Financial Sector
- When Fraud Needs a Bank: Inside An Ecosystem Built To Manufacture Trust
"An exact search for the phrase “one of the largest digital banking providers” in the source code of publicly available websites flagged approximately 2,200 domains. We investigated each one. Of the sites that still carried the phrase, 97% retained artifacts from Cuex, a commercially available template designed for currency exchange and money transfer websites. It cost $25 at the time of our research. That inexpensive visual layer had been adapted into applications with login and registration forms, investment and transfer language, account dashboards, and other bank-like functions. We call this layered approach legitimacy stacking. Those capabilities work alongside corporate details, compliance claims, and support channels to make an invented institution appear credible. The resulting financial front can provide a convincing pretext for investment, loan, romance, recovery, and advance-fee fraud. One sentence exposed the collection of domains. Deeper investigation and campaign mapping surfaced code, assets, form destinations, identifiers, and public records that ultimately showed how its pieces were connected."
https://alluresecurity.com/blog/signal-noise-when-fraud-needs-a-bank/
https://www.helpnetsecurity.com/2026/08/21/phantom-bank-websites-fraud-research/
Industrial Sector
- How An Emerging Industrial Protocol Family Could Put OT At Risk
"In operational technology (OT) networking, the reliability and availability of industrial processes trumps everything, even cybersecurity. But what happens when an OT networking protocol designed to ensure speedy availability of safety-critical communications also embeds a security weakness into the architecture? Without a full slate of cyber controls folded in, that reliability mechanism could itself become a vehicle for the kinds of industrial failures it's supposed to help prevent."
https://www.darkreading.com/ics-ot-security/how-emerging-industrial-protocol-family-put-ot-at-risk
Vulnerabilities
- Microsoft Warns Of Max Severity Entra ID Flaw Exploited In Attacks
"Microsoft has patched a maximum-severity vulnerability in the Entra ID identity and access management (IAM) platform that has been exploited in attacks. Formerly known as Azure Active Directory (or Azure AD), it is a cloud-based IAM platform that provides Microsoft 365, Azure, or Dynamics CRM Online customers with authentication, policy enforcement, and protection across apps and resources. Tracked as CVE-2026-69836, this critical security flaw was discovered by Microsoft principal security engineer Robert Fitzpatrick, and it allowed threat actors with no privileges to gain code execution in low-complexity attacks."
https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-max-severity-entra-id-flaw-exploited-in-attacks/
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69836
https://thehackernews.com/2026/08/microsoft-entra-id-flaw-cvss-100.html
https://www.securityweek.com/microsoft-rolls-out-22-fresh-security-patches/
https://www.helpnetsecurity.com/2026/08/21/microsoft-entra-id-vulnerability-cve-2026-69836/ - Cisco Patches Nine Crosswork And Secure Workload Flaws, Five Scoring CVSS 10.0
"Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal security review. Four of the security vulnerabilities affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, regardless of the device configuration. A brief description of each of the flaws is below -"
https://thehackernews.com/2026/08/cisco-patches-nine-crosswork-and-secure.html
https://securityaffairs.com/197640/security/six-maximum-severity-flaws-found-in-cisco-products.html
https://www.theregister.com/security/2026/08/21/cisco-bug-severity-warning-reads-like-olympic-gymnastics-scores-10-10-99-96-and-75/5290838 - GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days Of Disclosure
"A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-19478 (CVSS score: 9.4), a case of code injection that allows an unauthenticated attacker to modify or delete publicly accessible GitLab projects and rewrite their data under certain conditions without requiring credentials, user interaction, or obscure configuration."
https://thehackernews.com/2026/08/gitlab-cve-2026-19478-comes-under.html
https://securityaffairs.com/197622/uncategorized/gitlab-warns-of-active-exploitation-of-critical-graphql-flaw.html - CISA Adds One Known Exploited Vulnerability To Catalog
"CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2026-73570 Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability"
https://www.cisa.gov/news-events/alerts/2026/08/21/cisa-adds-one-known-exploited-vulnerability-catalog
https://securityaffairs.com/197693/security/u-s-cisa-adds-zimbra-collaboration-suite-zcs-flaw-to-its-known-exploited-vulnerabilities-catalog.html - Microsoft Defender's Own Driver Can Be Weaponized To Delete Security Software At Boot
"Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine. The driver, BTR.sys (Boot Time Removal Tool), is a required Windows component, which means it cannot be added to Microsoft's Vulnerable Driver Blocklist or blocked via Windows Defender Application Control (WDAC) without disrupting Defender itself."
https://thehackernews.com/2026/08/microsoft-defenders-own-driver-can-be.html
https://research.checkpoint.com/2026/btr-reforged-weaponizing-defenders-remediation-driver-as-a-kernel-operation-primitive/ - Reverse-Engineering Find My People To Stalk My Ex a Friend, Cause I Can
"As it can often be, I was bored. I wanted to look into a complex system, and had no idea which. Me and a friend have been sharing our locations to each other’s through Apple’s “Find My”. I asked if he was okay with me piping it into some dumb automations. He said yes, so the plan was to draw a few geofences around places he goes and make Discord announce whenever he arrived or left."
https://zerotistic.blog/posts/find-my-people-linux/
https://www.theregister.com/security/2026/08/20/researcher-tricks-apples-find-my-into-sharing-location-data-with-linux/5290496
Malware
- SynkLoader: When You Throw In Everything But The Kitchen Sink
"On August 18, we encountered a novel malicious loader while investigating an incident on a client network where the EDR alerted on a scheduled task. There appeared to be no public references to the loader or any of its components; every part of it appeared to be relatively new, with compile dates and file timestamps indicating it was first compiled and distributed around July 28, 2026. To see what the loader would do and what kind of components it might run, we reverse engineered it and created a modified version which logged the attacker’s commands instead of executing them. We also provided the loader with fake system information, making it look like the threat actors had infected a large corporate network."
https://expel.com/blog/synkloader-when-you-throw-in-everything-but-the-kitchen-sink/
https://www.bleepingcomputer.com/news/security/new-synkloader-malware-pushed-in-microsoft-teams-phishing-campaign/ - FTP Banners: The New Dead Drop Resolver Delivering Novel RATs
"Security products have become increasingly effective at detecting suspicious commands used for malware delivery. Consequently, threat actors are adopting more creative methods to bypass these defenses, such as utilizing Dead Drop Resolvers (DDRs): alternative locations, including legitimate web services or protocols, used to acquire malicious strings, Command and Control (C2) configurations, or commands. During an investigation, the SOCRadar Threat Research Unit (STRU) identified the active abuse of FTP banners as DDRs to distribute malicious commands, a technique observed in the wild since early July 2026. Further infrastructure analysis led to the discovery of two previously undocumented Remote Access Trojans (RATs), which we have named E4del and PINHOLE."
https://socradar.io/blog/ftp-banners-new-dead-drop-resolver-rats/
https://www.bleepingcomputer.com/news/security/hackers-abuse-ftp-server-banners-to-deliver-new-windows-malware/ - Fake AI, Real Malware: Attackers Impersonating AI Brands
"Sophos X-Ops reviewed a year of Managed Detection and Response (MDR) cases tagged as ‘AI activity.’ Of the 34 cases that held up, nearly all were attackers creating fake versions of legitimate AI sites and software to infect users with malware. Attackers are exploiting the surge in demand for AI software by faking the software itself: names users trust, like Claude, ChatGPT, and Copilot, become delivery vehicles for malware. For defenders that is good news – or at least, not all bad – because malware is a problem that existing controls are designed to address."
https://www.sophos.com/en-gb/blog/fake-ai-real-malware-attackers-impersonating-ai-brands
https://www.helpnetsecurity.com/2026/08/21/ai-brand-impersonation-malware-malware-research/ - Anatomy Of An Agent Tesla BEC Attack: From Inbox To In-Memory Infostealer
"Phishing is a form of social engineering that has evolved beyond simple lures into complex, multi-stage attacks exploiting trusted software, cloud identities and business platforms to bypass traditional security. Attackers leverage these campaigns to deliver trojans capable of stealing credentials and also establishing remote code execution, which might serve as a gateway for lateral movement. This evolution enables them to maintain persistent access, making it harder for conventional email defenses to detect and mitigate these high-impact threats."
https://blog.knowbe4.com/anatomy-agent-tesla-bec-attack-in-memory-infostealer
https://www.infosecurity-magazine.com/news/agent-tesla-malware-evasion/ - The Invisible Passenger In Your Car
"While monitoring Android threats in June 2026, we discovered a new piece of Android malware. What struck us as unusual was that it installed like an ordinary user app yet made no attempt to disguise itself as legitimate software: it had no user interface at all. This led us to suspect the app might be reaching users’ devices without their knowledge. Further investigation confirmed that hypothesis and allowed us to reconstruct the entire infection chain."
https://securelist.com/android-head-unit-malware/121106/
https://thehackernews.com/2026/08/android-car-malware-spreads-through.html
https://www.bleepingcomputer.com/news/security/hackers-infect-android-car-head-units-with-proxy-botnet-malware/
https://securityaffairs.com/197700/hacking/malware-hijacks-android-car-head-units.html - Prompting The Payload: How An Npm Supply Chain Attack Delivers The RedC2 AI-Powered Linux Implant
"Analysis revealed that a cluster of trojanized npm packages (posing as working calendar and streak utilities) each bundles a malicious Linux ELF payload alongside genuine date-math code. When the module loads, it locates the bundled binary, marks it executable, and launches it as a detached background process. No install hook function call is needed; a single import anywhere in the dependency graph, even a transitive one, is enough to execute the payload. RedC2 4.0 introduced the bundled payload RedShell, a native Linux implant sold on Hack Forums as a cross-platform C&C framework with Windows, macOS, and Linux beacons. It also ships Red Agent, an LLM-backed layer exposed via /ra that turns natural-language intent, such as dumping credentials or locating files, into an ordered chain of beacon commands."
https://www.trendaisecurity.com/en-us/resources-insights/trendai-security-blog/redc2-ai-powered-linux-implant
https://thehackernews.com/2026/08/14-trojanized-npm-packages-drop-redc2.html - iAuthFlow v2 Enrolls Google Passkeys That Survive Password Resets
"When an account compromise is limited to a captured session, revoking that session and resetting the password normally cuts off the attacker’s access. iAuthFlow v2 can use that temporary foothold to establish a separate way back into the account. Once the target completes a phishable Google login, the toolkit uses the authenticated session to enroll a passkey controlled by the operator. In the seller’s recorded demonstration, the account owner later changes their password, invalidating the active session—but the operator authenticates with the newly enrolled passkey and returns to the mailbox."
https://abnormal.ai/blog/iauthflow-v2-phishing-google-passkeys
https://www.securityweek.com/new-phishing-toolkit-uses-passkeys-to-maintain-access-after-password-resets/ - Windows Infostealer Hits Npm And Ruby
"Today, we came across independent research from OpenHack documenting a 37-package typosquatting campaign on npm, targeting chalk, commander, lodash, typescript, react, and axios. It described a 22 MB Rust loader carrying an embedded Go infostealer that decrypts entirely in memory with no second-stage download. That immediately caught our attention, because earlier this week we documented the RubyGems typosquatting campaign StubMaker, which has the same shape. That includes the specific file size."
https://opensourcemalware.com/blog/windows-infostealer-stubmaker-npm-ruby
Breaches/Hacks/Leaks
- Iranian Hackers Shut Down UK Power Plant
"Iran shut down a British power plant for four days in an unprecedented cyber attack, The Telegraph can disclose. It is thought to be the first time that hackers affiliated to the Iranian regime have succeeded in closing down such a facility in the UK, and is believed to be the most successful cyber attack of its kind. The Telegraph understands that the incident took place at the same time as a series of attacks on US water infrastructure last month, which affected 12 states and caused concern in the White House."
https://www.telegraph.co.uk/news/2026/08/22/iranian-hackers-shut-down-uk-power-plant/
https://www.bbc.com/news/articles/ce9793g34yvo
https://securityaffairs.com/197734/cyber-warfare-2/uk-power-plant-disabled-for-four-days-by-iran-linked-hackers-concurrent-with-us-water-attacks.html - 768 Leaked Corporate AWS Keys Held Full Admin Rights
"We re-verified 10,616 leaked AWS keys on August 10, 2026. They surfaced publicly between August 2022 and August 2026. 88% still authenticate. 768 of the live ones belong to a company and carry full control of its AWS account: 526 root keys plus 242 IAM users holding AdministratorAccess. The median live leaked key is five years old and has never been rotated."
https://trufflesecurity.com/blog/leaked-corporate-aws-keys-held-full-admin-rights
https://www.bleepingcomputer.com/news/security/hundreds-of-leaked-aws-keys-give-full-control-over-corporate-accounts/ - SickKids Data Breach Exposes Employee And Job Applicant Info
"The Hospital for Sick Children (SickKids) has disclosed that the personal information of some current and former employees, as well as job applicants, was exposed in a "cybersecurity incident." The hospital says the breach stemmed from a flaw in third-party software. Clinical systems and patient records were untouched, according to the Toronto pediatric hospital, but its public-facing Careers website was temporarily pulled offline."
https://www.bleepingcomputer.com/news/security/sickkids-data-breach-exposes-employee-and-job-applicant-info/
https://therecord.media/canada-hospital-for-sick-children-attacked-again-employee-data - ShinyHunters Leaks 7.1 Million Baxter International Records
"Extortion gang ShinyHunters has struck the healthcare sector again. The notorious cybercriminal gang claims on its darkweb site of leaking 7.1 million Salesforce records stolen from medical device maker Baxter International, including personally identifiable information. "The company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care," ShinyHunters wrote on a post on Wednesday that provided a button to download Baxter International's alleged stolen data."
https://www.bankinfosecurity.com/shinyhunters-leaks-71-million-baxter-international-records-a-32630 - U.S. Bank Says Breach Claims Related To Fourth-Party Incident
"U.S. Bancorp said recent claims of data theft by a ransomware gang are related to a breach involving a contractor for a third-party, and do not impact its own systems or network. A spokesperson told Recorded Future News that U.S. Bancorp has investigated the claims and traced it back to “a potential cyber incident…related to a fourth party event that occurred outside” of their environment. “At this time, there is no evidence that our systems, networks or data repositories were compromised,” the spokesperson said. “We have provided relevant information to law enforcement and continue to support their investigation.”"
https://therecord.media/us-bank-says-breach-claims-related-to-fourth-party-incident
https://www.theregister.com/security/2026/08/20/us-bank-investigates-lockbits-claims-as-ransomware-crims-set-pay-or-leak-deadline/5290560 - Russian Network Monitoring Firm Confirms Cyberattack Claimed By Pro-Ukraine Hackers
"Russian software developer Microolap confirmed that hackers had compromised some of its systems but denied claims that they gained access to its network monitoring platform or stole data belonging to major Russian companies. Microolap, which develops software for intercepting and analyzing network traffic, said Thursday that it had detected an attempted breach of several non-critical systems but found no evidence that hackers accessed its core infrastructure, customer data or other sensitive information. "We urge people not to treat the attackers' claims as fact," Microolap CEO Andrey Smirnov said. "Our cybersecurity systems worked as intended: We detected the incident and kept critical data secure.""
https://therecord.media/russian-network-monitoring-firm-confirms-cyberattack-claimed-by-pro-ukraine-group - Australian Hotel Chain Leaks Guests’ PII After Breach At Third-Party Database Operator
"Australian aparthotel chain Quest has revealed it leaked customer data. A Reg reader kindly shared an email from the chain with the subject line “Important Security Update Regarding Your Quest Data.” That missive opens with unwelcome news that “I am writing to inform you of a recent data security incident involving some of your personal information.” “On Monday, 17 August 2026, we identified unauthorised access to a database system and immediately took steps to contain the incident,” the email continues. “The incident arose from a vulnerability through our third-party service provider.”"
https://www.theregister.com/cyber-crime/2026/08/19/australian-hotel-chain-leaks-guests-pii-after-breach-at-third-party-database-operator/5289341 - Apollo Discloses Data Breach From Ongoing Wave Of Attacks Hitting Financial Sector
"Apollo Global Management confirmed it was among several financial institutions impacted by a string of social engineering attacks that hit the sector last month, the company said Friday. Attackers gained unauthorized access to some of the private equity firm’s cloud platforms between July 6 and July 10, the company said in a data breach notification filed in California. Apollo did not say when or how it became aware of the intrusion and did not respond to a request for comment."
https://cyberscoop.com/apollo-discloses-data-breach-social-engineering-attack/
General News
- July 2026 Infostealer Trend Report
"This report summarizes the distribution channels, number of Infostealers, number of detections, and target companies that were disguised as Infostealers collected during the month of July 2026. It was compiled based on results from AhnLab SEcurity intelligence Center (ASEC)’s automated data collection system, email honeypots, and automated C2 analysis, as well as diagnostic logs from AhnLab products."
https://asec.ahnlab.com/en/95066/ - Endpoint Blind Spots: The 5 Places Ransomware Hides Before It Detonates
"Ransomware rarely appears out of nowhere. Before encryption, extortion, or data theft begins, attackers often spend time establishing access, stealing credentials, moving laterally, and identifying valuable systems. These activities occur during the ransomware pre-execution phase, when malicious activity may be difficult to distinguish from legitimate administration. For security teams, understanding ransomware attack vectors, ransomware initial access methods, and how ransomware evades detection is critical. Endpoint security blind spots can give attackers the time they need to prepare an attack without triggering an obvious alarm."
https://cyble.com/blog/ransomware-attack-vectors-endpoint-blind-spots/ - OpenAI Adds Controls That Should've Been There Already
"OpenAI has committed to a number of security and guardrail improvements in the wake of an incident last month where cutting edge models inadvertently breached AI application store Hugging Face during a cyber capability benchmark exercise. Yet many of the newly announced controls appear less like groundbreaking safeguards and more like measures that should already have been in place for testing models with advanced cyber capabilities."
https://www.darkreading.com/application-security/openai-adds-controls-already - Nearly Half Of Enterprises Have No One Leading PQC Migration
"Enterprises believe they are prepared for the security challenges posed by quantum computing, but gaps in ownership, testing and visibility could complicate their transition to post-quantum cryptography (PQC), according to new research from Axiad. Organizations need to know where certificates, cryptographic keys and algorithms are used before they can plan a PQC migration. About 75% of respondents said they maintain a continuously updated inventory of these assets. However, responses about ownership and testing indicate that visibility does not always translate into migration readiness."
https://www.helpnetsecurity.com/2026/08/21/axiad-pqc-migration-readiness-gaps-report/ - Visualizing Infrastructure Security At Software Project Inception
"The earliest stage of a software project carries engineering risks that are easy to overlook. The software does not yet exist, and the team is busy standing up infrastructure: provisioning servers, writing automation scripts, configuring access controls, and establishing the scaffolding that everything else will run on. The code that does this work—Terraform templates, Ansible playbooks, shell scripts, Dockerfiles—is software too, and it has vulnerabilities. The potential issue at this stage is specific: Scripts that create infrastructure can be exploited to open back doors. A misconfigured Identity and Access Management (IAM) role, an exposed port left open in a provisioning script, or an unpatched base image can quietly become an entry point that persists through every phase of the lifecycle that follows."
https://www.sei.cmu.edu/blog/visualizing-infrastructure-security-at-software-project-inception/ - Named Pipes Under Attack: Securing Windows Interprocess Communication
"Named pipes are a common choice for communication between applications running on the same Windows computer. They are fast, supported directly by the operating system, and work well for communication between Windows services, desktop applications, tray processes, command-line utilities, and background agents. A typical design may include a privileged Windows service acting as the named-pipe server while a user-facing application connects as the client. Because both processes run on the same computer, developers often treat this communication as internal and therefore trusted."
https://www.bleepingcomputer.com/news/security/named-pipes-under-attack-securing-windows-interprocess-communication/ - If You're Not Using AI To Attack Your Own Systems, Your Adversaries Will
"AI agents excel at hacking organizations, as they’ve demonstrated in real-life attacks multiple times over the past few weeks. They also expose a whole new attack surface for organizations trying to protect against both human and AI intrusions. As if defenders needed more worries to keep them up at night, agents introduce new data-integration channels that attackers can abuse. They also introduce a new type – and ever growing number – of non-human identities that are difficult to manage and can bypass traditional, static security policies."
https://www.theregister.com/security/2026/08/22/if-youre-not-using-ai-to-attack-your-own-systems-your-adversaries-will/5291346 - Hardware Makers Implement Post-Quantum Cryptography As Security Threats Near
"Chip makers are baking post-quantum cryptography acceleration into hardware as the threat of quantum systems breaking current encryption rises. The technology is still years away from the general market, but defenders are concerned about harvest-now-decrypt-later attacks that could build up stores of data until quantum computing becomes more widely available to exploit it. Security professionals and regulators encourage organizations to begin future-proofing now, and some key players are acting."
https://www.darkreading.com/cyber-risk/hardware-makers-implement-post-quantum-cryptography
อ้างอิง
Electronic Transactions Development Agency (ETDA) 

































