In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review
SecurityWeek weekly roundup covers exploited WordPress Super Forms flaw CVE-2026-14894, a $10M bounty on an Iranian cyber official, InjectEave attacks, and more.
SecurityWeek's weekly roundup aggregates short items across the threat landscape, including Microsoft's report of invisible Unicode tag characters used in financial phishing lures at up to 2.37 million messages per day, and active exploitation of critical WordPress Super Forms plugin flaw CVE-2026-14894 to deploy PHP webshells. Policy items include a $10 million US bounty for IRGC-CEC Cyber Operations Command lead Amir Yaryab, a 16-month prison sentence for ex-AT&T employee Kenneth Carter over SIM swaps with nearly $600,000 in intended losses, and the US arraignment of Russian Sergei Anatolyevich Filimonov over credential harvesting. Technical items include InjectEave electromagnetic side-channel attacks tested on 11 devices, an FBI warning on OAuth consent phishing, and VulnCheck's finding that only 202 of 26,153 Anthropic Project Glasswing findings were fixed.
All-Line Equipment Company Fuel-Boss
CISA warns All-Line Equipment Fuel-Boss product versions contain flaws enabling remote command or code execution; fixes are available for some variants only.
CISA published ICS advisory ICSA-26-239-02 covering vulnerabilities in All-Line Equipment Company Fuel-Boss products, including the V1 Standard, V1 Portal, V1 Master/Slave, and V1 Backflush. Successful exploitation could allow attackers to execute arbitrary commands or code remotely on affected systems. Vendor fixes are available for Fuel-Boss V1 Standard and V1 Portal, fixes are not yet available for V1 Master/Slave, and no fix is planned for V1 Backflush. Customers are directed to contact All-Line Equipment Company for remediation instructions.
A $25 template helped scammers build hundreds of phantom bank domains
Allure Security researchers found 838 live phantom bank sites sharing a $25 template, built to lend credibility to investment and romance scams.
Allure Security researchers discovered roughly 2,200 domains presenting invented banks, of which 1,095 returned working pages and 838 contained a shared phrase. 97% of those retained parts of the $25 Cuex front-end template and 94% ran Laravel, with a misspelled 'Curreny Charts' heading on 90% of sites. The sites presented login pages, session cookies, and anti-forgery tokens consistent with a fraud model where scam contacts direct victims to fake financial portals. A leftover 'Remedy bank' title and form submission to remedycodes[.]site linked some sites to already-flagged fraud infrastructure.
Attackers impersonate popular AI brands to spread malware
Sophos documented 38 MDR cases where attackers impersonated AI brands like Claude and Perplexity to deliver infostealers and backdoors.
Sophos X-Ops analyzed 12 months of MDR cases and confirmed 38 incidents involving AI. Software impersonation accounted for 30 cases, with Claude impersonated in 26; fake installers used an 'InstallFix' technique delivering mshta commands, in-memory payloads, and process hollowing. Malicious browser extensions posing as AI assistants, including a fake Perplexity extension with 10,000 installs, acted as infostealers. In one case, attackers used a Claude coding agent to develop a Rust remote access trojan communicating over Slack after an SQL injection compromise.
TuxBot v3: Inside an IoT Botnet Framework With LLM
Unit 42 uncovers TuxBot v3, an LLM-assisted IoT botnet framework with 17-architecture builds, Telnet brute-forcing, and DDoS capabilities.
Palo Alto Unit 42 identified TuxBot v3 Evolution, a modular IoT botnet framework derived from AISURU, Wuhan-lineage botnets, and MHDDoS. The C-based bot brute-forces Telnet with 1,496 credential pairs, targets over 30 IoT device families, and communicates with a Go-based C2 over encrypted TCP with multiple fallback mechanisms including DGA, P2P, and DNS TXT. LLM-assisted development left hallucinated crypto implementations and broken exploit modules in the analyzed samples, though roughly 70% of core functionality works. Researchers warn polished production builds likely exist, raising the threat potential.
Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies
Fortinet researchers documented Evooo1Bot, a new Mirai-derived Linux botnet active since July 2026 that exploits known edge-device flaws to build SOCKS5 proxy networks.
Fortinet FortiGuard Labs identified Evooo1Bot, a previously undocumented Linux botnet built on the leaked Mirai source code, active in the wild since July 2026 and targeting internet-facing edge devices. It exploits numerous known CVEs in routers and devices from D-Link, Tenda, Telesquare, Zyxel, Hikvision, Atlassian Confluence, WSO2, TP-Link, NETGEAR, and others, delivering a bot binary via a wget.sh loader from 91.92.40.118 that clears bash history. The bot offers encrypted C2 on port 443, SSH brute-force scanning, credential sniffing, DDoS over DNS/TCP/UDP, an HTTP exploit dispatcher, and converts infected hosts into SOCKS5 proxies for anonymizing follow-on operations.