π₯ BREACHES & INCIDENTS
- River Bank Hit by June Ransomware Attack, Hackers Deleted Stolen Data
River Bank was hit by ransomware in June and hackers deleted stolen data after exfiltration.
- Applies to River Financial Corporation, holding company of River Bank & Trust
- Ransomware deployed across parts of the bank's server environment on June 16, 2026
- Hackers accessed network portions and exfiltrated certain data
- Investigation ongoing with third-party forensic firm; unclear if personal data was stolen
- Bank engaged with hackers to have stolen data deleted, likely after ransom payment π Coverage: securityweek.com Β· π via SecurityWeek
π΅οΈ RESEARCH & DEEP DIVES
-
Octagon Android RAT hides as Bahrain BH Alert app and survives reboots A new Android RAT called Octagon disguises as Bahrain's BH Alert app and persists through device reboots.
- Targets Android users, primarily in Bahrain, by impersonating the official BH Alert emergency app
- Delivers malware via phishing pages and APK downloads outside official app stores
- Uses layered architecture with encrypted payloads and watchdog services to survive reboots
- Steals device unlock credentials, SMS, banking info, and displays phishing overlays
- Abuses Accessibility Service and VPN permissions to capture input and intercept traffic π Coverage: cybersecuritynews.com Β· π via Cyber Security News
-
Samsung bans smart TV apps that share usersβ internet connections with strangers Samsung has banned smart TV apps that share users' internet connections via residential proxy networks.
- Applies to Samsung smart TV apps available on Samsung's app store
- Apps contain residential proxy (resproxy) code that shares users' internet connections with outsiders
- Some apps, including a Samsung-endorsed Pac-Man game, turn TVs into exit nodes for proxy traffic
- Resproxy code activates after user consent and can run continuously, risking hijacking and botnet use
- Samsung is removing existing apps with this functionality and banning new registrations with proxy features π Coverage: techcrunch.com Β· π via @zackwhittaker@mastodon.social
π UNDER-REPORTED
- Kaspersky reports ransomware and insider threats at Brazilian educational institutions
Brazilian educational institutions faced ransomware and insider attacks exploiting valid accounts and exposed apps.
- Applies to Brazilian public and private educational institutions, mainly in SΓ£o Paulo, Rio de Janeiro, and Pernambuco
- Ransomware families DragonForce and LockBit 3 were prevalent, with LockBit builder leaked in 2022
- Attackers used valid privileged accounts, exploited public-facing applications, and insider threats for initial access
- Tools like AnyDesk, PsExec, AV-killer malware, and Potato variants were used for remote access, lateral movement, and privilege escalation
- 60% of incidents were medium severity; 40% were high severity, mostly ransomware targeting private institutions π Coverage: securelist.com Β· π Original: securelist.com Β· π via Securelist (Kaspersky)
π CVEs & KEV
- CVE-2026-2346 β CVSS 9.8 β IDOR in Menulux Software's Mobile AppAuthorization bypass through User-Contro...
- CVE-2026-18598 β CVSS 8.8 β GL.iNet GL-MT3000 Logread Lua RPC plugin logread logread.get_system_log comma...
- CVE-2026-18599 β CVSS 8.0 β GL.iNet GL-MT3000 Logread Lua RPC Plugin logread logread.set_config command i...
- CVE-2026-56609 β CVSS 4.8 β HCL iControl is affected by multiple security vulnerabilities(CVE-2026-56608 ...
- CVE-2026-56608 β CVSS 3.7 β HCL iControl is affected by multiple security vulnerabilities(CVE-2026-56608 ...
- CVE-2026-18574 β CVSS β β Authentication Bypass in Check Point Security Management ServerAn authenticat...