View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Leak Exposes 669 Stripe Vendors and 1,033 Live API Keys

🚨 ACTIVE EXPLOITATION

  • SilkParasite Targets Central Asian Governments With Seven RAT Families
    SilkParasite targeted Central Asian government bodies with seven remote access tool families.

    • Government entities in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Kazakhstan, and Georgia were targeted.
    • The China-nexus cluster used seven RAT families, including five newly documented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT.
    • Spear-phishing emails delivered password-protected RAR archives containing malicious Microsoft Office documents.
    • Opening the documents triggered macros and DLL sideloading; the macro checked for Kaspersky antivirus before execution.
    • The implants used modular plugins and C2 through Google Drive, HTTP Cookie/ETag headers, and attacker servers; about 65 DriveSilkRAT infections were observed.
      πŸ“„ Source: businessinsights.bitdefender.com Β· πŸ“Ž Coverage: thehackernews.com Β· πŸ‘ via The Hacker News, securityboulevard.com (discovered)
  • Balonx Sistema Uses AI Voice Calls to Bypass MFA and Steal Bank Accounts
    Hackers are using AI voice calls and fake banking pages to steal accounts.

    • Banking customers are targeted in the Balonx Sistema campaign.
    • Fake banking pages capture login details and MFA information.
    • AI-generated phone calls guide victims through the phishing process.
    • Attackers monitor victims’ sessions live and request information when needed.
      πŸ“Ž Coverage: cybersecuritynews.com Β· πŸ‘ via Cyber Security News

πŸ’₯ BREACHES & INCIDENTS

  • Leak Exposes 669 Stripe Vendors and 1,033 Live API Keys
    Threat actors exposed Stripe vendor data and live API keys in a forum release.
    • The exposure affected 669 businesses using Stripe across multiple industries and countries.
    • The leak included 1,033 API keys, customer records, invoices, balances, charges, payouts, and promotional codes.
    • Exposed records contained names, email addresses, phone numbers, home addresses, IP addresses, purchase histories, and card last four digits.
    • Threat actor Satanic published a 33GB release on pwnforums and claimed access to about 20,000 Stripe APIs.
    • Live keys could enable programmatic customer-data access, unauthorized refunds, account changes, and payment rerouting.
      πŸ“Ž Coverage: infostealers.com Β· πŸ‘ via Cyber Security News, r/cybersecurity

πŸ•΅οΈ RESEARCH & DEEP DIVES

πŸ”“ CVEs & KEV

  • CVE-2026-76233 β€” CVSS 8.4 β€” Renovate 39.53.0 before 40.33.0 Command Injection via gleam managerRenovate v...

  • CVE-2026-76232 β€” CVSS 8.4 β€” Renovate 31.51.0 before 40.33.0 Command Injection via helmv3Renovate versions...

  • CVE-2026-76231 β€” CVSS 8.4 β€” Renovate 32.135.0 before 40.33.0 Command Injection via hermitRenovate version...

  • CVE-2026-76230 β€” CVSS 8.4 β€” Renovate 35.63.0 before 40.33.0 Command Injection via npmRenovate versions fr...

  • CVE-2026-76229 β€” CVSS 8.4 β€” Renovate 39.218.0 before 40.33.0 Arbitrary Command Injection via kustomizeRen...

  • CVE-2026-76228 β€” CVSS 8.4 β€” Renovate before 42.68.5 Remote Code Execution via Gradle WrapperRenovate vers...

  • CVE-2026-43961 β€” CVSS 7.8 β€” Vim: vimscript injection via unescaped filename in netrw s:netrwmarkfile() fi...

  • CVE-2026-54794 β€” CVSS 7.2 β€” Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side R...

  • CVE-2026-76227 β€” CVSS 6.8 β€” Renovate 42.68.1 before 42.96.3 Environment Variable ExposureRenovate version...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check