ZeroHour

Search: “vulnerability”

8 stories in the last 3d

ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories

Unit 42 exposed CL-CRI-1171, a pay-per-install operation spreading OfferLoader and Insomnia RAT via YouTube and SEO poisoning to corporate and government targets.

The ThreatsDay bulletin leads with Unit 42's disclosure of CL-CRI-1171, a pay-per-install marketplace using YouTube channels and SEO-poisoning funnels to push trojanized software and the OfferLoader loader, which delivered Docro Hijacker, ARKTunnel and the cross-platform Insomnia RAT between July 2025 and April 2026. Oasis Security reported that 230 of 243 unauthenticated LocalAI instances were exploitable, with root command execution confirmed on 23 servers, theft of 127 AWS credential records, and exfiltration from a Thai military workstation. The roundup also covers Irregular's research on agentic self-modification, an AEPD-notified breach executed with an AI agent, CISA's warning that ransomware gangs exploit VMware vCenter CVE-2026-59310, and Oracle's September 2026 CPU fixing over 800 flaws.

The Hacker News · 20h agoThreat actor in the wildCVE-2026-59310

Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers

Kaspersky details NightEagle, Hacking Cat, and Toy Ghouls targeting Russian enterprises with Exchange backdoors, Gorilla RAT, and destructive Monkey ransomware.

Kaspersky reports three threat clusters targeting Russian enterprises: NightEagle (APT-Q-95), the pro-Ukrainian hacktivist group Hacking Cat, and Toy Ghouls. NightEagle uses compromised VPN credentials and the GhostContainer modular backdoor to fully compromise Microsoft Exchange servers, chaining CVE-2020-0688 exploitation, BlueKeep (CVE-2019-0708), Active Directory vulnerabilities, and DCSync to seize domain controllers. Hacking Cat exploits Exchange flaws including CVE-2021-26855 and CVE-2026-42897 to deliver the Gorilla RAT and multiple Monkey ransomware variants written in Rust, .NET, C++, and Golang targeting Windows, Linux, and VMware ESXi, with some variants acting as wipers that never store the encryption key.

The Hacker Newsupdated · 42m agofirst · 1d agoThreat actor in the wild 6 sourcesCVE-2020-0688CVE-2019-0708CVE-2021-26855+1 CVEs2

BlackHatSect0r Uses DeepSeek-Powered AI Agent to Automate Attacks and Harvest 16,834 Credentials

SOCRadar linked the BlackHatSect0r crew to a DeepSeek-powered AI agent that automated scanning and harvested 16,834 credentials from exposed systems.

SOCRadar researchers found an exposed operation server with 4.9 GB across 9,299 files, including the DXSCAN scanning platform, phishing tools, extortion material and a vault holding 16,834 credentials such as AWS keys, GitHub tokens and Stripe keys. The French-speaking crew ran a Nous Research Hermes agent against a DeepSeek model with safety features removed, queuing 2,759,860 domains and reaching 726,989 hosts. Access came from misconfigurations like public cloud buckets and exposed .env files, not new vulnerabilities.

Cyber Security News · 1d agoThreat actor in the wild 4 sources1

PeckBirdy C2 Traffic Seen Across Enterprise Networks While Hiding Behind Casino Domainsnew

Infoblox and Trend Micro detail China-aligned actors hiding PeckBirdy JavaScript C2 behind Chinese casino domains, with over 3% of enterprise customers resolving malicious domains.

Infoblox telemetry found just over 3% of enterprise customers resolved at least one PeckBirdy C2 domain, including cache-mcp[.]com and mcp-source[.]online, indicating reach beyond the campaign's apparent Asian victim focus. Trend Micro links PeckBirdy, a JScript C2 framework active since 2023, to China-aligned campaigns targeting Chinese gambling organizations, Asian government entities, and private-sector organizations. Low-quality casino portals such as vip311[.]cc embed malicious JavaScript and WebSocket C2 endpoints that evade scanners, delivering tailored landing scripts for MSHTA, HTML, and WScript execution and abusing Windows LOLBins. Infoblox tracks roughly 1.7 million Chinese-language casino domains, with the FUNNULL CDN and Vigorish Viper clusters covering about 81% of that population.

GBHackers · 23m agoThreat actor in the wild 3 sources

China’s FamousSparrow hackers target Latin America with new backdoor

ESET links a new SparroWocky backdoor campaign against Latin American government agencies to Chinese espionage group FamousSparrow.

ESET researcher Alexandre Côté Cyr has tracked the campaign since at least August 2025, hitting government departments in Guatemala, Honduras, Puerto Rico, Panama, Venezuela, Peru and Argentina. The SparroWocky backdoor embeds a stanza of Lewis Carroll's "Jabberwocky," resists analysis, exfiltrates files and screenshots, and collects system information such as IP address and usernames. ESET attributes the operation to FamousSparrow, a Chinese espionage group active since at least 2019 and publicly linked to Salt Typhoon. The targeting is likely intended to help China anticipate Latin American government reactions to renewed US pressure in the region, including disputes over ports near the Panama Canal.

The Recordupdated · 18h agofirst · 21h agoThreat actor in the wild 9 sources

Handala Hack Uses CRUDEEXCLUDE to Disable Defender Protections and Deploy HEAVYGRAM

Group-IB links new HEAVYGRAM and CRUDEEXCLUDE malware to Iran-aligned Handala Hack (MOIS/Void Manticore), which spies on Iranian dissidents using Defender exclusions and Telegram C2.

Group-IB documented previously unreported HEAVYGRAM and CRUDEEXCLUDE malware linked with moderate confidence to the Iran-aligned Handala Hack, assessed as a MOIS-linked persona tied to Void Manticore (Storm-0842, Banished Kitten, Red Sandstorm). CRUDEEXCLUDE uses PowerShell to add attacker-controlled Microsoft Defender exclusions, then a Delphi-based loader deploys a PyInstaller-packaged HEAVYGRAM implant that abuses Telegram bot APIs for command-and-control, shell execution, screenshots, audio recording, and Telegram Desktop data theft. The campaign targets Iranian dissidents, journalists, and academics with fake KeePass, Telegram, WhatsApp, and Pictory installers. The DOJ seized four related domains in March 2026 and the FBI published a HEAVYGRAM FLASH report on September 15.

GBHackersupdated · 1d agofirst · 1d agoThreat actor in the wild 10 sources

SilkParasite Hackers Use SpiceRAT Infrastructure to Target Central Asian Governments and Energy Firms

Hunt.io links SpiceRAT C2 infrastructure to the China-nexus SilkParasite espionage cluster targeting Central Asian governments, telecoms, and energy firms.

Hunt.io analysis expanded the SpiceRAT command-and-control footprint tied to SilkParasite, a China-nexus espionage cluster (medium confidence per Bitdefender) targeting government, telecommunications, and energy entities across Central Asia. Five active servers coordinated from mid-March 2026 were clustered via reused hostnames, TLS certificates, and a byte-identical clone of RTX Corporation's webpage found on 13 IPs; a certificate for azure.uzrailwaystax[.]com appeared across eight servers. Domains impersonated Türkmengaz, Tojiktelecom, Turkmenistan's Foreign Ministry, and Uzbek and Kyrgyz bodies, with passive DNS history dating to mid-2022. Impersonated organizations were not confirmed as compromised; Cisco Talos previously linked SpiceRAT to SneakyChef's LNK/HTA infection chains.

GBHackersupdated · 23h agofirst · 1d agoThreat actor in the wild 3 sources

APT36 Targets Indian Government and Defense Organizations With New Rust Malware Arsenal

Pakistan-linked APT36 deployed a Rust malware suite, including RUSTYSHADE and USB-spreading RUSTYMOVE, against Indian and Afghan government and defense targets.

Zscaler ThreatLabz tracks the August 2026 activity as Operation RapidRust, introducing the Rust-based RUSTYSHADE backdoor, the RUSTYMOVE removable-media propagation utility, and PSNATCH and BASHNATCH file stealers for Windows and Linux. RUSTYSHADE uses private GitHub repositories as C2 with AES-256-GCM-encrypted traffic, supporting shell commands, screenshots, webcam capture, and encrypted exfiltration, while PSNATCH collects Office documents, archives, images, and databases from user folders and drives D: through H:. Typosquat domains spoofing ThePrint and India Today staged payloads with Backblaze storage, and persistence used scheduled tasks impersonating OneDrive and Microsoft Edge updates.

GBHackersupdated · 1d agofirst · 1d agoThreat actor in the wild 3 sources