ZeroHour

Search: “eavesdropping”

150 stories

Armored Likho expands its cyber-espionage toolkit

Kaspersky reports the Armored Likho espionage group now delivers its new Still Toolkit via fundraising-themed lures to steal Telegram data and eavesdrop on victims.

Kaspersky researchers describe a new campaign by the Armored Likho espionage actor. The campaign masquerades as fundraising efforts and delivers a newly developed Still Toolkit designed to steal Telegram data and eavesdrop on victims. The update expands the group's toolkit and continues its espionage-focused targeting.

Kaspersky Securelist · Aug 13, 2026Threat actor in the wild

In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review

SecurityWeek weekly roundup covers exploited WordPress Super Forms flaw CVE-2026-14894, a $10M bounty on an Iranian cyber official, InjectEave attacks, and more.

SecurityWeek's weekly roundup aggregates short items across the threat landscape, including Microsoft's report of invisible Unicode tag characters used in financial phishing lures at up to 2.37 million messages per day, and active exploitation of critical WordPress Super Forms plugin flaw CVE-2026-14894 to deploy PHP webshells. Policy items include a $10 million US bounty for IRGC-CEC Cyber Operations Command lead Amir Yaryab, a 16-month prison sentence for ex-AT&T employee Kenneth Carter over SIM swaps with nearly $600,000 in intended losses, and the US arraignment of Russian Sergei Anatolyevich Filimonov over credential harvesting. Technical items include InjectEave electromagnetic side-channel attacks tested on 11 devices, an FBI warning on OAuth consent phishing, and VulnCheck's finding that only 202 of 26,153 Anthropic Project Glasswing findings were fixed.

SecurityWeek · 4d agoIndustry in the wildCVE-2026-148942