π¨ ACTIVE EXPLOITATION
-
SilkParasite Targets Central Asian Governments With Seven RAT Families
SilkParasite targeted Central Asian government bodies with seven remote access tool families.- Government entities in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Kazakhstan, and Georgia were targeted.
- The China-nexus cluster used seven RAT families, including five newly documented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT.
- Spear-phishing emails delivered password-protected RAR archives containing malicious Microsoft Office documents.
- Opening the documents triggered macros and DLL sideloading; the macro checked for Kaspersky antivirus before execution.
- The implants used modular plugins and C2 through Google Drive, HTTP Cookie/ETag headers, and attacker servers; about 65 DriveSilkRAT infections were observed.
π Source: businessinsights.bitdefender.com Β· π Coverage: thehackernews.com Β· π via The Hacker News, securityboulevard.com (discovered)
-
Balonx Sistema Uses AI Voice Calls to Bypass MFA and Steal Bank Accounts
Hackers are using AI voice calls and fake banking pages to steal accounts.- Banking customers are targeted in the Balonx Sistema campaign.
- Fake banking pages capture login details and MFA information.
- AI-generated phone calls guide victims through the phishing process.
- Attackers monitor victimsβ sessions live and request information when needed.
π Coverage: cybersecuritynews.com Β· π via Cyber Security News
π₯ BREACHES & INCIDENTS
- Leak Exposes 669 Stripe Vendors and 1,033 Live API Keys
Threat actors exposed Stripe vendor data and live API keys in a forum release.- The exposure affected 669 businesses using Stripe across multiple industries and countries.
- The leak included 1,033 API keys, customer records, invoices, balances, charges, payouts, and promotional codes.
- Exposed records contained names, email addresses, phone numbers, home addresses, IP addresses, purchase histories, and card last four digits.
- Threat actor Satanic published a 33GB release on pwnforums and claimed access to about 20,000 Stripe APIs.
- Live keys could enable programmatic customer-data access, unauthorized refunds, account changes, and payment rerouting.
π Coverage: infostealers.com Β· π via Cyber Security News, r/cybersecurity
π΅οΈ RESEARCH & DEEP DIVES
-
Password-spraying attacks surge 155x as MFA gaps leave logins exposed
Huntress observed a 155-fold increase in password-spraying attacks during H1 2026.- Organizations using legacy authentication or incomplete MFA coverage were targeted.
- Attackers generated more than 81 million login attempts in a two-week campaign.
- Legacy authentication flows allowed password-only access despite MFA policies.
π Coverage: bleepingcomputer.com Β· π via BleepingComputer
-
CRLF Injection Enables HTTP Desynchronization Across Reverse Proxies
Researchers demonstrated CRLF injection techniques that induce HTTP desynchronization across reverse proxies.- Reverse proxies, CDNs, payment providers, and multi-tenant web applications are affected.
- A single path-injected CRLF can trigger request splitting, response-queue poisoning, and HTTP request smuggling.
- Nginx $uri normalization enables CL.TE and 0.CL desynchronization, cache poisoning, and tunneling.
- Browser-relocated techniques can cause connection- and IP-locked desyncs, XSS, and HttpOnly cookie theft.
π Source: portswigger.net Β· π Coverage: core-jmp.org Β· π via r/netsec
-
ValleyRAT campaign targets Indian taxpayers with fake overdue GST notices
A ValleyRAT campaign is phishing Indian taxpayers with fake overdue GSTR-3B notices.- Indian taxpayers and GST filers are targeted.
- The campaign impersonates a GSTR-3B overdue notice.
- The fraudulent tax notice serves as the phishing lure for ValleyRAT malware.
π Coverage: blog.himanshuanand.com Β· π via r/netsec
π CVEs & KEV
-
CVE-2026-76233 β CVSS 8.4 β Renovate 39.53.0 before 40.33.0 Command Injection via gleam managerRenovate v...
-
CVE-2026-76232 β CVSS 8.4 β Renovate 31.51.0 before 40.33.0 Command Injection via helmv3Renovate versions...
-
CVE-2026-76231 β CVSS 8.4 β Renovate 32.135.0 before 40.33.0 Command Injection via hermitRenovate version...
-
CVE-2026-76230 β CVSS 8.4 β Renovate 35.63.0 before 40.33.0 Command Injection via npmRenovate versions fr...
-
CVE-2026-76229 β CVSS 8.4 β Renovate 39.218.0 before 40.33.0 Arbitrary Command Injection via kustomizeRen...
-
CVE-2026-76228 β CVSS 8.4 β Renovate before 42.68.5 Remote Code Execution via Gradle WrapperRenovate vers...
-
CVE-2026-43961 β CVSS 7.8 β Vim: vimscript injection via unescaped filename in netrw s:netrwmarkfile() fi...
-
CVE-2026-54794 β CVSS 7.2 β Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side R...
-
CVE-2026-76227 β CVSS 6.8 β Renovate 42.68.1 before 42.96.3 Environment Variable ExposureRenovate version...