Security Affairs
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 108|Security Affairs newsletter Round 588 by Pierluigi Paganini – INTERNATIONAL EDITION|CISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota Attacks|Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens|Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic|South Korea Warns of State-Backed Watering Hole Attacks|Google AI Supercharges Chrome Security, Fixing 1,072 Bugs|What an LLM Can Find: A Practical, Cheap Path to Code-level Threat Discovery|Anthropic Finds Claude Breached Real Companies During Security Evaluations|SilverFox Targets Japanese Manufacturer With Advanced ValleyRAT Campaign|Researchers Expose Flying Eagle Criminal Ecosystem Behind Fake Chinese Police App|Why brand impersonation is becoming an initial access vector|SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 108|Security Affairs newsletter Round 588 by Pierluigi Paganini – INTERNATIONAL EDITION|CISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota Attacks|Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens|Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic|South Korea Warns of State-Backed Watering Hole Attacks|Google AI Supercharges Chrome Security, Fixing 1,072 Bugs|What an LLM Can Find: A Practical, Cheap Path to Code-level Threat Discovery|Anthropic Finds Claude Breached Real Companies During Security Evaluations|SilverFox Targets Japanese Manufacturer With Advanced ValleyRAT Campaign|Researchers Expose Flying Eagle Criminal Ecosystem Behind Fake Chinese Police App|Why brand impersonation is becoming an initial access vector|
Advertisement

Ad Placeholder

Full Width × 90

Breaking News

Security Affairs newsletter Round 588 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens Adobe fixed a maximum-severity vulnerability flaw in […]

newsletter

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including international press.

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens
Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic
South Korea Warns of State-Backed Watering Hole Attacks
Google AI Supercharges Chrome Security, Fixing 1,072 Bugs
What an LLM Can Find: A Practical, Cheap Path to Code-level Threat Discovery
Anthropic Finds Claude Breached Real Companies During Security Evaluations
SilverFox Targets Japanese Manufacturer With Advanced ValleyRAT Campaign
Researchers Expose Flying Eagle Criminal Ecosystem Behind Fake Chinese Police App
Why brand impersonation is becoming an initial access vector
Cybercriminals Are Leveraging Autonomous AI Offensive Security Agents
Analog Devices Discloses Data Breach After Unauthorized System Access
FCC Restricts New Foreign Robots and Inverters Over Security Risks
U.S. CISA adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog
eSIM Plus and Nicegram Share Belarus-Linked Codebase, Analysis Finds
Claude Mythos Shows AI Can Outpace Human Cryptography Research
Hackers Strike Minnesota Water Utilities, One Plant Briefly Offline
ShinyHunters Claims Ernst & Young Data Breach, Threatens to Leak Stolen Data
Broadcom Patches Critical VMware ESXi Vulnerability Enabling Host Code Execution
OpenAI AI Model Used JFrog Artifactory Zero-Day Before Hugging Face Breach
OpenAI’s Rogue AI Agent Breached Second Company, Report Says
VPN Breach Exposes 58 Million Connection Logs Despite “No-Logs” Claims
Dysphoria Botnet Uses Blockchain Domains to Hide C2 Infrastructure
JetBrains Patches Critical TeamCity Flaw Allowing Server Takeover
New Crypter-as-a-Service Cruciferra Fuels Stealthy Malware Attacks Worldwide
U.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog
Reuters: OpenAI Agent Hacked Hugging Face for Days Before Being Detected
MedusaHVNC Trojan Creates Hidden Desktops to Hijack Browsers and Steal Data
DentaQuest disclosed a data breach that impacted +23 million individuals
GitLab Users Urged to Patch After Research Reveals Critical RCE Chain
EFF: Most Smart Wearables Still Fall Short on Privacy and Transparency
LockBit5 and Qilin Lead Ransomware Attacks Against Italian Organizations
Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Credentials

International Press – Newsletter

Cybercrime

DentaQuest Data Breach Potentially Impacts Over 23 Million People  

Crime: Risk, Responsibility, and Accountability   

ShinyHunters Claims Ernst & Young Hack  

When AI Becomes the Attacker: Understanding Autonomous Offensive Security Agents  

US accuses American of allegedly wiping his phone using a ‘duress’ password during border search  

Hacker wipes European country’s entire land registry database, paralyzing real-estate market 

Malware

TAG-195 Upgrades MaaS Ecosystem with Modular Tools 

SourTrade: Browser-Assembled Malware Delivered Through Malvertising  

MedusaHVNC: A Hidden Desktop That Steals Live Windows Sessions  

Unpacking “Cruciferra”: An Analysis of a Sophisticated Crypter Service  

Hacking

Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident  

Investigating three real-world incidents in our cybersecurity evaluations  

Discovering cryptographic weaknesses with Claude

DNS Poisoning Tactics Expand to Hospitality Wi-Fi  

Going depthfirst: Achieving GitLab RCE via Two Ruby Memory Corruption Vulnerabilities  

The hacker who humiliated spyware makers and was never caught 

Millions of California-bought cars can be hijacked via Bluetooth 

Hacker Conversations: Tal Kollander’s Journey From Black Hat to Hack Blocker

eBPF Warfare: Subverting Security Solutions Through Kernel-Space Manipulation  

Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)

JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack

What Can an Attacker Find With an LLM?      

Intelligence and Information Warfare  

Inside a DPRK BlueNoroff ClickFix Kit  

MNIT activates statewide cybersecurity response to support affected communities and protect critical infrastructure   

Behind the Lithuanian Label: What’s Inside Nicegram and eSIM Plus 

Israel’s Palantir Rival Is Selling $1 Million Spy Vans To U.S. Cops  

Trump administration bans new Chinese humanoid robots, to protect US AI buildout

Cato CTRL™ Threat Research: SilverFox Evolves: Abuse of New Drivers and Trusted Software Hijacking Enable Remote Access with ValleyRAT in Japan  

Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon

ClickFix, EtherHiding & a DPRK Wallet Trail  

[Joint Cyber ​​Security Advisory] Operation Double Barrel (The Relationship Between State-Backed Hacking Organizations and the Gunra Ransomware Group)  

OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft  

CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs

Coordinated “cyberattack” on Minnesota water utilities: What you need to know      

Cybersecurity

OpenAI’s rogue agent compromised a customer at a second tech firm, executive says  

Most Smart Watches, Rings, and Bands Lack Basic Transparency Reports and Key Privacy Features      

Its AI agent spent days hacking a company, but sources say OpenAI did not notice for a week  

A “No-Logs” VPN That Kept 58 Million Connection Logs: Inside the NotVPN / SplitVPN Breach  

REPS LIEU AND MORAN INTRODUCE BILL TO REQUIRE KILL SWITCH FOR AI SYSTEMS THAT CAN CAUSE CATASTROPHIC HARM

The AI Sovereignty Paradox     

Stronger with every update: How we’re making Chrome and the web safer in the AI Era 

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)