DAILY BRIEFING
Iranian RATs targeting macOS, 22,000 unpatched Exchange servers, and METR API key breach
Today's briefing covers Iranian cross-platform malware targeting Linux and macOS, exposed Microsoft Exchange servers, social engineering tactics, and AI credit theft.
5 stories2 min read

Threat actors are increasingly focusing on cross-platform reach and repeatable, low-complexity delivery mechanisms. Iranian group Nimbus Manticore is deploying Node.js and JavaScript malware against macOS and Linux targets disguised as hiring tasks, while ClickFix techniques exploit user interaction to bypass scanning defenses entirely.
At the same time, infrastructure vulnerability management remains a primary exposure point. Nearly 22,000 Microsoft Exchange servers remain vulnerable to complete mailbox compromise, demonstrating how basic perimeter hygiene continues to lag behind known threat vectors.
Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks
Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes.
- Why it matters
- Organizations running unpatched Exchange servers face immediate risk of full email compromise, data exfiltration, and lateral movement across their enterprise network.
- What to do
- Patch exposed Microsoft Exchange servers immediately to resolve the authentication bypass vulnerability.
Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests
The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS systems using cross-platform remote access trojans (RATs) developed using Node.
Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones
Threat actors are heavily favoring simple, repeatable attack methods. Microsoft reports ClickFix social engineering—where users are tricked into running clipboard commands via terminal—accounted for 47% of initial access attacks, while Bitdefender found 84% of high-severity incidents leveraged living-off-the-land…
- Why it matters
- Attacks increasingly bypass traditional security tools because they rely on user actions and legitimate system binaries rather than custom malware or software exploits.
Attackers Steal METR API Key and Consume AI Credits Worth About $600,000
profit METR disclosed two security incidents in 2026. In March, threat actors stole an inference API key and consumed approximately $600,000 in AI credits. In May, attackers systematically probed public infrastructure and attempted to exploit an exposed endpoint.
- Why it matters
- Exposed API credentials and misconfigured public endpoints can lead to massive financial loss through resource abuse, even if underlying internal data remains intact.
Five Venezuelans plead guilty to ATM jackpotting attacks in US
Five Venezuelan nationals pleaded guilty in the US to executing ATM jackpotting attacks that deployed malware to force cash dispensers to empty physical currency.
Key takeaways
- Nimbus Manticore uses trojanized coding tests containing NodeRabbit and PollCat malware to target macOS and Linux platforms.
- Nearly 22,000 exposed Microsoft Exchange servers remain unpatched against an authentication bypass flaw allowing mailbox compromise.
- ClickFix social engineering was observed by Microsoft as the most common initial access vector last year, accounting for 47% of notifications.
- Attackers compromised an API key at AI research non-profit METR, consuming approximately $600,000 in inference credits.