๐ฅ BREACHES & INCIDENTS
-
Levi Strauss says social engineering attack stole corporate data Levi Strauss says hackers stole corporate information after compromising three employee computers.
- Levi Strauss & Co. was affected; consumer data was not impacted.
- An unauthorized third party accessed and exfiltrated certain corporate information.
- Attackers used social engineering to compromise three company-issued computers.
- The incident did not disrupt business operations; the investigation remains ongoing. ๐ Source: d18rn0p25nwr6d.cloudfront.net ยท ๐ Coverage: therecord.media ยท ๐ via BleepingComputer, @metacurity@infosec.exchange
-
UPDATE: Cyberattack disrupts gate operations at North Carolina's three ports A cyberattack disrupted operations at all three North Carolina port facilities.
- North Carolina Ports' Wilmington, Morehead City and Charlotte facilities were affected.
- The attack disrupted IT systems and port gate operations, causing delays.
- Port teams shifted to manual gate processing while restoring systems.
- The outside actor remains unidentified, and no sensitive-data compromise has been reported. ๐ Coverage: cyberscoop.com ยท ๐ via CyberScoop
๐ต๏ธ RESEARCH & DEEP DIVES
-
Attackers Abuse Commercial EDR Tools as Ransomware Trojan Horses Ransomware groups are increasingly disabling EDR tools before encrypting victim systems.
- Organizations using commercial EDR products are targeted.
- Ransomware operators disable EDR and antivirus tools before encryption.
- The Gentlemen ransomware group reverse-engineers Babuk, Qilin, LockBit 5.0 and Medusa samples.
- Halcyon recorded 1,988 publicly claimed attacks by 89 groups across 101 countries in Q2 2026. ๐ Source: halcyon.ai ยท ๐ Coverage: akamai.com ยท ๐ via Akamai Blog
-
TrustFall flaws undermine OP-TEE trusted execution environments ByteRay researchers disclosed vulnerabilities that undermine OP-TEE secure-world isolation.
- OP-TEE deployments in phones, TVs, cars, and industrial equipment are affected.
- The flaws can let the untrusted operating system reach into or crash the Secure World.
- The vulnerabilities were fixed upstream. ๐ Coverage: blog.byteray.co.uk ยท ๐ via r/netsec
-
Gen details H1 2026 business email and cryptocurrency hijacking attacks Gen reported two H1 2026 attack chains targeting business payments and cryptocurrency transfers.
- Business email users were targeted in a banking-malware campaign involving compromised inboxes and browser manipulation.
- Attackers used hijacked email conversations and browser manipulation to redirect business payments.
- Websites using Adform's compromised trackpoint-async.js script were exposed to cryptocurrency theft.
- The script monitored clipboard contents and replaced Bitcoin, Ethereum, and TRON wallet addresses with attacker-controlled addresses.
- Malicious Adform scripts contacted 84.32.102[.]230:7744 and were not detected by available VirusTotal antivirus engines. ๐ Coverage: bleepingcomputer.com ยท ๐ via BleepingComputer
๐ ADVISORIES
- stb TrueType library heap overflow affects versions through 1.26
CVE-2026-18497The stb TrueType library contains a heap buffer overflow in its font parser.- Applications using nothings/stb TrueType library version 1.26 or earlier are affected.
- Malformed TrueType font files can trigger a heap buffer overflow during glyph-shape parsing.
- An inflated endPtsOfContours value and truncated glyph data cause out-of-bounds reads, potentially enabling denial of service or information disclosure. ๐ Source: github.com ยท ๐ Coverage: kb.cert.org ยท ๐ via CVE ThreatInt, CERT/CC Vulnerability Notes
๐ CVEs & KEV
- CVE-2022-4995 โ CVSS 9.3 โ Weaver E-cology 9.0 File Upload RCE via uploaderOperate.jspWeaver (Fanwei) E-...