Risky Bulletin: BGP hijack targets Virtualizor to deliver malicious updates
In other news: White House launches Project Watershed 250; Indian authorities take down Telegram doxing bot; Composer packages deliver iOS badness.
This newsletter is brought to you by Dropzone. You can subscribe to an audio version of this newsletter as a podcast by searching for "Risky Business" in your podcatcher or subscribing via this RSS feed. You can also add the Risky Business newsletter as a Preferred Source to your Google search results by going here.
An unidentified threat actor has pulled off a successful BGP hijack that commandeered some of the IP address space and internet routing for software company Softacolous to deliver malicious updates for the Virtualizor web hosting management platform.
The BGP hijack took place for almost 33 hours, from Friday to Sunday last week.
The Virtualizor team says the hacker performed the BGP hijack, obtained a TLS certificate in its name, and hosted a clone website that delivered the malicious updates.
"At approximately 20:57 UTC on 28 August 2026, the network AS62390 (NexonHost) began announcing 162.55.80.0/24 — a portion of Hetzner’s address space containing IP addresses for a number of Softaculous systems — without authorization, routed through the transit provider AS6204 (Zet.net). This announcement was more specific than Hetzner’s normal announcement of the surrounding block (162.55.0.0/16), so under standard BGP route selection it took precedence on every network that accepted it. The announcement retained AS24940 (Hetzner) on the AS path as the apparent origin."
Virtualizer says it can't tell how many users were affected by the incident because it didn't see or log any of the hijacked traffic, which passed exclusively through the attacker's infrastructure.
The company also warns that users who made payments on the site during the attack most likely get their financial data stolen as well, but it's unclear if the hackers were even trying to collect such information in the first place.
Virtualizor is typically used by web hosting companies to manage virtual private servers (VPS) rented to customers.
The company didn't attribute the attack.
Taking a look at this BGP hijack of 162.55.80.0/24 that targeted Virtualizor in recent days. Hijackers forged the origin to make the route RPKI-valid: ... 6204 62390 24940 (hijack AS path) ... 24940 (legit AS path) More from the victim here: www.virtualizor.com/blog/securit...
— Doug Madory (@eldomador.bsky.social) September 1, 2026 at 1:00 AM
[image or embed]
Risky Business Podcasts
In this edition of Between Two Nerds, Tom Uren and The Grugq talk about how AI is the perfect hacker, but what makes it perfect for states is the opposite of what makes it perfect for criminals.
Breaches, hacks, and security incidents
Tectonic hacked for $75m: A hacker has attempted to steal $75 million worth of crypto tokens from the Tectonic DeFi platform. The attacker exploited a bug in the Cosmos blockchain platform, on which Tectonic runs. The hacker initially made off with $74 million but Tectonic clawed back $68 million in the hours after the hack. The same Cosmos bug was also exploited last week to steal almost $3 million from six other platforms. Cosmos said it fixed the bug last week but halted all activity after the Tectonic incident. [Tectonic // Peckshield // CCN // Cosmos post-mortem]
METR discloses two hack: AI model evaluation service METR has disclosed two security breaches that took place earlier this year. A hacker stole an API key and consumed credits worth $600,000 in March, and then a second group probed METR public infrastructure in May. The company says the incidents impacted backend infrastructure and no sensitive data was accessed. METR is currently helping both Anthropic and OpenAI investigate security incidents where their cyber models escaped test environments and hacked real companies. [METR]
DOD refrigeration hacking rumors: There's some heavy speculation going on right now that a widespread disruption that affected the food refrigeration systems at half-dozen commissaries on US military bases might be a cyber attack. [Military Times // Signal and Science // DysruptionHub]
Tate War Room leak: A security researcher has found more than 100,000 files leaking from Andrew Tate's multimedia business. The leaked files contained staff chats, videos from private events, and 76 paid course videos from Tate's War Room program. The courses taught members how to approach women, bribe police and government officials, and spy and exploit rich and powerful people. The files have been made available for download via the DDOSecrets portal. [SAN // DDOSecrets]
General tech, AI, and privacy
BlueSky adds a feature for less visibility: BlueSky has released a new feature that lets users hide their content from non-followers and the platform's algorithms, allowing users to remain more private and avoid going viral. [BlueSky]

Anthropic pauses cyber model evaluations: Anthropic has temporarily paused external cyber evaluations of its pre-release models. The company cited recent incidents where cyber models escaped their test environment and hacked real companies. Anthropic also paused reinforcement learning for some models to shore up monitoring. OpenAI also paused reinforcement learning after its agents hacked Hugging Face last month. [Anthropic]
This is a substantive post that people should read in full. Similar to OpenAI more recently, Anthropic previously did a pause on certain kinds of higher-risk RL environments for "several weeks."
— Nathan Calvin (@_NathanCalvin) August 31, 2026
The additional discussion on pacing is also noteworthy https://t.co/TSzmPKbV8O pic.twitter.com/mlXAbsVatU
Microsoft warns of buggy Defender alerts: Microsoft has told users to ignore alerts saying that Defender was turned off that are appearing shortly after installing the latest update. [Microsoft Support]
Ad-tech is a danger to journalists: A Harvard research paper warns that the same ad-tech surveillance platforms that can be used to track politicians for assassinations and to expose spies and military movement can also be used to spy on journalists and unmask their sources. [Harvard Kennedy School]
Dutch GDPR fines to go public: The Dutch data protection agency will now make all GDPR-related fines and sanctions public, joining other EU countries that share this information with the public by default. [Autoriteit Persoonsgegevens]\
More DSA members: The EU says that ChatGPT, Reddit, and Roblox have a large enough of an EU user base to fall under the provisions of the Digital Services Act (DSA). [European Commission]
Rust gets perma-maintainers: The Rust Foundation has hired its first six full-time maintainers to help ship updates and fixes on a more rapid pace. [Rust Blog]
SweepLED: A team of South Korean academics have developed a $7 phone-case that uses embedded LEDs to detect cameras hidden inside hotel rooms or rented properties. The phone uses a special app to illuminate an object from different angles and analyze reflections to spot hidden lenses. The device recorded a 94% accuracy during testing. [KAIST]

Government, politics, and policy
Project Watershed 250: The White House has launched a pilot program to protect the water sector from foreign hackers. The Project Watershed 250 program will connect water utility providers with cyber defense resources at no cost. The program will run for a six-month test phase in Texas before a possible expansion to other states. [Office of the Texas Governor]
US government to move to Login.gov in two years: The White House will require all government agencies to switch to the Login.gov platform as the default user authentication method for public-facing websites. According to a memo from the Office of Management and Budget, agencies have two years to make the switch. The US launched Login.gov in 2017 and has been slowly developing the platform to withstand current threats. [FNN]
Florida and Texas turn on Flock: The US states of Florida and Texas have taken steps against license plate reader and mass video surveillance company Flock. The Florida Department of Transportation has revoked permits for Flock cameras and license-plate readers and ordered agencies to remove all devices within the next 30 days. Texas Governor Greg Abbott has ordered agencies to pause all financing for Flock contracts pending an investigation. In recent months, the cameras have become the centerpiece in anti-AI surveillance and anti-government surveillance. [Orlando Sentinel // The Texas Tribune]
Secrecy order reform passes US House: The US House of Representatives has passed a bill that reforms the use of non-disclosure orders (NDOs) by US law enforcement. The NDO Fairness Act allows telcos and tech companies to notify all users whose data was subpoenaed and then placed under a secrecy order. Under the bill, non-disclosure orders are limited to 90 days, for both citizens and Members of Congress alike. The NDO Fairness Act passed unanimously in the US House and is headed for the Senate. [Rep. Scott Fitzgerald // Microsoft]
FSB warns of AI cyber risks: The Financial Stability Board, an international body that monitors the global financial system, has sent a letter to G20 leaders warning that frontier AI models pose an immediate risk to the global financial system. [FSB // The Record]
Sponsor section
In this Risky Business sponsor interview, James Wilson chats with Dropzone AI’s founder and CEO Edward Wu to debunk the adage, "an attacker only has to be right once."
Arrests, cybercrime, and threat intel
Indian authorities take down Telegram doxing bot: Indian authorities have taken down a Telegram bot that allowed threat actors to get detailed personal information on any Indian citizen for as low as 6 US cents. The platform returned extremely detailed information on personal data, vehicle ownership, employment information, and financial details. According to security firm Cyderes, the platform ran using legitimate credentials of at least three KYC providers, blending its queries inside their traffic. The company also linked the platform to a threat actor named MRXISBACK. [Cyderes]
Five Venezuelan plead guilty to ATM jackpotting: Five Venezuelan nationals pleaded guilty to hacking ATMs across the state of Kansas. The group installed malware on the device to force them to dispense their cash in what's known as an ATM jackpotting attack. The suspects were detained last December as part of a major bust of Venezuelan ATM jackpotting groups. [DOJ]
VantaCore profile: A new pro-Ukrainian hacking group is targeting Russian companies with ransomware. According to Russian security firm F6, the group has hit at least seven victims and has demanded ransoms worth millions of US dollars. The group uses its own custom ransomware and appears to include members from previous, older Ukrainian hacker groups. [F6 on Habr]
BREEZE COMET profile: Google has published a profile on BREEZE COMET, an e-crime group that has been targeting organizations tapped into Brazil's payment systems (Pix, STR, and Boleto) since 2024 to steal funds right from the source. The group is also known as UNC5669, Plump Spider, and SHADOW-AETHER-064. [Google // Trend Micro // Infoblox]
Spring Ring campaign: A hacking group has targeted more than 150 employees across at least 10 companies as part of a coordinated social engineering campaign. The hackers used external Microsoft Teams accounts to contact employees posing as IT help desk personnel. The attacks attempted to trick employees into installing malware or legitimate remote management tools that could be used for future access. The campaigns took place between January and April. Palo Alto Networks tracks this group under the name of Spring Ring. [PAN Unit42]

AWS password spraying campaign: A password spraying campaign has targeted the root user accounts of AWS tenants. The campaign began on July 24 and targeted at least 150 organizations. Cloud security firm Datadog says the attackers used a list of valid email addresses for AWS root user accounts. [Datadog]
AppPanda campaign: Intel471 researchers spotted a major phishing operation last month that used fake movie streaming apps to trick Mexican users into installing an Android RAT on their phones. The campaign appears to be run by Chinese-speaking threat actors. [Intel471]
SVG smuggling campaign: Kaseya's INKY team has spotted a massive email spam campaign using SVG smuggling to assemble a phishing page right in the user's browser. [Kaseya]
Composer packages deliver iOS badness: A cluster of 13 Composer packages are injecting malicious JavaScript code on websites built by Vietnamese developers. The code secretly shows websites visitors unwanted ads, redirects them to gambling sites or runs an iOS exploit that installs spyware on their smartphone. The spyware can steal passwords and cryptocurrency wallet seeds. Apple patched the exploit last November, with iOS 26.1. [Socket Security]
Faronics Deploy Abuse: Threat actors are abusing boobytrapped Faronics Deploy, a legitimate endpoint management platform, to execute attacker-controlled PowerShell after phishing victims install the software. [Huntress]
Operation RepoGhost: Security researchers have found a cluster of 52 malicious GitHub repositories that are spreading various payloads from loaders to infostealers. [Avyukt Security]

TeamPCP unmasking: Threat intel firm Flare has published its own investigation on how its researchers tracked down the real identities of TeamPCP members, who were arrested by Australian police last week. [Flare]

Malware technical reports
RevStealer: A cluster of GitHub repositories and game-cheat-themed sites are spreading apps infected with a new infostealer named RevStealer. [Morphisec]
ValleyRAT: Kaspersky noted a new tactic being used to deliver SilverFox's ValleyRAT, hiding the malware together with adware and PUPs. [Kaspersky]
New detections for that tiny mysterious backdoor: Earlier this month, GenDigital found a tiny backdoor that was used only once to infect a victim in the UK, suggesting this was a very targeted attack on a very specific target. ESET now says it also detected the same backdoor between November 2020 and November 2023 in attacks targeting the financial services sector in the Netherlands and Kazakhstan. [ESET // GenDigital]
JSCeal: Check Point has spotted new versions and infrastructure related to JSCeal, a malware strain used to target cryptocurrency users. Its name comes from the fact that it is delivered as a compiled V8 bytecode JSC file. [Check Point]
Gryxa: ReliaQuest has discovered Gryxa, a tool that enhances legit RMM tools for post-compromise operations, with features such as persistence, EDR blocking, and data collection and exfiltration. The tool appears to have been coded using AI. [ReliaQuest]
BraZetsu: Security researchers have identified BraZetsu, a new Python-based Windows malware framework developed by a Brazilian threat actor known as Exilware and used as a tool for initial access operations across LATAM. Compromised systems are later sold on a special marketplace. [Group-IB]
GOLD SHERWOOD: Sophos has published insights from 15 intrusions that deployed The Gentlemen ransomware, which the company tracks as GOLD SHERWOOD. [Sophos]
SuperProxy botnet: New research from the Plume team has discovered that the SuperProxy botnet they discovered back in May is involved in more shenanigans than just running a proxy botnet, now also working as a malware loader for other cybercrime groups. So far, SuperProxy has dropped payloads like Mirai, Maskify, and Cecbot. [Plume]

QTFY botnet: Last week, the DOJ seized a botnet used by Chinese state-sponsored hackers to attack US organizations. ZeroTrace has published a deep dive into how the botnet was organized and run. Several security firms have described QTFY as a "digital quartermaster" for MSS and PLA cyber contractors. [ZeroTrace Lab]

Sponsor section
In this sponsored product demo, Dropzone founder and CEO Edward Wu walks Risky Business podcast host Patrick Gray through the company's AI SOC analyst.
APTs, cyber-espionage, and info-ops
UNC3886's FireAnt campaign evolves: A cyber-espionage group tracked as UNC3886 has continued to be active in 2026 after its initial exposure last year. The biggest change is the group's evolution from targeting hypervisor infrastructure to also going after routers, authentication infrastructure, and Linux systems as a way to maintain persistence, additional collection, and launch new attacks. [Sygnia]
Mirage Kitten targets fintech with new malware: Iranian APT group Mirage Kitten is using two previously undocumented RATs named NodeRabbit and PollCat in a campaign targeting fintech and aviation companies across Africa and the Middle East. The APT is also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore. [Kaspersky]
Blind Eagle's GitHub loader: Researchers analyze a malware loader spread via boobytrapped GitHub projects, supposedly used by the Blind Eagle APT. [LevelBlue]
Lazarus moves more crypto funds: Digital wallets associated with North Korea's Lazarus Group laundered more than $30 million worth of Bitcoin through the Hyperliquid platform over the past three weeks. [Blockonomi]
Vulnerabilities, security research, and bug bounty
Security updates: Composer, GeoNetwork, JFrog, Proxmox, Qubes OS, Renovate, SonicWall, Ubuntu.
GreenSection and PrettyPrague zero-days: Security researcher Nightmare Eclipse has published two more zero-days on GitHub. The first gives full R/W access to the operating system via Nvidia GPU drivers. The second grants attackers SYSTEM access to the OS via the Avast antivirus. The two are named GreenSection and PrettyPrague, respectively. This is the researcher's third zero-day in as many days after they also published in Kaspersky's EDR as well. [GreenSection // PrettyPrague // HardBreacher]
Artifactory bug exploited in the wild: Threat actors are exploiting a recently patched vulnerability in JFrog Artifactory artifact repository management servers. The bug allows attackers to bypass authentication and gain admin access over servers. According to security firm WatchTowr Labs, exploitation began three days after a patch was released last week. The vulnerability is different from the one exploited by OpenAI agents to hack HuggingFace in July. [JFrog patches // WatchTowr // CVE Reports on CVE-2026-82329]
Sangoma Switchvox exploitation: Hackers are exploiting an SQL injection vulnerability in Sangoma Switchvox VoIP telephony servers. Attacks were spotted last week after patches were released in July. Exploitation does not require authentication. [Horizon3 // CVE-2026-9586 patch]
New Langflow attacks: Threat actors are exploiting another Langflow vulnerability to hijack AI servers and steal OpenAI and AWS keys. This one is CVE-2026-0768, which never received a patch. [Caitlin Condon on LinkedIn // CVE-2026-0768]
GeoNetwork vulnerabilities: The GeoNetwork project has released security updates on Monday to patch four vulnerabilities that can be used to take over servers. The project provides a web interface for viewing custom geospatial maps. It was developed by the UN's Food and Agriculture Organization and is commonly used by government agencies across the world for record-keeping and public-facing services. Security firm Etiack has identified vulnerable servers in 39 countries, used for government, military, and academic purposes. [Etiack]
"Originally developed at the UN's FAO, it has become a core component in many Spatial Data Infrastructure initiatives across Europe and beyond. If you've browsed a national or regional geoportal, there's a real chance GeoNetwork was helping serve the metadata underneath."
Secure disk bugs impact ATMs: German company CryptWare has released security updates to patch nine vulnerabilities in the CryptoPro software. The software is typically used with ATMs and other Windows-based embedded devices. The bugs can be exploited to bypass disk encryption and pre-boot authentication and read cleartext data from the devices. Major ATM vendors like Diebold Nixdorf have already rolled out patches. [WIRED // BlackHat, PDF]

Infosec industry
Threat/trend reports: F6, Neon Cyber, Omdia, and Prophet AI have recently published reports and summaries covering various emerging threats and industry trends.
New tool—OpenClaw 2.0: Version 2.0 of the OpenClaw open-source AI assistant has been released over the weekend. [OpenClaw]
New tool—Red Clippy: The Cyber Security and Privacy Foundation has open-sourced Red Clippy, an open-source pentest management platform built to be operated by an AI agent.
Acquisition news: Palo Alto Networks has acquired Console, an AI agent workflow startup. [Palo Alto Networks]
Risky Business podcasts
In this episode of Risky Business Features, James Wilson chats with Brian Krebs about the investigation that led him from recycled cybercrime handles and old forum records to the true identity of TeamPCP’s alleged leader in Perth.