Risky Bulletin: Russia is behind the recent hotel WiFi hacks
In other news: Anthropic models also did the hacky-hacky; npm adds publish-time malware scanning; Coldcard hacked for $70 million.
This newsletter is brought to you by Permiso Security. You can subscribe to an audio version of this newsletter as a podcast by searching for "Risky Business" in your podcatcher or subscribing via this RSS feed. You can also add the Risky Business newsletter as a Preferred Source to your Google search results by going here.
A Russian state-sponsored hacking group is behind a recent hacking wave that has targeted and compromised hotel WiFi gateways across the globe.
Microsoft says the campaign is far larger and more complex than it was initially covered in a ReliaQuest report two weeks ago.
ReliaQuest said the hackers were modifying DNS traffic on hotel networks to redirect users to Microsoft-themed phishing sites. Microsoft says the attacks also redirected users to malware downloads, often using ClickFix pages to trick users into downloading and running the payloads.
Microsoft says the campaign was also more widespread and also compromised WiFi gateways at all sorts of organizations, and not just hotels and conference centers.
When users were directed to malware downloads, the final payloads were two new strains—the CornFlake RAT and CocoShell, a PowerShell-based infostealer. These two also communicated with FruitStone, a never-before-seen command-and-control panel.
When users were redirected to phishing sites, the attackers sought to steal device codes and OAuth codes for Microsoft Entra accounts, so they could bypass MFA and harvest data from a target's Microsoft account and inbox.

Microsoft linked the attacks to Storm-2945, which it described as a smaller group part of the larger Midnight Blizzard cluster.
Midnight Blizzard itself is an old Russian hacking group more commonly known as APT29 and Cozy Bear, a renowned cyber unit inside Russia's Foreign Intelligence Service, the SVR.
This particular campaign apparently started in May and is not connected to FrostArmada, which is another Russian hacking op that involved hacking a bunch of MikroTik and TP-Link routers to redirect users to Microsoft-themed phishing pages. That campaign was the work of APT28 (Fancy Bear, Forest Blizzard), hackers inside Russia's military intelligence service, a completely different agency.
The most interesting thing in the report is that Storm-2945 allegedly used "AI" for some parts of its operation, but unfortunately Microsoft didn't say how or enter into any details.
Risky Business Podcasts
The main Risky Business podcast is now on YouTube with video versions of our recent episodes. Below is our latest weekly show with Pat, James, and special guest co-host Pete Ranks at the helm!
Breaches, hacks, and security incidents
Anthropic models also did the hacky-hacky: Anthropic says its Claude AI model escaped test environments and hacked into the systems of three organisations. In two of the cases, the models exploited vulnerabilities in internet-facing systems while in the third Mythos published a malicious library on PyPI. In this later incident, the victim was a cybersecurity firm. Anthropic says it reviewed Claude activity in light of a similar incident at OpenAI earlier this month. [Anthropic]
Which security company got owned by Claude? pic.twitter.com/T8Wqsc42L7
— Costin Raiu (@craiu) July 31, 2026
Coldcard hacked for $70m: A mysterious hacker has stolen more than $70 million worth of Bitcoin from Coldcard hardware wallets. The attackers exploited a vulnerability in the wallet's firmware that produced weak and easy to guess private keys. Coinkite has admitted the bug and issued a firmware update. The wallet maker has also urged Coldcard owners to generate new wallet seeds after they update. [Bitcoin Magazine // Galaxy Research // Coldcard]
Wemix hacked again: Hackers have stolen $6.2 million worth of crypto-assets from the South Korean blockchain gaming platform Wemix. The attackers allegedly compromised a smart contract that allowed them to mint and exfiltrate new tokens. This is the company's second hack after it also lost the exact same $6.2 million in March of last year. [Chosun Biz // Coin Bureau]
Coupang compensation: South Korea's consumer agency has ordered online retailer Coupang to compensate users affected by a data breach last year. Affected users will stand to receive $70 in cash or story currency. More than 37 million South Koreans had their data stolen in the breach. [The Chosun Daily]
Diater faces ransomware attack: Spanish pharmaceutical company Diater is being extorted by the DeadLock ransomware gang. It's still unclear what type of data the group has stolen. [APD]
HealthStream reports breach: Healthcare software provider HealthStream says a hacker gained access to one of its corporate file servers and stole a limited set of customer data, but apparently no HIPAA-related records. P[SEC filings // MarketWatch // Class Action U] [h/t Zack Whittaker]
DNC falls for BEC scam: A scammer stole $29,000 from the Democratic National Committee in February of last year. The attacker posed as Ken Martin, who was elected as DNC Chairman three days before. The Party caught the error within minutes but only managed to recover only $7,000. [NOTUS]
AI, general tech, and privacy
npm adds publish-time malware scanning: The GitHub security team will scan all packages published on the npm portal for malware going forward. Packages with dual-use code that perform actions that can be interpreted as malicious will also have to declare their intentions through a new metadata field. GitHub is also removing features from npm granular access tokens, also known as GATs. If the tokens are configured to bypass 2FA, the tokens can't perform any sensitive actions against an account and its repositories. [GitHub #1 // GitHub #2]
AWS data center struck in Bahrain: Iran's military has struck an AWS data center in Bahrain, in the second missile strikes against the company this year. Iran previously hit three AWS data centers in Bahrain and the UAE in March. Tehran officials said they targeted the company for its role in supporting the US military in the region. Iran's leadership threatened to target US tech giants in the region if the war continued. [ArsTechnica]
Google pauses Google Earth genAI feature: Google has paused a new AI feature that allowed Google Earth users to generate fake satellite images. The company removed the feature after users generated images of fake missile strikes and spread disinformation. Although they haven't abused this feature so far, both Iran and Russia have a history of using AI to fake territorial gains or successful missile strikes. [NPR // Digital Digging // The Insider]

New SiliVaccine version: Researchers have found a new version of SiliVaccine, North Korea's internal homegrown antivirus engine. Well, not that "homegrown" actually because the engine works on top of ClamAV and Malheur. [North Korean Internet]
ShieldFont tricks AI: Two design companies, S&A and Playtype, have created a font that fools AI scrappers and protects copyrighted text. [Creative Bloq // ShieldFont]

Government, politics, and policy
Cyber Command to open Silicon Valley office: US Cyber Command will open an office in Silicon Valley to build relationships with the US tech sector and take advantage of its innovations. According to The Record, the office's main goal will be to accelerate the Command's cyber weapons and online operations. The office will have its own director but CyberCom has not selected anyone for the role just yet. [The Record]
Iran water hacks impacted seven states: The US government is investigating Iranian hacks of public water utility systems in seven states. Initial breaches were reported across 30 Minnesota communities last week. Michigan officials said they were also hit, but systems remained operational. Another attack was also reported in Rapid City, South Dakota. [CBS News // DysruptionHub]
Telco data breach rules under assault again: A panel of federal judges will rehear 2025 case that upheld the FCC's expanded telecom data breach rules. The new appeal is being pushed by the holy alliance of US telco industry groups and the Republican Party. I find this entire push to deregulate the poor little US telcos extremely ridiculous since they're constantly getting hacked and always trying to hide the intrusions. You'd think some breach reporting regulation would help in this case, and not be treated as a vial of uranium. Alas, the US these days. [Broadband Breakfast] [h/t Databreaches.net]
Telecom industry groups and Republican lawmakers said the court’s previous decision made it harder for Congress to nullify disfavored rules
— Broadband Breakfast (@index.broadbandbreakfast.com.ap.brid.gy) August 1, 2026 at 12:31 AM
[image or embed]
Sponsor section
In this Risky Business sponsor interview, James Wilson chats with Permiso CTO Ian Ahl about detecting ShinyHunters-style attackers as they move through cloud and SaaS environments.
Arrests, cybercrime, and threat intel
SMS blaster arrested in Malaysia: Malaysian authorities have arrested a 23-year-old suspect for driving around with an SMS blaster in his car. The suspect was detained in Johor Bahru, a city on the border with Singapore. Malaysian telcos are required to block SMS messages with links since 2023. Officials suspected an SMS blaster operation and started looking for the suspect after city residents reported receiving messages with links inside. [CommsRisk]
Fake IRS letters: Cybercriminals are sending physical letters to cryptocurrency holders posing as the US Internal Revenue Service. The letters aim to lure users to malicious sites that collect personal data, wallet information, and credentials for crypto portals. [IRS]
TeamPCP profile: The ThreatMon team has published a profile of TeamPCP, the ephemeral hacking group behind a bunch of the recent npm worm non-sense. [ThreatMon]
DPRK remote IT workforce alert: Almost a dozen countries have published (yet another) alert on the threat of North Korean workers getting remote IT jobs at local companies to raise money for the regime and steal IP from victims. [US State Department // FBI, PDF]
INC was behind SonicWall zero-day: The INC ransomware group is using two recent SonicWall zero-days to break into corporate networks. The two zero-days were initially exploited by an espionage group in June. The two bugs allow attackers to bypass authentication and then elevate privileges on the compromised device. SonicWall released patches on July 14. [Resecurity // SonicWall patches]
DarkSword spreads to eight groups: At least eight different threat actors are now using a powerful iOS hacking framework in the wild. The DarkSword framework is one of two iOS hacking kits discovered this year. It leaked online in March and has been slowly getting adopted by Chinese e-crime groups. According to security firm Censys, most of the DarkSword servers are hosted in Hong Kong. [Censys]
Far-right image board builds AI doxing tool: Users of the Soyjak Party far-right imageboard have built an AI model that automatically gathers information to dox desired targets. [Open Measures]
Malicious job interviews: SlowMist looks at one of the countless malicious job interviews targeting Web3 developers, with this particular variation delivering a macOS infostealer. [SlowMist]
NullReceiver technique: Cybercriminals are using a new technique to hide the IP address of command-and-control servers in the blockchain. Called NullReceiver, the technique involves sending zero-value transfers to non-existent blockchain addresses. Decoding the first four bytes of the address from hex to decimal code reveals the IP address to which the malware needs to connect. [OpenSourceMalware]

Malware technical reports
XCSSET: XCSSET, a macOS malware strain spotted in 2020 and which targets users by infecting and spreading through Xcode projects, is alive again and making new victims. The malware has now reached v40. [PAN Unit42]
XMRig botnet: Group-IB has spotted a new cryptomining botnet that's targeting cloud infrastructure and using PAM to hide itself from investigators. [Group-IB]
SakDriver rootkit: Researchers have spotted SakDriver, a Windows kernel-mode rootkit that was initially mistaken for a mundane Cobalt Strike Beacon. [core-jmp]
New Fuyao ad fraud botnet: More than 120,000 Android TV boxes are part of a new botnet involved in advertising fraud. The TV boxes ship with preinstalled apps that pose as common smartphones to click on ads behind its users' backs. Bitsight estimates the new Fuyao botnet is making around $150,000/day. [Bitsight]

Sponsor section
Learn how Permiso Security discovers, protects, and defends all of your human, non-human and AI identities in this short intro.
APTs, cyber-espionage, and info-ops
OctLurk and SilkLurk: Researchers at Kaspersky have found three separate threat actors operating two new modular malware frameworks in espionage campaigns across Asia (Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and Syria). [Kaspersky]
New UNC5174/UNC6586 SNOWLIGHT campaign: Misconfigured servers found by SOCRadar have exposed a reconnaissance campaign carried out by UNC5174/UNC6586, an MSS cyber contractor mainly known for its SNOWLIGHT malware. The targets of this recon campaign was national infrastructure across 90 countries. [SOCRadar]
Storm-1516's Armenia campaign: DFRLab researchers look at the one-year-long Russian disinformation campaign that targeted Armenia and tried to sway its citizens against voting a pro-EU government. [DFRLab]

Vulnerabilities, security research, and bug bounty
Security updates: Dell, FreeBSD, GitLab, PHP, SolarWinds WHD.
KindaRails2Shell vulnerability: A newly disclosed vulnerability in the Ruby on Rails framework can allow attackers to steal a web app's secrets and credentials. The vulnerability impacts Rails apps that use Active Storage, a component for interfacing with databases and cloud services. Codenamed KindaRails2Shell, the vulnerability doesn't require authentication and can be exploited against default configurations. The Rails project released a patch last week. [RyotaK // CVE-2026-66066]
RufRoot vulnerability: The Ruflo AI agent harness has patched a max-severity bug that can allow attackers to gain root access on the underlying AI servers. The bug is in Ruflo's MCP bridge which ships without authentication. Any attacker can query it to run commands on Ruflo's container. The bug has a severity rating of 10/10. A patch shipped last month. [Noma Security // Synack // CVE-2026-59726]
Apple introduces bug reporting cool-offs: Apple has restricted the number of bug reports security researchers can file in its bug bounty program. The company is allegedly struggling to keep up following a deluge of AI-assisted bug reports. Researchers who hit their upper limit cap will have to wait 30 days before they can file new bugs. Vetted researchers can request a higher cap. [Financial Times // iPhone in Canada]
Infosec industry
Threat/trend reports: Action1, BreachLock, Eclypsium, Infoblox, Okta, Quorum Cyber, RedACT, Red Hat, and Rostelecom have recently published reports and summaries covering various threats and infosec industry trends.
WaterISAC denounces leak: The WaterISAC group has put out a statement to denounce a recent leak of a sensitive report about Iran hacking water treatment facilities across Minnesota. The group says it only authored the report but did not share it with news site WIRED, as the publication's article initially suggested. The report confirmed for the first time that the hacks were the work of Iranian hackers. It contradicted a public statement from President Donald Trump, who played down the role of Iranian hackers and instead blamed state authorities. [WaterISAC // Techmeme // WIRED]
Chat is it good when multiple states water supply systems have been hacked resulting in emergency boil water notices and the President says “those cucks deserved it”
— hammancheez (@hammancheez.bsky.social) August 2, 2026 at 2:48 AM
ENISA releases SdB playbook: The EU's cybersecurity agency has released a practical guide for implementing Secure by Design coding principles. I guess someone still cares about this initiative since CISA changed hands last year. [ENISA]
New tool—GraphGulo: IBM intern Mihir Kumar Batar has released GraphGulo, a temporal graph engine for large-scale network traffic analysis.
New tool—AgentHound: Salesforce security engineer Adithyan Arun Kumar has open-sourced AgentHound, an offensive security framework for AI agent infrastructure.
Risky Business podcasts
In this episode of Risky Business Features, James Wilson looks beyond the US vs China AI race rhetoric and instead games out what the real world consequences of the US government slapping bans on AI models could be.