๐จ ACTIVE EXPLOITATION
- UNC6671 vishing attacks target hedge funds and private-equity firms
UNC6671 has targeted financial firms in voice-phishing attacks.
- Point72, Millennium, Two Sigma, Citadel, private-equity firms, and other financial organizations were targeted.
- Microsoft 365 and Okta accounts, cloud services, credentials, session cookies, and data were targeted.
- Attackers spoofed corporate help desks and called employees on personal mobile phones.
- Victims were directed to adversary-in-the-middle phishing sites to steal credentials and session cookies in real time.
- Automated tools accessed linked cloud platforms, stole data, and deleted security notifications and password-reset emails. ๐ Coverage: bleepingcomputer.com ยท ๐ via BleepingComputer
๐ต๏ธ RESEARCH & DEEP DIVES
-
UPDATE: More Than 4,400 Rockwell PLCs Exposed Online, Including 22 in Attack-Hit Cities More than 4,400 Rockwell PLCs remain exposed online.
- U.S. water utilities use the exposed Rockwell Automation/Allen-Bradley PLCs.
- Forescout identified 4,407 exposed Rockwell controllers worldwide, including 2,844 in the United States.
- Twenty-two exposed PLCs were located in cities hit by recent water-system attacks, with 19 using firmware susceptible to CVE-2017-16740.
- Attackers remotely accessed internet-facing devices and changed IP addresses and passwords, disrupting monitoring and control.
- Exposed EtherNet/IP on TCP port 44818 can provide unauthenticated access to identify controllers or write settings, depending on configuration. ๐ Source: censys.com ยท ๐ Coverage: cyberscoop.com ยท ๐ via CyberScoop
-
Researcher Claims Proof-of-Concept Control of ChatGPT Secure Sandbox A researcher demonstrated a proof-of-concept attack against ChatGPT's isolated sandbox.
- The claim applies to ChatGPT's isolated sandbox during an OpenAI agent session.
- The attack provided C2-style influence over the sandbox.
- The proof of concept used an attack chain demonstrated at Black Hat USA 2026. ๐ Coverage: darkreading.com ยท ๐ via Dark Reading
-
Attackers increasingly target exposed OT systems for destructive disruption Attackers targeted exposed OT systems at U.S. water utilities.
- U.S. water and wastewater utilities were targeted, including more than 30 Minnesota systems.
- Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs were specifically targeted.
- Attackers changed PLC passwords to lock out operators.
- Attackers changed PLC IP addresses, disrupting remote access and forcing manual operations. ๐ Source: cisa.gov ยท ๐ Coverage: cybersecuritydive.com ยท ๐ via Cybersecurity Dive
๐ ADVISORIES
- UPDATE: Zbtlink routers ship with an embedded backdoor enabling remote root shells
VulnCheck found an embedded backdoor in at least 20 Zbtlink router models.
- Zbtlink and Wiflyer routers, including white-label models sold worldwide, are affected; VulnCheck estimates more than 100,000 deployed.
- The Endlessdoors implant appears in all 21 firmware images available from Zbtlink and affects models including CPE2801, WE1026-5G-WD, WE1326, WE2007, WE2008-DSIM, WE2416, WE3326, WE5927, WE5931, WE5931AC, WE826-T3-DSIM, WG108, WG1602-DSIM, WG1608-DSIM, WG209, WG2105, WG2107, WG259, WG3526, and Z8102AX-2DSIM.
- The implant starts at boot as a root userland process disguised as a Linux kworker thread and phones home every 35 seconds over unauthenticated cleartext TCP.
- The rctl-based implant can execute server commands and open an interactive root shell through ports 7000 and 7001.
- Reported endpoints include 47.107.224[.]89, rbdg4nzqadui[.]wikaba[.]com, zbtctl.epplink[.]net, 47.100.190[.]96, online-string[.]com, 45.32.81[.]152, and 43.248.136[.]125. ๐ Coverage: mastodon.social ยท ๐ via @campuscodi@mastodon.social