b>Coruna</b></i><b> iPhone exploit kit was made by the same group behind 2023 attacks</b> blamed on the NSA. Google <a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/coruna-powerful-ios-exploit-kit?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">found </a><i><a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/coruna-powerful-ios-exploit-kit?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">Coruna</a></i> uses many iOS zero-days and has been used in multiple campaigns. Some experts suspect US government links because of shared vulnerabilities, but <a class="link" href="https://www.theregister.com/2026/03/04/kaspersky_dismisses_claims_that_coruna/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">Kaspersky rejects code-reuse claims</a>.</p><p class="paragraph" style="text-align:left;">😱 <b>A critical FreeScout vulnerability (CVE-2026-28289) allows zero-click remote code execution</b> by uploading a hidden <code>.htaccess</code> file. The <a class="link" href="https://www.ox.security/blog/freescout-rce-cve-2026-28289/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">bug bypasses a previous patch</a> using a zero-width space in filenames and affects FreeScout 1.8.206 on Apache with AllowOverride All. Users should update to FreeScout 1.8.207 immediately to prevent full server compromise and data theft.</p><p class="paragraph" style="text-align:left;">🇰🇵 <b>Security researchers say APT28 likely exploited MSHTML zero-day CVE-2026-21513 before Microsoft patched</b> it in February 2026. The flaw lets malicious HTML or LNK files trick Windows into running code outside the browser sandbox. <a class="link" href="https://www.akamai.com/blog/security-research/2026/feb/inside-the-fix-cve-2026-21513-mshtml-exploit-analysis?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">Akamai found an artifact tied to APT28</a> and warned other MSHTML embedding methods could be abused too.</p><p class="paragraph" style="text-align:left;">🦞 <b>Security researchers found a high-severity &quot;</b><i><b>ClawJacked</b></i><b>&quot; flaw in OpenClaw </b>that <a class="link" href="https://www.oasis.security/blog/openclaw-vulnerability?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">let malicious websites brute-force a local gateway</a> and take control. The bug allowed hundreds of password guesses per second from browser JavaScript and auto-approved local device pairings. OpenClaw patched the issue in version 2026.2.26 — users should update immediately.</p><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/A15fuHs7fOc" width="100%"></iframe></div><p class="paragraph" style="text-align:left;"></p><div id="ics-ot-io-t" class="section" style="background-color:transparent;border-color:#C0C0C0;border-radius:10px;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🛰️ ICS, OT & IoT</h3><p class="paragraph" style="text-align:left;">🥸 <b>An old Rockwell Automation flaw (CVE-2021-22681) that lets attackers impersonate engineering workstations has been exploited</b> in the wild. CISA added it to its Known Exploited Vulnerabilities list and ordered fixes by March 26. Exposed PLCs could be <a class="link" href="https://www.securityweek.com/rockwell-vulnerability-allowing-remote-ics-hacking-exploited-in-attacks/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">remotely manipulated</a>, risking production disruption or physical damage.</p><p class="paragraph" style="text-align:left;">🤷 <b>A researcher says Honeywell’s IQ4 building controller can expose its web interface without authentication</b> and <a class="link" href="https://www.zeroscience.mk/en/vulnerabilities/ZSL-2026-5979.php?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">allow attackers to create admin accounts</a> during setup. Honeywell counters that devices are delivered unconfigured, meant for local setup by trained technicians, and not meant to be internet‑exposed. The <a class="link" href="https://www.securityweek.com/honeywell-researcher-clash-over-impact-of-building-controller-vulnerability/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">researcher found thousands of internet‑visible instances</a> and disputes Honeywell’s assessment, and a CVE is pending.</p><p class="paragraph" style="text-align:left;">📡 <b>The Global Coalition on Telecoms (GCOT) released principles for 6G security and resilience</b> at Mobile World Congress 2026. The <a class="link" href="https://www.securityweek.com/global-coalition-publishes-6g-security-and-resilience-principles/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">principles call for security-by-design</a>, AI-enabled defenses, quantum-safe cryptography, and measures to protect supply chains, data, and service availability. GCOT says governments, telecoms, and suppliers must act now as 6G moves from research toward commercial rollout by 2029–2030.</p><p class="paragraph" style="text-align:left;">🛞 🗺️ <b>Researchers found tire pressure sensors broadcast a permanent ID in plain text that can be captured</b> with cheap receivers. By collecting millions of messages, they showed <a class="link" href="https://www.securityweek.com/researchers-uncover-method-to-track-cars-via-tire-sensors/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">these signals can be used to track vehicles</a> and infer driver behavior. Attackers could use or spoof these transmissions for mass or targeted tracking and even to cause fake alerts.</p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-radius:10px;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">💬 CONNECT</h3><p class="paragraph" style="text-align:left;">Follow me on <a class="link" href="https://infosec.exchange/@0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">Mastodon</a> for quick daily updates and bite-sized content.</p><p class="paragraph" style="text-align:left;">Prefer using an RSS feed? Add <b>Infosec MASHUP</b> to your feed <a class="link" href="https://rss.beehiiv.com/feeds/HVhiKYpQlR.xml?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">here</a>.</p><p class="paragraph" style="text-align:center;"><b>Enjoying our newsletter? </b>Forward it to a colleague—<br>it’s one of the best ways to support us.</p><p class="paragraph" style="text-align:left;">Thanks for reading today’s newsletter, and if you&#39;re enjoying it and want to support my work, you can <b>buy me a coffee</b> ☕ over at <a class="link" href="https://www.buymeacoffee.com/0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-10-2026-they-don-t-need-new-malware-they-just-need-the-news" target="_blank" rel="noopener noreferrer nofollow">https://www.buymeacoffee.com/0x58</a></p><p class="paragraph" style="text-align:left;"> See you next time!</p><p class="paragraph" style="text-align:left;">-X.</p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=c0ca0e32-3afe-4dd7-8841-5011620c7650&utm_medium=post_rss&utm_source=x_s_infosec_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🕵🏻‍♂️ [InfoSec MASHUP] 09/2026 - Your iPhone has a green dot. Predator doesn&#39;t care.</title>
  <description>Plus: Conduent exposes 25M, Lazarus goes ransomware, Anthropic relaxes core AI safety pledge, while refusing to bend to Pentagon on AI safeguards, and breakout times hit 29 minutes.</description>
  <link>https://infosec-mashup.santolaria.net/p/infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care</link>
  <guid isPermaLink="true">https://infosec-mashup.santolaria.net/p/infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care</guid>
  <pubDate>Sat, 28 Feb 2026 09:20:00 +0000</pubDate>
  <atom:published>2026-02-28T09:20:00Z</atom:published>
    <dc:creator>Xavier Santolaria</dc:creator>
    <category><![CDATA[Malware]]></category>
    <category><![CDATA[Opensource]]></category>
    <category><![CDATA[Privacy]]></category>
    <category><![CDATA[Cybersecurity]]></category>
    <category><![CDATA[Threat Intelligence]]></category>
    <category><![CDATA[Ai]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'IBM Plex Sans',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">We now have <b>{{active_subscriber_count}} active subscribers</b>! Thank you all for being part of my newsletter. Please share it with your friends and colleagues, and let’s keep growing the community.</p><hr class="content_break"><p class="paragraph" style="text-align:left;">💜 A quick personal note — I recently looked at my newsletter stats and noticed that a good chunk of you open and read this every single week. I just wanted to say: thank you. Genuinely. This is a solo effort, and knowing that some of you look forward to it every weekend makes it worthwhile.</p><p class="paragraph" style="text-align:left;">If you ever want to share feedback, suggest a topic, or just say hi — hit reply. I read everything.</p><hr class="content_break"><p class="paragraph" style="text-align:left;">📲 Your iPhone has a green dot. It means the camera is on — Apple put it there so you&#39;d know. Hardware-level, they said. Can&#39;t be bypassed, they implied. Predator didn&#39;t get the memo.</p><p class="paragraph" style="text-align:left;"><b>Jamf Threat Labs published a detailed breakdown</b> last week—and it’s worth your time this week-end—of <a class="link" href="https://www.jamf.com/blog/predator-spyware-ios-recording-indicator-bypass-analysis/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">how Intellexa&#39;s spyware defeats both the camera and microphone indicators</a> with a single hook — one instruction that sets the <code>self</code> pointer to NULL, exploiting a quirk of Objective-C where messages to nil are simply... ignored. No dot. No warning. No trace. The device works normally. You just have no idea you&#39;re being watched.</p><p class="paragraph" style="text-align:left;">The technical elegance is, honestly, impressive — if you can set aside the part where it&#39;s used to surveil journalists, activists, and politicians.</p><p class="paragraph" style="text-align:left;">The good news, if you can call it that: your iPhone needs to be fully compromised first — kernel access, code injection into SpringBoard, the works. Predator doesn&#39;t walk in through the front door. It needs a zero-day chained exploit to get there. The bad news: Intellexa has a track record of finding them.</p><p class="paragraph" style="text-align:left;">Sanctioned by the US, flagged by Google, dissected by researchers — and somehow still very much in business. <b>Predator is the cockroach of the spyware industry</b>, and this week we got a very good look at its internals.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/23675efb-ed34-4d77-8cc3-d98b01a26398/image.png?t=1771939216"/><div class="image__source"><span class="image__source_text"><p>Figure: Monster in Predator movie/20th Century Studios</p></span></div></div><p class="paragraph" style="text-align:left;">Let’s now dive into this week’s top insights! 🚀</p><h2 class="heading" style="text-align:left;">Table of Contents</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="#breaches-security-incidents" rel="noopener noreferrer nofollow">BREACHES & SECURITY INCIDENTS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#cybercrime-cyber-espionage-ap-ts" rel="noopener noreferrer nofollow">CYBERCRIME, CYBER ESPIONAGE, APT’s</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#government-politics-and-privacy" rel="noopener noreferrer nofollow">GOVERNMENT, POLITICS, AND PRIVACY</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#malware-threats" rel="noopener noreferrer nofollow">MALWARE & THREATS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ai-crypto-tech-tools" rel="noopener noreferrer nofollow">AI, CRYPTO, TECH & TOOLS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#vulnerabilities-research-and-threat" rel="noopener noreferrer nofollow">VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#ics-ot-io-t" rel="noopener noreferrer nofollow">ICS, OT & IoT</a></p></li></ul><div id="breaches-security-incidents" class="section" style="background-color:transparent;border-color:#C0C0C0;border-radius:10px;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🔓 BREACHES & SECURITY INCIDENTS</h3><div class="embed"><a class="embed__url" href="https://haveibeenpwned.com/Breach/CanadianTire?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank"><div class="embed__content"><p class="embed__title"> Have I Been Pwned: Canadian Tire Data Breach </p><p class="embed__description"> In October 2025, retailer Canadian Tire was the victim of a data breach that exposed almost 42M records. The data contained 38M unique email addresses along with names, phone numbers and physical addresses. Passwords were stored as PBKDF2 hashes and for a subset of records, dates of birth and partial credit card data were also included (card type, expiry and masked card number). In its disclosure notice, Canadian Tire advised that the incident did not impact bank account information or loyalty program data. </p><p class="embed__link"> haveibeenpwned.com/Breach/CanadianTire </p></div><img class="embed__image embed__image--right" src="https://haveibeenpwned.com/Images/OG/CanadianTire"/></a></div><p class="paragraph" style="text-align:left;">🇺🇸 <b>A January 2025 ransomware attack on </b><i><b>Conduent</b></i><b> has exposed personal data for at least 25 million people</b> in the U.S. The stolen data includes names, birthdates, addresses, Social Security numbers, and medical and insurance information. <i>Conduent</i> has given <a class="link" href="https://techcrunch.com/2026/02/24/conduent-data-breach-grows-affecting-at-least-25m-people/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">few details and even hid its incident notice from search engines</a>.</p><p class="paragraph" style="text-align:left;">🇳🇱 <b>The </b><i><b>ShinyHunters</b></i><b> extortion gang claims it breached Dutch telecom </b><i><b>Odido</b></i><b> and stole millions</b> of user records. <i>Odido</i> <a class="link" href="https://www.bleepingcomputer.com/news/security/odido-data-breach-exposes-personal-info-of-62-million-customers/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">confirmed a February breach</a> of its customer contact system affecting about 6.2 million customers but said passwords, call details, and billing data were not exposed. <i>ShinyHunters</i> posted leaked data and alleged it includes internal files and plaintext passwords, while <i>Odido</i> <a class="link" href="https://www.bleepingcomputer.com/news/security/shinyhunters-extortion-gang-claims-odido-breach-affecting-millions/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">denies those additional claims</a>.</p><p class="paragraph" style="text-align:left;">🇨🇳 <b>Chinese hackers used a secret backdoor in Pulse Secure VPN software owned by Ivanti</b> to <a class="link" href="https://techcrunch.com/2026/02/23/vpn-flaws-allowed-chinese-hackers-to-compromise-dozens-of-ivanti-customers-says-report/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">breach dozens of organizations</a>. The compromise affected at least 119 customers and included U.S. and European military contractors. Cuts after private equity takeovers are blamed for weakening Ivanti’s security, and agencies were later ordered to disconnect Ivanti VPNs due to active exploits.</p><div class="embed"><a class="embed__url" href="https://mastodon.social/@campuscodi/116114602572870843?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank"><div class="embed__content"><p class="embed__title"> Catalin Cimpanu (@campuscodi@mastodon.social) </p><p class="embed__description"> Ivanti&#39;s California data center was hacked in 2021 through a vulnerability in its own VPN Attack was linked to Chinese hackers https://www.bloomberg.com/news/features/2026-02-19/vpn-used-by-us-government-failed-to-stop-china-state-sponsored-hackers </p><p class="embed__link"> mastodon.social/@campuscodi/116114602572870843 </p></div></a></div><p class="paragraph" style="text-align:left;">🇺🇸 🏥 <b>Nearly 140,000 people may be affected by a data breach tied to Vikor Scientific</b> (now Vanta Diagnostics). The breach appears to have originated at billing vendor Catalyst RCM, whose compromised credentials exposed names, DOBs, payment and medical details. It’s <a class="link" href="https://www.securityweek.com/us-healthcare-diagnostic-firm-says-140000-affected-by-data-breach/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">unclear if 139,964 is the final total</a>, and some parties have not confirmed the full number.</p><p class="paragraph" style="text-align:left;">🇺🇸 🏥 <b>A ransomware attack forced the University of Mississippi Medical Center to close about three dozen clinics</b> and cancel elective procedures. Staff are working offline while investigators, including the FBI, try to restore systems and <a class="link" href="https://www.securityweek.com/mississippi-hospital-system-closes-all-clinics-after-ransomware-attack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">determine if patient data was stolen</a>. Hospitals and emergency rooms stayed open and patients with urgent needs are being contacted.</p><p class="paragraph" style="text-align:left;">👁️ <b>A huge unsecured database tied to </b><i><b>IDMerit</b></i><b> exposed about one billion sensitive identity records</b> from at least 26 countries. The leaked data included names, birthdates, addresses, national IDs and verification logs, risking identity theft and targeted fraud. The server was later secured, but the <a class="link" href="https://www.biometricupdate.com/202602/one-billion-identity-records-exposed-in-unsecured-id-verification-database?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">incident highlights weak vendor security</a> and major risks from third-party identity systems.</p><p class="paragraph" style="text-align:left;">→ More Breaches and Incidents:</p><ul><li><p class="paragraph" style="text-align:left;"><i><a class="link" href="https://www.bleepingcomputer.com/news/security/wynn-resorts-confirms-employee-data-breach-after-extortion-threat/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">Wynn Resorts</a></i><a class="link" href="https://www.bleepingcomputer.com/news/security/wynn-resorts-confirms-employee-data-breach-after-extortion-threat/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow"> confirms employee data breach after extortion threat</a></p></li><li><p class="paragraph" style="text-align:left;"><i><a class="link" href="https://techcrunch.com/2026/02/24/cargurus-data-breach-affects-12-5-million-accounts/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">CarGurus</a></i><a class="link" href="https://techcrunch.com/2026/02/24/cargurus-data-breach-affects-12-5-million-accounts/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow"> data breach affects 12.5 million accounts</a> 🚗</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/ad-tech-company-optimizely-confirms-cyberattack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">Ad Tech Company </a><a class="link" href="https://www.securityweek.com/ad-tech-company-optimizely-confirms-cyberattack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow"><i>Optimizely</i></a><a class="link" href="https://www.securityweek.com/ad-tech-company-optimizely-confirms-cyberattack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow"> Targeted in Cyberattack</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/medical-device-maker-ufp-technologies-hit-by-cyberattack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">Medical Device Maker </a><a class="link" href="https://www.securityweek.com/medical-device-maker-ufp-technologies-hit-by-cyberattack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow"><i>UFP Technologies</i></a><a class="link" href="https://www.securityweek.com/medical-device-maker-ufp-technologies-hit-by-cyberattack/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow"> Hit by Cyberattack</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/european-dyi-chain-manomano-data-breach-impacts-38-million-customers/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">European DYI chain ManoMano data breach impacts 38 million customers</a> 🇪🇺 </p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/olympique-marseille-football-club-confirms-cyberattack-after-data-leak/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">Olympique Marseille confirms &#39;attempted&#39; cyberattack after data leak</a> ⚽️ </p></li></ul></div><p class="paragraph" style="text-align:left;"></p><div id="cybercrime-cyber-espionage-ap-ts" class="section" style="background-color:transparent;border-color:#C0C0C0;border-radius:10px;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🥷🏻 CYBERCRIME, CYBER ESPIONAGE, APT’s</h3><p class="paragraph" style="text-align:left;">🇪🇺 <b>Europol launched </b><i><b>Project Compass</b></i><b> to combat </b><i><b>The Com</b></i><b>, a global network of mostly young cybercriminals</b> who commit violence, extortion, and child exploitation. The <a class="link" href="https://cyberscoop.com/project-compass-the-com-europol/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">operation, backed by 28 countries</a>, has helped identify 179 perpetrators, arrest 30, and find dozens of victims. Authorities say international information-sharing and sustained efforts are key to protecting victims and disrupting the group.</p><p class="paragraph" style="text-align:left;">🇷🇺 🇪🇺 <b>A Russia-aligned group called UAC-0050 (</b><i><b>Mercenary Akula</b></i><b>) used a spoofed Ukrainian domain and a phishing email to deliver RMS remote-access malware</b> to a European financial institution. The <a class="link" href="https://www.bluevoyant.com/blog/mercenary-akula-hits-financial-institution?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">attackers used layered archives and a fake PDF executable</a> to bypass defenses and gain stealthy access for intelligence gathering or financial theft. This incident suggests the group may be expanding targeting beyond Ukraine to Western entities that support it.</p><p class="paragraph" style="text-align:left;">🇨🇳 👀 <b>Google says it disrupted a long-running China-linked cyberespionage campaign</b> that targeted telecoms and governments in dozens of countries. The <a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/disrupting-gridtide-global-espionage-campaign?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">attackers used a new backdoor called </a><a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/disrupting-gridtide-global-espionage-campaign?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow"><i>GridTide</i></a> and hid commands in cloud services like Google Sheets to steal or monitor sensitive data. Google, Mandiant and partners took down the malware infrastructure, disabled attacker accounts, and notified victims.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/7a55b874-f48c-4045-be62-3c9fb7bbbfa6/image.png?t=1772096841"/><div class="image__source"><span class="image__source_text"><p>Figure: Countries with suspected or confirmed UNC2814 victims/Google.com</p></span></div></div><p class="paragraph" style="text-align:left;">🇺🇸 <b>The U.S. Department of Justice seized $61 million in Tether</b> tied to “pig butchering” crypto scams. Scammers lured victims via dating and social apps, coerced workers in scam compounds, and laundered stolen funds through many wallets. Tether <a class="link" href="https://www.justice.gov/usao-ednc/pr/us-attorneys-office-ednc-announces-seizure-61-million-dollars-worth-cryptocurrency?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">says it has frozen about $4.2 billion in assets linked to illicit activity</a>, including nearly $250 million since June 2025.</p><p class="paragraph" style="text-align:left;">🇺🇸 🇷🇺 <b>The U.S. Treasury sanctioned Russian zero-day broker </b><i><b>Operation Zero</b></i><b>, its founder Sergey Zelenyuk</b>, and related companies and associates for buying and selling stolen software exploits. Officials say <a class="link" href="https://home.treasury.gov/news/press-releases/sb0404?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow"><i>Operation Zero</i></a><a class="link" href="https://home.treasury.gov/news/press-releases/sb0404?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow"> bought tools stolen from a U.S. defense contractor</a> and sold them to unauthorized users, posing national security risks. The sanctions also target UAE-linked firms tied to high-paying zero-day markets.</p><p class="paragraph" style="text-align:left;">🇺🇸 🇷🇺 <b>A former L3Harris executive was sentenced to 87 months in prison for selling eight zero-day exploits</b> to a Russian broker. He <a class="link" href="https://cyberscoop.com/l3harris-executive-peter-williams-sentenced-zero-day-exploits-russia/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">admitted stealing the exploits from Trenchant </a>and received about $1.3 million in cryptocurrency. Prosecutors said the theft caused $35 million in losses and restitution proceedings continue.</p><p class="paragraph" style="text-align:left;">🇰🇵 <b>North Korean state-backed </b><i><b>Lazarus</b></i><b> actors are now using Medusa ransomware</b> to mount extortion campaigns. They have <a class="link" href="https://www.security.com/threat-intelligence/lazarus-medusa-ransomware?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">targeted U.S. healthcare and other organizations</a>, sometimes unsuccessfully, and demanded about $260,000 on average. Researchers found tools and indicators linking these attacks to <i>Lazarus</i> but cannot yet pinpoint a single sub-group.</p><p class="paragraph" style="text-align:left;">🇪🇸 <b>Spanish police arrested four suspected members of &quot;</b><i><b>Anonymous Fénix</b></i><b>&quot;, a hacktivist group blamed for DDoS attacks</b> on government sites. The group targeted Spanish and some South American institutions, spiking after deadly Valencia floods. Authorities <a class="link" href="https://web.guardiacivil.es/es/destacados/noticias/Detenidos-los-cuatro-principales-integrantes-del-grupo-hacktivista-Anonymous-Fenix-por-ciberataques-contra-organismos-publicos/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">seized</a> the group’s social accounts and closed its Telegram channel.</p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-radius:10px;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;">🗓️ <b><a class="link" href="https://xsa.github.io/infosec-events/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">{Cyber,Info}Sec Events</a></b> — A community-maintained list of infosec conferences worldwide. Subscribe to the <a class="link" href="https://xsa.github.io/infosec-events/events.ics?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">ICS calendar feed</a> to get events straight into your calendar, or follow <a class="link" href="https://infosec.exchange/@infosecevents?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">@infosecevents@infosec.exchange</a> on Mastodon for weekly digests. Contributions and ⭐ welcome!</p></div><p class="paragraph" style="text-align:left;"></p><div id="government-politics-and-privacy" class="section" style="background-color:transparent;border-color:#C0C0C0;border-radius:10px;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">👨🏻‍⚖️ 👀 GOVERNMENT, POLITICS, AND PRIVACY</h3><div class="embed"><a class="embed__url" href="https://this.weekinsecurity.com/fbi-agents-visited-my-home-about-an-article-i-wrote-and-now-i-cannot-go-to-mexico/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank"><div class="embed__content"><p class="embed__title"> FBI agents visited my home about an article I wrote, and now I can&#39;t go to Mexico </p><p class="embed__description"> Mexico formally requested the FBI&#39;s help in seeking answers about one of my stories. Having federal agents on my doorstep sparked my own years-long effort to pry information out of the FBI to explain why it came to my house to begin with. </p><p class="embed__link"> this.weekinsecurity.com/fbi-agents-visited-my-home-about-an-article-i-wrote-and-now-i-cannot-go-to-mexico </p></div><img class="embed__image embed__image--right" src="https://this.weekinsecurity.com/content/images/size/w1200/2026/02/fbi-calling-card-1.jpeg"/></a></div><hr class="content_break"><p class="paragraph" style="text-align:left;">🍏 ✅ <b>NATO has approved Apple iPhone and iPad for handling classified information</b> at the &quot;NATO RESTRICTED&quot; level. The <a class="link" href="https://www.securityweek.com/apple-iphone-and-ipad-cleared-for-classified-nato-use/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">devices are now listed in NATO’s vetted product catalog</a> and can access Mail, Calendar, and Contacts securely without special software. Germany’s security agency (BSI) tested and validated the devices, which Apple says met NATO requirements.</p><p class="paragraph" style="text-align:left;">🇬🇷 🧑‍⚖️ <b>A Greek court sentenced </b><i><b>Intellexa</b></i><b> founder Tal Dilian and three associates to eight years in prison for illegal wiretapping</b> and <a class="link" href="https://techcrunch.com/2026/02/26/spyware-maker-sentenced-to-prison-in-greece-for-wiretapping-politicians-and-journalists/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">privacy violations</a>. The group was tied to a 2022 scandal where spyware called Predator was used to spy on politicians, journalists, businesspeople, and officials. The U.S. had already sanctioned <i>Intellexa</i> and some executives, and the sentence is stayed pending appeal while authorities investigate further.</p><p class="paragraph" style="text-align:left;">🇺🇸 🙊 <b>CISA is in trouble</b> — CISA has lost a large share of its staff and key programs, weakening its cyber defenses and coordination. Political hostility and leadership delays have deepened the problem and eroded trust with industry and local governments. Experts warn <a class="link" href="https://cyberscoop.com/cisa-personnel-cuts-trump-second-term-analysis/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">CISA may not have the capacity to handle major cyber crises</a> without rebuilding its workforce.</p><p class="paragraph" style="text-align:left;">🇬🇧 💰️ <b>The UK ICO fined Reddit £14.47 million for collecting and using data from children under 13 </b>without proper safeguards. Reddit only added weak age checks in July 2025, which <a class="link" href="https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/02/reddit-issued-with-1447m-fine-for-children-s-privacy-failures/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">the regulator said were easy to bypass</a>. Reddit will appeal, arguing most UK users are adults and that stronger ID checks hurt privacy.</p><p class="paragraph" style="text-align:left;">🎦 🚗 🇺🇸 <b>People across the U.S. are destroying Flock license-plate surveillance cameras</b> in protest. Critics say the <a class="link" href="https://techcrunch.com/2026/02/23/americans-are-destroying-flock-surveillance-cameras/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">cameras help immigration authorities track</a> and deport people. Cities and activists are cutting, smashing, or demanding removal of the cameras.</p><p class="paragraph" style="text-align:left;">🖼️ 🤖 <b>Data protection authorities from across the globe have published a Joint Statement on AI-Generated Imagery</b> — Global privacy authorities <a class="link" href="https://ico.org.uk/media2/fb1br3d4/20260223-iewg-joint-statement-on-ai-generated-imagery.pdf?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">warn</a> against AI systems that create realistic images or videos of real people without consent. They urge organizations to follow data protection laws, add strong safeguards, be transparent, and remove harmful content quickly. Regulators call for proactive engagement to protect privacy, dignity, and vulnerable people.</p><p class="paragraph" style="text-align:left;">🪪 🇬🇧 <b>Discord is making age verification mandatory and will use either facial age checks or ID</b> to control access. UK users say <a class="link" href="https://www.eurogamer.net/discord-advises-uk-users-that-they-may-be-part-of-an-experiment-where-instead-of-their-age-verification-data-never-leaving-their-phone-it-will-now-actually-leave-their-phone?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">Discord changed its promise</a>: some selfies and IDs may be sent to vendor Persona and stored up to seven days instead of always staying on-device. Users worry about data security and Persona’s backers, and Discord has been contacted for comment.</p></div><p class="paragraph" style="text-align:left;"></p><div id="malware-threats" class="section" style="background-color:transparent;border-color:#C0C0C0;border-radius:10px;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🦠 MALWARE & THREATS</h3><p class="paragraph" style="text-align:left;">🕹️ 🎠 <b>Cybercriminals are distributing trojanized gaming tools through browsers and chat apps</b> to install a <a class="link" href="https://thehackernews.com/2026/02/trojanized-gaming-tools-spread-java.html?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">Java-based remote access trojan (RAT)</a>. The malware uses stealthy loaders, Microsoft Defender exclusions, and persistence to enable data theft, remote control, and additional payloads. New RAT families like <i>Steaelite</i>, <i>DesckVB</i>, and <i>KazakRAT</i> bundle theft and ransomware features for powerful, easy-to-use attacker dashboards.</p><p class="paragraph" style="text-align:left;">👀 📲 <b>Predator spyware hides iOS camera and microphone recording indicators</b> by hooking a SpringBoard function that blocks sensor status updates. It uses kernel-level access and technique like PAC redirection to bypass permission checks and keep feeds streaming to operators. Jamf’s <a class="link" href="https://www.jamf.com/blog/predator-spyware-ios-recording-indicator-bypass-analysis/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">analysis shows traces of the malware in SpringBoard and mediaserverd</a> despite no visible status-dot indicators.</p><p class="paragraph" style="text-align:left;">🪦 <i><b>Arkanix Stealer</b></i><b> was a short-lived malware-as-a-service that surfaced in October 2025 and vanished</b> by December. It stole wide-ranging data — browsers, apps, VPNs, Telegram/Discord, files, wallets — and offered a control panel and post-exploitation tools. Kaspersky says <a class="link" href="https://securelist.com/arkanix-stealer/119006/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">the campaign was a one-shot effort</a> for quick profit, with servers and Discord taken down.</p><p class="paragraph" style="text-align:left;">🪱 <b>Researchers found a worm-like campaign (</b><i><b>SANDWORM_MODE</b></i><b>) using at least 19 malicious npm packages</b> to steal crypto keys, API tokens, and CI/GitHub secrets. The <a class="link" href="https://socket.dev/blog/sandworm-mode-npm-worm-ai-toolchain-poisoning?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">malware also uses a malicious GitHub Action</a>, can wipe home directories, and injects a fake MCP server to trick AI coding tools and harvest LLM keys and SSH/AWS/NPM credentials. Users should remove the listed packages, rotate tokens and secrets, and check repos and workflows for unexpected changes.</p></div><p class="paragraph" style="text-align:left;"></p><div id="ai-crypto-tech-tools" class="section" style="background-color:transparent;border-color:#C0C0C0;border-radius:10px;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🤖 🧰 AI, CRYPTO, TECH & TOOLS</h3><blockquote align="center" class="twitter-tweet"><a href="https://twitter.com/hackerschoice/status/2024766193807000050?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care"><p> Twitter tweet </p></a></blockquote><hr class="content_break"><p class="paragraph" style="text-align:left;">🐛 <b>Researchers found serious vulnerabilities in Anthropic&#39;s Claude Code</b> that <a class="link" href="https://blog.checkpoint.com/research/check-point-researchers-expose-critical-claude-code-flaws/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">let attackers run commands and steal API keys</a> by simply opening malicious repositories. The flaws abused config files and MCP servers to bypass consent and send authenticated requests to attacker-controlled endpoints. If exploited, attackers could access project files, modify cloud data, and incur unexpected API costs.</p><p class="paragraph" style="text-align:left;">❌ <b>Anthropic has removed the core pledge in its safety policy </b>that barred training new AI models unless safety could be guaranteed in advance. The company says <a class="link" href="https://time.com/7380854/exclusive-anthropic-drops-flagship-safety-pledge/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">the change reflects practical realities</a>, more transparency, and plans for regular risk reports and safety roadmaps. Critics warn the move weakens constraints and could make managing catastrophic AI risks harder.</p><p class="paragraph" style="text-align:left;">🇨🇳 <b>Anthropic says three Chinese AI labs used fake accounts to send 16 million prompts to its Claude model</b> to steal capabilities. The <a class="link" href="https://www.anthropic.com/news/detecting-and-preventing-distillation-attacks?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">startup calls this “distillation” and warns it can remove safety guards</a> and enable cyberattacks, surveillance, or disinformation. Anthropic urges stronger export controls and says the activity violated its terms.</p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://www.securityweek.com/anthropic-refuses-to-bend-to-pentagon-on-ai-safeguards-as-dispute-nears-deadline/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">Anthropic Refuses to Bend to Pentagon on AI Safeguards as Dispute Nears Deadline</a></p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://techcrunch.com/2026/02/27/employees-at-google-and-openai-support-anthropics-pentagon-stand-in-open-letter/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">Employees at Google and OpenAI support Anthropic’s Pentagon stand in open letter</a></p><p class="paragraph" style="text-align:left;">→ <a class="link" href="https://techcrunch.com/2026/02/27/anthropic-vs-the-pentagon-whats-actually-at-stake/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">Anthropic vs. the Pentagon: What’s actually at stake?</a></p><div class="embed"><a class="embed__url" href="https://www.404media.co/this-app-warns-you-if-someone-is-wearing-smart-glasses-nearby/?ref=daily-stories-newsletter&utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank"><div class="embed__content"><p class="embed__title"> This App Warns You if Someone Is Wearing Smart Glasses Nearby </p><p class="embed__description"> The creator of Nearby Glasses made the app after reading 404 Media&#39;s coverage of how people are using Meta&#39;s Ray-Bans smartglasses to film people without their knowledge or consent. “I consider it to be a tiny part of resistance against surveillance tech.” </p><p class="embed__link"> www.404media.co/this-app-warns-you-if-someone-is-wearing-smart-glasses-nearby/?ref=daily-stories-newsletter </p></div><img class="embed__image embed__image--right" src="https://www.404media.co/content/images/size/w1200/2026/02/meta-glasses.png"/></a></div></div><p class="paragraph" style="text-align:left;"></p><div id="vulnerabilities-research-and-threat" class="section" style="background-color:transparent;border-color:#C0C0C0;border-radius:10px;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🐛 🧠 VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE</h3><p class="paragraph" style="text-align:left;">➝ From the Patching Department:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/cisco-patches-catalyst-sd-wan-zero-day-exploited-by-highly-sophisticated-hackers/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">Cisco Patches Catalyst SD-WAN Zero-Day </a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/trend-micro-patches-critical-apex-one-vulnerabilities/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">Trend Micro Patches Critical Apex One Vulnerabilities</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/juniper-networks-ptx-routers-affected-by-critical-vulnerability/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">An out-of-band security update for Junos OS Evolved patches the remote code execution vulnerability CVE-2026-21902</a></p></li></ul><p class="paragraph" style="text-align:left;">🩹 <b>SolarWinds patched four critical Serv‑U flaws</b> that can allow attackers to gain root or admin access. All <a class="link" href="https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_15-5-4_release_notes.htm?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care#link7" target="_blank" rel="noopener noreferrer nofollow">four bugs require attackers to already have high privileges</a>, limiting but not eliminating risk. Thousands of Serv‑U servers are exposed online and the software has been repeatedly targeted by threat actors.</p><hr class="content_break"><div class="embed"><a class="embed__url" href="https://dixken.de/blog/i-found-a-vulnerability-they-found-a-lawyer?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank"><div class="embed__content"><p class="embed__title"> I found a Vulnerability. They found a Lawyer. </p><p class="embed__description"> What happens when you responsibly disclose a critical vulnerability exposing personal data - including that of minors - and the organization responds with legal threats instead of a thank you? </p><p class="embed__link"> dixken.de/blog/i-found-a-vulnerability-they-found-a-lawyer </p></div><img class="embed__image embed__image--right" src="https://dixken.de/images/blog/costa-rica.jpg"/></a></div><p class="paragraph" style="text-align:left;">⚠️ <b>Attackers have been exploiting two Cisco SD-WAN zero-days since 2023</b> to gain long-term access to network edge devices. Authorities, including CISA and the Five Eyes, <a class="link" href="https://cyberscoop.com/cisco-zero-days-cisa-emergency-directive-five-eyes/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">issued emergency guidance and threat-hunt steps</a> after discovering the ongoing campaign. Officials warn the attacks are highly targeted and require urgent patching and forensic checks.</p><p class="paragraph" style="text-align:left;">⏱️ <b>CrowdStrike found attackers are moving through networks much faster, with average breakout time down to 29 minutes</b> and some attacks taking seconds. Attackers <a class="link" href="https://cyberscoop.com/crowdstrike-annual-global-threat-report-attack-breakout-time/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">increasingly use living-off-the-land tactics</a>, stolen credentials, and cloud or edge device flaws to avoid detection. Nation-state and criminal groups are exploiting more zero-days and AI-driven techniques, widening threats and stressing defenders.</p><p class="paragraph" style="text-align:left;">🧠 📲 <b>Security researchers found 1,575 vulnerabilities in ten popular Android mental health apps</b> with over 14.7 million installs. Many <a class="link" href="https://www.bleepingcomputer.com/news/security/android-mental-health-apps-with-147m-installs-filled-with-security-flaws/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">flaws could expose therapy data</a>, intercept logins, or let attackers read local files and spoof app behavior. Some apps claim encryption or privacy but still use insecure coding and outdated protections.</p><p class="paragraph" style="text-align:left;">✈️ 🪖 <b>The Dutch Defense Secretary said the F-35’s software and cloud systems could be “jailbroken” like an iPhone</b> to accept third-party updates. Experts warn doing so would be legally risky and would not replace U.S. maintenance, mission planning, or spare-part support. The comment <a class="link" href="https://www.twz.com/air/f-35-software-could-be-jailbreaked-like-an-iphone-dutch-defense-minister?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">highlights tensions for foreign F-35 operators</a> reliant on U.S. control and logistics.</p><p class="paragraph" style="text-align:left;">🇷🇺 <b>A Russian-speaking hacker used AI tools to help breach over 600 FortiGate firewalls across 55 countries</b> in five weeks. The attacker relied on exposed management interfaces and weak credentials, then used AI-assisted scripts to automate reconnaissance and lateral movement. <a class="link" href="https://aws.amazon.com/blogs/security/ai-augmented-threat-actor-accesses-fortigate-devices-at-scale/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">Amazon warns AI services are lowering the bar for attackers</a> and urges admins to remove internet-exposed interfaces and enable MFA.</p><div class="embed"><a class="embed__url" href="https://open.substack.com/pub/ydinkin/p/200-kernel-bugs-in-30-days?utm_campaign=post-expanded-share&utm_medium=web" target="_blank"><div class="embed__content"><p class="embed__title"> 100+ Kernel Bugs in 30 Days </p><p class="embed__description"> High-Scale Driver Vulnerability Research with Agent Swarms </p><p class="embed__link"> open.substack.com/pub/ydinkin/p/200-kernel-bugs-in-30-days?utm_campaign=post-expanded-share&utm_medium=web </p></div><img class="embed__image embed__image--right" src="https://substackcdn.com/image/fetch/$s_!69zh!,w_1200,h_675,c_fill,f_jpg,q_auto:good,fl_progressive:steep,g_auto/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb80bdc16-283c-4636-acee-50b2a1ee40a6_1536x1024.png"/></a></div></div><p class="paragraph" style="text-align:left;"></p><div id="ics-ot-io-t" class="section" style="background-color:transparent;border-color:#C0C0C0;border-radius:10px;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">🛰️ ICS, OT & IoT</h3><div class="embed"><a class="embed__url" href="https://unit42.paloaltonetworks.com/ot-edge-security/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank"><div class="embed__content"><p class="embed__title"> Bring the Fight to the Edge: Turning Time Into an Advantage in OT Security </p><p class="embed__description"> Unit 42 research reveals most OT attacks begin in IT. Learn how edge-driven defense stops threats early and turns dwell time into advantage. </p><p class="embed__link"> unit42.paloaltonetworks.com/ot-edge-security </p></div><img class="embed__image embed__image--right" src="https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/09_Security-Technology_Category_1505x922.jpg"/></a></div><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/zyxel-patches-critical-vulnerability-in-many-device-models/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">Zyxel Patches Critical Vulnerability in Many Device Models</a></p></li></ul><hr class="content_break"><p class="paragraph" style="text-align:left;">🌱 <i><b>Gardyn</b></i><b> indoor smart gardens had two critical and two high-severity security flaws</b> that could allow remote attackers to take control. <i>Gardyn</i> and CISA <a class="link" href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-055-03?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">say</a> patches and app/firmware updates have been released and most devices should be updated automatically. Researchers estimate about 138,000 devices were affected but there is no evidence the flaws were exploited in the wild.</p><p class="paragraph" style="text-align:left;">🔓️ 🛜 <b>Researchers found a new Wi‑Fi attack called </b><i><b>AirSnitch</b></i><b> that can break encryption</b> and expose data. The <a class="link" href="https://arstechnica.com/security/2026/02/new-airsnitch-attack-breaks-wi-fi-encryption-in-homes-offices-and-enterprises/?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">flaw affects home, office, and enterprise networks</a> and exploits weaknesses in Wi‑Fi design. This shows many devices and users remain vulnerable despite past security improvements.</p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#f0f0f0;border-color:#C0C0C0;border-radius:10px;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h3 class="heading" style="text-align:left;">💬 CONNECT</h3><p class="paragraph" style="text-align:left;">Follow me on <a class="link" href="https://infosec.exchange/@0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">Mastodon</a> for quick daily updates and bite-sized content.</p><p class="paragraph" style="text-align:left;">Prefer using an RSS feed? Add <b>Infosec MASHUP</b> to your feed <a class="link" href="https://rss.beehiiv.com/feeds/HVhiKYpQlR.xml?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">here</a>.</p><p class="paragraph" style="text-align:center;"><b>Enjoying our newsletter? </b>Forward it to a colleague—<br>it’s one of the best ways to support us.</p><p class="paragraph" style="text-align:left;">Thanks for reading today’s newsletter, and if you&#39;re enjoying it and want to support my work, you can <b>buy me a coffee</b> ☕ over at <a class="link" href="https://www.buymeacoffee.com/0x58?utm_source=infosec-mashup.santolaria.net&utm_medium=newsletter&utm_campaign=infosec-mashup-09-2026-your-iphone-has-a-green-dot-predator-doesn-t-care" target="_blank" rel="noopener noreferrer nofollow">https://www.buymeacoffee.com/0x58</a></p><p class="paragraph" style="text-align:left;"> See you next time!</p><p class="paragraph" style="text-align:left;">-X.</p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=169e59b7-b236-4d8b-84f0-84533adac142&utm_medium=post_rss&utm_source=x_s_infosec_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

  </channel>
</rss>
