Security news
Latest security news
Wed, 19 Aug 2026
- MaaS Campaign Combines ClickFix, ErrTraffic and Cruciferra
eSentire uncovered a malware campaign combining ClickFix lures with ErrTraffic and Cruciferra
Infosecurity Magazine - Grandoreiro Resurfaces in Mexico With New DLL Sideloading Campaign
Grandoreiro is active after its 2024 disruption, with Mexico now accounting for 40% of detections
Infosecurity Magazine
Mon, 17 Aug 2026
- 17th August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 17th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Colombia’s Ministry of Justice has experienced a ransomware attack that affected part of its technology infrastructure and disrupted public services related to illicit-drug monitoring and legal processes. Officials confirmed that some files were
Check Point Research - Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline
Operation ASTERIX overview Rapid7 researchers identified an exposed web directory on infrastructure used to support a cryptocurrency fraud operation. The server contained raw phone-number datasets, account-validation tools, enriched lead records, phishing panels, voice-dialing scripts, fake wallet applications, persistence mechanisms, and Telegram exfiltration code. Among the artifacts was evidence that the operator relied on AI coding assistants throughout the campaign's development; recovered prompts, shell history, and project files show AI being used to package Electron applications, obfuscate code, troubleshoot builds, modify phishing infrastructure, and prepare malware for distribution. When one model began resisting parts of that workflow, the operator switched providers and attempted to bypass the next model's safety controls with a custom jailbreak prompt. Together, these artifacts provide an unusual view into how AI was integrated into the development of an active phishing operation rather than simply being used to generate isolated snippets of code. We track this activity as Operation ASTERIX, named after the Asterisk open-source telephony platform recovered on the serve
Rapid7 Blog
Fri, 14 Aug 2026
- Metasploit Wrap Up: Lot of summer shells and fit http profiles
This wrap-up brings a full-on shell parade. Thirteen shiny new modules landed, starting with a buffet of RCEs. WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, a Pix-for-WooCommerce, and for those who like their exploits closer to the bare-metal, the Fragnesia Linux kernel LPE (CVE-2026-46300). Metasploit also got the glow-up of the summer with the new http malleable profiles, MCP functionality and linux multi fetch payloads (more details on the [official 6.5 release blog post](https://www.rapid7.com/blog/post/pt-metasploit-framework-6-5-released/)!). Windows on ARM confirm to be the new first-class citizenship thanks to brand-new AArch64 reverse-TCP shells (both inline and staged), so your Snapdragon boxes can join the party too. Last but not least, an important message: *Nyan Nyan Nyan Nyan Nyan Nyan.* New module content (13) Ray Dashboard Logs API Path Traversal Author: Richard Howe Type: Auxiliary Pull request: #21681 contributed by rmhowe425 Path: `gather/ray_dashboard_logs_api_path_traversal` Description: This adds an auxiliary module that leverages a path traversal vulnerability in Ray to list the contents of
Rapid7 BlogWindows, SonicWall, Linux - Researchers Link 'Jewelbug' Chinese APT to Hack-for-Hire Operations
Threat intelligence researchers from Broadcom revealed that a known Chinese APT group may be linked to a lucrative crypto fraud operation
Infosecurity Magazine
Thu, 13 Aug 2026
- Armored Likho expands its cyber-espionage toolkit
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.
Securelist
Tue, 11 Aug 2026
- Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack
Key Points Introduction Since early 2026, Check Point Research has tracked a wave of the Operation Dream Job campaign. This wave primarily targeted the defense sector worldwide, with a particular emphasis on companies operating in the aerospace and aviation industries. We observed the threat actor distributing modified PDF viewers designed to execute malicious payloads embedded within specially
Check Point Research - Six npm Packages Read C2 Addresses From Ethereum Wallet
Six npm packages queried an Ethereum wallet to locate C2 infrastructure
Infosecurity Magazine - Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection
Project CAV3RN targets Israel with Google Apps Script C2 relays and DNS-based routing. Modular .NET NativeAOT framework blends C2 traffic with legitimate Google services to evade detection.
SecurelistGoogle
About this news
- 1,259
- Stories
- 33
- Added in the last 24 hours
- 17
- Critical in the last 7 days
- 4
- Reported by several outlets