Thread 🧵
1/ 🚨 NEW RESEARCH: We identified a training program provided to government employees in Angola by the Israeli influence-for-hire company BlackCore.
Full report: https://t.co/ABjWCO1jrr
Black Lotus Labs reported BambooToken uses MQTT to secretly control Windows and Linux devices across Asia, enabling broad data collection and stealthy C2 with Cloudflare routing and multi-target campaigns. https://t.co/vuGTaTc9EX
Group-IB linked the Telegram-based Windows backdoor HEAVYGRAM to Iran-linked Handala Hack, noting its since Fall 2023 use to surveil dissidents and opponents via remote execution, data exfiltration, and Telegram C2 persistence. https://t.co/90dOIKymXB
#ESETresearch discovered SparroWocky, a new backdoor of the #FamousSparrow APT group. This new malware has quickly replaced SparrowDoor as the 🇨🇳 China-aligned group’s flagship backdoor. https://t.co/BOY08qQrTl 1/6
Additional #SilkParasite infrastructure, historically linked to several malware families, including one associated with Seccom (IndigoZebra), a known user of BloodAlchemy who previously targeted Central Asia as well.
The infra also suggests targeting of Iranian victims.
Real pleasure working with https://t.co/XJnrs5L57c on SilkParasite!
My friends at Hunt chose a conservative approach on attribution :)
But guttribution-speaking, SilkParasite looks like the current reincarnation of IndigoZebra as several pivot points lead to ESET’s Speccom >>
⚠️ New Research: Spicerat infrastructure tied to energy and government targets across Central Asi
With the help of Guy Yasur (@Shto_ota), we tracked a cluster of SpiceRAT C2 servers active from late 2025 through August 2026 and connected it to the #SilkParasite infrastructure Bitdefender reported last month.
What we found:
-> A cloned RTX Corporation homepage, reused as a decoy, that pulled 13 servers from a single page hash
-> A TLS certificate from TLC, a Chinese state-funded CA, impersonating Uzbekistan's state railway
-> That same certificate connecting SpiceRAT to NodeEdgeRAT and NomadRAT
-> Domains spoofing Türkmengaz, the Galkynysh gas field, Tojiktelecom, and Turkmenistan's Ministry of Foreign Affairs
-> Passive DNS placing the activity back to at least mid-2022, so four years and counting
Full writeup and indicators 👇 https://t.co/mQKJfRCGQ6
For example: 45.86.162[.]141 (SpiceRAT C2 with hardened RDP) >> mail[.]postmfa[.]com >> 161.129.64[.]122 >> update[.]microsoft-tajikistan[.]com >> Linked to both SpiceRAT (2.58.15[.]184) and Speccom (MD5: 1dde1bb6e0f468d20aad076a53908150)
Which goes back to 2019!
One click was all it took.
We discovered a critical #vulnerability in Sogou Input Method that was actively exploited in the wild by #UNC3569 🇨🇳 to deploy the #GRAYRABBIT backdoor. Three separate weaknesses chained into a single RCE exploit.
Read our research:
https://t.co/jE4fO1kl2j
🚨 CISCO FIREWALL MANAGEMENT SERVERS ACTIVELY EXPLOITED — APT + QILIN RANSOMWARE ACTIVITY OBSERVED
Cisco Talos is warning of active exploitation targeting Cisco Secure Firewall Management Center (FMC) systems.
Two vulnerabilities are being abused in the wild:
* CVE-2026-20079 — CVSS 10.0
Critical authentication bypass allowing an unauthenticated remote attacker to execute scripts and obtain ROOT access.
* CVE-2026-20316 — CVSS 5.3
Allows remote login using a low-privileged account and can be chained with other FMC vulnerabilities to elevate privileges.
Talos has identified THREE separate post-compromise activity clusters.
🚨 CLUSTER #1 — UAT-12197
Attackers exploited CVE-2026-20079 and deployed:
* JSP web shell
* Malicious JAR command executor
* Credential harvesting
* Queries against FMC internal databases to extract authentication data
🚨 CLUSTER #2 — APT / CYCLOPS BLINK
Talos attributes the second cluster to UAT-11823, an APT actor whose tooling overlaps with Sandworm.
The attackers exploited the FMC vulnerabilities and deployed:
* Netcat reverse shells
* Malicious package files
* Configuration harvesting
* Credential theft
* Cyclops Blink malware
Cyclops Blink is malware previously attributed to Russia's Sandworm by U.S. and UK authorities.
The implant supports persistence, DNS-over-HTTPS resolution, file transfer, credential harvesting, arbitrary command execution, network reconnaissance and packet sniffing.
🚨 CLUSTER #3 — QILIN RANSOMWARE
Talos assesses with HIGH CONFIDENCE that UAT-11988 is a ransomware operator.
The actor gained access to an FMC device using static credentials associated with CVE-2026-20316 and then used legitimate FMC tooling to move deeper into the environment.
Activity included:
* Extensive internal reconnaissance
* Active Directory credential harvesting
* Domain enumeration
* MySQL credential theft
* SOCKS5 proxy deployment
* Reverse SSH tunneling
* Impacket
* Invoke-TheHash
* Custom AV killers
* Identification of endpoints for encryption
The intrusion ultimately resulted in deployment of Qilin ransomware on selected endpoints.
Talos says the actor's TTPs were consistent with Qilin ransomware affiliates.
⚠️ Analyst Note:
This is exactly why compromise of security infrastructure can be disproportionately dangerous.
FMC isn't simply another server.
It manages the security controls protecting the network.
Once an attacker obtains privileged access to the management plane, the security appliance itself can become:
Initial access
→ Credential harvesting platform
→ Network reconnaissance point
→ Internal pivot
→ Tunneling infrastructure
→ Ransomware staging point
Cisco has already released hotfixes and strongly recommends applying them immediately.
A broader Secure Firewall hardening release covering FMC, ASA and FTD is scheduled for September 16.
Organizations running Cisco Secure FMC should treat this as an ACTIVE EXPLOITATION event — not simply another vulnerability disclosure.
Official source — Cisco Talos:
https://t.co/XBjP1YWc9H
Cisco Security Advisory:
https://t.co/RZHoXIDxyG
#DDW #Cisco #Qilin #Ransomware #CyberSecurity
Gen Threat Labs discovered a critical remote code execution vulnerability (CVE-2026-51990) in Sogou Input Method. The vulnerability is actively exploited in the wild by the UNC3569 threat group to deploy the GRAYRABBIT backdoor through a crafted link. https://t.co/vi9GacWoZa
We're publishing our most detailed threat intelligence report to date.
It covers how people tried to misuse Claude—for cyberattacks, influence operations, surveillance, biology, and building weapons—and how we found and stopped them.
We disrupted every operation in the report, and used the lessons from them to strengthen our safeguards. Where appropriate, we also shared what we found with authorities and other AI companies.
These cases are not typical: we’re highlighting some of the most sophisticated misuse we’ve seen. But they’re especially important to discuss, because they show us where AI misuse is headed, where our safeguards work, and where they need to improve.
We’re publishing this report so others can spot the same activity on their own platforms, and so we can give the public a clearer view of how emerging threats develop.
Read the report: https://t.co/0EJUnYEgfz
great report by the folks over at @AnthropicAI - their GTG-20006 aligns with our UNC7005 and they've included some particularly juicy details about their operations here 👀 https://t.co/dIDYra0s48
Earlier this month, @Volexity detected multiple Chinese threat actors launching attacks against its customers using chained 0-day exploits in Google Chrome (CVE-2026-85046 & CVE-2026-87491) and Microsoft Windows (CVE-2026-85880). Volexity observed threat actors it tracks as UTA0560 and JungleBamboo using variations of the same exploits to deliver different malware implants. These implants ranged from a JScript backdoor (GRIMWEDGE) to a fake Google Gemini Chrome extension (LONGTALE).
Read the full analysis of the exploit chain and post-exploitation tradecraft here: https://t.co/BwRWNvsk6b
#DFIR #threatintel
Heard about those zero days in Chrome and Windows? Well, @markkelly0x found them being used in the SAME exploit kit, proliferating across the APT ecosystem.
Meet BlueMoon exploit kit:
https://t.co/AI3s64MJi1
Heads up, there is a 1-day full MikroTik RCE chain against SSH being used in the wild. Patch was released yesterday, so if you have a MikroTik router with ssh open on the internet, it may already be compromised. Detection guidance and IOCs courtesy of @CERT_Polska_en https://t.co/9RDSNxp3xD
Fileless execution on Linux still leaves (a lot of) observable behavior.
My latest research identifies five common patterns and maps each to the telemetry and detection rules that underlie them.
Read it here ↓
https://t.co/D0YPRmpiP4
The first piece of data we got was what seems to be a ransomware *panel in development*, not for creating payloads - for receiving the the stolen encrypted data and decrypting it.
From local banking trojans to foreign 🇨🇳 operators targeting Brazil 🇧🇷.
CPR uncovered #GamblingGoblin, a Chinese-speaking actor abusing Brazilian government sites for large-scale #SEO fraud.
Read more 👇: https://t.co/uzfFajajyf