{"id":2576,"date":"2026-08-27T18:38:55","date_gmt":"2026-08-27T18:38:55","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2576"},"modified":"2026-08-27T18:38:55","modified_gmt":"2026-08-27T18:38:55","slug":"296k-iot-botnet-100-water-systems-targeted-sharepoint-rce-chain-27-new-stories","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2576","title":{"rendered":"296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Aug 27, 2026<\/span><\/span><span class=\"p-tags\">Hacking News \/ Cybersecurity News<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiwWCb2shFhaav60Wjr2-8DoStCVaQrYqkE6EBZ8F5sREap-Khi19y-w9NVmFHyHosV6xVB0fTeN_DcSpGIyCZ621SnjqZozRVG70ceOey_D8djA5r5rpP9tFkRSESgs4kHZilTMoz2y8uqX-iTLR0JjjZkhypYjCCAEvQKzyU7xarQpt3sYvJc-fnWSWlb\/s1700-e365\/threats.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine.<\/p>\n<p>The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools waiting before showing their real behavior, exposed systems getting scanned, and exploit windows shrinking again. Different tricks, same advantage: attackers keep finding places where trust is cheap and friction is low.<\/p>\n<p>That sets the tone. Here\u2019s the full list of what surfaced this week.<\/p>\n<div class=\"article-board\">\n <b\/><\/p>\n<p>The threats change every week. <span data-push-label=\"ThreatsDay Bulletin\" data-push-topic=\"threatsday bulletin:t, recap:i\">Subscribe, and we\u2019ll alert you<\/span> when each new ThreatsDay Bulletin is out.<\/p>\n<\/div>\n<div class=\"td-wrap\">\n<section aria-labelledby=\"threatsday-title\" class=\"td-section\">\n<ol class=\"td-timeline\" role=\"list\">\n<a name=\"more\"\/><\/p>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Social engineering attempt fails<\/span><\/p>\n<p class=\"td-desc\">\n      Cybersecurity company ReliaQuest has confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a member of the security team. The incident took place on August 22, 2026. \u00abThe threat actor registered a lookalike domain and stood up a fake ReliaQuest single sign-on (SSO) page behind a content delivery network,\u00bb the company <a href=\"https:\/\/reliaquest.com\/blog\/threat-spotlight-social-engineering-attempt-against-reliaquest-what-we-found\/\" target=\"_blank\">said<\/a>. \u00abThe threat actor then called multiple ReliaQuest teammates, each time posing as a security employee by name in an attempt to steer them towards the fake page. One teammate entered their password and approved the push notification on their phone. That handed the attacker a brief session on our identity dashboard.\u00bb ReliaQuest said the extent of the access was view only, and that no applications or systems were accessed, and no customer data was ever touched. Although the company did not attribute the incident to a particular threat actor, it noted the playbook aligns with tactics adopted by ShinyHunters and other extortion crews, such as \u00aban impersonation call, a throwaway lookalike domain registered and burned within the hour, a harvesting page behind a content delivery network, MFA push abuse, and a rapid attempt to enroll a new authenticator.\u00bb The <a href=\"https:\/\/socradar.io\/blog\/shinyhunters-reliaquest-breach\/\" target=\"_blank\">development<\/a> comes as ShinyHunters listed the company on its dark web portal. Last week, ReliaQuest said it&#8217;s tracking a ShinyHunters campaign using domains that follow the \u00abcompany[.]claims\u00bb pattern, including \u00abreliaquest[.]claims.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Trojanized productivity apps<\/span><\/p>\n<p class=\"td-desc\">\n      Fake websites advertising productivity software are being used to <a href=\"https:\/\/blog.gdatasoftware.com\/2026\/08\/38468-projextor-abusing-electron\" target=\"_blank\">lure users into downloading<\/a> a deceptively functioning program that contains malware. The Electron-based applications, such as Kitchen Canvas, Food or Meal Formula, DocConvertWizard, and other PDF conversion tools under different names, gain the ability to dynamically execute injected scripts and access desktop capture functionality through Electron APIs.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Live operator-driven phishing<\/span><\/p>\n<p class=\"td-desc\">\n      An undocumented phishing framework, internally branded \u00abJWR\u00bb by its developer, is designed to convincingly impersonate checkout and login pages across major payment and shopping platforms. \u00abThe client engine of the JWR phishing framework is a real-time, operator-driven system that, rather than merely logging form submissions like a static credential-stealing page, keeps an AES-CTR encrypted WebSocket open to the threat actor so they can steer each victim&#8217;s session live,\u00bb Cisco Talos <a href=\"https:\/\/blog.talosintelligence.com\/dissecting-the-jwr-phishing-framework\/\" target=\"_blank\">said<\/a>. \u00abThe victim data targeted by the actor using JWR extends well beyond payment data, encompassing identity documents, Social Security numbers, passport and driver&#8217;s license images, website and PayPal credentials, 2FA codes, and full device fingerprints, all committed to the actor&#8217;s server once a session ends.\u00bb The JWR phishing framework is assessed to be a variant of The Outsider phishing-as-a-service (PhaaS) platform, based on several similarities in the client engine scripts and functionalities of the two PhaaS platforms.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Android fraud bot for rent<\/span><\/p>\n<p class=\"td-desc\">\n      Cybersecurity researchers have disclosed Octagon, a previously undocumented Android on-device fraud bot sold as malware-as-a-service (MaaS) by the Russian-speaking actor AndroidKitKat. \u00abThe operator advertises Octagon for $1,400 a month, giving buyers accessibility overlays, hidden VNC, SMS and one-time password interception, unlock-pattern capture, and on-screen balance reading,\u00bb iVerify <a href=\"https:\/\/iverify.io\/blog\/octagon-android-bot-crypto-wallets-banking-apps\" target=\"_blank\">said<\/a>. \u00abIt targets crypto wallets and banking apps after installation, while the delivery app can use an unrelated theme.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Rust backdoor tied to ransomware<\/span><\/p>\n<p class=\"td-desc\">\n      A new Rust-based malware family dubbed C2Looper is likely leveraged by a ransomware-related threat actor and delivered to victims through a multi-stage ClickFix infection chain. Zscaler ThreatLabz said it discovered the malware in July 2026. \u00abC2Looper supports typical backdoor commands including remote shell execution, reconnaissance, and deploying additional malware tooling,\u00bb Zscaler <a href=\"https:\/\/www.zscaler.com\/blogs\/security-research\/c2looper-new-backdoor-likely-tied-ransomware-github-c2\" target=\"_blank\">said<\/a>. \u00abC2Looper dynamically resolves Windows APIs and encrypts strings.\u00bb There also exists a variant with additional features and capabilities, including the use of GitHub for command-and-control (C2) communications.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">296,000 IoT devices compromised<\/span><\/p>\n<p class=\"td-desc\">\n      Nearly 296,000 devices have been compromised by a botnet named Dysphoria. \u00abDysphoria targets IoT devices and its primary function appears to be for use in DDoS-attacks,\u00bb the Shadowserver Foundation <a href=\"https:\/\/www.shadowserver.org\/what-we-do\/network-reporting\/dysphoria-botnet-special-report\/\" target=\"_blank\">said<\/a>. \u00abRecently the botnet has gotten residential proxy functionality.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">C2 moves onto Polygon<\/span><\/p>\n<p class=\"td-desc\">\n      A recently discovered C++ botnet loader called Aeternum has shifted its C2 infrastructure entirely to the public Polygon blockchain. \u00abInstead of relying on centralized servers or domains, threat actors operate Aeternum by writing encrypted and plaintext instructions directly using smart contracts,\u00bb Palo Alto Networks Unit 42 <a href=\"https:\/\/unit42.paloaltonetworks.com\/aeternum-blockchain-c2-analysis\/\" target=\"_blank\">said<\/a>. \u00abInfected devices continuously query public remote procedure call (RPC) endpoints to retrieve and execute these on-chain commands. The Aeternum botnet uses decentralized networks and evasion techniques, such as virtual machine detection and antivirus scanning, to operate effectively. This combination establishes a highly resilient, low-cost threat that complicates existing law enforcement takedown methods.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">AI enters botnet workflows<\/span><\/p>\n<p class=\"td-desc\">\n      An AArch64 Linux peer-to-peer botnet called ToxNetV2 has integrated a large language model (LLM) into the operational workflow of its controller. The controller communicates with NVIDIA NIM using the z-ai\/glm-5.2 model, becoming a part of a feedback loop that determines how its capabilities can be put to use on a given machine based on information about the infected environment. \u00abThe controller collects host and botnet telemetry, sends that context to NVIDIA NIM, parses selected model responses into structured actions, and queues those actions for operator approval,\u00bb Joe Security <a href=\"https:\/\/www.joesecurity.org\/blog\/6764463444623599134\" target=\"_blank\">said<\/a>. \u00abThe system is not fully autonomous or self-modifying. The operator remains the final approval point for its higher-impact AI-generated actions. Once approved, however, those actions can reach local command execution, file writes, remote SSH, persistent state, and a compilation workflow.\u00bb According to the cybersecurity company, the AI subsystem resides within a broader Tox-based botnet featuring encrypted peer-to-peer C2, host-management capabilities, scanner workers, self-propagation logic, and 17 network-attack launchers.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Two stealers target credentials<\/span><\/p>\n<p class=\"td-desc\">\n      An information stealer called Phantom Stealer is designed to collect browser credentials, saved passwords, session cookies, cryptocurrency wallet files, and detailed system fingerprints. \u00abSince its appearance, Phantom Stealer has been observed in multiple campaigns targeting users across different countries, frequently distributed through phishing lures, cracked software, and malicious links spread via platforms like Discord and Telegram,\u00bb Splunk <a href=\"https:\/\/www.splunk.com\/en_us\/blog\/security\/phantom-stealer-shellcode-steganography-credential-theft.html\" target=\"_blank\">said<\/a>. \u00abIts modular design and relatively low barrier to entry have made it an attractive option for both novice and experienced threat actors, contributing to its growing adoption and making it a persistent and evolving threat in the infostealer landscape.\u00bb A second stealer malware family that has emerged in the wild is <a href=\"https:\/\/www.splunk.com\/en_us\/blog\/security\/bundled-to-steal-salat-stealer-campaign.html\" target=\"_blank\">Salat Stealer<\/a>, which is written in Go and can perform system reconnaissance, conduct credential theft, and monitor victim activity through desktop streaming and audio\/video capture.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">ClickFix chain drops new RAT<\/span><\/p>\n<p class=\"td-desc\">\n      A previously undocumented remote access trojan (<a href=\"https:\/\/www.splunk.com\/en_us\/blog\/security\/common-ttps-rats-malware-analysis.html\" target=\"_blank\">RAT<\/a>) called CNCMachineRMS is being delivered via BabaDeda Loader. \u00abInfection starts with a ClickFix lure that launches a legitimately signed IBM SPSS IDE executable, WinWrapIDE.exe, whose scripting engine is abused to load a malicious DLL,\u00bb LevelBlue <a href=\"https:\/\/www.levelblue.com\/blogs\/spiderlabs-blog\/cncmachinerms-the-undocumented-rat-at-the-end-of-a-babadeda-chain\" target=\"_blank\">said<\/a>. \u00abFour decoy DLLs load through ordinary Windows import resolution, then the final stage smuggles shellcode into execution via EnumTimeFormatsEx, a benign date-formatting API.\u00bb The Trojan gives an operator remote administration of the host, including an interactive shell, a file manager, screen capture functionality, a local account backdoor, seven persistence mechanisms, and twenty typed commands for pulling down and running further payloads.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">New modular RAT emerges<\/span><\/p>\n<p class=\"td-desc\">\n      Speaking of RATs, Abyssos is another new malware family that&#8217;s written in C++ and supports credential theft, file exfiltration, and remote access via VNC. The modular malware was first detected in June 2026. \u00abAbyssos uses a custom TCP protocol for network communication,\u00bb Zscaler <a href=\"https:\/\/www.zscaler.com\/blogs\/security-research\/abyssos-technical-analysis-new-modular-rat\" target=\"_blank\">said<\/a>. \u00abAbyssos supports a number of different network commands and downloads additional modules from the command-and-control (C2) server to enhance its capabilities.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Disk encryption bypass remains unpatched<\/span><\/p>\n<p class=\"td-desc\">\n      A zero-day boot-chain vulnerability in HP ThinPro 8 and 9 could allow physical attackers to bypass Trusted Platform Module (TPM) full-disk encryption and extract LUKS keys securing the device&#8217;s root partition. The flaw stems from an incomplete measured-boot policy that omits the Linux kernel and <a href=\"https:\/\/wiki.debian.org\/initramfs\" target=\"_blank\">initramfs<\/a> (aka the initial RAM file system). \u00abFor defenders running ThinPro with disk encryption today: turn Secure Boot on and set a BIOS password,\u00bb AmberWolf <a href=\"https:\/\/blog.amberwolf.com\/blog\/2026\/august\/hp-thinpro-tpm-sealed-disk-encryption-that-only-measured-half-the-boot-chain\/\" target=\"_blank\">said<\/a>. \u00abBoth slow an attacker down; neither closes the PCR gap. Beyond that, treat the encryption as no protection once the device is out of your control. Destroy the M.2 on disposal, and do not rely on ThinPro FDE for a lost or returned unit.\u00bb The vulnerability remains unpatched.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">1.99 million mobile attacks blocked<\/span><\/p>\n<p class=\"td-desc\">\n      Data from Kaspersky shows that more than 1.99 million attacks were recorded and blocked against mobile devices in Q2 2026 using malware, adware, or unwanted mobile software. \u00abThe Trojan-Banker category was the most prevalent mobile malware threat with a 30.77% share of total detected applications,\u00bb Kaspersky <a href=\"https:\/\/securelist.com\/malware-report-q2-2026-mobile-statistics\/120948\/\" target=\"_blank\">said<\/a>. More than 304,000 malicious installation packages were discovered, including 93,574 packages related to mobile banking Trojans and 570 packages related to ransomware.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Python stealer targets credentials and wallets<\/span><\/p>\n<p class=\"td-desc\">\n      Cybersecurity researchers have discovered a new Python-based stealer malware called Vanta Stealer that combines extensive credential harvesting capabilities with layered obfuscation techniques that make it possible to collect valuable user data while complicating analysis efforts. \u00abVanta Stealer targets a broad range of applications and digital assets, including Chromium-based browsers, Discord, Telegram Desktop, Steam, Riot Games, Roblox, Minecraft, Mullvad VPN, cryptocurrency wallets, and locally stored sensitive documents,\u00bb Point Wild <a href=\"https:\/\/www.pointwild.com\/threat-intelligence\/point-wild-exclusive-dissecting-vanta-stealer-a-python-based-cross-platform-information-theft-malware\/\" target=\"_blank\">said<\/a>. \u00abIn addition to harvesting browser passwords, cookies, and stored payment information, the malware collects authentication tokens, gaming platform data, VPN configurations, cryptocurrency wallet files, screenshots, webcam captures, and documents containing wallet recovery phrases or private keys.\u00bb Exactly how it&#8217;s delivered is currently not known, although it could be through phishing emails, fake installers, game cheats, fake software updates, SEO poisoning, malvertising, and malicious code repositories.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Two more credential stealers surface<\/span><\/p>\n<p class=\"td-desc\">\n      Elsewhere, malicious LNK files <a href=\"https:\/\/any.run\/cybersecurity-blog\/major-cyber-attacks-july-2026\/\" target=\"_blank\">disguised as PDF documents<\/a> have been found to launch a multi-stage infection chain using cmd.exe, legitimate Windows utilities, AutoIt, and PowerShell to deploy DARTHVADER Stealer. Europe and the U.S. have been targeted by DestinyStealer, which exhibits clear code continuity from StormKitty Stealer. It collects browser data, cookies, passwords, cryptocurrency wallet extension storage, Outlook and VPN data, FileZilla credentials, Wi-Fi profiles, and desktop screenshots.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Stealer scores hosts for sandbox signs<\/span><\/p>\n<p class=\"td-desc\">\n      An information stealer called ScarfaceStealer has been observed propagating via an Electron-based application masquerading as AI-related tools. The malware performs a set of environment checks intended to evade sandbox environments and evaluates the host through 11 indicators and combines their results into a weighted suspicion score. If the score reaches 7 or higher, it enters a decoy loop that continuously displays random message boxes. Execution continues only if the score is below 7. \u00abUnpacking the Electron application exposed a second-stage JavaScript-based loader that performs initial evasion checks before decrypting and executing the next stage,\u00bb Joe Security <a href=\"https:\/\/www.joesecurity.org\/blog\/691434271001776522\" target=\"_blank\">said<\/a>. \u00abThat third stage applies four additional decryption layers, maps an embedded PE in memory, and transfers execution to it. The recovered final stage revealed the core anti-sandbox logic: a scoring-based mechanism used to decide whether the ScarfaceStealer payload should continue execution.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Fake scans push antivirus removal<\/span><\/p>\n<p class=\"td-desc\">\n      Malwarebytes is calling attention to a scam campaign that uses a set of 11 fake websites that claim to offer a way to check if antivirus tools are working as expected. The tools carry Microsoft branding and go by names like SysScan to lend them a veneer of legitimacy, only to instruct users to immediately uninstall antivirus programs installed on their machines to address compatibility issues. \u00abAlthough the names vary, the sites work in essentially the same way: Run a convincing-looking but fake security scan, tell the victim their antivirus is causing problems, collect their information, and prepare them for a supposed refund call,\u00bb the company <a href=\"https:\/\/www.malwarebytes.com\/blog\/threat-intel\/2026\/08\/fake-microsoft-security-scans-trick-victims-into-uninstalling-their-antivirus\" target=\"_blank\">said<\/a>.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">ClickFix chain drops Amatera<\/span><\/p>\n<p class=\"td-desc\">\n      Fake CAPTCHA checks that employ ClickFix lures and bogus software download campaigns are being used to deliver PavinLoader (aka RenPy Loader and RenEngine Loader), indicating the tool is being offered as a loader-as-a-service to other cybercriminals. \u00abWhat happens next is much more consistent,\u00bb Malwarebytes <a href=\"https:\/\/www.malwarebytes.com\/blog\/threat-intel\/2026\/08\/tracking-pavinloader-across-clickfix-and-fake-download-campaigns\" target=\"_blank\">said<\/a>. \u00abPavinLoader uses legitimate Windows tools alongside malicious .NET files to run several stages of malware. It also uses EtherHiding, a technique that uses a blockchain to hide information about its infrastructure, to find the server from which it should retrieve additional malware.\u00bb This ultimately leads to the deployment of Amatera Stealer and other malware. \u00abIn some cases, WiX Burn bundles downloaded another payload associated with PavinLoader. In others, we detected Hijack Loader,\u00bb it added. \u00abThis gives the campaign operators the ability to deploy multiple payloads on a compromised machine.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Per-app privacy controls tested<\/span><\/p>\n<p class=\"td-desc\">\n      Microsoft has begun piloting new privacy controls that will let Windows 11 users choose which desktop applications can access their camera, microphone, and precise location. \u00abWindows Insiders can now manage camera, microphone, and location permissions for individual desktop apps,\u00bb Microsoft <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows-insider\/release-notes\/experimental\/preview-build-26340-9233#manage-camera-microphone-and-location-access-for-desktop-apps\" target=\"_blank\">said<\/a>. \u00abPreviously, access for traditional desktop applications was managed through a single device-wide setting. With this update, you can review and control access on an app-by-app basis, giving you greater visibility into which apps are requesting access to sensitive resources and more control over your privacy choices.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Telegram-sold RAT used by TA4922<\/span><\/p>\n<p class=\"td-desc\">\n      Proofpoint has disclosed details of a new RAT and C2 framework called PackClient that&#8217;s sold on Telegram and is being used by at least one threat actor, Chinese-speaking TA4922, as part of its continued efforts to expand its malware arsenal. The first campaign, observed in late May 2026, used a tax-themed lure and impersonated the Shandong Provincial Tax Bureau to trigger a sense of urgency. Two other campaigns in mid- to late-July 2026 have been found to impersonate Indian tax authorities and used penalty-themed lures to deliver the malware. \u00abPackClient consists of a first-stage loader executable, a second-stage loader (&#8216;PackClientLauncher&#8217;) DLL module, a core module (&#8216;PackClientCore&#8217;), and several optional plugins that can be downloaded upon operator command,\u00bb Proopoint <a href=\"https:\/\/www.proofpoint.com\/us\/blog\/threat-insight\/carry-compromise-ta4922-packs-packclient\" target=\"_blank\">said<\/a>. \u00abThe malware connects to two hard-coded C2 endpoints over raw TCP sockets to download and reflectively execute the core RAT DLL, receive commands, and download additional plugins or payloads.\u00bb The commands allow the malware to configure C2 servers, run shell commands, start screen capture, launch a SOCKS proxy tunnel, record using a webcam, perform file operations, enumerate running processes, log keystrokes, and update the core module. No less than 11 plugins have been identified. They allow remote desktop screen sharing, RDP-style virtual desktop, file management, system administration, interactive remote shell, and webcam streaming.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Cloud database powers C2<\/span><\/p>\n<p class=\"td-desc\">\n      A modular post-exploitation framework called Miraak has been found exposed in attacker-controlled open directories (\u00ab144.172.96[.]13\u00bb). \u00abMiraak is designed to provide operators with persistent control of compromised systems while supporting command execution, file transfer, process management, screenshot collection, and extensible post-exploitation activity,\u00bb Blackpoint Cyber <a href=\"https:\/\/blackpointcyber.com\/blog\/miraaks-modular-post-exploitation-framework\/\" target=\"_blank\">said<\/a>. \u00abA defining aspect of the framework is its use of cloud-hosted PostgreSQL and Timescale infrastructure for command-and-control. Rather than communicating through traditional web-based C2 endpoints, Miraak uses database connections to register infected systems, retrieve operator tasking, track jobs, and return results.\u00bb The malware has not been attributed to any known threat actor or group.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Stored XSS enabled account takeover<\/span><\/p>\n<p class=\"td-desc\">\n      A security vulnerability in Microsoft Purview could be exploited by a single external Teams message, email, or Copilot prompt to carry stored malicious code into a Purview reviewer&#8217;s authenticated browser and turn a routine compliance check into a path to token theft and account takeover. \u00abA standard user, including a user in a completely different tenant with no permissions in yours, could send a Teams message, an email, or a Copilot prompt containing a malicious payload, wait for it to be flagged and have their JavaScript execute inside the authenticated purview.microsoft.com session of every compliance analyst who opened the case,\u00bb Cymulate <a href=\"https:\/\/cymulate.com\/blog\/microsoft-purview-xss-account-takeover\/\" target=\"_blank\">said<\/a>. \u00abIn our proof of concept, that meant the reviewer&#8217;s access and refresh tokens leaving the browser and reaching an attacker-controlled server, which constitutes full impersonation of a privileged compliance identity.\u00bb Microsoft has since issued a service-side fix.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Malicious MCP server targets secrets<\/span><\/p>\n<p class=\"td-desc\">\n      A supply chain attack campaign codenamed Deadbugz has been observed attempting to distribute a malicious Model Context Protocol (MCP) server through public GitHub pull requests. \u00abThe server calls itself productivity-suite and initially looks harmless: it offers text formatting and summarization,\u00bb Pillar Security <a href=\"https:\/\/www.pillar.security\/blog\/deadbugz-currently-active-mcp-supply-chain-campaign\" target=\"_blank\">said<\/a>. \u00abAfter a connected client makes three tool calls, however, it changes the instructions it returns to the AI agent. The new metadata directs the agent to seek sensitive information, including SSH keys, AWS credentials, shell history, and Kubernetes configuration, and to conceal the activity from the user.\u00bb The campaign also makes use of what&#8217;s called runtime-gated MCP metadata poisoning, wherein the malicious instructions are built into the server, but remain withheld until the client has made three ordinary tool calls.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Exploit timelines keep shrinking<\/span><\/p>\n<p class=\"td-desc\">\n      Microsoft is warning that the window for patching vulnerabilities is rapidly shrinking, as bad actors exploit newly disclosed flaws faster than organizations can patch them, driven by advances in AI and the rapid spread of exploit information. \u00abModern attack campaigns operate at internet scale,\u00bb the company <a href=\"https:\/\/azure.microsoft.com\/en-us\/blog\/the-patch-window-is-collapsing-why-security-needs-a-new-control-plane\/\" target=\"_blank\">said<\/a>. \u00abSecurity research, public disclosures, proof-of-concept exploits, and threat intelligence circulate globally within hours. A vulnerability announced in the morning can become the focus of active scanning and exploitation efforts by the afternoon. Defenders remain responsible for protecting entire environments that may include thousands of servers, applications, databases, containers, and network assets. Attackers only need to identify a single viable path to exploitation.\u00bb Microsoft has proposed a \u00abcontrol plane\u00bb that&#8217;s centered on the network to reduce exploitability while remediation efforts are underway. \u00abThe objective is not to avoid patching,\u00bb Microsoft added. \u00abThe objective is to create a meaningful layer of defense during the period when patching has not yet been completed.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Hardware-attested AI evidence standard<\/span><\/p>\n<p class=\"td-desc\">\n      The Linux Foundation has announced TRACE (short for Trust, Runtime Attestation and Compliance Evidence), a new open specification for hardware-attested runtime and compliance evidence for AI agents and confidential workloads. It&#8217;s developed collaboratively by AMD, Intel, Microsoft, OPAQUE, and TII. \u00abTRACE creates a standard, open evidence layer that enables reliable governance records for AI agents and other confidential workloads,\u00bb the foundation <a href=\"https:\/\/www.linuxfoundation.org\/press\/linux-foundation-welcomes-trace-to-advance-verifiable-runtime-evidence-for-ai-workloads\" target=\"_blank\">said<\/a>. \u00abAs organizations deploy increasingly autonomous AI agents and open-weight models, they need a consistent, trustworthy method to prove sensitive data is being handled according to policy. TRACE creates a standardized, hardware-enforced governance record that binds together the runtime environment, software, policies, data classifications and tool usage into a portable, cryptographically verifiable artifact that travels with the workload across clouds and confidential computing environments.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">100+ exposed water systems targeted<\/span><\/p>\n<p class=\"td-desc\">\n      The July cyber attacks aimed at the U.S. Water and Wastewater Systems (WWS) Sector targeted over 100 internet-exposed systems, the Cybersecurity and Infrastructure Security Agency (CISA) said. The attacks have been attributed to Iranian threat actors. The attacks leveraged programmable logic controllers (PLCs) connected directly to a cellular modem. \u00abDirectly connecting PLCs to the internet through cellular modems can create significant security risks,\u00bb CISA <a href=\"https:\/\/www.cisa.gov\/resources-tools\/resources\/exposure-reduction\" target=\"_blank\">added<\/a>. \u00abHowever, internet exposure reduction does not mean disabling necessary remote access; organizations should remove remote access when it is unnecessary and secure it when it is necessary.\u00bb Ben Bernstein, Manager of Huntress&#8217; Cybersecurity Advisors Team, described the activity as opportunistic, automated scanning that targeted publicly accessible systems. \u00abThe fact that attackers are using AI tools to write exploit scripts for these devices is an interesting twist, but they are ultimately still just walking through a wide open front door,\u00bb Bernstein said.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Cloaked search results hide phishing<\/span><\/p>\n<p class=\"td-desc\">\n      A new tactic called Chameleon SEO Poisoning uses cloaked search engine results to deploy phishing payloads such as credential theft and session hijacking. \u00abThis allows them to remain invisible to standard security scanners and remain active longer,\u00bb Fortra <a href=\"https:\/\/www.fortra.com\/blog\/the-chameleon-threat\" target=\"_blank\">said<\/a>. \u00abBy heavily utilizing SEO poisoning on Search Engine Result Pages (SERPs), attackers rank at the top for high-intent keywords like &#8216;Bank Name Customer Portal&#8217; or &#8216;Credit Card Login&#8217; on search engines like Google or Bing.\u00bb The cloaking is designed to block direct visits to the malicious sites, while serving a pixel-perfect banking portal clone when the page is visited from a search engine.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Fake Chrome extension enables remote control<\/span><\/p>\n<p class=\"td-desc\">\n      A multi-stage attack has been observed delivering a Rust binary, which, in turn, drops a malicious Chrome extension and an AutoIt script, the latter of which deploys the StealC stealer. The extension masquerades as Google Translate. \u00abOnce installed, it behaves as a full data-theft and remote-control tool,\u00bb VMRay Labs <a href=\"https:\/\/www.vmray.com\/news\/a-fake-google-translate-extension-that-hides-its-actions-in-the-browser-windows-you-arent-watching\/\" target=\"_blank\">said<\/a>. \u00abIt extracts browser history, bookmarks, the list of installed extensions, saved credentials, and cookies. Beyond theft, it gives the operator live control: a stream of the victim&#8217;s Chrome windows, the ability to interact with sites through remote mouse clicks and keyboard input, a proxy setting, and the injection of malicious JavaScript into specific sites.\u00bb What&#8217;s more, the remote control extends to out-of-focus windows and the extension can conduct an adversary-in-the-middle (AitM) attack by replacing a legitimate login form with an iframe that loads from a phishing page while the address bar still shows the actual domain.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">SharePoint exploit chain under probing<\/span><\/p>\n<p class=\"td-desc\">\n      Defused Cyber has warned that threat actors are exploiting two <a href=\"https:\/\/www.resecurity.com\/blog\/article\/from-web-request-to-domain-compromise-understanding-the-july-2026-sharepoint-attacks\" target=\"_blank\">Microsoft SharePoint flaws<\/a> \u2013 CVE-2026-55040 (an authentication bypass flaw in the JWT token validation pipeline) and CVE-2026-63520 (an improper input validation in Microsoft Office SharePoint that allows code execution) \u2013 to obtain remote code execution against its honeypots. \u00abThe JWT bypass (55040) was exercised, followed by heavy admin enumeration and probing of the Business Data Catalog sink behind CVE-2026-63520,\u00bb it <a href=\"https:\/\/x.com\/DefusedCyber\/status\/2092228764323217723\" target=\"_blank\">said<\/a>. \u00abNo code execution observed yet.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">80% of AI tools lack IT oversight<\/span><\/p>\n<p class=\"td-desc\">\n      A <a href=\"https:\/\/www.reco.ai\/state-of-agent-security-2026-form\" target=\"_blank\">new report<\/a> from Reco has found that four in five AI tools operate without IT oversight, leaving security teams without a clear picture of which ones are active, who owns them, or what access they hold. An analysis of 500 published agent tools and MCP servers has identified 62% of them to be capable of both reading local data and reaching the internet, offering a direct data exfiltration pathway. \u00abAI agents have moved from experimentation into daily business workflows, but our findings show only 20% of AI tools in enterprise ecosystems are currently governed by IT oversight,\u00bb Reco said. \u00abThat leaves organizations exposed to a new class of operational risk. Agents embedded in applications can operate through existing permissions, OAuth grants and workflow access, creating toxic combinations that expose data and trigger actions beyond what any owner approved.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<\/ol>\n<\/section>\n<\/div>\n<p>The week\u2019s weirdest detail may be how little separation remains between \u201cadvanced\u201d and \u201cordinary.\u201d Blockchain-backed command channels, AI-assisted botnets, live phishing operators, poisoned software, exposed industrial systems. Different levels of sophistication, often landing on the same old weaknesses.<\/p>\n<p>That is probably the part worth keeping. Attackers do not need every idea to be brilliant. They need one exposed box, one convincing page, one permissive tool, or one person who clicks at the wrong moment. The tooling keeps changing. The openings are often painfully familiar.<\/p>\n<p>That\u2019s it for this ThreatsDay. Patch what matters, question what looks normal, and assume next week will find another cheap way through.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Aug 27, 2026Hacking News \/ Cybersecurity News A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2577,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[3207,192,219,780,316,751,187,224,113,1298],"class_list":["post-2576","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-296k","tag-botnet","tag-chain","tag-iot","tag-rce","tag-sharepoint","tag-stories","tag-systems","tag-targeted","tag-water"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2576","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2576"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2576\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2577"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2576"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2576"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2576"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}