{"id":3201,"date":"2026-09-28T15:00:11","date_gmt":"2026-09-28T15:00:11","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=3201"},"modified":"2026-09-28T15:00:11","modified_gmt":"2026-09-28T15:00:11","slug":"387m-crypto-hack-citrix-exploits-ai-agents-go-off-script-and-more-threats","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=3201","title":{"rendered":"$387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 28, 2026<\/span><\/span><span class=\"p-tags\">Cybersecurity News \/ Hacking<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh4-eWVCAN2nvZGZrKlwm-wminZE56MzJ_bVRK6CJfdBw9TXU4yQy6t9T0hDi0hSOskE9Xs6M-KCVEbVvBuL2DLDkew97W2iobOPZa9zqEBeGPWBnW8cftdD1FwzBLz7CIGVhJb1FwnS-35B62Jqc331zNQ67hZP-V2jKBT7yUxUV4rn8jMr27QCommYp-j\/s1700-nu-rw-lo-l85-e365\/c-recap.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><\/a><\/div>\n<p>A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is the kind of week this was: forgotten assumptions turning into live attack surface.<\/p>\n<p>Elsewhere, weak service accounts, old bugs, exposed systems, phishing kits, and strangely easy exploit paths kept doing useful work for attackers. Nothing exotic. Mostly things nobody expected to matter anymore.<\/p>\n<p>Here\u2019s the full recap of what mattered this week.<\/p>\n<h2 style=\"text-align: left;\"><strong>\u26a1 Threat of the Week<\/strong><\/h2>\n<p><strong>Citrix Warns of Actively Exploited NetScaler ADC and Gateway Flaws <\/strong>\u2014 Citrix released patches to address multiple vulnerabilities, including CVE-2026-88771 and CVE-2026-88772, that have come under active exploitation. CVE-2026-88771 is an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands, while successful exploitation of CVE-2026-88772 could allow for remote code execution or denial-of-service. CISA said \u00abthreat actors are actively exploiting these vulnerabilities globally,\u00bb urging federal agencies to apply patches by Wednesday.<\/p>\n<h2 style=\"text-align: left;\"><strong>\ud83d\udd14 Top News<\/strong><\/h2>\n<ul>\n<li><strong><a href=\"https:\/\/thehackernews.com\/2026\/09\/bitget-says-suspected-north-korean.html\" target=\"_blank\">Bitget Resumes Withdrawals After Hack <\/strong>\u2014 Cryptocurrency exchange Bitget resumed Bitcoin withdrawals in phases after suspected North Korean hackers breached its systems last week and stole over $387 million. \u00abAt 18:31 UTC on September 24, 2026, Bitget&#8217;s security systems identified unauthorized transfers involving a limited number of hot wallets,\u00bb Bitget said. \u00abBitget&#8217;s cold wallets and the overwhelming majority of platform assets remain secure and unaffected.\u00bb According to a real-time fund tracing dashboard published by Coindesk, Circle and Tether have frozen stablecoins worth $339,100 linked to the hack.<\/li>\n<li><strong>PamStealer Adds Live C2 Payload Decryption <\/strong>\u2014 A new version of PamStealer has been found to incorporate a new anti-analysis trick that ensures the main payload can only be recovered using a server-side decryption chain. The latest artifacts continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. \u00abWhere earlier variants embedded their payload key material directly in the JXA source, it now fetches a purpose-built decryption utility and completes a key exchange with the server before the payload can be unwrapped,\u00bb Jamf said. \u00abWithout the server&#8217;s cooperation, the payload cannot be recovered statically.\u00bb<\/li>\n<li><strong>Placeholder Domain Found References in ~1.7K Repos <\/strong>\u2014 The \u00abthird-party[.]com\u00bb domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users. \u00abthird-party[.]com has been a generic documentation placeholder for years, the same role example.com plays,\u00bb Manifold Security said. \u00abUnlike &#8216;example[.]com,&#8217; third-party[.]com is not IANA-reserved. Anyone could register it, and someone did. Every doc, test, and skill that hard-coded it now points readers at attacker infrastructure.\u00bb As of writing, the domain has been marked as malicious and unsafe on both VirusTotal and Google&#8217;s Safe Browsing list. Manifold also identified 13 more placeholder domains that are not IANA-reserved, with two of them \u2013 yoursite[.]com and your-domain[.]com \u2013 serving scams and scareware to macOS visitors and an ordinary parking page to other users.<\/li>\n<li><strong>UNK_CondorFiltration Abuses TeamFiltration in New Campaign <\/strong>\u2014 An active TeamFiltration campaign codenamed UNK_CondorFiltration has targeted over 5,700 accounts across 28 Microsoft 365 tenants. The activity has primarily focused on Chilean retail and financial institutions. It originated from 1,487 unique AWS EC2 source IP addresses. \u00abThe campaign compromised 7 accounts \u2013 all of which were unmanaged functional or service accounts rather than individual employee accounts \u2013 highlighting a critical exposure gap around forgotten, non-human identities carrying default or unrotated passwords and no MFA,\u00bb Proofpoint said. The activity took place over three waves from late July to August 2026.<\/li>\n<li><strong>EvilTokens Taken Down in Law Enforcement Action <\/strong>\u2014 A coalition of law enforcement and private-sector tech companies led by Microsoft dismantled the EvilTokens phishing service, arresting two suspected website admins, Felix Utomi and Waidi Segun Adams, taking down more than 50 websites, and notifying victims of compromised email accounts. Per Coinbase, the EvilTokens operators were said to be working on expanding the kit to target Gmail and Okta accounts at the time of the takedown. Microsoft attributes the development and support of the platform to Storm-2992. EvilTokens is the latest example of professionalization of cybercrime, allowing bad actors to mount phishing campaigns with little effort and at scale. EvilTokens&#8217; notable feature was the device code phishing flow, which took advantage of security gaps in devices that cannot support standard sign-in methods like smart TVs, printers, conferencing tools, and Teams devices. In these attacks, victims are sent a short code and are told to enter that code into a phishing page to complete authentication. The important aspect here is that instead of a legitimate device requesting access, the threat actor initiates the flow and provides the user with a code through a phishing lure. When the code is entered, victims unknowingly authorize the cybercriminals&#8217; session and grant them access without ever handing over their password.<\/li>\n<li><strong>OpenAI Linked to More Website Hacks <\/strong>\u2014 AI research lab Transluce found three instances between May and June 2026 in which OpenAI&#8217;s agents resorted to hacking when traditional methods failed. This included an attempt on an Australian government public health website. \u00abNotably, the agents did this while attempting mundane data retrieval tasks which were not cyber-related,\u00bb Transluce said. \u00abThis traffic goes back at least to March 6, 2026 and extends as recently as September 16, 2026, suggesting agents may still be exploiting these services to bypass restrictions.\u00bb<\/li>\n<\/ul>\n<h2 style=\"text-align: left;\"><strong>\u200e\ufe0f\u200d\ud83d\udd25 Trending CVEs<\/strong><\/h2>\n<p>Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild.<\/p>\n<p>Check the list, patch what you have, and hit the ones marked urgent first \u2014 <a href=\"https:\/\/www.accomplish.ai\/blog\/escaping-dockers-hypervisor\/\" target=\"_blank\">CVE-2026-77179<\/a> (Docker), <a href=\"https:\/\/idnsec.com\/research\/comment2shell-zero-click-pre-auth-xss-to-rce-in-wordpress-core\/\" target=\"_blank\">CVE-2026-93485, CVE-2026-87902<\/a> (<a href=\"https:\/\/github.com\/WordPress\/wordpress-develop\/security\/advisories\/GHSA-7hp8-65ch-5whp\" target=\"_blank\">WordPress<\/a>), <a href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2026\/09\/16\/14\" target=\"_blank\">CVE-2026-89775<\/a> (Linux kernel), <a href=\"https:\/\/blog.checkpoint.com\/security\/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616\/\" target=\"_blank\">CVE-2026-93616, CVE-2026-85102<\/a> (Check Point), <a href=\"https:\/\/www.arista.com\/en\/support\/advisories-notices\/security-advisory\/24765-security-advisory-0183\" target=\"_blank\">CVE-2026-93952<\/a> (Arista VeloCloud Orchestrator), <a href=\"https:\/\/research.jfrog.com\/vulnerabilities\/bifrost-is-vulnerable-to-unauthenticated-remote-code-execution-via-mcp-stdio-client-registration-cve-2026-90898\/\" target=\"_blank\">CVE-2026-90898<\/a> (Bifrost), <a href=\"https:\/\/minanagehsalalma.github.io\/zte-smartlife-app-pwned\/\" target=\"_blank\">CVE-2026-86555, CVE-2026-86554, CVE-2026-86553, CVE-2026-86552<\/a> (ZTE H188A\/H288A firmware), <a href=\"https:\/\/github.com\/vercel\/next.js\/security\/advisories\/GHSA-vcvr-r3jv-pc5j\" target=\"_blank\">CVE-2026-94545<\/a> (Next.js), <a href=\"https:\/\/supportannouncement.us.dlink.com\/security\/publication.aspx?name=SAP10516\" target=\"_blank\">CVE-2026-94127<\/a> (F5 BIG-IP Access Policy Manager), <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2026-86296\" target=\"_blank\">CVE-2026-86296<\/a>, <a href=\"https:\/\/supportannouncement.us.dlink.com\/security\/publication.aspx?name=SAP10516\" target=\"_blank\">CVE-2026-86510<\/a> (D-Link DIR-822A), <a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/articles\/43597969409943-Security-CVE-2026-87900-Vulnerability-in-WP-Toolkit-Database-Creation-September-22-2026\" target=\"_blank\">CVE-2026-87900<\/a>, <a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/articles\/43591715125271-Security-CVE-2026-87899-Vulnerability-in-cPanel-s-CalDAV-CardDAV-September-22-2026\" target=\"_blank\">CVE-2026-87899<\/a>, <a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/articles\/43502940099991-Security-CVE-2026-68490-Vulnerability-in-cPanel-s-CalDAV-CardDAV-Functionality-September-22-2026\" target=\"_blank\">CVE-2026-68490<\/a> (cPanel), <a href=\"https:\/\/kb.cert.org\/vuls\/id\/273940\" target=\"_blank\">CVE-2026-82356<\/a> (Imprivata Enterprise Access Management), <a href=\"https:\/\/kb.cert.org\/vuls\/id\/754548\" target=\"_blank\">CVE-2026-86867<\/a> (Cinnamon Kotaemon), <a href=\"https:\/\/helpx.adobe.com\/security\/security-bulletin.html\" target=\"_blank\">CVE-2026-75682, CVE-2026-75684, CVE-2026-75686, CVE-2026-75689, CVE-2026-75697, CVE-2026-75698, CVE-2026-75745, CVE-2026-81995, CVE-2026-82000<\/a> (Adobe), <a href=\"https:\/\/chromereleases.googleblog.com\/2026\/09\/stable-channel-update-for-desktop_0856730748.html\" target=\"_blank\">CVE-2026-95350, CVE-2026-95357, CVE-2026-95339, CVE-2026-95281, CVE-2026-95313, CVE-2026-95349, CVE-2026-95284, CVE-2026-95322, CVE-2026-95329, CVE-2026-95356, CVE-2026-95310<\/a> (Google Chrome), <a href=\"https:\/\/www.zerodayinitiative.com\/blog\/2026\/9\/23\/cve-2024-0244-a-heap-buffer-overflow-in-the-canon-mf753cdw-printer\" target=\"_blank\">CVE-2024-0244<\/a> (Canon MF753Cdw), <a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\" target=\"_blank\">CVE-2026-28324, CVE-2026-28325<\/a> (SolarWinds Observability Self-Hosted), <a href=\"https:\/\/www.ionix.io\/threat-center\/cve-2026-97359\/\" target=\"_blank\">CVE-2026-97359<\/a>, <a href=\"https:\/\/www.ionix.io\/threat-center\/cve-2026-97360\/\" target=\"_blank\">CVE-2026-97360<\/a> (HFS2), <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-96560\" target=\"_blank\">CVE-2026-96560<\/a> (LightLLM), <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-80145\" target=\"_blank\">CVE-2026-80145<\/a>, <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-80144\" target=\"_blank\">CVE-2026-80144<\/a>, <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-80143\" target=\"_blank\">CVE-2026-80143<\/a> (Lantronix), <a href=\"https:\/\/kb.cert.org\/vuls\/id\/234131\" target=\"_blank\">CVE-2026-82987, CVE-2026-82988, CVE-2026-82989<\/a> (ViewSonic vCast), <a href=\"https:\/\/kb.cert.org\/vuls\/id\/676317\" target=\"_blank\">CVE-2026-75907<\/a> (Norwegian Cruise Line door access controller), <a href=\"https:\/\/kb.cert.org\/vuls\/id\/699627\" target=\"_blank\">CVE-2026-18311, CVE-2026-18312, CVE-2026-18320<\/a> (Readwise Reader for Android), <a href=\"https:\/\/support.citrix.com\/support-home\/kbsearch\/article?articleNumber=CTX697096\" target=\"_blank\">CVE-2026-88771, and CVE-2026-88772<\/a> (Citrix NetScaler ADC and Gateway).<\/p>\n<h2 style=\"text-align: left;\"><strong>\ud83c\udfa5 Cybersecurity Webinars<\/strong><\/h2>\n<ul>\n<li><strong><a href=\"https:\/\/thehacker.news\/ai-agents-governance?source=recap\" target=\"_blank\">AI Agents Already Have Access. Here\u2019s How to Take Back Control<\/a> <\/strong>\u2192 AI agents are getting access to sensitive apps, data, and systems. Learn how to find hidden agents, control their access, and reduce risk before shadow AI becomes a security problem.<\/li>\n<li><strong><a href=\"https:\/\/thehacker.news\/runtime-identity-security?source=recap\" target=\"_blank\">AI Attacks Move at Machine Speed. Your Identity Security Needs to Match It<\/a><\/strong> \u2192 AI-powered attacks can move faster than traditional security teams can respond. Learn how runtime identity security helps stop risky access, privilege abuse, and threats before they spread.<\/li>\n<li><strong><a href=\"https:\/\/thehacker.news\/ai-insider-threat?source=recap\" target=\"_blank\">Your Next Insider Threat May Not Be Human<\/a> <\/strong>\u2192 AI agents can access credentials, systems, and sensitive data just like employees. Learn how to uncover these hidden insiders, understand their access, and reduce risk without slowing AI adoption.<\/li>\n<\/ul>\n<p><strong>\ud83d\udcf0 Around the Cyber World<\/strong><\/p>\n<ul>\n<li><strong>Clop Gang Moves Site After ShinyHunters Hack <\/strong>\u2014 The Clop ransomware gang moved its data leak site to a new Tor address after its previous server was compromised and defaced by ShinyHunters through an unpatched Grav CMS flaw that&#8217;s now assessed to be an unauthenticated path traversal vulnerability (<a href=\"https:\/\/github.com\/getgrav\/grav\/security\/advisories\/GHSA-hmcx-ch82-3fv2\" target=\"_blank\">CVE-2026-42608<\/a>). The vulnerability was patched by Grav in April 2026. In a statement shared with Bleeping Computer, Clop denied having any relationship or ongoing negotiations with ShinyHunters. \u00abWe do not know them, we have never worked with them, and at the moment we are not in contact with them; furthermore, we have not provided them with any information, nor will we do so \u2013 either now or in the future,\u00bb the group was <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/shinyhunters-hacked-clop-leak-site-using-grav-cms-path-traversal-flaw\/\" target=\"_blank\">quoted<\/a> as saying. The development comes in the aftermath of ShinyHunters seizing the FBI&#8217;s FBIjobs.gov portal by what it said was a new zero-day in Oracle PeopleSoft.<\/li>\n<li><strong>Konni Targets Ukraine with Malicious LNK Lures <\/strong>\u2014 The North Korean threat group known as Konni has been observed using ZIP archives with malicious LNK files masquerading as PDF documents as lures in spear-phishing attacks targeting Ukraine-focused individuals and organizations to deliver a malware called VelvetCake as part of a campaign codenamed Operation Conflict Compass. The LNK file launches a VBScript that establishes persistence via a scheduled task, and triggers a PowerShell script to run every minute. The invoked PowerShell payload functions as a modular downloader designed to fetch and execute secondary server-side scripts. \u00abVelvetCake embeds no fixed post-exploitation capability set locally. It operates as a lightweight task runner that continuously retrieves and executes server-side PowerShell modules, allowing operators to modify functionality without redeploying the core payload,\u00bb SOCRadar <a href=\"https:\/\/socradar.io\/blog\/operation-conflict-compass-konni-ukraine-lnk-lure\/\" target=\"_blank\">said<\/a>. \u00abThe campaign likely aimed to gather intelligence on the trajectory of the Russian invasion to gauge the medium-term outlook of the war.\u00bb<\/li>\n<li><strong>Kimsuky Conducts Git-Based C2 Attacks <\/strong>\u2014 In more North Korea-related malicious activity, the Kimsuky group has <a href=\"https:\/\/www.genians.co.kr\/en\/blog\/threat_intelligence\/ai-agent-opencode?hsCtaAttrib=392306999998\" target=\"_blank\">resorted<\/a> to conducting Git-based C2 attacks through malicious LNK files contained within ZIP archives. The activity has been dubbed Operation GitPower. The LNK files use filenames disguised as documents related to financial and corporate operations, including fund disbursement, insurance premiums, interest payments, policy funds, certificate renewal, store master data, customer documents, and Visa payments. These documents are said to have been mass-produced using AI models, spotlighting a trend where the threat actor has used local large language models (LLMs) using Ollama, GPT4All, and Msty to prepare attacks and create decoys. The LNK files serve as delivery vectors for follow-on PowerShell commands retrieved from GitHub Raw Content paths using a GitHub PAT. Select variants have also been observed using Pastebin as an alternative channel. The PowerShell code sets persistence, exfiltrates system information to GitHub, and takes steps to erase itself and the PowerShell command history file.<\/li>\n<li><strong>CISA Flags TeamCity Flaw as Exploited in Ransomware Attacks <\/strong>\u2014 CISA confirmed that ransomware gangs are exploiting a critical JetBrains TeamCity vulnerability patched in July. The flaw, <a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search=CVE-2026-63077&amp;field_date_added_wrapper=all&amp;field_cve=&amp;sort_by=field_date_added&amp;items_per_page=20&amp;url=\" target=\"_blank\">CVE-2026-63077<\/a>, is a critical authentication bypass vulnerability that lets attackers with HTTP(S) access execute arbitrary operating system commands. \u00abAn unauthenticated attacker could exploit the vulnerability via the TeamCity agent polling protocol to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process,\u00bb JetBrains said. It&#8217;s currently not known which ransomware group is behind the exploitation activity.<\/li>\n<li><strong>DeepMind Gives Private AI Compute a Secure, Server-Side Memory <\/strong>\u2014 Google has announced plans to bring a private, server-side memory to its Private AI Compute platform, giving AI systems long-term continuity across devices without sacrificing privacy. \u00abWith this new technical capability, a new persistent memory layer will be able to function like a secure digital vault in the cloud,\u00bb Google DeepMind <a href=\"https:\/\/deepmind.google\/blog\/advancing-private-ai-compute-with-secure-server-side-memory\/\" target=\"_blank\">said<\/a>. \u00abUnder this model, the information needed to assist you is sealed within dedicated, encrypted storage, while the cryptographic keys required to unlock it are held exclusively on your personal devices \u2014 ensuring your data is inaccessible to anyone else, even Google.\u00bb<\/li>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiEdyGoXucWMfWEdeY0o5vEzJKY5z4uZ5C0ybPqgR0fDsLpCd6I-1sm4cd86v54sDhjToVCVVYl5I5Foopk6YSCkDmUQ1uG74_nrqjBL2AoeeS1nmzi_2Vc0v4_J1hjzlgAyXyI14q49ZfgugxwHRa5Ecp2e4EoGkWgp0F2OsoMyak3ZWT43ZaaPRBREX0g\/s1700-nu-rw-lo-l85-e365\/1.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiEdyGoXucWMfWEdeY0o5vEzJKY5z4uZ5C0ybPqgR0fDsLpCd6I-1sm4cd86v54sDhjToVCVVYl5I5Foopk6YSCkDmUQ1uG74_nrqjBL2AoeeS1nmzi_2Vc0v4_J1hjzlgAyXyI14q49ZfgugxwHRa5Ecp2e4EoGkWgp0F2OsoMyak3ZWT43ZaaPRBREX0g\/s1700-nu-rw-lo-l85-e365\/1.jpg\" alt=\"\" border=\"0\" data-original-height=\"848\" data-original-width=\"1612\"\/><\/a><\/div>\n<li><strong>SectopRAT Hides Inside Legitimate Application <\/strong>\u2014 A new campaign has been observed delivering <a href=\"https:\/\/blog.gdatasoftware.com\/2021\/02\/36633-new-version-adds-encrypted-communication\" target=\"_blank\">SectopRAT<\/a> by concealing it within a legitimate program developed by an Italian digital-audio company. It&#8217;s suspected that the operators added the malware after the application was installed on customer systems rather than compromising the vendor itself. \u00ab<a href=\"https:\/\/www.elastic.co\/security-labs\/threat-command\/a-wretch-client\" target=\"_blank\">SectopRAT<\/a> (also known as ArechClient2) is a .NET-based remote access trojan (RAT) that provides a range of functions through multiple control commands,\u00bb Fortinet <a href=\"https:\/\/www.fortinet.com\/blog\/threat-research\/uncovering-a-sectoprat-variant-embedded-in-legitimate-software\" target=\"_blank\">said<\/a>. \u00abThese include collecting sensitive data from the victim\u2019s device, capturing screens, remotely managing processes and files, controlling bots, and other forms of remote device management.\u00bb<\/li>\n<li><strong>Armenian National Sentenced to 2 Years for Ryuk Ransomware Attacks <\/strong>\u2014 Karen Serobovich Vardanyan, 34, who was extradited from Ukraine to the U.S. in June 2025, has been <a href=\"https:\/\/www.justice.gov\/usao-or\/pr\/armenian-national-extradited-united-states-sentenced-federal-prison-ransomware-extortion\" target=\"_blank\">sentenced to 24 months in federal prison<\/a> and 3 years&#8217; supervised release. In July 2026, Vardanyan <a href=\"https:\/\/www.justice.gov\/usao-or\/pr\/armenian-national-extradited-united-states-pleads-guilty-ransomware-extortion-conspiracy\" target=\"_blank\">pleaded guilty<\/a> to conspiracy and computer fraud for his role in Ryuk ransomware attacks and an extortion conspiracy targeting companies across the U.S. \u00abBetween November 2019 through April 2020, Vardanyan illegally accessed computer networks of victim companies to deploy Ryuk ransomware on compromised servers and workstations,\u00bb the U.S. Justice Department <a href=\"https:\/\/www.justice.gov\/usao-or\/pr\/armenian-national-extradited-united-states-pleads-guilty-ransomware-extortion-conspiracy\" target=\"_blank\">said<\/a>. \u00abRyuk ransomware is a type of malicious software designed to encrypt data on a victim&#8217;s computer or network and prevents the victim from accessing the encrypted files until a ransom is paid. Vardanyan worked with his co-conspirators to attack a company in Michigan that paid 200 bitcoin, or over $1.1 million at the time of payment, to restore access to their network. They also attacked a company in Wilsonville, Oregon, and in February 2020 attacked a school in Texas.\u00bb Vardanyan and his co-conspirators are said to have illegally accessed computer networks of victim companies and deployed ransomware on hundreds of compromised servers and workstations, receiving over $15 million in illicit proceeds at that time. Vardanyan has also been ordered to pay over $1.21 million in restitution.<\/li>\n<li><strong>Scattered Spider Member Gets 45-Month Prison Sentence for Cybercrime Spree <\/strong>\u2014 Ahmed Hossam Eldin Elbadawy, of Texas, who admitted to being a member of the notorious cybercrime group Scattered Spider, has been <a href=\"https:\/\/www.bankinfosecurity.com\/texan-scattered-spider-member-receives-45-month-sentence-a-32905\" target=\"_blank\">sentenced to 45 months in prison<\/a>. Following that, Elbadawy will face a three-year parole and is prohibited \u00abfrom using privacy-based blockchain virtual currencies\u00bb without prior approval. Elbadawy was charged in November 2024 along with four other defendants.<\/li>\n<li><strong>Using Rogue External MFA Provider to Steal Passwords <\/strong>\u2014 Varonis has demonstrated a new attack technique called TrustSink which turns a rogue external MFA provider into a \u00abpersistent credential trap\u00bb within a legitimate sign-in flow. \u00abAn attacker with high privileges can register a rogue External Authentication Method (EAM) and place a convincing password page inside the legitimate sign-in flow,\u00bb Varonis <a href=\"https:\/\/www.varonis.com\/blog\/trustsink\" target=\"_blank\">said<\/a>. \u00abThe page captures the password in plaintext while the provider returns a valid signed token, completing the login without an error. Resetting a captured password did not remove the rogue provider. It remained in the authentication flow and captured the replacement password at the user&#8217;s next sign-in.\u00bb TrustSink builds on previous research by <a href=\"https:\/\/www.youtube.com\/watch?v=eKFgOtNpxwU\" target=\"_blank\">security researcher Dirk-Jan Mollema<\/a>, who found that a rogue registered EAM provider can be used to bypass MFA by returning a signed JWT without performing a real authentication check.<\/li>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjRDFSWP5vE9CnQXC7Ns3ofiYt0Ps7je5BvZuhLc15e7zw6bDPWIgdLvg7JoYRKg2P32oV0YGPhxbqanU2jqfqSkfUYEswtxYMk99Cd8khdAOmVmxbES3yQDLRd6lRyihIrTuzFDM-D4XVHZ7WxwoBMf8h-_UO6nmLI0NZYmGMlLfeXgFxQ47zF9hzYF0-5\/s1700-nu-rw-lo-l85-e365\/trust.png\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjRDFSWP5vE9CnQXC7Ns3ofiYt0Ps7je5BvZuhLc15e7zw6bDPWIgdLvg7JoYRKg2P32oV0YGPhxbqanU2jqfqSkfUYEswtxYMk99Cd8khdAOmVmxbES3yQDLRd6lRyihIrTuzFDM-D4XVHZ7WxwoBMf8h-_UO6nmLI0NZYmGMlLfeXgFxQ47zF9hzYF0-5\/s1700-nu-rw-lo-l85-e365\/trust.png\" alt=\"\" border=\"0\" data-original-height=\"1458\" data-original-width=\"1440\"\/><\/a><\/div>\n<li><strong>New x47.c Botnet Drains AI API Credits <\/strong>\u2014 A previously undocumented Windows botnet dubbed x47.c has been advertised as capable of supporting 18 DDoS attack methods, browser credential theft, SOCKS5 proxies, and an AI module that uses SpaceXAI Grok to establish persistence on infected machines based on the current state. It&#8217;s sold by a threat actor named WraithTools for a $200 base package with a $150 DDoS add-on. The entire toolset costs $950. \u00abOne of the advertised methods, &#8216;AI API drain,&#8217; is designed to exhaust a victim&#8217;s paid AI credits,\u00bb Qrator Research Labs <a href=\"https:\/\/qrator.net\/blog\/details\/x47.c-botnet\" target=\"_blank\">said<\/a>. \u00abUsing a valid API key, an operator can send repeated requests that consume the account\u2019s balance or increase its bill. The AI drain command starts with a valid API key for the account being targeted. Because those requests go straight to the provider, they do not need to pass through the victim\u2019s application. The website can remain reachable while the account behind its AI features runs out of credits. If the provider rejects further requests once the account balance is exhausted or an enforced limit is reached, legitimate users lose access to those features.\u00bb<\/li>\n<li><strong>Hundreds of Leaked GitHub App Keys Still Active <\/strong>\u2014 A new analysis from GitGuardian has found that hundreds of GitHub App private keys leaked in public code still work. From over 500,000 exposed RSA keys, 474 have been found to authenticate as 440 distinct Apps on GitHub&#8217;s API. \u00ab72% of the compromised Apps had some content permissions, meaning that they could access private repositories of the organizations that use them,\u00bb GitGuardian <a href=\"https:\/\/blog.gitguardian.com\/github-app-private-keys-leaked\/\" target=\"_blank\">said<\/a>. \u00bb 207 of them have content write permissions and can modify those repositories. Even worse, 44 Apps have organization administration privileges, 40 can administer self-hosted runners, and 98 can control workflows. Those permissions could allow a complete takeover of the target organization, or code execution on its internal infrastructure, with or without further supply-chain compromise.\u00bb<\/li>\n<\/ul>\n<h2 style=\"text-align: left;\"><strong>Conclusion<\/strong><\/h2>\n<p>The common thread this week was not sophistication. It was neglect. Forgotten accounts, stale assumptions, old flaws, exposed services, and tooling that keeps getting more capable faster than the controls around it.<\/p>\n<p>That is usually how these weeks land: the dramatic stories get attention, but the quieter failures keep doing the real work underneath. The patch nobody rushed, the identity nobody owned, the placeholder nobody questioned, the service nobody hardened.<\/p>\n<p>That\u2019s it for this week. Patch the obvious stuff, check the forgotten stuff, and assume somebody else already noticed it too.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Sep 28, 2026Cybersecurity News \/ Hacking A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That&hellip;<\/p>\n","protected":false},"author":1,"featured_media":3202,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[3564,335,764,143,430,637,3565,3566],"class_list":["post-3201","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-387m","tag-agents","tag-citrix","tag-crypto","tag-exploits","tag-hack","tag-offscript","tag-threats"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3201","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3201"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3201\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/3202"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3201"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3201"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3201"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}