In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure
Roundup: ShinyHunters defaced Cl0p’s leak site, new secret-stealing implants emerged, and US water credentials were exposed.
SecurityWeek’s weekly roundup reports that ShinyHunters defaced the Cl0p ransomware gang’s Tor leak site, claiming theft of logs, source code and onion-service keys, and demanded an eight-figure payment. Malicious MemOS packages on npm and PyPI carry a Go implant named sckit that steals developer and cloud secrets, while Cisco Talos documented CLOSEDQUORUM, which has DeepSeek, Qwen, Mistral and Gemini vote on credential theft and persistence. SpyCloud found infostealer exposure at 1,787 of about 10,000 US water-sector organizations, including OT or remote-access credentials at 258. Separately, CVE-2026-42542 is an unauthenticated denial-of-service flaw in TDengine 3.4.0.0 through 3.4.1.5.