惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

I
Intezer
Jina AI
Jina AI
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
有赞技术团队
有赞技术团队
J
Java Code Geeks
人人都是产品经理
人人都是产品经理
博客园 - 叶小钗
M
MIT News - Artificial intelligence
月光博客
月光博客
C
Check Point Blog
Y
Y Combinator Blog
S
SegmentFault 最新的问题
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
C
Cybersecurity and Infrastructure Security Agency CISA
A
Arctic Wolf
S
Security Archives - TechRepublic
S
Securelist
美团技术团队
SecWiki News
SecWiki News
H
Help Net Security
V
Vulnerabilities – Threatpost
S
Secure Thoughts
F
Fortinet All Blogs
量子位
aimingoo的专栏
aimingoo的专栏
T
Tor Project blog
大猫的无限游戏
大猫的无限游戏
Scott Helme
Scott Helme
MyScale Blog
MyScale Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
D
Docker
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
L
Lohrmann on Cybersecurity
F
Fox-IT International blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园 - 三生石上(FineUI控件)
Engineering at Meta
Engineering at Meta
Microsoft Security Blog
Microsoft Security Blog
Recorded Future
Recorded Future
V
Visual Studio Blog
WordPress大学
WordPress大学
S
Schneier on Security
Stack Overflow Blog
Stack Overflow Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
Apple Machine Learning Research
Apple Machine Learning Research
N
News | PayPal Newsroom
GbyAI
GbyAI
T
Threat Research - Cisco Blogs

Hackread – Cybersecurity News, Data Breaches, AI and More

Can Big Data Predict Market Movements Accurately? How Can MSSPs Scale Threat Detection Without Burning Out Their Analysts? Link11 is fully committed to Europe and is opening a Customer Excellence Hub in Lisbon Trojanized Gemini and Claude Installers Target Developers Via SEO Poisoning Claude Mythos AI Identified 10,000+ Software Vulnerabilities in One Month FBI Chief Kash Patel’s Clothing Store Hacked in ClickFix Infostealer Attack Netherlands Busts Bulletproof Hosting Network Linked to Disinfo and Cybercrime Hacker Selling 340 Million OnlyFans User Records Built From Old Breaches RondoDox Botnet Exploits Critical 2018 Vulnerability to Hijack ASUS Routers FBI Warns of Kali365 Phishing Service Targeting Microsoft 365 Account 5,561 GitHub Repositories Hit by Megalodon Supply Chain Attack in Six Hours Deleted Google API Keys Remain Active up to 23 Minutes, Study Finds Europol Seizes First VPN Used by Ransomware Gangs, Arrests Administrator Android Malware Spotted Subscribing Victims to Paid Services Without Consent Microsoft’s Retired IE Tool MSHTA Now Being Used in Fileless Malware Attacks Understanding Trend Structure: Higher Highs and Lower Lows Explained GitHub Breach: TeamPCP Steals 3,800 Repositories via VS Code Extension Verizon DBIR: AI Helped Hackers Exploit Vulnerabilities in 31% of Recent Breaches Fake Word Phishing Reveals Enterprise Blind Spot in Trusted Remote Access Tools Banana RAT Malware in Fake Invoices Hits Customers at 16 Brazilian Banks AI Agent Security: Automating Workflow Without Creating Prompt Injection or Data Leak Risks How Parts Inventory Management Software Fixes Inventory Challenges Pwn2Own Berlin 2026 Closes With $1.3 Million in Zero-Day Payouts Criminal IP Returns to Infosecurity Europe 2026 with Advanced AI-Driven TI & ASM Two-Thirds of Nonhuman Accounts Are Unseen and Unmanaged, According to Orchid Security's Identity Gap Hosting Service Standards That Define High-Performing Agencies Hackers Actively Exploit ‘Nginx Rift’ Vulnerability Affecting NGINX, F5 Products 10 Top OSINT Tools Every Investigator Should Know in 2026 New Reaper Malware Uses Fake Microsoft Domain to Steal macOS Passwords 10 Tips for Phrasing Employee Feedback in Reviews Government Backed Hackers Abuse Cloudflare in Malaysian Espionage Campaign Continuous Detection, Continuous Response: Mate Security Redefines the Modern SOC The Gentlemen Ransomware Gang Hit by Internal Breach, Operations Exposed Closing the Gap: The Regulatory and Structural Maturation of Digital Assets Scammers Send Physical Phishing Letters to Steal Ledger Wallet Seed Phrases Grafana Says It Rejected Ransom Demand After Source Code Theft AI Voice Cloning: The Technology Behind It, Who's Building It, and Where It's Headed Critical ‘Claw Chain’ Vulnerabilities Put Thousands of OpenClaw AI Servers at Risk The Next Cybersecurity Challenge May Be Verifying AI Agents Hackers Use PyInstaller and AMSI Patching to Deliver XWorm RAT v7.4 CalPhishing Scam Uses EvilTokens Kit, Outlook Invites to Steal M365 Sessions Fake Job Interview Apps Drop JobStealer Malware on Windows and macOS How Fintech APIs Are Modernizing Business Cash Flow Management FamousSparrow Targeted Oil and Gas Industry via MS Exchange Server Exploit China-Linked Twill Typhoon Uses Fake Apple and Yahoo Sites for Espionage TeamPCP Claims Sale of Mistral AI Repositories Amid Mini Shai-Hulud Attack Instructure Reaches Deal with ShinyHunters to Prevent Canvas Data Leak TeamPCP Used Mini Shai-Hulud Worm to Poison Over 400 npm and PyPI Packages Slovakian Admin of Dark Web Kingdom Market Jailed for 16 Years in US Why Canadian Telecom Providers Are Prime Targets for Cyberattacks Canvas Hackers ShinyHunters Say Their Official Domain Was Suspended Fake Claude Code Installer Targets Developers With Browser Credential Stealer Pwn2Own Berlin 2026 Hits Capacity as Rejected Hackers Release 0-Days Top Video Downloaders in 2026: Why Wondershare UniConverter Remains a Strong Choice Operation HumanitarianBait Uses Fake Aid Documents to Deploy Python Spyware Google Says Hackers Used AI to Develop a Zero-Day Exploit Romanian Man Faces Up to 30 Years in US Prison Over Vishing Scams 9-Year-Old Dirty Frag Vulnerability Enables Root Access on Linux Systems Lyrie.ai Joins First Batch of Anthropic’s Cyber Verification Program Hackers Exploit Vercel GenAI to Mass-Produce Convincing Phishing Sites Two US Men Sentenced for Helping North Korean Hackers Infiltrate US Firms Hackers Trick DigiCert Into Issuing Certificates Used to Sign Malware Hackers Hijack JDownloader Site to Deliver Malware Through Installers Fake macOS Troubleshooting Sites Used to Steal iCloud Data in ClickFix Scam ClaudeBleed Vulnerability Lets Hackers Hijack Claude Chrome Extension to Steal Data ShinyHunters Defaces Canvas LMS Portal, Hundreds of Universities Affected Hackers Use Fake Claude AI Site to Infect Users With New Beagle Malware Researcher Shows Edge Browser Stores Saved Passwords in Plaintext Google Chrome Accused of Silently Installing 4GB AI Model on User Devices Why Outdated Maintenance Software Is a Growing Ransomware Risk Scammers Use Hidden Text to Bypass AI Email Filters in Phishing Scams Best OSINT Tools for Investigations and Threat Intelligence in 2026 Google Fixes CVSS 10 Gemini CLI Vulnerability Enabling GitHub Issue-Based RCE ShinyHunters’ Instructure Canvas LMS and Vimeo Breaches Impact Millions of Users Building Strategic Advantage With Integrated Planning The "Juice" Factor: Designing Game Feel Application Security Strategies Are Changing as AI-generated Code Floods the SDLC Massive “Low and Slow” DDoS Attack Hits Platform With 2.45 Billion in 5 Hours LuxSci Launches Enterprise-Grade HIPAA-Compliant Email Security for Mid-Sized Healthcare Organizations Anti-ICE Site GTFO ICE Accused of Exposing Data of 17,000+ Activists FEMITBOT Network Abuses Telegram Mini Apps for Crypto Scams and Android Malware Wiz ZeroDay.Cloud Event Reveals 20-Year-Old PostgreSQL Vulnerabilities Cyber-Secure Philanthropy: Tech Infrastructure for Global Donations 7 Key Features That Make Secure Browsers Safer Paying Ransom Won’t Help as VECT 2.0 Ransomware Destroys Data Irreversibly Google AppSheet Exploited in 30,000-User Facebook Phishing Operation 2 US Cybersecurity Experts Jailed for Aiding ALPHV (BlackCat) Ransomware 45,000 Attacks, 5,300+ Backdoors Tied to China-Linked Cybercrime Operation Hackers Use Jenkins Access to Deploy DDoS Botnet Against Gaming Servers Criminal IP and Securonix ThreatQ Collaborate to Enhance Threat Intelligence Operations Critical cPanel Vulnerability Lets Attackers Bypass Login, Gain Root Access Best Diagram Software in 2026, Why EdrawMax Works for Everyday Use Private Chats, Photos of Celebs Exposed in Suspected Stalkerware Leak Misconfigured Server Run by Hackers Leaks 345,000 Stolen Credit Cards Managed vs Self-Managed Cloud Hosting: Choosing the Best Option for Your Business 9-Year-Old Linux Kernel Vulnerability “Copy Fail” Enables Full Root Access Cursor AI Agent Wipes PocketOS Database and Backups in 9 Seconds New AI-Powered Bluekit Phishing Kit Targets Major Platforms with MFA Bypass Attacks Polymarket Rejects Data Breach Claims as Hacker Alleges 300K Records Stolen Brinker Introduces a Novel Approach to Deepfake Detection
Iran’s Nimbus Manticore Used Trojanized Zoom Installers Against US Firms
Deeba Ahmed · 2026-05-28 · via Hackread – Cybersecurity News, Data Breaches, AI and More

If you installed Zoom from unofficial sites earlier this year, your device may have been exposed to malware linked to Iran’s Nimbus Manticore hackers.

Check Point Research (CPR) recently exposed a series of cyberattacks carried out by an Iranian group called Nimbus Manticore (also tracked as UNC1549), which is affiliated with the Islamic Revolutionary Guard Corps (IRGC).

Nimbus Manticore has been most active between February and April 2026- a time of major military tension after the launch of Operation Epic Fury on 28 February 2026. Reportedly, the group has expanded its targets beyond Israel and the UAE to hit aviation and software firms in the US.

Fake Job Offers and Zoom Invites

According to CPR’s blog post, in February 2026, the hackers targeted workers in Saudi Arabia and Australia with fake job offers on OnlyOffice. When victims downloaded a ZIP archive, the group used a technique called AppDomain hijacking. By placing a malicious configuration file (Setup.exe.config) with a safe Microsoft binary (Setup.exe), they tricked the system into running a malicious file (uevmonitor.dll) to launch MiniJunk malware.

By March 2026, they switched to fake Zoom meeting invitations containing Zoominstall64.zip. This launched a real Zoom installer (Zoom_cm.exe) to hide the attack, while AppDomain hijacking quietly deployed a new backdoor called MiniFast via InitInstall.dll. The malware even hijacked a real Windows scheduled task (ZoomUpdateTaskUser) to stay hidden on the system.

Attack chain during Operation Epic Fury (Source: Check Point Research)

Search Engine Tricks

MiniFast stands out for showing clear signs of AI-assisted development. The code was exceptionally neat, featured modular organisation, and included excessive error handling for basic tasks such as GetUserName. This allowed the group to build tools rapidly mid-conflict, and when active, MiniFast gave hackers full remote control via cmd.exe while hiding its traffic by impersonating a Google Chrome browser.

In April, the group abandoned emails for SEO poisoning. They built a fake website, getsqldevelopercom, to mimic Oracle’s SQL Developer software. By registering dozens of connected domains and using keyword stuffing, they pushed the scam site to the top of Bing and DuckDuckGo results, tricking developers into downloading the MiniFast backdoor directly.

2026 campaign timeline (Source: Check Point Research)

The Verdict

Check Point Research noted that wartime pressures actually accelerated the group’s capabilities. By mixing AI-driven coding with public search engine manipulation, Nimbus Manticore skipped targeted emails entirely to compromise systems faster, showing an expansion of their ambitions well beyond regional spying.