Today

All security news captured in the last 24 hours. Items with source-backed analyst research are placed first and retained in the research archive.

17 stories · all new in the last 24h · updated

How to read this page
Signals — evidence found for a story
Confirmed exploited · CISA KEVExploitation confirmed in the wild (CISA KEV catalog)
EPSS 94%Predicted chance of exploitation in the next 30 days
2 PoCPublic proof-of-concept or exploit code exists
3 OSINTOSINT or dark-web chatter references the story
CVE-2026-XXXXXTracked vulnerability — links to the NVD entry
Story markers
reported on 08/07/26When the source first reported the story
Full ReportOpens the analyst's full research report
high confidenceHow well deep-dive claims are backed by sources
Entities named in deep-dives
Storm-2603Threat actor or group
WarlockMalware, ransomware or tooling
on-prem SharePointTargeted product, sector or population
Full research reports 5 source-backed items
Confirmed exploited · CISA KEV EPSS 100% 1 PoC? 1 OSINT CVE-2019-11510
Full Report
reported on 31/08/26

DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims

The U.S. Department of Justice corrected a press statement originally claiming several federal agencies were victims of Chinese state-sponsored hacking, revising the language to indicate those agencies were 'among the targets' of the threat actor QTFY. QTFY, also known as QT AND QTCYBER, is linked to Nanjing Xinjiuwei Network Technology Co. and assessed to conduct operations on behalf of China's Ministry of State Security. The group has been active since 2018 and operates QScan, a vulnerability scanning and exploitation platform, and QTRouter, an obfuscation network built on infected IoT devices and leased VPSs. The FBI disrupted three domains tied to these tools (qtproxy[.]xyz, qt-proxy[.]org, qt-team[.]com), and Lumen Black Lotus Labs documented QTFY's role in industrializing Operational Relay Box (ORB) botnet infrastructure for Chinese espionage. The scope of actual successful compromises versus failed intrusion attempts remains unresolved by the corrected statement.

Why it matters

The distinction between 'targeted' and 'compromised' has direct consequence for defenders assessing exposure: organizations previously listed as victims may not have suffered confirmed intrusions, but QTFY's ORB botnet and QScan platform represent an active, commercially-operated reconnaissance-and-exploitation-as-a-service model that lowers the barrier for broad Chinese espionage campaigns. Defenders should treat CVE-2019-11510 (Pulse Secure VPN) patching and IoT device inventory as immediate priorities given QTFY's known TTPs.

Full research report see the analyst’s trail →
★ Threat intelligence assessment medium confidence

Executive assessment

The durable event is the FBI's disruption of QTFY infrastructure and the Justice Department's subsequent correction: several agencies were targeted, but the public record does not establish that each was compromised. QScan and QTRouter provided reconnaissance and obscured routing through compromised devices, leased systems and commercial proxy services, creating a reusable capability for China-linked espionage operations. CVE-2019-11510 is relevant through an alleged 2019 attempt against NASA and remains operationally important because CISA confirms prior exploitation and public exploit code is readily available. Nothing reviewed demonstrates a fresh August 2026 exploitation wave for that CVE, and defenders should not convert historical exploitation evidence into a claim of current QTFY activity.

What happened

On 26 August 2026, the US Department of Justice and FBI announced court-authorised seizures of domains essential to QScan and QTRouter, tools allegedly operated by QTFY to support China-linked cyber-espionage activity. The Justice Department updated the release on 28 August to describe listed US agencies as targets rather than victims, correcting an implication that all had been compromised. Reporting published on 31 August highlighted the correction and an alleged 2019 QTFY attempt to access NASA through CVE-2019-11510.

Affected scope

The disrupted activity targeted US federal bodies and organisations across government, defence, academia, healthcare, telecommunications, energy, finance and critical infrastructure in the United States and abroad. CVE-2019-11510 affects Pulse Connect Secure 8.2 before 8.2R12.1, 8.3 before 8.3R7.1 and 9.0 before 9.0R3.4; these legacy branches should be treated as obsolete unless demonstrably patched and supported.

Technical assessment

The Justice Department says QScan identified and infected internet-connected devices, while QTRouter combined compromised Internet of Things devices, commercial proxies and leased virtual private servers to conceal the origin of intrusion traffic. Black Lotus Labs describes QScan primarily as a distributed reconnaissance framework and Fast Labyrinth/QTRouter as the routing and obfuscation layer, with observed transitions from scanning to probable exploitation. CVE-2019-11510 independently presents a serious initial-access risk because an unauthenticated remote party with HTTPS access to a vulnerable Pulse Connect Secure appliance can read arbitrary files, potentially exposing credentials or configuration material; public code lowers the barrier to abuse but does not prove current QTFY exploitation.

Recommended defensive actions

  1. inventory all Pulse Connect Secure appliances and verify that no affected legacy release remains exposed or unsupported
  2. patch affected appliances to at least 8.2R12.1, 8.3R7.1 or 9.0R3.4, or migrate to a currently supported platform
  3. reset credentials and revoke active sessions where an appliance may have remained vulnerable, particularly if internet-exposed during or after 2019
  4. hunt historical VPN, DNS and network-flow records for unexplained file-access requests, suspicious credential use and the QTFY indicators published by the FBI, NSA and Black Lotus Labs
  5. monitor internet-facing management and remote-access services for reconnaissance followed by stable bidirectional sessions from residential, Internet of Things or commercial-proxy addresses
  6. segment and update routers and Internet of Things devices so compromise of an edge device cannot provide trusted local access to sensitive networks

Uncertainties and evidence gaps

  • The corrected Justice Department wording establishes targeting, not successful compromise, for each named US agency.
  • The precise number and identity of organisations successfully compromised by QTFY remain undisclosed.
  • The alleged CVE-2019-11510 activity against NASA dates to 2019; the available reporting does not establish current exploitation of that vulnerability by QTFY in August 2026.
  • The Justice Department and Black Lotus Labs emphasise somewhat different QScan roles—automated device infection versus reconnaissance—leaving the division of capabilities and customer activity incompletely resolved.
  • Domain seizure should disrupt the hard-coded infrastructure described by the Justice Department, but it does not establish that every QTFY capability, customer or previously compromised device has been neutralised.

Vulnerability flow

Defender-oriented path reconstructed only from sourced report findings. Unknown stages are omitted.

AccessUnauthenticated network access to the HTTPS interface of an internet-reachable, vulnerable Pulse Connect Secure appliance.
ComponentPulse Connect Secure web interface and the boundary protecting files stored on the appliance.
MechanismImproper path handling allows a specially formed web request to read files without authentication.
ImpactExposure of sensitive appliance files and potentially reusable credentials or configuration data, creating a route to broader network compromise.
DetectionReview appliance and perimeter logs for anomalous file-access requests, subsequent unexpected authentications, new sessions using exposed accounts and suspicious traffic from residential or commercial-proxy infrastructure.
MitigationApply Pulse Connect Secure 8.2R12.1, 8.3R7.1 or 9.0R3.4 as applicable; preferably migrate legacy appliances to a currently supported release, then rotate potentially exposed credentials and invalidate sessions.
Exploitation status

No confirmed current active exploitation is established by this correction; a 2019 QTFY attempt against NASA allegedly used CVE-2019-11510, the vulnerability has previously been exploited in the wild, and public exploit code exists.

The investigation first separated the August 2026 correction from the broader QTFY disruption and from the historical Pulse Connect Secure vulnerability. The corrected Justice Department release confirms that named agencies were targets, while Black Lotus Labs independently supports the wider reconnaissance and obfuscation campaign. NVD, CISA and original vulnerability research confirm CVE-2019-11510's technical scope, prior exploitation and public exploit availability, but they do not demonstrate a new 2026 exploitation wave.

  1. What claim was corrected, and which historical vulnerability was associated with the story?
    Read the supplied report and followed its cited primary and independent references.
    thehackernews.com ↗

    The report says the Justice Department changed named agencies from victims to targets and alleges that QTFY attempted to access NASA through CVE-2019-11510 in 2019.

    why This framed the event as a correction to compromise claims, not a newly disclosed CVE campaign.

  2. What does the corrected government record actually allege?
    Read the updated Justice Department announcement and its revision note.
    justice.gov ↗

    The release identifies the agencies as QTFY targets, attributes QScan and QTRouter to QTFY, says seized hard-coded domains made the tools inoperable and records an update on 28 August 2026.

    why This is the strongest evidence for both the corrected wording and the scope of the disruption.

  3. Is there independent technical corroboration of the QTFY campaign and its target scope?
    Reviewed Black Lotus Labs' research into the quartermaster infrastructure.
    lumen.com ↗

    Researchers observed distributed reconnaissance, commercial-proxy and relay infrastructure, probable exploitation sessions and targeting of government, defence, research, healthcare, energy and financial networks.

    why This independently corroborates the infrastructure and sector targeting while distinguishing reconnaissance from confirmed compromise.

  4. What products and versions are affected by CVE-2019-11510?
    Read the National Vulnerability Database record.

    Pulse Connect Secure 8.2 before 8.2R12.1, 8.3 before 8.3R7.1 and 9.0 before 9.0R3.4 allow unauthenticated arbitrary file reading through a specially crafted URI.

    why This established the defensible technical scope and minimum historical fixed versions without inferring a broader exploit chain.

  5. Has CVE-2019-11510 been exploited in the wild independently of the QTFY allegation?
    Filtered and reviewed the CISA Known Exploited Vulnerabilities catalogue entry.

    CISA lists the vulnerability as known exploited, records known ransomware use and directs organisations to apply vendor updates.

    why This confirms historical exploitation risk but does not establish current QTFY use or exploitation against every named target.

  6. Is technical disclosure or public exploit material available?
    Reviewed the original DEVCORE vulnerability research.
    devco.re ↗

    DEVCORE documents the vulnerability, reports patches released on 24 April 2019 and states that third parties subsequently published exploit implementations.

    why This confirmed that exploitation knowledge has been public for years and that proof-of-concept availability is not evidence of a new campaign.

  7. Does a cited public exploit repository still exist?
    Opened the CVE-2019-11510 repository linked by the original researchers.
    github.com ↗

    The public repository remains available and identifies itself as an arbitrary file-read exploit for Pulse Secure SSL VPN.

    why This directly verifies public exploit-code availability without relying on a search-result description.

  8. Does the supplied community record add evidence of current actor activity?
    Read the referenced community-maintained CVE index.
    raw.githubusercontent.com ↗

    The record lists CVE-2019-11510 and points to the same public repository but contains no time-bounded QTFY discussion or evidence of current exploitation.

    why It corroborates public code availability only and should not be treated as proof of active campaign activity.

  9. What additional campaign context was reported around the original disruption announcement?
    Reviewed the earlier detailed report on the FBI disruption.
    thehackernews.com ↗

    The report describes QTFY's alleged customers, QScan and QTRouter infrastructure, broad vulnerability-led targeting and persistence activity, while preserving the distinction between scanning, exploitation and compromise.

    why This supplied context for the broader campaign but remained secondary to the corrected Justice Department record and independent Lumen research.

ActorsQTFY (also reported as QT and QTCYBER)Nanjing Xinjiuwei Network Technology CompanyPeople's Republic of China Ministry of State SecurityPeople's Liberation Army
MalwareQScanQTRouter
TargetsNASAFederal ReserveDepartment of EnergyDepartment of JusticeDepartment of Health and Human ServicesNational Institutes of HealthU.S. Senategovernment and defence networksresearch universitieshealthcare organisationstelecommunications providersenergy and critical-infrastructure organisationsfinancial institutionsdefence contractors
Related CVEs CVE-2019-11510

Research coverage

All 73 registered source leaves were evaluated for this run: 63 completed, 0 were unavailable, 3 failed and 7 were disabled. For this story, 18 registered sources supplied useful evidence (2 primary, 14 corroborating, 2 contextual and 0 PoC/exploit references). 45 completed sources contained no matched information for this story.

Primary evidence Independent corroboration Operational context PoC reference Checked — no match Unavailable Failed Disabled
Complete source-by-source audit 73 sources
SourceRun resultValueWhy it was useful — or not
CISA KEVkev ok1687 records Primary evidence1 matched items Confirmed that a related CVE is listed in CISA's Known Exploited Vulnerabilities catalogue.
The Hacker Newsnews ok7 records Primary evidence1 matched items Published the source report used to frame and date the event.
CISA Alertsnews ok empty0 records Corroborating1 matched items A page from this source was opened and verified during focused research.
deepdarkCTI Discorddeepdarkcti ok7 records Corroborating1 matched items A page from this source was opened and verified during focused research.
deepdarkCTI exploitsdeepdarkcti ok24 records Corroborating1 matched items A page from this source was opened and verified during focused research.
deepdarkCTI forumsdeepdarkcti ok264 records Corroborating1 matched items A page from this source was opened and verified during focused research.
deepdarkCTI malware as a servicedeepdarkcti ok7 records Corroborating1 matched items A page from this source was opened and verified during focused research.
deepdarkCTI malware samplesdeepdarkcti ok3 records Corroborating1 matched items A page from this source was opened and verified during focused research.
deepdarkCTI marketsdeepdarkcti ok127 records Corroborating1 matched items A page from this source was opened and verified during focused research.
deepdarkCTI phishingdeepdarkcti ok19 records Corroborating1 matched items A page from this source was opened and verified during focused research.
deepdarkCTI ransomware gangsdeepdarkcti ok689 records Corroborating1 matched items A page from this source was opened and verified during focused research.
deepdarkCTI RATsdeepdarkcti ok1 records Corroborating1 matched items A page from this source was opened and verified during focused research.
deepdarkCTI Telegram infostealerdeepdarkcti ok130 records Corroborating1 matched items A page from this source was opened and verified during focused research.
deepdarkCTI Telegram threat actorsdeepdarkcti ok1013 records Corroborating1 matched items A page from this source was opened and verified during focused research.
deepdarkCTI Twitter threat actorsdeepdarkcti ok39 records Corroborating1 matched items A page from this source was opened and verified during focused research.
NVDcve ok900 records Corroborating1 matched items A page from this source was opened and verified during focused research.
deepdarkCTI CVE most exploiteddeepdarkcti ok94 records Context2 matched items Provided lower-confidence OSINT context matched to an explicit CVE. Supplied OSINT or actor context opened and verified during focused research.
FIRST EPSSepss ok8075 records Context1 matched items Added exploitation-probability context; EPSS does not itself prove exploitation.
AlienVault OTXdark_web failed0 records Failed The current collection attempt failed; this source cannot support the report.
BleepingComputernews ok10 records Checked — no match The source completed, but none of its retained records matched this story.
CERT-EU Threat Intelligencenews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
CIRCL CVEcve ok30 records Checked — no match The source completed, but none of its retained records matched this story.
Cisco PSIRTvendor_advisory ok5333 records Checked — no match The source completed, but none of its retained records matched this story.
Cisco Talosnews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Exploit-DBexploit_reference ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Fortinet PSIRTvendor_advisory disabled Disabled Disabled in the source registry; no check was attempted.
GitHub topic: cveresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
GitHub topic: exploitresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
GitHub topic: penetration-testingresearch failed0 records Failed The current collection attempt failed; this source cannot support the report.
GitHub topic: pocresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
GitHub topic: vulnerabilityresearch failed0 records Failed The current collection attempt failed; this source cannot support the report.
GreyNoiseexploit_reference ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
KrebsOnSecuritynews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
LinkedIn RSS proxy feeds (disabled)research disabled Disabled Disabled in the source registry; no check was attempted.
MalwareBazaardark_web ok9 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #cveresearch ok20 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #cybersecurityresearch ok17 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #exploitresearch ok20 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #infosecresearch ok20 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #malwareresearch ok20 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #ransomwareresearch ok19 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #threatintelresearch ok5 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #vulnerabilityresearch ok19 records Checked — no match The source completed, but none of its retained records matched this story.
Metasploit module metadataexploit_reference ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Microsoft MSRCvendor_advisory ok1591 records Checked — no match The source completed, but none of its retained records matched this story.
Microsoft Securitynews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
MISP Galaxyresearch ok3 records Checked — no match The source completed, but none of its retained records matched this story.
MISP threat actor galaxyactor ok0 records Checked — no match The source completed, but none of its retained records matched this story.
Palo Alto Networks PSIRTvendor_advisory ok25 records Checked — no match The source completed, but none of its retained records matched this story.
ProjectDiscovery nuclei templatesexploit_reference ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Rapid7news ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Reddit r/AskNetsec (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/cybersecurity (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/malware (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/netsec (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/ReverseEngineering (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
SANS ISCnews ok1 records Checked — no match The source completed, but none of its retained records matched this story.
SentinelLabsnews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Shadowserver public aggregate honeypot observationsexploit_reference ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Shodanresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Sigma Rulesresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Sophos IOCsresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Sophos X-Opsnews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
The DFIR Reportnews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
ThreatFoxthreat_intelligence ok100 records Checked — no match The source completed, but none of its retained records matched this story.
UK NCSCnews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Unit 42news ok1 records Checked — no match The source completed, but none of its retained records matched this story.
Unit42 IOCsresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
URLhausdark_web ok10 records Checked — no match The source completed, but none of its retained records matched this story.
VirusTotal Community IOC enrichmentresearch ok4 records Checked — no match The source completed, but none of its retained records matched this story.
VulnCheck KEVkev ok500 records Checked — no match The source completed, but none of its retained records matched this story.
Vulnerability Lookupcve ok30 records Checked — no match The source completed, but none of its retained records matched this story.
WeLiveSecuritynews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Additional verified pages 15 opened outside the registered collection
Vulnerability & exploitation2
CVE-2019-11510 CISA KEV Ivanti Pulse Connect Secure · added 2021-11-03 · used in ransomware CISA catalog ↗
CVE-2019-11510 EPSS 100.0% 100th percentile exploitation probability
Reporting-linked PoC claims1
https://github.com/projectzeroindia/CVE-2019-11510 github.com ↗

Linked by reporting but not validated as PoC by the configured exploit indexes.

OSINT / dark-web chatter1
deepdarkCTI: CVE-2019-11510 (Pulse) raw.githubusercontent.com ↗
PoC & exploit code2
Project Zero India CVE-2019-11510 exploit github.com ↗

Public shell-based proof-of-concept for the Pulse Connect Secure arbitrary file-read vulnerability.

DEVCORE: The Golden Pulse Secure SSL VPN RCE Chain devco.re ↗

Original researchers describe CVE-2019-11510, affected releases, disclosure dates and the subsequent publication of exploit code.

Vendor & gov advisories2
Justice Department and FBI seize QTFY platforms justice.gov ↗

Primary announcement of the domain seizures, corrected target wording and alleged relationship between QTFY, QScan and QTRouter.

FBI and NSA cybersecurity advisory on QTFY ic3.gov ↗

Government advisory linked by the Justice Department as providing indicators associated with QTFY activity since at least 2018.

OSINT / dark-web chatter1
deepdarkCTI most-exploited CVE index raw.githubusercontent.com ↗

Community-maintained index lists CVE-2019-11510 and links the public exploit repository, but provides no independent evidence of current QTFY activity.

Analysis & research3
DoJ corrects China hacking claim thehackernews.com ↗

Reports that the affected agencies were targets rather than confirmed victims and links the alleged 2019 NASA attempt to CVE-2019-11510.

Black Lotus Labs: The infrastructure quartermaster lumen.com ↗

Independent research describes QTFY's reconnaissance and obfuscation infrastructure, target sectors, defensive guidance and indicators.

FBI disrupts China-linked QTFY infrastructure thehackernews.com ↗

Provides additional reporting on QTFY infrastructure, customers, target sectors and vulnerability-led access activity.

Full Report
reported on 31/08/26

ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions

The threat actor tracked as Silver Fox has been observed distributing the ValleyRAT backdoor (also known as Winos 4.0) by embedding it inside a trojanized copy of QN Wallpaper, a legitimate signed Chinese adware application. The attack leverages DLL sideloading: the installer places a malicious libcef.dll alongside the signed QnWallpaper.exe, which loads the malicious library under a trusted process identity. Before activating its adware component, the malware disables Windows Defender via the DisableAntiSpyware registry key, adds itself to autorun, and escalates privileges via runas if the current user is unprivileged. Once installed, ValleyRAT grants operators full remote control including keylogging, clipboard capture, screenshot collection, and delivery of additional malicious modules, and it can flag its own process as critical to trigger a blue screen of death if termination is attempted. Kaspersky published the analysis on August 31, 2026, attributing the campaign to Silver Fox based on geography, payload, and overlap with prior campaigns including a recent attack against a Japanese manufacturer and earlier tax-themed campaigns targeting organizations in India and Russia.

Why it matters

This campaign demonstrates how users who add adware or borderline-legitimate software to antivirus exclusions inadvertently strip away their last line of detection against sophisticated backdoors running under signed process identities. Defenders should treat any signed application in an exclusion list as a potential sideloading vehicle and enforce strict allow-listing and DLL integrity controls regardless of code-signing status.

Full research report see the analyst’s trail →
★ Threat intelligence assessment high confidence

Executive assessment

Silver Fox has operationalised the intersection of two user behaviours—installing low-reputation adware and adding it to antivirus exclusions—to create a reliable, low-noise delivery path for ValleyRAT that sidesteps endpoint controls without requiring any software vulnerability. The technique itself is not new: Nextron Systems documented Silver Fox DLL sideloading via signed executables in November 2025, and Cato Networks confirmed the group was still abusing legitimate applications in July 2026 against a Japanese manufacturer, though with a different DLL. What distinguishes this campaign is the deliberate selection of adware as the host application, exploiting the institutional tolerance users and IT teams extend to adware that was already present and excluded before compromise occurred. ValleyRAT's ability to mark its own process as critical—turning any termination attempt into a system crash—significantly complicates live incident response and means that safe-mode or offline remediation is the realistic path once the implant is established. The Kaspersky report rests on a single submitted sample, so while the technical evidence is solid, the true geographic and organisational spread of this specific installer remains an open question.

What happened

Silver Fox, a China-nexus threat actor active since at least 2022, was observed distributing the ValleyRAT backdoor hidden inside a modified installer of QN Wallpaper, a signed Chinese adware application. Kaspersky identified the campaign from a single customer-submitted sample and published its analysis on 31 August 2026. The campaign exploits user behaviour: adware is frequently tolerated and added to antivirus exclusions, granting the malicious DLL an unmonitored execution environment inside a trusted signed process. Over 100,000 ValleyRAT detections affecting more than 1,500 unique users were recorded across 2026 in China and India, though that figure encompasses the broader ValleyRAT campaign rather than this installer specifically.

Affected scope

Windows users who install QN Wallpaper or similarly signed adware, particularly those who add such software to antivirus exclusions; geographic focus is China and India; no specific sector targeting confirmed in this campaign, contrasting with Silver Fox's prior focus on healthcare, industrial manufacturing, and financial-themed lures

Technical assessment

The installer deploys a modified QN Wallpaper package and plants a malicious libcef.dll alongside the legitimately signed QnWallpaper.exe. Windows DLL search-order behaviour loads the local library before any system-path equivalent, executing ValleyRAT within the signed process's security context and bypassing signature-based trust controls. Before launching the application, the installer disables Windows Defender via the DisableAntiSpyware registry key and establishes autorun persistence; when the active session lacks administrator rights, the malware re-invokes itself via runas to elevate. ValleyRAT subsequently injects into svchost.exe for persistence, marks its own process as critical—forcing a Blue Screen of Death on termination attempts—and establishes command-and-control communications over non-standard ports, complicating incident response once the implant is resident.

Recommended defensive actions

  1. Block outbound connections to 103.45.66.18 (ports 441, 442, 443) and 192.253.225.173 (ports 6666, 8888) at perimeter firewall and endpoint security controls
  2. Hunt across endpoint telemetry for the three known MD5 hashes: c24e99f9437feacaa63766a3cde3fe3d (installer), 07ddbbe2c71c45577a7a4fbcdba0df91 (malicious libcef.dll), and 8a626d844943da3456b044f38deae3a2
  3. Audit all antivirus and EDR exclusion lists and remove entries for adware, wallpaper utilities, or any software from unverified or low-reputation publishers
  4. Hunt for the DisableAntiSpyware registry value and the install directory C:\Program Files\QNWallpaper\5.4.0.1662\ as indicators of compromise
  5. Enforce application allowlisting or software installation controls to prevent unvetted installers from executing, particularly in environments where users may install consumer-grade utilities

Uncertainties and evidence gaps

  • The Kaspersky report rests on a single customer-submitted sample; independent evidence of wider campaign scale is not available, meaning victim count and distribution method breadth are unverified
  • The 100,000-detection and 1,500-user figures cover ValleyRAT and associated malware broadly across 2026, not specifically this QN Wallpaper installer
  • The claim that libcef.dll featured in a 2025 ValleyRAT loader is asserted in secondary reporting but no primary source was found to verify the specific 2025 sample lineage; Nextron Systems' November 2025 report used a different DLL
  • Silver Fox attribution rests on geography and payload characteristics identified by Kaspersky; no government body or independent threat-intelligence firm has formally corroborated the attribution for this specific campaign

Vulnerability flow

Defender-oriented path reconstructed only from sourced report findings. Unknown stages are omitted.

AccessUser-initiated installation of what appears to be a legitimate signed adware application, compounded when the user has previously added the software to antivirus exclusions
ComponentWindows DLL search-order and signed-executable trust model within the QN Wallpaper application directory
MechanismMalicious libcef.dll placed in the installation directory is loaded automatically by the signed QnWallpaper.exe before any system-path equivalent, executing within the signed process's security context without triggering signature-based controls
ImpactFull backdoor access enabling keylogging, clipboard and screenshot theft, persistent code injection into svchost.exe, and loading of additional attacker-controlled modules; Windows Defender disabled prior to execution
DetectionDisableAntiSpyware registry value set at installation time; unexpected libcef.dll in C:\Program Files\QNWallpaper\5.4.0.1662\; outbound connections from QnWallpaper.exe or svchost.exe to 103.45.66.18 or 192.253.225.173; critical-process flag on non-system processes causing BSOD on termination
MitigationRemove QN Wallpaper installations matching the known install path; block C2 IPs at perimeter; restore Windows Defender configuration via registry; hunt and remediate using published IoCs
Exploitation status

No CVE exploitation involved; Silver Fox is actively delivering ValleyRAT via a trojanised QN Wallpaper adware installer confirmed by Kaspersky analysis of an in-the-wild sample published 31 August 2026; a separate Silver Fox BYOVD campaign against a Japanese manufacturer in July 2026 exploited CVE-2023-52271, but that is a distinct operation.

The investigation began from the claim that Silver Fox was abusing signed adware to deliver ValleyRAT through DLL sideloading. The primary Kaspersky Securelist advisory was fetched and confirmed the infection chain, IoCs, and attribution. Parallel searches identified the Cato Networks July 2026 report on a separate Silver Fox campaign, which independently corroborated the group's established pattern of abusing legitimate signed executables and documented CVE-2023-52271 in a distinct BYOVD chain. The Nextron Systems November 2025 report was fetched to test the claim that libcef.dll appeared in a prior loader, but that campaign used a different DLL, leaving the specific lineage assertion unverified against a primary source. Multiple independent outlets corroborated the Kaspersky findings without contradiction, supporting a high-confidence assessment on the event itself, with a material uncertainty around campaign scale.

  1. Which primary source covers this specific campaign?
    Searched for ValleyRAT Silver Fox QN Wallpaper DLL sideloading Kaspersky 2026

    Kaspersky Securelist published the originating vendor analysis at securelist.com/valleyrat-backdoor-adware/121175/

    why Locating the primary vendor report establishes the evidentiary baseline before assessing secondary coverage

  2. What does the Kaspersky report actually state about the infection chain, IoCs, and scope?
    Fetched the Kaspersky Securelist report
    securelist.com ↗

    Confirmed: libcef.dll sideloaded via signed QnWallpaper.exe; three MD5 hashes and two C2 IPs documented; Windows Defender disabled via DisableAntiSpyware; ValleyRAT injected into svchost; Silver Fox attribution based on geography and payload; 100,000+ detections in 2026 across 1,500+ users (note: broader campaign metric)

    why Primary source verification; all IoCs and technical claims anchored here

  3. Does The Hacker News reporting reference any independent sources that should be verified?
    Fetched the THN article
    thehackernews.com ↗

    Confirmed Kaspersky findings; identified Cato Networks as having documented Silver Fox DLL sideloading five weeks prior against a Japanese manufacturer; asserted libcef.dll appeared in a 2025 loader without citing a specific report

    why Surfaced Cato Networks as an independent corroborating source; flagged the 2025 libcef.dll claim as requiring primary-source verification

  4. What did Cato Networks actually document about Silver Fox DLL sideloading in July 2026?
    Searched for Cato Networks Silver Fox blog and fetched the report
    catonetworks.com ↗

    Cato documented a campaign against a Japanese manufacturer using PDFCORE8.dll sideloaded via Zeon Corporation PDF tools, not libcef.dll; CVE-2023-52271 exploited in a three-driver BYOVD chain; confirms Silver Fox pattern of abusing signed legitimate executables

    why Provides independent corroboration of Silver Fox tradecraft from a different vendor; clarifies the libcef.dll claim in THN applies to earlier campaigns, not specifically the Cato July report

  5. Does the Nextron Systems 2025 report confirm prior libcef.dll usage by Silver Fox?
    Fetched the Nextron Systems November 2025 report
    nextron-systems.com ↗

    Nextron's campaign uses log.dll sideloaded via NtHandleCallback.exe, not libcef.dll; confirms Silver Fox DLL sideloading via signed executables was active by November 2025 but does not verify the specific libcef.dll lineage

    why Establishes a material uncertainty: the 2025 libcef.dll claim remains unverified against a primary source in available evidence

  6. Does Security Affairs provide independent corroboration of Kaspersky's findings?
    Fetched the Security Affairs article
    securityaffairs.com ↗

    Security Affairs confirms the same IoCs, campaign scope, and Silver Fox attribution; adds context from the Cato July 2026 report confirming the group's documented DLL sideloading evolution; no contradictions found

    why Second independent domain corroborating Kaspersky findings; strengthens confidence in attribution and technical detail

ActorsSilver FoxUTG-Q-1000Void ArachneSwimSnake
MalwareValleyRATWinos 4.0
TargetsWindows users in China and Indiaorganisations whose users install adware from unverified sources

Research coverage

All 73 registered source leaves were evaluated for this run: 63 completed, 0 were unavailable, 3 failed and 7 were disabled. For this story, 1 registered sources supplied useful evidence (1 primary, 0 corroborating, 0 contextual and 0 PoC/exploit references). 62 completed sources contained no matched information for this story.

Primary evidence Independent corroboration Operational context PoC reference Checked — no match Unavailable Failed Disabled
Complete source-by-source audit 73 sources
SourceRun resultValueWhy it was useful — or not
The Hacker Newsnews ok7 records Primary evidence1 matched items Published the source report used to frame and date the event.
AlienVault OTXdark_web failed0 records Failed The current collection attempt failed; this source cannot support the report.
BleepingComputernews ok10 records Checked — no match The source completed, but none of its retained records matched this story.
CERT-EU Threat Intelligencenews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
CIRCL CVEcve ok30 records Checked — no match The source completed, but none of its retained records matched this story.
CISA Alertsnews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
CISA KEVkev ok1687 records Checked — no match The source completed, but none of its retained records matched this story.
Cisco PSIRTvendor_advisory ok5333 records Checked — no match The source completed, but none of its retained records matched this story.
Cisco Talosnews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
deepdarkCTI CVE most exploiteddeepdarkcti ok94 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI Discorddeepdarkcti ok7 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI exploitsdeepdarkcti ok24 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI forumsdeepdarkcti ok264 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI malware as a servicedeepdarkcti ok7 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI malware samplesdeepdarkcti ok3 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI marketsdeepdarkcti ok127 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI phishingdeepdarkcti ok19 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI ransomware gangsdeepdarkcti ok689 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI RATsdeepdarkcti ok1 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI Telegram infostealerdeepdarkcti ok130 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI Telegram threat actorsdeepdarkcti ok1013 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI Twitter threat actorsdeepdarkcti ok39 records Checked — no match The source completed, but none of its retained records matched this story.
Exploit-DBexploit_reference ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
FIRST EPSSepss ok8075 records Checked — no match The source completed, but none of its retained records matched this story.
Fortinet PSIRTvendor_advisory disabled Disabled Disabled in the source registry; no check was attempted.
GitHub topic: cveresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
GitHub topic: exploitresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
GitHub topic: penetration-testingresearch failed0 records Failed The current collection attempt failed; this source cannot support the report.
GitHub topic: pocresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
GitHub topic: vulnerabilityresearch failed0 records Failed The current collection attempt failed; this source cannot support the report.
GreyNoiseexploit_reference ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
KrebsOnSecuritynews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
LinkedIn RSS proxy feeds (disabled)research disabled Disabled Disabled in the source registry; no check was attempted.
MalwareBazaardark_web ok9 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #cveresearch ok20 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #cybersecurityresearch ok17 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #exploitresearch ok20 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #infosecresearch ok20 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #malwareresearch ok20 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #ransomwareresearch ok19 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #threatintelresearch ok5 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #vulnerabilityresearch ok19 records Checked — no match The source completed, but none of its retained records matched this story.
Metasploit module metadataexploit_reference ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Microsoft MSRCvendor_advisory ok1591 records Checked — no match The source completed, but none of its retained records matched this story.
Microsoft Securitynews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
MISP Galaxyresearch ok3 records Checked — no match The source completed, but none of its retained records matched this story.
MISP threat actor galaxyactor ok0 records Checked — no match The source completed, but none of its retained records matched this story.
NVDcve ok900 records Checked — no match The source completed, but none of its retained records matched this story.
Palo Alto Networks PSIRTvendor_advisory ok25 records Checked — no match The source completed, but none of its retained records matched this story.
ProjectDiscovery nuclei templatesexploit_reference ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Rapid7news ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Reddit r/AskNetsec (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/cybersecurity (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/malware (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/netsec (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/ReverseEngineering (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
SANS ISCnews ok1 records Checked — no match The source completed, but none of its retained records matched this story.
SentinelLabsnews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Shadowserver public aggregate honeypot observationsexploit_reference ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Shodanresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Sigma Rulesresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Sophos IOCsresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Sophos X-Opsnews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
The DFIR Reportnews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
ThreatFoxthreat_intelligence ok100 records Checked — no match The source completed, but none of its retained records matched this story.
UK NCSCnews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Unit 42news ok1 records Checked — no match The source completed, but none of its retained records matched this story.
Unit42 IOCsresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
URLhausdark_web ok10 records Checked — no match The source completed, but none of its retained records matched this story.
VirusTotal Community IOC enrichmentresearch ok4 records Checked — no match The source completed, but none of its retained records matched this story.
VulnCheck KEVkev ok500 records Checked — no match The source completed, but none of its retained records matched this story.
Vulnerability Lookupcve ok30 records Checked — no match The source completed, but none of its retained records matched this story.
WeLiveSecuritynews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Additional verified pages 6 opened outside the registered collection
Vendor & gov advisories1
ValleyRAT is spreading disguised as adware – Kaspersky Securelist securelist.com ↗

Primary vendor analysis; full infection chain, IoCs, and Silver Fox attribution

Analysis & research4
SilverFox Evolves: Trusted Software Hijacking Delivers ValleyRAT – Cato CTRL catonetworks.com ↗

July 2026 independent report documenting Silver Fox DLL sideloading against a Japanese manufacturer; CVE-2023-52271 BYOVD chain detailed

ValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool – Security Affairs securityaffairs.com ↗

Independent corroboration of Kaspersky findings and Silver Fox attribution

Thor vs. Silver Fox: Uncovering and Defeating a Sophisticated ValleyRAT Campaign – Nextron Systems nextron-systems.com ↗

November 2025 report establishing Silver Fox DLL sideloading via signed executables predates this campaign; uses log.dll/NtHandleCallback.exe variant

SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain – The Hacker News thehackernews.com ↗

July 2026 coverage of Silver Fox BYOVD campaign; independently confirms group's ongoing abuse of legitimate signed executables for sideloading

Full Report
reported on 31/08/26

Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets

Threat actors operating the Aurora (aka Aur0ra) ransomware, a Russian-speaking cybercrime group, have been observed leveraging Cursor, an AI-powered coding assistant, to plan and execute attacks against organizations across at least nine countries between April and July 2026. Research from CloudSEK and Gambit Security, based on exposed infrastructure and recovered shell history, revealed the operators used Cursor to draft attack plans in Russian, including a full Active Directory Certificate Services exploitation strategy. Initial access methods include aggressive email bombing combined with vishing calls impersonating IT helpdesk personnel, followed by deployment of open-source remote access tool Xray-core. Post-access activity involves lateral movement across SMB, LDAP, WinRM, RDP, and RPC, disabling Microsoft Defender, clearing logs, and deploying Windows and Linux/ESXi encryptors written in Zig. As of reporting, Ransomware.Live lists 33 victims located in the U.S., Germany, the Netherlands, Canada, and the U.K., with four officially claimed on Aurora's data leak site.

Why it matters

The group's documented use of an AI coding assistant to plan multi-phase intrusions—including AD CS exploitation and cross-platform encryptor development—signals a maturing capability to accelerate attack planning without specialized expertise, lowering the barrier for sophisticated ransomware operations. Defenders should prioritize monitoring for Xray-core deployment, AD CS misconfigurations, and bulk log-clearing events as early-stage indicators.

Full research report see the analyst’s trail →
★ Threat intelligence assessment medium confidence

Executive assessment

The strongest finding is not a new software vulnerability but the integration of Cursor into an already established ransomware workflow. Gambit Security's ten-target observation shows that the operator supplied access and retained direction, while CloudSEK's wider records connect planning activity to credential theft, Active Directory compromise, exfiltration and cross-platform encryption. Independent incident-response evidence confirms Aurora's use of social engineering, tunnelling, broad internal scanning and recovery inhibition. Defenders should therefore prioritise identity, certificate-service, administrative-path and virtualisation hardening rather than treating this as a vulnerability in Cursor itself.

What happened

Gambit Security reported that an Aurora ransomware operator used Cursor during hands-on activity against ten target organisations from 8 April to 21 May 2026, supplying it with credentials or an existing route into each environment. CloudSEK separately examined exposed operator infrastructure covering April to July and found activity against more than 20 organisations across nine countries, including Cursor-assisted planning, credential material, tooling and Aurora encryptors. Earlier reporting established the ransomware by May, while an independent August incident-response account documented email bombing, help-desk impersonation and subsequent deployment activity.

Affected scope

The recovered activity affected unnamed organisations across multiple countries and sectors, including manufacturing, food and agriculture, professional and financial services, transport, consumer goods and backup infrastructure. Aurora tooling supports Windows and Linux, including a dedicated VMware ESXi mode; Active Directory, certificate services, remote administration paths and virtualisation infrastructure were prominent security boundaries. The ten organisations in the focused Cursor finding were not publicly identified.

Technical assessment

The evidence indicates that Cursor was used after credentials or network access had already been obtained, helping the operator perform routine internal discovery, privilege assessment and iterative exploitation tasks under human direction. The broader operation combined credential theft, Active Directory compromise, data staging and exfiltration with a Zig-based encryptor compiled for Windows and Linux/ESXi; the ESXi build stopped virtual machines before encrypting their files, while the Windows build inhibited recovery. This demonstrates operational acceleration rather than a novel vulnerability in Cursor, and the sources do not establish that automation alone achieved compromise.

Recommended defensive actions

  1. Audit Active Directory Certificate Services templates and remediate dangerous enrolment, subject-name and web-enrolment configurations.
  2. Enable Server Message Block signing and Extended Protection for Authentication, disable SMBv1, and disable Link-Local Multicast Name Resolution and NetBIOS Name Service where operationally possible.
  3. Restrict Windows Remote Management, Remote Desktop Protocol and other administrative services to designated management hosts and monitored administrator accounts.
  4. Isolate backup and VMware ESXi management infrastructure from production Active Directory using separate credentials and network segments.
  5. Hunt for the published Aurora file hashes, ransom-note filename, infrastructure indicators, unexpected SSH-banner changes and renamed Xray-core binaries.
  6. Monitor for unusual internal scanning, mass outbound SMB or LDAP connections, certificate-enrolment anomalies, security-control tampering and deletion of recovery artefacts.
  7. Train service-desk personnel and users to treat email bombing followed by unsolicited support calls as a likely intrusion attempt, and establish an independently verified callback process.
  8. Remove unauthorised remote-access tools, scheduled tasks, startup entries and tunnelling configurations identified during investigation.

Uncertainties and evidence gaps

  • The ten Cursor-associated targets were unnamed, preventing independent confirmation of their identities, sectors and outcomes.
  • CloudSEK and Gambit Security examined exposed infrastructure associated with Aurora, but public evidence does not prove that every recorded target was successfully encrypted or extorted.
  • The precise initial-access method for the ten Cursor-associated targets is unknown; Gambit Security established only that credentials or an existing route were supplied.
  • Ransomware.live records actor claims and currently describes an older Go-based Aurora malware under the same name, creating a possible naming conflation with the 2026 Zig-based ransomware operation.
  • No specific CVE was identified as the defining cause of these intrusions, despite the operator possessing public exploit code for several known weaknesses.

Vulnerability flow

Defender-oriented path reconstructed only from sourced report findings. Unknown stages are omitted.

AccessThe Cursor-assisted sessions began with supplied credentials or an existing network route; a separately documented Aurora incident began with email bombing and help-desk impersonation.
ComponentEnterprise identity and administration boundaries, particularly Active Directory, certificate services, Windows endpoints, backup systems and VMware ESXi hosts.
MechanismHuman-directed automation was used to enumerate internal environments and iterate through established credential, relay and certificate-abuse techniques before data theft and ransomware deployment.
ImpactDomain compromise, credential theft, data exfiltration, disabled recovery controls, stopped virtual machines and encryption of Windows or Linux/ESXi files.
DetectionLook for abnormal internal scanning, high-volume SMB and LDAP connections, anomalous certificate requests, suspicious remote-administration sessions, renamed tunnelling utilities, recovery-control changes, unexpected ESXi SSH banners and the filename !!!README!!!DO_NOT_DELETE.txt.
MitigationHarden Active Directory Certificate Services, enforce SMB signing and Extended Protection for Authentication, disable legacy name-resolution and SMBv1, restrict administrative protocols, segment backup and ESXi systems, and hunt using the indicators published by CloudSEK and Gambit Security.
Exploitation status

Confirmed malicious operations affected multiple organisations; public exploit code for several underlying known weaknesses was present in operator infrastructure, but no single CVE defines this campaign.

The investigation first tested whether the headline represented a Cursor vulnerability, a new exploitation technique or the use of a general-purpose coding tool during an established ransomware operation. Primary research from Gambit Security and CloudSEK independently supported sustained Cursor use, while Black Hills Information Security and CYFIRMA corroborated Aurora's wider intrusion and ransomware activity. The evidence supports a multi-platform, human-directed ransomware campaign, but not a Cursor vulnerability or a single campaign-defining CVE.

  1. What precise event did the supplied story describe?
    Reviewed the supplied article and followed its cited research references.
    thehackernews.com ↗

    The article linked the ten-target claim to Gambit Security and the broader April-to-July operation to CloudSEK, while citing earlier Aurora reporting and a separate incident response.

    why This separated the focused Cursor finding from broader claims about more than 20 organisations and the ransomware campaign as a whole.

  2. Did exposed operator records support attribution, scope and actual ransomware activity?
    Read CloudSEK's primary investigation of the exposed Aurora infrastructure.
    cloudsek.com ↗

    CloudSEK reported more than 20 targets across nine countries, interactive or domain-level access at 17, four subsequent leak-site listings, Russian-language Cursor planning and Windows plus Linux/ESXi encryptors built from one Zig codebase.

    why The combination of access records, matching ransom artefacts, encryptors and payment evidence strongly supports association with an operational Aurora affiliate rather than a collection of unrelated tools.

  3. Was Cursor used directly during intrusions, and what access did it require?
    Read Gambit Security's technical account of the Cursor-associated sessions and encryptor.
    gambit.security ↗

    Gambit Security observed sessions against ten organisations between 8 April and 21 May 2026; each began with credentials or an existing route, and many attempted commands required refinement or failed.

    why This confirms operational use while showing that Cursor was not the initial-access vulnerability and did not function autonomously or reliably.

  4. Was Aurora activity independently observed in a victim environment?
    Reviewed Black Hills Information Security's incident-response account.
    activesoc.blackhillsinfosec.com ↗

    Responders documented email bombing followed by fake help-desk calls, disguised Xray-core tunnelling, noisy lateral movement, security-control tampering and an Aurora ransom note matching the known filename and format.

    why This independently corroborates Aurora operations and supplies actionable behavioural detections, although it does not establish that the same initial-access method applied to the ten Cursor-associated targets.

  5. Did published evidence pre-date the August infrastructure disclosures?
    Reviewed CYFIRMA's 22 May ransomware report.
    cyfirma.com ↗

    CYFIRMA had already described Aur0ra's Windows encryption behaviour, unchanged filenames, double-extortion claim and !!!README!!!DO_NOT_DELETE.txt ransom note.

    why The earlier publication corroborates the malware identity and timeline independently of the later exposed-infrastructure analyses.

  6. What public victim scale was visible, and how reliable was it?
    Checked the current Aurora group record maintained by Ransomware.live.
    ransomware.live ↗

    The record showed 34 claimed victims across ten countries, with a first estimated attack date of 17 April 2026 and discovery on 29 April.

    why This supports continued public extortion activity but remains actor-claim-derived and contains a potentially conflated description of an older Go-based malware sharing the Aurora name.

ActorsAurora ransomware groupRussian-speaking Aurora affiliate
MalwareAurora (Aur0ra) ransomware
TargetsWindows environmentsLinux and VMware ESXi environmentsActive Directory estatesManufacturing and industrial organisationsFood, agriculture and distribution organisationsProfessional and financial servicesTransport and logistics organisationsIT and backup infrastructure

Research coverage

All 73 registered source leaves were evaluated for this run: 63 completed, 0 were unavailable, 3 failed and 7 were disabled. For this story, 1 registered sources supplied useful evidence (1 primary, 0 corroborating, 0 contextual and 0 PoC/exploit references). 62 completed sources contained no matched information for this story.

Primary evidence Independent corroboration Operational context PoC reference Checked — no match Unavailable Failed Disabled
Complete source-by-source audit 73 sources
SourceRun resultValueWhy it was useful — or not
The Hacker Newsnews ok7 records Primary evidence1 matched items Published the source report used to frame and date the event.
AlienVault OTXdark_web failed0 records Failed The current collection attempt failed; this source cannot support the report.
BleepingComputernews ok10 records Checked — no match The source completed, but none of its retained records matched this story.
CERT-EU Threat Intelligencenews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
CIRCL CVEcve ok30 records Checked — no match The source completed, but none of its retained records matched this story.
CISA Alertsnews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
CISA KEVkev ok1687 records Checked — no match The source completed, but none of its retained records matched this story.
Cisco PSIRTvendor_advisory ok5333 records Checked — no match The source completed, but none of its retained records matched this story.
Cisco Talosnews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
deepdarkCTI CVE most exploiteddeepdarkcti ok94 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI Discorddeepdarkcti ok7 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI exploitsdeepdarkcti ok24 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI forumsdeepdarkcti ok264 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI malware as a servicedeepdarkcti ok7 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI malware samplesdeepdarkcti ok3 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI marketsdeepdarkcti ok127 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI phishingdeepdarkcti ok19 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI ransomware gangsdeepdarkcti ok689 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI RATsdeepdarkcti ok1 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI Telegram infostealerdeepdarkcti ok130 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI Telegram threat actorsdeepdarkcti ok1013 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI Twitter threat actorsdeepdarkcti ok39 records Checked — no match The source completed, but none of its retained records matched this story.
Exploit-DBexploit_reference ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
FIRST EPSSepss ok8075 records Checked — no match The source completed, but none of its retained records matched this story.
Fortinet PSIRTvendor_advisory disabled Disabled Disabled in the source registry; no check was attempted.
GitHub topic: cveresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
GitHub topic: exploitresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
GitHub topic: penetration-testingresearch failed0 records Failed The current collection attempt failed; this source cannot support the report.
GitHub topic: pocresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
GitHub topic: vulnerabilityresearch failed0 records Failed The current collection attempt failed; this source cannot support the report.
GreyNoiseexploit_reference ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
KrebsOnSecuritynews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
LinkedIn RSS proxy feeds (disabled)research disabled Disabled Disabled in the source registry; no check was attempted.
MalwareBazaardark_web ok9 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #cveresearch ok20 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #cybersecurityresearch ok17 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #exploitresearch ok20 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #infosecresearch ok20 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #malwareresearch ok20 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #ransomwareresearch ok19 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #threatintelresearch ok5 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #vulnerabilityresearch ok19 records Checked — no match The source completed, but none of its retained records matched this story.
Metasploit module metadataexploit_reference ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Microsoft MSRCvendor_advisory ok1591 records Checked — no match The source completed, but none of its retained records matched this story.
Microsoft Securitynews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
MISP Galaxyresearch ok3 records Checked — no match The source completed, but none of its retained records matched this story.
MISP threat actor galaxyactor ok0 records Checked — no match The source completed, but none of its retained records matched this story.
NVDcve ok900 records Checked — no match The source completed, but none of its retained records matched this story.
Palo Alto Networks PSIRTvendor_advisory ok25 records Checked — no match The source completed, but none of its retained records matched this story.
ProjectDiscovery nuclei templatesexploit_reference ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Rapid7news ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Reddit r/AskNetsec (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/cybersecurity (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/malware (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/netsec (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/ReverseEngineering (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
SANS ISCnews ok1 records Checked — no match The source completed, but none of its retained records matched this story.
SentinelLabsnews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Shadowserver public aggregate honeypot observationsexploit_reference ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Shodanresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Sigma Rulesresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Sophos IOCsresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Sophos X-Opsnews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
The DFIR Reportnews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
ThreatFoxthreat_intelligence ok100 records Checked — no match The source completed, but none of its retained records matched this story.
UK NCSCnews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Unit 42news ok1 records Checked — no match The source completed, but none of its retained records matched this story.
Unit42 IOCsresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
URLhausdark_web ok10 records Checked — no match The source completed, but none of its retained records matched this story.
VirusTotal Community IOC enrichmentresearch ok4 records Checked — no match The source completed, but none of its retained records matched this story.
VulnCheck KEVkev ok500 records Checked — no match The source completed, but none of its retained records matched this story.
Vulnerability Lookupcve ok30 records Checked — no match The source completed, but none of its retained records matched this story.
WeLiveSecuritynews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Additional verified pages 13 opened outside the registered collection
Technical references1
github.com/xtls/xray-core ↗

Repository captured from the source article as technical context; not validated as PoC or exploit code.

OSINT / dark-web chatter1
Ransomware.live Aurora group record ransomware.live ↗

Leak-site monitoring recorded 34 claimed victims across ten countries as of 1 September 2026; victim claims are not independently verified.

Analysis & research5
Caught in 4K: The Aurora Files cloudsek.com ↗

Documents activity against more than 20 organisations, Cursor-assisted planning, cross-platform encryptors and defensive indicators.

Aurora ransomware targets ESXi and abuses Cursor for exploitation gambit.security ↗

Reports Cursor-assisted activity against ten targets between 8 April and 21 May 2026 and analyses the Linux/ESXi encryptor.

Introducing the Aur0ra Ransomware Group activesoc.blackhillsinfosec.com ↗

Independently documents an Aurora incident beginning with email bombing and help-desk impersonation, followed by tunnelling and lateral movement.

Weekly Intelligence Report – 22 May 2026 cyfirma.com ↗

Provides earlier corroboration of the Aur0ra ransomware, its Windows focus, ransom-note filename and double-extortion claims.

Aurora operators use Cursor AI in attacks against ten targets thehackernews.com ↗

Secondary reporting that brought together the CloudSEK, Gambit Security and earlier campaign findings.

Full Report
reported on 31/08/26

Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams

Between January and April 2026, Palo Alto Networks Unit 42 identified a coordinated social engineering campaign dubbed 'Spring Ring' in which threat actors used external Microsoft Teams accounts to impersonate IT help desk personnel and conduct voice phishing (vishing) calls against employees. The operation targeted more than 150 employees across at least 10 organizations in unspecified industries. Attackers used live voice interaction to coerce victims into executing remote monitoring and management (RMM) tools or custom malware, bypassing detection mechanisms that rely on identifying malicious links or software exploits. A more advanced campaign variant escalated from a vishing call to an NTLM relay attack targeting an organization's domain controller. The report notes that phishing alerts originating from collaboration platforms represented 42% of all phishing alerts in Palo Alto's Cortex telemetry during the first four months of 2026, up from 30% in the prior four months.

Why it matters

Defenders face a fundamental detection gap: Teams-based vishing relies on human voice manipulation rather than malicious links or executable files, rendering traditional email and URL filtering largely ineffective and requiring organizations to implement identity-centric controls and employee awareness programs specifically for collaboration platforms. The escalation path to NTLM relay against domain controllers means a successful vishing call can result in full domain compromise.

Full research report see the analyst’s trail →
★ Threat intelligence assessment high confidence

Executive assessment

Spring Ring represents a maturation of the Teams-based social engineering threat, moving beyond the credential-harvesting link-drop techniques historically associated with state-aligned actors toward a model requiring live voice interaction—deliberately bypassing link-scanning and banner-based user-training defences. The use of PetitPotam coercion in Campaign B, even when blocked, signals that at least one actor behind this pattern was pursuing domain-level compromise as the objective, not merely initial access. The concurrent operation of at least three independently tracked clusters—Spring Ring, UNC6692, and STAC4749—using the same Teams external access vector over the same six-month window confirms this is now a commoditised attack pattern being used by financially motivated groups with varying sophistication levels and ranging from custom malware deployment to ransomware. The fundamental defensive gap is structural: Teams external federation is enabled by default, RMM tools are legitimate, and voice interaction bypasses every link-centric detection control, meaning organisations without behavioural identity analytics and tightly scoped external access policies remain broadly exposed.

What happened

Between January and April 2026, an unattributed threat cluster Unit 42 designated Spring Ring conducted coordinated voice phishing operations via external Microsoft Teams accounts, impersonating IT help desk personnel across at least 10 organisations. Attackers exploited Teams' default 'Chat with Anyone' feature to initiate unsolicited chats and live voice calls, coercing targets into executing remote management tools or custom malware. Two distinct campaigns are documented: Campaign A deploying an obfuscated PowerShell remote access trojan, and Campaign B escalating to a PetitPotam-based NTLM relay attempt against a domain controller. At least two independent research organisations (Mandiant and Sophos) tracked separate clusters using the same attack vector concurrently.

Affected scope

More than 150 employees across at least 10 organisations in unspecified industries (Spring Ring direct); parallel campaigns extended confirmed impact to financial services, healthcare, manufacturing, energy, and construction sectors, primarily in Canada and the United States.

Technical assessment

Attackers registered external Microsoft 365 tenants using display names and domain suffixes that project internal IT authority, then leveraged Teams' cross-tenant federation to contact targets directly. Voice interaction replaced malicious links, bypassing URL-scanning controls entirely. Campaign A used Quick Assist for initial remote access before deploying a nine-line PowerShell stager that set the amsiInitFailed flag to bypass AMSI, then beaconed to san-sid[.]com for a secondary payload. Campaign B used victim-specific AWS S3 URLs to deliver a custom executable dropper, established persistence via a sideloaded Microsoft Edge extension, then used Python tooling to scan for open SMB (port 445) and invoked PetitPotam to coerce NTLM authentication from a domain controller—the relay attempt was blocked in the observed instance. No software vulnerability was exploited; the attack surface is the identity and trust model of SaaS collaboration platforms.

Recommended defensive actions

  1. Restrict Microsoft Teams external access: audit and disable or scope the 'Chat with Anyone' setting to prevent unsolicited external contact with employees.
  2. Block or alert on external Teams communications from tenants using IT-authority keywords (help, support, internal, certified, network, infrastructure) in display names or domain strings.
  3. Audit and restrict execution of Quick Assist, RemSupp, TeamViewer, and other remote monitoring and management tools via endpoint policy, alerting on use by users with no documented support workflow.
  4. Enforce Extended Protection for Authentication (EPA) on domain controllers and disable NTLM where Kerberos is operationally viable, to neutralise PetitPotam-class coercion attempts.
  5. Deploy identity-threat detection tuned to external-entity chat-to-call transitions and rapid multi-target contact patterns from a single external identity within a short window.
  6. Train employees to verify any unsolicited IT contact via a separate, out-of-band channel before granting remote access, regardless of the platform origin.

Uncertainties and evidence gaps

  • Spring Ring's threat actor attribution is unconfirmed; Unit 42 does not link it to a named group, and its relationship to UNC6692 or STAC4749 is not established by any published source.
  • The full scope of targeted industries and organisations is not disclosed; 'various industries' leaves true exposure breadth unknown.
  • Whether the PetitPotam-based NTLM relay succeeded in any incident beyond the one blocked case has not been confirmed in published reporting.
  • No government or vendor advisory specifically addressing the Teams external access attack surface has been issued; defenders must rely on vendor-specific detection guidance and manual configuration changes.

Vulnerability flow

Defender-oriented path reconstructed only from sourced report findings. Unknown stages are omitted.

AccessAttacker requires only a free Microsoft 365 account to reach any Teams user whose organisation has external access enabled, which is the default configuration.
ComponentMicrosoft Teams external access ('Chat with Anyone') and the SaaS platform identity trust model.
MechanismAttacker registers a credibly named external tenant and uses Teams cross-tenant federation to contact targets directly, then substitutes a live voice call for a malicious link to manipulate the target into executing attacker-controlled software under the guise of IT support.
ImpactRemote code execution and persistence via RMM or custom malware; in the advanced variant, attempted domain-level privilege escalation via NTLM relay to a domain controller.
DetectionExternal entity initiating a voice call shortly after a chat message; RMM tool execution by non-IT users; outbound connections to unexpected cloud storage domains from an endpoint; SMB port 445 scanning originating from a newly enrolled device; anomalous NTLM authentication events directed toward a domain controller from an unusual source.
MitigationRestrict or disable Teams external access; block unsanctioned RMM tools at the endpoint via policy; enforce EPA and Kerberos-only authentication on domain controllers; apply conditional access policies to external identity interactions.
Exploitation status

No software vulnerability exploited; Spring Ring actively conducted voice phishing via Microsoft Teams January–April 2026, confirming operational execution against 150+ employees. Parallel clusters (UNC6692, STAC4749) were separately confirmed active over the same period using identical initial access.

Investigation began with the Unit 42 primary report on Spring Ring, which provided a detailed account of two vishing campaigns active January–April 2026. Web searches confirmed that at least two separately tracked clusters—UNC6692 (Mandiant) and STAC4749 (Sophos)—were operating the same Teams external access impersonation vector concurrently, establishing that Spring Ring reflects a broader commoditised shift rather than an isolated incident. The KnowBe4 Phishing Threat Trends Report Vol. 7 independently corroborated the 41% surge in Teams-based attacks cited in the source article. No CVEs were identified and no government advisory was found; the attack surface is entirely behavioural and platform-configuration-based.

  1. What are the full technical details, scope, and IOCs of the Spring Ring campaign?
    Fetched the Unit 42 primary report.
    unit42.paloaltonetworks.com ↗

    Two-campaign breakdown confirmed: Campaign A (Quick Assist → AMSI-bypass PowerShell RAT, C2 san-sid[.]com); Campaign B (S3 dropper → Edge extension → PetitPotam NTLM relay attempt). 26 attacker identities, 48+ spoofed accounts, 150+ targets across 10+ organisations. No CVEs exploited.

    why Establishes the authoritative primary account of the event, tools, infrastructure, and IOCs.

  2. Are there independent reports of Teams vishing with similar TTPs operating in the same period?
    Searched for Microsoft Teams vishing IT help desk social engineering 2026.

    Multiple independent campaigns identified: UNC6692 (Mandiant, April 2026), STAC4749/Chaos ransomware (Sophos, February–June 2026), and CyberProof H1 2026 analysis—all use the same external Teams tenant impersonation pattern.

    why Confirms Spring Ring is not isolated; the Teams external access vector is being exploited by multiple distinct clusters simultaneously, elevating the assessment from a single campaign to a class of threat.

  3. Does the UNC6692 reporting provide attribution or additional technical context?
    Fetched the Hacker News article on UNC6692.
    thehackernews.com ↗

    UNC6692 attributed to former Black Basta affiliates; uses distinct SNOW malware ecosystem (SNOWBELT, SNOWGLAZE, SNOWBASIN); targets senior executives; achieves lateral movement via pass-the-hash. No CVEs. Not directly linked to Spring Ring.

    why Adds actor context and a named malware family to the broader threat picture, though UNC6692 and Spring Ring remain unlinked by published evidence.

  4. What is STAC4749's connection to this threat trend and what are the downstream impacts?
    Fetched the Bleeping Computer article on Teams vishing leading to Chaos ransomware.
    bleepingcomputer.com ↗

    STAC4749, linked to former Conti/Royal/BlackSuit affiliates, targeted dozens of North American organisations Feb–June 2026 via Teams impersonation. Achieved encryption in under 17 hours in one case. Canada (50%) and US (45%) primary targets.

    why Provides the ransomware end-game context absent from Spring Ring's own reporting, confirming the same vector is being monetised by ransomware-affiliated groups.

  5. Does the KnowBe4 report independently confirm the 41% Teams phishing surge cited in the Unit 42 article?
    Fetched the KnowBe4 2026 Phishing Threat Trends Report Vol. 7.
    knowbe4.com ↗

    Report confirms Teams attacks surged 41% in six months. Also notes 84.4% of successful phishing now passes DMARC verification, underlining why platform-trust exploitation is effective.

    why Independent statistical corroboration from a separate security vendor, validating the scale of the Teams-based phishing trend described by Unit 42.

  6. Does the CyberProof H1 2026 analysis provide independent sector-specific detail?
    Fetched the CyberProof H1 2026 Microsoft Teams vishing analysis.
    cyberproof.com ↗

    Confirms financial services and healthcare as targeted sectors; identifies SINDOOR malware in one incident; notes Iranian state-aligned actors among suspected threat groups. Call durations averaged approximately 20 minutes.

    why Extends the sector scope beyond what Unit 42 disclosed and adds a state-aligned actor dimension, though SINDOOR is not linked to Spring Ring specifically.

  7. Are there any government or vendor advisories specifically addressing this Teams external access attack surface?
    Searched for CISA or Microsoft advisories on Teams external access vishing 2026.

    No government advisory directly addressing Spring Ring or the Teams external access vishing pattern was found in search results.

    why Absence of formal advisory is a material gap; defenders must rely on vendor detection guidance and manual configuration hardening rather than a directed remediation notice.

ActorsSpring Ring (unattributed cluster)UNC6692 (former Black Basta affiliates)STAC4749 (former BlackSuit/Royal/Conti affiliates)
MalwareCustom PowerShell RAT (AMSI bypass)SNOWBELTSNOWGLAZESNOWBASINChaos ransomware
TargetsCorporate employees across 10+ organisations (various industries)Senior-level executivesFinancial servicesHealthcareManufacturingEnergy and constructionPrimarily North American organisations (STAC4749 data)

Research coverage

All 73 registered source leaves were evaluated for this run: 63 completed, 0 were unavailable, 3 failed and 7 were disabled. For this story, 2 registered sources supplied useful evidence (1 primary, 1 corroborating, 0 contextual and 0 PoC/exploit references). 61 completed sources contained no matched information for this story.

Primary evidence Independent corroboration Operational context PoC reference Checked — no match Unavailable Failed Disabled
Complete source-by-source audit 73 sources
SourceRun resultValueWhy it was useful — or not
Unit 42news ok1 records Primary evidence2 matched items Published the source report used to frame and date the event. Supplied independent analysis opened and verified during focused research.
BleepingComputernews ok10 records Corroborating1 matched items Supplied independent analysis opened and verified during focused research.
AlienVault OTXdark_web failed0 records Failed The current collection attempt failed; this source cannot support the report.
CERT-EU Threat Intelligencenews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
CIRCL CVEcve ok30 records Checked — no match The source completed, but none of its retained records matched this story.
CISA Alertsnews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
CISA KEVkev ok1687 records Checked — no match The source completed, but none of its retained records matched this story.
Cisco PSIRTvendor_advisory ok5333 records Checked — no match The source completed, but none of its retained records matched this story.
Cisco Talosnews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
deepdarkCTI CVE most exploiteddeepdarkcti ok94 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI Discorddeepdarkcti ok7 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI exploitsdeepdarkcti ok24 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI forumsdeepdarkcti ok264 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI malware as a servicedeepdarkcti ok7 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI malware samplesdeepdarkcti ok3 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI marketsdeepdarkcti ok127 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI phishingdeepdarkcti ok19 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI ransomware gangsdeepdarkcti ok689 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI RATsdeepdarkcti ok1 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI Telegram infostealerdeepdarkcti ok130 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI Telegram threat actorsdeepdarkcti ok1013 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI Twitter threat actorsdeepdarkcti ok39 records Checked — no match The source completed, but none of its retained records matched this story.
Exploit-DBexploit_reference ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
FIRST EPSSepss ok8075 records Checked — no match The source completed, but none of its retained records matched this story.
Fortinet PSIRTvendor_advisory disabled Disabled Disabled in the source registry; no check was attempted.
GitHub topic: cveresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
GitHub topic: exploitresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
GitHub topic: penetration-testingresearch failed0 records Failed The current collection attempt failed; this source cannot support the report.
GitHub topic: pocresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
GitHub topic: vulnerabilityresearch failed0 records Failed The current collection attempt failed; this source cannot support the report.
GreyNoiseexploit_reference ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
KrebsOnSecuritynews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
LinkedIn RSS proxy feeds (disabled)research disabled Disabled Disabled in the source registry; no check was attempted.
MalwareBazaardark_web ok9 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #cveresearch ok20 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #cybersecurityresearch ok17 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #exploitresearch ok20 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #infosecresearch ok20 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #malwareresearch ok20 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #ransomwareresearch ok19 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #threatintelresearch ok5 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #vulnerabilityresearch ok19 records Checked — no match The source completed, but none of its retained records matched this story.
Metasploit module metadataexploit_reference ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Microsoft MSRCvendor_advisory ok1591 records Checked — no match The source completed, but none of its retained records matched this story.
Microsoft Securitynews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
MISP Galaxyresearch ok3 records Checked — no match The source completed, but none of its retained records matched this story.
MISP threat actor galaxyactor ok0 records Checked — no match The source completed, but none of its retained records matched this story.
NVDcve ok900 records Checked — no match The source completed, but none of its retained records matched this story.
Palo Alto Networks PSIRTvendor_advisory ok25 records Checked — no match The source completed, but none of its retained records matched this story.
ProjectDiscovery nuclei templatesexploit_reference ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Rapid7news ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Reddit r/AskNetsec (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/cybersecurity (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/malware (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/netsec (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/ReverseEngineering (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
SANS ISCnews ok1 records Checked — no match The source completed, but none of its retained records matched this story.
SentinelLabsnews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Shadowserver public aggregate honeypot observationsexploit_reference ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Shodanresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Sigma Rulesresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Sophos IOCsresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Sophos X-Opsnews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
The DFIR Reportnews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
The Hacker Newsnews ok7 records Checked — no match The source completed, but none of its retained records matched this story.
ThreatFoxthreat_intelligence ok100 records Checked — no match The source completed, but none of its retained records matched this story.
UK NCSCnews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Unit42 IOCsresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
URLhausdark_web ok10 records Checked — no match The source completed, but none of its retained records matched this story.
VirusTotal Community IOC enrichmentresearch ok4 records Checked — no match The source completed, but none of its retained records matched this story.
VulnCheck KEVkev ok500 records Checked — no match The source completed, but none of its retained records matched this story.
Vulnerability Lookupcve ok30 records Checked — no match The source completed, but none of its retained records matched this story.
WeLiveSecuritynews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Additional verified pages 3 opened outside the registered collection
Technical references1
github.com/topotam/PetitPotam ↗

Repository captured from the source article as technical context; not validated as PoC or exploit code.

Analysis & research5
Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams unit42.paloaltonetworks.com ↗

Primary Unit 42 report; full attack lifecycle, two campaign variants, IOCs, and telemetry.

UNC6692 Impersonates IT Help Desk via Microsoft Teams to Deploy SNOW Malware thehackernews.com ↗

Mandiant-tracked cluster using near-identical Teams impersonation TTPs; SNOW malware suite targeting senior executives.

Microsoft Teams Vishing Attacks Lead to Chaos Ransomware bleepingcomputer.com ↗

Sophos-tracked STAC4749 campaign; same Teams external access vector leading to ransomware deployment by former Conti affiliates.

2026 Phishing Threat Trends Report, Vol. 7 knowbe4.com ↗

Independent corroboration of the 41% surge in Teams-based phishing attacks over six months.

Microsoft Teams Vishing and Cross-Tenant Attack Chronicles: H1 2026 Analysis cyberproof.com ↗

Independent H1 2026 analysis of Teams impersonation attacks across financial and healthcare sectors.

Full Report
reported on 31/08/26

China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs

A China-nexus actor tracked as Fire Ant compromised Cisco IOS XR routers, TACACS servers, and Linux management hosts as part of an espionage campaign extending from prior VMware targeting. The group used the routers to capture network traffic via PCAPs, harvest credentials, and suppress logging and telemetry by modifying system libraries and command outputs. Activity was identified after an anomaly involving an unexplained GRE tunnel on a router, leading investigators to a legacy Linux system used for further probing of connected networks. Sygnia assessed the actor explored paths toward critical infrastructure but observed only scanning and connection attempts without confirmed compromise. The 2026 reporting follows Sygnia's July 2025 disclosure of the same group and notes possible overlap with UNC3886 without conclusive attribution.

Why it matters

Router compromise provides attackers with traffic perspective and the ability to blind logs, severely limiting defenders' visibility into network activity and incident reconstruction. Organizations must prioritize integrity checks on network device configurations and logging mechanisms.

Full research report see the analyst’s trail →
★ Threat intelligence assessment medium confidence

Executive assessment

The strongest evidence concerns post-compromise activity: concealed GRE tunnelling, router packet capture, selective log forwarding, manipulation of administrative command output and credential interception inside tac_plus. TacTap and BridgeAgent extend previously documented UNC3886-style tradecraft into the authentication and Linux management layers, while REPTILE and MEDUSA provide further behavioural overlap. No evidence identified a Cisco IOS XR vulnerability, affected version range or public exploit, so historical VMware and Fortinet CVEs should not be presented as the cause of this router intrusion. Defenders should treat router configuration and local logs as potentially hostile evidence and corroborate them with protected external telemetry and forensic acquisition.

What happened

On 31 August 2026, reporting described a Sygnia investigation into Fire Ant compromises of Cisco IOS XR routers, TACACS+ servers and associated Linux management hosts. Components reportedly planted during 2025 were reused for hands-on activity in 2026, including traffic capture, credential collection, covert tunnelling and telemetry suppression. The activity overlaps with previously documented UNC3886 tradecraft, but Sygnia did not make a conclusive attribution.

Affected scope

The documented environment included Cisco devices running IOS XR, a tac_plus-based TACACS+ authentication server, a legacy Linux system and other Linux management hosts; affected software versions and the victim organisation were not disclosed. Connected high-value and critical-infrastructure environments reportedly received scans and connection attempts, but their compromise was not confirmed.

Technical assessment

The router implants reportedly modified IOS XR control-plane behaviour to suppress most log messages and conceal an unauthorised Generic Routing Encapsulation tunnel from administrative show-command output. Fire Ant also captured packet data for external transfer, while TacTap injected a library into tac_plus to collect live authentication credentials and BridgeAgent provided persistent command access from a Linux host. This is significant because compromised routing and authentication infrastructure can expose trusted traffic and administrative credentials while simultaneously making configuration and logging evidence unreliable.

Recommended defensive actions

  1. Immediately isolate suspected routers, TACACS+ servers and connected management hosts while preserving volatile memory and network evidence.
  2. Hunt for unexplained Generic Routing Encapsulation interfaces, discrepancies between operational state and commit history, unexpected packet captures and outbound FTP transfers from network devices.
  3. Inspect TACACS+ systems for /usr/sbin/acppid, /lib/libseconfd.so, /var/log/.tacplus.acct, unauthorised library injection and anomalous local Unix sockets involving tac_plus.
  4. Audit Linux hosts for zabbix_agent.service persistence, /opt/.ICEauthority, processes masquerading as /usr/bin/gnome-shell, disabled SELinux and binaries impersonating security products.
  5. Rotate TACACS+, router-administration and other exposed credentials only after restoring the integrity of routing, authentication and management systems.
  6. Restrict router and TACACS+ management access to dedicated administration networks and independently export configuration, authentication and flow telemetry to protected collectors.
  7. Validate device integrity using memory, disk, configuration, authentication and network evidence rather than relying solely on potentially suppressed local logs.

Uncertainties and evidence gaps

  • The method used to obtain initial access to the Cisco IOS XR router is unknown.
  • No affected IOS XR or tac_plus version range, exploited vulnerability or vendor fix was identified.
  • Fire Ant's relationship to UNC3886 is assessed from overlapping targeting and tradecraft rather than conclusive attribution.
  • The victim organisation, campaign scale and number of compromised devices were not disclosed.
  • Scanning and connection attempts towards critical infrastructure were reported, but compromise of those connected environments was not confirmed.

Vulnerability flow

Defender-oriented path reconstructed only from sourced report findings. Unknown stages are omitted.

AccessInitial access to the IOS XR router was not established; the documented activity presupposed privileged control of routing, authentication or management infrastructure.
ComponentCisco IOS XR control-plane libraries and command handling, the tac_plus authentication process, and trusted Linux management hosts.
MechanismPurpose-built components altered logging and command-output behaviour, captured routed traffic, injected credential-collection code into TACACS+ processing and established disguised Linux persistence.
ImpactThe actor could observe trusted traffic, collect administrative credentials, establish covert connectivity and reduce the reliability of logs and administrative inspection.
DetectionLook for unexplained GRE interfaces without corresponding commit history, missing logs or SNMP traps, unexpected packet captures or FTP traffic, TacTap file indicators, zabbix_agent.service anomalies, /opt/.ICEauthority and inconsistencies between live state and independently collected telemetry.
MitigationIsolate and rebuild affected infrastructure from trusted images, remove unauthorised components, rotate exposed credentials, restrict management-plane reachability and export telemetry to protected external collectors; no vulnerability-specific patch was identified.
Exploitation status

Compromise was documented in an investigated intrusion, but no vulnerability-specific active exploitation or public proof-of-concept was identified and initial router access remains unknown.

The investigation began by testing whether the headline described exploitation of a disclosed Cisco vulnerability or a broader infrastructure intrusion. The available reporting supports a real incident involving router, TACACS+ and Linux implants, while earlier Mandiant research independently corroborates closely matching UNC3886 targeting and credential-theft tradecraft. No CVE, public exploit or affected-version range could be tied to the 2026 router compromise, and the inaccessible primary report plus unresolved initial-access path limit the conclusion to medium confidence.

  1. What event and timeline does the supplied story describe?
    Read the complete supplied article and its reported technical details.
    thehackernews.com ↗

    The article describes components planted in 2025 and reused in 2026 across Cisco IOS XR routers, a TACACS+ server and Linux management hosts, with traffic collection, credential theft and telemetry suppression.

    why This established that the focused event was an observed multi-system intrusion rather than disclosure of a specific Cisco vulnerability.

  2. Could the incident-response firm's primary account be verified directly?
    Opened the linked Sygnia research page.
    sygnia.co ↗

    The page existed but presented an automated security-verification challenge, preventing direct review of its substantive report content.

    why Because the primary account could not be read directly, detailed incident claims remain dependent on the accessible secondary report and confidence cannot be high.

  3. Does independent research support the proposed UNC3886 overlap and router-focused tradecraft?
    Reviewed Mandiant's investigation of UNC3886 compromises of Juniper routers.
    cloud.google.com ↗

    Mandiant documented custom router backdoors, disabled logging, long-term persistence and targeting of end-of-life network infrastructure by UNC3886; it also stated that this activity had no identified technical overlap with Salt Typhoon or Volt Typhoon.

    why The findings independently support the behavioural overlap while warning against conflating distinct China-nexus clusters.

  4. Was Fire Ant previously associated with vulnerability exploitation?
    Reviewed the July 2025 reporting on Fire Ant's earlier virtualisation campaign.
    thehackernews.com ↗

    The earlier reporting associated Fire Ant with exploitation of VMware and other infrastructure vulnerabilities, including CVE-2023-34048 and CVE-2023-20867, before movement into network appliances.

    why Those CVEs provide historical campaign context but are not evidence that the 2026 IOS XR compromise used the same vulnerabilities, so they were excluded from related_cves.

  5. Are TACACS+ credential theft and the named rootkits consistent with established UNC3886 activity?
    Reviewed Mandiant's detailed 2024 UNC3886 intrusion analysis.
    cloud.google.com ↗

    Mandiant documented UNC3886 extracting TACACS+ credentials with LOOKOVER, replacing tac_plus, and using the REPTILE and MEDUSA rootkits for persistence, evasion and credential collection.

    why This independently corroborates the reported authentication-server focus and malware overlap, but similarity alone does not prove that UNC3886 conducted the Fire Ant intrusion.

ActorsFire AntUNC3886
MalwareTacTapBridgeAgentLOOKOVERREPTILEMEDUSA
TargetsCisco IOS XR routersTACACS+ authentication serversLinux management and jump hostsvirtualisation infrastructurehigh-value and critical-infrastructure networks

Research coverage

All 73 registered source leaves were evaluated for this run: 63 completed, 0 were unavailable, 3 failed and 7 were disabled. For this story, 1 registered sources supplied useful evidence (1 primary, 0 corroborating, 0 contextual and 0 PoC/exploit references). 62 completed sources contained no matched information for this story.

Primary evidence Independent corroboration Operational context PoC reference Checked — no match Unavailable Failed Disabled
Complete source-by-source audit 73 sources
SourceRun resultValueWhy it was useful — or not
The Hacker Newsnews ok7 records Primary evidence1 matched items Published the source report used to frame and date the event.
AlienVault OTXdark_web failed0 records Failed The current collection attempt failed; this source cannot support the report.
BleepingComputernews ok10 records Checked — no match The source completed, but none of its retained records matched this story.
CERT-EU Threat Intelligencenews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
CIRCL CVEcve ok30 records Checked — no match The source completed, but none of its retained records matched this story.
CISA Alertsnews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
CISA KEVkev ok1687 records Checked — no match The source completed, but none of its retained records matched this story.
Cisco PSIRTvendor_advisory ok5333 records Checked — no match The source completed, but none of its retained records matched this story.
Cisco Talosnews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
deepdarkCTI CVE most exploiteddeepdarkcti ok94 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI Discorddeepdarkcti ok7 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI exploitsdeepdarkcti ok24 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI forumsdeepdarkcti ok264 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI malware as a servicedeepdarkcti ok7 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI malware samplesdeepdarkcti ok3 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI marketsdeepdarkcti ok127 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI phishingdeepdarkcti ok19 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI ransomware gangsdeepdarkcti ok689 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI RATsdeepdarkcti ok1 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI Telegram infostealerdeepdarkcti ok130 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI Telegram threat actorsdeepdarkcti ok1013 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI Twitter threat actorsdeepdarkcti ok39 records Checked — no match The source completed, but none of its retained records matched this story.
Exploit-DBexploit_reference ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
FIRST EPSSepss ok8075 records Checked — no match The source completed, but none of its retained records matched this story.
Fortinet PSIRTvendor_advisory disabled Disabled Disabled in the source registry; no check was attempted.
GitHub topic: cveresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
GitHub topic: exploitresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
GitHub topic: penetration-testingresearch failed0 records Failed The current collection attempt failed; this source cannot support the report.
GitHub topic: pocresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
GitHub topic: vulnerabilityresearch failed0 records Failed The current collection attempt failed; this source cannot support the report.
GreyNoiseexploit_reference ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
KrebsOnSecuritynews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
LinkedIn RSS proxy feeds (disabled)research disabled Disabled Disabled in the source registry; no check was attempted.
MalwareBazaardark_web ok9 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #cveresearch ok20 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #cybersecurityresearch ok17 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #exploitresearch ok20 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #infosecresearch ok20 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #malwareresearch ok20 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #ransomwareresearch ok19 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #threatintelresearch ok5 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #vulnerabilityresearch ok19 records Checked — no match The source completed, but none of its retained records matched this story.
Metasploit module metadataexploit_reference ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Microsoft MSRCvendor_advisory ok1591 records Checked — no match The source completed, but none of its retained records matched this story.
Microsoft Securitynews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
MISP Galaxyresearch ok3 records Checked — no match The source completed, but none of its retained records matched this story.
MISP threat actor galaxyactor ok0 records Checked — no match The source completed, but none of its retained records matched this story.
NVDcve ok900 records Checked — no match The source completed, but none of its retained records matched this story.
Palo Alto Networks PSIRTvendor_advisory ok25 records Checked — no match The source completed, but none of its retained records matched this story.
ProjectDiscovery nuclei templatesexploit_reference ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Rapid7news ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Reddit r/AskNetsec (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/cybersecurity (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/malware (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/netsec (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/ReverseEngineering (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
SANS ISCnews ok1 records Checked — no match The source completed, but none of its retained records matched this story.
SentinelLabsnews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Shadowserver public aggregate honeypot observationsexploit_reference ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Shodanresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Sigma Rulesresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Sophos IOCsresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Sophos X-Opsnews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
The DFIR Reportnews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
ThreatFoxthreat_intelligence ok100 records Checked — no match The source completed, but none of its retained records matched this story.
UK NCSCnews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Unit 42news ok1 records Checked — no match The source completed, but none of its retained records matched this story.
Unit42 IOCsresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
URLhausdark_web ok10 records Checked — no match The source completed, but none of its retained records matched this story.
VirusTotal Community IOC enrichmentresearch ok4 records Checked — no match The source completed, but none of its retained records matched this story.
VulnCheck KEVkev ok500 records Checked — no match The source completed, but none of its retained records matched this story.
Vulnerability Lookupcve ok30 records Checked — no match The source completed, but none of its retained records matched this story.
WeLiveSecuritynews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Additional verified pages 13 opened outside the registered collection
Analysis & research4
China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs thehackernews.com ↗

Reports the 2025–2026 Cisco IOS XR, TACACS+ and Linux management-host intrusion investigated by Sygnia.

Ghost in the Router: China-Nexus Espionage Actor UNC3886 Targets Juniper Routers cloud.google.com ↗

Independently documents UNC3886 targeting routers with custom malware, log suppression and long-term persistence.

Cloaked and Covert: Uncovering UNC3886 Espionage Operations cloud.google.com ↗

Documents UNC3886 credential theft from TACACS+, use of LOOKOVER, and deployment of REPTILE and MEDUSA.

Fire Ant Exploits VMware Flaws to Compromise ESXi Hosts and vCenter Environments thehackernews.com ↗

Provides historical context for the earlier Fire Ant activity against virtualisation and network infrastructure.

More security news Captured reporting without a full research report
reported on 31/08/26

North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales

North Korean threat actors tied to the DPRK have expanded their fraudulent remote job scheme beyond IT roles into healthcare, sales, and marketing positions at companies including an Australian healthcare firm and an unnamed financial services organization. The yearslong campaign uses stolen or forged identities, VPNs such as Astrill, proxies like IPRoyal, and hardware including PiKVM and Guermok USB capture cards to mask locations and enable remote work while funding nuclear and missile programs. Specific cases include three suspected workers flagged in February 2026 at the healthcare company and incidents in August 2026 involving PiKVM installation followed by USB attachment plus a sales hire onboarded 13 days prior. Huntress conducted the investigations and noted the actors often perform legitimate work after hiring. The activity is tracked under names including Famous Chollima, Jasper Sleet, Nickel Tapestry, PurpleDelta, UNC5267, and Wagemole.

Why it matters

Defenders must address insider hiring risks rather than external breaches, requiring stronger pre-employment identity checks and monitoring for anomalous hardware, VPN patterns, and connection behaviors that enable funding of prohibited programs.

Source-researched news report

The single supplied source from the_hacker_news aggregates Huntress findings on three specific cases and technical indicators while listing multiple campaign aliases and the scheme's funding purpose.

Key facts

  • DPRK actors have secured roles in healthcare, sales, and marketing using forged documents and proxies beyond traditional IT positions.
  • February 2026 case at Australian healthcare company involved three employees connecting via Astrill VPN and IPRoyal Proxy with fraudulent identity documents.
  • August 2026 financial services case detected PiKVM installation on a device followed by Guermok USB capture card attachment for webcam streaming in tools like Zoom.
  • Sales and marketing hire in August 2026 appeared to use a stolen or borrowed identity and accessed SendGB for a modified GitHub profile image.
  • Scheme relies on remote laptop farms and is attributed to groups tracked as Famous Chollima, Jasper Sleet, Nickel Tapestry, PurpleDelta, UNC5267, and Wagemole.
  • Actors are described as often completing legitimate work after fraudulent hiring, complicating detection.

Evidence gaps

  • Only one source is available (the_hacker_news article dated Aug 31, 2026), with no independent corroboration from other outlets.
  • Source text is truncated mid-sentence in the description of the third case, leaving full details unknown.
  • Exact scope of affected companies, total number of placements, and current operational status of the identified workers remain unspecified.
  • Whether the medical and sales cases represent isolated detections or broader expansion is not quantified.
1 sources reviewed · the_hacker_news
reported on 31/08/26

Berlin confirms data theft after Rhysida ransomware attack claims

Berlin's city administration has confirmed a ransomware attack and data theft by the Rhysida ransomware gang, which publicly claimed the intrusion on August 28, 2026, after the attack was first discovered in mid-August. The threat actor claims to have exfiltrated 5.79 TB of data comprising approximately 1.44 million files, including government records, plaintext credentials, personnel files, classified material, and critical-infrastructure security assessments for Berlin's water supply. Mayor Kai Wergner publicly stated the city will not pay the ransom, and the State Criminal Police Office, public prosecutor's office, and federal security agencies have opened investigations. Forensic investigators believe data exfiltration from the Senate Department for Mobility, Transport, Climate Protection and the Environment occurred between approximately August 7 and 12, with affected departments disconnected from the state network on August 14. Rhysida is using GDPR liability as additional extortion leverage, issuing a four-day payment deadline before threatening to publish the stolen files.

Why it matters

The alleged theft of plaintext credentials, password vaults, senior-official account data, and critical-infrastructure security assessments for a major European capital's water supply represents a significant national-security and public-safety risk beyond typical ransomware data exposure. Defenders in public-sector and critical-infrastructure environments should treat Rhysida as an active, capable threat actor with demonstrated ability to exfiltrate large volumes of sensitive data before detection.

Source-researched news report

All reported details derive from a single BleepingComputer article dated August 31, 2026, which blends official statements from Berlin's mayor and forensic investigators with unverified claims made directly by the Rhysida threat actor on their leak site. Because there is only one source, no independent corroboration exists for the specific data-volume figures, file categories, or the characterization of material as classified.

Key facts

  • Rhysida ransomware gang publicly claimed the Berlin attack on August 28, 2026, with the intrusion discovered in mid-August and exfiltration estimated between August 7–12.
  • The threat actor claims to have stolen 5.79 TB of data (~1.44 million files) including government, legal, financial, HR, and health records, as well as allegedly classified Bundesrat committee documents.
  • Stolen data reportedly includes plaintext credentials, password vaults, payment-system data, and credentials belonging to senior Berlin officials.
  • Critical-infrastructure security assessments for Berlin's water supply and more than 3,200 NDA documents are among the claimed exfiltrated materials.
  • Mayor Kai Wergner confirmed Berlin will not pay the ransom; multiple law-enforcement and federal security agencies are now investigating.
  • Rhysida has been active since mid-2023 and has a documented pattern of targeting healthcare, state governments, education, and critical infrastructure.

Evidence gaps

  • Only a single source (BleepingComputer) covers this story; no independent corroboration of specific claims is available.
  • The source article is truncated, cutting off Senator Iris Spranger's statement, which may contain additional official details or clarifications.
  • The full scope and authenticity of the exfiltrated data have not been independently verified; the 5.79 TB and file-count figures are attacker claims.
  • Whether any of the alleged classified government material or water-supply security assessments has been confirmed as genuine by Berlin authorities is not established in the available reporting.
  • The attack vector and initial access method used by Rhysida have not been disclosed.
  • The outcome of the four-day extortion deadline and whether data has been published is unknown at time of reporting.
1 sources reviewed · bleepingcomputer
reported on 31/08/26

Cronos blockchain restarts after $74 million Tectonic exploit

The Cronos blockchain halted operations following a price-manipulation attack on the Tectonic DeFi lending protocol that enabled an attacker to borrow $74 million by inflating the TONIC token price 100 times over 20 minutes. The attacker extracted roughly $6 million in Ethereum while the remainder remained stuck on the chain. Cronos performed a validator-consensus halt to freeze transactions, then restored the chain state to pre-exploit conditions and restarted block production on 2026-08-30 at 23:49:01 UTC from block 90,896,189. Tectonic, previously holding $122 million in total value locked, saw TVL drop below $3 million. The network is now under monitoring for stability and plans a post-mortem report.

Why it matters

Rapid oracle or collateral-price manipulation on DeFi platforms can trigger large-scale unauthorized borrowing, forcing blockchain operators to execute emergency halts that disrupt all users and require state rollback.

Source-researched news report

The single BleepingComputer report aggregates statements from Cronos and PeckShield describing the exploit, the halt, the state restoration, and the restart timeline without additional independent sources.

Key facts

  • Attacker inflated TONIC token price 100x in 20 minutes to use as collateral for $74 million in borrows on Tectonic.
  • Only approximately $6 million worth of Ethereum was successfully extracted; remaining funds stayed on Cronos.
  • Cronos executed an emergency validator-consensus halt that froze all in-progress transactions.
  • Chain state was restored to the pre-exploit snapshot and block production resumed at 2026-08-30 23:49:01 UTC from block 90,896,189.
  • Tectonic TVL fell from $122 million to under $3 million after the incident.
  • Cronos is an Ethereum-compatible chain linked to Crypto.com; Tectonic was its largest lending protocol at the time.

Evidence gaps

  • Only one source report is available, so all details lack independent corroboration.
  • Exact technical mechanism used to inflate TONIC price and any oracle involvement remain undisclosed.
  • Whether the attacker retains control of additional stuck funds or can extract them later is unknown.
  • Full scope of affected user accounts and any secondary losses beyond the reported $6 million are not specified.
  • Identity of the threat actor and potential links to prior incidents are not reported.
1 sources reviewed · bleepingcomputer
reported on 31/08/26

Microsoft warns of TerminalFix attacks deploying reverse tunnels

Microsoft warned of TerminalFix, a ClickFix variant that uses fake Cloudflare CAPTCHA prompts on compromised websites to trick users into running malicious PowerShell commands via Windows Terminal. The multi-stage chain downloads a ZIP containing a signed executable and malicious DLL, then uses steganography in PNG images to assemble payloads in memory before establishing persistence. A custom Python reverse-tunnel module connects outbound to gitnow[.]dev:443 over WebSocket, enabling SOCKS5-style access to internal resources such as domain controllers and databases. Microsoft observed the activity in the wild but reported no hands-on attacker operations at the time of the warning. The report is dated August 31, 2026 and highlights risks of lateral movement, credential theft, or ransomware.

Why it matters

Defenders must monitor for unusual PowerShell or Windows Terminal executions triggered by web prompts and outbound WebSocket connections that could proxy internal network access, as this bypasses common ClickFix mitigations and provides attackers with reconnaissance and pivoting capabilities.

Source-researched news report

The single bleepingcomputer article reports Microsoft's findings on the TerminalFix attack chain, technical components including steganography and the Python reverse tunnel, and potential post-compromise actions while adding context on how the ClickFix variant differs from prior campaigns.

Key facts

  • TerminalFix differs from typical ClickFix by directing victims to Windows Terminal or PowerShell to run complex multi-line scripts.
  • The chain uses a fake CAPTCHA to place a command in the clipboard, downloads a ZIP with signed EXE and malicious DLL, then retrieves payloads hidden via steganography in three PNG images.
  • Persistence is maintained through a scheduled task and Registry Run key configured to run every hour.
  • The malware performs reconnaissance including probes for domain controllers, databases, backup servers, and Active Directory enumeration.
  • The reverse-tunnel component connects to gitnow[.]dev:443 over encrypted WebSocket and supports SOCKS5-style TCP proxying to internal hosts.
  • Microsoft discovered the attacks in the wild but did not observe hands-on activity.

Evidence gaps

  • Only a single source report from bleepingcomputer is available, with no independent corroboration from other outlets.
  • Exact scope of victims, duration of the campaign, and volume of infections remain unknown.
  • No specific start date for the observed attacks or details on any targeted organizations are provided.
  • The report is truncated and does not confirm whether the reverse-tunnel multiplexing feature was fully observed in operation.
1 sources reviewed · bleepingcomputer
reported on 31/08/26

Microsoft Exchange Online outage causes email failures, auth issues

Microsoft is investigating a widespread service issue causing authentication issues, connection problems, email delays and failures for Microsoft 365 customers. The incident was first acknowledged at 5:30 PM UTC under tracking ID EX1464935 and later linked to a broader report MO1465074. Impact extends beyond Exchange Online to OneDrive for Business, SharePoint Online, Microsoft Teams, Microsoft Purview, and Microsoft Defender XDR. Microsoft isolated a common failure pattern tied to authentication and protocol connectivity while analyzing telemetry and assessing scope. Downdetector indicated tens of thousands of Outlook and Microsoft 365 users affected.

Why it matters

Disruptions to email delivery, authentication, and Microsoft 365 services can impair security operations, threat monitoring, and incident response workflows for organizations reliant on these platforms.

Source-researched news report

The single BleepingComputer report draws from Microsoft's admin center updates and Downdetector user reports to describe symptoms and ongoing investigation without additional independent sources.

Key facts

  • Incident first acknowledged at 5:30 PM UTC under EX1464935.
  • Symptoms include email send/receive delays or failures, mailbox search issues, authentication errors, and admin experience difficulties.
  • Broader incident MO1465074 affects OneDrive for Business, SharePoint Online, Teams, Purview, and Defender XDR.
  • Tens of thousands of users reported issues via Downdetector.
  • Microsoft identified failure pattern associated with authentication and protocol connectivity.
  • Prior Exchange Online outages noted in June and April.

Evidence gaps

  • Only a single source report is available, limiting independent corroboration.
  • Specific regions impacted have not been disclosed.
  • Root cause remains unidentified and remediation timeline is unknown.
  • Full scope of affected scenarios continues to be assessed.
1 sources reviewed · bleepingcomputer
reported on 31/08/26

OpenAI confirms ChatGPT outage as users report errors

OpenAI confirmed a partial outage affecting ChatGPT Work starting at approximately 11:04 AM ET on August 31, 2026. The incident caused elevated latency and errors, preventing users from starting or continuing tasks. Plus subscribers were particularly impacted as Work mode became unavailable for some. OpenAI acknowledged the issues on its status page and stated it was working on a mitigation. As of 12:02 PM ET, the outage remained ongoing.

Why it matters

Security teams using ChatGPT Work for analysis or task automation may encounter workflow interruptions from the elevated errors and latency. Dependence on the service creates potential single points of failure during incidents.

Source-researched news report

The single BleepingComputer report details OpenAI's status page updates confirming the ChatGPT Work outage and mitigation efforts without additional independent sources.

Key facts

  • Outage began around 11:04 AM ET on August 31, 2026.
  • Impacted ChatGPT Work with elevated errors and latency.
  • Plus users particularly affected with Work mode unavailable.
  • OpenAI working on mitigation as of 12:02 PM ET.
  • Affects users across multiple subscription plans.
  • Acknowledged by OpenAI on status page.

Evidence gaps

  • Only one source report available, limiting independent corroboration.
  • Cause of the outage not specified.
  • Duration until full resolution unknown.
  • Exact number or distribution of affected users not detailed.
1 sources reviewed · bleepingcomputer
reported on 31/08/26

Chinese Fire Ant hackers turn Cisco routers into spying platforms

Chinese Fire Ant threat actors compromised Cisco IOS XR routers to convert them into spying platforms via custom malware and concealed GRE tunnels. Sygnia researchers identified the activity after discovering an unexplained active GRE tunnel interface on a router that lacked corresponding configuration or commit history. The attackers deployed malware providing persistence through a fake system service active only in alternating hours, suppressed syslog messages, established outbound Telnet connections, and captured router traffic for upload to external FTP servers. This enabled reconnaissance from a connected legacy Linux staging server into high-value connected networks, including critical infrastructure systems, using ports for SSH, web services, SMB/RPC, and RDP. The operation reflects a shift from prior VMware hypervisor targeting to Cisco routers, TACACS servers, and Linux management hosts under a 'target behind the target' approach.

Why it matters

Compromised routers become covert collection points for internal traffic, topology, and authentication data, enabling undetected pivots into trusted partner or critical infrastructure networks. Defenders should prioritize detection of anomalous GRE interfaces, unexplained traffic captures, and selective logging suppression on Cisco IOS XR devices.

Source-researched news report

The single bleepingcomputer article presents Sygnia researchers' findings on Fire Ant's router compromises, GRE tunnel usage, traffic capture, and reconnaissance into connected networks. No additional outlets or independent sources are referenced in the supplied reporting.

Key facts

  • Sygnia identified an active GRE tunnel on a Cisco IOS XR router unexplained by running configuration or commit history.
  • Custom malware on routers used a fake system service for persistence, activating the implant only during alternating hours.
  • Malware suppressed syslog messages to conceal tunnel details, supported interactive shells without logging, and enabled outbound Telnet to attacker infrastructure.
  • Attackers captured traffic from multiple routers and uploaded PCAP files to external FTP servers.
  • A concealed GRE tunnel linked a compromised router to a legacy Linux server used for staging and probing connected high-value environments.
  • The tactic focused on using initial trusted infrastructure compromises as bridges to explore access paths into associated critical infrastructure networks.

Evidence gaps

  • Only one source report is available, limiting independent corroboration of the claims.
  • Initial access vectors, exact timeline of compromise, and duration of the operation are not specified.
  • Specific victims, total number of affected routers or organizations, and full scope of compromised networks remain unknown.
  • Technical details on malware deployment method, indicators of compromise, and any defensive responses are absent.
1 sources reviewed · bleepingcomputer
reported on 31/08/26

File servers are here to stay. Here’s how to manage them securely

An article published August 31, 2026 on BleepingComputer states that organizations continue using on-premises file servers alongside SaaS due to cloud costs, data sovereignty, risk ownership, and legacy needs. It describes hybrid setups as a way to retain control over retention, backups, and access. The piece stresses that effective access governance remains essential regardless of storage location. It begins listing best practices for administrators, opening with the rule against assigning permissions directly to users.

Why it matters

Untracked direct permissions on file servers create persistent access risks that defenders must address through group-based governance to limit exposure in hybrid environments.

Source-researched news report

The single bleepingcomputer source argues that file servers will remain relevant and supplies initial guidance on permission management while noting practical tracking difficulties.

Key facts

  • File servers persist in many organizations because of concerns over subscription costs, data ownership, and regulatory requirements.
  • Hybrid on-premises and SaaS setups are presented as common for preserving control over cost, risk, retention, backups, and access.
  • Recommendation is to grant directory access only via dedicated single-purpose security groups using consistent naming such as fs_finance_read.
  • Direct user permissions cannot be easily tracked because they appear only in folder properties rather than user group memberships.
  • The article is marked as sponsored by Tenfold Software.

Evidence gaps

  • Only one source report is available, from bleepingcomputer, so no independent corroboration exists.
  • The supplied text is truncated after the first best-practice point, leaving the full list and any promoted solutions unknown.
  • No specific incidents, CVEs, timelines of attacks, or quantified affected scope are reported.
1 sources reviewed · bleepingcomputer
reported on 31/08/26

Securing Claude Code: The New Compliance API, Local Visibility, and Identity Governance

Anthropic introduced new Compliance API endpoints, including local session transcript endpoints, to give security teams visibility into Claude Code activities as of August 2026. Claude Code functions as a local agent on developers' machines that reads files, runs shell commands, invokes MCP tools, and uses available credentials. The article notes that local agents account for 68.6% of AI agents found in customer environments by Token Security and often inherit employee permissions. Prior to these API updates, native controls provided limited visibility, pushing reliance on third-party extensions. The piece contrasts the cloud-based LLM with the local harness component that executes actions and connects externally.

Why it matters

Defenders must shift monitoring and controls to endpoints because local AI agents bypass centralized SaaS consoles while inheriting user credentials and network access.

Source-researched news report

The single the_hacker_news source presents Anthropic's new Compliance API as an improvement for local visibility while stressing that activity logs alone cannot confirm legitimate access and that local harnesses require endpoint-level governance.

Key facts

  • Anthropic added local session transcript endpoints to its Compliance API for governing Claude Code activity.
  • Local agents comprise 68.6% of AI agents discovered by Token Security in customer environments.
  • A Token-commissioned Cloud Security Alliance survey of 418 professionals found 68% rated AI agent visibility as high while 82% had discovered previously unknown agents.
  • Claude Code runs on developer endpoints via a harness that executes commands and connects to MCP servers, separate from the cloud LLM.
  • Before August 2026, Anthropic's native controls offered limited visibility into local agent behavior.

Evidence gaps

  • Only one source report is available, preventing independent corroboration of any claims.
  • Real-world effectiveness, adoption rate, or limitations of the new Compliance API endpoints are not quantified.
  • Survey results and local-agent percentage originate from Token Security and Cloud Security Alliance without additional verification in the supplied text.
1 sources reviewed · the_hacker_news
reported on 31/08/26

Microsoft says Windows 11 KB5120998 update resets mouse settings

Microsoft confirmed that the optional non-security preview update KB5120998 for Windows 11 versions 24H2 and 25H2, released August 27 2026, is causing mouse cursor personalization settings to reset or revert to standard values. User reports describe high-DPI cursors being replaced by larger white ones, custom animations reverting, and appearance regressions with intermittent changes. Affected users are unable to restore previous customizations after the update installs. Microsoft stated it is investigating the root cause and directed impacted customers to submit reports through the Feedback Hub. The update also includes improvements to the Start menu, taskbar, and Windows search but must be manually downloaded unless automatic update options are enabled.

Why it matters

This post-update regression can disrupt user productivity and accessibility configurations on Windows 11 endpoints, requiring defenders to track optional update deployments and potential rollback needs to maintain consistent system behavior.

Source-researched news report

The single BleepingComputer report presents Microsoft's direct statements acknowledging user-submitted issues with KB5120998 alongside details on the update's release date, optional nature, and content.

Key facts

  • KB5120998 is an optional non-security preview update released August 27 2026 for Windows 11 24H2 and 25H2 that includes Start menu, taskbar, and search improvements.
  • Microsoft acknowledged receiving reports that the update changes or reverts mouse cursor personalization settings to standard values.
  • Reported effects include high-DPI cursors replaced by larger white cursors, custom animations reverting, appearance regressions, and intermittent animation changes.
  • Users cannot successfully restore previous cursor customizations after the settings revert.
  • Microsoft is investigating the root cause and recommends affected users file reports via the Feedback Hub.

Evidence gaps

  • Only one source report is available, so independent corroboration cannot be established.
  • Exact scope of affected devices, total number of impacted users, and specific Windows 11 builds beyond 24H2/25H2 remain unknown.
  • Root cause has not been identified and no fix timeline or workaround has been provided.
  • Whether the issue affects all installations of KB5120998 or only certain hardware configurations is unclear.
1 sources reviewed · bleepingcomputer
reported on 31/08/26

Microsoft asks users to ignore 'Antivirus is turned off' errors

Microsoft has directed users to disregard false 'Microsoft Defender Antivirus is turned off' notifications that appear after installing recent Defender updates. The issue has impacted Windows Insider Release Preview Channel users since June and was publicly addressed by Microsoft in a late August release health dashboard update. It affects all supported Windows client and server versions, including Windows 11 26H1 and Windows Server 2025. Notifications display in the Windows Security app on startup and intermittently afterward, persisting even when notification settings are disabled. Microsoft stated it is developing a fix for release in a future Microsoft Defender Antivirus update.

Why it matters

False alerts may generate unnecessary user or admin actions, contributing to alert fatigue and potential distraction from actual security events on Windows systems.

Source-researched news report

The single bleepingcomputer report presents Microsoft's official explanation along with examples of prior similar false-alert incidents, without additional outlets contributing further details or contradictions.

Key facts

  • Microsoft advised ignoring erroneous Defender Antivirus turned off alerts after latest updates, confirming the service remains active and functional.
  • Issue has affected Release Preview Channel users since June and was acknowledged in an August 31, 2026 dashboard update.
  • Problem impacts every supported Windows client and server version, including Windows 11 26H1 and Windows Server 2025.
  • Notifications appear at Windows startup and intermittently, continuing regardless of notification settings.
  • Microsoft is preparing a fix to be delivered via a future Defender Antivirus update.
  • Similar false-alert issues occurred after prior 2025 updates involving WinRE, BitLocker, Firewall, and CertEnroll errors.

Evidence gaps

  • Only one source report (bleepingcomputer) is available, preventing independent corroboration of details or scope.
  • Exact date when the issue began affecting production users outside the Insider program is unspecified.
  • No timeline or release date provided for the planned fix.
1 sources reviewed · bleepingcomputer

Confirmed exploited · CISA KEV New KEV additions

CISA KEV additions from the last 72 hours without a corresponding news story above. Full catalogue available in the Data Hub.