Dutch authorities took down more than 200 servers at a local provider supporting a sprawling botnet of at least 17 million infected computers, tablets, and smartphones. Investigators linked the infrastructure to the Asocks residential proxy service, which monetized hijacked devices for covert traffic. The takedown should reduce abuse of residential IPs for fraud and credential-stuffing, but defenders should expect operator retooling and check for unusual outbound proxy traffic.
Source: Security Affairs
ShinyHunters Dumps Alleged Charter Communications Customer Data After Failed Extortion
Extortion group ShinyHunters published data it claims to have stolen from Charter Communications after the US telecom giant reportedly refused to pay. The leak could impact up to 5 million customers and exposes millions of records. Enterprises should monitor for targeted phishing leveraging leaked PII and refresh detection rules for data appearing on criminal forums.
Source: Security Affairs
Signal Users Hit by Phishing Campaign Aiming to Steal Backup Recovery Keys
Attackers are sending texts impersonating “Signal Support” to trick users into sharing their backup recovery key. Possession of this key allows decryption of a victim’s entire Signal message history, not just future chats. Targets include journalists and activists; advise users to treat unsolicited messages as suspicious and never share recovery keys over SMS.
Source: Security Affairs
Exploit Released for Critical Flowise RCE via Malicious Chatflows
Public exploit code is out for a one-click remote code execution flaw in self-hosted Flowise servers. Attackers can achieve arbitrary code execution by luring admins into importing a booby-trapped chatflow. Organizations running Flowise should restrict imports, review recent admin actions, and apply patches or mitigations immediately.
Source: SecurityWeek
Western Officials Warn: Russian Intelligence Ramps Up Tech Acquisition and Cyber Ops
Officials say Russian spy services are aggressively pursuing Western technology despite sanctions, creating shell companies and using intermediaries to evade controls. Alongside human intelligence, Moscow is deploying cyber operators to gather information that could enable attacks on critical infrastructure. Security teams in sensitive sectors should revisit third‑party risk and export-control exposure.
Source: SecurityWeek
Fake Anthropic Sites Push Fileless Infostealer at Claude Code Users
Threat actors set up convincing Anthropic-themed domains to target developers using Claude Code, delivering a fileless infostealer that evades many defenses. The malware focuses on extracting browser credentials and other sensitive data without dropping binaries to disk. Verify download origins, use browser isolation where possible, and monitor for anomalous credential access.
Source: HackRead
When Cyber Attacks Turn Physical: Rising Impact on US Critical Infrastructure
A new analysis highlights an uptick in cyber incidents that produce physical-world consequences across US critical infrastructure. The first half of 2026 shows shifting attacker tradecraft and escalating risks to utilities, healthcare, and transportation. Boards and operators should align IT/OT incident response and rehearse scenarios where outages affect safety and service delivery.
Source: GovTech
You May Also Be Interested In...