๐จ ACTIVE EXPLOITATION
- China-Linked Fire Ant Compromises Cisco Routers to Steal Credentials
Fire Ant compromised Cisco routers and TACACS servers to steal credentials and hide activity.- The campaign targeted organizations using Cisco IOS XR routers, TACACS authentication servers, and Linux management hosts.
- Fire Ant collected router traffic and administrative credentials while probing paths to connected high-value environments; confirmed compromise of those networks was not reported.
- A GRE tunnel from a legacy Linux host pivoted into an edge router, while IOS XR malware filtered logs and command output to conceal activity.
- TacTap injected /lib/libseconfd.so into tac_plus; credentials were stored in /var/log/.tacplus.acct and obfuscated with XOR key 0xEF.
- BridgeAgent persisted through zabbix_agent.service and used TLS on port 443; other implants included /usr/bin/acpid (SHA1 be6b27f429324a4af05a310d8ec9635e37c68a94) and /var/tmp/ping (SHA1 5ba1242050b5b447052b210788a5a25593d6987d).
๐ Source: sygnia.co ยท ๐ Coverage: thehackernews.com ยท ๐ via The Hacker News
๐ต๏ธ RESEARCH & DEEP DIVES
-
Spring Ring Uses Microsoft Teams Voice Phishing to Deploy Malware
Spring Ring uses Microsoft Teams voice phishing to deploy malware.- The campaign targets enterprises using Microsoft Teams.
- Attackers deploy malware and target enterprise domain controllers.
- The attack abuses Microsoft Teams and voice phishing.
๐ Source: unit42.paloaltonetworks.com ยท ๐ Coverage: radar.offseq.com ยท ๐ via Palo Alto Unit 42
-
ValleyRAT Backdoor Masquerades as QN Wallpaper Adware in Asia
Kaspersky has identified a ValleyRAT campaign disguised as QN Wallpaper adware.- Users and organizations in Asia, especially India and China, are targeted.
- ValleyRAT steals keystrokes and clipboard data, captures screenshots, and delivers additional modules.
- A trojanized QN Wallpaper installer uses DLL sideloading to launch the backdoor.
- The payload runs under a process signed with a legitimate developer certificate.
- Kaspersky detected related ValleyRAT malware more than 100,000 times on devices belonging to over 1,500 users in 2026.
๐ Source: securelist.com ยท ๐ Coverage: lankabusinessnews.com ยท ๐ via Securelist (Kaspersky)
-
Gryxa AI-Assisted Malware Survives Cleanup and Targets Windows Credentials
ReliaQuest identified Gryxa, an AI-assisted Windows malware toolkit.- A financially motivated actor used Gryxa across 324 listed Windows hosts, with 69 online during analysis.
- Gryxa abuses legitimate RMM software for covert access and steals credentials from Chromium-based browsers and crypto wallets.
- Phishing emails likely deliver a 19 MB invoice-themed executable matching invoice_before 10 digits>.exe, which downloads components over HTTPS.
- At least seven scheduled tasks, permanent WMI persistence and backup files restore the toolkit after partial removal.
- A surviving component sends Windows logs to the operator and may disable endpoint security after relay failures; IOCs include wirbe[.]com, gryxa[.]com, 144.172.107[.]56 and 209.145.55[.]189.
๐ Source: reliaquest.com ยท ๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News, cryptika.com (discovered)
๐ ADVISORIES
-
UK NCSC Cyber Assessment Framework reaches version 4.0
The UK NCSC has released Cyber Assessment Framework version 4.0.- CAF 4.0 applies mainly to critical-sector organizations and essential-service suppliers.
- It covers energy, healthcare, transportation, water, digital infrastructure, telecommunications and government.
- The framework has four objectives, 14 principles and 41 contributing outcomes.
- Released in August 2025, CAF 4.0 adds AI risks, threat hunting, monitoring and secure software development.
- Organizations assess outcomes as Achieved, Partially Achieved, Not Achieved or Not Applicable.
๐ Coverage: centraleyes.com ยท ๐ via securityboulevard.com (discovered)
-
๐ Source for Manchester Airports Group confirms data breach affecting 8.7 million customers โ manchesterairport.co.uk
-
๐ Source for Rhysida Claims Berlin State Network Data Theft, Demands 30 Bitcoin โ berlin.de
๐ CVEs & KEV
-
CVE-2026-82860 โ CVSS 9.3 โ @hulumi/policies before 1.3.2 Admin Policy Bypass@hulumi/policies versions be...
-
CVE-2026-82866 โ CVSS 8.9 โ @pdfme/common before 5.5.10 SSRF via Unvalidated URL Fetch@pdfme/common befor...
-
CVE-2026-82863 โ CVSS 8.7 โ @hulumi/baseline before 1.3.2 CloudTrail Selector Tampering Detection@hulumi/...
-
CVE-2026-82861 โ CVSS 8.7 โ @hulumi/policies before 1.3.2 SecureBucket Parent Spoof Bypass@hulumi/policie...
-
CVE-2026-82862 โ CVSS 8.6 โ Hulumi before v1.3.2 Helper Script Shadowing via Workspace FilesHulumi versio...
-
CVE-2026-82871 โ CVSS 8.2 โ ToolJet before v3.16.208 Cross-Organization Data Read via Database RoutesTool...
-
CVE-2026-82869 โ CVSS 8.2 โ ToolJet Database before v3.16.44 Privilege Escalation via join_tablesToolJet ...
-
CVE-2026-81624 โ CVSS 7.5 โ Undertow-core: undertow: websocketcontainer defaults for buffers and timeouts...
-
CVE-2026-82872 โ CVSS 7.1 โ ToolJet before v3.16.208 Cross-Workspace Authorization BypassToolJet before v...
-
CVE-2026-82864 โ CVSS 7.1 โ pdfme pdf-lib before 5.5.10 Denial of Service via Decompression Bombpdfme pdf...
-
CVE-2026-82870 โ CVSS 7.0 โ ToolJet before v3.16.208 Cross-Tenant Database ManipulationToolJet before v3....