← All issues
cybersecurityCyberBubbleIran

Iran's Telegram Spy Tool, a DNS Time Bomb, and the Data Broker That Faked Its Own CEO

🌐  World Intel
Iran: Telegram Used as a Spy Tool Against Dissidents and Journalists

Iran-linked hackers operating under the name "Handala Hack" have been caught using a sneaky program called HEAVYGRAM that hides inside Telegram. Once installed, it can steal your passwords, take screenshots, and hand full control of your computer to someone overseas. The FBI first warned about this group back in March 2026, and researchers at Group-IB have now connected the dots between the malware and the Iranian-linked persona.

↗ The Hacker News
China: FamousSparrow Targets Latin American Governments with New Backdoor

A Chinese state-sponsored hacking group called FamousSparrow — previously linked to attacks on hotels and governments worldwide — is now targeting government organizations across Latin America. They're using a brand-new backdoor named SparroWocky, which researchers at ESET say is unusually sophisticated and built to avoid detection. Oddly, early versions of the malware included the opening lines of Lewis Carroll's nonsense poem "Jabberwocky" embedded inside the code.

↗ The Hacker News / BleepingComputer
Iran: CHOSEN BRICK Malware Targets Activists and Journalists Worldwide

Government agencies are sounding fresh alarms about another Iranian hacking campaign, this one using spyware called CHOSEN BRICK. The malware runs on Windows and is being used to spy on dissidents, activists, and journalists — people who criticize the Iranian government. If you or someone you know fits that profile, extra caution online is warranted right now.

↗ BleepingComputer
⚔️  Active Attacks
Hackers Hijack HBO Max's Reddit Account to Spread Malware via Fake Ads

Attackers took over the official HBO Max account on Reddit and used it to post fake ads loaded with a ClickFix scam. ClickFix is a technique where victims are shown a fake error message and told to manually run a command to "fix" it — but that command actually installs malware. Because the ads came from a verified, trusted brand account, many users had no reason to be suspicious.

🛡 What to do: Never paste a command into your computer because a website, ad, or social media post told you to — even if it looks like it comes from a brand you trust. Legitimate companies never ask you to do this.
Banking Malware Force-Installs Fake Browser Extensions to Steal Your Credentials

A banking malware operation active since mid-2025 is using a toolkit called KREMLIN to quietly install malicious extensions in Chrome and Edge — bypassing the normal checks that are supposed to prevent this. Once installed, these browser extensions steal your login credentials, session cookies, and other sensitive data. Your bank login, saved passwords, and active sessions are all at risk.

🛡 What to do: Open your browser's extensions page (chrome://extensions or edge://extensions) and remove anything you don't recognize or didn't intentionally install.
🔓  New Vulnerabilities
CVE-2026-81642 Unbound DNS Resolver CRITICAL 9.1

Every version of Unbound before 1.26.1 has a serious flaw in the part that validates DNS security signatures. An attacker who controls a malicious DNS zone can send a specially crafted response that crashes the resolver and runs their own code on your server — from anywhere on the internet, with no login required. This is about as bad as it gets for a network-facing service.

Status: Patch available — update to Unbound 1.26.1 immediately. No active exploitation confirmed yet.

CVE-2026-82717 Unbound DNS Resolver — CNAME Synthesis CRITICAL

A second serious bug was found in Unbound at the same time, this one in how the software processes CNAME records. It can corrupt memory in a way that could also lead to remote code execution on vulnerable systems, depending on how the software was compiled. It was discovered by a researcher at Anthropic — the AI company — and reported responsibly.

Status: Fixed in Unbound 1.26.1. No known active exploitation.

CVE-2026-CISCO-ISE Cisco Identity Services Engine (ISE) CRITICAL — MAX SEVERITY

Cisco has issued emergency patches for a maximum-severity zero-day vulnerability in its Identity Services Engine — software that many large organizations use to control who can access their network. Attackers are already actively exploiting this flaw in the wild. If your organization uses Cisco ISE, this needs to move to the top of your IT team's to-do list today.

Status: Patch available from Cisco. Actively exploited — patch immediately.

🛠  New Tech
FBI Takes Down NightmareStresser — One of the World's Longest-Running DDoS-for-Hire Services

The FBI has seized the domains belonging to NightmareStresser, a platform that let anyone — with no hacking skills — pay a small fee to knock websites and online services offline with a flood of fake traffic. These services are called booter or stresser services, and NightmareStresser was one of the oldest and most widely used. The takedown removes a tool that was routinely used for harassment, extortion, and disrupting businesses. It's part of an ongoing push by US law enforcement to dismantle the commercial infrastructure that makes cybercrime easy and accessible.

💡  Deep Dive
The Data Broker That Stonewalled Courts for a Decade Just Lost Its Website — Here's the Wild Story

If you've ever Googled your own name and found a website displaying your home address, phone number, and family members' details, you've probably encountered a data broker. Radaris.com was one of the biggest and most brazen of the bunch — and it just lost control of its own domain name in court after years of spectacular legal dodge-ball.

The story starts in New Jersey, where a law called Daniels Law gives police officers, judges, and other government officials the right to have their personal information scrubbed from data broker sites. A company called Atlas Data Privacy Corp sued Radaris for ignoring removal requests. What followed was a masterclass in stalling: Radaris kept shifting ownership of its domains through shell companies in places like the Marshall Islands, the British Virgin Islands, and the Seychelles. Every time a court judgment got close, a new mystery company would appear on paper as the "real" owner. At one point, investigators discovered that a freshly created Marshall Islands entity Radaris claimed was running the site didn't even exist yet when the paperwork was filed.

The co-founders — Russian-born brothers Igor and Dmitry Lubarsky, living in Massachusetts — even invented a fake CEO named "Gary Norden" to put on press releases while they sought investment. Their own attorney later admitted the name was made up. Despite all this, the legal games worked for nearly a decade. Previous plaintiffs gave up, exhausted by the procedural runaround. This time, Atlas committed to seeing it through. On August 26, 2026, after the defendants once again failed to appear and defend themselves, a judge ordered the radaris.com domain and more than a dozen related sites transferred directly to the plaintiffs.

This matters for regular people because data brokers quietly profit from publishing your personal details — and the people most at risk are often those who most need privacy, like domestic violence survivors, law enforcement officers, and journalists. The Radaris case shows both that the legal tools to fight back exist, and that using them can take years of grinding effort. If you want your own data removed from broker sites, services like DeleteMe or Google's Results About You tool can help automate requests — because waiting for the courts isn't always an option.

🛡️

Stay sharp. It's free.

Join thousands of readers who get daily cybersecurity news in plain English.

Subscribe Free →