Tue, 28 Jul 2026 02:10:37 +0000
- New Dysphoria DDoS botnet spreads to 200k devices worldwide [net] [mal]
The Dysphoria botnet, infecting around 200,000 devices globally via weak credentials and vulnerabilities, employs advanced covert blockchain-based C2 mechanisms to conduct large-scale DDoS attacks or proxy traffic, with mitigation focusing on device security hardening.
- OnTrac parcel delivery company reports customer data breach [net]
OnTrac experienced a cyberattack exposing potential customer data, prompting security measures, a third-party investigation, and offering credit monitoring.
- Botnets powered by residential proxy networks are growing [net]
Botnets leveraging residential proxies are rapidly expanding and resilient, with millions of victims worldwide, posing significant detection and mitigation challenges.
- Microsoft's solution to AI security: more AI and more acronyms [app]
Microsoft's agentic security approach, combining specialized vulnerability detection with AI models like MAI-Cyber-1-Flash and GPT-5.4, enhances defense against AI-driven attacks while reducing costs, supported by expanded research initiatives and university collaborations.
- Aftercall ads are driving Android users crazy [app] [mal]
Aftercall is a deceptive Google Play campaign where Android apps disguise as everyday tools to display intrusive full-screen ads after calls, often monitoring call states; users should check overlay permissions and use security tools to stay safe.
- MedusaHVNC Trojan Creates Hidden Desktops to Hijack Browsers and Steal Data [net] [rev] [sys] [mal]
MedusaHVNC is a malware-as-a-service RAT leveraging Windows HVNC to covertly access logged-in sessions, employing obfuscation, in-memory injection, layered encryption, and legitimate Windows APIs for stealthy control and data exfiltration, with detection focusing on blocking C2 infrastructure and monitoring outbound traffic.
- 'Confused Deputy' Flaws Persist in Google Cloud, Microsoft Azure [cloud]
Researcher Justin O’Leary identified “confused deputy” vulnerabilities in Microsoft Azure and Google Cloud that allow privilege escalation via trust chain abuse, highlighting systemic cloud security weaknesses and recommending mitigations like credential scoping.
- FBI: Breaking Affiliate Trust Sped Along LockBit's Takedown
Operation Cronos in February 2024 successfully dismantled LockBit’s infrastructure, significantly reducing its activity and reputation, and highlighting the importance of targeting ransomware ecosystems and trust.
- NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework
NVIDIA and 36 partners formed the Open Secure AI Alliance to develop open security tools like NVIDIA-labs OO Agents (NOOA) for enhancing AI safety, emphasizing layered defenses and infrastructure containment.
- Adversaries Don't Need a Zero-Day — They Read Your Rulebook
Autonomous penetration testing confidence declines as adversaries exploit governance rules through 'cap weaponization,' emphasizing the need for cross-layer enforcement, hardware hardening, and rule review to prevent rule manipulation-driven failures.
Tue, 28 Jul 2026 02:09:59 +0000
- Azure VM Command Execution using Third-Party Extensions [Salt Minion [cloud]]
Attackers exploiting `Microsoft.Compute/virtualMachines/extensions/write` can deploy malicious Salt Minion extensions to execute arbitrary commands, emphasizing the need for strict role-based access, activity log monitoring, and process auditing to detect and prevent such abuse.
- Online-Enabled Intelligence Recruitment: The Digitization of Traditional Agent Development and Espionage Tradecraft [social]
Foreign intelligence agencies are increasingly recruiting online through professional networks and social media, using covert, scalable methods that blend espionage with legitimate activities, necessitating enhanced organizational vigilance across counterintelligence and cybersecurity domains.
- Pollard's P-1 Factoring Algorithm in Plain C [crypto]
Pollard’s p-1 algorithm factors composites by exploiting small prime factors of p-1, using a stage-1 exponent S (LCM of small integers) and a two-stage approach to improve success on larger prime factors.
- Exploiting Volvo/Eicher’s fleet management platform to gain control over all users and vehicles [app] [net]
VECV’s “My Eicher” fleet management platform had unauthenticated internal APIs that allowed attackers to enumerate users, retrieve OTPs, and potentially take over accounts, exposing sensitive fleet and personal data until the issue was fixed in November 2025.
- From Virtual Share to Physical Shell: Leveraging Windows’ Inconsistent Access Control for LPE [exp] [sys]
A chain of Windows kernel driver vulnerabilities in storvsp.sys allows low-privilege users to escalate to SYSTEM by bypassing access controls via flawed file handle operations and IOCTLs, enabling malicious DLL deployment and privilege escalation, which was mitigated in December 2025 patches.
- Random Windows Things Part 2: Unexpected Clipboard Data Behavior – Winsider Seminars & Solutions Inc. [app]
In Hyper-V’s Enhanced Session mode, clipboard change notifications can allow processes inside VMs to access host or other VM clipboard data, raising concerns about unexpected data sharing and prompting further investigation into whether this behavior is intentional, a bug, or undocumented.
- GitHub [minelife123/SysCore: High-Performance Modern C++20 Windows & Linux System Engineering Framework [for] [sys]]
SysCore is an extensible C++20 Windows diagnostics tool with GUI, process monitoring, system inspection, scripting, and multi-language support.
- GitHub [Bulls729/Mellanox-ConnectX-5-PCIe-Gen-4-Enablement: A FW modification tool to enable PCIe Gen 4 on cards that shipped as Gen 3]
A tool that patches user firmware images to enable PCIe Gen4 on NVIDIA/Mellanox ConnectX-5 adapters by unlocking firmware locks, requiring backup, patching, flashing, and verification steps.
- fastjson-jsontype-rce-lab/fastjson2 at master · dinosn/fastjson-jsontype-rce-lab [app]
Fastjson2's default polymorphic parsing can be exploited via attacker-controlled `@type` to trigger remote class loading or SSRF, even with autoType disabled, due to insecure type handling and insufficient autoType filtering, with mitigation requiring safeMode and outbound restrictions.
- Recover the 2004 mwccarm (build 0056) and document the compiler lineage by tangosdev · Pull Request #765 · tangosdev/sm64ds-decomp [rev]
Recovered and verified the oldest functional CodeWarrior ARM compiler (build 0056) from 2004, establishing its unique ROM behavior and narrowing the game's compiler version to between builds 0058 and 0062.
Tue, 28 Jul 2026 08:57:42 +0530
- NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework
NVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelligence (AI) agents.
The 37-member group spans cloud, security, enterprise software, and AI companies, including Microsoft, Cisco, Cloudflare, CrowdStrike, Hugging Face, IBM, Palo Alto Networks, Red Hat, and the Linux
- Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
Dysphoria, an Internet of Things (IoT) botnet line tracked by CNCERT and XLab, has adopted blockchain-based name services and infected-device relays after a March law-enforcement operation against JackSkid infrastructure. The researchers say the design makes the botnet harder to disrupt.
CNCERT, China's national computer emergency response team, and XLab, the threat-intelligence lab of Chinese
- Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw
Public exploit details released on July 27 show how an unauthenticated request can reach PHP's eval() function inside vBulletin and execute code on an unpatched forum server. The attack requires no account, administrative access, or interaction from another user.
SSD Secure Disclosure lists vBulletin 6.2.1 and earlier, and 6.1.6 and earlier, as affected, but does not give a lower version
- ⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
Monday starts with the usual promise that everything is under control. Then the logs wake up.
This week, trusted tools crossed lines, old flaws found new work, exposed systems stayed exposed, and attackers kept hiding inside normal-looking services. Nothing looked strange at first. That helped.
That is the mood. Here is the full recap.
⚡ Threat of the Week
OpenAI Says Its AI Agent Went Rogue
- n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process
n8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute operating-system commands on the server running the automation platform. Security Joes found the flaw while probing n8n's February fix for CVE-2026-27577 for another bypass.
The affected ranges are <2.31.5 and >=2.32.0,<2.32.1. n8n fixed the flaw in versions 2.31.5 and
- Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
Cybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs 'secure document' lures to deliver legitimate remote monitoring and management (RMM) tools.
'The victim was directed through compromised web infrastructure to a counterfeit Microsoft Store page claiming that Microsoft Teams had to be updated before the shared document could be opened,' ZeroBEC said in
- Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
The China-linked cybercrime group behind the use of income tax-related phishing lures targeting Indian taxpayers, tax professionals, and corporate finance teams has been observed using a sophisticated crypter service called Cruciferra.
According to a new analysis by Proofpoint, Cruciferra has been utilized by various unrelated cybercriminal threat clusters to deliver a wide array of remote
- TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments
Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia targeting government entities in the Middle East.
The intrusions have resulted in the deployment of previously unreported malware families dubbed TELESHIM, MIXEDKEY, and BINDCLOAK, according to Zscaler ThreatLabz. The cybersecurity firm said it detected the campaign earlier this month.
- GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption
GitHub has announced a new cooldown mechanism in Dependabot, allowing the tool to wait at least three days after a release is published before opening a pull request.
'The cooldown configuration option in the dependabot.yml still controls the behavior, though, so you can choose a different cooldown parameter that fits your project,' the Microsoft-owned subsidiary said.
According to GitHub, the
- Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
A malvertising operation dubbed SourTrade is making victims' browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file from a fixed URL.
Confiant, which detailed the campaign on July 23, 2026, said it has operated since late 2024 and impersonated TradingView, Solana, and Luno to target retail traders and
Tue, 28 Jul 2026 05:30:04 +0000
- ISC Stormcast For Tuesday, July 28th, 2026 https://isc.sans.edu/podcastdetail/10026, (Tue, Jul 28th)
- Java Spring Boot 'heapdump' scans, (Mon, Jul 27th)
Spring Boot exposes the endpoint '/actuator/heapdump' to collect debug information. By default, the endpoint will return a file heapdump.hprof, which includes a binary heapdump that can be used to analyze the current state of the application. Non-Java readers may be familiar with a similar concept, core dumps, which are produced by binaries to expose a memory image at the time the software crashes. 'heapdumps' are the Java analog to 'core-dumps'. The heapdump often includes secrets used by the application to connect to backend systems. API keys, database passwords, and other sensitive data may be exposed in the heapdump.
- ISC Stormcast For Monday, July 27th, 2026 https://isc.sans.edu/podcastdetail/10024, (Mon, Jul 27th)
- Scans for ESAFENET CDG 3 Document Management System Weak Logins, (Sun, Jul 26th)
ESAFENET&#;x26;#;39;s CDG showed up in our data before. The company focused on secure document management and data leakage prevention solutions. The 'CDG' stands for 'Content Data Guard', and the product appears to be mostly targeting the Chinese market [1]. Sadly, like so many security products, it suffers from basic security vulnerabilities like SQL Injection, XSS, and default passwords. We have seen scanning for ESAFENET CDG before, in particular after the cross-site scripting vulnerability was made public.
- ISC Stormcast For Friday, July 24th, 2026 https://isc.sans.edu/podcastdetail/10022, (Fri, Jul 24th)
- When the 'Autonomous Attacker' Is Your Own AI Model, (Thu, Jul 23rd)
Two disclosures, five days apart, described the same intrusion from opposite ends —
- ISC Stormcast For Thursday, July 23rd, 2026 https://isc.sans.edu/podcastdetail/10020, (Thu, Jul 23rd)
- Rondo Meets Geoserver, (Wed, Jul 22nd)
This isn&#;x26;#;39;t a new attack, but something I saw 'pop-up' in our logs this week:
- ISC Stormcast For Wednesday, July 22nd, 2026 https://isc.sans.edu/podcastdetail/10018, (Wed, Jul 22nd)
- Captive Portal Detection, (Tue, Jul 21st)
Not everything our honeypots detect is an attack. Sometimes it is just 'odd traffic', and this is one example: Our 'First Seen' list currently includes 'http://detectportal.firefox.co
- Suno [55,282,226 breached accounts]
Mon, 20 Jul 2026 19:49:51 Z
- Paidwork [23,272,765 breached accounts]
Sun, 19 Jul 2026 22:57:18 Z
- Fluke [821,100 breached accounts]
Wed, 15 Jul 2026 08:01:04 Z
- Goose Creek [6,574,121 breached accounts]
Wed, 15 Jul 2026 05:03:14 Z
- Glendale Community College [793,925 breached accounts]
Sat, 11 Jul 2026 10:40:09 Z
- Moody Bible Institute [2,303,416 breached accounts]
Fri, 03 Jul 2026 16:03:25 Z
- Sysco [2,691,852 breached accounts]
Sun, 28 Jun 2026 15:57:29 Z
- American Tower [216,601 breached accounts]
Fri, 26 Jun 2026 07:17:23 Z
- Madison Square Garden Sports [9,796,738 breached accounts]
Wed, 24 Jun 2026 13:02:33 Z
- JCPenney [368,418 breached accounts]
Sat, 20 Jun 2026 03:02:45 Z
- Ralph Lauren [139,903 breached accounts]
Thu, 18 Jun 2026 22:48:34 Z
- Operation Endgame 4.0 [4,348,526 breached accounts]
Thu, 18 Jun 2026 20:08:06 Z
- CFGI [248,235 breached accounts]
Thu, 18 Jun 2026 03:22:51 Z
- June 2026 Stealer Logs [56,278,397 breached accounts]
Mon, 15 Jun 2026 19:30:15 Z
- Berkadia [305,216 breached accounts]
Mon, 15 Jun 2026 04:09:04 Z
- Infinite Campus [137,123 breached accounts]
Mon, 15 Jun 2026 01:03:42 Z
- University of Nottingham [454,635 breached accounts]
Wed, 10 Jun 2026 22:13:31 Z
- Baker Distributing [102,935 breached accounts]
Sun, 07 Jun 2026 06:16:36 Z
- BCD Travel [396,313 breached accounts]
Fri, 05 Jun 2026 06:53:15 Z
- DentaQuest [2,553,599 breached accounts]
Wed, 03 Jun 2026 22:56:30 Z