investigations

Winsage
August 17, 2026
A suspected advanced persistent threat (APT) group linked to China exploited a newly patched vulnerability in VMware vCenter (CVE-2026-59310), which has a critical CVSS score of 9.8, allowing for arbitrary code execution and the deployment of Babuk-derived ransomware. A recently patched vulnerability in Apple macOS (CVE-2026-65400) has been exploited to deploy a cryptocurrency miner, granting unauthorized root access. The Lazarus Group from North Korea exploited a zero-day vulnerability in Microsoft Windows, targeting defense and aerospace sectors. GeoServer patched a critical SQL injection vulnerability that was actively exploited. A new macOS malware, Amnesia Stealer, targets users through ClickFix attacks, stealing data and allowing real-time access to authenticated sessions. A novel attack technique named GhostSplice can manipulate AI coding assistants. Research revealed a method exploiting Chromium's DevTools Protocol for data theft. Noteworthy CVEs this week include CVE-2026-68820, CVE-2026-58231, and multiple others across various platforms. A high-severity command injection flaw in FileRun allows remote code execution. An advanced ClickFix attack has been reported, deploying sophisticated malware. A heap overflow vulnerability in Citrix NetScaler was patched after indications of exploitation. A new malware loader targeting Portuguese-speaking users has been identified. A significant reduction in exposed Automatic Tank Gauge systems has been observed. A phishing campaign targeting Brazil has been detected, and an F.B.I. agent faces charges for unauthorized crypto withdrawals. Authorities in Ukraine dismantled fraudulent call centers, and a North Carolina man was sentenced for cyber extortion. Unauthorized access to sensitive data by the ExfilSquad group has been confirmed. LightSpy activity linked to China has been detected in over 13 countries. A supply chain attack exposed over 2,500 companies, and an Azure exfiltration campaign has exposed millions of enterprise records.
Winsage
August 14, 2026
CoolClient is a sophisticated backdoor family linked to the HoneyMyte APT group, actively used in cyber-espionage campaigns targeting organizations in Asia and Russia since its initial disclosure in 2022. It has capabilities such as keylogging, clipboard theft, credential harvesting, and system reconnaissance. Investigations in 2023 revealed enhancements, including clipboard theft and HTTP traffic interception. By late 2025 and into 2026, a variant was noted that could deploy a signed kernel-mode driver as a Windows service, improving its stealth and operational capabilities. In a recent campaign targeting Myanmar, the HoneyMyte group used PlugX to deploy CoolClient components. They configured Microsoft Defender to exclude a fake Windows Defender installation directory and a renamed executable, defender.exe, to avoid detection. Persistence was achieved through a scheduled task that executed defender.exe with SYSTEM privileges at startup, which sideloaded the malicious libngs.dll to initiate the CoolClient execution chain. The latest CoolClient variant has a multi-stage execution chain, including: - defender.exe / Sang.exe: Exploited legitimate application for DLL sideloading. - libsrapc.dll: Benign dependency for the Sangfor application. - libngs.dll: First-stage loader that decrypts and loads the next stage. - loadcert.ini: Second-stage DLL implementing core functionalities. - cert.ini: Final-stage implant for command and control communication. - time.ini: Configuration file for CoolClient. The execution begins with the legitimate Sangfor application loading libngs.dll, which uses obfuscation to conceal its operations. The second stage, loadcert.ini, is injected into synchost.exe and performs tasks including persistence and process injection. The kernel-mode driver deployment routine involves decrypting time.ini, verifying privileges, and creating a service to execute the driver, enhancing stealth. The deployed kernel-mode driver, msagent.sys, is digitally signed and helps hide processes, files, and registry objects, making detection more difficult. The latest variant continues to target organizations consistent with previous HoneyMyte activities, with confirmed victims in Myanmar, Mongolia, Pakistan, and Russia, including government entities. The deployment of CoolClient as a secondary backdoor after a PlugX infection indicates a strategic approach to maintain access to compromised systems. The malware is confirmed as a new variant of CoolClient associated with the HoneyMyte threat group, with the kernel-mode driver marking a significant advancement in its capabilities.
Winsage
August 13, 2026
Nightmare Eclipse has released a new zero-day exploit called ShieldBreak, which can bypass Microsoft's RoguePlanet patch (CVE-2026-50656) and allow attackers to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems. The exploit has been confirmed by security expert Kevin Beaumont, who provided detection methods for it. ShieldBreak is the tenth zero-day from Nightmare Eclipse since April and was released shortly after Microsoft's monthly Patch Tuesday. The exploit allows local privilege escalation and has a 100% success rate on the latest version of Windows 11 and Windows Server 2025, while Windows 10 remains vulnerable. Microsoft is aware of the vulnerability and is investigating it, emphasizing the importance of coordinated vulnerability disclosure. Previous exploits from Nightmare Eclipse include LegacyHive and GreatXML, with earlier vulnerabilities having been patched but recent ones still unaddressed. Microsoft had threatened legal action against Nightmare Eclipse in May but later reconsidered its approach to vulnerability disclosure.
Tech Optimizer
August 13, 2026
Users of Chromium-based browsers, including Google Chrome, Brave, and Opera, are experiencing deceptive pop-ups that falsely claim a "Critical Update Required" or "Update available." These notifications are part of a scam designed to trick users into downloading malware disguised as software updates. Clicking on these prompts can lead to the download of harmful scripts, such as .vbs or .exe files, which traditional antivirus software often fails to detect. The issue is linked to compromised browser extensions that fetch malicious scripts from external servers. A specific extension, QuickLens – Search Screen with Google Lens, has been identified as a source of these pop-ups and has been removed from the Web Store. Other extensions, like “Enable Right Click & Copy Smart Unlock + OCR,” have also been implicated despite their popularity. Users are advised not to click on any links or run downloaded files and to check their browser settings for legitimate updates, as well as to audit and disable suspicious extensions.
AppWizard
August 9, 2026
Toronto has seen an increase in gunfire incidents aimed at the U.S. consulate, leading to the arrests of a 19-year-old and a 15-year-old. These incidents are linked to alleged gun-for-hire plots that also target Jewish schools, synagogues, and waste management facilities in the Greater Toronto Area. Investigators are facing difficulties in identifying the masterminds behind these operations, partly due to the use of encrypted messaging apps to recruit young individuals. The federal government's Bill C-22 aims to provide law enforcement with tools to address these challenges, but it has faced criticism for potential overreach and privacy concerns. Police Chief Myron Demkiw emphasized the need for effective tools to prevent violence facilitated through encrypted communication. Technology analyst Carmi Levy raised concerns about balancing law enforcement needs with privacy rights. Additionally, there is a societal responsibility to protect children from online recruitment by criminal networks, with calls for proactive conversations between parents and children and educational initiatives in schools.
AppWizard
August 6, 2026
A report from the Electronic Frontier Foundation (EFF) highlights concerns about third-party software development kits (SDKs) in mobile applications collecting and sharing user location data with advertising companies, often without user consent. Many developers use these advertising SDKs for monetization, but their default settings allow for location data collection. This data is sent to advertising companies and location data brokers, which can misuse it in sensitive contexts. Users may unknowingly expose their location data when granting permissions to apps, as third-party SDKs can access this information without clear user awareness. The EFF identified several advertising SDKs, including InMobi, BidMachine, Verve’s HyBid, and Huawei’s Petal Ads, that collect and share location data by default. Developers are encouraged to review SDK settings to protect user privacy, and the EFF calls for regulatory scrutiny of data harvesting practices.
AppWizard
August 5, 2026
Advertising companies provide software development kits (SDKs) for mobile app monetization, which often automatically transmit users' location data to ad systems and location data brokers, raising privacy concerns. Many developers and users may be unaware of this data sharing. When developers allow SDKs to collect location data, it poses risks beyond targeted ads, including potential misuse by agencies like ICE and global surveillance. Location data brokers harvest precise movements of individuals, often without their consent, through mobile applications. Some apps directly collaborate with data brokers, while others leak data through advertising SDKs during real-time bidding (RTB) auctions. An incident in 2025 revealed that many apps unknowingly contributed to a location data broker's database. Developers must understand their SDKs' location-sharing practices to mitigate risks. Advertising SDKs can collect location data automatically once users grant permission, without specific permissions for the SDKs themselves. Precise location data can be collected when apps have location permissions, leading to potential privacy violations. Several SDKs have been identified as collecting location data by default, increasing the risk of unintentional data leaks. The Electronic Frontier Foundation (EFF) found that four advertising SDKs collect users' location data by default when location permissions are granted. InMobi encourages location sharing for higher revenue, while BidMachine updated its documentation after EFF's inquiry, confirming precise location data collection. Verve's SDK also collects location data by default but presents a cautious narrative in its Play Store guidance. Huawei's SDK recommends obtaining location permissions to enhance revenue, with default location sharing occurring if permissions are granted. Location data can be shared without users' knowledge or meaningful consent, complicating informed consent issues. The focus on four SDKs does not imply that others adequately protect location data, as many have faced criticism for similar practices. Studies indicate that SDKs often encourage increased data collection through design and documentation, leading to minimal control for developers over data transmission. The EFF's analysis highlights that advertising SDKs incentivize location data sharing through default settings and unclear documentation. Developers should assess third-party SDKs and disable unnecessary data collection. Regulators must hold developers accountable for unlawful data sharing, while legislators should enact laws to protect location privacy and address online behavioral advertising, which drives data tracking.
AppWizard
August 4, 2026
Security researchers found that several Samsung Smart TV applications, including Pac-Man, were embedding residential proxy SDKs from data brokers like Bright Data. In response, Samsung has banned the inclusion of residential proxy functionality in new app submissions and is working to remove existing apps with such software. The investigation by Norwegian cybersecurity firm Mnemonic revealed that the Bright Data SDK was integrated into various gaming applications, some promoted by Samsung. While Samsung TVs were not automatically sharing internet connections, the SDK could be activated remotely by developers, requiring user consent. Once consent was granted, the proxy service could operate in the background. Many Samsung TV applications were found to download most of their code from remote servers, complicating verification processes. The issue of residential proxy software is not limited to Samsung, as it has also been identified in various Android apps and devices. Following these findings, LG and Google have also taken measures to address the risks associated with residential proxy networks.
Search