View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Aurora Affiliate Used AI to Attack More Than 20 Organizations

🚨 ACTIVE EXPLOITATION

  • SparkRAT Campaign Targets Cambodia Using Vulnerable OPSWAT Driver
    A Cambodia-focused campaign uses a vulnerable OPSWAT driver to deploy SparkRAT.

    • Individuals and organizations in Cambodia were targeted with government, health, dental, real estate, and promotional lures.
    • The campaign deployed the open-source Go-based SparkRAT and abused OPSWAT AppRemover driver ardrv.sys, affected by CVE-2026-36425.
    • Compressed archives delivered Inno Setup executables that used signed Tencent binary F7u00ex.exe to sideload malicious DLL WfoY.qf.
    • PNG-embedded shellcode, timing-based anti-sandbox checks, process injection, services, and scheduled tasks supported execution and persistence.
    • The malware impaired Microsoft Defender, Huorong Internet Security, and Tencent PC Manager; observed C2 included sx.nuihuw.com:443 and nuihuw.top:443.
      πŸ“„ Source: acronis.com Β· πŸ“Ž Coverage: thehackernews.com Β· πŸ‘ via The Hacker News
  • Aurora Affiliate Used AI to Attack More Than 20 Organizations
    A Russian-speaking Aurora ransomware affiliate used Cursor AI during attacks on more than 20 organizations.

    • A Russian-speaking Aurora affiliate targeted more than 20 organizations across nine countries from April through July 2026.
    • Victims spanned manufacturing, food and agriculture, professional services, transport, consumer goods, waste management, and IT infrastructure; at least 17 environments were compromised.
    • An unauthenticated file listing on port 8888 exposed the operator’s Linux home directory, including credentials, Kerberos tickets, AD data, tools, chat logs, and ransomware binaries.
    • The affiliate used Cursor in Russian to plan intrusions and AD escalation, alongside NetExec, noPac, ADCS abuse, PetitPotam, PrinterBug, and DFSCoerce.
    • Aurora’s Zig-based Windows and Linux/ESXi lockers included hashes eb0aab1e892d7e09e2c7bcf1d21fd83c1743ed9196b3efac6c78482fb0d99207 and a4af136d159a8eb96b54924fa80355ca52874913301300f55af7d67ae97edcfe; ransom notes used !!!README!!!DO_NOT_DELETE.txt.
      πŸ“„ Source: cloudsek.com Β· πŸ“Ž Coverage: gbhackers.com Β· πŸ‘ via Cyber Security News, cryptika.com (discovered)

πŸ”“ CVEs & KEV

  • CVE-2026-77533 β€” CVSS 9.9 β€” A malicious actor with access to the network and low privileges could exploit...

  • CVE-2026-75977 β€” CVSS 8.8 β€” Mang Board WP through 2.3.7 - Authenticated (Subscriber+) Privilege Escalation to ...

  • CVE-2026-78236 β€” CVSS 8.8 β€” Insecure PIN derivation mechanism in Admin By Request (ABR)An insecure PIN de...

  • CVE-2026-78237 β€” CVSS 7.8 β€” Insufficient input validation in Admin By Request (ABR)Insufficient input val...

  • CVE-2026-18884 β€” CVSS 7.5 β€” WooCommerce Lottery through 2.2.9 - Unauthenticated Time-Based SQL Injection via '...

  • CVE-2026-9668 β€” CVSS 6.3 β€” SQL injection vulnerability in ZTE SCP productWith legitimate user credential...

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • UPDATE: Two alleged TeamPCP hackers charged in Australia
    Australian authorities have charged two alleged TeamPCP members over global supply-chain attacks.

    • The suspects are two Western Australian men aged 21 and 23, allegedly principal TeamPCP participants.
    • The attacks allegedly compromised more than 1,000 organizations across government, academia and the private sector.
    • The stolen data included more than 500,000 credentials and at least 300 GB of data.
    • TeamPCP allegedly inserted malicious code into open-source software that developers unwittingly distributed through software updates.
    • The group used the Shai-Hulud worm after phishing or stealing developer credentials from repositories including GitHub and NPM.
      πŸ“„ Source: afp.gov.au Β· πŸ“Ž Coverage: krebsonsecurity.com Β· πŸ‘ via Krebs on Security, @campuscodi@mastodon.social (+4)
  • OpenAI Disrupts Cambodian Scam Network Using ChatGPT
    OpenAI disrupted a Cambodian social-engineering network that used ChatGPT to run scams.

    • Online targets were exposed to scams run by a Cambodian criminal network.
    • The group used dating personas to promote fraudulent cryptocurrency and spot-gold investments.
    • Operators also conducted romance scams, fake gambling promotions, and law-enforcement impersonation scams.
    • ChatGPT supported personalized identities and extended conversations across multiple scam schemes.
      πŸ“„ Source: openai.com Β· πŸ“Ž Coverage: schneier.com Β· πŸ‘ via Schneier on Security
  • Kaspersky Reports Q2 2026 Threats Targeting Industrial Control Systems
    Kaspersky documented ransomware, miners, spyware and other threats affecting industrial control systems in Q2 2026.

    • Industrial automation and industrial control system operators are covered.
    • Kaspersky tracked ransomware, cryptocurrency miners, spyware and other threats detected and blocked on ICS environments.
    • The report presents Q2 2026 threat statistics broken down by region and industry.
      πŸ“„ Source: ics-cert.kaspersky.com Β· πŸ“Ž Coverage: securelist.com Β· πŸ‘ via Securelist (Kaspersky)
  • Cisco Talos explains how JavaScript obfuscation powers phishing kits
    Cisco Talos details how obfuscated JavaScript conceals phishing and malware activity.

    • Phishing victims, malware analysts, developers, and users of compromised websites may encounter obfuscated JavaScript.
    • Phishing kits use it to hide credential theft, malware loaders, browser abuse, and fake CAPTCHA or update flows.
    • String arrays, encoded URLs, runtime decoders, and renamed functions conceal the script’s intent.
    • Packed code can reconstruct payloads at runtime and execute them with eval().
      πŸ“Ž Coverage: blog.talosintelligence.com Β· πŸ‘ via Cisco Talos
  • NIST Says Agentic AI Requires a Strong Identity Foundation
    NIST says agentic AI deployments need stronger identity security.

    • Enterprises are deploying AI agents for commerce, customer service, security, and software development.
    • AI agents act as non-human identities while invoking tools, accessing sensitive data, calling APIs, and delegating to sub-agents.
    • 69% of surveyed enterprises have deployed AI agents, while 90% plan to do so within two years.
    • 71% of developers use insecure methods to handle non-human identities such as service accounts and API keys.
    • Agents operate at machine speed, making static IAM policies and standing privileges inadequate for runtime decisions and attribution.
      πŸ“Ž Coverage: nist.gov Β· πŸ‘ via NIST Cybersecurity Insights

πŸ“‹ ADVISORIES

πŸ“‹ ADVISORIES

  • πŸ“„ Source for Critical Veeam ONE Flaw Enables Unauthenticated SMB Authentication Coercion β€” veeam.com

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • polymorphic-phishing-pages β€” SANS ISC

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check