Blog
SentinelCores Cybersecurity News, Threat Intelligence & Practical Defense
- April 22, 2026
- Posted by: User User
- Category: Security News
A threat actor keeps spreading the WeedHack malware to Minecraft players despite its original infrastructure taken down in July A 35-year-old man operating from China ran the largest fraudulent dark web network ever dismantled and the most disturbing detail… ShinyHunters used a phone-based social engineering attack to access Google’s corporate Salesforce database. Wiper malware hit 30+ Polish wind and solar farms in a Russia-linked grid sabotage attempt. Breach reports, malware alerts, and practical defense guidance, published as the threat landscape moves. The activity was concentrated on DSEwiki , a German software developer wiki that runs on the ProWiki farm at wikiservice.at and had been edited about 20 times over the previous decade.
While threat actors are known to abuse legitimate services to point to additional command-and-control (C2) infrastructure and blend https://heplerbroom.com/insights/publications/davis-publishes-article-on-cybersecurity-for-healthcare-experts/ in with regular network traffic, the development marks the first time this unusual technique has been spotted in the wild. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication. The targets are owners of Apple devices that were recently lost or stolen, and the pages and calls ask each of them for the 4- or 6-digit device passcode, then the Apple ID credentials, and finally a live two-factor authentication (2FA) code. OpenAI on Tuesday said it banned a cluster of Russian ChatGPT accounts that used VPNs to bypass access restrictions and run an influence operation, which relied on its artificial intelligence (AI) tool to generate social media posts and comments that were shared on Substack, Telegram, X, Facebook and LinkedIn.
The Chinese gaming company sold the online platform to an investor group called San Vicente Acquisition LLC in May 2020. Over allegations that it shared users’ personal information, including their HIV status, with third-parties. “TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its entire command-and-control infrastructure inside trusted Microsoft services,” Ontinue said in a technical report shared with The Hacker News. According to the analysis , observed execution began from an interactive zsh Terminal session consistent with ClickFix social engineering, followed by curl retrieving attacker-controlled content over a recurring /curl/ path and na…
Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler
Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control without authentication, according to CERT Polska’s attack warning , published on September 5. Malvertising campaigns distributing the malware make use of two ZIP archives delivered via PowerShell… The activity overlaps with a threat cluster tracked under the monikers WEEVILPROXY and MeadowLocust. The counterfeit sites instruct them to download bogus installers for TradingView that lead to the deployment of the malware. JSCeal was first documented by Check Point in July 2025, highlighting the threat actors’ use of fake cryptocurrency trading sites to which unsuspecting users are redirected via malicious ads on Facebook and Google.
- Cybersecurity researchers have flagged a new malware family that’s specifically designed to infect Android-based vehicle head unit firmware developed by DoFun.
- Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a macOS-focused information stealer, after correlating recurring endpoint and network behaviors across changing infrastructure, tracing the malware from payload retrieval through data collection, staging, and exfiltration.
- Grandoreiro is active after its 2024 disruption, with Mexico now accounting for 40% of detections
- Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser.
The mechanism allows “malware stagers to fetch commands directly from the protocol’s initial response,” SOCRadar said in a technical report. An FTP banner is a welcome message or text string that an FTP server sends to a client immediately upon connection. “While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn’t do harm, the threat actor’s use of npm isn’t to infect developers who install it, but to use the registry and its mirrors as a safe, validated storage for the malware,” OX Security researchers Moshe Siman Tov Bustan and Vitalii Chepurko said . Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages.
Qilin Ransomware Gang Hits German Political Party Die Linke, Threatens Data Leak
For each category, they compared how many accounts had at least one issue in it across the three providers. Add active attacks on browsers, routers, and online stores, and there’s plenty to check—even for teams that have kept up with the patches. It also said https://californiarent24.com/ukraine-s-startup-ecosystem-opportunities-for-foreign-venture-capital.html that the data extortion threat actor known as Cinder likely represents yet another rebrand or a possible continuation of Pink operations, citing overlaps between organizations listed on the Cinder leak site and those connected to Pink. It also functions as a remote access and browser monitoring toolkit that runs host commands, steals credentials, hijacks sessions… Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser.
Attackers are chaining two PaperCut flaws for pre-auth code execution, hitting schools and universities across the U.S. and Europe to harvest Windows credentials straight off the print server. “A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host,” Broadcom said in an alert. JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. Attackers are exploiting a new unpatched vulnerability in Magento Open https://365eventcyprus.com/cqr-pentests-main-goal-in-providing-cybersecurity-and-protection-against-hacker-attacks.html Source and Adobe Commerce that lets them run malicious code on an online store’s server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5 . Security firm TantoSec has published a working exploit chain targeting vulnerabilities in Telerik UI for ASP.NET AJAX that can allow an unauthenticated attacker to execute remote code on the server hosting a vulnerable application.
Fake Recruiter Scams Target Corporate Credentials on Mobile
“The malware spread through the built-in updaters of Android-based automotive head unit firmware,” security researcher Dmitry Kalinin said. Cybersecurity researchers have flagged a new malware family that’s specifically designed to infect Android-based vehicle head unit firmware developed by DoFun. McAfee Labs said it detected and blocked more than 6,300 attempts to access malicious sites, adding that it found lookalike gaming websites designed to mimic legitimate projects, including branding, feature lists, FAQs, installation guides, developer credits, and links to genuine GitHub repositories. Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft clients.
Gambling Goblin Turns Brazilian Government Sites Into SEO Weapons
However, once the ScreenConnect instances were installed, the cybersecurity company said it observed the clients repeatedly spawning “wscript.exe” to execute VBScripts named 1.vbs, 2.vbs, 3.vbs, and 4.vbs. Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems. Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management gave outsiders useful clues before login. Securities and Exchange Commission on September 2, 2026, the California-based company said it settled the suit related to historical data practices before 2020, when it was managed by Kunlun.
Cybersecurity researchers have unpacked JSCeal , a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities. N-able’s incident notice says the flaw has been exploited in the wild; its release notes say that is unconfirmed. A TantoSec proof-of-concept turns an AES-CBC “padding oracle” in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. Attacker tools and infrastructure are now changing at machine speed. Weak IAM controls and missing logging are near-universal, affecting between 80% and 98% of accounts regardless of provider.
“These clusters engage in persistent, adaptive phishing campaigns, using sophisticated social engineering tactics to compromise personal accounts across multiple platforms,” Google Threat Intelligence Group (GTIG) researchers Gabby Roncone and Wesley Shields said in a report published today. Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks within the U.S. Developers are advised to search ~/.cargo/registry/cache for the deleted crate files and to pin arrayref at 0.3.9 or earlier, after the Rust Security Response Team unyanked the maliciously-yanked versions during the response.