A threat group linked to Iran, known as TAG-182, is actively distributing a surveillance tool called MarkiRAT. This malware is being spread through fake applications disguised as VPNs and download tools, primarily targeting Iranian citizens both within and outside the country. The operations appear to be conducted via social media platforms and are likely part of Iran's intensified cyber surveillance efforts.

A cyber-espionage group identified as TAG-182, believed to be operating on behalf of the Iranian government, is actively distributing a surveillance tool known as MarkiRAT. This malware is being disseminated through fake applications designed to mimic legitimate services like VPNs and media players, with the apparent aim of collecting intelligence on Iranian targets both within and outside the country.
Researchers have observed TAG-182 utilizing social media platforms, particularly Instagram, to promote these deceptive applications. The group's activities are thought to have intensified following a period of reduced kinetic conflict involving Iran, the United States, and Israel. This shift in focus is seen as a redirection of Iranian security efforts towards enhanced cyber surveillance and digital enforcement against perceived dissidents and alleged foreign collaborators. The restoration of partial internet access in Iran on May 26, 2026, is also believed to be a factor in the increased activity.
The MarkiRAT malware itself has a history of being employed by a group previously tracked as Ferocious Kitten for surveillance operations targeting anti-government networks, activists, and human rights advocates within Iran. Analysis of new MarkiRAT samples associated with TAG-182 reveals significant overlaps in tradecraft with earlier variants. One notable similarity is the use of the Background Intelligent Transfer Service (BITS) for malicious purposes, a technique also observed in previous Ferocious Kitten campaigns.
TAG-182 has been observed creating dedicated websites to host and distribute these fake applications. One such application is named "YESHICA," with related samples found under the name "YEPlayer." Another lure identified is "Pis2ray VPN," which is not available on official app stores. In March 2026, researchers noted a new sample associated with TAG-182's infrastructure using the name "YESHICA YEPlayer," indicating a continued use of similar naming conventions despite previous exposure of their methods.
The infrastructure supporting TAG-182's operations includes a cluster of domains hosted on a server managed by 23M GmbH. Additional attacker-controlled assets are also hosted on servers provided by CrownCloud. The group predominantly uses Let's Encrypt certificates for its domains and employs a variety of naming conventions, often incorporating terms like "microsoft," "download," "vpn," "google," and names of social media entities to lend an air of legitimacy to their fake applications.
Initial access to a victim's system typically begins with a request to a compromised or attacker-controlled domain, such as vip.yeplayer.store, to download a malicious archive. Even if the website displays an error, the payload continues to be delivered, suggesting deliberate staging. Upon execution of the malware, such as YEPlayer.exe, it initiates communication with a command-and-control server, for example, microsotf.comi-site.website, using a POST request to upload data.
Further analysis of the malware reveals it attempts to disguise itself by creating a file named "svehost.exe," which mimics the legitimate Windows process "svchost.exe." This malicious file is often placed in the AppData\Windows directory, and the malware then removes the hidden file attribute to make it visible.
The researchers emphasize that TAG-182 is likely an integral part of Iran's broader surveillance apparatus. The group's focus on targeting Farsi-speaking communities, combined with the technical overlaps in malware and infrastructure, strongly suggests a direct connection to Iranian state-sponsored cyber operations. The ongoing nature of these operations is expected, particularly as Iranian authorities continue to prioritize digital surveillance for domestic security objectives.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed