Critical

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 110

Security Affairs
Actively Exploited

Overview

The latest edition of the Security Affairs Malware newsletter features significant developments in malware tactics, particularly focusing on the Kimsuky group. Researchers report that Kimsuky has integrated artificial intelligence into its operations, employing AI-generated decoy documents to mislead targets and utilizing a local language model for enhanced attack capabilities. Additionally, the newsletter discusses the evolution of the Kimwolf botnet, now at version 7, which poses a growing risk to various organizations. Agencies like CISA and the FBI are urging companies to stay vigilant against these emerging threats. The evolution of these malware tactics underscores the need for organizations to bolster their cybersecurity measures to protect sensitive information.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: Kimsuky group, Kimwolf botnet, various organizations
  • Action Required: Organizations should enhance cybersecurity measures, monitor for suspicious activity, and educate employees about potential phishing attempts.
  • Timeline: Newly disclosed

Original Article Summary

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM ShieldBreak – August 2026 disclosure Kimwolf v7: An Evolution of the Kimwolf Botnet CISA, FBI and Partners Warn Organizations of […]

Impact

Kimsuky group, Kimwolf botnet, various organizations

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Newly disclosed

Remediation

Organizations should enhance cybersecurity measures, monitor for suspicious activity, and educate employees about potential phishing attempts.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Malware, Botnet.

Related Coverage

Large-scale DDoS attacks disrupted Threema secure messaging service

BleepingComputer

Threema, a secure messaging platform, experienced significant disruptions earlier this week due to multiple distributed denial-of-service (DDoS) attacks. These attacks overwhelmed Threema's servers, causing service outages and making it difficult for users to send messages. While the company worked to restore normal operations, the incident raised concerns about the security of communication platforms and the potential for similar attacks in the future. Such disruptions can affect users' ability to securely communicate, particularly in sensitive situations where privacy is paramount. This event serves as a reminder of the vulnerabilities that even well-regarded secure services can face from malicious actors.

Aug 16, 2026

Mustang Panda Upgrades CoolClient With a Kernel Rootkit

Security Affairs

Mustang Panda, also known as HoneyMyte, has enhanced its CoolClient backdoor by deploying a signed kernel-mode driver that can conceal processes, files, and network activity. This upgrade makes it significantly harder for security software to detect and remove the malware from infected Windows systems. Kaspersky's recent analysis indicates that this new variant of CoolClient deepens the malware's integration into the operating system, raising concerns for users and organizations relying on Windows. The implications are serious, as this could allow attackers to maintain prolonged access to compromised systems while evading detection. Users and organizations need to remain vigilant and implement security measures to protect against this evolving threat.

Aug 16, 2026

Sophisticated Cyberattack Exposes Data of 678,000 French Taxpayers

Security Affairs

France's tax agency has reported a significant cyberattack that compromised the personal data of approximately 678,000 taxpayers. The breach, which occurred in late June, involved hackers stealing sensitive information including income and tax details. This incident has prompted the agency to launch a criminal investigation to identify the perpetrators and assess the extent of the breach. The exposure of such sensitive data raises serious concerns about identity theft and privacy for those affected. As authorities work to secure the system and protect citizens, this attack serves as a reminder of the ongoing risks posed by cybercriminals targeting government institutions.

Aug 16, 2026

Security Affairs newsletter Round 590 by Pierluigi Paganini – INTERNATIONAL EDITION

Security Affairs

A recent cybersecurity concern involves attackers purchasing expired domain names and using them to distribute malware. This tactic allows them to exploit the trust users have in familiar web addresses, potentially leading to security breaches and data theft. Companies and individuals who own domains should monitor their registrations closely to avoid falling victim to this scheme. Additionally, organizations need to educate users about the risks associated with clicking on links from unknown or expired domains. The implications of this practice are significant as it not only affects the victims directly but also undermines overall internet security trust. Staying vigilant and proactive in domain management is essential to mitigate these risks.

Aug 16, 2026

Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day

Help Net Security

Salesforce and ServiceNow portals were exposed for 17 months due to a security vulnerability that allowed unauthorized access to sensitive data. The flaw was discovered by researchers who pointed out that it could have been exploited by attackers to gain critical information from user accounts. The prolonged exposure raises serious concerns about data protection and incident response practices within these platforms. Organizations using these services should review their security measures and consider implementing additional safeguards to protect user data. This incident is a stark reminder of the importance of timely security updates and monitoring for vulnerabilities in widely used software.

Aug 16, 2026

APT36 Suspected in PATCHCORD Espionage Campaign Using Google Sheets C2

Security Affairs

Researchers at Acronis have identified a new espionage operation known as PATCHCORD, which targets telecommunications and infrastructure in Afghanistan and South Asia. This stealthy backdoor is delivered through fake VPN tools and utilizes Google Sheets as a command and control (C2) channel. The operation appears sophisticated, using common tools in deceptive ways to evade detection. The implications of this threat are significant, as it could compromise sensitive data and operations in a region already facing security challenges. Understanding the tactics used in PATCHCORD can help organizations better defend against such targeted attacks.

Aug 16, 2026