CVE-2019-18935, CVE-2021-29441, CVE-2021-3156, CVE-2022-0847, CVE-2022-27925
Domains:
197[.]150, tippusoni[.]in
Get tomorrow's brief in your inbox
Today: Chinese cybercrime group UAT-10147 is using AI tools to automate exploitation of known vulnerabilities across 170,000 targets, deploying a new cross-platform implant called SPECTRE with EDR bypass capabilities. Iran-linked hackers shut down a UK power plant for four days in July, raising questions about distributed energy infrastructure resilience. ShinyHunters claims a breach of cybersecurity firm ReliaQuest, and a new attack technique revives expired Visa contactless cards for fraudulent transactions.
UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit (CVE-2022-0847, CVE-2021-3156, CVE-2019-18935, CVE-2022-27925)
Cisco Talos disclosed a Chinese-speaking cybercrime group, UAT-10147, targeting Windows and Linux web servers across education, media, tech, and gaming sectors using a 170,000-URL target list. The group integrates AI tools (PentestGPT, DeepAudit) to automate exploitation, reconnaissance, and payload generation at scale. They chain known vulnerabilities for initial access and privilege escalation, deploying BadIIS (MaaS), Noodle RAT, Gh0stCringe, Quasar RAT, and a new cross-platform implant called SPECTRE. On Linux, they exploit CVE-2022-0847/Dirty Pipe (CISA KEV, EPSS 0.886), CVE-2021-3156/Baron Samedit (CISA KEV, EPSS 0.993), CVE-2019-18935/Telerik UI deserialization (CISA KEV, ransomware-linked, EPSS 0.997), and CVE-2022-27925/Zimbra RCE (CISA KEV, ransomware-linked, EPSS 0.987). On Windows, they use EfsPotato for privilege escalation, configure Defender exclusions, and persist via scheduled tasks disguised as "Google Chrome Start."
139.180.197[.]150 and domain adminapi.tippusoni[.]in. Hunt for scheduled tasks named "Google Chrome Start" and unexpected BadIIS/Quasar RAT artifacts. Review IIS servers and Zimbra/Telerik/Nacos deployments for compromise indicators.ShinyHunters Claims Hack of ReliaQuest
Threat actor ShinyHunters posted claims of breaching cybersecurity firm ReliaQuest. The claim surfaced on a forum after ReliaQuest's threat research team (@ReliaQuestTR) published tracking of ShinyHunters campaigns. A forum user replied with screenshots and the taunt "Who's hunting who?" ReliaQuest deleted the original tweet and has not posted since. No confirmation or proof of breach has been provided by either party.
Iran-Linked Hackers Shut Down UK Power Plant for Four Days
Iranian-affiliated hackers shut down a small-scale UK power plant for four days in July 2026. The attack was not publicly reported until August 22. The facility was not a major grid asset, and wider grid stability was not affected, but the incident demonstrates operational disruption capability against distributed energy infrastructure. Security experts warn this attack pattern is repeatable and could be deployed at scale against thousands of distributed UK energy assets. The attackers are believed to be the same group that previously breached US water utilities. Since the Iran-US/Israel conflict escalated, Iranian cyber groups have targeted critical infrastructure across the US, Israel, GCC states, and Europe.
Expired Visa Contactless Cards Can Be Revived for Fraudulent Transactions
Researchers at UMass Amherst developed an NFC Man-in-the-Middle attack that modifies the expiration date on contactless card transactions in transit. Banks delegate expiration checks to POS terminals rather than enforcing them server-side. The attack works on Visa terminals and was not caught by five tested banks' backends. Mastercard, Amex, and Discover terminals detected the hash mismatch and rejected the modified transactions. The attack requires only basic NFC emulators and a recovered expired card.
Lazarus Hacks South Korea's Presidential Office
North Korean espionage group Lazarus compromised South Korea's Presidential Office in February 2026 as part of a broader campaign that hit 100+ victims by April, including universities, police departments, news agencies, and hospitals. Investigation is ongoing with no technical details released.
SFR Telco Breach Exposes 2.1M French Customers
French telecom SFR suffered a breach exposing names, postal addresses, phone numbers, contract details, and for some customers, IP addresses and equipment details. 2.1 million customers affected.
DOUBLECUP Malware Uses PNG Payload Delivery via FINDSTR
SANS ISC analyzed a DOUBLECUP malware sample that appends a PowerShell payload after the end of a PNG file (not true steganography). The payload begins with CR+LF bytes, allowing extraction via Windows FINDSTR command piped directly into powershell.exe. This technique avoids embedding payloads in image metadata or pixel data, instead exploiting how Windows text tools handle binary files.
Anthropic Expands Mythos 5 Access for Defenders, Launches $35M Open Source Security Fund
Anthropic is expanding access to its Mythos 5 model for defensive security use through partner integrations. Claude Security (public beta for Enterprise customers) now runs code scans on Mythos 5, surfacing findings with CWE categories, confidence/severity ratings, and suggested fixes. The new Defender Advantage Fund (0xDAF) provides $35M in Claude credits toward open source security projects. The Cyber Verification Program is expanding to cover broader dual-use capabilities on Opus and Sonnet models with reduced safeguards for authorized security work.
TikTok Settles $400M Children's Privacy Lawsuit
TikTok reached a $400M settlement with the DOJ over COPPA violations, paying $300M immediately and $100M after a prior consent decree against Musical.ly is vacated.
Multiple CVEs Actively Exploited by UAT-10147
The UAT-10147 campaign chains multiple known CVEs, several of which are CISA KEV entries with near-perfect EPSS scores: CVE-2019-18935 (Telerik UI deserialization, EPSS 0.997, ransomware-linked), CVE-2022-27925 (Zimbra RCE, EPSS 0.987, ransomware-linked), CVE-2022-0847 (Dirty Pipe, EPSS 0.886), CVE-2021-3156 (sudo heap overflow, EPSS 0.993), CVE-2021-29441/29442 (Nacos auth bypass, EPSS 0.696/0.655). All have been in CISA KEV for years; any unpatched instances are high-priority targets.
AI-assisted offensive operations are moving from theoretical to operational. UAT-10147's use of PentestGPT and DeepAudit to automate exploit refinement and post-exploitation at scale across 170,000 targets marks a shift in how commodity threat actors operate. Meanwhile, the Iran-UK power plant incident reinforces that distributed critical infrastructure, often operated by smaller entities with limited security budgets, remains a soft target for state-affiliated groups testing operational disruption capabilities.