Domains:
aquasecurtiy[.]org, aquasecurtiy[.]org.
Get tomorrow's brief in your inbox
Today: Microsoft Azure Monitor alerts exploited for callback phishing with legitimate Microsoft headers bypassing email security. Trivy vulnerability scanner compromised in supply chain attack pushing credential stealers across GitHub Actions. Russian state-sponsored phishing campaigns targeting Signal and WhatsApp accounts of government officials and journalists.
Trivy Vulnerability Scanner Supply Chain Compromise
TeamPCP threat actors compromised the Trivy security scanner by backdooring version 0.69.4 and nearly all GitHub Actions tags in the trivy-action repository. The attackers exploited previously stolen credentials with write access to inject malicious code into the entrypoint.sh script and published trojanized binaries. The infostealer payload harvested SSH keys, cloud credentials (AWS, GCP, Azure), database configs, environment variables, CI/CD secrets, cryptocurrency wallets, and system authentication files. Exfiltrated data was sent to a typosquatted C2 server at scan.aquasecurtiy[.]org, and if that failed, uploaded to public GitHub repositories named tpcp-docs in victims' accounts. The malware also established persistence via a systemd service running ~/.config/systemd/user/sysmon.py for follow-on payload delivery.
Microsoft Azure Monitor Alert Abuse for Callback Phishing
Attackers are exploiting legitimate Azure Monitor alert functionality to deliver callback phishing emails that pass SPF, DKIM, and DMARC checks. The emails originate from Microsoft's [email protected] address and impersonate fraud alerts from the Microsoft Security Team, claiming unauthorized charges of $389.90 for Windows Defender. Threat actors create Azure Monitor alerts with billing-themed triggers (invoices, payments, orders) and embed phishing messages in the alert description field. These alerts are configured to send to attacker-controlled mailing lists that forward to targeted recipients while preserving Microsoft's legitimate authentication headers. The campaign uses urgency-driven social engineering with phone numbers leading to credential theft, payment fraud, or remote access tool installation.
Russian State Phishing Targeting Signal and WhatsApp Accounts
CISA and FBI warn that Russian intelligence-linked threat actors (Star Blizzard, UNC5792, UNC4221) are conducting phishing campaigns against government officials, military personnel, journalists, and political figures to compromise Signal and WhatsApp accounts. The attacks impersonate "Signal Support" and use social engineering to trick targets into sharing verification codes/PINs or clicking malicious links/QR codes. Sharing codes allows attackers to recover accounts on their devices, locking victims out and enabling message monitoring and impersonation. Clicking links or scanning QR codes links attacker-controlled devices to the victim's account, granting access to all past messages while the victim retains access. Thousands of accounts have been compromised globally.
Google Announces Advanced Flow for Android APK Sideloading
Google is introducing Advanced Flow in August 2026 as a security mechanism for power users who need to sideload apps from unverified developers. The system requires a one-time process involving enabling developer options, confirming the user is not being coached by attackers, restarting the device, reauthenticating, and waiting one day before confirming the installation is legitimate. After completing this flow, users can install unverified apps with warnings displayed. The friction is designed to disrupt scam tactics that exploit urgency and fear to trick users into installing malware. This accompanies Google's developer verification requirement that will block installation of apps from unverified publishers on certified Android devices starting August 2026.
Supply chain attacks continue to target developer tools and CI/CD infrastructure, with the Trivy compromise demonstrating how stolen credentials can enable widespread malware distribution through trusted platforms. Social engineering remains effective against both technical users (Azure Monitor callback phishing) and high-value targets (messaging app account takeovers), with attackers exploiting legitimate infrastructure and trust relationships to bypass security controls.