π¨ ACTIVE EXPLOITATION
-
FBI disrupts proxy network used in Chinese espionage operations
The FBI disrupted a proxy network used to support Chinese cyber espionage.- U.S. defense, government, research, aerospace, healthcare, finance, energy, and software organizations were targeted.
- The quartermaster service profiled targets and supported data theft by China-linked operators.
- QScan collected ports, banners, operating-system fingerprints, and configuration data.
- Fast Labyrinth encrypted and rotated relays, while QTRouter and QTProxy managed devices and routes through fastlink.ws nodes.
π Coverage: bleepingcomputer.com Β· π via BleepingComputer
-
Tortoiseshell Expands Espionage Campaign With Windows Backdoor and Reverse SSH
Tortoiseshell has added a Windows backdoor and reverse SSH tunneling utility to its espionage toolkit.- Tortoiseshell, also known as Mirage Kitten, UNC1549 and Nimbus Manticore, targets organizations for espionage.
- The campaign deploys a Windows backdoor to maintain access after network compromise.
- A reverse SSH utility tunnels traffic through an attacker-controlled server.
- The tunneling capability supports persistent remote access inside compromised networks.
π Coverage: cryptika.com Β· π via Cyber Security News, cryptika.com (discovered)
π₯ BREACHES & INCIDENTS
- Suspected Chinese-Speaking Operator Breached Philippine Nuclear and Naval Groups
Hunt.io found evidence of intrusions into two Philippine organizations by a suspected Chinese-speaking operator.- A Philippine nuclear research agency and a Navy-contracted marine engineering company were targeted.
- The stolen data included reactor component databases, radiation safety documents, employee personal information, and credential stores.
- The nuclear agency was breached through ownCloud CVE-2023-49105 and a default empty signing secret.
- The naval contractor was compromised through LiteSpeed Cache CVE-2024-28000 and XML-RPC brute force using rockyou.txt; 176 recovered files totaled about 372 MB, while a CSV referenced roughly 9 GB of exfiltrated data.
- Simplified Chinese appeared in the operatorβs scripts, logs, and folder names.
π Coverage: hunt.io Β· π via r/cybersecurity
π΅οΈ RESEARCH & DEEP DIVES
-
NovaCookies Phishing Service Steals Microsoft 365 Sessions for $320 Monthly
NovaCookies is a $320-a-month service stealing Microsoft 365 authenticated sessions.- Microsoft 365 users at hundreds of organizations across the U.S., U.K., Canada, Germany, Israel, and the U.A.E. are targeted.
- The kit steals credentials, MFA codes, and authenticated Microsoft 365 sessions; it also supports Okta and federated Entra ID flows.
- Genuine DocuSign notifications deliver counterfeit document lures, with malicious destinations hidden inside shared documents.
- NovaCookies uses OAuth redirects and a real-time adversary-in-the-middle relay, plus Cloudflare gates and debugging checks to evade analysis.
- Lure domains often use the .vu TLD and alternating-case labels such as PwPt-sHaRe, Ms36-AcCeSs, and ClOd-ViEw.
π Source: island.io Β· π Coverage: thehackernews.com Β· π via Dark Reading, The Hacker News
-
Tenable and SentinelOne Find State and Criminal Groups Converging on Edge Infrastructure
Tenable and SentinelOne found state and criminal groups targeting the same edge infrastructure.- Internet-facing edge infrastructure, including Ivanti, Fortinet and Palo Alto Networks products, is in scope.
- The joint analysis covered 93 CVE-actor attribution pairs.
- State-sponsored and financially motivated groups independently exploit weaknesses in perimeter devices.
- The findings combine Tenable exposure telemetry with SentinelOne incident-response observations.
π Source: sentinelone.com Β· π Coverage: tenable.com Β· π via Tenable Cyber Exposure, SentinelOne Blog
π ADVISORIES
-
Ubiquiti patches critical vulnerabilities across UniFi products
Ubiquiti has patched critical vulnerabilities in its UniFi products.- UniFi Access, Protect, Network, and OS Server deployments are affected.
- CVE-2026-77543 and CVE-2026-77533 enable command injection with low privileges.
- CVE-2026-77539 and CVE-2026-77535 enable command injection with high privileges.
- CVE-2026-77545 involves active debug code that can enable privilege escalation.
- The flaws are remotely exploitable over the network, with CVSS scores from 9.0 to 9.9.
π Source: community.ui.com Β· π Coverage: bleepingcomputer.com Β· π via BleepingComputer
-
Adobe and Nvidia Patch Dozens of Critical Product Vulnerabilities
Adobe and Nvidia patched dozens of vulnerabilities across their products.- Adobe customers using Substance 3D Designer, Sampler, Painter, XD, Campaign Classic, Illustrator, and Content Credentials SDK are affected.
- Nvidia customers using NemoClaw, OpenShell, DGX Spark, Unified Fabric Manager, Triton Inference Server, Cumulus Linux, and NVOS are affected.
- Nvidia fixed critical and high-severity flaws enabling code execution, privilege escalation, data tampering, information disclosure, and denial of service.
- Adobe patched critical code execution flaws; it said none had been exploited in the wild, while Campaign Classic received a Priority 1 rating.
π Source: helpx.adobe.com Β· π Coverage: securityweek.com Β· π via SecurityWeek
-
snowflake-service-account-passwordless-migration
π BleepingComputer -
π Source for CISA Red Team Fully Compromised Two Critical Infrastructure Organizations
-
π cisa.gov