DAILY BRIEFING
SilkParasite Espionage, 14,500+ Dahua Devices Hacked, and StopAndProtect Campaign
Today's briefing details AI-assisted SilkParasite malware targeting Central Asia, widespread Dahua IoT device compromises, and a WordPress-driven malware campaign.
5 stories2 min read

Network administrators and IoT operators should prioritize remediation immediately. Dahua device owners need to patch authentication bypasses and disable unneeded P2P relays, while WordPress site owners must audit installations used by the StopAndProtect campaign.
These operations demonstrate how attackers leverage automation and existing exposed infrastructure to scale cybercrime and espionage operations simultaneously.
SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs
A China-nexus threat cluster named SilkParasite has been observed targeting Central Asian government bodies using seven remote access tool (RAT) families. Five of the RATs—DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT—were previously undocumented and feature AI-assisted lures and human-developed code.
- Why it matters
- Central Asian government networks face stealthy cyber espionage campaigns leveraging novel malware strains designed to evade standard detection mechanisms.
Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P
Operation CameraSwarm compromised over 14,530 Dahua devices between June and July 2026 using credential attacks, two authentication bypass vulnerabilities, and a P2P relay technique. Over 1,900 devices were configured with persistent accounts, with compromises concentrated in Ukraine and Russia.
- Why it matters
- Organizations with exposed Dahua hardware risk device commandeering and unauthorized access via unauthenticated P2P relays and auth bypass flaws.
- What to do
- Update Dahua device firmware to the latest fixed release, disable P2P functionality if not required, and audit accounts for unknown users.
StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data
Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track the status of the activity.
- Why it matters
- WordPress site owners risk having infrastructure leveraged for malware delivery, while end users face ransomware and credential theft from ClickFix lures.
Phishing 3.0: The Fight Moves to Agent Versus Agent
Most email defenses still do the job they did a decade ago.
Microsoft fixes known issue causing Windows Defender crashes
Microsoft resolved a known issue where Windows Defender crashed with 0xc0000005 access violation errors following a recent security update.
- Why it matters
- Affected Windows endpoints were left without active Windows Defender protection due to service crashes until patched.
Key takeaways
- Update Dahua device firmware immediately and disable P2P relays to prevent Operation CameraSwarm exploitation.
- Bitdefender reports China-nexus SilkParasite campaign using five new RATs against Central Asian governments.
- Check Point uncovered StopAndProtect using nearly 2,000 hacked WordPress sites to host ransomware and steal data.
- Microsoft resolved a Windows Defender bug causing 0xc0000005 access violation crashes following a security update.