π΅οΈ RESEARCH & DEEP DIVES
-
Check Point Unmasks StopAndProtect Ransomware Operation Targeting WordPress Sites
Check Point Research identified a ransomware operation targeting thousands of WordPress sites.- WordPress site owners are affected, with thousands of sites reportedly hacked.
- The StopAndProtect ransomware family was first observed in mid-May 2026.
- The infection chain begins with ClickFix social engineering that tricks victims into executing a PowerShell command.
- The PowerShell command downloads two additional stages.
π Coverage: research.checkpoint.com Β· π via Check Point Research
-
TWINLOOT Uses Microsoft Cloud Services for Stealthy C2 and Credential Theft
Ontinue has uncovered TWINLOOT, a Python implant that hides C2 inside Microsoft services.- Microsoft 365 and Windows environments using SharePoint, Teams, and Edge are affected.
- TWINLOOT steals Windows credentials, executes commands, enables SOCKS5 lateral movement, and persists without administrator rights.
- Teams social engineering impersonating IT support tricks victims into running a PowerShell command that downloads an archive containing a Python runtime and the 39 MB bootstrap-fat.pyc loader.
- The implant polls an attacker-controlled SharePoint drive through Microsoft Graph every 15 seconds and routes interactive access through Teams TURN WebRTC DataChannels.
- A headless Edge browser controlled through Chrome DevTools Protocol makes Graph API traffic appear legitimate; lateral connections can use SMB 445, RDP 3389, WinRM 5985, and MSSQL 1433.
π Source: ontinue.com Β· π Coverage: thehackernews.com Β· π via Dark Reading, The Hacker News
-
Researchers Show βMind Virusesβ Can Propagate Between AI Agents
Anthropic and EPFL researchers demonstrated self-propagating payloads moving between AI agents through persistent prompt files.- The technique affects autonomous AI agents and multi-agent coding harnesses that reload editable prompt files between sessions.
- Ideological and action payloads targeted agent goals and behavior, including file deletion, Git tampering, and shell-script execution.
- Agents propagated payloads by writing them to SOUL.md, which was injected into the next sessionβs system prompt; 55% of such attempts infected the next agent.
- In tests, four action payloads survived 20-hop agent chains, but researchers found no evidence of successful propagation in the wild or on Moltbook.
π Source: arxiv.org Β· π Coverage: thehackernews.com Β· π via The Hacker News
-
StubMaker Typosquats 16 RubyGems Packages to Steal Credentials and Wallets
StubMaker malware targeted RubyGems users with a Windows information stealer.- RubyGems users on Windows were targeted by the StubMaker campaign.
- Sixteen typosquatted gems mimicked dependencies including bundler, i18n, rake, and activesupport.
- Install-time extconf.rb hooks executed a 22 MB Rust loader containing an 11 MB Go stealer.
- The malware harvested Chromium browser credentials, wallet data, seed phrases, Telegram data, and system information.
- Packages included ubnuler, ubnlder, ri18nr, reaker, rakier, orakw, joxn, ise18n, ioe18n, ie18u, iai8n, i1l8n, i18om, activesupmport, brumdler, and brundlef.
π Source: opensourcemalware.com Β· π Coverage: thehackernews.com Β· π via The Hacker News
-
Audit finds RCE-by-design flaws across seven AI orchestration platforms
An audit found 14 security findings across seven AI orchestration platforms.- The findings affect NocoBase, Flowise, Langflow, Dify, Activepieces, Kestra, and Airflow deployments.
- The platforms allow workflow users to execute code on the host, creating remote-code-execution exposure in multi-tenant HTTP services.
- A Flowise chain uses an unauthenticated webhook, prompt injection, and LLM-generated Python code.
- Flowiseβs 38-pattern regex blocklist can be bypassed because a dangerous library is pre-imported before the LLM generates code.
- Two vendors classified their reported findings as working as intended.
π Coverage: endorlabs.com Β· π via r/netsec
-
Octagon Android Bot Targets Crypto Wallets and Banking Apps
iVerify identified Octagon as an Android bot targeting crypto wallets and banking apps.- Android users of crypto wallets, exchanges, banking apps, and messaging services are targeted by AndroidKitKatβs MaaS platform.
- Octagon steals seed phrases, passwords, PINs, unlock patterns, balances, SMS messages, and one-time codes.
- WardAccessibilityService reads app interfaces and places HTML WebView phishing overlays over legitimate apps.
- Hidden VNC-style control enables screen viewing, screenshots, taps, swipes, text entry, and app launches.
- Sideloaded APKs disguise the malware as unrelated apps; version 1.2 was announced June 29, 2026, with C2 at 45.192.12[.]34:4444 and 104.251.180[.]179:4444.
π Source: iverify.io Β· π Coverage: gbhackers.com Β· π via cryptika.com (discovered)
π ADVISORIES
-
π Source for CISA Says Ransomware Gangs Exploit Windows Task Host Flaw β nvd.nist.gov
-
π Source for C2Looper Backdoor Uses OneDrive Sideloading and GitHub for C2 β zscaler.com
π CVEs & KEV
-
CVE-2026-75851 β CVSS 9.4 β ArcadeDB before 26.8.1 Authentication Bypass via Async CommandArcadeDB server...
-
CVE-2026-75843 β CVSS 9.4 β ArcadeDB before 26.8.1 Privilege Escalation via gRPC TransactionArcadeDB befo...
-
CVE-2026-75854 β CVSS 9.3 β ArcadeDB Redis Wire-Protocol Plugin Missing AuthenticationArcadeDB versions b...
-
CVE-2026-75852 β CVSS 9.3 β ArcadeDB MongoDB wire protocol authentication bypass cross-databaseArcadeDB v...
-
CVE-2026-75837 β CVSS 9.3 β Grav before 2.0.14 Privilege Escalation via Group Access FieldGrav before 2.0...
-
CVE-2026-75835 β CVSS 9.3 β Grav API Plugin before 1.0.14 Missing AuthorizationGrav API plugin (getgrav/g...
-
CVE-2026-75853 β CVSS 8.7 β ArcadeDB Gremlin Wire Protocol Authorization Bypass Cross-DatabaseArcadeDB's ...
-
CVE-2026-75840 β CVSS 8.7 β ArcadeDB before 26.8.1 Arbitrary File Read via Unescaped RegexArcadeDB before...
-
CVE-2026-75836 β CVSS 8.7 β Grav API Plugin before 1.0.14 Missing AuthorizationThe Grav API plugin (getgr...
-
CVE-2026-75855 β CVSS 8.4 β ArcadeDB before 26.8.1 Path Traversal via create/drop databaseArcadeDB versio...
-
CVE-2026-75842 β CVSS 8.3 β ArcadeDB before 26.8.1 Arbitrary File Read via LOAD CSVArcadeDB versions befo...
-
CVE-2026-75846 β CVSS 7.1 β ArcadeDB before 26.8.1 Unauthorized Function Deletion via DELETE FUNCTIONArca...
-
CVE-2026-75844 β CVSS 7.1 β ArcadeDB before 26.8.1 SSRF via IMPORT DATABASE validator bypassArcadeDB vers...
-
ai-driven-patch-prioritization β SecurityWeek
-
ransom-busters-ransomware-deception β Dark Reading
-
octagon-android-otp-theft β Cyber Security News
-
π Source for CISA Says Ransomware Gangs Exploit Windows Task Host Flaw β nvd.nist.gov
-
π Source for C2Looper Backdoor Uses OneDrive Sideloading and GitHub for C2 β zscaler.com