This website uses cookies

Read our Privacy policy and Terms of use for more information.

The White House this week quietly formalized something the security industry has been doing informally for years: letting private companies punch back. The new program authorizes vetted U.S. firms to run offensive cyber operations against foreign criminal hacking groups — under federal contracts, multi-agency approval, and a strict list of things they're not allowed to do. No actions that cause loss of life. No targeting Americans. Immediate halt and notification if something goes sideways. The framework is more considered than most people will give it credit for.

It's also, historically speaking, a template for exactly the kind of scope creep that frameworks like this are designed to prevent. Private military contractors started with logistics. The distance between "strictly vetted offensive cyber under federal oversight" and "plausibly deniable third-party operations with a government contract on file" is shorter than the press release implies. The targets today are transnational criminal organizations — a category broad enough to be useful and vague enough to be stretched. The guardrails are real. So is the precedent.

Table of Contents

🔓 BREACHES & SECURITY INCIDENTS

🇳🇱 Shell is investigating after the Cl0p ransomware gang claimed it stole 89GB of data, including engineering drawings and project plansCl0p says the theft exploited a critical PTC Windchill and FlexPLM vulnerability (CVE-2026-12569) that is being actively exploited. Security groups and authorities urge affected organizations to patch, isolate compromised systems, and rotate exposed credentials.

🇺🇸 Hackers from the ShinyHunters group stole personal data from 1.6 million RingCentral accounts after a July breach. RingCentral said a social engineering attack led to a limited compromise and its services remain running. The stolen data was leaked after the company refused to pay a ransom.

🔓 Most of the 2,500+ organizations blamed for the LiteLLM supply-chain attack were actually exposed earlier via a compromised Trivy scanner. The worm-like malware stole developer secrets and used them to push poisoned packages across CI/CD systems and package registries. Stolen credentials from over 1,000 organizations are now being brokered online.

💸 Trezor says nearly 14,000 customers had personal data exposed after its shipping partner ShipMonk was hacked. The leaked data included names, addresses, emails, and phone numbers for orders between May 10 and August 8, 2026. Trezor warns customers to watch for increased phishing but says its devices and systems were not compromised.

🇺🇸 Wesco is investigating a claimed cybersecurity incident after ExfilSquad said it stole CRM data and published it. Wesco says it detected the issue quickly, found no ransomware, and believes sensitive payment or employee data is not at risk. ExfilSquad claims 2.6 million records were taken, and researchers note the group often targets misconfigured Microsoft Power Pages.

🕹 Valve says hackers stole Steam hardware customers' delivery data after breaching its shipping partner CEVA Logistics. Stolen details include names, addresses, phone numbers, emails, and order info, but not passwords or payment data. Valve warns customers to watch for phishing and is pressing CEVA and notifying authorities.

LexisNexis took Nexis Diligence, Metabase API, and Newsdesk offline after detecting unusual activity on servers run by a third-party vendor. They are investigating with a cybersecurity forensic firm and rebuilding affected systems in a new environment. The company says the outage is unrelated to the Metabase Cloud zero-day and follows prior cyber incidents.

🥷🏻 CYBERCRIME, CYBER ESPIONAGE, APT’s

🇺🇦 Ukrainian authorities shut down 94 fraudulent call centers and carried out 411 searches. They seized computers, phones, cash (about $2 million), cars, SIMs, bank cards, and crypto access tools. Twenty-six people are suspects and face long prison terms while investigations continue.

🇺🇸 A former Brightly Software contractor, Cameron Curry, stole company data and tried to extort about $2.5 million — He emailed threats and leaked payroll screenshots to pressure the company. Curry was convicted and sentenced to two years in prison plus one year of supervised release.

🇺🇸 Delta is investigating after a passenger allegedly created a fake onboard Wi‑Fi network called “Delta WiFi Fast” on flight 591 from Las Vegas to Atlanta. Crew disabled Wi‑Fi for about 30 minutes, no systems were harmed, and federal agencies are involved. The tactic matches an “evil twin” spoofing attack that can steal data from connected devices.

🇺🇸 🇰🇵 The FBI is investigating how a North Korean worked for an unnamed U.S. federal agency — North Korean IT workers often use fake identities to get remote jobs, steal data, and send wages back to the regime. U.S. authorities have taken actions to disrupt these schemes, which help fund North Korea’s sanctioned programs.

🇬🇧 A 20-year-old UK man, Justin Swaddle, was jailed for two years after admitting to abusing and blackmailing 117 victims online while part of the criminal network known as The Com. He targeted girls aged 13–17 across multiple countries, using Snapchat, Discord and Telegram to coerce explicit images and personal details. Authorities say the group causes severe, long-lasting harm and have been arresting members internationally.

🗓️ {Cyber,Info}Sec Events — A community-maintained list of infosec conferences worldwide. Subscribe to the ICS calendar feed to get events straight into your calendar, or follow @[email protected] on Mastodon for weekly digests. Contributions and ⭐ welcome!

👨🏻‍⚖️ 👀 GOVERNMENT, POLITICS, AND PRIVACY

🇺🇸 The White House created a program letting vetted U.S. companies run cyber operations against foreign criminal hacking groups under federal control. Companies must sign contracts, pass strict vetting, and follow multi-agency approval and safeguards that forbid actions causing loss of life or targeting Americans. The program limits targets to non-state transnational criminal organizations and requires immediate halt and notification if U.S. systems or persons are affected.

🇺🇸 🤖 The FTC proposes treating ideological bias in AI as an unfair or deceptive practice and wants federal authority over state AI laws. Critics from both left and right say the proposal is vague, risks political censorship, and may exceed the FTC’s legal role. Lawmakers and experts worry the rule could let future administrations reshape AI to match their views.

🦠 MALWARE & THREATS

🦀 🍎 A fake GitHub page tricks macOS users into running a command that installs AmnesiaStealer, a Rust-based three-stage info stealer. It harvests keychains, Chromium browsers, Apple Notes and documents, tries TCC bypasses, and sends data to a C&C server. On command it runs a headless browser module that gives attackers live, interactive control of the victim’s browser session.

🔔 📲 Apple sent new "Threat Notification" alerts saying some iPhones were targeted by mercenary spyware. These high-confidence alerts don’t name specific spyware but warn users who may be individually targeted. If you get one, verify it at account.apple.com, enable Lockdown Mode, and seek cybersecurity help.

📲 🐀 Researchers found Android malware called WindRelay used with the SpyNote RAT to steal card data and take out loans. Attackers trick victims by phone to sideload a fake app, grant permissions, then relay NFC card transactions and PINs in real time. Users should avoid APKs outside Google Play and hang up to call the bank’s official number if asked for urgent actions.

🛠 Researchers say the Kimwolf botnet was rebuilt to hide its attacks and avoid takedowns — It now mimics Chrome traffic using HTTP/2 so DDoS defenses struggle to spot it. Command addresses are stored via the Ethereum Name Service and Tor so investigators cannot easily seize them.

🇨🇳 Microsoft says China-linked group Storm-1175 deployed a new C++ ransomware called StormEncryptor that appends .encrypted and drops a !!!README_FIRST!!!.txt ransom note. The group likely gained access by exploiting an N-able N-central flaw (CVE-2026-18577) that bypasses authentication. Storm-1175 moves fast, using RMM tools and known exploits to exfiltrate data and deploy ransomware within days.

🤖 🧰 AI, CRYPTO, TECH & TOOLS

💬 🔑 Signal added Automatic Key Verification to let users confirm their chats’ encryption hasn’t been tampered with. The system uses independent auditors (Cloudflare and Trail of Bits) to check key integrity without in-person verification. Users can enable it in Settings or stick with manual safety number checks.

🆕 OpenAI is expanding its Daybreak program to give defenders access to stronger frontier models for cybersecurity work. It will offer Daybreak Blue for defensive tasks and Daybreak Red with a more powerful GPT-5.6-Cyber for advanced red-teaming under strict monitoring. OpenAI also launched a partner program with major security firms to deploy these models through existing services.

🦊 🔑 Mozilla found an unencrypted GPG signing subkey in a private GitHub repo and has revoked it — They issued a new key and added protections to prevent repeats. Most users need do nothing, but people who verify signatures or use RPMs must update keys per Mozilla’s instructions.

🐛 🧠 VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE

➝ From the Patching Department:

🩹 Microsoft released fixes for 398 security flaws in Windows and related software. One bug is actively exploited and 42 were rated critical. Experts say AI is finding more bugs, but human review is still needed to test and safely apply patches.

🔑 Three research teams found ways to bypass passkey protections without breaking FIDO2 cryptography — The attacks abused Windows logging, Chrome's synced-passkey master secret, and use of Windows Hello keys in compromised sessions to replay or recreate credentials. Fixes and mitigations differ, so install patches, harden endpoints, and enforce proper user-verification and token checks.

🌐 🐛 NATO’s cyber defense arm and AI startup AISLE can now assign official CVE ID numbers for software flaws, ENISA announced last week. This lets NATO track vulnerabilities across its networks and lets AISLE label bugs in its own products faster. The move comes as AI-driven discovery and changes to the CVE system increase pressure on vulnerability tracking.

🛰️ ICS, OT & IoT

🇨🇦 A ransomware attack hit Winnipeg's Health Sciences Centre and disrupted building systems like doors and HVAC. Officials say patient care was not impacted so far and the incident is under investigation. Experts warn hospitals must better secure operational systems to prevent similar attacks.

🩹 Industrial vendors Siemens, Schneider Electric, and Phoenix Contact released August Patch Tuesday alerts fixing serious vulnerabilities in their ICS products. Siemens patched multiple high- and critical-severity flaws that could allow code execution, crashes, or data access, while Schneider and Phoenix Contact fixed remote execution, authentication, and DoS issues. CISA and other vendors also issued advisories for additional affected industrial and building management systems.

🇺🇸 👀 🚰 Federal lawmakers proposed the Water Cyber Shield Act to give the EPA new authority, set security standards, and fund upgrades for water system cybersecurity. A $300 million yearly funding stream and stricter reporting and assessments are included to protect utilities after recent attacks. A new Water Watch Center will provide managed detection services and share threat intelligence to help small, under-resourced utilities.

💬 CONNECT

Follow me on Mastodon for quick daily updates and bite-sized content.

Prefer using an RSS feed? Add Infosec MASHUP to your feed here.

Enjoying our newsletter? Forward it to a colleague—
it’s one of the best ways to support us.

Thanks for reading today’s newsletter, and if you're enjoying it and want to support my work, you can buy me a coffee ☕ over at https://www.buymeacoffee.com/0x58

See you next time!

-X.

Reply

Avatar

or to participate