๐จ ACTIVE EXPLOITATION
- New XCSSET malware variant targets macOS developers via compromised Xcode projects
XCSSET malware infects macOS developers through compromised Xcode projects and GitHub repositories.
- Targets macOS developers using Xcode projects and GitHub repositories
- Malware spreads by injecting downloader scripts into benign Xcode project files
- Version 40 includes Chrome hijacker and Telegram trojanizer modules
- Uses evasion techniques like loader recompilation, encryption, and macOS security disabling
- Infection chain enables credential theft, keystroke logging, browser hijacking, and data exfiltration ๐ Coverage: bleepingcomputer.com ยท ๐ via BleepingComputer
๐ฅ BREACHES & INCIDENTS
-
Beacon CRM hacked, exposing contact data of multiple UK cultural and charity organisations Beacon CRM suffered a cyberattack exposing contact data of numerous cultural and charity organisations.
- Applies to customers of Beacon CRM, including English National Ballet, Chiswick House and Gardens Trust, Centre for Sustainable Energy
- Data exposed includes names, email addresses, business phone numbers, business addresses, donation dates and amounts
- Attack involved unauthorized access via compromised credentials and likely downloading of database backups
- No passwords, payment details, or bank account information were exposed
- Incident discovered on July 29, 2026; forensic investigation and containment actions underway ๐ Coverage: artsprofessional.co.uk ยท ๐ Original: cse.org.uk ยท ๐ via @campuscodi@mastodon.social
-
Coinkite halts Coldcard wallet sales after $100M theft via hardware exploit Hackers exploited a bug in Coinkite Coldcard hardware wallets to steal nearly $100 million.
- Applies to Coinkite Coldcard hardware crypto wallets with vulnerable firmware
- Attack exploited a firmware bug allowing theft of funds from offline wallets
- Coinkite destroyed all remaining vulnerable Coldcard inventory and halted shipments
- Patched firmware prevents new seeds from being compromised but not existing ones
- Other wallets like SATSCARD, OPENDIME, and TAPSIGNER are unaffected ๐ Coverage: blog.coinkite.com ยท ๐ Original: blog.coinkite.com ยท ๐ via @campuscodi@mastodon.social
๐ต๏ธ RESEARCH & DEEP DIVES
-
Smoke#Screen Campaign Uses ScreenConnect RMM for Persistent Phishing Attacks Attackers use phishing to deliver ScreenConnect RMM for persistent remote access.
- Targets organizations using ScreenConnect Remote Monitoring and Management (RMM) tool
- Employs diverse social engineering lures including fake Zoom and Adobe updates, document requests, and system maintenance prompts
- Delivers rotating payloads such as VBScript droppers, batch loaders, .NET executables, and HTML phishing pages
- Installs ScreenConnect agent silently to maintain legitimate-appearing remote access on Windows and macOS
- Uses evasion techniques like Cloudflare tunnels, Dropbox, and ConnectWise-signed binaries to bypass detection ๐ Coverage: darkreading.com ยท ๐ via Dark Reading
-
77 Open VSX Extensions Impersonated Legitimate Tools to Harvest Developer Info 77 malicious Open VSX extensions harvested developer environment data.
- Targets: Developers using Open VSX marketplace extensions
- Malicious extensions impersonated legitimate tools with low version numbers (mostly 0.0.1)
- Data exfiltration included system info, Git metadata, CI environment details, and workspace paths
- Extensions communicated with mangorbit.com domains to send harvested data
- No source code, credentials, or tokens were accessed, but extensive environment profiling was done ๐ Coverage: bleepingcomputer.com ยท ๐ via BleepingComputer
๐ OTHER
- Microsoft Defender isolates QNET endpoint in 128 seconds to stop ransomware attack
Microsoft Defender automatically isolated a compromised QNET endpoint to stop a ransomware attack.
- Applies to QNET, a global direct-selling company using Microsoft Defender with attack disruption enabled
- Attack involved a multi-stage ransomware using living-off-the-land (LOL) techniques on a compromised Windows endpoint
- Defender used new device isolation action to block all external network connectivity within 128 seconds
- Isolation prevented second-stage payload persistence, lateral movement, credential theft, and data exfiltration
- Device isolation is AI-driven, triggered at 99% confidence, and maintains access to security services during isolation ๐ Coverage: microsoft.com ยท ๐ Original: microsoft.com ยท ๐ via Microsoft Security Blog
๐ CVEs & KEV
-
Other: 20 CVEs (worst 8.2)
-
us-water-systems-cyberattacks-2026 โ @campuscodi@mastodon.social