Cyware at Space ISAC 2026
Daily Threat Briefing
Diamond Trail

Cyware Daily Threat Intelligence - August 17, 2026

shutterstock 2048595065

A single click on a fake technical assessment can drain cryptocurrency wallets in seconds, as attackers use LinkedIn outreach to lure victims into running NeedleStealer. Cyware tracks how this campaign leverages browser telemetry and Telegram reporting to automate theft across six blockchains, turning job seekers into targets for rapid asset loss.

A critical flaw in Metabase is letting attackers run arbitrary SQL commands against business data, with public exploits and active attacks already impacting companies like Framework and Tally. With 13% of cloud environments running Metabase, defenders face urgent pressure to patch or risk real-world data exposure.

Leaked credentials are fueling a wave of data theft as TheHatman targets Fortune 500 Azure directories, exposing over 1.7 million records from McDonald’s alone. Attackers are mapping internal structures to enable more convincing spear-phishing and privilege escalation across global sectors.

Top Malware Reported in the Last 24 Hours

NeedleStealer lures crypto users via LinkedIn

NeedleStealer is a Rust-based infostealer deployed in a fake recruiting campaign targeting cryptocurrency users. NeedleStealer collects telemetry including IP address, geolocation, ISP, operating system, and browser details, and NeedleStealer reports victim interactions into Telegram chats for operator tracking. NeedleStealer’s infection chain includes a Rust infostealer and a Go-based RAT, enabling credential theft and remote access. NeedleStealer is delivered through LinkedIn outreach, where victims are tricked into running a malicious Google Apps Script disguised as a technical assessment. NeedleStealer specifically targets wallet extensions such as MetaMask, Phantom, Rabby, Keplr, OKX, Coinbase Wallet, and Trust Wallet. Researchers observed NeedleStealer operators stealing assets across six blockchains, repaying lending positions, and consolidating Ether.

StubMaker typosquats RubyGems to steal

StubMaker is a multi-stage Windows infostealer distributed via a RubyGems typosquatting campaign. StubMaker targets Chromium-based browser data, including saved passwords, cookies, and credit card details, and StubMaker also seeks out cryptocurrency wallets and Telegram data. StubMaker uses near-miss package names such as brumdler and brundlef, published from compromised RubyGems accounts, to evade detection. StubMaker is installed when developers or organizations mistakenly pull malicious dependencies during routine package installation. StubMaker’s victims include developers and companies that rely on rapid dependency management, exposing them to account takeovers, stolen funds, and private chat compromise. Researchers traced the campaign to two initial packages and a subsequent wave of 15 more gems after takedowns.

Projextor hides inside trojanized Electron apps

Projextor is a malware campaign that embeds itself in Electron-based productivity applications to enable arbitrary JavaScript execution and desktop capture. Projextor abuses Electron preload scripts and insecure app settings to load code dynamically and capture on-screen content. Projextor is distributed through websites impersonating legitimate services, offering trojanized apps like Kitchen Canvas and DocConvertWizard to users seeking document converters or meal planners. Projextor’s infection vector relies on users downloading and installing these tampered applications. Projextor targets users of productivity software, increasing the risk of credential theft and privacy loss. G DATA detailed Projextor as part of a broader campaign exploiting trust in familiar workflows.

Top Vulnerabilities Reported in Last 24 hours

Metabase bug lets attackers query your data (CVE-2026-72898, CVSS 10.0)

CVE-2026-72898 is a critical SQL injection vulnerability in Metabase with a CVSS score of 10.0. Successful exploitation allows attackers to execute arbitrary SQL commands and access sensitive business data. CVE-2026-72898 is actively exploited in the wild, with public proof-of-concept exploits available. Researchers at Wiz discovered CVE-2026-72898, and impacted companies include Framework, Tally, n8n, Kilo Code, and ChecklyHQ. A fix is available in the latest Metabase patches, and defenders can check /api/session/properties to identify vulnerable versions. Metabase is present in 13% of cloud environments, with 25% of those instances internet accessible, increasing the risk of data exposure and service disruption.

Windows Defender ‘ShieldBreak’ enables SYSTEM takeover (CVE-2026-69414)

CVE-2026-69414 is a privilege escalation vulnerability in Microsoft Defender, dubbed ShieldBreak. Exploitation of CVE-2026-69414 allows an attacker with local access to escalate privileges to SYSTEM, granting full device control. No active exploitation of CVE-2026-69414 has been confirmed in the provided report, but public disclosure increases the risk of real-world attacks. The issue affects Microsoft Defender, and the reporting notes Microsoft was not notified in advance of disclosure. Microsoft is working on a security update for CVE-2026-69414, but no release date has been specified. All supported versions of Microsoft Defender are potentially affected.

WordPress plugin flaw enables admin account hijack (User Profile Builder, CVSS 9.8)

A critical authentication bypass in the WordPress User Profile Builder plugin (CVSS 9.8) allows attackers to hijack administrator accounts. Exploitation lets attackers log in as admin by abusing a username-length mismatch between the plugin (70 characters) and WordPress core (60 characters), generating an autologin nonce tied to user ID 1. Attackers are expected to leverage this vulnerability, and thousands of sites remain exposed despite an update being available since July 16. Wordfence identified the issue, and attackers can add new admin users, install malicious plugins, and steal site data. A security update is available, and enabling two-factor authentication for admin accounts is recommended to reduce takeover risk.

Top Threat Actors Reported in Last 24 hours

TheHatman raids Fortune 500 Azure directories

TheHatman, a financially motivated threat actor of suspected origin, is linked to a large-scale Azure/Entra data-theft campaign targeting Fortune 500 companies. TheHatman uses leaked credentials to exfiltrate internal employee directories, including names, corporate email addresses, job titles, manager relationships, group memberships, service accounts, and privileged account entries. TheHatman leverages this data to enable spear-phishing, business email compromise, and privilege escalation by impersonating real teams and targeting decision-makers. TheHatman’s campaign spans global retail, IT services, telecommunications, hospitality, and logistics sectors. The campaign involved exfiltration of over 1.7 million records from McDonald’s, 800,000 from TCS, 425,000 from Vodafone, 250,000 from HCL Technologies, and 185,000 from IHG. Hudson Rock attributed the compromised credentials to a targeted infostealer campaign.

Operation QUICSILVER hits Myanmar via VHD lures

Operation QUICSILVER, attributed to a China-nexus actor of suspected origin, is a campaign focused on persistent access and surveillance. Operation QUICSILVER uses virtual hard disk files to deliver a Go-based backdoor called QUICAgent, and Operation QUICSILVER employs spearphishing lures such as a fabricated Belgian–Myanmar public holiday calendar and a Burmese-language graduation ceremony invitation. Operation QUICSILVER initiates infection with a malicious LNK file disguised as a PDF, triggering a script via ftp.exe to reconstruct and deploy the payload. Operation QUICSILVER targets Myanmar’s government and IT sectors, enabling ongoing data access and surveillance. Seqrite reported Operation QUICSILVER has been active since April 2026, with new VHD samples observed in June and July 2026.

NeedleStealer lures crypto users via hiring

NeedleStealer, a Rust-based infostealer used by a financially motivated group of suspected origin, is deployed in a fake recruitment workflow targeting cryptocurrency users and developers. NeedleStealer leverages LinkedIn outreach to push victims toward a malicious technical assessment built with Google Apps Script, then deploys malware to gather system and browser telemetry and report victim interactions into Telegram chats. NeedleStealer’s tactics focus on accessing wallet extensions including MetaMask, Phantom, Rabby, Keplr, OKX, Coinbase Wallet, and Trust Wallet. NeedleStealer’s campaign turns job conversations into direct routes to asset theft, with compromised browser sessions and wallet access leading to irreversible transfers across chains. The report notes NeedleStealer’s operational activity included theft of assets across six blockchains, repaying lending positions, and consolidating Ether, with overlap to Russia-based traffer and malware-as-a-service ecosystems.

Frequently Asked Questions

  1. What is NeedleStealer? NeedleStealer is part of a fake recruiting campaign that tricks cryptocurrency users into running malware through what looks like a legitimate technical assessment built in Google Apps Script. After the first contact on LinkedIn, it collects telemetry such as IP address, geolocation, ISP, operating system, and browser details, and it reports victim interactions into Telegram chats for operators to track.

  2. What is StubMaker? StubMaker is a RubyGems typosquatting campaign that delivers a multi-stage Windows infostealer, using clumsy near-miss package names rather than the usual SEO tricks. Researchers traced the first wave to two packages, brumdler and brundlef, published from the RubyGems account gemlewqqhu1, before a second account (mod8rz41mje) pushed 15 more gems after takedowns.

  3. What is Projextor? Projextor is a malware campaign that disguises itself inside Electron-based productivity apps, turning everyday downloads into tools for arbitrary JavaScript execution and desktop capture. It spreads through websites that mimic legitimate services, pushing trojanized applications such as Kitchen Canvas and DocConvertWizard to people looking for document converters or meal planners.

  4. What is CVE-2026-72898? A critical SQL injection flaw in Metabase (CVE-2026-72898, CVSS 10.0) is being exploited in the wild, letting attackers run arbitrary SQL commands against affected deployments and potentially reach sensitive business data. The issue sits in the /api/session/reset_password endpoint, where Clojure’s merge behavior and JSON keywordization can be abused via an undocumented user-id parameter to manipulate database queries.

  5. What is CVE-2026-69414? A newly disclosed Microsoft Defender flaw dubbed ShieldBreak (CVE-2026-69414) can let an attacker who already has a foothold on a machine escalate privileges all the way to SYSTEM, turning a limited intrusion into full device control. In practical terms, the exploitation method is privilege escalation: it doesn’t need to break in from the outside, but it can turn a small compromise into complete dominance over the host.

  6. What is TheHatman? TheHatman, a financially motivated threat actor, has been linked to a sweeping Azure/Entra data-theft campaign that exposed internal employee directories from several Fortune 500 companies. They used leaked credentials to exfiltrate records that map how organizations are structured, including names, corporate email addresses, job titles, manager relationships, group memberships, service accounts, and even entries tied to highly privileged accounts.

  7. What is Operation QUICSILVER? Operation QUICSILVER, a campaign attributed to a China-nexus actor, is using virtual hard disk files to smuggle a Go-based backdoor called QUICAgent into targets in Myanmar’s government and IT sectors. They drew victims in with spearphishing lures including a fabricated Belgian–Myanmar public holiday calendar and a Burmese-language graduation ceremony invitation, then used a VHD-delivered chain to reach execution.

Discover Related Resources