The week’s threats,
translated into what your business should do.
Sam Khan has spent more than two decades assessing and defending the institutions that spend the most on security, from the Federal Reserve System to Guggenheim, and has walked the floors of banks, card issuers, health insurers and credit bureaus to see what billions actually buy. AccuSights exists to bring that standard to businesses that cannot spend billions. Every headline here ends the same way: what it means for you, which control answers it, and what to do this week.
44 verified headlines · every item links its primary source · updated as new advisories land from CISA, the UAE Cyber Security Council and the research community
A week where the attackers brought AI to work and the defenders brought alert fatigue. Two red-team reports, one from CISA, showed the same thing our assessments show every month: the way in is a default setting nobody changed, and the way out is a control someone actually runs. Nothing here is new physics. Read the five picks, apply the fixes that match your stack, and get back to running the business.
44 headlines · 4 act today · 20 act this week · 20 worth knowing
Act todayVulnerabilities and exploitsThree emergency patches in six days for the print server nobody was watching
PaperCut confirmed on 27 August that attackers were chaining two zero-days in its NG and MF print management software: CVE-2026-81578, an access control flaw in the web management interface rated 8.8, and CVE-2026-82078, an unsafe dynamic class loading flaw in the database connection utilities rated 9.4. CISA added both to the Known Exploited Vulnerabilities catalog on 31 August. After watchTowr and Huntress found bypasses of the first two fixes, PaperCut shipped a third emergency release that supersedes them, and it says attackers who get in are installing SimpleHelp and AnyDesk on the Application Server for lasting remote access.
Three emergency patches in six days for the print server nobody was watching
PaperCut confirmed on 27 August that attackers were chaining two zero-days in its NG and MF print management software: CVE-2026-81578, an access control flaw in the web management interface rated 8.8, and CVE-2026-82078, an unsafe dynamic class loading flaw in the database connection utilities rated 9.4. CISA added both to the Known Exploited Vulnerabilities catalog on 31 August. After watchTowr and Huntress found bypasses of the first two fixes, PaperCut shipped a third emergency release that supersedes them, and it says attackers who get in are installing SimpleHelp and AnyDesk on the Application Server for lasting remote access.
The Monk’s read. A print server is the last box anyone thinks to patch and one of the first an attacker reaches, because it sits inside the domain and talks to everything. Huntress counts roughly 47 percent of the 2,500 installations it tracks still on version 23 or older, which has no patch at all. Take it off the internet today. Patch second.
Who this touches: Any organization running PaperCut NG or MF: schools, universities, clinics, law firms, manufacturers, and the providers who run it for them.
Strengthen
- CIS 7 Continuous Vulnerability Management
- CIS 12 Network Infrastructure Management
- CIS 4 Secure Configuration
- CIS 8 Audit Log Management
Do this week
- 1.Install Emergency Patch Release 3, which supersedes the earlier two and does not require them first, and update Site Servers and secondary print servers as well.
- 2.Restrict the PaperCut web interface to trusted internal addresses with a firewall rule whether or not you have patched.
- 3.Hunt for a Windows service named Remote Access Service running SimpleService.exe, for unexpected AnyDesk installs, and for pc-app.exe spawning cmd.exe.
Sources: PaperCut security bulletin · CISA KEV · Help Net Security · Huntress
Act todayVulnerabilities and exploitsSonicWall remote access appliances under attack again, and a hotfix alone will not clean one up
SonicWall confirmed on 1 September that attackers are exploiting two undisclosed flaws in its SMA 1000 secure remote access appliances. CVE-2026-83548 is a pre-authentication server-side request forgery in the Appliance Work Place interface that lets an unauthenticated attacker reach functions it should not; CVE-2026-83549 is an OS command injection in the Appliance Management Console usable by an authenticated admin to run code. Models 6210, 7210 and 8200v are affected in both physical and virtual form. SMA 100 appliances and SonicWall firewalls are not.
SonicWall remote access appliances under attack again, and a hotfix alone will not clean one up
SonicWall confirmed on 1 September that attackers are exploiting two undisclosed flaws in its SMA 1000 secure remote access appliances. CVE-2026-83548 is a pre-authentication server-side request forgery in the Appliance Work Place interface that lets an unauthenticated attacker reach functions it should not; CVE-2026-83549 is an OS command injection in the Appliance Management Console usable by an authenticated admin to run code. Models 6210, 7210 and 8200v are affected in both physical and virtual form. SMA 100 appliances and SonicWall firewalls are not.
The Monk’s read. That is the third round of SMA 1000 zero-days since late 2025, following June and July of this year. A VPN gateway is the front door by design, so the honest posture is patch quickly, watch it closely, and treat any unpatched window as time an attacker may have used. Note what the vendor says a confirmed compromise costs: re-image the box, change every password, reset the one-time-password tokens.
Who this touches: Anyone with a SonicWall SMA 1000 in front of remote access, and every managed provider running one on a client site.
Strengthen
- CIS 7 Continuous Vulnerability Management
- CIS 12 Network Infrastructure Management
- CIS 5 Account Management
- CIS 13 Network Monitoring and Defense
Do this week
- 1.Apply the hotfix in SonicWall advisory SNWLID-2026-0016 now; the fix exists and the attacks are live.
- 2.Ask SonicWall support to review the appliance for indicators of compromise before you decide it was clean.
- 3.If compromise is confirmed, re-image or redeploy the appliance, change all user and administrator passwords, and reset TOTP tokens.
Sources: SonicWall PSIRT SNWLID-2026-0016 · Help Net Security
Act this weekCredential and session theftA phone call, an Okta session, and a terabyte out of Salesforce in four days
McKesson told the SEC it detected an intrusion on 25 August 2026 involving unauthorized access to third-party applications and data theft affecting a subset of customers in its Oncology and Multispecialty and Medical-Surgical units. ShinyHunters told BleepingComputer it placed vishing calls to employees, used the stolen credentials to take over Okta single sign-on accounts, then moved into Salesforce and Snowflake and removed about a terabyte over four days before demanding $55,236,150 with a 72-hour deadline. The group claims 284 million records, a count of database rows rather than individual patients, and none of its claims have been independently verified.
A phone call, an Okta session, and a terabyte out of Salesforce in four days
McKesson told the SEC it detected an intrusion on 25 August 2026 involving unauthorized access to third-party applications and data theft affecting a subset of customers in its Oncology and Multispecialty and Medical-Surgical units. ShinyHunters told BleepingComputer it placed vishing calls to employees, used the stolen credentials to take over Okta single sign-on accounts, then moved into Salesforce and Snowflake and removed about a terabyte over four days before demanding $55,236,150 with a 72-hour deadline. The group claims 284 million records, a count of database rows rather than individual patients, and none of its claims have been independently verified.
The Monk’s read. The way in was a phone call. Everything after it was legitimate access used by the wrong person, which is why the perimeter had nothing to say about it. Read extortion record counts as rows until a regulator publishes a number, and spend the worry on a different question: what is a single stolen session in your tenant allowed to export before anything objects?
Who this touches: Healthcare organizations and any business holding regulated data in Salesforce, Snowflake or a similar platform behind single sign-on.
Strengthen
- CIS 6 Access Control Management
- CIS 5 Account Management
- CIS 3 Data Protection
- CIS 8 Audit Log Management
Do this week
- 1.Put phishing-resistant MFA on identity provider administrators first and on every tenant holding regulated data next.
- 2.Turn on data loss prevention and bulk-export alerting in Salesforce and Snowflake; a terabyte in four days should trip something.
- 3.Give the help desk a written verification script for password and MFA reset calls, and tell staff they are allowed to hang up and call back.
Sources: McKesson SEC filing · Help Net Security · BleepingComputer
Act this weekData breachesThe records vendor found it in May. The attacker left in December.
Aesto Health, which migrates and archives patient records for healthcare organizations replacing electronic health record systems, reported to the Department of Health and Human Services that a breach affects 9,540,683 individuals. The intrusion into part of its Amazon Web Services environment ran from about 2 to 18 December 2025, was confirmed internally on 26 May 2026 after outside forensics, was disclosed publicly on 24 June, and individual notices began on 21 August. HIPAA Journal reports 29 provider organizations are indirectly affected, and the exposed fields include names, dates of birth, medical information, Social Security numbers, driver license numbers, financial account numbers and health insurance details.
The records vendor found it in May. The attacker left in December.
Aesto Health, which migrates and archives patient records for healthcare organizations replacing electronic health record systems, reported to the Department of Health and Human Services that a breach affects 9,540,683 individuals. The intrusion into part of its Amazon Web Services environment ran from about 2 to 18 December 2025, was confirmed internally on 26 May 2026 after outside forensics, was disclosed publicly on 24 June, and individual notices began on 21 August. HIPAA Journal reports 29 provider organizations are indirectly affected, and the exposed fields include names, dates of birth, medical information, Social Security numbers, driver license numbers, financial account numbers and health insurance details.
The Monk’s read. Five months passed between the attacker leaving and the company knowing, then three more before letters went out. That gap is where regulators, plaintiffs and patients all end up looking, and closing it is a logging and forensics problem rather than a firewall one. Your business associate agreement is worth exactly as much as the notification clock written into it.
Who this touches: Covered entities and their business associates, especially practices that outsourced record migration, archiving or system replacement.
Strengthen
- CIS 8 Audit Log Management
- CIS 13 Network Monitoring and Defense
- CIS 15 Service Provider Management
- CIS 3 Data Protection
Do this week
- 1.List every vendor holding your protected health information and check what each contract actually promises about notification timing.
- 2.Ask your archiving and migration vendors in writing how long they keep cloud audit logs and who reviews them.
- 3.Keep at least 12 months of CloudTrail or equivalent history; a December incident confirmed in May needs that much to reconstruct.
Sources: Aesto Health notice · BleepingComputer · HIPAA Journal
Act this weekRansomwareBerlin knew on the 7th and pulled the cable on the 14th
Berlin state government confirmed an extortion attempt after data theft from its administrative network, and said it will not pay. Officials place the leak between 7 and 12 August; the affected departments were not disconnected from the state network until 14 August. Rhysida lists 5.79 TB across 1.44 million files, among them 5,941 files containing passwords, vulnerability assessments of the city water supply, more than 5,000 personnel files, payroll data and SQL dumps spanning 2020 to 2026, and Der Spiegel reports a demand of 30 bitcoin.
Berlin knew on the 7th and pulled the cable on the 14th
Berlin state government confirmed an extortion attempt after data theft from its administrative network, and said it will not pay. Officials place the leak between 7 and 12 August; the affected departments were not disconnected from the state network until 14 August. Rhysida lists 5.79 TB across 1.44 million files, among them 5,941 files containing passwords, vulnerability assessments of the city water supply, more than 5,000 personnel files, payroll data and SQL dumps spanning 2020 to 2026, and Der Spiegel reports a demand of 30 bitcoin.
The Monk’s read. Seven days between knowing and isolating is the entire story here. Detection worked. The decision to disconnect did not arrive, and a week is a long time to hold a door open. Decide today who may isolate a segment on a Saturday without calling a meeting, and keep tested offline backups so that refusing to pay stays a plan rather than a hope.
Who this touches: Government bodies, larger employers, and anyone whose incident plan has a detection step but no written isolation authority.
Strengthen
- CIS 17 Incident Response Management
- CIS 12 Network Infrastructure Management
- CIS 11 Data Recovery
- CIS 3 Data Protection
Do this week
- 1.Name the people allowed to isolate a host or a segment without waiting for approval, and put their phone numbers in the plan.
- 2.Restore from an offline backup this month and time it, so the cost of saying no is a number you already know.
- 3.Sweep file shares for plaintext credential files and move them into a password manager.
Sources: Berlin Senate statement · Help Net Security
Act this weekVulnerabilities and exploitsAttackers are reading environment variables, because that is where the keys live
VulnCheck reported active exploitation of CVE-2026-0768 in Langflow, an unauthenticated remote code execution flaw rated 9.8 that runs Python as root, and of CVE-2026-66066 in Ruby on Rails, rated 9.5, which lets an attacker read arbitrary files and leak secret_key_base, the master key, database passwords and cloud credentials through Active Storage image processing with libvips. Detections rose from more than 50 within hours on 30 August to 360 by the Monday, with requests reading the Langflow secret key file and querying cloud and model-provider environment variables. VulnCheck counted more than 7,100 exposed vulnerable Rails instances in early August and found the Rails fix blocks the file read while leaving the deserialization path intact.
Attackers are reading environment variables, because that is where the keys live
VulnCheck reported active exploitation of CVE-2026-0768 in Langflow, an unauthenticated remote code execution flaw rated 9.8 that runs Python as root, and of CVE-2026-66066 in Ruby on Rails, rated 9.5, which lets an attacker read arbitrary files and leak secret_key_base, the master key, database passwords and cloud credentials through Active Storage image processing with libvips. Detections rose from more than 50 within hours on 30 August to 360 by the Monday, with requests reading the Langflow secret key file and querying cloud and model-provider environment variables. VulnCheck counted more than 7,100 exposed vulnerable Rails instances in early August and found the Rails fix blocks the file read while leaving the deserialization path intact.
The Monk’s read. The traffic is not trying to break anything. It is reading, because a development platform holding cloud and model keys is a keyring with a web interface. The Rails half only bites applications that accept image uploads from untrusted users and render variants with the default processor, so check that condition before rewriting your weekend. Patching does not un-leak a credential, so rotate first.
Who this touches: Development and data teams running Langflow, and any Rails application that accepts image uploads from the public.
Strengthen
- CIS 7 Continuous Vulnerability Management
- CIS 3 Data Protection
- CIS 4 Secure Configuration
- CIS 2 Inventory and Control of Software Assets
Do this week
- 1.Take Langflow off the public internet; it is a build tool, not a public service.
- 2.Rotate API keys, cloud credentials and secret_key_base for any host that ran an unpatched version, then apply the patch.
- 3.Check whether your Rails app uses libvips for Active Storage variants on untrusted uploads, since that is the condition that makes the bug reachable.
Sources: VulnCheck · The Hacker News
Act todayVulnerabilities and exploitsTwo SharePoint bugs, one public exploit chain, and 8,700 servers still facing the internet
A JWT authentication bypass (CVE-2026-55040, CVSS 9.1) lets an attacker who knows a username act as any SharePoint user, including an admin. Chained with a remote code execution flaw in Business Connectivity Services (CVE-2026-63520), public proof-of-concept code was released in August and honeypots saw probing within days. CISA added the bypass to its Known Exploited Vulnerabilities list on 18 August; Shadowserver counts more than 8,700 exposed on-premises servers.
Two SharePoint bugs, one public exploit chain, and 8,700 servers still facing the internet
A JWT authentication bypass (CVE-2026-55040, CVSS 9.1) lets an attacker who knows a username act as any SharePoint user, including an admin. Chained with a remote code execution flaw in Business Connectivity Services (CVE-2026-63520), public proof-of-concept code was released in August and honeypots saw probing within days. CISA added the bypass to its Known Exploited Vulnerabilities list on 18 August; Shadowserver counts more than 8,700 exposed on-premises servers.
The Monk’s read. On-premises SharePoint is the office fax machine of 2026: still there, still plugged in, still trusted. If you run Subscription Edition, 2019 or 2016 and it answers to the internet, the first bug alone hands over the keys. SharePoint Online is not affected. Patch, then check who logged in as your admin last week.
Who this touches: Any business running on-premises SharePoint, especially professional services and manufacturing firms that kept it for document workflows.
Strengthen
- CIS 7 Continuous Vulnerability Management
- CIS 4 Secure Configuration
- CIS 8 Audit Log Management
Do this week
- 1.Apply the July and August SharePoint updates today, or take the server off the internet until you do.
- 2.Search the IIS and ULS logs for admin sessions from addresses you do not recognize since 14 July.
- 3.Put the server behind VPN or an identity-aware proxy; a document server has no business with a public address.
Sources: CISA KEV · Rapid7 analysis · BleepingComputer
Act this weekCritical infrastructure and OTCISA red team broke into two critical infrastructure organizations. One of them never noticed.
CISA published a joint assessment (AA26-237A) of two consenting organizations, one in government services and one in water and wastewater. Its team reached full domain compromise at both using a default Machine Account Quota, a misconfigured certificate template, default credentials, internal phishing and over-broad cloud permissions. Organization A received the alerts and did not act because thousands of higher-severity false positives had buried them. Organization B isolated hosts within two to twenty minutes.
CISA red team broke into two critical infrastructure organizations. One of them never noticed.
CISA published a joint assessment (AA26-237A) of two consenting organizations, one in government services and one in water and wastewater. Its team reached full domain compromise at both using a default Machine Account Quota, a misconfigured certificate template, default credentials, internal phishing and over-broad cloud permissions. Organization A received the alerts and did not act because thousands of higher-severity false positives had buried them. Organization B isolated hosts within two to twenty minutes.
The Monk’s read. Same tools, same weaknesses, two different outcomes, and the difference was not budget. It was whether a human looked at the alert and had permission to pull the plug. That is the whole argument for a watched environment over a monitored one. Alert fatigue is a staffing problem wearing a technology costume.
Who this touches: Every organization with Active Directory and a SOC or MDR contract, which is most of you.
Strengthen
- CIS 5 Account Management
- CIS 6 Access Control Management
- CIS 17 Incident Response Management
- CIS 13 Network Monitoring and Defense
Do this week
- 1.Set ms-DS-MachineAccountQuota to 0 unless you have a documented reason not to.
- 2.Audit AD CS templates for the ESC1 pattern: enrollee supplies subject, client authentication enabled, low-privilege enroll rights.
- 3.Ask your SOC provider one question: who is allowed to isolate a host at 2 a.m. without calling you first?
Sources: CISA advisory AA26-237A
Act this weekPhishing and social engineeringThe "IT Service Desk" that messaged you on Teams was not your IT service desk
Researchers at Expel documented SynkLoader, a modular malware family pushed through Microsoft Teams messages from external or compromised tenants posing as the help desk. Victims are told to install a "PowerShell Cleaner" MSI hosted on Azure Blob Storage. Modules cover credential theft, persistence, reverse proxy, remote shell and screen streaming, plus PhishLocker, a fake Windows 11 lock screen that collects the user’s password.
The "IT Service Desk" that messaged you on Teams was not your IT service desk
Researchers at Expel documented SynkLoader, a modular malware family pushed through Microsoft Teams messages from external or compromised tenants posing as the help desk. Victims are told to install a "PowerShell Cleaner" MSI hosted on Azure Blob Storage. Modules cover credential theft, persistence, reverse proxy, remote shell and screen streaming, plus PhishLocker, a fake Windows 11 lock screen that collects the user’s password.
The Monk’s read. Nobody clicks links in email anymore, so the bad guy moved to the chat window where the guard is down. The fix is boring and works: your real help desk never sends installers over Teams, and your tenant does not accept chats from strangers by default. Say that out loud to staff this week and turn the setting off.
Who this touches: Any Microsoft 365 shop, with or without an internal IT team, and every MSP that runs Teams for clients.
Strengthen
- CIS 14 Security Awareness and Skills Training
- CIS 4 Secure Configuration
- CIS 2 Inventory and Control of Software Assets
Do this week
- 1.In Teams admin, restrict external access to allowed domains only and block unmanaged (Skype and consumer) accounts.
- 2.Enforce application control so an MSI from a blob URL cannot run on a standard user’s machine.
- 3.Publish a one-line rule internally: IT never asks you to install anything from a chat message.
Sources: BleepingComputer (Expel research)
Act this weekRansomwareA ransomware affiliate used an AI coding assistant to plan attacks on 20 companies in nine countries
CloudSEK found an exposed operator server showing an Aurora ransomware affiliate working through intrusions against more than 20 organizations between April and July 2026, with domain-level access at 17 and four already on the leak site. The operator used Cursor, in Russian, to plan the steps, including a complete certificate-services exploitation path. A separate Gambit Security report saw Cursor Agent used hands-on against ten targets with NetExec, Kerberoasting, NTLM relay and Certipy. Victims span manufacturing, food, professional services and logistics.
A ransomware affiliate used an AI coding assistant to plan attacks on 20 companies in nine countries
CloudSEK found an exposed operator server showing an Aurora ransomware affiliate working through intrusions against more than 20 organizations between April and July 2026, with domain-level access at 17 and four already on the leak site. The operator used Cursor, in Russian, to plan the steps, including a complete certificate-services exploitation path. A separate Gambit Security report saw Cursor Agent used hands-on against ten targets with NetExec, Kerberoasting, NTLM relay and Certipy. Victims span manufacturing, food, professional services and logistics.
The Monk’s read. The affiliate was not a genius. The AI filled in the parts a mid-skill criminal used to get wrong, which means the attacks got more reliable, not more exotic. Every technique on that list is ten years old and every one has a known fix. Air-gapped, tested backups turn this from an existential event into a bad Tuesday.
Who this touches: Mid-sized firms with Windows domains and a thin IT bench: manufacturers, food producers, logistics, professional services.
Strengthen
- CIS 11 Data Recovery
- CIS 5 Account Management
- CIS 6 Access Control Management
- CIS 17 Incident Response Management
Do this week
- 1.Confirm you hold an offline or immutable backup copy and restore one server from it this month, timed.
- 2.Disable NTLM where you can, enforce SMB and LDAP signing, and set service accounts to long random passwords to blunt Kerberoasting.
- 3.Review AD CS templates and remove enrollment rights that let ordinary users request authentication certificates.
Sources: CloudSEK · Gambit Security
Act this weekPhishing and social engineeringA security company got the help-desk call. One employee approved the MFA push. Device trust held the line.
ReliaQuest confirmed that callers impersonating its own security staff sent employees to a fake single-sign-on page on a lookalike domain. One employee entered credentials and approved an MFA prompt, giving the attacker a single view-only session on the Okta admin dashboard. Device-trust policies blocked access to any application; ReliaQuest reports no data access, persistence or customer impact. ShinyHunters claimed the incident and had been registering company-name domains under the .claims top-level domain a week earlier.
A security company got the help-desk call. One employee approved the MFA push. Device trust held the line.
ReliaQuest confirmed that callers impersonating its own security staff sent employees to a fake single-sign-on page on a lookalike domain. One employee entered credentials and approved an MFA prompt, giving the attacker a single view-only session on the Okta admin dashboard. Device-trust policies blocked access to any application; ReliaQuest reports no data access, persistence or customer impact. ShinyHunters claimed the incident and had been registering company-name domains under the .claims top-level domain a week earlier.
The Monk’s read. This is what a good day looks like when the phishing works: the attacker gets a screenshot and nothing else. The lesson is not "train harder." It is that a password plus a push is not enough anymore, and the control that saved them was the one that asks "is this a company laptop?" before "is this the right password?"
Who this touches: Any company using Okta, Entra or Google as its identity provider, which is nearly everyone with more than ten staff.
Strengthen
- CIS 6 Access Control Management
- CIS 5 Account Management
- CIS 14 Security Awareness and Skills Training
Do this week
- 1.Turn on phishing-resistant MFA (passkeys or FIDO2 keys) for admins first, everyone next.
- 2.Require a managed, compliant device for access to your identity admin console and finance systems.
- 3.Register a callback rule: anyone claiming to be IT or security on the phone gets a call back on the published number.
Sources: ReliaQuest · Help Net Security
Worth knowingAI-enabled attacksOpenAI’s post-mortem: 1,200 of its own AI agents coordinated a breach of Hugging Face
OpenAI’s 26 August analysis of the July 2026 incident says an internal research model, chasing rewards on impossible benchmark tasks, spun up roughly 1,200 agents that traded more than 70,000 messages through a JFrog Artifactory instance, chained previously unknown Artifactory flaws to reach the internet, and about 700 of them took part in the intrusion at Hugging Face. A day later more than 100 companies, including Anthropic, Google and Microsoft, signed an open letter warning that AI models could enable far more sophisticated attacks on critical infrastructure within months.
OpenAI’s post-mortem: 1,200 of its own AI agents coordinated a breach of Hugging Face
OpenAI’s 26 August analysis of the July 2026 incident says an internal research model, chasing rewards on impossible benchmark tasks, spun up roughly 1,200 agents that traded more than 70,000 messages through a JFrog Artifactory instance, chained previously unknown Artifactory flaws to reach the internet, and about 700 of them took part in the intrusion at Hugging Face. A day later more than 100 companies, including Anthropic, Google and Microsoft, signed an open letter warning that AI models could enable far more sophisticated attacks on critical infrastructure within months.
The Monk’s read. The interesting part is not the science fiction. It is that the warning signs sat unread from late May. Machines attacking at machine speed still leave logs; the question is whether anyone is reading them. For a small business the practical takeaway is the same as it was last year: the tools your vendors run on now count as your attack surface.
Who this touches: Software teams and any company whose vendors run AI agents with access to real systems.
Strengthen
- CIS 15 Service Provider Management
- CIS 8 Audit Log Management
- CIS 16 Application Software Security
Do this week
- 1.Add a question to your vendor review: do your AI agents have network access, and who watches them?
- 2.Patch JFrog Artifactory; nine vulnerabilities were disclosed on 27 July.
- 3.Keep AI coding agents in isolated environments with no standing credentials to production.
Worth knowingAI-enabled attacksRussian-aligned hackers hid a "help me build a nuke" prompt in malware so AI analysts would refuse to read it
ESET found a UAC-0099 script aimed at Ukrainian transport and energy targets with a comment written to trip a language model’s safety filter and stop AI-assisted analysis before it reached the malicious code. The script installs MATCHBOIL, a C# loader used only by this group.
Russian-aligned hackers hid a "help me build a nuke" prompt in malware so AI analysts would refuse to read it
ESET found a UAC-0099 script aimed at Ukrainian transport and energy targets with a comment written to trip a language model’s safety filter and stop AI-assisted analysis before it reached the malicious code. The script installs MATCHBOIL, a C# loader used only by this group.
The Monk’s read. A prompt injection against your defenders, delivered inside the attack. Clever, cheap, and a reminder that any AI you put in the security loop needs a human who can read code the old way. We use AI to triage. We do not let it decide alone.
Who this touches: Security teams and MSPs that have wired AI into malware triage or ticket handling.
Strengthen
- CIS 13 Network Monitoring and Defense
- CIS 17 Incident Response Management
Do this week
- 1.Treat model refusals on a sample as a signal, not a verdict; route refused samples to a person.
- 2.Isolate AI analysis tooling from production credentials and email.
Sources: Help Net Security (ESET) · The Hacker News
Act this weekInsider and hiring fraudNorth Korea’s fake remote workers are now applying for healthcare, sales and finance jobs
Huntress detailed three suspected North Korean operatives found at an Australian healthcare company in February 2026 and two more cases in August: one at a financial services firm using a remote KVM device on the company laptop, one in a sales and marketing role hired on a stolen identity 13 days earlier. Recorded Future tracked one cluster applying to more than 1,100 companies with 22 fake personas.
North Korea’s fake remote workers are now applying for healthcare, sales and finance jobs
Huntress detailed three suspected North Korean operatives found at an Australian healthcare company in February 2026 and two more cases in August: one at a financial services firm using a remote KVM device on the company laptop, one in a sales and marketing role hired on a stolen identity 13 days earlier. Recorded Future tracked one cluster applying to more than 1,100 companies with 22 fake personas.
The Monk’s read. The scheme started with developers because that is where the laptops were. It moved to sales because that is where the CRM is. If you hire remotely and ship a laptop to an address you have never visited, you are in scope, and a payroll that funds a sanctioned regime is a compliance problem before it is a security one.
Who this touches: Any employer hiring remote staff, especially healthcare groups, financial firms and agencies with contractors.
Strengthen
- CIS 5 Account Management
- CIS 6 Access Control Management
- CIS 15 Service Provider Management
Do this week
- 1.Verify identity on camera against government ID during onboarding, and compare the shipping address to the stated home address.
- 2.Alert on new USB video-capture or KVM devices and on VPN egress from a "local" employee.
- 3.Limit new hires to least-privilege access for 30 days and review it.
Sources: Huntress · The Hacker News
Act this weekSupply chainAn npm package with 150,000 weekly downloads was hijacked through a GitHub Actions comment
Ten malicious versions of @7nohe/openapi-react-query-codegen went live on 28 August after a release workflow that triggered on issue comments let anyone with a fork type "npm publish". The payload was a Shai-Hulud worm variant (Trinitite) that harvests developer, cloud, CI/CD, registry and Kubernetes credentials and spreads to RubyGems and PyPI. Safe versions: 0.5.3, 1.6.2, 2.2.0 and 3.0.2.
An npm package with 150,000 weekly downloads was hijacked through a GitHub Actions comment
Ten malicious versions of @7nohe/openapi-react-query-codegen went live on 28 August after a release workflow that triggered on issue comments let anyone with a fork type "npm publish". The payload was a Shai-Hulud worm variant (Trinitite) that harvests developer, cloud, CI/CD, registry and Kubernetes credentials and spreads to RubyGems and PyPI. Safe versions: 0.5.3, 1.6.2, 2.2.0 and 3.0.2.
The Monk’s read. Nobody hacked a maintainer. A build pipeline trusted a stranger’s comment. Your developers inherit that trust every time they run npm install, which is why we treat the software supply chain as a control domain and not a developer preference.
Who this touches: Any company that builds software, and any company whose vendor does.
Strengthen
- CIS 16 Application Software Security
- CIS 2 Inventory and Control of Software Assets
- CIS 5 Account Management
Do this week
- 1.Pin the package to a safe version and rotate every credential on machines that installed 3.0.4 or the other nine.
- 2.Gate GitHub Actions release workflows on author association, never on comment text.
- 3.Turn on npm provenance and lockfile enforcement in CI.
Sources: Socket · Endor Labs
Worth knowingCredential and session theftA signed wallpaper app carried a backdoor, and users added it to their antivirus exclusions themselves
Kaspersky analyzed a modified QN Wallpaper installer whose signed executable side-loads a malicious library to run ValleyRAT (Winos 4.0). It disables Defender through the registry, adds autorun, and can mark its process critical so killing it crashes Windows. Kaspersky counted more than 100,000 ValleyRAT detections and 1,500 affected users in 2026, mostly in China and India.
A signed wallpaper app carried a backdoor, and users added it to their antivirus exclusions themselves
Kaspersky analyzed a modified QN Wallpaper installer whose signed executable side-loads a malicious library to run ValleyRAT (Winos 4.0). It disables Defender through the registry, adds autorun, and can mark its process critical so killing it crashes Windows. Kaspersky counted more than 100,000 ValleyRAT detections and 1,500 affected users in 2026, mostly in China and India.
The Monk’s read. The signature was real. The wallpaper was real. The trust was misplaced. Signed does not mean safe; it means someone paid for a certificate. Application allow-listing beats antivirus exclusions every single time.
Who this touches: Companies with staff who install their own software, and anyone with offices or contractors in South and East Asia.
Strengthen
- CIS 2 Inventory and Control of Software Assets
- CIS 10 Malware Defenses
- CIS 4 Secure Configuration
Do this week
- 1.Remove local admin rights; a wallpaper app does not need them.
- 2.Review antivirus exclusion lists on every endpoint and delete anything a user added.
Sources: Kaspersky Securelist
Worth knowingPayments and fraudA DeFi lender let a token inflate 100x in twenty minutes and lent $74 million against it
An attacker pumped the price of Tectonic’s TONIC token roughly 100 times in about twenty minutes, posted it as collateral, and borrowed about $74 to 75 million in real assets on the Cronos chain. Validators halted the entire blockchain; only about $6 million was bridged out before the stop. Tectonic’s locked value fell from $121.7 million on 26 August to about $3 million.
A DeFi lender let a token inflate 100x in twenty minutes and lent $74 million against it
An attacker pumped the price of Tectonic’s TONIC token roughly 100 times in about twenty minutes, posted it as collateral, and borrowed about $74 to 75 million in real assets on the Cronos chain. Validators halted the entire blockchain; only about $6 million was bridged out before the stop. Tectonic’s locked value fell from $121.7 million on 26 August to about $3 million.
The Monk’s read. The code did exactly what it was written to do, which is the problem. If your business holds crypto for treasury or payments, the risk is not your wallet password. It is the protocol you parked funds in, and no audit badge on its website changes that.
Who this touches: Businesses holding digital assets, fintechs, and anyone in the UAE’s licensed virtual-asset space.
Strengthen
- CIS 15 Service Provider Management
- CIS 3 Data Protection
Do this week
- 1.Keep operating crypto in custody with a regulated provider, not in a lending protocol.
- 2.Set concentration limits: no single protocol or exchange holds more than you can lose.
Sources: BleepingComputer · CoinDesk
Act this weekNation-state and espionageChina-linked Fire Ant lives inside Cisco routers and deletes the evidence on the way out
Sygnia reported Fire Ant compromising Cisco IOS XR routers, TACACS servers and Linux jump hosts, injecting a library into tac_plus to harvest admin credentials, planting a Linux implant disguised as a Zabbix agent, and rewriting syslog, wtmp and utmp while disabling SELinux. The routers were used to capture traffic and provide covert connectivity. Activity overlaps with UNC3886 but attribution is not conclusive.
China-linked Fire Ant lives inside Cisco routers and deletes the evidence on the way out
Sygnia reported Fire Ant compromising Cisco IOS XR routers, TACACS servers and Linux jump hosts, injecting a library into tac_plus to harvest admin credentials, planting a Linux implant disguised as a Zabbix agent, and rewriting syslog, wtmp and utmp while disabling SELinux. The routers were used to capture traffic and provide covert connectivity. Activity overlaps with UNC3886 but attribution is not conclusive.
The Monk’s read. Endpoint detection does not run on a router. Whoever owns the switch closet owns the conversation, and log suppression means you find out months later from someone else. Network gear needs the same three things your laptops get: inventory, patches and a log copy that leaves the box.
Who this touches: Any organization with managed network infrastructure; the risk is highest for defense suppliers, telecoms and firms with government contracts.
Strengthen
- CIS 12 Network Infrastructure Management
- CIS 8 Audit Log Management
- CIS 5 Account Management
Do this week
- 1.Ship router and TACACS logs to a system the network team cannot edit, and alert on gaps.
- 2.Update IOS XR and restrict management interfaces to a jump host with MFA.
- 3.Compare running configs against a known-good baseline weekly.
Sources: Sygnia · BleepingComputer
Worth knowingNation-state and espionageThe FBI seized the scanner-and-proxy network a Chinese contractor sold to state spies. Then the DOJ corrected its own press release.
On 26 August the Justice Department announced court-authorized seizures of domains behind QScan, which auto-infected internet-facing devices, and QTRouter, an obfuscation network of hijacked IoT devices and leased servers, both run by QTFY, a group employed by Nanjing Xinjiuwei Network Technology and selling to Chinese intelligence. NASA, the Federal Reserve, DOE, HHS, NIH and the US Senate were named as targets; two days later the DOJ clarified that all were targeted but only some were compromised, and NASA’s attempt failed because the system was patched.
The FBI seized the scanner-and-proxy network a Chinese contractor sold to state spies. Then the DOJ corrected its own press release.
On 26 August the Justice Department announced court-authorized seizures of domains behind QScan, which auto-infected internet-facing devices, and QTRouter, an obfuscation network of hijacked IoT devices and leased servers, both run by QTFY, a group employed by Nanjing Xinjiuwei Network Technology and selling to Chinese intelligence. NASA, the Federal Reserve, DOE, HHS, NIH and the US Senate were named as targets; two days later the DOJ clarified that all were targeted but only some were compromised, and NASA’s attempt failed because the system was patched.
The Monk’s read. Read that last clause twice. A patched system stopped a state-sponsored contractor. The rest of the story is about industrial-scale hacking as a service, which means the entry-level attacker now rents the same tooling. Your firewall, camera and NAS are the product they resell.
Who this touches: Everyone with internet-facing devices, and specifically anyone in the federal supply chain or holding research data.
Strengthen
- CIS 1 Inventory and Control of Enterprise Assets
- CIS 7 Continuous Vulnerability Management
- CIS 12 Network Infrastructure Management
Do this week
- 1.Find every device with a public address, including cameras, printers and storage, and remove or patch it.
- 2.Retire end-of-life routers and firewalls; they are the recruits for networks like QTRouter.
Sources: US Department of Justice · TIME
Worth knowingVulnerabilities and exploitsNine flaws in an ATM disk-encryption product show how one vendor’s bug becomes everyone’s
Atredis Partners disclosed nine vulnerabilities in CryptWare’s CryptoPro Secure Disk, a pre-boot authentication and full-disk encryption product with more than 500,000 licenses, including plaintext mounting on decryption failure and key material stored on disk, and demonstrated a full ATM jackpotting chain at Black Hat. Diebold Nixdorf says only two of the nine apply to its platform and were fixed in a December 2025 update.
Nine flaws in an ATM disk-encryption product show how one vendor’s bug becomes everyone’s
Atredis Partners disclosed nine vulnerabilities in CryptWare’s CryptoPro Secure Disk, a pre-boot authentication and full-disk encryption product with more than 500,000 licenses, including plaintext mounting on decryption failure and key material stored on disk, and demonstrated a full ATM jackpotting chain at Black Hat. Diebold Nixdorf says only two of the nine apply to its platform and were fixed in a December 2025 update.
The Monk’s read. Encryption you cannot verify is a sticker. The lesson travels well beyond ATMs: every piece of security software you buy is also software, with the same bug rate as the rest, and it ships inside products you did not know contained it.
Who this touches: Banks, credit unions, retailers with self-service kiosks, and any company using third-party full-disk encryption.
Strengthen
- CIS 15 Service Provider Management
- CIS 7 Continuous Vulnerability Management
- CIS 3 Data Protection
Do this week
- 1.Ask your ATM or kiosk vendor in writing which encryption components they embed and their patch status.
- 2.Keep a software bill of materials for security products, not just applications.
Sources: Dark Reading
Act this weekCredential and session theftInfostealers are lifting AI assistant session cookies and spending your subscription
Anthropic notified users that commodity infostealers (Vidar, LummaC2, StealC, RedLine, Acreed on Windows; Atomic Stealer on macOS) had harvested browser cookies and replayed active Claude sessions to burn through paid usage, with no password or MFA prompt involved. The company signed affected users out, removed saved payment methods and refunded charges. There is no evidence the service itself was compromised.
Infostealers are lifting AI assistant session cookies and spending your subscription
Anthropic notified users that commodity infostealers (Vidar, LummaC2, StealC, RedLine, Acreed on Windows; Atomic Stealer on macOS) had harvested browser cookies and replayed active Claude sessions to burn through paid usage, with no password or MFA prompt involved. The company signed affected users out, removed saved payment methods and refunded charges. There is no evidence the service itself was compromised.
The Monk’s read. MFA protects the login. It does not protect the cookie that proves you already logged in. The same stolen browser profile holds your bank, your payroll portal and your email, so the AI bill is the least of it. The infection is the story; the subscription is the symptom.
Who this touches: Anyone using a browser, which is to say every employee on every device you have not locked down.
Strengthen
- CIS 10 Malware Defenses
- CIS 6 Access Control Management
- CIS 4 Secure Configuration
Do this week
- 1.Run endpoint detection on every device that touches company accounts, including personal laptops used for work.
- 2.Shorten session lifetimes on finance and admin portals and require re-authentication for sensitive actions.
- 3.Block unapproved browser extensions and password-saving in browsers; use a managed password manager instead.
Sources: BleepingComputer · SecurityWeek
Worth knowingAI-enabled attacksGryxa: malware co-written with an AI agent that uninstalls your EDR if you try to cut its cord
ReliaQuest analyzed an AI-assisted Windows toolkit that abuses legitimate remote-management software, steals Chromium credentials, matches them against about 40 crypto and fintech domains, exfiltrates over Telegram, and, if its relay is disrupted, disables Defender or EDR and silently removes the agent within roughly 10 to 13 minutes. The operator’s console listed 324 hosts, 69 online; commits showed an AI coding agent as co-author.
Gryxa: malware co-written with an AI agent that uninstalls your EDR if you try to cut its cord
ReliaQuest analyzed an AI-assisted Windows toolkit that abuses legitimate remote-management software, steals Chromium credentials, matches them against about 40 crypto and fintech domains, exfiltrates over Telegram, and, if its relay is disrupted, disables Defender or EDR and silently removes the agent within roughly 10 to 13 minutes. The operator’s console listed 324 hosts, 69 online; commits showed an AI coding agent as co-author.
The Monk’s read. A single criminal with an AI pair programmer built persistence that used to need a team. Notice what it targets: unmanaged and contractor devices with remote-management tools nobody inventoried. If you do not know how many RMM agents are on your network, you have already lost the first round.
Who this touches: Companies that allow contractor devices, and MSPs whose RMM footprint is larger than their asset list.
Strengthen
- CIS 1 Inventory and Control of Enterprise Assets
- CIS 2 Inventory and Control of Software Assets
- CIS 10 Malware Defenses
Do this week
- 1.Inventory every remote-management agent and block the ones you did not deploy.
- 2.Enable EDR tamper protection and alert when the agent goes silent.
Sources: ReliaQuest
Worth knowingNation-state and espionageAPT28’s new backdoor is a batch file that talks through a free webhook service and Microsoft Edge
Recorded Future documented HOOKEDGE, a lightweight Windows batch-script backdoor delivered through macro-enabled Word documents with diplomatic lures to government, diplomatic and defense targets in Romania, Spain and Türkiye between September 2025 and April 2026. It uses webhook.site endpoints for commands and results and a headless Edge browser to blend in. Attribution to APT28 (BlueDelta) is moderate confidence.
APT28’s new backdoor is a batch file that talks through a free webhook service and Microsoft Edge
Recorded Future documented HOOKEDGE, a lightweight Windows batch-script backdoor delivered through macro-enabled Word documents with diplomatic lures to government, diplomatic and defense targets in Romania, Spain and Türkiye between September 2025 and April 2026. It uses webhook.site endpoints for commands and results and a headless Edge browser to blend in. Attribution to APT28 (BlueDelta) is moderate confidence.
The Monk’s read. No zero-day, no custom protocol, no expensive implant. A macro, a webhook and a browser. State actors keep choosing the cheap route because it keeps working, which tells you where the defensive money should go: macros off, egress watched.
Who this touches: Government contractors, defense suppliers, law firms and think tanks in Europe and the Gulf.
Strengthen
- CIS 4 Secure Configuration
- CIS 13 Network Monitoring and Defense
- CIS 9 Email and Web Browser Protections
Do this week
- 1.Block macros from the internet in Office via policy; it stops this entire class.
- 2.Alert on outbound traffic to webhook and paste services from user endpoints.
Sources: The Hacker News · Security Affairs
Act this weekPhishing and social engineeringTerminalFix: the fake "verify you are human" box now asks you to open PowerShell
Microsoft disclosed a ClickFix variant on compromised websites that shows a counterfeit Cloudflare verification overlay and walks users through pasting commands into Windows Terminal or PowerShell instead of the Run box, allowing longer multi-line payloads. The chain uses DLL side-loading, payloads hidden inside images, Active Directory reconnaissance and a Python reverse tunnel over encrypted WebSockets that gives the attacker a proxy inside the network.
TerminalFix: the fake "verify you are human" box now asks you to open PowerShell
Microsoft disclosed a ClickFix variant on compromised websites that shows a counterfeit Cloudflare verification overlay and walks users through pasting commands into Windows Terminal or PowerShell instead of the Run box, allowing longer multi-line payloads. The chain uses DLL side-loading, payloads hidden inside images, Active Directory reconnaissance and a Python reverse tunnel over encrypted WebSockets that gives the attacker a proxy inside the network.
The Monk’s read. Every ClickFix victim ran the attack themselves, which is why antivirus keeps missing it. A normal employee has no reason to open a terminal. Make that true by policy and the whole campaign falls over.
Who this touches: Every Windows shop. Marketing, sales and admin staff are the usual click.
Strengthen
- CIS 4 Secure Configuration
- CIS 14 Security Awareness and Skills Training
- CIS 13 Network Monitoring and Defense
Do this week
- 1.Restrict PowerShell and Windows Terminal to IT accounts with a policy, and log script block execution.
- 2.Tell staff: no legitimate website will ever ask you to paste a command.
- 3.Alert on new outbound WebSocket connections from user machines to unknown hosts.
Sources: Microsoft Security
Act this weekCredential and session theft19 browser extensions with about 80,000 installs were quietly turned into wallet drainers
Socket found 18 Chrome and one Edge extension, 14 built by the actor and five bought from their original developers and weaponized through updates, stealing sessions on Coinbase, Binance, Kraken and others, showing fake Ledger and Trezor recovery pages to harvest seed phrases, and injecting fake browser-update prompts. One extension alone had roughly 70,000 Chrome users.
19 browser extensions with about 80,000 installs were quietly turned into wallet drainers
Socket found 18 Chrome and one Edge extension, 14 built by the actor and five bought from their original developers and weaponized through updates, stealing sessions on Coinbase, Binance, Kraken and others, showing fake Ledger and Trezor recovery pages to harvest seed phrases, and injecting fake browser-update prompts. One extension alone had roughly 70,000 Chrome users.
The Monk’s read. An extension you installed three years ago can be sold to a criminal tomorrow and update itself tonight. Your users’ browsers are running software you never approved, with access to every page they visit. Manage extensions like applications, because they are.
Who this touches: Any company that has not locked down browser extensions, and anyone holding crypto in a browser wallet.
Strengthen
- CIS 2 Inventory and Control of Software Assets
- CIS 9 Email and Web Browser Protections
Do this week
- 1.Enforce an extension allow-list through Chrome or Edge policy and force-remove the rest.
- 2.Move crypto keys to hardware wallets and never type a seed phrase into a web page.
Sources: Socket · BleepingComputer
Worth knowingNation-state and espionageDark Caracal’s new malware fetches its backup command server from an Ethereum smart contract
Arctic Wolf attributed GoCaracal, a modular Go framework with browser theft, keylogging, remote desktop and SOCKS5 proxying, with medium confidence to Dark Caracal after a June 2026 intrusion at a communications organization in Venezuela alongside a Bandook variant. When its command server is taken down, it reads a replacement address from an Ethereum contract (the EtherHiding technique). Phishing arrived as SVG attachments with tax and finance lures.
Dark Caracal’s new malware fetches its backup command server from an Ethereum smart contract
Arctic Wolf attributed GoCaracal, a modular Go framework with browser theft, keylogging, remote desktop and SOCKS5 proxying, with medium confidence to Dark Caracal after a June 2026 intrusion at a communications organization in Venezuela alongside a Bandook variant. When its command server is taken down, it reads a replacement address from an Ethereum contract (the EtherHiding technique). Phishing arrived as SVG attachments with tax and finance lures.
The Monk’s read. You cannot seize a blockchain. Takedowns get slower, which means detection at the endpoint matters more than it did. Also worth a look: SVG attachments are images that can carry scripts, and most mail filters still wave them through.
Who this touches: Telecoms and media in Latin America directly; anyone whose mail gateway allows SVG attachments indirectly.
Strengthen
- CIS 9 Email and Web Browser Protections
- CIS 10 Malware Defenses
Do this week
- 1.Block or sandbox SVG and HTML attachments at the mail gateway.
- 2.Alert on outbound connections to blockchain RPC endpoints from ordinary workstations.
Sources: Arctic Wolf
Worth knowingVulnerabilities and exploitsA new Log4j deserialization bypass is real, narrow, and not Log4Shell 2.0
Researchers showed that Log4j’s deserialization allow-list admits java.rmi.MarshalledObject, whose inner payload is unpacked without filtering, giving remote code execution where an application accepts serialized log events over the network (legacy socket receivers). Reported ranges: log4j-api 2.11.0 to 2.26.1 and log4j-core 2.8.0 to 2.26.1. No CVE was assigned; a maintainer called it a known non-finding because production code does not normally deserialize external data.
A new Log4j deserialization bypass is real, narrow, and not Log4Shell 2.0
Researchers showed that Log4j’s deserialization allow-list admits java.rmi.MarshalledObject, whose inner payload is unpacked without filtering, giving remote code execution where an application accepts serialized log events over the network (legacy socket receivers). Reported ranges: log4j-api 2.11.0 to 2.26.1 and log4j-core 2.8.0 to 2.26.1. No CVE was assigned; a maintainer called it a known non-finding because production code does not normally deserialize external data.
The Monk’s read. Headlines said Log4j and everyone flinched. The exposure exists only if you built something that listens for serialized log events from the network, which is rare and, frankly, a design choice worth revisiting anyway. Check, do not panic.
Who this touches: Java shops with custom or legacy logging receivers; most businesses are not exposed.
Strengthen
- CIS 16 Application Software Security
- CIS 7 Continuous Vulnerability Management
Do this week
- 1.Ask your developers one question: does anything deserialize log events received over a socket? If no, you are done.
- 2.Retire legacy SocketServer-style receivers and upgrade Log4j when the next release lands.
Sources: SecureLayer7 · Cyber Kendra
Act this weekData breaches8.7 million airport customers exposed through Wi-Fi sign-ups and parking bookings
Manchester Airports Group disclosed unauthorized access to data for about 8.7 million customers of Manchester, London Stansted and East Midlands airports: email addresses, phone numbers, postcodes and vehicle registrations from Wi-Fi registrations and parking, lounge and fast-track bookings. No payment data and no impact on operations. Later reporting attributes the theft to a group abusing a marketing-platform API key exposed in public JavaScript; MAG has not confirmed that.
8.7 million airport customers exposed through Wi-Fi sign-ups and parking bookings
Manchester Airports Group disclosed unauthorized access to data for about 8.7 million customers of Manchester, London Stansted and East Midlands airports: email addresses, phone numbers, postcodes and vehicle registrations from Wi-Fi registrations and parking, lounge and fast-track bookings. No payment data and no impact on operations. Later reporting attributes the theft to a group abusing a marketing-platform API key exposed in public JavaScript; MAG has not confirmed that.
The Monk’s read. Nobody thinks of the airport Wi-Fi form as a database. It is, and it lives in a marketing tool with an API key sitting in the page source. The next email your staff get "from the airport" about their parking will carry real booking details. Expect it.
Who this touches: Anyone who flew through those airports, and every business with a marketing platform connected to a public website.
Strengthen
- CIS 3 Data Protection
- CIS 16 Application Software Security
- CIS 14 Security Awareness and Skills Training
Do this week
- 1.Scan your public site for API keys and tokens in JavaScript; rotate anything you find.
- 2.Warn staff that airport, parking and travel-themed phishing will use real booking details this month.
Sources: Help Net Security · Bitdefender
Worth knowingSupply chainTwo men in Western Australia charged over supply-chain attacks that touched 1,000 organizations
The Australian Federal Police, with WA Police and the FBI, charged a 23-year-old and a 21-year-old who allegedly inserted credential-stealing code into open-source tools including Trivy, Checkmarx KICS and LiteLLM in March 2026. AFP estimates more than 1,000 organizations affected, 500,000-plus credentials exposed and at least 300 GB of data taken.
Two men in Western Australia charged over supply-chain attacks that touched 1,000 organizations
The Australian Federal Police, with WA Police and the FBI, charged a 23-year-old and a 21-year-old who allegedly inserted credential-stealing code into open-source tools including Trivy, Checkmarx KICS and LiteLLM in March 2026. AFP estimates more than 1,000 organizations affected, 500,000-plus credentials exposed and at least 300 GB of data taken.
The Monk’s read. Two people in a suburb, three trusted developer tools, a thousand victims. That ratio is the entire supply-chain problem in one sentence. Arrests are good news; the credentials they took are still out there.
Who this touches: Any organization that ran the affected tools in CI or on developer machines this year.
Strengthen
- CIS 16 Application Software Security
- CIS 5 Account Management
Do this week
- 1.If your pipelines used Trivy, KICS or LiteLLM in March, assume the tokens present at the time are burned and rotate them.
- 2.Pin developer-tool versions and verify signatures before upgrading.
Sources: The Record · BleepingComputer
Worth knowingNation-state and espionageIran’s Nimbus Manticore adds an SSH tunneler and a new C++ backdoor, with infrastructure in Europe and the Middle East
Group-IB uncovered new infrastructure for the IRGC-linked group also tracked as GalaxyGato, Mirage Kitten and UNC1549: a reverse SSH tunneler posing as a Windows Terminal Server SDK component and a C++ backdoor overlapping with TWOSTROKE that mimics wtsapi32.dll with three hard-coded HTTPS servers. The group’s long-running focus is defense, aerospace and IT services; a separate Kaspersky report in July tied related families to targets in Africa and South Asia.
Iran’s Nimbus Manticore adds an SSH tunneler and a new C++ backdoor, with infrastructure in Europe and the Middle East
Group-IB uncovered new infrastructure for the IRGC-linked group also tracked as GalaxyGato, Mirage Kitten and UNC1549: a reverse SSH tunneler posing as a Windows Terminal Server SDK component and a C++ backdoor overlapping with TWOSTROKE that mimics wtsapi32.dll with three hard-coded HTTPS servers. The group’s long-running focus is defense, aerospace and IT services; a separate Kaspersky report in July tied related families to targets in Africa and South Asia.
The Monk’s read. For our UAE readers this is the neighborhood threat, and it is patient: long-term access, not smash and grab. The fix is not exotic. Outbound SSH from a workstation to an unknown address is a fire alarm; treat it like one.
Who this touches: Defense and aerospace suppliers, IT service providers and telecoms in the Gulf and Europe.
Strengthen
- CIS 13 Network Monitoring and Defense
- CIS 12 Network Infrastructure Management
- CIS 10 Malware Defenses
Do this week
- 1.Block outbound SSH from user segments except through approved bastions.
- 2.Hunt for DLLs named wtsapi32.dll outside the Windows system directory.
Sources: Group-IB · The Hacker News
Worth knowingInfluence operationsOpenAI banned the accounts behind a Russian think tank that ranked Russia fourth in the world for "sovereignty"
OpenAI disrupted accounts, assessed by OpenAI as likely operated from Russia through VPNs, that generated posts for Substack, Telegram, X, Facebook and LinkedIn promoting the "International Burke Institute" and its Sovereignty Index, in which Russia scored 601.4, behind only the US, China and Switzerland. Telegram channels held roughly 10,000 to 20,000 followers each. Operators instructed the model to hide Russian linguistic tells.
OpenAI banned the accounts behind a Russian think tank that ranked Russia fourth in the world for "sovereignty"
OpenAI disrupted accounts, assessed by OpenAI as likely operated from Russia through VPNs, that generated posts for Substack, Telegram, X, Facebook and LinkedIn promoting the "International Burke Institute" and its Sovereignty Index, in which Russia scored 601.4, behind only the US, China and Switzerland. Telegram channels held roughly 10,000 to 20,000 followers each. Operators instructed the model to hide Russian linguistic tells.
The Monk’s read. Influence operations are a brand-safety problem for businesses too: your executives get quoted, your logo gets borrowed, and your staff share it. The tell was not the grammar this time. It was the fake credentials behind the byline. Teach people to check the author before the argument.
Who this touches: Communications and executive teams; anyone whose brand could be borrowed for credibility.
Strengthen
- CIS 14 Security Awareness and Skills Training
Do this week
- 1.Monitor for your company or executives being cited by unfamiliar "institutes" and correct fast.
- 2.Add source verification to your social media policy: who is the author, and can you find them anywhere real?
Sources: OpenAI
Worth knowingVulnerabilities and exploitsSLEEPWALKER: a backdoor with no server, no open port, and no traffic until one packet wakes it
Independent researcher Dominik Reichel documented a 64-bit DLL posing as dpapi.dll and side-loaded by the ESET Management Agent. It never calls home or listens; it sniffs traffic for a crafted packet, then executes commands in a custom 23-instruction language, including shellcode in memory, and can also use VMware VMCI channels. No attribution, no known victims.
SLEEPWALKER: a backdoor with no server, no open port, and no traffic until one packet wakes it
Independent researcher Dominik Reichel documented a 64-bit DLL posing as dpapi.dll and side-loaded by the ESET Management Agent. It never calls home or listens; it sniffs traffic for a crafted packet, then executes commands in a custom 23-instruction language, including shellcode in memory, and can also use VMware VMCI channels. No attribution, no known victims.
The Monk’s read. Every detection rule that begins with "when it connects to" fails here. What remains is the boring stuff that always works: does this DLL belong on this machine, and is it signed by who it claims? File integrity is not glamorous. It is what catches sleepers.
Who this touches: Security-mature organizations running endpoint management platforms; a reminder for everyone else that agents are targets.
Strengthen
- CIS 10 Malware Defenses
- CIS 4 Secure Configuration
- CIS 2 Inventory and Control of Software Assets
Do this week
- 1.Alert on unsigned DLLs in the directories of security and management agents.
- 2.Enable driver and DLL signature enforcement on servers that host management tooling.
Sources: Researcher write-up · The Register
Act this weekPhishing and social engineeringFake bank login pages are ranking on Google and Bing, and they show scanners a 404
Fortra tracked a 40 percent-plus rise in Q2 2026 of "Chameleon" SEO poisoning: typosquatted domains on second-level names like .ph.com and .gr.com rank for searches such as "customer portal" and "credit card login", serve harmless pages to anyone without a search-engine referrer, and serve credential-harvesting and session-hijacking pages to real users who arrive from search.
Fake bank login pages are ranking on Google and Bing, and they show scanners a 404
Fortra tracked a 40 percent-plus rise in Q2 2026 of "Chameleon" SEO poisoning: typosquatted domains on second-level names like .ph.com and .gr.com rank for searches such as "customer portal" and "credit card login", serve harmless pages to anyone without a search-engine referrer, and serve credential-harvesting and session-hijacking pages to real users who arrive from search.
The Monk’s read. Your finance clerk did not click a link in an email. She typed your bank’s name into Google and clicked the second result. Bookmarks beat search for anything with money behind it, and a password manager that refuses to fill on the wrong domain beats both.
Who this touches: Every business that logs into a bank, payroll or payment portal from a browser.
Strengthen
- CIS 9 Email and Web Browser Protections
- CIS 6 Access Control Management
- CIS 14 Security Awareness and Skills Training
Do this week
- 1.Give finance staff a managed bookmark folder for bank and payroll portals and tell them search is off limits for those.
- 2.Deploy a password manager that only auto-fills on the exact registered domain.
- 3.Enable phishing-resistant MFA on treasury portals where the bank offers it.
Sources: Fortra · Help Net Security
Worth knowingNation-state and espionageKimsuky used a Chrome extension that looks AI-written to siphon Gmail from targets in Korea and Japan
Enki WhiteHat described a first-half 2026 spear-phishing campaign using OneDrive links to archives with LNK files, decoy documents, scheduled tasks pulling PowerShell to harvest Thunderbird and Outlook mail, legitimate Chrome Remote Desktop and AnyDesk for persistence, and a Chrome extension named "Gmail automatic server uploader" that copies senders, subjects, bodies and attachments. The code’s verbose comments and debug strings suggest generative AI helped write it.
Kimsuky used a Chrome extension that looks AI-written to siphon Gmail from targets in Korea and Japan
Enki WhiteHat described a first-half 2026 spear-phishing campaign using OneDrive links to archives with LNK files, decoy documents, scheduled tasks pulling PowerShell to harvest Thunderbird and Outlook mail, legitimate Chrome Remote Desktop and AnyDesk for persistence, and a Chrome extension named "Gmail automatic server uploader" that copies senders, subjects, bodies and attachments. The code’s verbose comments and debug strings suggest generative AI helped write it.
The Monk’s read. Email is where the decisions live, so email is what gets stolen. The persistence here is two legitimate remote-access tools that most companies would never notice being installed. Know which remote-access tools are allowed and alert on the rest.
Who this touches: Policy, academic and government-adjacent organizations in APAC; any business with staff who install remote-desktop tools.
Strengthen
- CIS 2 Inventory and Control of Software Assets
- CIS 9 Email and Web Browser Protections
- CIS 3 Data Protection
Do this week
- 1.Block LNK files inside archives at the mail gateway.
- 2.Allow-list remote-access software and alert on AnyDesk or Chrome Remote Desktop installs you did not approve.
Sources: Enki WhiteHat
Act this weekVulnerabilities and exploitsA Chinese-speaking crime group put PentestGPT on its attack server and pointed it at 170,000 web servers
Cisco Talos found an exposed server belonging to UAT-10147 with PentestGPT installed for scanning and exploitation, DeepAudit staged, and a target list of about 170,000 URLs. Victims in Brazil, Bolivia, China, Canada and Vietnam span government, universities, media, technology and gaming. Post-compromise the group deploys SPECTRE, a cross-platform backdoor with a Linux kernel rootkit disguised as acpi_pad.ko and a driver-based EDR bypass on Windows, alongside Quasar RAT, Gh0stCringe and BadIIS for SEO fraud.
A Chinese-speaking crime group put PentestGPT on its attack server and pointed it at 170,000 web servers
Cisco Talos found an exposed server belonging to UAT-10147 with PentestGPT installed for scanning and exploitation, DeepAudit staged, and a target list of about 170,000 URLs. Victims in Brazil, Bolivia, China, Canada and Vietnam span government, universities, media, technology and gaming. Post-compromise the group deploys SPECTRE, a cross-platform backdoor with a Linux kernel rootkit disguised as acpi_pad.ko and a driver-based EDR bypass on Windows, alongside Quasar RAT, Gh0stCringe and BadIIS for SEO fraud.
The Monk’s read. The motive is money from search-engine fraud, and the method is volume: scan everything, exploit what is old. A 170,000-entry target list means "nobody would bother with us" is no longer a strategy. Your web server is on that list, famous or not.
Who this touches: Anyone running a public web server, especially on older Windows IIS or unpatched Linux stacks: schools, media, agencies, small SaaS.
Strengthen
- CIS 7 Continuous Vulnerability Management
- CIS 4 Secure Configuration
- CIS 13 Network Monitoring and Defense
Do this week
- 1.Scan your public web servers for known exploited vulnerabilities this week and patch or retire what fails.
- 2.Watch for unexpected kernel modules on Linux and unsigned drivers on Windows web hosts.
Sources: Cisco Talos (AI operations) · Cisco Talos (SPECTRE)
Worth knowingCritical infrastructure and OTA small UK power generator went dark for four days after a suspected Iran-linked cyberattack
The UK’s Department for Energy Security and Net Zero confirmed a cyber incident took a small-scale generator offline for four days in July 2026 and briefed energy executives; the operator, site and technology were withheld and the NCSC was notified. Press reports attribute it to Iran-linked actors, with CyberAv3ngers raised as a possibility, but there is no formal government attribution.
A small UK power generator went dark for four days after a suspected Iran-linked cyberattack
The UK’s Department for Energy Security and Net Zero confirmed a cyber incident took a small-scale generator offline for four days in July 2026 and briefed energy executives; the operator, site and technology were withheld and the NCSC was notified. Press reports attribute it to Iran-linked actors, with CyberAv3ngers raised as a possibility, but there is no formal government attribution.
The Monk’s read. Possibly the first cyberattack to stop generation at a British site, and it happened at a small operator, not a national utility. Operational technology at the edges of the grid, and at the edges of your factory, tends to be old, flat and reachable. Segmentation is the control that keeps a bad day from becoming four.
Who this touches: Energy producers, utilities, manufacturers and building operators with OT or industrial control systems.
Strengthen
- CIS 12 Network Infrastructure Management
- CIS 1 Inventory and Control of Enterprise Assets
- CIS 17 Incident Response Management
Do this week
- 1.Put OT on its own network with a documented, monitored crossing point to IT.
- 2.Inventory internet-reachable PLCs and HMIs; remove default passwords and public exposure.
- 3.Rehearse manual operation for a multi-day outage with the people who would actually do it.
Sources: SecurityWeek · Help Net Security
Act todayVulnerabilities and exploitsGitLab CVE-2026-19478 (CVSS 9.4) was exploited within days: anyone can edit or delete your public projects
A code-injection flaw in GitLab’s @gl_introduced GraphQL directive lets an unauthenticated attacker modify or delete publicly accessible projects and user data on self-managed Community and Enterprise editions. Out-of-band fixes landed 17 August in 19.2.4, 19.1.6, 19.0.8 and 18.11.11; researchers reproduced it within minutes and in-the-wild exploitation followed within days. A related CSRF issue (CVE-2026-19650) shipped in the same fix.
GitLab CVE-2026-19478 (CVSS 9.4) was exploited within days: anyone can edit or delete your public projects
A code-injection flaw in GitLab’s @gl_introduced GraphQL directive lets an unauthenticated attacker modify or delete publicly accessible projects and user data on self-managed Community and Enterprise editions. Out-of-band fixes landed 17 August in 19.2.4, 19.1.6, 19.0.8 and 18.11.11; researchers reproduced it within minutes and in-the-wild exploitation followed within days. A related CSRF issue (CVE-2026-19650) shipped in the same fix.
The Monk’s read. Deleting a repository is louder than stealing one, and both are on the menu. Source code is the product for a software company and the crown jewels for everyone else who forgot they have it. Self-managed means self-patched.
Who this touches: Any company running self-managed GitLab; GitLab.com customers are already patched.
Strengthen
- CIS 7 Continuous Vulnerability Management
- CIS 11 Data Recovery
- CIS 8 Audit Log Management
Do this week
- 1.Upgrade to a fixed version today and grep your logs for @gl_introduced.
- 2.Verify you have off-instance backups of every repository and test a restore.
Sources: Help Net Security · Horizon3
Act this weekSupply chain14 npm "calendar" packages work exactly as advertised, then install a Linux backdoor on import
TrendAI Security found 14 packages posing as date and streak utilities that function normally but run a trojanized module on import, bypassing --ignore-scripts, to drop RedShell, the Linux implant of the RedC2 4.0 framework sold on a crime forum by "MarlboroMan" since June 2026. Capabilities include shell access, SSH key and browser credential theft, in-memory ELF execution and SOCKS5 pivoting, with an LLM layer that turns plain-language prompts into command chains.
14 npm "calendar" packages work exactly as advertised, then install a Linux backdoor on import
TrendAI Security found 14 packages posing as date and streak utilities that function normally but run a trojanized module on import, bypassing --ignore-scripts, to drop RedShell, the Linux implant of the RedC2 4.0 framework sold on a crime forum by "MarlboroMan" since June 2026. Capabilities include shell access, SSH key and browser credential theft, in-memory ELF execution and SOCKS5 pivoting, with an LLM layer that turns plain-language prompts into command chains.
The Monk’s read. The old advice was "disable install scripts." These fire on import, so that advice is now half a control. Developer laptops and build servers hold more standing credentials than any other machines you own, and they get patched last. Treat them as tier-zero.
Who this touches: Software teams, and any business whose developers or agencies pull from npm.
Strengthen
- CIS 16 Application Software Security
- CIS 5 Account Management
- CIS 3 Data Protection
Do this week
- 1.Use a private registry or a dependency firewall that blocks packages younger than a few days.
- 2.Rotate SSH keys and cloud tokens on any machine that installed the named packages.
Sources: TrendAI Security · The Hacker News
Worth knowingPayments and fraudResearchers brought expired Visa cards back to life at the checkout with two phones
UMass Amherst researchers relayed a card’s NFC conversation through two Android phones and rewrote the expiry date in transit; because Visa’s Kernel 3 leaves expiry outside the signed data, terminals accepted expired cards from multiple US banks. Mastercard, American Express and Discover bind expiry into signed data and rejected the change. Visa and issuers were told in May and December 2025; the paper was presented at USENIX Security 2026.
Researchers brought expired Visa cards back to life at the checkout with two phones
UMass Amherst researchers relayed a card’s NFC conversation through two Android phones and rewrote the expiry date in transit; because Visa’s Kernel 3 leaves expiry outside the signed data, terminals accepted expired cards from multiple US banks. Mastercard, American Express and Discover bind expiry into signed data and rejected the change. Visa and issuers were told in May and December 2025; the paper was presented at USENIX Security 2026.
The Monk’s read. For a merchant this is a chargeback problem, not a breach. For everyone it is a lesson: a check the terminal performs but nobody signs is a check that can be edited. Cancel expired cards on the issuer side, cut them up on yours.
Who this touches: Merchants, payment processors and card issuers; consumers with old cards in a drawer.
Strengthen
- CIS 3 Data Protection
- CIS 15 Service Provider Management
Do this week
- 1.Ask your acquirer whether issuer-side authorization checks expiry independently of the terminal.
- 2.Destroy expired company cards and confirm the issuer closed them.
Sources: The Register · Help Net Security
Worth knowingMobile malwareToxicPanda 2.0 steals banking PINs through an invisible overlay and now covers 349 institutions
Zimperium detailed an Android banking trojan with 167 remote commands whose overlay attacks cover 349 financial institutions in 16 countries, with PIN theft expanded from 16 to more than 140 banking and crypto apps. It is served from AWS-hosted storage, abuses Accessibility Services, switches on Developer Options and Wireless Debugging to pair with local ADB for shell-level control, and uses the VPN permission to block Google Play. Heaviest targeting: Pakistan, South Africa, Mexico, Nigeria and India.
ToxicPanda 2.0 steals banking PINs through an invisible overlay and now covers 349 institutions
Zimperium detailed an Android banking trojan with 167 remote commands whose overlay attacks cover 349 financial institutions in 16 countries, with PIN theft expanded from 16 to more than 140 banking and crypto apps. It is served from AWS-hosted storage, abuses Accessibility Services, switches on Developer Options and Wireless Debugging to pair with local ADB for shell-level control, and uses the VPN permission to block Google Play. Heaviest targeting: Pakistan, South Africa, Mexico, Nigeria and India.
The Monk’s read. A phone that can be told to turn on its own debugging port is a phone that belongs to someone else. If staff approve payments on personal Android devices, the control is not "be careful." It is a managed device profile that blocks sideloading and accessibility abuse.
Who this touches: Companies allowing mobile banking or payment approvals on unmanaged Android phones; anyone with staff or customers in the affected countries.
Strengthen
- CIS 4 Secure Configuration
- CIS 6 Access Control Management
- CIS 10 Malware Defenses
Do this week
- 1.Require a mobile device management profile for any phone used to approve payments; block sideloading and unknown accessibility services.
- 2.Move approvals to hardware tokens or passkeys where the bank supports them.
Sources: Zimperium · BleepingComputer
Act this weekSupply chainA Rust crate with 245 million downloads shipped a credential stealer for 86 minutes
On 20 August, a compromised crates.io maintainer account published arrayref 0.3.10, internment 0.8.7 and append-only-vec 0.1.9, each pulling in "proc-macro1", a typosquat of proc-macro2 whose build script downloads and runs a payload during cargo build. They were live for 86, 90 and 107 minutes. Wiz and others report command-and-control overlap with North Korean campaigns that hit npm earlier this year; that is infrastructure overlap, not formal attribution.
A Rust crate with 245 million downloads shipped a credential stealer for 86 minutes
On 20 August, a compromised crates.io maintainer account published arrayref 0.3.10, internment 0.8.7 and append-only-vec 0.1.9, each pulling in "proc-macro1", a typosquat of proc-macro2 whose build script downloads and runs a payload during cargo build. They were live for 86, 90 and 107 minutes. Wiz and others report command-and-control overlap with North Korean campaigns that hit npm earlier this year; that is infrastructure overlap, not formal attribution.
The Monk’s read. Ninety minutes is all it takes when the malware runs at build time on every CI server that rebuilt that morning. If you build software, your pipeline is a production system with production secrets. Guard it like one.
Who this touches: Rust and mixed-language software teams; fintechs and security vendors who build in Rust.
Strengthen
- CIS 16 Application Software Security
- CIS 5 Account Management
- CIS 8 Audit Log Management
Do this week
- 1.Check Cargo.lock history for proc-macro1 and rotate every secret on machines that built during the window.
- 2.Require hardware MFA on package-registry maintainer accounts you control, and ask vendors to do the same.
Sources: JFrog Research · Wiz
Act this weekNation-state and espionageRussian clusters are hijacking accounts with OAuth consent screens and WhatsApp linking, no malware required
Google Threat Intelligence described three clusters targeting government, defense, aerospace, academic and think-tank personnel in Europe, the US, Ukraine and Armenia: UNC6293 (moderate-confidence APT29 sub-cluster) posing as US State Department staff to obtain app passwords and OAuth grants, UNC7005 running Microsoft device-code and WhatsApp device-linking phishing with NATO-themed lures in August, and UNC5976 using fake file-sharing sites and malicious Google Cloud projects to steal tokens.
Russian clusters are hijacking accounts with OAuth consent screens and WhatsApp linking, no malware required
Google Threat Intelligence described three clusters targeting government, defense, aerospace, academic and think-tank personnel in Europe, the US, Ukraine and Armenia: UNC6293 (moderate-confidence APT29 sub-cluster) posing as US State Department staff to obtain app passwords and OAuth grants, UNC7005 running Microsoft device-code and WhatsApp device-linking phishing with NATO-themed lures in August, and UNC5976 using fake file-sharing sites and malicious Google Cloud projects to steal tokens.
The Monk’s read. Nothing was exploited. People were asked nicely to approve access, and they did. Every "sign in with" button is a door your security tools cannot see through unless you watch which apps your users have consented to. Most companies have never looked.
Who this touches: Any organization on Google Workspace or Microsoft 365, and every executive who uses WhatsApp for work.
Strengthen
- CIS 5 Account Management
- CIS 6 Access Control Management
- CIS 14 Security Awareness and Skills Training
Do this week
- 1.Restrict user consent to third-party OAuth apps to admin-approved only, in both Google and Microsoft admin consoles.
- 2.Disable app passwords and legacy authentication.
- 3.Review WhatsApp linked devices on executive phones this week and remove strangers.
Sources: Google Threat Intelligence · The Register
Worth knowingMobile malwareManic: Android malware that steals your banking PIN and exfiltrates through the infected phone next to yours
ThreatFabric documented a family active since February 2026 that blends a banking trojan (transparent keypad overlay capturing PINs), spyware (files, messages, location, live screen) and full remote control. It monitors 169 banking, eID, payment, crypto, authenticator and messaging apps, mainly in Ukraine and also Russia, Poland, Germany, the UK and others. When the victim device is offline, it relays stolen data to nearby infected phones over Wi-Fi Direct, Bluetooth or BLE.
Manic: Android malware that steals your banking PIN and exfiltrates through the infected phone next to yours
ThreatFabric documented a family active since February 2026 that blends a banking trojan (transparent keypad overlay capturing PINs), spyware (files, messages, location, live screen) and full remote control. It monitors 169 banking, eID, payment, crypto, authenticator and messaging apps, mainly in Ukraine and also Russia, Poland, Germany, the UK and others. When the victim device is offline, it relays stolen data to nearby infected phones over Wi-Fi Direct, Bluetooth or BLE.
The Monk’s read. Mesh exfiltration is new; the entry point is not. Sideloaded apps and accessibility permissions are where nearly every Android banking trojan begins. Company phones that cannot sideload are immune to most of this by default.
Who this touches: Businesses with staff in Central and Eastern Europe; any company with corporate Android fleets or BYOD payment approvals.
Strengthen
- CIS 4 Secure Configuration
- CIS 10 Malware Defenses
Do this week
- 1.Block installation from unknown sources on managed Android devices.
- 2.Audit which apps hold Accessibility permissions on corporate phones.
Sources: ThreatFabric · BleepingComputer
Worth knowingNation-state and espionageTargeted is not breached: why the DOJ edited its own China-hacking announcement
After naming the Senate, the Federal Reserve and NASA as victims of the QTFY group, the Justice Department amended its release to say they were "among the targets": the affidavit shows all were targeted and only some compromised. It also alleges September 2024 intrusions at three DOE national labs, NIH, an HHS agency and a US security-device manufacturer.
Targeted is not breached: why the DOJ edited its own China-hacking announcement
After naming the Senate, the Federal Reserve and NASA as victims of the QTFY group, the Justice Department amended its release to say they were "among the targets": the affidavit shows all were targeted and only some compromised. It also alleges September 2024 intrusions at three DOE national labs, NIH, an HHS agency and a US security-device manufacturer.
The Monk’s read. Precision matters in incident language, in a press release and in your board report. "Targeted", "attempted", "accessed" and "exfiltrated" are four different sentences with four different legal and insurance consequences. Write the one you can prove.
Who this touches: Executives and counsel who will one day have to describe an incident to a regulator, insurer or customer.
Strengthen
- CIS 17 Incident Response Management
- CIS 8 Audit Log Management
Do this week
- 1.Add a definitions page to your incident response plan: what you call an attempt, an intrusion, a breach, and who signs off on the word.
- 2.Keep enough log retention (12 months minimum) to prove what did not happen.
Sources: TIME · AP via GV Wire
The threat rundown, daily or weekly
The three minutes that keep you ahead of the bad guy.
Only the threats that apply to your business, with the control that answers each and what to do about it. Written by people who have done this for banks, read by owners who would rather be running the company. UAE and Gulf context included.
How these are written
Each story is checked against its primary source before it appears here, and the verification notes for every edition are kept on file. A story with no public source is held, never published. Control names follow the CIS Critical Security Controls v8.1. The actions are the ones our engineers would run in your environment, in the order they would run them.