hacker-news · Crawled Aug 3, 2026

⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks

3 IoCs 2 Actors 1 Malware 4 CVEs
Read original article ↗

AI Summary

Multiple active threats were reported this week, including Russian threat actors exploiting a Microsoft OWA XSS vulnerability (CVE-2026-42897) to deploy a JavaScript-based implant called OWAReaper for persistent mailbox access. A critical Ruby on Rails vulnerability (CVE-2026-66066) allows unauthenticated attackers to read arbitrary files via crafted image uploads, potentially leading to remote code execution. Additionally, Iranian-linked actors are suspected in coordinated attacks on over 30 Minnesota water systems, where exposed PLCs were targeted to disrupt operations. Storm-2945 (APT29) conducted DNS hijacking via compromised Wi-Fi networks to deliver CornFlake malware and ChocoShell infostealer, while a malicious campaign in RubyGems distributed 199 trojanized packages embedding XMRig cryptojacking payloads.

AI-extracted · verify before operational use

Extracted Entities 7 found

Indicators of Compromise 3 extracted

Type Value Detail
IP 165[.]154[.]236[.]93 Details →
Domain corepack[.]org Details →
Filename lib/.threadpool.rb Details →

MITRE ATT&CK TTPs 57 techniques

T1003 OS Credential Dumping · Credential Access T1003.001 LSASS Memory · Credential Access T1021.003 Distributed Component Object Model · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1055 Process Injection · Defense Evasion T1056.001 Keylogging · Collection T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1059.007 JavaScript · Execution T1070.004 File Deletion · Defense Evasion T1071 Application Layer Protocol · Command And Control T1071.001 Web Protocols · Command And Control T1071.003 Mail Protocols · Command And Control T1071.004 DNS · Command And Control T1074.001 Local Data Staging · Collection T1080 Taint Shared Content · Lateral Movement T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1090 Proxy · Command And Control T1098 Account Manipulation · Persistence T1105 Ingress Tool Transfer · Command And Control T1110 Brute Force · Credential Access T1114 Email Collection · Collection T1132.002 Non-Standard Encoding · Command And Control T1190 Exploit Public-Facing Application · Initial Access T1203 Exploitation for Client Execution · Execution T1204.002 Malicious File · Execution T1485 Data Destruction · Impact T1496 Resource Hijacking · Impact T1530 Data from Cloud Storage · Collection T1539 Steal Web Session Cookie · Credential Access T1552 Unsecured Credentials · Credential Access T1555 Credentials from Password Stores · Credential Access T1557 Adversary-in-the-Middle · Credential Access T1558.003 Kerberoasting · Credential Access T1566 Phishing · Initial Access T1568 Dynamic Resolution · Command And Control T1570 Lateral Tool Transfer · Lateral Movement T1588 Obtain Capabilities · Resource Development T1021.001 Remote Desktop Protocol · Lateral Movement T1036 Masquerading · Defense Evasion T1036.005 Match Legitimate Name or Location · Defense Evasion T1053.005 Scheduled Task · Execution T1055.001 Dynamic-link Library Injection · Defense Evasion T1136.001 Local Account · Persistence T1558 Steal or Forge Kerberos Tickets · Credential Access T1566.001 Spearphishing Attachment · Initial Access T1006 Direct Volume Access · Defense Evasion T1012 Query Registry · Discovery T1014 Rootkit · Defense Evasion T1048 Exfiltration Over Alternative Protocol · Exfiltration T1055.015 ListPlanting · Defense Evasion T1068 Exploitation for Privilege Escalation · Privilege Escalation T1548.002 Bypass User Account Control · Privilege Escalation T1059 Command and Scripting Interpreter · Execution T1078 Valid Accounts · Defense Evasion T1484 Domain or Tenant Policy Modification · Defense Evasion