← All issues
cybersecurityCyberBubblezero-days

Convicted Felons Are Buying Zero-Days — Plus Zimbra, ShareFile & Crypto Theft

🌐  World Intel
Netherlands: Dutch Hackers Suspected in Major Telecom Breach

Dutch police say they have strong evidence that local hackers broke into Odido, one of the country's largest mobile carriers, in a breach discovered back in February. The investigation is ongoing, and no arrests have been announced yet. If confirmed, it would be a rare case of a major telecom being hit by hackers from its own country.

↗ BleepingComputer
USA: FBI Seizes Millions of Devices Used as Covert Internet Relays

The FBI shut down NetNut, an Israeli-linked residential proxy service that secretly turned smart TVs and streaming boxes into internet traffic relays. At least two million home devices were roped into the network. The FBI worked with Google, Lumen, and Shadowserver to seize hundreds of domains tied to the operation.

↗ Krebs on Security
USA: Ryuk Ransomware Member Pleads Guilty, Faces 15 Years

A 34-year-old Armenian man admitted in a US court to hacking American companies and deploying ransomware called Ryuk — one of the most destructive ransomware families ever seen. He now faces up to 15 years in prison. Ryuk has been linked to hundreds of millions of dollars in damages against hospitals, schools, and businesses.

↗ BleepingComputer
⚔️  Active Attacks
Gitea Docker Image: Hackers Actively Exploiting Auth Bypass to Hijack Accounts

Attackers are actively exploiting a critical flaw in the official Docker image for Gitea, a popular self-hosted code repository tool. The bug lets anyone skip the login process entirely and impersonate any user on the platform — including administrators. That means an attacker could read private code, delete projects, or plant malicious changes in your software without ever knowing your password. If your organization runs a Gitea server using the official Docker image, you're potentially exposed right now.

🛡 What to do: If you run a self-hosted Gitea instance via Docker, update to the latest image immediately and audit your admin accounts for any unauthorized activity.
Injective Labs SDK Poisoned on npm — Crypto Wallet Keys Stolen

Hackers broke into the GitHub account of a trusted developer working on the Injective Labs crypto project. They used that access to publish a poisoned version of a widely used software package on npm. The fake package quietly grabbed cryptocurrency wallet private keys and seed phrases — essentially the master keys to your crypto — and sent them to the attackers. The malicious version was live on npm from July 8th before being flagged, but download files are still available on GitHub.

🛡 What to do: If you're a developer who uses @injectivelabs/sdk-ts, check whether version 1.20.21 is in your project. If so, treat any wallets it touched as compromised and move your funds immediately.
🔓  New Vulnerabilities
CVE PENDING Zimbra Classic Web Client — Stored XSS CRITICAL

A specially crafted email sent to a Zimbra user can run malicious code the moment that email is opened in the Classic Web Client. This is called a stored XSS flaw. An attacker who pulls it off could steal your login session, read your emails, and change your account settings — all without you clicking any link or downloading anything.

Status: Patch available — Zimbra is urging all customers to update immediately. No CVE number assigned yet.

CVE PENDING ×6 U-Boot Bootloader — Multiple Flaws CRITICAL / HIGH

Researchers found six bugs in U-Boot, the startup program used in millions of home routers, security cameras, and data center chips. Two of the bugs let an attacker run their own code before the device even finishes starting up, meaning all the security checks that follow could be bypassed. Four other bugs can crash the device outright. The attack works by slipping a malicious startup image in front of the bootloader before it verifies the software is genuine.

Status: Patches in progress from firmware vendors. Device owners should watch for firmware updates from their router or camera manufacturer.

CVE PENDING Progress ShareFile — Storage Zone Controller HIGH — THREAT ACTIVE

Progress Software told customers running ShareFile's Storage Zone Controller to shut their servers down immediately after identifying a credible external security threat. The company hasn't said exactly what the vulnerability is or who's behind it, but it preemptively disabled affected accounts and is working with outside security experts. No confirmed data breach yet — but the urgency of the shutdown order is a serious warning sign.

Status: No patch yet. Progress says to shut down Storage Zone Controller servers now while the investigation continues.

🛠  New Tech
Ghostcommit: The Attack That Hides Malicious Instructions Inside Images

Researchers demonstrated a new technique called Ghostcommit that hides prompt injection attacks inside ordinary PNG image files. The trick: AI-powered code review tools like CodeRabbit and Bugbot don't actually open or read image files — they skip them entirely. So a hidden instruction inside a PNG gets ignored by the reviewer, but a coding AI agent that later processes the repo reads it and follows the instruction. In the proof-of-concept demo, the agent found the project's secret environment variables and quietly wrote them into the code as a list of numbers — a way to smuggle stolen secrets out in plain sight. This matters because more and more software teams are using AI agents to review and write code, and this shows those agents can be manipulated in ways the human developers never see.

💡  Deep Dive
The Zero-Day Brokers Who Are Actually Convicted Felons Running a Fake Intelligence Company

A company calling itself IRIS C2 has been dangling payouts of up to $7 million to attract hackers willing to sell powerful, undisclosed software vulnerabilities — what the industry calls zero-days. The company presents itself as a legitimate Virginia-based cybersecurity firm. But investigative reporter Brian Krebs found that it's run by Jack Burkman and Jacob Wohl — two men with a long track record of running fake intelligence operations and spreading deliberate disinformation.

Burkman and Wohl are not exactly unknown quantities. Over the past several years, they fabricated sexual assault allegations against public figures including Robert Mueller and Pete Buttigieg, staged fake press conferences, and ran an illegal robocall campaign targeting Black voters in Detroit during the 2020 election. They were convicted on felony counts related to that scheme and sentenced to probation in late 2025. Now, under the corporate name Calvexa Group LLC, they appear to be positioning themselves inside the lucrative and largely unregulated market for offensive hacking tools.

Why does this matter to ordinary people? The zero-day market sits at the shadowy intersection of cybersecurity research and national security. Legitimate brokers do exist — governments and defense contractors pay real money for undisclosed vulnerabilities in software you use every day. But when bad actors enter that market, the flaws they acquire can end up in the hands of anyone willing to pay, from foreign governments to criminal ransomware gangs. A high-value zero-day in your phone's operating system or your company's email server is worth more than most people's annual salary.

The deeper issue is that this market has almost no public oversight. There's no licensing body, no background check requirement, and no law that stops convicted felons from buying and reselling software exploits. Watch for whether regulators or Congress respond to this story — and in the meantime, keeping your software updated is the single best defense against zero-days, because a patched flaw stops being a zero-day the moment the fix is released.

🛡️

Stay sharp. It's free.

Join thousands of readers who get daily cybersecurity news in plain English.

Subscribe Free →