Cyberattacks
A new exploit kit called BlueMoon is letting espionage groups chain Chrome and Windows flaws to plant backdoors on government, defense, and commercial targets. Proofpoint counted four clusters using it since late August 2026, most suspected of a China nexus, though some use is unattributed and the kit may not be exclusive to Chinese actors.
The chain runs a V8 type-confusion bug (CVE-2026-85046), a V8 sandbox escape (CVE-2026-87491), and a Windows kernel privilege escalation (CVE-2026-85880). Both Chrome flaws were patch-gap zero-days, fixed in public Chromium source but missing from stable releases. That gap has since closed, with the V8 fix reaching stable Chromium on September 3.
Exposure is narrower than it sounds. The privilege escalation only fires on older Windows builds, which Proofpoint says substantially cuts the pool of viable targets, and successful exploitation ends in a plain curl command that leaves endpoint tools plenty to catch. Circumstantial signs point to AI-assisted development, including verbose debugging comments and a markdown handover file of the kind coding agents leave behind.
TA412, also known as APT31, posed as students seeking internships and conference organizers to reach US NGOs, mining firms, and commodity traders, then installed a surveillance extension disguised as Google Gemini across Chrome, Edge, Brave, and Vivaldi. How four groups obtained the same kit is unknown. Proofpoint expects the technique to reach financially motivated actors too.
Source: Cybersecurity News
A new exploit kit called BlueMoon is letting espionage groups chain Chrome and Windows flaws to plant backdoors on government, defense, and commercial targets. Proofpoint counted four clusters using it since late August 2026, most suspected of a China nexus, though some use is unattributed and the kit may not be exclusive to Chinese actors.
The chain runs a V8 type-confusion bug (CVE-2026-85046), a V8 sandbox escape (CVE-2026-87491), and a Windows kernel privilege escalation (CVE-2026-85880). Both Chrome flaws were patch-gap zero-days, fixed in public Chromium source but missing from stable releases. That gap has since closed, with the V8 fix reaching stable Chromium on September 3.
Exposure is narrower than it sounds. The privilege escalation only fires on older Windows builds, which Proofpoint says substantially cuts the pool of viable targets, and successful exploitation ends in a plain curl command that leaves endpoint tools plenty to catch. Circumstantial signs point to AI-assisted development, including verbose debugging comments and a markdown handover file of the kind coding agents leave behind.
TA412, also known as APT31, posed as students seeking internships and conference organizers to reach US NGOs, mining firms, and commodity traders, then installed a surveillance extension disguised as Google Gemini across Chrome, Edge, Brave, and Vivaldi. How four groups obtained the same kit is unknown. Proofpoint expects the technique to reach financially motivated actors too.
Source: Cybersecurity News
KnowBe4 published research on September 4 into a phishing campaign still running in the wild, and the trick sits in the link. Rather than hide a malicious URL and hope the gateway misses it, the operators built a three-hop redirect chain from Google's own services, so every hop an inspector checks resolves to a domain it already trusts.
The services named include Google Meet, DoubleClick, Custom Search, Image Search, Tag Manager, and Analytics. What waits at the end varies: some victims get a fake corporate login page, others a fake identity verification prompt that quietly installs ScreenConnect for remote access.
The login page is the more inventive half. JavaScript builds it on the fly from the victim's email address alone, sets a live screenshot of their real corporate website behind it, and localizes the interface to their location. Credentials reach the operator's Telegram channel within seconds, along with the victim's IP, geolocation, browser string, and their organization's verified MX records.
KnowBe4 wants the IOCs blocked at DNS filter, proxy, and SIEM level now, Telegram bot API traffic hunted, unauthorized ScreenConnect installs checked, and credential resets forced for anyone who may have received a lure. An email address after the # in a URL signals a pre-targeted link, though it is base64-encoded, so nobody will spot one by eye.
Source: Dark Reading
KnowBe4 published research on September 4 into a phishing campaign still running in the wild, and the trick sits in the link. Rather than hide a malicious URL and hope the gateway misses it, the operators built a three-hop redirect chain from Google's own services, so every hop an inspector checks resolves to a domain it already trusts.
The services named include Google Meet, DoubleClick, Custom Search, Image Search, Tag Manager, and Analytics. What waits at the end varies: some victims get a fake corporate login page, others a fake identity verification prompt that quietly installs ScreenConnect for remote access.
The login page is the more inventive half. JavaScript builds it on the fly from the victim's email address alone, sets a live screenshot of their real corporate website behind it, and localizes the interface to their location. Credentials reach the operator's Telegram channel within seconds, along with the victim's IP, geolocation, browser string, and their organization's verified MX records.
KnowBe4 wants the IOCs blocked at DNS filter, proxy, and SIEM level now, Telegram bot API traffic hunted, unauthorized ScreenConnect installs checked, and credential resets forced for anyone who may have received a lure. An email address after the # in a URL signals a pre-targeted link, though it is base64-encoded, so nobody will spot one by eye.
Source: Dark Reading
Everett City Hall has been closed to the public since Tuesday, September 8, after the city discovered a cybersecurity incident on its internal network on Sunday night. Officials still haven't said what kind of incident it was or how far it reached, and the doors stay shut through Thursday, September 10.
Business has moved rather than stopped. Nine departments, from the Treasurer to Inspectional Services, are operating out of the Connolly Center from 9 to 5 on both closure days, with 311 taking questions. Police, fire, public works, schools, and libraries are unaffected.
Online bill payments also still work, though only because they run on third-party systems rather than the city's own network. What Everett hosts internally is what went down, and Mayor Robert J. Van Campen says IT staff and investigators are working around the clock to restore it.
Everett is at least the second Massachusetts case this week, after Springfield Public Schools canceled classes Tuesday. Cynthia Kaiser, formerly of the FBI's Cyber Division, says local government makes an easy mark because agencies each run thin IT teams, and that patching a known flaw is an emergency, not maintenance
Source: CBS News Boston
Everett City Hall has been closed to the public since Tuesday, September 8, after the city discovered a cybersecurity incident on its internal network on Sunday night. Officials still haven't said what kind of incident it was or how far it reached, and the doors stay shut through Thursday, September 10.
Business has moved rather than stopped. Nine departments, from the Treasurer to Inspectional Services, are operating out of the Connolly Center from 9 to 5 on both closure days, with 311 taking questions. Police, fire, public works, schools, and libraries are unaffected.
Online bill payments also still work, though only because they run on third-party systems rather than the city's own network. What Everett hosts internally is what went down, and Mayor Robert J. Van Campen says IT staff and investigators are working around the clock to restore it.
Everett is at least the second Massachusetts case this week, after Springfield Public Schools canceled classes Tuesday. Cynthia Kaiser, formerly of the FBI's Cyber Division, says local government makes an easy mark because agencies each run thin IT teams, and that patching a known flaw is an emergency, not maintenance
Source: CBS News Boston
North Korea's Kimsuky group turned to opencode, an open-source AI coding agent, to mass-produce the decoy documents behind its latest phishing run. Speed came at the cost of care. Genians counted placeholder text for payment dates, grace periods, and interest rates surviving into the files that shipped, nine times over, which is what gave the tool away.
What reaches the inbox is handled far more carefully. Genians examined 13 shortcut files sent in ZIP archives between August 11 and 19, 2026, aimed at Korean financial and corporate staff, each wearing a Chrome icon over a forged "Hangul Document" property. Open one and PowerShell runs behind 5,800 to 9,500 characters of arguments, held out of sight by roughly 300 leading spaces.
From there the loader reaches GitHub Raw with a hardcoded access token, then registers a hidden scheduled task misspelled to pass for BitLocker, MATLAB, or .NET before deleting itself. Three samples never fetch a decoy and open a 16-byte error file instead, which looks like a failed attack. Persistence and payload retrieval run anyway.
That is why document quality settles nothing. Genians points defenders at the shortcut itself: a chrome.exe icon over a PowerShell target, randomly named scripts written into AppData and executed on the spot, and scheduled tasks carrying slight misspellings or long strings of digits.
Source: Cyber Security News
North Korea's Kimsuky group turned to opencode, an open-source AI coding agent, to mass-produce the decoy documents behind its latest phishing run. Speed came at the cost of care. Genians counted placeholder text for payment dates, grace periods, and interest rates surviving into the files that shipped, nine times over, which is what gave the tool away.
What reaches the inbox is handled far more carefully. Genians examined 13 shortcut files sent in ZIP archives between August 11 and 19, 2026, aimed at Korean financial and corporate staff, each wearing a Chrome icon over a forged "Hangul Document" property. Open one and PowerShell runs behind 5,800 to 9,500 characters of arguments, held out of sight by roughly 300 leading spaces.
From there the loader reaches GitHub Raw with a hardcoded access token, then registers a hidden scheduled task misspelled to pass for BitLocker, MATLAB, or .NET before deleting itself. Three samples never fetch a decoy and open a 16-byte error file instead, which looks like a failed attack. Persistence and payload retrieval run anyway.
That is why document quality settles nothing. Genians points defenders at the shortcut itself: a chrome.exe icon over a PowerShell target, randomly named scripts written into AppData and executed on the spot, and scheduled tasks carrying slight misspellings or long strings of digits.
Source: Cyber Security News
A critical zero-day called StyleSmuggler is being actively exploited against Magento Open Source stores, giving unauthenticated attackers remote code execution. Dutch security firm Sansec, which disclosed the flaw on September 5, 2026, says every current version of Magento and Adobe Commerce is affected. It published early because stores were already being compromised.
Sansec reproduced the attack chain on clean 2.4.7, 2.4.8, and 2.4.9 installations, and the first identified victim ran 2.4.6-p15 with July and August 2026 patches applied. The exploit abuses Magento's own template and email systems, dropping a Rust implant disguised as a Linux kernel thread.
Adobe has issued no advisory, CVE, or fix. Its next scheduled security release is September 8, though Sansec says there is no confirmation it covers this bug. Until then, store owners are on stopgaps.
Disrex, ProxiBlue, and Graycore have each published unofficial patches guarding specific Magento classes. Disrex says its own patch is verified against 2.4.6 through 2.4.9. Sansec recommends temporarily disabling GraphQL, which classic and Hyvä themes generally don't need, unlike headless and progressive web app storefronts.
The layer that doesn't depend on knowing the exploit is server-level. Disable PHP's exec functions, proc_open included, since a list blocking five of the six stops nothing, and mount temporary directories with noexec. Check both var/report and var/log/system.log too, since Sansec's published check looks only at the first
Source: Cybersecurity News
A critical zero-day called StyleSmuggler is being actively exploited against Magento Open Source stores, giving unauthenticated attackers remote code execution. Dutch security firm Sansec, which disclosed the flaw on September 5, 2026, says every current version of Magento and Adobe Commerce is affected. It published early because stores were already being compromised.
Sansec reproduced the attack chain on clean 2.4.7, 2.4.8, and 2.4.9 installations, and the first identified victim ran 2.4.6-p15 with July and August 2026 patches applied. The exploit abuses Magento's own template and email systems, dropping a Rust implant disguised as a Linux kernel thread.
Adobe has issued no advisory, CVE, or fix. Its next scheduled security release is September 8, though Sansec says there is no confirmation it covers this bug. Until then, store owners are on stopgaps.
Disrex, ProxiBlue, and Graycore have each published unofficial patches guarding specific Magento classes. Disrex says its own patch is verified against 2.4.6 through 2.4.9. Sansec recommends temporarily disabling GraphQL, which classic and Hyvä themes generally don't need, unlike headless and progressive web app storefronts.
The layer that doesn't depend on knowing the exploit is server-level. Disable PHP's exec functions, proc_open included, since a list blocking five of the six stops nothing, and mount temporary directories with noexec. Check both var/report and var/log/system.log too, since Sansec's published check looks only at the first
Source: Cybersecurity News
McKesson, one of North America's largest pharmaceutical distributors with $403.4 billion in annual revenue, disclosed a cyberattack on August 28, 2026, three days after discovering it. Unauthorized access to certain third-party applications led to data theft affecting a subset of customers within its Oncology & Multispecialty and Medical-Surgical business units, the company says.
ShinyHunters claimed responsibility, though McKesson has not named the group. It says it used voice phishing to compromise employees' Okta single sign-on accounts, then reached the Salesforce and Snowflake environments and exfiltrated data between August 21 and August 25, claiming roughly 284 million records and demanding over $55 million.
That figure counts database rows rather than patients, and the group has not fully analyzed the data. None of its claims are independently verified. A September 1 deadline to open negotiations passed without a response from the company, which has declined to comment on the demand.
Its distribution centers remain operational, McKesson says, though it warned customers to expect intermittent service degradation. Health-ISAC had warned the healthcare sector about ShinyHunters just weeks before the breach.
Source: CyberScoop
McKesson, one of North America's largest pharmaceutical distributors with $403.4 billion in annual revenue, disclosed a cyberattack on August 28, 2026, three days after discovering it. Unauthorized access to certain third-party applications led to data theft affecting a subset of customers within its Oncology & Multispecialty and Medical-Surgical business units, the company says.
ShinyHunters claimed responsibility, though McKesson has not named the group. It says it used voice phishing to compromise employees' Okta single sign-on accounts, then reached the Salesforce and Snowflake environments and exfiltrated data between August 21 and August 25, claiming roughly 284 million records and demanding over $55 million.
That figure counts database rows rather than patients, and the group has not fully analyzed the data. None of its claims are independently verified. A September 1 deadline to open negotiations passed without a response from the company, which has declined to comment on the demand.
Its distribution centers remain operational, McKesson says, though it warned customers to expect intermittent service degradation. Health-ISAC had warned the healthcare sector about ShinyHunters just weeks before the breach.
Source: CyberScoop
A hacking group linked to Silver Fox (also known as Yinhu) is running a campaign that tricks users into downloading fake installers disguised as Razer, Microsoft Edge, Kaspersky, and other trusted tools. The sites look legitimate — until you open the ZIP file. Microsoft says the payload changes on every download, so hashes shift while filenames stay put.
Once installed, the malware doesn't switch Microsoft Defender off — it uses short-lived SYSTEM scheduled tasks to write sweeping scan exclusions, then deletes the tasks to cover its tracks. It also deletes shadow copies, stops Windows Update, and sets up recurring tasks that restart malicious code every 60 seconds.
Victims span healthcare, manufacturing, gaming, technology, logistics, government, and education, most of them the China-based operations of multinational organizations, or Chinese-speaking users. Microsoft assesses with moderate confidence that the activity is consistent with the reported Silver Fox campaign, and has stopped short of attributing it to a nation-state.
Turn on Tamper Protection — Microsoft says it blocks Defender exclusion and registry writes even when the payload is running as SYSTEM, which is exactly what this campaign depends on. And always download software directly from official publishers.
Source: Cybersecurity News
A hacking group linked to Silver Fox (also known as Yinhu) is running a campaign that tricks users into downloading fake installers disguised as Razer, Microsoft Edge, Kaspersky, and other trusted tools. The sites look legitimate — until you open the ZIP file. Microsoft says the payload changes on every download, so hashes shift while filenames stay put.
Once installed, the malware doesn't switch Microsoft Defender off — it uses short-lived SYSTEM scheduled tasks to write sweeping scan exclusions, then deletes the tasks to cover its tracks. It also deletes shadow copies, stops Windows Update, and sets up recurring tasks that restart malicious code every 60 seconds.
Victims span healthcare, manufacturing, gaming, technology, logistics, government, and education, most of them the China-based operations of multinational organizations, or Chinese-speaking users. Microsoft assesses with moderate confidence that the activity is consistent with the reported Silver Fox campaign, and has stopped short of attributing it to a nation-state.
Turn on Tamper Protection — Microsoft says it blocks Defender exclusion and registry writes even when the payload is running as SYSTEM, which is exactly what this campaign depends on. And always download software directly from official publishers.
Source: Cybersecurity News
Chick-fil-A began notifying customers across 11 jurisdictions in late July after a credential-stuffing attack on its loyalty program between June 17 and 19. Thieves used usernames and passwords stolen from a third-party source to break into Chick-fil-A One accounts through the website and app. The company had concluded on July 13 that data may have been accessed.
Data that may have been accessed includes names, email addresses, membership numbers, Mobile Pay numbers, partial payment card digits, gift card balances, and QR codes. Customers who had saved more to their accounts may also have had their birth month and day, phone number, and address accessed.
Chick-fil-A calls it a limited number of accounts and hasn't given a total; filings show 2,182 in Texas and 39 in Massachusetts. It's the second credential-stuffing hit on Chick-fil-A One — an earlier one in 2023 reached more than 71,000 customers.
The company logged out affected users, removed stored payment methods, restored balances, and added rewards as compensation. Customers should reset their passwords and make them unique — reuse is what credential stuffing runs on — then check account activity. A law firm has been investigating a possible class action since early August.
Source: CBS News
Chick-fil-A began notifying customers across 11 jurisdictions in late July after a credential-stuffing attack on its loyalty program between June 17 and 19. Thieves used usernames and passwords stolen from a third-party source to break into Chick-fil-A One accounts through the website and app. The company had concluded on July 13 that data may have been accessed.
Data that may have been accessed includes names, email addresses, membership numbers, Mobile Pay numbers, partial payment card digits, gift card balances, and QR codes. Customers who had saved more to their accounts may also have had their birth month and day, phone number, and address accessed.
Chick-fil-A calls it a limited number of accounts and hasn't given a total; filings show 2,182 in Texas and 39 in Massachusetts. It's the second credential-stuffing hit on Chick-fil-A One — an earlier one in 2023 reached more than 71,000 customers.
The company logged out affected users, removed stored payment methods, restored balances, and added rewards as compensation. Customers should reset their passwords and make them unique — reuse is what credential stuffing runs on — then check account activity. A law firm has been investigating a possible class action since early August.
Source: CBS News
Norcross, Georgia is dealing with the fallout from a ransomware attack that hit some of the city's computer systems on August 1. Officials didn't go public until August 28 — nearly four weeks later — saying they responded as soon as the incident was detected, bringing in cybersecurity experts and notifying law enforcement.
Most city systems are back up and running, but some disruptions may continue as restoration work wraps up. The city is also rolling out new security measures.
Details are still limited given the ongoing investigation. Norcross hasn't said whether any resident or employee data was taken, nobody has claimed the attack, and the city hasn't disclosed a ransom demand. It says it will share more as things develop.
Source: CBS News Atlanta
Norcross, Georgia is dealing with the fallout from a ransomware attack that hit some of the city's computer systems on August 1. Officials didn't go public until August 28 — nearly four weeks later — saying they responded as soon as the incident was detected, bringing in cybersecurity experts and notifying law enforcement.
Most city systems are back up and running, but some disruptions may continue as restoration work wraps up. The city is also rolling out new security measures.
Details are still limited given the ongoing investigation. Norcross hasn't said whether any resident or employee data was taken, nobody has claimed the attack, and the city hasn't disclosed a ransom demand. It says it will share more as things develop.
Source: CBS News Atlanta
Arctic Wolf has uncovered a new Go-based malware framework, GoCaracal, deployed alongside the long-running Bandook backdoor against a communications organization in Venezuela in June 2026. Researchers assess with medium confidence that the activity is linked to Dark Caracal, a cyberespionage group with a long history in Latin America.
Attacks begin with Spanish-language emails on financial and tax themes, carrying weaponized SVG attachments. The SVG holds no payload — just an encoded shortened link that redirects through intermediaries to a 7-Zip archive containing the first-stage implant, which is why the attachment slips past filters.
GoCaracal ships in two builds. The lightweight one establishes access and delivers payloads; the extended one handles control and intelligence collection, and it is the one with the blockchain trick. When it loses contact with its primary server, it queries an Ethereum smart contract named BulletproofC2 for a replacement address — no new file needed on the victim's device.
Arctic Wolf also assesses with moderate confidence that related activity reaches Brazil, Ecuador, Chile, Colombia, El Salvador, and Uruguay, though the regional scope is still under investigation. Treat SVG attachments as active content, watch for failed control-server connections followed by Ethereum RPC requests, and read a single takedown as one step, not the end of the intrusion.
Source: Cyber Security News
Arctic Wolf has uncovered a new Go-based malware framework, GoCaracal, deployed alongside the long-running Bandook backdoor against a communications organization in Venezuela in June 2026. Researchers assess with medium confidence that the activity is linked to Dark Caracal, a cyberespionage group with a long history in Latin America.
Attacks begin with Spanish-language emails on financial and tax themes, carrying weaponized SVG attachments. The SVG holds no payload — just an encoded shortened link that redirects through intermediaries to a 7-Zip archive containing the first-stage implant, which is why the attachment slips past filters.
GoCaracal ships in two builds. The lightweight one establishes access and delivers payloads; the extended one handles control and intelligence collection, and it is the one with the blockchain trick. When it loses contact with its primary server, it queries an Ethereum smart contract named BulletproofC2 for a replacement address — no new file needed on the victim's device.
Arctic Wolf also assesses with moderate confidence that related activity reaches Brazil, Ecuador, Chile, Colombia, El Salvador, and Uruguay, though the regional scope is still under investigation. Treat SVG attachments as active content, watch for failed control-server connections followed by Ethereum RPC requests, and read a single takedown as one step, not the end of the intrusion.
Source: Cyber Security News