TeamViewer security advisory (AV26-852)
Canada's Cyber Centre warns that multiple TeamViewer client products are affected by vulnerabilities, urging users to update to 15.64.7 or later.
Advisory AV26-852, dated August 26, 2026, reports vulnerabilities in TeamViewer Full Client, Host, and QuickSupport across multiple versions and platforms, and in Portable prior to 15.64.7. The Canadian Centre for Cyber Security encourages users and administrators to apply the necessary updates, referencing TeamViewer security bulletins TV-2026-1008 and TV-2026-1009. No exploitation details are provided in the advisory.
Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands
US DoJ charged extradited Russian Searzhudin Aktulaev for a 2016-2017 Excel macro campaign infecting ~80,000 freelance platform users with TVRAT and DarkVNC.
Searzhudin Tamirlanovich Aktulaev, 40, was arrested in Cyprus in May 2025 and extradited to the US on August 28, facing charges including wire fraud conspiracy and aggravated identity theft. The indictment alleges ~255 fake freelance-platform accounts were used to send Excel macro attachments to about 80,000 users in 2016-2017, deploying TVRAT (TeamSpy/TVSPY) and DarkVNC RATs for remote access and data theft. Thousands of infected machines called back to a US-hosted C2 domain, with stolen credentials and PII stored in the shared email account used in the scheme.
Risks in IoT Supply Chain
Unit 42 analyzes multilayer IoT supply chain risks across hardware, firmware, and software, citing counterfeit Cisco switches and OpenWrt attacks.
Unit 42 examines weaknesses in the IoT supply chain ecosystem across hardware, firmware, operation, and vulnerability layers, noting that 89% of IT decision-makers reported IoT device growth and IDC forecast 41.6 billion connected IoT devices by 2025. Examples include counterfeit Cisco Catalyst 2960-X switches with possible backdoor access (F-Secure, July 2020), a March 2020 OpenWrt flaw enabling malicious update impersonation, and threat actor interest in TeamViewer remote support software. The report stresses that untracked third-party components and missing device inventories make it hard to assess vulnerability impact across vendors.