🛡️ Cyber Pulse Weekly | 17–23 August 2026 — Threats, CVEs, Attacks & AI Innovations

🔍 Threat Radar: Top 10 Active Threats, APTs & Dark Web Alerts

  1. Cavern C2 expands Iranian espionage tradecraft

    Kaspersky disclosed Cavern components that switch between direct HTTPS and Google Apps Script relays using DNS responses. The framework has targeted Israeli entities and is linked to Cavern Manticore, with only a low-confidence overlap assessment involving OilRig.

    Source: The Hacker News — https://thehackernews.com/2026/08/cavern-c2-uses-dns-and-google-apps.html

  2. Evooo1Bot turns exposed edge devices into SOCKS5 relays

    Fortinet reported that Evooo1Bot exploits known flaws in routers, cameras and other Linux edge devices. Its proxy, credential-sniffing, SSH brute-force and DDoS capabilities make compromised Gulf-facing infrastructure useful for anonymous follow-on operations.

    Source: The Hacker News — https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html

  3. SynkLoader uses Teams social engineering for hands-on access

    Operators impersonate IT support in Microsoft Teams and persuade targets to run a fake PowerShell-cleaner package. SynkLoader can harvest Windows credentials, tunnel into internal services and give attackers interactive shell or VNC control.

    Source: BleepingComputer — https://www.bleepingcomputer.com/news/security/new-synkloader-malware-pushed-in-microsoft-teams-phishing-campaign/

  4. ToxicPanda 2.0 blocks Google Play protections

    ToxicPanda now abuses Android VPN and Wireless ADB permissions, supports 167 remote commands and targets hundreds of financial applications. Its network control can interfere with Play Protect while overlays and PIN-harvesting functions capture banking credentials.

    Source: BleepingComputer — https://www.bleepingcomputer.com/news/security/toxicpanda-android-malware-uses-vpn-permissions-to-block-google-play/

  5. MoYu compromises Android vehicle head-unit update path

    Kaspersky attributed a supply-chain infection of DoFun Android car head units to MoYu. The malicious update chain installed proxy-botnet and ad-fraud payloads, although researchers found no interference with safety-critical vehicle controls.

    Source: BleepingComputer — https://www.bleepingcomputer.com/news/security/hackers-infect-android-car-head-units-with-proxy-botnet-malware/

  6. Rust crates poisoned in a high-impact supply-chain attack

    A compromised maintainer account published malicious versions of arrayref, append-only-vec and internment that executed infostealer code during compilation. Researchers noted infrastructure overlap with recent DPRK-linked activity but did not make a definitive attribution.

    Source: BleepingComputer — https://www.bleepingcomputer.com/news/security/hackers-poison-arrayref-rust-crate-to-push-infostealer-malware/

  7. FTP banners deliver E4del and PINHOLE RATs

    Threat actors embedded PowerShell commands in FTP greeting banners to deliver two new remote-access trojans. SOCRadar found the infrastructure remained operational in August and assessed phishing as the likely initial vector.

    Source: BleepingComputer — https://www.bleepingcomputer.com/news/security/hackers-abuse-ftp-server-banners-to-deliver-new-windows-malware/

  8. Head Mare exploits TrueConf servers to distribute backdoors

    CISA confirmed exploitation of CVE-2026-72529 and CVE-2026-72530, while Kaspersky linked attacks to Head Mare. Compromised servers replaced client installers with malicious versions targeting Russian organizations.

    Source: BleepingComputer — https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-trueconf-server-flaws/

  9. Medusa ransomware broadens critical-infrastructure impact

    U.S. agencies said Medusa affected more than 500 critical-infrastructure victims as of April 2026 across healthcare, defense, manufacturing, government, IT and finance. The affiliate operation recruits initial-access brokers to gain entry to prospective victims.

    Source: BleepingComputer — https://www.bleepingcomputer.com/news/security/cisa-medusa-ransomware-hit-over-500-critical-infrastructure-orgs/

  10. Manic relays stolen data through nearby infected phones

    ThreatFabric documented Manic using Wi-Fi Direct and Bluetooth peers to exfiltrate data when an infected device lacks internet access. The Android spyware and banking-malware platform targets 169 applications and can capture credentials, SMS, files and screens.

    Source: BleepingComputer — https://www.bleepingcomputer.com/news/security/new-manic-android-malware-can-exfiltrate-data-through-nearby-devices/