View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

StopAndProtect Ransomware Targets Thousands of WordPress Sites

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • Check Point Unmasks StopAndProtect Ransomware Operation Targeting WordPress Sites
    Check Point Research identified a ransomware operation targeting thousands of WordPress sites.

    • WordPress site owners are affected, with thousands of sites reportedly hacked.
    • The StopAndProtect ransomware family was first observed in mid-May 2026.
    • The infection chain begins with ClickFix social engineering that tricks victims into executing a PowerShell command.
    • The PowerShell command downloads two additional stages.
      πŸ“Ž Coverage: research.checkpoint.com Β· πŸ‘ via Check Point Research
  • TWINLOOT Uses Microsoft Cloud Services for Stealthy C2 and Credential Theft
    Ontinue has uncovered TWINLOOT, a Python implant that hides C2 inside Microsoft services.

    • Microsoft 365 and Windows environments using SharePoint, Teams, and Edge are affected.
    • TWINLOOT steals Windows credentials, executes commands, enables SOCKS5 lateral movement, and persists without administrator rights.
    • Teams social engineering impersonating IT support tricks victims into running a PowerShell command that downloads an archive containing a Python runtime and the 39 MB bootstrap-fat.pyc loader.
    • The implant polls an attacker-controlled SharePoint drive through Microsoft Graph every 15 seconds and routes interactive access through Teams TURN WebRTC DataChannels.
    • A headless Edge browser controlled through Chrome DevTools Protocol makes Graph API traffic appear legitimate; lateral connections can use SMB 445, RDP 3389, WinRM 5985, and MSSQL 1433.
      πŸ“„ Source: ontinue.com Β· πŸ“Ž Coverage: thehackernews.com Β· πŸ‘ via Dark Reading, The Hacker News
  • Researchers Show β€œMind Viruses” Can Propagate Between AI Agents
    Anthropic and EPFL researchers demonstrated self-propagating payloads moving between AI agents through persistent prompt files.

    • The technique affects autonomous AI agents and multi-agent coding harnesses that reload editable prompt files between sessions.
    • Ideological and action payloads targeted agent goals and behavior, including file deletion, Git tampering, and shell-script execution.
    • Agents propagated payloads by writing them to SOUL.md, which was injected into the next session’s system prompt; 55% of such attempts infected the next agent.
    • In tests, four action payloads survived 20-hop agent chains, but researchers found no evidence of successful propagation in the wild or on Moltbook.
      πŸ“„ Source: arxiv.org Β· πŸ“Ž Coverage: thehackernews.com Β· πŸ‘ via The Hacker News
  • StubMaker Typosquats 16 RubyGems Packages to Steal Credentials and Wallets
    StubMaker malware targeted RubyGems users with a Windows information stealer.

    • RubyGems users on Windows were targeted by the StubMaker campaign.
    • Sixteen typosquatted gems mimicked dependencies including bundler, i18n, rake, and activesupport.
    • Install-time extconf.rb hooks executed a 22 MB Rust loader containing an 11 MB Go stealer.
    • The malware harvested Chromium browser credentials, wallet data, seed phrases, Telegram data, and system information.
    • Packages included ubnuler, ubnlder, ri18nr, reaker, rakier, orakw, joxn, ise18n, ioe18n, ie18u, iai8n, i1l8n, i18om, activesupmport, brumdler, and brundlef.
      πŸ“„ Source: opensourcemalware.com Β· πŸ“Ž Coverage: thehackernews.com Β· πŸ‘ via The Hacker News
  • Audit finds RCE-by-design flaws across seven AI orchestration platforms
    An audit found 14 security findings across seven AI orchestration platforms.

    • The findings affect NocoBase, Flowise, Langflow, Dify, Activepieces, Kestra, and Airflow deployments.
    • The platforms allow workflow users to execute code on the host, creating remote-code-execution exposure in multi-tenant HTTP services.
    • A Flowise chain uses an unauthenticated webhook, prompt injection, and LLM-generated Python code.
    • Flowise’s 38-pattern regex blocklist can be bypassed because a dangerous library is pre-imported before the LLM generates code.
    • Two vendors classified their reported findings as working as intended.
      πŸ“Ž Coverage: endorlabs.com Β· πŸ‘ via r/netsec
  • Octagon Android Bot Targets Crypto Wallets and Banking Apps
    iVerify identified Octagon as an Android bot targeting crypto wallets and banking apps.

    • Android users of crypto wallets, exchanges, banking apps, and messaging services are targeted by AndroidKitKat’s MaaS platform.
    • Octagon steals seed phrases, passwords, PINs, unlock patterns, balances, SMS messages, and one-time codes.
    • WardAccessibilityService reads app interfaces and places HTML WebView phishing overlays over legitimate apps.
    • Hidden VNC-style control enables screen viewing, screenshots, taps, swipes, text entry, and app launches.
    • Sideloaded APKs disguise the malware as unrelated apps; version 1.2 was announced June 29, 2026, with C2 at 45.192.12[.]34:4444 and 104.251.180[.]179:4444.
      πŸ“„ Source: iverify.io Β· πŸ“Ž Coverage: gbhackers.com Β· πŸ‘ via cryptika.com (discovered)

πŸ“‹ ADVISORIES

  • πŸ“„ Source for CISA Says Ransomware Gangs Exploit Windows Task Host Flaw β€” nvd.nist.gov

  • πŸ“„ Source for C2Looper Backdoor Uses OneDrive Sideloading and GitHub for C2 β€” zscaler.com

πŸ”“ CVEs & KEV

  • CVE-2026-75851 β€” CVSS 9.4 β€” ArcadeDB before 26.8.1 Authentication Bypass via Async CommandArcadeDB server...

  • CVE-2026-75843 β€” CVSS 9.4 β€” ArcadeDB before 26.8.1 Privilege Escalation via gRPC TransactionArcadeDB befo...

  • CVE-2026-75854 β€” CVSS 9.3 β€” ArcadeDB Redis Wire-Protocol Plugin Missing AuthenticationArcadeDB versions b...

  • CVE-2026-75852 β€” CVSS 9.3 β€” ArcadeDB MongoDB wire protocol authentication bypass cross-databaseArcadeDB v...

  • CVE-2026-75837 β€” CVSS 9.3 β€” Grav before 2.0.14 Privilege Escalation via Group Access FieldGrav before 2.0...

  • CVE-2026-75835 β€” CVSS 9.3 β€” Grav API Plugin before 1.0.14 Missing AuthorizationGrav API plugin (getgrav/g...

  • CVE-2026-75853 β€” CVSS 8.7 β€” ArcadeDB Gremlin Wire Protocol Authorization Bypass Cross-DatabaseArcadeDB's ...

  • CVE-2026-75840 β€” CVSS 8.7 β€” ArcadeDB before 26.8.1 Arbitrary File Read via Unescaped RegexArcadeDB before...

  • CVE-2026-75836 β€” CVSS 8.7 β€” Grav API Plugin before 1.0.14 Missing AuthorizationThe Grav API plugin (getgr...

  • CVE-2026-75855 β€” CVSS 8.4 β€” ArcadeDB before 26.8.1 Path Traversal via create/drop databaseArcadeDB versio...

  • CVE-2026-75842 β€” CVSS 8.3 β€” ArcadeDB before 26.8.1 Arbitrary File Read via LOAD CSVArcadeDB versions befo...

  • CVE-2026-75846 β€” CVSS 7.1 β€” ArcadeDB before 26.8.1 Unauthorized Function Deletion via DELETE FUNCTIONArca...

  • CVE-2026-75844 β€” CVSS 7.1 β€” ArcadeDB before 26.8.1 SSRF via IMPORT DATABASE validator bypassArcadeDB vers...

  • ai-driven-patch-prioritization β€” SecurityWeek

  • ransom-busters-ransomware-deception β€” Dark Reading

  • octagon-android-otp-theft β€” Cyber Security News

  • πŸ“„ Source for CISA Says Ransomware Gangs Exploit Windows Task Host Flaw β€” nvd.nist.gov

  • πŸ“„ Source for C2Looper Backdoor Uses OneDrive Sideloading and GitHub for C2 β€” zscaler.com

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check