Critical

Angry Birds: Toy Ghouls’ new toys

Securelist
Actively Exploited

Overview

Kaspersky's GERT team has identified new backdoors linked to the hacking group known as Toy Ghouls. These backdoors utilize two distinct methods for command-and-control: one operates through the HiveMQ MQTT broker, while the other employs the Matrix-based Element messenger. This discovery raises alarms as it indicates the group's ongoing efforts to establish secure communication channels for their malicious activities. The use of these platforms suggests that the attackers may be adapting their techniques to evade detection, which could pose significant risks to organizations relying on these technologies. Understanding and mitigating this threat is crucial for enhancing cybersecurity measures against such evolving tactics.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: HiveMQ MQTT broker, Matrix-based Element messenger
  • Action Required: Organizations should monitor their systems for unusual activity related to HiveMQ and Element, and implement security measures to detect and block unauthorized access.
  • Timeline: Newly disclosed

Original Article Summary

Kaspersky GERT experts have discovered new backdoors used by the Toy Ghouls group. One version of the backdoor uses the HiveMQ MQTT broker as its command-and-control server; the other uses the Matrix-based Element messenger.

Impact

HiveMQ MQTT broker, Matrix-based Element messenger

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Newly disclosed

Remediation

Organizations should monitor their systems for unusual activity related to HiveMQ and Element, and implement security measures to detect and block unauthorized access.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Malware, Kaspersky.

Related Coverage

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

The Hacker News

Recent vulnerabilities in PaperCut have been exploited by attackers to steal credentials from educational institutions in the U.S. and Europe. The Arctic Wolf Adversary Research Team identified two specific vulnerabilities, CVE-2026-81578 and CVE-2026-82078, which allow for authentication bypass and remote code execution. These flaws enable attackers to execute commands and gather information within the affected systems. The impact is particularly significant for schools and universities, as they often handle sensitive student and staff information. Immediate action is essential to prevent unauthorized access and potential data breaches.

Sep 5, 2026

European parliament members call for slowdown of Serbia’s EU entry over spyware use

CyberScoop

Members of the European Parliament are urging a delay in Serbia's entry into the European Union due to concerns over the government's use of spyware against activists. This call comes after reports that Serbian student activists were targeted with the invasive Pegasus and NoviSpy spyware. These revelations have raised alarms about human rights and privacy violations in Serbia, especially in the context of its EU accession talks. The situation reflects broader pressures on the Serbian government regarding its commitment to democratic practices and the protection of civil liberties. The Parliament's stance indicates that future EU membership may depend on significant improvements in these areas.

Sep 4, 2026

HPE Patches Critical RCE Vulnerabilities in AOS-CX

SecurityWeek

Hewlett Packard Enterprise (HPE) has released critical patches to address a series of vulnerabilities in its AOS-CX networking operating system. These vulnerabilities, collectively identified as CVE-2026-73749, carry a high severity score of 9.8, indicating they could allow remote code execution. This means that attackers could potentially exploit these flaws to take control of affected systems from a distance. Organizations using AOS-CX should prioritize applying these updates to safeguard their networks. The vulnerabilities are significant as they could affect a wide range of network devices, potentially putting sensitive data and operations at risk.

Sep 4, 2026

Companies Have 6 Months to Prepare for Automated Attacks

darkreading

Recent advancements in AI technology have enabled automated systems to conduct end-to-end attacks on various digital infrastructures. These AI models can compromise systems either intentionally or inadvertently, raising alarms for organizations that rely on traditional cybersecurity defenses. Experts warn that companies have a six-month window to enhance their security measures in anticipation of these automated threats becoming more prevalent. The urgency lies in the fact that as AI capabilities improve, so does the potential for sophisticated attacks that could bypass existing security protocols. Organizations need to prepare by investing in updated security technologies and protocols to safeguard their data and systems against these emerging risks.

Sep 4, 2026

Critical Citrix NetScaler auth bypass now leveraged in attacks

BleepingComputer

Attackers are now exploiting a significant vulnerability in Citrix NetScaler, identified as CVE-2026-19490, which allows for authentication bypass. This flaw poses a severe risk as it could enable unauthorized access to systems using affected versions of NetScaler. Companies that utilize Citrix NetScaler for application delivery or networking are particularly at risk, as this vulnerability can compromise their security posture. Security researchers from Previdian have reported that the flaw is actively being exploited in the wild, indicating an urgent need for users to assess their systems. Organizations should prioritize applying any available patches or implementing mitigation strategies to protect against potential breaches.

Sep 4, 2026

PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution

The Hacker News

PostgreSQL has issued updates to fix a serious security vulnerability, tracked as CVE-2026-6471, that has existed for 12 years. This flaw allows users with the REPLICATION attribute to execute arbitrary code as the operating system user running the database server. The vulnerability affects several versions of PostgreSQL, specifically those released before 18.6, 17.11, 16.15, 15.19, and 14.24. The potential for attackers to exploit this flaw poses a significant risk to database security, making it crucial for users to apply the updates promptly. The vulnerability was introduced with the logical decoding feature in PostgreSQL 9.4, highlighting the importance of regularly updating database systems to protect against long-standing vulnerabilities.

Sep 4, 2026