Visualização normal

Antes de ontemFirewall Daily – The Cyber Express

The Cyber Express Weekly Roundup: Exploited Entra ID Flaw, AI Agent Risks, and Global Cybercrime Crackdown

28 de Agosto de 2026, 08:17

The Cyber Express weekly roundup, podcast

This weekly roundup highlights a broad range of cybersecurity and technology developments affecting cloud identity infrastructure, social media platforms, businesses, digital assets, and international law enforcement.   From a critical Microsoft Entra ID vulnerability exploited before remediation to a global crackdown on West African cybercrime networks, recent developments demonstrate how attackers continue to target both technical systems and human trust.  The latest developments also show that cybersecurity risks are expanding alongside the rapid adoption of cloud services and artificial intelligence. Organizations are facing threats involving identity infrastructure, autonomous AI agents, software vulnerabilities, digital transactions, online fraud, and the misuse of emerging technologies. 

The Cyber Express Weekly Roundup 

Microsoft Confirms Exploited Entra ID Flaw 

Microsoft confirmed that a critical vulnerability in Entra ID, CVE-2026-69836, was exploited before the flaw was fixed server-side. The vulnerability carries a CVSS score of 10.0 and could allow unauthenticated attackers to achieve remote code execution, potentially affecting Microsoft’s cloud-based identity infrastructure. Read more... 

New Zealand Proposes Social Media Ban for Under-16s 

New Zealand has introduced legislation that would require high-risk social media platforms to prevent users under the age of 16 from accessing their services. Proposed age-verification methods could include digital identification, facial age estimation, or official identification documents. Read more... 

Cyble and DRONA Launch AI Cyber Defense Initiative in India 

Cyble and DRONA Cyber Solutions have launched an AI-powered cybersecurity initiative in Ahmedabad aimed at helping mid-sized businesses detect, investigate, and contain cyber threats. The initiative combines threat intelligence, AI-driven investigations, and endpoint enforcement to provide organizations with faster and more coordinated responses to security incidents. Read more... 

AI Agents Could Create New Cybersecurity Risks 

Adarsh Kant Sinha, CEO of ANVE.AI, warned that autonomous AI agents could introduce significant new cybersecurity risks as organizations increasingly allow them to interact with business-critical systems. AI agents may gain access to email, customer relationship management platforms, cloud infrastructure, and financial systems, potentially creating new avenues for misuse or compromise. Read more... 

Ledger Fixes Ethereum App Flaw Amid Disclosure Dispute 

Ledger said it fixed a clear-signing vulnerability in its Ethereum application approximately two weeks before security firm TestMachine publicly disclosed the issue. The vulnerability could potentially allow a malicious application to display one transaction to a user while preparing a different transaction for signing. Read more... 

Global Crackdown Nets 58 Arrests in West African Crime Networks 

An eight-month international law enforcement operation led by INTERPOL has resulted in 58 arrests and the identification of 263 suspects across 22 countries. Operation Jackal IV targeted West African criminal networks involved in cyber-enabled fraud, money laundering, romance scams, and investment scams. Read more... 

Weekly Cybersecurity Takeaway 

This week’s developments demonstrate that cybersecurity threats are crossing organizational, technological, and geographical boundaries, affecting cloud identity systems, artificial intelligence, digital platforms, cryptocurrency applications, and international financial crime.  Organizations should prioritize strong identity and access controls, rapid vulnerability remediation, careful management of AI-agent permissions, secure integrations, human oversight, and continuous threat monitoring.   As autonomous technologies become more deeply integrated into business operations and cybercriminal networks continue to operate across borders, security teams must adapt to a threat landscape that is becoming broader, more interconnected, and increasingly difficult to contain. 

The Cyber Express Weekly Roundup: Ransomware Surge, Government Data Breaches, Logistics Disruptions, and Third-Party Security Risks

The Cyber Express weekly roundup H1

This weekly roundup highlights the growing cybersecurity risks affecting businesses, government agencies, and critical service providers. From the continued dominance of ransomware operations to government database breaches and third-party supply chain incidents, recent events demonstrate how attackers are increasingly targeting trusted systems and external service providers to maximize disruption and data exposure.  The latest developments reinforce that cyber threats are no longer limited to direct attacks on organizations. Threat actors are exploiting ransomware-as-a-service ecosystems, compromising government registries, targeting law enforcement databases, and abusing third-party platforms that support retail and healthcare operations.   Organizations must strengthen third-party risk management, improve data protection measures, and enhance incident response capabilities to reduce the impact of evolving cyber threats. 

The Cyber Express Weekly Roundup 

Qilin Dominated Ransomware Attacks in H1 2026 

Qilin emerged as the most active ransomware group during the first half of 2026, targeting organizations worldwide through its ransomware-as-a-service (RaaS) operation. Manufacturing, healthcare, construction, and professional services were among the sectors most affected as the group continued expanding its global reach. Read more… 

Hackers Breach Beneficial Owners Registry, Expose Data of 31,000 Firms 

Hackers breached the Register of Beneficial Owners (VwbP), gaining unauthorized access to data associated with approximately 31,000 legal entities. Authorities temporarily took the registry offline, launched an investigation, and established a crisis response team, stating there is currently no evidence that records were altered or deleted. Read more… 

PNLD Data Breach Leaks Police and Government Contact Details 

A data breach involving the Police National Legal Database (PNLD) exposed names, organizations, and work email addresses belonging to police officers, government partners, criminal justice professionals, and some Ask the Police users after the information appeared on the dark web. Authorities are investigating the incident and assessing its potential impact. Read more… 

De Bijenkorf Logistics Cyberattack Delays Orders and Raises Data Exposure Concerns 

A cyberattack targeting a third-party logistics provider disrupted deliveries, returns, and refunds for Dutch retailer De Bijenkorf. While the retailer confirmed its internal systems were not compromised, investigators are assessing whether customer contact details and order information were exposed. Payment information, passwords, and financial data were not affected, and customers have been advised to remain vigilant against phishing attempts. Read more… 

Updoc Data Breach Exposes Customer Contact Information 

Australian telehealth provider Updoc disclosed a data breach after unauthorized access to a third-party operational platform exposed some customers' names, email addresses, and postal addresses. The company confirmed that its internal systems remained secure and that no medical records, payment information, or financial data were compromised. Read more… 

Weekly Cybersecurity Takeaway 

This week's incidents highlight the continued evolution of cyber threats across ransomware operations, government data breaches, and third-party supply chain compromises.  A common theme across these events is the growing risk posed by trusted third-party platforms and shared digital ecosystems. Attackers are targeting external service providers, government databases, and ransomware affiliate networks to expand their reach and maximize operational disruption.  Organizations should prioritize stronger third-party risk management, continuous monitoring, robust access controls, and timely incident response to reduce the impact of supply chain attacks and data breaches. As businesses become more interconnected, strengthening the security of partner ecosystems is becoming just as important as protecting internal infrastructure. 

The Cyber Express Weekly Roundup: AI Fraud, Data Leaks, Malware Campaigns, and Critical Infrastructure Threats

The Cyber Express weekly Roundup July 2026 new

This weekly roundup highlights the growing complexity of digital threats affecting governments, businesses, developers, and consumers. From artificial intelligence being misused for financial fraud to large-scale customer data exposures, malicious software targeting developer ecosystems, and cyberattacks against critical infrastructure, recent incidents demonstrate how attackers are exploiting both emerging technologies and existing security weaknesses.  The latest developments show that cyber risks are expanding beyond traditional network attacks. Threat actors are targeting identities, trusted platforms, software supply chains, and operational technology environments. Organizations must strengthen security controls, improve monitoring capabilities, and adopt proactive measures to protect sensitive data and critical services. 

The Cyber Express Weekly Roundup 

Four Men Admit to $2.2 Million Medicaid Fraud Scheme Using AI 

Four Minnesota men have pleaded guilty in connection with a Medicaid fraud scheme that allegedly generated approximately $2.2 million through fraudulent claims for housing-related services. Prosecutors stated that artificial intelligence tools, including ChatGPT, were used to create false documentation supporting fraudulent billing activity. Read more... 

Tribeca Data Leak Exposes Celebrity-Linked Information 

A reported data leak connected to the Tribeca Film Festival exposed nearly 666,000 records containing personal information associated with attendees, contacts, and individuals linked to the entertainment industry. The exposed data reportedly included names, email addresses, phone numbers, and limited device-related information. Read more... 

Origin Energy Data Breach Impacts Around 900,000 Customers 

Australian energy company Origin Energy confirmed a data breach affecting approximately 900,000 current and former customers. The exposed information may include customer names, contact details, dates of birth, and partial account information. The company is investigating the incident and has advised customers to remain alert for possible scams or suspicious communications. Read more... 

Joyfill npm Packages Found Distributing DEV#POPPER Malware 

Security researchers discovered that two beta versions of Joyfill npm packages were distributing DEV#POPPER, a remote access trojan (RAT) capable of stealing information, executing commands, and compromising developer environments. Read more... 

Student Accused of IIT Website Breaches Offered Technical Assessment 

A student accused of breaching parts of the IIT Kanpur and IIT Madras websites after being rejected from IIT Kanpur’s cybersecurity program will undergo a technical skills assessment rather than facing immediate legal action. The institute stated that admissions for the current session are closed but indicated that future opportunities may be considered if the student demonstrates strong cybersecurity abilities. Read more... 

FBI Warns of PLC Cyberattacks Targeting U.S. Water Utilities 

The FBI and the U.S. Environmental Protection Agency warned that cyberattacks targeting internet-connected programmable logic controllers (PLCs) have disrupted water utilities across multiple U.S. states. Attackers reportedly manipulated PLC settings, affecting monitoring and operational processes. Read more... 

Weekly Cybersecurity Takeaway

This week’s incidents demonstrate how cyber threats continue to evolve across multiple domains, including artificial intelligence abuse, personal data exposure, software supply chain attacks, and critical infrastructure targeting.  A common theme across these events is the exploitation of trust. Attackers are abusing trusted technologies, legitimate software ecosystems, customer databases, and connected infrastructure to achieve their objectives.  Organizations must focus on building cyber resilience through stronger identity protection, secure development practices, continuous monitoring, and effective incident response planning.  As emerging technologies such as artificial intelligence and connected industrial systems become more widespread, cybersecurity strategies must evolve alongside them. Protecting digital assets requires not only stronger technical defenses but also responsible for technology use, awareness, and proactive risk management. 

One Country Absorbed Nearly Half of the World’s Ransomware Attacks in Just Six Months – The United States

24 de Julho de 2026, 02:09

Ransomware Attacks, Qilin, US, Ransomware Attacks on US

Strip away the geopolitics, the hacktivist noise, and the espionage headlines, and one number from the first half of 2026 stands out above everything else: 1,721. That's how many ransomware attacks hit organizations in the United States between January and June, according to new research from Cyble Research and Intelligence Labs (CRIL). It's not just the highest total of any country tracked in the report — it's more than the next nine most-targeted countries combined.

Canada, in second place worldwide, recorded 179 attacks. Germany logged 155. The United Kingdom, 138. Add up the rest of the global top 10 — France, Italy, Spain, Thailand, India and Brazil — and the total still falls more than 600 attacks short of the U.S. figure alone. Out of 3,836 ransomware attacks CRIL tracked worldwide this half, roughly 45% landed on American soil.

Also read: Fairlife Ransomware Attack Hits Production Systems, U.S. Operations Suspended

A Single Region, an Outsized Share

Widen the lens slightly and the picture holds. North America as a whole recorded 1,981 ransomware attacks in H1 2026 — more than half of every ransomware incident Cyble observed globally — alongside 35 data breach and leak incidents and 9 initial access sale listings. The report describes the region as home to "a mature, persistently active RaaS ecosystem operating at high volume across a wide range of industries and geographies."

Two ransomware-as-a-service operators did much of the damage. Qilin, the single most prolific gang worldwide, claimed 370 of those North American attacks on its own — nearly 19% of the regional total. Akira followed with 268, and INC Ransom added another 164. Together, Qilin and Akira alone accounted for more than half of all recorded ransomware activity across the region, a level of concentration that points to a small number of highly organized affiliate networks doing the bulk of the damage rather than a diffuse swarm of opportunists.

Also read: Qilin Ransomware Group’s TTPs Examined by Researchers

Where the Pressure Lands

Professional Services bore the brunt of North American ransomware activity, with INC Ransom showing a marked preference for law firms and other high-value services with sensitive client data. Construction, Manufacturing and Healthcare followed close behind.

One operator, AiLock, stood out for a coordinated wave of victim disclosures that all landed on the same day — March 3 — a pattern consistent with a mass-exploitation campaign rather than isolated intrusions. LockBit, despite years of law enforcement pressure and takedown attempts, kept up a steady tempo against public-sector and educational targets throughout the period, showcasing how difficult the group has been to fully dismantle.

On the data breach side, Technology and financial services (BFSI) were the most frequently targeted sectors in North America, together accounting for roughly 43% of incidents — a reflection of how much intellectual property and monetizable personal data those industries hold.

Notably, Agriculture & Livestock emerged as a significant target for initial access brokers, accounting for a third of all access listings tied to the region. Cyble flags this as a sign of "growing risk in the food supply chain," an area that has historically drawn less attention from ransomware operators than finance or healthcare.

The initial access market itself was strikingly concentrated: two sellers, tracked under the handles "redpin" and "xpl0itrs," accounted for nearly all listings targeting North American organizations. Threat actors also continued to lean on known and zero-day vulnerabilities in widely deployed enterprise platforms — including products from Ivanti and Palo Alto Networks — as their preferred way into corporate networks.

Hacktivism Blurs into Cybercrime

North America wasn't spared the hacktivism wave sweeping the rest of the world either. Collectives including SOLDADOS DIGITALES – UNIÓN AMERICANA and LYSTIC TEAM #ID drove roughly 56 data leak or dump posts and touched about 360 unique domains across the region, with Government, Technology, financial services and telecommunications entities most frequently in the crosshairs.

Cyble's broader findings suggest many groups marketing themselves as ideologically driven hacktivists are, in practice, running side businesses in stolen data brokerage and DDoS-for-hire services — a blurring of motive that complicates how defenders triage the threat.

The scale of the U.S. numbers doesn't necessarily mean American companies have weaker defenses than their global peers — the concentration also reflects the sheer size and digital density of the U.S. economy, and its outsized share of the high-value targets ransomware affiliates chase. But the data does argue for a shift in posture.

Cyble's broader recommendations — treating data exfiltration, not just encryption, as the primary risk; prioritizing patches for the recurring vendor list; and monitoring initial access markets as a leading indicator rather than an afterthought — apply nowhere more urgently than in a country absorbing this much of the world's ransomware volume on its own.

  • ✇Firewall Daily – The Cyber Express
  • Vishing Call Becomes Key Lead in Massive Odido Cyberattack Samiksha Jain
    The investigation into the Odido cyberattack has uncovered possible involvement of Dutch nationals, according to Dutch police, as authorities continue to investigate the ShinyHunters ransomware-linked attack that exposed the personal data of approximately 6.39 million customers. Law enforcement has urged the public to come forward with information as investigators work to identify those responsible for one of the country's largest telecom data breaches. The cyberattack took place on February 5
     

Vishing Call Becomes Key Lead in Massive Odido Cyberattack

Odido cyberattack

The investigation into the Odido cyberattack has uncovered possible involvement of Dutch nationals, according to Dutch police, as authorities continue to investigate the ShinyHunters ransomware-linked attack that exposed the personal data of approximately 6.39 million customers. Law enforcement has urged the public to come forward with information as investigators work to identify those responsible for one of the country's largest telecom data breaches.

The cyberattack took place on February 5 and 6 after attackers allegedly used voice phishing (vishing) to deceive Odido's customer service team.

According to the company, the attackers posed as members of its internal IT staff, gaining unauthorized access before exfiltrating customer data. Odido said its teams detected the unauthorized access immediately on both occasions and revoked the attackers' access, but the incident still resulted in a large-scale data breach.

Odido Cyberattack Investigation Finds Possible Dutch Link

Under the direction of the National Public Prosecution Service, the High Tech Crime Team (THTC) of the National Investigation and Intervention Unit launched an extensive investigation into the breach.

Authorities said investigators have found strong indications that Dutch criminals may have been involved. One key lead centers on a phone call made shortly before the breach in which a Dutch-speaking man allegedly impersonated an Odido IT employee while speaking with customer service representatives. Police are continuing efforts to identify the caller and have indicated that his voice could be made public if necessary.

Investigators believe people within cybercrime circles may have information about those responsible and are encouraging anyone with relevant details to contact law enforcement.

ShinyHunters Named as Threat Actor

Odido attributed the attack to the cybercriminal group ShinyHunters, which the company said carried out the social engineering campaign.

Chief Executive Officer Søren Abildgaard acknowledged the incident in a public statement, apologizing to customers and outlining the company's commitment to strengthening its cybersecurity capabilities. He said Odido would continue investing in security, improve data protection practices, expand customer support, and share lessons learned from the incident.

The CEO also explained why the company refused to pay the ransom demand. According to Odido, paying cybercriminals would reward illegal activity and could encourage future attacks against other Dutch organizations. The company said the decision was made following guidance from authorities, despite knowing that stolen data could eventually be published.

Millions of Customers Impacted

Odido confirmed that approximately 6.39 million active and former customers of Odido and its Ben brand were affected by the breach. Customers of Simpel were not impacted.

The exposed information varied by individual and included names, addresses, mobile phone numbers, customer numbers, email addresses, IBAN numbers, dates of birth, identification details, nationality, and gender.

The company clarified that My Odido account passwords, call records, location data, billing information, and scans of identity documents were not compromised.

Odido also addressed reports claiming customer passwords had been leaked, stating that login passwords remain securely encrypted and were never accessible during the attack. Instead, a separate telephone verification field known as "password_c," used as a customer challenge code, was included for a limited number of customers. The company has since discontinued using that verification method.

Customer Support and Security Measures Expanded

Following the breach, Odido increased customer support by adding more than 140 service agents and introduced additional security measures. These include its "Check je Gesprek" verification service, allowing customers to confirm whether communications claiming to be from Odido are legitimate, along with access to the F-Secure digital security service.

The telecom provider said all customers identified as affected have been notified by email or SMS, while customer service teams continue assisting users with questions related to their specific data exposure.

Meanwhile, Dutch authorities expect investigations into the Odido cyberattack to continue for several months. Police have also warned that cyberattacks targeting businesses and institutions are becoming increasingly common, urging organizations to strengthen cybersecurity defenses and encouraging citizens to remain vigilant against follow-on fraud and phishing attempts.

  • ✇Firewall Daily – The Cyber Express
  • Belarus-Linked UNC1151 Launches Gmail Phishing Campaign to Steal 2FA Codes Samiksha Jain
    The UNC1151 Gmail phishing campaign has emerged as a cyber threat targeting Polish internet users, with attackers now focusing on Gmail accounts and deploying phishing pages capable of stealing both passwords and two-factor authentication (2FA) credentials. According to researchers at CERT Polska, the campaign marks a notable evolution in the tactics of the Ghostwriter-linked threat group, which has spent years targeting email users across Poland. Also tracked as Ghostwriter and Storm-0257, U
     

Belarus-Linked UNC1151 Launches Gmail Phishing Campaign to Steal 2FA Codes

UNC1151 Gmail Phishing Campaign

The UNC1151 Gmail phishing campaign has emerged as a cyber threat targeting Polish internet users, with attackers now focusing on Gmail accounts and deploying phishing pages capable of stealing both passwords and two-factor authentication (2FA) credentials. According to researchers at CERT Polska, the campaign marks a notable evolution in the tactics of the Ghostwriter-linked threat group, which has spent years targeting email users across Poland. Also tracked as Ghostwriter and Storm-0257, UNC1151 has been linked by cybersecurity researchers to Belarusian state intelligence services and has remained active against Polish targets since Russia's full-scale invasion of Ukraine.

UNC1151 Gmail Phishing Campaign Expands Target Scope

For years, UNC1151 primarily targeted users of popular Polish email providers including Onetpasswords, Wirtualna Polska, and Interia. Since March 2026, however, the group has shifted its attention to Gmail users, launching high-volume phishing operations that run almost daily during weekdays. CERT Polska researchers said the attackers target a wide range of individuals, including politicians, public officials, researchers, journalists, law enforcement personnel, government employees, and people connected to them through professional, family, or social relationships. [caption id="attachment_112742" align="aligncenter" width="600"]UNC1151 Gmail Phishing Campaign Image Source: CERT Polska[/caption] The group also conducts campaigns against specific professional sectors and geographic regions. In some cases, phishing emails are sent to unintended recipients because attackers attempt to guess email addresses based on names and affiliations.

How the UNC1151 Gmail Phishing Campaign Works

The UNC1151 Gmail phishing campaign relies on fraudulent emails designed to resemble official Gmail security notifications. The messages often warn recipients about suspicious account activity, unauthorized login attempts, or alleged violations of service policies. Victims are urged to act quickly to avoid account suspension or permanent deletion. The emails are typically sent from Gmail accounts created specifically for phishing operations, although attackers occasionally use compromised accounts to increase credibility. Common subject lines include warnings about security alerts, suspicious activity, and account verification requirements. Embedded links direct recipients to fake Gmail login pages that closely imitate Google's legitimate authentication portal. Once users enter their credentials, attackers capture both usernames and passwords.

2FA Credential Theft Marks Key Evolution

One of the most concerning developments in the campaign is its ability to harvest two-factor authentication theft credentials. Unlike earlier phishing campaigns targeting Polish email services, the latest operation includes additional prompts requesting verification codes after login credentials have been entered. If a victim's account is protected by 2FA, the phishing page automatically displays a form requesting the authentication code. This enables attackers to steal both SMS-based verification codes and codes generated through applications such as Google Authenticator. Researchers noted that attackers frequently continue targeting the same victims even after unsuccessful login attempts. Multiple phishing emails may be delivered within days to increase pressure and improve the chances of credential theft. [caption id="attachment_112735" align="aligncenter" width="600"]UNC1151 Gmail Phishing Campaign Source: CERT Polska[/caption]

Ghostwriter Phishing Infrastructure Continues to Evolve

The campaign relies on a constantly changing phishing infrastructure. According to CERT Polska, operators use domains registered specifically for phishing activities, often leveraging top-level domains such as .icu, .digital, and .top. The group also abuses hosting platforms such as Netlify by creating deceptive subdomains that imitate account verification services. Examples of domains observed in the campaign include mailverify.digital, verify-check.digital, monitoring-google-konta.netlify.app, and service-auth.netlify.app. In addition, attackers host fake login panels on compromised websites belonging to legitimate organizations. Rather than replacing the main website, the phishing content is hidden within the compromised infrastructure, allowing attacks to remain undetected for extended periods.

Gmail Phishing Attacks Signal Broader Threat

Security researchers warn that the increase in Gmail phishing attacks demonstrates UNC1151's continued ability to adapt its tactics while maintaining its long-standing objective of gaining access to email accounts. Once access is obtained, attackers search for sensitive documents, contact lists, and linked services, including social media accounts that can be further compromised. Stolen contacts may also be used to identify additional targets for future phishing campaigns. Although the group's recent focus has shifted toward Gmail, researchers caution that attacks against users of Polish email providers have not disappeared entirely. The findings highlight the growing sophistication of state-linked phishing operations and reinforce the importance of scrutinizing login requests, verifying website domains, and protecting accounts with strong authentication practices. As the UNC1151 Gmail phishing campaign continues to evolve, cybersecurity experts expect further adaptations designed to bypass defenses and increase the success rate of credential theft operations.

ServiceNow Flaw Prompted Security Update After Researcher-Observed Activity, Not Active Attacker Exploitation

ServiceNow flaw

A recently disclosed ServiceNow flaw led to an emergency security update after unusual activity was identified in customer environments. While early reports suggested that unknown threat actors had exploited the vulnerability, ServiceNow has clarified that the observed activity originated from security researchers and customer security teams, not malicious actors. The issue, first widely discussed on Reddit, triggered concern across the cybersecurity community after evidence emerged showing that certain queries against ServiceNow instance data were possible under specific conditions. However, ServiceNow has now confirmed that no data was used or retained in a malicious manner. The company stated that the vulnerability affected certain customer configurations and could, in limited scenarios, allow an unauthenticated user to gain elevated access beyond intended permissions.

ServiceNow Flaw and Security Update Deployment

ServiceNow released a security update on June 5, 2026, addressing the issue across hosted customer environments.

“On June 5, 2026, ServiceNow applied a security update to hosted customer instances. The update concerned a security issue that could allow an unauthenticated user, in certain circumstances, to gain greater access to ServiceNow instances than intended.”

To reduce the risk associated with the ServiceNow flaw, the company modified endpoint configurations to ensure access is restricted to authenticated users only. At the time of disclosure, the issue had not yet been assigned a CVE identifier.

The vulnerability initially surfaced through Reddit discussions, where users raised concerns about potential exposure and questioned the internal response timeline.

No Evidence of Attacker Exploitation, Says ServiceNow

ServiceNow has clarified that there is no evidence of active exploitation by threat actors. Instead, the company said it identified unusual activity linked to research testing and customer-led investigations. According to ServiceNow, a subset of customer instances was queried during this activity, but the activity was not malicious in nature. The company also emphasized that affected customers were directly notified and provided with remediation guidance.

Scope of the ServiceNow Flaw and Affected Customers

The issue primarily impacted customers using the Australia platform release and some instances running pre-Australia configurations with specific changes.

“The security issue pertains to customers who are on the Australia platform release or made certain configuration changes to instances on releases prior to Australia.”

ServiceNow stressed that the incident was limited in scope and not a systemic issue affecting its entire customer base.

A company spokesperson reiterated that communication efforts focused on a small subset of impacted customers rather than a broad population.

Community Discussion and Reddit Timeline Questions

The ServiceNow flaw also sparked debate on Reddit regarding disclosure timelines and internal awareness.

One user, “d3s7iny,” claimed their security team had previously reported the vulnerability and alleged that ServiceNow had known about the issue since April 7, 2026. The post suggested the issue had been treated as non-urgent and scheduled for a later fix.

While these claims circulated widely online, they remain unverified and have not been confirmed by ServiceNow.

Bug Bounty Reports and Early Disclosure Signals

ServiceNow’s advisory confirmed that multiple bug bounty submissions were received shortly before the patch was released.

Between June 3 and June 4, 2026, customers reported a potential security issue through bug bounty channels that aligned with earlier internal findings.

The company also referenced a confidential report submitted on April 22, 2026, which described similar behavior affecting instance data access under specific conditions.

These overlapping reports contributed to the eventual identification and remediation of the ServiceNow flaw.

Clarification on Researcher Activity and Final Response

ServiceNow has since issued a public clarification, stating that the observed activity came from security researchers and customer investigation teams, not from malicious exploitation.

An official notification is available on the company’s trust portal: https://trust.servicenow.com/notifications/1205429e-fea3-4cbf-b37b-8cd3a4e07aef

The company emphasized that no customer data was retained or misused during the process and that the vulnerability was addressed through a targeted security update.

  • ✇Firewall Daily – The Cyber Express
  • Miasma Malware Targets Red Hat npm Packages in New Supply Chain Attack Ashish Khaitan
    A newly discovered software supply chain campaign, dubbed Miasma, has emerged as the latest evolution of the Shai-Hulud supply chain attack, compromising several redhat-cloud-services npm packages to steal credentials, harvest secrets from developer systems, and spread through development environments using worm-like behavior. Security researchers at Socket described the operation as a smaller but highly capable successor to earlier Shai-Hulud campaigns, noting that it employs many of the sam
     

Miasma Malware Targets Red Hat npm Packages in New Supply Chain Attack

Miasma

A newly discovered software supply chain campaign, dubbed Miasma, has emerged as the latest evolution of the Shai-Hulud supply chain attack, compromising several redhat-cloud-services npm packages to steal credentials, harvest secrets from developer systems, and spread through development environments using worm-like behavior. Security researchers at Socket described the operation as a smaller but highly capable successor to earlier Shai-Hulud campaigns, noting that it employs many of the same techniques that made previous attacks effective against software development ecosystems.
"This is effectively a Mini Shai-Hulud campaign: it uses the same core tactics of install-time execution, credential harvesting, CI/CD targeting, encrypted exfiltration, and potential downstream propagation," Socket said.

Attribution Remains Unclear as TeamPCP Tools Continue to Circulate

The identity of the threat actor behind the latest Shai-Hulud supply chain attack remains uncertain. One major reason is the role of TeamPCP, a well-known cybercrime group that previously open-sourced tools associated with the original Shai-Hulud worm. By publicly releasing those resources, TeamPCP lowered the barrier for other attackers to launch similar operations, making attribution significantly more difficult. Researchers have not yet linked the Miasma campaign to any specific actor with confidence.

Affected redhat-cloud-services Packages

The attack targeted multiple packages published under the redhat-cloud-services namespace. The known compromised packages include:
  • @redhat-cloud-services/vulnerabilities-client
  • @redhat-cloud-services/tsc-transform-imports
  • @redhat-cloud-services/topological-inventory-client
  • @redhat-cloud-services/sources-client
  • @redhat-cloud-services/rule-components
  • @redhat-cloud-services/remediations-client
  • @redhat-cloud-services/rbac-client
The malicious code embedded within these packages was designed to execute during installation, allowing attackers to collect sensitive information from infected developer environments.

Encrypted Data Theft and GitHub-Based Propagation

Similar to earlier waves of the Shai-Hulud supply chain attack, the malware incorporates encrypted exfiltration capabilities. Stolen information is transmitted to the endpoint "api.anthropic[.]com:443/v1/api," while GitHub serves as a secondary communication and propagation channel. According to Socket, the malware can commit encrypted data packages directly through GitHub's API.
"It commits the encrypted result envelope through the GitHub API," Socket said. "The commit message can include: IfYouInvalidateThisTokenItWillNukeTheComputerOfTheOwner:."
Researchers from OX Security identified the first commit containing the phrase "Miasma: The Spreading Blight" on May 29, 2026. This suggests either that the malware variant had already been active by that date or that attackers began testing the campaign around that time.

GitHub Abuse Enables Verified Malicious Commits

The Miasma malware actively searches for repositories where stolen GitHub tokens possess write permissions. It then inspects action.yml and action.yaml files using GraphQL queries before injecting malicious workflows through GitHub's createCommitOnBranch mutation. This technique allows the resulting commits to appear as legitimate, verified, and signed changes, increasing the likelihood that malicious modifications will evade scrutiny. The malware is also capable of performing several additional actions, including:
  • Attempting privilege escalation by launching containers that bind-mount the host's /etc/sudoers.d directory and grant passwordless sudo access to CI runners.
  • Detecting endpoint protection products such as CrowdStrike, SentinelOne, Carbon Black, and StepSecurity Harden-Runner before executing malicious activities.
  • Establishing persistence by modifying Anthropic Claude Code through a SessionStart hook.
  • Creating Visual Studio Code tasks.json files configured with "runOn": "folderOpen" to ensure automatic execution whenever a project is opened.

Red Hat GitHub Account Believed to Be Initial Entry Point

Investigators believe the campaign originated from the compromise of a Red Hat employee's GitHub account. Evidence indicates that the account served as the patient zero event used to inject malicious code into the affected redhat-cloud-services packages. The compromised account reportedly pushed malicious orphan commits into two RedHatInsights repositories, allowing the attacker to bypass normal code review procedures and introduce the malicious payload.

Recommended Response and Remediation Steps

Security experts advise organizations that installed affected redhat-cloud-services package versions to immediately isolate impacted systems and remove compromised releases. Additional recommendations include:
  • Rotating all potentially exposed credentials.
  • Reviewing GitHub and npm activity for suspicious behavior.
  • Auditing environments for persistence mechanisms.
  • Investigating modifications to configuration files such as:
    • ~/.claude/settings.json
    • .vscode/tasks.json
    • .github/workflows/codeql.yml
    • .github/setup.js
  • Enforcing stronger access controls across development environments.
Socket warned that removing the malicious package alone is not sufficient.
"Because the malware includes background execution and potential developer-tool persistence mechanisms, uninstalling the npm package or deleting node_modules should not be considered sufficient cleanup," Socket explained.
The company also urged organizations operating CI/CD pipelines to suspend affected workflows, invalidate any build artifacts created during the exposure period, and review whether software releases, container images, npm packages, or deployment artifacts were generated after installation of the malicious package.
  • ✇Firewall Daily – The Cyber Express
  • Threat Actors Target Critical Windows Netlogon Flaw CVE-2026-41089 Ashish Khaitan
    A critical Windows Netlogon vulnerability, tracked as CVE-2026-41089, has emerged as a significant security concern after authorities warned that threat actors are actively attempting to exploit the flaw to gain remote code execution capabilities on vulnerable systems.  The security issue, which carries a CVSS severity score of 9.8, was publicly disclosed on May 12, 2026, when Microsoft addressed it alongside 136 other vulnerabilities as part of its monthly Patch Tuesday security updates.
     

Threat Actors Target Critical Windows Netlogon Flaw CVE-2026-41089

CVE-2026-41089

A critical Windows Netlogon vulnerability, tracked as CVE-2026-41089, has emerged as a significant security concern after authorities warned that threat actors are actively attempting to exploit the flaw to gain remote code execution capabilities on vulnerable systems.  The security issue, which carries a CVSS severity score of 9.8, was publicly disclosed on May 12, 2026, when Microsoft addressed it alongside 136 other vulnerabilities as part of its monthly Patch Tuesday security updates. While several of the bugs fixed during that release were identified as likely candidates for exploitation, CVE-2026-41089 was not initially included among those expected to be targeted by attackers. 

Threat Actors Reportedly Exploiting CVE-2026-41089 

The Centre for Cybersecurity Belgium (CCB) issued a warning on Friday, stating that threat actors have begun exploiting the critical Windows Netlogon vulnerability in real-world attacks. The agency urged organizations to deploy available security updates immediately to reduce the risk of compromise.  According to the CCB, the flaw is “now actively exploited in the wild,” raising concerns that attackers may already be targeting unpatched systems. The organization noted that successful exploitation could allow remote attackers to execute arbitrary code with System-level privileges, providing extensive control over affected environments.  Despite the warning, no additional public reports have surfaced confirming exploitation attempts involving CVE-2026-41089. Furthermore, Microsoft has not updated its advisory to indicate that active attacks have been verified. 

How the Windows Netlogon Vulnerability Works 

Microsoft’s advisory describes CVE-2026-41089 as a stack-based buffer overflow vulnerability affecting the Netlogon service. The flaw can be triggered through specially crafted network requests sent to a Windows server operating as a domain controller.  Importantly, the vulnerability can be exploited by unauthenticated attackers, meaning no valid credentials or prior access to the targeted environment are required.  Microsoft explained the risk in its advisory, stating:  “If successful, this could cause the Netlogon service to improperly handle the request, potentially allowing the attacker to run code on the affected system without needing to sign in or have prior access.”  Because the flaw enables remote code execution and does not require authentication, security experts consider CVE-2026-41089 one of the more dangerous vulnerabilities addressed during the May 2026 Patch Tuesday release. 

Why the Netlogon Service Remains a High-Value Target 

The Netlogon service plays a critical role in Windows domain-based environments by handling authentication processes between users, computers, and domain controllers. As a core background service, it is essential to maintain secure communication and identity verification across enterprise networks.  Historically, weaknesses in Netlogon have attracted the attention of threat actors because successful exploitation can provide access to highly privileged systems. Critical flaws affecting the service can potentially allow attackers to gain control over a domain controller and, by extension, influence or compromise connected machines throughout the network.  Given the importance of the service, security professionals have long viewed any severe Windows Netlogon vulnerability as a high-priority issue requiring rapid remediation. Regardless of the differing assessments, security experts recommend that organizations prioritize patching CVE-2026-41089 as soon as possible.   The combination of its critical severity rating, the potential for unauthenticated remote code execution, and reports of activity by threat actors makes the vulnerability a significant risk for organizations operating Windows domain environments. 
  • ✇Firewall Daily – The Cyber Express
  • Megalodon Supply Chain Attack Hits 5,500+ GitHub Repositories in Six Hours Ashish Khaitan
    A large-scale software supply chain attack dubbed “Megalodon” has compromised more than 5,500 repositories on GitHub, raising fresh concerns about the growing abuse of automated development pipelines and GitHub Actions workflows. The incident, uncovered by SafeDep, involved thousands of malicious commits that injected credential-stealing payloads into repositories over a short period of time.  According to researchers, the Megalodon campaign targeted repositories through automated commits tha
     

Megalodon Supply Chain Attack Hits 5,500+ GitHub Repositories in Six Hours

Megalodon

A large-scale software supply chain attack dubbed “Megalodon” has compromised more than 5,500 repositories on GitHub, raising fresh concerns about the growing abuse of automated development pipelines and GitHub Actions workflows. The incident, uncovered by SafeDep, involved thousands of malicious commits that injected credential-stealing payloads into repositories over a short period of time.  According to researchers, the Megalodon campaign targeted repositories through automated commits that inserted malicious GitHub Actions workflows capable of harvesting sensitive credentials, cloud access keys, API tokens, and other secrets stored within continuous integration and continuous delivery (CI/CD) environments. 

Thousands of Malicious GitHub Actions Commits Detected Within Hours 

The attack unfolded on May 18, 2026, when attackers pushed more than 5,700 malicious commits across thousands of repositories within six hours. SafeDep’s investigation found that a total of 5,718 commits were deployed between approximately 11:36 UTC and 17:48 UTC, affecting 5,561 distinct GitHub repositories.  Researchers said the Megalodon operation relied heavily on GitHub Actions to establish persistence and silently collect sensitive information from infected development environments. The attackers deployed two separate payloads as part of the campaign. One payload introduced a new GitHub Actions workflow configured to run on every push and pull request. The second payload replaced existing workflows tied to specific triggers, effectively creating dormant backdoors that could later be activated remotely.  The malicious commit associated with the infection was reportedly authored by a user identified as “build-bot” and pushed on May 18. During its investigation into the linked email address, the researchers uncovered 2,878 commits made on the same day. Researchers also identified another 2,841 commits tied to a second email address connected to the operation.  Researchers noted that all 5,718 commits tied to the Megalodon campaign landed within the same six-hour timeframe, indicating a highly coordinated and automated attack strategy. The scale and speed of the operation highlighted how threat actors are weaponizing GitHub Actions and software development workflows to distribute malicious code at scale. 

Megalodon Malware Targeted CI/CD Secrets and Cloud Credentials 

On compromised systems, the malware attempted to exfiltrate a broad range of sensitive data. According to researchers, the stolen information included CI environment variables, AWS credentials, Google Cloud Platform access tokens, Azure credentials, SSH private keys, Docker and Kubernetes configuration files, database connection strings, GitHub Actions tokens, GitLab CI/CD tokens, API keys, and numerous other secrets commonly stored in development pipelines.  Another significant concern raised by researchers involved the attackers’ use of the “workflow_dispatch” feature within GitHub Actions. According to researchers, the malicious workflow leveraged this trigger mechanism to establish dormant backdoors that could later be activated through the GitHub API using stolen GitHub tokens.  Researchers explained that the “workflow_dispatch” mechanism is exempt from GitHub’s anti-recursion protections, which normally prevent workflows from spawning additional workflow runs through GitHub token-triggered events. This loophole potentially allowed attackers to reactivate compromised workflows even after the initial breach. 

Searchers Links Megalodon Campaign to Compromised Open-Source Packages 

The researchers discovered the Megalodon campaign after identifying malicious versions of the Tiledesk package, an open-source live chat and chatbot platform. The infected packages were reportedly published between May 19 and May 21, shortly after the malicious commits were introduced into the source repositories.  In its analysis, SafeDep stated that the same NPM account, “eljohnny” using the email address giovanni@tiledesk.com, had published both the legitimate version 2.18.5 and the compromised versions of the package. Researchers emphasized that the attacker did not directly compromise the NPM account itself.  “The attacker never touched the NPM account. They compromised the GitHub repository, and the maintainer published from the poisoned source without realizing it,” SafeDep explained.  The Megalodon incident emerged shortly after NPM announced new security measures aimed at limiting similar supply chain attacks. Last week, NPM invalidated all granular access tokens with write permissions that bypassed two-factor authentication protections. The move was intended to reduce the risk of attacks resembling the earlier Mini Shai-Hulud campaign.  However, cybersecurity researchers warned that token protection alone may not fully address the broader issue of repository compromise and malicious code propagation.  Security company Ox Security stated that while stricter token controls may reduce account hijacking risks, they do not solve the underlying problem of compromised repositories distributing malicious code through trusted development ecosystems.  “If platforms continue allowing any type of code to be uploaded without serious vetting, the number of attacks will only increase,” Ox Security noted.  The company also warned that the Megalodon campaign could represent the beginning of a larger wave of attacks targeting developers and open-source ecosystems globally.  “We’ve entered a new supply chain attack era, and TeamPCP compromising GitHub was only the beginning. What’s coming next is an endless wave, a tsunami of cyber attacks on developers worldwide,” the firm said.
  • ✇Firewall Daily – The Cyber Express
  • GitHub Confirms Cyberattack Targeting Thousands of Internal Repositories Ashish Khaitan
    GitHub confirmed that attackers associated with TeamPCP gained unauthorized access to thousands of the company’s internal code repositories after compromising an employee’s device through a malicious VS Code extension. Despite the scale of the GitHub cyberattack, the Microsoft-owned platform said there is currently no evidence that customer repositories or enterprise data were affected.  The cyberattack on GitHub marks the latest operation linked to TeamPCP, a cybercriminal group that has rap
     

GitHub Confirms Cyberattack Targeting Thousands of Internal Repositories

GitHub cyberattack

GitHub confirmed that attackers associated with TeamPCP gained unauthorized access to thousands of the company’s internal code repositories after compromising an employee’s device through a malicious VS Code extension. Despite the scale of the GitHub cyberattack, the Microsoft-owned platform said there is currently no evidence that customer repositories or enterprise data were affected.  The cyberattack on GitHub marks the latest operation linked to TeamPCP, a cybercriminal group that has rapidly expanded its activity through coordinated attacks on developer-focused platforms and cloud infrastructure.  

Decoding the GitHub Cyberattack 

GitHub publicly acknowledged the incident on Wednesday after TeamPCP allegedly advertised stolen source code on a cybercrime forum. According to the company, the attackers attempted to extort the platform by offering the stolen code for sale at $50,000 and threatening to leak it publicly if no buyer emerged.  [caption id="attachment_112192" align="alignnone" width="717"]GitHub Cyberattack Details Image Source: X[/caption] In a statement shared on X, formerly Twitter, GitHub said:  “We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.”  The company further stated:  “If any impact is discovered, we will notify customers via established incident response and notification channels.”  GitHub said the breach originated after an employee’s system was infected through a poisoned VS Code extension. The company described the incident as “detected and contained,” emphasizing that the compromise was restricted to internal repositories and did not extend to customer-owned data.  As part of its response to the GitHub cyberattack, the company rotated critical credentials on the same day the breach was discovered, prioritizing the most sensitive secrets first. GitHub also acknowledged that TeamPCP’s claim of stealing around 3,800 repositories was “directionally consistent” with the company’s own internal assessment regarding the scope of the intrusion.  The platform hosts code for more than 100 million developers globally, making the cyberattack on GitHub particularly significant within the software development and cybersecurity communities. GitHub said it plans to release a more detailed report once the investigation is complete. 

TeamPCP’s Growing Role in Cloud-Focused Cybercrime 

Cybersecurity researchers at Cyble have identified TeamPCP as a cloud-focused cybercriminal operation that emerged as a large-scale exploitation platform in late 2025. The group is also tracked under several aliases, including DeadCatx3, PCPcat, PersyPCP, and ShellForce.  [caption id="" align="alignnone" width="936"]TeamPCP Image Source: X[/caption] Unlike threat actors that depend heavily on zero-day vulnerabilities, TeamPCP has reportedly built its operations around automation and the exploitation of known weaknesses and cloud misconfigurations. Researchers say the group combines these methods into a scalable and largely self-propagating attack framework.  Beginning in late 2025, TeamPCP launched extensive scanning campaigns targeting exposed Docker APIs, Kubernetes control planes, Ray dashboards, and Redis services. Once access is achieved, compromised systems are integrated into a distributed infrastructure used for proxying internet traffic, performing additional scans, hosting command-and-control infrastructure, deploying ransomware, and conducting unauthorized cryptomining operations. 

Operational Structure Behind the Cyberattack on GitHub 

The operational model used by TeamPCP differs from many conventional cybercriminal campaigns because it prioritizes cloud-native environments over traditional end-user devices. Instead of relying primarily on phishing campaigns against individual users, the group focuses on exposed administrative services and container orchestration platforms.  Researchers observed that TeamPCP attack chains commonly begin with automated internet-wide scanning for externally accessible services that either lack authentication or are improperly secured. This allows the group to scale attacks rapidly across large numbers of organizations without relying on highly customized exploitation techniques.  The GitHub cyberattack appears consistent with the group’s broader strategy of targeting software development environments and cloud infrastructure that can provide access to sensitive operational resources. 

Countries and Industries Impacted by TeamPCP 

Security researchers said TeamPCP activity has been observed across multiple countries, including the United Arab Emirates, Canada, South Korea, Serbia, the United States, and Vietnam. Researchers noted that the group’s targeting pattern appears opportunistic rather than politically motivated, with attacks primarily focused on exposed infrastructure.  Industries affected by TeamPCP operations include Banking, Financial Services, and Insurance (BFSI), consumer goods, and professional services organizations. These sectors often depend heavily on scalable cloud-based systems and internet-facing services, making them vulnerable to automated scanning campaigns, cloud misconfiguration abuse, ransomware deployment, and cryptomining activities. 
  • ✇Firewall Daily – The Cyber Express
  • eBay Struggles with Widespread Outage, Disrupting Transactions and API Access Ashish Khaitan
    The e-commerce platform eBay, a giant in online auctions and fixed-price listings, faced widespread disruptions beginning late Sunday, April 26, 2026, extending into Monday, as users across the globe reported severe technical issues. The eBay outage, which has crippled essential features of the site, particularly the API, has left many buyers and sellers frustrated, struggling to access critical functions, including search features, listings, and checkout processes.  As users faced slow page
     

eBay Struggles with Widespread Outage, Disrupting Transactions and API Access

eBay Outage

The e-commerce platform eBay, a giant in online auctions and fixed-price listings, faced widespread disruptions beginning late Sunday, April 26, 2026, extending into Monday, as users across the globe reported severe technical issues. The eBay outage, which has crippled essential features of the site, particularly the API, has left many buyers and sellers frustrated, struggling to access critical functions, including search features, listings, and checkout processes.  As users faced slow page loads, failed transactions, and difficulty completing sales, a series of unverified reports surfaced suggesting that the hacktivist group 313 Team was behind the massive denial-of-service (DDoS) attack, claiming responsibility for the outage. While the true cause remains unconfirmed by eBay, the timing and scale of the disruption have fueled speculation that a cyberattack was involved. 

The Scope of the eBay Outage 

The eBay outage first began to affect eBay users on the afternoon of April 26, when they began reporting issues with the platform’s functionality. According to Downdetector, a popular service that tracks online outages, the spike in complaints reached around 3:30 PM ET, with the situation worsening the evening. As of 10:30 PM ET, more than 1,300 outage reports were logged, although the number eventually decreased to about 600 by 11:50 PM ET.  Users complained that essential functions like search were malfunctioning, and pages were loading extremely slowly. "I can't even search for anything or complete a purchase," one frustrated user posted on social media. Others echoed similar concerns, noting that critical transactions were unable to be completed, with error messages preventing them from checking out.  Sellers also voiced their frustrations, noting that they could not access the API, which is crucial for the functioning of third-party tools used to manage listings, inventory, and sales. "It’s been nearly 6 hours since the API went down, and we have no word from support," one seller wrote, emphasizing the financial impact of the outage. 

Social Media Users Complain About the Outage

While eBay has not officially confirmed the cause of the outage, rumors quickly began circulating on social media that the hacktivist group 313 Team was responsible for a DDoS attack targeting the platform. DDoS attacks, which flood a website with traffic to overwhelm its servers and take it offline, have become a frequent tactic for hacktivist groups in recent years. The group, which has previously targeted high-profile organizations, allegedly posted a claim on various forums, taking credit for the disruption. However, this attribution has not been independently verified, and eBay has not provided details about the nature of the attack. The company’s official status page displayed no alerts of a cyberattack, showing only minor updates on the system’s functionality.  Despite these official updates, the community’s response has been vocal, with many users continuing to report issues well into the night. One individual posted, "It’s not just down for me, it’s down for everyone. Is this part of a bigger attack targeting e-commerce sites?"  With eBay’s customer support channels largely silent or offering only generic responses, users took to social media to express their frustration. The company’s Instagram account, where many users had previously reached out for help, quickly became a forum for complaints. One commenter wrote, “Brooo you’re down—come on, get up! I need to pay for an auction.” Others left similar messages, questioning the reliability of the platform and demanding answers. 

The Cyber Express Weekly Roundup: Data Breaches, Malware Campaigns, and Cyber Fraud Investigations

weekly roundup TCE cybersecurity news

In this week’s edition of The Cyber Express weekly roundup, we explore the latest developments in the world of cybersecurity, focusing on high-profile data breaches, growing malware campaigns, and law enforcement actions against cybercriminals.   As the digital threat landscape continues to evolve, attackers are targeting sensitive personal and organizational data, from health records to financial credentials. Meanwhile, government regulators are ramping efforts to protect minors and combat harmful content on social platforms, while cybercriminals continue to exploit vulnerabilities in both public and private sectors.  This weekly roundup highlights how various industries, from healthcare and social media to finance and government, are grappling with rising threats, making it clear that the intersection of data security, regulation, and cybercrime is more critical than ever.  

The Cyber Express Weekly Roundup 

UK Biobank Data Breach Triggers Urgent Review of Data Security Measures 

A significant data breach at the UK Biobank has raised major concerns over the security of health-related data used in scientific research. In April 2026, de-identified participant information was discovered being sold on a Chinese consumer platform, sparking widespread alarm among the research community. Read more... 

Vercel CEO Reveals Expansion of Malware Campaign Affecting Multiple Targets 

Vercel's CEO, Guillermo Rauch, confirmed that the recent breach involving Context.ai was part of a much larger malware campaign affecting multiple targets. Following a review of network logs, Vercel’s security team uncovered evidence of malware distribution that compromised several customer accounts, including access to valuable Vercel account keys. Read more... 

Ofcom Investigates Telegram and Teen Platforms 

In the UK, Ofcom has launched an investigation into Telegram and several popular teen chat platforms, such as Teen Chat and Chat Avenue, after reports surfaced of online grooming and child sexual abuse material (CSAM) on these services. Under the Online Safety Act, platforms are required to take proactive steps to prevent harmful content and protect minors from exploitation. Read more... 

Personal Data Exposed in Breach of France’s ANTS Portal 

A recent breach of France’s ANTS (Agence Nationale des Titres Sécurisés) portal has compromised personal data, including names, email addresses, and birthdates, although no documents or sensitive attachments were affected. The breach, which occurred on April 15, 2026, raises significant concerns about identity theft and phishing risks, as the exposed data could be used to target individuals. Read more... 

Bluesky Faces Coordinated DDoS Attack 

Bluesky, the rapidly expanding social media platform, suffered a major disruption on April 15, 2026, when it was targeted by a sophisticated distributed denial-of-service (DDoS) attack. The attack caused widespread outages, impacting core platform functions such as user feeds, notifications, and search capabilities. Read more... 

Indian Authorities Arrest Key SIM Card Supplier in Cyber Fraud Crackdown 

India’s Central Bureau of Investigation (CBI) has arrested a key conspirator in a major cyber fraud operation as part of Operation Chakra-V. The suspect, arrested in Guwahati, is accused of supplying fraudulent SIM cards used in various cybercrime schemes, including extortion and fake loan scams. The SIM cards were acquired using fake identities and distributed to cybercriminal networks. Read more... 

Weekly Takeaway 

This week’s roundup highlights the diverse and evolving nature of cyber threats. From the exposure of sensitive health data and sophisticated malware campaigns to DDoS attacks and SIM card fraud schemes, the cybersecurity landscape remains fraught with challenges. Regulatory bodies and companies alike continue to grapple with emerging risks, particularly in sectors like public health data, social media platforms, and digital content safety. As these incidents unfold, it’s clear that both technical vulnerabilities and human factors, such as social engineering, continue to be central targets for attackers.  With regulatory frameworks like the Online Safety Act and increased investigative efforts in places like India and France, the pressure on platforms and authorities to act quickly and decisively is higher than ever. As the cyber threat landscape becomes more interconnected, the need for enhanced security protocols, improved monitoring, and greater accountability in digital spaces remains critical. 
  • ✇Firewall Daily – The Cyber Express
  • China-Linked Cyber Actors Turn to Massive Covert Botnets to Evade Detection Ashish Khaitan
    A newly issued cybersecurity advisory highlights an evolution in the tactics, techniques and procedures (TTPs) employed by China-Nexus threat actors. The report, released with support from the UK Cyber League and coordinated by the National Cyber Security Centre (NCSC-UK) alongside international partners, sheds light on how Chinese threat actors are relying on large-scale covert networks of compromised devices to conduct malicious cyber operations. A Strategic Shift in China-Nexus TTPs  In rec
     

China-Linked Cyber Actors Turn to Massive Covert Botnets to Evade Detection

China-Nexus

A newly issued cybersecurity advisory highlights an evolution in the tactics, techniques and procedures (TTPs) employed by China-Nexus threat actors. The report, released with support from the UK Cyber League and coordinated by the National Cyber Security Centre (NCSC-UK) alongside international partners, sheds light on how Chinese threat actors are relying on large-scale covert networks of compromised devices to conduct malicious cyber operations.

A Strategic Shift in China-Nexus TTPs 

In recent years, cybersecurity experts have observed a clear transition in China-Nexus TTPs. Rather than relying on dedicated, individually controlled infrastructure, Chinese threat actors are now leveraging expansive networks of compromised devices, commonly referred to as covert networks or botnets. These networks are primarily composed of Small Office/Home Office (SOHO) routers, Internet of Things (IoT) devices, and other internet-connected hardware. According to the advisory, the majority of China-Nexus actors are believed to be using such covert networks, with multiple networks operating simultaneously and often shared among different groups. These networks are continuously updated, making them highly adaptable and difficult to track. Any organization targeted by Chinese threat actors could be affected. For example, the group known as Volt Typhoon has used these covert networks to pre-position cyber capabilities within critical infrastructure, while Flax Typhoon leveraged similar methods for espionage operations.

How Covert Networks Operate 

Although botnets are not new, China-Nexus actors are now deploying them at an unprecedented scale and with strategic intent. These covert networks allow attackers to mask their identity, route malicious traffic through multiple nodes, and reduce the risk of attribution. Typically, an attacker accesses the network via an entry point, or “on-ramp,” and routes activity through numerous compromised devices—called traversal nodes—before exiting near the target. This multi-hop approach obscures the origin of the attack. These networks support every stage of a cyber operation, from reconnaissance and scanning to malware delivery, command-and-control communication, and data exfiltration. They are also used for general browsing, enabling threat actors to research vulnerabilities and refine TTPs without revealing their identity. The presence of legitimate users on some networks further complicates attribution. 

Real-World Examples and Scale 

Evidence suggests that some covert networks used by China-Nexus actors are developed and maintained by Chinese cybersecurity firms. One notable example is the “Raptor Train” network, which infected over 200,000 devices globally in 2024. It was reportedly managed by Integrity Technology Group, a company also linked by the FBI to activities associated with Flax Typhoon. Another example includes the KV Botnet used by Volt Typhoon, which primarily exploited outdated Cisco and NetGear routers. These devices were particularly vulnerable because they had reached “end-of-life” status, meaning they no longer received security updates. The scale and adaptability of these networks present a major challenge. As Paul Chichester, NCSC Director of Operations, stated: “Botnet operations represent a significant hreat to the UK by exploiting vulnerabilities in everyday internet-connected devices with the potential to carry out large-scale cyberattacks.”

Challenges for Network Defenders 

Cybersecurity researchers have long been aware of such threats, but the evolving nature of China-Nexus TTPs introduces new difficulties. A key issue identified by Mandiant Intelligence in May 2024 is “indicator of compromise (IOC) extinction.” Traditional defenses, such as static IP blocklists, are becoming less effective because attackers can operate from vast, constantly changing pools of devices.  As compromised nodes are patched or removed, new ones are quickly added, making these networks highly dynamic. This fluidity undermines conventional detection and mitigation strategies. 

Defensive Measures and Best Practices 

The advisory outlines several steps organizations can take to defend against China-Nexus covert networks: 

For all organizations: 

  • Maintain a clear inventory of network edge devices. 
  • Establish baselines for normal network activity, particularly VPN access. 
  • Monitor for unusual connections, including those from consumer broadband ranges. 

For higher-risk organizations: 

  • Use IP allow lists instead of blocklists for VPN access. 
  • Apply geographic and behavioral profiling of incoming connections. 
  • Adopt zero-trust security models. 
  • Enforce SSL machine certificates. 
  • Reduce exposure of internet-facing systems. 
  • Explore machine learning tools to detect anomalies. 

For the most at-risk entities: 

  • Treat China-Nexus covert networks as advanced persistent threats (APTs). 
  • Map and monitor known covert networks using threat intelligence. 
  • ✇Firewall Daily – The Cyber Express
  • Hacker Active Well Beyond Context.ai Compromise, Says Vercel CEO Mihir Bagwe
    Vercel CEO Guillermo Rauch, in an update today said that after scanning through petabytes of logs of the company's networks and APIs, his security team concluded that the threat actor behind the Vercel breach had been active well beyond Context.ai's compromise. Rauch said that the "threat intel points to the distribution of malware to computers in search of valuable tokens like keys to Vercel accounts and other providers. Once the attacker gets ahold of those keys, our logs show a repeated p
     

Hacker Active Well Beyond Context.ai Compromise, Says Vercel CEO

23 de Abril de 2026, 05:35

Vercel, Vercel Breach, APIs, npm Packages

Vercel CEO Guillermo Rauch, in an update today said that after scanning through petabytes of logs of the company's networks and APIs, his security team concluded that the threat actor behind the Vercel breach had been active well beyond Context.ai's compromise. Rauch said that the "threat intel points to the distribution of malware to computers in search of valuable tokens like keys to Vercel accounts and other providers. Once the attacker gets ahold of those keys, our logs show a repeated pattern: rapid and comprehensive API usage, with a focus on enumeration of non-sensitive environment variables." Researchers at Hudson Rock had earlier confirmed that the attack actually initiated in February itself when a Context.ai employee’s computer was infected with Lumma Stealer malware after they searched for Roblox game exploits, a common vector for infostealer deployments. What the latest findings mean is that there could be a wider net of victims that the threat actor may have phished for and what we know is just the tip of the iceberg - or not.
Also read: Vercel Incident Linked to AI Tool Hack, Internal Access Gained

Vercel Finds Customers Breached in Separate Malware, Social Engineering Attacks

In an official update, the company also stated that initially it identified a limited subset of customers whose non-sensitive environment variables stored on Vercel were compromised. However, a deeper assessment of the their network, as well as environment variable read events in the company's logs uncovered two additional findings.

"First, we have identified a small number of additional accounts that were compromised as part of this incident," the company noted.

But the main concern is the next finding: "Second, we have uncovered a small number of customer accounts with evidence of prior compromise that is independent of and predates this incident, potentially as a result of social engineering, malware, or other methods." 

The company did not disclose who were the attackers, what was the motive, or the impact on customers, and is yet to respond to these queries from The Cyber Express. It only stated: "In both cases, we have notified the affected customers."

Meanwhile, Rauch said, Vercel had notified other suspected victims and encouraged them to rotate credentials and adopt best practices.

No Compromise of npm Packages

The news of npm packages being compromised has surfaced a lot in recent times. To cover that front, Vercel's security team in collaboration with GitHub, Microsoft, npm, and Socket, confirmed that no npm packages published by Vercel had been compromised. "There is no evidence of tampering, and we believe the supply chain remains safe," the company said.

March 2026 Cyber Threat Landscape Fueled by Ransomware, Breaches, and Access Markets

2026 threat landscape

The 2026 threat landscape continued to intensify in March, with ransomware attacks, expanding data breach activity, and a growing underground market for compromised access shaping the global cybersecurity environment. According to analysis from CRIL (Cyble Research & Intelligence Labs), organizations worldwide faced a highly active and coordinated threat ecosystem throughout the month.  CRIL’s findings point to a cybercriminal landscape driven by financial extortion, credential theft, and operational disruption. Attackers consistently targeted industries that rely heavily on uptime or store large volumes of sensitive data, reinforcing the urgency for stronger defensive strategies. 

Ransomware Attacks Dominate the 2026 Threat Landscape 

Top five ransomware actors (Data Source: Cyble Blaze AI) One of the most defining aspects of the March 2026 threat landscape was the scale of ransomware attacks. CRIL recorded 702 ransomware incidents globally, underscoring the continued dominance of ransomware as a primary attack vector.  Among the most active threat groups were Qilin, Akira, The Gentlemen, Dragonforce, and INC Ransom. Collectively, these actors were responsible for over 56% of all observed ransomware activity, reflecting their operational maturity and extensive affiliate networks.  Industries most affected by ransomware attacks included: 
  • Construction  
  • Professional Services  
  • Manufacturing  
  • Healthcare  
  • Energy & Utilities  
Attackers frequently employed double-extortion tactics, combining data theft with system disruption to increase pressure on victims. Geographically, the United States remained the primary target, influenced in part by ongoing geopolitical tensions, including those involving Iran. 

Rise of Access Brokers in the CRIL Threat Analysis 

Another notable trend in the 2026 threat landscape, as identified by CRIL, was the continued growth of the compromised access market. During March, 20 separate incidents involving the sale of unauthorized network access were tracked across cybercrime forums.  The most targeted sectors for access sales were: 
  • Professional Services (25%)  
  • Retail (20%)  
  • IT & ITES  
  • Manufacturing  
A small group of threat actors, vexin, holyduxy, and algoyim, dominated this space, accounting for more than 55% of observed listings. These access brokers play a critical upstream role, enabling ransomware attacks, espionage campaigns, and financial fraud operations. 

Data Breaches and Leak Markets Stay Active 

CRIL also documented 54 significant data breach and leak incidents in March, further highlighting the scale of data exposure risks in the current 2026 threat landscape.  The most targeted sectors for data breaches included: 
  • Government & Law Enforcement  
  • Retail  
  • Technology  
Several incidents stood out: 
  • A threat actor known as “nightly” claimed to have stolen over 5TB of data from Hospitality Holdings, including biometric data, CCTV footage, and financial records. 
  • Another actor, XP95, advertised 3.8TB of allegedly stolen South African government data for sale.  
  • A separate breach exposed more than 95,000 travel-related records, including passport and payment information.  

Exploitation of Critical Vulnerabilities Accelerates 

The 2026 threat landscape also saw increased exploitation of critical vulnerabilities, particularly those listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog.  Key vulnerabilities targeted included: 
  • CVE-2026-20131 (Cisco Secure Firewall Management Center)  
  • CVE-2025-53521 (F5 BIG-IP APM)  
  • CVE-2026-20963 (Microsoft SharePoint Server)  
  • CVE-2026-33017 (Langflow AI)  
  • CVE-2021-22681 (Rockwell Automation ICS 
CRIL observed attackers exploiting both newly disclosed zero-day vulnerabilities and older, unpatched flaws. This trend reflects persistent gaps in patch management and exposure mitigation across organizations. 

Emerging Threat Developments in March 2026 

Beyond ransomware attacks and data breaches, CRIL identified several strategic developments shaping the 2026 threat landscape: 
  • AI-Driven Attacks: Threat actors reportedly leveraged an open-source framework called CyberStrikeAI to target Fortinet FortiGate devices across 55 countries, compromising more than 600 systems. 
  • Supply Chain RisksNorth Korean-linked actors were associated with 26 malicious npm packages distributing remote access trojans (RATs) via infrastructure hosted on Pastebin and Vercel. 
  • Geopolitical Cyber Activity: Iran-linked cyber operations are expected to increase, with potential ransomware attacks and hacktivist campaigns targeting organizations in the Middle East. 
❌
❌