ZeroHour

Search: “salt-typhoon”

30 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

Us Thwarts Volt Typhoon Espionage

US thwarts an espionage operation by Chinese state-linked threat actor Volt Typhoon, according to the headline.

The headline indicates US authorities disrupted espionage activity attributed to Volt Typhoon, the Chinese state-sponsored group known for targeting critical infrastructure. No article text is available, so details on scope, victims, or method are unavailable.

Infosecurity Magazine · 29d agoThreat actor in the wild

China Is Strapping ‘Digital Bombs’ to Civilian Infrastructure—Is the US Ready?

WIRED examines Volt Typhoon pre-positioning 'digital bombs' in US civilian infrastructure via a war game simulation discussion.

WIRED's Uncanny Valley podcast features reporter Andy Greenberg discussing a war game simulating a cyberattack by Chinese hacking group Volt Typhoon. The episode examines Volt Typhoon's practice of planting persistent access in US civilian infrastructure that could be activated during conflict, and questions whether the US is prepared.

WIRED · Security · 27d agoThreat actor

'Breeze Comet' Tears Into Brazilian & Global Financial Systems

Threat group 'Breeze Comet' is attacking Brazil's financial systems and reportedly stealing funds directly, per Dark Reading threat intelligence.

Dark Reading reports that 'Breeze Comet', described as Brazil's most sophisticated threat group, is compromising the country's financial systems. The activity is financially motivated, with funds reportedly moved directly to the attackers. The campaign reportedly extends to global financial systems, though technical details, victims and attribution evidence were not disclosed in the excerpt.

Dark Reading · 13d agoThreat actor in the wild

Philippine Nuclear and Naval Targets Hit by Suspected Chinese Operator

Suspected Chinese-speaking operator breached Philippine nuclear research and naval supplier systems via ownCloud CVE-2023-49103 and WordPress CVE-2024-28000.

Hunt.io found an exposed staging server containing custom Python scripts, logs, and stolen data documenting intrusions against a Philippine nuclear research body and a marine engineering company serving the Philippine Navy. The actor exploited an ownCloud authentication bypass (CVE-2023-49103) using empty-secret pre-signed WebDAV URLs and a LiteSpeed Cache plugin flaw (CVE-2024-28000) to gain WordPress admin access, also guessing passwords against XML-RPC with rockyou.txt. Roughly 9 GB was referenced as stolen from the nuclear agency, including reactor databases, radiation-safety records, and staff passport data; Simplified Chinese labels suggest a Chinese-speaking operator.

Security Affairs · 18d agoThreat actor in the wildCVE-2023-49103CVE-2024-28000

Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency

Threat actors exploited old unpatched ownCloud vulnerabilities to breach the Philippines nuclear agency, stealing reactor databases, personnel records, and credentials.

Attackers used commodity vulnerabilities in ownCloud as their initial access vector to compromise the Philippines nuclear agency. Stolen data reportedly includes reactor databases, personnel records, and credential stores. The flaws had gone unpatched, allowing sustained access to internal systems. The incident underscores continued exploitation of known file-sharing vulnerabilities against critical infrastructure targets.

Dark Reading · 15d agoData breach in the wild

The long tail of Clop’s PTC hack is just beginning to emerge

Clop mass-exploited CVE-2026-12569 in PTC Windchill and FlexPLM in early June, claiming data theft from dozens of large organizations.

Clop began sending extortion emails in mid-July after exploiting CVE-2026-12569 in PTC Windchill and FlexPLM, likely as a zero-day in early June before PTC's June 17 disclosure and patch. Confirmed victims include Toast and Zebra, while GE, Philips and Shell are among claimed victims. CISA added the flaw, which allows unauthenticated remote code execution, to its KEV catalog on June 25. ReliaQuest said the group used a custom Windchill-specific web shell for credential theft and large-scale exfiltration, echoing its past MOVEit and Oracle E-Business Suite mass-exploitation campaigns.

CyberScoop · 28d agoThreat actor in the wildCVE-2026-125691

ZDI-26-583: Clam AntiVirus 7z Archive Parsing Integer Overflow Remote Code Execution Vulnerability

Zero Day Initiative discloses CVE-2026-20215, an integer overflow in ClamAV's 7z archive parsing enabling remote code execution, rated CVSS 8.4.

The Zero Day Initiative published ZDI-26-583 for an integer overflow in Clam AntiVirus's 7z archive parsing. A remote attacker can execute arbitrary code when the antivirus processes a crafted archive, with attack vectors varying by implementation. The flaw is tracked as CVE-2026-20215 and rated CVSS 8.4. The advisory does not mention active exploitation.

ZDI Published Advisories · Aug 13, 2026VulnerabilityCVE-2026-202151

Identifying a BOLA Vulnerability in Harbor, a Cloud

Unit 42 found a BOLA flaw, CVE-2024-22278 (CVSS 6.4), letting Maintainers improperly alter Harbor project metadata; fixed in versions 2.9.5, 2.10.3, and 2.11.0.

Unit 42 researchers identified a broken object-level authorization flaw, CVE-2024-22278, in Harbor, a CNCF-graduated cloud-native container registry with 1.8 million downloads. The flaw (CVSS 6.4) lets users with the Maintainer role create, update, and delete project metadata, actions reserved for ProjectAdmin, risking data exposure, integrity compromise, and circumvention of vulnerability scanning. Harbor patched the issue in versions 2.9.5, 2.10.3, and 2.11.0. The finding came from Unit 42's automated BOLA detection tool built on generative AI.

Palo Alto Unit 42 · Aug 17, 2026VulnerabilityCVE-2024-22278

Analysis of Smoke Loader in New Tsunami Campaign

Fake Japanese Meteorological Agency tsunami warning emails delivered Smoke Loader and AzoRult malware to steal credentials from targets in Japan.

A fake tsunami warning email impersonating Japan's Meteorological Agency asked recipients to click a link on a registered fake agency domain, delivering the commodity loader Smoke Loader to targets in Japan. Smoke Loader, active since 2011, is modular, and its payloads have included banking trojans, ransomware, cryptominers, password stealers, and PoS malware; the campaign later also deployed AzoRult. New samples add junk-jump obfuscation, encrypted network traffic and payload files, a unique machine ID used for tracking and encryption, and PROPagate injection into explorer.exe, with persistence via a Startup folder shortcut and RC4-encrypted C2 communication.

Palo Alto Unit 42 · Aug 17, 2026Malware in the wild

Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

ReliaQuest details a bespoke JSP web shell that Clop deploys on hacked PTC Windchill and FlexPLM servers after exploiting CVE-2026-12569.

ReliaQuest analyzed a custom Java web shell planted on vulnerable PTC Windchill and FlexPLM servers following exploitation of CVE-2026-12569 (CVSS 9.3). The implant decrypts Windchill keystore credentials including the LDAP manager password, enumerates the file vault for engineering data, and loads attacker-supplied Java classes in memory for post-exploitation. Commands let operators read and delete files, exfiltrate results, and deliver follow-on payloads such as ransomware. Ransom-ISAC, eCrime.ch and Defused previously attributed the campaign to the Clop data-theft extortion group.

The Hacker News · 28d agoThreat actor in the wildCVE-2026-12569

N-able patches max severity N-central flaw amid ongoing attacks

N-able ships an emergency hotfix for a maximum-severity RCE flaw in its N-central RMM platform that attackers are actively exploiting.

N-able has released an emergency hotfix for a maximum-severity remote code execution vulnerability affecting its N-central remote monitoring and management (RMM) platform. The company urges customers to apply the fix immediately because attacks against N-central instances are ongoing. N-central is widely used by managed service providers, so a compromise of one deployment can expose many downstream customer environments.

BleepingComputer · 9d agoExploit / PoC in the wild

Is Someone Hacking DoD Refrigerators?

Refrigeration outages hit commissaries at seven US military installations, with hacking suspected but not confirmed by the Pentagon.

Refrigeration disruptions were reported at Defense Commissary Agency commissaries at Fort Irwin, F.E. Warren AFB, Fort Huachuca, Naval Station Newport, Columbus AFB, Travis AFB, and Naval Air Station Lemoore. A defense official acknowledged awareness of a possible refrigeration disruption, but the services and Pentagon declined to provide details. The post is speculative, arguing the coincidence of outages suggests possible hacking, though no evidence or attribution is provided.

Schneier on Security · 16d agoData breach

Storm-1175 Replaces Medusa With New StormEncryptor Ransomware

Microsoft reports China-linked ransomware group Storm-1175 switched from Medusa to a new C++ strain, StormEncryptor, likely exploiting N-able flaw CVE-2026-18577.

Microsoft Threat Intelligence reports that the financially motivated, China-linked group Storm-1175 began deploying a new ransomware strain called StormEncryptor on August 2, 2026, replacing its previous Medusa ransomware. StormEncryptor is written in C++, appends the .encrypted extension to files, and drops a !!!README_FIRST!!!.txt ransom note in each scanned directory. Microsoft assesses the group is likely exploiting CVE-2026-18577, an authentication bypass in N-able disclosed on August 2, 2026 and added to CISA's Known Exploited Vulnerabilities catalog the next day. Since 2023, Storm-1175 has exploited more than 16 vulnerabilities in products including Microsoft Exchange, Ivanti, ConnectWise ScreenConnect, JetBrains TeamCity, SimpleHelp, CrushFTP, and GoAnywhere MFT, often moving from initial access to data theft and ransomware deployment within days.

Security Affairs · Aug 13, 2026Ransomware in the wildCVE-2026-18577CVE-2026-1731CVE-2023-21529+15 CVEs1

Mitsubishi Electric CNC Series (Update A)

CISA's updated ICS advisory details CVE-2025-2399, an out-of-bounds read in Mitsubishi Electric CNC series that lets a remote attacker cause a denial-of-service condition.

CISA released Update A of ICS advisory ICSA-26-078-05 covering Mitsubishi Electric CNC series controllers. The vulnerability CVE-2025-2399 is an out-of-bounds read that a remote attacker can exploit to trigger a denial-of-service condition. Affected products include M800VW, M800VS, M80V, M80VW, M800W, M800S and M80 series controllers up to specified firmware revisions. No exploitation is reported in the advisory.

CISA Advisories · 20d agoAdvisoryCVE-2025-2399

ClamAV Vulnerabilities Affecting Cisco Products: August 2026

Cisco patched ClamAV vulnerabilities that allow remote attackers to cause denial-of-service conditions, rated High only for Windows-based platforms.

Cisco released an advisory covering multiple ClamAV vulnerabilities that could let a remote attacker interrupt scanning operations with a denial of service. Software updates are available for affected Cisco platforms, and no workarounds exist. The Security Impact Rating is High for Windows-based platforms because ClamAV runs there in a privileged security context.

Cisco Security Advisories · Aug 13, 2026Advisory

Mitsubishi Electric Multiple FA Products (Update D)

CISA warns Mitsubishi Electric CC-Link IE TSN remote I/O modules are vulnerable to denial-of-service via crafted UDP packets (CVE-2025-3511).

CISA published Update D of advisory ICSA-25-128-03 covering Mitsubishi Electric factory automation products. Affected products include CC-Link IE TSN Remote I/O modules NZ2GN2S1-32D, NZ2GN2S1-32T, NZ2GN2S1-32TE, and NZ2GN2S1-32DT at firmware version 09 or earlier (CVE-2025-3511). A remote attacker can send a specially crafted UDP packet to cause denial-of-service conditions, timeout errors, or communication delays on the affected products.

CISA Advisories · 20d agoAdvisoryCVE-2025-3511

North Korean Hackers Tied to Rust Supply Chain Attack

Researchers linked a backdoor hidden in compromised Rust packages to North Korean actors' prior software supply chain attack campaigns.

Cybersecurity researchers attributed a malicious backdoor planted in compromised Rust packages to North Korean threat actors based on ties to earlier supply chain attacks. The campaign targets the open-source developer ecosystem, where infected packages can propagate downstream to developer build systems. The attribution suggests DPRK-aligned actors continue investing in open-source supply chain tradecraft.

Infosecurity Magazine · 26d agoThreat actor in the wild

CaptiveCrunch: Midnight Blizzard Weaponizes Hotel Wi-Fi Captive Portals to Steal Microsoft 365 Credentials

Zscaler details CaptiveCrunch: Midnight Blizzard's Storm-2945 compromises hotel Wi-Fi captive portals to redirect guests and harvest Microsoft 365 credentials via device code phishing.

Zscaler ThreatLabz analyzed the CaptiveCrunch credential theft campaign first reported by Microsoft on July 31. Microsoft attributes the activity to Storm-2945, a sub-cluster of Russia-linked Midnight Blizzard (APT29, Cozy Bear, NOBELIUM, BlueBravo). The actor manipulates DNS and HTTP traffic on captive portal networks at hotels and conference centers, redirecting victims to attacker-controlled infrastructure for Microsoft 365 credential harvesting, device code phishing, and malware delivery. Evidence indicates shared captive portal services were compromised rather than each venue being breached individually.

Zscaler ThreatLabz · Aug 11, 2026Threat actor in the wild

Cisco Warns of Seven ClamAV Flaws, Two With Public PoCs

Cisco warns of seven ClamAV denial-of-service flaws in Secure Endpoint Connector, two with public PoCs; patches due in August.

Cisco warned that seven ClamAV denial-of-service vulnerabilities, tracked as CVE-2026-20337 through CVE-2026-20339 and CVE-2026-20345 through CVE-2026-20348, affect the Secure Endpoint Connector on Windows, macOS and Linux. Two flaws, CVE-2026-20337 (CVSS 7.5, out-of-bounds write) and CVE-2026-20338 (memory double-free), have public proof-of-concept code, but Cisco PSIRT reports no evidence of malicious exploitation. Fixes shipped in ClamAV 1.5.4, with Cisco patches due in August and no workaround available. Windows is rated high risk because ClamAV runs with elevated privileges there.

Threat Bulletin

Palo Alto Networks Unit 42 published a threat bulletin, but no article body was available for detailed analysis.

The feed item contained only the title 'threat bulletin' with no article text. No specific incidents, actors, or vulnerabilities could be extracted from the available content.

Palo Alto Unit 42 · 20d agoAdvisory

Cl0p Targets 40+ Organizations Through PTC Windchill Flaw

Cl0p claims over 40 organizations including Shell and Philips were breached by exploiting critical RCE CVE-2026-12569 in PTC Windchill and FlexPLM.

Cl0p claims more than 40 organizations were victimized via CVE-2026-12569 (CVSS 9.3), a critical deserialization-based remote code execution flaw in PTC Windchill PDMlink and FlexPLM, affecting releases prior to 11.0 M030; CISA added the flaw to its KEV catalog in June. ReliaQuest found the group deployed a custom web shell that maps vault data, decrypts all credentials in the Windchill keystore, and includes a Java class loader enabling arbitrary code execution, lateral movement, persistence, and large-scale data exfiltration without extra tooling. Named victims include Shell, Philips, Fiserv, Zebra Technologies, Ingersoll Rand, Toast, Mindray, and Apple lens supplier Largan Precision, with stolen data ranging from one gigabyte to multiple terabytes per target. The campaign mirrors Cl0p's earlier mass-exploitation extortion operations against MOVEit, Cleo, GoAnywhere, and Oracle E-Business Suite.

Security Affairs · 26d agoRansomware in the wildCVE-2026-12569

Critical Langflow Vulnerability Exploited as Attacks on AI Platform Rise

Attacks exploiting CVE-2026-0768, a critical vulnerability in the Langflow low-code AI platform, are rising amid growing adversary attention this year.

CVE-2026-0768 is a critical vulnerability in Langflow, a low-code AI development platform, with exploitation attacks now rising. Dark Reading notes the platform has drawn increasing adversary attention in 2026. Organizations running exposed Langflow instances face elevated risk and should patch promptly and review instances for compromise.

Dark Reading · 15d agoExploit / PoC in the wildCVE-2026-07681

[Control Systems] Siemens security advisory (AV26-864)

Siemens fixed a vulnerability in Element maps-ng V47-V49 (SSA-682041); Canada's Cyber Centre urges administrators to apply the updated releases.

Siemens advisory SSA-682041 addresses a vulnerability affecting Element maps-ng V47 prior to V47.12.3, V48 prior to V48.11.3, and V49 prior to V49.16.1. Canada's Cyber Centre republished the notice (AV26-864) encouraging users and administrators to review the vendor links and apply the necessary updates. No CVSS score or exploitation details were provided in the bulletin.

Canadian Centre for Cyber Security · 16d agoAdvisory

Ransomware attackers are zeroing in on mid-market companies

Black Kite found mid-market firms were 73% of disclosed ransomware victims in North America and Europe from January 2023 to June 2026.

Black Kite analyzed 13,336 publicly disclosed ransomware and data-extortion incidents with known revenue between January 2023 and June 2026, finding mid-market companies (annual revenue $10M-$1B) accounted for 73% of victims in North America and Europe, consistently between 72% and 75%. Manufacturing was the most affected sector, followed by professional, scientific, and technical services and construction. Of more than 120,000 assessed mid-market organizations, 54.7% had at least one significant patch-management issue on a public-facing system, over a quarter had a known-exploited vulnerability, and nearly one-third had stealer-log credential findings.

Help Net Security · 24d agoRansomware

I Think the Military Commissary Freezers Were Hacked

Refrigeration failures at six-plus US military commissaries prompt speculation of a cyber attack on DeCA's remote monitoring systems; Pentagon acknowledges possible disruption.

The author documents near-simultaneous freezer and refrigeration failures at confirmed installations including Fort Huachuca, F.E. Warren AFB, Fort Irwin and Travis AFB on August 26-27, with freezers entering defrost mode that heated and spoiled food. DeCA's Remote Monitoring Control System controls defrost across roughly 182 locations, and an unverified comment attributed the Fort Huachuca failure to a network issue. Stars and Stripes and Military Times independently reported the multi-base failures, and the Pentagon acknowledged a 'possible refrigeration disruption,' though no evidence of hacking has been confirmed.

Lobsters · security · 13d agoData breach

A battery storage cyberattack would look exactly like a badly tuned controller

Risk modeling suggests a few hundred compromised grid-scale batteries dispatched through cloud optimizers could trigger blackouts in Texas or Great Britain.

Centrii analysis estimates 1,500 compromised one-megawatt units (5.4% of ERCOT's ~28 GW fleet) or 400 units (about 29% of Great Britain's ~1,400-unit fleet) could destabilize the grids, with modeled damage of $12-65 billion in Texas and a national blackout costing £2-10 billion in Britain. The study puts the probability of a major attack affecting at least one million people by 2031 at 92.1%, dropping to 61.4% with IEC 62443 certification and quarterly drills, based on 10,000 Monte Carlo runs. Because hostile battery swings are phased like legitimate frequency response, control rooms would see nothing unusual; Centrii proposes hunting for a reverse-governor signature where inverter output feeds oscillations. Spain's April 2025 blackout took an expert panel until March 2026 to rule out cyberattack, partly because key plants had no recordings.

Help Net Security · 15d agoResearch

Chaotic Eclipse Releases GenDigital Avast Antivirus ZeroDay PrettyPrague

Researcher Chaotic Eclipse released PrettyPrague, a PoC zero-day privilege escalation exploit against fully patched GenDigital Avast Antivirus.

Security researcher Chaotic Eclipse (also known as INFINITE NIGHTMARE or MSNightmare) published a PoC named PrettyPrague exploiting a zero-day privilege escalation flaw in Avast Antivirus. The PoC abuses a flaw in the Avast Sandbox to dump the Windows SAM database and spawn a SYSTEM-level shell, reportedly working on fully patched Avast and patched Windows 11 25H2. The researcher believes the flaw may also affect other GenDigital products such as AVG and Norton. It follows his recent HardBreacher PoC for a Kaspersky Endpoint Security privilege escalation flaw.

Security Affairs · 15d agoExploit / PoC