View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

FBI disrupts proxy network used in Chinese espionage operations

🚨 ACTIVE EXPLOITATION

  • FBI disrupts proxy network used in Chinese espionage operations
    The FBI disrupted a proxy network used to support Chinese cyber espionage.

    • U.S. defense, government, research, aerospace, healthcare, finance, energy, and software organizations were targeted.
    • The quartermaster service profiled targets and supported data theft by China-linked operators.
    • QScan collected ports, banners, operating-system fingerprints, and configuration data.
    • Fast Labyrinth encrypted and rotated relays, while QTRouter and QTProxy managed devices and routes through fastlink.ws nodes.
      πŸ“Ž Coverage: bleepingcomputer.com Β· πŸ‘ via BleepingComputer
  • Tortoiseshell Expands Espionage Campaign With Windows Backdoor and Reverse SSH
    Tortoiseshell has added a Windows backdoor and reverse SSH tunneling utility to its espionage toolkit.

    • Tortoiseshell, also known as Mirage Kitten, UNC1549 and Nimbus Manticore, targets organizations for espionage.
    • The campaign deploys a Windows backdoor to maintain access after network compromise.
    • A reverse SSH utility tunnels traffic through an attacker-controlled server.
    • The tunneling capability supports persistent remote access inside compromised networks.
      πŸ“Ž Coverage: cryptika.com Β· πŸ‘ via Cyber Security News, cryptika.com (discovered)

πŸ’₯ BREACHES & INCIDENTS

  • Suspected Chinese-Speaking Operator Breached Philippine Nuclear and Naval Groups
    Hunt.io found evidence of intrusions into two Philippine organizations by a suspected Chinese-speaking operator.
    • A Philippine nuclear research agency and a Navy-contracted marine engineering company were targeted.
    • The stolen data included reactor component databases, radiation safety documents, employee personal information, and credential stores.
    • The nuclear agency was breached through ownCloud CVE-2023-49105 and a default empty signing secret.
    • The naval contractor was compromised through LiteSpeed Cache CVE-2024-28000 and XML-RPC brute force using rockyou.txt; 176 recovered files totaled about 372 MB, while a CSV referenced roughly 9 GB of exfiltrated data.
    • Simplified Chinese appeared in the operator’s scripts, logs, and folder names.
      πŸ“Ž Coverage: hunt.io Β· πŸ‘ via r/cybersecurity

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • NovaCookies Phishing Service Steals Microsoft 365 Sessions for $320 Monthly
    NovaCookies is a $320-a-month service stealing Microsoft 365 authenticated sessions.

    • Microsoft 365 users at hundreds of organizations across the U.S., U.K., Canada, Germany, Israel, and the U.A.E. are targeted.
    • The kit steals credentials, MFA codes, and authenticated Microsoft 365 sessions; it also supports Okta and federated Entra ID flows.
    • Genuine DocuSign notifications deliver counterfeit document lures, with malicious destinations hidden inside shared documents.
    • NovaCookies uses OAuth redirects and a real-time adversary-in-the-middle relay, plus Cloudflare gates and debugging checks to evade analysis.
    • Lure domains often use the .vu TLD and alternating-case labels such as PwPt-sHaRe, Ms36-AcCeSs, and ClOd-ViEw.
      πŸ“„ Source: island.io Β· πŸ“Ž Coverage: thehackernews.com Β· πŸ‘ via Dark Reading, The Hacker News
  • Tenable and SentinelOne Find State and Criminal Groups Converging on Edge Infrastructure
    Tenable and SentinelOne found state and criminal groups targeting the same edge infrastructure.

    • Internet-facing edge infrastructure, including Ivanti, Fortinet and Palo Alto Networks products, is in scope.
    • The joint analysis covered 93 CVE-actor attribution pairs.
    • State-sponsored and financially motivated groups independently exploit weaknesses in perimeter devices.
    • The findings combine Tenable exposure telemetry with SentinelOne incident-response observations.
      πŸ“„ Source: sentinelone.com Β· πŸ“Ž Coverage: tenable.com Β· πŸ‘ via Tenable Cyber Exposure, SentinelOne Blog

πŸ“‹ ADVISORIES

  • Ubiquiti patches critical vulnerabilities across UniFi products
    Ubiquiti has patched critical vulnerabilities in its UniFi products.

    • UniFi Access, Protect, Network, and OS Server deployments are affected.
    • CVE-2026-77543 and CVE-2026-77533 enable command injection with low privileges.
    • CVE-2026-77539 and CVE-2026-77535 enable command injection with high privileges.
    • CVE-2026-77545 involves active debug code that can enable privilege escalation.
    • The flaws are remotely exploitable over the network, with CVSS scores from 9.0 to 9.9.
      πŸ“„ Source: community.ui.com Β· πŸ“Ž Coverage: bleepingcomputer.com Β· πŸ‘ via BleepingComputer
  • Adobe and Nvidia Patch Dozens of Critical Product Vulnerabilities
    Adobe and Nvidia patched dozens of vulnerabilities across their products.

    • Adobe customers using Substance 3D Designer, Sampler, Painter, XD, Campaign Classic, Illustrator, and Content Credentials SDK are affected.
    • Nvidia customers using NemoClaw, OpenShell, DGX Spark, Unified Fabric Manager, Triton Inference Server, Cumulus Linux, and NVOS are affected.
    • Nvidia fixed critical and high-severity flaws enabling code execution, privilege escalation, data tampering, information disclosure, and denial of service.
    • Adobe patched critical code execution flaws; it said none had been exploited in the wild, while Campaign Classic received a Priority 1 rating.
      πŸ“„ Source: helpx.adobe.com Β· πŸ“Ž Coverage: securityweek.com Β· πŸ‘ via SecurityWeek
  • snowflake-service-account-passwordless-migration
    πŸ“Ž BleepingComputer

  • πŸ“„ Source for CISA Red Team Fully Compromised Two Critical Infrastructure Organizations

  • πŸ“Ž cisa.gov

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check