AUTO-UPDATED

ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories

Cybersecurity threats are evolving rapidly as attackers increasingly leverage AI, blockchain infrastructure, and sophisticated social engineering to exploit familiar vulnerabilities across enterprise and industrial systems.

Key Points

  • ReliaQuest confirmed a social engineering attack where hackers used a lookalike domain and fake SSO page to harvest credentials.
  • A new Android fraud bot named Octagon is being sold as malware-as-a-service for $1,400 per month, targeting banking and crypto apps.
  • The ToxNetV2 botnet has integrated NVIDIA NIM’s large language models to automate and optimize its malicious operational workflows.
  • CISA reported that Iranian threat actors targeted over 100 internet-exposed U.S. water systems by exploiting programmable logic controllers.
  • Microsoft warned that the window for patching vulnerabilities is shrinking as attackers use AI to accelerate the exploitation of newly disclosed flaws.
  • A supply chain attack dubbed Deadbugz is distributing malicious Model Context Protocol (MCP) servers to steal sensitive credentials from AI agents.

Why it Matters

The rapid integration of AI and decentralized infrastructure into malware campaigns is significantly shortening the time between vulnerability disclosure and active exploitation. Organizations face heightened risk as traditional security perimeters struggle to keep pace with automated, AI-assisted threats that bypass standard detection methods.
Internet Published by info@thehackernews.com (The Hacker News)
Read original