CHECKLEAKED.CC

Loading

Classic site

DAILY BRIEFING

SilkParasite Espionage, 14,500+ Dahua Devices Hacked, and StopAndProtect Campaign

Today's briefing details AI-assisted SilkParasite malware targeting Central Asia, widespread Dahua IoT device compromises, and a WordPress-driven malware campaign.

Network administrators and IoT operators should prioritize remediation immediately. Dahua device owners need to patch authentication bypasses and disable unneeded P2P relays, while WordPress site owners must audit installations used by the StopAndProtect campaign.

These operations demonstrate how attackers leverage automation and existing exposed infrastructure to scale cybercrime and espionage operations simultaneously.

SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs

A China-nexus threat cluster named SilkParasite has been observed targeting Central Asian government bodies using seven remote access tool (RAT) families. Five of the RATs—DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT—were previously undocumented and feature AI-assisted lures and human-developed code.

Why it matters
Central Asian government networks face stealthy cyber espionage campaigns leveraging novel malware strains designed to evade standard detection mechanisms.
  • SilkParasite
  • RAT
  • Espionage
  • Malware
Read the original

Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P

Operation CameraSwarm compromised over 14,530 Dahua devices between June and July 2026 using credential attacks, two authentication bypass vulnerabilities, and a P2P relay technique. Over 1,900 devices were configured with persistent accounts, with compromises concentrated in Ukraine and Russia.

Why it matters
Organizations with exposed Dahua hardware risk device commandeering and unauthorized access via unauthenticated P2P relays and auth bypass flaws.
What to do
Update Dahua device firmware to the latest fixed release, disable P2P functionality if not required, and audit accounts for unknown users.
  • Dahua
  • IoT
  • CameraSwarm
  • Bypass
Read the original

StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data

Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track the status of the activity.

Why it matters
WordPress site owners risk having infrastructure leveraged for malware delivery, while end users face ransomware and credential theft from ClickFix lures.
  • WordPress
  • StopAndProtect
  • Ransomware
  • ClickFix
Read the original

Phishing 3.0: The Fight Moves to Agent Versus Agent

Most email defenses still do the job they did a decade ago.

  • Phishing
  • AI
Read the original

Microsoft fixes known issue causing Windows Defender crashes

Microsoft resolved a known issue where Windows Defender crashed with 0xc0000005 access violation errors following a recent security update.

Why it matters
Affected Windows endpoints were left without active Windows Defender protection due to service crashes until patched.
  • Microsoft
  • Windows
  • Defender
Read the original

Key takeaways

  • Update Dahua device firmware immediately and disable P2P relays to prevent Operation CameraSwarm exploitation.
  • Bitdefender reports China-nexus SilkParasite campaign using five new RATs against Central Asian governments.
  • Check Point uncovered StopAndProtect using nearly 2,000 hacked WordPress sites to host ransomware and steal data.
  • Microsoft resolved a Windows Defender bug causing 0xc0000005 access violation crashes following a security update.
  • SilkParasite
  • DriveSilkRAT
  • CookiETagRAT
  • NomadRAT
  • GoginRAT