< ciso
brief />
Incidents and Data Breaches Banner

All news in category “Incidents and Data Breaches

3296 articles · page 2 of 165

CISA Adds Critical Oracle WebLogic Flaw to KEV

🔒 CISA has added a maximum-severity vulnerability affecting Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in (CVE-2026-21962, CVSS 10.0) to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. The flaw allows unauthenticated HTTP access to create, modify, or delete critical data and potentially gain full access to affected instances. Oracle released patches in January, but reports from GreyNoise and CloudSEK indicate ongoing exploitation activity. Federal agencies must remediate under BOD 26-04 by August 27, 2026.
read more →

miniOrange SAML plugin under active auth bypass attacks

🔐 Attackers are exploiting two critical authentication bypass flaws in the miniOrange SAML 2.0 Single Sign On WordPress plugin to forge SAML responses and gain administrator access. The plugin, used to integrate WordPress with corporate IdPs like Microsoft Entra ID, Okta, and Google Workspace, improperly accepts the incoming signature algorithm and mishandles OpenSSL verification errors. Fixes were released in July for free and paid editions, but incomplete vendor disclosure left many paid installations unpatched and exposed to exploitation.
read more →

Weedhack malware spread via fake Minecraft clients

🛡️ McAfee Labs found ongoing campaigns distributing the Weedhack malware by impersonating popular Minecraft clients and hosting convincing lookalike sites. The attacks use SEO poisoning, Discord and file-hosting links to redirect victims and deploy multi-stage JAR payloads that collect system data and disable security protections. Threat actors even used an AI site builder to create believable malicious domains that outrank legitimate sources.
read more →

ReliaQuest confirms failed data-theft attempt after breach

🔒 ReliaQuest disclosed that an employee was targeted by a social engineering campaign in which attackers impersonated a security team member and hosted a fake SSO page. The actor obtained temporary, view-only access after the employee entered credentials and approved an MFA push, but device-trust controls prevented further access. ReliaQuest revoked sessions, reset tokens, and found no evidence of application, system, or customer data access.
read more →

Malicious Firefox Add‑Ons Target Crypto Wallets

🔒 Security researchers at Socket uncovered a campaign of linked Firefox add‑ons designed to steal cryptocurrency wallet seed phrases and browser credentials. Dubbed the "Offside Wallet Theft Factory," the operation has been active since at least March 2026 and uses minimal‑permission extensions that switch behavior via a Supabase backend. Some extensions pose as wallets, VPNs, or utilities while others impersonate sports score tools, and attackers remotely toggle malicious pages to harvest recovery phrases and passwords. Out of 77 linked add‑ons, 40 were confirmed to steal data, illustrating how shared code and infrastructure enable rapid weaponization.
read more →

Weekly Recap: AI-Enabled PLC Exploits Rise

🔍 U.S. agencies warn that threat actors are using AI to craft exploit scripts targeting internet-exposed Siemens S7 Series programmable logic controllers (PLCs), posing risks to water, energy, manufacturing, and other critical infrastructure. Attackers leverage public scanning services to locate vulnerable PLCs and deploy AI-generated tools that masquerade as legitimate monitoring software to probe and prepare for disruptive write operations. The advisory stresses this is an active, not theoretical, threat and highlights the need for improved segmentation, monitoring, and remediation.
read more →

Doubloon Dredger abuses Notion to harvest tokens

📄 Sublime's Threat Intelligence team identified a financially motivated actor, tracked as Doubloon Dredger, abusing free Notion accounts and malicious PDFs in July 2026 to harvest authentication tokens. Fake notifications from compromised Notion accounts bypassed DKIM/SPF/DMARC checks and steered victims to intermediary PDFs that redirected to an EvilTokens device-code phishing page. If users entered the provided code on Microsoft's legitimate device-code entry, attackers obtained authorization tokens and could access accounts and inboxes via tools like MailVault.
read more →

Operation QUICSILVER: QUICAgent Targets Myanmar Networks

🛡️ Cybersecurity researchers have uncovered Operation QUICSILVER, a cyber espionage campaign targeting Myanmar's government and IT sectors that uses graduation ceremony invitation lures to deliver a Go-based backdoor named QUICAgent. First seen in April 2026, the multi-stage attack abuses a Windows Shortcut (LNK) and the legitimate ftp.exe binary as a LOLBAS to reconstruct and deploy the payload from hidden files inside a VHD. QUICAgent employs sandbox evasion, fetches a C2 address via Cloudflare Workers, and communicates over QUIC on UDP/443, while maintaining persistence through a Startup LNK.
read more →

Entrepreneurial Façading and Criminal Deception Trends

📰 A recent academic study analyzes court data from Silicon Valley fraud prosecutions between 2000 and 2023 to explain how entrepreneurs use deceptive practices to mislead investors and stakeholders. The authors introduce the concept of façading, describing three escalating forms—surface, reinforced, and deep—that correspond to the gap between expected and actual performance. The paper offers policy and practical recommendations, including enhanced SEC surveillance, whistleblower support, investor due diligence reform, and targeted education to clarify when entrepreneurial behavior becomes criminal deception.
read more →

ToxicPanda Android malware adds VPN and ADB abuse

🛡️ ToxicPanda 2.0 now requests VPN service permissions to create a local interface that can block Google Play and Google Play Services, enabling it to interfere with app verifications, updates, and Play Protect checks. After establishing the VPN, the malware extracts and installs payloads, requests Accessibility Service permissions, and automates Wireless ADB to gain shell-level access. Zimperium reports distribution via AWS-hosted buckets and notes support for 167 remote commands and overlays targeting 349 financial apps across 16 countries.
read more →

Supply-chain malware infects Android car head units

🔍 Kaspersky researchers say a supply-chain attack abused a legitimate DoFun update app to deliver JarService malware to Android-based car head units, attributing the campaign to the MoYu group. The loader retrieves encrypted payloads and exposes nine remote commands used to collect device metadata, run code, open URLs, and perform network checks. Operators primarily install a reverse-proxy module named zhima to convert head units into proxy nodes for ad fraud and monetization, while DoFun says it has remediated the issue.
read more →

Android head-unit malware expands automotive botnets

🔍 In June 2026, researchers discovered malware targeting Android-based car head units that is delivered via an automatic firmware-update service. The attackers exploit DoFun’s TWCore updater to install a hidden dropper called JarService, which downloads a clicker and a proxy module to enroll head units in a botnet. Infected devices are used for ad fraud and to provide residential proxy services, degrading performance and exposing cars to further payloads.
read more →

North Korean Supply Chain Attack Targets Rust Ecosystem

🔒 Wiz researchers linked a recent supply chain attack in the Rust ecosystem to state-sponsored North Korean actors. The campaign compromised maintainer accounts on crates.io to alter manifests and import a typosquatted dependency, allowing malicious build-time code to run during compilation. The backdoor aimed to harvest browser credentials, crypto wallets and developer secrets, affecting widely used crates including arrayref, internment and append-only-vec.
read more →

Agent Tesla v4 uses emoji obfuscation to evade detection

🛡️ KnowBe4 has identified a new Agent Tesla v4 campaign using emoji-based obfuscation and a JScript dropper to bypass detection and steal credentials. The lure leveraged a convincing BEC email spoofing a Philippine bank and instructing finance staff to open an attachment. The dropper embeds Unicode emoji characters to disrupt signature matching, then uses DonutLoader for reflective PE injection so the final binary never touches disk. Researchers advise updating email security and creating YARA rules that combine emoji patterns with JScript function calls to detect the threat.
read more →

Attackers Use FTP Banners to Deliver New Windows RATs

🔍 Threat actors are embedding commands in FTP server banners to deliver two new remote access trojans, E4del and PINHOLE, observed in attacks since July 2026. The campaign begins with a ZIP archive and LNK-based infection chain, likely introduced via phishing, and uses FTP banners as dead-drop resolvers to retrieve PowerShell stagers. SOCRadar discovered the technique and highlights indicators of compromise to help defenders identify affected systems. E4del is a Node.js RAT masquerading as Discord, while PINHOLE uses Pinterest and SurveyMonkey for C2 resilience.
read more →

AI-Generated Exploits Target Siemens PLCs, Risking ICS Safety

🛡️ U.S. agencies warned of an active threat using AI-generated exploit scripts to target Siemens S7 Series PLCs and other industrial controllers, posing risks to Critical Manufacturing, Energy, Water, and related sectors. The campaign leverages internet scanning services to find exposed devices and uses custom Python tools integrating snap7.dll or python-snap7 to mimic legitimate monitoring utilities. Agencies urge patching, network isolation, strong access controls, and enhanced ICS monitoring to mitigate potential disruption, data compromise, and safety incidents.
read more →

Distinct Russian-linked clusters targeting individuals

🛡️ Google Threat Intelligence Group (GTIG) reports three suspected Russian cyber espionage clusters—UNC6293, UNC7005, and UNC5976—targeting academia, aerospace and defense, governments, and think tanks across Europe and the US. These groups abuse legitimate authentication flows, including app passwords, OAuth prompts, and device linking, and use persistent, adaptive phishing with sophisticated social engineering. UNC7005 employs website templates, fingerprinting, analysis-evasion scripts, and malicious JavaScript to record audio/video or deliver further compromise.
read more →

Researchers Demonstrate 'Zombie Card' Revival Attack

🔒 Researchers at UMass Amherst demonstrated the "Zombie Card" attack that can revive expired Visa contactless cards by rewriting the terminal-facing expiration date over NFC, without breaking cryptography. The technique requires proximity or possession of the card and a relay between card and POS; success depends on issuer and EMV kernel. Tests across multiple banks and kernels produced mixed outcomes, and the team presented the work at USENIX Security 2026.
read more →

Kriminal service bypasses AI guardrails at low cost

🛡️ Security researchers warn of a criminal AI service called Kriminal that resells uncensored access to powerful models for as little as $12.99 per month. ThreatDown found the service is a storefront that proxies legitimate providers (including Grok and Claude), uses jailbreak prompts to bypass safety filters, and offers packages for exploit development, OSINT, on-chain tracing, social engineering and code generation. Hosted on mainstream infrastructure and indexed publicly, Kriminal commoditizes advanced offensive capabilities and raises concerns about the widening asymmetry between attackers and defenders.
read more →

CDN Tsunami: HTTP/3-to-HTTP/1.1 Amplification Risk

🔍 Researchers disclosed two denial-of-service techniques, collectively dubbed CDN Tsunami, that exploit how major CDNs translate client-facing HTTP/3 into backend HTTP/1.1 requests, amplifying small attacker traffic to large origin load. The study tested Alibaba, Baidu, Cloudflare, CloudFront, Fastly, and Tencent, finding widespread susceptibility to a bandwidth amplification variant and partial susceptibility to a connection-amplification variant. Vendor mitigations are applied at CDN edges, and the work will be presented at a September 2026 symposium.
read more →