A sophisticated cyberattack campaign, identified in July 2025, leveraged SEO poisoning to trick users searching for ManageEngine OpManager into downloading a trojanized installer. This led to the deployment of Bumblebee malware, which then established a command-and-control channel using AdaptixC2. The attackers exploited this access for credential harvesting, lateral movement, and ultimately deployed Akira ransomware across the victim's network.

In July 2025, a targeted cyberattack campaign initiated through SEO poisoning successfully compromised a network by luring a user searching for "ManageEngine OpManager" to a fraudulent website. This site delivered a trojanized installer, which, upon execution, deployed the Bumblebee malware. The initial infection was facilitated by a malicious MSI installer, executed by an IT administrator who was deceived by a convincing look-alike domain.
Following initial access, Bumblebee established command-and-control (C2) communication using a component known as AdaptixC2. This allowed the threat actors to map the internal network using legitimate Windows tools and gain further access. The attackers demonstrated a clear objective to escalate privileges, creating new domain accounts with Enterprise Admin rights and installing remote access tools like RustDesk on multiple servers.
The attackers then moved laterally within the network, targeting a domain controller and a backup server. They employed advanced techniques for credential harvesting, including extracting the NTDS.dit Active Directory database and decrypting Veeam backup credentials. Tools like lsassy were used to dump LSASS memory, further aiding in credential acquisition.
Defense evasion and stealth were key components of the attack. The threat actors utilized reverse SSH tunnels to bypass firewall restrictions and employed obfuscation techniques for command-line arguments. In one instance, a Bring Your Own Vulnerable Driver (BYOVD) attack was used to disable endpoint security controls, highlighting a multi-faceted approach to evading detection.
Data exfiltration was conducted using FileZilla, with over 75GB of sensitive data, including file shares and domain configurations, being transferred to a server controlled by the attackers. The operation concluded with the deployment of Akira ransomware, which was used to encrypt critical systems after Volume Shadow Copies were deleted to prevent easy recovery.
This campaign is part of a broader pattern of Bumblebee SEO poisoning attacks observed since May 2025, which consistently use a two-tier delivery architecture involving impersonation front-ends and universal delivery gateways. These attacks have targeted various enterprise software, including WinMTR, Zenmap, and Ivanti VPN, often utilizing shared infrastructure and code-signing certificates.
Analysis of the infrastructure revealed overlap with other campaigns, including one targeting Ivanti VPN users, which also employed SEO poisoning and similar delivery mechanics. However, the Ivanti campaign differed in its payload and signature attribution, suggesting a coordinated but potentially evolving threat landscape.
The intrusion was first reported to customers in July 2025 and publicly disclosed in August 2025 in partnership with Swisscom B2B CSIRT, which observed a related intrusion. The detailed analysis of these incidents provides valuable insights into the tactics, techniques, and procedures employed by these threat actors.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed