> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> InfoSec News Nuggets – 10/09/2026

[SOURCE] AboutDFIR [AUTHOR: Mary] [DATE: 09/10/2026 13:46] [LANGUAGE: EN]
US Disrupts Chinese State-Sponsored Hacking Tools The United States has disrupted MicroScan and FishHub, two hacking tools built by Beijing-based Integrity Technology Group and used by Flax Typhoon and other Chinese state-sponsored groups against US and foreign critical infrastructure. Authorities seized the domains used to access the tools, which supported vulnerability scanning through a Mirai-based IoT botnet and spear-phishing intrusions that hit targets including a US power company, Japanese and Polish airports, and at least 20 Taiwanese universities. A joint advisory from seven countries says MicroScan has been active since at least 2017 and packs more than 1,300 scanning scripts, while the operators stole email data from government, law enforcement, healthcare, and religious organizations across Southeast Asia.   Low-cost Android phones ship with residential proxy malware A campaign dubbed Midnight Mimosa has been found embedded in the firmware of budget Android phones running MediaTek chipsets, giving the malware system-level privileges to silently install apps, commit ad fraud, and turn devices into residential proxies. Bitdefender researchers say thousands of devices across more than 150 countries were affected over roughly two years, including models branded as Doogee and Cubot as well as knockoffs posing as Samsung and Apple phones. The malware disguises itself as Android system packages, briefly disables the Play Store to dodge Play Protect, and can only be removed through firmware-level cleanup or ADB, while 13 related apps were also found on Google Play.   ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms CrowdStrike has detailed a campaign that used ARTEX, an open-source agentic penetration testing tool developed in China, together with large language models to steal data from South Korean financial organizations between late September and early October. Researchers uncovered the operation through open directories on a Hong Kong server that exposed AI coding session histories, memory files, and ARTEX configuration files, with the tool running on DeepSeek alongside other models. The activity has not been tied to a known group but points to a financially motivated Chinese-speaking operator, and the ARTEX developer has since taken the project closed source, citing abuse of the tool.   Exploitation attempts against critical Atlassian flaw have begun (CVE-2026-21589) Attackers began probing a critical arbitrary file access vulnerability in Atlassian’s self-managed Data Center products just hours after watchTowr published a technical analysis, a day after patches were released. The flaw, CVE-2026-21589, affects Jira, Confluence, Bitbucket, Bamboo, Crowd, Crucible, and Fisheye, and stems from a shared library that converts double colons into forward slashes, letting attackers slip path-traversal payloads past defenses. Researchers showed that reading Crowd’s plaintext properties file can hand over credentials capable of creating Jira admin accounts, and Atlassian is urging customers to upgrade immediately or pull vulnerable instances off the internet.   ASOS “hackers” send push notifications to customers Thousands of ASOS customers received a push notification through the retailer’s own app claiming attackers had fully compromised the company’s Snowflake instance and threatening to leak data unless ASOS engaged with them. The message was linked to a group calling itself Xuanye, and ASOS is known to use the Snowflake-based personalization platform Simon AI alongside Braze to drive customer messaging, which could expose detailed shopping profiles if accessed. ASOS confirmed the unauthorized notification, restricted access to its messaging platforms, and said names and contact details may have been accessed but not payment card data or passwords, so customers should watch for follow-on phishing. The post InfoSec News Nuggets – 10/09/2026 appeared first on AboutDFIR - The Definitive Compendium Project.
[messages.read_original_source] →