Sign in

Cybersecurity News Everyday

@hendryadrian.bsky.social
256 followers 101 following 8.7K posts

🔍#ThreatResearch 📰#CybersecurityNews 🖥️#RansomMonitor 📂#InfoDataLeak 🎥#Youtube hendryadrian.com/tweet

PostsRepliesMedia
Cybersecurity News Everyday @hendryadrian.bsky.social · 34m
Ransomware hit Hospital de la Santa Creu i Sant Pau in Barcelona, with potential disruption to healthcare and research operations. The incident was attributed to thegentlemen. #Spain #Barcelona #Healthcare
hendryadrian.com
Ransom! Hospital De La Santa Creu I Sant Pau (OCT-2026)
Hospital de la Santa Creu i Sant Pau (Spain) reported a ransomware incident attributed to thegentlemen, potentially disrupting hospital operations and services. As a major Barcelona academic medical center with extensive research and clinical trial activity, any such impact would affect healthcare delivery across Spain. #Spain
000
Cybersecurity News Everyday @hendryadrian.bsky.social · 49m
Rotamac in Canada was reportedly hit by ransomware from thegentlemen, disrupting industrial equipment distribution and e-commerce operations. #Canada #Ransomware #Manufacturing
hendryadrian.com
Ransom! Rotamac (OCT-2026)
Rotamac Inc. (rotamac.ca) in Canada was reportedly targeted by ransomware by threat actor thegentlemen, impacting operations tied to its industrial equipment distribution and e-commerce services. The incident affected the victim in #Canada
010
Cybersecurity News Everyday @hendryadrian.bsky.social · 1h
Mandurah State Emergency Service in Australia reports a ransomware attack linked to thegentlemen, disrupting 24/7 volunteer rescue operations and cadet support. #Australia #Ransomware #EmergencyService
hendryadrian.com
Ransom! Mandurah State Emergency Service (OCT-2026)
Mandurah State Emergency Service (mandurahses.org.au) in Australia is reported as being targeted by ransomware linked to the threat actor thegentlemen, disrupting operations for a volunteer emergency rescue unit providing 24/7/365 services in WA. The incident claim implicates Australian systems and services, with potential impact on the organization’s responders and cadet support activities. #Australia
010
Cybersecurity News Everyday @hendryadrian.bsky.social · 4h
WOOSHIN SAFETY SYSTEMS CO LTD in South Korea reported a ransomware incident attributed to thegentlemen, disrupting its operations and online services. #SouthKorea #Ransomware #Manufacturing
hendryadrian.com
Ransom! WOOSHIN SAFETY SYSTEMS CO LTD (OCT-2026)
WOOSHIN SAFETY SYSTEMS CO LTD (KR) reported a ransomware incident attributed to the threat actor “thegentlemen,” impacting its wooshinsys.co.kr and related online assets. The claim indicates disruption to operations and services in South Korea. #SouthKorea
000
Cybersecurity News Everyday @hendryadrian.bsky.social · 4h
Storm ransomware disrupted Step By Step, Inc., a US nonprofit serving people with disabilities, impacting residential, behavioral health, autism, and in-home support programs. #UnitedStates #Ransomware #Nonprofit
hendryadrian.com
Ransom! Step By Step (OCT-2026)
Storm ransomware targeted Step By Step, Inc. (US-based nonprofit human services organization) disrupting community-based support services across residential, behavioral health, autism, and in-home programs for individuals with intellectual and physical disabilities and related needs. The incident impacted United States #UnitedStates
000
Cybersecurity News Everyday @hendryadrian.bsky.social · 5h
TheGentlemen ransomware hit Zelham, a Boise-based hospitality renovation contractor, aiming to steal data and disrupt operations across multiple U.S. states. #UnitedStates #Ransomware #Boise
hendryadrian.com
Ransom! Zelham (OCT-2026)
Thegentlemen ransomware group compromised Zelham (zelham.com) and targeted systems of the U.S. hospitality renovation general contractor, seeking to extort through data theft and disruption. Zelham, Inc., headquartered in Boise, Idaho, with operations across multiple U.S. states, was affected in #unitedstates
000
Cybersecurity News Everyday @hendryadrian.bsky.social · 9h
MI5 says over 100 U.K.-linked academics may have aided China’s MSS through CGTRI-funded research in AI and cybersecurity, raising national security concerns under the National Security Act 2023. #UK #MI5 #MSS
hendryadrian.com
MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics
MI5 has warned that more than 100 U.K.-linked academics may have helped China’s Ministry of State Security strengthen its intelligence capabilities through research funded by CGTRI, which the agency assesses is a front company for the MSS. The alert urges U.K. institutions to review collaborations with CGTRI and warns that continued...
000
Cybersecurity News Everyday @hendryadrian.bsky.social · 9h
Warlock exploits SharePoint flaws to disable security tools and deploy ransomware, targeting critical infrastructure, government, and education sectors across Europe, Africa, and Latin America. #Portugal #SharePoint #Ransomware
hendryadrian.com
Warlock Exploits SharePoint Flaws To Disable Security Tools And Deploy Ransomware
Warlock, also known as Gold Salem, Longlegs, and Storm-2603, is still exploiting Microsoft SharePoint vulnerabilities to attack organizations in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America. The group has targeted critical infrastructure, government, and education sectors while using web shells, BYOVD, legitimate tools, and SYSVOL staging to disable...
010
Cybersecurity News Everyday @hendryadrian.bsky.social · 10h
Suspected ShinyHunters member Rey, identified as Saif al-Din Khader, was reportedly detained in Jordan and is now cooperating with the FBI in efforts to identify other members. #ShinyHunters #Jordan #FBI
hendryadrian.com
ShinyHunters Hacker Reportedly Detained In Jordan, Aiding FBI
A suspected ShinyHunters member known as "Rey," identified as Saif al-Din Khader, has reportedly been detained in Jordan and is now cooperating with the FBI and other law enforcement agencies. The reported arrest comes amid intensified action against ShinyHunters following claims of an FBI breach, as the group’s infrastructure appeared to go offline even while a new data leak site later surfaced. #ShinyHunters #SaifalDinKhader #Rey #FBI #Jordanianauthorities
001
Cybersecurity News Everyday @hendryadrian.bsky.social · 11h
Wallstreet ransomware reportedly disrupted St. Francis Healthcare Systems of Hawaii, a nonprofit Catholic provider serving families since 1927, affecting operations and critical systems. #UnitedStates #Healthcare #Hawaii
hendryadrian.com
Ransom! St. Francis Healthcare Systems Of Hawaii (OCT-2026)
Wallstreet ransomware reportedly targeted St. Francis Healthcare Systems of Hawaiʻi, a Catholic, nonprofit healthcare organization serving Hawaiʻi families since 1927, disrupting operations and access to critical systems. The impacted country(s) is #UnitedStates.
000
Cybersecurity News Everyday @hendryadrian.bsky.social · 11h
Wallstreet claims a breach of the Saudi network tied to the Jeddah Central Stadium project for World Cup 2034, alleging 17 TB and 1.5M files exfiltrated, including contracts and employee data. #SaudiArabia #WorldCup2034 #Ransomware
hendryadrian.com
Ransom! World Cup 2034 (OCT-2026)
Wallstreet ransomware actors claim they compromised the Saudi network of the China Railway Construction Corporation Saudi Branch / Sama Construction consortium, targeting the main contractor work for the Jeddah Central Stadium for FIFA World Cup 2034 in Saudi Arabia. They report exfiltrating 17 TB and 1.5M files, including contract, dispute/suspension documentation, IFC design files, supplier bid data, and personal data for 150,000+ employees. #SaudiArabia
010
Cybersecurity News Everyday @hendryadrian.bsky.social · 12h
Ransomware gang Storm claimed Allied Machine and Engineering, a US manufacturer of precision tooling for metalworking. The Dover, Ohio company was disclosed on Oct. 2, 2026. #US #Manufacturing #Ransomware
hendryadrian.com
Ransom! Allied Machine & Engineering (OCT-2026)
Allied Machine & Engineering, a US precision cutting tool manufacturer, reported a ransomware incident attributed to the Storm threat actor. The company, headquartered in Dover, Ohio, produces advanced holemaking and finishing tooling for metalworking industries and was impacted in the United States. #UnitedStates
000
Cybersecurity News Everyday @hendryadrian.bsky.social · 14h
FortiMail zero-day abuse, Dell CSM privilege risk, Kiteworks code injection, and self-repairing WordPress malware headline the recap. AI agents probed U.S. and Canada government sites with SQLi. #USA #FortiMail #WordPress
hendryadrian.com
Page Not Found - Cybersecurity News Everyday
000
Cybersecurity News Everyday @hendryadrian.bsky.social · 14h
At the Global Anti-Scam Summit America, Gen’s scam research lead discussed moving beyond general warnings to help people recognize manipulation and make safer decisions as scams unfold.
cyber.hendryadrian.com
Gen Highlights Real-Time Consumer Education in the Fight Against Scams
At the Global Anti-Scam Summit America, Gen’s scam research lead discussed moving beyond general warnings to help people recognize manipulation and make…
000
Cybersecurity News Everyday @hendryadrian.bsky.social · 14h
Genesis Credit Management in the US reported a Qilin ransomware incident disrupting systems and data availability. #UnitedStates #Ransomware #Qilin
hendryadrian.com
Ransom! Genesis Credit Management (OCT-2026)
Genesis Credit Management in the US reported a ransomware incident attributed to the qilin threat actor, resulting in disruption of its systems and data availability. The impacted country is: #UnitedStates
000
Cybersecurity News Everyday @hendryadrian.bsky.social · 15h
Precon Marine Inc reported a ransomware attack by netrunner, disrupting operations in a limited country impact. The marine contractor specializes in heavy construction and subsea services. #Transportation #Marine #countryname
hendryadrian.com
Ransom! Precon Marine Inc (OCT-2026)
Precon Marine Inc, a diversified marine contractor specializing in heavy marine construction and advanced subsea services, reported a ransomware incident allegedly carried out by threat actor netrunner. The attack resulted in disruption to the company’s operations, with impact limited to the affected country/entities. #countryname
000
Cybersecurity News Everyday @hendryadrian.bsky.social · 15h
doxx.net raised $38M led by Andreessen Horowitz to expand its Agentic Defined Networking platform, using private serverless networking and DNS-level protection to block phishing and malware before connections form. #doxxnet #AIagents #Networking
hendryadrian.com
Doxx.net Raises $38 Million To Prevent AI Agent-on-the-Internet Misadventures
doxx.net has raised $38 million in a Series A round led by Andreessen Horowitz to expand its Agentic Defined Networking platform for humans and AI agents. The platform combines private, serverless networking with DNS-level threat protection to block malicious destinations, phishing sites, and malware before connections are made. #doxxnet #AndreessenHorowitz #AgenticDefinedNetworking...
020
Cybersecurity News Everyday @hendryadrian.bsky.social · 15h
Fortra patched 8 BoKS flaws, including 3 critical bugs that could enable auth bypass, command injection, and remote memory corruption in Manager deployments and exposed interfaces. #Fortra #BoKS #CVE202679901
hendryadrian.com
Fortra Patches Critical Vulnerabilities In BoKS
Fortra has patched eight vulnerabilities in Core Privileged Access Manager (BoKS), including three critical flaws that could lead to authentication bypass, command injection, and remote memory corruption. The issues affect BoKS Manager deployments, with notable risks tied to Active Directory service account management and network-accessible interfaces such as BCC and WSI....
000
Cybersecurity News Everyday @hendryadrian.bsky.social · 16h
Cybersecurity in 2026 is centered on identity security, smarter telemetry, and unified protection across endpoints, cloud, and connected devices as organizations move toward continuous visibility and faster remediation. #IdentitySecurity
hendryadrian.com
The State Of Cybersecurity In 2026: Key Segments, Insights, And Innovations
Cybersecurity is evolving to keep pace with cloud expansion, AI, distributed systems, and the growing complexity of modern digital environments. The report shows how organizations are shifting toward continuous visibility, stronger identity control, faster remediation, and unified protection across identities, endpoints, cloud, and connected devices. #KeeperSecurity #Cribl #Automox #Nisos #SurfAI #AdaptiveSecurity...
000
Cybersecurity News Everyday @hendryadrian.bsky.social · 19h
Storm ransomware claimed an attack on States Industries, a Eugene, Oregon hardwood plywood and veneer manufacturer, disrupting operations, products, and employees. #UnitedStates #Manufacturing #Ransomware
hendryadrian.com
Ransom! States Industries (OCT-2026)
Storm ransomware claimed it targeted States Industries, a privately held US hardwood plywood and veneer panel manufacturer based in Eugene, Oregon. The company’s operations, products, and employees were impacted, with the claim ending in #UnitedStates
000
Cybersecurity News Everyday @hendryadrian.bsky.social · 20h
Aware, Inc. reports a ransomware attack by thegentlemen, disrupting biometrics identity verification SaaS operations. About 400 GB of data was reportedly stolen. #UnitedStates #Ransomware #Biometrics
hendryadrian.com
Ransom! Aware (OCT-2026)
Aware, Inc. (US) reports a ransomware incident associated with the threat actor “thegentlemen,” impacting its biometrics identity verification SaaS operations and related workflows. The alleged intrusion is linked to the company’s online presence and the incident is reported in the United States. #UnitedStates
000
Cybersecurity News Everyday @hendryadrian.bsky.social · 21h
A dataset allegedly linked to the Royal Belgian Football Association is for sale by RedStone, with claims of 346,685 unique names and records on players, referees, clubs, and officials. #Belgium #RBFA #DataLeak
hendryadrian.com
Royal Belgian Football Association Dataset Offered For Sale With 346,685 Unique Names Claimed
A dataset allegedly linked to the Royal Belgian Football Association is being offered for sale by the actor “RedStone,” with claims of 346,685 unique names and extensive records on players, referees, clubs, and officials. If authentic, the exposed data could enable phishing, impersonation, and other social-engineering attacks against people connected to...
000
Cybersecurity News Everyday @hendryadrian.bsky.social · 21h
Aqua Nautilus describes Koske, a Linux cryptomining malware campaign that uses image-embedded payloads, persistence mechanisms and a userland rootkit. Researchers say its modular code and adaptive behavior may indicate AI assistance.
cyber.hendryadrian.com
Koske Linux Malware Hides in Panda Images and Shows Signs of AI-Assisted Development
Aqua Nautilus describes Koske, a Linux cryptomining malware campaign that uses image-embedded payloads, persistence mechanisms and a userland rootkit…
010
Cybersecurity News Everyday @hendryadrian.bsky.social · 03/10/2026
Nightspire ransomware hit Forma Therapeutics in the US, exposing clinical trial data, lab notebooks, research IP, drug discovery, and genomic records. #UnitedStates #Ransomware #PharmaData
hendryadrian.com
Ransom! Forma Therapeutics Holdings, Inc. (OCT-2026)
Nightspire ransomware targeted Forma Therapeutics Holdings, Inc. in the US, compromising clinical trial and statistical data along with electronic lab notebooks, research IP, drug discovery and pipeline information, and biological/genomic data. Impacted country: #UnitedStates
011
Cybersecurity News Everyday @hendryadrian.bsky.social · 03/10/2026
Spirals ransomware claims a breach of Seven Seas Group, a UK maritime services provider for ship supplies, spare parts, and technical brands. Disruption has been linked to the attack in the United Kingdom. #UnitedKingdom #Maritime #Ransomware
hendryadrian.com
Ransom! Seven Seas Group (OCT-2026)
Spirals ransomware claimed it compromised Seven Seas Group, a GB-based global maritime services provider specializing in ship supplies, stores, spare parts, and technical maritime brands. The victim’s disruption is attributed to the attack’s effects in #UnitedKingdom
011
Cybersecurity News Everyday @hendryadrian.bsky.social · 03/10/2026
Settra claims a ransomware leak involving Windor Supply and Manufacturing, Inc., with details published on a leak site in Oct 2026. #Ransomware #Windor #Manufacturing
hendryadrian.com
Ransom! Www.windor.com (OCT-2026)
Settra ransomware impacted www.windor.com, encrypting files including “Windor Supply & Manufacturing, Inc. PROLOGUE Sales representative Mark Brewster, on D…”. The victim’s systems were compromised with data/availability harm, affecting #countryname
001
Cybersecurity News Everyday @hendryadrian.bsky.social · 03/10/2026
Autonomous weapons are already active in Ukraine, with AI-assisted drones selecting targets with minimal human control. International red lines, accountability, and civilian safeguards are needed before such systems spread. #Ukraine #AIWeapons #ICRC
hendryadrian.com
Autonomous Weapons Are A Global Threat To Civilians And Require International Cooperation
Autonomous AI weapons are no longer theoretical, and the war in Ukraine shows how they can independently navigate, identify, and strike targets with minimal human control. The article urges governments to set clear international red lines, accountability rules, and protections for civilians before these systems become normalized in future conflicts. #Nvidia #JetsonOrin #Zaporizhzhia #Ukraine #Russia #InternationalCommitteeoftheRedCross #UnitedNations #ICAS #GCRAI
100
Cybersecurity News Everyday @hendryadrian.bsky.social · 03/10/2026
Thai Lion Air was hit by a Qilin ransomware attack in Thailand, disrupting business operations through unauthorized file encryption. #Thailand #ThaiLionAir #Ransomware
hendryadrian.com
Ransom! Thai Lion Air (OCT-2026)
Thai Lion Air in Thailand was targeted by ransomware attributed to the qilin threat actor, resulting in disruption to business operations through unauthorized encryption of files. The incident impacted systems in #Thailand
000
Cybersecurity News Everyday @hendryadrian.bsky.social · 03/10/2026
Qilin ransomware reportedly hit Sports Events365 in the UK, encrypting files and disrupting operations at the hospitality firm. #UnitedKingdom #Ransomware #Hospitality
hendryadrian.com
Ransom! Sports Events365 (OCT-2026)
Sports Events365 in the UK was targeted by the qilin ransomware threat actor, resulting in encrypted files and disruption of operations. The incident impacted the United Kingdom #UnitedKingdom
020
Cybersecurity News Everyday @hendryadrian.bsky.social · 03/10/2026
A post claims to sell 882,918 CNAM records with names, birth dates, birthplaces, and internal student IDs, plus a 1,500-line sample. If real, the data could support impersonation and identity fraud. #CNAM #DataLeak #France
hendryadrian.com
CNAM Data Claim Lists 882,918 Records With Birth Details And Internal Student IDs
A listing attributed to Syrv4x claims to offer data tied to CNAM, including 882,918 records and fields such as names, dates and locations of birth, and internal student IDs. If genuine, the dataset could enable phishing, impersonation, and identity fraud against students and other individuals connected to CNAM. #Syrv4x #CNAM #ConservatoireNationaldesArtsetMétiers...
000
Cybersecurity News Everyday @hendryadrian.bsky.social · 03/10/2026
Threat listing claims data tied to Morocco's MICEPP, alleging 150,000 folders and records on 50,000 investors, plus ID-related files, company data, and public institution info. #Morocco #MICEPP #DataLeak
hendryadrian.com
Morocco Investment Ministry Data Claim Includes 150,000 Folders And Records On 50,000 Investors
A threat listing claims to sell data tied to Morocco’s Ministry of Investment, Convergence and Evaluation of Public Policies (MICEPP), alleging more than 150,000 folders and records on over 50,000 investors. The unverified dataset is said to include administrative documents, authorization files, national ID-related data, and information on Moroccan companies and...
000
Cybersecurity News Everyday @hendryadrian.bsky.social · 03/10/2026
Claimed FMG Sales and Marketing data lists 10,343 records in a 7 MB file, with names, phones, emails, addresses, birth details, and a field labeled numSecurite that may indicate French social security IDs. #DataLeak #France #DarkWeb
hendryadrian.com
FMG Sales & Marketing Data Claim Lists 10,343 Records With Contact And Social Security Fields
A threat actor named Syrv4x claims to be offering a free dataset tied to FMG Sales & Marketing, with 10,343 records in a 7 MB file. If authentic, the data could include contact details, birth information, addresses, and a field labeled numSecurite that may contain French social security identifiers. #FMGSalesMarketing #Syrv4x...
000
Cybersecurity News Everyday @hendryadrian.bsky.social · 03/10/2026
A threat actor claims to sell an Explorest dataset from a breach affecting 263,900 users. The alleged records span 2017-2026 and include names, emails, password fields, countries, and device tokens. #Explorest #USA #DataLeak
hendryadrian.com
Explorest Dataset Offered For One-Time Sale After Claimed Breach Of 263,900 Users
A threat actor using the handle "888" claims to be selling a one-time dataset tied to Explorest, a U.S.-based travel and photography platform, with 263,900 unique users reportedly affected. The alleged data spans 2017–2026 and includes names, email addresses, password-related values, countries, and device tokens. #Explorest #888...
000
Cybersecurity News Everyday @hendryadrian.bsky.social · 03/10/2026
Unverified listing claims a FitnessBoutique customer dataset is for sale: 1.96M records, 3.5 GB, priced at $750 negotiable. Data may include names, emails, phone numbers, and addresses. #FitnessBoutique #DataLeak #France
hendryadrian.com
FitnessBoutique Customer Dataset Offered For Sale With 1.96 Million Records
A listing by the actor Syrv4x claims to offer a FitnessBoutique customer dataset containing 1,960,466 records and 3.5 GB of data for $750, negotiable. If authentic, the data could expose customer contact details and account-related information, but the claim remains unverified. #FitnessBoutique #Syrv4x #fitnessboutiquefr...
000
Cybersecurity News Everyday @hendryadrian.bsky.social · 03/10/2026
Bipartisan backlash is mounting against AI-powered ALPR cameras as Congress introduces two bills targeting Flock-style license plate readers, with lawmakers pushing for stronger privacy safeguards and oversight. #ALPR #Flock #Congress
hendryadrian.com
Bipartisan Backlash To ALPRs Grows As Two High-profile Bills Are Introduced
Two new congressional bills show that bipartisan backlash against AI-powered ALPR cameras has intensified, putting Flock and other license plate reader companies under growing political pressure. Lawmakers and privacy advocates argue the systems enable mass surveillance and abuse, while Flock says the technology needs guardrails, oversight, and support for public safety....
000
Cybersecurity News Everyday @hendryadrian.bsky.social · 03/10/2026
Vicksburg, Mississippi shut down city systems after a ransomware attack disrupted utility payments. Emergency services stayed online as officials, FBI, DHS, and experts investigate possible data exposure. #Vicksburg #Mississippi #FBI
hendryadrian.com
Mississippi Mayor Says Ransomware Incident Led City To Shut Down Systems
A ransomware attack has temporarily shut down the computer systems of Vicksburg, Mississippi, affecting utility payments but not emergency services. The city is working with the FBI, DHS, state officials, and private cybersecurity experts to investigate whether any personal or confidential information was accessed. #Vicksburg #FBI #DepartmentofHomelandSecurity...
010
Cybersecurity News Everyday @hendryadrian.bsky.social · 03/10/2026
California federal judge dismisses El Faro journalists' Pegasus spyware lawsuit for lack of jurisdiction. The case involved at least 226 attacks on Carlos Dada and colleagues, with an appeal planned. #ElFaro #Pegasus #Salvadoran
hendryadrian.com
Judge Dismisses Spyware Case Brought By Salvadoran Journalists Targeted With Pegasus
A California federal judge dismissed a lawsuit brought by El Faro journalists whose phones were targeted with Pegasus spyware, ruling the case lacked jurisdiction in California. The Knight First Amendment Institute said Pegasus was used against Carlos Dada and colleagues at least 226 times, and it plans to appeal the decision....
000
Cybersecurity News Everyday @hendryadrian.bsky.social · 03/10/2026
Microsoft tracked a fake software download campaign impersonating trusted vendors to deliver malicious installers, hitting China-based operations and Chinese-speaking users. #SilverFox #China #FakeInstaller
hendryadrian.com
DNS Spotlight: Silver Fox Strikes Anew With A Fake Installer Campaign
Microsoft tracked a fake software download campaign that impersonated trusted vendors and pushed malicious installers, with the activity mainly affecting multinational organizations’ China-based operations and Chinese-speaking users. The investigation linked the campaign to patterns consistent with prior Silver Fox fake software activity and uncovered multiple domain, subdomain, IP, and email-connected artifacts, including malicious domains such as oijfwe[.]net and ai-claude[.]com[.]cn. #SilverFox #oijfwe #ai-claude
010
Cybersecurity News Everyday @hendryadrian.bsky.social · 03/10/2026
SMTP port 25 is being abused by BPFDoor, BPF Rekoobe, and AVERAT to blend into telecom and appliance networks with BPF filters and fileless staging. South Korea, Taiwan, and edge devices were hit. #SouthKorea #BPFDoor #AVERAT
hendryadrian.com
SMTP Is The Key: BPFDoor And AVERAT Hitting The Network Edge
Rapid7 analyzed BPFDoor, BPF Rekoobe, and AVERAT samples that disguise themselves to match telecom and appliance environments, using port 25, BPF socket filters, and fileless staging to evade detection. The campaign affected South Korean, Taiwanese, and ShareTech/SpamSniper-related systems, including mail-security appliances, NAS devices, DVRs, and other edge infrastructure. #BPFDoor #BPFRekoobe #AVERAT #ShareTech #SpamSniper #ChunghwaTelecom
010
Cybersecurity News Everyday @hendryadrian.bsky.social · 03/10/2026
Panzer ransomware hit Brazilian IT firm Paessolucoes, disrupting operations and possibly exposing data. The company provides software, hosting, backup, VPS, and support. #Brazil #Ransomware #ITCompany
hendryadrian.com
Ransom! Paessolucoes (OCT-2026)
Paessolucoes, a Brazilian IT company (paessolucoes.com.br) in Campo Mourão, Paraná, was targeted by the Panzer ransomware threat actor. The attack resulted in disruption and potential data exposure, impacting operations in #Brazil
000
Cybersecurity News Everyday @hendryadrian.bsky.social · 03/10/2026
Rhysida claims a breach at Electro Heat Sweden AB, alleging 1.7M files and 2.55 TB stolen, including SolidWorks IP, accounting and payroll data, passports, visas, and signed contracts. #Sweden #Ransomware #Energy
hendryadrian.com
Ransom! Electro Heat Sweden AB (OCT-2026)
rhysida ransomware claims to have compromised Electro Heat Sweden AB in Sweden (SE) by exfiltrating 1,723,527 files totaling 2.55 TB, including SolidWorks CAD intellectual property and critical engineering and business records such as Visma/SCPS accounting and payroll databases. The group further alleges theft of legally sensitive documents, employee passport and visa data, and signed contracts/acceptance certificates. #Sweden
000
Cybersecurity News Everyday @hendryadrian.bsky.social · 02/10/2026
Socket found a VS Code theme cluster across Marketplace and Open VSX, with 2 malicious extensions, GlassWorm links, obfuscated loaders, a batch downloader, and Solana memo dead drops. #GlassWorm #VSCode #OpenVSX
hendryadrian.com
Pretty Themes, Hidden Loaders: GlassWorm-Linked Extensions Span VS Code Marketplace And Open VSX
Socket uncovered a cluster of VS Code theme extensions spanning the Visual Studio Marketplace and Open VSX, including two confirmed malicious extensions and a high-confidence link to GlassWorm. The investigation found obfuscated JavaScript loaders, a Windows batch downloader, Solana transaction-memo dead drops, and shared Git history linking extensions such as Aurora Nocturne Night Theme, Coca-Cola Christmas, Aurora Borealis Studio Theme, and Cosmic Nebula Themes. #GlassWorm #AuroraNocturneNightTheme #CocaColaChristmas #AuroraBorealisStudioTheme #CosmicNebulaThemes
000
Cybersecurity News Everyday @hendryadrian.bsky.social · 02/10/2026
Beyond Gravity disclosed a targeted cyberattack after detecting malicious activity on Aug. 12. The aerospace supplier is working with Swiss authorities and Mandiant as forensic investigations continue. #BeyondGravity #Switzerland #Mandiant
hendryadrian.com
The Aerospace Company Beyond Gravity Was The Target Of A Cyberattack
Beyond Gravity, a federally owned aerospace supplier, has disclosed a targeted cyberattack after detecting malicious activity in its IT environment on August 12. The company is working with the Federal Office for Cybersecurity and Mandiant, while forensic investigations and security measures continue. #BeyondGravity #Mandiant #FederalOfficeforCybersecurity #Ruag
000
Cybersecurity News Everyday @hendryadrian.bsky.social · 02/10/2026
GitLab fixed CVE-2026-90970, a critical 9.9 AI Gateway flaw in self-hosted servers that could let logged-in Duo Agent Platform users run commands. Patched in 19.2.4, 19.3.2, and 19.4.1. #GitLab #CVE202690970 #DuoAgentPlatform
hendryadrian.com
GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution On Self-Hosted Servers
GitLab has fixed a critical AI Gateway flaw, tracked as CVE-2026-90970, that could let a logged-in user with Duo Agent Platform access execute arbitrary commands under certain conditions. Organizations hosting their own gateway should update immediately to the patched versions 19.2.4, 19.3.2, or 19.4.1. #GitLab #CVE-2026-90970 #DuoAgentPlatform...
000
Cybersecurity News Everyday @hendryadrian.bsky.social · 02/10/2026
China-nexus UAT-11587 hit government and policy groups across Asia and Syria with Antino, a Rust-based Windows backdoor using Outlook and OneDrive for Microsoft 365 command-and-control. #China #Antino #Outlook
hendryadrian.com
Antino Backdoor Uses Outlook And OneDrive For C2 In China-Nexus Espionage Campaign
A China-nexus threat actor tracked as UAT-11587 has targeted government and policy organizations across Asia and Syria using a new Rust-based Windows backdoor called Antino. The campaign relies on spear-phishing, spoofed identities, and Microsoft 365-based command-and-control through Outlook and OneDrive to deliver multi-stage malware and evade detection. #UAT11587 #Antino #Microsoft365 #Outlook...
000
Cybersecurity News Everyday @hendryadrian.bsky.social · 02/10/2026
Dell patched critical flaws in Container Storage Modules that could allow unauthenticated admin access, credential theft, and root on Kubernetes nodes. Affected versions are prior to 1.17.0, fixed in 1.18.0. #Dell #Kubernetes #CVE202663688
hendryadrian.com
Dell CSM Flaws Enable Unauthenticated Admin Access And Root On Kubernetes Nodes
Dell has released updates for multiple critical flaws in Dell Container Storage Modules (CSM) that could let attackers bypass authentication, steal credentials, and gain administrative or root access across storage infrastructure and Kubernetes clusters. The issues affect CSM versions prior to 1.17.0 and are fixed in 1.18.0, with Dell urging customers...
010
Cybersecurity News Everyday @hendryadrian.bsky.social · 02/10/2026
Frontline Education says a third-party flaw exposed school district employee data, including Social Security numbers, emails, and addresses. The issue has been fixed, law enforcement notified, and credit monitoring offered. #FrontlineEducation
hendryadrian.com
Frontline Education Breach Exposes School District Employee Data
Frontline Education is warning school districts about a data breach after attackers abused a vulnerability in a third-party application to access parts of its environment and steal employee data, including Social Security numbers. The company says it remediated the flaw, involved law enforcement, and is offering credit monitoring and identity protection to impacted individuals while notifying districts and regulators. #FrontlineEducation #TransUnion
000
Cybersecurity News Everyday @hendryadrian.bsky.social · 02/10/2026
Warlock ransomware used SharePoint flaws to breach a water utility, telecom provider, government body, and university across Europe, Africa, and Latin America, then deployed an EDR killer before encryption. #Warlock #SharePoint #China
hendryadrian.com
Warlock Ransomware Breach SharePoint In Water, Telecom Operator Attacks
Warlock, a China-linked ransomware group, targeted multiple organizations including a water utility, telecom provider, regional government body, and a university by exploiting SharePoint vulnerabilities for initial access. The attackers used ToolShell flaws, deployed an EDR-killing tool, and staged Warlock ransomware across compromised networks before launching encryption. #Warlock #ToolShell #Longlegs #K7RKScan #MicrosoftSharePoint
000
Cybersecurity News Everyday @hendryadrian.bsky.social · 02/10/2026
GitLab disclosed CVE-2026-90970, a critical AI Gateway RCE that can let authenticated users with basic privileges escape the sandbox and run arbitrary commands on self-hosted instances. #GitLab #CVE202690970 #AIGateway
hendryadrian.com
GitLab Warns Of Critical RCE Vulnerability In AI Gateway Service
GitLab has warned customers to urgently patch CVE-2026-90970, a critical AI Gateway vulnerability that could let authenticated attackers with basic privileges escape the sandbox and execute arbitrary commands on vulnerable self-hosted instances. The company released fixed versions for GitLab Self-Hosted AI Gateway users and said hosted GitLab AI Gateway customers are already protected, following its recent patching of CVE-2026-85706. #GitLab #CVE-2026-90970 #CVE-2026-85706 #CISA
000
Cybersecurity News Everyday @hendryadrian.bsky.social · 02/10/2026
US Treasury sanctioned 8 Tren de Aragua members tied to ATM jackpotting hacks that stole millions. Authorities say malware like Ploutus forced ATMs to spit out cash. #TrenDeAragua #FBI #US
hendryadrian.com
US Sanctions Tren De Aragua Gang Members In ATM Hacks Crackdown
The U.S. Treasury has sanctioned eight members of Tren de Aragua for their roles in ATM jackpotting attacks that stole millions of dollars from U.S. financial institutions. Authorities say the gang used malware such as Ploutus to force ATMs to dispense cash, and the case has led to major U.S. enforcement actions against TdA-linked networks. #TrenDeAragua #Prometheus #Ploutus #OFAC #FBI
000