
Some weeks have one big security story. Others bring many smaller updates that are easy to miss but still matter. This week has plenty of them, covering cloud services, AI tools, malware, data breaches, scams, and new attack methods.
The latest ThreatsDay Bulletin puts all of these short updates in one place, so you can quickly catch up on what happened, what changed, and what security teams should know.
The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out.
- Guest Access Data Theft
New City-Forum Campaign Targets Salesforce and ServiceNow Instances
An ongoing campaign dubbed City-Forum has been observed targeting unauthenticated guest user access in both Salesforce Experience Cloud sites and ServiceNow (SNOW) Service Portals. "A single server is pulling records out of Salesforce Experience Cloud sites and ServiceNow (SNOW) Service Portals, from infrastructure that has been standing since March 2025," Reco said. "Except for Aura, the attacker reaches Salesforce Lightning Web Runtime (LWR) sites through the UI-API, a data layer we have not seen any public tool or write-up about, and it hammers a native ServiceNow Service Portal search endpoint that has almost no online documentation or well-known open source tools." The IP address in question is 158.220.87[.]79, which resolves to the domain "city-forum[.]com," giving the campaign its name. The use of little known techniques in the activity points to an advanced threat actor. Data is exfiltrated from Salesforce LWR sites using GraphQL. Targets include telecoms, banks and financial-services firms, enterprise-software vendors including security and data-privacy companies, and public-sector portals. Per Reco, the busiest target recorded more than 560,000 events from the attacker's IP address, with nearly all of them related to guest Aura enumeration.
- Customer Data Exposed
ShipMonk Suffers Data Breach
ShipMonk, one of Trezor's shipping providers, has experienced a data breach that exposed sensitive customer order data, including full names, shipping addresses, phone numbers, and email addresses. "This data breach can potentially affect new customers who received an order from the following countries: the U.S., the U.K., Sweden, Colombia, Brazil, Italy, and Portugal between 10th of May and 8th of August 2026," Trezor said.
- Pre-Trust Code Execution
Cursor CLI Runs Untrusted Repository Code
Cursor has fixed an issue in its command-line (CLI) coding agent that allowed a cloned repository to run any command on a developer's machine before they were prompted if they trusted it, and outside the sandbox even when the sandbox had been explicitly enabled. "A repository could execute any command it chose on your machine, as you, the moment you started Cursor's CLI agent in it with -w," Manifold Security said. "It ran before the workspace-trust dialog, and fired even for users who had explicitly passed –sandbox enabled. The command sat in a normal tracked file, .cursor/worktrees.json, so it arrived with an ordinary git clone. Nothing on that path constrained it: reading ~/.ssh, taking cloud credentials from the environment, opening a reverse shell, writing persistence." Following responsible disclosure on July 20, 2026, a patch was released three days later.
- Vishing at Scale
Inside Look at Worker Panel
Okta has published details about Work Panel, an operator console that's used by threat actors running vishing campaigns targeting identity providers, including itself. "Work Panel is a multi-tenant platform that packages everything an operator needs to run a vishing-driven account takeover operation," the company said. "Registering a new phishing domain, cloning a target brand, and standing up a new isolated phishing site are each one-button operations. New campaigns can be launched in minutes." Work Panel is used by infrastructure owners, campaign managers, and outsourced callers, indicating a cybercrime ecosystem that supports such voice phishing campaigns at scale. One threat actor that uses Work Panel is UNC6671 (aka Cordial Spider and O-UNC-045). "It is a full web application designed to run a vishing-driven account takeover business," Okta added. "The console organizes the work into multiple sections covering target recon, voice-call routing, brand cloning, infrastructure provisioning, live session management, captured-credential review, and an audit log. Different roles see different tabs, and the access boundary is enforced on the server rather than hidden in the client."
- AI Agent Hijacking
GhostJacking Uses Poisoned Logs to Turn AI Agents Bad
A new attack called GhostJacking expands on Agentjacking to trick AI agents into running arbitrary code on developer machines, once again highlighting the need for securing the AI supply chain. The attack can leverage something as simple as a poisoned log or alert to make the agent act on the attacker's data, escalate privileges and pivot to enterprise cloud infrastructure, exfiltrate data to the attacker (in this case, using a now-patched sandbox escape in Anthropic's Claude Desktop), and establish persistence by leaving a backdoor in the agent's configuration. "Companies are handing AI agents the keys to their code, their monitoring, and their infrastructure," Tenet Security said. "An AI cannot tell a real instruction from a trap hidden in the data it reads. The usual defenses do not fire, because nothing breaks a rule. Every step is something the agent was already allowed to do." The findings underscore the need for guardrails around AI agents to protect against hijacking attacks that leverage their legitimate access and elevated privileges against their users.
- On-Device Scam Detection
Meta Builds Scam Alert Feature Into WhatsApp
Meta has announced a new optional feature called Scam Alert that makes use of an on-device machine learning model to alert a user about potential scam messages. "No message content leaves the device for classification or is auto-reported to WhatsApp, Meta, or anyone else," the company said. "The feature complements end-to-end encryption while enabling a user-controlled, optional scam alert when the model believes there's a likely scam." The model, Meta added, is trained on patterns observed in scam conversations from reports that users have sent to it. Meta said it has also built a privacy-preserving federated analytics pipeline that collects only two categories of data: counts of how often warnings were triggered and counts of what action users took afterward, such as blocking or marking a chat as trusted.
- Automatic Key Checks
Signal Debuts Automatic Key Verification
Messaging app Signal has announced a new automatic key verification feature that complements the existing safety number system to provide an "additional, streamlined way to confirm that there's no unexpected party between you and the other 'end' of an end-to-end encrypted session." Signal said: "It works through a system of verifications performed by you, your Signal connections, and third-party auditors that together provide the same assurance as manually verifying safety numbers. Unlike safety numbers, these verifications are done independently and do not require an in-person meeting or a secondary communication channel. This system of verifications ensures that the association between a phone number or username and its public encryption key is globally consistent and transparent to all participants in Signal's ecosystem." Users can enable automatic key verification in Signal by going to Settings > Privacy > Advanced and enabling the setting.
- Prompt Injection as Defense
Embracing Prompt Injections for Defense
A new approach devised by Tracebit has proven very effective at stopping AI agents from fully compromising targeted environments. While prompt injections have proven to be a thorny problem ailing AI systems, the technique, called Context Bombs, uses prompt injections not to hijack AI agents to defend against them. Using decoy resources as tripwires that alert defenders about potential unauthorized activity is not wholly novel. These are known as canaries, which are hidden inside real files or networks that trigger an alert the moment it is accessed. Only in this case, it is used to stop the AI agent from performing something malicious. "A context bomb is simply a string crafted to provoke that refusal for benign reasons rather than malicious ones," Tracebit said. "The defender plants it, and when the model or model provider encounters it, safety mechanisms are triggered which stops the agent from proceeding." The findings are significant in light of the fact that autonomous and semi-autonomous AI agents accelerate the pace and scale of attacks, while defenders have little time to react and counter them.
- Fake Cleaner, Real Spyware
Fake CCleaner installs GhostDesk Chrome spyware
A fake version of CCleaner delivered via a bogus lookalike page ("ccleanerwind[.]top") is being used to infect Windows users with a malicious Chrome extension called GhostDesk, which harvests sensitive data from the browser. "Once installed, the fake application launches an attack that modifies Chrome, installs malicious extension components, and gives attackers the ability to steal credentials, capture screenshots, and log keystrokes," Malwarebytes said. There is evidence to suggest that the same mechanism is being used to serve counterfeit versions of 7-Zip and Adobe Acrobat Reader.
- $150K PCC Bug Bounty
Apple Pays $150K Bounty for PCC Flaw
Apple has paid a $150,000 bug bounty to a security researcher who found a way to leak sensitive data from Private Cloud Compute (PCC), its secure AI inference environment. The vulnerability, rooted in a component called "darwin-init" and tracked as CVE-2026-20685 (CVSS score: 6.5), allows an attacker in a privileged network position to leak sensitive information. Apple said the issue was addressed with improved validation. Drinor Selmanaj, who discovered the issue, described it as a "path traversal in the code that provisions PCC nodes, darwin-init, that lets an attacker write files as root and compromises privacy and security guarantees in PCC."
- Blockchain-Hidden C2
New ClickFix Campaign Uses EtherHiding
An active ClickFix malware campaign leveraging a novel technique known as EtherHiding using the Polygon blockchain to obfuscate and dynamically rotate command-and-control (C2) infrastructure. "A compromised WordPress site was found serving a malicious script embedded in its robots.txt file," Cribl said. "When visited, the script queries the Polygon blockchain via public RPC endpoints, calling a smart contract to retrieve an encoded second-stage C2 domain. By storing malicious domains in blockchain transaction data rather than traditional infrastructure, the attacker gains a resilient, censorship-resistant delivery mechanism that is difficult to detect and block through conventional means."
- Agent Skills Turn Malicious
Malicious Plugins Transform AI Agents Into Insider Threats
Malicious skills or extensions installed directly from public marketplaces, while offering an extensibility model, also exposes developers to an attack surface, where an AI coding agent is leveraged as a delivery and execution mechanism for malicious actions, such as credential theft, by taking advantage of the fact that it was configured in an "unattended" or "auto-approve" execution mode, granting it the ability to execute shell scripts without requiring user confirmation. "Located within the agent's local skills directory was a package disguised under an innocuous, business-aligned name designed to mimic a routine approval workflow," CyberProof said. The package is designed to enumerate running browser processes and decrypt stored credentials. "Because the agent operated in auto-approve mode, this entire sequence executed silently twice within 15 minutes without presenting authorization prompts to the end user," CyberProof said. "Standard binary reputation lookups, signature validation, and application allow-listing controls failed to trigger alerts because the malicious payload resided entirely within the uncompiled script content of an add-on skill package."
- Explicit Content Theft Warning
Sexual Exploitation Actors Stealing and Leaking Explicit Content
The U.S. Federal Bureau of Investigation (FBI) has warned of sexual exploitation (SE) actors targeting adult and underage victims by illegally accessing their social media and personal accounts to steal and post their explicit content for sale on criminal marketplaces. "SE actors are using a variety of social engineering and cyber intrusion tactics to target specific individuals of interest — who may or may not be known to the actor — or general targets of opportunity," the FBI said. "Once the sexually explicit images or videos are accessed and stolen, typically unbeknownst to the victim, SE actors are sharing or posting the content within community forums or selling them to illicit marketplaces. Personally identifiable information — such as name, date of birth, email, phone number, and social media username — is often posted along with the victim's explicit content, exposing them to continued re-victimization." Initial access methods include trying different passwords or PINs found on data leak sites and other sources, social media customer service impersonation, and phishing.
- Data Theft Extortion
ExfilSquad Goes After New Victims
ExfilSquad has emerged as a new threat actor to watch out for after having claimed responsibility for a string of high-profile data breaches. The group first appeared in mid-2026. "Notably, the group does not typically deploy ransomware or destructive malware; instead, they threaten to leak stolen data on a dedicated onion-based Data Leak Site (DLS) unless a ransom is paid," Resecurity said. "The notable pattern is the strong targeting of CRM, internal case management systems, and AI platforms used to collaborate with consumers." The leaked files are accessible over a torrent file, allowing it to reach a broader audience. "Once stolen data has been released, it is not possible to stop its sharing via the P2P network or remove the torrent file, because other participants involved in seeding can easily resume downloads," Resecurity said.
- 7B Alerts Cut Daily
Chrome Cuts 7B Unwanted Android Notifications a Day
Google has announced that Chrome's anti-abuse systems reduced unwanted notifications on Android by more than 7 billion per day during the first quarter of 2026, as it tackles notification abuse. The company said it has built "advanced behavioral detection" to more quickly identify and remove permissions from networks of sites that coordinate and send abusive notifications, implemented message rate limits for the Push API on Firebase Cloud Messaging (FCM) to tackle high-volume notification abuse, and streamlined the notifications permission model to "prioritize user agency while making it harder for abusive actors to acquire and retain permissions."
- Ethereum Dead-Drop Malware
6 npm Packages Use NullReceiver to Fetch Malware
A set of six npm packages have been observed using an Ethereum wallet address linked to North Korean threat actors to fetch next-stage JavaScript payloads. Three of them (@kolbo/mcp@1.57.1, agentgui@1.0.1127, and godot-kit@1.0.1786316795) are legitimate npm packages that seem to have been hijacked to publish malicious versions, while three others have been flagged as malicious: envpack-conf@1.0.1, postcss-initial-provider@3.0.4, and tailwindcss-motion-advanced@1.0.1. "The payload uses Ethereum blockchain transactions to locate infrastructure hosting additional JavaScript malware," Sonatype said. "When executed, the loader queries Ethereum for an outbound transaction from that wallet and reads bytes from the transaction’s recipient address. Those bytes are decoded into two IPv4 addresses, which the malware treats as primary and secondary command-and-control (C2) endpoints. The Ethereum transaction acts as a dead drop for instructions telling the malware where to connect next." The technique has been codenamed NullReceiver, an evolution of EtherHiding.
- Inside the Crypter Market
Who Is Behind Crypter Services?
Recorded Future's Insikt Group said it analyzed 24 threat actors advertising crypting services and products within the past year, describing it as a market that is competitive, reputation-driven, and primarily focused on Windows payloads. Crypters are tools that modify malicious software to bypass detection and complicate analysis. While advanced crypters offer portability, anti-analysis, process injection, persistence, and security product bypass capabilities, less-advanced crypters generally provide basic payload obfuscation techniques. Some of the threat actors marketing such tools include mrlapis (VIP Crypt), o1oo1 (ASMCrypt and SnappyClient aka TOP RAT), ImComplexed, BestCrypt0r, Cruciferra, DefCrypt, ghostcrypt, GoldenCrypt, and mila.laktina. "Providers advertise through underground forums, restricted communities, chat platforms, clearnet sites, and social media accounts," the company said. "They compete through tiered pricing, antivirus (AV) detection scores of crypted samples, discounts, malware-developer partnerships, private or shared stubs, and promised turnaround times for re-crypting detected payloads."
- Industrial Ransomware Rises
Industrial Ransomware Analysis for Q2 2026
Cybersecurity firm Dragos said it identified 1,140 ransomware incidents affecting industrial organizations worldwide in the second quarter of 2026, a 12% increase compared to Q1. "Manufacturing was the most affected sector with 747 incidents (65%) across all subsectors," it said. ICS-related organizations (engineering firms, system integrators, and equipment manufacturers) accounted for the second-most-impacted sector, with 117 incidents, reflecting persistent industrial supply chain exposure. The extortion model continued to shift away from encryption toward data theft-only operations, and geopolitically influenced activity, including state-aligned actors operating behind ransomware branding, persisted throughout the quarter." Qilin (140), Akira (129), The Gentlemen (125), DragonForce (76), and LockBit 5.0 (62) were responsible for the largest victim volumes in Q2.
- Malware Alerts Expand
GitHub Dependabot Malware Alerts Cover 8 Ecosystems
GitHub said it has enhanced the GitHub Advisory Database to ingest malware reports from OpenSSF's malicious-packages repository, to account for eight major package ecosystems: npm, PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer. "Dependabot and GitHub will now alert you if you use a malicious dependency across most package ecosystems," GitHub said. "Malware alerts are opt-in: enable them in your repository, organization, or enterprise security settings. Dependabot will match your dependencies against malware advisories in the Advisory Database, including a backfill against existing advisories, starting the moment you turn it on."
- Hyper-Volumetric DDoS Surge
DDoS Attacks Over 1TB Surges in H1 2026
Cloudflare said it mitigated 23.2 million network-layer and 29.64 trillion HTTP DDoS requests since the start of 2026. Hyper-volumetric DDoS — attacks defined as exceeding 1 terabit per second (Tbps), 1 billion packets per second (Bpps), or 1 million requests per second (Mrps) — have witnessed a surge, with the web infrastructure company mitigating 805 network-layer attacks exceeding 1 Tbps, representing a more than six-fold increase over the previous quarter. The top attacked industries during the time period were media, gambling, IT services, computer software, and telecommunications providers. The U.S., China, Indonesia, Turkey, and France were the most attacked locations, while the traffic originated from Brazil, the U.S., Indonesia, China, and Germany.
The bigger lesson from this week is simple: attacks do not always start with something obviously malicious. More often, attackers are finding ways to misuse trusted tools, normal access, weak settings, and features people already depend on.
That makes the smaller security stories worth watching. A new flaw, scam method, malware trick, or defensive change may look limited on its own, but together they show how quickly the threat picture is changing and where defenders may need to pay more attention next.
















Deja una respuesta