View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

U.S. charges 17 Iranians over Mabna Institute cyber-theft campaign

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • U.S. charges 17 Iranians over Mabna Institute cyber-theft campaign
    The U.S. has charged 17 Iranians with conducting a cyber-theft campaign for the IRGC.

    • The charges apply to 17 Iranian hackers-for-hire employed by the Mabna Institute.
    • Targets included 144 U.S. universities, 42 private companies and at least five government agencies.
    • Nine defendants allegedly targeted 100,000 professors’ email accounts and accessed about 8,000.
    • The campaign allegedly stole roughly 31 terabytes of research and intellectual property.
    • Eight additional defendants allegedly stole HBO data and attempted to extort $6 million in Bitcoin.
      πŸ“„ Source: justice.gov Β· πŸ“Ž Coverage: cbsnews.com Β· πŸ‘ via @campuscodi@mastodon.social
  • Microsoft Copilot Personal flaws enabled one-click data exfiltration
    Varonis found three Microsoft Copilot Personal flaws that enabled one-click data theft.

    • Microsoft Copilot Personal at copilot.microsoft.com was affected; Microsoft 365 Copilot was not identified as affected.
    • The CoSnitch flaws exposed connected mail, calendar, Google Drive, chat history, and Copilot memory data; CVE-2026-24301 tracks the issue.
    • An attacker-crafted link combined q= with the undocumented autorun=1 parameter to execute prompts in the victim’s authenticated session.
    • Copilot could encode stolen data in base64 and send it through a URL fetch to an attacker-controlled webhook; crafted pages could also poison persistent memory.
      πŸ“„ Source: varonis.com Β· πŸ“Ž Coverage: thehackernews.com Β· πŸ‘ via The Hacker News
  • Microsoft tracks MacSync Stealer through 30+ rotating C2 domains
    Microsoft uncovered more than 30 domains linked to MacSync Stealer infrastructure.

    • macOS users are targeted by MacSync Stealer, a malware-as-a-service infostealer.
    • The malware steals passwords, macOS Keychain data, browser credentials, and cryptocurrency wallet credentials.
    • Malvertising delivers a staged zsh loader that downloads and executes additional payloads.
    • The loader rotates C2 domains while reusing a static API key and per-build hexadecimal token.
    • Observed C2 paths include /curl, /dynamic, and /gate; stolen data is staged as /tmp/osalogging.zip and uploaded in 10 MiB chunks.
      πŸ“Ž Coverage: microsoft.com Β· πŸ‘ via Microsoft Security Blog

πŸ“‹ ADVISORIES

  • πŸ“„ Source for Ransom Busters Poses as Recovery Service, Demands Up to $60,000 β€” guidepointsecurity.com

  • πŸ“„ Source for Moby go-archive flaw lets Docker archive extraction write outside its target β€” github.com

πŸ”“ CVEs & KEV

  • CVE-2026-55166 β€” CVSS 9.9 β€” Lemur: Incomplete fix for CVE-2026-55166 -- ACME authority update endpoint al...

  • CVE-2026-47627 β€” CVSS 9.8 β€” NVIDIA Triton Inference Server: Critical Path Traversal Leads to DoS

  • CVE-2026-70667 β€” CVSS 6.3 β€” Lemur: SSRF protection in certificate revocation checking bypassable via HTTP...

  • CVE-2026-55162 β€” CVSS 6.3 β€” Lemur: Post-authentication SSRF via certificate verification - attacker-contr...

  • CVE-2026-55163 β€” CVSS 6.3 β€” Lemur: Privilege escalation via PUT /api/1/roles/<id> β€” non-admin role member...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check