Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Latest News

Polish Dental Software Firm Hit by Cyberattack

  Polish dental software provider FELG Software has confirmed a cybersecurity incident affecting its FELG Dent cloud-based practice manageme...

All the recent news you need to know

ShinyHunters Hacker Reportedly Detained as FBI Seeks Cooperation


The FBI has reportedly detained a suspected ShinyHunters member known online as “Rey” and is cooperating with the government. Jordanian authorities captured a suspect identified as Saif al-Din Khader this week. According to two sources cited by Reuters, Khader is helping U.S. and international investigators identify other members of the hacking group. 


It is believed that Khader's cooperation will provide investigators with information regarding the group's activities and alleged co-conspirators, according to a source. He has shown investigators his electronic devices and digital communication to help locate other suspected members. The FBI has not responded to Khader's reported detention specifically, however it has stated that it is continuing to investigate the recent cyber incident allegedly involving ShinyHunters and is collaborating with international partners to resolve the matter. 

A series of law enforcement actions targeting individuals affiliated with ShinyHunters has led to this reported detention. Dutch authorities arrested a 24-year-old man in connection with an investigation into the group in September. Following the arrest, the FBI issued a warning encouraging other suspected members to surrender while they continued to investigate the matter. 

The developments are following the claim by ShinyHunters that a job portal breach had taken place. As claimed by the group, it obtained a significant amount of sensitive information from FBI systems. Particularly, it claimed to have acquired employee information, though the extent of the alleged theft has yet to be independently verified. During Khader's reported detention, the group's online activity was also disrupted. 

In addition to the disappearance of the group's data leak website, an account previously used to communicate with journalists no longer responded. Later, another ShinyHunters leak site appeared, indicating the group may continue to conduct activities. Moreover, Khader's reported cooperation strengthens the investigation, which has already been conducted by several individuals associated with the ShinyHunters network in general. 

Khader's identity was previously associated with the group until the latest detention was made. It has been reported that Brian Krebs identified Khader as a member of the Scattered Lapsus$ Hunters umbrella operation in 2025, which is affiliated with ShinyHunters, Lapsus$, and Scattered Spider. Aside from being linked to the HellCat leak site and BreachForums hacking forum, Khader had previously asserted that he was cooperating with law enforcement and had ceased all data theft and extortion activities. Those claims were not independently verified. 

While this was the case, ShinyHunters continued to conduct attacks in 2026, including attacks on Rockstar Games as well as Canvas, which disrupted schools across the country. Despite this, the group has continued to engage in data theft and extortion operations. ShinyHunters has recently begun targeting cloud-based services as well as third-party providers, resulting in incidents that are linked to organizations such as Google, Cisco, and Pornhub.

ShinyHunters has also been linked to the May 2026 breach involving Instructure Canvas, while previous investigations have resulted in arrests related to Snowflake-related attacks, PowerSchool and Breached hacking forums. It may be possible for investigators to gain a better understanding of how this loosely organized network operates and who remains active within it through the recent arrests. 

It has been reported that FBI agents have indicated that information obtained from arrests and seized infrastructure may be useful for identifying additional participants. However, the appearance of a new ShinyHunters leak site following the earlier closure indicates that the organization has not been completely dismantled. Furthermore, the case illustrates the difficulty of disrupting cybercrime groups that are built upon informal networks rather than a rigid organizational structure. 

According to Reuters, investigations and prosecutions can become complicated by the young age of some suspects, the fluid nature of related groups, and the limited cooperation of victims. While ShinyHunters' continued online activity suggests that law enforcement efforts are ongoing, the reported detention and cooperation may provide investigators with valuable insight into ShinyHunters' wider network.

Dell Patches Six Critical Flaws in Container Storage Modules, Some Scoring a Perfect 10

 




Dell has shipped security fixes for six critical vulnerabilities in its Container Storage Modules (CSM) that could allow unauthenticated attackers to seize full administrative control over an organization's storage infrastructure and every node in a Kubernetes cluster. Four of the six flaws carry CVSS scores of 9.6 or higher, two of which hit the maximum possible rating of 10.0.

The bugs affect every version of CSM prior to 1.17.0, and Dell patched them in version 1.18.0. The company says no workarounds or interim mitigations exist, which means organizations running the affected software are down to one option: update now.


What CSM Does, and Why These Bugs Matter

Dell Container Storage Modules are Kubernetes-native extensions that manage persistent storage for containerized workloads across Dell's storage product families, including PowerFlex, PowerStore, PowerMax, PowerScale, and Unity XT. Because CSM sits at the intersection of storage credentials and cluster-level access controls, vulnerabilities in the platform carry a particularly high blast radius. An attacker who compromises CSM does not just gain access to data; they gain the ability to manipulate who can access what across every tenant connected to the system.


A closer look at the Six Vulnerabilities

The most severe of the six, CVE-2026-63688, scored a perfect 10.0. The flaw lives in the csm-authorization-storage gRPC server and requires no authentication to exploit. An attacker on the network can send requests directly to this endpoint and pull the backend administrator credentials for every storage array registered with the system. Dell's own advisory described it as enabling "a complete bypass of the csm-authorization security model," handing an attacker full administrative control over storage spanning all five supported Dell storage product families.

The second maximum-severity flaw, CVE-2026-63692, also a 10.0, targets the authorization proxy and tenant service. Like its counterpart, it requires zero credentials to exploit. A successful attack gives an adversary administrative control over the entire authorization service and the ability to access or manipulate storage resources across all connected tenants.

CVE-2026-67269 scored 9.9 and introduces a different threat model. It is a privilege escalation flaw in the ContainerStorageModule Custom Resource reconciler. A low-privilege attacker, not even a full admin, can submit a single maliciously crafted custom resource to the cluster and walk away with root-level access on every node in the environment. The attack surface is as small as one API call; the damage is cluster-wide.

Two of the remaining flaws center on hardcoded secrets. CVE-2026-54472 (CVSS 9.8) buries a static set of credentials inside the CSM Authorization module, allowing any remote attacker to forge cryptographically valid administrative tokens and seize control of the Authorization proxy. CVE-2026-61421 (also 9.8) compounds the problem: the JWT authentication component in karavi-authorization uses a hardcoded signing key. Because the signing secret is publicly available, anyone who locates it, something that is not especially difficult when code repositories are involved, can mint valid authentication tokens and claim administrative privileges without going through any login flow whatsoever.

The final flaw, CVE-2026-67273, scored 9.6 and is a template injection vulnerability. A low-privilege attacker with remote access can manipulate input fed through the template engine to escalate their own privileges, read sensitive information, and tamper with role-based access controls at the cluster scope. Dell's advisory noted that exploitation yields the ability to "create cluster-scoped RBAC resources, effectively bypassing the intended Kubernetes access controls."


Context: Dell's Track Record With Exploited Flaws

This batch of CSM vulnerabilities does not arrive in isolation. Dell has faced repeated problems with critical infrastructure flaws being turned against real targets in the field. Earlier this year, researchers at Mandiant and Google's Threat Intelligence Group documented how CVE-2026-22769, a hardcoded-credential flaw in Dell RecoverPoint for Virtual Machines carrying a CVSS score of 10.0, had been actively exploited as a zero-day since mid-2024 before Dell published a fix in February 2026. CISA added it to its Known Exploited Vulnerabilities catalog the following day. Years earlier, CVE-2021-21551, an access control flaw in Dell's dbutil driver, made the same list after evidence of active exploitation emerged in the wild.

The pattern here is consistent: attackers increasingly go after enterprise infrastructure components that security teams tend to treat as inherently trusted. Storage management platforms and low-level system utilities rarely face the same scrutiny as public-facing applications, and that blind spot has proven to be consequential.


What to Do

Dell is directing all customers to upgrade CSM to version 1.18.0 immediately. For systems affected by CVE-2026-61421, the company is additionally recommending that JWT signing secrets be rotated post-upgrade, since those secrets were embedded in code that has been publicly accessible and should be treated as already compromised. No partial mitigations apply. The fix is available, and for organizations still running pre-1.17.0 versions, the exposure is active.



China Nexus Cyber Espionage Attacks Government Organizations


A China-nexus cyber-espionage campaign is targeting government and policy organizations across Asia with a previously undocumented Windows backdoor called Antino. Researchers at Cisco Talos are tracking the threat activity as UAT-11587.

Campaign details 

The campaign has targeted organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria. By July 2026, Talos had identified at least 16 affected or targeted institutional environments and approximately 350 compromised endpoints.

The campaign's lure theme and targeting provide additional contextual support. Its lures and observed targets include Taiwanese political, legislative, civil defense, and policy research subjects, together with regional government, maritime, diplomatic, and security themes. This collection focus is consistent with China-nexus actor interests,” Talos said.

The most notable feature of Antino is its use of legitimate Microsoft 365 services as command-and-control (C2) infrastructure. Instead of relying on a traditional attacker-controlled server, the malware communicates through Microsoft Outlook and OneDrive using Microsoft Graph.

About Antino

Antino is a Rust-compiled Windows backdoor capable of gathering information about infected systems, executing commands through Windows shell and PowerShell, transferring files, loading shellcode directly into memory and maintaining persistence.

About the infection 

The infection generally begins with a carefully prepared spear-phishing email. Attackers used government, diplomatic, maritime, legislative and foreign-policy themes designed to appear relevant to their intended victims.

Attack tactic

In some cases, the attackers recreated Gmail’s attachment-preview interface inside the email. When victims interacted with the fake attachment, they were directed to attacker-controlled infrastructure.

The attack then proceeds through multiple stages involving HTA or WSF files, JavaScript and a .NET-based downloader before ultimately installing Antino. The malware has also been deployed through DLL sideloading, using a legitimate Microsoft-signed executable to load the malicious DLL. 

Once installed, Antino uses Microsoft Graph to communicate with Microsoft 365. Outlook is used for receiving commands, while OneDrive handles heartbeat communications and file transfers. This allows malicious traffic to terminate at legitimate Microsoft infrastructure, potentially making conventional network-based detection more difficult.

Impact on systems

A successful Antino infection can provide attackers with persistent access to a Windows system, allowing them to conduct reconnaissance, execute commands, run PowerShell, access files and transfer data.

The targeting of government agencies, diplomatic organizations, universities, think tanks and policy groups suggests that the campaign is focused primarily on intelligence gathering and espionage rather than ordinary financial cybercrime.

Cisco Talos assessed UAT-11587 as China-nexus with high confidence, citing technical, language, infrastructure and targeting indicators. However, researchers noted that attribution to a specific Chinese group remains more complicated. 

Google's Android 17 Locks Accessibility Services to Verified Apps as Malware Threat Branches Out




Google is tightening restrictions on one of mobile malware's most persistent entry points. With Android 17, the company is limiting access to its AccessibilityService API to verified Accessibility Tools only, a change that takes effect the moment a user switches on Advanced Protection.

The move, announced Thursday, targets a problem that has haunted Android security for years. The AccessibilityService API was built to help people with disabilities use their smartphones. Screen readers, voice control apps, and motor-assistance tools all rely on it. But the privileges it carries are significant. Apps that tap into the API can run in the background, observe what appears on screen, intercept UI events, and take actions inside other applications on a user's behalf. That set of capabilities made it a target for malware developers almost immediately after it was introduced.

Google stated in its announcement that the new version automatically restricts AccessibilityService access to verified Accessibility Tool applications, closing off a major attack avenue while keeping genuine assistive technology functional.


A Clichéd Attack Path

Malware families have been weaponizing Android's accessibility services since at least 2017. The list of known offenders runs long: Vultur, SharkBot, Xenomorph, BianLian, Anatsa (also tracked as TeaBot), and more recently BTMOB RAT, a remote access trojan documented attacking banking customers across Brazil, Argentina, Spain, Portugal, and Mexico through 2025 and 2026. According to Kaspersky data, trojans accounted for 40 percent of Android malware infections in Q1 2025, with nearly 12 percent of malicious apps falling into the banking trojan category that specifically abused the Accessibility API, totaling around 154,000 apps.

The attack chain is well understood. A malicious app, typically distributed through sideloaded APKs or disguised as something routine, tricks a user into granting accessibility permissions. The Anatsa trojan, for instance, slipped onto Google Play as a PDF viewer update as recently as July 2025. Once the permission is granted, the malware operates without root access. It can monitor keystrokes, layer fake login pages on top of legitimate banking apps, approve system dialogs silently, and initiate fraudulent fund transfers from financial applications without the user noticing anything unusual on screen. Google noted in its announcement that this access also allows malware to block its own uninstallation, locking users out of any easy remedy.


What Changes in Android 17

The new restriction applies specifically when Advanced Protection is active, a device-level security mode introduced with Android 16 that consolidates multiple hardening features under a single toggle. When a user enables it, the system now automatically enforces that only verified, legitimate accessibility apps can request AccessibilityService access. Everything else is denied.

This is part of a gradual tightening that has been underway for several years. Android 13 made it significantly harder for sideloaded apps to acquire accessibility permissions. In-call protections, rolled out more recently, prevent users from granting those permissions during a phone call, cutting off a common social engineering scenario. Google also introduced the `accessibilityDataSensitive` flag to let developers mark UI elements as off-limits to third-party accessibility readers.


The Rest of Android 17's Security Updates

The accessibility change is one piece of a wider hardening effort in Android 17. Intrusion Logging, developed in collaboration with Amnesty International's Security Lab and other civil society organizations, creates a persistent, privacy-preserving forensic record of sensitive system events. Amnesty's team simultaneously updated AndroidQF and its Mobile Verification Toolkit to process the new log format, making it immediately useful for researchers investigating suspected spyware infections.

USB Protection blocks new data connections over a USB port while the device is locked, preventing physical access attacks where an attacker might attempt to extract data or push commands through a connected cable. Google has also included an option to disable WebGPU, a graphics API that has surfaced in sophisticated browser-based exploit chains. Failed Authentication Lock responds to repeated incorrect login attempts by locking the device entirely, making brute-force attempts against a stolen or seized phone substantially harder.

A fifth addition, View Supporting Apps, gives users a clear window into which installed applications have checked whether Advanced Protection is active on the device.

For developers, Google confirmed that applications can receive a notification when a user enables Advanced Protection, allowing them to switch on their own high-security features automatically for that audience.

Existing Advanced Protection users will receive a notification when the new capabilities land on their device. Intrusion Logging is not switched on by default and must be enabled manually from the Advanced Protection settings page.


AI Turns Into Both Threat and Shield in Supply-Chain Cyberattacks

 

Artificial intelligence is emerging as both a growing cybersecurity risk and a critical defence tool for supply-chain companies. As warehouses, factories and logistics networks adopt connected sensors, GPS tracking, tablets and automated equipment, every new digital connection can potentially give attackers another route into operational systems. 

Recent incidents underline the scale of the threat. Uber Freight disclosed unauthorized access to part of its systems and data in mid-August, while Ceva Logistics reported a breach affecting multiple companies and exposing customer information. Coca-Cola dairy brand Fairlife was also struck by ransomware, temporarily suspending its US operations. Such attacks can halt production, delay deliveries and cause time-sensitive products to spoil. 

The consequences can extend well beyond the directly targeted business. When Jaguar Land Rover suffered a cyberattack last fall, its production remained halted for six weeks, disrupting suppliers and reportedly contributing to the failure of some smaller companies. Software supply-chain attacks create an additional danger because compromised code can spread malware across many organisations using the same tools or automated systems. 

AI-powered security systems can help companies identify unusual activity, scan code for vulnerabilities and flag deviations from normal system behaviour. When a potential weakness is detected, organisations can deploy patches quickly before attackers exploit it. However, technology alone is not enough. Employees across offices, plants and warehouses need training to recognize phishing attempts, protect privileged access and use strong password-management practices. 

The challenge is becoming more difficult as criminals use AI to create convincing phishing emails, deepfake voice calls and fake videos that remove traditional warning signs such as poor grammar. Businesses are therefore reassessing supplier contracts, cybersecurity audits and third-party risk management. With more diversified supplier networks sharing inventory, operational and customer data, firms must ensure partners maintain comparable security standards and maintain incident-response plans. In an era when attackers can use AI to find weaknesses rapidly, using AI for defence is becoming essential.

Mayor Confirms Ransomware Incident Disrupted Mississippi City Systems


The city of Vicksburg, Mississippi, has taken its computer systems offline after a ransomware attack disrupted several city functions. Mayor Willis Thompson confirmed the incident and announced a temporary shutdown while officials investigate the incident and restore the affected systems. Due to this incident, residents will be unable to use online utility payment services and will experience delays making payments in person due to the incident. 

Even with the disruption, emergency response, police, fire, and utility services remain operational. In addition, residents of Vicksburg will not be subjected to late payments or termination of utility services while the systems remain offline, according to the city. As part of the recovery effort, Vicksburg has enlisted outside cybersecurity experts and is working with the FBI, Department of Homeland Security, and state officials. 

As part of the investigation, officials are examining whether personal or confidential information belonging to customers, contractors, vendors, employees or business partners has been accessed. As of this writing, officials do not know whether any information has been accessed or taken without authorization. Also, it has not been disclosed who the attackers are or whether a ransom demand has been placed. 

Although the investigation and system recovery are ongoing, technical details about the incident will remain withheld while questions remain regarding its exact nature and scope. Reporting has not been able to establish whether the incident involved the encryption of city systems typically associated with ransomware or whether the term was being used in connection with a ransom demand. 

There was no publicly asserted responsibility at the time of reporting, and the city did not disclose whether a ransom was demanded, or whether any communication with the attackers occurred. In addition, officials have withheld technical information that could impact the ongoing investigation. 

Investigations are aimed at investigating whether the incident exposed personal or confidential information of current and former customers, contractors, vendors, employees and affiliated business partners, as well as other parties involved. 

If a compromise is confirmed, officials have informed affected individuals that appropriate information and resources will be provided. However, a final determination has not been reached regarding whether such information was accessed or acquired without authorization.

The city is currently partnering with external cybersecurity specialists and other partners in order to secure the restoration of affected services, alongside the investigation. Some routine government operations, particularly utility payment processing, have already been affected by the shutdown, even though vital emergency and utility services have been provided. 

There are approximately 10,000 utility accounts that are serviced by the city's water and gas office, which means that the disruption may affect a significant proportion of the local community. Other ransomware attacks have also been reported in Mississippi following the Vicksburg incident. As part of its recovery process, the University of Mississippi Medical Center consulted with the FBI following a ransomware incident that caused parts of its systems to be unavailable for several weeks. 

In previous years, Mississippi saw ransomware affect an electric utility and a county government, highlighting that a number of public-sector and critical service organizations have experienced similar disruptions. However, Vicksburg is unsure whether the shutdown will last for a prolonged period of time. 

Investigations are currently underway to determine how the intrusion occurred, which systems were affected, and whether any sensitive information has been compromised. Further details will be provided once verified findings have been identified.

Featured