ZeroHour

Search: “Hungary”

26 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

International Operation Disrupts Sality P2P Botnet

US-led international operation with Europol, CrowdStrike, and Shadowserver sinkholed the 20-year-old Sality P2P botnet, once exceeding one million infected machines.

On August 31, 2026, authorities from the US, Bulgaria, Hungary, and Romania, supported by Europol, CrowdStrike, and the Shadowserver Foundation, disrupted the Sality P2P botnet by sinkholing communications and seizing domains. Sality has operated for over 20 years, at its peak controlling more than one million infected machines used for credential theft, spam, proxy services, crypto-theft, and DDoS attacks, with over 11 million unique IP addresses linked to its infrastructure since 2017. The disruption exploited the botnet's super-peer reputation mechanism by removing legitimate peers via protocol-level manipulation and inserting sinkhole entries into emptied peer lists.

Infosecurity Magazine · 13d agoMalware

Norway announces investigations into telecom Telenor’s work with Myanmar junta

Norwegian police opened crimes-against-humanity and sanctions investigations into Telenor's data handovers to Myanmar's junta, raiding its Oslo headquarters.

Norway's National Criminal Investigation Service is investigating Telenor for complicity in crimes against humanity for repeatedly handing over historical customer traffic data to Myanmar's military regime between the February 2021 coup and the March 2022 subsidiary sale. The Police Security Service is separately probing sanctions violations because the sale to M1 Group included sanctioned surveillance equipment transferred without foreign ministry permission. The subsequent resale passed historical call data of over 18 million people to junta-linked owners, and a class action on behalf of 1,200 people alleges the data enabled arrests, torture, and at least one execution.

The Record · 23h agoPolicy & legal

Sality, one of the longest

US and European authorities, with CrowdStrike and Shadowserver, disrupted the 20-year-old Sality peer-to-peer botnet, severing 15,000+ infected machines from operators.

US and European authorities disrupted the Sality botnet, active since at least 2003, in an operation involving the DOJ, CrowdStrike, the Shadowserver Foundation and agencies in Bulgaria, Hungary and Romania. Researchers reverse-engineered the botnet's peer-to-peer architecture and injected false data into infected machines' 'super peer' lists, cutting more than 15,000 systems off from their operators. For the past eight years Sality primarily distributed EggJagger, malware that replaces clipboard cryptocurrency addresses and is estimated to have netted the operator at least $150,000. No arrests were announced, and CrowdStrike assesses the operator works from Russia's Bashkortostan region.

The Record · 14d agoMalware in the wild

Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor

Seqrite Labs details Operation QUICSILVER, a China-nexus espionage campaign targeting Myanmar government and IT with graduation-invite lures deploying QUICAgent backdoor.

Seqrite Labs reported Operation QUICSILVER, a cyber espionage campaign against Myanmar's government and IT sectors attributed with moderate confidence to a China-nexus actor. Since April 2026, attacks used fake Belgian-Myanmar holiday and Burmese graduation ceremony invitation lures delivered via VHD/LNK files that abuse ftp.exe (LOLBAS) to assemble and launch QUICAgent, a Go backdoor communicating over QUIC on UDP 443 with five commands and Startup-folder persistence. Separately, China-linked Mustang Panda was observed using an updated COOLCLIENT backdoor with a signed kernel-mode driver across Myanmar, Mongolia, Pakistan, and Russia.

The Hacker News · 23d agoThreat actor in the wild1

Global sinkhole operation ends Sality botnet’s 23-year run

Law enforcement, CrowdStrike, and Shadowserver sinkholed the 23-year-old Sality P2P botnet, cutting 15,000+ infected machines from its operator.

Sality, active since 2003 as a file-infecting virus with two P2P networks (versions 3 and 4), distributed credential thieves, spam, proxies, and DDoS payloads, and most recently delivered the EggJagger clipboard hijacker that swapped cryptocurrency wallet addresses for at least $150,000 in operator profit. A coordinated sinkhole operation replaced the botnet's super-peer list with defender-controlled sinkholes, and investigators in the US, Bulgaria, Hungary, and Romania seized payload domains. The Shadowserver Foundation is coordinating ISP and CERT notifications to infected device owners.

Help Net Security · 14d agoMalware1

European parliament members call for slowdown of Serbia’s EU entry over spyware use

29 MEPs urge delaying Serbia's EU accession after researchers found Pegasus and NoviSpy spyware on student activists' phones.

Twenty-nine Members of the European Parliament sent a letter Friday demanding Serbia's EU accession be slowed until an investigation into its spyware use is completed. The letter follows a SHARE Foundation report, with Amnesty International and the Citizen Lab, documenting Pegasus and NoviSpy infections on Serbian student activists' phones; NoviSpy evidence pointed to Serbian government authorities, though Pegasus attribution was not assigned. The MEPs also urged European Commission President Ursula von der Leyen to cancel a planned visit to Serbia and called the surveillance 'a direct state attack on democracy' ahead of upcoming elections. The Serbian government did not respond to requests for comment.

CyberScoop · 11d agoPolicy & legal in the wild

Risky Bulletin: Dutch intel services to get extensive new powers

Netherlands proposed a bill granting AIVD and MIVD expanded warrantless tapping, faster hacking powers, and forced data disclosure, citing Russia, China, and Iran threats.

The Dutch government introduced a bill greatly expanding surveillance powers of intelligence agencies AIVD and MIVD, allowing up to one year of tapping without pre-approval and simplified hacking operations against 'foreign adversaries'. Agencies could compel Dutch companies or citizens to provide data under threat of charges, share data with the private sector, and oversight bodies would merge into a new CTT board. The bill follows similar overhauls in Ireland, Germany, and France after Russia's invasion of Ukraine. The newsletter also reports Moonwell hacked for $8.7M, a Cosmos EVM bug exploited for ~$3M, ShinyHunters listing McKesson with claimed hundreds of millions of records, and a pro-Kremlin DDoS claim against Norway's government network.

Risky Business News · 16d agoPolicy & legal

UK Council Attack Linked to Mass Exploitation of SonicWall Flaw

Hunt.io links a UK council attack to mass exploitation of SonicWall SMA1000 flaw CVE-2026-15409 (CVSS 10.0), enabling credential and Active Directory theft.

Hunt.io links, with moderate confidence, the July 17, 2026 attack on the Borough Council of King's Lynn and West Norfolk to mass exploitation of SonicWall SMA1000 appliances via CVE-2026-15409, an unauthenticated SSRF in the WorkPlace portal WebSocket proxy with CVSS 10.0. The operator adapted Rapid7's July 15 PoC into a 50-thread mass scanner within days and stole LDAP credentials for 534 Active Directory accounts across 160 domains, with nine environments losing SAM/LSA secrets and five losing full AD databases via DCSync. CISA added the flaw to its Known Exploited Vulnerabilities catalog and noted use in ransomware campaigns; targeting of ~200,000 Shodan-derived SonicWall addresses spanned government, healthcare, finance, universities, and manufacturing worldwide.

Security Affairs · 5d agoExploit / PoC in the wildCVE-2026-154091

Russian-Linked Hackers Accessed Polish Power Plant OT Network Through Private APN, Says CERT.PL

CERT.PL disclosed that Russian-linked hackers accessed a Polish combined heat and power plant's OT network through a private APN in 2025.

Poland's CERT (CERT.PL) released details of a 2025 attack on a Polish combined heat and power plant. Russian-linked hackers accessed the plant's OT network through a private APN. The disclosure adds to a series of intrusions against Polish critical infrastructure attributed to Russian-linked actors.

Infosecurity Magazine · Aug 12, 2026Threat actor in the wild

Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes

Law enforcement and CrowdStrike disrupted the 23-year-old Sality P2P botnet, isolating 15,000+ infected machines and seizing linked domains.

International law enforcement, working with CrowdStrike and the Shadowserver Foundation, executed a peer-to-peer sinkhole operation against Sality, a botnet active since 2003 that delivered malware to more than 15,000 machines worldwide. Sality's primary payload for eight years was EggJagger, a clipboard hijacker that swaps copied bitcoin and ethereum wallet addresses with attacker-controlled ones, yielding at least $150,000 in stolen cryptocurrency. The US Justice Department, FBI, and DoD Office of Inspector General's Defense Criminal Investigative Service seized Sality-linked domains, with parallel action in Bulgaria, Hungary, and Romania. The Shadowserver Foundation is coordinating with ISPs and CSIRTs to identify infections and notify victims.

The Register · Security · 14d agoMalware in the wild

US Sanctions Mabna Institute Hackers for Iranian Cyber-Attacks

US sanctions individuals tied to Iranian hacking-for-hire group the Mabna Institute over cyber-attacks.

The United States has imposed sanctions on individuals connected to the Mabna Institute, an Iran-based hacking-for-hire group. The move targets the actors behind Iranian cyber-attack operations. Sanctions are a government enforcement action rather than a new technical threat.

Infosecurity Magazine · 22d agoPolicy & legal

Dogged Russia-based botnet dismantled after 23-year run

Law enforcement, CrowdStrike and Shadowserver dismantled the 23-year-old Sality P2P botnet that infected more than 11 million devices.

Sality, a Russia-based peer-to-peer botnet active for 23 years and infecting over 11 million devices, was dismantled by law enforcement working with CrowdStrike and the Shadowserver Foundation. CrowdStrike poisoned the botnet's peer list so infected machines permanently disappeared from the operator's view, while domains were seized in a coordinated effort involving the FBI, Justice Department, Europol and authorities from Bulgaria, Hungary and Romania. The financially motivated operation enabled cryptocurrency theft, DDoS attacks and other cyberattacks, and Europol said the effort dates back to 2017; the operators were not named.

CyberScoop · 14d agoMalware

Competence-Gated Pooling of Language Models and Priors for Event Forecasting

Paper proposes a competence gate pooling language model forecasts with external priors, improving Brier score from 0.0771 to 0.0732 across 2,357 binary questions.

The paper defines a language model's relative competence as its marginal value beyond an available external forecast, and derives conditions under Brier loss where model disagreement improves that forecast. A competence gate estimates domain-level source weights from resolved outcomes, shrinks uncertain estimates toward a global weight, and recalibrates the pooled forecast. Across 2,357 resolved binary questions and five language models, it improves the external baseline from 0.0771 to 0.0732 Brier and beats global forecast combinations, though it defers to the market on ForecastBench. Across four Qwen models, verbal confidence failed to identify when the model outperformed the external forecast, while outcome-estimated competence supported better abstention.

Hugging Face daily papers · 6d agoAI research

Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads

US and European authorities with CrowdStrike dismantled the two-decade-old Sality P2P botnet using peer-list manipulation, blocking payload delivery to infected hosts.

The US Department of Justice announced a coordinated takedown of the Sality peer-to-peer botnet, executed August 31, 2026 by authorities from the US, Bulgaria, Hungary, and Romania with CrowdStrike and the Shadowserver Foundation. Sality, active since 2003, infects Windows executables and delivers payloads including the EggJagger crypto clipper, which stole at least $150,000, and was used for DDoS campaigns. The operation abused the botnet's peer-list maintenance cycle to insert sinkhole nodes and isolate both super peers and NAT-hidden infections, cutting off URL and payload distribution to more than 15,000 infected machines across two P2P networks.

The Hacker News · 14d agoMalware

Wake-Up Call for CNI After Iranian Attack Shuts Down UK Power Plant

A cyber-attack attributed to Iran shut down a UK power plant, exposing the frailty of critical national infrastructure, security experts warn.

Security experts say an Iranian cyber-attack forced a UK power plant offline, describing the incident as a wake-up call for critical national infrastructure operators. The attack caused physical operational disruption at an energy facility. Technical details about the intrusion path and the affected operator remain limited in initial reporting.

Infosecurity Magazine · 23d agoThreat actor in the wild

Automatically Detecting DNS Hijacking in Passive DNS

Unit 42's machine learning pipeline detected 6,729 DNS hijacking events between March and September 2024, hitting political parties, ISPs, and universities.

Unit 42 processes roughly 167 million new DNS records daily and applies a machine learning model using 74 features over 169 TB of passive DNS and geolocation data to flag hijacked domains. From March to September 2024 the pipeline screened over 29 billion records and classified 6,729 as DNS hijacking, averaging 38 detections per day; a new model detects hijacks in customer traffic within about 10 minutes. Notable cases include a Hungarian political party's hijacked domain, defacement of a large utility company and ISP, and university and research center domains repurposed for illicit gambling. DNS hijacking typically relies on stolen registrar or DNS provider credentials or cache poisoning, enabling MitM attacks, phishing, drive-by downloads, and scams.

Palo Alto Unit 42 · Aug 17, 2026Research in the wild

Structural Jailbreaks Generalize but Do Not Compound: A cross-provider and multilingual study of Involuntary In-Context Learning

Researchers show IICL structural jailbreaks generalize to Google Gemini, lifting attack success to 80-100% on harm and financial benchmarks; non-English prompts attenuate it.

The study red-teams two Google Gemini models with Involuntary In-Context Learning (IICL), a structural jailbreak reframing harmful requests as the final cell of a data-labeling task. IICL lifts attack success from at most 6.7% to 80-90% on HarmBench and 97-100% on financial abuse (FinProof), an order of magnitude above prior results on OpenAI's GPT-5.4. Against a compounding hypothesis, forcing IICL output into Spanish, Hindi, or Arabic attenuates the attack in 11 of 12 conditions, attributed to a 'relevance curse' producing lower-quality harmful content in lower-resource languages. Findings replicate under an independent non-Google judge (Cohen's kappa 0.86 over 377 paired verdicts).

arXiv cs.CR · 8d agoAI safety & security

From Parameters to Answers: How LLMs Retrieve and Use Their Internal Knowledge

Interpretability study traces how Qwen, Llama, and Gemma route query information and internal knowledge across layers when answering questions.

Researchers used layerwise interventions on hidden states to separate query-routing signals from target knowledge in language models, testing Qwen, Llama, and Gemma on country-continent questions with varied answer types. A pair-conditioned request direction strengthens before interventions alter downstream knowledge, opening a causal window while answer-supporting content is still forming. Trajectories differ by model: Gemma shows a partially overlapping mid-layer routing profile, while Llama has no sustained routing-effect window under the same gates.

arXiv cs.AI / cs.LG / cs.CL · 6d agoAI research1

U.K. Supreme Court Opens Door for Spyware Victims to Sue Foreign States

UK Supreme Court ruled Bahrain not immune from spyware litigation, letting two dissidents pursue claims over FinSpy hacking; case returns to the High Court.

The UK Supreme Court ruled in The Kingdom of Bahrain v. Shehabi that Bahrain is not immune from litigation over its alleged use of FinSpy spyware against two Bahraini dissidents living in the UK. Citizen Lab researchers Siena Anstis, Natalia Krapiva, and Kate Pundyk, writing in Lawfare, called the decision a milestone for accountability in transnational repression. The case now returns to the UK High Court, where attribution, causation, and injury must be proven.

Citizen Lab · 14d agoPolicy & legal in the wild

Welsh environment regulator's FoI blunder exposes diversity data of 2,000 staff

Natural Resources Wales inadvertently exposed diversity data of about 2,000 current and former staff via a 2021 Freedom of Information spreadsheet published online.

Natural Resources Wales confirmed equality monitoring data of roughly 2,000 employees who worked between April 2013 and March 2018 was inadvertently disclosed in a spreadsheet released in 2021 in response to a Freedom of Information Act request. The data may have included ethnicity, disability status, religion or belief, sexual orientation, Welsh language ability, and caring responsibilities — special category data under UK GDPR. The breach was reported to the Information Commissioner's Office, the data was removed and permanently deleted, and NRW says it has found no evidence of misuse. The issue was discovered only after a member of the public alerted the regulator on 23 August 2026.

The Register · Security · 9d agoData breach

One Symptom, Three Levers: A Critical Review of On-Policy Self-Distillation

A review paper frames on-policy self-distillation collapse as governed by three levers: token weighting, privileged information, and guidance decay.

The paper critically reviews On-Policy Self-Distillation (OPSD), where a language model trains on its own generations scored token-by-token by a teacher conditioned on privileged information such as reference solutions or environment feedback. It identifies collapse, the progressive narrowing of producible reasoning paths, as the dominant failure mode and analyzes it through three levers: signal weighting, the nature of privileged information, and teacher dynamics. The review is restricted to mathematical reasoning, reports no new experiments, and offers a shared vocabulary separating settled findings from disputed ones.

Hugging Face daily papers · 21d agoAI research

Suspected Iran-linked attack knocked UK power plant offline for days

Suspected Iranian hackers knocked a small UK power plant offline for four days in July 2026, with no noticeable impact on the national grid.

Sources told The Telegraph that a British power plant was offline for four days in July 2026 following a suspected Iranian cyberattack, reported to the National Cyber Security Centre. The UK energy minister said the incident affected a small-scale energy generator with no noticeable effect on the power supply, and energy CEOs were briefed and given further advice afterward. The attack followed warnings about Iranian cyber activity against US energy, water, and government networks, including a coordinated attack on 30+ US community water utilities.

Help Net Security · 23d agoThreat actor

Risky Bulletin: Slovakia finds Russian backdoor in traffic speed cameras

Slovakia's NBU found an SMS-triggered backdoor in Russian-made NERO R-ONE traffic cameras, pausing a 279-unit deployment.

Slovakia's national security service NBU issued an alert against NERO R-ONE high-speed traffic cameras after finding a backdoor that grants shell and network access via SMS from hardcoded Russian phone numbers. The cameras are a rebranded version of the Russian CORDON PRO.M model by St. Petersburg firm Semicon, purchased via a Cyprus shell company under a €30 million EU-funded project. The report also found SecureBoot disabled, vulnerable web management, and unauthenticated live streams; the Interior Ministry paused deployment of 279 cameras pending independent assessment.

Risky Business News · 28d agoThreat actor in the wild1

Unit 42 Researchers Discover Multiple Espionage Operations Targeting Southeast Asian Government

Unit 42 attributes three espionage clusters targeting a Southeast Asian government to Stately Taurus, Alloy Taurus, and Gelsemium APTs.

Unit 42 investigated espionage attacks starting in late 2022 against multiple governmental entities in a Southeast Asian country, including critical infrastructure, public healthcare, financial administrators, and ministries. Analysis revealed three distinct clusters: CL-STA-0044 attributed to Stately Taurus (Mustang Panda), CL-STA-0045 to Alloy Taurus (GALLIUM), and CL-STA-0046 to Gelsemium. The first cluster used a ToneShell backdoor variant, ShadowPad, China Chopper web shells, Impacket, and credential dumping tools across roughly Q1 2021 to Q3 2023. All three operated with distinct tools, infrastructure, and long-term surveillance tradecraft consistent with APTs.

Palo Alto Unit 42 · Aug 17, 2026Threat actor in the wild