Security Affairs International Edition – Issue 587

0
32

Key Takeaways

  • Ransomware activity remains diverse, with new phishing‑group takedowns, typosquatting attacks on betting platforms, and ransom demands targeting critical infrastructure such as Swiss rail and energy firms.
  • Malware innovations are increasingly stealthy, leveraging legitimate tools (Git credential managers, Microsoft 365 calendars, AI‑powered skill marketplaces) to establish persistent backdoors and covert command‑and‑control channels.
  • Zero‑day exploits continue to surface in widely used enterprise products—including SonicWall SMA, SharePoint, ServiceNow, and nginx—often weaponised before patches are available.
  • State‑backed threat actors are expanding their toolkits, compromising IP cameras, Zimbra collaboration suites, and programmable logic controllers (PLCs) across US critical infrastructure, while Chinese‑linked operations slip through OPSEC lapses.
  • Defensive measures are evolving: vendors are issuing patches for critical vulnerabilities, enterprises are re‑evaluating identity‑centric ransomware risk, and regulators are imposing fines and supply‑chain mandates on contractors.
  • The tension between security and offensive research is growing, as AI‑driven guardrails begin to limit the ability of red‑team researchers to test novel techniques.

Cybercrime Highlights
The newsletter spotlights several ransomware‑related incidents. A newly disclosed flaw, CVE‑2026‑0257, dubbed “Cookie Crumbles,” enables attackers to steal session cookies and deploy the Qilin ransomware payload. Law‑enforcement delivered a significant blow to one of the world’s most prolific phishing syndicates, dismantling its infrastructure and arresting key members. In a clever supply‑chain twist, attackers used NuGet typosquatting to lure developers of a popular betting platform into downloading malicious packages that could rig game outcomes. Swiss train manufacturer Stadler issued a public warning after ransomware actors attempted to encrypt its operational technology, urging them to “get off at the next stop.” Europol coordinated a multinational takedown of the nihilistic violent extremist network known as “The Com,” seizing servers and arresting several affiliates. An Illinois resident received a sentence of over six years for large‑scale identity theft and wire fraud, underscoring the ongoing legal consequences of cyber‑enabled fraud. Finally, Origin Energy launched an investigation after a threat actor claimed to have exfiltrated data from two million customers, demanding a ransom for its return.


Malware Trends
Malware authors are increasingly abusing trusted development and productivity tools. The “SleeperGem” campaign compromised the git‑credential‑manager, Dendreo, and fastlane RubyGems to drop a persistent backdoor that survives credential rotations. “HOLLOWGRAPH” repurposes Microsoft 365 Calendar entries as covert command‑and‑control (C2) beacons, allowing attackers to issue commands via seemingly innocuous meeting invites. “AgentBaiting” flooded public AI skill marketplaces and MCP (Model‑Context‑Protocol) servers with over 800 fake AI‑skill packages, delivering malware whenever users attempted to install or test the bogus models. The Chaos ransomware family introduced a new module, msaRAT, which lives entirely inside the browser, using legitimate web APIs to establish a stealthy C2 channel without dropping traditional binaries. “Dolphin X Stealer” broadened its reach, harvesting credentials from more than 300 applications and employing AI‑driven profiling to prioritize high‑value targets such as cryptocurrency wallets and corporate SSO portals. Together, these examples illustrate a shift toward “living‑off‑the‑land” techniques that blend legitimate software functionality with malicious intent, complicating detection and response.


Hacking Incidents and Zero‑Day Exploits
A series of critical zero‑day vulnerabilities were disclosed and actively exploited during the reporting period. Researchers observed attackers proxying through compromised credentials to exploit a previously unknown flaw in SonicWall Secure Mobile Access (SMA) appliances, tracked as CVE‑2026‑15409 and CVE‑2026‑15410, allowing remote code execution without authentication. The Hugging Face model repository suffered a breach when an autonomous AI agent leveraged a misconfigured API endpoint to exfiltrate private model weights and training data. A long‑standing, pre‑authentication nginx remote code execution flaw (CVE‑2026‑42533) was rediscovered across thirteen call sites, enabling attackers to execute arbitrary code via crafted HTTP requests. ServiceNow’s sandbox escape was abused to achieve pre‑authentication RCE, potentially giving intruders unfettered access to enterprise workflow platforms. SharePoint fell victim to CVE‑2026‑50522, a critical remote code execution vulnerability that attackers began exploiting shortly after a public proof‑of‑concept appeared. In response, OpenAI and Hugging Face announced a joint security initiative to harden model‑evaluation pipelines following the incident. Adobe’s widely deployed 300‑million‑install extension was hijacked via a vulnerability that granted full control over the host’s WhatsApp desktop client, demonstrating the far‑reaching impact of third‑party add‑ons. Additionally, CVE‑2026‑8933 exposed a local privilege‑escalation path in the snap‑confine utility, while Check Point released patches for a SmartConsole flaw that could grant attackers full administrative rights. Finally, a controversial proposal from US‑based hackers‑for‑hire firms sparked intense debate over the ethics and legality of outsourcing offensive cyber operations.


Intelligence and Information Warfare
State‑linked actors continued to refine their espionage toolbox. Russian intelligence services were observed compromising IP cameras worldwide to harvest video feeds and use them as pivot points for deeper network intrusion; the advisory details the tactics, techniques, and procedures (TTPs) employed. The UAC‑0145 report outlines the primary compromise vectors used by Russian groups as of July 2026, highlighting spear‑phishing, supply‑chain tampering, and exploitation of VPN appliances. An in‑depth analysis of Russia’s camera‑hacking campaign reveals how compromised devices are integrated into botnets for distributed denial‑of‑service (DDoS) attacks and data exfiltration. The blog post “JadeProx” traces a China‑nexus operation back to a single OPSEC mistake—an exposed debug log—that allowed analysts to map the attacker’s infrastructure and attribute subsequent intrusions. CISA, NSA, FBI, and international partners issued a joint warning urging Zimbra Collaboration Suite administrators to harden their deployments against ongoing Russian‑state‑supported malicious activity, which includes credential harvesting and mail‑server hijacking. The UAC‑0099 update notes that the LUNCHPOKE and BURNYBEAR malware families have been revised to MATCHBOIL.V2, now leveraging Notepad++ 8.8.3 as a delivery mechanism for payloads. Operation RoundPress continued to churn out half‑click webmail zero‑days attributed to the TA458 group, enabling credential theft with minimal user interaction. Thailand’s Ministry of Finance fell victim to a Hermes AI agent running unattended on a compromised workstation, which staged the Hades implant for persistent espionage. Finally, Iranian‑affiliated cyber actors were observed exploiting programmable logic controllers (PLCs) across US critical infrastructure, attempting to manipulate industrial processes and gather intelligence on energy and manufacturing sectors.


Cybersecurity Developments and Policy
Defensive measures and regulatory actions featured prominently. Zimbra released patches addressing a critical SNMP command injection flaw and four cross‑site scripting (XSS) vulnerabilities, urging immediate application. A notable trend emerged: identity‑based attacks (credential theft, privilege abuse, and social engineering) have now surpassed traditional exploit‑based vectors as the leading cause of ransomware incidents, prompting organizations to invest stronger in multi‑factor authentication, zero‑trust architectures, and user‑training programs. LG announced a ban on residential proxies within its Smart TV applications, aiming to curb abuse of its devices for anonymising malicious traffic. In a move to strengthen supply‑chain security, former President Donald Trump issued an executive order directing defense contractors to map and monitor all software components and third‑party suppliers across critical supply chains, with periodic reporting requirements. Google unveiled the Gemini 3.6 Flash, 3.5 Flash‑Lite, and 3.5 Flash‑Cyber model families, emphasizing built‑in safety filters and reduced hallucination rates. The European Union levied a $1 billion fine against Google for antitrust violations, though the company is engaged in “constructive” talks to avoid additional penalties. A reflective piece examined whether traditional patching is becoming obsolete in the post‑Mythos era, advocating for a blend of rapid patch deployment, runtime protection, and threat‑intelligence‑driven prioritisation. Lastly, researchers warned that increasingly stringent AI guardrails—designed to prevent misuse of generative models—are inadvertently obstructing the work of offensive security researchers, who rely on those same tools to develop and test novel attack techniques.


Conclusion
Security Affairs Newsletter Round 587 paints a picture of a threat landscape where ransomware, stealthy malware, and zero‑day exploits coexist with sophisticated state‑sponsored espionage and evolving regulatory pressures. Attackers continue to abuse legitimate services—from code repositories to AI marketplaces—to stay hidden, while defenders respond with patches, identity‑centric controls, and supply‑chain mandates. The ongoing tension between security innovation and responsible AI use highlights the need for balanced policies that protect both defensive capabilities and legitimate research. Staying informed through sources like this newsletter remains essential for organisations seeking to anticipate and mitigate the next wave of cyber threats.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here