daily cyber × ai intelligence

index

tagged

[contagious-interview]

5 editions · 4 items

August 4, 2026

  • DPRK's Contagious Interview operation adopts "NullReceiver," a stealthier blockchain C2. Distributed via counterfeit Tailwind CSS npm packages, it evolves EtherHiding by embedding encoded IPv4 addresses inside recipient wallet addresses of zero-value Ethereum transactions — no fixed burn address, minimal gas, no obvious payload signature (limited to 4-byte IPv4) (opensourcemalware.com). · Threat Activity

in Attackers Seize N-central RMM Servers After N-able's Second Fix Falls Short

June 19, 2026

FortiBleed Burns 70,000+ Fortinet Edge Devices While a Leaked GitHub Token Guts Novo Nordisk

FortiBleed exposed working SSL-VPN credentials for 70,000+ Fortinet devices across 194 countries via industrialized hash-cracking by a Russian-speaking group, while a forgotten GitHub token cost Novo Nordisk 1.3TB of drug formulas and internal AI models. Critical vulnerabilities in NGINX (CVE-2026-42530), Cisco SD-WAN and ISE, Splunk, and Joomla are under active exploitation, alongside AI pipeline supply-chain attacks hitting Mastra, JetBrains Marketplace, and Google Vertex AI. The AtomicArch campaign compromised ~1,500 Arch Linux AUR packages with Rust infostealers and eBPF rootkits.