Sable Index
870 subscribers
133 photos
2 videos
6 links
Download Telegram
[MALWARE] Microsoft Patches 400 Flaws After Lazarus Zero-Day Attacks

Microsoft released security updates for 400 vulnerabilities, including a Windows zero-day already exploited by North Korea’s Lazarus group.

After gaining local access, attackers can exploit the flaw without further user interaction, obtain SYSTEM privileges and deploy a stealthy rootkit.

Two more zero-days were publicly disclosed, while 42 vulnerabilities were rated critical.

@SableIndex | @SableIndexDiscussion
🤓73
[EXPLAINED · CRIME] Scattered Spider Wins by Making Employees Open the Door

Scattered Spider does not usually begin with an exotic software exploit. Its operators call a company’s help desk, sound convincing and persuade someone to hand them access.

That simple idea has produced extraordinary damage. In July 2026, the US Justice Department described the group as responsible for more than 100 network intrusions, over $100 million in ransom payments and millions more in disruption. The statement accompanied the extradition of 19-year-old Peter Stokes, an alleged member who has not been convicted.

Scattered Spider is less a traditional gang than a shifting cybercrime network. Authorities and researchers also track parts of the same activity as Octo Tempest, UNC3944, 0ktapus and Muddled Libra. Those labels describe overlapping behavior, not a reliable membership list.

The attack often starts with research. Criminals collect an employee’s name, role, phone number and internal vocabulary from social media, leaked databases and previous breaches. They then impersonate that employee to technical support, or pose as support when contacting the employee.

The goal is a password reset and a new multifactor-authentication device. If persuasion fails, the attackers may flood the victim with login prompts, steal a one-time code or convince a mobile carrier to transfer the victim’s number to another SIM. No Hollywood-style hacking is required when the criminal can make the real support process work on their behalf.

Once inside, the group frequently uses legitimate administration software such as AnyDesk, TeamViewer or ScreenConnect. These tools are common in real IT departments, so their presence alone may not trigger an alarm. The intruders steal data, move through cloud accounts and sometimes deploy ransomware. CISA says recent activity has included DragonForce.

The 2023 MGM Resorts attack showed what this method can do. Hotel systems, digital room keys and casino operations were disrupted. MGM later estimated that the incident reduced quarterly earnings by roughly $100 million. The attackers did not need to defeat every security product; they needed an identity trusted by those products.

The network also appears willing to move quickly between targets and monetization methods. A 2026 US complaint alleges that Stokes and accomplices demanded about $8 million from a jewelry retailer. The company expelled them and paid nothing, yet still recorded at least $2 million in response and disruption costs.

Arrests matter, but they do not automatically dismantle Scattered Spider. A loose network can replace an operator, reuse stolen access and reorganize under another name. Its most valuable capability is fluent, patient social engineering - not a single server that police can seize.


The uncomfortable lesson is that an employee can follow a familiar support procedure and still open the door. Strong defenses require phishing-resistant security keys, strict identity checks for password resets and callbacks through a known company number. A convincing voice should never be enough to transfer control of an account.

@SableIndex | @SableIndexDiscussion
🤓8🕊2👀1
[FRAUD] FBI Warns Hackers Are Stealing Private Photos for Blackmail

The FBI says criminals are breaking into social media accounts to steal intimate photos and videos, including content belonging to children.

Stolen material may be sold on criminal marketplaces or used for sextortion. Victims can then face repeated harassment, stalking and threats aimed at obtaining more images or money.

@SableIndex | @SableIndexDiscussion
👀6💊2
[DEVELOPING · MALWARE] Poisoned AI Package Exposes Secrets From Thousands of Companies

Researchers say malicious LiteLLM releases captured files linked to more than 2,500 organizations after circulating on PyPI for only 40 minutes.

The malware ran whenever Python started, stealing cloud keys, SSH keys, database passwords and AI-provider credentials, even without LiteLLM being imported.

The figure shows potential exposure, not 2,500 confirmed breaches. Confirmed downstream victims include Mercor and Checkmarx; CERT-EU says a related compromise exfiltrated about 91.7 GB from a European Commission cloud account.

@SableIndex | @SableIndexDiscussion
👀8🤓4💊3
[MALWARE] 737 Fake VPN Extensions Routed Users Through Proxies

Researchers found 737 Chrome VPN and proxy extensions with 75,486 installs; 274 impersonated established brands such as Proton VPN, ExpressVPN and AdGuard.

While connected, the extensions routed entire browser sessions through SOCKS5 servers tied to one provider, exposing destinations, IP addresses and any data sent over plain HTTP.

@SableIndex | @SableIndexDiscussion
🤓6💊3👀22
[MALWARE] WindRelay Turns Android Phones Into Payment Relays

Researchers found WindRelay, Android malware that can relay a victim’s contactless card to an attacker’s payment terminal.

WindRelay works with the SpyNote remote-access trojan. After a fake banking app is installed, criminals activate the phone’s NFC reader remotely and stream live card data to another device, enabling card-present purchases or cash withdrawals.

@SableIndex | @SableIndexDiscussion
💊9🕊5👀3
[CRIME] Hackers Drain 99.7% of XRP-Coreum Bridge Reserves

Attackers drained 99.7% of the XRP-Coreum bridge’s reserves in less than two hours.

The exploit targeted the cross-chain bridge that moves tokens between the XRP Ledger and Coreum. Once the attack began, the reserves were rapidly emptied, leaving almost nothing behind for users and liquidity providers.

The incident highlights why bridges remain one of crypto’s most dangerous weak points: a single exploit can empty an entire pool before developers can react.

@SableIndex | @SableIndexDiscussion
👀7🕊4💊41
[CRIME] Brightly contractor gets two years for insider extortion

A former Brightly Software contractor was sentenced Thursday to 24 months in prison after stealing employee and corporate data, then demanding $2.5 million in cryptocurrency to keep it private.

Cameron Curry, 27, sent more than 60 threatening emails under the alias “Loot.” A federal jury convicted him in March on six extortion counts. CyberScoop reports Brightly ultimately paid $7,540.92.

@SableIndex | @SableIndexDiscussion
🤓7👀5🕊2
[DEVELOPING · FRAUD] Jewelbug Spies on Governments While Running Crypto Scams

The China-based Jewelbug group breached webmail accounts across 15 government tenants while operating a parallel cryptocurrency fraud business.

Symantec found one control panel linking both operations. Hackers injected a script into shared webmail software to steal cookies, credentials and email data.

Researchers found more than 580,000 stolen browser cookies, thousands of credentials and over 2,300 exfiltrated emails.

The group also uses AI-generated pages and lookalike OKX and Binance domains to push fake crypto exchanges.

@SableIndex | @SableIndexDiscussion
👀5🕊2🤓2
[MALWARE] Apple Sends New Mercenary Spyware Alerts to iPhone Users

Apple sent a new wave of threat notifications on August 13 to iPhone users it believes were individually targeted by mercenary spyware, according to user reports and updated company guidance.

Apple calls these high-confidence alerts but has not named the spyware, operator, countries or number of targets.

@SableIndex | @SableIndexDiscussion
👀5🤓1💊1
[CRIME] Four Arrested Over €30M Bank Fraud Linked to Payment Flaw

Brazilian police arrested four suspects and seized assets worth up to R$106 million in Operation Klonen.

Investigators allege the attackers exploited a faulty software update at a financial service provider to trigger unauthorized withdrawals from German online-bank accounts in November 2023. The funds were routed through Brazil, pass-through accounts, payment institutions and crypto platforms.

Three more suspects were charged in Spain and Bulgaria. Commerzbank said clients were affected but suffered no financial loss.

@SableIndex | @SableIndexDiscussion
👀4🕊1🤓1
[MALWARE] Evooo1Bot Adds Stealth and Credential Theft to Mirai

Fortinet researchers identified Evooo1Bot, a new Mirai-based Linux botnet targeting internet-facing routers and edge devices since July.

It installs persistence, brute-forces SSH, steals credentials and turns infected systems into SOCKS5 relays that can hide attacks or reach restricted networks. Targets include Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare and D-Link devices.

Newer builds add exploits for cameras, firewalls, NAS devices and Kubernetes ingress. Patch edge devices, replace default credentials and disable remote administration.

@SableIndex | @SableIndexDiscussion
👀51
[BREACH] Forum Account Claims 40GB National Grid Leak

A cybercrime forum account posted a 40GB archive it says came from UK energy operator National Grid. HackRead found 5,525 files totaling about 42.8GB, including source code, CI/CD scripts, Terraform, cloud configurations and internal project documents.

The account has no previous posts, and the access path is unknown. National Grid has not confirmed an incident. There is no evidence of disrupted electricity services or compromised control systems; customer data is not confirmed.

@SableIndex | @SableIndexDiscussion
👀3
[EXPLAINED · FRAUD] The $5M “Support” Scam Trail - Calls, Monero and Telegram Usernames

ZachXBT says US-based Tiffany Milanovich was a caller in a crypto support-impersonation network tied to at least $5M in thefts. The caller’s role is simple and brutal: pose as wallet or exchange support, keep the victim on the phone, and talk them into handing over access.

In June 2026, a victim allegedly lost $1.2M in BTC and ETH after receiving a spoofed BitcoinIRA email under the alias “Patricia Massie.” The group then drained the victim’s Trezor wallet. ZachXBT attributes the phishing-panel infrastructure to an actor known as “bled” / “harm” - and says most of the proceeds still have not moved.

A separate October 2025 case involved about $500K in BTC drained from a Coinbase account. ZachXBT says Tiffany was recorded complaining about her share, and later posted a withdrawal screenshot herself.

The more niche clue is the money trail: in February, Tiffany allegedly showed off $100K in an Exodus wallet during a Discord “band 4 band” call. The address now holds 631K DAI, reportedly funded via multiple instant exchanges from Monero.

The exposure began after Tiffany allegedly mocked John “Lick” Daghita in a recording; Daghita then posted her name in Telegram. ZachXBT also says Shuffle reviewed evidence that stolen funds were gambled through one of its accounts and agreed to lock it.

Two days later, Telegram username NFTs linked to Tiffany and her associate Haby appeared for sale in a marketplace channel. A channel reportedly tied to @disappear, @trezor666, also contains satanic-themed drawings - a bizarre detail, but not evidence of any mental-health condition.


These remain ZachXBT’s allegations, supported by recordings, chats and on-chain data. No public court finding against Milanovich has been identified.

@SableIndex | @SableIndexDiscussion
1👀8🤓3
[BREACH] France Confirms Theft of 678,000 Tax Records

France’s tax authority says attackers used compromised credentials to extract data on 678,000 individuals and businesses. Exposed fields include names, taxable income, withholding-tax rates, company IDs, addresses and property details.

Passwords and secure tax accounts were not compromised. Actor “ZeroBytes” claimed access to 2 million records and offered them for sale, but that figure is unverified. The confirmed data can fuel targeted phishing and identity fraud.

@SableIndex | @SableIndexDiscussion
4