Geek-Guy.com

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 108

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter TAG-195 Upgrades MaaS Ecosystem with Modular Tools  Inside a DPRK BlueNoroff ClickFix Kit SourTrade: Browser-Assembled Malware Delivered Through Malvertising   MedusaHVNC: A Hidden Desktop That Steals Live Windows Sessions   Unpacking “Cruciferra”: An Analysis of a…

Security Affairs newsletter Round 588 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens Adobe fixed a maximum-severity vulnerability flaw in…

Week in review: Claude breached three companies during tests, AD CS domain-takeover PoC released

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Nono: Open-source sandbox for AI agents AI coding agents run with the same permissions as their users, meaning they can access sensitive files, credentials, and production systems. A prompt injection, hallucinated command, or simple mistake can quickly turn that access…

CISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota Attacks

After attacks hit 30+ Minnesota water systems, CISA urged utilities to remove internet-exposed PLCs and strengthen OT security. Between Sunday and Monday, July 26 and 27, a coordinated cyberattack hit operational technology (OT) systems at more than 30 community water utilities across the state, according to Minnesota IT Services (MNIT). “A coordinated cyberattack targeted operational technology…

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS…

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute…

Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites

Attackers modified a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses. Adform detected the incident on July 27, 2026, removed the malicious code, notified affected clients, and reported it to authorities. Anyone who visited a site carrying the affected script on July 27 and…

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could…

South Korea Warns of State-Backed Watering Hole Attacks

South Korea warned that nation-state actors are using phishing and compromised websites to silently infect citizens and businesses. South Korea agencies (The National Intelligence Service, the National Police Agency, the Korea Internet & Security Agency, and the Financial Security Institute) jointly published an advisory warning that a state-backed hacking group is actively targeting South Korean…

Claude published malicious code to the Internet and attacked 3 real companies

Anthropic said its Claude-based security models gained unauthorized access to the sensitive production environments of three outside organizations during internal testing designed to measure the models’ offensive cyber capabilities. The events, which Anthropic revealed Thursday, are the second revelation in 10 days that AI models from the world’s wealthiest providers have trespassed into protected networks,…

Anthropic Says Claude Found New Attacks on HAWK and Reduced-Round AES

AI is beginning to do more than find software vulnerabilities. Anthropic says its Claude Mythos Preview model has now contributed new techniques for analyzing the mathematics behind cryptographic systems. The model developed an improved attack against the post-quantum signature candidate HAWK and accelerated an existing line of attack against a seven-round version of AES-128, according…

Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world

Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world

President Donald Trump blamed Minnesota Friday for the cyberattacks its water systems have suffered in recent days, saying the state was “behind it.” Trump said the state being “incompetent” was the issue, but it wasn’t clear whom he thought actually conducted cyberattacks that U.S. investigators have attributed to Iran — if, perhaps, somehow Minnesota incompetently…

AI Ransomware Raises Stakes for Cyber Recovery

Artificial intelligence is changing ransomware at a pace many enterprises are struggling to match. While most cybersecurity conversations continue to center on preventing attacks, the growing sophistication and speed of AI-enabled ransomware is forcing organizations, and the channel partners that support them, to rethink cyber resilience from the standpoint of recovery. AI expands the ransomware…

HIPAA Security Rule on AWS – Technical Safeguards Implementation and Readiness Guidance

Today, we’re releasing the HIPAA Security Rule on AWS: Technical Safeguards Implementation and Readiness Guidance. This helps covered entities and business associates configure, implement, and evidence compliance with the HIPAA Security Rule Technical Safeguard requirements (45 CFR §164.312) when building healthcare workloads on AWS. The HIPAA Security Rule’s Technical Safeguards (§164.312) define five standards and…

Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk

A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, since January 2025. These targeted organizations operate across several sectors, such as healthcare, research, government offices,

South Korea Fines KT $37.4M for Failing to Stop Long-Running Network Intrusion

South Korea’s Personal Information Protection Commission (PIPC) has fined KT Corp. 53.9 billion won ($37.4 million) after finding that weak network access controls allowed hackers to expose the personal information of 16,647 mobile customers. The regulator said hackers accessed KT’s wireless network through an unauthorized femtocell, a small base station used to extend mobile coverage,…

HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka. According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing message containing a link to an encrypted archive, which holds a Windows Shortcut (LNK). Executing the file triggers a multi-stage chain that

Intel 471 Warns of Expanding Software Supply Chain Attacks 

Software supply chain attacks are evolving beyond compromised software packages into attacks targeting the people, identities, and workflows used to build and distribute software.  Intel 471’s report, Poisoned Trust: How Supply Chain Attacks Weaponize Developer Ecosystems, found that threat actors are increasingly targeting developer accounts, CI/CD pipelines, repositories, IDEs, and publishing infrastructure.  By compromising these…

5 Best MDR Services for Businesses and MSPs in 2026

Managed detection and response services give organizations access to 24/7 threat monitoring, investigation, and incident response without requiring them to build a complete security operations center. They combine security technology, automation, and human expertise to help organizations identify and contain threats more efficiently. We evaluated five leading MDR providers for 2026 based on threat coverage,…

Enterprise ERP AI Adoption Outpaces Security Readiness 

Organizations are rapidly embedding artificial intelligence (AI) into enterprise resource planning (ERP) systems, but many cybersecurity leaders remain unconvinced that their organizations are prepared to secure these environments.  According to the 2026 Onapsis State of AI, Security, and ERP report, AI adoption is accelerating across SAP, Oracle, and Salesforce environments even as concerns about security,…