~/greenteam/nerd

Monday, June 8, 2026

Daily digest

cybersec The Hacker News

UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign

Google Mandiant has detailed a financially motivated threat actor (UNC3753/Silent Ransom Group) that combined voice phishing, physical office intrusions, and social engineering to steal data from dozens of U.S. professional, legal, and financial services firms between January and May 2026. The group achieves data theft within hours of initial contact, making rapid detection and response critical. Organizations relying on help-desk workflows and physical access controls should review both their vishing awareness training and badge/visitor policies.

cybersec BleepingComputer

Silent Ransom Group Targets Law Firms with Fake IT Support Calls

Mandiant reports the Silent Ransom Group is actively targeting U.S. law firms and professional services organizations through social engineering calls impersonating IT support, leading to data exfiltration within hours of first contact. The campaign is notable for its speed — traditional IR timelines may be too slow to contain the damage. IT admins should ensure help-desk staff are trained to verify caller identity through out-of-band channels before taking any account or access actions.

cybersec The Hacker News

VerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux Appliances

Volexity has attributed a new campaign to VerdantBamboo (overlapping with Microsoft's Clay Typhoon), a China-nexus espionage group deploying a BSD-variant of the BRICKSTORM backdoor alongside two additional malware families (PLENET/GRIMBOLT and AGENTPSD) against Linux systems and network appliances. The targeting of Linux and BSD-based infrastructure is directly relevant to environments running Nutanix AHV and other Linux-backed hypervisors. Organizations should audit edge appliances and Linux hosts for indicators of compromise and ensure firmware/OS patching is current.

cybersec BleepingComputer

C0XMO Botnet Spreads via DD-WRT Router Flaw, Kills Rival Malware

A new Gafgyt variant called C0XMO is actively exploiting a vulnerability in DD-WRT router firmware and supports multiple CPU architectures, allowing lateral spread across heterogeneous network devices. The botnet also removes competing malware to secure exclusive control of compromised hosts — a sign of increasing sophistication in IoT/network-device threats. Admins should audit any DD-WRT devices on or connected to their networks and apply available patches or replace end-of-life hardware.

cybersec BleepingComputer

Over 20,000 Instagram Accounts Stolen in Meta AI Support Hack

Attackers abused Meta's AI-powered support system to trigger password resets and hijack more than 20,000 Instagram accounts in a single campaign. The incident highlights how AI-assisted customer support workflows can introduce new attack surfaces if authentication gates are insufficiently hardened. For enterprise environments using AI-powered helpdesk or identity tooling, this is a timely reminder to review account-recovery and password-reset authorization controls.

cmmc BleepingComputer

Oxford University Discloses Data Breach After CareerConnect Platform Hack

Oxford University disclosed a breach of its CareerConnect careers platform after third-party provider Group GTI notified the university that the system had been compromised. The incident underscores ongoing supply-chain and third-party vendor risk, a key concern under CMMC Level 2's requirements for assessing and managing external system connections (NIST 800-171 3.13.x). Organizations should verify contractual security requirements with SaaS and platform vendors handling any sensitive or PII data.

infrastructure The Hacker News

VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks

Microsoft is implementing a two-hour hold on automatic VS Code extension updates, giving the security community a window to detect and flag malicious or tampered packages before they reach developer workstations. This is a direct response to growing software supply chain risk in developer tooling, which is increasingly relevant as Ansible playbooks, infrastructure-as-code, and CI/CD pipelines depend on extension ecosystems. Development teams in CUI-handling environments should also consider pinning extension versions and auditing marketplace extensions against approved software lists.

cybersec Schneier on Security

Anthropic's Project Glasswing Update

Bruce Schneier pushes back on widespread claims that Anthropic's Mythos model (from Project Glasswing) is superior at finding software vulnerabilities, noting that much of the coverage uncritically repeated Anthropic's marketing and that independent benchmarks don't support the claim. The post links to IEEE Spectrum analysis questioning the methodology behind the widely cited results. For teams evaluating AI-assisted vulnerability scanning tools, this is a useful caution against over-relying on vendor-driven benchmark narratives.