๐จ ACTIVE EXPLOITATION
-
Akira affiliate rebooted Windows host into Safe Mode to evade EDR An Akira affiliate used Windows Safe Mode to evade endpoint defenses.
- Organizations using exposed SonicWall SSL VPNs and Windows endpoints were targeted.
- Safe Mode disabled the Huntress agent and Microsoft Defender real-time protection.
- The attacker used credential spraying, RDP, AnyDesk and msconfig.exe to reach and reboot the host.
- The actor stole credentials and file shares with WinRAR and s5cmd before launching akira.exe; encryption failed from virtual-memory errors.
- IOC: 72.23.77[.]35; akira.exe SHA-256 414b9985f46714f44dd1bd63860d2a48dcfababcfe5c712a4b4f575378127a56. ๐ Source: huntress.com ยท ๐ Coverage: theregister.com ยท ๐ via Cyber Security News, cryptika.com (discovered)
-
Phantom Stealer Hides Encrypted Payloads in PNGs to Steal Windows Data Phantom Stealer is stealing sensitive data from Windows users.
- Windows users in multiple countries are targeted by .NET-based Phantom Stealer campaigns.
- The malware steals browser passwords, cookies, payment-card data, cryptocurrency wallets, credentials, files, screenshots, keystrokes and clipboard contents.
- Phishing emails, malicious links, pirated software and Discord or Telegram lures deliver the malware.
- A .NET loader decrypts payloads hidden in PNG resources, while obfuscated PowerShell compiles C# and injects shellcode into explorer.exe.
- Reported SHA-256 IOCs include b588caa5365451a6c60fd73fec5b73f13ac41bcc2a3a3bed7244df5917a62f32, 382233c398cbc35dcee845ee17046815f37588a382a8106bfb9b0252ea803961 and be119a21bedc3a79bf4dea8bcf5adf18304997a01ea23e276b9c31be37b789ab. ๐ Source: splunk.com ยท ๐ Coverage: gbhackers.com ยท ๐ via Cyber Security News, cryptika.com (discovered)
๐ต๏ธ RESEARCH & DEEP DIVES
-
White House Authorizes Vetted Firms to Conduct Cyber Operations Against Foreign Gangs The White House has authorized vetted private firms to conduct government-supervised cyber operations against foreign criminal groups.
- The program applies to vetted U.S. cybersecurity companies targeting foreign cyber-enabled transnational criminal organizations.
- Targets include groups linked to ransomware, financial fraud and other crimes affecting Americans.
- Companies may conduct cyber surveillance and cyber effects operations, including disruption, degradation or destruction of systems.
- The DHS National Coordination Center will manage the program under DHS and DOJ oversight.
- Participating firms may need a bond or escrow of at least $1 million. ๐ Source: whitehouse.gov ยท ๐ Coverage: securityweek.com ยท ๐ via SecurityWeek, @campuscodi@mastodon.social (+4)
-
Jewelbug APT Conducts Espionage and Cryptocurrency Theft Jewelbug hackers-for-hire conducted both cyber espionage and cryptocurrency theft.
- Jewelbug is a suspected advanced persistent threat group linked to hackers-for-hire.
- The group conducted cyber espionage and financially motivated cryptocurrency heists.
- Researchers observed both operations managed through the same web panel. ๐ Coverage: darkreading.com ยท ๐ via Dark Reading
-
SpecterOps Blacklight Finds Sensitive AI Coding-Agent Artifacts SpecterOps released Blacklight to identify sensitive artifacts left by AI coding agents.
- AI coding-agent users of Codex, Claude Code, Cursor, and Antigravity CLI are affected.
- Local agent artifacts can expose authentication data, tokens, session history, project details, and connected services.
- Blacklight is an open-source toolkit that discovers and analyzes these artifacts on endpoints. ๐ Source: specterops.io ยท ๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News, cryptika.com (discovered)
-
Imperva Finds Nearly 40% of APIs Have Multiple Authentication Risks Imperva found that nearly 40% of APIs have multiple authentication risks.
- The report covers 1,104 customer environments and 32,725 live API endpoints.
- The risks affect JWTs, Basic Authentication, and token lifecycles.
- Measured issues include sensitive JWT data, weak signing algorithms, long token lifespans, raw Basic Auth credentials, and expired tokens retaining access.
- Weak JWT signing algorithms appeared in 15.2% of detections, down from 19.0% year over year.
- The findings are based on real API detection data across five authentication-risk categories. ๐ Coverage: imperva.com ยท ๐ via Imperva