ZeroHour

Search: “Steam”

40 stories

Cyberattack on logistics giant Ceva hits retailers and Steam customers across Europe

Cyberattack on Ceva Logistics disrupted eight European warehouses, delaying shipments for Bol, De Bijenkorf, Ajax and exposing Steam hardware buyers' data.

A cyberattack on Ceva Logistics disrupted operations at eight European warehouses, delaying shipments for Bol, De Bijenkorf, Ace & Tate, Ajax and Steam hardware customers. Attackers accessed two Ceva systems processing Bol orders, potentially exposing names, addresses, phone numbers, email addresses and order details. Valve began notifying European Steam customers whose hardware shipping data may have been compromised and is contacting data protection authorities. Ceva, with about 110,000 employees and over 1,700 facilities, has not disclosed the attackers or whether ransomware was involved.

The Record · Aug 11, 2026Data breach in the wild

ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager

Cisco Talos details ClearFake WebDAV chains delivering Amatera stealer to a Ukrainian government organization, with cryptocurrency and credential theft payloads.

Cisco Talos investigated DLL executions named 'verification.google' via WebDAV UNC paths at a Ukrainian government organization, tracking the actor as UAT-10820 and assessing with moderate confidence the activity is Russian and opportunistic rather than targeted. The infection chain uses ClearFake JavaScript injected via a Cloudflare Worker, EtherHiding storage on BNB Smart Chain contracts, and a ClickFix fake Google CAPTCHA prompt to deliver Amatera stealer. Secondary payloads differ by C2: one loader deploys ZigCryptoStealer with a Go reverse TCP proxy and a vulnerable driver that kills EDR, while the other installs an unauthorized NetSupport Manager with a Russia-based C2. Similar Amatera chains were separately documented by Malwarebytes and Blackpoint Cyber, but with no shared infrastructure.

Cisco Talos · 9d agoMalware in the wild1

Scammers have figured out the best time to text you

Malwarebytes threat data shows scammers tailor platforms per scam, with the web as top channel, Friday midday peaks, and MrBeast the most impersonated person.

Malwarebytes analyzed its threat data from April 15 to July 14, 2026 across more than 20 scam categories, finding scammers match platforms to scam types: job scams via email, romance scams via social media, and tech support scams via phone. The web is the top delivery channel ahead of email and SMS, and Malwarebytes says it blocks about 500,000 phishing sites a day. Scam texts peak at 12:00 pm ET, roughly 874% above the quietest hour, with volume peaking on Fridays about 50% higher than the start of the week. MrBeast (Jimmy Donaldson) appears in about 30% of impersonation scams, and the most impersonated brands are Google, Microsoft, Apple, Roblox and Amazon.

Help Net Security · 13d agoPhishing & fraud in the wild

Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day

Weekly digest: exploited Metabase zero-day breached Framework; Salesforce/ServiceNow portals read for 17 months; Microsoft patched 400+ flaws.

Help Net Security's week in review aggregates top stories: a 'City-Forum' campaign tracked by Reco has been pulling records from Salesforce and ServiceNow portals worldwide for 17 months, and Framework suffered a breach via an exploited Metabase zero-day exposing customer contact and IP data. It also covers Microsoft's August 2026 Patch Tuesday fixing 400+ flaws including exploited zero-day CVE-2026-68820, Cisco's fix for exploited firewall DoS bug CVE-2026-20349 (added to CISA KEV), and a second N-able N-central hotfix for actively exploited CVE-2026-18577. Other items include GitHub expanding Dependabot malware alerts to eight package ecosystems and EU AI Act enforcement beginning on 2 August 2026.

Help Net Security · Aug 16, 2026Industry in the wildCVE-2026-18577CVE-2026-68820CVE-2026-203491

Infostealers Target Claude, Cursor, Codex and Other AI Agents to Steal Credentials and Sensitive Data

Gen Digital researchers report infostealer families Amatera, Remus and CallbackBeaver now harvest Claude, Cursor and Codex agent data, including tokens and MCP configs.

Gen Digital researchers found commodity infostealers extending their collection rules to local AI coding agent data from Claude, Cursor, Codex, Cline, Continue and OpenCode on Windows and macOS. Amatera targets Cline and Continue, Remus targets Claude, Cursor and OpenCode, and CallbackBeaver added Claude and Cursor with more than 5,000 samples observed in 30 days; Djinn Stealer hits Claude, Codex, Gemini, Cline, OpenCode and Kilo on macOS. Stolen data includes access and refresh tokens, prompt histories, conversation databases and MCP configurations holding API keys, potentially exposing connected source-control, cloud and ticketing systems. Remus is assessed as a Lumma Stealer variant using EtherHiding C2 resolution via Ethereum smart contracts.

GBHackers · 8d agoMalware in the wild1

ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories

Weekly ThreatsDay bulletin details a ShinyHunters-style social engineering hit on ReliaQuest, the 296,000-device Dysphoria IoT botnet, and several new malware families.

ReliaQuest confirmed a social engineering attack on August 22, 2026, in which an attacker used a fake SSO page and MFA push approval to gain brief view-only access to an identity dashboard, with tactics matching ShinyHunters, which has since listed the firm on its leak portal. The Shadowserver Foundation reported the Dysphoria botnet has compromised nearly 296,000 IoT devices for DDoS attacks and recently added residential proxy capability. Cisco Talos documented JWR, an operator-driven phishing-as-a-service framework linked to The Outsider that harvests credentials, identity documents, and 2FA codes over an encrypted WebSocket. New malware coverage includes the Octagon Android fraud bot ($1,400/month), the C2Looper Rust backdoor delivered via ClickFix, and the Aeternum loader that moved C2 to the Polygon blockchain.

The Hacker News · 15d agoMalware in the wild

CEVA Logistics Cyberattack Disrupts European Warehouses and Shipments

Cyberattack on CEVA Logistics disrupted eight European warehouses and exposed customer data of clients including Valve, Ajax, and De Bijenkorf.

CEVA Logistics, part of CMA CGM Group, suffered a July 29 cyberattack that disrupted eight European warehouses and halted shipments of stored goods. Customer data linked to Valve, Ajax, and Dutch retailer De Bijenkorf was exposed, potentially including names, contact details, and online order information; Valve said payment details and passwords were not accessed. No ransomware group has claimed responsibility and the company has not disclosed technical details. A database containing customer lists, shipping records, and banking details was reportedly later offered for sale on a dark web marketplace.

Security Affairs · Aug 12, 2026Data breach in the wild