View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

Jewelbug Runs Government Espionage and Crypto Fraud From One Panel

๐Ÿ’ฅ BREACHES & INCIDENTS

  • Third-party breach exposes data from 300 Scottish prosecution staff A supplier breach may have exposed personal data belonging to around 300 COPFS staff.

    • The affected organization is Scotland's Crown Office and Procurator Fiscal Service (COPFS).
    • Names, roles, work email addresses and other employment data from a Scottish Government survey may have been accessed.
    • The data came from an online data maturity assessment managed by an external supplier.
    • The supplier detected suspicious activity on August 5; COPFS systems and confidential casework were not affected. ๐Ÿ“„ Source: copfs.gov.uk ยท ๐Ÿ“Ž Coverage: theregister.com ยท ๐Ÿ‘ via Dark Reading
  • ExfilSquad targets misconfigured Microsoft Power Pages portals ExfilSquad stole data from publicly accessible Microsoft Power Pages portals.

    • Organizations using Microsoft Power Pages and Dataverse are affected.
    • Exfiltrated data may include names, email addresses, phone numbers, customer records and business information.
    • ExfilSquad searched the internet for portals with overly broad anonymous permissions.
    • The group accessed Dataverse records without exploiting a software flaw or deploying malware. ๐Ÿ“„ Source: venarix.com ยท ๐Ÿ“Ž Coverage: msdynamicsworld.com ยท ๐Ÿ‘ via Cybersecurity Dive

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Jewelbug Runs Government Espionage and Crypto Fraud From One Control Panel Jewelbug is using shared infrastructure to conduct cyberespionage and cryptocurrency fraud.
    • Governments, militaries, telecom providers, and Chinese-speaking cryptocurrency users in Asia and the Middle East are affected.
    • The group compromised more than 15 government webmail tenants and stole over 580,000 browser cookies, thousands of credentials, and 2,300 email bodies.
    • A watering-hole script on shared webmail infrastructure connected victims to attacker-controlled WebSockets and delivered fake Adobe updates.
    • The XG-Web platform remotely controlled Chrome and Firefox through a malicious "PDF Viewer" extension, while Antino targeted Windows and ClientKing targeted Linux, ARM64 devices, and ASUS routers.
    • Observed tooling included Antino samples named flashcenter_pp_ax_install_en.exe and Adobe_installer (1).exe. ๐Ÿ“Ž Coverage: securityboulevard.com ยท ๐Ÿ‘ via securityboulevard.com (discovered)

๐Ÿ”“ CVEs & KEV

  • CVE-2026-19871 โ€” CVSS 9.3 โ€” Use of hard-coded credentials in Prospero Flow CRM employee onboardingUse of ...
  • CVE-2026-19884 โ€” CVSS 8.4 โ€” In Eclipse Theia versions up to and including 1.69.0, opening a folder starts...
  • CVE-2026-63700 โ€” CVSS 7.8 โ€” Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Inco...
  • CVE-2026-66271 โ€” CVSS 7.2 โ€” Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unre...
  • CVE-2026-66270 โ€” CVSS 7.2 โ€” Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unre...
  • CVE-2025-11226 โ€” CVSS 7.0 โ€” Incomplete protection against CVE-2025-11226Path-traversal vulnerability in Q...
  • CVE-2026-58224 โ€” CVSS 6.5 โ€” Samba: ctdb fails to do integrity checking of received packetsA flaw was foun...
  • CVE-2026-63701 โ€” CVSS 6.3 โ€” Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Impr...
  • CVE-2026-63702 โ€” CVSS 6.3 โ€” Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Use o...
  • CVE-2026-19880 โ€” CVSS 6.3 โ€” Incomplete protection against CVE-2025-11226Path-traversal vulnerability in Q...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check