CHECKLEAKED.CC

Loading

Classic site

DAILY BRIEFING

Rhysida Attacks Berlin Administration as Aurora Ransomware Operators Abuse Cursor AI

Today's briefing covers Rhysida ransomware data theft in Berlin, Aurora ransomware operators using Cursor AI, and ValleyRAT disguised as adware to bypass antivirus exclusions.

Cybercrime groups are increasingly leveraging legitimate administrative tools and AI platforms to streamline operations and bypass security controls. In recent activity, Rhysida ransomware operators targeted Berlin's city administration, while threat actors associated with Aurora ransomware utilized the Cursor AI coding assistant to plan attacks across target networks.

At the same time, endpoint security faces growing risks from user-level software choices and local AI agents. The Silver Fox group has been observed deploying the ValleyRAT backdoor inside signed adware applications like QN Wallpaper, taking advantage of users who add such tools to antivirus exclusions.

Security teams must prioritize endpoint governance, manage local exclusions strictly, and maintain visibility over AI agent activity to counter these evolving threat vectors.

Berlin confirms data theft after Rhysida ransomware attack claims

Berlin's city administration confirmed cybercriminals are attempting to extort the city after the Rhysida ransomware gang listed it on their data leak site following data theft.

  • Berlin
  • Rhysida
  • ransomware
Read the original

ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions

Threat actor Silver Fox is distributing the ValleyRAT backdoor disguised as QN Wallpaper, a signed Chinese adware app. The malware operates under trusted processes to evade detection on endpoints where users added the adware to antivirus exclusions.

  • ValleyRAT
  • backdoor
  • adware
Read the original

Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets

Threat actors associated with Aurora ransomware used the AI-powered coding assistant Cursor to plan attacks against over 20 organizations. An exposed open directory revealed months of activity and leaked attack toolkits.

Why it matters
Cybercrime groups are leveraging agentic AI tools to streamline attack execution and network intrusion planning across corporate targets.
  • Aurora
  • ransomware
  • Cursor
  • AI
Read the original

Securing Claude Code: The New Compliance API, Local Visibility, and Identity Governance

Anthropic introduced new Compliance API endpoints for Claude Code to help security teams monitor local file access, shell command execution, and tool usage. Local AI agents currently account for 68.6% of AI agents found in customer environments.

Why it matters
Local AI agents run on endpoints inheriting employee credentials and network permissions, making activity monitoring necessary to prevent unchecked access.
  • Anthropic
  • Claude
  • AI
  • compliance
Read the original

Microsoft says Windows 11 KB5120998 update resets mouse settings

Microsoft confirmed that installing the KB5120998 August 2026 non-security preview update for Windows 11 causes mouse settings to automatically revert to defaults.

  • Microsoft
  • update
Read the original

Key takeaways

  • Berlin confirmed data theft following ransomware extortion claims by the Rhysida group.
  • Aurora ransomware operators used the Cursor AI coding assistant to help plan network attacks.
  • Silver Fox deployed ValleyRAT inside signed QN Wallpaper adware to bypass antivirus exclusions.
  • Local AI agents like Claude Code require identity governance and endpoint visibility controls.
  • Rhysida
  • Ransomware
  • ValleyRAT
  • SilverFox
  • Aurora