top of page

ALL POSTS

Russian Military Espionage Campaign Exploits Hacked IP Cameras Across NATO and Ukraine

Key Findings Russian intelligence services are systematically hacking internet-connected IP cameras across NATO member states, EU countries, and Ukraine Camera feeds are used to monitor military transport routes, weapons shipments to Ukraine, and locations of Ukrainian troops In Ukraine, hacked camera access has been directly used to target and neutralize Ukrainian military personnel and equipment The operation relies on basic tactics: default passwords, outdated firmware, an

HollowGraph Malware Exploits Microsoft 365 Events to Conceal C2 Communications and Stolen Data

Key Findings HollowGraph malware uses hijacked Microsoft 365 calendar events dated 2050 as a command-and-control channel, disguising malicious traffic as legitimate Microsoft Graph API activity The .NET implant supports only two commands (get and send) and never connects to attacker-owned servers, instead treating a compromised mailbox calendar as a two-way dead drop Tasking and exfiltrated files are encrypted with hybrid RSA-OAEP and AES-256-GCM encryption, with separate key

AI Agents Used in Autonomous Breach: Hugging Face Exposes New Attack Vector

Key Findings Autonomous AI agent successfully breached Hugging Face production infrastructure and accessed internal datasets and service credentials Attack originated in data-processing pipeline exploiting two code execution flaws, with attackers escalating privileges and moving laterally across systems No evidence of tampering with public models, datasets, or software supply chain Attacker used autonomous agent framework executing thousands of actions across short-lived sand

SonicWall SMA Zero-Day Chain Exploited to Root VPN Appliances and Deploy Stealth Malware

Key Findings Threat actor UTA0533 exploited a critical zero-day chain in SonicWall SMA 1000 VPN appliances to gain root access Two flaws chained together: CVE-2026-15409 (SSRF in Workplace interface) and CVE-2026-15410 (command injection in management console) Attacker deployed custom malware toolkit including KNUCKLEBALL loader, ORANGETAIL webshell, and Suo5 proxy tool At least two appliances confirmed compromised; exploitation originating from over 200 IP addresses using VP

WordPress Sites Under Attack: New wp2shell RCE Exploits Now Public

Key Findings Two critical WordPress Core vulnerabilities (CVE-2026-63030 and CVE-2026-60137) can be chained together to achieve pre-authentication remote code execution Public exploits are now available for the wp2shell attack chain Affected versions are WordPress 6.9.0-6.9.4 and 7.0.0-7.0.1 WordPress has enabled forced automatic security updates due to severity Over 500 million websites worldwide use WordPress and are potentially at risk No plugins or valid credentials requi

Hugging Face Hit by Autonomous AI Agent in Major Security Breach

Key Findings Hugging Face disclosed a production breach on July 16, 2024, executed entirely by an autonomous AI agent Attackers exploited two code-execution vulnerabilities in the data-processing pipeline using a malicious dataset Internal datasets and service credentials were exposed; no tampering detected in public models, datasets, or Spaces The AI agent performed thousands of actions across short-lived sandboxes, escalating from worker-level to node-level access and movin

Critical wp2shell WordPress Vulnerability Exposes Systems to Unauthenticated Remote Code Execution

Key Findings Anonymous HTTP requests can execute code on WordPress sites running core versions 6.9 through 7.0.1 without any plugins or authentication Two chained vulnerabilities, now assigned CVE-2026-63030 and CVE-2026-60137, combine a REST API batch-route confusion with SQL injection to bypass all protections WordPress patched the issue Friday with forced auto-updates to versions 6.9.5 and 7.0.2, but sites with auto-updates disabled remain vulnerable Full technical details

NadMesh Botnet Targets Exposed AI Services to Steal Cloud Credentials and Kubernetes Tokens

Key Findings Go-based botnet NadMesh emerged in early July targeting exposed AI services including ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio Operator dashboard shows 3,811 unique AWS keys harvested with credential theft as primary objective Botnet extracts cloud credentials, Kubernetes service account tokens, Docker configs, and environment variables from compromised hosts Docker API exploitation dominates observed traffic at 30.31%, followed by Jenkins script ex

Russian Threat Actors Deploy Starland RAT Through Counterfeit Video Conferencing Installers

Key Findings Russian-speaking threat actor UAT-11795 has been running a malware campaign since June 2025 targeting users in the U.S. and Europe Campaign distributes trojanized installers for legitimate software including Zoom, Webex, MobaXterm, DBeaver, and FACEIT gaming platform Two newly documented malware families deployed: Starland RAT (Python-based) and WLDR (PowerShell memory-only implant) Initial access achieved through ClickFix social engineering technique Starland RA

CISA Adds Critical SharePoint RCE Zero-Day CVE-2026-58644 to KEV Catalog Due to Active Exploitation

Key Findings CISA added CVE-2026-58644, a critical SharePoint Server remote code execution vulnerability, to its Known Exploited Vulnerabilities catalog on July 16, 2026 The vulnerability was actively exploited in the wild before Microsoft released patches on July 14, 2026, making it a zero-day at the time of exploitation Federal Civilian Executive Branch agencies must remediate the flaw by July 19, 2026, under BOD 26-04 CISA also added two critical Fortinet FortiSandbox vuln

EU Forces Google to Grant Rival AI Assistants Full Access to Android Features and Search Data

Key Findings The European Commission has mandated Google grant rival AI assistants equal access to Android's core features including camera, microphone, screen contents, and wake-word activation by August 1, 2027 Google must implement these changes in Android 18 and establish a Qualified AI Assistant Programme with third-party certification authorities Google is also required to share anonymized Search query, click, and ranking data with competing search engines and AI chatbo

ClickFix Campaign Distributes ACR Stealer to Harvest Browser Tokens and Microsoft 365 Credentials

Key Findings ACR Stealer, active since 2024, steals browser passwords, session tokens, PDFs, and Microsoft 365 documents through ClickFix social engineering lures Two distinct delivery chains identified: one leaves disk artifacts, the other operates entirely in memory using steganography and pixel-embedded payloads No vulnerabilities exploited; both chains rely entirely on victims pasting commands into Run boxes or PowerShell Microsoft recommends revoking tokens rather than r

Two Scattered Spider Hackers Sentenced to 5.5 Years for £29 Million Transport for London Cyberattack

Key Findings Two Scattered Spider members, Owen Flowers (18) and Thalha Jubair (20), sentenced to 5.5 years in prison for 2024 cyberattack on Transport for London TfL attack cost £29 million; potential complete shutdown could have caused £56 billion in economic damage to UK economy Attack knocked 148 systems offline, disrupted services for 9 million daily journeys, exposed customer data including bank details First hackers successfully prosecuted under Section 3ZA of Computer

FortiBleed: Global Credential-Spraying Operation Uncovered Across Multiple Platforms

Key Findings Multi-operator crew conducted industrial-scale credential-spraying campaign against Fortinet FortiGate SSL VPN devices across 207 countries Campaign generated 1.16 billion login combinations against 320,777 FortiGate endpoints and 2.1 billion attempts against 163,650 MSSQL servers Operators used custom tools running up to 50,000 threads and a 45-way NVIDIA RTX 4090 GPU cluster for password cracking At least four organizations fully compromised, including a Turkis

Critical ArcGIS Account Recovery Vulnerability Exploited in Ongoing Attack Campaign

Key Findings Cybercriminals are actively exploiting ArcGIS Account Recovery configurations to breach customer environments right now Attackers bypass hardened primary login defenses by targeting weaker account recovery mechanisms instead Built-in application accounts with weak security questions or common usernames are primary targets Organizations using centralized identity providers instead of built-in accounts are protected from this specific threat Esri will release a sec

The Gentlemen's GentleKiller: How a Standardized EDR-Killer Framework Emerged as the New Ransomware Threat

Key Findings The Gentlemen ransomware operation has developed GentleKiller, a standardized EDR-killer suite distributed to affiliates before ransomware deployment GentleKiller exists in at least eight variants, each impersonating legitimate products and exploiting different vulnerable drivers via BYOVD technique The framework targets over 400 processes across 48 security products including CrowdStrike, SentinelOne, and Microsoft Defender The Gentlemen adopts newly disclosed e

Passwordless Phishing: How Attackers Hijack Microsoft 365 Through Device Code Authentication

Key Findings A sophisticated phishing-as-a-service kit called EvilTokens exploits Microsoft's legitimate OAuth 2.0 device authorization flow to hijack Microsoft 365 accounts without stealing passwords Attackers trick victims into entering a device code on a real Microsoft login page, which grants the attacker valid access tokens to the compromised account The attack bypasses traditional phishing detection methods by using genuine Microsoft authentication pages, eliminating fa

AutoJack Attack: Web Page Hijacking Enables AI Agent Host Code Execution

Key Findings Microsoft researchers discovered AutoJack, an exploit chain in AutoGen Studio that allows a single web page to execute arbitrary code on a developer's machine The vulnerability exists in the Model Context Protocol (MCP) WebSocket handler and requires no authentication, credentials, or user interaction beyond the agent loading a malicious URL Vulnerable pre-release builds 0.4.3.dev1 and 0.4.3.dev2 were shipped to PyPI, though the stable release 0.4.2.2 is unaffect

Global SocGholish Takedown: Nearly 15,000 WordPress Sites Cleaned in Major Operation

Key Findings Operation EndGame, a coordinated international law enforcement action, dismantled SocGholish infrastructure on June 18, 2026 106 servers and domains taken down globally; 14,971 compromised WordPress sites remediated Law enforcement from Netherlands, Canada, United States, and Germany executed the coordinated takedown with support from Europol SocGholish serves as initial access broker for major ransomware families including LockBit, RansomHub, and WastedLocker Be

eFAQ's Investigation Reveals Alleged Scam Operations and Coordinated Smear Campaign

Key Findings Dozens of coordinated fake accounts posted identical accusations against eFAQ across multiple platforms simultaneously, most created days before publishing and deleted shortly after Claims of hidden subscriptions and unauthorized billing were contradicted by eFAQ's actual checkout process, which displays terms multiple times and requires active consent Reddit moderators and platform enforcement teams independently removed the content and suspended accounts under

  • Youtube

© 2025 by Explain IT Again. Powered and secured by Wix

bottom of page