ZeroHour

Search: “Unit 221B”

32 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

The EU CRA's Real Question: What Shipped, and When Did You Know?

ActiveState argues the EU CRA's 24-hour ENISA exploit-notification duty, effective September 11, 2026, makes current SBOMs and provenance visibility a legal necessity.

An ActiveState essay warns that the EU Cyber Resilience Act's reporting obligations take effect on September 11, 2026, requiring manufacturers of products with digital elements sold into the EU to notify ENISA within 24 hours of learning a vulnerability is actively exploited, with a fuller report within 72 hours. The law's engineering requirements only apply from December 11, 2027, leaving a visibility-first runway, and Article 13 requires the SBOM to stay current unlike one-time artifacts generated under US Executive Order 14028. The author contrasts the 24-hour notification clock with an industry-average 55 days to remediate high or critical vulnerabilities and recommends automated SBOM regeneration or consuming pre-vetted, attested open source components.

BleepingComputer · 7d agoPolicy & legal

Jail time for Maine child in 764 marks turning point in federal law enforcement

A 17-year-old from Maine became the first minor federally adjudicated for 764 extremist crimes, including child exploitation, signaling a policy shift on prosecuting juveniles.

The FBI said a Maine teenager is the first child federally charged and adjudicated for crimes tied to the nihilistic violent extremist collective 764, part of The Com network. Charges include conspiracy to sexually exploit a child, distributing CSAM, interstate threats, cyberstalking, and identity theft. The case marks a turning point in federal policy on prosecuting juveniles and continues heightened enforcement: Kyle Spitze was sentenced to 77 years and Alexis Chavez to 40 years in related cases. The FBI is investigating more than 500 subjects connected to 764 and its offshoots nationwide.

CyberScoop · 13d agoPolicy & legal

Bipartisan Senate bill aims to prepare energy sector for Q

Bipartisan Senate bill would direct FERC to factor quantum computing threats and post-quantum cryptography into US electric grid cybersecurity reliability standards.

The Quantum Grid Utility Assurance and Resilient Defense (Quantum-GUARD) Act, introduced by Senators Mike Rounds and Chris Coons, would require FERC to consider quantum computing threats when reviewing electric reliability standards and to explore post-quantum cryptography use in both IT and OT systems, plus a technical sandbox to study quantum impacts. It aligns with NIST's post-quantum algorithm work, and a June executive order moved the federal PQC migration deadline from 2035 to 2030. Industry experts noted the hard part is upgrading infrastructure such as SCADA communications and software update integrity ahead of those deadlines.

CyberScoop · 22d agoPolicy & legal

Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist

Kyle Spitze, an early 764 member, was sentenced to 77 years for producing CSAM, the longest sentence for a nihilistic violent extremist.

Kyle William Spitze, an original member of the 764 nihilistic violent extremist network and administrator of the Harm Nation offshoot, was sentenced to 77 years in federal prison. He pleaded guilty in December 2024 to producing child sexual abuse material, possession of CSAM, and distributing animal crush videos, victimizing dozens of girls through coercion, doxing and swatting threats. Investigators found roughly 25 photo albums of abuse imagery on his phone and evidence of animal torture. The Justice Department framed the sentence as a signal in a broader enforcement push against 764, which has seen multiple members arrested or sentenced since 2025.

CyberScoop · 26d agoPolicy & legal

U.S. Offers $10 Million Reward for Iranian IRGC Cyber Chief Linked to Critical Infrastructure Attacks

The U.S. State Department offered up to $10 million for information on Amir Yaryab, an IRGC cyber chief linked to critical infrastructure attacks.

The U.S. State Department's Rewards for Justice program offers up to $10 million for information identifying or locating Amir Yaryab, who allegedly oversees the Cyber Operations Command of Iran's IRGC Cyber-Electronic Command (IRGC-CEC). Officials tie him to units called Shahid Hemmat and Shahid Shushtari conducting cyber and information campaigns against defense, telecommunications, energy, and finance sectors across the US, Europe, and the Middle East, and to groups including CyberAv3ngers and Dadeh Afzar Arman. CyberAv3ngers compromised at least 75 Unitronics Vision Series PLCs, including 34 in US water and wastewater facilities, between November 2023 and January 2024.

Cyber Security News · 8d agoPolicy & legal

Mitsubishi Electric CNC Series (Update A)

CISA's updated ICS advisory details CVE-2025-2399, an out-of-bounds read in Mitsubishi Electric CNC series that lets a remote attacker cause a denial-of-service condition.

CISA released Update A of ICS advisory ICSA-26-078-05 covering Mitsubishi Electric CNC series controllers. The vulnerability CVE-2025-2399 is an out-of-bounds read that a remote attacker can exploit to trigger a denial-of-service condition. Affected products include M800VW, M800VS, M80V, M80VW, M800W, M800S and M80 series controllers up to specified firmware revisions. No exploitation is reported in the advisory.

CISA Advisories · 20d agoAdvisoryCVE-2025-2399

ATF declares ‘major incident’ as ransomware gang claims hack

The ATF declared a major cybersecurity incident and notified Congress after a ransomware gang claimed responsibility for hacking the federal agency.

The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) formally declared a major incident involving its cybersecurity and notified Congress, according to the agency. A ransomware gang has publicly claimed responsibility for the attack. ATF is the latest in a series of US federal agencies in recent years to report a major cyber incident, though the gang's identity and the scope of data affected were not specified in initial reporting.

TechCrunch · Security · 19d agoRansomware

Cyberattack forces UT San Antonio to delay start of fall semester

UT San Antonio delayed fall semester start by three days after a weekend cyberattack was caught at the network edge before core systems.

The University of Texas at San Antonio, which serves more than 42,000 students, moved its fall semester start from August 19 to August 24 after a weekend cyberattack on its academic network. Officials said the intrusion attempt was caught at the edge of the network before reaching core systems and that no evidence of data theft has been found. The university took systems and services offline for review, causing phone system outages and password reset tool delays. The incident follows the Instructure Canvas breach during spring finals week that exposed data tied to millions of students and staff worldwide.

Help Net Security · 28d agoExploit / PoC

CISA's logging guidance works beyond government

CISA released its Logging Reference Architecture in August 2026 to help federal agencies meet OMB M-26-14 logging requirements, usable as a benchmark by critical infrastructure operators.

CISA's Logging Reference Architecture (LRA), released in August 2026, helps US federal civilian agencies satisfy logging requirements in OMB Memorandum M-26-14 and explicitly encourages critical infrastructure operators to use it as a benchmark. The framework is organized around continuous event monitoring and threat hunting, investigation, response, and forensics, with a federal baseline of six months searchable and one year retrievable logs. Agencies must submit Agency Logging Plans within 90 days and work toward Advanced maturity within 320 days; the guidance also treats AI outputs as derived data requiring human review and preserved metadata.

Help Net Security · 23d agoAdvisory

ATF responds to 'major' cybersecurity incident after ransomware gang's claims

The ATF is responding to a major cybersecurity incident claimed by a ransomware gang, with the US Justice Department investigating the breach.

The US Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) acknowledged a 'major' cybersecurity incident after a ransomware gang claimed responsibility for an attack. The US Justice Department is investigating the breach. Available reporting provides limited technical detail, and the scope of data theft and operational impact remains unclear.

The Register · Security · 20d agoRansomware

2,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber Operators

Leaked Bauman Moscow State Technical University files reveal a hidden GRU training pipeline feeding APT28 and Sandworm units.

More than 2,000 leaked Bauman Moscow State Technical University documents show that Department No. 4, a hidden program inside the Military Training Center, trained roughly 250 career and reserve students for GRU cyber and intelligence roles across six academic years. Graduates were linked to Military Unit 26165 (APT28), Unit 74455 (Sandworm/APT44) and Unit 29155, and former Unit 26165 commander Viktor Netyksho was involved in department oversight. Reporting by The Insider, The Guardian, Le Monde, Der Spiegel and other outlets, with independent analysis by DomainTools, estimates 10-15 students annually were selected for GRU-related assignments before graduating.

Security Affairs · 13d agoThreat actor1

SonicWall SMA 1000 appliances under attack via zero-day flaws

SonicWall confirms active exploitation of zero-day SSRF (CVE-2026-83548) and command injection (CVE-2026-83549) flaws in SMA 1000 remote access appliances.

SonicWall confirmed attackers are actively exploiting two previously undisclosed vulnerabilities in SMA 1000 SSL VPN appliances, affecting physical and virtual models 6210, 7210, and 8200v but not SMA 100 appliances or SonicWall firewalls. CVE-2026-83548 is a pre-authentication SSRF in the Appliance Work Place interface allowing remote unauthenticated attackers to gain unauthorized access to sensitive functionality, while CVE-2026-83549 is an OS command injection in the Appliance Management Console that can yield remote code execution under specific conditions for authenticated admins. The vendor urged immediate hotfix deployment, IoC review with technical support, and re-imaging or redeployment plus password and TOTP token resets on confirmed compromise. This is the latest in a series of zero-day attacks against SMA 1000 appliances following waves in late 2025 and June-July 2026.

Help Net Security · 14d agoExploit / PoC in the wildCVE-2026-83548CVE-2026-83549

Batten the Hatches: Cybersecurity with Military Mariners

Interviews with 20 U.S. Navy and Coast Guard mariners reveal informal, safety-oriented shipboard cyber risk models that may delay attribution and containment.

The study conducts semi-structured interviews with 20 military mariners from U.S. Navy and Coast Guard vessels to understand how service members recognize and respond to cyber risk aboard ships. Unique consequences of compromising military systems identified include weapon takeover and purposeful geopolitical escalation. Cybersecurity is organizationally abstract on ships, so mariners build cyber risk models from informal experience rather than formal instruction. A safety-oriented incident-response model creates resilience but may delay cyber attribution and containment.

arXiv cs.CR · 5d agoResearch

SonicWall's SMA1000 boxes under active attack again

SonicWall warns attackers are chaining two SMA1000 zero-days, a CVSS 10.0 SSRF and command injection, to compromise VPN gateways.

SonicWall says attackers are actively exploiting two chained zero-days in SMA 1000 appliances: CVE-2026-83548, a pre-authentication SSRF rated CVSS 10.0, and CVE-2026-83549, a post-authentication OS command injection (CVSS 7.8) in the Appliance Management Console. Hotfixes are available for SMA 6210, 7210, and 8200v appliances with no workarounds; SonicWall recommends reimaging compromised devices, rotating passwords, and resetting TOTP tokens. NHS England assesses further exploitation as almost certain, following a similar exploited pair in July when CISA added CVE-2026-15409 to its KEV catalog.

U.S. CISA adds a Ray-Project Ray flaw to its Known Exploited Vulnerabilities catalog

CISA added actively exploited Ray RCE flaw CVE-2025-62593 (CVSS 9.4) to its KEV catalog, ordering federal agencies to patch by August 20, 2026.

CISA added CVE-2025-62593 (CVSS 9.4), a critical remote code execution flaw in the Ray AI compute engine, to its Known Exploited Vulnerabilities catalog with a due date of August 20, 2026. Versions before 2.52.0 relied on a User-Agent header check to guard the dashboard/API, which combined with DNS rebinding allows arbitrary code execution on developers' machines via malicious websites or ads. Aviatrix's analysis describes privilege escalation, lateral movement, command and control, and data exfiltration following exploitation. Federal civilian agencies must remediate under BOD 22-01; the flaw affects Firefox and Safari.

Security Affairs · 29d agoExploit / PoC in the wildCVE-2025-62593

ENISA launched the CRA Single Reporting Platform for actively exploited vulnerabilities

ENISA launched the CRA Single Reporting Platform, making EU manufacturers report actively exploited vulnerabilities and severe incidents through one portal.

ENISA switched on the Cyber Resilience Act's Single Reporting Platform on 11 September 2026, the same day CRA reporting obligations became binding on manufacturers. Reports require an early warning within 24 hours, a fuller notification within 72 hours, and a final report within 14 days (one month after notification for severe incidents). Filings go through an EU Login account with MFA, are routed to a coordinating CSIRT chosen by the manufacturer, and no API is available in the first release. Open-source software stewards fall under the same obligations from 11 December 2027.

Help Net Security · 2d agoPolicy & legal

Persistent Attempts at Cyberespionage Against Southeast Asian Government Target Have Links to Alloy Taurus

Alloy Taurus (GALLIUM) compromised Southeast Asian government networks from 2022 to 2023 using Exchange web shells and undocumented .NET backdoors Reshell and Zapoa.

Unit 42 tracked persistent multiwave intrusions at a Southeast Asian government starting in early 2022 and continuing through 2023, attributing the activity with moderate confidence to Alloy Taurus (aka GALLIUM), a Chinese state-aligned espionage group. Attackers exploited Exchange Server vulnerabilities to deploy web shells including China Chopper, then ran reconnaissance with Fscan and WebScan, created administrative accounts, and installed undocumented .NET backdoors named Reshell and Zapoa. They established resilience by installing SoftEther VPN, brute-forced Active Directory credentials with Kerbrute, and dumped credential stores with GoDumpLsass and LsassUnhooker. The campaign reflects long-term espionage tradecraft to maintain a foothold.

Palo Alto Unit 42 · Aug 17, 2026Threat actor in the wild1

The push to designate AI as the next critical infrastructure sector

Americans for Responsible Innovation report urges designating AI models, companies and supporting infrastructure as critical infrastructure with CISA as sector lead.

A report from the nonprofit Americans for Responsible Innovation calls for the federal government to declare the AI sector — including frontier model designs, model weights, datacenters, AI hardware and semiconductors — the 17th critical infrastructure sector, with CISA as the lead agency for sector cyberthreats. The authors argue AI is concentrated among a handful of foundation models and interdependent with other sectors, so a single attack on the AI stack could cascade widely, citing incidents like Iranian drone attacks on Amazon datacenters. Former DHS officials note the designation would unlock federal resources such as CDM access and threat intelligence, but warn that picking a lead agency could trigger a bureaucratic turf war with Commerce and Treasury.

CyberScoop · 27d agoAI policy

Ncsc Raises Alarms Prompt

The UK NCSC raised alarms about prompt injection risks in LLM-integrated systems, urging organizations deploying AI to review exposure.

The UK National Cyber Security Centre (NCSC) has raised alarms about prompt injection attacks against systems using large language models. The warning highlights how attackers can manipulate model instructions to bypass safeguards, exfiltrate data, or trigger unintended agent actions. Organizations deploying LLM-based features are advised to assess and mitigate their exposure to this technique.

Infosecurity Magazine · 28d agoAI safety & security

[Control Systems] National Instruments security advisory (AV26-856)

Canada's Cyber Centre relayed National Instruments advisories for memory corruption, out-of-bounds read, and out-of-bounds write flaws in LabVIEW versions.

The Canadian Centre for Cyber Security published control systems advisory AV26-856 covering National Instruments LabVIEW. Affected versions include releases before 23.0.0, 23.3.10, 24.3.7, 25.3.5, and 26.3.1. The flaws include memory corruption, an integer conversion out-of-bounds read, and an integer overflow out-of-bounds write. Users and administrators are urged to review the links and apply NI security updates.

Canadian Centre for Cyber Security · 19d agoAdvisory

31st August – Threat Intelligence Report

Manchester Airports Group disclosed a cyberattack exposing contact details of about 8.7 million customers across Manchester, Stansted, and East Midlands airports.

Manchester Airports Group, the UK operator of Manchester, London Stansted, and East Midlands airports, disclosed a cyberattack that exposed data belonging to roughly 8.7 million customers. Check Point's weekly threat intelligence bulletin reports the compromised information includes contact details. The disclosure appeared in Check Point's 31 August Threat Intelligence Report covering the week's top attacks and breaches.

Check Point Research · 16d agoData breach in the wild

Analysis of Smoke Loader in New Tsunami Campaign

Fake Japanese Meteorological Agency tsunami warning emails delivered Smoke Loader and AzoRult malware to steal credentials from targets in Japan.

A fake tsunami warning email impersonating Japan's Meteorological Agency asked recipients to click a link on a registered fake agency domain, delivering the commodity loader Smoke Loader to targets in Japan. Smoke Loader, active since 2011, is modular, and its payloads have included banking trojans, ransomware, cryptominers, password stealers, and PoS malware; the campaign later also deployed AzoRult. New samples add junk-jump obfuscation, encrypted network traffic and payload files, a unique machine ID used for tracking and encryption, and PROPagate injection into explorer.exe, with persistence via a Startup folder shortcut and RC4-encrypted C2 communication.

Palo Alto Unit 42 · Aug 17, 2026Malware in the wild

Stately Taurus Activity in Southeast Asia Links to Bookworm Malware

Unit 42 links Stately Taurus APT activity in ASEAN region and Myanmar to the decade-old Bookworm malware family via infrastructure overlaps.

Unit 42 connected Stately Taurus (aka Mustang Panda) espionage activity targeting ASEAN-affiliated organizations and Myanmar to the Bookworm malware family, first published in 2015. Earlier attacks delivered the PubLoad stager via DLL sideloading, with a PubLoad variant communicating with C2 at 123.253.32[.]15 while mimicking Windows Update URLs. Three previously unreported loader samples from 2021-2022 used UUID-decoded shellcode loaded via heap allocation and API callbacks, ultimately decrypting and loading Bookworm DLLs. A ToneShell backdoor variant shared debug paths with Bookworm loaders, and the January 2024 CSIRT CTI post corroborated the Myanmar attacks.

Palo Alto Unit 42 · Aug 17, 2026Threat actor in the wild

Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack

Check Point details an Operation Dream Job wave using trojanized PDF viewers to hit defense, aerospace, and aviation targets since early 2026.

Since early 2026, Check Point Research has tracked a wave of the Operation Dream Job campaign primarily targeting the global defense sector, with emphasis on aerospace and aviation companies. The threat actor distributes modified PDF viewers that execute malicious payloads embedded in specially crafted files, delivered under fake job-offer pretexts. Check Point characterizes the operation as a zero-day attack.

Check Point Research · Aug 11, 2026Threat actor in the wild

Banking Trojans: Ursnif Global Distribution Networks Identified

Unit 42 maps banking-trojan distribution networks: spam botnets push Shiotob downloaders and Ursnif, KINS, Tinba at Japan and European targets via compromised web servers.

Unit 42 identified the distribution networks behind banking trojan attacks against Japan, Italy, Spain, Poland, Australia, and Germany. A spam botnet delivered 75 unique Shiotob (Bebloh/URLZone) variants across 7 million spam emails, with Shiotob acting mainly as a downloader that installs Ursnif and the Pushdo spam bot from C2 commands. Over 200 malicious files were hosted on 74 compromised, mostly European small-business web servers between April 2015 and January 2017, with localized invoice and photo-themed email lures per target country.

Palo Alto Unit 42 · Aug 17, 2026Malware in the wild

Privileged File System Vulnerability Present in a SCADA System

Unit 42 details CVE-2025-0921 (CVSS 6.5), a privileged file operations flaw in Iconics Suite enabling DoS and privilege escalation.

Unit 42 disclosed CVE-2025-0921 (CVSS 6.5), an execution-with-unnecessary-privileges flaw in the Pager Agent of the AlarmWorX64 MMX feature of Mitsubishi Electric Iconics Digital Solutions GENESIS64. Attackers could misuse privileged file system operations to corrupt critical binaries, causing denial-of-service or integrity loss on vulnerable SCADA systems. The analysis demonstrates a chain with CVE-2024-7587, which grants excessive permissions to the C:\ProgramData\ICONICS directory via the GenBroker32 installer. Iconics released an advisory with a workaround that addresses the reported issues.

KRBanker Targets South Korea Through Adware and Exploit Kits

Unit 42 details KRBanker banking trojan targeting South Korean bank users via KaiXin exploit kit and NEWSPOT adware, using pharming and process hollowing.

KRBanker (aka Blackmoon) is a banking trojan targeting online banking users in the Republic of Korea, with roughly 2,000 unique samples and 200+ pharming servers observed by Unit 42 over six months. It is distributed through the KaiXin exploit kit exploiting Adobe Flash CVE-2014-0569 and CVE-2015-3133, and through the NEWSPOT adware update channel that also delivers the Venik trojan. The trojan uses process hollowing, retrieves pharming server IPs from Qzone profile nickname fields, and abuses Proxy Auto-Config with a local proxy to redirect banking traffic to forged sites.

Palo Alto Unit 42 · Aug 17, 2026Malware in the wildCVE-2014-0569CVE-2015-3133

EU Cyber Resilience Act to Enforce New Reporting Requirements

EU Cyber Resilience Act reporting obligations begin Friday, requiring businesses to notify serious product security incidents within 24 hours.

The EU Cyber Resilience Act's new reporting requirements take effect starting Friday. Businesses operating in the EU will have 24 hours to notify the government whenever they discover serious product security incidents.

Dark Reading · 6d agoPolicy & legal

CISA confirms hackers targeted over 100 US water systems during July

CISA says hackers targeted over 100 US water systems in July amid suspected Iran-backed attacks on critical water infrastructure.

CISA confirmed that hackers targeted more than 100 US water systems during July. The federal agency's warning comes amid a wave of suspected Iran-backed cyberattacks against critical water infrastructure across the United States. The available text does not specify intrusion methods, compromised utilities by name, or data impact.

TechCrunch · Security · 21d agoThreat actor in the wild

Unit 42 Researchers Discover Multiple Espionage Operations Targeting Southeast Asian Government

Unit 42 attributes three espionage clusters targeting a Southeast Asian government to Stately Taurus, Alloy Taurus, and Gelsemium APTs.

Unit 42 investigated espionage attacks starting in late 2022 against multiple governmental entities in a Southeast Asian country, including critical infrastructure, public healthcare, financial administrators, and ministries. Analysis revealed three distinct clusters: CL-STA-0044 attributed to Stately Taurus (Mustang Panda), CL-STA-0045 to Alloy Taurus (GALLIUM), and CL-STA-0046 to Gelsemium. The first cluster used a ToneShell backdoor variant, ShadowPad, China Chopper web shells, Impacket, and credential dumping tools across roughly Q1 2021 to Q3 2023. All three operated with distinct tools, infrastructure, and long-term surveillance tradecraft consistent with APTs.

Palo Alto Unit 42 · Aug 17, 2026Threat actor in the wild