<?xml version="1.0" encoding="UTF-8" ?><feed xmlns="http://www.w3.org/2005/Atom">
    <title>Babgond</title>
    <subtitle>Babgond</subtitle>
    <id>https://babgond.com/moonmoonApple_v9/</id>
    <link rel="self" type="application/atom+xml" href="https://babgond.com/moonmoonApple_v9/atom.php" />
    <link rel="alternate" type="text/html" href="https://babgond.com/moonmoonApple_v9/" />
    <updated>2026-07-26T01:23:50Z</updated>
    <author><name>Babgond</name></author>


    <entry>
        <title type="html">IT-Sentinel - Actualités Cybersécurité : The hacker who humiliated spyware makers and was never caught</title>
        <id>https://techcrunch.com/2026/07/25/the-hacker-who-humiliated-spyware-makers-and-was-never-caught/</id>
        <link rel="alternate" href="https://techcrunch.com/2026/07/25/the-hacker-who-humiliated-spyware-makers-and-was-never-caught/"/>
        <published>2026-07-25T22:24:00+00:00</published>
        <updated>2026-07-25T22:24:00+00:00</updated>
        <author><name><div>Lorenzo Franceschi-Bicchierai</div></name></author>

        <content type="html"><![CDATA[<div>An awe-inspiring hacktivist who hacked two controversial government spyware makers may be the most prolific hacker to have never gotten caught. What do we know about Phineas Fisher?</div>]]></content>
    </entry>


    <entry>
        <title type="html">IT-Sentinel - Actualités Cybersécurité : Iran-Linked Actors Breach Are Targeting US Water and Energy Control Systems</title>
        <id>https://securityaffairs.com/195991/apt/iran-linked-actors-breach-are-targeting-us-water-and-energy-control-systems.html</id>
        <link rel="alternate" href="https://securityaffairs.com/195991/apt/iran-linked-actors-breach-are-targeting-us-water-and-energy-control-systems.html"/>
        <published>2026-07-25T22:11:00+00:00</published>
        <updated>2026-07-25T22:11:00+00:00</updated>
        <author><name><div>Pierluigi Paganini</div></name></author>

        <content type="html"><![CDATA[<div>US agencies warn Iran-linked actors are targeting internet-exposed water and energy control systems, risking disruption.



Federal agencies updated their cybersecurity advisory this week: Iran-linked actors are inside American water and energy control systems, and they’re not just looking around. They’re changing things.



The updated advisory from CISA, the FBI, NSA, and the Department of Energy says these actors are getting into programmable logic controllers, the small industrial computers that run pumps, valves, and safety alarms. Once inside, they can mess with what operators see on their screens. That’s how you get outages nobody saw coming.



“The authoring agencies urgently warn U.S. organizations of ongoing Iranian-affiliated cyber targeting of internet-connected operational technology (OT) devices, including programmable logic controllers (PLCs).” reads the advisory. “These actions disrupted PLCs across several U.S. critical infrastructure sectors through malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruption and financial loss.”



This isn’t new territory. Back in April, the same agencies flagged Iranian hackers going after Rockwell Automation controllers specifically. The updated advisory widens the net. Now Schneider Electric and Siemens equipment is on the list too.



US agencies have expanded guidance on detecting malicious code changes in PLCs after observing attacks targeting Rockwell Automation, Schneider Electric, Siemens, and other internet-exposed industrial controllers. 



Attackers access exposed devices via OT ports (44818, 2222, 102, 502) and modems over SSH (port 22), then exfiltrate PLC project files using vendor tools such as Studio 5000, EcoStruxure Control Expert, and TIA Portal. They modify or delete project logic, including Add-On Instructions (AOIs), manipulate HMI and SCADA displays, and disable shutdown and alarm functions, allowing industrial systems to enter unsafe states without alerting operators.



Organizations should follow vendor security best practices, remove PLCs from direct internet access using secure gateways and firewalls, and monitor logs for indicators of compromise and suspicious traffic on OT ports such as 44818, 2222, 102, and 502. Rockwell users should set controllers to Run mode, while suspected victims should contact vendors and federal agencies.



The agencies say potentially any internet-exposed industrial control system could be a target. Here’s the part that should make plant operators lose some sleep. In one case, the hackers didn’t just peek at a system. They rewrote the controller’s programming logic to disable the processes meant to trigger shutdowns and alarms during dangerous conditions. 



“At one U.S. victim, the FBI observed the APT actors download a malicious project file to a targeted PLC using configuration software. Analysis indicated the project file retained ladder logic for downstream function but added logic that overrode specific instruction sets responsible for maintaining safe operating parameters in the victim’s environment.



“Since at least March 2026, the authoring agencies identified (through engagements with victim organizations) an Iranian-affiliated APT group disrupted the function of PLCs.” states the advisory. “Organizations across several U.S. critical infrastructure sectors (including Government Services and Facilities, WWS, and Energy Sectors) deployed these PLCs within a wide variety of industrial automation processes. Some of the victims experienced operational disruption and financial loss.”



Systems could then drift into unsafe territory with nobody watching the warning lights, because the warning lights had been switched off from the inside.



“After the actors extracted device project files, the FBI and CISA identified the modification and deletion of project file logic, to include Add-On Instructions (AOIs) and data manipulation on HMI and SCADA displays [T1565].” continues the advisory.” Additionally, the changes disabled critical shutdown and alarm logic, allowing systems to enter unsafe conditions without notifying operators of the anomalies.”



The advisory ties the activity to the ongoing conflict between Iran and the US and Israel, framing it as an effort to cause disruption inside the United States. It fits a pattern going back to February, when the war started and Iranian-linked hacking picked up sharply across the region.



Not all of it looks like this. Some of it has been standard espionage and embarrassment campaigns, like the leak of FBI Director Kash Patel’s personal email account. Some of it has been genuinely destructive. The Iranian group known as Handala remotely wiped tens of thousands of employee devices at medical device maker Stryker, and separately claimed a breach at California’s Cal Water, saying it could disrupt the water supply. Cal Water pushed back, saying it found no sign anyone had touched its operational networks.



That’s the pattern worth watching: espionage on one track, disruption on another, and now a wider set of manufacturers exposed on the operational technology side. If your PLC talks to the internet, it’s not a bystander anymore.



Nobody wants their water plant’s alarm system to be the one thing an adversary quietly switches off. Time to check who can actually reach those controllers from outside.



Follow me on Twitter: @securityaffairs and Facebook and Mastodon



Pierluigi Paganini



(SecurityAffairs – hacking, Iran-Linked Actors)</div>]]></content>
    </entry>


    <entry>
        <title type="html">IT-Sentinel - Actualités Cybersécurité : Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable</title>
        <id>https://thehackernews.com/2026/07/malvertising-sends-malware-in-pieces.html</id>
        <link rel="alternate" href="https://thehackernews.com/2026/07/malvertising-sends-malware-in-pieces.html"/>
        <published>2026-07-25T20:48:00+00:00</published>
        <updated>2026-07-25T20:48:00+00:00</updated>
        <author><name>anonymous</name></author>

        <content type="html"><![CDATA[<div>A malvertising operation dubbed SourTrade is making victims' browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file from a fixed URL.

Confiant, which detailed the campaign on July 23, 2026, said it has operated since late 2024 and impersonated TradingView, Solana, and Luno to target retail traders and</div>]]></content>
    </entry>


    <entry>
        <title type="html">IT-Sentinel - Actualités Cybersécurité : Australian energy provider Origin Energy disclosed a data breach impacting customer data</title>
        <id>https://securityaffairs.com/195973/data-breach/australian-energy-provider-origin-energy-disclosed-a-data-breach-impacting-customer-data.html</id>
        <link rel="alternate" href="https://securityaffairs.com/195973/data-breach/australian-energy-provider-origin-energy-disclosed-a-data-breach-impacting-customer-data.html"/>
        <published>2026-07-25T17:21:00+00:00</published>
        <updated>2026-07-25T17:21:00+00:00</updated>
        <author><name><div>Pierluigi Paganini</div></name></author>

        <content type="html"><![CDATA[<div>Origin Energy confirmed a data breach after a hacker claimed to have stolen data from 2 million customers and threatened to leak it.



Origin Energy disclosed a cyberattack that exposed customer data after a hacker claimed to have stolen records belonging to 2 million customers and threatened to publish them. An alleged hacker calling themselves “John Doe” claimed responsibility for the Origin Energy breach, saying they accessed the company’s customer systems and stole customers’ personal data. 



“Most are loyal, long-term customers,” reads an email sent by the hacker to Australian media outlet 7News.  



“Despite my outreach to their board members, security teams, and customer care departments, Origin hasn’t made a public announcement about the breach or responded to negotiate next steps.



“They’ve shown no interest in resolving it before the data goes public.” 



Source 7News



The claim prompted an urgent investigation by the Australian energy provider.



The Australian energy provider said unauthorized access affected some customer information and is still investigating the incident to determine how many people were impacted.



“Origin can confirm there has been unauthorised access and disclosure of some customers’ data. We are working to understand the total number of impacted customers, and we will contact any customers where we can confirm they have been affected.” reads the update on data security incident published by the company on July 23.



“For affected customers, impacted data may include name, address, date of birth, contact phone number and account information, as well as the last four digits of a credit card, or the last three digits of a bank account. Incomplete credit card or bank account information cannot be used to make purchases or access accounts.”



Origin Energy is one of Australia’s largest integrated energy companies, with approximately 4.8 million customers. Headquartered in Sydney, it operates across the electricity and natural gas sectors.



The firm is investigating the security breach with the help of external cybersecurity experts. 



The company said the attacker may have stolen customers’ names, addresses, dates of birth, phone numbers, account details, and partial payment card or bank account numbers. The energy firm is notifying affected customers and has informed Australian law enforcement, cyber, and privacy authorities, including the Australian Cyber Security Centre, the Australian Federal Police and the Office of the Australian Information Commissioner. 



Origin Energy pointed out that its operations have not been impacted.



The “John Doe” gave Origin 14 days to respond and threatened to release the stolen data if the company does not reach an agreement.



Follow me on Twitter: @securityaffairs and Facebook and Mastodon



Pierluigi Paganini



(SecurityAffairs – hacking, newsletter)</div>]]></content>
    </entry>


    <entry>
        <title type="html">IT-Sentinel - Actualités Cybersécurité : Malicious sites use JavaScript to build malware in browser memory</title>
        <id>https://www.bleepingcomputer.com/news/security/malicious-sites-use-javascript-to-build-malware-in-browser-memory/</id>
        <link rel="alternate" href="https://www.bleepingcomputer.com/news/security/malicious-sites-use-javascript-to-build-malware-in-browser-memory/"/>
        <published>2026-07-25T17:21:00+00:00</published>
        <updated>2026-07-25T17:21:00+00:00</updated>
        <author><name><div>Bill Toulas</div></name></author>

        <content type="html"><![CDATA[<div>A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory. [...]</div>]]></content>
    </entry>


    <entry>
        <title type="html">IT-Sentinel - Actualités Cybersécurité : 1,500 curl authors</title>
        <id>https://daniel.haxx.se/blog/2026/07/25/1500-curl-authors/</id>
        <link rel="alternate" href="https://daniel.haxx.se/blog/2026/07/25/1500-curl-authors/"/>
        <published>2026-07-25T16:29:00+00:00</published>
        <updated>2026-07-25T16:29:00+00:00</updated>
        <author><name><div>Daniel Stenberg</div></name></author>

        <content type="html"><![CDATA[<div>It takes a village to make curl. A rather big village.



I have not been a solo maintainer of curl for a long time and I don’t even do half of the commits anymore 



Since today, the curl git repository holds the accumulated efforts from 1,500 separate and named individuals. Only 4.5 years since we passed 1,000. Yay for us!



Author 1,500 turned out to be Sameeh Jubran who authored this.




			
				
			
		Number of commit authors in the curl project</div>]]></content>
    </entry>


    <entry>
        <title type="html">IT-Sentinel - Actualités Cybersécurité : ShinyHunters data leaks fuel $2,000 sextortion email scam</title>
        <id>https://www.bleepingcomputer.com/news/security/shinyhunters-data-leaks-fuel-2-000-sextortion-email-scam/</id>
        <link rel="alternate" href="https://www.bleepingcomputer.com/news/security/shinyhunters-data-leaks-fuel-2-000-sextortion-email-scam/"/>
        <published>2026-07-25T16:16:00+00:00</published>
        <updated>2026-07-25T16:16:00+00:00</updated>
        <author><name><div>Lawrence Abrams</div></name></author>

        <content type="html"><![CDATA[<div>Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin. [...]</div>]]></content>
    </entry>


    <entry>
        <title type="html">IT-Sentinel - Actualités Cybersécurité : Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available</title>
        <id>https://thehackernews.com/2026/07/fastjson-1x-rce-vulnerability-targeted.html</id>
        <link rel="alternate" href="https://thehackernews.com/2026/07/fastjson-1x-rce-vulnerability-targeted.html"/>
        <published>2026-07-25T14:52:00+00:00</published>
        <updated>2026-07-25T14:52:00+00:00</updated>
        <author><name>anonymous</name></author>

        <content type="html"><![CDATA[<div>Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process.

Tracked as CVE-2026-16723, the vulnerability carries an Alibaba-assigned CVSS score of 9.0. The confirmed chain requires</div>]]></content>
    </entry>


    <entry>
        <title type="html">IT-Sentinel - Actualités Cybersécurité : ConfigoMatic : le configurateur de PC sur mesure 100% compatible</title>
        <id>https://www.it-connect.fr/configomatic-configurateur-pc-sur-mesure/</id>
        <link rel="alternate" href="https://www.it-connect.fr/configomatic-configurateur-pc-sur-mesure/"/>
        <published>2026-07-25T13:00:00+00:00</published>
        <updated>2026-07-25T13:00:00+00:00</updated>
        <author><name><div>Florian BURNEL</div></name></author>

        <content type="html"><![CDATA[<div>Découvrez le ConfigoMatic, le configurateur PC de TopAchat pour concevoir un PC gamer sur mesure 100% compatible, à monter soi-même ou pas : à vous de choisir.
Le post ConfigoMatic : le configurateur de PC sur mesure 100% compatible a été publié sur IT-Connect.</div>]]></content>
    </entry>


    <entry>
        <title type="html">IT-Sentinel - Actualités Cybersécurité : The OpenAI Models That Hacked Hugging Face Were ‘Active on the Internet’ for Days</title>
        <id>https://www.wired.com/story/security-news-this-week-the-openai-models-that-hacked-hugging-face-were-active-on-the-internet-for-days/</id>
        <link rel="alternate" href="https://www.wired.com/story/security-news-this-week-the-openai-models-that-hacked-hugging-face-were-active-on-the-internet-for-days/"/>
        <published>2026-07-25T12:30:00+00:00</published>
        <updated>2026-07-25T12:30:00+00:00</updated>
        <author><name><div>Lily Hay Newman, Dhruv Mehrotra</div></name></author>

        <content type="html"><![CDATA[<div>Plus: Russian hackers are trying to steal US nuclear scientists’ emails, the State Department bans known scammers from entering the United States, and more.</div>]]></content>
    </entry>


</feed>
