View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Jewelbug breached government webmail while running crypto fraud

🚨 ACTIVE EXPLOITATION

🚨 7 | Jewelbug breached government webmail while running crypto fraud operations
Jewelbug ran government espionage and cryptocurrency-fraud operations from shared infrastructure.

  • Governments and militaries in the Middle East, Southeast Asia, South Asia and Taiwan were targeted alongside Chinese-speaking crypto users.
  • A shared government webmail platform serving more than 15 tenants was compromised, exposing cookies, credentials and more than 2,300 email bodies.
  • Jewelbug injected scripts into login and mailbox pages to open WebSocket connections to its C2 and identify target government domains.
  • Fake Adobe updates and malicious HTA files delivered the Antino backdoor, while the PDF Viewer Chrome/Firefox extension stole cookies, credentials, browsing data and clipboard contents.
  • The XG-Web panel coordinated espionage and fraud using AI-generated fake exchange pages, SEO poisoning and hundreds of lookalike domains impersonating OKX and Binance.
    :page_facing_up: Source: security.com · :paperclip: Coverage: bleepingcomputer.com · :eye: via BleepingComputer

⚠️ BREACHES & INCIDENTS

⚠️ 6 | Beacon CRM Confirms UK Charity Database Was Copied and Likely Downloaded
Beacon CRM confirmed attackers copied and likely downloaded its entire customer database.

  • The breach affects more than 1,500 UK charities and nonprofits using Beacon CRM.
  • The copied database included customer data and attachment files, potentially exposing donor, supporter, volunteer and beneficiary records.
  • Potentially exposed fields include names, addresses, email addresses, phone numbers, dates of birth and donation histories.
  • Compromised credentials were used to access Beacon's systems, with an AWS access key exposed in public JavaScript build artifacts as the leading suspect.
  • Malicious activity began July 27, 2026, lasted 87 minutes and coincided with a significant AWS data-transfer spike on July 27-28.
    :page_facing_up: Source: beaconcrm.org · :paperclip: Coverage: theregister.com · :eye: via cryptika.com (discovered)

🕵️ RESEARCH & DEEP DIVES

⚠️ 6 | Docker Sandboxes read-only mounts could be bypassed via a writable VirtioFS path CVE-2026-18171
Docker Sandboxes had a read-only mount bypass.

  • Docker Sandboxes users running coding agents such as Claude Code, Codex, or Gemini CLI were affected.
  • Versions 0.35.0 through before 0.38.0 allowed read-only host-mounted directories to be modified.
  • The bypass used Docker’s writable /mnt/host VirtioFS export instead of the restricted /readonly mount.
  • Modified source code, CI configurations, infrastructure code, or build inputs could be executed later outside the sandbox.
  • The issue is CVE-2026-18171 with a CVSS score of 5.7; Docker fixed it in version 0.38.0.
    :paperclip: Coverage: aikido.dev · :eye: via aikido.dev (discovered)

⚠️ 5 | Cheaper AI models are becoming much better at hacking
XBOW found cheaper AI models have become effective at complex hacking tasks.

  • The finding affects open-weight and proprietary AI models used in offensive security workflows.
  • Z.ai GLM-5.2, xAI Grok 4.5, Anthropic Opus 4.7 and Meta Muse Spark 1.1 performed strongly on hacking and exploitation tasks.
  • OpenAI GPT-5.5 improved autonomous web application testing, with a 10% vulnerability miss rate versus 40% for GPT-5.
  • Cheaper models can be run repeatedly for longer agentic tasks, while live interaction with target software mattered more than source-code access.
    :page_facing_up: Source: xbow.com · :paperclip: Coverage: cyberscoop.com · :eye: via CyberScoop

:pushpin: 4 | Connecticut court faults hidden AI prompt injection in legal filing
A Connecticut judge faulted a self-represented plaintiff for hiding instructions to influence AI review of court filings.

  • The case involved a self-represented plaintiff and a Connecticut Superior Court.
  • The plaintiff embedded instructions telling AI systems to favor the filing and reverse a clerk’s denial.
  • The text used tiny white-on-white font that was invisible to people but machine-readable.
  • The instructions appeared in Docket Entries 177.00 and 178.00, with additional hidden text in later filings.
    :page_facing_up: Source: civilinquiry.jud.ct.gov · :paperclip: Coverage: 404media.co · :eye: via 404 Media, @metacurity@infosec.exchange

🔓 CVEs & KEV

Other: 13 CVEs (worst 9.3)
Apache: 3 CVEs (worst 7.5)

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check