CyberNews

Cybersecurity News Dashboard

Category

Filter the feed by target type (multi-select)
Clear
Showing 41–50 of 183 articles
RANSOMWARE Security Affairs Ransomware

Akira Ransomware Uses Safe Mode to Bypass EDR

Akira attackers used Safe Mode to disable EDR before deploying ransomware, but memory issues caused the encryptor to fail. An Akira ransomware affiliate broke into a company through an MFA-less SonicWall VPN on August 4, stole credentials and file shares, and then rebooted the compromised host into Safe Mode with Networking to kill the security tools before launching the encryptor. The plan worked on the EDR. It did not work on the ransomware. “After gaining access via an exposed SonicWall VPN, an Akira affiliate rebooted the victim host into Safe Mode with Networking to defeat EDR, a first for this ransomware variant in our telemetry.” reads the report published by Huntress. “In this incident, Safe Mode also broke the ransomware. In its stripped-down memory environment, the Akira process tree hit an out-of-virtual-memory failure seconds after launching.” The attacker also added AnyDesk to the Safe Mode registry before rebooting, so their remote access survived the restart even though everything else didn’t. For ten minutes, the host had no working EDR and Defender’s real-time protection was down. The attack followed Akira’s standard playbook almost exactly: VPN credential spray resolved into a successful login at 03:52 UTC, then two hours of quiet before the operator RDP’d to the domain controller, dumped all Active Directory users and computers with a PowerShell enumeration that disabled truncation to capture every group membership, archived mapped file shares with WinRAR using the same flags documented in previous Akira campaigns, and uploaded the data to an attacker-controlled S3 bucket using s5cmd. Exfiltration happened before any encryption attempt, which matters, because it means the victim can still be extorted even when the ransomware fails. The ransomware failed because Safe Mode limited available memory. About 13 seconds after launching, akira.exe triggered multiple memory errors, apparently overwhelming the stripped-down environment and causing the encryption process to fail. “akira.exe executed at 06:34:29 UTC and spawned its child-process burst at 06:36:21 UTC. About 13 seconds later, the host started throwing memory errors:” continues the report. “Safe Mode boots with a stripped-down environment and constrained virtual memory, and the Akira process tree appears to have starved it, getting the “Out of Virtual Memory” pop-up and the cascade of PowerShell hard errors line up exactly with the moment the payload tried to kick things off.” Defender’s scheduled scan eventually detected akira.exe as Ransom:Win32/Akira.B!ibt, but couldn’t quarantine it while real-time protection was disabled in Safe Mode. The file was only removed after the attacker rebooted back to normal mode, restoring Defender’s protections, at which point their own anti-EDR move undid itself. Huntress notes that Snatch and AvosLocker have abused Safe Mode for years, but this is the first time the company observed Akira using it. The more uncomfortable takeaway is that a host with more RAM or a larger page file might have given the encryptor enough memory to run successfully in Safe Mode. Akira’s developers could also reduce the payload’s memory footprint to make Safe Mode launches reliable, which means the same lucky failure won’t necessarily repeat. The detection guidance is specific: alert on msconfig.exe or bcdedit activity, watch for Kernel-Boot Event ID 27 with a SAFEBOOT load option, Kernel-General Event ID 12 with BootMode=2, and third-party services stopping. Also watch for remote-access tools being added to the Safe Mode service registry, that’s the tell that the operator is planning to maintain access through the reboot. “The takeaway is a little uncomfortable. While Safe Mode blinded our controls, it may also have prevented the encryption it was meant to enable. That’s a lucky side effect of the attacker’s own mistake in these circumstances, not a defence you can plan around.” concludes the report. “Ultimately, this could be a case of winning the battle, but not the war. It’s possible that a host with more physical memory or a larger page file might give akira.exe enough virtual memory to encrypt the endpoint in Safe Mode.  Akria’s developers or affiliates could retool the encryptor to reduce its memory demands or make its Safe Mode launch sequence more reliable, meaning that the same failure may not occur in a future intrusion.” Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, Akira Ransomware)

Aug 17, 2026, 07:15 AM Read more →
NETWORK The Hacker News

Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic

Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel. Russian cybersecurity company Kaspersky said its ongoing monitoring of the threat activity cluster since December 2025 has led to the discovery of previously unreported components that expand the

Aug 17, 2026, 05:41 PM Read more →
NETWORK The Hacker News

How MCP Servers Can Expose Enterprise Secrets

MCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access and prompt injection, often before security teams even know the server is running. As more organizations adopt AI agents into their systems, that exposure can silently become a major gap in MCP server security. The Model Context Protocol (MCP) allows AI agents to reach the tools and data,

Aug 17, 2026, 11:58 AM Read more →
RANSOMWARE The Hacker News CVE-2026-59310 ↗ Ransomware

Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware

Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT). The attacks involve the exploitation of CVE-2026-59310 (CVSS score: 9.8), a severe directory-traversal vulnerability in the VMware vCenter server that could be weaponized by a malicious actor to execute arbitrary code

Aug 17, 2026, 07:36 AM Read more →
NETWORK Security Affairs

DDoS Attacks Cause Major Threema Outages

Large DDoS attacks disrupted Threema, causing severe communication outages. Threema On-Prem users were unaffected by the attacks. Threema suffered multiple large-scale DDoS attacks that disrupted its secure messaging service and caused severe communication issues. Organizations using Threema On-Prem were not affected, as their deployments run on their own infrastructure. Threema is a Swiss paid secure messaging service, similar to WhatsApp or Signal, focused heavily on privacy and security. “If the attack originates simultaneously from multiple (and potentially changing) sources, it is referred to as a “Distributed Denial of Service” (DDoS) attack. This makes the attack significantly more difficult to defend against because it is not possible to simply block a single source.” reads the report. “Because sophisticated attackers constantly change their methods, sources, and attack patterns during an attack, a cat-and-mouse game ensues, with both sides continuously reacting to the other’s most recent action.” Users began reporting Threema outages on Tuesday evening. The company initially blamed a network issue at its colocation provider, but later confirmed it was facing a series of DDoS attacks. The attacks caused intermittent disruptions into Wednesday, with users in several countries still reporting problems even after Threema’s status page showed the service as operational. The company said a series of large-scale DDoS attacks also targeted its colocation partner, Nine. Attack patterns kept changing, making mitigation difficult. The service was unavailable for about four hours Tuesday evening, followed by intermittent outages Wednesday morning. Normal operations were restored at 12:23 p.m. CEST. “It is not entirely clear whether Threema was the primary target or whether the attacks were directed at multiple targets. In any case, they continued over an extended period and their patterns were constantly adapted, making them difficult to defend against.” continues the report. “As a result of these attacks, Threema was unavailable on Tuesday between 7:30 p.m. and 11:30 p.m. CEST. The page providing information on the current system status was initially not updated due to a technical issue unrelated to the attack. We therefore temporarily took it offline until the problem was resolved.” Threema communicated the service disruptions progressively through social media, while Threema Work customers received updates by email. To strengthen its defenses, Threema deployed additional upstream DDoS protection on August 14, filtering malicious traffic before it reached its infrastructure. The company also plans to improve its status page with an incident history and RSS feed, giving users and administrators another way to receive independent service updates. “We will also expand the status page in the coming days. The update will include an incident history and an RSS feed that interested users and Threema Work administrators can subscribe to in order to receive system updates through an independent channel.” concludes the report. “We apologize for any inconvenience caused and appreciate your understanding.” Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, DDoS) “Business customers using Threema Work were informed via email on Wednesday morning about the unstable service conditions, and account managers provided information on the current situation in response to inquiries.” To avoid similar incidents, the Swiss company has implemented “specialized DDoS protection as an additional measure” to filter attack traffic upstream and reduce the load on its infrastructure. Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, newsletter)

Aug 16, 2026, 11:38 PM Read more →
NETWORK BleepingComputer

Large-scale DDoS attacks disrupted Threema secure messaging service

Multiple distributed denial-of-service (DDoS) attacks targeted the Threema secure messaging service earlier this week, causing severe disruptions to communications. ​Organizations using Threema On-Prem did not experience any issues because they rely on their own infrastructure. In a post-mortem report on Friday, the end-to-end encrypted instant messaging service said that the attacks were difficult to defend against because the threat actor constantly changed patterns. Threema is a paid messaging application developed by the Swiss technology company of the same name, with a heavy focus on security and privacy. The service relies on its own server infrastructure in various locations in Switzerland and promises “no ads, no profiling, no hidden data analyses.” On Tuesday around 6 PM UTC, users started to report service interruptions. The company responded about an hour later, saying that based on the information available at the time, the cause was “a network outage on our colocation partner’s side.”

Aug 16, 2026, 05:29 PM Read more →
RANSOMWARE Security Affairs

Sophisticated Cyberattack Exposes Data of 678,000 French Taxpayers

France’s tax agency says hackers stole data on 678,000 taxpayers, including income and tax details, in a sophisticated cyberattack. A threat actor claimed to have breached France’s tax agency in late June. France’s tax administration confirmed that a cyberattack exposed personal data of 678,000 individuals and businesses, prompting an immediate criminal investigation. The cybercrime unit of the Paris Public Prosecutor’s Office has opened a probe and handed it to OFAC, France’s dedicated cybercrime fighting office. Tax officials described the attack as more sophisticated than anything they’d faced before. “The attack allowed hackers to extract data relating to 678,000 users of France’s tax system, including both private individuals and companies.” reports French media RFI. “Tax authorities said the incident was more complex than cyberattacks they had faced in the past, potentially renewing concerns over the security of government information systems following a series of recent breaches involving other public bodies.” The Directorate-General for Public Finances (DGFiP) stressed that the stolen data doesn’t grant access to taxpayers’ secure accounts on impots.gouv.fr. That’s a meaningful distinction, but income figures, tax rates, and family circumstances are exactly what an attacker needs to make a phishing email or phone call sound credible enough to extract a password or bank account number. “Officials said those affected would be contacted from early next week, with particular emphasis on alerting them to the potential risk of identity theft and fraudulent attempts to obtain further personal information.” continues RFI. French authorities did not disclose technical details about the cyberattack or its motivation. The breach follows recent attacks on systems linked to ANTS, the national secure documents agency, and INSEE, France’s statistics authority. Three government bodies hit in quick succession is a pattern, not a coincidence. For businesses, the exposed data was considered less sensitive, SIREN registration numbers, business addresses, and the address of the authorized representative. Public Accounts Minister David Amiel has asked the DGFiP to start notifying affected taxpayers from Monday and requested proposals on how to strengthen security procedures. Investigators still need to establish how the attackers got in, who they are, and whether the data has already been sold or used. Anyone contacted about this breach should treat follow-up requests for passwords or banking information as fraudulent regardless of how official they sound. Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, France’s tax agency)

Aug 16, 2026, 08:55 AM Read more →
NETWORK Security Affairs

Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware

Attackers are buying expired domains to exploit their reputation, traffic and DNS history, using them for malware delivery, scams and C2 infrastructure. Every day, roughly 65,000 domain names that once belonged to someone else get re-registered by a new owner. Infoblox Threat Intel calls these dropcatch domains, and in the first half of 2026 they accounted for nearly 20% of all new domain registrations, meaning one in five “new” domains has a prior life. Some end up with legitimate investors or researchers. Others end up with attackers who have figured out that a domain with history is worth more than a blank slate. “These domains can be particularly interesting, even dangerous, because they inherit reputation and sometimes connections from their previous life. For example, a domain that was originally registered 10 years ago, later dropped, and then acquired by someone else may still carry signals associated with its long history.” reads the report published by Infoblox. “Researchers, security products, and reputation-based algorithms may view it more favorably than a genuinely brand-new registration. Threat actors know this and take advantage of it.” Among gTLDs, the average is 50,400 per day, with 15 TLDs accounting for about 92% of all dropcatch activity. .net and .xyz have the highest rates, with nearly 30% of new registrations previously registered, while .com reaches 24.5%. Determining who buys these domains and how they are used remains difficult due to WHOIS privacy, transfers, parking, and auctions. The inherited value isn’t just a better reputation score. Expired domains also come with residual web traffic from old backlinks, email still arriving for the previous owner, cached search results, and in some cases lingering DNS records that point to infrastructure no longer under the original owner’s control. One in every five new domains has all of that already baked in before the new registrant does anything. Infoblox tracked one threat actor it calls Sable Squirrel, which has spent nearly $7 million acquiring expired domains to build a criminal operation spanning illegal sports streaming, gambling promotion, and malware infrastructure. The actor controls more than 10,000 domains and runs streaming platforms under brands like Xoilac, Cakhia, and 90phut that direct Vietnamese, Korean, Japanese, and Australian users toward betting sites, while a subset of those same streaming domains double as command-and-control servers for malware including Quasar RAT, AsyncRAT, DCRat, and Remcos RAT. Among the expired domains Sable Squirrel has acquired are healthymagination.com, originally a General Electric health initiative, and rezilion.com, a cybersecurity company whose assets were sold to GitLab in 2024. The actor bought the reputation of a defunct infosec firm and pointed it at malware infrastructure — which is either darkly ironic or exactly what you’d do if you understood how security tools evaluate domain age. “For threat actors specifically, the inherited reputation isn’t the only thing valuable about acquiring a dropped domain. They also come with a variety of lingering connections: email intended for the original domain holder (see watchTowr Labs’ The Perils of Expired Domains: We’re Reading Your Email), cached search results, inherited web traffic, and in some cases, a ready-made platform for code injection on already compromised sites.” continues the report. “Lingering DNS records can also create opportunities for threat actors. We previously discussed dangling CNAME attacks in our blog post, Who Knew Domain Hijacking Is So Easy?.” Once Sable Squirrel re-registers a domain, it moves fast: 24% go live the same day, 76% within seven days, 94% within two weeks. The whole point is to start capturing traffic before security systems have updated their assessments. Infoblox is also tracking three scavenger actors, Stuffy Squirrel, Shady Squirrel, and Swiping Squirrel, that operate differently: rather than buying domains wholesale for a planned operation, they acquire expired domains that were previously compromised by other attackers and simply inherit the existing infection traffic. Shady Squirrel, assessed to be Russian-speaking and active since at least July 2023, feeds that traffic to SocGholish and tech support scam networks. SocGholish reportedly regained access to thousands of compromised sites by teaming up with Shady Squirrel days after its own infrastructure was disrupted by law enforcement. The practical lesson for defenders is uncomfortable: domain age and reputation are inputs worth questioning, not trusting, because an old domain in new hands is only as trustworthy as whoever currently holds it. “This is just one story of how threat actors use dropcatch domains to further their schemes. We’ll cover many more in the next two parts of this research: Part 2, $7 Million in Expired Domains Fuel a Streaming Empire with a Malware Secret, where we examine Sable Squirrel, a threat actor that has spent millions of dollars acquiring dropped domains, and Part 3, Dropcatch Scavengers: Expired Malicious Domains Become Cash Cows, where we explore actors that scavenge expired malicious domains and inherit traffic from previously compromised websites.” concludes the report. Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, Expired domains)

Aug 15, 2026, 05:48 PM Read more →
NETWORK Security Affairs

Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware

Attackers are buying expired domains to exploit their reputation, traffic and DNS history, using them for malware delivery, scams and C2 infrastructure. Every day, roughly 65,000 domain names that once belonged to someone else get re-registered by a new owner. Infoblox Threat Intel calls these dropcatch domains, and in the first half of 2026 they accounted for nearly 20% of all new domain registrations, meaning one in five “new” domains has a prior life. Some end up with legitimate investors or researchers. Others end up with attackers who have figured out that a domain with history is worth more than a blank slate. “These domains can be particularly interesting, even dangerous, because they inherit reputation and sometimes connections from their previous life. For example, a domain that was originally registered 10 years ago, later dropped, and then acquired by someone else may still carry signals associated with its long history.” reads the report published by Infoblox. “Researchers, security products, and reputation-based algorithms may view it more favorably than a genuinely brand-new registration. Threat actors know this and take advantage of it.” Among gTLDs, the average is 50,400 per day, with 15 TLDs accounting for about 92% of all dropcatch activity. .net and .xyz have the highest rates, with nearly 30% of new registrations previously registered, while .com reaches 24.5%. Determining who buys these domains and how they are used remains difficult due to WHOIS privacy, transfers, parking, and auctions. The inherited value isn’t just a better reputation score. Expired domains also come with residual web traffic from old backlinks, email still arriving for the previous owner, cached search results, and in some cases lingering DNS records that point to infrastructure no longer under the original owner’s control. One in every five new domains has all of that already baked in before the new registrant does anything. Infoblox tracked one threat actor it calls Sable Squirrel, which has spent nearly $7 million acquiring expired domains to build a criminal operation spanning illegal sports streaming, gambling promotion, and malware infrastructure. The actor controls more than 10,000 domains and runs streaming platforms under brands like Xoilac, Cakhia, and 90phut that direct Vietnamese, Korean, Japanese, and Australian users toward betting sites, while a subset of those same streaming domains double as command-and-control servers for malware including Quasar RAT, AsyncRAT, DCRat, and Remcos RAT. Among the expired domains Sable Squirrel has acquired are healthymagination.com, originally a General Electric health initiative, and rezilion.com, a cybersecurity company whose assets were sold to GitLab in 2024. The actor bought the reputation of a defunct infosec firm and pointed it at malware infrastructure — which is either darkly ironic or exactly what you’d do if you understood how security tools evaluate domain age. “For threat actors specifically, the inherited reputation isn’t the only thing valuable about acquiring a dropped domain. They also come with a variety of lingering connections: email intended for the original domain holder (see watchTowr Labs’ The Perils of Expired Domains: We’re Reading Your Email), cached search results, inherited web traffic, and in some cases, a ready-made platform for code injection on already compromised sites.” continues the report. “Lingering DNS records can also create opportunities for threat actors. We previously discussed dangling CNAME attacks in our blog post, Who Knew Domain Hijacking Is So Easy?.” Once Sable Squirrel re-registers a domain, it moves fast: 24% go live the same day, 76% within seven days, 94% within two weeks. The whole point is to start capturing traffic before security systems have updated their assessments. Infoblox is also tracking three scavenger actors, Stuffy Squirrel, Shady Squirrel, and Swiping Squirrel, that operate differently: rather than buying domains wholesale for a planned operation, they acquire expired domains that were previously compromised by other attackers and simply inherit the existing infection traffic. Shady Squirrel, assessed to be Russian-speaking and active since at least July 2023, feeds that traffic to SocGholish and tech support scam networks. SocGholish reportedly regained access to thousands of compromised sites by teaming up with Shady Squirrel days after its own infrastructure was disrupted by law enforcement. The practical lesson for defenders is uncomfortable: domain age and reputation are inputs worth questioning, not trusting, because an old domain in new hands is only as trustworthy as whoever currently holds it. “This is just one story of how threat actors use dropcatch domains to further their schemes. We’ll cover many more in the next two parts of this research: Part 2, $7 Million in Expired Domains Fuel a Streaming Empire with a Malware Secret, where we examine Sable Squirrel, a threat actor that has spent millions of dollars acquiring dropped domains, and Part 3, Dropcatch Scavengers: Expired Malicious Domains Become Cash Cows, where we explore actors that scavenge expired malicious domains and inherit traffic from previously compromised websites.” concludes the report. Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, Expired domains)

Aug 15, 2026, 05:48 PM Read more →
RANSOMWARE Security Affairs CVE-2026-58231 ↗

SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild

Attackers are actively exploiting a maximum severity SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231, just days after SAP released a patch. A critical SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231 (CVSS score of 10.0), is under active exploitation just days after SAP released a patch. The flaw stems from insufficient authorization checks and input validation. “SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation.” reads the advisory. “Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.” An unauthenticated attacker can abuse a default authentication client and send crafted input to vulnerable functions, potentially achieving arbitrary code execution and compromising internal components. Researchers at Defused Cyber observed exploitation attempts against honeypots only three days after the patch was released. The researchers pointed out that this vulnerability has no public PoC and had not been known to be exploited prior to their discovery. First exploitation attempts against CVE-2026-58231 (unauth RCE in SAP Commerce Cloud, CVSS 10.0) is now hitting our honeypots – 3 days after patch day. This vulnerability has no public PoC and is not known to be exploited. View the full payload https://t.co/GXFaqggV8a pic.twitter.com/zMJuo45Ahx — Defused (@DefusedCyber) August 14, 2026 The attackers behind the current exploitation remain unknown. However, previous critical SAP flaws have been exploited by China-linked APT groups, including UNC5221 and UNC5174, and ransomware gangs. Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, SAP Commerce Cloud)

Aug 15, 2026, 05:14 PM Read more →