BagheeraAltered's CyberSecurity Newsletter logo

BagheeraAltered's CyberSecurity Newsletter

Archives
Subscribe
August 24, 2026

ShinyHunters phished the security firm that researches ShinyHunters

This week, a story about what actually stops an attack after the phishing has already worked.

On August 17, ReliaQuest’s threat research account posted about a ShinyHunters phishing campaign it was tracking. Five days later, ShinyHunters ran that same playbook against ReliaQuest: a lookalike domain, a fake ReliaQuest single sign-on page behind a CDN, and phone calls to employees from someone impersonating a named member of the company’s own security team. One employee entered their password and approved the MFA push. On August 23, ShinyHunters listed ReliaQuest on its leak site with three Okta screenshots, a taunt — “Who’s hunting who?” — and nothing else. ReliaQuest’s research post came down. Its incident write-up went up.

What the attacker actually got was a single view-only identity session. Device trust controls refused to let an unenrolled device open a single business application, and containment killed the session, expired the password and reset every authentication factor. No applications, no systems, no customer data. The lesson is not that ReliaQuest got phished — everyone gets phished. It is that the control that mattered was nowhere near the login page.

Cybersecurity firm ReliaQuest has reported its research findings about ShinyHunters multiple times recently. On August 17,  @ReliaQuestTR tweeted that they were tracking yet another ShinyHunters campaign. But after another forum user replied on August 23 with some screenshots and a pithy “Who’s hunting who?” ReliaQuestTR deleted their tweet and hasn’t posted anything on that account since @odysseusgroup’s reply. On its dedicated leak site, ShinyHunters named ReliaQuest, LLC, but has offered no substantial evidence to support its claims. The listing merely says, in part, “This time the post is about you, not us. Let Mandiant report and advise on us accurately, go away.”
https://databreaches.net/2026/08/23/shinyhunters-claims-hack-of-reliaquest-but-provides-no-proof/

The Hospital for Sick Children in Toronto says a recent cybersecurity “incident” resulted in unauthorized access to the personal information of some of its current and former employees. In an email to CTV News, SickKids confirmed the breach, which it said temporarily affected its external careers website. That website has since been restored.
https://www.ctvnews.ca/toronto/article/sickkids-responding-to-cybersecurity-incident-which-compromised-personal-information-of-current-former-employees/

A new Android malware named Manic targeting users in multiple European countries has a fallback mechanism for exfiltrating data through nearby infected devices. The malware has been active since at least February and combines spyware, banking fraud, and remote control capabilities. It targets at least 169 banking, government/eID, payment, crypto wallet, messaging, and authenticator/2FA apps, with users in Ukraine being the primary focus.
https://www.bleepingcomputer.com/news/security/new-manic-android-malware-can-exfiltrate-data-through-nearby-devices/

Data allegedly from the Microsoft Azure and Entra environments of McDonald's, Vodafone and seven other major companies is being offered for sale on underground forums. The perpetrator, who goes by the alias "TheHatman", claims to have millions of employee records in his possession.
https://en.hacks.gr/sok-sti-silicon-valley-chaker-dierreysan-ekatommyria-dedomena-apo-mcdonald-s-vodafone-kai-kolossoys-ton-fortune-500/

A code host is the one server a team assumes it can trust with its own history. CVE-2026-19478 breaks that assumption in the worst way. Under the right conditions it lets someone who never logged in reach into a self-managed GitLab and erase public projects, and the accounts behind them, outright. GitLab rated it 9.4 and shipped an emergency fix this week. Most of the critical bugs we have written up this year were about reading data you should not see or running code you should not run. This one is different: it destroys, and destruction of your source of truth is an availability and integrity event, not a leak.
https://suriq.io/blog/gitlab-graphql-unauth-delete-cve-2026-19478

Metabase, a widely adopted open-source business intelligence and data visualization platform, has disclosed a critical zero-day vulnerability, identified as GHSA-vwf4-m7j8-wcjf, which has been actively exploited in the wild. This flaw enables unauthenticated attackers to obtain full administrator access to affected instances.
https://thedailytechfeed.com/critical-metabase-0-day-exploited-to-gain-admin-access/

Ransomware crews working across Southeast Asia are picking noticeably different targets than they do elsewhere in the world. Over the last 90 days, hotels, resorts and travel operators accounted for roughly one in fourteen of the region's named victims, close to three times their share of ransomware listings everywhere else. Hospitals, the sector that dominates ransomware coverage in the United States and Europe, barely feature at all.
https://www.intelfusions.com/news/southeast-asia-ransomware-hotels-not-hospitals

Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun. Kaspersky, which discovered the threat in June 2026, said the end goal of the malware is to serve a multi-stage downloader to enable ad fraud and creation of a proxy botnet. "The malware spread through the built-in updaters of Android-based automotive head unit firmware," security researcher Dmitry Kalinin said. "This is the first documented case of malware found on a car head unit with an infection chain specific to that type of device."
https://thehackernews.com/2026/08/android-car-malware-spreads-through.html

iAuthFlow V2 is a malware toolkit first seen on a Russian-language cybercrime forum. It is an advanced form of phishing that offers persistent access to the victim’s account, surviving a password reset. The base toolkit is offered for sale at $10,000, with additional modules available separately. Using available information from the seller’s forum posts and demonstrations (but without acquiring or running the malware), Abnormal researchers have postulated an analysis of its operation, based on the ‘passkey’ module and employed against a Gmail account.
https://www.securityweek.com/new-phishing-toolkit-uses-passkeys-to-maintain-access-after-password-resets/

Following Black Hat/DEF CON, a Huntress researcher was targeted by a threat actor who used X DMs and fake security conference planning as a pretext to establish trust before attempting to deploy malware. The researcher recognized the lure as a scam and did not fall for it, but continued engaging with the actor to better understand the tactics they were using.
https://www.huntress.com/blog/defcon-phishing-google-doc-malware

GenDigital found a custom Windows backdoor on a single corporate workstation while hunting for unusual WMI persistence. The malware was small, had a limited command set and disguised itself as legitimate Realtek software. Its most unusual feature was its configuration: the address of its command-and-control server was not stored as readable text or encrypted data, but encoded in the number of spaces on each line of a Windows desktop.ini file.
https://www.gendigital.com/blog/insights/research/kb-backdoor

Russian software developer Microolap confirmed that hackers had compromised some of its systems but denied claims that they gained access to its network monitoring platform or stole data belonging to major Russian companies. Microolap, which develops software for intercepting and analyzing network traffic, said Thursday that it had detected an attempted breach of several non-critical systems but found no evidence that hackers accessed its core infrastructure, customer data or other sensitive information.
https://therecord.media/russian-network-monitoring-firm-confirms-cyberattack-claimed-by-pro-ukraine-group

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.
https://github.com/keycloak/keycloak/issues/51833

Threat actors are abusing FTP banners to hide commands that deliver two previously undocumented remote access trojans named E4del and PINHOLE. MalwareHunterTeam observed this unusual technique in July in an attack that used shortcut files (.LNK) and FTP server banners as dead-drop resolvers (DDR) to retrieve commands. FTP banners are text strings the server uses as a greeting message for connecting hosts before they log in.
https://www.bleepingcomputer.com/news/security/hackers-abuse-ftp-server-banners-to-deliver-new-windows-malware/

Citrix is urging its NetScaler ADC and NetScaler Gateway customers to quickly patch two critical security holes, one involving a memory overflow vulnerability leading to unpredictable behavior or denial of service, and the other allowing authentication bypass.
https://www.csoonline.com/article/4212082/citrix-issues-critical-security-updates-for-its-netscaler-devices.html

A security researcher has published a proof-of-concept exploit for a Microsoft zero-day called ShieldBreak that fully bypasses a recent Microsoft Defender patch, while North Korea’s Lazarus Group has been caught exploiting a separate actively exploited Windows privilege escalation flaw in the wild.
https://pulseofnations.lol/shieldbreak-poc-bypasses/

Cybersecurity researchers have shed light on an updated version of ToxicPanda (aka TgToxic) that comes with "significant enhancements," including a set of 167 remote commands and expands its targeting footprint globally. Zimperium zLabs, in a Wednesday report, said the Android malware also features a PIN harvesting workflow targeting more than 140 banking and cryptocurrency applications. ToxicPanda is known to be active in the wild since at least July 2022.
https://thehackernews.com/2026/08/toxicpanda-20-and-golddigger-expand.html

A malicious executable masquerading as a Google Gemini installer was used to deliver the Vidar infostealer on a company network in the EMEA region, according to Darktrace researchers who investigated the incident.
https://www.helpnetsecurity.com/2026/08/20/fake-google-gemini-installer-vidar-infostealer/

UAT-10147 is a highly capable Chinese-speaking intrusion actor operating a multi-platform post-exploitation ecosystem targeting IIS and Linux servers, combining search engine optimization (SEO) fraud monetization with advanced persistence and defense evasion techniques. 

UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities

The newly identified SPECTRE implant represents an evolution in commodity intrusion tooling, integrating cross-platform C2 operations, process injection, credential theft, anti-analysis protections, and kernel-level endpoint detection and response (EDR) bypass functionality.

On August 7, 2026, the giant tanker “VL PROSPERITY”, with a capacity of 2.3 million barrels of crude oil, which was sailing under the Liberian flag from Egypt’s Sidi Kerir port toward one of the ports of the United States, was targeted by a major cyberattack in the Strait of Gibraltar, and all of its communications were cut off for 30 hours.
https://en.mehrnews.com/news/247123/US-bound-oil-tanker-targeted-in-Cyberattack

Check Point Research says the StopAndProtect campaign turned nearly 2,000 compromised WordPress sites into criminal infrastructure for malware delivery, data theft, victim monitoring, and ransomware deployment. Researchers also found that attacker operational failures exposed internal logs, screenshots, stolen files, and management tools, revealing more than 6,000 unique IPs by July 24.
https://whale-alert.io/stories/cfdd0101356df4/StopAndProtect-campaign-used-nearly-2000-hacked-WordPress-sites-to-spread-malware-steal-data-and-deploy-ransomware

CyrusOne, LLC. in the US reported a ransomware extortion claim by shinyhunters, stating they refused a $13 million demand and faced a 24-hour deadline. The attackers alleged theft of 12.9 million Salesforce records plus substantial SharePoint files and sensitive business, employee, and security documentation, warning of data leakage if demands were not met.
https://www.hendryadrian.com/ransom-cyrusone-llc-aug-2026/

Don't miss what's next. Subscribe to BagheeraAltered's CyberSecurity Newsletter:
← Newer The malware comment that makes AI refuse to keep reading Older → Washington is hiring pirates to fight cybercrime
Powered by Buttondown, the easiest way to start and grow your newsletter.