π¨ ACTIVE EXPLOITATION
-
Ransomware Gangs Exploit VPN and Firewall Flaws in Palo Alto, Fortinet, Citrix, Check Point
Ransomware operators are exploiting VPN and firewall vulnerabilities from four major vendors to breach corporate networks.- Targets include Palo Alto Networks, Fortinet, Citrix, and Check Point VPN and firewall appliances
- Exploitation involves authentication bypass, credential harvesting, and legacy protocol weaknesses
- Notable campaigns: Fortibleed mass credential compromise of FortiGate devices, Palo Alto GlobalProtect CVE-2026-0257 bypass
- Check Point CVE-2026-50751 IKEv1 authentication bypass exploited by Qilin ransomware affiliates
- Citrix NetScaler CVE-2026-8451 memory disclosure exploited within 24 hours of disclosure
π Coverage: cybersecuritynews.com Β· π via Cyber Security News
-
East Asian-linked TELESHIM malware abuses Telegram for C2 in Middle East govt attacks
A new malware campaign using TELESHIM abuses Telegram for command-and-control in Middle East government attacks.- Targets government entities in the Middle East with previously unreported malware TELESHIM, MIXEDKEY, and BINDCLOAK
- Attack begins with ISO file deploying a legitimate executable to sideload TELESHIM backdoor DLL
- TELESHIM uses Telegram API for C2 communication to blend with legitimate traffic and evade detection
- Employs heavy code obfuscation and virtualization detection to hinder analysis and reverse engineering
- Final payload BINDCLOAK is a 64-bit implant contacting external C2 server cert.hypersnet[.]com
π Coverage: thehackernews.com Β· π via The Hacker News
-
SparkKitty malware steals crypto wallet seed phrases from iOS and Android photos
SparkKitty malware steals cryptocurrency wallet seed phrases by scanning photos on mobile devices.- Targets cryptocurrency users on iOS and Android devices
- Steals wallet seed phrases hidden in screenshots and gallery images using OCR technology
- Spreads via trojanized apps on official app stores and third-party sideloading channels
- Requests photo access to scan images and sends extracted data to attacker-controlled servers
- Notable infected apps include iOS app 'εΈcoin' and Android app 'SOEX' with over 10,000 Google Play downloads
π Coverage: cybersecuritynews.com Β· π via Cyber Security News
-
BlueNoroff Hijacks Trusted Telegram Accounts to Spread ClickFix Malware via Fake Zoom Calls
BlueNoroff hijacks Telegram accounts to deliver ClickFix malware through fake Zoom and Teams invites.- Targets senior staff at cryptocurrency and Web3 firms using hijacked Telegram accounts of trusted contacts
- Delivers fake Zoom and Microsoft Teams meeting links that lead to ClickFix malware installation
- Attack uses deepfake video calls and clipboard hijacking to run PowerShell loaders and macOS shell scripts
- Malware scans browsers for crypto wallets before stealing credentials and funds
- Indicators include multiple malicious domains, PowerShell loaders, VBScript implants, and Mach-O binaries
π Coverage: cybersecuritynews.com Β· π via Cyber Security News
π₯ BREACHES & INCIDENTS
- DentaQuest Data Breach in May 2026 Potentially Affects Over 23 Million People
Hackers stole personal and dental health information from DentaQuest's network in May 2026.- Applies to DentaQuest customers, a dental and vision benefits administrator serving 35 million people
- Stolen data includes names, addresses, Social Security numbers, member IDs, Medicaid/Medicare numbers, diagnosis, treatment, and billing details
- Attackers accessed the network between May 17 and May 20, 2026
- Extortion group ShinyHunters claimed responsibility and leaked approximately 234 GB of data
- At least 15 million individuals confirmed affected; over 23 million potentially impacted according to HIPAA Journal
π Coverage: securityweek.com Β· π via SecurityWeek
π΅οΈ RESEARCH & DEEP DIVES
- Hackers Create Over 70 Fake Websites Impersonating Popular Windows Apps to Spread Malware
Hackers are using fake websites mimicking popular Windows apps to distribute malware.- Targets over 70 popular Windows utilities including PowerToys, WinUtil, EasyBCD, and CrystalDiskMark
- Attackers register domains closely matching app names and use old logos and guides to appear legitimate
- Fake sites initially offer real downloads to build trust before swapping in malware payloads
- Malware includes remote access tools and bandwidth sharing software delivered via trojanized installers
- Infrastructure uses anonymized WHOIS email and proxy hosting to evade takedown efforts
π Coverage: cybersecuritynews.com Β· π via Cyber Security News
π ADVISORIES
- GitHub Adds 3-Day Cooldown to Dependabot to Limit Poisoned Package Adoption
GitHub introduced a 3-day cooldown in Dependabot to delay updates and reduce supply chain attack risks.- Applies to GitHub Dependabot users managing software dependencies
- Cooldown delays pull requests for version updates by at least three days after release
- Security updates bypass cooldown and are pushed immediately
- Aims to reduce risk from short-lived poisoned package versions spreading quickly
- Cooldown duration is configurable via dependabot.yml and defaults to three days
π Coverage: thehackernews.com Β· π via The Hacker News