๐จ ACTIVE EXPLOITATION
- Silent Ransom Group Extracted $28 Million in Two Attacks
Silent Ransom extracted $28 million from two attacks.
- Silent Ransom, also known as Luna Moth, Chatty Spider and UNC3753, targets U.S. law firms and organizations in finance, insurance and healthcare.
- The group steals sensitive data, including legal records, and threatens public exposure to pressure victims into paying.
- Attacks begin with phishing emails or phone calls seeking credentials or remote-access software.
- When remote social engineering fails, operatives pose as IT workers and enter offices to image computers or create backups. ๐ Coverage: cutoday.info ยท ๐ via @campuscodi@mastodon.social
๐ต๏ธ RESEARCH & DEEP DIVES
- HTTP/3 Trailer HEADERS frame causes Google ESF hangs and QUIC errors
A malformed HTTP/3 Trailer HEADERS frame can hang Google ESF for 60 seconds.
- Google ESF deployments using HTTP/3 are affected.
- Trailer HEADERS frames trigger an unhandled exception.
- The connection hangs for about 60 seconds and returns QUIC INTERNAL_ERROR 0x0001. ๐ Coverage: netacoding.com ยท ๐ via r/netsec
๐ CVEs & KEV
- CVE-2026-64638 โ CVSS 8.9 โ No Title