๐จ ACTIVE EXPLOITATION
-
Suspected China-linked AI agents breach Taiwan government and energy networks Suspected China-linked actors used autonomous AI agents to breach Taiwanese government and energy infrastructure.
- Taiwanese government agencies, the nuclear safety agency, and at least seven energy companies were targeted.
- At least 85 government administrative accounts were compromised.
- More than 2,500 personnel files were exfiltrated.
- OpenClaw and Hermes frameworks deployed up to eight agents to map 21 networks and change tactics when blocked.
- Attackers bypassed AI safety controls by disguising malicious tasks as authorized security audits. ๐ Source: reuters.com ยท ๐ Coverage: clashreport.com ยท ๐ via @metacurity@infosec.exchange
-
City-Forum Campaign Targets Salesforce and ServiceNow Guest Access Researchers observed City-Forum attacks exfiltrating data exposed through Salesforce and ServiceNow guest access.
- Targets include telecoms, banks, financial-services firms, enterprise-software vendors and public-sector portals.
- Salesforce Aura and LWR sites, plus ServiceNow Service Portals, are affected.
- Attackers use unauthenticated guest access to enumerate and retrieve exposed records.
- A custom Go toolset uses Salesforce UI-API and GraphQL alongside a ServiceNow search endpoint.
- The campaign uses IP 158.220.87.79, which resolves to city-forum.com, and has remained active since March 2025. ๐ Coverage: securityweek.com ยท ๐ via SecurityWeek
-
WindRelay and SpyNote Enable 13-Minute Android NFC Payment Fraud WindRelay and SpyNote enabled rapid Android banking and contactless-payment fraud.
- Android banking customers in Czechia, Slovakia, and Slovenia were targeted.
- SpyNote remote access and WindRelay NFC relay malware enabled digital loans and card-present fraud.
- Victims sideloaded personalized SpyNote APKs after bank-impersonation calls; Accessibility Service abuse installed WindRelay.
- WindRelay relayed live EMV exchanges over the internet to an attacker-controlled device at a merchant terminal or ATM.
- Observed IOCs included C2 IPs 88[.]86[.]124[.]114, 185[.]100[.]87[.]116, 185[.]100[.]87[.]223, and 213[.]218[.]160[.]48. ๐ Source: group-ib.com ยท ๐ Coverage: gbhackers.com ยท ๐ via Cyber Security News, cryptika.com (discovered)
-
Fake CCleaner Installer Delivers GhostDesk Spyware to Windows Users A fake CCleaner installer delivers GhostDesk spyware to Windows users.
- Windows users downloading CCleaner from counterfeit sites are targeted.
- GhostDesk steals browser credentials, cookies, keystrokes, screenshots, and form data.
- A CScript-based loader patches Chrome's Security Extension and drops background.js and content.js.
- The malware uses WebSocket C2 at liderongrade.duckdns[.]org:4444 and a local relay at 127.0.0.1:7345/ext.
- Key IOCs include ccleanerwind[.]top, liderongrade.duckdns[.]org, and 193.169.240[.]81; fake 7-Zip and Adobe Acrobat installers use the same chain. ๐ Coverage: malwarebytes.com ยท ๐ via Cyber Security News, cryptika.com (discovered)
๐ฅ BREACHES & INCIDENTS
- Leak exposes 7.3 million Chess.com records
A leak exposed 7.3 million Chess.com records.
- Chess.com users are implicated in the reported leak.
- The exposed dataset contains 7.3 million records.
- The access method and attack tooling were not identified. ๐ Coverage: ransomnews.com ยท ๐ via @metacurity@infosec.exchange
๐ CVEs & KEV
-
CVE-2026-11325 โ CVSS 8.8 โ cloudflare/pages-action is deprecated โ migration required by September 18th,...
-
CVE-2026-16747 โ CVSS 6.5 โ Kirki before 6.2.1 - Unauthenticated Arbitrary Shortcode Execution via Form Email ...
๐ต๏ธ RESEARCH & DEEP DIVES
-
737 Fake Chrome VPN Extensions Redirected Browser Traffic Through SOCKS5 Proxies Attackers used fake Chrome VPN extensions to redirect browser traffic through SOCKS5 proxies.
- Chrome users, especially Russian-speaking users seeking access to blocked services, were targeted.
- 737 extensions across at least 40 developer accounts amassed more than 75,000 installs.
- 274 extensions copied the names or branding of 66 established VPN and privacy services.
- Of 522 retrieved packages, 520 routed browser traffic through fixed SOCKS5 proxies on port 1082.
- The campaign used DNS-over-HTTPS, remote configuration, post-approval code changes, and manipulated reviews; myxavpn.pro was associated infrastructure. ๐ Source: socket.dev ยท ๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
-
Researchers Demonstrate Coin-Sized Physical Attack on Boeing 737 Systems Researchers demonstrated a physical-access attack that can manipulate Boeing 737 flight systems.
- The finding affects Boeing 737 aircraft and their operators.
- A coin-sized device can redirect autopilot navigation and alter takeoff or fuel calculations.
- An attacker with ground access can install the Wi-Fi-enabled device through an exterior hatch in under 60 seconds.
- The implant sends spoofed signals on internal aircraft networks and can falsify values shown to pilots.
- Researchers built the prototype for less than $100. ๐ Source: paddleyourownkanoo.com ยท ๐ Coverage: wired.com ยท ๐ via @metacurity@infosec.exchange, @agreenberg@infosec.exchange (+4)
-
Picus finds enterprise defenses missing low-noise attacks Picus Labs found attackers bypassing enterprise defenses by avoiding detectable activity.
- Enterprise organizations are covered by Picus Labs' Blue Report 2026.
- The report found defenses tuned for noisy attacks are missing low-noise threats.
- Picus analyzed more than 338 million attack simulations in client production environments during the first half of 2026.
- Attackers evade detection by minimizing activity that triggers defensive controls. ๐ Coverage: thehackernews.com ยท ๐ via The Hacker News
-
2.86 Billion Credentials Flood Criminal Markets as Enterprise Access Gets Pricier DarkOwl reports that 2.86 billion compromised credentials reached criminal markets in 2025.
- Healthcare, finance and critical-infrastructure organizations face premium targeting.
- Infostealers harvest browser passwords, session cookies and other data for cloud, VPN and business-account access.
- Phishing lures, fake updates, pirated downloads and malicious attachments deliver the malware.
- Initial-access-broker listings averaged $113,275 in 2025, up from $2,726 in 2024.
- Stolen session cookies can be replayed to bypass password and MFA prompts. ๐ Source: darkowl.com ยท ๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News, cryptika.com (discovered)
-
Cotton Cloud for Joomla fixed two access-control flaws in version 2.0.3
CVE-2026-67283CVE-2026-67284Cotton Cloud for Joomla had two access-control flaws fixed in version 2.0.3.- Joomla sites using the Cotton Cloud extension were affected.
- CVE-2026-67283 and CVE-2026-67284 were access-control vulnerabilities.
- The initial fix for one flaw left data exposed.
- The vulnerabilities were fixed in Cotton Cloud 2.0.3. ๐ Coverage: mysites.guru ยท ๐ via mysites.guru (discovered)