View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Ransomware Gangs Exploit VPN and Firewall Flaws in Palo Alto

🚨 ACTIVE EXPLOITATION

  • Ransomware Gangs Exploit VPN and Firewall Flaws in Palo Alto, Fortinet, Citrix, Check Point
    Ransomware operators are exploiting VPN and firewall vulnerabilities from four major vendors to breach corporate networks.

    • Targets include Palo Alto Networks, Fortinet, Citrix, and Check Point VPN and firewall appliances
    • Exploitation involves authentication bypass, credential harvesting, and legacy protocol weaknesses
    • Notable campaigns: Fortibleed mass credential compromise of FortiGate devices, Palo Alto GlobalProtect CVE-2026-0257 bypass
    • Check Point CVE-2026-50751 IKEv1 authentication bypass exploited by Qilin ransomware affiliates
    • Citrix NetScaler CVE-2026-8451 memory disclosure exploited within 24 hours of disclosure
      πŸ“Ž Coverage: cybersecuritynews.com Β· πŸ‘ via Cyber Security News
  • East Asian-linked TELESHIM malware abuses Telegram for C2 in Middle East govt attacks
    A new malware campaign using TELESHIM abuses Telegram for command-and-control in Middle East government attacks.

    • Targets government entities in the Middle East with previously unreported malware TELESHIM, MIXEDKEY, and BINDCLOAK
    • Attack begins with ISO file deploying a legitimate executable to sideload TELESHIM backdoor DLL
    • TELESHIM uses Telegram API for C2 communication to blend with legitimate traffic and evade detection
    • Employs heavy code obfuscation and virtualization detection to hinder analysis and reverse engineering
    • Final payload BINDCLOAK is a 64-bit implant contacting external C2 server cert.hypersnet[.]com
      πŸ“Ž Coverage: thehackernews.com Β· πŸ‘ via The Hacker News
  • SparkKitty malware steals crypto wallet seed phrases from iOS and Android photos
    SparkKitty malware steals cryptocurrency wallet seed phrases by scanning photos on mobile devices.

    • Targets cryptocurrency users on iOS and Android devices
    • Steals wallet seed phrases hidden in screenshots and gallery images using OCR technology
    • Spreads via trojanized apps on official app stores and third-party sideloading channels
    • Requests photo access to scan images and sends extracted data to attacker-controlled servers
    • Notable infected apps include iOS app '币coin' and Android app 'SOEX' with over 10,000 Google Play downloads
      πŸ“Ž Coverage: cybersecuritynews.com Β· πŸ‘ via Cyber Security News
  • BlueNoroff Hijacks Trusted Telegram Accounts to Spread ClickFix Malware via Fake Zoom Calls
    BlueNoroff hijacks Telegram accounts to deliver ClickFix malware through fake Zoom and Teams invites.

    • Targets senior staff at cryptocurrency and Web3 firms using hijacked Telegram accounts of trusted contacts
    • Delivers fake Zoom and Microsoft Teams meeting links that lead to ClickFix malware installation
    • Attack uses deepfake video calls and clipboard hijacking to run PowerShell loaders and macOS shell scripts
    • Malware scans browsers for crypto wallets before stealing credentials and funds
    • Indicators include multiple malicious domains, PowerShell loaders, VBScript implants, and Mach-O binaries
      πŸ“Ž Coverage: cybersecuritynews.com Β· πŸ‘ via Cyber Security News

πŸ’₯ BREACHES & INCIDENTS

  • DentaQuest Data Breach in May 2026 Potentially Affects Over 23 Million People
    Hackers stole personal and dental health information from DentaQuest's network in May 2026.
    • Applies to DentaQuest customers, a dental and vision benefits administrator serving 35 million people
    • Stolen data includes names, addresses, Social Security numbers, member IDs, Medicaid/Medicare numbers, diagnosis, treatment, and billing details
    • Attackers accessed the network between May 17 and May 20, 2026
    • Extortion group ShinyHunters claimed responsibility and leaked approximately 234 GB of data
    • At least 15 million individuals confirmed affected; over 23 million potentially impacted according to HIPAA Journal
      πŸ“Ž Coverage: securityweek.com Β· πŸ‘ via SecurityWeek

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • Hackers Create Over 70 Fake Websites Impersonating Popular Windows Apps to Spread Malware
    Hackers are using fake websites mimicking popular Windows apps to distribute malware.
    • Targets over 70 popular Windows utilities including PowerToys, WinUtil, EasyBCD, and CrystalDiskMark
    • Attackers register domains closely matching app names and use old logos and guides to appear legitimate
    • Fake sites initially offer real downloads to build trust before swapping in malware payloads
    • Malware includes remote access tools and bandwidth sharing software delivered via trojanized installers
    • Infrastructure uses anonymized WHOIS email and proxy hosting to evade takedown efforts
      πŸ“Ž Coverage: cybersecuritynews.com Β· πŸ‘ via Cyber Security News

πŸ“‹ ADVISORIES

  • GitHub Adds 3-Day Cooldown to Dependabot to Limit Poisoned Package Adoption
    GitHub introduced a 3-day cooldown in Dependabot to delay updates and reduce supply chain attack risks.
    • Applies to GitHub Dependabot users managing software dependencies
    • Cooldown delays pull requests for version updates by at least three days after release
    • Security updates bypass cooldown and are pushed immediately
    • Aims to reduce risk from short-lived poisoned package versions spreading quickly
    • Cooldown duration is configurable via dependabot.yml and defaults to three days
      πŸ“Ž Coverage: thehackernews.com Β· πŸ‘ via The Hacker News

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check