Critical

FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails

The Hacker News
Actively Exploited

Overview

On October 8, the FBI, along with agencies from six other countries, reported that hackers linked to a Chinese cybersecurity company, Integrity Technology Group, have been stealing emails from various organizations in Southeast Asia. These include government bodies, law enforcement, healthcare systems, and religious institutions. The hackers exploited vulnerabilities in websites to gain access to sensitive information. The U.S. and the UK have already imposed sanctions on Integrity Technology Group due to its involvement. This incident raises concerns about the security of critical sectors and the potential for sensitive data to be misused, highlighting the ongoing risks posed by state-sponsored cyber activities.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: Email systems of government organizations, law enforcement agencies, healthcare systems, religious institutions
  • Action Required: Organizations should review and strengthen their website security, patch vulnerabilities, and monitor for unusual access patterns.
  • Timeline: Disclosed on October 8, 2023

Original Article Summary

Hackers tied to a Chinese cybersecurity company stole email from government organizations, law enforcement agencies, healthcare systems, and religious institutions in Southeast Asia, the FBI and agencies in 6 other countries said on October 8. The company, Integrity Technology Group, has been sanctioned by the U.S. and the UK. The hackers scanned websites for flaws using a tool containing more

Impact

Email systems of government organizations, law enforcement agencies, healthcare systems, religious institutions

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Disclosed on October 8, 2023

Remediation

Organizations should review and strengthen their website security, patch vulnerabilities, and monitor for unusual access patterns.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Data Breach, Critical.

Related Coverage

FakeGit malware campaign returns with 17,610 malicious GitHub repos

BleepingComputer

A resurgence of the FakeGit malware campaign has been reported, with over 17,000 fake repositories on GitHub found to be distributing SmartLoader malware. This campaign has been reactivated to push the StealC infostealer, which is designed to steal sensitive information from users. Researchers indicate that both developers and users who download or interact with these fraudulent repositories are at risk. The situation is concerning because it not only affects individual users but also poses a threat to organizations that rely on GitHub for software development. The presence of such a large number of malicious repositories underlines the need for vigilance in verifying the legitimacy of software sources.

Oct 8, 2026

Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks

The Hacker News

A rise in personal data leaks has been reported in Japan, attributed to attackers exploiting mobile application APIs and known software vulnerabilities. The JPCERT Coordination Center issued an alert on October 8, 2026, based on various incident reports but did not name specific organizations or attackers involved. This increase in data breaches raises concerns for both consumers and businesses, as personal information may be exposed or misused. Organizations need to review their API security and address any software flaws to prevent further incidents. Users should be vigilant about their personal data privacy as these vulnerabilities can lead to significant risks.

Oct 8, 2026

UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML

The Hacker News

UAC-0099, a Russia-aligned hacking group, has been linked to a new malware called ASHVEIN, which functions as both an infostealer and a remote access trojan (RAT). This malware is currently being used in targeted attacks against Ukrainian government personnel. Researchers from TrendAI, who are tracking this activity under the name Earth Sirrush, report that ASHVEIN disguises its commands within HTML, making it harder to detect. This development raises concerns about the security of government systems in Ukraine, particularly given the ongoing geopolitical tensions in the region. As these attacks evolve, it highlights the need for enhanced cybersecurity measures among officials and government staff.

Oct 8, 2026

SonicWall and Splunk Patch Critical Vulnerabilities

SecurityWeek

SonicWall and Splunk have recently addressed serious vulnerabilities that could let attackers bypass authentication, execute arbitrary code, or gain higher privileges on affected systems. These vulnerabilities are critical and high-severity, meaning they pose significant risks to organizations using these products. The flaws affect various versions of SonicWall's firewall software and Splunk's data analytics platform, making it essential for users to apply the patches as soon as possible. If left unaddressed, these vulnerabilities could lead to unauthorized access and manipulation of sensitive data. Organizations using these services should prioritize updating their systems to protect against potential exploitation.

Oct 8, 2026

ASOS links data breach to social engineering attack, credential theft

BleepingComputer

ASOS has confirmed that it recently experienced a data breach linked to a social engineering attack, which led to the theft of customer credentials. The company is actively notifying affected customers about the incident, which involved unauthorized access to personal data. This breach raises concerns about the security measures in place to protect user information, especially given the rise in social engineering tactics that trick individuals into revealing sensitive data. Customers are advised to monitor their accounts for any suspicious activity and to change their passwords as a precaution. The incident serves as a reminder of the vulnerabilities that can arise from social engineering and the importance of maintaining strong security practices.

Oct 8, 2026

16 Malicious Firefox Extensions Pose as Rabby and OKX Wallets to Steal Recovery Phrases

The Hacker News

Cybersecurity researchers have identified 16 harmful extensions for Mozilla Firefox that disguise themselves as wallet applications for Rabby and OKX. These malicious extensions are designed to steal sensitive information, specifically recovery phrases and private keys, by intercepting them during the wallet import process. Users who unknowingly install these extensions may find their cryptocurrency assets at risk. This incident serves as a reminder for users to be cautious about the browser extensions they add, especially those related to cryptocurrency management. Ensuring the legitimacy of such tools is crucial to safeguarding digital assets.

Oct 8, 2026