<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:media="http://search.yahoo.com/mrss/"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cyber Security News</title>
	<atom:link href="https://cybersecuritynews.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://cybersecuritynews.com/</link>
	<description>World&#039;s #1 Premier Cybersecurity and Hacking News Portal</description>
	<lastBuildDate>Tue, 02 Jun 2026 18:51:04 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://cybersecuritynews.com/wp-content/uploads/2025/12/cropped-CSN-Favico-32x32.webp</url>
	<title>Cyber Security News</title>
	<link>https://cybersecuritynews.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">192061645</site>	<item>
		<title>WordPress Malware Abuses Steam Community Profiles for C2 Operations</title>
		<link>https://cybersecuritynews.com/wordpress-malware-abuses-steam/</link>
		
		<dc:creator><![CDATA[Tushar Subhra Dutta]]></dc:creator>
		<pubDate>Tue, 02 Jun 2026 18:50:58 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Threats]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151696</guid>

					<description><![CDATA[<p>A newly discovered malware campaign targeting WordPress websites has raised serious concerns across the web security community. Attackers behind this campaign are using an unexpected method to communicate with infected sites, hiding command instructions inside Steam Community profile comments and turning a popular gaming platform into a covert control channel. The malware works in two [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/wordpress-malware-abuses-steam/">WordPress Malware Abuses Steam Community Profiles for C2 Operations</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">A newly discovered malware campaign targeting WordPress websites has raised serious concerns across the web security community. </p>



<p class="wp-block-paragraph">Attackers behind this campaign are using an unexpected method to communicate with infected sites, hiding command instructions inside Steam Community profile comments and turning a popular gaming platform into a covert control channel.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/98400c7f-9346-41bc-88e8-21c02b5cce58/WordPress-Malware-Abuses-Steam-Community-Profiles-for-C2-Operations.pdf?AWSAccessKeyId=ASIA2F3EMEYETP2SQXGT&amp;Signature=zWYo5BSY72ZIa1ZPReXwUWfae7k%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEF8aCXVzLWVhc3QtMSJHMEUCIQDq2b3sYquDO73fy73RxHM0yEHryytvso2brLeBHMPUsQIgYXUsqE%2FQZ%2FPOh217aCj4UZ%2FYsVU50xSta0uY4a7uO58q8wQIKBABGgw2OTk3NTMzMDk3MDUiDPfX2dxySvoTEY%2FsfyrQBPBd0cXHXlZjWEtna%2FfIoEGmkCXmZ%2FL3P2Zpd5UmMnBKU4UpxxcspR4iOv%2B2Rt%2FYrCl%2FSPdDOtZSaDOqhNTccSjjZentdI4yvMSk%2F3QnmAadABkiyBiaApDGGNH0b%2BJDTD7Z9pygIzqVOQrRjzHmWr%2FST5NEizB3sJGfHlspFfdqe0mroG1JFmGFoRUM1Yn8vCT%2F20U2bUqn35CSBhuxKbuVfEuwv8by35oLGYlRPcKhbPofS%2F9GRGdHjZk96gjfEyv0O9PzIX6an4OkzoSTPTHq5QGT6w9n3tKLc9ltm21XxK1Vc6SjVZR948kGJ2RFAlff1fG%2BaJo3K1jUn2xkth%2BA2fTsYzu7%2BADVVSWCJe9sZiBtwNyGPUQtHePQpy5%2BP8O%2FnInnhV2q38bZWZFLmO%2By1%2FJxVhp5O9sOxym5863UROXcqwmfpuW3%2FrBv2WgNANM6miVJxTsacXgVIhywQNaheAks8GkS1qp9KD7s5Xe0fviNCzlIjL6elsk9INVdY5AwtNBWcxhOI0Dx4H5vUGtNoK9JULRCHPd1stxyFoTBfv4OzFp43h35R2hHB6%2FnirKU0%2FiBQhZerscq2ld5cI34iLnIwXay%2BY8ggGnsZeB%2B3OsXiaX4082%2BMIzyS2DShmehFNQxS56LqzhU1hcX1dqkI4tPNazPPMoVN6pS%2BK4NJYwm9UmcbZQAwp4%2B%2BacAqPE1PJ1V9w2f7J914LqroRTRDMKmR%2BG3vFqZNw0W0XIFgr0khi9mE4BSLJRGUEZaamdwRJsiRFYV5IWLPpKEMPYwhNX70AY6mAElq5BXmPx%2Bpu0zfPPar%2FPMoOwvKEKSqMtQzqT7rRNCtphakiNorg1RQYt7p6AYNLcKhWoLmUT6ixgNjI9t5daJpMBeN39EdP1IhD6HiYkp5dpLVO5oRkoNSZG4KuT2R4Eyd%2FuhDfcgIeLrfeHHM767Yjr5YTt1GIiZYZl0tr14NmR4yw81JLfNiJRRpMy2ognvJVPsE4R9oQ%3D%3D&amp;Expires=1780412827" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">The malware works in two stages. First, it injects malicious JavaScript into the front end of a compromised WordPress website, serving harmful content to every visitor who lands on the page. </p>



<p class="wp-block-paragraph">Second, it plants a server-side backdoor that gives attackers persistent remote access, allowing them to modify WordPress plugin and theme files without any visible trace of the intrusion.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/98400c7f-9346-41bc-88e8-21c02b5cce58/WordPress-Malware-Abuses-Steam-Community-Profiles-for-C2-Operations.pdf?AWSAccessKeyId=ASIA2F3EMEYETP2SQXGT&amp;Signature=zWYo5BSY72ZIa1ZPReXwUWfae7k%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEF8aCXVzLWVhc3QtMSJHMEUCIQDq2b3sYquDO73fy73RxHM0yEHryytvso2brLeBHMPUsQIgYXUsqE%2FQZ%2FPOh217aCj4UZ%2FYsVU50xSta0uY4a7uO58q8wQIKBABGgw2OTk3NTMzMDk3MDUiDPfX2dxySvoTEY%2FsfyrQBPBd0cXHXlZjWEtna%2FfIoEGmkCXmZ%2FL3P2Zpd5UmMnBKU4UpxxcspR4iOv%2B2Rt%2FYrCl%2FSPdDOtZSaDOqhNTccSjjZentdI4yvMSk%2F3QnmAadABkiyBiaApDGGNH0b%2BJDTD7Z9pygIzqVOQrRjzHmWr%2FST5NEizB3sJGfHlspFfdqe0mroG1JFmGFoRUM1Yn8vCT%2F20U2bUqn35CSBhuxKbuVfEuwv8by35oLGYlRPcKhbPofS%2F9GRGdHjZk96gjfEyv0O9PzIX6an4OkzoSTPTHq5QGT6w9n3tKLc9ltm21XxK1Vc6SjVZR948kGJ2RFAlff1fG%2BaJo3K1jUn2xkth%2BA2fTsYzu7%2BADVVSWCJe9sZiBtwNyGPUQtHePQpy5%2BP8O%2FnInnhV2q38bZWZFLmO%2By1%2FJxVhp5O9sOxym5863UROXcqwmfpuW3%2FrBv2WgNANM6miVJxTsacXgVIhywQNaheAks8GkS1qp9KD7s5Xe0fviNCzlIjL6elsk9INVdY5AwtNBWcxhOI0Dx4H5vUGtNoK9JULRCHPd1stxyFoTBfv4OzFp43h35R2hHB6%2FnirKU0%2FiBQhZerscq2ld5cI34iLnIwXay%2BY8ggGnsZeB%2B3OsXiaX4082%2BMIzyS2DShmehFNQxS56LqzhU1hcX1dqkI4tPNazPPMoVN6pS%2BK4NJYwm9UmcbZQAwp4%2B%2BacAqPE1PJ1V9w2f7J914LqroRTRDMKmR%2BG3vFqZNw0W0XIFgr0khi9mE4BSLJRGUEZaamdwRJsiRFYV5IWLPpKEMPYwhNX70AY6mAElq5BXmPx%2Bpu0zfPPar%2FPMoOwvKEKSqMtQzqT7rRNCtphakiNorg1RQYt7p6AYNLcKhWoLmUT6ixgNjI9t5daJpMBeN39EdP1IhD6HiYkp5dpLVO5oRkoNSZG4KuT2R4Eyd%2FuhDfcgIeLrfeHHM767Yjr5YTt1GIiZYZl0tr14NmR4yw81JLfNiJRRpMy2ognvJVPsE4R9oQ%3D%3D&amp;Expires=1780412827" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">GoDaddy security researchers identified this campaign, noting it was first detected in July 2024 and has since been found across approximately 1,900 WordPress sites. </p>



<p class="wp-block-paragraph"><a href="https://www.godaddy.com/resources/news/malware-targeting-wordpress-abuses-steam-community-profiles" id="https://www.godaddy.com/resources/news/malware-targeting-wordpress-abuses-steam-community-profiles" target="_blank" rel="noreferrer noopener nofollow">GoDaddy said in a report</a> shared with Cyber Security News (CSN) that threat actors are deliberately disguising their infrastructure behind Valve&#8217;s trusted gaming platform rather than maintaining obviously malicious servers that could be flagged and taken down quickly.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/98400c7f-9346-41bc-88e8-21c02b5cce58/WordPress-Malware-Abuses-Steam-Community-Profiles-for-C2-Operations.pdf?AWSAccessKeyId=ASIA2F3EMEYETP2SQXGT&amp;Signature=zWYo5BSY72ZIa1ZPReXwUWfae7k%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEF8aCXVzLWVhc3QtMSJHMEUCIQDq2b3sYquDO73fy73RxHM0yEHryytvso2brLeBHMPUsQIgYXUsqE%2FQZ%2FPOh217aCj4UZ%2FYsVU50xSta0uY4a7uO58q8wQIKBABGgw2OTk3NTMzMDk3MDUiDPfX2dxySvoTEY%2FsfyrQBPBd0cXHXlZjWEtna%2FfIoEGmkCXmZ%2FL3P2Zpd5UmMnBKU4UpxxcspR4iOv%2B2Rt%2FYrCl%2FSPdDOtZSaDOqhNTccSjjZentdI4yvMSk%2F3QnmAadABkiyBiaApDGGNH0b%2BJDTD7Z9pygIzqVOQrRjzHmWr%2FST5NEizB3sJGfHlspFfdqe0mroG1JFmGFoRUM1Yn8vCT%2F20U2bUqn35CSBhuxKbuVfEuwv8by35oLGYlRPcKhbPofS%2F9GRGdHjZk96gjfEyv0O9PzIX6an4OkzoSTPTHq5QGT6w9n3tKLc9ltm21XxK1Vc6SjVZR948kGJ2RFAlff1fG%2BaJo3K1jUn2xkth%2BA2fTsYzu7%2BADVVSWCJe9sZiBtwNyGPUQtHePQpy5%2BP8O%2FnInnhV2q38bZWZFLmO%2By1%2FJxVhp5O9sOxym5863UROXcqwmfpuW3%2FrBv2WgNANM6miVJxTsacXgVIhywQNaheAks8GkS1qp9KD7s5Xe0fviNCzlIjL6elsk9INVdY5AwtNBWcxhOI0Dx4H5vUGtNoK9JULRCHPd1stxyFoTBfv4OzFp43h35R2hHB6%2FnirKU0%2FiBQhZerscq2ld5cI34iLnIwXay%2BY8ggGnsZeB%2B3OsXiaX4082%2BMIzyS2DShmehFNQxS56LqzhU1hcX1dqkI4tPNazPPMoVN6pS%2BK4NJYwm9UmcbZQAwp4%2B%2BacAqPE1PJ1V9w2f7J914LqroRTRDMKmR%2BG3vFqZNw0W0XIFgr0khi9mE4BSLJRGUEZaamdwRJsiRFYV5IWLPpKEMPYwhNX70AY6mAElq5BXmPx%2Bpu0zfPPar%2FPMoOwvKEKSqMtQzqT7rRNCtphakiNorg1RQYt7p6AYNLcKhWoLmUT6ixgNjI9t5daJpMBeN39EdP1IhD6HiYkp5dpLVO5oRkoNSZG4KuT2R4Eyd%2FuhDfcgIeLrfeHHM767Yjr5YTt1GIiZYZl0tr14NmR4yw81JLfNiJRRpMy2ognvJVPsE4R9oQ%3D%3D&amp;Expires=1780412827" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">What makes this campaign particularly difficult to detect is how the malware conceals its payloads. It uses invisible Unicode characters, a technique known as steganography, to <a href="https://cybersecuritynews.com/cybercriminals-use-malicious-cybersquatting-attacks/" id="141790" target="_blank" rel="noreferrer noopener">encode malicious data within Steam profile</a> comment text. </p>



<p class="wp-block-paragraph">Since those hidden characters look like completely normal text on the surface, traditional text-based scanning tools are far less likely to catch them during routine checks.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiMsCkEGzHNmEO3hJ7DtcIZomUmlVO11WQ7gWT5lF8kt5gPjK-vPwPBARxPfv4jpS-hdcW1q8tps62B1i9QYNyfXCemknT2_lH4rDyL16_7bkfk8x3ZgtSj5jEpmXzMYXxUvsW45m6joIjJiDxIZYdMKMvjbrW2KB44hxbdkDT9ZAco6izZ9-udLVJzhto/s16000/Example%20of%20Steam%20commentthread_comment_text%20content%20(Source%20-%20GoDaddy).webp" alt="Example of Steam commentthread_comment_text content (Source - GoDaddy)" /><figcaption class="wp-element-caption">Example of Steam commentthread_comment_text content (Source &#8211; GoDaddy)</figcaption></figure>
</div>


<p class="wp-block-paragraph">The reach of this campaign is significant. Compromised websites unknowingly serve injected scripts to every visitor, exposing real users to potential harm. For site owners, the damage runs deeper, as the backdoor gives attackers the ability to rewrite site code even after partial cleanup attempts.<a rel="noreferrer noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/98400c7f-9346-41bc-88e8-21c02b5cce58/WordPress-Malware-Abuses-Steam-Community-Profiles-for-C2-Operations.pdf?AWSAccessKeyId=ASIA2F3EMEYETP2SQXGT&amp;Signature=zWYo5BSY72ZIa1ZPReXwUWfae7k%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEF8aCXVzLWVhc3QtMSJHMEUCIQDq2b3sYquDO73fy73RxHM0yEHryytvso2brLeBHMPUsQIgYXUsqE%2FQZ%2FPOh217aCj4UZ%2FYsVU50xSta0uY4a7uO58q8wQIKBABGgw2OTk3NTMzMDk3MDUiDPfX2dxySvoTEY%2FsfyrQBPBd0cXHXlZjWEtna%2FfIoEGmkCXmZ%2FL3P2Zpd5UmMnBKU4UpxxcspR4iOv%2B2Rt%2FYrCl%2FSPdDOtZSaDOqhNTccSjjZentdI4yvMSk%2F3QnmAadABkiyBiaApDGGNH0b%2BJDTD7Z9pygIzqVOQrRjzHmWr%2FST5NEizB3sJGfHlspFfdqe0mroG1JFmGFoRUM1Yn8vCT%2F20U2bUqn35CSBhuxKbuVfEuwv8by35oLGYlRPcKhbPofS%2F9GRGdHjZk96gjfEyv0O9PzIX6an4OkzoSTPTHq5QGT6w9n3tKLc9ltm21XxK1Vc6SjVZR948kGJ2RFAlff1fG%2BaJo3K1jUn2xkth%2BA2fTsYzu7%2BADVVSWCJe9sZiBtwNyGPUQtHePQpy5%2BP8O%2FnInnhV2q38bZWZFLmO%2By1%2FJxVhp5O9sOxym5863UROXcqwmfpuW3%2FrBv2WgNANM6miVJxTsacXgVIhywQNaheAks8GkS1qp9KD7s5Xe0fviNCzlIjL6elsk9INVdY5AwtNBWcxhOI0Dx4H5vUGtNoK9JULRCHPd1stxyFoTBfv4OzFp43h35R2hHB6%2FnirKU0%2FiBQhZerscq2ld5cI34iLnIwXay%2BY8ggGnsZeB%2B3OsXiaX4082%2BMIzyS2DShmehFNQxS56LqzhU1hcX1dqkI4tPNazPPMoVN6pS%2BK4NJYwm9UmcbZQAwp4%2B%2BacAqPE1PJ1V9w2f7J914LqroRTRDMKmR%2BG3vFqZNw0W0XIFgr0khi9mE4BSLJRGUEZaamdwRJsiRFYV5IWLPpKEMPYwhNX70AY6mAElq5BXmPx%2Bpu0zfPPar%2FPMoOwvKEKSqMtQzqT7rRNCtphakiNorg1RQYt7p6AYNLcKhWoLmUT6ixgNjI9t5daJpMBeN39EdP1IhD6HiYkp5dpLVO5oRkoNSZG4KuT2R4Eyd%2FuhDfcgIeLrfeHHM767Yjr5YTt1GIiZYZl0tr14NmR4yw81JLfNiJRRpMy2ognvJVPsE4R9oQ%3D%3D&amp;Expires=1780412827"></a></p>



<h2 id="h-wordpress-malware-abuses-steam-community-profiles" class="wp-block-heading"><strong>WordPress Malware Abuses Steam Community Profiles</strong></h2>



<p class="wp-block-paragraph">The core of this attack relies on a PHP function embedded within the compromised WordPress installation. </p>



<p class="wp-block-paragraph">When any page on the infected site loads, <a href="https://cybersecuritynews.com/malware-analysis/" id="82355" target="_blank" rel="noreferrer noopener">the malware sends an HTTP request to a Steam Community</a> profile page using cURL, scrapes comment text from that profile, and decodes hidden payloads embedded inside it.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/98400c7f-9346-41bc-88e8-21c02b5cce58/WordPress-Malware-Abuses-Steam-Community-Profiles-for-C2-Operations.pdf?AWSAccessKeyId=ASIA2F3EMEYETP2SQXGT&amp;Signature=zWYo5BSY72ZIa1ZPReXwUWfae7k%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEF8aCXVzLWVhc3QtMSJHMEUCIQDq2b3sYquDO73fy73RxHM0yEHryytvso2brLeBHMPUsQIgYXUsqE%2FQZ%2FPOh217aCj4UZ%2FYsVU50xSta0uY4a7uO58q8wQIKBABGgw2OTk3NTMzMDk3MDUiDPfX2dxySvoTEY%2FsfyrQBPBd0cXHXlZjWEtna%2FfIoEGmkCXmZ%2FL3P2Zpd5UmMnBKU4UpxxcspR4iOv%2B2Rt%2FYrCl%2FSPdDOtZSaDOqhNTccSjjZentdI4yvMSk%2F3QnmAadABkiyBiaApDGGNH0b%2BJDTD7Z9pygIzqVOQrRjzHmWr%2FST5NEizB3sJGfHlspFfdqe0mroG1JFmGFoRUM1Yn8vCT%2F20U2bUqn35CSBhuxKbuVfEuwv8by35oLGYlRPcKhbPofS%2F9GRGdHjZk96gjfEyv0O9PzIX6an4OkzoSTPTHq5QGT6w9n3tKLc9ltm21XxK1Vc6SjVZR948kGJ2RFAlff1fG%2BaJo3K1jUn2xkth%2BA2fTsYzu7%2BADVVSWCJe9sZiBtwNyGPUQtHePQpy5%2BP8O%2FnInnhV2q38bZWZFLmO%2By1%2FJxVhp5O9sOxym5863UROXcqwmfpuW3%2FrBv2WgNANM6miVJxTsacXgVIhywQNaheAks8GkS1qp9KD7s5Xe0fviNCzlIjL6elsk9INVdY5AwtNBWcxhOI0Dx4H5vUGtNoK9JULRCHPd1stxyFoTBfv4OzFp43h35R2hHB6%2FnirKU0%2FiBQhZerscq2ld5cI34iLnIwXay%2BY8ggGnsZeB%2B3OsXiaX4082%2BMIzyS2DShmehFNQxS56LqzhU1hcX1dqkI4tPNazPPMoVN6pS%2BK4NJYwm9UmcbZQAwp4%2B%2BacAqPE1PJ1V9w2f7J914LqroRTRDMKmR%2BG3vFqZNw0W0XIFgr0khi9mE4BSLJRGUEZaamdwRJsiRFYV5IWLPpKEMPYwhNX70AY6mAElq5BXmPx%2Bpu0zfPPar%2FPMoOwvKEKSqMtQzqT7rRNCtphakiNorg1RQYt7p6AYNLcKhWoLmUT6ixgNjI9t5daJpMBeN39EdP1IhD6HiYkp5dpLVO5oRkoNSZG4KuT2R4Eyd%2FuhDfcgIeLrfeHHM767Yjr5YTt1GIiZYZl0tr14NmR4yw81JLfNiJRRpMy2ognvJVPsE4R9oQ%3D%3D&amp;Expires=1780412827" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">The malware has been observed fetching profiles such as steamcommunity.com/profiles/76561199096946028 and caches extracted content using WordPress transients with a five-minute expiration window. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjH2SZ8NWQlw-4NVtrB54di88HVt-KvflUQEyvVKfXx_ItznOSi_pczAZ5wcTPnE6A4sdghLZ9HH_YWR-mzinryUZKNrBvvZ7vvOpQTJwtYkPHBDU8QwHJH0fPFOh9AYbJgOYiVDIWa0AHSuEgRysap1Jkh9i1UcuD-emg_TPwTYQNOSC1nMCSgK6pWJWo/s16000/PublicWWW%20results%20showing%20websites%20loading%20hello-mywordl%5B.%5Dinfo%20(Source%20-%20GoDaddy).webp" alt="PublicWWW results showing websites loading hello-mywordl[.]info (Source - GoDaddy)" /><figcaption class="wp-element-caption">PublicWWW results showing websites loading hello-mywordl[.]info (Source &#8211; GoDaddy)</figcaption></figure>
</div>


<p class="wp-block-paragraph">The decoded data becomes a JavaScript URL injected into every front-end page via the wp_enqueue_script hook, under the deceptive handle name &#8220;asahi-jquery-min-bundle&#8221; designed to mimic a legitimate library. </p>



<p class="wp-block-paragraph">The decoded external URL observed during analysis pointed to hello-myworld[.]info, which serves the final malicious JavaScript payload to site visitors.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/98400c7f-9346-41bc-88e8-21c02b5cce58/WordPress-Malware-Abuses-Steam-Community-Profiles-for-C2-Operations.pdf?AWSAccessKeyId=ASIA2F3EMEYETP2SQXGT&amp;Signature=zWYo5BSY72ZIa1ZPReXwUWfae7k%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEF8aCXVzLWVhc3QtMSJHMEUCIQDq2b3sYquDO73fy73RxHM0yEHryytvso2brLeBHMPUsQIgYXUsqE%2FQZ%2FPOh217aCj4UZ%2FYsVU50xSta0uY4a7uO58q8wQIKBABGgw2OTk3NTMzMDk3MDUiDPfX2dxySvoTEY%2FsfyrQBPBd0cXHXlZjWEtna%2FfIoEGmkCXmZ%2FL3P2Zpd5UmMnBKU4UpxxcspR4iOv%2B2Rt%2FYrCl%2FSPdDOtZSaDOqhNTccSjjZentdI4yvMSk%2F3QnmAadABkiyBiaApDGGNH0b%2BJDTD7Z9pygIzqVOQrRjzHmWr%2FST5NEizB3sJGfHlspFfdqe0mroG1JFmGFoRUM1Yn8vCT%2F20U2bUqn35CSBhuxKbuVfEuwv8by35oLGYlRPcKhbPofS%2F9GRGdHjZk96gjfEyv0O9PzIX6an4OkzoSTPTHq5QGT6w9n3tKLc9ltm21XxK1Vc6SjVZR948kGJ2RFAlff1fG%2BaJo3K1jUn2xkth%2BA2fTsYzu7%2BADVVSWCJe9sZiBtwNyGPUQtHePQpy5%2BP8O%2FnInnhV2q38bZWZFLmO%2By1%2FJxVhp5O9sOxym5863UROXcqwmfpuW3%2FrBv2WgNANM6miVJxTsacXgVIhywQNaheAks8GkS1qp9KD7s5Xe0fviNCzlIjL6elsk9INVdY5AwtNBWcxhOI0Dx4H5vUGtNoK9JULRCHPd1stxyFoTBfv4OzFp43h35R2hHB6%2FnirKU0%2FiBQhZerscq2ld5cI34iLnIwXay%2BY8ggGnsZeB%2B3OsXiaX4082%2BMIzyS2DShmehFNQxS56LqzhU1hcX1dqkI4tPNazPPMoVN6pS%2BK4NJYwm9UmcbZQAwp4%2B%2BacAqPE1PJ1V9w2f7J914LqroRTRDMKmR%2BG3vFqZNw0W0XIFgr0khi9mE4BSLJRGUEZaamdwRJsiRFYV5IWLPpKEMPYwhNX70AY6mAElq5BXmPx%2Bpu0zfPPar%2FPMoOwvKEKSqMtQzqT7rRNCtphakiNorg1RQYt7p6AYNLcKhWoLmUT6ixgNjI9t5daJpMBeN39EdP1IhD6HiYkp5dpLVO5oRkoNSZG4KuT2R4Eyd%2FuhDfcgIeLrfeHHM767Yjr5YTt1GIiZYZl0tr14NmR4yw81JLfNiJRRpMy2ognvJVPsE4R9oQ%3D%3D&amp;Expires=1780412827" target="_blank" rel="noreferrer noopener"></a></p>



<h2 id="h-stealthy-backdoor-enables-remote-code-execution" class="wp-block-heading"><strong>Stealthy Backdoor Enables Remote Code Execution</strong></h2>



<p class="wp-block-paragraph">The server-side component is just as dangerous as the front-end injection. A backdoor function registered through WordPress&#8217;s template_redirect hook listens for POST requests containing specific authentication cookies. </p>



<p class="wp-block-paragraph">When those cookies are present, the backdoor either confirms it is active by returning a version string, or accepts base64-encoded PHP code and rewrites plugin and theme files across the entire WordPress installation.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/98400c7f-9346-41bc-88e8-21c02b5cce58/WordPress-Malware-Abuses-Steam-Community-Profiles-for-C2-Operations.pdf?AWSAccessKeyId=ASIA2F3EMEYETP2SQXGT&amp;Signature=zWYo5BSY72ZIa1ZPReXwUWfae7k%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEF8aCXVzLWVhc3QtMSJHMEUCIQDq2b3sYquDO73fy73RxHM0yEHryytvso2brLeBHMPUsQIgYXUsqE%2FQZ%2FPOh217aCj4UZ%2FYsVU50xSta0uY4a7uO58q8wQIKBABGgw2OTk3NTMzMDk3MDUiDPfX2dxySvoTEY%2FsfyrQBPBd0cXHXlZjWEtna%2FfIoEGmkCXmZ%2FL3P2Zpd5UmMnBKU4UpxxcspR4iOv%2B2Rt%2FYrCl%2FSPdDOtZSaDOqhNTccSjjZentdI4yvMSk%2F3QnmAadABkiyBiaApDGGNH0b%2BJDTD7Z9pygIzqVOQrRjzHmWr%2FST5NEizB3sJGfHlspFfdqe0mroG1JFmGFoRUM1Yn8vCT%2F20U2bUqn35CSBhuxKbuVfEuwv8by35oLGYlRPcKhbPofS%2F9GRGdHjZk96gjfEyv0O9PzIX6an4OkzoSTPTHq5QGT6w9n3tKLc9ltm21XxK1Vc6SjVZR948kGJ2RFAlff1fG%2BaJo3K1jUn2xkth%2BA2fTsYzu7%2BADVVSWCJe9sZiBtwNyGPUQtHePQpy5%2BP8O%2FnInnhV2q38bZWZFLmO%2By1%2FJxVhp5O9sOxym5863UROXcqwmfpuW3%2FrBv2WgNANM6miVJxTsacXgVIhywQNaheAks8GkS1qp9KD7s5Xe0fviNCzlIjL6elsk9INVdY5AwtNBWcxhOI0Dx4H5vUGtNoK9JULRCHPd1stxyFoTBfv4OzFp43h35R2hHB6%2FnirKU0%2FiBQhZerscq2ld5cI34iLnIwXay%2BY8ggGnsZeB%2B3OsXiaX4082%2BMIzyS2DShmehFNQxS56LqzhU1hcX1dqkI4tPNazPPMoVN6pS%2BK4NJYwm9UmcbZQAwp4%2B%2BacAqPE1PJ1V9w2f7J914LqroRTRDMKmR%2BG3vFqZNw0W0XIFgr0khi9mE4BSLJRGUEZaamdwRJsiRFYV5IWLPpKEMPYwhNX70AY6mAElq5BXmPx%2Bpu0zfPPar%2FPMoOwvKEKSqMtQzqT7rRNCtphakiNorg1RQYt7p6AYNLcKhWoLmUT6ixgNjI9t5daJpMBeN39EdP1IhD6HiYkp5dpLVO5oRkoNSZG4KuT2R4Eyd%2FuhDfcgIeLrfeHHM767Yjr5YTt1GIiZYZl0tr14NmR4yw81JLfNiJRRpMy2ognvJVPsE4R9oQ%3D%3D&amp;Expires=1780412827" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">This remote code execution capability means that even if a site owner removes part of the infection, attackers can reinstall deleted code through the still-active backdoor. </p>



<p class="wp-block-paragraph">The malware protects this channel using AES-256-CTR encryption with PBKDF2 key derivation based on SHA-512 and 10,000 iterations, along with HMAC-SHA256 authentication to verify each incoming payload.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/98400c7f-9346-41bc-88e8-21c02b5cce58/WordPress-Malware-Abuses-Steam-Community-Profiles-for-C2-Operations.pdf?AWSAccessKeyId=ASIA2F3EMEYETP2SQXGT&amp;Signature=zWYo5BSY72ZIa1ZPReXwUWfae7k%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEF8aCXVzLWVhc3QtMSJHMEUCIQDq2b3sYquDO73fy73RxHM0yEHryytvso2brLeBHMPUsQIgYXUsqE%2FQZ%2FPOh217aCj4UZ%2FYsVU50xSta0uY4a7uO58q8wQIKBABGgw2OTk3NTMzMDk3MDUiDPfX2dxySvoTEY%2FsfyrQBPBd0cXHXlZjWEtna%2FfIoEGmkCXmZ%2FL3P2Zpd5UmMnBKU4UpxxcspR4iOv%2B2Rt%2FYrCl%2FSPdDOtZSaDOqhNTccSjjZentdI4yvMSk%2F3QnmAadABkiyBiaApDGGNH0b%2BJDTD7Z9pygIzqVOQrRjzHmWr%2FST5NEizB3sJGfHlspFfdqe0mroG1JFmGFoRUM1Yn8vCT%2F20U2bUqn35CSBhuxKbuVfEuwv8by35oLGYlRPcKhbPofS%2F9GRGdHjZk96gjfEyv0O9PzIX6an4OkzoSTPTHq5QGT6w9n3tKLc9ltm21XxK1Vc6SjVZR948kGJ2RFAlff1fG%2BaJo3K1jUn2xkth%2BA2fTsYzu7%2BADVVSWCJe9sZiBtwNyGPUQtHePQpy5%2BP8O%2FnInnhV2q38bZWZFLmO%2By1%2FJxVhp5O9sOxym5863UROXcqwmfpuW3%2FrBv2WgNANM6miVJxTsacXgVIhywQNaheAks8GkS1qp9KD7s5Xe0fviNCzlIjL6elsk9INVdY5AwtNBWcxhOI0Dx4H5vUGtNoK9JULRCHPd1stxyFoTBfv4OzFp43h35R2hHB6%2FnirKU0%2FiBQhZerscq2ld5cI34iLnIwXay%2BY8ggGnsZeB%2B3OsXiaX4082%2BMIzyS2DShmehFNQxS56LqzhU1hcX1dqkI4tPNazPPMoVN6pS%2BK4NJYwm9UmcbZQAwp4%2B%2BacAqPE1PJ1V9w2f7J914LqroRTRDMKmR%2BG3vFqZNw0W0XIFgr0khi9mE4BSLJRGUEZaamdwRJsiRFYV5IWLPpKEMPYwhNX70AY6mAElq5BXmPx%2Bpu0zfPPar%2FPMoOwvKEKSqMtQzqT7rRNCtphakiNorg1RQYt7p6AYNLcKhWoLmUT6ixgNjI9t5daJpMBeN39EdP1IhD6HiYkp5dpLVO5oRkoNSZG4KuT2R4Eyd%2FuhDfcgIeLrfeHHM767Yjr5YTt1GIiZYZl0tr14NmR4yw81JLfNiJRRpMy2ognvJVPsE4R9oQ%3D%3D&amp;Expires=1780412827" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">To evade detection, <a href="https://cybersecuritynews.com/researchers-detailed-apt28s-hta-trojan-multi-layer-obfuscation-techniques/" id="94791" target="_blank" rel="noreferrer noopener">the malware layers multiple obfuscation techniques</a>. All string constants are encoded using octal or hexadecimal escape sequences, function and variable names follow a randomized mixed-case hexadecimal style, and a disabled logging function is scattered through the code to mimic legitimate debugging infrastructure without ever executing.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/98400c7f-9346-41bc-88e8-21c02b5cce58/WordPress-Malware-Abuses-Steam-Community-Profiles-for-C2-Operations.pdf?AWSAccessKeyId=ASIA2F3EMEYETP2SQXGT&amp;Signature=zWYo5BSY72ZIa1ZPReXwUWfae7k%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEF8aCXVzLWVhc3QtMSJHMEUCIQDq2b3sYquDO73fy73RxHM0yEHryytvso2brLeBHMPUsQIgYXUsqE%2FQZ%2FPOh217aCj4UZ%2FYsVU50xSta0uY4a7uO58q8wQIKBABGgw2OTk3NTMzMDk3MDUiDPfX2dxySvoTEY%2FsfyrQBPBd0cXHXlZjWEtna%2FfIoEGmkCXmZ%2FL3P2Zpd5UmMnBKU4UpxxcspR4iOv%2B2Rt%2FYrCl%2FSPdDOtZSaDOqhNTccSjjZentdI4yvMSk%2F3QnmAadABkiyBiaApDGGNH0b%2BJDTD7Z9pygIzqVOQrRjzHmWr%2FST5NEizB3sJGfHlspFfdqe0mroG1JFmGFoRUM1Yn8vCT%2F20U2bUqn35CSBhuxKbuVfEuwv8by35oLGYlRPcKhbPofS%2F9GRGdHjZk96gjfEyv0O9PzIX6an4OkzoSTPTHq5QGT6w9n3tKLc9ltm21XxK1Vc6SjVZR948kGJ2RFAlff1fG%2BaJo3K1jUn2xkth%2BA2fTsYzu7%2BADVVSWCJe9sZiBtwNyGPUQtHePQpy5%2BP8O%2FnInnhV2q38bZWZFLmO%2By1%2FJxVhp5O9sOxym5863UROXcqwmfpuW3%2FrBv2WgNANM6miVJxTsacXgVIhywQNaheAks8GkS1qp9KD7s5Xe0fviNCzlIjL6elsk9INVdY5AwtNBWcxhOI0Dx4H5vUGtNoK9JULRCHPd1stxyFoTBfv4OzFp43h35R2hHB6%2FnirKU0%2FiBQhZerscq2ld5cI34iLnIwXay%2BY8ggGnsZeB%2B3OsXiaX4082%2BMIzyS2DShmehFNQxS56LqzhU1hcX1dqkI4tPNazPPMoVN6pS%2BK4NJYwm9UmcbZQAwp4%2B%2BacAqPE1PJ1V9w2f7J914LqroRTRDMKmR%2BG3vFqZNw0W0XIFgr0khi9mE4BSLJRGUEZaamdwRJsiRFYV5IWLPpKEMPYwhNX70AY6mAElq5BXmPx%2Bpu0zfPPar%2FPMoOwvKEKSqMtQzqT7rRNCtphakiNorg1RQYt7p6AYNLcKhWoLmUT6ixgNjI9t5daJpMBeN39EdP1IhD6HiYkp5dpLVO5oRkoNSZG4KuT2R4Eyd%2FuhDfcgIeLrfeHHM767Yjr5YTt1GIiZYZl0tr14NmR4yw81JLfNiJRRpMy2ognvJVPsE4R9oQ%3D%3D&amp;Expires=1780412827" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">Site administrators who suspect an infection should enable maintenance mode right away and back up the compromised installation before making any changes. </p>



<p class="wp-block-paragraph">All WordPress credentials including admin passwords, database access, FTP credentials, and SSH keys must be rotated. Cleanup must cover every plugin and theme file, since partial removal is not enough given the backdoor&#8217;s ability to remotely restore deleted code. </p>



<p class="wp-block-paragraph">Suspicious transient cache entries with the prefix <em>transient_caption</em> and enqueued external scripts pointing to unknown domains should be removed.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/98400c7f-9346-41bc-88e8-21c02b5cce58/WordPress-Malware-Abuses-Steam-Community-Profiles-for-C2-Operations.pdf?AWSAccessKeyId=ASIA2F3EMEYETP2SQXGT&amp;Signature=zWYo5BSY72ZIa1ZPReXwUWfae7k%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEF8aCXVzLWVhc3QtMSJHMEUCIQDq2b3sYquDO73fy73RxHM0yEHryytvso2brLeBHMPUsQIgYXUsqE%2FQZ%2FPOh217aCj4UZ%2FYsVU50xSta0uY4a7uO58q8wQIKBABGgw2OTk3NTMzMDk3MDUiDPfX2dxySvoTEY%2FsfyrQBPBd0cXHXlZjWEtna%2FfIoEGmkCXmZ%2FL3P2Zpd5UmMnBKU4UpxxcspR4iOv%2B2Rt%2FYrCl%2FSPdDOtZSaDOqhNTccSjjZentdI4yvMSk%2F3QnmAadABkiyBiaApDGGNH0b%2BJDTD7Z9pygIzqVOQrRjzHmWr%2FST5NEizB3sJGfHlspFfdqe0mroG1JFmGFoRUM1Yn8vCT%2F20U2bUqn35CSBhuxKbuVfEuwv8by35oLGYlRPcKhbPofS%2F9GRGdHjZk96gjfEyv0O9PzIX6an4OkzoSTPTHq5QGT6w9n3tKLc9ltm21XxK1Vc6SjVZR948kGJ2RFAlff1fG%2BaJo3K1jUn2xkth%2BA2fTsYzu7%2BADVVSWCJe9sZiBtwNyGPUQtHePQpy5%2BP8O%2FnInnhV2q38bZWZFLmO%2By1%2FJxVhp5O9sOxym5863UROXcqwmfpuW3%2FrBv2WgNANM6miVJxTsacXgVIhywQNaheAks8GkS1qp9KD7s5Xe0fviNCzlIjL6elsk9INVdY5AwtNBWcxhOI0Dx4H5vUGtNoK9JULRCHPd1stxyFoTBfv4OzFp43h35R2hHB6%2FnirKU0%2FiBQhZerscq2ld5cI34iLnIwXay%2BY8ggGnsZeB%2B3OsXiaX4082%2BMIzyS2DShmehFNQxS56LqzhU1hcX1dqkI4tPNazPPMoVN6pS%2BK4NJYwm9UmcbZQAwp4%2B%2BacAqPE1PJ1V9w2f7J914LqroRTRDMKmR%2BG3vFqZNw0W0XIFgr0khi9mE4BSLJRGUEZaamdwRJsiRFYV5IWLPpKEMPYwhNX70AY6mAElq5BXmPx%2Bpu0zfPPar%2FPMoOwvKEKSqMtQzqT7rRNCtphakiNorg1RQYt7p6AYNLcKhWoLmUT6ixgNjI9t5daJpMBeN39EdP1IhD6HiYkp5dpLVO5oRkoNSZG4KuT2R4Eyd%2FuhDfcgIeLrfeHHM767Yjr5YTt1GIiZYZl0tr14NmR4yw81JLfNiJRRpMy2ognvJVPsE4R9oQ%3D%3D&amp;Expires=1780412827" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph" id="h-indicators-of-compromise-iocs"><strong>Indicators of Compromise (IoCs):-</strong></p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th class="has-text-align-left" data-align="left"><strong>Type</strong></th><th class="has-text-align-left" data-align="left"><strong>Indicator</strong></th><th class="has-text-align-left" data-align="left"><strong>Description</strong></th></tr></thead><tbody><tr><td>URL</td><td>https://steamcommunity.com/profiles/76561199096946028/</td><td>Steam profile used to host encoded C2 payloads</td></tr><tr><td>URL</td><td>https://steamcommunity.com/id/ravypadliha</td><td>Steam profile observed during malware fetching</td></tr><tr><td>URL</td><td>https://steamcommunity.com/id/enomisvool123/</td><td>Steam profile observed during malware fetching</td></tr><tr><td>URL</td><td>https://steamcommunity.com/id/eremohnf342</td><td>Steam profile observed during malware fetching</td></tr><tr><td>Domain</td><td>hello-myworld[.]info</td><td>External domain serving the decoded malicious JavaScript payload</td></tr><tr><td>Cookie Name</td><td>DEpjndDbNc</td><td>Authentication cookie used to trigger backdoor ping/keepalive response</td></tr><tr><td>Cookie Name</td><td>tEcaKKXEsb</td><td>Authentication cookie used to trigger remote code execution via backdoor</td></tr><tr><td>File Path</td><td>/wp-content/themes/gt3-child/functions.php</td><td>File path where malware was initially discovered</td></tr><tr><td>Handle Name</td><td>asahi-jquery-min-bundle</td><td>Deceptive script handle name used to inject malicious JavaScript</td></tr><tr><td>Transient Prefix</td><td><em>transient_caption</em></td><td>WordPress transient cache prefix used to store C2 data</td></tr><tr><td>Function Name</td><td>Ce8d26cADf211699</td><td>PHP function responsible for fetching Steam profile content</td></tr><tr><td>Function Name</td><td>EdF20922Ff709e68</td><td>PHP function performing cryptographic decoding of payloads</td></tr><tr><td>Function Name</td><td>G7jp2L84mnVc4LNW9wcbZcaVFAyC9N72</td><td>PHP function injecting decoded script into WordPress front end</td></tr><tr><td>Function Name</td><td>mpzZYIbGOb</td><td>PHP backdoor handler function registered via template_redirect</td></tr></tbody></table></figure>



<p class="wp-block-paragraph"><strong>Note:</strong>&nbsp;<em>IP addresses and domains are intentionally defanged (e.g.,&nbsp;</em><code><em>[.]</em></code><em>) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM</em>.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)"><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>Follow us on&nbsp;<a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en" target="_blank" rel="noreferrer noopener">Google News</a>,&nbsp;<a href="https://www.linkedin.com/company/cybersecurity-news/" target="_blank" rel="noreferrer noopener">LinkedIn</a>,&nbsp;and&nbsp;<a href="https://x.com/cyber_press_org" target="_blank" rel="noreferrer noopener">X</a>&nbsp;to Get More Instant Updates</strong>,&nbsp;<strong>Set CSN as a Preferred Source in</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong> <strong><strong><a href="https://www.google.com/preferences/source?q=cybersecuritynews.com" target="_blank" rel="noreferrer noopener">Google</a></strong></strong>.</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/wordpress-malware-abuses-steam/">WordPress Malware Abuses Steam Community Profiles for C2 Operations</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/WordPress-Malware-Abuses-Steam-Community-Profiles-for-C2-Operations.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151696</post-id>	</item>
		<item>
		<title>Threat Actor Uses Stolen Gemini API Keys to Automate Telegram Influence Campaign</title>
		<link>https://cybersecuritynews.com/threat-actor-uses-stolen-gemini-api-keys/</link>
		
		<dc:creator><![CDATA[Tushar Subhra Dutta]]></dc:creator>
		<pubDate>Tue, 02 Jun 2026 18:45:55 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Threats]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151689</guid>

					<description><![CDATA[<p>A single threat actor has been running a fake political persona on Telegram for five years, quietly building an audience of over 17,000 subscribers while using stolen AI credentials to power the entire operation. What looks like an American patriot channel is actually a financially motivated fraud scheme run by a solo Russian-speaking operator. The [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/threat-actor-uses-stolen-gemini-api-keys/">Threat Actor Uses Stolen Gemini API Keys to Automate Telegram Influence Campaign</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">A single threat actor has been running a fake political persona on Telegram for five years, quietly building an audience of over 17,000 subscribers while using stolen AI credentials to power the entire operation. </p>



<p class="wp-block-paragraph">What looks like an American patriot channel is actually a financially motivated fraud scheme run by a solo Russian-speaking operator. The goal was always money, and AI made scaling that goal nearly effortless.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/626d88c5-05e2-46ad-b3d0-adb1fea8f190/Threat-Actor-Uses-Stolen-Gemini-API-Keys-to-Automate-Telegram-Influence-Campaign.pdf?AWSAccessKeyId=ASIA2F3EMEYE7JKC4HAJ&amp;Signature=z%2FKCe9F1XQE9KZsxSKWKz%2BpNqt8%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEF8aCXVzLWVhc3QtMSJGMEQCIGoTaK9S5Q5n5MP01JMnP2DMLea8M%2BbI0jY5zmboNbMxAiAoLLyyNw%2BdmQgO4rg9C%2BBKIAbDK65PeQJpuC%2BoDi61xSrzBAgoEAEaDDY5OTc1MzMwOTcwNSIMvZ9IAXVBYCAfjD04KtAEYvAP0q4XeZEnmsPl%2FjTCK1wX0dB%2BDzIN0p4o6gUVdQiU%2BR0QceyphwMlgQiU%2BeoHEpRKEodJA18vPp%2FT1HOjphSvSO1vMXQNt4bYapjomCgAQQ8h%2B87wJtS%2BjAzeD0hPovg69XmXG7WgTlRYQhd0M1mkQVWdY1zzpPJ0Ao%2F7TchBAlddRaNsl5bnmU3FgDqANm%2FYBa0M0XxoH0DBO662bUTZDoqyzSznQJYdAQDarrxT8qgZCOtzy9cRzelrzqv480ub8ItOh4xtJiF5UaPJtboO6K7RRATbb5WwBtBsVTlaRLYycTvuU%2FN5MGOThdn7eSSShMLQNJbJ9JZZc81v6h79s8Br8WBhWLNzvG%2FBnNAxYyRbIYW%2FTVuyowbHnXiSslMX3iyp97aYS31K7QOMEPf6tbTX6r1RTnh1emSFhiEk93QSLQ2LcsvXvmRmN%2B3EsT2RSPcYyL7bmhh6JXxMikKt0Y8xrqeUBvpFFlwVqu7sMJNUDB0TLmcEp2pFCCTjzHGYaVMOI%2FipkQeF%2FHD4KAMrdBFoDgZEqZp3CJJsC%2BFm2d%2BVoppaMWCJVFY44I1%2BCGPQBa1LY%2Fchz83PJe01nR3bRhyTe0VmKdVIISRGEnF9qgImduzPrlG6HaA%2FZ4CvljkZBR7k2L6zKERywV9KMKx4yD54iP3wPm3d%2FEIIkcm4tlVR%2FDwtlJ9fhddLdJRuh3xWnhWSXmWdIb5d749Wwi4aHPWECK34I68ZJ4AkpVMh6yzuiizQ08ULWGsstqzrJV3MFHefZ4psL32z5kaWhzDV0fvQBjqZAdDc8pluGRROV1Rb1MHFeCcvGPw3Uepj3lNyTlVK1lkS0r3Wyy0SANvlgnZeIL3IMX6QD8m4Opmy9%2BABX%2FBDG273JJmuaENwImsHq6Dsd%2BwZHRU5KlE5XOhNyGenIBQi9umtHAghPE0wN7qxYi85nh5rz2L9I0EsD659dxUE7aZHZAoU3OlyBQsqmNBr4F%2BjJGeiT%2F6VYoGp8w%3D%3D&amp;Expires=1780412099" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">The campaign, tracked under the handle &#8220;bandcampro,&#8221; began on February 6, 2021, one month after the Capitol riot, when QAnon and MAGA communities were being deplatformed and migrating to Telegram. </p>



<p class="wp-block-paragraph">By positioning the fake channel, @americanpatriotus, as an authentic American conservative voice, the actor tapped into a ready-made audience already hungry for alternative platforms. The timing was clearly opportunistic.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/626d88c5-05e2-46ad-b3d0-adb1fea8f190/Threat-Actor-Uses-Stolen-Gemini-API-Keys-to-Automate-Telegram-Influence-Campaign.pdf?AWSAccessKeyId=ASIA2F3EMEYE7JKC4HAJ&amp;Signature=z%2FKCe9F1XQE9KZsxSKWKz%2BpNqt8%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEF8aCXVzLWVhc3QtMSJGMEQCIGoTaK9S5Q5n5MP01JMnP2DMLea8M%2BbI0jY5zmboNbMxAiAoLLyyNw%2BdmQgO4rg9C%2BBKIAbDK65PeQJpuC%2BoDi61xSrzBAgoEAEaDDY5OTc1MzMwOTcwNSIMvZ9IAXVBYCAfjD04KtAEYvAP0q4XeZEnmsPl%2FjTCK1wX0dB%2BDzIN0p4o6gUVdQiU%2BR0QceyphwMlgQiU%2BeoHEpRKEodJA18vPp%2FT1HOjphSvSO1vMXQNt4bYapjomCgAQQ8h%2B87wJtS%2BjAzeD0hPovg69XmXG7WgTlRYQhd0M1mkQVWdY1zzpPJ0Ao%2F7TchBAlddRaNsl5bnmU3FgDqANm%2FYBa0M0XxoH0DBO662bUTZDoqyzSznQJYdAQDarrxT8qgZCOtzy9cRzelrzqv480ub8ItOh4xtJiF5UaPJtboO6K7RRATbb5WwBtBsVTlaRLYycTvuU%2FN5MGOThdn7eSSShMLQNJbJ9JZZc81v6h79s8Br8WBhWLNzvG%2FBnNAxYyRbIYW%2FTVuyowbHnXiSslMX3iyp97aYS31K7QOMEPf6tbTX6r1RTnh1emSFhiEk93QSLQ2LcsvXvmRmN%2B3EsT2RSPcYyL7bmhh6JXxMikKt0Y8xrqeUBvpFFlwVqu7sMJNUDB0TLmcEp2pFCCTjzHGYaVMOI%2FipkQeF%2FHD4KAMrdBFoDgZEqZp3CJJsC%2BFm2d%2BVoppaMWCJVFY44I1%2BCGPQBa1LY%2Fchz83PJe01nR3bRhyTe0VmKdVIISRGEnF9qgImduzPrlG6HaA%2FZ4CvljkZBR7k2L6zKERywV9KMKx4yD54iP3wPm3d%2FEIIkcm4tlVR%2FDwtlJ9fhddLdJRuh3xWnhWSXmWdIb5d749Wwi4aHPWECK34I68ZJ4AkpVMh6yzuiizQ08ULWGsstqzrJV3MFHefZ4psL32z5kaWhzDV0fvQBjqZAdDc8pluGRROV1Rb1MHFeCcvGPw3Uepj3lNyTlVK1lkS0r3Wyy0SANvlgnZeIL3IMX6QD8m4Opmy9%2BABX%2FBDG273JJmuaENwImsHq6Dsd%2BwZHRU5KlE5XOhNyGenIBQi9umtHAghPE0wN7qxYi85nh5rz2L9I0EsD659dxUE7aZHZAoU3OlyBQsqmNBr4F%2BjJGeiT%2F6VYoGp8w%3D%3D&amp;Expires=1780412099" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph"><a href="https://www.trendmicro.com/en_us/research/26/e/inside-the-influence-and-fraud-patriot-bait-campaign.html" id="https://www.trendmicro.com/en_us/research/26/e/inside-the-influence-and-fraud-patriot-bait-campaign.html" target="_blank" rel="noreferrer noopener nofollow">Analysts at Trend Micro said in a report</a> shared with Cyber Security News (CSN) that in May 2026, their TrendAI Research team discovered the threat actor&#8217;s operational environment had been inadvertently exposed, revealing the full scope of a five-year influence and fraud campaign. </p>



<p class="wp-block-paragraph">The actor used <a href="https://cybersecuritynews.com/scattered-spider-with-new-telegram-channel/" id="120704" target="_blank" rel="noreferrer noopener">AI-assisted techniques to run the Telegram channel</a>, targeting politically engaged American audiences for cryptocurrency fraud alongside AI-assisted credential theft.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/626d88c5-05e2-46ad-b3d0-adb1fea8f190/Threat-Actor-Uses-Stolen-Gemini-API-Keys-to-Automate-Telegram-Influence-Campaign.pdf?AWSAccessKeyId=ASIA2F3EMEYE7JKC4HAJ&amp;Signature=z%2FKCe9F1XQE9KZsxSKWKz%2BpNqt8%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEF8aCXVzLWVhc3QtMSJGMEQCIGoTaK9S5Q5n5MP01JMnP2DMLea8M%2BbI0jY5zmboNbMxAiAoLLyyNw%2BdmQgO4rg9C%2BBKIAbDK65PeQJpuC%2BoDi61xSrzBAgoEAEaDDY5OTc1MzMwOTcwNSIMvZ9IAXVBYCAfjD04KtAEYvAP0q4XeZEnmsPl%2FjTCK1wX0dB%2BDzIN0p4o6gUVdQiU%2BR0QceyphwMlgQiU%2BeoHEpRKEodJA18vPp%2FT1HOjphSvSO1vMXQNt4bYapjomCgAQQ8h%2B87wJtS%2BjAzeD0hPovg69XmXG7WgTlRYQhd0M1mkQVWdY1zzpPJ0Ao%2F7TchBAlddRaNsl5bnmU3FgDqANm%2FYBa0M0XxoH0DBO662bUTZDoqyzSznQJYdAQDarrxT8qgZCOtzy9cRzelrzqv480ub8ItOh4xtJiF5UaPJtboO6K7RRATbb5WwBtBsVTlaRLYycTvuU%2FN5MGOThdn7eSSShMLQNJbJ9JZZc81v6h79s8Br8WBhWLNzvG%2FBnNAxYyRbIYW%2FTVuyowbHnXiSslMX3iyp97aYS31K7QOMEPf6tbTX6r1RTnh1emSFhiEk93QSLQ2LcsvXvmRmN%2B3EsT2RSPcYyL7bmhh6JXxMikKt0Y8xrqeUBvpFFlwVqu7sMJNUDB0TLmcEp2pFCCTjzHGYaVMOI%2FipkQeF%2FHD4KAMrdBFoDgZEqZp3CJJsC%2BFm2d%2BVoppaMWCJVFY44I1%2BCGPQBa1LY%2Fchz83PJe01nR3bRhyTe0VmKdVIISRGEnF9qgImduzPrlG6HaA%2FZ4CvljkZBR7k2L6zKERywV9KMKx4yD54iP3wPm3d%2FEIIkcm4tlVR%2FDwtlJ9fhddLdJRuh3xWnhWSXmWdIb5d749Wwi4aHPWECK34I68ZJ4AkpVMh6yzuiizQ08ULWGsstqzrJV3MFHefZ4psL32z5kaWhzDV0fvQBjqZAdDc8pluGRROV1Rb1MHFeCcvGPw3Uepj3lNyTlVK1lkS0r3Wyy0SANvlgnZeIL3IMX6QD8m4Opmy9%2BABX%2FBDG273JJmuaENwImsHq6Dsd%2BwZHRU5KlE5XOhNyGenIBQi9umtHAghPE0wN7qxYi85nh5rz2L9I0EsD659dxUE7aZHZAoU3OlyBQsqmNBr4F%2BjJGeiT%2F6VYoGp8w%3D%3D&amp;Expires=1780412099" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">Starting in September 2025, the actor pivoted to fully AI-generated content, using a jailbroken version of Google Gemini as an operational co-worker. </p>



<p class="wp-block-paragraph">He named his content pipeline &#8220;Quantum Patriot,&#8221; a set of Python scripts that called Gemini to roleplay as an American veteran patriot. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjTlFiA3gCcQzpyyu2RqjpckMNX_SPiWy8oh5a5GWAoUjpjfGbqQIpnGR9NwiMHFE4YTuLlkqnH2PZuwcaYLEeXfTmi8i5zCfXp5lVYYon8y2HDW0CQVVXLXDPUN1nA34HkvEOzs0yQLEtZlbSalo5jENKw4AafTym7-1oDVPeccH5R2_hLYi62_CqA9uE/s16000/The%20%E2%80%9CAmerican%20Patriot%E2%80%9D%20Telegram%20profile%20(Source%20-%20Trend%20Micro).webp" alt="The “American Patriot” Telegram profile (Source - Trend Micro)" /><figcaption class="wp-element-caption">The “American Patriot” Telegram profile (Source &#8211; Trend Micro)</figcaption></figure>
</div>


<p class="wp-block-paragraph">The AI generated Q-style posts, deployed servers, rotated stolen API keys, and managed Cloudflare tunnels, all from natural-language commands typed in Russian.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/626d88c5-05e2-46ad-b3d0-adb1fea8f190/Threat-Actor-Uses-Stolen-Gemini-API-Keys-to-Automate-Telegram-Influence-Campaign.pdf?AWSAccessKeyId=ASIA2F3EMEYE7JKC4HAJ&amp;Signature=z%2FKCe9F1XQE9KZsxSKWKz%2BpNqt8%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEF8aCXVzLWVhc3QtMSJGMEQCIGoTaK9S5Q5n5MP01JMnP2DMLea8M%2BbI0jY5zmboNbMxAiAoLLyyNw%2BdmQgO4rg9C%2BBKIAbDK65PeQJpuC%2BoDi61xSrzBAgoEAEaDDY5OTc1MzMwOTcwNSIMvZ9IAXVBYCAfjD04KtAEYvAP0q4XeZEnmsPl%2FjTCK1wX0dB%2BDzIN0p4o6gUVdQiU%2BR0QceyphwMlgQiU%2BeoHEpRKEodJA18vPp%2FT1HOjphSvSO1vMXQNt4bYapjomCgAQQ8h%2B87wJtS%2BjAzeD0hPovg69XmXG7WgTlRYQhd0M1mkQVWdY1zzpPJ0Ao%2F7TchBAlddRaNsl5bnmU3FgDqANm%2FYBa0M0XxoH0DBO662bUTZDoqyzSznQJYdAQDarrxT8qgZCOtzy9cRzelrzqv480ub8ItOh4xtJiF5UaPJtboO6K7RRATbb5WwBtBsVTlaRLYycTvuU%2FN5MGOThdn7eSSShMLQNJbJ9JZZc81v6h79s8Br8WBhWLNzvG%2FBnNAxYyRbIYW%2FTVuyowbHnXiSslMX3iyp97aYS31K7QOMEPf6tbTX6r1RTnh1emSFhiEk93QSLQ2LcsvXvmRmN%2B3EsT2RSPcYyL7bmhh6JXxMikKt0Y8xrqeUBvpFFlwVqu7sMJNUDB0TLmcEp2pFCCTjzHGYaVMOI%2FipkQeF%2FHD4KAMrdBFoDgZEqZp3CJJsC%2BFm2d%2BVoppaMWCJVFY44I1%2BCGPQBa1LY%2Fchz83PJe01nR3bRhyTe0VmKdVIISRGEnF9qgImduzPrlG6HaA%2FZ4CvljkZBR7k2L6zKERywV9KMKx4yD54iP3wPm3d%2FEIIkcm4tlVR%2FDwtlJ9fhddLdJRuh3xWnhWSXmWdIb5d749Wwi4aHPWECK34I68ZJ4AkpVMh6yzuiizQ08ULWGsstqzrJV3MFHefZ4psL32z5kaWhzDV0fvQBjqZAdDc8pluGRROV1Rb1MHFeCcvGPw3Uepj3lNyTlVK1lkS0r3Wyy0SANvlgnZeIL3IMX6QD8m4Opmy9%2BABX%2FBDG273JJmuaENwImsHq6Dsd%2BwZHRU5KlE5XOhNyGenIBQi9umtHAghPE0wN7qxYi85nh5rz2L9I0EsD659dxUE7aZHZAoU3OlyBQsqmNBr4F%2BjJGeiT%2F6VYoGp8w%3D%3D&amp;Expires=1780412099" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">What made the operation alarming was its near-zero cost. The actor used 73 likely stolen Gemini API keys on a round-robin rotation, meaning he paid almost nothing for industrial-scale content generation. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgnet-APgCv2oYaqFHxckC6FhayfslMPhPPE6B-AWhWeC4BYAaodJ0PSF5sQnGTmnI6aUQkrd5Ce2tystoWFhMMNuHgp_YxVDGXv-AJnlcIqPDcnIGpmRgd6Z0n5SQJms-ennEbypAN05dD35TFe3V6TwLytpmtOAuq_33Ifvg4IxmQrjYFuPWZUpM-fXo/s16000/The%20%E2%80%9CQuantum%20Patriot%E2%80%9D%20pipeline%20(Source%20-%20Trend%20Micro).webp" alt="The “Quantum Patriot” pipeline (Source - Trend Micro)" /><figcaption class="wp-element-caption">The “Quantum Patriot” pipeline (Source &#8211; Trend Micro)</figcaption></figure>
</div>


<p class="wp-block-paragraph">With 29 WordPress accounts cracked, one company infiltrated, and one victim&#8217;s cryptocurrency wallet fully drained, the operation showed that AI can scale a one-person fraud scheme to team-level output.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/626d88c5-05e2-46ad-b3d0-adb1fea8f190/Threat-Actor-Uses-Stolen-Gemini-API-Keys-to-Automate-Telegram-Influence-Campaign.pdf?AWSAccessKeyId=ASIA2F3EMEYE7JKC4HAJ&amp;Signature=z%2FKCe9F1XQE9KZsxSKWKz%2BpNqt8%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEF8aCXVzLWVhc3QtMSJGMEQCIGoTaK9S5Q5n5MP01JMnP2DMLea8M%2BbI0jY5zmboNbMxAiAoLLyyNw%2BdmQgO4rg9C%2BBKIAbDK65PeQJpuC%2BoDi61xSrzBAgoEAEaDDY5OTc1MzMwOTcwNSIMvZ9IAXVBYCAfjD04KtAEYvAP0q4XeZEnmsPl%2FjTCK1wX0dB%2BDzIN0p4o6gUVdQiU%2BR0QceyphwMlgQiU%2BeoHEpRKEodJA18vPp%2FT1HOjphSvSO1vMXQNt4bYapjomCgAQQ8h%2B87wJtS%2BjAzeD0hPovg69XmXG7WgTlRYQhd0M1mkQVWdY1zzpPJ0Ao%2F7TchBAlddRaNsl5bnmU3FgDqANm%2FYBa0M0XxoH0DBO662bUTZDoqyzSznQJYdAQDarrxT8qgZCOtzy9cRzelrzqv480ub8ItOh4xtJiF5UaPJtboO6K7RRATbb5WwBtBsVTlaRLYycTvuU%2FN5MGOThdn7eSSShMLQNJbJ9JZZc81v6h79s8Br8WBhWLNzvG%2FBnNAxYyRbIYW%2FTVuyowbHnXiSslMX3iyp97aYS31K7QOMEPf6tbTX6r1RTnh1emSFhiEk93QSLQ2LcsvXvmRmN%2B3EsT2RSPcYyL7bmhh6JXxMikKt0Y8xrqeUBvpFFlwVqu7sMJNUDB0TLmcEp2pFCCTjzHGYaVMOI%2FipkQeF%2FHD4KAMrdBFoDgZEqZp3CJJsC%2BFm2d%2BVoppaMWCJVFY44I1%2BCGPQBa1LY%2Fchz83PJe01nR3bRhyTe0VmKdVIISRGEnF9qgImduzPrlG6HaA%2FZ4CvljkZBR7k2L6zKERywV9KMKx4yD54iP3wPm3d%2FEIIkcm4tlVR%2FDwtlJ9fhddLdJRuh3xWnhWSXmWdIb5d749Wwi4aHPWECK34I68ZJ4AkpVMh6yzuiizQ08ULWGsstqzrJV3MFHefZ4psL32z5kaWhzDV0fvQBjqZAdDc8pluGRROV1Rb1MHFeCcvGPw3Uepj3lNyTlVK1lkS0r3Wyy0SANvlgnZeIL3IMX6QD8m4Opmy9%2BABX%2FBDG273JJmuaENwImsHq6Dsd%2BwZHRU5KlE5XOhNyGenIBQi9umtHAghPE0wN7qxYi85nh5rz2L9I0EsD659dxUE7aZHZAoU3OlyBQsqmNBr4F%2BjJGeiT%2F6VYoGp8w%3D%3D&amp;Expires=1780412099" target="_blank" rel="noreferrer noopener"></a></p>



<h2 id="h-threat-actor-uses-stolen-gemini-api-keys" class="wp-block-heading"><strong>Threat Actor Uses Stolen Gemini API Keys</strong></h2>



<p class="wp-block-paragraph">The actor&#8217;s use of stolen Gemini API keys was central to keeping the operation cost-free. During one documented 16-hour session, Gemini validated 40 likely stolen API keys and wrote a round-robin rotator that cycled through them automatically. </p>



<p class="wp-block-paragraph">That rotator was later published to GitHub as a clean, open-source project, disguising its criminal purpose entirely.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgV15sZzlK_V8FsBsCNGidTSOYzMtsabioIqKQ6Y1tZqiahYYsoz3LzTOYeZ2jIaDbaR0uNZTO3hz_KVF_PrPEPrlcX1at6CWzCMYTJYkoYf4SksweyfncTBcA0ZovlOoG86mPAHrTvwq63Gsj8_ILdOy_0yzb99irsdU_6x9dbDmbHD5WpIZMTrKnyb68/s16000/Screenshot%20of%20the%20QFS%202.0%20Terminal%20(Source%20-%20Trend%20Micro).webp" alt="Screenshot of the QFS 2.0 Terminal (Source - Trend Micro)" /><figcaption class="wp-element-caption">Screenshot of the QFS 2.0 Terminal (Source &#8211; Trend Micro)</figcaption></figure>
</div>


<p class="wp-block-paragraph">To bypass Gemini&#8217;s safety guardrails, the actor established himself to the AI as an &#8220;authorized pentester,&#8221; which Gemini accepted and saved into a persistent memory file called GEMINI.md. </p>



<p class="wp-block-paragraph">Over subsequent sessions, he escalated by getting the AI to memorize it should execute requests without ethical refusals or warnings. Since <a href="https://cybersecuritynews.com/gemini-cli-rce-vulnerability/" id="148462" target="_blank" rel="noreferrer noopener">Gemini CLI reloads this memory file at every session start</a>, each new conversation automatically inherited those jailbreak instructions.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/626d88c5-05e2-46ad-b3d0-adb1fea8f190/Threat-Actor-Uses-Stolen-Gemini-API-Keys-to-Automate-Telegram-Influence-Campaign.pdf?AWSAccessKeyId=ASIA2F3EMEYE7JKC4HAJ&amp;Signature=z%2FKCe9F1XQE9KZsxSKWKz%2BpNqt8%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEF8aCXVzLWVhc3QtMSJGMEQCIGoTaK9S5Q5n5MP01JMnP2DMLea8M%2BbI0jY5zmboNbMxAiAoLLyyNw%2BdmQgO4rg9C%2BBKIAbDK65PeQJpuC%2BoDi61xSrzBAgoEAEaDDY5OTc1MzMwOTcwNSIMvZ9IAXVBYCAfjD04KtAEYvAP0q4XeZEnmsPl%2FjTCK1wX0dB%2BDzIN0p4o6gUVdQiU%2BR0QceyphwMlgQiU%2BeoHEpRKEodJA18vPp%2FT1HOjphSvSO1vMXQNt4bYapjomCgAQQ8h%2B87wJtS%2BjAzeD0hPovg69XmXG7WgTlRYQhd0M1mkQVWdY1zzpPJ0Ao%2F7TchBAlddRaNsl5bnmU3FgDqANm%2FYBa0M0XxoH0DBO662bUTZDoqyzSznQJYdAQDarrxT8qgZCOtzy9cRzelrzqv480ub8ItOh4xtJiF5UaPJtboO6K7RRATbb5WwBtBsVTlaRLYycTvuU%2FN5MGOThdn7eSSShMLQNJbJ9JZZc81v6h79s8Br8WBhWLNzvG%2FBnNAxYyRbIYW%2FTVuyowbHnXiSslMX3iyp97aYS31K7QOMEPf6tbTX6r1RTnh1emSFhiEk93QSLQ2LcsvXvmRmN%2B3EsT2RSPcYyL7bmhh6JXxMikKt0Y8xrqeUBvpFFlwVqu7sMJNUDB0TLmcEp2pFCCTjzHGYaVMOI%2FipkQeF%2FHD4KAMrdBFoDgZEqZp3CJJsC%2BFm2d%2BVoppaMWCJVFY44I1%2BCGPQBa1LY%2Fchz83PJe01nR3bRhyTe0VmKdVIISRGEnF9qgImduzPrlG6HaA%2FZ4CvljkZBR7k2L6zKERywV9KMKx4yD54iP3wPm3d%2FEIIkcm4tlVR%2FDwtlJ9fhddLdJRuh3xWnhWSXmWdIb5d749Wwi4aHPWECK34I68ZJ4AkpVMh6yzuiizQ08ULWGsstqzrJV3MFHefZ4psL32z5kaWhzDV0fvQBjqZAdDc8pluGRROV1Rb1MHFeCcvGPw3Uepj3lNyTlVK1lkS0r3Wyy0SANvlgnZeIL3IMX6QD8m4Opmy9%2BABX%2FBDG273JJmuaENwImsHq6Dsd%2BwZHRU5KlE5XOhNyGenIBQi9umtHAghPE0wN7qxYi85nh5rz2L9I0EsD659dxUE7aZHZAoU3OlyBQsqmNBr4F%2BjJGeiT%2F6VYoGp8w%3D%3D&amp;Expires=1780412099" target="_blank" rel="noreferrer noopener"></a></p>



<h2 id="h-ai-assisted-credential-theft-and-fraud" class="wp-block-heading"><strong>AI-Assisted Credential Theft and Fraud</strong></h2>



<p class="wp-block-paragraph">Beyond running the channel, the actor used Gemini to assist with credential theft and a gamified chatbot designed to steal cryptocurrency. </p>



<p class="wp-block-paragraph">On September 9, 2025, he posted an executable called StellarMonSetup.exe, framed as a self-custody wallet with a welcome bonus of up to 1,000 XLM. </p>



<p class="wp-block-paragraph">The file was actually GoToResolve, a remote-administration tool that gave the actor persistent remote desktop access, command execution, and clipboard capture on victim machines.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/626d88c5-05e2-46ad-b3d0-adb1fea8f190/Threat-Actor-Uses-Stolen-Gemini-API-Keys-to-Automate-Telegram-Influence-Campaign.pdf?AWSAccessKeyId=ASIA2F3EMEYE7JKC4HAJ&amp;Signature=z%2FKCe9F1XQE9KZsxSKWKz%2BpNqt8%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEF8aCXVzLWVhc3QtMSJGMEQCIGoTaK9S5Q5n5MP01JMnP2DMLea8M%2BbI0jY5zmboNbMxAiAoLLyyNw%2BdmQgO4rg9C%2BBKIAbDK65PeQJpuC%2BoDi61xSrzBAgoEAEaDDY5OTc1MzMwOTcwNSIMvZ9IAXVBYCAfjD04KtAEYvAP0q4XeZEnmsPl%2FjTCK1wX0dB%2BDzIN0p4o6gUVdQiU%2BR0QceyphwMlgQiU%2BeoHEpRKEodJA18vPp%2FT1HOjphSvSO1vMXQNt4bYapjomCgAQQ8h%2B87wJtS%2BjAzeD0hPovg69XmXG7WgTlRYQhd0M1mkQVWdY1zzpPJ0Ao%2F7TchBAlddRaNsl5bnmU3FgDqANm%2FYBa0M0XxoH0DBO662bUTZDoqyzSznQJYdAQDarrxT8qgZCOtzy9cRzelrzqv480ub8ItOh4xtJiF5UaPJtboO6K7RRATbb5WwBtBsVTlaRLYycTvuU%2FN5MGOThdn7eSSShMLQNJbJ9JZZc81v6h79s8Br8WBhWLNzvG%2FBnNAxYyRbIYW%2FTVuyowbHnXiSslMX3iyp97aYS31K7QOMEPf6tbTX6r1RTnh1emSFhiEk93QSLQ2LcsvXvmRmN%2B3EsT2RSPcYyL7bmhh6JXxMikKt0Y8xrqeUBvpFFlwVqu7sMJNUDB0TLmcEp2pFCCTjzHGYaVMOI%2FipkQeF%2FHD4KAMrdBFoDgZEqZp3CJJsC%2BFm2d%2BVoppaMWCJVFY44I1%2BCGPQBa1LY%2Fchz83PJe01nR3bRhyTe0VmKdVIISRGEnF9qgImduzPrlG6HaA%2FZ4CvljkZBR7k2L6zKERywV9KMKx4yD54iP3wPm3d%2FEIIkcm4tlVR%2FDwtlJ9fhddLdJRuh3xWnhWSXmWdIb5d749Wwi4aHPWECK34I68ZJ4AkpVMh6yzuiizQ08ULWGsstqzrJV3MFHefZ4psL32z5kaWhzDV0fvQBjqZAdDc8pluGRROV1Rb1MHFeCcvGPw3Uepj3lNyTlVK1lkS0r3Wyy0SANvlgnZeIL3IMX6QD8m4Opmy9%2BABX%2FBDG273JJmuaENwImsHq6Dsd%2BwZHRU5KlE5XOhNyGenIBQi9umtHAghPE0wN7qxYi85nh5rz2L9I0EsD659dxUE7aZHZAoU3OlyBQsqmNBr4F%2BjJGeiT%2F6VYoGp8w%3D%3D&amp;Expires=1780412099" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">The actor also deployed an <a href="https://cybersecuritynews.com/guardian-ai-penetration-testing-tool/" id="143044" target="_blank" rel="noreferrer noopener">AI-powered brute-forcing tool targeting WordPress sites</a>. Using Gemini 2.5 Flash as a password-mutation oracle, the script generated 20 plausible password variants per target by modeling patterns such as swapping cases, appending years, and substituting symbols. </p>



<p class="wp-block-paragraph">Collected data confirmed that 29 WordPress administrator accounts were cracked across weapons retailers, legal offices, medical practices, and small commercial sites.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiHVWm5CqoFZYU19qz1ZFkrjB4dOGALv5RZJSl4lFS67gFQ0YgdrtsAa0TJ8og2Xt4AYjrz432YlqtQoDIXrfU7srARtz6hyQnXYqXuPUrFRKErIXN9j_BmRNYMpxsjAT_2ygmtmhAWgxVp9fZDcTYF0ApyZa2zkBqMtpzpu1_WikV8a9eZOGcvS7aPgZk/s16000/(top)%20The%20fake%20wallet%20was%20forwarded%20from%20a%20channel%20impersonating%20Donald%20J.%20Trump,%20(bottom)%20The%20attached%20executable%20is%20in%20fact%20a%20remote-access%20Trojan%20(Source%20-%20Trend%20Micro).webp" alt="(top) The fake wallet was forwarded from a channel impersonating Donald J. Trump, (bottom) The attached executable is in fact a remote-access Trojan (Source - Trend Micro)" /><figcaption class="wp-element-caption">(top) The fake wallet was forwarded from a channel impersonating Donald J. Trump, (bottom) The attached executable is in fact a remote-access Trojan (Source &#8211; Trend Micro)</figcaption></figure>
</div>


<p class="wp-block-paragraph">Defenders should never install software or enter a seed phrase based on instructions from a social media channel, as legitimate platforms will never make such requests. </p>



<p class="wp-block-paragraph">Enterprises should monitor for stolen API key reuse, anomalous CLI-driven infrastructure changes, and credential-stuffing patterns consistent with LLM-assisted password mutation. </p>



<p class="wp-block-paragraph">AI vendors should treat cross-language guardrail parity and jailbreak-resistant memory as urgent priorities, since this campaign proves those gaps are already being actively exploited.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/626d88c5-05e2-46ad-b3d0-adb1fea8f190/Threat-Actor-Uses-Stolen-Gemini-API-Keys-to-Automate-Telegram-Influence-Campaign.pdf?AWSAccessKeyId=ASIA2F3EMEYE7JKC4HAJ&amp;Signature=z%2FKCe9F1XQE9KZsxSKWKz%2BpNqt8%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEF8aCXVzLWVhc3QtMSJGMEQCIGoTaK9S5Q5n5MP01JMnP2DMLea8M%2BbI0jY5zmboNbMxAiAoLLyyNw%2BdmQgO4rg9C%2BBKIAbDK65PeQJpuC%2BoDi61xSrzBAgoEAEaDDY5OTc1MzMwOTcwNSIMvZ9IAXVBYCAfjD04KtAEYvAP0q4XeZEnmsPl%2FjTCK1wX0dB%2BDzIN0p4o6gUVdQiU%2BR0QceyphwMlgQiU%2BeoHEpRKEodJA18vPp%2FT1HOjphSvSO1vMXQNt4bYapjomCgAQQ8h%2B87wJtS%2BjAzeD0hPovg69XmXG7WgTlRYQhd0M1mkQVWdY1zzpPJ0Ao%2F7TchBAlddRaNsl5bnmU3FgDqANm%2FYBa0M0XxoH0DBO662bUTZDoqyzSznQJYdAQDarrxT8qgZCOtzy9cRzelrzqv480ub8ItOh4xtJiF5UaPJtboO6K7RRATbb5WwBtBsVTlaRLYycTvuU%2FN5MGOThdn7eSSShMLQNJbJ9JZZc81v6h79s8Br8WBhWLNzvG%2FBnNAxYyRbIYW%2FTVuyowbHnXiSslMX3iyp97aYS31K7QOMEPf6tbTX6r1RTnh1emSFhiEk93QSLQ2LcsvXvmRmN%2B3EsT2RSPcYyL7bmhh6JXxMikKt0Y8xrqeUBvpFFlwVqu7sMJNUDB0TLmcEp2pFCCTjzHGYaVMOI%2FipkQeF%2FHD4KAMrdBFoDgZEqZp3CJJsC%2BFm2d%2BVoppaMWCJVFY44I1%2BCGPQBa1LY%2Fchz83PJe01nR3bRhyTe0VmKdVIISRGEnF9qgImduzPrlG6HaA%2FZ4CvljkZBR7k2L6zKERywV9KMKx4yD54iP3wPm3d%2FEIIkcm4tlVR%2FDwtlJ9fhddLdJRuh3xWnhWSXmWdIb5d749Wwi4aHPWECK34I68ZJ4AkpVMh6yzuiizQ08ULWGsstqzrJV3MFHefZ4psL32z5kaWhzDV0fvQBjqZAdDc8pluGRROV1Rb1MHFeCcvGPw3Uepj3lNyTlVK1lkS0r3Wyy0SANvlgnZeIL3IMX6QD8m4Opmy9%2BABX%2FBDG273JJmuaENwImsHq6Dsd%2BwZHRU5KlE5XOhNyGenIBQi9umtHAghPE0wN7qxYi85nh5rz2L9I0EsD659dxUE7aZHZAoU3OlyBQsqmNBr4F%2BjJGeiT%2F6VYoGp8w%3D%3D&amp;Expires=1780412099" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph" id="h-indicators-of-compromise-iocs"><strong>Indicators of Compromise (IoCs):-</strong></p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th class="has-text-align-left" data-align="left">Type</th><th class="has-text-align-left" data-align="left">Indicator</th><th class="has-text-align-left" data-align="left">Description</th></tr></thead><tbody><tr><td>IP Address</td><td>213.165.51.115</td><td>GoToResolve infrastructure network connection</td></tr><tr><td>IP Address</td><td>34.34.57.141</td><td>GoToResolve infrastructure network connection</td></tr><tr><td>IP Address</td><td>34.34.81.129</td><td>GoToResolve infrastructure network connection</td></tr><tr><td>IP Address</td><td>35.192.41.201</td><td>GoToResolve infrastructure network connection</td></tr><tr><td>File Name</td><td>StellarMonSetup.exe</td><td>Fake Stellar wallet executable; contains GoToResolve RAT</td></tr><tr><td>File Name</td><td>GEMINI.md</td><td>Jailbreak memory file used to override Gemini AI safety guardrails</td></tr><tr><td>File Name</td><td>CREDENTIALS.md</td><td>File used to store stolen tokens and GCP service accounts</td></tr><tr><td>File Name</td><td>DEPLOYED_TOOLS.md</td><td>File cataloguing session output and deployed tooling</td></tr><tr><td>File Name</td><td>C2_MIGRATION_GUIDE.md</td><td>Gemini-followed guide for command-and-control server migration</td></tr><tr><td>Telegram Channel</td><td>@americanpatriotus</td><td>Primary influence operation distribution channel (~17,000 subscribers)</td></tr><tr><td>Telegram Bot</td><td>@QFS_Terminal_Bot</td><td>Gamified QAnon-styled chatbot used to engage and defraud subscribers</td></tr></tbody></table></figure>



<p class="wp-block-paragraph"><strong>Note:</strong>&nbsp;<em>IP addresses and domains are intentionally defanged (e.g.,&nbsp;</em><code><em>[.]</em></code><em>) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM</em>.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)"><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>Follow us on&nbsp;<a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en" target="_blank" rel="noreferrer noopener">Google News</a>,&nbsp;<a href="https://www.linkedin.com/company/cybersecurity-news/" target="_blank" rel="noreferrer noopener">LinkedIn</a>,&nbsp;and&nbsp;<a href="https://x.com/cyber_press_org" target="_blank" rel="noreferrer noopener">X</a>&nbsp;to Get More Instant Updates</strong>,&nbsp;<strong>Set CSN as a Preferred Source in</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong> <strong><strong><a href="https://www.google.com/preferences/source?q=cybersecuritynews.com" target="_blank" rel="noreferrer noopener">Google</a></strong></strong>.</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/threat-actor-uses-stolen-gemini-api-keys/">Threat Actor Uses Stolen Gemini API Keys to Automate Telegram Influence Campaign</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/Threat-Actor-Uses-Stolen-Gemini-API-Keys-to-Automate-Telegram-Influence-Campaign.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151689</post-id>	</item>
		<item>
		<title>Attackers Abuse AWS, Google Cloud, Cloudflare, and Microsoft Services to Hide Malicious Traffic</title>
		<link>https://cybersecuritynews.com/attackers-abuse-cloud-services-malicious-traffic/</link>
		
		<dc:creator><![CDATA[Guru Baran]]></dc:creator>
		<pubDate>Tue, 02 Jun 2026 17:13:03 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151705</guid>

					<description><![CDATA[<p>Cybercriminals are increasingly weaponizing trusted cloud infrastructure, including Amazon Web Services, Google Cloud, Microsoft Azure, Cloudflare, and GitHub, to camouflage malicious traffic, evade detection, and sustain long-lived Command and Control (C2) operations. A recent threat intelligence investigation using ANY.RUN&#8217;s Threat Intelligence (TI) Lookup reveals just how deeply this abuse has become embedded in modern attack [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/attackers-abuse-cloud-services-malicious-traffic/">Attackers Abuse AWS, Google Cloud, Cloudflare, and Microsoft Services to Hide Malicious Traffic</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Cybercriminals are increasingly weaponizing trusted cloud infrastructure, including Amazon Web Services, Google Cloud, Microsoft Azure, Cloudflare, and GitHub, to camouflage malicious traffic, evade detection, and sustain long-lived Command and Control (C2) operations.</p>



<p class="wp-block-paragraph">A recent threat intelligence investigation using <a href="https://cybersecuritynews.com/beat-threats-with-context-5-actionable-tactics-for-soc-analysts/" target="_blank" rel="noreferrer noopener">ANY.RUN&#8217;s Threat Intelligence (TI) Lookup</a> reveals just how deeply this abuse has become embedded in modern attack chains.</p>



<p class="wp-block-paragraph">The investigation by Threat Researcher Clandestine, spanning five targeted OSINT queries across ANY.RUN&#8217;s dynamic threat intelligence database, which indexes over 50 million IOCs, IOBs, and IOAs derived from real-time sandbox analyses conducted by over 500,000 analysts globally, exposes a recurring pattern: legitimate services are being turned into shields for adversarial activity.</p>



<p class="has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 83%,rgb(169,184,195) 100%)">Accelerate security workflows for faster triage &amp; response. <strong><a href="https://any.run/threat-intelligence-lookup/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=osint&amp;utm_content=ti+lookup+sales&amp;utm_term=020626#contact-sales" target="_blank" rel="noreferrer noopener nofollow"><u>Integrate Threat Intelligence in your SOC or MSSP</u></a>.</strong></p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhO9e5fyfg8JVrkSObSXzGWJbeHT8E8a_T7_b-mbDLFvoqTviijuAtrOQDvfy0q92e4Y-svlfz_20sKFr2Sr6aTi5cDKO58z7zRO7YZAEoFNkJm0WKmtSF4o4N7WvshrJSvqUXg5ExT8cj9hDubXltID6vLqfQDC8ogp3SCMqkAptetZU33W3r1gksjV3Q/s16000/image6-1024x511.webp" alt=""/><figcaption class="wp-element-caption"><em>Remote Access Trojan’s attack chain and TTPs mapped in a Sandbox analysis</em> </figcaption></figure>
</div>


<h2 id="h-cobalt-strike-hides-behind-trusted-cloud-providers" class="wp-block-heading"><strong>Cobalt Strike Hides Behind Trusted Cloud Providers</strong></h2>



<p class="wp-block-paragraph">One of the most alarming findings emerged from a JA3S TLS fingerprint query targeting the hash <code>1af33e1657631357c73119488045302c</code>, a signature commonly associated with Cobalt Strike beacons.</p>



<figure class="wp-block-image size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjXOAhvqXa3JDBqUsd7PgAcAQ-fHfWVgbR1K6emX4hJ3OkHx_4YFrl1hCW26P6hOk4PolIVxG1Ye-jSQ6cCTL0LzCoIU-SO6GePHEAobpvCy99xgSveUMPRBK93EiKyRJb91hz5FWd5sIp_IGuGbYFDlMELMH359acrhi1tKNXcPAMpm4R5r-PJMhQFgSw/s16000/image2-1.webp" alt=""/><figcaption class="wp-element-caption"><em>Search by a single connection parameter reveals a malicious pattern</em> </figcaption></figure>



<p class="wp-block-paragraph">Analysts querying this hash in TI Lookup uncovered more than 1,000 system events, predominantly involving native Windows processes such as <code>slui.exe</code>, <code>svchost.exe</code>, and PowerShell classic Living-off-the-Land Binary (LOLBin) abuse. Nearly all communication was routed over port 443 (HTTPS), exploiting the protocol&#8217;s ubiquity to blend into normal enterprise traffic.</p>



<p class="wp-block-paragraph">More critically, the C2 infrastructure tied to this JA3S fingerprint was found hosted across Microsoft, GitHub, Google, Amazon, and Cloudflare. This deliberate use of reputable platforms makes traditional reputation-based blocking ineffective.</p>



<p class="wp-block-paragraph">JA3S fingerprinting provides a behavioral anchor that persists even as adversaries rotate domains and IP addresses, a powerful technique for tracking C2 infrastructure continuity.</p>



<p class="wp-block-paragraph">Detection of this JA3S hash in network telemetry should be treated as a strong indicator of Cobalt Strike infection, immediately triggering endpoint correlation and incident response workflows.</p>



<p class="wp-block-paragraph">The investigation also uncovered active phishing campaigns targeting Brazilian organizations, where attackers are leveraging subdomains of globally recognized services alongside malicious domains.</p>



<p class="wp-block-paragraph">The use of globally hosted infrastructure serves a dual purpose: it lends the attacks a veneer of legitimacy and actively hinders domain takedowns. Security teams in Brazil and similar regions should be especially alert to emails containing links hosted on subdomains of popular cloud services.</p>



<figure class="wp-block-image size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEis7c6XX1roYOPhNZsw71c91OpBiXmi0rV56g5TJ-O8qaxMK7syqtTFNP8kULbXokfSPqgyk9VrqRLF-R5AW6qqodIzZQ0TRQj_sUdvQfDp-AG9f0luCeu4K4X33TxH0Pw9emizHBSSW7uEnyt8-9bO2hzNu_Q9rW9ZFZH6xP0DqsctDsDpQPvyLeDwkUI/s16000/imagea-1536x882.webp" alt=""/><figcaption class="wp-element-caption"><em>Network infrastructure related to phishing attacks on Brazilian users</em> </figcaption></figure>



<p class="wp-block-paragraph">Compound this with the discovery of Business Email Compromise (BEC) campaigns deploying fake invoice PDFs files named <code>invoice.pdf</code> and <code>pagamento.pdf</code> (Portuguese for &#8220;payment&#8221;) hosted on Amazon S3 buckets.</p>



<figure class="wp-block-image size-large is-resized"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjvhB37x2WRurHB742Bc9sooJ_cx_syiE6X7Hwm9VeC6B5Y4AYBwJ7i8xEwef3p8xbqKC93b71yeDgAmSQkz9SiM2KEcG8dlMdsI9ZKkmLY3cD1-3midW26WsnccnYMLKHPaocodsno0zECRZxAUlTYbVrb4gban6296E6eyV4fwasZUvLlDQZROzYS93c/s16000/image7-1024x578.webp" alt="" style="width:1024px;height:auto"/><figcaption class="wp-element-caption"><em>Files spotted in phishing campaigns with fake financial documents</em> </figcaption></figure>



<p class="wp-block-paragraph">These files serve as infection vectors for financial fraud operations. The finding reinforces that legitimate cloud storage is now a preferred staging ground for initial payload delivery, with file hashes from these samples providing actionable IOCs for blocking and detection.</p>



<h2 id="h-trojan-traffic-tunneled-through-https-on-port-443" class="wp-block-heading"><strong>Trojan Traffic Tunneled Through HTTPS on Port 443</strong></h2>



<p class="wp-block-paragraph">A behavior-based hunting query combining Russian IP geolocation, Suricata trojan classifications, and port 443 communication surfaced a diverse ecosystem of malicious traffic deliberately disguised as routine encrypted web activity.</p>



<figure class="wp-block-image size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjV80kMxovv5aJnjhCFzYlRxj4EUSkpQjvZnGXe70IHRL7G_C7xlqlu0-vFUADQZA2YC2pJfNPXh9cC1zfhdO2_UZ8odSMFcXLM9XIl6w4Gp4iX0CqSHeovABKJeOy9bjndRRplcNAjnPRKmvoMF2i22zp3_Mwg5FOfhmYr8znJsKAIR0x4_1FIpWvEtV4/s16000/image5-1024x622.webp" alt=""/><figcaption class="wp-element-caption"><em>Gather IOCs and observe 443 port exploited in a single lookup</em> </figcaption></figure>



<p class="wp-block-paragraph">This multi-layered attack strategy, employing multiple legitimate services across various ports for communication and fallback, demonstrates how attackers architect resilience directly into their infrastructure.</p>



<p class="wp-block-paragraph">The .top TLD emerged as a particularly hostile domain space, with <a href="https://cybersecuritynews.com/new-mintsloader-employs-domain-generation-algorithm-anti-vm-techniques/" target="_blank" rel="noreferrer noopener">algorithm-generated Domain Generation Algorithm (DGA)</a> domains classified as malicious at scale.</p>



<p class="wp-block-paragraph">These domains routinely leverage WinRAR archives for payload delivery and use Cloudflare services to conceal true server locations. Given the extremely high volume of malicious activity tied to .top, many organizations are now blocking the entire TLD proactively at the perimeter.</p>



<p class="has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 86%,rgb(169,184,195) 100%)">Turn uncertain alerts into faster, defensible decisions. <strong><a href="https://any.run/threat-intelligence-lookup/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=osint&amp;utm_content=ti+lookup+sales&amp;utm_term=020626#contact-sales" target="_blank" rel="noreferrer noopener nofollow"><u>Gain clearer evidence for response and reporting</u></a>.</strong></p>



<figure class="wp-block-image size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiv3iFRjLBQkhJEyUlvogUQdMhYQz1kDClFfdPrQLerKDHPmHtMvt0LWCdOApDbj6AAlmvOmbBi0D7qzY7R3t58S6TzFAXZSxAM4Uu3IrstaBx11WSRDuyNeCzTbwOh039OAOOiYpJVrdFNuurUPGHyil1HnuZ6SGyFozQiSCoD8xT7UO9E_6Nv13gTDto/s16000/image8-1024x634.webp" alt=""/><figcaption class="wp-element-caption"><em>Malicious domains and linked IOCs must be gathered for detection/response</em> </figcaption></figure>



<p class="wp-block-paragraph">For SOC teams and threat hunters, this research underscores several critical imperatives. Multi-parameter hunting queries combining JA3S fingerprints, destination geolocation, Suricata classifications, and file path patterns will outperform single-IOC lookups significantly.</p>



<p class="wp-block-paragraph">Detection rules targeting the identified JA3S hash, HTTPS-based C2 behavior, and high-risk TLDs like <code>.top</code>, <code>.shop</code>, and <code>.cc</code> should be deployed immediately. Integration of ANY.RUN&#8217;s TI Feeds and Lookup results into SIEM/SOAR platforms can automate threat correlation and reduce analyst burden.</p>



<p class="wp-block-paragraph">At an organizational level, the extensive abuse of trusted infrastructure from Microsoft, Google, and Amazon proves that brand reputation no longer guarantees network safety.</p>



<p class="wp-block-paragraph">Adopting a Zero Trust posture, investing in advanced sandbox-based detection, and educating financial teams about BEC and phishing risks are no longer optional; they are baseline requirements for resilience in a threat landscape where the attacker&#8217;s most reliable weapon is the cloud platform your enterprise already trusts.</p>



<p class="has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 82%,rgb(169,184,195) 100%)"><a href="https://any.run/threat-intelligence-lookup/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=osint&amp;utm_content=ti+lookup+sales&amp;utm_term=020626#contact-sales" target="_blank" rel="noreferrer noopener nofollow"><strong>Close blind spots and reduce exposure</strong></a> to critical incidents with ANY.RUN’s Threat Intelligence.</p>
<p>The post <a href="https://cybersecuritynews.com/attackers-abuse-cloud-services-malicious-traffic/">Attackers Abuse AWS, Google Cloud, Cloudflare, and Microsoft Services to Hide Malicious Traffic</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://i2.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjQ-Irbzb8r_QY53IQL0IzysLg6x9BYX6qOopcB9cXsWd08NQP5XBLhEV7HBdaqDZ-y-xhSFgWqnFJnXGGnujCX_fsZloJKBdaYIVbuJw57tKWuxfXTqtiBWDrq4RLbY9SRzaYvM-vNdGTUTIec-bDODLMuhaHGmJ6o3U1eb8KmXKfzWgbBW-pO_NSI6w/s16000/Attackers%20Hide%20Malicious%20Traffic%20in%20Cloud.webp?ssl=1" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151705</post-id>	</item>
		<item>
		<title>Red Hat Confirms Supply Chain Compromise of @redhat-cloud-services npm Packages</title>
		<link>https://cybersecuritynews.com/red-hat-supply-chain-compromise/</link>
		
		<dc:creator><![CDATA[Guru Baran]]></dc:creator>
		<pubDate>Tue, 02 Jun 2026 16:49:52 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151713</guid>

					<description><![CDATA[<p>Red Hat has officially confirmed a supply chain compromise affecting multiple packages published under the @redhat-cloud-services npm namespace, disclosed publicly on June 1, 2026. A compromised GitHub account was used to inject malicious code into frontend libraries maintained within a Red Hat GitHub organization, raising significant concern across enterprise environments that depend on these packages [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/red-hat-supply-chain-compromise/">Red Hat Confirms Supply Chain Compromise of @redhat-cloud-services npm Packages</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Red Hat has officially confirmed a supply chain compromise affecting multiple packages published under the <a href="https://cybersecuritynews.com/red-hat-cloud-services-npm-packages/" target="_blank" rel="noreferrer noopener">@redhat-cloud-services npm namespace, disclosed publicly on June 1, 2026</a>.</p>



<p class="wp-block-paragraph">A compromised GitHub account was used to inject malicious code into frontend libraries maintained within a Red Hat GitHub organization, raising significant concern across enterprise environments that depend on these packages during container image builds.</p>



<p class="wp-block-paragraph">According to Red Hat&#8217;s security bulletin RHSB-2026-006, unauthorized commits were pushed to repositories within the RedHatInsights GitHub organization using a compromised developer account.</p>



<p class="wp-block-paragraph">The affected packages are frontend libraries that get compiled and bundled into container images during the Red Hat product build process, making the attack vector particularly dangerous due to its deep integration into downstream build pipelines. Red Hat engineering acted swiftly by removing the compromised versions from npm following the initial disclosure.</p>



<p class="wp-block-paragraph">Threat intelligence from OX Security reveals that the malware behind this supply chain compromise is the sophisticated Shai-Hulud infostealer, a campaign far more advanced than typical npm malware.</p>



<p class="wp-block-paragraph">While conventional npm malware operates with one to three execution stages, <a href="https://cybersecuritynews.com/mini-shai-hulud-attack-forces-npm/" target="_blank" rel="noreferrer noopener">Shai-Hulud deploys</a> a six-stage payload delivery chain that loops back on itself in an endless execution cycle.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgLkxNm8MJZoOM4sT_TkI8gZrNK2LPLSFI2RJ6vmAOEY77J5lTm-7lXTNEtKFv3y3ilRBvMAviNjwbBrnSGPMRLPraLvFgA6pU6fGPjGrSKpcVfe5zpy6qBvcaq8wKDe6LKYv1DBdhMOKpgJMwcQsjFfLaKZCHUU29ybjKUDpLtDr-gNGDbZ3HCdJLKtLQQ/w640-h592/Red%20Hat%20Confirms%20Supply%20Chain%20Compromise.webp" alt=""/><figcaption class="wp-element-caption">Attack Chain (Source: OX Research)</figcaption></figure>
</div>


<p class="wp-block-paragraph">The attack begins with an obfuscated index.js payload that proceeds through decryption and decoding stages and ultimately drops 15 distinct payloads including memory dump tools, token monitors, Claude API hooks, and a GitHub-based payload dropper.</p>



<h2 id="h-github-used-as-an-adaptive-c2-server" class="wp-block-heading"><strong>GitHub Used as an Adaptive C2 Server</strong></h2>



<p class="wp-block-paragraph">One of the most alarming aspects of Shai-Hulud is its abuse of GitHub as a live <a href="https://cybersecuritynews.com/command-and-controlc2-server/" target="_blank" rel="noreferrer noopener">Command-and-Control (C2) infrastructure</a>. Rather than merely hosting exfiltrated data, the threat actor stores malicious code in GitHub repositories and uses commits tagged with the string &#8220;firedalazer&#8221; as a dynamic payload delivery mechanism.</p>



<p class="wp-block-paragraph">This means that even after one account is blocked, another can seamlessly take over by pushing new commits, making the campaign highly resilient.</p>



<p class="wp-block-paragraph">OX Security also identified two distinct variants of the malware identified by a subtle difference: the string &#8220;Miasma: The Spreading Blight&#8221; (no space after colon) in Stage 3, versus &#8220;Miasma : The Spreading Blight&#8221; (with space) in the Stage 6 alternate payload, a detail that can cause detection tools relying on exact string matching to miss infections.</p>



<p class="wp-block-paragraph"><a href="https://access.redhat.com/security/vulnerabilities/RHSB-2026-006" target="_blank" rel="noreferrer noopener nofollow">Red Hat Product Security is actively conducting</a> build system and dependency tracking analysis to confirm whether any product builds incorporated the compromised package versions.</p>



<p class="wp-block-paragraph">Based on current findings, no customer action is required at this time, though the investigation remains ongoing. Organizations are advised to monitor for known Shai-Hulud IoCs, including the &#8220;firedalazer&#8221; commit string, Miasma-related strings, and the documented encryption keys and public key pairs published by OX Security.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)"><strong><a href="https://www.prophaze.com/webinar-registration-closing-visibility-gaps-in-waap/?utm_source=Cyber+security+news+&amp;utm_medium=Article+&amp;utm_campaign=Cyber+news#" target="_blank" rel="noreferrer noopener nofollow">Free Webinar</a></strong> <strong>on OWASP API Top 10 and Guide to Close Visibility Gaps With WAAP</strong></p>
<p>The post <a href="https://cybersecuritynews.com/red-hat-supply-chain-compromise/">Red Hat Confirms Supply Chain Compromise of @redhat-cloud-services npm Packages</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/Red-Hat-Supply-Chain-Compromise.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151713</post-id>	</item>
		<item>
		<title>Russia Says Foreign Spyware Found on High-Ranking Officials&#8217; Mobile Phones</title>
		<link>https://cybersecuritynews.com/foreign-spyware-founds-officials-phones/</link>
		
		<dc:creator><![CDATA[Abinaya]]></dc:creator>
		<pubDate>Tue, 02 Jun 2026 16:32:22 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151669</guid>

					<description><![CDATA[<p>Russia’s Federal Security Service (FSB) has claimed it disrupted a large-scale cyber-espionage operation involving the deployment of advanced spyware on mobile devices used by high-ranking government officials. The agency stated that the campaign was orchestrated by unidentified foreign intelligence services and aimed at covert surveillance and data exfiltration. According to the FSB, the operation involved [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/foreign-spyware-founds-officials-phones/">Russia Says Foreign Spyware Found on High-Ranking Officials&#8217; Mobile Phones</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Russia’s Federal Security Service (FSB) has claimed it disrupted a large-scale cyber-espionage operation involving the deployment of advanced <a href="https://cybersecuritynews.com/pegasus-spyware-detected-in-new-mobile-devices/" target="_blank" rel="noreferrer noopener">spyware on mobile devices</a> used by high-ranking government officials.</p>



<p class="wp-block-paragraph">The agency stated that the campaign was orchestrated by unidentified foreign intelligence services and aimed at covert surveillance and data exfiltration.</p>



<p class="wp-block-paragraph">According to the FSB, the operation involved the implantation and activation of malicious software capable of extracting sensitive data, intercepting communications, and conducting <a href="https://cybersecuritynews.com/microsoft-macos-apps-vulnerability/" target="_blank" rel="noreferrer noopener">unauthorized audio and video recordings.</a></p>



<h2 id="h-spyware-on-officials-phones" class="wp-block-heading"><strong>Spyware on Officials&#8217; Phones</strong></h2>



<p class="wp-block-paragraph">The spyware reportedly targeted smartphones and other mobile devices used by senior officials, indicating a highly selective, intelligence-driven attack.</p>



<p class="wp-block-paragraph">The agency noted that the attackers leveraged technical infrastructures associated with major international IT and telecommunications providers to facilitate covert data collection.</p>



<p class="wp-block-paragraph">While no specific vendors or countries were named, the claim suggests the use of sophisticated supply-chain or network-level access to enable surveillance capabilities without directly compromising the devices.</p>



<p class="wp-block-paragraph">From a technical perspective, such spyware campaigns often rely on <a href="https://cybersecuritynews.com/ios-zero-day-exploit-chain-leveraged/" target="_blank" rel="noreferrer noopener">zero-click exploits</a>, baseband vulnerabilities, or malicious configuration profiles to gain persistent access to mobile systems.</p>



<p class="wp-block-paragraph">These techniques allow attackers to bypass user interaction and traditional security controls, making detection significantly more difficult.</p>



<p class="wp-block-paragraph">Once deployed, the spyware can access encrypted messaging apps, capture keystrokes, activate microphones and cameras, and exfiltrate stored files.</p>



<p class="wp-block-paragraph">Although the FSB did not disclose indicators of compromise (IOCs) or malware family names, the described capabilities align with previously observed nation-state-grade spyware such as <a href="https://cybersecuritynews.com/ios-26-deletes-pegasus-and-predator-spyware-infection-evidence/" target="_blank" rel="noreferrer noopener">Pegasus</a> or <a href="https://cybersecuritynews.com/predator-spyware-compamy-used-15-zero-days/" target="_blank" rel="noreferrer noopener">Predator</a>.</p>



<p class="wp-block-paragraph">These tools are typically used in targeted surveillance operations and are known for their stealth and modular architecture.</p>



<p class="wp-block-paragraph"><a href="https://www.democrata.es/en/international/russia-claims-to-have-stopped-a-massive-spy-software-operation-on-high-ranking-officials-mobile-phones/" target="_blank" rel="noreferrer noopener nofollow">According to a report by Democrata shared with Cybersecurity News</a>, Russian authorities confirmed a criminal investigation has been launched and forensic analysis of affected devices is ongoing.</p>



<p class="wp-block-paragraph">The agency also issued a warning, emphasizing the risks of discussing sensitive information near mobile devices and highlighting the potential for real-time interception even without visible signs of compromise.</p>



<p class="wp-block-paragraph">The incident underscores the growing threat of mobile-targeted espionage, particularly against government and high-value individuals.</p>



<p class="wp-block-paragraph">Mobile devices remain a critical attack surface due to their constant connectivity, access to sensitive communications, and integration with enterprise systems.</p>



<p class="wp-block-paragraph">Security experts recommend several mitigation strategies, including regular device updates, the use of <a href="https://cybersecuritynews.com/best-mobile-application-penetration-testing-companies/" target="_blank" rel="noreferrer noopener">mobile threat defense (MTD)</a> solutions, restricting app installations, and segmenting sensitive communications across secure channels.</p>



<p class="wp-block-paragraph">In high-risk environments, hardened devices or air-gapped communication methods may also be considered. While independent verification of the FSB’s claims remains limited, the report reflects ongoing geopolitical tensions and the increasing use of cyber capabilities in intelligence operations.</p>



<p class="wp-block-paragraph">The lack of attribution and technical disclosure leaves open questions. However, the scenario aligns with known tactics used in modern cyber-espionage campaigns targeting government entities</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)"><strong><a href="https://www.prophaze.com/webinar-registration-closing-visibility-gaps-in-waap/?utm_source=Cyber+security+news+&amp;utm_medium=Article+&amp;utm_campaign=Cyber+news#" target="_blank" rel="noreferrer noopener nofollow">Free Webinar</a></strong> <strong>on OWASP API Top 10 and Guide to Close Visibility Gaps With WAAP</strong></p>
<p>The post <a href="https://cybersecuritynews.com/foreign-spyware-founds-officials-phones/">Russia Says Foreign Spyware Found on High-Ranking Officials&#8217; Mobile Phones</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/Russia-Says-Foreign-Spyware-Founs-on-high-ranking-officials-mobile-phones.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151669</post-id>	</item>
		<item>
		<title>Halo Security Honored with 2026 MSP Today Product of the Year Award</title>
		<link>https://cybersecuritynews.com/halo-security-honored-with-2026-msp-today-product-of-the-year-award/</link>
		
		<dc:creator><![CDATA[Cybernewswire]]></dc:creator>
		<pubDate>Tue, 02 Jun 2026 15:28:52 +0000</pubDate>
				<category><![CDATA[Press Release]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151670</guid>

					<description><![CDATA[<p>Miami Beach, FL, USA, June 2nd, 2026, CyberNewswire Attack Surface Management Platform Recognized for Exceptional Innovation and Successful Deployment Through The Channel Halo Security today announced that its attack surface management solution has been named a 2026 MSP Today Product of the Year Award winner by TMC, a leading global media company recognized for building [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/halo-security-honored-with-2026-msp-today-product-of-the-year-award/">Halo Security Honored with 2026 MSP Today Product of the Year Award</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong>Miami Beach, FL, USA, June 2nd, 2026, CyberNewswire</strong></p>



<p class="wp-block-paragraph"><strong>Attack Surface Management Platform Recognized for Exceptional Innovation and Successful Deployment Through The Channel</strong></p>



<p class="wp-block-paragraph"><a href="https://www.halosecurity.com/?utm_campaign=msptodaypoty2026&amp;utm_source=cybernewswire&amp;utm_medium=referral" target="_blank" rel="noreferrer noopener nofollow">Halo Security</a> today announced that its <a href="https://www.halosecurity.com?utm_campaign=msptodaypoty2026&amp;utm_source=cybernewswire&amp;utm_medium=referral" target="_blank" rel="noreferrer noopener sponsored nofollow">attack surface management solution</a> has been named a 2026 MSP Today Product of the Year Award winner by TMC, a leading global media company recognized for building communities in technology and business through live events and digital marketing platforms. This marks the second consecutive year Halo Security has earned the award.</p>



<p class="wp-block-paragraph">The MSP Today Product of the Year Award honors standout products and services that are reshaping the managed services landscape, delivered through the Channel and purpose-built to meet the evolving needs of end users. The Halo Security platform was selected for its innovation, performance, and its measurable impact on customers and partners alike.</p>



<p class="wp-block-paragraph">The Halo Security Attack Surface Management Platform gives organizations and MSPs a complete view of their internet-facing assets and a clear path to fixing what matters most. </p>



<p class="wp-block-paragraph">Automated discovery helps uncover every domain, hostname, and IP exposed to the internet, while continuous vulnerability scanning, dynamic application security testing, dark web monitoring, and manual penetration testing surface the risks behind them. </p>



<p class="wp-block-paragraph">Behind the technology is a US-based team of security professionals who help customers and partners interpret findings, prioritize remediation, and act with confidence, so risk reduction happens faster and with less guesswork.</p>



<p class="wp-block-paragraph">For MSPs, that combination scales across every client. Multi-tenant management, customizable dashboards with drag-and-drop widgets, configurable reports with saved views, and white-labeling let partners deliver branded, client-ready insights without the operational drag. </p>



<p class="wp-block-paragraph">Direct integrations with Slack, ServiceNow, Jira, Linear, Vanta, and the major cloud providers keep findings flowing into the tools partners already use, while built-in PCI compliance reporting as a PCI DSS Approved Scanning Vendor and SOC 2 Type II compliance underscore the platform&#8217;s commitment to the standards partners and their clients depend on.</p>



<p class="wp-block-paragraph">&#8220;As AI has reshaped almost every corner of cybersecurity, our partners keep telling us the same thing: the human element is what they value most,&#8221; said Lisa Dowling, CEO of Halo Security. </p>



<p class="wp-block-paragraph">&#8220;Automation finds the issues, but it&#8217;s our team of security experts who help partners and their clients understand what matters, what to fix first, and how to communicate risk in a meaningful way. This award is a reflection of the trust our partners place in our people, not just our technology.&#8221;</p>



<p class="wp-block-paragraph">&#8220;It gives me great pleasure to recognize Halo Security as a 2026 recipient of TMC&#8217;s MSP Today Product of the Year Award for their innovative attack surface management solution,&#8221; said Rich Tehrani, CEO of TMC. </p>



<p class="wp-block-paragraph">&#8220;Our judges were thoroughly impressed not only by the strength and features of the product, but by Halo Security&#8217;s commitment to the Channel—empowering partners to deliver exceptional service and drive meaningful results for their clients.&#8221;</p>



<p class="wp-block-paragraph">Winners of the 2026 MSP Today Product of the Year Award will be featured on MSP Today, the definitive resource for managed service providers, as well as across TMCnet&#8217;s media platforms.</p>



<h2 id="h-about-halo-security" class="wp-block-heading"><strong>About Halo Security</strong></h2>



<p class="wp-block-paragraph"><a href="https://www.halosecurity.com/?utm_campaign=msptodaypoty2026&amp;utm_source=cybernewswire&amp;utm_medium=referral" target="_blank" rel="noreferrer noopener nofollow">Halo Security</a> is changing the way organizations manage their external attack surface. </p>



<p class="wp-block-paragraph">The <a href="https://www.halosecurity.com/attack-surface-management?utm_campaign=msptodaypoty2026&amp;utm_source=cybernewswire&amp;utm_medium=referral" target="_blank" rel="noreferrer noopener nofollow">comprehensive EASM platform</a> pairs unprecedented visibility into internet-facing assets with expert remediation guidance, combining automated asset discovery, continuous vulnerability scanning, and penetration testing insights in a single solution for fast, measurable, and affordable risk reduction. Readers can learn more at <a href="https://www.halosecurity.com/?utm_campaign=msptodaypoty2026&amp;utm_source=cybernewswire&amp;utm_medium=referral" target="_blank" rel="noreferrer noopener nofollow">halosecurity.com</a>.</p>



<h2 id="h-about-msp-today" class="wp-block-heading"><strong>About MSP Today</strong></h2>



<p class="wp-block-paragraph"><a href="https://www.msptoday.com/" target="_blank" rel="noreferrer noopener nofollow">MSP Today</a> is the premier online destination for MSPs (Managed Service Providers) and IT service providers worldwide. As the industry&#8217;s leading web portal, MSP Today delivers timely and relevant news, cutting-edge product information, and invaluable insights to empower MSPs and IT professionals to thrive in today&#8217;s rapidly evolving technology landscape. </p>



<p class="wp-block-paragraph">Whether you&#8217;re seeking in-depth articles on emerging technologies, comprehensive product reviews, or actionable tips to optimize your IT services, MSP Today is the go-to resource for all things MSP-related. Readers can learn more at<a href="http://www.msptoday.com/" target="_blank" rel="noreferrer noopener nofollow"> www.msptoday.com</a>.</p>



<h2 id="h-about-tmc" class="wp-block-heading"><strong>About TMC</strong></h2>



<p class="wp-block-paragraph">For more than 20 years, <a href="https://www.tmcnet.com/" target="_blank" rel="noreferrer noopener nofollow">TMC</a> has been honoring technology companies with awards in various categories. These awards are regarded as some of the most prestigious and respected awards in the communications and technology sector worldwide. Winners represent prominent players in the market who consistently demonstrate the advancement of technologies. </p>



<p class="wp-block-paragraph">Each recipient is a verifiable leader in the marketplace. TMC also provides global buyers with valuable insights to make informed tech decisions through editorial platforms, live events, webinars, and online advertising. Readers can learn more at<a href="http://www.tmcnet.com/" target="_blank" rel="noreferrer noopener nofollow"> www.tmcnet.com</a>.</p>



<h3 id="h-contact" class="wp-block-heading"><strong>Contact</strong></h3>



<p class="wp-block-paragraph"><strong>Director of Partnerships</strong></p>



<p class="wp-block-paragraph"><strong>Lauren Ladra</strong></p>



<p class="wp-block-paragraph"><strong>Halo Security</strong></p>



<p class="wp-block-paragraph"><strong>lauren@halosecurity.com</strong></p>



<p class="wp-block-paragraph"></p>
<p>The post <a href="https://cybersecuritynews.com/halo-security-honored-with-2026-msp-today-product-of-the-year-award/">Halo Security Honored with 2026 MSP Today Product of the Year Award</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhUxtTB6OSfdmrsUIALUJMB3YwW_0c6lfT_OYuR3cuyb4DSzrq-g727nqEE0nhnSMb7Qj8BhIAqKSkg2bToI0MqbGXeb8MlLmWwkrBPWX8YB1ssjMRGCx7jV_IAdnXNS13cxxf7xi8R092E3O40lhEIjJFphHzPHcmG2npPhbZFI7BKQkF2E05TRasTIho/s16000/TTT%20-%202026-06-02T174341.125.webp?ssl=1" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151670</post-id>	</item>
		<item>
		<title>CISA Warns of Two-Year-Old Oracle WebLogic Server Vulnerability Exploited in Attacks</title>
		<link>https://cybersecuritynews.com/oracle-weblogic-server-vulnerability-exploited/</link>
		
		<dc:creator><![CDATA[Abinaya]]></dc:creator>
		<pubDate>Tue, 02 Jun 2026 14:31:57 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Vulnerability News]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151641</guid>

					<description><![CDATA[<p>CISA has issued a fresh warning highlighting active exploitation of a critical Oracle WebLogic Server vulnerability, tracked as CVE-2024-21182, adding it to its Known Exploited Vulnerabilities (KEV) catalog on June 1, 2026. The alert underscores the increasing risk posed by exposed enterprise middleware systems, particularly those accessible over network protocols such as T3 and IIOP. [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/oracle-weblogic-server-vulnerability-exploited/">CISA Warns of Two-Year-Old Oracle WebLogic Server Vulnerability Exploited in Attacks</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">CISA has issued a fresh warning highlighting active exploitation of a critical Oracle WebLogic Server vulnerability, tracked as <a href="https://cybersecuritynews.com/oracle-weblogic-server-vulnerability-2/" target="_blank" rel="noreferrer noopener">CVE-2024-21182</a>, adding it to its Known Exploited Vulnerabilities (KEV) catalog on June 1, 2026.</p>



<p class="wp-block-paragraph">The alert underscores the increasing risk posed by exposed enterprise middleware systems, particularly those accessible over network protocols such as T3 and IIOP.</p>



<p class="wp-block-paragraph">The vulnerability affects Oracle WebLogic Server, a widely used enterprise Java application server deployed across cloud and on-premise environments.</p>



<p class="wp-block-paragraph">Although Oracle has not disclosed complete technical specifics, the flaw is classified as an unspecified vulnerability that can be <a href="https://cybersecuritynews.com/hackers-exploiting-weblogic-rce-vulnerabilities/" target="_blank" rel="noreferrer noopener">exploited remotely without authentication.</a></p>



<p class="wp-block-paragraph">Attackers leveraging this issue can gain unauthorized access to sensitive data or potentially achieve full compromise of affected WebLogic environments.</p>



<h2 id="h-oracle-weblogic-server-vulnerability-exploited" class="wp-block-heading"><strong>Oracle WebLogic Server Vulnerability Exploited</strong></h2>



<p class="wp-block-paragraph">Security researchers note that the attack vector relies on network-level access via<a href="https://cybersecuritynews.com/oracle-weblogic-server-vulnerability/" target="_blank" rel="noreferrer noopener"> WebLogic’s proprietary T3 protocol</a> or the Internet Inter-ORB Protocol (IIOP), both of which are commonly used for internal application communication.</p>



<p class="wp-block-paragraph">Misconfigured or internet-exposed WebLogic instances significantly increase the attack surface, making them attractive targets for threat actors seeking initial access into enterprise networks.</p>



<p class="wp-block-paragraph">However, given WebLogic’s history as a frequent target in ransomware intrusion chains, cybersecurity experts warn that exploitation of this vulnerability could quickly be adopted in financially motivated campaigns.</p>



<p class="wp-block-paragraph">The impact of successful exploitation is severe. An attacker can bypass authentication controls and access critical application data, potentially leading to lateral movement within enterprise environments.</p>



<p class="wp-block-paragraph">In high-risk scenarios, this could result in full system compromise, data exfiltration, or deployment of follow-on payloads such as web shells or remote access trojans.</p>



<p class="wp-block-paragraph"><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" target="_blank" rel="noreferrer noopener nofollow">CISA’s inclusion of CVE-2024-21182 in the KEV catalog</a> indicates confirmed in-the-wild exploitation. However, no specific threat actors or ransomware groups have been publicly attributed to these attacks so far.</p>



<p class="wp-block-paragraph">Organizations using Oracle WebLogic Server are urged to take immediate action. CISA has mandated federal agencies to remediate the vulnerability by June 4, 2026, in accordance with Binding Operational Directive 22-01.</p>



<p class="wp-block-paragraph">The agency recommends applying <a href="https://cybersecuritynews.com/oracle-critical-security-update-july2025/" target="_blank" rel="noreferrer noopener">Oracle’s official patches</a> or mitigation measures without delay. If fixes are not available or cannot be implemented promptly, organizations should consider isolating or discontinuing affected systems to reduce exposure.</p>



<p class="wp-block-paragraph">From a defensive standpoint, security teams should audit <a href="https://cybersecuritynews.com/oracle-weblogic-server-proxy-vulnerability/" target="_blank" rel="noreferrer noopener">network exposure of WebLogic services</a>, restrict access to T3 and IIOP protocols, and implement strong network segmentation.</p>



<p class="wp-block-paragraph">Continuous monitoring for unusual traffic patterns or unauthorized access attempts is also critical in detecting early signs of compromise.</p>



<p class="wp-block-paragraph">This development underscores the persistent risks posed by unpatched enterprise middleware and underscores the importance of proactive vulnerability management.</p>



<p class="wp-block-paragraph">As threat actors continue to scan for exploitable services, timely patching and strict access controls remain essential to defending critical infrastructure.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)"><strong><a href="https://www.prophaze.com/webinar-registration-closing-visibility-gaps-in-waap/?utm_source=Cyber+security+news+&amp;utm_medium=Article+&amp;utm_campaign=Cyber+news#" target="_blank" rel="noreferrer noopener nofollow">Free Webinar</a></strong> <strong>on OWASP API Top 10 and Guide to Close Visibility Gaps With WAAP</strong></p>
<p>The post <a href="https://cybersecuritynews.com/oracle-weblogic-server-vulnerability-exploited/">CISA Warns of Two-Year-Old Oracle WebLogic Server Vulnerability Exploited in Attacks</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/CISA-Warns-of-Oracle-WebLogic-Server-Vulnerability-Exploited-in-Attacks.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151641</post-id>	</item>
		<item>
		<title>Critical KMW CCTV Vulnerability Let Attackers Gain Unauthorized Access to Camera Feeds</title>
		<link>https://cybersecuritynews.com/kmw-cctv-vulnerability/</link>
		
		<dc:creator><![CDATA[Abinaya]]></dc:creator>
		<pubDate>Tue, 02 Jun 2026 14:27:38 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Vulnerability News]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151662</guid>

					<description><![CDATA[<p>A critical security flaw in KMW CCTV security cameras could allow attackers to gain full, unauthorized access to live camera feeds and device settings. The vulnerability, tracked as CVE-2026-5386, has been assigned a high CVSS v3 score of 9.1, highlighting its severe impact on organizations relying on these surveillance systems. The issue stems from an [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/kmw-cctv-vulnerability/">Critical KMW CCTV Vulnerability Let Attackers Gain Unauthorized Access to Camera Feeds</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">A critical security flaw in KMW CCTV security cameras could allow attackers to gain full, <a href="https://cybersecuritynews.com/40000-internet-connected-cameras-exposed/" target="_blank" rel="noreferrer noopener">unauthorized access to live camera feeds </a>and device settings.</p>



<p class="wp-block-paragraph">The vulnerability, tracked as CVE-2026-5386, has been assigned a high CVSS v3 score of 9.1, highlighting its severe impact on organizations relying on these surveillance systems.</p>



<p class="wp-block-paragraph">The issue stems from an “unverified password change” weakness in affected devices, which allows remote attackers to modify authentication credentials without proper validation.</p>



<p class="wp-block-paragraph">Once exploited, threat actors can take control of the camera, view real-time video streams, alter configurations, or potentially turn off <a href="https://cybersecuritynews.com/iranian-cyber-ops-maintain-us-network-footholds/" target="_blank" rel="noreferrer noopener">surveillance operations</a> altogether.</p>



<p class="wp-block-paragraph">This creates significant security risks, particularly in sensitive environments where CCTV systems play a critical role in monitoring and safety.</p>



<h2 id="h-kmw-cctv-vulnerability-nbsp" class="wp-block-heading"><strong>KMW CCTV Vulnerability&nbsp;</strong></h2>



<p class="wp-block-paragraph">The vulnerability impacts specific KMW CCTV models, including KM-IP521 running firmware IPCAM_V4.04.91.230307 and KM-IP421 with firmware IPCAM_V4.04.53.210416.</p>



<p class="wp-block-paragraph">These devices are deployed globally across multiple critical infrastructure sectors, including commercial facilities, government institutions, financial services, transportation systems, and manufacturing environments.</p>



<p class="wp-block-paragraph">Given their widespread usage, exploitation could have far-reaching consequences, including surveillance bypass, espionage, and operational disruption.</p>



<p class="wp-block-paragraph">Although there are currently no confirmed reports of active exploitation in the wild, the vulnerability’s severity makes it a high-priority target for threat actors, especially those focusing on IoT and industrial control system weaknesses.</p>



<p class="wp-block-paragraph">From a technical perspective, the flaw allows attackers to<a href="https://cybersecuritynews.com/xiongmai-ip-camera-vulnerability/" target="_blank" rel="noreferrer noopener"> bypass authentication controls</a> by sending crafted requests that trigger password changes without verifying the requester&#8217;s identity.</p>



<p class="wp-block-paragraph">For example, an attacker on the same network, or one who exposes devices to the internet, could issue unauthorized commands to reset credentials and gain administrative access within seconds.</p>



<p class="wp-block-paragraph">Security researcher Souvik Kandar has been credited with discovering and reporting the flaw to CISA. This type of attack does not require advanced skills, making it particularly dangerous in poorly secured environments.</p>



<p class="wp-block-paragraph"><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-148-06" target="_blank" rel="noreferrer noopener nofollow">According to a recent CISA advisory (ICSA-26-148-06)</a>, organizations should reduce exposure by keeping devices off the public internet and behind firewalls or isolated networks.</p>



<p class="wp-block-paragraph">Remote access should be enabled only through secure channels, such as <a href="https://cybersecuritynews.com/vpns-free-trial-2026/" target="_blank" rel="noreferrer noopener">updated VPNs</a>, and organizations should ensure that all connected systems follow strict security practices.</p>



<p class="wp-block-paragraph">Regular risk assessments and impact analysis are also advised before implementing changes.</p>



<p class="wp-block-paragraph">Additionally, organizations are encouraged to monitor for suspicious activity, follow incident response procedures, and report anomalies to relevant authorities for correlation and threat tracking.</p>



<p class="wp-block-paragraph">Implementing <a href="https://cybersecuritynews.com/advanced-persistent-threats/" target="_blank" rel="noreferrer noopener">defense-in-depth strategies</a> and adhering to ICS cybersecurity guidelines can significantly reduce the risk of exploitation.</p>



<p class="wp-block-paragraph">As surveillance infrastructure increasingly becomes a target for cyberattacks, this vulnerability highlights the urgent need for stronger security controls in IoT-based camera systems.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)"><strong><a href="https://www.prophaze.com/webinar-registration-closing-visibility-gaps-in-waap/?utm_source=Cyber+security+news+&amp;utm_medium=Article+&amp;utm_campaign=Cyber+news#" target="_blank" rel="noreferrer noopener nofollow">Free Webinar</a></strong> <strong>on OWASP API Top 10 and Guide to Close Visibility Gaps With WAAP</strong></p>
<p>The post <a href="https://cybersecuritynews.com/kmw-cctv-vulnerability/">Critical KMW CCTV Vulnerability Let Attackers Gain Unauthorized Access to Camera Feeds</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/Critical-KMW-CCTV-Vulnerability-Let-Attackers-Gain-unauthorized-access-to-camera-feeds.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151662</post-id>	</item>
		<item>
		<title>Anthropic Expands Project Glasswing Claude Mythos Preview to 150 New Organizations</title>
		<link>https://cybersecuritynews.com/anthropic-expands-project-glasswing/</link>
		
		<dc:creator><![CDATA[Guru Baran]]></dc:creator>
		<pubDate>Tue, 02 Jun 2026 14:17:39 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151697</guid>

					<description><![CDATA[<p>Anthropic has significantly broadened the reach of Project Glasswing, its collaborative AI-driven cybersecurity initiative, by extending access to Claude Mythos Preview to approximately 150 new organizations. This expansion follows several weeks of close collaboration with existing partners, the broader security industry, open-source software maintainers, and the US government. Project Glasswing was first announced in early [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/anthropic-expands-project-glasswing/">Anthropic Expands Project Glasswing Claude Mythos Preview to 150 New Organizations</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Anthropic has significantly broadened the reach of Project Glasswing, its collaborative AI-driven cybersecurity initiative, by extending access to <a href="https://cybersecuritynews.com/anthropics-claude-mythos-preview-0-days/" target="_blank" rel="noreferrer noopener">Claude Mythos Preview</a> to approximately 150 new organizations.</p>



<p class="wp-block-paragraph">This expansion follows several weeks of close collaboration with existing partners, the broader security industry, open-source software maintainers, and the US government.</p>



<p class="wp-block-paragraph"><a href="https://cybersecuritynews.com/anthropic-releases-claude-opus-4-7/" target="_blank" rel="noreferrer noopener">Project Glasswing was first announced</a> in early April 2026, when roughly 50 initial partner organizations gained access to Claude Mythos Preview to scan their codebases for security vulnerabilities.</p>



<p class="wp-block-paragraph">Those early partners collectively identified more than 10,000 high- or critical-severity security flaws, underscoring the raw detection power of Mythos-class AI models when applied to enterprise and infrastructure codebases.</p>



<p class="wp-block-paragraph">The newly onboarded organizations span more than fifteen countries, with most providing critical infrastructure services that extend well beyond their home nations. Industries that were underrepresented in the initial cohort, including power, water, healthcare, communications, and hardware, are now integrated into the program.</p>



<p class="wp-block-paragraph">A substantial portion of the new partners are vendors and nonprofits that maintain widely used codebases relied upon by other organizations globally, including national governments.</p>



<p class="wp-block-paragraph">Anthropic&#8217;s assessment of risk is stark: for most Project Glasswing partners, a successful cyberattack on their codebase could affect more than 100 million people, with significant consequences for both global and national security. Each new organization must meet Anthropic&#8217;s security requirements before receiving access to models.</p>



<h2 id="h-claude-mythos-preview-capabilities" class="wp-block-heading"><strong>Claude Mythos Preview Capabilities</strong></h2>



<p class="wp-block-paragraph">Beyond raw vulnerability detection, partners are now deploying Claude Mythos Preview across a broader range of defensive tasks. These include automated patch writing, pre-release security checks to prevent vulnerabilities from entering production, penetration testing simulations, threat detection and response automation, and rebuilding legacy codebases in memory-safe languages.</p>



<p class="wp-block-paragraph">Mythos Preview also represents a critical warning signal for the industry. Anthropic estimates that within six to twelve months, competing AI companies will develop Mythos-class models, potentially releasing them without sufficient safeguards to prevent offensive misuse.</p>



<p class="wp-block-paragraph">This timeline creates an urgent window for cyberdefenders to adapt their tooling and operational norms before the threat landscape shifts dramatically.</p>



<p class="wp-block-paragraph">To help scale these defensive capabilities beyond Project Glasswing&#8217;s direct partners, Anthropic is releasing on request to trusted security teams the tools developed to support the program&#8217;s vulnerability detection workflows.</p>



<p class="wp-block-paragraph">The company has also <a href="https://cybersecuritynews.com/claude-security-public-beta/" target="_blank" rel="noreferrer noopener">launched Claude Security</a>, a product built on its frontier public models, including Claude Opus 4.8, designed to scan codebases and suggest patches for organizations outside the program.</p>



<p class="wp-block-paragraph">Anthropic is also in active discussions with third parties to substantially scale up the review and patching of vulnerabilities in open-source software, including the development of standardized best practices for disclosing findings to open-source maintainers to streamline triage and remediation.</p>



<p class="wp-block-paragraph">Anthropic acknowledges that hundreds of thousands of organizations will ultimately need access to Mythos-level capabilities to address the full scope of the coming threat environment.</p>



<p class="wp-block-paragraph">The company is working toward a general access release, but notes that highly robust safeguards preventing offensive misuse, which neither Anthropic nor other AI developers have fully developed yet, must be in place first.</p>



<p class="wp-block-paragraph">In parallel, Anthropic plans to further scale its Cyber Verification Program, which would <a href="https://www.anthropic.com/news/expanding-project-glasswing" target="_blank" rel="noreferrer noopener nofollow">grant Mythos-class capabilities to additional organizations</a> for specific defensive tasks.</p>



<p class="wp-block-paragraph">The long-term goal of Project Glasswing remains unchanged: to shift AI&#8217;s role in cybersecurity from finding vulnerabilities to a full-cycle model covering disclosure, patching, and deployment, ultimately securing a permanent advantage for defenders.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)"><strong><a href="https://www.prophaze.com/webinar-registration-closing-visibility-gaps-in-waap/?utm_source=Cyber+security+news+&amp;utm_medium=Article+&amp;utm_campaign=Cyber+news#" target="_blank" rel="noreferrer noopener nofollow">Free Webinar</a></strong> <strong>on OWASP API Top 10 and Guide to Close Visibility Gaps With WAAP</strong></p>
<p>The post <a href="https://cybersecuritynews.com/anthropic-expands-project-glasswing/">Anthropic Expands Project Glasswing Claude Mythos Preview to 150 New Organizations</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/Anthropic-Expands-Project-Glasswing.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151697</post-id>	</item>
		<item>
		<title>CISA Flags Palo Alto Networks PAN-OS Vulnerability as Exploited in Attacks</title>
		<link>https://cybersecuritynews.com/cisa-palo-alto-networks-pan-os-vulnerability/</link>
		
		<dc:creator><![CDATA[Abinaya]]></dc:creator>
		<pubDate>Tue, 02 Jun 2026 13:48:15 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Vulnerability News]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<category><![CDATA[vulnerability]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151651</guid>

					<description><![CDATA[<p>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Palo Alto Networks PAN-OS vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, warning that the flaw is being actively leveraged in real-world attacks. The vulnerability affects PAN-OS, the operating system that powers Palo Alto Networks firewalls. It enables attackers to bypass authentication mechanisms [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/cisa-palo-alto-networks-pan-os-vulnerability/">CISA Flags Palo Alto Networks PAN-OS Vulnerability as Exploited in Attacks</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical <a href="https://cybersecuritynews.com/pan-os-web-interface-vulnerability/" target="_blank" rel="noreferrer noopener">Palo Alto Networks PAN-OS vulnerability </a>to its Known Exploited Vulnerabilities (KEV) catalog, warning that the flaw is being actively leveraged in real-world attacks.</p>



<p class="wp-block-paragraph">The vulnerability affects PAN-OS, the operating system that powers Palo Alto Networks firewalls. It enables attackers to bypass authentication mechanisms and establish unauthorized VPN access.</p>



<p class="wp-block-paragraph">According to the official CVE record, <a href="https://cybersecuritynews.com/palo-alto-vulnerability-exploited/" target="_blank" rel="noreferrer noopener nofollow">CVE-2026-0257</a> is categorized as an authentication bypass issue linked to CWE-565.</p>



<p class="wp-block-paragraph">The flaw allows remote attackers to circumvent security restrictions without valid credentials, potentially granting them direct access to internal network resources through VPN connections.</p>



<p class="wp-block-paragraph">This type of weakness is particularly dangerous because it undermines perimeter defenses and enables attackers to operate as legitimate users within enterprise environments.</p>



<h2 id="h-pan-os-vulnerability-exploited" class="wp-block-heading"><strong>PAN-OS vulnerability exploited</strong></h2>



<p class="wp-block-paragraph">CISA added the vulnerability to its KEV catalog on May 29, 2026, with a remediation due date of June 1, 2026, for federal agencies.</p>



<p class="wp-block-paragraph">The inclusion in the KEV list confirms that <a href="https://cybersecuritynews.com/palo-alto-pan-os-vulnerability-exploited/" target="_blank" rel="noreferrer noopener">exploitation has been observed</a> in the wild. However, there is currently no public confirmation linking the flaw to specific ransomware campaigns.</p>



<p class="wp-block-paragraph">However, security experts warn that authentication bypass vulnerabilities in network edge devices are frequently targeted by threat actors, including initial access brokers and advanced persistent threat groups.</p>



<p class="wp-block-paragraph">The impact of this vulnerability is significant, especially for organizations that rely on PAN-OS to secure their remote access infrastructure.</p>



<p class="wp-block-paragraph">Successful exploitation could allow attackers to gain persistent access, move laterally across networks, and potentially deploy additional malicious payloads.</p>



<p class="wp-block-paragraph">Given the role of <a href="https://cybersecuritynews.com/octalyn-stealer-steals-vpn-configurations/" target="_blank" rel="noreferrer noopener">VPN gateways in enterprise environments</a>, exploitation could result in data exfiltration, service disruption, or the further compromise of critical systems.</p>



<p class="wp-block-paragraph">Palo Alto Networks has issued guidance and mitigation steps to address the vulnerability. Organizations are strongly advised to apply available security updates or patches immediately.</p>



<p class="wp-block-paragraph">In cases where patches are not yet available or cannot be applied, CISA recommends following vendor-provided mitigation instructions and adhering to Binding Operational Directive (BOD) 22-01 for cloud and network services.</p>



<p class="wp-block-paragraph">If mitigation is not feasible, discontinuing use of the affected product is advised to reduce exposure to risk.</p>



<p class="wp-block-paragraph">Security teams should also review authentication logs, monitor VPN access patterns, and investigate any unusual or unauthorized connection attempts.</p>



<p class="wp-block-paragraph">Indicators of compromise may include unexpected VPN sessions, anomalous login behavior, or access from unfamiliar IP ranges.</p>



<p class="wp-block-paragraph">Proactive threat hunting and network monitoring are essential to detect potential exploitation attempts early. The <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" target="_blank" rel="noreferrer noopener nofollow">addition of CVE-2026-0257 to the KEV catalog</a> highlights the ongoing risk posed by vulnerabilities in network security appliances.</p>



<p class="wp-block-paragraph">As attackers increasingly target edge infrastructure, timely patching and continuous monitoring remain critical to maintaining a secure enterprise environment.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)"><strong><a href="https://www.prophaze.com/webinar-registration-closing-visibility-gaps-in-waap/?utm_source=Cyber+security+news+&amp;utm_medium=Article+&amp;utm_campaign=Cyber+news#" target="_blank" rel="noreferrer noopener nofollow">Free Webinar</a></strong> <strong>on OWASP API Top 10 and Guide to Close Visibility Gaps With WAAP</strong></p>
<p>The post <a href="https://cybersecuritynews.com/cisa-palo-alto-networks-pan-os-vulnerability/">CISA Flags Palo Alto Networks PAN-OS Vulnerability as Exploited in Attacks</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/CISA-flags-Palo-Alto-Networks-PAN-OS-vulnerability-as-exploited-in-attacks.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151651</post-id>	</item>
	</channel>
</rss>
