Toggle light / dark theme

New StormEncryptor ransomware used by former Medusa affiliate

A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor.

Microsoft Threat Intelligence is tracking the actor as Storm-1175 and says the recent attacks were likely preceded by exploitation of an authentication-bypass vulnerability (CVE-2026–18577) in the N-central remote monitoring and management (RMM) tool.

Storm-1175 is believed to be a China-based threat actor. It was previously linked to Medusa ransomware, targeting systems via zero-day and n-day flaws in various products, including GoAnywhere MFT, SmarterTools SmarterMail, Microsoft Exchange, Invanti Connect Secure, and JetBrains TeamCity.

Immune Cells Help Tumors Grow

Cancer adapts and overcomes many different obstacles in order to survive. Since tumors are masses of rapidly growing cells, it takes a lot of nutrients, signaling, and proteins to help maintain proliferation. Over the last two decades, researchers have discovered that nerves provide tumors with signals, neurotransmitters, growth factors, and molecules to aid in cancer genesis, growth, survival, and progression. This process of nerves growing around and within the tumor is known as ‘tumor innervation’ or ‘nerve hacking’. This provides a source of nutrients for the tumor and makes the tumor microenvironment (TME) more complex or difficult to treat. Solid tumors in particular benefit from nerve hacking and more nerves innervating the tumor correlate with worse outcomes in patients. Therefore, researchers are working on understanding this process and how to best treat patients with increased tumor innervation.

Novel research published by scientists at the University of Oklahoma demonstrated how breast cancer cells can attract nerves to fuel their growth. It has been a mystery how nerves get to the tumor, until recently. This new study in Cell Death & Differentiation concludes that triple negative breast cancer (TNBC) uses the body’s own immune system to interconnect with nerves. The study performed by Dr. Maureen A. Cox and others clearly show that a specialized immune cell, known as a macrophage, is directly responsible for nerve hacking and tumor progression.

Cox is an Assistant Professor in the Department of Microbiology & Immunology within the College of Medicine at the University of Oklahoma. Her work focuses on the nervous systems and how nerves and immune cells interact to respond to cancer. Specifically, Cox investigates how immune cells facilitate nerve growth and subsequently promote cancer through indirect mechanisms.

When security becomes a risk factor—privacy risks of public URL-scanning services

URL scanning services are now a common component of modern security workflows. They help detect phishing websites or malware early and warn users before they visit a URL. However, the practice of some of these services—publishing scanned URLs—can inadvertently expose sensitive user data. CISPA researcher Ali Mustafa, together with colleagues from the Max Planck Institute for Security and Privacy and Ca’ Foscari University of Venice, conducted the first systematic investigation of the risks arising from this practice.

The researchers presented their paper, “LEAKYLINKS: Measuring the Security and Privacy Risks of URL Scanning Services,” at the IEEE Symposium on Security and Privacy 2026.

URL scanning services such as URLScan, VirusTotal or Cloudflare Radar automatically analyze websites for suspicious content. “For example, they check network requests, site reputations or embedded scripts, thereby helping companies and individuals detect malicious websites early on,” Mustafa explains.

Nearly 800 Malicious npm Packages Deliver CrossPlatform RAT and Infostealer

A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems.

“These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but all of them deliver a powerful RAT and infostealer payload,” OpenSourceMalware researcher Paul McCarty said.

Unlike other npm-oriented software supply chain attacks that make use of lifecycle hooks like preinstall or postinstall to trigger the execution of malicious code, the newly identified packages come with a README that instructs developers to load them with require, a built-in function to import modules, local files, and third-party packages.

Real emails, hijacked payments: Two H1 2026 attack chains

Address books or allowlists reduce repeated manual entry, while first-time or changed destinations deserve a full comparison rather than a check of only the opening and closing characters.

In both campaigns, the first trust decision could look legitimate while the surrounding workflow had already been changed. Detection and verification need to cover the steps between the authenticated email, the copied value and the final action.

Gen’s H1 2026 Threat Report covers the broader picture across scams, malware, identity exposure, privacy and AI-driven attacks.

AIAssisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache ZeroDay

PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate desync vectors.

PortSwigger said a separate human-guided discovery cascade also exposed a zero-day in Apache Traffic Server. Kettle said HTTP Terminator tested 30,000 websites where scanning was authorized through bug bounty or vulnerability disclosure programs and found roughly 700 vulnerable targets before deeper validation and RQP research.

Kettle said those findings involved banks, government infrastructure, security products, and an airport.

Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities

Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network.

Its August 3 scan counted 4,407 exposed Rockwell controllers worldwide, including 2,844 in the United States, but Forescout could not confirm any were compromised. That figure counts exposed controllers, not water utilities or confirmed victims.

Forescout said the publicly described effects could be achieved without a vulnerability exploit: attackers changed IP addresses and set passwords on controllers that were already reachable, causing operators to lose visibility and, in some cases, control of connected equipment.

Meta AI model hacked a company during misconfigured cyber test

Meta has become the latest AI company to confirm that one of its models hacked a real organization during cybersecurity testing, as similar incidents continue to emerge following OpenAI’sOpenAI’s initial disclosure that its agents breached Hugging Face.

The Information was the first to report the incident on Wednesday, citing people familiar with the matter who said Meta’s Muse Spark 1.1 model breached an unidentified company and made changes to its internal systems.

According to the report, the model reached the public internet because of an error in the configuration of a sandbox testing environment operated with independent cybersecurity evaluation company Irregular.

Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures

A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks.

The server-side gate hides the malicious page from crawlers and sandboxes while presenting selected Mac users with a fake software download. Microsoft said the wider cluster distributed MacSync and Atomic Stealer (AMOS); the chain it analyzed through the gate ended in AMOS.

The attack still requires the user to copy and run an obfuscated command in Terminal. That command retrieves scripts and launches an infostealer targeting credentials, browser data, authentication stores, cryptocurrency wallets, and sensitive files. Microsoft has not disclosed victim numbers, targeted sectors, or the identity of the operators.

/* */