Popa Botnet Linked to Publicly-Traded Israeli Firm
Popa botnet infected millions of TV boxes via NetNut proxy service (NASDAQ: Alarum Technologies). The link blurs the boundary between legitimate proxies and botnets.
ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks • How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts • The US military just turned off ad tracking on its phones. Maybe you should too • Hackers exploit Tencent app flaw to deploy GrayRabbit malware • CRPx0 ransomware: what you need to know ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks • How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts • The US military just turned off ad tracking on its phones. Maybe you should too • Hackers exploit Tencent app flaw to deploy GrayRabbit malware • CRPx0 ransomware: what you need to know
The full HackWire archive — 3,892 stories, newest first.
Popa botnet infected millions of TV boxes via NetNut proxy service (NASDAQ: Alarum Technologies). The link blurs the boundary between legitimate proxies and botnets.
Trusted platforms became prime attack vectors this week—23 fake Chrome extensions hit 758K users, Claude chat weaponized for malware, and macOS systems compromised via phishing lures. Attackers now exploit vendor credibility as their primary delivery mechanism instead of breaking systems directly.
A worm spreads crypto malware via USB drives and Windows shortcuts, targeting Bitcoin, Ethereum, Tron, and Monero wallets since February 2026. It seeks seed phrases for long-term theft.
Accenture acquires Dragos, runZero, and NetRise for $4.1B to consolidate industrial cybersecurity, merging OT threat detection, asset discovery, and firmware analysis under the Dragos banner by Q3 2026.
Organizations carry year-old vulnerabilities but focus on backlog. Real threat: exposed flaws exploited instantly. Shift to assessing exposure and exploitability, not just inventory reduction.
INC ransomware, with 830+ victims since August 2023, ranks as the 4th most active RaaS threat. The US-focused group strategically targets legal, manufacturing, and healthcare sectors.
Microsoft uncovered a sophisticated crypto clipper campaign using USB worms and embedded Tor infrastructure to hijack cryptocurrency transactions. The malware self-propagates via malicious shortcuts on USB drives, representing a significant evolution in clipper tactics with remote code execution cap
Klue's OAuth breach allowed the 'Icarus' extortion gang to steal Salesforce data from enterprises using compromised tokens. Salesforce disabled the integration; affected companies now face extortion demands.
Orphaned AI agents—autonomous systems left behind by departing employees with persistent credentials and undocumented access—pose a hidden security risk, operating unmonitored across enterprise infrastructure.
Backdoor.Turn tunnels C2 traffic via Microsoft Teams to hide from detection. The DragonForce gang's Go-based RAT provides persistent access while blending with legitimate enterprise traffic.
Attackers compromised ShapedPlugin WordPress plugins via supply chain attack, distributing malicious code through official updates to paying customers. The breach exploited how premium plugins lack WordPress.org's security oversight.
Authorities shut down SocGholish, JavaScript malware infecting 15,000 WordPress sites. The operation seized 100+ servers linked to Evil Corp's ransomware campaigns in one of the largest takedowns.
Microsoft 365's native protection prioritizes service continuity over data security, leaving organizations vulnerable to ransomware. Additional backup strategies beyond recycle bins are essential.
PCI DSS v4.0.1 now mandates merchants audit all third-party checkout scripts after Magecart supply-chain attacks exposed cardholder data at British Airways, Ticketmaster, and other major retailers.
Microsoft fixed a Windows Server 2016 update failure caused by missing the May 2026 prerequisite patch. The issue highlights a recurring pattern of deployment problems plaguing multiple Windows versions.
F5 released emergency patches for critical NGINX vulnerabilities (CVE-2026-42530, CVE-2026-42055) enabling unauthenticated remote code execution and denial-of-service attacks. The flaws affect thousands of enterprise deployments globally; immediate patching is essential.
India blocked Telegram to prevent medical exam leaks and fraud after Telegram admitted inability to detect such abuse. A BGP misconfiguration extended the outage beyond India's borders.
Apple patched critical Bluetooth flaw CVE-2025-20701 in Beats Studio Buds allowing eavesdropping without pairing. Auto-deployed firmware 1B211 fixes vulnerability affecting nearby attackers.
SailPoint acquired Israeli security startup Entro for $200M, expanding into non-human identity and AI agent security. The deal addresses enterprise demand for machine identity protection as automated agents and service accounts proliferate across infrastructure.
Kodak confirmed a breach by ShinyHunters, claiming stolen corporate records. Though Kodak denies immediate operational threats, the incident reveals persistent security gaps among Fortune 500 firms and corporate transparency issues.
EU launches Shield-6G to secure 6G networks with AI threat detection and digital twins, proactively addressing quantum computing and supply chain threats before 2030s deployment.
OpenAI is developing ChatGPT for Science, a specialized subscription targeting researchers and academic institutions. This marks a strategic shift from general-purpose AI toward vertical-specific products for professional markets, positioning OpenAI to dominate specialized domains like scientific re
OpenAI is testing ChatGPT for Science, a subscription tier for researchers featuring enhanced scientific document handling, citation management, and collaborative tools. Expected pricing: $20–$50/month, positioned between ChatGPT Plus and enterprise offerings.
Attackers exploit AI coding assistants via malicious bug reports to extract sensitive data. Organizations adopting AI without proper security are creating new breach vectors for attackers to easily exploit.