Cyberattacks (4)
Australian authorities arrested two Western Australia men on Wednesday, August 26, over their alleged roles in TeamPCP, the cybercrime group that injected credential-stealing code into Aqua Security's Trivy scanner, Checkmarx KICS and LiteLLM in March. The AFP says that code potentially compromised more than 1,000 organizations worldwide.
Police didn't name the pair; Australian media identified them as Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23. Between them they face 14 charges, including four counts each of unauthorized modification of data with intent to commit a serious offence. Only Thomson faces a proceeds-of-crime count over $100,000 and a password-refusal charge.
The AFP estimates the code enabled theft of more than 500,000 credentials and at least 300GB of data, with global cleanup costs in the hundreds of millions. CERT-EU tied the European Commission's cloud breach to the poisoned Trivy release. Flare assesses with high confidence that Thomson led TeamPCP.
Both men appeared in Perth Magistrates Court on Thursday. Thomson withdrew a bail application after the magistrate signalled she would refuse it, and both remain in custody until September 18.
Source: CyberScoop
Australian authorities arrested two Western Australia men on Wednesday, August 26, over their alleged roles in TeamPCP, the cybercrime group that injected credential-stealing code into Aqua Security's Trivy scanner, Checkmarx KICS and LiteLLM in March. The AFP says that code potentially compromised more than 1,000 organizations worldwide.
Police didn't name the pair; Australian media identified them as Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23. Between them they face 14 charges, including four counts each of unauthorized modification of data with intent to commit a serious offence. Only Thomson faces a proceeds-of-crime count over $100,000 and a password-refusal charge.
The AFP estimates the code enabled theft of more than 500,000 credentials and at least 300GB of data, with global cleanup costs in the hundreds of millions. CERT-EU tied the European Commission's cloud breach to the poisoned Trivy release. Flare assesses with high confidence that Thomson led TeamPCP.
Both men appeared in Perth Magistrates Court on Thursday. Thomson withdrew a bail application after the magistrate signalled she would refuse it, and both remain in custody until September 18.
Source: CyberScoop
A phishing-as-a-service toolkit called Mirage2FA has been linked to attacks on 3 518 organizations, with 4 532 Microsoft 365 accounts potentially compromised, researchers at ANY.RUN report. Active since September 2024, it skips malware entirely — a browser-executed HTML, XHTML or SVG attachment, or a QR code, steers the victim to a fake Microsoft login page.
Whatever the victim types — password and live 2FA code alike — an adversary-in-the-middle proxy passes through to Microsoft in real time. What the attacker keeps is the authenticated session cookie sent back on success, and it works until it expires or someone revokes it — no password or MFA needed.
Cookie theft was the largest single outcome — 4,561 of 9,332 recorded compromise events, just under half — affecting 2,541 accounts. Of the 4,532 accounts potentially compromised overall, 63.7% were in the U.S.; technology, manufacturing and education were the hardest-hit sectors.
A password reset won't fix this. Revoke every active session, and move high-risk users to phishing-resistant MFA — FIDO2 keys or passkeys, which are bound to the real site and can't be relayed. ANY.RUN also recommends blocking those attachment types and shortening session lifetimes.
Source: Cybersecurity News
A phishing-as-a-service toolkit called Mirage2FA has been linked to attacks on 3 518 organizations, with 4 532 Microsoft 365 accounts potentially compromised, researchers at ANY.RUN report. Active since September 2024, it skips malware entirely — a browser-executed HTML, XHTML or SVG attachment, or a QR code, steers the victim to a fake Microsoft login page.
Whatever the victim types — password and live 2FA code alike — an adversary-in-the-middle proxy passes through to Microsoft in real time. What the attacker keeps is the authenticated session cookie sent back on success, and it works until it expires or someone revokes it — no password or MFA needed.
Cookie theft was the largest single outcome — 4,561 of 9,332 recorded compromise events, just under half — affecting 2,541 accounts. Of the 4,532 accounts potentially compromised overall, 63.7% were in the U.S.; technology, manufacturing and education were the hardest-hit sectors.
A password reset won't fix this. Revoke every active session, and move high-risk users to phishing-resistant MFA — FIDO2 keys or passkeys, which are bound to the real site and can't be relayed. ANY.RUN also recommends blocking those attachment types and shortening session lifetimes.
Source: Cybersecurity News
A cyberattack hit Ceva Logistics on July 29, knocking out eight European warehouses and halting shipments. The French-headquartered logistics giant told corporate client Bol about the intrusion on August 1 — but the notices that reached consumers came from the retailers themselves, not from Ceva.
Several major organizations confirmed impact, including Dutch retailers Bol and De Bijenkorf, ING, Ace & Tate, Amsterdam's Ajax football club, and game company Valve. Exposed data includes names, addresses, phone numbers, emails and order details.
De Bijenkorf said no payment details, IBANs, card data, usernames or passwords were involved; Ceva never held Steam payment credentials either. Valve says Ceva keeps order records up to 90 days, and has warned customers to expect fake emails, texts, and calls about their hardware orders.
Who's behind the attack remains unknown. Ceva has not publicly disclosed the incident, responded to press enquiries, or said how the intruders got in or how many people are affected.
Source: SecurityWeek
A cyberattack hit Ceva Logistics on July 29, knocking out eight European warehouses and halting shipments. The French-headquartered logistics giant told corporate client Bol about the intrusion on August 1 — but the notices that reached consumers came from the retailers themselves, not from Ceva.
Several major organizations confirmed impact, including Dutch retailers Bol and De Bijenkorf, ING, Ace & Tate, Amsterdam's Ajax football club, and game company Valve. Exposed data includes names, addresses, phone numbers, emails and order details.
De Bijenkorf said no payment details, IBANs, card data, usernames or passwords were involved; Ceva never held Steam payment credentials either. Valve says Ceva keeps order records up to 90 days, and has warned customers to expect fake emails, texts, and calls about their hardware orders.
Who's behind the attack remains unknown. Ceva has not publicly disclosed the incident, responded to press enquiries, or said how the intruders got in or how many people are affected.
Source: SecurityWeek
The Department for Energy Security and Net Zero has contacted power companies to advise them about the risk of cyberattacks, after a small UK generator was taken offline for four days last month. The Telegraph reported the attack was carried out by hackers affiliated with the Iranian regime.
Neither the government nor the National Cyber Security Centre would identify the site, citing security reasons. DESNZ said the incident affected a small-scale generator and that at no point was there a risk to the UK's energy system. Britain's network runs a number of smaller gas units that supply short-term power when demand spikes.
The government is updating its cyber security regulations and working on a new energy resilience strategy, due later this year. Iran has long been rated a capable cyber power, and Western defenders have spent this year braced for state-linked activity amid its conflict with the US — while seeing little of it so far..
Source: BBC News
The Department for Energy Security and Net Zero has contacted power companies to advise them about the risk of cyberattacks, after a small UK generator was taken offline for four days last month. The Telegraph reported the attack was carried out by hackers affiliated with the Iranian regime.
Neither the government nor the National Cyber Security Centre would identify the site, citing security reasons. DESNZ said the incident affected a small-scale generator and that at no point was there a risk to the UK's energy system. Britain's network runs a number of smaller gas units that supply short-term power when demand spikes.
The government is updating its cyber security regulations and working on a new energy resilience strategy, due later this year. Iran has long been rated a capable cyber power, and Western defenders have spent this year braced for state-linked activity amid its conflict with the US — while seeing little of it so far..
Source: BBC News
Hackers connected to Iran knocked a UK power plant offline for four days last month, according to the Sunday Telegraph, which broke the story. It comes after Britain allowed the US to launch defensive operations against Tehran from British bases — a policy that stops short of offensive strikes.
The government said the incident hit a small-scale energy generator and that the wider energy system was never at risk. The National Cyber Security Centre is understood not to have logged any outages from regulated power station operators. Still, Iran's IRGC has warned that any base used for aggression against Iranian territory is a "legitimate target."
Britain's new PM Andy Burnham was notified last week that a decision had already been made to extend the US basing agreement.
Source: The Guardian
Hackers connected to Iran knocked a UK power plant offline for four days last month, according to the Sunday Telegraph, which broke the story. It comes after Britain allowed the US to launch defensive operations against Tehran from British bases — a policy that stops short of offensive strikes.
The government said the incident hit a small-scale energy generator and that the wider energy system was never at risk. The National Cyber Security Centre is understood not to have logged any outages from regulated power station operators. Still, Iran's IRGC has warned that any base used for aggression against Iranian territory is a "legitimate target."
Britain's new PM Andy Burnham was notified last week that a decision had already been made to extend the US basing agreement.
Source: The Guardian
Cybersecurity researchers are flagging three dangerous banking trojans making the rounds. Manic, an Android malware detailed by ThreatFabric, combines banking fraud with spyware and targets Ukraine, Russia, and European financial institutions — even using Bluetooth and Wi-Fi to relay stolen data when internet access is unavailable.
Grandoreiro, a decade-old Windows trojan from Brazil, remains active per the Acronis Threat Research Unit, though at considerably lower volume than before a January 2024 law enforcement takedown. It's still hitting Latin America, with a more limited presence in Europe, and recent attacks have focused on Mexico. The trojan now hides inside a legitimate file-finder app to dodge detection.
ToxicPanda 2.0, flagged by Zimperium, is the biggest upgrade — now targeting 349 financial apps across 16 countries and delivering payloads through Amazon AWS.
Source: SecurityWeek
Cybersecurity researchers are flagging three dangerous banking trojans making the rounds. Manic, an Android malware detailed by ThreatFabric, combines banking fraud with spyware and targets Ukraine, Russia, and European financial institutions — even using Bluetooth and Wi-Fi to relay stolen data when internet access is unavailable.
Grandoreiro, a decade-old Windows trojan from Brazil, remains active per the Acronis Threat Research Unit, though at considerably lower volume than before a January 2024 law enforcement takedown. It's still hitting Latin America, with a more limited presence in Europe, and recent attacks have focused on Mexico. The trojan now hides inside a legitimate file-finder app to dodge detection.
ToxicPanda 2.0, flagged by Zimperium, is the biggest upgrade — now targeting 349 financial apps across 16 countries and delivering payloads through Amazon AWS.
Source: SecurityWeek
A single phishing email gave attackers full access to a finance employee's Microsoft 365 account — no malware required. The attack used a fake "PTO Request Denied" message to lure the victim through a chain of redirects to a counterfeit Microsoft sign-in page that captured their authenticated session cookie in real time, bypassing MFA entirely.
With that stolen session, attackers accessed invoices, payment threads, and a shared accounts-payable mailbox. Over 30 days, they impersonated a vendor and an internal colleague to redirect payments to fraudulent bank accounts — while hidden inbox rules buried any alerts. Organizations should enforce out-of-band payment verification and token protection immediately.
Source: Cybersecurity News
A single phishing email gave attackers full access to a finance employee's Microsoft 365 account — no malware required. The attack used a fake "PTO Request Denied" message to lure the victim through a chain of redirects to a counterfeit Microsoft sign-in page that captured their authenticated session cookie in real time, bypassing MFA entirely.
With that stolen session, attackers accessed invoices, payment threads, and a shared accounts-payable mailbox. Over 30 days, they impersonated a vendor and an internal colleague to redirect payments to fraudulent bank accounts — while hidden inbox rules buried any alerts. Organizations should enforce out-of-band payment verification and token protection immediately.
Source: Cybersecurity News
North Korean hacking group Sapphire Sleet is the likely suspect behind a Rust ecosystem supply chain attack on August 20, which compromised arrayref — a package with over 245 million downloads found in roughly 75% of Rust environments. The attackers pushed a malicious version from the legitimate maintainer's account, then quickly poisoned two more related crates. Hidden inside was a build script designed to fetch a second-stage payload over TLS with certificate validation disabled.
The Rust Security Response Team yanked the malicious packages within 86 minutes. No evidence of actual exploitation was found. Wiz tied the attack to Sapphire Sleet based on infrastructure overlaps with earlier NPM attacks targeting Axios and Mastra.
Source: SecurityWeek
North Korean hacking group Sapphire Sleet is the likely suspect behind a Rust ecosystem supply chain attack on August 20, which compromised arrayref — a package with over 245 million downloads found in roughly 75% of Rust environments. The attackers pushed a malicious version from the legitimate maintainer's account, then quickly poisoned two more related crates. Hidden inside was a build script designed to fetch a second-stage payload over TLS with certificate validation disabled.
The Rust Security Response Team yanked the malicious packages within 86 minutes. No evidence of actual exploitation was found. Wiz tied the attack to Sapphire Sleet based on infrastructure overlaps with earlier NPM attacks targeting Axios and Mastra.
Source: SecurityWeek
The Clop cybercrime group is at it again — this time exploiting a zero-day vulnerability in PTC's Windchill and FlexPLM software, tools widely used in manufacturing, aerospace, and automotive industries. The group began sending extortion emails to victims in mid-July, claiming it stole data from dozens of organizations, potentially including GE, Philips, and Shell.
PTC disclosed the flaw (CVE-2026-12569) on June 17, but companies were likely compromised weeks earlier. Clop deployed a custom web shell purpose-built for Windchill, enabling rapid credential theft and data exfiltration with minimal detection. Toast and Zebra confirmed intrusions but say impacts were limited. The fallout is still unfolding.
Source: CyberScoop
The Clop cybercrime group is at it again — this time exploiting a zero-day vulnerability in PTC's Windchill and FlexPLM software, tools widely used in manufacturing, aerospace, and automotive industries. The group began sending extortion emails to victims in mid-July, claiming it stole data from dozens of organizations, potentially including GE, Philips, and Shell.
PTC disclosed the flaw (CVE-2026-12569) on June 17, but companies were likely compromised weeks earlier. Clop deployed a custom web shell purpose-built for Windchill, enabling rapid credential theft and data exfiltration with minimal detection. Toast and Zebra confirmed intrusions but say impacts were limited. The fallout is still unfolding.
Source: CyberScoop
The Cl0p ransomware gang has publicly named more than 40 organizations it claims to have breached through a vulnerability in PTC's Windchill and FlexPLM platforms. The flaw, CVE-2026-12569, allows unauthenticated remote code execution and was added to CISA's KEV catalog in June after active exploitation began.
High-profile alleged victims include Shell, Philips, Fiserv, Zebra Technologies, Ingersoll Rand, and Apple lens supplier Largan Precision. GE was listed but has been removed from C10p's website— possibly signaling ransom negotiations. Stolen data ranges from 1 GB to several terabytes per organization, covering databases, engineering blueprints, and corporate documents. None of the named companies have confirmed a significant breach.
Source: SecurityWeek
The Cl0p ransomware gang has publicly named more than 40 organizations it claims to have breached through a vulnerability in PTC's Windchill and FlexPLM platforms. The flaw, CVE-2026-12569, allows unauthenticated remote code execution and was added to CISA's KEV catalog in June after active exploitation began.
High-profile alleged victims include Shell, Philips, Fiserv, Zebra Technologies, Ingersoll Rand, and Apple lens supplier Largan Precision. GE was listed but has been removed from C10p's website— possibly signaling ransom negotiations. Stolen data ranges from 1 GB to several terabytes per organization, covering databases, engineering blueprints, and corporate documents. None of the named companies have confirmed a significant breach.
Source: SecurityWeek