π¨ ACTIVE EXPLOITATION
-
SparkRAT Campaign Targets Cambodia Using Vulnerable OPSWAT Driver
A Cambodia-focused campaign uses a vulnerable OPSWAT driver to deploy SparkRAT.- Individuals and organizations in Cambodia were targeted with government, health, dental, real estate, and promotional lures.
- The campaign deployed the open-source Go-based SparkRAT and abused OPSWAT AppRemover driver ardrv.sys, affected by CVE-2026-36425.
- Compressed archives delivered Inno Setup executables that used signed Tencent binary F7u00ex.exe to sideload malicious DLL WfoY.qf.
- PNG-embedded shellcode, timing-based anti-sandbox checks, process injection, services, and scheduled tasks supported execution and persistence.
- The malware impaired Microsoft Defender, Huorong Internet Security, and Tencent PC Manager; observed C2 included sx.nuihuw.com:443 and nuihuw.top:443.
π Source: acronis.com Β· π Coverage: thehackernews.com Β· π via The Hacker News
-
Aurora Affiliate Used AI to Attack More Than 20 Organizations
A Russian-speaking Aurora ransomware affiliate used Cursor AI during attacks on more than 20 organizations.- A Russian-speaking Aurora affiliate targeted more than 20 organizations across nine countries from April through July 2026.
- Victims spanned manufacturing, food and agriculture, professional services, transport, consumer goods, waste management, and IT infrastructure; at least 17 environments were compromised.
- An unauthenticated file listing on port 8888 exposed the operatorβs Linux home directory, including credentials, Kerberos tickets, AD data, tools, chat logs, and ransomware binaries.
- The affiliate used Cursor in Russian to plan intrusions and AD escalation, alongside NetExec, noPac, ADCS abuse, PetitPotam, PrinterBug, and DFSCoerce.
- Auroraβs Zig-based Windows and Linux/ESXi lockers included hashes eb0aab1e892d7e09e2c7bcf1d21fd83c1743ed9196b3efac6c78482fb0d99207 and a4af136d159a8eb96b54924fa80355ca52874913301300f55af7d67ae97edcfe; ransom notes used !!!README!!!DO_NOT_DELETE.txt.
π Source: cloudsek.com Β· π Coverage: gbhackers.com Β· π via Cyber Security News, cryptika.com (discovered)
π CVEs & KEV
-
CVE-2026-77533 β CVSS 9.9 β A malicious actor with access to the network and low privileges could exploit...
-
CVE-2026-75977 β CVSS 8.8 β Mang Board WP through 2.3.7 - Authenticated (Subscriber+) Privilege Escalation to ...
-
CVE-2026-78236 β CVSS 8.8 β Insecure PIN derivation mechanism in Admin By Request (ABR)An insecure PIN de...
-
CVE-2026-78237 β CVSS 7.8 β Insufficient input validation in Admin By Request (ABR)Insufficient input val...
-
CVE-2026-18884 β CVSS 7.5 β WooCommerce Lottery through 2.2.9 - Unauthenticated Time-Based SQL Injection via '...
-
CVE-2026-9668 β CVSS 6.3 β SQL injection vulnerability in ZTE SCP productWith legitimate user credential...
π΅οΈ RESEARCH & DEEP DIVES
-
UPDATE: Two alleged TeamPCP hackers charged in Australia
Australian authorities have charged two alleged TeamPCP members over global supply-chain attacks.- The suspects are two Western Australian men aged 21 and 23, allegedly principal TeamPCP participants.
- The attacks allegedly compromised more than 1,000 organizations across government, academia and the private sector.
- The stolen data included more than 500,000 credentials and at least 300 GB of data.
- TeamPCP allegedly inserted malicious code into open-source software that developers unwittingly distributed through software updates.
- The group used the Shai-Hulud worm after phishing or stealing developer credentials from repositories including GitHub and NPM.
π Source: afp.gov.au Β· π Coverage: krebsonsecurity.com Β· π via Krebs on Security, @campuscodi@mastodon.social (+4)
-
OpenAI Disrupts Cambodian Scam Network Using ChatGPT
OpenAI disrupted a Cambodian social-engineering network that used ChatGPT to run scams.- Online targets were exposed to scams run by a Cambodian criminal network.
- The group used dating personas to promote fraudulent cryptocurrency and spot-gold investments.
- Operators also conducted romance scams, fake gambling promotions, and law-enforcement impersonation scams.
- ChatGPT supported personalized identities and extended conversations across multiple scam schemes.
π Source: openai.com Β· π Coverage: schneier.com Β· π via Schneier on Security
-
Kaspersky Reports Q2 2026 Threats Targeting Industrial Control Systems
Kaspersky documented ransomware, miners, spyware and other threats affecting industrial control systems in Q2 2026.- Industrial automation and industrial control system operators are covered.
- Kaspersky tracked ransomware, cryptocurrency miners, spyware and other threats detected and blocked on ICS environments.
- The report presents Q2 2026 threat statistics broken down by region and industry.
π Source: ics-cert.kaspersky.com Β· π Coverage: securelist.com Β· π via Securelist (Kaspersky)
-
Cisco Talos explains how JavaScript obfuscation powers phishing kits
Cisco Talos details how obfuscated JavaScript conceals phishing and malware activity.- Phishing victims, malware analysts, developers, and users of compromised websites may encounter obfuscated JavaScript.
- Phishing kits use it to hide credential theft, malware loaders, browser abuse, and fake CAPTCHA or update flows.
- String arrays, encoded URLs, runtime decoders, and renamed functions conceal the scriptβs intent.
- Packed code can reconstruct payloads at runtime and execute them with eval().
π Coverage: blog.talosintelligence.com Β· π via Cisco Talos
-
NIST Says Agentic AI Requires a Strong Identity Foundation
NIST says agentic AI deployments need stronger identity security.- Enterprises are deploying AI agents for commerce, customer service, security, and software development.
- AI agents act as non-human identities while invoking tools, accessing sensitive data, calling APIs, and delegating to sub-agents.
- 69% of surveyed enterprises have deployed AI agents, while 90% plan to do so within two years.
- 71% of developers use insecure methods to handle non-human identities such as service accounts and API keys.
- Agents operate at machine speed, making static IAM policies and standing privileges inadequate for runtime decisions and attribution.
π Coverage: nist.gov Β· π via NIST Cybersecurity Insights
π ADVISORIES
- PaperCut issues urgent security advisory for all NG/MF versions
PaperCut has issued an urgent security advisory affecting all NG/MF versions.- PaperCut NG and MF customers across all versions are affected.
- Available advisory details about the vulnerability are limited.
- The advisory includes indicators of compromise (IoCs).
π Source: papercut.com Β· π Coverage: reddit.com Β· π via r/cybersecurity
π ADVISORIES
- π Source for Critical Veeam ONE Flaw Enables Unauthenticated SMB Authentication Coercion β veeam.com
π΅οΈ RESEARCH & DEEP DIVES
- polymorphic-phishing-pages β SANS ISC