View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Canadian hacker pleads guilty after compromising 165 organizations

๐Ÿšจ ACTIVE EXPLOITATION

  • Hackers run khunt post-exploitation toolkit from Oracle database Hackers used an Oracle database to run the khunt post-exploitation toolkit.
    • Huntress observed the attack against a corporate network using an Oracle database server.
    • A public-facing Java application running Apache Tomcat was vulnerable to SQL injection through its autocomplete search endpoint.
    • Attackers stored khunt as Oracle Java objects and executed it through SQL commands.
    • khunt components enabled command execution, credential theft, file access, and archive extraction.
    • The attackers ran commands with Windows SYSTEM privileges and connected from 178.162.151[.]229. ๐Ÿ“Ž Coverage: bleepingcomputer.com ยท ๐Ÿ‘ via BleepingComputer

๐Ÿ’ฅ BREACHES & INCIDENTS

  • Canadian hacker pleads guilty after compromising 165 organizations Connor Moucka pleaded guilty to hacking at least 165 organizations and extorting victims.
    • Moucka and co-conspirators targeted at least 165 customers of a U.S.-based software-as-a-service company.
    • They stole billions of customer records and terabytes of data, affecting at least 100 million individuals.
    • The stolen data included call and text histories, financial information, payroll records, and identity documents.
    • Attackers used stolen login credentials to access cloud-hosted customer data and threatened to publish it.
    • They advertised stolen data on BreachForums, Exploit.in, XSS.is, and Telegram, collecting more than $2.5 million in ransom payments. ๐Ÿ“Ž Coverage: justice.gov ยท ๐Ÿ‘ via @metacurity@infosec.exchange

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Researchers Used a $50,000 Exploit Chain to Hijack Samsung Phones via Bixby Researchers demonstrated a chained attack that gained system-level control of Samsung phones through Bixby.

    • Samsung Galaxy S25, S24, and Flip 7 smartphones were successfully compromised; older devices may also be affected.
    • Samsung Members and Samsung Account vulnerabilities enabled attacks against phones with those apps installed.
    • Malicious ads or messaging links led victims to attacker-controlled websites.
    • CVE-2025-21079, CVE-2025-58486, and CVE-2025-58487 chained redirects, XSS, and Bixby access.
    • Abusing Bixby Capsules enabled sensitive-data theft, remote code execution, and system-level device control. ๐Ÿ“Ž Coverage: securityweek.com ยท ๐Ÿ‘ via SecurityWeek
  • Cyber Operations Become a Fourth Domain of Global Conflict Nation states increasingly use cyber operations to support geopolitical and military objectives.

    • Governments, militaries, and commercial enterprises face nation-state cyber operations.
    • China, Russia, Iran, and North Korea are identified as major state actors.
    • Operations target military capabilities, intelligence, and intellectual property through espionage.
    • Cyber activity can precede kinetic conflict or cause physical damage in cyber-kinetic attacks.
    • Nation-state campaigns are typically low and slow, emphasizing stealth and prolonged network dwell time. ๐Ÿ“Ž Coverage: securityweek.com ยท ๐Ÿ‘ via SecurityWeek
  • Malware Can Hijack Accounts Protected by Google-Synced Passkeys Palo Alto Networks researchers demonstrated malware attacks that hijack Google-synced passkey accounts.

    • The attacks target Google-synced passkeys used with Chrome on Windows machines.
    • Pass-ta-key malware accesses Chrome's local synchronization database and recovers a device identity key.
    • Windows cryptographic APIs let the malware sign Google authentication challenges without biometric verification, device unlock, or elevated privileges.
    • Silver Pass-ta-key registers an attacker-controlled verification key during Chrome re-registration.
    • Golden Pass-ta-key extracts a master secret from Chrome memory to decrypt synchronized passkey private keys. ๐Ÿ“Ž Coverage: securityweek.com ยท ๐Ÿ‘ via SecurityWeek
  • Brown Health Medical Group-MA Breach Affects 311,760 People A data breach at Brown Health Medical Group-MA affected 311,760 people.

    • Lifespan Physician Group of Massachusetts, doing business as Brown Health Medical Group-MA, was affected.
    • The breach exposed personal, medical, financial, personnel, and human resources information.
    • Attackers accessed a historic file server at the organization's Hawthorn location in December 2025.
    • The electronic health record system was not affected; no threat actor or ransomware group has claimed responsibility. ๐Ÿ“Ž Coverage: securityweek.com ยท ๐Ÿ‘ via Security

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check