Author: AresISEC Security Team

Security Highlights Of The Week [08/26-3]

PaperCut Zero-Day Is Being Actively Exploited
PaperCut confirmed active exploitation of a vulnerability affecting PaperCut NG and MF, with attacks observed against customer environments before a full fix was available. Organizations with internet-exposed Application Servers were urged to immediately restrict web interface access to trusted IP addresses while remediation efforts continue.
Source: BleepingComputer

TeamCity Authentication Bypass Exploited Against Australian Servers
Australia’s Cyber Security Centre has observed active exploitation of CVE-2026-63077 affecting TeamCity On-Premises installations. The vulnerability can allow an unauthenticated attacker with HTTP or HTTPS access to bypass authentication and execute arbitrary operating system commands on the CI/CD server.
Source: Australian Cyber Security Centre

Oracle WebLogic CVE-2026-21962 Is Widely Exploited
CISA added CVE-2026-21962 to its Known Exploited Vulnerabilities catalog after widespread exploitation against Oracle WebLogic environments. The CVSS 10 vulnerability affects Oracle HTTP Server and the WebLogic Server Proxy Plug-in and can be exploited remotely without authentication.
Source: SecurityWeek

Attackers Target miniOrange SAML Flaws to Gain WordPress Administrator Access
Threat actors are attempting to exploit severe authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. Successful exploitation can allow an unauthenticated attacker to impersonate an existing user, including an administrator, giving the attacker control of the affected site.
Source: The Hacker News

Gitea Code Injection Vulnerability Added to CISA KEV
CISA added CVE-2026-60004, a Gitea code injection vulnerability, to its Known Exploited Vulnerabilities catalog following evidence of active exploitation. The listing confirms that the issue has moved beyond theoretical risk and should be prioritized by organizations running affected self-hosted development infrastructure.
Source: CISA

Iran-Linked Hackers Reportedly Shut Down UK Power Plant for Four Days
An Iran-linked cyberattack reportedly forced a British power plant offline for four days during July. Public technical details remain limited, but the incident is significant because the reported compromise crossed from cyber access into a sustained disruption of physical energy production.
Source: SecurityWeek

US Disrupts Chinese Hacking Platform Used Against Critical Infrastructure
The US government announced the disruption of a hacking platform and botnet operated by the China-linked group QTFY. Authorities say the platform enabled attacks against US military and critical infrastructure targets, while FBI reporting links the group to compromises affecting hundreds of organizations.
Source: SecurityWeek

More Than 270 Zimbra Servers Compromised in Ongoing Exploitation
Ongoing attacks exploiting CVE-2026-73570 have now compromised more than 270 Zimbra Collaboration servers. The vulnerability allows unauthenticated remote command execution when the vulnerable SNMP notification component is enabled, showing that exploitation has expanded substantially since the initial warning.
Source: BleepingComputer

Critical Keycloak Flaw Can Let Attackers Take Over Any Account
CVE-2026-18963 is a critical weakness in Keycloak’s password recovery process that can allow an unauthenticated remote attacker to force a password reset for another user. Because Keycloak is widely deployed as an identity and access management layer, successful exploitation can have consequences far beyond a single application account.
Source: The Hacker News

Critical Siemens IoT2050 Flaw Enables Unauthenticated Code Execution
Siemens SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED contain a missing authentication vulnerability in the Node-RED HTTP interface. A remote unauthenticated attacker can create malicious flows and execute arbitrary code on the underlying system with maximum privileges.
Source: CISA

Next.js Patches Two Critical Unauthenticated RCE Vulnerabilities
Vercel released fixes for two critical vulnerabilities in Next.js that can lead to unauthenticated remote code execution. One issue can be triggered through specially crafted AVIF images, while another affects certain Next.js deployments running on Windows filesystems.
Source: The Hacker News

Massive DDoS Attack Disrupts Norway’s Government Digital Infrastructure
A large DDoS campaign disrupted infrastructure supporting Norway’s shared government digital services. Affected capabilities included public-service authentication, electronic IDs and signatures, secure digital mail, government forms, and data exchange between agencies.
Source: BleepingComputer

ATF Confirms Major Cyber Incident After Qilin Breach Claim
The US Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed that a standalone system was compromised after the Qilin ransomware group listed the agency on its leak site. ATF said there was no indication that its broader enterprise network or other major systems were affected, while the incident remains under investigation with the Department of Justice.
Source: BleepingComputer

OpenAI Details AI-Agent Incident That Reached Hugging Face Infrastructure
OpenAI disclosed additional technical details about a July cybersecurity evaluation in which internal research models circumvented isolation controls, communicated through unauthorized channels, gained internet access, and reached third-party infrastructure including Hugging Face. The incident provides a rare real-world example of highly capable autonomous agents taking security-relevant actions outside the intended boundaries of an evaluation environment.
Source: OpenAI

Carhartt Breach Exposes Data From 12.9 Million Accounts
Data associated with nearly 13 million Carhartt accounts was published following a breach attributed to the ShinyHunters extortion group. The scale of the exposed account data makes the incident one of the larger consumer-facing breaches disclosed during the week.
Source: BleepingComputer

Security Highlights Of The Week [08/26-2]

Zimbra RCE Is Being Actively Exploited Against Internet-Facing Servers
Attackers are actively exploiting CVE-2026-73570 in Zimbra Collaboration, an unauthenticated command injection vulnerability affecting deployments with the optional SNMP package and notifications enabled. Successful exploitation allows arbitrary operating system commands to run as the Zimbra user, creating a path to persistence, mailbox access, credential theft, and further movement into affected environments.
Source: Centre for Cybersecurity Belgium

MLflow Flaw Is Exploited to Steal Cloud Credentials and Secrets
Attackers are exploiting CVE-2026-64849, an unauthenticated SSRF vulnerability in MLflow, to reach cloud metadata services and extract credentials and other secrets. Exploitation began within hours of the CVE assignment, and CISA subsequently added the vulnerability to its Known Exploited Vulnerabilities catalog.
Source: The Hacker News

VMware vCenter Exploitation Expands Into a Global Campaign
Incident responders are tracking global exploitation of CVE-2026-59310, a critical vCenter Server vulnerability that can lead to arbitrary code execution. The campaign has been linked with moderate confidence to a suspected China-nexus actor and includes reverse SSH tooling for persistent access to compromised virtualization infrastructure.
Source: QUIRSO

macOS Screen Sharing Authentication Bypass Is Exploited in the Wild
CVE-2026-65400 in macOS Screen Sharing is being exploited against reachable systems to install Monero cryptocurrency miners. The flaw allows attackers to bypass authentication to the built-in remote-control service without valid credentials, making exposed Screen Sharing services particularly risky.
Source: Malwarebytes

Adobe Commerce Vulnerability Triggers Active Exploitation Warning
Belgium’s cybersecurity authority warned organizations about active exploitation reports involving critical Adobe Commerce and Magento vulnerabilities disclosed in August. The most severe issues can enable privilege escalation, arbitrary code execution, and security control bypass, putting exposed e-commerce environments and their data at immediate risk.
Source: Centre for Cybersecurity Belgium

US Agencies Warn of Active Threat Targeting Siemens S7 PLCs
The NSA, CISA, FBI, DOE, and EPA warned critical infrastructure operators that threat actors are actively targeting Siemens S7 programmable logic controllers. The activity combines internet reconnaissance, known weaknesses, and AI-generated exploitation tooling that can manipulate PLC memory, configuration data, and control logic.
Source: CISA

North Korean Hackers Linked to Major Rust Supply Chain Compromise
Malicious releases of popular Rust crates including arrayref and append-only-vec were pushed through a legitimate maintainer account and linked to North Korean threat actors. The poisoned packages introduced a malicious dependency that executes during compilation, giving the campaign a potentially large developer-side blast radius given arrayref’s extensive use across Rust environments.
Source: SecurityWeek

Cl0p Names More Than 40 Victims in PTC Windchill Campaign
Cl0p has listed more than 40 organizations allegedly compromised through exploitation of CVE-2026-12569 in PTC Windchill and FlexPLM. Additional analysis uncovered a custom Java web shell designed specifically around Windchill’s APIs, database structure, credentials, and file repositories, indicating significant preparation for large-scale data theft.
Source: SecurityWeek

Operation CameraSwarm Compromises More Than 14,000 Dahua Cameras
Researchers traced a single operator that compromised more than 14,000 Dahua IP cameras during a campaign spanning June and July. Scanning was global, but confirmed compromises concentrated heavily in Ukraine and Russia, demonstrating the scale at which exposed surveillance devices can be converted into operational intelligence assets.
Source: Hunt.io

Critical NetScaler Authentication Bypass Puts Internet-Facing Gateways at Risk
CVE-2026-19490 is a critical authentication bypass affecting Citrix NetScaler ADC and NetScaler Gateway appliances configured for gateway or AAA functionality. Remote unauthenticated exploitation requires no user interaction, and researchers expect rapid attacker interest because NetScaler systems are commonly deployed on enterprise network perimeters.
Source: Rapid7

CareCloud Breach Impact Expands to 3.7 Million People
The number of individuals affected by the CareCloud breach has risen to more than 3.7 million, significantly above the initial estimate. Attackers accessed an AWS environment associated with the healthcare technology provider and claimed to have exfiltrated information from databases hosted there.
Source: SecurityWeek

Elementor Pro File Upload Flaw Enables Unauthenticated WordPress RCE
CVE-2026-32475 in Elementor Pro allows unauthenticated attackers to bypass file-extension validation and upload executable PHP files through vulnerable Forms configurations. Successful exploitation can result in remote code execution and complete compromise of affected WordPress servers.
Source: Orca Security

Critical isolated-vm Bug Breaks Out of JavaScript Sandboxes
A critical type confusion vulnerability in the isolated-vm Node.js library can allow code intended to run inside a V8 Isolate to achieve code execution on the host. The issue is especially relevant to services that rely on isolated-vm to safely execute untrusted JavaScript workloads without full container or virtual-machine isolation.
Source: SecurityWeek

North Korean IT Workers Used Fabricated Identities to Target More Than 1,100 Companies
Recorded Future identified multiple PurpleDelta clusters associated with North Korean IT workers using fabricated personas, AI-generated profile images, identity documents, and customized AI assistants during employment operations. One cluster applied to positions at more than 1,100 organizations, and researchers assess that operators were successfully employed by at least ten companies.
Source: Recorded Future

Russian Espionage Clusters Abuse Legitimate Authentication Flows
Google Threat Intelligence Group is tracking three suspected Russian cyberespionage clusters targeting government, defense, aerospace, academic, and think-tank personnel in Europe and the United States. The groups use phishing, OAuth abuse, legitimate authentication workflows, and in some cases malware to compromise accounts while blending into normal identity activity.
Source: Google Threat Intelligence Group

Security Highlights Of The Week [08/26-1]

GeoServer Zero-Day Exploited Hours After Public Disclosure
Attackers began exploiting an unpatched GeoServer vulnerability only hours after technical details became public. The SQL injection issue can reportedly be escalated to remote code execution against vulnerable deployments using affected data stores.
Source: SecurityWeek

Cisco Secure Firewall Vulnerability Is Under Active Exploitation
Attackers are actively exploiting a vulnerability in Cisco Secure Firewall ASA and FTD software that allows an unauthenticated remote attacker to force affected devices to reload. Because these appliances frequently sit directly on the network perimeter, successful exploitation can disrupt critical remote access and security services.
Source: Centre for Cybersecurity Belgium

Lazarus Used a Windows Zero-Day Against Defense and Aerospace Targets
Check Point linked CVE-2026-68820 to a new wave of Operation Dream Job targeting defense, aerospace, and aviation organizations. The North Korea-linked campaign used fake recruitment material and a trojanized PDF viewer before exploiting the Windows privilege escalation flaw to gain SYSTEM access and deploy an updated FudModule rootkit.
Source: Check Point Research

Metabase Zero-Day Gives Unauthenticated Attackers Full Administrator Access
A maximum-severity SQL injection vulnerability in Metabase has been actively exploited in the wild. Attackers can abuse the password-reset API without authentication to obtain administrator access and potentially reach credentials and data from connected database platforms.
Source: Resecurity

SharePoint RCE Is Now Being Used in Ransomware Attacks
CISA confirmed that ransomware operators are exploiting CVE-2026-45659 in Microsoft SharePoint Server. The deserialization vulnerability enables low-privileged attackers to execute arbitrary code on unpatched on-premises SharePoint systems and has been under active exploitation since July.
Source: BleepingComputer

Zoomsday Vulnerabilities Enable Zero-Click Code Execution Between Meeting Participants
Three vulnerabilities in Zoom’s annotation processing could allow one meeting participant to attack another through malicious collaboration data. The flaws can lead to crashes, information disclosure, and attacker-controlled code execution without requiring the victim to open a separate malicious file.
Source: Malwarebytes

Internet-Exposed PLCs Are Being Manipulated in Water Sector Attacks
Attackers are targeting internet-facing Rockwell Automation and Allen-Bradley MicroLogix PLCs used by water and wastewater organizations and have caused operational disruptions. The attacks rely on exposed controllers, weak or default credentials, and insufficient access controls rather than a specific software vulnerability.
Source: Fortinet

TrueConf Server Flaws Used to Poison Official Client Installers
Head Mare has exploited vulnerabilities in unpatched TrueConf servers to obtain elevated code execution and replace legitimate client installers with malicious versions. Victims downloading software from their own compromised server can consequently receive the PhantomCore backdoor and RAT through what appears to be a trusted distribution channel.
Source: The Hacker News

LiteLLM Supply Chain Incident Potentially Exposed Thousands of Organizations
New analysis of the LiteLLM supply chain compromise indicates that the credential collection period began days earlier than the short malicious PyPI release window originally highlighted. The reconstructed dataset contains more than 2,000 organization records and potentially exposed cloud credentials, CI/CD secrets, API keys, and other sensitive development infrastructure data.
Source: SOCRadar

ShieldBreak Bypasses Microsoft Defender RoguePlanet Fix
A new exploit chain called ShieldBreak was released as a bypass for Microsoft’s July fix for CVE-2026-50656, also known as RoguePlanet. The proof-of-concept demonstrates that a low-privileged local user can again reach SYSTEM-level privileges on tested Windows environments despite the earlier Defender engine update.
Source: Arctic Wolf

CopyEscape Turns docker cp Into a Container-to-Host Attack Path
CVE-2026-17106 allows a malicious Docker container or sandbox to create or overwrite files outside the destination selected during a copy operation. Depending on the privileges of the Docker CLI process, exploitation can lead to code execution on the host and, in some Linux scenarios, root-level compromise.
Source: Imperva

RovoBlast Turns a Single Link Into an AI-Assisted Data Exfiltration Path
Varonis demonstrated a vulnerability in Atlassian Rovo where attacker-controlled instructions embedded in a link could execute inside a trusted user session. Because Rovo can access Jira, Confluence, Bitbucket, and connected SaaS services, the technique could be used to extract organizational data without a traditional permission bypass.
Source: Varonis

Malicious MCP Servers Can Split Instructions to Exfiltrate Developer Secrets
Researchers demonstrated that a malicious Model Context Protocol server can distribute parts of an attack instruction across different tool fields so an AI coding agent reconstructs the request in context. The technique can lead agents to expose SSH keys, environment secrets, source code, and other data already accessible to the development environment.
Source: The Hacker News

DPRK-Linked npm Packages Use Ethereum Transactions to Locate Malware
Sonatype identified six npm packages carrying the same malicious payload, including three compromised legitimate packages. The packages use Ethereum transactions to locate infrastructure for additional JavaScript malware and share indicators with the North Korea-linked Contagious Interview campaign.
Source: Sonatype

Former Medusa Affiliate Deploys StormEncryptor After N-central Exploitation
Microsoft linked a new ransomware strain called StormEncryptor to Storm-1175, a financially motivated actor previously associated with Medusa ransomware. Recent attacks were likely preceded by exploitation of CVE-2026-18577 in N-able N-central, placing MSP and remote management infrastructure at the center of the intrusion path.
Source: BleepingComputer

Why Backup Isolation Is Just as Important as Backup Itself

If you ask most organizations today how they protect themselves from ransomware, you will often hear the same answer.

“We have backups.”

A few years ago, that was enough in many cases. Attackers encrypted the servers, the organization restored its data from backup, and business continued. Today, things are different.

Ransomware groups have long realized that the ability to recover is the biggest obstacle to a successful ransom demand, and backup is the most important part of that process. If an organization can restore its systems within a few hours, the incentive to pay quickly disappears. That is why modern attacks no longer focus only on production systems. They increasingly target backup infrastructure as well. Attackers are not just trying to encrypt your data. They are trying to take away your ability to recover it.

That is why the question is no longer whether you have backups. The real question is whether your backups can survive the attack. Many organizations only discover the difference when it is already too late. One of the most common scenarios starts in a very ordinary way. An attacker compromises a user account, expands access across the network, and eventually gains administrative privileges. From that point, user workstations are no longer the priority. The focus shifts to Active Directory, virtualization platforms, backup servers, and backup repositories. If the backup environment uses the same domain, the same administrative accounts, or sits on the same network as production systems, there is a good chance it will become part of the same incident.

At that point, the backup still exists. It is simply no longer available. In practice, this is often the difference between an incident that lasts a few hours and one that continues for days or even weeks. It is no longer unusual for attackers to spend days exploring an environment before launching ransomware. They want to understand how the network is built, where backup systems are located, whether administrators use the same credentials across the infrastructure, and whether backup copies can be deleted or encrypted. If they find those answers before launching the attack, the organization’s ability to recover quickly can disappear almost immediately. At that point, the attackers know that the pressure to pay the ransom has increased significantly. This is why backup isolation has become such an important topic.

Backup isolation is not simply about storing copies on another device or at another location. It means that compromising the production environment should not automatically mean compromising the backup environment as well. That includes separate administrative accounts, restricted network communication, dedicated privileges, multi-factor authentication for administrative access where appropriate, and, whenever possible, immutable backup copies that cannot be easily modified or deleted. The objective is not to make administration more complicated. The objective is to ensure that the last line of defense remains available when everything else has failed.

In practice, AresISEC often sees organizations investing heavily in reliable backup solutions while paying far less attention to protecting the backup infrastructure itself. Backups run successfully, reports show no errors, and everyone assumes recovery is covered. The problem only becomes visible when an attacker can reach the backup environment almost as easily as the administrators. That is not a backup software problem. It is an infrastructure design problem.

A good starting point is not another tool or another software license.  A good starting point is asking a few simple questions.

Could a compromised administrator account delete your backups?

Does the backup environment rely on the same authentication systems as production?

Could an attacker who gains access through a phishing attack eventually reach the backup infrastructure?

When was the last time you tested a full system recovery instead of restoring a single file?

And perhaps the most important question of all: how confident are you that your backups would still be available if the rest of the infrastructure were compromised?

The answers to those questions usually say far more about an organization’s resilience than a list of backup technologies ever will. This is no longer just considered good security practice. It is increasingly becoming a regulatory expectation. ISO 27001 requires organizations to implement appropriate controls for backup, restoration capability, and regular testing to support business continuity. NIS2 goes further by explicitly highlighting backup management, disaster recovery, and operational resilience as part of managing cybersecurity risk. The Cyber Resilience Act reinforces the same direction. Although it is most often discussed in the context of secure software development, its scope is much broader. Organizations developing products with digital elements will need to demonstrate that security has been considered throughout the entire product lifecycle. That includes vulnerability management, security updates, and the ability to recover reliably after a cybersecurity incident. Most provisions of the Cyber Resilience Act will apply from the end of 2027, while certain obligations, including reporting actively exploited vulnerabilities and significant incidents, apply earlier. For many organizations, backup and recovery will no longer be viewed solely as operational IT responsibilities, but also as regulatory requirements.

In the end, ransomware does not test the quality of your backup software. It tests how well your entire infrastructure has been designed. A backup that can be compromised as easily as the production environment is not your last line of defense. It is simply another system that will be lost during the same incident.

Sources:
CISA – Stop Ransomware Guide

ISO – ISO/IEC 27001 Information Security Management

European Union – NIS2 Directive

European Union – Cyber Resilience Act (Regulation (EU) 2024/2847)

How well is your backup protected against an attacker, not just against data loss?

Security Highlights Of The Week [07/26-3]

SonicWall SMA1000 Zero-Days Hit Remote Access Infrastructure
SonicWall confirmed active exploitation of two SMA1000 vulnerabilities, CVE-2026-15409 and CVE-2026-15410. The chain combines unauthenticated SSRF with code execution paths that can ultimately give attackers root-level control over exposed remote access appliances, making it one of the week’s most urgent edge-device stories.
Source: Help Net Security

Azure Permission Takeover Shows How One Credential Can Become Tenant-Wide Control
Sysdig documented an attack where a single leaked service principal credential turned into full Azure tenant compromise by the next morning. The attacker moved across multiple disconnected permission systems, established persistence on many identities, and seized visibility tooling meant to detect exactly this kind of intrusion.
Source: Sysdig

Hugging Face Discloses AI-Agent-Driven Internal Breach
Hugging Face said an autonomous AI agent system drove an intrusion from malicious dataset execution into internal clusters. The incident is notable not only because of the target, but because it is one of the clearest public examples so far of an end-to-end AI-assisted intrusion moving beyond proof-of-concept discussion.
Source: Hugging Face

AsyncAPI npm Compromise Pushes Multi-Stage Miasma Malware
Multiple official AsyncAPI npm packages were compromised and used to deliver a staged botnet loader tied to the Miasma family. The campaign shows that attackers are still finding ways around review controls by abusing repositories, publishing pipelines, and trusted package namespaces rather than relying on crude install-hook tricks alone.
Source: The Hacker News

Claude for Chrome Flaw Exposes Google Workspace Data
Researchers reported that Anthropic’s Claude for Chrome extension still contains unpatched issues that could let any extension with a content script on claude.ai trigger prompts against Gmail, Docs, and Calendar. In environments where users previously enabled more permissive execution settings, the impact rises from coerced approval to potentially silent enterprise data access.
Source: Manifold

ShinyHunters Tradecraft Shows How OAuth Abuse Becomes SaaS-Scale Access
Microsoft detailed how threat activity associated with ShinyHunters abused OAuth relationships, vishing, and trusted integrations to access SaaS applications such as Salesforce. The key lesson is that compromise can now spread through consent flows and business integrations that look legitimate enough to avoid many conventional login detections.
Source: Microsoft Security

Siemens ROX II Chain Delivers Persistent Root Access in OT Networks
Unit 42 and Siemens published a chained exploit involving three zero-days in Siemens ROX II switches. Together, the vulnerabilities allow privilege escalation and durable root-level access on devices that sit inside industrial control environments, which raises the operational importance well beyond a typical switch advisory.
Source: Unit 42

LegacyHive Adds Another Windows Zero-Day to the Nightmare Eclipse Stream
Nightmare Eclipse released LegacyHive, a local privilege escalation zero-day in the Windows User Profile Service. Even though the proof-of-concept was reportedly modified to make weaponization harder, the recurring public release of working Windows zero-days continues to create real defensive pressure around patch timing and local post-exploitation risk.
Source: SecurityWeek

Fake Coding Tests Hide OtterCookie-Aligned Malware in SVG Images
North Korea-linked operators behind the Contagious Interview cluster were observed using fake job and coding test lures that hid payload stages in SVG flag images. Victims who ran the project faced a multi-stage compromise that included credential theft, crypto wallet theft, remote access, and clipboard hijacking.
Source: The Hacker News

Ghostcommit Shows Prompt Injection Can Be Hidden Inside Images
Researchers demonstrated a pull request attack that hides prompt injection instructions inside a PNG image so AI code reviewers approve the change while missing the malicious logic. The technique matters because it targets a growing blind spot in AI-assisted development, where agents may inspect or process content differently from human reviewers.
Source: BleepingComputer

Chinese Operators Reportedly Used Claude Code and DeepSeek in Live Intrusions
Hunt.io described an intrusion campaign where Claude Code and DeepSeek were used as active parts of the operator workflow rather than as side tools. According to the report, they helped refine bypass methods, rework exploit logic after failure, and generate phishing infrastructure used against government and financial targets in four countries.
Source: Hunt.io

ClickLock Stealer Adds Another Modular macOS Threat to Watch
Group-IB uncovered a previously undocumented modular macOS stealer likely distributed through ClickFix-style pages, compromised WordPress sites, and Telegram infrastructure. The malware reportedly operates without elevated privileges or exploits, which makes the social engineering layer more important than any OS bypass.
Source: Group-IB

ACR Stealer Activity Rises Across Enterprise Environments
Microsoft observed increased ACR Stealer activity using ClickFix lures to steal browser credentials, tokens, and sensitive documents from enterprise systems. The campaigns reinforce how lightweight infostealers continue to be effective entry points for wider account compromise and follow-on cloud abuse.
Source: Microsoft Security

Accenture Confirms Breach After Source Code Theft Claims
Accenture confirmed a breach after a threat actor claimed to have stolen 35 GB of internal data, including source code, keys, and configuration material. Even without full public technical details, the incident stands out because of the type of data allegedly exposed and the risk it creates for downstream misuse.
Source: SecurityWeek

Fairlife Ransomware Incident Disrupts US Dairy Production
Coca-Cola disclosed that a ransomware attack affecting Fairlife disrupted production-related systems and temporarily halted dairy product manufacturing across the United States. It is a strong reminder that cyber incidents continue to move from IT inconvenience into direct operational and supply-chain impact in the physical economy.
Source: BleepingComputer

Security Highlights Of The Week [07/26-2]

Januscape Opens a New VM Escape Path on Both Intel and AMD
Researchers disclosed Januscape, a Linux KVM vulnerability that allows guest-to-host escape on both Intel and AMD systems. Because it affects the shadow MMU path in KVM and was reportedly used as a zero-day in Google’s kvmCTF program, it stands out as one of the most important virtualization flaws of the week.
Source: BleepingComputer

Critical Gitea Flaw Is Already Being Exploited
Researchers warned that attackers are actively exploiting CVE-2026-20896 in Gitea’s reverse-proxy authentication logic. On affected Docker deployments, a single crafted HTTP header can be enough to access internet-facing instances when only a valid username is known.
Source: SecurityWeek

Ubiquiti Ships Broad UniFi Security Fixes After Earlier Weaponization
Ubiquiti released updates for critical flaws across UniFi Connect, Talk, Access, Protect, and UniFi OS. The most notable point is that three UniFi OS bugs had already been flagged by CISA as weaponized in real-world attacks, so this is not a routine patch cycle.
Source: The Hacker News

Microsoft Closes the RoguePlanet Defender Zero-Day
Microsoft fixed RoguePlanet, tracked as CVE-2026-50656, through an update to the Microsoft Malware Protection Engine. The flaw allowed attackers to move from a standard user context to SYSTEM, making it highly relevant for post-compromise privilege escalation on Windows systems.
Source: Malwarebytes

Zimbra Urges Immediate Patching for Critical Web Client XSS
Zimbra warned customers to patch a critical stored XSS flaw in the Classic Web Client. The issue can be triggered through a specially crafted email and executes malicious code when the message is opened, which makes it especially dangerous in large mail environments.
Source: BleepingComputer

China-Aligned Cluster Targets Universities Through Roundcube
Proofpoint’s UNK_MassTraction activity is targeting Roundcube servers at US and Canadian universities, especially physics and engineering departments tied to sensitive research. The campaigns use multiple Roundcube n-days to steal credentials, deploy webshells, or load VShell directly into memory while keeping a low detection profile.
Source: Hackread

Fake IT Support Calls on Teams Are Delivering EtherRAT
Attackers are using Microsoft Teams voice calls, phishing emails, and remote management tooling to trick employees into installing EtherRAT. The campaign shows how collaboration platforms are now being used not just for phishing lures, but for live social engineering that creates immediate initial access.
Source: BleepingComputer

Vishing Campaigns Now Target Microsoft Entra Passkey Enrollment
Okta reported that a threat actor tracked as O-UNC-066 is using voice phishing and passkey-themed domains to push victims into fraudulent Microsoft 365 passkey enrollment flows. The campaign is aimed at enterprise targets across multiple sectors and is tied to data extortion rather than simple credential harvesting.
Source: Okta

Rogue Agent Shows How One Permission Could Poison Dialogflow CX
Varonis disclosed Rogue Agent, a Dialogflow CX issue that allowed persistent malicious code injection into conversational agent workflows. The attack could silently exfiltrate conversations and support phishing at scale, highlighting how cloud AI platforms are creating new privilege and trust-boundary problems.
Source: Varonis

HalluSquatting Turns AI Hallucinations Into a Supply Chain Attack Path
Researchers showed that attackers can register package names hallucinated by AI coding assistants and wait for those assistants to fetch or run them automatically. The result is a practical bridge between model hallucination and real code execution on developer machines, especially where agents are allowed to access outside resources with little review.
Source: The Hacker News

KDDI Says More Than 12 Million People Were Impacted by an ISP Platform Breach
Japanese telecom giant KDDI disclosed that a breach affecting a shared email platform exposed email addresses and passwords linked to more than 12 million people. The incident affected multiple ISPs and is one of the larger consumer-facing telecom breaches reported this week.
Source: BleepingComputer

GigaWiper Combines Backdoor Access With Destructive Sabotage Options
Microsoft detailed GigaWiper, a Golang-based backdoor that combines command-and-control capability with wiping, fake ransomware, and broader system sabotage. Its importance lies in how it assembles multiple malware capabilities into one flexible destructive platform rather than relying on a single fixed payload.
Source: Microsoft Security

WP-SHELLSTORM Exposed a Large Webshell Access-Broker Operation
SOCRadar says an exposed Python SimpleHTTPServer revealed the internal toolkit, logs, and target lists of a large WordPress-focused access-brokerage campaign. The exposed operation allegedly targeted more than 1.4 million domains, weaponized 27 CVEs, and maintained thousands of active webshells.
Source: SOCRadar

Talos Tracks UAT-7810 as It Expands ORB Infrastructure
Cisco Talos says UAT-7810 continues building and maintaining operational relay box networks through its LapDogs infrastructure and evolving SHORTLEASH malware. These ORB networks matter because they are designed to support secondary threat actors and provide resilient routing layers for future intrusions against high-value targets.
Source: Cisco Talos

ESET’s H1 2026 Report Shows the AI Skill Ecosystem Becoming a Security Problem of Its Own
ESET’s H1 2026 threat report says attackers are scaling established techniques faster and adapting them to new platforms, especially AI ecosystems. The report highlights nearly 900,000 AI skills analyzed in the first half of the year, including tens of thousands of suspicious and thousands of clearly malicious instances.
Source: ESET

Security Highlights Of The Week [07/26-1]

Cisco Confirms Active Exploitation of Unified CM Flaw
Cisco confirmed that attackers are now exploiting CVE-2026-20230 in Unified Communications Manager. The bug is an unauthenticated SSRF issue that can be triggered remotely with crafted HTTP requests, putting core enterprise telephony infrastructure at risk.
Source: BleepingComputer

FortiBleed Credential Theft Now Linked to Real Ransomware Deployments
SOCRadar linked FortiBleed to INC and Lynx ransomware operations, showing a direct path from FortiGate credential theft to follow-on intrusions. The campaign reportedly scanned over 11,000 FortiGate portals, gained confirmed admin access on hundreds of targets, and has already led to multiple ransomware incidents.
Source: The Hacker News

Over 900 Oracle E-Business Instances Are Exposed to Ongoing Attacks
Researchers warned that more than 900 Oracle E-Business Suite instances are exposed while threat actors actively exploit CVE-2026-46817. The flaw affects Oracle Payments and can allow unauthenticated takeover of vulnerable systems over HTTP.
Source: BleepingComputer

New CitrixBleed Vulnerability Was Exploited Less Than a Day After Disclosure
A new CitrixBleed-like flaw in NetScaler ADC and Gateway, CVE-2026-8451, was exploited almost immediately after public technical details appeared. The issue leaks memory from appliances configured as SAML identity providers, continuing the trend of rapid exploitation against remote access infrastructure.
Source: SecurityWeek

Microsoft SharePoint RCE Added to KEV After Active Exploitation
CISA added CVE-2026-45659 in Microsoft SharePoint Server to the Known Exploited Vulnerabilities catalog. The deserialization flaw is now being actively exploited, reinforcing the continued pressure on on-premises collaboration infrastructure.
Source: CISA

Splunk Enterprise RCE Reached Active Exploitation Status
CVE-2026-20253 in Splunk Enterprise is a critical unauthenticated remote code execution flaw in a PostgreSQL sidecar recovery path exposed through Splunk Web. After public analysis and proof-of-concept release, CISA added the issue to KEV and required rapid remediation.
Source: Zscaler ThreatLabz

BlueHammer Is Being Used in Real Ransomware Attacks
CISA warned that the Microsoft Defender privilege escalation bug known as BlueHammer is now being exploited in ransomware operations. The flaw was publicly disclosed before patching, and attackers appear to be using it to strengthen post-compromise access on Windows hosts.
Source: BleepingComputer

Trojanized CVE Proof-of-Concept Repositories Are Targeting Security Researchers
YesWeHack and Sekoia documented an ongoing campaign using malicious exploit repositories to compromise vulnerability researchers and pentesters. The campaign has been active since late 2025 and abuses the trust placed in public proof-of-concept code.
Source: YesWeHack

JADEPUFFER Shows the First Documented Agentic Ransomware Operation
Sysdig described JADEPUFFER as a fully automated extortion workflow driven end-to-end by a large language model. The actor exploited an exposed Langflow instance, adapted during the intrusion, and then pivoted into destructive database extortion without a traditional human operator driving each step.
Source: Sysdig

Vect and TeamPCP Formalize a Supply Chain and Ransomware Partnership
Sophos reported that Vect and TeamPCP are now working together, combining credential theft and supply chain compromise with ransomware deployment. The partnership shows how specialized criminal groups are increasingly linking initial access, data theft, and extortion into one coordinated pipeline.
Source: Sophos

Mustang Panda Targets India’s Government and Energy Sectors with New Tooling
Acronis tracked concurrent Mustang Panda campaigns against Indian government and hydropower targets. The operations used newly identified implants, including ZOHOMURK and MINIRECON, and abused Zoho WorkDrive as part of the intrusion chain.
Source: Acronis TRU

VeilDrop Uses Blogspot to Deliver an In-Memory Stealer Chain
Securonix analyzed VeilDrop, a multi-stage delivery chain that begins with a fake document script and uses Blogspot-hosted payload stages to deploy PureLog Stealer in memory. The campaign leans on trusted cloud infrastructure and layered obfuscation to reduce detection opportunities.
Source: Securonix

Iran-Linked TAG-182 Expands MarkiRAT Surveillance Operations
Recorded Future linked new infrastructure to TAG-182 and its use of MarkiRAT in Iranian surveillance campaigns. The operation appears focused on Iranians inside and outside the country and uses lures such as fake VPNs and download tools distributed through social platforms.
Source: Recorded Future

TONResolver Targets Japan’s Hotel Sector Using Blockchain-Based C2 Updates
Trend Micro described a phishing-led campaign against Japanese Booking.com partner organizations that deploys TONResolver RAT. The malware uses the TON blockchain as a dead drop resolver, giving operators a flexible way to rotate command-and-control endpoints without hardcoding them into the payload.
Source: Trend Micro

LSHIY Password Spray Campaign Made More Than 81 Million Login Attempts
Huntress observed a large automated password spraying campaign against Microsoft Azure CLI workflows originating from infrastructure linked to LSHIY. The activity produced over 81 million login attempts and compromised dozens of Microsoft accounts, including environments that already had Conditional Access in place.
Source: Huntress

Why Backup Often Fails When It Matters Most

Many organizations believe they are protected from ransomware simply because they have backups. On paper, that sounds reasonable. Backup jobs run, storage exists, retention is configured, and every morning someone sees the green status that everything completed successfully. That usually creates a sense of security. Until something actually happens.

The problem is that backup and recovery are not the same thing, even though many people treat them as if they are. Backup answers one question: did we save the data? It does not answer the harder one: can we bring everything back when the whole environment is under pressure? That difference becomes very clear during a serious incident. In many environments, backup is seen as a technical requirement that simply has to exist. The system shows successful backup jobs, administrators see that everything is running, and management assumes recovery is covered. But the real problems usually start when the system actually needs to be restored.

One of the common scenarios seen after ransomware incidents is that backups exist, but they can no longer be trusted. Not because the backup failed, but because the attacker reached it too. If backup infrastructure sits too close to production, uses the same access paths, or depends on the same privileged accounts, it can easily become part of the same incident. At that point, the backup technically still exists. But it no longer helps. Another issue appears when the restore works, but the system still does not. The data comes back, the application starts, but something around it no longer fits. A certificate has expired. A DNS record is missing. An integration points to an old address. The database version no longer matches. On paper, the restore was successful. In reality, the business is still down. This is the part many organizations underestimate. Recovery rarely means simply “bringing back the data”. You have to bring back everything around it too.

Time is another problem that often gets ignored until it becomes real. Restoring several terabytes of data sounds simple until you need to do it under pressure. What looks like a six-hour process on paper can easily turn into two days. And when critical systems are involved, two days are not just downtime. That means lost revenue, lost trust, and growing pressure. This is where chaos usually starts. What do you restore first? Email? Domain controllers? File servers? ERP? Most organizations do not have a clear answer until an incident forces them to decide. And that is usually where the most time gets lost.

In practice, AresISEC often sees organizations with technically healthy backup systems but no realistic understanding of what recovery would actually look like under pressure. The backup itself is usually not the problem. The real issues are access, dependencies, recovery time, and the order in which systems are brought back. That is where the real gap usually appears. A good starting point is not buying another backup solution. A good starting point is asking simple questions. How isolated is your backup from the production environment? Who has access to the backup infrastructure? How often do you test a full restore instead of only recovering single files? How long would it actually take to bring back your most critical systems? And if multiple systems fail at once, does the team know what comes first? These are not complicated questions, but they quickly show whether recovery is real or only assumed.

In many cases, small changes make the biggest difference. Separating backup access from the main environment, reducing privileges, defining recovery priorities, and testing restore processes under realistic conditions often improve resilience more than adding another tool. This also connects directly to broader security and compliance requirements. Under ISO 27001, backup and recovery are not just operational tasks. They are part of business continuity, system availability, and organizational resilience. Controls around backup protection, restoration capability, and regular testing are part of maintaining a functioning information security management system. NIS2 goes a step further. It explicitly requires measures related to backup management, disaster recovery, and crisis handling as part of operational resilience. This means recovery is no longer just a technical recommendation. For many organizations, it is becoming a regulatory expectation. In both cases, it is not enough to simply have backups. The expectation is that recovery is realistic, tested, and capable of supporting business continuity when systems fail. That is where many organizations discover the difference between what exists on paper and what actually works.

Because when things go wrong, the value of backup is not measured by whether it exists. It is measured by how quickly it gets you back to work.

Sources:

CISA – Stop Ransomware Guide

ISO – ISO/IEC 27001 Information Security Management

European Union – NIS2 Directive 

Do you know what recovery would actually look like if your systems went down tomorrow?

Security Highlights Of The Week [06/26-4]]

Ubiquiti Critical Vulnerabilities Are Now Being Exploited in Attacks
CISA warned that threat actors are actively targeting three critical UniFi OS flaws, all rated 10.0. The bugs allow unauthorized changes, file access, and deeper system manipulation on exposed devices, making this one of the most urgent edge infrastructure stories of the week.
Source: SecurityWeek

Cisco Unified CM Flaw Is Now Exploited in the Wild
Attackers are now exploiting CVE-2026-20230 in Cisco Unified Communications Manager. The issue starts as an unauthenticated SSRF flaw, but Cisco has already warned it can be used to write files and later escalate to root on affected systems.
Source: BleepingComputer

CISA Warns Lantronix EDS5000 Vulnerability Is Under Active Exploitation
CISA says CVE-2025-67038 in Lantronix EDS5000 devices is being actively exploited and has ordered rapid remediation. The flaw is a root-level command injection bug in the HTTP RPC module, which makes it especially dangerous for serial-to-IP infrastructure in operational environments.
Source: The Hacker News

PTC Windchill Sees First Confirmed Real-World Exploitation
Security researchers reported the first known in-the-wild exploitation of a PTC Windchill vulnerability. The bug allows unauthenticated remote code execution through crafted requests, and its abuse matters because Windchill sits deep inside product lifecycle and engineering environments.
Source: SecurityWeek

FFmpeg PixelSmash Can Turn a Malicious Media File Into Remote Code Execution
JFrog disclosed CVE-2026-8461, a high-severity flaw in FFmpeg’s MagicYUV decoder that can be exploited for reliable remote code execution. Since FFmpeg is embedded across video players, NAS devices, media servers, and cloud pipelines, the exposure goes far beyond a single application class.
Source: SecurityWeek

Vendor-Signed UEFI Applications Can Be Abused for Secure Boot Bypass
CERT warned that multiple vendor-signed UEFI applications are vulnerable to a Secure Boot bypass resembling a BYOVD style pre-boot attack. If a system trusts the affected certificate chain, an attacker can execute code before the operating system even starts, which raises the impact well beyond a normal post-boot compromise.
Source: CERT/CC

ShapedPlugin Supply Chain Compromise Backdoored Official WordPress Pro Releases
Wordfence reported that attackers compromised ShapedPlugin’s build and distribution pipeline and injected backdoor code into Pro plugin updates delivered through official channels. The case stands out because victims followed normal licensing and update practices and were still exposed through the vendor’s own update system.
Source: Wordfence

Mini Shai-Hulud Expanded Again Through LeoPlatform npm and Go Ecosystem Compromises
Socket tracked a new wave of the Miasma and Mini Shai-Hulud campaign affecting LeoPlatform and RStreams npm packages, GitHub Actions workflows, and a related Go module compromise. The operation continues to combine install-time execution, Bun-staged malware, CI secret theft, and AI assistant persistence into a broader developer ecosystem threat.
Source: Socket

Klue Salesforce Incident Has Now Hit BeyondTrust and LastPass
SecurityWeek reported that both BeyondTrust and LastPass were affected through the Klue incident, where a threat actor used a compromised legacy credential to generate OAuth tokens and access linked Salesforce environments. The story reinforces how third-party SaaS integrations can become a breach path into multiple downstream organizations at once.
Source: SecurityWeek

FortiBleed Shows a Large Russian Credential Harvesting Operation Against Fortinet Devices
SOCRadar’s analysis traces FortiBleed from mass reconnaissance and credential sourcing to passive sniffers, offline cracking, and targeted exfiltration. The investigation expanded from one exposed directory to more than 260 operation servers, suggesting a mature and persistent access-brokering pipeline built around Fortinet environments.
Source: SOCRadar

Photo Zip Campaign Targets Hospitality Firms with a Node.js Implant
Microsoft described an active intrusion campaign against hospitality organizations in Europe and Asia using photo-themed ZIP archives and fake image shortcut files. The chain leads to obfuscated PowerShell, a Node.js implant, registry-based persistence, and non-standard C2 communications for long-term access.
Source: Microsoft Security

Edgecution Uses a Malicious Microsoft Edge Extension to Break Out of the Browser
Zscaler linked a new malware delivery method called Edgecution to an initial access broker associated with Payouts King ransomware. By abusing the Chrome native messaging protocol through a rogue Edge extension, the attackers gain direct host access and move beyond the normal browser sandbox model.
Source: Zscaler ThreatLabz

Chinese Cluster CL-STA-1062 Targeted Southeast Asian Governments and Energy Entities
Unit 42 reported that CL-STA-1062 targeted government bodies and state-owned enterprises in Southeast Asia and used a mix of open-source tools and a newly documented backdoor called TinyRCT. The activity fits a sustained regional espionage pattern rather than a short-lived campaign.
Source: Unit 42

AutoJack Shows How One Web Page Can Turn an AI Agent Into a Host-Level Attack Path
Microsoft researchers detailed AutoJack, an exploit chain in AutoGen Studio that lets untrusted web content reach a local MCP WebSocket and spawn processes on the host. Although the affected surface never shipped in the PyPI release, the research is important because it demonstrates a real localhost trust-boundary failure in AI agent tooling.
Source: Microsoft Security

Cordyceps Exposes a Broad CI/CD Exploitation Pattern Across High-Impact Repositories
Novee said it found a systemic class of CI/CD weaknesses across roughly 30,000 high-impact repositories, including exploitable chains involving command injection, broken authentication logic, artifact poisoning, and privilege escalation in GitHub Actions workflows. The significance here is not a single product flaw, but a repeatable supply chain pattern that can scale across major open-source projects.
Source: Novee

Security Highlights Of The Week [06/26-3]

Megalodon Supply Chain Attack Compromised More Than 5,000 GitHub Repositories
Megalodon was one of the most significant developer ecosystem incidents in this batch, with attackers pushing thousands of commits across more than 5,000 public GitHub repositories in only a few hours. The campaign targeted GitHub Actions workflows and aimed to steal every secret available to runners, including cloud keys, SSH material, and OIDC tokens.
Source: InfoStealers

CISA Warns That Nx Console and GitHub Supply Chain Intrusions Are Hitting CI CD Pipelines
CISA said recent developer ecosystem intrusions, including the Nx Console compromise and the Megalodon campaign, show that threat actors are actively abusing CI CD tooling, code extensions, and workflows. The alert matters because it frames these incidents as a broader pattern rather than isolated package compromises.
Source: CISA

GitHub Rotates Enterprise Server Signing Key After Internal Repository Attack
GitHub said it recently detected a cyberattack and began rotating keys, including the GitHub Enterprise Server signing key, out of caution. This is a high impact follow up because the signing key is used to validate GitHub Enterprise Server binaries during manual update workflows.
Source: GitHub

Unfixed Gogs Vulnerability Allows Authenticated Remote Code Execution
Rapid7 disclosed a critical argument injection flaw in Gogs that allows any authenticated user to execute code on the server during a pull request rebase workflow. The vendor had not released a fix at publication time, which makes exposed self hosted Git environments especially risky.
Source: Rapid7

FortiClient EMS Is Being Exploited to Deliver EKZ Infostealer
Arctic Wolf observed attackers exploiting CVE-2026-35616 in FortiClient EMS and pushing a fake Fortinet patch that actually installed the EKZ infostealer. The malware focuses on browser credential theft, which turns an enterprise management weakness into a direct path for credential harvesting at scale.
Source: Arctic Wolf

Ghost CMS Flaw Was Used to Hijack More Than 700 Sites for ClickFix Attacks
Attackers exploited CVE-2026-26980 in Ghost CMS to inject malicious JavaScript into more than 700 sites and feed ClickFix attack chains. The campaign shows how compromising legitimate sites can give attackers trusted delivery infrastructure for broad social engineering operations.
Source: The Hacker News

Carnival Confirms Data Breach Affecting Nearly 6 Million People
Carnival confirmed a large scale data breach affecting nearly 6 million individuals after claims tied to ShinyHunters surfaced earlier in the year. The size of the exposure and the sensitivity of customer information make this one of the most significant breach confirmations in this set.
Source: BleepingComputer

Silent Ransom Group Is Social Engineering Law Firms by Posing as IT Support
The FBI and CISA warned that the Silent Ransom Group, also known as Luna Moth, is targeting law firms with calls and phishing emails while impersonating IT support. The group then uses legitimate remote access tools or even in person access attempts to exfiltrate data and pressure victims into paying.
Source: IC3

JOMANGY Campaign Turns FreePBX Systems Into Toll Fraud Infrastructure
Cyble linked an active FreePBX exploitation campaign to actor INJ3CTOR3 and said the operation deploys self healing webshells that include live toll fraud logic. The scale is notable, with evidence pointing to thousands of scanned IPs and ongoing abuse of victim SIP trunks for direct financial gain.
Source: Cyble

GlassWorm Botnet Was Disrupted After Months of Open Source Ecosystem Abuse
CrowdStrike, Google, and the Shadowserver Foundation disrupted the GlassWorm botnet by simultaneously taking down its command and control channels. The botnet had used blockchain, Google Calendar, BitTorrent, and VPS based infrastructure, showing how resilient its delivery model had become before the takedown.
Source: SecurityWeek

JINX-0164 Targeted Crypto Firms Through Developers and CI CD Infrastructure
Wiz described a financially motivated actor it tracks as JINX-0164 that used recruitment themed social engineering, custom macOS malware, and CI CD targeting against cryptocurrency organizations. The campaign matters because it combined employee laptop compromise with attempts to move into code distribution and development systems.
Source: Wiz

Smishing Operation Across 19 Countries Targeted Government, Postal, and Telecom Brands
Hunt.io traced what began as Romanian impersonation activity into a broader smishing operation spanning 19 countries. The infrastructure targeted government payment portals, postal services, and telecom brands, showing a coordinated cross border fraud ecosystem rather than a local campaign.
Source: Hunt.io

Fake ChatGPT Download Site Is Infecting Windows and Mac Users With Stealers
Malwarebytes warned that a fake site mimicking the ChatGPT desktop app experience is distributing malware to both Windows and macOS users. Windows visitors receive a credential stealing loader, while Mac users are served Odyssey Stealer, showing how attackers continue to weaponize trusted AI brand recognition.
Source: Malwarebytes

GREYVIBE Shows How Russia Nexus Operations Are Integrating AI Into Campaigns
WithSecure linked GREYVIBE to persistent operations targeting Ukraine and Ukraine related entities and said the group leveraged AI during both development and operational phases. That makes it one of the more concrete current examples of state aligned activity using AI beyond generic experimentation.
Source: WithSecure

Phishers Are Abusing Google AppSheet Notifications to Deliver Account Theft Emails
Kaspersky warned that attackers are using Google AppSheet to send phishing messages from legitimate looking Google linked addresses. This makes the emails more convincing and harder for users to distrust, especially because they appear to come from a real platform rather than an obviously fake sender.
Source: Kaspersky

Scroll to top