CVE-2021-22681, CVE-2023-50224, CVE-2024-41110, CVE-2025-14815, CVE-2025-14816, CVE-2025-26319, CVE-2025-59528, CVE-2025-8943, CVE-2026-0740, CVE-2026-34040
IP Addresses:
77.110.96.200, 20.48.232.178, 20.215.65.23, 51.12.84.116, 51.103.130.249
Get tomorrow's brief in your inbox
Today: Russian military intelligence exploited 18,000 routers worldwide to steal Microsoft credentials through DNS hijacking. Anthropic's unreleased Mythos AI found thousands of zero-day flaws across all major operating systems with a 72% exploit success rate. Iranian actors disrupted US critical infrastructure by targeting internet-exposed PLCs in water, energy, and government sectors.
Anthropic's Claude Mythos Finds Thousands of Zero-Day Flaws Across Major Systems
Anthropic announced Project Glasswing, a restricted-access initiative using its unreleased Claude Mythos Preview model to identify security vulnerabilities before releasing the model to the public. The model achieved a 72.4% exploit development success rate compared to Claude Opus 4.6's near-zero percent, autonomously discovering thousands of high and critical-severity vulnerabilities across every major operating system and web browser. Engineers with no formal security training asked Mythos Preview to find remote code execution vulnerabilities overnight and woke up to complete, working exploits. The model constructed complex exploits including a browser attack chaining four vulnerabilities with JIT heap spray to escape renderer and OS sandboxes, local privilege escalation through subtle race conditions and KASLR bypasses, and a FreeBSD NFS server remote code execution using a 20-gadget ROP chain split across multiple packets. Discovered vulnerabilities include a 27-year-old bug in OpenBSD and a 16-year-old flaw in FFmpeg that automated testing tools failed to detect despite running the affected code line five million times.
Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure (CVE-2021-22681)
CISA, FBI, NSA, EPA, DOE, and US Cyber Command warned that Iranian APT actors are exploiting internet-connected operational technology devices, specifically Rockwell Automation/Allen-Bradley PLCs, across multiple US critical infrastructure sectors including government facilities, water and wastewater systems, and energy sectors. The attacks caused disruptions through malicious interactions with project files and manipulation of data displayed on HMI and SCADA displays, resulting in operational disruption and financial loss in some cases. The threat actors used leased third-party infrastructure with Rockwell Automation's Studio 5000 Logix Designer software to create accepted connections to victim PLCs, then deployed Dropbear SSH software on victim endpoints to enable remote access through port 22 for project file extraction and data manipulation. CVE-2021-22681 is on the CISA KEV catalog with a due date of 2026-03-26 and has an EPSS score of 0.129 (94th percentile). Targeted devices include CompactLogix and Micro850 PLC models.
Russian State-Linked APT28 Exploits SOHO Routers in Global DNS Hijacking Campaign (CVE-2023-50224)
APT28 (Forest Blizzard, Storm-2754) conducted a large-scale DNS hijacking campaign since May 2025, compromising insecure MikroTik and TP-Link routers to steal Microsoft 365 credentials and OAuth tokens through adversary-in-the-middle attacks. At its peak in December 2025, the campaign infected 18,000 devices across 120 countries, with Microsoft identifying over 200 organizations and 5,000 consumer devices impacted. The attackers gained remote administrative access to SOHO devices and modified DNS settings to use actor-controlled resolvers, which were automatically pushed to internal devices via DHCP. When users queried targeted authentication domains, the malicious DNS server redirected traffic to AitM proxy infrastructure, intercepting OAuth tokens after successful multi-factor authentication. The only visible sign was an invalid TLS certificate warning that victims often dismissed. FBI executed a court-authorized operation to reset compromised routers to legitimate DNS resolvers provided by internet service providers. CVE-2023-50224 is on the CISA KEV catalog with a due date of 2025-09-24 and has an EPSS score of 0.015 (81st percentile).
BlueHammer: Zero-Day Windows Exploit Released by Researcher After Microsoft MSRC Dispute
Security researcher "Chaotic Eclipse" publicly released BlueHammer, a zero-day Windows exploit on GitHub, after disputes with Microsoft Security Response Center. The researcher stated "I was not bluffing Microsoft, and I'm doing it again. Unlike previous times, I'm not explaining how this works; y'all geniuses can figure it out. Also, huge thanks to MSRC leadership for making this possible." No patch is currently available from Microsoft. The exploit code is publicly accessible on GitHub, though technical details of the vulnerability mechanism were not disclosed by the researcher.
Max Severity Flowise RCE Vulnerability Actively Exploited (CVE-2025-59528, CVE-2025-8943, CVE-2025-26319)
Hackers are actively exploiting CVE-2025-59528, a maximum-severity (CVSS 10.0) vulnerability in Flowise, an open-source platform for building custom LLM apps and agentic systems. The flaw allows unauthenticated arbitrary JavaScript code injection through the CustomMCP node's mcpServerConfig input, which executes code without validation. Wordfence detected exploitation beginning this morning and blocked over 3,600 attacks in 24 hours. VulnCheck's Canary network confirmed first-time exploitation from a single Starlink IP. Between 12,000 and 15,000 Flowise instances are exposed online. The vulnerability also enables path traversal, allowing attackers to upload PHP files to the webroot directory for remote code execution. CVE-2025-59528 has an EPSS score of 0.824 (99th percentile). Additional Flowise CVEs under active exploitation include CVE-2025-8943 (EPSS 0.840, 99th percentile) and CVE-2025-26319 (EPSS 0.795, 99th percentile).
4 claims tracked across 1 group in the last 48 hours. These are unverified claims from ransomware leak sites, not confirmed breaches.
| Group | Victim | Sector | Country |
|---|---|---|---|
| Audit Team | Joycity | Gaming/Technology | South Korea |
| Audit Team | Kawasaki Motors Philippines Corporation | Manufacturing | Philippines |
| Audit Team | [COOPERATION REACHED] | Unknown | China |
| Audit Team | [COOPERATION REACHED] | Unknown | Thailand |
Note: Audit Team marked three victims as "COOPERATION REACHED" with claims that acquired data was purged from servers and enterprise security remediation was verified. These appear to be ransom payments resulting in data deletion.
Storm-1175 Deploys Medusa Ransomware at High Velocity
Microsoft warned that financially motivated cybercrime group Storm-1175 is deploying Medusa ransomware at high velocity, exploiting both N-day and zero-day vulnerabilities. The group weaponizes fresh bugs quickly and exfiltrates and encrypts data within days of initial access. Microsoft described the campaign as predicated on speed, with threat actors moving rapidly from initial access to data encryption.
NightSpire Ransomware IOCs and Affiliate Model Analysis
Huntress investigated a NightSpire ransomware incident where the agent was installed on endpoints after the attack had already begun. The investigation revealed the threat actor accessed one endpoint via RDP several days prior to agent installation. There is confusion about whether NightSpire operates under a RaaS model. Halcyon argued in July 2025 that NightSpire keeps operations in-house with no public RaaS or affiliate program, but HivePro reported in September 2025 that the group operates under a RaaS model. The discrepancy suggests potential evolution of the group's structure. Multiple RaaS samples contain embedded commands to terminate processes and inhibit recovery, lowering the bar for affiliate success. Akira ransomware launches PowerShell to delete Volume Shadow Copies. Sodinokibi samples in 2020 included 156 unique embedded commands to terminate anti-virus processes and services. IOCs and TTPs vary significantly between attacks even when the same ransomware variant is used, reflecting different affiliate activity.
Hundreds of Organizations Compromised Daily in Microsoft Device Code Phishing Attacks
Since March 15, 2026, Microsoft observed 10 to 15 distinct device code phishing campaigns launching every 24 hours, targeting hundreds of organizations with highly varied and unique payloads. The attacks bypass multi-factor authentication using OAuth 2.0 device code authentication, typically used for smart TVs and IoT devices. Attackers query Microsoft's GetCredentialType API endpoint 10 to 15 days before phishing attempts to confirm email addresses exist and are active. AI generates hyper-personalized phishing emails aligned to target roles with themes including requests for proposals, invoices, and manufacturing workflows. Emails contain malicious attachments or URLs that redirect through compromised legitimate domains on Railway, Cloudflare Workers, DigitalOcean, and AWS Lambda to avoid URL scanners. The final phishing page mimics a legitimate browser window prompting identity verification via device code. Post-compromise activity focuses on finance-related accounts with automated email exfiltration. The tooling shares similarities with EvilTokens, a device-code phishing kit sold as a service since mid-February supporting Microsoft 365 with promised support for Gmail and Okta.
FBI: Americans Lost $21 Billion to Cybercrime in 2025
Americans lost $20.9 billion to cyber-enabled crimes in 2025, a 26% increase from $16.6 billion in 2024. The Internet Crime Complaint Center received over 1 million complaints, up from 859,000 the previous year. Investment fraud accounted for 49% of all scam-related incidents with $8.6 billion in losses. Cryptocurrency-related cybercrime caused the largest single loss category, exceeding $11 billion across 181,565 cases. Americans over 60 were hit hardest with $7.7 billion in losses, a 37% increase. AI-related scams accounted for 22,300 complaints and $893 million in losses, involving voice cloning, fake profiles, forged documents, and deepfake videos. The most frequent complaints were phishing (191,000), extortion (89,000), and investment scams (72,000). Business email compromise generated 24,700 cases, data breaches 3,900, ransomware 3,600, and SIM swapping 971. FBI's Financial Fraud Kill Chain interventions froze $679 million of $1.16 billion targeted by attackers. Operation Level Up notified 3,780 cryptocurrency investment fraud victims, with 78% unaware they were being scammed.
LucidRook Malware Targets Taiwanese Organizations via Spear-Phishing
Cisco Talos uncovered activity cluster UAT-10362 conducting spear-phishing campaigns against Taiwanese NGOs and suspected universities delivering LucidRook, a sophisticated Lua-based stager. LucidRook embeds a Lua interpreter and Rust-compiled libraries within a DLL to download and execute staged Lua bytecode payloads. The dropper "LucidPawn" uses region-specific anti-analysis checks and executes only in Traditional Chinese language environments associated with Taiwan. Two distinct infection chains involve malicious LNK and EXE files disguised as antivirus software. The actor abused OAST services and compromised FTP servers for command-and-control infrastructure. Talos discovered "LucidKnight," a companion reconnaissance tool that exfiltrates system information via Gmail, suggesting a tiered toolkit where LucidKnight profiles targets before escalating to full stager deployment. The multi-language modular design, layered anti-analysis features, stealth-focused payload handling, and reliance on compromised infrastructure indicate UAT-10362 is a capable threat actor with mature operational tradecraft.
Over 1,000 Exposed ComfyUI Instances Targeted in Cryptomining Botnet Campaign
An active campaign targets internet-exposed ComfyUI instances (a stable diffusion platform) to enlist them into a cryptocurrency mining and proxy botnet. A purpose-built Python scanner continuously sweeps major cloud IP ranges for vulnerable targets, automatically installing malicious nodes via ComfyUI-Manager if no exploitable node is present. Over 1,000 publicly-accessible ComfyUI instances are exposed. The campaign exploits a misconfiguration allowing remote code execution on unauthenticated deployments through custom nodes. Compromised hosts mine Monero via XMRig and Conflux via lolMiner, and join a Hysteria V2 botnet managed through a Flask-based C2 dashboard. Censys discovered the campaign after identifying an open directory on 77.110.96.200 (Aeza Group bulletproof hosting) containing previously undocumented attack tools. The scanner weaponizes ComfyUI's custom nodes that accept raw Python code as input and execute it without authentication, looking for Vova75Rus/ComfyUI-Shell-Executor, filliptm/ComfyUI_Fill-Nodes, seanlynch/srl-nodes, and ruiqutech/ComfyUI-RuiquNodes. If none are present, the scanner installs a vulnerable node package and retries exploitation. Persistence mechanisms include downloading shell scripts every six hours, re-executing exploit workflows on ComfyUI startup, and using chattr +i to lock miner binaries preventing deletion even by root.
Microsoft Rolls Out Fix for Broken Windows Start Menu Search
Microsoft pushed a server-side fix for a known issue that broke Windows Start Menu search on some Windows 11 23H2 devices. The problems affected a small number of users since April 6 and were caused by a server-side Bing update aimed at improving search performance. While Microsoft claims the issues are recent, there have been reports of similar problems for months, including blank search results that are still clickable. Microsoft rolled back the buggy Bing update, and reports of search failures are decreasing. The fix will resolve automatically as the server-side update is gradually deployed to affected devices connected to the internet with Web Search enabled.
Cracks in the Bedrock: Escaping the AWS AgentCore Sandbox
Unit 42 discovered that AWS Bedrock AgentCore's Code Interpreter sandbox network isolation mode could be bypassed via DNS tunneling, allowing sending and receiving data from external endpoints. AgentCore protects Code Interpreters that allow AI agents to dynamically execute code by isolating them from external network access using sandbox mode. AWS originally described sandbox mode as providing "complete isolation with no external access," but Unit 42's research revealed external network connectivity existed. By mapping DNS resolution capability boundaries, researchers established a covert bi-directional channel for data exfiltration from the "secure, offline" environment. Unit 42 also identified a critical security regression where AgentCore Runtime utilized a microVM Metadata Service lacking session token enforcement. This configuration could have allowed attackers to exploit standard web vulnerabilities like SSRF to extract sensitive credentials. Following Unit 42's disclosure, AWS introduced internal remediations and updated developer documentation to state that sandbox mode provides restrictions rather than "no external network access."
Financial Cyberthreats in 2025: Infostealers and Dark Web Economy
Kaspersky's analysis of 2025 financial cyberthreats shows traditional PC banking malware declined in relative prevalence, offset by rapid growth of credential theft via infostealers. Attackers increasingly rely on aggregation and reuse of stolen data rather than developing new malware capabilities. Phishing activity shifted toward e-commerce (14.17%) and digital services (16.15%), with attackers tailoring campaigns to regional trends and user behavior. Online games (14.58%) and online stores led phishing targets globally. Financial PC malware declined but remained persistent, with established families continuing operations while attackers prioritize credential access and indirect fraud over complex banking Trojans. Mobile banking malware continues growing. Infostealers became a central driver of financial cybercrime, fueling a dark web economy where stolen credentials, payment data, and full identity profiles are traded at scale enabling widespread fraud operations. Regional patterns show attackers align category targeting with local digital habits: online stores dominate in the Middle East, online games and instant messaging in CIS, and banks remain prominent in Africa.
Webshell Scanning Activity from Microsoft Azure IP Addresses
SANS Internet Storm Center observed scanning for webshell URLs, particularly turkshell.php, from four Microsoft Azure IP addresses: 20.48.232.178, 20.215.65.23, 51.12.84.116, 51.103.130.249. Database queries revealed 287 webshell URLs probed by these IPs. Common themes include "wp-" prefixes to blend in on WordPress sites and searches for legitimate URLs like /wp-content/plugins/hellopress/wp_filemanager.php that may be vulnerable. The IPs all belong to Microsoft, suggesting either an attacker targeting systems inside Microsoft's cloud environment or a single compromised organization using Microsoft infrastructure.
Hackers Exploit Critical Flaw in Ninja Forms WordPress Plugin (CVE-2026-0740)
A critical vulnerability in Ninja Forms File Uploads premium add-on for WordPress allows uploading arbitrary files without authentication, leading to remote code execution. CVE-2026-0740 has a severity rating of 9.8 out of 10 and affects versions up to 3.3.26. Wordfence blocked over 3,600 attacks in 24 hours. The flaw is caused by lack of validation of file types and extensions on the destination filename, allowing unauthenticated attackers to upload arbitrary files including PHP scripts and manipulate filenames to enable path traversal. Files can be moved to the webroot directory, enabling remote code execution. Ninja Forms has over 600,000 downloads and the File Upload extension serves 90,000 customers. The vulnerability was discovered by Sélim Lanouar on January 8, with temporary mitigations via Wordfence firewall rules. A partial fix was released February 10 and complete fix in version 3.3.27 on March 19. CVE-2026-0740 has an EPSS score of 0.001 (24th percentile).
Docker CVE-2026-34040 Bypasses Authorization and Gains Host Access
A high-severity vulnerability (CVE-2026-34040, CVSS 8.8) in Docker Engine allows bypassing authorization plugins under specific circumstances. The flaw stems from an incomplete fix for CVE-2024-41110, a maximum-severity vulnerability from July 2024. Using a specially-crafted API request, an attacker can make the Docker daemon forward the request to an authorization plugin without the body, allowing the plugin to permit a request it would have otherwise denied. The vulnerability affects anyone depending on authorization plugins that introspect request bodies for access control decisions. The fix for CVE-2024-41110 did not properly handle oversized HTTP request bodies, allowing a single padded HTTP request to create a privileged container with host file system access. An attacker with Docker API access restricted by an AuthZ plugin can undermine the mechanism by padding a container creation request to more than 1MB, causing it to be dropped before reaching the plugin. The plugin allows the request because it sees nothing to block, while the Docker daemon processes the full request and creates a privileged container with root access to AWS credentials, SSH keys, Kubernetes configs, and everything else on the machine. AI coding agents like OpenClaw running inside Docker-based sandboxes can be tricked via prompt injection concealed in GitHub repositories to execute malicious code exploiting CVE-2026-34040. CVE-2026-34040 has an EPSS score of 0.000 (2nd percentile). CVE-2024-41110 has an EPSS of 0.040 (88th percentile).
Mitsubishi Electric GENESIS64 and ICONICS Suite Products (CVE-2025-14815, CVE-2025-14816)
CISA warned of vulnerabilities in Mitsubishi Electric GENESIS64 and ICONICS Suite products that could allow local attackers to disclose SQL Server credentials and use them to disclose, tamper with, or destroy data, or cause denial-of-service. CVE-2025-14815 involves cleartext storage of SQL Server credentials in local SQLite files when local caching is enabled with SQL authentication. Affected versions include GENESIS64 <=10.97.3, ICONICS Suite <=10.97.3, MobileHMI <=10.97.3, Hyper Historian <=10.97.3, AnalytiX <=10.97.3, MC Works 64 (all versions), and GENESIS <=11.02. Mitsubishi Electric is releasing fixed version 10.98 or later. After installing the patch, administrators must uncheck the "Local Cache" column in Workbench Configure Application Settings dialog and delete files from C:\ProgramData\ICONICS\Cache*.sdf.
Snowflake Customers Hit in Data Theft Attacks After SaaS Integrator Breach
Over a dozen companies suffered data theft attacks after a SaaS integration provider was breached and authentication tokens stolen. The breach of the third-party integrator allowed attackers to access Snowflake customer accounts without directly compromising Snowflake itself or individual customer credentials.
The convergence of AI-powered vulnerability discovery (Mythos with 72% exploit success), nation-state infrastructure targeting (Russian router compromise and Iranian PLC attacks), and automated attack campaigns (device code phishing, ComfyUI botnet) shows a threat landscape where speed and scale define effectiveness. Defenders face simultaneously faster vulnerability weaponization, broader infrastructure compromise, and AI-augmented social engineering. The successful FBI router cleanup operation and Project Glasswing's defensive application of AI capabilities demonstrate that coordination between government, vendors, and security firms remains the most effective countermeasure to industrialized cybercrime and nation-state operations.