Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Latest News

Attackers Exploit Cosmos EVM Flaw Affecting Multiple Blockchain Networks

Cosmos EVM Flaw Exploited After Widespread Blockchain Exposure Was Confirmed It has been revealed that Cosmos Labs has disclosed exploiting ...

All the recent news you need to know

Storm-1175 Deploys StormEncryptor Ransomware After N-able N-central Vulnerability Exploitation

 

Financially motivated hackers believed to be based in China are using a new ransomware for the first time after targeting a vulnerability in the N-central remote monitoring and management software. The threat group, which goes by the name Storm-1175, started deploying C++ StormEncryptor ransomware on August 2, following several months of inactivity since April, Microsoft Threat Intelligence said today. 

It marks a departure from the Medusa ransomware previously used by the group. Microsoft says that Storm-1175 most likely used a publicly known zero-day vulnerability, CVE-2026-18577, which was identified as the weakness Storm-1175 attackers used to gain unauthorized access to N-central. N-central is a remote monitoring and management solution used to track and patch servers and endpoints, Microsoft says. 

It means that successful exploitation of the vulnerability allows the attackers to target downstream organizations managed by the N-central server. N-able released a statement saying that it identified active exploitation of the zero-day vulnerability for the first time on July 31. Its initial advisory underestimated the scope of the problem, while the first patch was ineffective against active attacks. The company later released two additional emergency patches. 

Rapid7 reports that CVE-2026-18577 was published on August 2, following an ineffective attempt to address another authentication bypass vulnerability, CVE-2026-18556. The newly discovered weakness has a CVSS score of 8.2 and was added to the CISA Known Exploited Vulnerabilities catalog on August 3. Huntress says that attackers could abuse Take Control Manager to deploy Cloudflare-based tunnels on the N-central servers and gain access to downstream managed endpoints as well as the initial compromise via Take Control Manager.  

Microsoft notes that Storm-1175 actors are accelerating the ransomware lifecycle and are already targeting downstream victims for ransom within 24 hours of initial access. The group is using AnyDesk or SimpleHelp, Advanced IP Scanner for reconnaissance, and Mimikatz to dump credentials from the LSASS process. Storm-1175 ransomware encrypts files and demands payment, threatening to release the data within three days. Several organizations, including companies involved in e-commerce, fintech, healthcare, and home security, have been reported on the group’s ransomware site. Storm-1175’s ransomware activity is similar to the Medusa ransomware campaigns previously attributed to the same hacking group. 

Microsoft says in its report that Storm-1175 actors are also abusing legitimate remote monitoring and management software in order to maintain persistent access to the corporate network and downstream organizations. The company says that attackers can use Take Control Manager to deploy additional implants, establish alternate C2 channels, and interact with the compromised servers or endpoints. 

Attackers could use Remote Desktop Protocol (RDP) to connect to the domain controllers and install software such as PSExec or Windows Management Instrumentation to access other computers. With the domain controllers compromised, the attackers would be able to steal Active Directory data, including user credentials and the hashes of passwords, to gain more visibility and control over the corporate network.

FBI Investigates Cyberattack on Kansas Water Technology Firm

 

The FBI is investigating a cyberattack targeting Micro-Comm, a Kansas-based company that develops technology used by water and wastewater utilities, adding to concerns over the security of America’s critical water infrastructure.

The incident at the Olathe, Kansas, company was confirmed by both Micro-Comm and the FBI. It does not appear to be connected to a suspected Iran-linked cyber campaign that targeted water facilities in Minnesota and several other U.S. states beginning in July. However, the breach underscores the broader cybersecurity risks facing water systems and the technology providers that support them.

A ransomware operation known as Barracuda, which describes itself as financially motivated and independent of government sponsorship, claimed responsibility for the attack. On August 6, the group released what it said were nearly 850,000 company files, totaling about 644 gigabytes of data.

Micro-Comm produces programmable logic controllers (PLCs), computerized systems that help control machinery used in critical infrastructure, including wastewater treatment facilities.

The attack came as U.S. authorities were already dealing with a series of intrusions targeting PLCs in Minnesota and at least six other states in late July. Cybersecurity specialists have linked those incidents to an ongoing campaign allegedly associated with Iran.

On July 30, the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) warned that cybercriminals were actively targeting PLCs manufactured by U.S.-based Rockwell Automation, France’s Schneider Electric and Germany’s Siemens.

CISA later reported on August 19 that attackers were using artificial intelligence to make attacks against Siemens systems more efficient. Siemens said it was working with CISA and maintained that its products remain secure.

Dixon Land, a spokesperson for the FBI’s Kansas City field office, said in an email that the bureau was in communication with Micro-Comm and working alongside other law enforcement agencies. CISA directed questions about the incident to Micro-Comm.

Jim Cote, a co-owner of Micro-Comm, said the company detected the intrusion on July 31. According to Cote, the information released by the attackers did not contain sensitive data such as customer passwords or credentials, which are retained by individual clients. He also said the exposed material did not include information about Micro-Comm’s ability to remotely access its equipment.

In a client newsletter dated August 8, Micro-Comm described the incident as a limited malware attack and said sensitive information within the affected files had been encrypted. The company stated that the incident was "in no way related to water system hacks currently being reported on the news."

Cote said the FBI informed the company that the attack appeared to be opportunistic rather than a targeted operation against Micro-Comm. Despite that assessment, the company recommended that customers change their passwords as a precaution.

Data from internet-monitoring platform Censys indicates that around 200 deployments of Micro-Comm’s SCADAview CSX systems in the U.S. remain accessible online. Meanwhile, an index maintained by cybercrime research platform eCrime.ch reportedly contains references to public-sector customers, including municipalities and a U.S. military facility, as well as employee names and technical information such as system diagrams.

Tom Hegel, a senior threat researcher at cybersecurity company SentinelOne, said the leaked information does not suggest that any water facility experienced an operational shutdown. However, he warned that the information could potentially provide useful intelligence to malicious actors in the future.

Berlin Confirms Extortion Attempt After Network Compromise as Manchester Airports Group Reports Customer Data Theft

 

The state of Berlin confirms that it is the victim of an extortion attempt after allegedly having its network hacked back in August. Authorities say they will not give in to the hackers’ demands. 

Forensic analyses of the network of the Senate Department of Mobility, Transport, Climate Protection and the Environment have revealed additional data thefts outside the network in the period between August 7 and 12. The department had first noticed data loss on August 7 and had been cut off on August 14. Berlin is currently still investigating the extent and scope of the data loss, saying that it is possible that personal data or other confidential information had been accessed. 

The amount of data stolen in the cyber-attack on Berlin has not been disclosed officially; however, one entry on the dark web by the hackers’ group Rhysida, published on August 28, claims that 5,79 TB of data containing personal information of 12,076 people were stolen. The entry also stated that approximately 1,44 million files had been scanned. 

According to the post, the target of the attack was Berlin, Germany, without specifying any ransom value. Der Spiegel revealed that the ransom note was published by the hacker collective Rhysida, citing the group’s dark web blog and security sources. According to the report, a monitoring service confirmed on Friday that a post titled “Berlin, Germany” appeared on the leak site of Rhysida on August 28. Berlin has not officially attributed the attack to any hacker group. 

A joint security advisory released by the U.S. Cybersecurity and Infrastructure Security Agency, the FBI and the Multi-State Information Sharing and Analysis Center highlights that Rhysida has been abusing compromised legitimate usernames and passwords from remote access services and has been using phishing and the Zerologon vulnerability (CVE-2020-1472). The advisory recommends prioritizing the response to known exploited vulnerabilities, implementing multi-factor authentication and network segmentation. 

Berlin’s data protection commissioner and the Federal Office for Information Security have been informed of the attack. Interior Minister Iris Spranger stated that, according to preliminary information, no data from the election-relevant IT systems were removed from the network. Thus far, no election functions have been interrupted. Meanwhile, Manchester Airports Group (MAG) has announced that a cyber-security incident involving the unauthorized collection of customer data occurred at its UK airports. 

The personal data of passengers who booked car parking, lounges, or Fast Track services or who subscribed to in-airport WiFi were affected. The data compromised in the breach include customers’ email addresses, phone numbers, vehicle registration numbers, and postcode details. According to MAG, the data do not include customers’ payment or bank details, and no impact has been made on passengers’ safety or aviation safety or airport operations.

As of August 29, the online booking system, called Manage My Booking, has been temporarily offline for security reasons. It has been reported that affected customers have been contacted directly and have been warned to be vigilant of further communication attempts from unauthorized third parties.

US Says Chinese Hackers Hit Federal Agencies

 

The U.S. says a China-linked hacking operation broke into or targeted systems at NASA, the Federal Reserve, the Justice Department, the Senate, and other sensitive networks, then hid activity by routing traffic through a large botnet of compromised internet-connected devices. Authorities say they disrupted the operation by seizing domains tied to two hacking platforms, QScan and QTRouter. 

According to court filings cited by U.S. media, the campaign dates back to at least 2018 and extended across government agencies, hospitals, telecom firms, power companies, financial institutions, and defense contractors. The filings also list the Department of Energy, the Department of Health and Human Services, and the National Institutes of Health among the victims or targets.

Investigators say the group behind the activity was identified as QTFY, which was allegedly employed by the China-based Nanjing Xinjiuwei Network Technology Company. The DOJ says QTFY created and operated the two platforms to help customers infiltrate networks and cover their tracks. Reports say the services functioned as a paid hacking model, with QScan and QTRouter scanning for vulnerable devices, infecting them, and turning them into proxy nodes. 

The technical method was especially concerning because it relied on IoT devices that were easier to compromise than hardened corporate systems. By spreading traffic through those devices, the attackers could make malicious connections look ordinary and make attribution more difficult. U.S. officials said that tactic allowed the hackers to quietly reach into sensitive networks while reducing the chance of immediate detection. 

The case also shows how cyber operations can blend state interests, commercial tooling, and infrastructure abuse into one long-running campaign. Officials described the seizure as part of a wider push to disrupt Chinese-linked hacking against U.S. government systems and critical infrastructure. For security teams, the key lesson is that even well-defended institutions can be exposed when attackers use botnets, proxy layers, and broad scanning to find weak entry points.

McKesson Probes Data Theft After ShinyHunters Claims Access to Patient Records




McKesson Corporation is investigating a cybersecurity incident involving unauthorized access to third-party applications and data exfiltration, while the ShinyHunters extortion group claims it stole approximately 284 million patient-related records from the healthcare and pharmaceutical distribution company.

McKesson said it discovered the incident on August 25 and immediately activated its incident-response procedures. The company has brought in external cybersecurity specialists to assist with the investigation, which it said remains in its early stages.

In a filing with the U.S. Securities and Exchange Commission, McKesson said it has not determined that the incident is material or that it has had, or is reasonably likely to have, a material impact on its financial condition or operations.

The company confirmed in a separate customer notice that the incident involved unauthorized access to third-party applications and the exfiltration of data. McKesson has not identified the affected applications, disclosed how the attackers obtained access, or confirmed what information was taken.

Customers could also experience intermittent service degradation believed to be related to the incident. McKesson said it was not proactively disconnecting systems within its environment.


ShinyHunters claims employee accounts were compromised

ShinyHunters claims it obtained initial access through voice-phishing, or vishing, attacks targeting multiple McKesson employees.

According to the group, the attacks resulted in the compromise of several employee Okta single sign-on accounts. Those accounts were allegedly used to access McKesson's Salesforce and Snowflake environments.

The group claims it obtained extensive access to Salesforce, including support cases, and extracted a larger volume of patient-related information from Snowflake.

ShinyHunters alleges that approximately 1 TB of data was removed over four days, from August 21 through August 25.

The group has claimed that the Snowflake data contained roughly 284 million patient-related records. However, it later clarified that this figure represents individual database records or lines, rather than 284 million unique patients.

ShinyHunters also said it has not completed its analysis of the stolen material and therefore cannot determine how many individuals are represented in the dataset.

The alleged information includes names, addresses, dates of birth, Social Security numbers, patient IDs, phone numbers, email addresses, Medicaid numbers and medical record numbers. The group also claims the data contains medication and allergy information, illnesses, disabilities, appointments, physician details, prescriptions and medication shipments.

Other allegedly stolen material includes information relating to deceased and terminally ill patients, invoices, employee data, Salesforce records, internal communications, and information about healthcare providers and clinics using McKesson's services.

McKesson has not confirmed any of these specific data categories, and the claims about the stolen information have not been independently verified.


McKesson domain follows ShinyHunters pattern

The alleged campaign also involved the "mckesson[.]claims" domain.

The domain follows a pattern previously associated with ShinyHunters activity. ReliaQuest has documented campaigns in which domains using a targeted company's name or abbreviation alongside the ".claims" top-level domain were used to impersonate help-desk or IT personnel.

The technique is particularly relevant to the alleged McKesson attack because social engineering is increasingly being used to obtain legitimate employee credentials rather than deploying malware directly against an organization's infrastructure.

ReliaQuest recently documented an attempted attack against its own employees in which an attacker used a lookalike domain, impersonated a security employee and attempted to persuade staff to authenticate through a fraudulent SSO page. Additional security controls prevented the attacker from reaching business applications or customer information.

Health-ISAC has also warned healthcare organizations about an increase in ShinyHunters activity involving social engineering, identity compromise and subsequent access to cloud and SaaS platforms.

Its analysis describes an attack chain in which threat actors use vishing or help-desk manipulation to compromise identity-provider accounts before moving into connected services. Such access can allow attackers to retrieve large volumes of information through legitimate cloud applications.

Research from the Retail & Hospitality ISAC has further linked ShinyHunters to the abuse of OAuth relationships and SaaS applications. By operating through legitimate identities or application permissions, attackers can make unauthorized activity more difficult to distinguish from ordinary cloud usage.

The alleged McKesson intrusion has not been independently confirmed to have followed this entire sequence, but the claimed compromise of employee SSO accounts followed by access to Salesforce and Snowflake is consistent with the identity-focused tactics researchers have been tracking.


$55 million ransom demand claimed

ShinyHunters claims it contacted McKesson after completing the alleged data theft on August 25 and demanded $55,236,150 in ransom, giving the company 72 hours to respond.

The group claims McKesson did not negotiate over the demand.

McKesson has not publicly confirmed the ransom demand or its alleged communications with the extortion group.

The incident comes as ShinyHunters-linked attacks continue to target healthcare and health-technology organizations. Recent organizations reportedly targeted by the group include Medtronic, DentaQuest, iRhythm, One Medical and AdaptHealth.

For McKesson, the immediate question remains the actual scope of the incident. The company has confirmed unauthorized access to third-party applications and data exfiltration, but has not established which systems were affected, what information was taken or how many individuals may ultimately be impacted.

Until McKesson completes its investigation, the 284 million-record figure and the specific claims surrounding the alleged Snowflake and Salesforce compromise remain unverified.

Bitcoin Lightning Nodes Drained Through Critical BTCPay Server Flaw


There has been another security breach of Bitcoin payment infrastructure as attackers exploited critical vulnerabilities in BTCPay Server deployments to steal funds from Lightning nodes. Transactions via Lightning Network are faster and more cost-effective than traditional bitcoin transactions, affecting merchants and other operators. 


An attack was observed late Friday involving LND nodes connected to BTCPay Server. Using the vulnerability, an unauthenticated remote attacker may be able to access .macaroon credentials related to Lightning Nodes, according to BTCPay. These credentials grant access to Lightning nodes and, once compromised, could enable the node to be controlled and its funds moved. 

According to BTCPay, real funds were stolen, and operators of LND were advised to upgrade immediately to version 2.4.2. A system that cannot be updated should be taken offline until the vulnerability is addressed. No details have yet been provided about how many installations were affected or how much bitcoin was lost. Foundation's CEO Zach Herbert stated that attackers drained the company's BTCPay Lightning node, shut down its payment channels, and transferred the funds available.

In contrast, the company's separate hot wallet for BTCPay on-chain was unaffected by the attack. A Bitcoin publication, Citadel21, announced that its Lightning node had also been compromised and swept. Citadel21 stated that only a small amount of funds were stored on the affected node. 

A vulnerability was previously reported to BTCPay by members of the Bitcoin Red Team, which is a group that investigates security flaws in Bitcoin-related software. Craig Raw, Rob Hamilton, Calle and Evan Kaloudis were credited with reporting the issue and assisting with its analysis, according to BTCPay. 

A key concern of the incident is the risk posed when vulnerabilities are discovered while affected systems remain vulnerable. By the time the public warning was issued, attackers had already exploited the flaw against live servers. After its initial alert, BTCPay clarified that the vulnerability does not affect its standard on-chain wallets, including hot wallets created within the company. 

Initially, LND deployments were exposed, however funds stored in LND's own on-chain wallet, which is also under the affected node, may also be vulnerable. While operators attempt to secure affected systems, BTCPay has not provided technical details regarding the flaw. A detailed postmortem is expected to be released within the next few days. 

LND Deployments Remain the Primary Exposure

BTCPay Server installations configured to use Lightning payments can be affected by the vulnerability. If hackers have compromised macaroon credentials, they can gain access to the affected node, making exposed Lightning funds a direct target. The credential exposure has not affected BTCPay's standard on-chain wallets. 

A LND node's on-chain wallet does not receive protection from that security breach, and funds in the wallet may continue to be accessible if the node is compromised. Researchers are taking a close look at widely used codebases following a series of security concerns pertaining to Bitcoin-related software. 

The Bitcoin Red Team identified the issue before attackers began exploiting exposed installations, giving operators limited time to implement the available fix. So far, BitcoinPay has not provided detailed technical information regarding this vulnerability while affected operators have begun to secure their systems. It is expected that the project will publish a comprehensive postmortem in the coming days that will provide additional information regarding the flaw, the attack path, and the extent of the breach. 

Operators using LND behind BTCPay Server should use version 2.4.2 as their current mitigation plan. Until the vulnerability has been addressed, systems which cannot be patched should remain offline. This incident illustrates the security risks associated with cryptocurrency payment infrastructure as well as the importance of patching exposed Lightning nodes as soon as possible.

Featured