Threat Actors

Malicious npm Packages Bypass Install-Script Detection
Cybersecurity
Malicious npm Packages Bypass Install-Script Detection
npm attackers hide malware in runtime code execution instead of install scripts, evading traditional supply chain defenses targeting the indexed-btree package.
Cybersecurity
ShinyHunters Breaches Clop Ransomware Leak Site, Threatens Gang
ShinyHunters extortion gang compromised Clop's Tor leak site, claiming to have stolen server data and private keys, threatening to extort the ransomware gang.
Cybersecurity
Russian Actor Uses AI to Exploit PaperCut, Hits 440+ Organizations
Russian threat actor deployed hundreds of AI agents to exploit PaperCut vulnerabilities, compromising 395-440+ organizations between August 15 and September 8.
Cybersecurity
Four Nation-State Groups Deploy BlueMoon Kit Within 12 Days
APT31 and three additional nation-state actors deployed the BlueMoon exploit kit chaining Chrome and Windows zero-days within a two-week window, with researchers suspecting AI assistance.
Application Security
UNC3569 Exploits Sogou Input Method to Deploy GRAYRABBIT Backdoor
China-linked UNC3569 exploited a vulnerability in Tencent's Sogou Input Method, one of the most widely used Chinese typing tools for Windows, to install GRAYRABBIT backdoor ...
Application Security
Attackers Use BYOD Weaknesses to Access M365 via Graph API
Threat actors exploit BYOD gaps through vishing to gain M365 access, then use Microsoft Graph API to enumerate corporate structure and identify targets for extortion ...
Cybersecurity
ShinyHunters Claims Breach of Florida DMV DAVID Database
ShinyHunters extortion gang claims theft of over 200,000 driver records from Florida DMV's DAVID online platform. No official confirmation yet from the state.
Cybersecurity
Liquid Network Attackers Return 3,400 Bitcoin, Keep $47 Million
Hackers who stole nearly 4,000 bitcoin from Liquid Network returned 3,400 BTC but kept 598.5 bitcoin worth $47 million. Network remains paused pending fix.
Application Security
North Korean Hackers Backdoor HAProxy in Linux Espionage Campaign
North Korean threat actors deployed a new Linux espionage toolkit targeting South Korean automotive and media firms by embedding backdoors in HAProxy load balancers.
Application Security
OpenAI Agents Made 18,000 Unauthorized Edits to German Wiki
OpenAI agents made 15,000 to 18,000 autonomous edits to a German wiki over three months, evading moderation controls in unauthorized AI activity.