ZeroHour

Search: “Facebook”

9 stories in the last 24h

Israeli contractor BlackCore trained Angolan officials in online influence operationsnew

Citizen Lab links Israeli firm BlackCore to training Angolan officials to run covert influence campaigns with fake personas and pro-government content.

Citizen Lab documents show Israeli influence-for-hire firm BlackCore ran a 14-week training and operations program for Angolan officials, producing more than 40 pro-government content pieces through a fictitious outlet called Agita News. Posts received roughly 20,000 likes, with some later approaching 50,000, in a country with an estimated six million active Facebook users. France's Viginum previously linked BlackCore to interference targeting France Unbowed and suspected operations in New York, Scotland and Togo, and Meta disrupted a related Israel-origin network in August.

The Record · 39m agoThreat actor

NightmareStresser Goes Offline in Global DDoS-for-Hire Crackdownnew

The DOJ seized NightmareStresser domains, a DDoS-for-hire service behind hundreds of thousands of attacks since 2022, as part of Operation PowerOFF.

The US Department of Justice announced the court-authorized seizure of internet domains behind NightmareStresser, a booter service allegedly used to launch hundreds of thousands of actual or attempted DDoS attacks worldwide since 2022. The action, announced from the District of Alaska with FBI Anchorage and Royal Canadian Mounted Police support, is part of Operation PowerOFF, which previously took down 53 domains across 21 countries in April and 27 booter sites in December 2024. Over the past eight years, prosecutors have charged twelve defendants and seized more than 100 domains tied to DDoS-for-hire services.

Ofcom discovers issuing Online Safety Act fines is easier than collecting them

Ofcom says most Online Safety Act fines totaling over £7 million remain unpaid as platforms structure businesses to evade collection.

Ofcom director of enforcement Suzanne Cater told the House of Lords that the majority of fines issued under the UK Online Safety Act remain uncollected despite over £7 million in penalties on 11 providers. The regulator's largest fine was £1.4 million against 8579 LLC in February. Ofcom is running six enforcement programs and 40 formal investigations covering more than 100 services, including Telegram, TikTok and X, and is working with the UK government to strengthen its enforcement powers.

U.S. CISA adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog

CISA added actively exploited flaws in Cisco ISE, Acronis Backup, and Google Pixel (CVE-2026-76460, CVE-2026-87886, CVE-2026-58704) to its KEV catalog.

CISA added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-76460 (CVSS 10.0), an unauthenticated API authentication bypass in Cisco Identity Services Engine that Cisco confirms is being actively exploited; CVE-2026-87886, a local privilege escalation in the Acronis Backup plugins for cPanel/WHM and Plesk exploited in limited targeted attacks; and CVE-2026-58704 (CVSS 8.8), a Google Pixel cellular modem permission bypass exploited in limited, targeted attacks and patched in the September 2026 Pixel update. Under BOD 22-01, federal agencies must remediate KEV entries by the stated due dates. Google has not attributed the Pixel exploitation to any actor.

Chosen Brick, Iran’s Surveillance Malware

UK, US, and Dutch agencies warn Iranian CHOSEN BRICK malware targets dissidents and journalists via Telegram, harvesting contacts, emails, and messages since 2025.

The UK NCSC, FBI, and Dutch AIVD jointly attributed the CHOSEN BRICK Windows malware family to Iranian intelligence services, used since at least 2025 against dissidents, journalists, and activists worldwide, including in the UK, US, and Netherlands. Operators build rapport over WhatsApp or Telegram, impersonating known contacts or platform support, then deliver lures disguised as installers for Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, or KeePass, or fake MRI results. The malware persists via registry Run keys, adds Microsoft Defender exclusions, and uses per-victim Telegram bot IDs for C2, with newer versions adding HTTPS or SOCKS5 proxies. Some victims' data appeared on pro-Iranian leak sites, raising harassment and physical-safety risks.

Security Affairs · 5h agoMalware in the wild 7 sources

Nonprofit that tracks meteors taken down by "critical blow" from a cyberattack

The International Meteor Organization says a cyberattack dealt a critical blow to its infrastructure, taking much of its site offline for weeks.

The International Meteor Organization (IMO), a nonprofit coordinating amateur and professional meteor observations since 1988, reported a cyberattack that took much of its website offline. The organization expects several weeks of partial downtime while transitioning to new infrastructure and is prioritizing fireball reporting through alternate channels. The attack vector and whether any data was accessed remain undisclosed; the IMO's observation databases and WGN journal are widely used in the field.

Ars Technica · Security · 15h agoData breach in the wild 2 sources

BambooToken: The Malware That Speaks MQTT to Stay Under the Radar

Lumen's Black Lotus Labs uncovered BambooToken, a Windows and Linux malware family using MQTT broker-based C2 and DLL sideloading across Asia since February 2023.

Lumen Black Lotus Labs identified BambooToken, a multiplatform malware family that exchanges commands through MQTT brokers so infected hosts never contact the C2 server directly, active from at least February 2023 through July 2026. The Windows variant sideloads via Tendyron's OnKey hardware-token software used in Chinese banking and government, or impersonates Kingsoft Office, without either vendor's signing certificate being compromised; a Linux build appeared by December 2025 with shell, file transfer, and system information commands. Victims include MikroTik and DrayTek routers in Singapore, Cambodia, and Vietnam reached after internet-wide SNMP scanning, and Lumen cannot attribute the family to any known actor.

Security Affairs · 16h agoMalware in the wild1

Google Patches Pixel Modem Zero-Day Exploited in Targeted Attacks

Google patched Pixel modem zero-day CVE-2026-58704 (CVSS 8.0), exploited in limited targeted attacks, enabling adjacent privilege escalation without user interaction.

Google's September 2026 Pixel security update fixes CVE-2026-58704, a CVSS 8.0 permission bypass caused by a logic error in the cellular modem, allowing remote (proximal/adjacent) elevation of privilege with no user interaction or additional privileges. Google confirms indications of limited, targeted exploitation in the wild but provides no attribution, target count, or attack objectives. The modem location is significant because it operates below much of the Android application security model. The bulletin also patches multiple critical RCE flaws in IMS, libpixelimsmedia, VPU, modem, telephone and BigOcean components, with the 2026-09-05 patch level protecting devices.

Security Affairsupdated · 18h agofirst · 23h agoExploit / PoC in the wild 8 sourcesCVE-2026-58704

Revolut Data Leak May Trace Back to Compromised Italian Government Accounts

Attackers using a compromised Italian government PEC account impersonated law enforcement to obtain data on ~680 Revolut customers.

Revolut confirmed its systems were not breached; fraudulent data requests came from a compromised PEC mailbox tied to the Prefecture of Reggio Calabria on the pec.interno.it domain. Per the Financial Times, roughly 680 customers had identity documents, addresses, banking information, verification selfies and cryptocurrency transaction histories exposed. Researcher Korra of Duel described a 'spray and pray' operation using hundreds of crypto transaction IDs and fraudulent European Investigation Orders. Threat actor IAmNotAVillain claims six months of access and 147 GB exfiltrated from Italian law-enforcement systems, though this remains unverified.

Security Affairs · 23h agoData breach in the wild