Russian state hackers use new RedFlick technique to push malware
News

Russian state hackers use new RedFlick technique to push malware

The Russian state-sponsored actor Star Blizzard has been detected using a novel malware-installation method called “RedFlick” to deliver its favored CosmicPulse backdoor. While the described technique is nothing new, it allows the threat actor to diversify its attack methods and increase the level of automation while reducing the interaction surface with the victim. Microsoft notes that threat group Star Blizzard has been observed ramping up phishing activities and improving malware-delivery techniques in 2026. The group, which has been active since 2017, has diversified its attack vectors, utilizing various platforms for payload delivery such as ClickFix and WhatsApp, and has also been noted for its continuous development and deployment of new malware families. This attack ch...
Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks
News

Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks

Microsoft has warned of phishing campaigns delivering an installer for the MSP360 Remote Monitoring and Management (RMM) software through fake meeting invites, PDF-themed lures, software update prompts, and other social-engineering content. The legitimate MSP360 installer, which had been distributed under a deceptive file name, allowed attackers to establish remote management access on the targeted devices and provide an initial foothold by using trusted administrative software, Microsoft Security Research team said. The initial foothold was later used to download and install a ConnectWise ScreenConnect client, providing a redundant remote-access channel for the compromised endpoints. The access was then abused to deliver additional tools and perform information collection and crede...
Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager
News

Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager

Attackers are weaponizing a brand new critical zero-day vulnerability in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco said in an advisory on September 30. The vulnerability, CVE-2026-76504, allows a remote attacker with no login access to use the Manager's API as the admin user. Fixed releases are available, and there is no workaround. It has a CVSS score of 9.8 out of 10. It's in the part of the Manager's API that handles login sessions. The Manager has incorrect handling of URI encoding of an HTTP request. A crafted request can therefore bypass an authentication rule that's meant to restrict access to a single API endpoint. The attacker does not need any credentials to mount this attack, only the ability to send the reques...
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures
News

Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures

Threat actors are abusing ChatGPT Custom GPTs to impersonate as legitimate product offerings to lure unsuspecting victims into malicious sites, which are using ClickFix lures to deliver malware. Huntress, who witnessed the activity in late September 2026, reported it is another abuse of yet another feature in trusted artificial intelligence (AI) platforms. Earlier campaigns have weaponized shared conversations with AI chatbots and malicious Claude Artifacts to distribute stealer malware and remote access trojans (RATs). Custom GPTs are a personalized version of ChatGPT that, as the name suggests, allow users to define custom instructions, upload reference files, and enable specific skills to handle unique tasks without any coding. They are hosted on the legitimate ChatGPT website wi...
Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT
News

Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT

Unknown threat actors have been observed to take advantage of a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target businesses in North America and Europe. According to Mandiant Consulting and Google Threat Intelligence Group (GTIG)’s observation in September 2026, the attack has targeted government, financial services, technology, education, and legal and professional services sectors. In a post published on LinkedIn, Charles Carmakal, chief technology officer at Mandiant Consulting, mentioned that the targeted intrusions affected dozens of organizations, noting that there is a broad and opportunistic exploitation of CVE-2026-88772 and CVE-2026-88771 by various threat actors in the near term. Exploitation of CVE-2026-88772 allows attack...
OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted
News

OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted

A high-severity OpenSSL vulnerability could lead to heap memory disclosure on the other side of a DTLS connection or cause a program crash, OpenSSL said September 29 as it rolled out fixes. DTLS (the TLS variant used for UDP traffic) re-sends a handshake message if no response is received before the timeout, and the leak or crash could occur during such a resend if a larger handshake message was paused in transmission. The vulnerability, CVE-2026-84782, is fixed in OpenSSL 4.0.3, 3.6.5, 3.5.9 and 3.4.8. Fixes for the older 3.0, 1.1.1 and 1.0.2 branches are available only to customers with an active subscription for premium support from OpenSSL. OpenSSL 3.0 stopped receiving public security fixes on September 7. OpenSSL has not said whether an attacker could cause such a resend to...
Russia’s Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor
News

Russia’s Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor

Russian state hackers known as Star Blizzard have been using fake event invitations to trick people into installing a back door on their Windows computers, according to Microsoft. The campaigns, aimed at people and organizations associated with Ukraine, have affected over 100 organizations since January, mainly in the U.S. and U.K. At least one computer was infected, but the number of breached organizations has not been revealed. Security agencies in the U.S., U.K., Australia, Canada and New Zealand stated in December 2023 that Star Blizzard is almost certainly operating under Center 18 of Russia's Federal Security Service (FSB). The group has been stealing email passwords by posing as people its targets know. By 2023, it used fake meeting and conference invites as lures to lure ...
Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown
News

Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown

Kiteworks announced on Monday it worked with federal intelligence agencies over the weekend as it identified and patched a critical security vulnerability during the scheduled precautionary shutdown. During the shutdown, this activity led to the discovery of a previously unknown critical vulnerability confined to a capability that is enabled for less than 1% of the customer base, the company said in a statement. It developed and deployed a fix during the window, [and] applied an additional protective layer across all environments. The company says there is no evidence that the vulnerability has ever been exploited in a malicious context. Other Kiteworks products are not impacted by the flaw. The move follows shortly after Kiteworks (formerly Accellion) instructed customers to dis...
Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation
News

Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation

Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group. "It is true that this month a 24-year-old Amsterdam man was arrested in an investigation into the hacker group ShinyHunters," the Politie Landelijke Opsporing en Interventies said in an X post Monday. Police said the individual is expected to appear before the Rotterdam District Court on September 29, 2026. Although law enforcement officials did not disclose any additional details, independent security journalist Brian Krebs and DataBreaches.Net identified the arrested man as Pepijn van der Stap (aka Umbreon), who was previously apprehended in 2023 for his role in a series of data thefts and extortions. According to the source, van der Stap was arrest...
Japan’s Keio confirms ransomware attack disrupted business systems
News

Japan’s Keio confirms ransomware attack disrupted business systems

Japanese private railway operator Keio Corp. (Keio) announced that its system was targeted by a ransomware attack this weekend, causing a disruption to some business functions. The firm stated that after experiencing a system malfunction in the early hours of Saturday, they found out the cause of the malfunction and isolated their network to avert further damage. The company also said that they were looking into the matter to assess the scope of the impact and whether any customer or business data was compromised. Keio is a major Japanese railroad company that operates 85 km of track, 69 stations, and a separate hospitality business of 25 hotels. The company employs over 2,200 people, and its annual revenue is estimated at $2.6 billion. At around midnight on September 26, 2026...