UTA0560 exploited Chrome and Windows zero-days in one chain
Chinese-linked threat actor UTA0560 targeted NGOs and European organisations with precision spear-phishing. Victims were sent to trusted websites where a reflective XSS flaw in Google Chrome helped launch the first stage of the attack.
The chain then used CVE-2026-85046 in Chrome and CVE-2026-85880 in the Windows kernel to escape browser protections and execute malware silently. The combination allowed attackers to move from a booby-trapped web page to deeper system access without obvious user interaction.
@SableIndex | @SableIndexOTC
Chinese-linked threat actor UTA0560 targeted NGOs and European organisations with precision spear-phishing. Victims were sent to trusted websites where a reflective XSS flaw in Google Chrome helped launch the first stage of the attack.
The chain then used CVE-2026-85046 in Chrome and CVE-2026-85880 in the Windows kernel to escape browser protections and execute malware silently. The combination allowed attackers to move from a booby-trapped web page to deeper system access without obvious user interaction.
@SableIndex | @SableIndexOTC
π€£7π1π€1
Mexican Raid Finds 300 GPUs in Suspected Cartel Crypto Mine
Mexican authorities seized 300 GPUs, 80 medium-voltage terminals and eight satellite antennas from a hidden mine in Puebla, disrupting a suspected operation tied to cartel financing and stolen electricity.
The suspected actors are Mexican drug cartels, although authorities have not named a specific group. It was the fourth crypto mine uncovered near the dam since early 2025.
@SableIndex | @SableIndexOTC
Mexican authorities seized 300 GPUs, 80 medium-voltage terminals and eight satellite antennas from a hidden mine in Puebla, disrupting a suspected operation tied to cartel financing and stolen electricity.
The suspected actors are Mexican drug cartels, although authorities have not named a specific group. It was the fourth crypto mine uncovered near the dam since early 2025.
@SableIndex | @SableIndexOTC
π₯±6π2
Threat actor horrible Claims 200000 Integra EnergΓa Records For Sale
That a fresh dump from Spanish energy provider contains 200000 customer records, including emails, phone numbers, IBANs and service addresses.
If genuine, the combination could support targeted phishing or unauthorized SEPA direct-debit attempts.
@SableIndex | @SableIndexOTC
That a fresh dump from Spanish energy provider contains 200000 customer records, including emails, phone numbers, IBANs and service addresses.
If genuine, the combination could support targeted phishing or unauthorized SEPA direct-debit attempts.
@SableIndex | @SableIndexOTC
π6π4π€£1
Bro WE(yes you and me) are Ancy Sojan
And if you dont see news about it: 100+ tiktok accounts verifed to one leaked passport
@SableIndex | @SableIndexOTC
And if you dont see news about it: 100+ tiktok accounts verifed to one leaked passport
@SableIndex | @SableIndexOTC
π8
Suspected TON NFT exploit may leave buyers without assets
One seller is receiving GRAM from automatic buy orders while keeping the NFT, potentially leaving buyers without the asset they paid for. The wallet balance reportedly rose from about 300 to 1,400 TON within minutes and is still increasing.
The reported wallet is visible on TONViewer.
The exploit and any losses remain unverified.
@SableIndex | @SableIndexOTC
One seller is receiving GRAM from automatic buy orders while keeping the NFT, potentially leaving buyers without the asset they paid for. The wallet balance reportedly rose from about 300 to 1,400 TON within minutes and is still increasing.
The reported wallet is visible on TONViewer.
The exploit and any losses remain unverified.
@SableIndex | @SableIndexOTC
1π6π€£1
Sable Index
Suspected TON NFT exploit may leave buyers without assets One seller is receiving GRAM from automatic buy orders while keeping the NFT, potentially leaving buyers without the asset they paid for. The wallet balance reportedly rose from about 300 to 1,400β¦
The suspected Getgems exploit appears to have been closed. Based on the walletβs latest activity, the operator reportedly earned no more than 2,000 TON before selling the gifts used in the scheme and moving the proceeds to exchanges.
That is a remarkably small return for a flaw that could have been aimed at much more valuable NFTs, including Anon Numbers, High Value Scared Cats or Pepe.
@SableIndex | @SableIndexOTC
That is a remarkably small return for a flaw that could have been aimed at much more valuable NFTs, including Anon Numbers, High Value Scared Cats or Pepe.
@SableIndex | @SableIndexOTC
π€£8π1
Sable Index
π9π2π1
$174M Just Move Out of Bitget? Analysts Suspect a Hack
Analysts speculate that over $174M moved from Bitget-labelled hot and cold wallets to 0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee. Bitget has not confirmed a breach.
On Arbitrum, analysts flag an unverified $19.67M USDT0 buy of 7,111 ETH in six minutes via UniswapX and 1inch Fusion: WETH/USDC reportedly hit $2,870.
@SableIndex | @SableIndexOTC
Analysts speculate that over $174M moved from Bitget-labelled hot and cold wallets to 0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee. Bitget has not confirmed a breach.
On Arbitrum, analysts flag an unverified $19.67M USDT0 buy of 7,111 ETH in six minutes via UniswapX and 1inch Fusion: WETH/USDC reportedly hit $2,870.
@SableIndex | @SableIndexOTC
π5π€£1π1
ShinyHunters Puts Odido Leak Threat Back in Play
ShinyHunters has revived its pressure campaign against Dutch telecom company Odido, claiming it holds customer data and rejecting reports that its leak site was shut down.
The group previously demanded at least β¬1 million to keep the alleged data off the dark web.
@SableIndex | @SableIndexOTC
ShinyHunters has revived its pressure campaign against Dutch telecom company Odido, claiming it holds customer data and rejecting reports that its leak site was shut down.
The group previously demanded at least β¬1 million to keep the alleged data off the dark web.
@SableIndex | @SableIndexOTC
π€£6
A $1B Laundering Ring Hid in Plain Sight
After the $1.5 billion Bybit theft, blockchain investigator ZachXBT says he found alleged money launderers asking for help in public Telegram and Discord chats.
Posing as a client, he says he routed $349,700 in USDC through one contact, accepting roughly 5% in costs to build trust. The contact then shared wallet addresses, transaction screenshots and details of where funds would move next.
ZachXBT traced a cluster of more than $12 million allegedly linked to the Bybit theft as it moved through Bitcoin, Ethereum, Solana and Tron. Tether later froze about $442,000 in USDT tied to that cluster.
The investigator says the same network discussed $332,000 from the Poloniex hack and roughly $3 million from another fraud victim. His estimate: a Chinese laundering syndicate may have processed more than $1 billion stolen by Lazarus Group across multiple hacks.
ZachXBT says the evidence has been sent to law enforcement.
@SableIndex | @SableIndexOTC
After the $1.5 billion Bybit theft, blockchain investigator ZachXBT says he found alleged money launderers asking for help in public Telegram and Discord chats.
Posing as a client, he says he routed $349,700 in USDC through one contact, accepting roughly 5% in costs to build trust. The contact then shared wallet addresses, transaction screenshots and details of where funds would move next.
ZachXBT traced a cluster of more than $12 million allegedly linked to the Bybit theft as it moved through Bitcoin, Ethereum, Solana and Tron. Tether later froze about $442,000 in USDT tied to that cluster.
The investigator says the same network discussed $332,000 from the Poloniex hack and roughly $3 million from another fraud victim. His estimate: a Chinese laundering syndicate may have processed more than $1 billion stolen by Lazarus Group across multiple hacks.
ZachXBT says the evidence has been sent to law enforcement.
@SableIndex | @SableIndexOTC
π€£5π1π1