TechLogHub Blog — Page 8 of 22

Insights, guides, and product strategy for builders and product teams.

Showing 20 of 423 articles
FBI warns of fake FIFA websites running World Cup fraud schemes
May 29, 2026

FBI warns of fake FIFA websites running World Cup fraud schemes

The FBI warns that hundreds of fake FIFA websites are circulating ahead of the 2026 World Cup in the US, Canada, and Mexico to steal personal and financial data, sell fake tickets and hospitality, and run related fraud. Impersonators use minor typos (like fiffa.com) and various non-.com domains, plus fake job portals. Cybersecurity researchers from Group-IB and Bitdefender report large-scale World Cup-related malvertising and more than 300 phishing sites tied to a campaign called Ghost Stadium. Fake merchandise, kits, streaming services, and Panini offers are also involved across multiple countries. The FBI advises fans to manually type fifa.com, avoid ads and suspicious links, verify .com domains, bookmark official sites, and report incidents to IC3.

By TechLogHub
BTMOB Android malware service generates custom phishing payloads
May 29, 2026

BTMOB Android malware service generates custom phishing payloads

Security researchers warn of BTMOB, an Android remote access trojan sold as malware‑as‑a‑service with a builder to generate customized phishing payloads. The tool can steal data, intercept financial transactions, capture screenshots, and grant remote control, with options to disable Google Play, hide its icon, or prevent sleep. Active mainly in Brazil and Latin America, BTMOB is sold through private Telegram channels for about $700 per month or a $5,000 lifetime license. Linked to the SpySolr family, it is distributed via phishing sites posing as streaming services or crypto miners and uses localized lures, including one tied to an Argentinian government agency. It abuses Android Accessibility Services to gain elevated permissions. Defenses include installing only from the Google Play Store, running Play Protect, and revoking high‑risk permissions like Accessibility when not needed.

By TechLogHub
GreyVibe hackers use ChatGPT, Gemini to power cyberattacks
May 29, 2026

GreyVibe hackers use ChatGPT, Gemini to power cyberattacks

Researchers from WithSecure link the GreyVibe group, a likely Russian threat actor, to a cyber-espionage campaign that uses AI-generated lures and custom malware to target Ukraine-related and other sectors since August 2025. While the operation shows state-aligned traits, experts caution it may lack the discipline of mature nation-state actors, suggesting possible hybrid ties with cybercriminals. GreyVibe reportedly used multiple attack chains—PhantomMail, PhantomClick, PrincessClub, DroneLink, and Nebo—and employed AI tools like ChatGPT and Google Gemini to craft convincing content and bespoke obfuscators (LOOKVALPS, LOOKVALJS, DAYLIGHT, TEASOUP). Additional tools include the LegionRelay and PhantomRelay PowerShell RATs and the FallSpy Android spyware, with cryptocurrency mining observed in some samples. WithSecure provides IoCs to help defenders detect and block this activity.

By TechLogHub
Anthropic confirms Claude Mythos-class models will roll out to the public
May 29, 2026

Anthropic confirms Claude Mythos-class models will roll out to the public

Anthropic has confirmed that Claude Mythos-class models will roll out to the public in the coming weeks after a delay over security concerns, with Mythos touted as more capable than Opus 4.8 in code reasoning and autonomy. Guardrails are in place, and a small number of organizations are already using a Mythos preview for cybersecurity work, though no exact public rollout date was announced.

By TechLogHub
Charter Communications data breach affects 4.9 million accounts
May 29, 2026

Charter Communications data breach affects 4.9 million accounts

Charter Communications confirms a data breach by the ShinyHunters extortion gang affecting 4.9 million accounts, with the attackers claiming to have stolen 42 million Salesforce records including names, emails, addresses, and phone numbers. Charter says no sensitive PI or CPNI data was exfiltrated and authorities were alerted, but the data was leaked on the dark web after Charter declined ransom; the FBI has advised victims not to pay. The incident forms part of a broader Salt Typhoon campaign that has breached multiple telecoms.

By TechLogHub
Carnival Cruise confirms data breach affecting nearly 6 million people
May 28, 2026

Carnival Cruise confirms data breach affecting nearly 6 million people

Carnival Corporation has confirmed a data breach affecting nearly 6 million people after a social engineering attack on its IT systems in April 2026. The ShinyHunters gang claimed responsibility, stating they stole personal data—including names, dates of birth, email addresses, genders, locations, and Holland America’s Mariner Society loyalty data—across Carnival’s brands; Carnival began notifying affected customers in May 2026, while investigators assess the attackers’ claims.

By TechLogHub
Canadian Man Sentenced to 33 Years for Sextortion Targeting 145 U.S. Children
May 28, 2026

Canadian Man Sentenced to 33 Years for Sextortion Targeting 145 U.S. Children

A Canadian man, 40-year-old Ramanan Pathmanathan, was sentenced to 33 years in a U.S. federal prison after pleading guilty to coercion and enticement of a minor and child pornography production in an eight-year sextortion scheme targeting about 145 children across the United States, some as young as six. He posed as a New Jersey teenager online and used Instagram and Facebook Messenger to coerce victims into sexually explicit acts via video chats, recording their conduct and threatening to share the material with friends and family. Pathmanathan already is serving a 12-year Canadian prison term for related offenses, and the U.S. sentence includes sex-offender registration and 10 years of supervised release.

By TechLogHub
GPU mining malware spreads via SEO poisoning, AI chatbots
May 27, 2026

GPU mining malware spreads via SEO poisoning, AI chatbots

A new GPU‑mining malware campaign is spreading through SEO poisoning and AI chatbot recommendations, redirecting users seeking common utilities to attacker‑controlled download pages. The attack payload includes a legitimate utility plus a malicious DLL that installs ScreenConnect for persistence, uses process hollowing to inject into Microsoft‑signed binaries, and establishes six persistence points. It then downloads and runs GPU mining tools (gminer, lolMiner, SRBMiner‑MULTI) to monetize compromised machines, with defenders warned to watch for the implicated indicators of compromise.

By TechLogHub
Can you enforce strong Active Directory password rules without frustrating users?
May 27, 2026

Can you enforce strong Active Directory password rules without frustrating users?

Sponsored post arguing that strong Active Directory password policies can be effective without frustrating users. It champions moving from traditional complexity rules to passphrase-based, length-focused standards (minimum 15+ characters, up to 64), and actively blocking weak or breached passwords. It also suggests extending expiration periods with length-based aging, using a password manager to reduce reuse, enabling self-service resets with MFA, and providing clear, real-time feedback during password creation. The piece promotes Specops tools (Password Policy and Password Auditor) as practical solutions and invites readers to try them for free or book a demo.

By TechLogHub
Glassworm botnet disrupted after resilient C2 infrastructure takedown
May 27, 2026

Glassworm botnet disrupted after resilient C2 infrastructure takedown

Researchers have disrupted the Glassworm botnet, which targeted developers through software-supply-chain attacks, by taking down its multi-channel C2 infrastructure. In a coordinated operation, CrowdStrike, Google, and The Shadowserver Foundation blocked four C2 channels that used Solana blockchain memos, BitTorrent DHT, Google Calendar events, and traditional servers, rendering infected machines unable to receive further instructions. Active since October 2025, Glassworm evolved from malicious OpenVSX/VS Code extensions to GitHub/npm campaigns, even deploying dormant OpenVSX extensions that activated on update. Post-takedown, infected hosts beacon to 164.92.88.210; investigators have published remediation guidance and YARA rules to help detection.

By TechLogHub
FBI warns of in-person data theft attacks from extortion gang
May 27, 2026

FBI warns of in-person data theft attacks from extortion gang

The FBI warns that the Silent Ransom Group (aka Luna Moth, Chatty Spider, UNC3753) is targeting U.S. law firms with in-person data theft and extortion, using social-engineering to pose as IT staff and coax remote access, or sending insiders to offices to insert USB drives; indicators include unauthorized USB devices and unfamiliar individuals claiming IT roles. The group, active since 2022 with ties to BazarCall, has targeted legal and financial sectors since 2023, with ongoing alerts in 2025.

By TechLogHub
CISA gives feds 4 days to patch actively exploited cPanel plugin flaw
May 27, 2026

CISA gives feds 4 days to patch actively exploited cPanel plugin flaw

CISA has given federal agencies four days to patch a critical, actively exploited vulnerability in the LiteSpeed cPanel user-end plugin (CVE-2026-48172). The privilege-escalation flaw in lsws.redisAble could allow remote attackers with no privileges to execute arbitrary root code, affecting plugin versions 2.3–2.4.4. LiteSpeed issued urgent updates on May 21, and CISA has added the flaw to the Known Exploited Vulnerabilities catalog, ordering patching by midnight May 29 under BOD 22-01. Defenders in both public and private sectors are urged to patch per vendor guidance or disable the product if mitigations are unavailable; a detection command is provided to verify vulnerability.

By TechLogHub
Dutch police arrests suspect linked to Ajax football club hack
May 27, 2026

Dutch police arrests suspect linked to Ajax football club hack

Dutch police arrested a 35-year-old man from Buren on May 26, 2026, on suspicion of computer trespass tied to a breach of Ajax Amsterdam’s IT systems earlier this year. The attacker allegedly exploited vulnerabilities to access fan data, modify stadium bans, and transfer tickets—affecting thousands of season tickets and information on more than 300,000 accounts—before Ajax patched the flaws and notified authorities. Ajax disclosed the breach in March 2026.

By TechLogHub
Windows 11 KB5089573 update released with performance improvements
May 27, 2026

Windows 11 KB5089573 update released with performance improvements

Microsoft released the Windows 11 KB5089573 preview cumulative update for 25H2 and 24H2. This optional, non-security update adds about 30 changes focused on performance and reliability, including faster launches for Start, Search, and Action Center, improved Windows Hello sign-in behavior, and greater reliability in File Explorer, sign-in/lock screens, and touch gestures. It also introduces shared audio, better VM CPU readouts after resume, and enhanced HID power management along with Secure Boot certificate rollouts. Installation is via Windows Update or the Microsoft Update Catalog, and it upgrades affected devices to builds 26200.8524 (25H2) and 26100.8524 (24H2).

By TechLogHub
KnowledgeDeliver flaw exploited as a zero-day to install web shells
May 27, 2026

KnowledgeDeliver flaw exploited as a zero-day to install web shells

Researchers reveal a critical zero-day in KnowledgeDeliver LMS (CVE-2026-5426) that enables unauthenticated remote code execution via ViewState deserialization by abusing a shared hardcoded ASP.NET machineKey. Hackers deployed the Godzilla/BlueBeam in-memory web shell to take control of servers, sign malicious payloads, and prompt users to install a rogue security plugin, effectively backdooring the host with a Cobalt Strike beacon. Mandiant attributes the exploit to standardized web.config machine keys across deployments prior to Feb 24, 2026, and notes this reflects a broader trend of machine key misuse in ViewState attacks across multiple products.

By TechLogHub
Charter confirms data breach after ShinyHunters extortion threat
May 26, 2026

Charter confirms data breach after ShinyHunters extortion threat

Charter Communications confirms a data breach following ShinyHunters’ extortion threat, but says no sensitive personal information or customer CPNI was exfiltrated, even as the group claims up to 40 million records were stolen in an April 1 vishing attack targeting Salesforce data.

By TechLogHub
CISA Orders Federal Agencies to Patch Actively Exploited Drupal Vulnerability
May 26, 2026

CISA Orders Federal Agencies to Patch Actively Exploited Drupal Vulnerability

CISA has ordered Federal Civilian Executive Branch agencies to patch an actively exploited Drupal SQL injection vulnerability (CVE-2026-9082) in the Drupal database abstraction API by midnight on May 27, 2026, under Binding Operational Directive 22-01. Exploitation has been detected in the wild, with Shadowserver tracking about 670 unpatched Drupal installations worldwide, many in North America and Europe. While BOD 22-01 applies to federal agencies, CISA urges all organizations to apply vendor patches and mitigations to reduce risks of information disclosure, privilege escalation, or remote code execution.

By TechLogHub
Anthropic’s restricted Claude Mythos model may be coming to Claude Code
May 25, 2026

Anthropic’s restricted Claude Mythos model may be coming to Claude Code

Anthropic is moving toward a public rollout of Mythos, a restricted Claude model unveiled in April that shows highly advanced code reasoning and security capabilities, including the potential to autonomously develop cyberattacks. To mitigate risk, the rollout has been delayed while guardrails are put in place, with Mythos previews briefly appearing in Claude Code and Claude Security as claude-mythos-1-preview. Through the Glasswing initiative, Mythos is being tested with about 50 partners to uncover and remediate AI-driven exploits, reportedly finding 10,000 high- or critical-severity vulnerabilities in its first month. The article also notes current Claude Opus versions and related security coverage.

By TechLogHub
FBI warns of Kali365 phishing service targeting Microsoft 365 accounts
May 25, 2026

FBI warns of Kali365 phishing service targeting Microsoft 365 accounts

FBI warns of Kali365, a phishing-as-a-service platform that hijacks Microsoft 365 and Entra accounts by abusing OAuth device-code authentication to steal session tokens and bypass MFA. Emerged in April 2026 and distributed via Telegram, it directs victims to a device-login portal to authorize attackers, granting access to cloud apps. Kali365 operates as a business with admins, resellers, and affiliates, and offers two attack modes: device-code phishing and an adversary-in-the-middle “Cookie Link” that captures tokens. The FBI urges organizations to block device-code authentication flows with Conditional Access, audit usage, and report incidents to IC3, noting that device-code phishing is becoming widespread in 2026 alongside EvilTokens and Tycoon2FA.

By TechLogHub
Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign
May 24, 2026

Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign

A critical Ghost CMS SQL injection (CVE-2026-26980) is being exploited in a large-scale ClickFix campaign, impacting 700+ domains including Harvard, Oxford, Auburn, and DuckDuckGo. The flaw allows unauthenticated access to read database data and steal admin API keys, enabling attackers to inject malicious JavaScript into articles. The attack chain uses stolen keys to deploy a loader that fetches second-stage payloads and a fake Cloudflare prompt to deliver the ClickFix lure, with multiple payloads observed. Ghost patched the flaw in version 6.19.1 on February 19, 2026, but many sites have not updated. Admins should upgrade to 6.19.1+, rotate all exposed keys, review IoCs, and maintain 30 days of admin API call logs for retrospective analysis, as operators have shown reinfection and varied payloads.

By TechLogHub

Showing 20 of 423 articles