BotNet News

Your source for Online Security News

What happened:

Russian threat actor UAT11795 trojanized installers for WebEx, Zoom, DBeaver, MoaXTerm, and FaceIt via ClickFix lures since June 2026 to deliver Starland RAT and steal credentials. This expands attack vectors from Windows and raises the stakes for users of those applications.

Cybercriminals use vishing to extort money, impersonate company employees, and more over the phone. This new technique combines email phishing and smishing with voice calls and can include fake police station signage to build credibility layers, per a recent FBI/CISA advisory.

Interpol’s 5,800 arrests in Operation First Light demonstrate organized crime’s sophistication, including fake police stations, and reinforce why user awareness training must be real and substantive, not checkbox compliance. Threat actors weaponize dormant GitHub accounts for supply chain reconnaissance and private repo access, requiring stronger detection controls.

The UK is becoming a cybersecurity hub, with firms investing in resilience-focused vendors to meet increasing regulatory scrutiny. This aligns with a shift toward more risk-based approaches to security assessment.

What to watch:

Two Scattered Spider members received 5.5-year sentences for their roles in the Transport for London ransomware attack that cost PS39 million and disrupted critical infrastructure. This leniency sets a concerning precedent that could embolden other gangs to escalate their operations and justify lowered punishments. Meanwhile, phishing-as-a-service platform Forge 365 democratizes sophisticated account takeover attacks by wrapping device code fishing, adversary-in-the-middle attacks, and token management into a polished dashboard interface. Its browser cookie refresh feature enables persistent access even after password changes and 2FA resets.