🚨 ACTIVE EXPLOITATION
- Pro-Russian group claims DDoS attack on Norway’s public digital services
A DDoS attack disrupted Norway’s shared government digital services.- Norwegian citizens, businesses, public agencies and some health services were affected.
- The attack disrupted Digdir services including ID-porten, MinID and eSignering; ID-porten serves more than 4.5 million users.
- Attackers flooded Digdir and provider Vivicta infrastructure with massive traffic, causing outages, slow responses and login failures.
- Pro-Russian group Server Killers claimed responsibility, but Norwegian officials had not confirmed the attribution.
- Digdir reported no evidence of system compromise or personal-data exposure.
📎 Coverage: apnews.com · 👁 via SecurityWeek
💥 BREACHES & INCIDENTS
- ATF confirms standalone system breach after Qilin ransomware claim
ATF confirmed a major incident involving a compromised standalone system.- The incident affects the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF).
- A standalone ATF system was compromised; the enterprise network, eForms system and other systems show no indicated impact.
- Qilin listed ATF on its dark-web leak portal but provided no evidence of stolen data.
- ATF has not attributed the incident to Qilin, and the intrusion method and data accessed remain undisclosed.
📎 Coverage: bleepingcomputer.com · 👁 via BleepingComputer
🕵️ RESEARCH & DEEP DIVES
-
Russian-Linked Groups Use Fake Google Drive Pages to Hijack Accounts
Russian-linked groups are hijacking targeted accounts through fake cloud-storage pages and diplomatic lures.- Targets include academics, diplomats, defense and aerospace personnel, government users, nonprofits, and think tanks in Europe and the United States.
- UNC6293, UNC7005, and UNC5976 abuse Google OAuth, app-password, and WhatsApp device-linking workflows rather than software vulnerabilities.
- UNC5976 uses file-sharing-themed domains and fake Google Drive pages to redirect victims through legitimate Google sign-in and capture OAuth tokens.
- UNC7005 uses diplomatic and conference invitations to link attacker-controlled WhatsApp devices and deploy JavaScript that records calls.
- UNC7005 has also delivered Vidar, Atomic (AMOS), and other infostealers to Windows and macOS users.
📎 Coverage: theregister.com · 👁 via Cyber Security News, cryptika.com (discovered)
-
ESET Identifies GuardBreaker LLM Safety-Evasion Technique in Ukraine Attack
ESET observed Russia-aligned UAC-0099 using GuardBreaker to disrupt AI malware analysis.- The campaign targeted a victim in Ukraine; UAC-0099 typically targets transportation and energy sectors.
- A malicious VBS script downloaded and installed MATCHBOIL malware used by UAC-0099.
- The script embedded nuclear-weapon text as a comment to trigger LLM safety mechanisms and halt analysis of the remaining code.
📄 Source: cert.gov.ua · 📎 Coverage: infosec.exchange · 👁 via @ESETresearch@infosec.exchange
-
RPC-Triage maps and ranks Windows RPC attack surfaces from PE files
RPC-Triage is an open-source tool for statically analyzing Windows RPC attack surfaces.- Windows RPC security researchers and assessors are the target users.
- The tool analyzes PE files to recover RPC, MIDL, and NDR internals, endpoints, security state, and method-level input signals.
- It works offline without PDBs, live endpoint-mapper access, or target execution.
- An AHP/Saaty-based model ranks interfaces and provides scoring receipts plus questionable-extraction markers.
📄 Source: github.com · 📎 Coverage: reddit.com · 👁 via r/cybersecurity
📋 ADVISORIES
-
📄 Source for US Seizes QTFY Infrastructure Used in Chinese Espionage Campaign — lumen.com
-
📄 Source for GPUThor Rowhammer Bypasses ECC on NVIDIA GDDR6 GPUs for Root Access — discourse.org
🔓 CVEs & KEV
-
CVE-2026-18431 — CVSS 9.8 — Avada through 7.16 and Fusion Builder through 3.16 - Unauthenticated Remote Code Execut...
-
CVE-2026-77693 — CVSS 8.7 — Order Tip for WooCommerce before 1.6.0 - Shop Manager+ Arbitrary File Deletion via...
-
CVE-2026-75797 — CVSS 7.7 — AI Engine 3.3.3 - 3.7.1 - Subscriber+ Arbitrary File Read via 'url' Parameter...
-
CVE-2026-74928 — CVSS 7.5 — WP Project Manager 2.1.0 - 4.0.6 - Unauthenticated Subscriber Account Creatio...
-
CVE-2026-78146 — CVSS 6.5 — Noptin before 4.3.3 - Unauthenticated Subscriber PII and confirm_key Disclosure vi...
-
CVE-2026-3002 — CVSS 6.4 — Gutenverse through 4.0.2 - Authenticated (Contributor+) Stored Cross-Site Scriptin...