Cyberattacks (2)
Malicious releases across 42 @tanstack npm packages, published May 11, harvested GitHub tokens, SSH keys, and cloud credentials from developer machines. One belonged to a CrowdSec developer who had just left, whose access the company kept open so he could finish outstanding work. On May 22 an attacker used his OAuth token to clone roughly 170 private repositories from a Toronto IP address in nine minutes.
CrowdSec revoked the account on May 25, three days after the clone, and learned of the theft only on September 16, when the code appeared on a breach forum. The archive held the SaaS console, data-science models, deployment tools, email addresses for 83 users — under 0.05% of its user base — and names and investment details for 51 potential investors from 2020.
Production systems, databases, and the CrowdSec agent and blocklist data were untouched, and no code was altered. The one live credential was an AWS token scoped to a single SNS topic, probed on August 17 and taken no further. CrowdSec's own lesson is blunt: multi-factor authentication cannot stop malware that already holds a valid token, and only enterprise GitHub plans retain git activity, on a rolling seven-day window.
Source: Cybersecurity News
Malicious releases across 42 @tanstack npm packages, published May 11, harvested GitHub tokens, SSH keys, and cloud credentials from developer machines. One belonged to a CrowdSec developer who had just left, whose access the company kept open so he could finish outstanding work. On May 22 an attacker used his OAuth token to clone roughly 170 private repositories from a Toronto IP address in nine minutes.
CrowdSec revoked the account on May 25, three days after the clone, and learned of the theft only on September 16, when the code appeared on a breach forum. The archive held the SaaS console, data-science models, deployment tools, email addresses for 83 users — under 0.05% of its user base — and names and investment details for 51 potential investors from 2020.
Production systems, databases, and the CrowdSec agent and blocklist data were untouched, and no code was altered. The one live credential was an AWS token scoped to a single SNS topic, probed on August 17 and taken no further. CrowdSec's own lesson is blunt: multi-factor authentication cannot stop malware that already holds a valid token, and only enterprise GitHub plans retain git activity, on a rolling seven-day window.
Source: Cybersecurity News
Security firm Sansec estimates that a supply chain attack on customer engagement platform Brevo pushed malicious code to as many as 100,000 websites. A separate incident on September 10 saw attackers exploit Brevo's SAML SSO handling to reach 138 customer accounts, including Trezor's, which reported phishing that reached 347,000 user email addresses and compromised at least 2,500. Brevo has not said the two incidents are linked.
On September 14, attackers used a compromised Cloudflare API key — long-lived, fully permissioned, and hardcoded in Brevo's source code — to deploy a worker that injected malware into Brevo's domains and three JavaScript files customers embed. Because the worker rewrote responses at the CDN edge and stripped Content-Security-Policy headers, Brevo's origin files stayed untouched and standard integrity checks detected nothing.
The worker ran roughly five and a half hours, serving a fake Cloudflare verification page that used ClickFix prompts to get visitors running commands themselves. WordPress administrators logged in during the window were prompted to install a plugin from an attacker domain. Review September 14 logs for plugin uploads, compare your filesystem against the admin plugin list, and rotate administrator passwords if anything turns up.
Source: SecurityWeek
Security firm Sansec estimates that a supply chain attack on customer engagement platform Brevo pushed malicious code to as many as 100,000 websites. A separate incident on September 10 saw attackers exploit Brevo's SAML SSO handling to reach 138 customer accounts, including Trezor's, which reported phishing that reached 347,000 user email addresses and compromised at least 2,500. Brevo has not said the two incidents are linked.
On September 14, attackers used a compromised Cloudflare API key — long-lived, fully permissioned, and hardcoded in Brevo's source code — to deploy a worker that injected malware into Brevo's domains and three JavaScript files customers embed. Because the worker rewrote responses at the CDN edge and stripped Content-Security-Policy headers, Brevo's origin files stayed untouched and standard integrity checks detected nothing.
The worker ran roughly five and a half hours, serving a fake Cloudflare verification page that used ClickFix prompts to get visitors running commands themselves. WordPress administrators logged in during the window were prompted to install a plugin from an attacker domain. Review September 14 logs for plugin uploads, compare your filesystem against the admin plugin list, and rotate administrator passwords if anything turns up.
Source: SecurityWeek
Acronis researchers say Red Heron, a Chinese-speaking threat actor, is exploiting CVE-2026-60004, a Gitea remote code execution flaw rated CVSS 9.8 (Critical). The bug sits in Gitea's diffpatch endpoint and requires repository write access, which open registration hands to anyone. Gitea fixed it in version 1.27.1 on July 27, 2026.
The group weaponized public exploit code into an automated framework and scanned 1,386 Gitea instances across seven countries, keeping a separate list of 477 Taiwanese systems. Confirmed compromises stand at 13 organizations in six countries. Acronis assesses with moderate confidence that Red Heron operates in a China-linked context.
Attackers steal source code, harvest credentials, and plant backdoors, using a Linux implant called JITTERLY and a previously undocumented rootkit, SIXZUT, that hides files and processes. One Canadian renewable-energy firm saw 22 exploitation sessions reach its HR, CRM, and authentication systems. A Taiwanese target lost root access to a three-node Proxmox cluster.
Versions 1.17 through 1.27.0 are affected. Upgrade to 1.27.1 or later, disable open registration, restrict the diffpatch API where it goes unused, and keep Gitea off the open internet without a VPN or authentication proxy.
Source: Cybersecurity News
Acronis researchers say Red Heron, a Chinese-speaking threat actor, is exploiting CVE-2026-60004, a Gitea remote code execution flaw rated CVSS 9.8 (Critical). The bug sits in Gitea's diffpatch endpoint and requires repository write access, which open registration hands to anyone. Gitea fixed it in version 1.27.1 on July 27, 2026.
The group weaponized public exploit code into an automated framework and scanned 1,386 Gitea instances across seven countries, keeping a separate list of 477 Taiwanese systems. Confirmed compromises stand at 13 organizations in six countries. Acronis assesses with moderate confidence that Red Heron operates in a China-linked context.
Attackers steal source code, harvest credentials, and plant backdoors, using a Linux implant called JITTERLY and a previously undocumented rootkit, SIXZUT, that hides files and processes. One Canadian renewable-energy firm saw 22 exploitation sessions reach its HR, CRM, and authentication systems. A Taiwanese target lost root access to a three-node Proxmox cluster.
Versions 1.17 through 1.27.0 are affected. Upgrade to 1.27.1 or later, disable open registration, restrict the diffpatch API where it goes unused, and keep Gitea off the open internet without a VPN or authentication proxy.
Source: Cybersecurity News
A threat actor posted a 2.5 GB archive on a cybercrime forum on September 12, claiming it holds 7.49 million records belonging to CenterPoint Energy customers. The listing cites names, contact and billing details, move-in dates, driver's license information, and the last four digits of Social Security numbers, and says the data came from a poorly secured API.
CenterPoint's Form 8-K confirms far less. An unauthorized third party obtained personal information relating to a portion of its customers through an external-facing system. The Houston utility serves around 7 million customers in Texas, Indiana, Minnesota, and Ohio, so the claimed record count exceeds its entire customer base. Nobody has verified the archive.
Gas and electricity delivery are unaffected, and CenterPoint does not expect a material financial impact. The company is still working with outside experts to determine scope, and intends to notify affected customers and regulators. The poster also threatened to move from stealing data to attacking the main infrastructure.
Source: SecurityWeek
A threat actor posted a 2.5 GB archive on a cybercrime forum on September 12, claiming it holds 7.49 million records belonging to CenterPoint Energy customers. The listing cites names, contact and billing details, move-in dates, driver's license information, and the last four digits of Social Security numbers, and says the data came from a poorly secured API.
CenterPoint's Form 8-K confirms far less. An unauthorized third party obtained personal information relating to a portion of its customers through an external-facing system. The Houston utility serves around 7 million customers in Texas, Indiana, Minnesota, and Ohio, so the claimed record count exceeds its entire customer base. Nobody has verified the archive.
Gas and electricity delivery are unaffected, and CenterPoint does not expect a material financial impact. The company is still working with outside experts to determine scope, and intends to notify affected customers and regulators. The poster also threatened to move from stealing data to attacking the main infrastructure.
Source: SecurityWeek
Cisco is warning of a zero-day in its Secure Email Gateway appliances, CVE-2026-76461, rated CVSS 9.8 (Critical) and under active exploitation. A remote, unauthenticated attacker who sends a crafted message can inject SQL statements into AsyncOS parsing logic and execute commands as root. Physical and virtual appliances are affected in any configuration.
Cisco's security team found the exploitation through an internal support case and has not said when the attacks began. CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 14 and gave federal agencies until September 17 to patch. Secure Email and Web Manager and Secure Web Appliance are not affected.
No workarounds exist. Update to AsyncOS 16.5.0-780 on the 16.5 branch, 16.0.4-302 on 16.0, or 15.5.5-0141 on 15.5 and earlier. Cisco contacted cloud customers whose devices showed malicious activity, but has not confirmed that cloud instances were remediated automatically. On-premises admins must apply the update themselves.
Source: Cybersecurity News
Cisco is warning of a zero-day in its Secure Email Gateway appliances, CVE-2026-76461, rated CVSS 9.8 (Critical) and under active exploitation. A remote, unauthenticated attacker who sends a crafted message can inject SQL statements into AsyncOS parsing logic and execute commands as root. Physical and virtual appliances are affected in any configuration.
Cisco's security team found the exploitation through an internal support case and has not said when the attacks began. CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 14 and gave federal agencies until September 17 to patch. Secure Email and Web Manager and Secure Web Appliance are not affected.
No workarounds exist. Update to AsyncOS 16.5.0-780 on the 16.5 branch, 16.0.4-302 on 16.0, or 15.5.5-0141 on 15.5 and earlier. Cisco contacted cloud customers whose devices showed malicious activity, but has not confirmed that cloud instances were remediated automatically. On-premises admins must apply the update themselves.
Source: Cybersecurity News
A phishing campaign reached roughly 347,000 Trezor customers after an attacker got into Brevo, the marketing platform Trezor uses for newsletters. Brevo says the attacker reached 138 accounts, sent phishing from six, and exported contacts from 43, with BitBox and CoinTracking users apparently hit as well.
The attacker created a Brevo account, enabled single sign-on, and invited legitimate Brevo users into that configuration, then signed in as them through their own identity provider. That access was never scoped to one organization, so it reached every organization those users could see. Brevo closed the route two hours after spotting it, signed out every user, and disabled the links.
Because the emails left real Brevo infrastructure, they passed the usual authentication checks. Trezor's carried the subject line "Critical Security Alert: STM32 Entropy Vulnerability" and pointed at a site set up to harvest wallet backups. Around 2,500 people clicked in the 20 minutes before Trezor caught it.
It is Trezor's second third-party failure in a month, after a breach at shipping provider ShipMonk exposed nearly 14,000 people, plus another 67,000 US customers disclosed on September 4.
Source: SecurityWeek
A phishing campaign reached roughly 347,000 Trezor customers after an attacker got into Brevo, the marketing platform Trezor uses for newsletters. Brevo says the attacker reached 138 accounts, sent phishing from six, and exported contacts from 43, with BitBox and CoinTracking users apparently hit as well.
The attacker created a Brevo account, enabled single sign-on, and invited legitimate Brevo users into that configuration, then signed in as them through their own identity provider. That access was never scoped to one organization, so it reached every organization those users could see. Brevo closed the route two hours after spotting it, signed out every user, and disabled the links.
Because the emails left real Brevo infrastructure, they passed the usual authentication checks. Trezor's carried the subject line "Critical Security Alert: STM32 Entropy Vulnerability" and pointed at a site set up to harvest wallet backups. Around 2,500 people clicked in the 20 minutes before Trezor caught it.
It is Trezor's second third-party failure in a month, after a breach at shipping provider ShipMonk exposed nearly 14,000 people, plus another 67,000 US customers disclosed on September 4.
Source: SecurityWeek
A new exploit kit called BlueMoon is letting espionage groups chain Chrome and Windows flaws to plant backdoors on government, defense, and commercial targets. Proofpoint counted four clusters using it since late August 2026, most suspected of a China nexus, though some use is unattributed and the kit may not be exclusive to Chinese actors.
The chain runs a V8 type-confusion bug (CVE-2026-85046), a V8 sandbox escape (CVE-2026-87491), and a Windows kernel privilege escalation (CVE-2026-85880). Both Chrome flaws were patch-gap zero-days, fixed in public Chromium source but missing from stable releases. That gap has since closed, with the V8 fix reaching stable Chromium on September 3.
Exposure is narrower than it sounds. The privilege escalation only fires on older Windows builds, which Proofpoint says substantially cuts the pool of viable targets, and successful exploitation ends in a plain curl command that leaves endpoint tools plenty to catch. Circumstantial signs point to AI-assisted development, including verbose debugging comments and a markdown handover file of the kind coding agents leave behind.
TA412, also known as APT31, posed as students seeking internships and conference organizers to reach US NGOs, mining firms, and commodity traders, then installed a surveillance extension disguised as Google Gemini across Chrome, Edge, Brave, and Vivaldi. How four groups obtained the same kit is unknown. Proofpoint expects the technique to reach financially motivated actors too.
Source: Cybersecurity News
A new exploit kit called BlueMoon is letting espionage groups chain Chrome and Windows flaws to plant backdoors on government, defense, and commercial targets. Proofpoint counted four clusters using it since late August 2026, most suspected of a China nexus, though some use is unattributed and the kit may not be exclusive to Chinese actors.
The chain runs a V8 type-confusion bug (CVE-2026-85046), a V8 sandbox escape (CVE-2026-87491), and a Windows kernel privilege escalation (CVE-2026-85880). Both Chrome flaws were patch-gap zero-days, fixed in public Chromium source but missing from stable releases. That gap has since closed, with the V8 fix reaching stable Chromium on September 3.
Exposure is narrower than it sounds. The privilege escalation only fires on older Windows builds, which Proofpoint says substantially cuts the pool of viable targets, and successful exploitation ends in a plain curl command that leaves endpoint tools plenty to catch. Circumstantial signs point to AI-assisted development, including verbose debugging comments and a markdown handover file of the kind coding agents leave behind.
TA412, also known as APT31, posed as students seeking internships and conference organizers to reach US NGOs, mining firms, and commodity traders, then installed a surveillance extension disguised as Google Gemini across Chrome, Edge, Brave, and Vivaldi. How four groups obtained the same kit is unknown. Proofpoint expects the technique to reach financially motivated actors too.
Source: Cybersecurity News
KnowBe4 published research on September 4 into a phishing campaign still running in the wild, and the trick sits in the link. Rather than hide a malicious URL and hope the gateway misses it, the operators built a three-hop redirect chain from Google's own services, so every hop an inspector checks resolves to a domain it already trusts.
The services named include Google Meet, DoubleClick, Custom Search, Image Search, Tag Manager, and Analytics. What waits at the end varies: some victims get a fake corporate login page, others a fake identity verification prompt that quietly installs ScreenConnect for remote access.
The login page is the more inventive half. JavaScript builds it on the fly from the victim's email address alone, sets a live screenshot of their real corporate website behind it, and localizes the interface to their location. Credentials reach the operator's Telegram channel within seconds, along with the victim's IP, geolocation, browser string, and their organization's verified MX records.
KnowBe4 wants the IOCs blocked at DNS filter, proxy, and SIEM level now, Telegram bot API traffic hunted, unauthorized ScreenConnect installs checked, and credential resets forced for anyone who may have received a lure. An email address after the # in a URL signals a pre-targeted link, though it is base64-encoded, so nobody will spot one by eye.
Source: Dark Reading
KnowBe4 published research on September 4 into a phishing campaign still running in the wild, and the trick sits in the link. Rather than hide a malicious URL and hope the gateway misses it, the operators built a three-hop redirect chain from Google's own services, so every hop an inspector checks resolves to a domain it already trusts.
The services named include Google Meet, DoubleClick, Custom Search, Image Search, Tag Manager, and Analytics. What waits at the end varies: some victims get a fake corporate login page, others a fake identity verification prompt that quietly installs ScreenConnect for remote access.
The login page is the more inventive half. JavaScript builds it on the fly from the victim's email address alone, sets a live screenshot of their real corporate website behind it, and localizes the interface to their location. Credentials reach the operator's Telegram channel within seconds, along with the victim's IP, geolocation, browser string, and their organization's verified MX records.
KnowBe4 wants the IOCs blocked at DNS filter, proxy, and SIEM level now, Telegram bot API traffic hunted, unauthorized ScreenConnect installs checked, and credential resets forced for anyone who may have received a lure. An email address after the # in a URL signals a pre-targeted link, though it is base64-encoded, so nobody will spot one by eye.
Source: Dark Reading
Everett City Hall has been closed to the public since Tuesday, September 8, after the city discovered a cybersecurity incident on its internal network on Sunday night. Officials still haven't said what kind of incident it was or how far it reached, and the doors stay shut through Thursday, September 10.
Business has moved rather than stopped. Nine departments, from the Treasurer to Inspectional Services, are operating out of the Connolly Center from 9 to 5 on both closure days, with 311 taking questions. Police, fire, public works, schools, and libraries are unaffected.
Online bill payments also still work, though only because they run on third-party systems rather than the city's own network. What Everett hosts internally is what went down, and Mayor Robert J. Van Campen says IT staff and investigators are working around the clock to restore it.
Everett is at least the second Massachusetts case this week, after Springfield Public Schools canceled classes Tuesday. Cynthia Kaiser, formerly of the FBI's Cyber Division, says local government makes an easy mark because agencies each run thin IT teams, and that patching a known flaw is an emergency, not maintenance
Source: CBS News Boston
Everett City Hall has been closed to the public since Tuesday, September 8, after the city discovered a cybersecurity incident on its internal network on Sunday night. Officials still haven't said what kind of incident it was or how far it reached, and the doors stay shut through Thursday, September 10.
Business has moved rather than stopped. Nine departments, from the Treasurer to Inspectional Services, are operating out of the Connolly Center from 9 to 5 on both closure days, with 311 taking questions. Police, fire, public works, schools, and libraries are unaffected.
Online bill payments also still work, though only because they run on third-party systems rather than the city's own network. What Everett hosts internally is what went down, and Mayor Robert J. Van Campen says IT staff and investigators are working around the clock to restore it.
Everett is at least the second Massachusetts case this week, after Springfield Public Schools canceled classes Tuesday. Cynthia Kaiser, formerly of the FBI's Cyber Division, says local government makes an easy mark because agencies each run thin IT teams, and that patching a known flaw is an emergency, not maintenance
Source: CBS News Boston
North Korea's Kimsuky group turned to opencode, an open-source AI coding agent, to mass-produce the decoy documents behind its latest phishing run. Speed came at the cost of care. Genians counted placeholder text for payment dates, grace periods, and interest rates surviving into the files that shipped, nine times over, which is what gave the tool away.
What reaches the inbox is handled far more carefully. Genians examined 13 shortcut files sent in ZIP archives between August 11 and 19, 2026, aimed at Korean financial and corporate staff, each wearing a Chrome icon over a forged "Hangul Document" property. Open one and PowerShell runs behind 5,800 to 9,500 characters of arguments, held out of sight by roughly 300 leading spaces.
From there the loader reaches GitHub Raw with a hardcoded access token, then registers a hidden scheduled task misspelled to pass for BitLocker, MATLAB, or .NET before deleting itself. Three samples never fetch a decoy and open a 16-byte error file instead, which looks like a failed attack. Persistence and payload retrieval run anyway.
That is why document quality settles nothing. Genians points defenders at the shortcut itself: a chrome.exe icon over a PowerShell target, randomly named scripts written into AppData and executed on the spot, and scheduled tasks carrying slight misspellings or long strings of digits.
Source: Cyber Security News
North Korea's Kimsuky group turned to opencode, an open-source AI coding agent, to mass-produce the decoy documents behind its latest phishing run. Speed came at the cost of care. Genians counted placeholder text for payment dates, grace periods, and interest rates surviving into the files that shipped, nine times over, which is what gave the tool away.
What reaches the inbox is handled far more carefully. Genians examined 13 shortcut files sent in ZIP archives between August 11 and 19, 2026, aimed at Korean financial and corporate staff, each wearing a Chrome icon over a forged "Hangul Document" property. Open one and PowerShell runs behind 5,800 to 9,500 characters of arguments, held out of sight by roughly 300 leading spaces.
From there the loader reaches GitHub Raw with a hardcoded access token, then registers a hidden scheduled task misspelled to pass for BitLocker, MATLAB, or .NET before deleting itself. Three samples never fetch a decoy and open a 16-byte error file instead, which looks like a failed attack. Persistence and payload retrieval run anyway.
That is why document quality settles nothing. Genians points defenders at the shortcut itself: a chrome.exe icon over a PowerShell target, randomly named scripts written into AppData and executed on the spot, and scheduled tasks carrying slight misspellings or long strings of digits.
Source: Cyber Security News