Risky Bulletin: Russia tells data centers to deploy drone defenses

In other news: Dropbox discloses security breach; new spyware wave hits Serbians; CISA scraps six free cybersecurity programs.

Share
Risky Bulletin: Russia tells data centers to deploy drone defenses

This newsletter is brought to you by Dropzone. You can subscribe to an audio version of this newsletter as a podcast by searching for "Risky Business" in your podcatcher or subscribing via this RSS feed. You can also add the Risky Business newsletter as a Preferred Source to your Google search results by going here.

The Russian government has instructed data center operators to deploy protections against drone strikes and other physical threats as part of a national effort to boost defenses at critical infrastructure organizations.

Companies that fail to follow the Kremlin's instructions risk having their operations put under the state's administration.

Russian President Vladimir Putin signed a presidential decree last month allowing the state to temporarily take over the operations of critical infrastructure operators who fail to protect against Ukrainian hacks and drone strikes, or take too long to repair damage.

While data centers are not formally considered a critical infrastructure sector in Russia, data center operators were told that the decree also applies to them, primarily because other critical infrastructure relies so heavily on cloud services that any data center outage is likely to cause widespread impact across both the public and private sectors.

According to a Kommersant report this week, most of the larger Russian data centers already have solid cybersecurity defenses put in place due to the nature of their operations, which means most only have to deploy drone defenses. It is unclear what those will be.

The expected business aftermath is that the investment cost of deploying these additional drone defenses will eventually be passed down to customers, leading to a spike in IT costs across Russia and neighboring countries.

The conversation around Putin's latest presidential order has also shifted over the past week. Initially, the decree caused quite the panic among Russian business owners, with many viewing it as a legal framework for the government to nationalize their assets.

Since then, Kremlin officials have made it clear the transfer of ownership and assets is only temporary and will be used very rarely, for the most egregious offenders.

There are currently more than 180 data centers in Russia, with more than 80% located in the country's European region, in the range of Ukrainian strikes.

Risky Business Podcasts

The main Risky Business podcast is now on YouTube with video versions of our recent episodes. Below is our latest weekly show with Pat, James, and guest co-host The Grugq at the helm!


Breaches, hacks, and security incidents

Dropbox discloses security breach: Hackers have gained access and downloaded data from almost 5,000 Dropbox accounts. The breaches took place last month. Hackers got into the accounts by abusing Dropbox's integration with Lenovo's identification service. Attackers registered on the Lenovo ID service with the same email address used for valid Dropbox accounts. They then bypassed Lenovo's email verification process and used the newly verified account to pivot back to the equivalent Dropbox accounts. [Reuters]

New spyware wave hits Serbians: At least 14 Serbian individuals have been targeted with advanced spyware since the beginning of the year. Targets include at least a member of the Serbian parliament, a local government official, and members of the peaceful student pro-democracy movement. Their devices were infected with the NoviSpy or Pegasus spyware families. Victims learned of the attacks after receiving alerts from Apple at the end of August. [SHARE Foundation // CitizenLab]

Password recovery attack hits Twitter: Twitter has mitigated on Tuesday a password recovery attack that hit hundreds of thousands of accounts. Engineers believe the attacker tried to breach accounts and then pivot to the company's recently launched X Money digital banking service. No account was allegedly compromised. US Attorney General Todd Blanche said the DOJ is working with the company to track down the attackers. [USAG Todd Blanche]

Coder hacked to deliver malicious Terraform modules: Hackers have compromised Coder's Cloudflare infrastructure to add new registry servers that delivered malicious Terraform modules. The malicious registries were live for 14 hours on August 31. Coder provides tools for developers to deploy secure cloud infrastructure for hosting AI applications. [Coder]

Hackers expose Russian donor data: Hackers have stolen sensitive donor data from two Russian organizations that raised funds for Russian political prisoners and Ukrainians affected by the war. Davayte and You Are Not Alone disclosed security breaches related to their payment systems this week. Hackers stole donor email addresses and limited card information. Both linked the breach to the integration between payment processor Stripe and the WooCommerce WordPress plugin. [The Record]

Aquifer crypto-heist: Hackers have stolen $2.5 million worth of crypto assets from the Aquifer automated market. [crypto.news // Defimon Alerts]

TVING breach: South Korean video streaming service TVING says hackers stole the personal data of almost 40 million user accounts in a security breach at the start of June. The stolen data includes more than 70 types of personal details, from names to emails, phone numbers, and more. The company's executives apologized for the incident in a public press conference. TVING will also offer compensation worth about 20,000 won ($15) per user in streaming benefits. It also risks a fine from authorities for reporting the incident a day too late. [UPI // The Herald Business]

C-Track breach: C–Track, an online case management platform developed by Thompson Reuters, has disclosed a security breach. The hackers allegedly accessed legal case data across the US and Canada. [C-Track US // C-Track Canada // Reuters]

Jack Henry breach: Bank IT provider Jack Henry has notified more than 7,200 customers of a recent security breach. Hackers used a voice phishing attack to gain access to its network and steal internal documents. The ShinyHunters hacking group took credit for the attack but Jack Henry says it won't pay them any ransom. [Jack Henry]

General tech, AI, and privacy

OpenAI prepares Astra: OpenAI says it's close to releasing Astra, its most recent GPT model. The company claims Astra can find zero-day vulnerabilities and execute end-to-end cyber intrusions. Astra will be available for early testing to cybersecurity experts who signed up through OpenAI's Daybreak Blue program. [OpenAI]

Google releases Gemini 3.8 Flash Cyber: Google has released a new Gemini version, including a model dedicated to cybersecurity work. [Google]

NVIDIA buys HuggingFace: Chipmaker NVIDIA has agreed to buy AI model hosting platform HuggingFace for $12,930,300,000. [NVIDIA]

Microsoft enables Memory Integrity for more devices: Microsoft will enable the Memory Integrity security feature on more Windows devices starting next month. The feature uses isolated virtual environments to run code that accesses the Windows kernel. Any malicious code is caught in the environment and doesn't interact with the kernel. All new Windows 11 clean installs ship with the feature enabled. Microsoft has warned that the feature impacts performance. Tests have shown a drop of up to 20% in gaming performance once the feature was enabled. [Microsoft // PCMag]

ArtStation backtracks: ArtStation, the largest online portal for graphic artists, will set the protection against using an artist's work for AI training to off-by-default for all accounts after huge backlash from its community. The company will also roll out better bot protection after the site saw massive scrapping of its content over the past months. [ArtStation]

HSE gets fined: Ireland's data protection agency fined the national healthcare service HSE €645,000 for improperly storing patient paper records in external storage facilities. [DPC // RTE]

Firefox 155: Mozilla has released Firefox 155. New features and security fixes are included. The biggest feature in this release is Smart Windows, Firefox's new AI-centric New Tab window that nobody asked for and everyone will hate or ignore.

Government, politics, and policy

AB govCIRT: The government of Antigua and Barbuda has launched a Cyber Incident Response Team (CIRT). [Antigua News Room]

CISA scraps six free cybersecurity programs: CISA has ended six free cybersecurity assessments for critical infrastructure operators. This includes Cyber Resilience Reviews, the Cyber Resilience Essentials Surveys, Ransomware Readiness Assessments, Incident Management Reviews, External Dependencies Management Assessments, and Cyber Infrastructure Surveys. The agency didn't say why it's stopping the programs. CISA is still severely understaffed after the Trump administration laid off more than a third of its staff since taking office. [CybersecurityDive]

CISA and G7 call for quantum action: CISA and the Group of Seven (G7) Cyber Security Working Group have urged governments and companies across the world to speed up their adoption of post-quantum cryptography (PQC) technologies. [CISA]

In this Risky Business sponsor interview, James Wilson chats with Dropzone AI’s founder and CEO Edward Wu to debunk the adage, "an attacker only has to be right once."

Arrests, cybercrime, and threat intel

Authorities take down Sality botnet: An international law enforcement operation has disrupted the Sality peer-to-peer botnet. Authorities and security firms from the US and Europe have seized servers, domains, and are now sinkholing traffic from infected devices. Sality was one of the oldest botnets in existence, having launched in 2003. It was primarily being used to steal cryptocurrency from infected devices and then rent access to the infected hosts to other cybercrime groups. [DOJ // Europol // CrowdStrike]

Russian charged for hacking freelancers: The US Justice Department has charged a Russian national for a phishing campaign that targeted online freelancers with malware. Searzhudin Tamirlanovich Aktulaev was arrested in Cyprus last year and extradited to the US last month. He used hundreds of fake accounts to send private messages to more than 80,000 users of a US freelancing platform in 2016 and 2017. The messages contained malicious Excel files that deployed the TVSPY and DarkVNC malware on job seekers' devices. [DOJ]

Gambling Goblin targets Brazil: A Chinese cybercrime group is hacking Brazilian government and educational websites to hijack visitor traffic and manipulate search engine results. The group hacks the site's underlying Linux server and deploys backdoors and malicious Apache modules. The hacked sites host ads for online gambling and sports betting to boost those sites' reputations, while some incoming visitors are also redirected to phishing pages for various app stores. Check Point tracks the attackers as Gambling Goblin, a group that was previously active across Southeast Asia with the same tactics. [Check Point]

Dark web service sells 153m+ drivers licenses: The FBI is investigating a now-defunct dark web service that sold drivers licenses for more than 153 million US and Canadian citizens. The service was named Nexus, launched this week, and was advertised on the Exploit underground hacking forum. It shut down hours after cybersecurity reporter Brian Krebs covered its launch. According to Krebs, the source of the stolen drivers license scans appears to be a New Orleans identity verification company named IDScan.net. [KrebsOnSecurity]

Phantom Deal profile: Gen Digital has stumbled upon a cybercrime group that poses as executives who use WhatsApp social-engineering to trick victims into investing or acquiring fake companies. [Gen Digital]

Bot attacks on FIFA's WC ticket sales: Security firm Vesal looks at the bot attacks that targeted the USA 2026 World Cup ticket sales. [Vesal]

Node.js abuse: Broadcom has published a technical report looking at how threat actors have returned to abusing the Node.js runtime to execute their malware inside a trusted environment. Abuse has been seen in cyber-espionage but also mundane e-crime, including ransomware. [Broadcom]

ASCII smuggling abuse: Another old technique seeing a resurgence is ASCII smuggling, which Microsoft says it's seeing in a lot of phishing campaigns these days. [Microsoft]

AI-based cyber intrusion IR: Palo Alto Networks has published an incident report from an incident where an attacker allegedly used a "frontier AI" to breach the victim's network. [PAN Unit42]

AI-based campaigns target LATAM: Palo Alto Networks has spotted two hacking campaigns that are using AI tools to enhance capabilities. [PAN Unit42]

  • Mexican transportation campaign: This campaign impacted a transportation organization, alongside federal government ministries and municipal water utilities in Mexico and Ecuador. Operators relied on living-off-the-land (LotL) techniques. They executed iterative batch scripts to manipulate and exfiltrate sensitive data, and self-hosted NextChat instances on operational infrastructure. We track the activity in this cluster as CL-CRI-1131.
  • Brazilian financial campaign: Attackers targeted the Brazilian financial sector. We observed an expansion of previously reported targeting of vulnerable web servers in a job-themed phishing campaign. The attackers employed custom remote access Trojans (RATs) and tunneling tools, including a Go-based SOCKS5 proxy with iterative filenames that suggest AI-enablement. We track the activity in this cluster as CL-CRI-1163.

Maybe a ScreenConnect worm: Security firm Huntress has spotted something curious in three different incidents, where attackers deployed a malicious ScreenConnect version that tried to spread to other ScreenConnect installs and poison them too. [Huntress]

SilverFox fake installer campaign: Microsoft's security team is tracking a new SilverFox campaign that is distributing boobytrapped installers using fake websites for known software vendors. It's 2026 and this still works! [Microsoft]

Malware technical reports

StreamRAT: ThreatFabric researchers have discovered StreamRat, a new Android banking trojan promoted to Spanish-speaking users through Meta and TikTok ads. [ThreatFabric]

Knight Office PhaaS: Huntress researchers have found a new AitM-capable phishing kit named Knight Office. The kit is already used in the wild. [Huntress]

Outsider PhaaS returns: The Outsider phishing service has returned online after a Google-orchestrated takedown and lawsuit in June. More than 700 new Outsider-based phishing pages have been spotted since the June lawsuit. [Group-IB]

BlueKit PhaaS: ZeroBEC joins the ranks of security firms looking at Bluekit, a popular PhaaS platform advertised on the dark web. [ZeroBEC // Netcraft //Varonis // CloudSEK

In this sponsored product demo, Dropzone founder and CEO Edward Wu walks Risky Business podcast host Patrick Gray through the company's AI SOC analyst. 

APTs, cyber-espionage, and info-ops

New Prince of Persia infrastructure: Whisper security researchers have spotted new backend infra and domains linked to Prince of Persia (Infy) APT operations. [Whisper Security]

New IRGC-CEC reward: The US State Department is offering a $10 million reward for a top official in Iran's military cyber force. Amir Yaryab is the leader of Cyber Operations Command inside the Iran Islamic  Revolutionary Guard Corps Cyber-Electronic Command, also known as IRGC-CEC. From his role he directs the activity of multiple Iranian hacking groups, such as the CyberAv3ngers, Shahid Hemmat, and Dadeh Afzar Arman. The groups have attacked US critical infrastructure operators since the US and Iran started bombing Iran in February. [Rewards for Justice]

Vulnerabilities, security research, and bug bounty

Security updates: Cisco, Firefox, HPE, Jenkins, Kubernetes, Plex, SonicWell, VMware.

SonicWall zero-day: SonicWall has released security updates on Tuesday to patch two actively exploited zero-days in SMA1000 mobile access gateways. The two zero-days allow attackers to bypass authentication (CVE-2026-83548) and run malicious commands on the devices (CVE-2026-83549). There is no information on the attackers, but SMA1000 gateways have been targeted by state and e-crime actors on a regular basis over the past half decade. [SonicWall]

FalconFlank zero-day: Security researcher Nightmare Eclipse has released a zero-day in the CrowdStrike Falcon EDR. Named FalconFlank, the vulnerability can let attackers gain admin access over a Windows system. The same researchers also released similar zero-days for other security software like Microsoft Defender, the Avast antivirus, and the Kaspersky EDR. [GitHub]

Meccha Chameleon RCE: Researchers have found a remote code execution in the Meccha Chameleon video game, but this can only be exploited from an attacker-controlled map. [Aikido Security]

GitSpawn vulnerability: Security researchers have disclosed vulnerabilities across seven AI CLI agents that will read and execute malicious commands stored in Git repo's configuration files. The vulnerabilities allow a downloaded project to run code on a user's computer before the AI agent asks the user whether they trusted it or not.  [Manifold Security]

Cleo bug write-up: Armadin has published a write-up on two bugs in the Cleo Harmony file transfer software that can allow attackers to gain admin control over the server. A public POC is also available. [Armadin // WatchTowr // VulnDB]\

Chamilo LMS write-up: Quarkslab has published an analysis of 11 vulnerabilities they found in the Chamilo LMS. The bugs were patched over the past few months. [Quarkslab]

Unauth SQLi in popular WP plugin: Security researchers have found an unauthenticated SQL injection bug in the All-in-One WP Migration and Backup WordPress plugin. The vulnerability is located in the plugin's archive restore functionality. All-in-One WP Migration and Backup is one of the WordPress ecosystem's most popular plugins, with more than 5 million installs. A third of all installs have already been patched. [Wordfence]

Elementor Pro bug exploited in the wild: Threat actors are exploiting an unauthenticated file upload vulnerability (CVE-2026-32475) in the Elementor Pro plugin to drop webshells on WordPress sites. [Wordfence]

KEV update: CISA has updated its KEV database with seven vulnerabilities that are currently exploited in the wild.

Infosec industry

Threat/trend reports: BlackFog, CyFirma, Recorded Future, and Shadowserver Foundation have recently published reports and summaries covering various emerging threats and industry trends.

Honeywell fined for security lapses: A DOD government contractor has agreed to pay a $2 million fine for failing to comply with cybersecurity requirements related to aerospace contracts. Honeywell Aerospace admitted to failing to comply with NIST standards. More than $375,000 from the fine will go to a former Honeywell employee who exposed the company's failure. [DOJ]

Acquisition news: US email security company Proofpoint is in talks to acquire Israeli security firm Varonis. Since Varonis is valued at over $5 billion, it will cost a pretty penny. [CTech]

REcon 2026 videos: Talks from the REcon 2026 security conference, which took place in June, are available on YouTube.

Risky Business podcasts

In this edition of Seriously Risky Business, Tom Uren and James Wilson talk about China's long-term shift to getting private companies to build botnets for cyberespionage. A disruption effort from the US this week is good news, but China has been using these networks for a surprisingly long time and will rebuild.