Ticker feed
Microsoft and law enforcement pulled off something new this week — dismantling two criminal hacking tools simultaneously instead of one at a time. Working under Europol's Operation Endgame alongside ESET, IBM X-Force, Proofpoint, BitSight, Lumen and police forces in Germany, the Netherlands and Denmark, they took down more than 200 command-and-control servers linked to Amadey and StealC. Europol puts the wider operation's haul at 326 servers.
The two tools are commonly used together: Amadey delivers malware, StealC steals passwords, crypto wallets and personal data. In just the first week of May, they infected over 140,000 computers globally. The operation also recovered roughly 27 million stolen credentials.
Microsoft says its Copilot AI helped lawyers connect both threats as a single criminal conspiracy under the RICO Act — a strategy it plans to expand.
Source: CyberScoop
Microsoft and law enforcement pulled off something new this week — dismantling two criminal hacking tools simultaneously instead of one at a time. Working under Europol's Operation Endgame alongside ESET, IBM X-Force, Proofpoint, BitSight, Lumen and police forces in Germany, the Netherlands and Denmark, they took down more than 200 command-and-control servers linked to Amadey and StealC. Europol puts the wider operation's haul at 326 servers.
The two tools are commonly used together: Amadey delivers malware, StealC steals passwords, crypto wallets and personal data. In just the first week of May, they infected over 140,000 computers globally. The operation also recovered roughly 27 million stolen credentials.
Microsoft says its Copilot AI helped lawyers connect both threats as a single criminal conspiracy under the RICO Act — a strategy it plans to expand.
Source: CyberScoop
A high-severity Android zero-day, CVE-2025-48595 (CVSS 8.4), is being actively exploited in targeted attacks — no user interaction required. Disclosed in Google's June 2026 Android Security Bulletin, the integer overflow in the Android Framework gives an attacker who already has code running on the device local privilege escalation, bypassing core security boundaries to reach sensitive system resources. Chained with other exploits, that becomes full device compromise.
Devices running Android 14, 15, 16 and 16 QPR2 are all affected. Patch level 2026-06-05 fixes the issue, and Google notified OEM partners over a month ahead of public disclosure. CISA added the flaw to its Known Exploited Vulnerabilities catalog on June 2.
Update immediately. Sideloaders face the highest risk, since third-party app channels are exactly how the attacker's code gets on the device in the first place.
Source: Cybersecurity News
A high-severity Android zero-day, CVE-2025-48595 (CVSS 8.4), is being actively exploited in targeted attacks — no user interaction required. Disclosed in Google's June 2026 Android Security Bulletin, the integer overflow in the Android Framework gives an attacker who already has code running on the device local privilege escalation, bypassing core security boundaries to reach sensitive system resources. Chained with other exploits, that becomes full device compromise.
Devices running Android 14, 15, 16 and 16 QPR2 are all affected. Patch level 2026-06-05 fixes the issue, and Google notified OEM partners over a month ahead of public disclosure. CISA added the flaw to its Known Exploited Vulnerabilities catalog on June 2.
Update immediately. Sideloaders face the highest risk, since third-party app channels are exactly how the attacker's code gets on the device in the first place.
Source: Cybersecurity News
A severe vulnerability chain in Splunk Enterprise is letting unauthenticated attackers execute remote code, no login required. Tracked as CVE-2026-20253 with a CVSS score of 9.8, the flaw targets the PostgreSQL Sidecar Service in Splunk Enterprise 10.0.0–10.0.6 and 10.2.0–10.2.3. Versions 9.4 and earlier, and Splunk Cloud Platform, are not affected.
The sidecar is active by default on AWS deployments, making those installations immediately exposed; on-premises deployments don't enable it by default. Researchers at watchTowr Labs found attackers can send crafted HTTP requests to internal API endpoints, manipulate file paths, inject malicious database connections, and ultimately overwrite Python scripts to run arbitrary commands. A non-weaponised proof of concept is already public.
Splunk has patched it in 10.0.7 and 10.2.4 — AWS users should prioritise updating immediately. If you can't patch yet, the sidecar can be disabled with [postgres] disabled = true in server.conf, but that breaks Edge Processor, OpAmp and SPL2 pipelines, so check what you're running first. Either way, Splunk Web on port 8000 shouldn't be reachable from the internet.
Updated 12 Aug 2026: Splunk updated its advisory on 18 June to warn of active exploitation in the wild, and CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day.
Source: Cybersecurity News
A severe vulnerability chain in Splunk Enterprise is letting unauthenticated attackers execute remote code, no login required. Tracked as CVE-2026-20253 with a CVSS score of 9.8, the flaw targets the PostgreSQL Sidecar Service in Splunk Enterprise 10.0.0–10.0.6 and 10.2.0–10.2.3. Versions 9.4 and earlier, and Splunk Cloud Platform, are not affected.
The sidecar is active by default on AWS deployments, making those installations immediately exposed; on-premises deployments don't enable it by default. Researchers at watchTowr Labs found attackers can send crafted HTTP requests to internal API endpoints, manipulate file paths, inject malicious database connections, and ultimately overwrite Python scripts to run arbitrary commands. A non-weaponised proof of concept is already public.
Splunk has patched it in 10.0.7 and 10.2.4 — AWS users should prioritise updating immediately. If you can't patch yet, the sidecar can be disabled with [postgres] disabled = true in server.conf, but that breaks Edge Processor, OpAmp and SPL2 pipelines, so check what you're running first. Either way, Splunk Web on port 8000 shouldn't be reachable from the internet.
Updated 12 Aug 2026: Splunk updated its advisory on 18 June to warn of active exploitation in the wild, and CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day.
Source: Cybersecurity News
A well-known hacking group has breached the University of Nottingham's systems, accessing "a significant amount of data" — including financial information — belonging to current students and alumni. The university confirmed the attack on 10 June and has since set up a helpline, notified police, and alerted the Information Commissioner's Office, the Office for Students and Action Fraud.
Students and graduates are rattled. Incoming law student Tolu Olufunwa, 17, said the news left her "scared" and wondering whether she had made the right decision, though she is still planning to start in September. Graduate Jacob Edwards, 23, criticised the university's communication as "so little and vague." Former applicant Margaret Ladipo, 19, has already changed her bank details and passwords after her national insurance number was caught up in the breach.
Source: BBC News
A well-known hacking group has breached the University of Nottingham's systems, accessing "a significant amount of data" — including financial information — belonging to current students and alumni. The university confirmed the attack on 10 June and has since set up a helpline, notified police, and alerted the Information Commissioner's Office, the Office for Students and Action Fraud.
Students and graduates are rattled. Incoming law student Tolu Olufunwa, 17, said the news left her "scared" and wondering whether she had made the right decision, though she is still planning to start in September. Graduate Jacob Edwards, 23, criticised the university's communication as "so little and vague." Former applicant Margaret Ladipo, 19, has already changed her bank details and passwords after her national insurance number was caught up in the breach.
Source: BBC News
The ShinyHunters extortion gang exploited a critical zero-day vulnerability in Oracle's PeopleSoft software between May 27 and June 9, 2026, compromising more than 300 instances. The flaw, CVE-2026-35273 (CVSS 9.8), allowed unauthenticated remote code execution through PeopleSoft's Environment Management Hub service.
Mandiant and Google Threat Intelligence Group spotted the campaign and contacted more than 100 at-risk organisations, about 68% of them higher education institutions and most in the US. The University of Nottingham confirmed a breach, with ShinyHunters claiming more than 40 GB of sensitive data taken from its student records.
Oracle pushed an out-of-band patch on June 10, the day after being alerted. Organisations should disable the EMHub service or block external access to it immediately — researchers note doing so doesn't break PeopleSoft's core functionality.
Source: Dark Reading
The ShinyHunters extortion gang exploited a critical zero-day vulnerability in Oracle's PeopleSoft software between May 27 and June 9, 2026, compromising more than 300 instances. The flaw, CVE-2026-35273 (CVSS 9.8), allowed unauthenticated remote code execution through PeopleSoft's Environment Management Hub service.
Mandiant and Google Threat Intelligence Group spotted the campaign and contacted more than 100 at-risk organisations, about 68% of them higher education institutions and most in the US. The University of Nottingham confirmed a breach, with ShinyHunters claiming more than 40 GB of sensitive data taken from its student records.
Oracle pushed an out-of-band patch on June 10, the day after being alerted. Organisations should disable the EMHub service or block external access to it immediately — researchers note doing so doesn't break PeopleSoft's core functionality.
Source: Dark Reading
GitHub is overhauling npm with version 12, flipping three long-standing permissive defaults to fight software supply chain attacks. Starting July 2026, npm will block install scripts, Git dependencies and remote URL packages by default — all requiring explicit developer opt-in. Upgrade to npm 11.16.0 now to preview, then run the new npm approve-scripts command to see which of your dependencies will break and build an allowlist before the deadline.
Security experts are cautiously supportive. Semgrep's Isaac Evans praised the structural approach but warned attackers will pivot to the next trusted layer, naming Artifactory and Nexus. Researcher Paul McCarty welcomed closing the defaults but fears developers will "simply blind-approve blocked scripts" to get builds working, since "this builds" always wins — which would leave the security benefit on paper only.
Source: Infosecurity Magazine
GitHub is overhauling npm with version 12, flipping three long-standing permissive defaults to fight software supply chain attacks. Starting July 2026, npm will block install scripts, Git dependencies and remote URL packages by default — all requiring explicit developer opt-in. Upgrade to npm 11.16.0 now to preview, then run the new npm approve-scripts command to see which of your dependencies will break and build an allowlist before the deadline.
Security experts are cautiously supportive. Semgrep's Isaac Evans praised the structural approach but warned attackers will pivot to the next trusted layer, naming Artifactory and Nexus. Researcher Paul McCarty welcomed closing the defaults but fears developers will "simply blind-approve blocked scripts" to get builds working, since "this builds" always wins — which would leave the security benefit on paper only.
Source: Infosecurity Magazine
South Korea has hit e-commerce giant Coupang with fines totalling more than $400 million over a 2025 data breach that exposed personal information belonging to roughly 37.5 million users — more than half the country's population. Seoul's Personal Information Protection Commission issued 423.6bn won over the breach itself, plus a further 201bn won for collecting data without user consent, after finding the company failed to properly manage authentication signing keys and access controls.
Exposed data included names, contact and delivery details, and order histories. Coupang was alerted to a breach involving 4,500 accounts in November 2025 and reported it immediately; its own later checks put the figure at nearly 34 million South Korean accounts, and it believes the intrusion began as early as June 2025 through a server based abroad.
CEO Park Dae-jun resigned after the incident, with chief administrative officer Harold Rogers stepping in as interim. Coupang says its explanations "were not sufficiently reflected" in the ruling and plans to fight it in court.
Source: BBC News
South Korea has hit e-commerce giant Coupang with fines totalling more than $400 million over a 2025 data breach that exposed personal information belonging to roughly 37.5 million users — more than half the country's population. Seoul's Personal Information Protection Commission issued 423.6bn won over the breach itself, plus a further 201bn won for collecting data without user consent, after finding the company failed to properly manage authentication signing keys and access controls.
Exposed data included names, contact and delivery details, and order histories. Coupang was alerted to a breach involving 4,500 accounts in November 2025 and reported it immediately; its own later checks put the figure at nearly 34 million South Korean accounts, and it believes the intrusion began as early as June 2025 through a server based abroad.
CEO Park Dae-jun resigned after the incident, with chief administrative officer Harold Rogers stepping in as interim. Coupang says its explanations "were not sufficiently reflected" in the ruling and plans to fight it in court.
Source: BBC News
A researcher known as Nightmare-Eclipse has released yet another Microsoft zero-day exploit — this one called RoguePlanet — timed to drop right after Microsoft's June Patch Tuesday, which addressed a record 206 CVEs.
The new exploit abuses a race condition in Windows Defender's signature update workflow and, when it lands, spawns a shell with full SYSTEM privileges on Windows 10 and 11. It's unreliable by the researcher's own account — hit or miss — and doesn't work on Windows Server, though he claims a redesigned version would.
It's the latest salvo in a months-long feud that began in April with BlueHammer (CVE-2026-33825). Microsoft patched that one within the month and attackers exploited it anyway; there's no sign yet of RoguePlanet being used in the wild.
The researcher claims to have more vulnerabilities in Defender and other Windows components ready to go.
Updated 12 Aug 2026: RoguePlanet was assigned CVE-2026-50656 and patched by Microsoft in July, 29 days after the public exploit appeared.
Source: Dark Reading
A researcher known as Nightmare-Eclipse has released yet another Microsoft zero-day exploit — this one called RoguePlanet — timed to drop right after Microsoft's June Patch Tuesday, which addressed a record 206 CVEs.
The new exploit abuses a race condition in Windows Defender's signature update workflow and, when it lands, spawns a shell with full SYSTEM privileges on Windows 10 and 11. It's unreliable by the researcher's own account — hit or miss — and doesn't work on Windows Server, though he claims a redesigned version would.
It's the latest salvo in a months-long feud that began in April with BlueHammer (CVE-2026-33825). Microsoft patched that one within the month and attackers exploited it anyway; there's no sign yet of RoguePlanet being used in the wild.
The researcher claims to have more vulnerabilities in Defender and other Windows components ready to go.
Updated 12 Aug 2026: RoguePlanet was assigned CVE-2026-50656 and patched by Microsoft in July, 29 days after the public exploit appeared.
Source: Dark Reading
A malware incident on the ICT network at Great Marlow School in Buckinghamshire led staff to shut down parts of the system as a precaution, closing the school to most pupils on Wednesday 10 June. The school can't contact parents and carers through its usual email system, teachers can't set work, and internal exams for Years 10 and 12 have been postponed. Only Year 11 and 13 students are in, for external exams.
The school says it is working with cybersecurity professionals to restore normal operations, following guidance from the Department for Education and the National Cyber Security Centre. Headteacher Guy Pendlebury said the safety and wellbeing of students, staff and the wider school community "remain our highest priority at all times." The school, famously attended by Olympic rower Steve Redgrave, also cancelled a Year 7 rowing lesson.
Source: BBC News
A malware incident on the ICT network at Great Marlow School in Buckinghamshire led staff to shut down parts of the system as a precaution, closing the school to most pupils on Wednesday 10 June. The school can't contact parents and carers through its usual email system, teachers can't set work, and internal exams for Years 10 and 12 have been postponed. Only Year 11 and 13 students are in, for external exams.
The school says it is working with cybersecurity professionals to restore normal operations, following guidance from the Department for Education and the National Cyber Security Centre. Headteacher Guy Pendlebury said the safety and wellbeing of students, staff and the wider school community "remain our highest priority at all times." The school, famously attended by Olympic rower Steve Redgrave, also cancelled a Year 7 rowing lesson.
Source: BBC News
Two Russia-linked hacker groups — Gamaredon and Shadow-Earth-066 — are actively exploiting a WinRAR vulnerability (CVE-2025-8088) that WinRAR patched in version 7.13 back in July 2025, targeting Ukrainian military and government organizations through weaponized phishing emails. Trend Micro, which tracks the campaigns, notes Sandworm, Turla and Void Rabisu have weaponized the same flaw.
The attacks differ in execution but share the same goal. Shadow-Earth-066 deploys the GiftedCrook stealer to harvest credentials, browser cookies and documents, while Gamaredon spear-phishes from compromised government accounts to plant espionage malware via malicious HTA files. Both abuse the path traversal flaw to write payloads into Windows Startup folders using NTFS alternate data streams.
The flaw stays dangerous because WinRAR doesn't auto-update, doesn't support Group Policy, and falls outside tools like WSUS and SCCM — leaving millions of endpoints exposed. Version 7.13 or later fixes it.
Source: Dark Reading
Two Russia-linked hacker groups — Gamaredon and Shadow-Earth-066 — are actively exploiting a WinRAR vulnerability (CVE-2025-8088) that WinRAR patched in version 7.13 back in July 2025, targeting Ukrainian military and government organizations through weaponized phishing emails. Trend Micro, which tracks the campaigns, notes Sandworm, Turla and Void Rabisu have weaponized the same flaw.
The attacks differ in execution but share the same goal. Shadow-Earth-066 deploys the GiftedCrook stealer to harvest credentials, browser cookies and documents, while Gamaredon spear-phishes from compromised government accounts to plant espionage malware via malicious HTA files. Both abuse the path traversal flaw to write payloads into Windows Startup folders using NTFS alternate data streams.
The flaw stays dangerous because WinRAR doesn't auto-update, doesn't support Group Policy, and falls outside tools like WSUS and SCCM — leaving millions of endpoints exposed. Version 7.13 or later fixes it.
Source: Dark Reading