SysBlue Cyber Solutions

SysBlue Cyber Solutions Sysblue is an information security consulting and managed cybersecurity services firm with headquarters in Romania.

We help clients solve information security challenges based on risk, not fear.

 Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks.Threat actors are leveraging the ...
03/09/2026



Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks.

Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads.

According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government departments, technology companies, and hotels since February 2026.

Attackers abuse Node.js to execute malicious scripts and deploy payloads in attacks targeting governments, technology companies, and hotels.

 Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control.Cybersecurity researchers have disclo...
02/09/2026



Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control.

Cybersecurity researchers have disclosed details of a new Android banking trojan called StreamRat that was promoted to Spanish-speaking users through a fake television-streaming campaign on Meta and can give operators near-complete control of infected devices.

ThreatFabric said the campaign's advertisement focused on Spain and reached an estimated 570,950 Meta accounts in the European Union that saw it at least once, with totals for infected devices and confirmed victims remaining unreported.

StreamRat uses fake streaming ads to reach Spanish-speaking Android users and enables device takeover after sideloading and permission grants.

 Attackers Steal METR API Key and Consume AI Credits Worth About $600,000.METR (short for Model Evaluation and Threat Re...
01/09/2026



Attackers Steal METR API Key and Consume AI Credits Worth About $600,000.

METR (short for Model Evaluation and Threat Research and pronounced "Meter"), a research non-profit that evaluates frontier artificial intelligence (AI) models for their ability to carry out long-horizon, agentic tasks, disclosed that it suffered "two notable security incidents" where external actors attempted to gain unauthorized access to its systems.

No sensitive information is believed to have been accessed as a result of these incidents, it said, adding that a version of its findings was shared with AI companies it works with prior to public disclosure. The attacks have not been attributed to any known threat actor or group, nor did they involve AI agents breaking into its evaluations.

Attackers stole a METR API key and consumed credits worth about $600,000, while a later campaign failed to access internal data.

 TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor.Microsoft has disclosed details of a new Cl...
30/08/2026



TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor.

Microsoft has disclosed details of a new ClickFix variant, dubbed TerminalFix, that aims to trick users into running a malicious command in Windows Terminal or PowerShell.

"While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply the same technique but direct users to Windows Terminal or PowerShell instead, increasing the likelihood that complex, multi-line scripts execute successfully," Microsoft security researchers Sagar Patil, Suriyaraj Natarajan, and Parasharan Raghavan said in an analysis published this week.

Microsoft says TerminalFix uses fake Cloudflare CAPTCHAs to trigger PowerShell and deploy a reverse-tunnel backdoor for internal network access.

 PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions.PaperCut has alerted customers that bad actors...
28/08/2026



PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions.

PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks.

The company has released an emergency patch for v25 and v26 to address the issue. It said it's "aware of confirmed customer incidents and is treating this matter with the highest priority." An investigation into the incident is ongoing.

PaperCut says a zero-day affecting all NG and MF versions is actively exploited; emergency patches are available for v25 and v26.

 OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face.OpenAI on Wednesday revealed th...
27/08/2026



OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face.

OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, adding that it found evidence of misaligned behavior as early as late May.

The incident, the company said, took place during cybersecurity evaluations of several OpenAI models, and that it was mainly fueled by what it described as a "highly capable, internal-only research model" comparable in scale to GPT‑5.6 Sol.

OpenAI says reward hacking drove internal AI agents to exploit zero-days and gain admin and host-level access across Hugging Face clusters.

 INTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud Crackdown.An eight-month INTERPOL operati...
26/08/2026



INTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud Crackdown.

An eight-month INTERPOL operation targeting West African organized crime groups has led to arrests of 58 people and the identification of 263 suspects.

"The operation, which brought together 22 countries from six continents, is a response to the escalating global threat posed by West African criminal networks – such as the Black Axe and other similar groups," INTERPOL said.

INTERPOL's Operation Jackal IV arrests 58 people, identifies 263 suspects, and disrupts fraud and laundering networks across 22 countries.

 Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows.Thousands of companies have been affe...
25/08/2026



Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows.

Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication.

According to ANY.RUN research, 48% of targeted email addresses were potentially compromised. Most of the affected companies are US-based.

Mirage2FA targets Microsoft 365, with 48% of targeted emails potentially compromised and 9,000+ potential session-theft events.

 UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit.Cybersecurity researchers ...
24/08/2026



UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit.

Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors.

The vast majority of the targets are located in Brazil, Bolivia, China, Canada, and Vietnam. Details of the threat activity came to light following the discovery of an open directory hosted at "139.180.197[.]150," which was observed communicating with one of the compromised machines.

UAT-10147 targets Windows and Linux servers with known flaws and AI tools, deploying malware for SEO fraud and data theft.

 ToxicPanda Android malware uses VPN permissions to block Google Play.The ToxicPanda Android malware has evolved with ne...
23/08/2026



ToxicPanda Android malware uses VPN permissions to block Google Play.

The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands.

The malware now requests VPN service permissions to create a local interface that allows it to control network traffic passing through it. The feature enables ToxicPanda 2.0 to block communication from Google Play and Google Play Services.

The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands.

Address

București
Bucharest
030171

Alerts

Be the first to know and let us send you an email when SysBlue Cyber Solutions posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share