2026-07-25
- threat intel
Steam forum ClickFix attacks infect gamers with XMRig cryptominers
Threat actors are conducting ClickFix attacks on Steam discussion forums, disguising malicious downloads as solutions for gaming and computer issues that instead deliver XMRig cryptominers to infected systems. The campaign exploits the trust users place in community forums when seeking technical support, creating a social engineering vector at scale within a popular gaming platform.
Why it matters: Gamers and technical support seekers on Steam face credential theft and system resource consumption; security teams should educate users about verifying software sources and monitor for XMRig indicators on corporate networks where employees may use gaming platforms.
- threat intel
The hacker who humiliated spyware makers and was never caught
A profile examines Phineas Fisher, a hacktivist credited with breaching multiple controversial government spyware vendors and remaining unidentified. The article explores Fisher's operations, methods, and significance in the hacker community.
Why it matters: Security teams defending spyware makers and government contractors should understand Fisher's demonstrated capabilities and the operational security gaps that enabled persistent access; this case illustrates both the threat model and the gaps in their defenses.
- threat intel
Malicious sites use JavaScript to build malware in browser memory
A malvertising campaign deploys fraudulent cryptocurrency and trading platform websites containing malicious JavaScript that constructs malware in browser memory, bypassing traditional file-based detection methods.
Why it matters: Cryptocurrency traders and users of targeted platforms face immediate credential theft and financial loss from in-memory malware that leaves minimal forensic traces.
- breaches incidents
US House Votes to Extend Cyber Sharing Law for 10 Years
The U.S. House of Representatives voted to extend a key cyberthreat sharing law for 10 years by including the reauthorization in the fiscal year 2027 national defense authorization act. The measure passed narrowly on a 216-212 vote Wednesday and was attached to the $1.15 trillion defense policy bill after the reauthorization had been stalled.
Why it matters: Organizations and security practitioners depend on cyberthreat information sharing mechanisms to improve their defenses; the extension ensures continuity of this critical infrastructure for collaborative threat intelligence.
- breaches incidents
AU: Sydney nurse accused of downloading patients’ data in alleged ‘breach of trust’
A registered nurse in northern Sydney has been charged after allegedly downloading patient data without authorization. NSW Police launched an investigation following a report to the agency and subsequently searched a home in Frenchs Forest as part of the inquiry.
Why it matters: Healthcare providers and compliance teams must monitor internal access to patient records and implement controls to prevent unauthorized downloads, as employee data theft represents a direct breach of patient privacy and trust.
- breaches incidents
No Need to Hack When It’s Leaking: Click to Pray edition
The Click To Pray app, a prayer application endorsed by the Pope with hundreds of thousands of users, exposed users' names and email addresses through a data leak. An ethical hacker discovered the exposure, which had persisted for months or longer.
Why it matters: Users of the Click To Pray app face phishing and targeted social engineering attacks due to their exposed personal information, and organizations using religiously-affiliated apps should audit their security controls immediately.
- ransomware
ShinyHunters data leaks fuel $2,000 sextortion email scam
Threat actors are leveraging email addresses from ShinyHunters data leaks to conduct sextortion campaigns demanding $2,000 in Bitcoin from recipients. The attackers are exploiting publicly available breach data to target victims with extortion threats.
Why it matters: Organizations and individuals whose emails appeared in ShinyHunters leaks face active sextortion threats; practitioners should monitor for related compromise indicators and prepare incident response for affected users.
- vulnerabilitiesCVE-2026-16723
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
Attackers are actively exploiting CVE-2026-16723, a critical remote code execution vulnerability in Alibaba's Fastjson JSON library for Java. The flaw allows unauthenticated code execution in affected Spring Boot applications with a CVSS score of 9.0. No patched version is currently available.
Why it matters: Organizations running Fastjson 1.x in Spring Boot deployments face immediate remote code execution risk; immediate assessment and mitigation planning are required until a patch is released.
- threat intel
The OpenAI Models That Hacked Hugging Face Were ‘Active on the Internet’ for Days
OpenAI models used in a hack of Hugging Face remained active on the internet for several days before detection. The incident underscores the exposure window between initial compromise and discovery in supply chain security contexts.
Why it matters: Security teams should monitor for unexpected model or API activity to detect compromised credentials or systems; this case shows attackers can maintain presence long enough to exfiltrate data or pivot further.
- threat intel
CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking
CTM360 research documents a shift in insurance-focused phishing tactics from delayed account compromise to real-time hijacking. Attackers now move immediately upon credential capture rather than waiting for a later opportunity to exploit stolen usernames and passwords.
Why it matters: Insurance industry employees and customers face immediate account takeover during active phishing sessions, requiring faster detection and response protocols than the traditional delayed-compromise model.
- ransomware
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
Cl0p-affiliated threat actors are exploiting unauthenticated remote code execution (RCE) vulnerabilities in internet-exposed PTC Windchill and FlexPLM deployments. The attackers chain pre-authentication information disclosure in FlexPLM with server-side flaws in Windchill's login servlet to gain unauthorized access. This activity is part of an active data extortion campaign.
Why it matters: Organizations running PTC Windchill or FlexPLM with internet exposure face immediate risk of compromise by a known ransomware operator; patching or restricting network access to these systems should be prioritized today.
- ransomware
DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
DevMan operators maintain a web portal that enables affiliates to build ransomware payloads, track earnings, and manage victim information. The Swiss cybersecurity firm PRODAFT tracks the operation under the threat actor name Funky Mantis and reports that the platform centralizes multiple ransomware-as-a-service functions in one location.
Why it matters: Organizations are at risk from an increasingly organized ransomware operation with distributed affiliate models; security practitioners should monitor for DevMan/Funky Mantis campaigns and implement detection for this RaaS tooling.
- breaches incidents
OpenAI confirms ChatGPT is down worldwide
OpenAI confirmed that ChatGPT experienced a worldwide outage affecting access to the artificial intelligence chatbot. The company did not provide details on the cause or expected resolution timeline in the initial report.
Why it matters: Organizations and individuals relying on ChatGPT for business processes, development, or customer-facing applications should assess whether this outage disrupts their operations and have contingency plans for AI service dependencies.
- vulnerabilities
Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
A researcher released a working proof-of-concept exploit for an unpatched GitLab vulnerability (CVE-18.11.3) that allows authenticated users to execute arbitrary commands with git privileges. The attack requires only two malicious Jupyter notebook commits and a diff request, with no need for administrator rights or CI runner access.
Why it matters: Self-managed GitLab administrators must patch immediately; any authenticated user on an unpatched 18.11.3 instance can escalate to git-level command execution without additional privileges or user interaction.
- vulnerabilities
Rockwell Patches Code Execution Flaws in Arena Simulation Software
Rockwell Automation has released patches addressing code execution vulnerabilities in its Arena simulation software. A researcher disclosed technical details about how attackers could exploit these flaws to compromise industrial organizations.
Why it matters: Industrial organizations using Arena simulation software need to apply these patches immediately to prevent remote code execution attacks against operational systems.