News

Daily News Articles

Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure
News

Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure

According to watchTowr, threat actors are taking advantage of a recently fixed critical security vulnerability affecting JFrog Artifactory just days after it was made public. The vulnerability in question is CVE-2026-82329 (CVSS score: 9.8), an instance of an Artifactory authentication bypass that may grant administrative access. According to a description of the defect on CVE.org, JFrog Artifactory has an authentication vulnerability that, under normal settings, may enable an unauthenticated attacker with network access to achieve administrative rights. On August 28, 2026, JFrog published Artifactory version 7.161.20, which fixed the vulnerability. The following versions are impacted: 7.161.0 > 7.161.19 7.146.0 > 7.146.36 7.133.0 > 7.133.28 7.125.0 > 7.125.19 7.1...
Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems
News

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

A financially motivated threat actor known as Breeze Comet (previously UNC5669) has been targeting Brazilian financial services, retail, and e-commerce companies since 2024. The threat actor was identified by the Mandiant and Google Threat Intelligence Group (GTIG) teams as "specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers." At least one theft of assets valued at tens of thousands of dollars is reportedly successfully completed by the adversary. The activity is similar to threat activity clusters that Trend Micro and CrowdStrike are monitoring under the names SHADOW-AETHER-064 and Plump Spider. The Brazilian e-crime group has been active since September 2023, according to CrowdStrike. They make money off of their attacks by ...
Microsoft warns of TerminalFix attacks deploying reverse tunnels
News

Microsoft warns of TerminalFix attacks deploying reverse tunnels

Using phony Cloudflare CAPTCHA prompts on hacked websites, a new ClickFix variation known as TerminalFix deceives victims into running malicious PowerShell instructions in Windows Terminal. This campaign employs a multi-stage intrusion chain that eventually provides attackers with a reverse tunnel into the victim's internal network, in contrast to standard ClickFix attacks that frequently result in infostealer malware infections. In contrast to standard ClickFix attacks, TerminalFix points users to Windows Terminal or PowerShell, which allows more complicated, multi-line scripts to be successfully executed. Microsoft did not see any hands-on activity, but they were aware of the attacks in the wild. The researchers caution that access gained in this manner may be used for ransomwa...
ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
News

ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions

The ValleyRAT backdoor has been seen to be distributed by the threat actor Silver Fox under the pretense of a signed Chinese adware program. The malware operates under a trusted process to evade consumers who add such applications to their antivirus exclusions. According to Russian cybersecurity vendor Kaspersky, the attackers created the disguise around QN Wallpaper, a legitimate Chinese desktop wallpaper utility that displays ad banners, bundles partner apps, and is adware in its unaltered form. After installation, the operator has complete control over the compromised PC thanks to ValleyRAT (also known as Winos 4.0). Kaspersky advised users to steer clear of software with dubious reputations and to keep it away from security-tool exclusions, claiming that the attack's geography a...
Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets
News

Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets

According to research from CloudSEK and Gambit Security, threat actors connected to the Aurora (also known as Aur0ra) ransomware have been seen breaking into target networks using SpaceX's AI-powered coding tool Cursor. The toolkit, shell history, and encryptor of the Russian-speaking cybercrime gang were found through the two separate analyzes, which are based on exposed infrastructure connected to the group. According to CloudSEK, between April and July 2026, "months of activity" were leaked from the exposed open directory against over 20 enterprises in nine different nations. Since then, its data leak website has mentioned four of those victims. According to CloudSEK, the operator planned attacks in Russian using Cursor, an agentic coding assistance, while omitting CIS [Commonwea...
China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
News

China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs

A long-running campaign to compromise Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS) servers, and Linux management hosts used to route, authenticate, and manage high-value networks has been extended beyond VMware hypervisors by a China-nexus cyber espionage actor known as Fire Ant. The hacked routers were transformed into collecting platforms by the actor, according to Sygnia, the incident response company that looked into the intrusion. This allowed the actor to gather credentials, capture network traffic, and suppress the logging and telemetry that defenders use to reconstruct an assault. According to the firm's assessment, the hacker gang explored routes to connected high-value environments, including vital infrastructure, using its footing. Never...
Chrome Web Store extensions caught stealing crypto browser data
News

Chrome Web Store extensions caught stealing crypto browser data

A malware framework that deployed modules to steal bitcoin, private information, and browser history as well as to inject ClickFix lures was distributed by several extensions for Google Chrome and Microsoft Edge. According to researchers, each of the 19 malicious modules found during the campaign has a different function and is intended to be "highly extensible." Application security firm Socket discovered the activity, which may have been in existence since early 2024, according to the research. According to Socket, several of the extensions offered the promised features and were free of malware when they were first released on the Chrome Web Store. The researchers claim that five of the extensions were obtained from their original developers and infected with malware through autom...
Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable
News

Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable

A crucial balance-handling vulnerability in the shared Cosmos EVM module was used to drain money from six blockchains between August 20 and August 25, 2026, according to a warning from Cosmos Labs. The vulnerability, identified as GHSA-7g4w-cg88-2cq2, was released without a CVSS score, a weakness categorization, or a CVE name. Cosmos Labs has classified it Critical. Versions < 0.6.2 and >= 0.7.0 < 0.7.2 are impacted; the patch was released in v0.6.2 and v0.7.2 on August 19. Chain operators are instructed to update to one of those releases or later; this is a state-breaking modification that necessitates a coordinated network upgrade. Instead of attempting a coordinated governance upgrade, operators who are unable to upgrade right away are instructed to stop the chain. ...
DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims
News

DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims

The U.S. Department of Justice (DoJ) clarified on Friday that they were among those attacked in a news release that had earlier claimed that several of its agencies had been the targets of attacks by Chinese threat actors. The DoJ reported last week that QTFY, a state-sponsored organization connected to the People's Republic of China (PRC), was responsible for "computer intrusion activity" that affected the National Aeronautics and Space Administration, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate. The aforementioned organizations are identified as "among the targets of QTFY" in the recently revised statement." Over the weekend, Reuters reported the update...
TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
News

TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor

Microsoft has revealed information on a new ClickFix variation called TerminalFix, which attempts to fool users into executing a malicious command in PowerShell or Windows Terminal. According to an analysis released this week by Microsoft security researchers Sagar Patil, Suriyaraj Natarajan, and Parasharan Raghavan, TerminalFix campaigns use the same technique as traditional ClickFix campaigns but direct users to Windows Terminal or PowerShell instead, increasing the likelihood that complex, multi-line scripts execute successfully. Targeting businesses in a variety of industries, the effort uses hacked websites as a springboard to offer phony Cloudflare CAPTCHA verifications, which lead unwary website users to copy and run a malicious PowerShell command. According to the Windows...