๐จ ACTIVE EXPLOITATION
-
CareCloud Data Breach Exposes Personal, Financial, and Medical Data of 350,000+ Hackers stole personal, financial, and medical data from CareCloud's AWS environment.
- Applies to CareCloud Health division's electronic health record environment
- Over 350,000 individuals impacted with stolen names, addresses, SSNs, DOBs, IDs, financial and medical info
- Hackers accessed CareCloud's AWS environment between March 10 and March 16, 2026
- Data exfiltration confirmed after investigation concluded on June 24, 2026 ๐ Coverage: securityweek.com ยท ๐ via SecurityWeek
-
ExfilSquad hacks UK Department for Education, steals 600,000 records Hackers from ExfilSquad breached the UK Department for Education and stole data.
- Targets: UK Department for Education and UK Police National Legal Database
- Data stolen: 600,000 records including names, emails, and phone numbers
- Attack vector: Breach of two web portals, including the agency's help desk portal
- Threat actor: ExfilSquad claims responsibility and is attempting extortion
- Additional claims: ExfilSquad also claims breaches of UK Police database and Microsoft ๐ Coverage: news.risky.biz ยท ๐ via @campuscodi@mastodon.social
-
No detailed public reports on OpenAI-Hugging Face rogue AI incident CVE-2026-59726 and CVE-2026-66803
No substantive information is available on the OpenAI-Hugging Face rogue AI incident or related CVEs.- Applies to OpenAI and Hugging Face AI platforms
- Vulnerabilities identified as CVE-2026-59726 and CVE-2026-66803
- No public technical details or attack vectors disclosed
- No confirmed exploitation or impact reports found ๐ Coverage: mastodon.social ยท ๐ via @campuscodi@mastodon.social
๐ CVEs & KEV
- Other: 21 CVEs (worst 9.8)
๐ต๏ธ RESEARCH & DEEP DIVES
-
Astaroth Malware Uses WhatsApp Web to Spread Banking Trojan in Brazil Astaroth malware spreads via victims' WhatsApp Web sessions by sending malicious ZIP files to contacts.
- Targets Brazilian WhatsApp users by exploiting active WhatsApp Web sessions
- Sends convincing Portuguese messages with malicious ZIP attachments to contacts
- Uses WebDriver to automate hidden browser sessions and WPPConnectWA-JS library for messaging
- Filters contacts to exclude groups, unsaved numbers, and non-Brazilian contacts
- Evolved from email phishing to automated WhatsApp propagation for faster infection chains ๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
-
OctLurk and SilkLurk Backdoors Target Central Asian Government Networks Custom backdoors OctLurk and SilkLurk have compromised Central Asian government computers.
- Targets government networks in Afghanistan, Kazakhstan, Kyrgyzstan, Tajikistan, Uzbekistan, and Syria
- Backdoors enable keylogging, browser password theft, email exfiltration, and remote command execution
- OctLurk uses victim-specific loaders and in-memory plugins for stealth and broad control
- SilkLurk hides behind legitimate Windows programs and injects payloads into memory
- Attackers use stolen admin credentials, scheduled tasks, malicious services, and PlugX RAT for persistence and lateral movement ๐ Coverage: cybersecuritynews.com ยท ๐ Original: cybersecuritynews.com ยท ๐ via Cyber Security News
-
Gentlemen Ransomware Kills Nearly 180 Security Processes Before Encryption Gentlemen ransomware disables nearly 180 security processes before encrypting files.
- Targets businesses using antivirus, endpoint detection, backup agents, and monitoring software
- Uses kernel-level driver anticheatG13.sys to terminate security-related processes and manipulate system memory
- Driver supports process termination, network traffic control, command-line rewriting, and driver load inspection
- Attackers gain deep system access to disable defenses before deploying ransomware encryption ๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
๐ ADVISORIES
-
CISA Warns Water Utilities of Cyberattacks on Internet-Exposed PLCs CISA warns water utilities of rising cyberattacks targeting internet-exposed PLCs.
- Applies to water and wastewater utilities using programmable logic controllers (PLCs)
- PLCs controlling water treatment, pumping, chemical dosing, and wastewater management are vulnerable
- Attackers alter PLC passwords and IP addresses to disrupt operations and lock out operators
- PLCs exposed via direct internet connections or vendor-installed cellular modems are targeted
- Rockwell Automation MicroLogix 1400 PLCs specifically mentioned for password recovery guidance ๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
-
PHP fixes three vulnerabilities causing SQL injection, memory corruption, and crashes PHP patched three high-severity flaws affecting ext-pgsql, ext-bcmath, and ext-phar extensions.
- Affects PHP optional extensions: ext-pgsql, ext-bcmath, and ext-phar
- SQL injection via php_pgsql_convert() in PostgreSQL extension with standard_conforming_strings enabled
- Out-of-bounds memory write in bccomp() due to incorrect buffer handling in BCMath extension
- Denial-of-service crash from infinite recursion in phar_get_link_source() following circular symbolic links in Phar archives
- Fixed in PHP versions 8.2.33, 8.3.33, 8.4.24, and 8.5.9 ๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News